samba-dsdb-modules-4.15.7+git.376.dd43aca9ab2-150300.3.32.1 >  A bp9|B! sPjHJ<@Frأ+jB_+uyFY7yc9zAe/xF PqTqPp|Urx׍z@ / [ [{*FYwg!mMq@F7OFnTuNz(=y;Y jmG4n)Ig`b^(5l ~0%wm`[Ԯ590%EZ}[I@wy,812acf3e5710427c1347635f1338c34c51e3baebe47b00fc138ecd0ce0d1310940d8a5914f603fd77c8cc8359ecd77c52da2de575=bp9|[t=fM˻ ;3?9z4_wa׃"A9bkTv?$} ت ɟ5s?H_53VOYޥ0C0CpF2hmz[h[8~  I((xa>Z 9ߚB<.%4Tԣ{lb"s@R}dgr檓y^ɟ7A'rz_@⾎Pl:Qΰ>pAa<?a,d0 > P ;RX^-|- - 0- - Q- -4--0-uu)u()8)9-:>J>0@0F0G0-H1-I24-X2dY2l\2-]3t-^65b6Kc6d7te7yf7|l7~u7-v8D-wQ-xRH-yRtz````a(Csamba-dsdb-modules4.15.7+git.376.dd43aca9ab2150300.3.32.1Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.bs390zl37SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxs390xrm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigW7Gw7gWWW''7Xp7G'7GG7Y@'hpWi@G'''77GG'bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbba1d8a8bd385438108360589bb2b45aa32fa3680741b994c1536aac2c84197d61be4b14d4da756cbb00bfd8d2d668a5c0945a119a527e6b4442baabf08b893cd88018560610301608be90dd0895bbbedfbf0c1c0245298dda7047c6be676ab7cdc20a29b91206154a06c6aef52b4bea450e8f30ef278029069b1c565189c5f5076000170092dfcd52e7cd3c0f9323b5e1b37613c64b06983d5e8c21014357eae0664b2b304e7b7b0e3493e4b9cdc24791b053cedd3d552caed5e6c4b12f5c474d44f6f8a84098097405fdbfd60cdf71fa29a08a8b29aea8b1320be9cb3181813593c536a1b20264c8a92682a067333f2da419efe3f6d71fa3570ca42683d2bd669350daa1152aacab141f3baee429bc8fea3bb9ce1af2d1f09a012e42c4ac5ee419d8f5d751364d6f89cf5b8d691d67f7b5a3f3da5348fbe4e3889706adc36391b0c82e3411aa553d137e956840bdfc9c0e2483abadc5e39bb58eceb334a70f8ed9aa490244c468076ae2f5fd7698c87e337d1eed1b8ce2b444bb92fa39b1803d47fcc34fd22a8a7e98b8d3a5c56b6e0135ea7fa7ee3a54512a453e47a1dfc9eacd7bb1a367bb27b52aefda915b90c27f97c9c0497a18549d8c3ffab28b8d99a43f7c1b1812a034075bda1a8376ac7c5a949e35a2dbea188496b8c2e35844a116f5a3242b0b5135b75d8eb10ec4d3351866c70f0b2c25d4711cec4fe24de0fc71db451f8d37efdfc71104f67fa255b751e331d8704750e5a5303b089b10154ee896f80c852c4cf8f3b99488101dd40c5d76358895569711c6b702cf2369f77f9abf0d616bae333bcfa21471abe90c16d9de74ece83943bf4e2cfa6e460132d550972f4527c1424064347507bbd8cb8ca6d5b99b505688f78cd161b41b53976d788e8e4605a656a707a60998860050ac299c02f5e398597fbf7a57926bd043ef5f7d37e7fe9661658986414102240cf790ff587775f0f517379cf0439cb9c6f02637575f1153e34d3b9b6291c09be7383c117baf60f92e12a3c27fc4ef704178d88252ec462d36254a5b7867290b367a83dc0823d3c2f6fcb4395f31f17a8d6398ca69d86ca5a7499563e2221be77b3fc34cf55d00b963f6aa59bcf1c9db2e6c22e237da8c8e3d4a07d0cad3daf372004975815d6c1ba39bbc8bbcab08c8214e8f7ca49e9a61000465b6a8c6c28158fe56eca96f36d91d179bc735bceae6db80b2b80c913c73236a5a86e52771d4234e6b469386f0431a7b410e3234aa37e0fb7012794e1ad91ae71704d08b05f630ffe0a151460626a2e53920e95084491fada68da78993741ebcdc9c03784e252ba275abe95c2e3985187693b0e7857e90931d5ba4bde3917aa2b37855ca7bc2644e9e3160ecc7b97a9a4f976f0f260d9bb9f322607040202cf80e887e028a6850b58efbe80401a70e468f451a5178fba7843af75a76a65780f609931d08325d9e10bc7c83733c39d74363a385334be4570a078f4b04a6579582b42b8318ad032a028680f1214c0379cddd9e32c3002b33da70a8433a504262f39835196753cca67473b71bee27afa076a448ec9885b5a19f343a8d9933e59310150b02d98fcb52447fbca825988e4f9628a84821ceed64d1b29dd8490e1ee5e17b3853b26556e6b5ec5b23d0679de434490e8c7513f47736a4ae033327029f7a20391d270ae81594490436d478d04313c88eec1130353d1a4936c24946d94e1b835969530a5630b8c5735a70bb979c6a701ba28fb74dc40f510ea51d0f50b7e32bf6add125a2c81ecc49d899c7105e6aa9a68d9d17aaea397090a14146a4844b164044147ff8931d275ff367825856ac0a14c303d871c70acce19d7a81daf05bb12cfd927d5955cff2b2978157fefcc52bc69a1cd46998569d07f42a86b376118cc7c3d1d3a738e1ff05a2cbe98545af2a4793c2613321511c72b59b0566f1ca8d51a8b403cbc625aee42fc157fff459f1f069e561298a451bced4f687fc5c59b0e82c25f7865d1259a6aefa8cd8f01509c01dd8b432b23254rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.7+git.376.dd43aca9ab2-150300.3.32.1.src.rpmsamba-dsdb-modulessamba-dsdb-modules(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfiglibMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.7_GIT.376.DD43ACA9AB2150300.3.32.1_SUSE_OS15.0_S390X)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.23.0.4-14.6.0-14.0-15.2-14.15.7+git.376.dd43aca9ab24.14.3bascabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigs390zl37 1652865052  !"#$%&'()*+,-4.15.7+git.376.dd43aca9ab2-150300.3.32.14.15.7+git.376.dd43aca9ab2-150300.3.32.1acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:24194/SUSE_SLE-15-SP3_Update/c0ea892337fc5048773e39b4fa88f344-samba.SUSE_SLE-15-SP3_Updatecpioxz5s390x-suse-linux  !"#$%&'()*+,ELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=de415211abed5d33828ccce04b70c0cc704f84e8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=bf9b9cea810071c30a8d71258335a98bf50e4a45, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=cdbe897cc9a7941bc47e7910241977c1735ca617, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=66315ec1271e6f23f7f60ac40ad495f03ceceec7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2166f90fff2f5be720bb6972ba51a96026900fb7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=be19e9dd2338262d6c86cdc255f45e887a69c893, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=32f9c7bd9c6eea863083cb1e0a579077985e0774, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=92d3da0b27bbc7cc83b19a720f45d9f31d391736, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=59dcc7bc6fb300380ad4204a4b906aaf808d0ed0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e6365b7accc3f9dc70b7dae5139908e9c7462bc5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1084527b9bbeb2f9243352a80b8b1dc38020757e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=896a3ac5ce894783ba8527281b2304d8071f457d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6beb7f0b4b286c2465576b09fa0a659cd280ed6d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=25d7ac9f483b64fdc0e75bd9439f2e7ca26c75e5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=65730ed7106fd46a13d6cd202df622d554bc26aa, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=188ea8108313b8d524078d6b88e4c6741603ba17, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=38cd6c8b5de2be55b3fce18b699be7f78ada7e76, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7733acd484145a5946d22967ebb0d3dacaa6455a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=097fe3de638fa45f0d1d03c8f6dad426b3966108, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f1c7c511f671f28d3b5ec0863e00df30b22093a0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=0ddf69b6d60746d0752e287bb9521704c3b8e36a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4042dbbc070129e7f27ed4c9b45954260dc02438, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=94620c8f622cff59965c3f56e83382e81b7db02f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f358087ca7046a42e9d3634ffe8865b2b644f77a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1e2f3b2be8f3f9c6c2063f06b615a2697c38843e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2c3a49416d207115cc39692bef24efc08c35b4d3, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b73470cf074a7577cf7235a539492be01d9cca90, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4ad050040d05a8dad4d5597162411848f0301d25, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9b66b498593185cabc325b2b2753ac8195bcc615, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8948f1d65fd3c5dcff844af8904ea089b8d0c4d3, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=cc0c3887a45984dd972c11dbab639839e64ceca1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1f75173887d71cf379866fda8bb8c6691fdc2ef6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d38e0bcf21e19a4e0ac69a6ff97fb47ee38ba2a6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ae84bddee6ee66245c2049de1f4193a390104f21, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=53c3967e9285e8ba908f02478632dd415534e6ad, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8940ed53554b289e4e22c8b37b5ee61d717a43db, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=bcec2ce022745f4e59128070345d9b62af49fad3, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4439de14ac671bdb362ffb30590f4178e30dc16c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8c15be5cce3d00035676c998f71f803b803692b7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=52bc78b3c856eb20b7e98d30c8de6825c65b886a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e520e6b4f6eaa3d805bbb5b0a3f76aa987637989, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f90eed86ba57d86f56d54aec31d1effc7f7a5ebb, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ef676b668e396cd6ee6f63b551639f30439c8028, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b2b04aa4656ee2141513fb17e14e5ce6eb61878f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=0b792087b375dbf72ef051b76c52541fba48b48a, stripped7Daq5?G]izAMz  *;K\i    7 % - !  RRVR\R,RRR^RdR?R R RER*RR0R.RR[R+RDR]RQRR>RUR)RcR-RRXR?RERVR\R^RRRdR R RR1R6R7R0R.RRWRDR]R>RUR[RQRcR-RR?RdR\R7R.R0R R R[R>RcR-RRR\RZRVR R RRERFRTRRRdRXR0R.RRRYRQR[RDRWRRSRURRcR-RRfRVRdRhRRR0R.R R RURQReRgRcR-RR?R\R R RERFR^RRRRdRXR/R5R0R.RDRRWR[R]R>RQRcR-RR\RRARRRdR R RER6R0R.R?R^RRDR]R>R@R[RQRcR-RRVR?RHRkRRCRmRTRRRRdR R R0R.RRRRBRDRRjRURSR>RQRlRcR-RR^R\RdRR R R0R.RR]R[RcR-RRERLRNRR%RARdR R R\R0R.RR[RMRDR@RKRcR-R$RR^R?RRdR R R7R4R0R1R.RR]R>RcR-RR\RER?RRdR^R R R7R0R.RDRR[R]R>RcR-RR\RdRR?RXR R R4R0R1R.R^RR[RWR]R>RcR-RR\RRVRZR R RRRRdR^RXR0R.RRRYRQR]R[RWRRURRcR-RR^RR R R0R.RR]R-RRR R R0R.RR-RR\RER?RRRdRR R R;R3R0R.R^RRDR]R>R[RQRcR-RRdR^RRR R R0R.R]RQRcR-RRdR?RR\R^R R R0R1R.RR[R]R>RcR-RRdR\RR R R0R1R.R?RR[R>RcR-RRERdR^RR.R0R R RDRR]RcR-RR?RERARTRRRRXR R RdR\R^R0R.RR]R[RDRWR@RQR>RSRcR-RRFRERdR R R0R3R.RDRcR-RRLRfRVR?RRRdR R R RiRhR\RRRUR[ReRQRKRcRgR-RRRRRRNRRRRXRTRRVR*R R R RoRERLR,R^R%R#RARdR0R.R(R'R\RRR@RMRRDRRSR+RURWRR]R[RQR"RnR$R)RRKR&RRcR-RRdR R R R0R.RcRKR-RRXRVRNRARTRRRR R RdR\R3R;R4R/R9R0R.RGRFRER?R^RDRRWR@RMRSR[R]R>RURQRcR-RR\R?RdR.R0R R R[R>RcR-RR?RZRRkRCR\RmRRTRRRXRdRR R RHRERVRR^RR1R8R0R.RRRBRWRDR[R]RRYRjRURRSR R>RQRlRcR-RRXRdRERbR\R3R.R R RDRWRaR[RcR-RRdR^RRVR.R0R R RR]RURcR-RRdR?RR\R R R:R.R0R2RR[R>RcR-RRdR R R0R.R2RcR-RKRR#RLRERVRR!RRRdR R RR\RXR1R0R.R^R?RRDRWR]R>RUR[RR RQR"RKRcR-RR^RRRTRdR R R0R.R?R]R>RSRQRcR-RRVRfR R R?R\RRRRdRhR0R:R.RR>RUR[ReRQRcRgR-RRRdR^R`R.R0R R RRR_RR]RcR-RRdR\RR R R0R.RR[RcR-RRdRR R R0R.RRcR-RRdRR R R0R.RRcR-RR!RdR?RR^R R R/R0R.RR]R R>RcR-RR\RdRXRR^R R R0R.RR]RWR[RcR-RRdRRR\R.R0R R RPRRR[RORRcR-RRFR^RdR R R0R3R.R]RDRcR-RRVRdR.RJR R RIRURcR-R_~Qx!;utf-8a0d80e238f4a8d52c372ef8290d8da96098720d661c5a939c1d32f94e0aa37a4?7zXZ !t/䶳] crv9w!Ji@h@=tМ^T\U~a^ ѣڗ!aF'A$g#*Yq}vVl֢ڶVeqű^C?jJ ںjjC>6zbS< ^?45ki3旰;<;ݮeb.Qa]ꌥpAa .f{TU#: eQ=d eUq[>G`kD>o8# $"8r臤$kK9PKRUĽ6L:Dz JW3h̼j d~^ƽɢBk ߟ=ƷjaY={`VZo0%'8iCuXfDD$UX>֧B7te;D'J}3}3^'i-Z}-!lp64:鷮9`%uc/Z@-+ȗN t`6._+(-(㐐͑8;\Ɛٽ-P_Mi*N$H=Ruj*YOr:2yo a!u"N<WK O=uS]=߭*rm23vz$fĞ+Q9VU^Ka h51}C8RBу7S6;HqhT/{ EY缡~̖+ى^:T2((N deS7X6++Oxh6KFp|e4P^әEI8L `#s=yX> .*6f*iAE(wU>q }\m'ja˚- {ڴ$@%D4Wv~avu_-^BK,yvv!Jv㕆E-傺gMӜHOfA(K-+qCie4}Fhlˈ0'wYטed~)D, |$:  ѡ \:6mjGgo"65ԏ1WwUEU2(;`^_*

7.ChkQ UV}tpcY#c~QHݓWtʇkZ.vsgHiۧjDK_R Pq|fPV(S밿! :@} 았vR`g՟X1-Atk76[Fsԧi+!=(\'~+De%dܧOşle %)K_A✺Я[s;xB,A'*R$fZV)utqo',|SRKU Yq.FP+2)lsp:H, e x/oSu·߂d P❯ă=5$-ibOX:/ C7*x# ;I"~2 iUޖ/d{M4CD*| ͅ(IRGWb3oD$F ʑ&7PD .~sIS%Fj|l|-񦒤-.M%:+d8EPh#IYM9twk '&Ѳ1Mu"wffh'K$Kl-ͅtȣgR"@'e+Ɂ&Df ԥ{ι> ݭښ6L>7%͋08Ͱ+I|%iupdċ|z{"hZ@6kNI`($&ߔW؜ԊdH,{SXoIۭgkN'fAlJ'k{Wd'yFe(F'Tގ*]e H7o\1Yk0x ͘+@H[}8ffgTI,҆w6TB*DQr3 m$XdL?"pBHKݟ&6G$Qe76YOHǵD!odr@ :UxU}NrZLbUUnTpjۃf&pdſ ofd65ז/{+ÐZ-E+et:"-Z街)/BeU{:wa#{M{;}͈\Y4(Ӱ6A^xr|br1 rUVvNnUXGŠa!ޟBL6| H"`kL J{4`mw?F2/}zF֐t&쵽_x*0u`?6 1L VN S|ANuA1m.ڃ23-CINcxTLPS-| Q饣\יʐYYk̭q5n|3Q2N;˼b߰{qmA'T.&y lmW8 [ 틯;63S|zTBv}"bu` rQ@ 8P9OЕπ㲵y#z9\x(^2O492iiGq)>\>@RǸ͞ B2;N㤿4 N l>i v90vH2NZn!s.tmה;M60)r'65tU%ؒGFBRM ]Ϫu`G͘-qiJ?PD|4Cj|޿g~MqϪg<5\1FMy"L~I`<5EKP܁,@jeJ_Bq&OY}( 2.yAi54v cu ]df?MY:|[R8v?Tv/{z_x(|\na!N\ID\UlX-AЂ`= "}oewn-&^ˈsGmRFk %B޺DQ{ae7<¥V" uiN>'^+84yO&j{TNY9ap]Jdݥ s}v\|8[uF0n2hҖ/qg CÊB_7tQK_l]2.8y-x?*Ҩ:,2q0R$-HrfHIu)c'B CbI@Zq{aB~g~_Yʉu*t; !+{P"X0`QrYt#0PBMz [# TH8<"Щ@5o\l *Q ;614.2;EJ\yIjP([S|o`[p]^$EA'H4tFVȲ/)0(kO.AH24[𚚫`ܛ)KaJtVo)< 7ϲczć"Kj%1)% FZ:=qAH,|}t&&1mP)aѮ\SP8bP[J"wOzRNv{ hmY+'L 阆Ҩ)nVK8#k${횪8~"K0S-2Kga[4'PV(]՛©5?#~ӑҦĢ)52ۏd,PIq>OuNE\46BLG}3`@D].hXd('S2?crx[}:*\ *}2 5Gj czmV`)9YG@8mn">{hF*'۟o}`@Fwr7Y|V~/֌,H/s7k,a -XM;QM`b+ G JIgwo 58yxe[H [j{cs3v j3C1;͂-؇cY5:6X0 G+nQY߯ǿ%Z Y*cO1-4*@G2!<)"nӧ4gy 75fla՛M>lrK]E2?lFI8}UM#}svۉR6Ha \Y{[k \̒(8-6^fK ?G$oĮDpD-"Љ;z.$/΢r٪1(,y5J": 3A( u<9HӦ6[O{'}7,%N^Y`_.擱0=?2 2a=csEM HzL83~#g[ơ7fihZ *ckEGyynƅKP+;V{[G*c"La\vgPC{1#xUBK}AGCrqG^mz;v!XwO!(@o@'$g^Ggm3U}ݸJbZv~ICLaڬZ'E9K/62@%`wїL_,2Sz! l> er7&yl3eSfW Ut1SIadg^Mشci?SRyVX`38˟.n)e"95|**o?wb "a ZyٺwW<;|"ܟdc^P-tΙ#GSE/C{+=[ߘI`)c-K`er5K U#/E;$j!4Pll19&EErQ݋U_I5fz\dm;v^ >3 7_3)dDQ&xE B7=G=%yDg!% /f=L **jLcw;W!2j͇55s_fm{YW*JZv?^{?b"@9Ãp-pY^GEIwRa O,7z&߫tcF9r+QKK{] :8䝁$"$U?mtKwewyaGކ 7.CEQ|}8[RPU7yt^E̿axepvP~%7[Y 9hQO'i{Dss{ɻzug{noeW]Yz!?<V0~hm/6= tB(ǭIJ:/g@㌐ԍP%~}Zes䘖I*`{=D vUrKkZ=j]&*>OC9#6v~?dS10A|}/&e )t/@]ǐ{{C}ipۊzDp0AG=(l"26ߠ pFf*:lx壝D;%oU/gA6޶qQ4[5U;\\ArM b tm"6u9e9l",?1]guFY ف}-'Es}*Of1ޔ/k ]W}}zx"2 2}a4|*r䆹/>!Xe㙴 B۬ fmC^:#d c%^ӢF_DŽx Xgm{;_ @k'+ƝUqL+x!gOLȪ&5+,M>˓xhJFH{0:n|V|;ۡ)2Heo<_D |{nqjCULERaegfv gX6盚YdMBEw{0e ry4(4g8M|k<6<_vB̕Z ]I[_n)gAJ:ؙHP.;NB&__{2l\zG3T4[W~pϿX{xI7{|>"Gm9CyM1)E2Jc^ (ó7Z4僾uiPƾgDEM`eoΌ~9NۇI TdׯA[/賎gTnjĒOWzYƶxosN<>^%)׿֛2ɿzwn^YW ![%ܾAex'-ƥB%yvY#|Ma&ΦVAnxjIs ߂M׃OL1!)Z> }6/Xюeyߜ-nn}Ig_| u!ׁ5%~%X@j2"\Q%Lѻ3'HU3,-VW_f&E* E55a˸3nE8]bu-^?~?d0*xȶtIEץ.{q<8:)O'צ}}@'w2>W0y~M1PLFn}fB( *iG=XwOq6ģ a}0\3[z(N#Iy2oY#YjoJy:1hX4\W5^OLJq=z%?lTQV ;풮/lfOtx=/a-!B” @EuSDV`~3IPdH7&y+dAEHsq`Sjt_ ?jƧ +N[r4x)41-F1x8*#sRHsH ?88@ja @zg%\ = H}'w$Z+Su{0+G cx/MB6Km<ͬD_;ڟXTl-/a)g4m}: UkI`V2pP¬Wsbt =g=#PC 734LJ+0xV~uΟ4Srz¾3ֳ:qX|&w/R#ŌF'2z#}8żf&U}@}uȷ'iFBUG/Po5}ح>Z̞15\(TˌL[h^뭫$K18kP\Y-sˈ|;@D{x=:d&O1ڥ pLzs(tO%80A$q;(NӺ"͝.b"2귲 <ɵjosIPQ] ~5#=aƾqN;pi.7Җ5)F̞\,24ʟ瓵qh<,GWsĘXd=T %k4Gip)iZ{Sq/#NZ$́lYZ8z8wO.@cXj\ˆcqF2mX&}%yy޹~sA-E`g"78 '10cWH9- 3k12Ag xHQ,h,-J5L8yt"*Ef.Jfj,Ꞌ6U(GcG5&P٭{Uo"R;þ {@cZ=hy0ӈJNlŗnin8#m06ۚ|τbP5,E̟b8Ɍ3ϞY;=((\\:ucOVG7)K*tD{!S$ajӇ\eât"R+$VT7R^x W3"u6':mPնrH0lhF6=J@t$5_Q7Wz0.r 'pK{Oھk+q0oqH})G*ЁXe%5s8-Bc]p,޵IVت!; 2 jM''; eu"p&@Mc5 Ҹ<iC\I> &jW`%0?yBw|\m"j)}җRtMwWV[,yf!?}[M0֮m2BL^rl[Qam̢Ӻ:D'.Kf*eGBHunݬۖVR] 1j+Mژjxʁ.k񻑹 {#oMlnbN6gtt@p(N fVA8f@Ppv/BF*J܉ajG:r3y=s3G*'A/j=O[wdc#y#yDcIz /a2H:{^!:" ˞9?0 nqZ z'JʐVb4Ђ7 OF.-[sE&Z[0ά|XkU&r1ʪMqpS^FϖL+Z̡w~;stMoi^Uz+SmFwo*\9",bgxW(_w\[ bM=Um wJb XUH3^M<ߦn@y2䎝euE=k` ae-UZZC8c`/WF1)Aȗߔj _-pF(ETuVh4X72==c5;3JҺ<2qIw^+uY:ܿO6¾f= М{vއ#r<DZ\q@D\g@],(V10q.N\μ)maD*I00~Zm(W*xdHtq.[F&:Kpf!) T4]QQVM!vlvv u|G(s-Gas(b|Mu{R`r0JO0{:ξ` - ͨG6z p)mla5"<,K-vxfM0.<iIw~Z}S]MAFeT3>ld10 2Bce sJ:O0OxJ!Ywƶ\gQ"O>hfPs}`kdٜC6/Ή #yh_&˜ñ42GF>IʤMHTiFB1XQtR xgJyAl|()rw˜ABl^:5LvQ܃_Ɯtv?\THYt6=קSmiKE 5U]%\8v8NqgO/`Qr_@2{%si侴u*Zq]kf գ.p_c#`bM=B107Z)x*VG9ڶ.r\5W:2UNu! H\Z)>9IĪ܎nsNܢd-6^RQPh=X~\NJ%)% Rk2{d Uj69SSȹi}: %(Ԛ fTH ziO=A;$P6c~OgUmp96:&swÀTKbN8?OD̑ٷiBٖ$Ւ4&2_5(d,_ɏ791dDr'RkQi6_ciǷ[欠 UԳ82 蠡!,-`0dxbSd;jMmx]W\ym0BAl2F M'c|{OGHuX+Ŕf%m!zl2s& )I¸="pҴ<CBwLpkxcC<v? F"2bxn딢Ċ1(ݫ#h'GS(MV.]|n(aWK6&XL [L<<(I"[́9d](gfEes\hr_?j9sz_^yZ9,%~va~Ԕޮ 癦`dÕЦ| ᧥F?&8Ȋ;?obu'pyOMl۸ =x="a)Ґ|*Fy\S0UAwI[ǚnI;"9&l!~rn(PIF6wgȇ~.C%NptdI37x|.&kBRZϑ.zosT"0|f I'Xݿ_TsӦ4FI"k| jh"TFuֱqxȮm~tJmsvWek Us?ӕ[([$x')ĸ[y\d%,Cфv4f$>8-jV i,\AJ| M`T9bnGpacɭ0܋d_+$?tDVqUfІBUF̄>HvX9B&*.\Iq$F,RY7o0FΈN;9$xG^t>0˺ZZkSi+Jhv.ʿmSE;r+/FO `GVXlz@V >[v9fߠ͎= &]< H]:7U{9Yu`]2r-ܷlܣw]_Y Of7E@-BsUxmYeh;_"C,ФyaȯFe]^NM3˩{L/`]/ 8?NׂDҁrPq%RDi/PDcGT6uI'?o*7 5m' Z-i1@l)q.6! *V E?)':41S~d Q^4NBUT9O /,E{lN#)qDXfv+ 9}4p;s9BN&/] d03MBTn-Ǣ.623k1$&'BR!kYRA)l#EWPFP[Ct2ntrrF!:lHmqH712Tz@ISЮ /)TĮ;I+:KJ1O wAn>@DОΥTck $|*Vu8DpEJ膺5y8;"&{_$EtӭHIG~s''}>ucӻ*s֫9!\YQ8%Q6U^k)'Є)pZb, E3c _~H8!aI`rۧNuQjwrw#/[#R/qfXG5 #E% Ry\3ݗ&qpW[oFm'\jcEmw.q{6zE{rU&XC1J PbMmيn΋9%ljq?!ާ!Y0* Y["T \[[蜒d[+r@jI<kJwpyhsQ| O ECX,f¼"yux3@&5ҏgq /3xiA5ͼԬ>!0Q׽V:v'+8CW4v|@E6u@bb͡7K YPJ "Gt?v":ϫUkTcUj ^e#V}H%IP^ܴ~sAaD}Mt֍ }nH5Ph[N 0Q̛yaq\ Eǜ2%篷  s2IM2-Ju _ш5.1)d.y&Wji*fZJ!Qz WpS`|AT ̣M3;.&0C_jRp@Jܧ7Ӥ%Z;n! d*3I]]w^oaiL=7R)tv67xSbm+xmaLNW_Y3PEe w9[Fy4tsX4B(.m|T2PAi:m1w~;&LXTnU%|XyON;8;qXxrKI.'ژU)!rQ\P0c-Jr2_XczN!N"񊑻Xم)a6ȄXpߍ:~+Z 7!-UT0 - _q;U|(Vb,GlĹ*y,Z#dvೝ*c|+rTˊ1PZVssYCJ%mK`Ԡ6Ƒ{hgc}ː0inUa Uӵm߬Qx̶Չ-^&j v$.[:+eٸE@!/}fζ+?7W%x J(u {X,^&K дPv kwMwU@.LE# h <č"@;c]`'1 l0e.~I`5VgT(1>)hf&:] ofJZ=.,/D:y盛)ϊA СϽ_%ZFgӁ|L(ae%z& q-( ,}++(';6rҝ]P+t~ЮY{ՙrY`z .e'tJ#6kYE]"GzD&˿=PžĶL\ɡ(9iՈ|)(؞e8A=C|ȋ}{=3 .0m⛰+ox/u@<7&X1fCHQƺ<8Kf! ͇؜ML SftT2xIL _]HZhBLMU/Z" i1y>-Hxw]KV/uUM9dʅh$6`G:V=IߪHwH`R OD٠+.[i^݄F hfwQvayĸEFN0Ap`KmonlE+a[a}p)yԳl Z3ጦcB=F-|hZIWX*=bk\O}f\(oo;}8 zG?mƧqY9?JX3lVT2(`뒺ʭ P2^hi+% OH7 9O PY)۵] dg%brw+̀.MZ!mAkR~vr!uSJȣ)O ע<q#~\1232T(۔AvF7PSDtGJ)ȓz\,NO>4+#,dP}8P"W㇯}ֆ@JV JRŜ ˫cyU[YR:u [l/qk퍡 v*0¸:fQ#,h Td̾H(Q.+؞CG 朘+3^/ _ljNbIb˧i8aRŽq'Ǜi j@;X~j }ѲM/h?3(TJÑx`Bc9, Cpps|2*x~p%upeQsyBkRgP@@^vpr] 5;K qb)[֖E\eGbPW,,igE;_!xnC%h]J+F7;'?t")_ϖk(J;pppm`zQPܾoG rK9f-e4JN&#QMSqvU grD)jg >M3*M#gǼZl^,P.[Xt22>m8 B߮s3ό'*U>`!P_)iy=y͸AiDN-8+.Zo}B<)ﳁC樣ԻY\g[\œeI8 ݅XT i= Q+qj;+DˋKN*\DZRE1W?r-JJZ]%O6]BDU/Ļ[ ]qR]Le 9F"2 xHA"=q~dx)xDcWp T"#aP&wrioPgIثm, HܜAՒ1<!0]c, ⣻.;ḂvLn^VE5yeS@Qê] Qd^yJTQqƒ @I!>sY_HEJy-r]m<ꅼheQ 1TӐΩ3dL=e~]V=ݫ4tZ=S `+"?lC k3CѼ6\Yu*{Hi.Ȕ6v< Du)0SE~!!":?e4$Y,:ۉs/Κo0矠)y^1yJ[[V&JȑkӱRuN*o^G_ _fq%Ӭ7s!mGuY (If<_K'u\ӳ%dT@;#ͧ {=]!rݏsvq>x;HQ 8#gc,_[dS(ѹS ,BC O~nnIIMFh%W4ukr{Mcp=Hdq+ R{O/RJm6V% S/Sۉ ܟZwXzC3\w:ASϦ\,B>J41Lj؝B_E<ɞ;{9ۣ#l\"s MfIyգrs-9q.iT%O<UAT=ؖ]@ U)J"_Ԭ^[b~>K l yv- xH-}3F3/g2C+c0[FͅʃSw79YLٺ9 91g'!rE0[<2?oY_E `.e@byV$J׃Ͷ}q? e:hMHc4?4!.pF~I'~8Ea7Fc  \qZr2t?znJ5]kmgǴR g6/ZɧZpO8]n>z1LȀ.#cB83N5wgnӍ#Vb3Xk`4BQP'OѿҾwy03h*V4![qqXf DᑱWu`RchjD6|1syI`跽q`+Rw)[B$^nVL(0AIB.Kyyh?m,,ȁ;D[.:f?`ve .6E@ NGN8YqI<l@jm ۹@K4@[̈٧e ߤ,)I3Ee%oOF4TQ%dOF5@OKs飧7dy~BHH=+`@$l'P?^CDY~Av ~bI!Dt14 IhZSȝ :O] ͂(vY!<2lnP84JHc7f!n po߬:P{x_X"fJzTmuxTjzEԡN8- d'-ѤAJ$6XL/p$zm!kWɊ֘Ns4 =Չ,p?1_%fJi"P]䰗KO5\!>gpVIu ʜ>v̉fR\Es8c$/,K+wk8@.$ր TlXM 43'Mj_YY'2e=o@6(?0\a)0gDV$e-i]-!6M9@}{lj)xniAtlMC Ip|^d!H=YqZڎb掭(fX8ճHS;)n1עx⢀{0e:Ȅ5 a7}!>th?WqwcX4h1.1+1f9f~z{~oD_7?}z58y+sTrR^ܩyhrtͺpT ^͵)%B#`9{NYDiJo9/AW_ Ƌ6cR qLR(lr"#FAZ3[}׌@e^id f>gBQM%XNcm67 4(쀐# s\4nʭ˱mӸ@ PQIy" 7`r(U&4G/FL/3ye+\B;y;#&3O߯-eE°sճtk |)HxʉvjLV&&> _ӷ3, `"BOaI䷉b3 >b^Kșf5VӰQ_+R\Y1*ѷbY%.hl1'_å2]qhb80*7%B(vߚL%[M$_6ElPya*lɚrl+^]:hT ~0˓YAq`ςsXS=f/`d0``+Q1Xs"v/÷Ɛ hîZ|7qk gPQ)5"Y!s7FPHJj\=B7&<>L\ʿbe(7~FzJn;֖nbEn~:,tʱsC٢GR$>$t2!wQNp:3s%l~.]IpN V XQS=|X~3syayR佄]岀\o™1H$8ɍڳğ6X#d/b|blɯ]J{߉$[ĈQv|h|a$V65CEz5icR&  8Baˡ 8X%n_.9Hpf,qi[M9_@ 72wC6t0{,[j͊K53lG6h"];U\JIJFP5lkg'NSHw_#ætq8`/â>''49SDJֳ`> nHŏЌ ^Y؛/B٫h& E,~$T,kP͔J)PpH^r8ߕq\X?( t235 Pm?r,mP>9+0I@Q#UlF:e.vUb9< aDr1  }<;8;BV oj~36|;;׻AO8ǿ6imxvQho+ɑ=>un-ijU.f N $"9-tCI*X]-hy_ooc1h!L &!# TO~pj'aH3cW'(v3%tiCmڮ2Z)_i5ȤfC.uBN{큯Ӯ2Xfe%Jڃ$dj _Byq[/>`CƋ4Gp+X]W_& k#&^* abhtWMumU8j/C} x͈%lh#}c`۳-o{ʘm ktj#ɑ7pSjUHcq%C/*oxR 6){֩.Sԃ<4]pG,)Š*[ UoV_w=˗ē$;HUb#Q`m^9nj iRI]iep9 t(kq)+/OQg4K.TqL\78 rtg^];3{SeU k-f[3.q.b+e%E3[ 5?Ȱ] d48ε]d_ Xќgbkz[?S,и>Va9ŽԸLų;Q='L̳W:1٤B<{_ֽh"ۧS%'SWrSǛhNjl3Dq|sJ`:Av4?J$6YC]JB9QRhlPFPHMܲQ3~ aKRCۏμ(9![<%doJ]lrϮd:"JĺPvsCd@]<nkvLB*zJ"~n{`p罅Ψy`7KS}H/E2;b> iߣ|lF4S ?E5B `{sYމ琢AGƌQ;´RpΪ^fS$d4G6 a{{_;0oHoΜ i}H\/&0rkphݖP)Dng&`?iD.y䡩Q*RhoF3gƨ 2:}_b'WeaYWُSKiyW'x9Qr: g(-&v9с{\{b<8B 8$¾V^=+Iҋa~QFTRxv&Ωn*rsD;HCM viՋ>ZͿxϏ~|1%r_:Iv_⾗]`\gzUTd{7T 0?ݛHz-:Q:-.M2pGm'9YרՏE3jo2<hOBo~&WSJR(pOӬw={@E^(Kx"ƚEjXQdϫgyJBkT#&_r73obh{^ zНjs5/XΓɤJnN3 ^?[DmF㕂{J,? /b'r"`3fkDVYWDHX<6{gucGR5'8V8%奨 SHMm v"4/ ߨn*j#NGn2diY|dҀ EA{AjP43RYUV9Xn5`bnsI[LOF$ bGf.[HZdB=y6̈́l!w-xm۠RF`)O"͹@X eb͗n㫼AV4wΐϊ=2+ Z-v3.~MLaJ;!AFBe} u&Z X% uO:bD|y3Ӕx L!CCzp%*}Xģ/ ve7Wehq@B :VlIBx3iV1)6ڌ9;+e̤M/9j'6[ϗBN%b@N,jg7]HrH>24,V6/sv "Jkm7؋M'UR~K]V$qc7,mÖ8:05^y)ObGbXn>8g/y=[?F+ V}()U@%CFZkH,`Q]!֖hQo]y`-LsQ:9s@ŤF=\y`(li3 4 O#7Mm}!zb)h를t0BCړ IrF; Ci%ӣUe`l6]szR]1O΃y6;CacB@o,[-cٵǩ|J 0j ;w\naɰ2.".̔!3lSIR0+ʕL Ďwww@>h)@ܾׅΊu x ZS= rNh^6M[ ztҦ=M`1JIJz?㥨Ušm+6۲TԮnb4%ytXD5;1h欥Hj(5羘nN\cV yqcXwڨl2M#g_= 섀?Db"&I,ilړ+IcEό1 CaF\%X>Eodΰ7Z8nB0/FثM)=tlr^J(GSYoxtubя5RcѶ8j^:j`i ]R@&"'+_F,/q.j*XX<^%צqzvR#IBN j#i"%c4FDـ8s+֢G_t%r [_UoX`63p>##Ay\ h#ȣ'$ &uFX]X;GuA0z)ѴȘ5gq$8aLb.h˫J^^$ b؀8ñD[&}|~6=VɚcblN`K2~_n)\-[û}1 :TS; L{ vP0FIzzKcfG\Q[ClB#}gOkT@"M3)$**HiPAu(}Fɠ 6xta'=;(q#/5> ֟Bl6λǝB |y3 8?2m s3k~f DX`{2E0W;^)q.!Nq0C*m:!`hn3Ts[$d]0`// RNQXvhkumF54] {ftޓT?\,B.\ip,ކF1 츿 fRչtԏ\p u0BB3|f,ڇf Ol Ț E]Ԇ+,ZءnWRů-j6t盰{I4U왏y񸃵VD/4`(Z\:Q"/hXb4;j\KS<OͲ)%C][>b)c2}]=hЂ̫S;|F.t^+ 1]p-;.LOmr' G9tMt>r@a48xJU#g\P!BZ%,,SϾ1ccV7J0 Q֎ (~NoE{rI:!~J,-M^}qWr3d-¤PϦxt dY2"Q83& gR(]21BJ)d`ayMֳ00n)ǩ0Ϛp'Bخ `O΋_7t7,QR2 ;wͽsE~918zQ< z+0 /x2O[Fz_P%[9BgRg_6I.8˯، 2*ӟ7#컵Ffn,?Z0k\DNPdSt2kUi[_: "2CJo;8) 4'PD0o~V6&n|'Vᵅ1jg"wtH0cd_]SnF˶Խ<wjzR4=4TjmF` #G(Z({׍8sg> _@"l8,c&TIA% zYT`09Evvzg~Ğ-*چpw2z^[v b17qfxnEEd5$}BuIt^I`u$PNC km&uBi}5 vKR,(%Bߵ"qCe"n\V(kH>ul-z,Fe2Vz R%N.xiu&^ ޜcm6AD$q=$t=UY\3 8-êL҃ɠ$oٿ}p6e_!:AaDP(lK 0i&Aw䫠)S&cd'_yrdd .kHh<4/{WuZ}|G0i'&)EOZ>U!9 )XѾ<(yUs";dώ_Wk1k#+l*6wϫԩ&@QT5hQq AHm {){#vAeڜz!ΨC|ZiG/LT?z}B4b *tf@bovخFqy*KK40ɬxnd{K45"l G,'hzAꍕEȫpIם+2êެ-P_AakUz堲 #j_D#Uf>X/12O2Ɯމѳ祝 VSGND@:RDJ+37AyǩJGaI)HF,kVLZMJ @*M.}$+\ GTkNAWuH  χzy#Uio=dma^j,5ަ֑v^`J2 =u>>Vj Ҹl}P R>סƺ9hgqiԫljL? M+ }+oM8'Bc}Vv{^ٞ,78dOC} EHr^'i~7JRS0)L1,Qِ%f17$vQ͈!HuH| yp(5ĸ td9rcWXH;FS1/-:Ml (D'j&:H {hШy;ͳNpCYZ@Vyj WT/ Fw;cZgtw>`PGP6d{ (xy$yNB~tؑhR=YV񞟧I=jXm08fd*&g8!2]V'e鶪4h/pGlGeL99"£&yk7Vc Fh :wSwe~} +)Zbb~A >MZÞG:HmekcZ :u]Vw'=t|+ ІQ|ӗ抲kj?uFQT9] ByM+|޵MlAx|^f+i_f]fO}~0(*oRҿt ISA%<쪷~ H<:Hi $R$x8B14 j8*x}2)_J]Z)h\@|w]QTJWwUUb (, .Fgc;0.r'~:O@fUP /f횅WCv@0pe%*k4^<ޝYKI0o5vުlE4>_N1Wî Ӻzn+z;uX\b~ٙp|LZvfWK4hx/u\%`b}Z@`cc+ Ō-Tދg ]- WiJoVq 88r#ipW+ߌ[JbXn&8Ϗ y^OYo?> tܟGGYohPW0Xe"jk 7tW5z4=GO Db+\GCT.VзR Τ'=F[AyXz!]ޖgKv@hQ˗`Pg]ORkUAԙ5-f# @C+Ekcxkϣ e<Ӗ7ӲN3W@Z'47=eHFɿǫBY]RW,>S#+f2njqQynaqQ]x{hW sEG <0%!&X%Gf /{utRX0~??ت1!Fs#w'@y$Ud=x@dHrh[Y1EMbu<6\:ԒUY1&/]x|^i="Q[l:#sQ`H{*MOR}6(waVr%_×\pbĔ"=UCEOKԧ Ljo?dbŇև' Q*RiϻW^db7֮O9ۓxrNE.Qm읐2g}IE*8!#6j4b|)#JXEijud`ُx μ_^뇨#k9gx \tP48De yyҐ[XBc" \X 3Dևo=gr!~"i]"5D:,CxI 6 iw׳--5f++oU}n|= $$\#) ;fRZ/>SkE-?c0A@=J싁y &nMP>TKL_̈́4t5=EnΩ%VX;4Zb#lX$T -ؐ?;]~},sP/)bR+] ~ ?LFON\؉H({;BP<Wp,aJ"< ߌ-d <*;nPŹ4vJb @- $~,Iõ84,?Y^mO͕c7iPҭfGأ^9e8<% 9Yw{'2x5 ٓ{#9h_'A4$mF36kϣӥ߼żn~%+8b^M5(/pAOe)\_-+Ļ1J$p7mZj3vͤ~hlVm 5.QjJ QʵkOA^G(GJ-\pa^+$4]R/{8or MbsS^6t(@_5<-WO|H[ӆ:j9o0MP LpG1p4r Zb&Sb%=]jQjIIKc_Z.I׮j FbHoA&4f! )5*d{H:FշȓѦ&"#?WUKك;h`h*D%+*>헲(wLNYr[9d<Ԧ5a B.NĨX60wQaƘS2x%dC cI-_Xs Bge yĒo3Fފ[ ,叶NO̝tBM }YK.Ϻ@Y"K<#`Z Af9]|QQ؟z2YFͯw E[mhǙ]d̺4iD͎Cc쌙7]lœDx1N-Hbu0 K5 E\mѾ%'=x]10-+t[Pi!IϩKGt`G p`BO(FfS+46 %ZȐG8Rv>cLj.@scIl<&ZFrQ:f0%.c+AgٌԷ@7h,Ԏnz9SIRܨ`U]~%B2^ RQ)x@Ҙcٱ.݊!8I=rdxAp0%Zm\ϕ63PSt> u,M REL@x&gB ؍ЮH]U.*]{s肀Z_14@">C7beZ$7~ P.Ax؁tp} 8^8uו+@}W'TW]9ܫ^ƴ~^yK[钓;~ DO12gv屩;lz7Dra(RA D}sb}ѧ0E~zIEWQ v@̚ Z_X]?DSa88-ĺ&89C*vA>c]QBA7̈́+̍>.sOS K6ڦT1X8Q=@ aØ[U()_be5u-lo%eAv,'kYK"#BYEpt)T3|T~4e8 \~7S;_ocE]Io,&q [$6ZHYu`+?8̴$px~gUqMuQo(n ߀Z-UvQ\}=ѤeA\B.BPXYV]Xk:s)UkEbE6c_Ӣv8%#[;Wz`|eX~$O)qn/y'-"0`@2z㎤U0\Fq_ mv N!(.U5-emF?.SD#Zhx\R{>)8}y_*# Z۷|}S䟓vx&8tV"RgUxzZԺu[wQc9QH4 Y7S$%.OJ'3?~PpRޚՇ > wZp]ʟdLu'XdP/>Ǎ=#x/,*]Tlj9;+$yؗ*3P5m).՚&tTF1ڹ#C<}kUw滇[p6bu 9\w$\(3C:.WiF`4X'~1-I? 7H:R{rqE22b?isp%Y6=AX!bQJFm[eN颪J>}U4dKweճ$"-36ģ5l5r;?p΃?㇦Z5L7lni|UoHiTK[m;F 3כD U:~[ɛx FHLf{\40'vD2yPOC4sJ!htjwW!co8::@NM!Xp0 4eGٴ\|di&Yi*# >iXF#R0[|JFܮȇ,HuKT}Wwn**pPZC.<IjvkuBfz6U#ұK VP/y ?`P(&M6Mhi8ےFBe% UHIN/  ;k"*93J'&w܇W-\P _2Dke>pxlG!|;=oMfB_oң=S+)Y@ZT?<)N*oo @JbqH,fvk>!eQ)C )JWpnЎC\N8+زqX m ؠ;?kH8k6dOrokǽ@ *$;%(! A *GR 泫̽i4L 쳡y^K;Htotsͬ]7Z%)*$9H[u#j QMH8Ӛt&8YX}d/< uXI FA p*K8ꉗy* L1[ f3:'`.K(G@=wo(]w"a&xvt1&uhe1xEb,] =s/0O]~"oAd;C(FnK~(_\*aqf͸(ኄ d} 7+MYן ,!7[!!tXeT>=M 5 #V"sF6ܚͼ:8\=yO ܶ,"lC?>Bls3㉀pcT10Ȏ a*f $~U=:nG뒷ە@@ 1pwox/f91d;ps]N"+upx #s\ lj;̵<߯q6wIG".m4|7' lv7X%ّ^:iAT_ڑ!4ײMIs&4m^b@>RCffBcml^ɢ?n){*G,b< 3zv%]d,?$xz1l^xN#'X8ӝ6Yn o*,,HC#G>鶫#,Eob^sWϤG:=3~/t&s㤆ɹ8¶f1NwnI:JmTjko'R@Tس"54ă ;MSXE. :QH_ovFp{D֕v5{ *JP$ACld/"V%*pl/11ѨٗQ }c-YUg9_υSY*ВƠ7Ar': s0@|XocNi?i$eXK drpo.HLYSeiz+F[FLa!Q&QpаXkHwL(BL AmyÉi:fŎ-l]' j$g8hlz6[D}V$i(*%P9ZIФ2;`&[}0:{\ qg THy`hmםrʚ]2<M0uݯH(R^KǶƫ :8-JTx''U/?g~  /EY/T0@2c&RU ;oخR2MpK҂9' Q;<'0M+r@yAC:] Y Fu?&+Lkz'5rOx6bi#" ȕw4:%}c$壡GtDU?$8O#=E{u}bT;&(8!*%* J([#0F҃D y}VRr"T-V&kCzA50fk%\( lX,#I7ͽB5(|K ,%ǏvG! NQl~}~|F[YےP/F*]QKWz j~ =t}L~xuH(.MY0pJ&-"B۬ÍbGEh?@V՗/=8Jl0&Q5,ٰ"ҼX3D~I4=k,WGLl龯}rv(mk} ;H@#=X?N1ա2L|U[C=ms;o(iղpKhQ{֭ 2鍀s_ b {_0x#-kElX)A/]mC 9t1muY,OoF ;&H)aqR{_WdYa4KqKzO'ΏgAlEh`q7?C"2CazwDdIMbd#'iXwJCn u0q( Ky=<bVG`0>gpUZSA,03zCO=݊I eQ<-* :Wm|䨤UКA.~m2H viR󄛣>MUa͕ öwVmW7eӬlAa2f HEQ&#& Î(9,<(I N/Fn I5He y\%j60pCZn "` s _)i+/ۻ$oL;֖~v8+I%Г]z-qfrj-VHb3&k=Fnb< AF]{ L){+w'ցݪtmF*8.HU re]ᣳzUJsZrO~!RzCi~|{YyaKCHB=iUaj8 `4y^"g[ϼB!%`a? 9~`zjt2TGqJ!:nR8e[Ji^Ӌ!L4hƸ|w>$x3ͱWW iO@!J"q8y_y^=&LZ|B:z_b rgH9Z)ߗ8zO-gחINwvMx-xX2vq'N7Q|}h>>:w}ɚBX!xIV/kGo1LD^=y }t9Өw6gd,c8'\EByhXQ-o"j:HQa#*w͜(Yr Js}+FR&be;9')] p&+ qhA#LN(N9lKtaoeڕW0N?W'> !22cTQV9o6S[-><~SU+=uu#3v?K 9[gZ?^ ę>cɌ$ޙ\a7 /WE1ʖ߷F) n\Pyc#JՀ -նMF>~O WbFB\ʄp }N߰ &pLM]R.K[&Lor#^QP}_|!!SjPjjއB4ay<isKSo65@ Xx쩾ȯJLcL߉~Tnv'S/DK$-%g38j4kHk=OaJgvQ{ute'6X< Ӵ^2g{`!kDR 3 ujJe4QO= ܓy$_X߹$xH+v$JN=6t E![(@Swv5HT7;Ojno*a֠2Ftӄ{ܡ21YJ2-փ^"aגEHKMi!A|^ʼns1w)]KE=z\e\+tHpU8I:]t5"+vcw¶FdL0׺3.\a.ēCl%!,{H!6A~}{?sTfÏٞcݧ{s8[sU~*H})s-DqBZ['N YlEx‘ Bly;ƞckӤh.߁Y.A]etȜ7!T$G{i sS`_ *=|{ҜIciAjݕl@KLNϧڟ7X8 )+XP C.B?9/Bj ,L4٫i89 VI|b&|u\ʬ~/g#jkXw,g['ʫ'[xw5vZ(d ʀH(kWD/kY{2,H4"Ͱr 5_z+9C~SƯ>z|КDg B4jL-_|j?k'zjv~ڜvцPC&iڷEŀ=] *?6 ,u.7=9 $d:[-6x" yjwO+X'^7}=#ap7N* !}TAeWI rM Sv0"1cu 枧>v?N~H1I$bO `Im}¿/yGX®L^qRh,6zV܇%LeFhS2rnϜAY S;GCSػ¯[TU408/c!j8/.-CDc~eĮ4wRv/(P /+c AFQ71">٣@D2K{ggn}I?$ 2͞]Cm {ٳ>Q,S E R5c[F|*5 ѐ7Oﱘ9Gx( 1W VULToX~qs6,r_X$dTUT;&H lv3#|zӯ:H&å߀oĥ)ꦞ:)ǖL3})x|"Ws_Uhyb p,H΀c 9]rzJD‘dSzz zg˧rK(to ߇Ⱦבy5^LxՍeׄn'ް6^2]geQ&uV!S1et5ܩ2Bu?5S!͚D\j.L9eq8/Sl VaDϯρ%jc׌$92}%㥝)?T.cy:j;BQ2zw$U3̛mAwe Nɍ}|yAɄJ}BzXnUŊ'-RJ -$ K= yGᒹ@WUUrVLmCJO!a1Hu!@4׏W9P}c6+]qzubrϭ?((aޘl&xd+rהA6&zAyde'';CZ1?=MMZWIA=GRy]Q\gf}WG&]هbږI&GJ1y݉m R(7ǧ +kkc3^%يl7apc8 2U)&K+6qTXʐ`wQuNКv=<]Tк 6b3_sJw+o F!|ģKM@6@]JHbd@2l[q4hFy )>Hyh=׋on͇yk fNHTC*V`͹uvp4Ȍ Xޱgiow6bϨn:/p$'L~UNt"</;!Z;=Į0ݹI`€>߆pa°f@*xk#EF4<8LRl74Go 29c%( (?Clp."B8w„jk |*FM?69|݊G 3>eF: r^Wx*˔U~M^߹ole;Oɸn5觸%֢woXÀlBLFe,CQn -arU‴ V! ֤ 8e=ͱҠKT٭RzuWX<[c"ͥ{T`y'aDyɔ ܕ@ Œ1@'^ 5[qPה%g X*KbS][d A]pHMƔ] CNv%d|53 ":-ɆӺ,J դܽ ɪ&`s_vNΓmçGi' rT:y$y/V aY'3>!UHYk8$^9D/xYR%gQo!+oE8S_5ixdt6ZD.#t1`p1Or;pp$"B1Ԯ,[ڨ7|rB $!wFP^-F~11;Q5l$JC)t^=Vk6y>O8մUBV }Ҭwa QV~edajr ZeCR$3k Q>IvDH:`CzQJ8!1 iv9$]frcB*5eUb".9cQMx3j>a40_o[e[hԞ=Dd t ۸](A|}x˹-5iIғ>_5'uiwL5 L][o&v"ޟXysKU8(w(W ? {❌jٶZ/>ה$ Yiz3Ko^,~I讝iŨկ Msy>&[R&Jo]>W-ʂ¯jC}MK\M:_},Gd3 $XW{RbJl?^;iE-w!Yъ$ꑑFnֈZc^ˎdSINmǗ,tېJ" R67YL[{I?-W s=H=}j5|dJ!op&b*X@()0u~-bZ/ຟ*=sc4ʜLt w 09fEⓁ~Mฏ1ɲ CA`5EX*N4ޝ3{̶7z_UDIgNݪj3*C4ݛY y~@؉E3|o׼+?NMzx:z$_э8b^Iwf-)fV|fHIaOQ\b 5;?a _~w(&^U0}=^Ug/b£#~zxXs?4\'T%t SÙ2+o2 +eDY.ai[#&i|T'މr\:JY~j)n@/#NޡiWckNS!=Ugd,zY)OgQ~uBtZB HjK o砶%Wi?{, 3єHS &}6-=Z{uljbt3Ӭa('Kn6\&ݩf,CT{pSE:`}œ>k̾122u}#[W 8$p32Rt7MadYYxNR(6'gS4dK6>X7pwZv)"-fg)W3%& _bsݹm#S7dޑ ?TqZUy _` /ǨYt"8|w%/S2bgPB懲Ա l=BRن:ů< DZwՈ]?׽N BliЮ; ܯ+ە(4A1aJn㗄$bl|75Դ;sLXUD#!2J\+CY)IC؏ Pظl`>mkrD%T+)s2O/I>g$鳁z)9\(ƕuQIbNNP="VB!> )$ 8G W)k05YE@l(ķj5SZ9)]-tT}.k"KjѪw@e c0d׾3U.TN20y Us"Բ{])\-v%RpF`mp&!4ΑC6R4!{J"GP0`,"?d}c!hwwi[voq$iHl`i-B>$}OבP{Ĥ,v4bXAkεZ>yzV]Re<ĢFQC4Ϧ^ddC|Y_l,F]bRo,oeE*fDB2c%>Gx\=lj+p]Hbb!lq=pDKf;.t㿬I sb`mQhrBoע!,nAklL|Zk7Be G;;ShMI`ZFϨGGdkHsŵ5Sڿqbu;z?`9[{84nUPmVxbdm^> ZPWid=l(ء(|ͱRņrl,# I<*^c2PhE-M*Hkj*Q;%gDUD(I|a MeH&, 4F^:9χ#DdEd`(ݪ6 rw^ 6 d}RV[$/n/|T 1Wi< n?~>}JjHp#O?@gNn׌Bl=Pt3~ڗ (H{v:rWi=w[`NejtgsÛQ҆j(`܃]rLZdq.ePEī"ԣDm3KΝgӋۿR=ׯ>&{\r#XZ5mJ`~_03>' X*:ŋGY@.RKS&-pGހ-btJ00+#~b,PO*&`Ls\+셌[[X$/yqjGTجw)0oܥ_yrOS&XwD$]$nb&6/# GR1_h\q=׸#2VdG[)ǒ#59/Gy0&g[MZPeB7 a ws.01fB[/h DÏkKaF^1)oz=QJEJ?_}w(U\-dt3x7D*z󱳗s8 s^ <FtEt>H]>u xdHTltWhI[jn.+ڀb7 ,9(e1G0SB3(݈VP_DcC 2~Q$8տCD4󘵤>/C@k0--9Q(/w}gD6 1x# :0Gxw0ۏdnl{Z {Yrw-qgxO z6z~AMF 桍w<+m>EvvuOCe㞢3z% 6&c!?nХL3vlb3@w.v]1>r,^C(Uu 4|ug*{6i=KkuJrD` ~1гMZ\$:Fn33(akVێr`U֨%(mgJ%tXs(!7^/JDnZί!A!!7N'.l&v2T@"{`C>-ԫkNp2b֩ů<ο-DрؾP8FVcq)T7j+-x@wCEzC_Bjcɂe\X \Fu_5}%)Rn˺dH=53XMmܘhKRTH@X8;'kQ(O@D`Pm (U~#c^m2!4{:R4""CjrW9v MZW bzϕOe[xW#zztimr7Vn ՈLsdXNlZ>b/T[kas<}D'֦RV/#\Jcלuȇiѣ\%ět*+L; bU}I 'S7оeXute+%=̿wy}M=P ID tr7ȉIsհsI5KH%М1u ၾٲeDRvOŃo??b>u)m8ELdGu.PI|A{{d(ҏ/tqϯ ݫē_@F:dJaރKWJ(KbVTy-B6zsZZWGnb)^BԳdm L-xEVfq@󽂝DQ Uv2K .9T]_ ݠ|B3iSTt&sv}r>}[FaV2]S>JEm4F WSjvϒVT9jſ ({3g.QÎ}ߘ?#I͐fK SSN~-syJ#ੵ7E7*kHtv'*]fD=ٮi  "/bM'+_EI'Qq`{vPm A@-Dl [^,TZW-zVcas;1U':nDS]+0J};fGF͖kl#L3Փ-įtj~Q8F7>Fie<V.$oʎީFǝ(37BVDV'__VȀOCNdF&Ll%Gi fPc|1@ =.Z!Bݣؤ&\].,ۙ`Sj > QMXOq(*1wxbZ5ߌ .ø*(R&kЯ>ɱ-;ø?}*,i$|VI@޽&W4L H(Ǡ$Zixj'徛3AZnn, <2'8Nܭg(의b{uGkcpzU$0FQ{?eCر$^i m%Yi23\@_6`5iPh6{V?6>v䳷brftQ1ehIOd"7EZw;!엓CB] `F(7|G=nl67Ry7[֮f^0ER; ;vȧ$BeMnѢ9y~_f3Y\۰~4K s rbq 3߬ FC~/,;JEnSJF.@4/٧o<->t-!{2LU|hy!&hܗnhRݘEDCiPz/cH;s&pWD{/RW؁`Ht ?_x_-jczaKӻm\ ul^D{9*2)y~/,pAa#Mr=/HPcdQW:@-fm! ~<~ja F R۰)MCcI'@!&~9hR&/atNVtWt$mpi$1ǫH0»y1Nsmd _CBF.׿Ni!yd`P3*E^11Z{8ISorh̰mIKE4U_KRAFʛ;Xa]?|e\X{;K2d9x8ΐ:5F.4Щ\QF2g:kh$}/MP?<ƀJՆDŽ5y#K~">b[ImGeԐzsrUVwFxK--p݈m.QTjQ4FCϺ Jn"wfmߎ"?ۉÔxOӸo5Tl^<6ZaZ18@݋=N7!F!exzXS10hfňT*VvMM֢̯cSfo? b%vb4,"a{p&W=9FZTf$? Xf&e?,>ռ9v5Gye;PzbcOFFU?x{;0 pk~Pxuuj䯲!`Pa v)g\7$HE]m`4M('E2F kMPAO'S;6G(jg0MI 6Lx,wizV8f<e pֻ1jRhV @8|tg}ZfQJ1'e`XF3jBeՒ_0^#{sP{ ML[־ծϪ\K:qh;#1ma͊kjsk [L(B شsܕjZ+ TIw\C=,lعDuCPWע|YM{޸tڸdN,o災>FySDvkMfJs+l.(<@>w7oWV]>&ҭcB3$,xA!{֠YT{&kРAln QJ)I!!,kޝ +E4c%LlI(dg98i!0:J+-ቦe@nPoɺX(?O! ɝX&ρ ؛]I8 6%Ȋ1o:FN+Pm\tpp:Hݱ`@-) 3mvB.ںk.CoҜ7ܗd5y*`[UM0gX^?ĩ@6G8By+'$#lZ3pDI F `mTo/eʒԁ `U ~p\2оQCs$';&-ƚdޖr-)DѢX5AOϣ i r6Pٶ"ԔoƠ%U4Ϋ!\: jG|.2ǡ6CS|Ml'{!GՈnsvsr(WnbҢTwMbq*ԌPSDLzRؑExIdNK̇t >Oh>W@K|qU:4t~ev@~ӨOmNjuC.㤭ݤuOK#I|<`?Jhn D PUQeG[Jnn#AT5doH%ܔ- }'ڔ>^&۾t.;FC1OV#g[/Z91#< ^߻t;fjIw(Y[ y5P_Ws+LyDL%h߈:0W䆇Nau;@yR'z_}~*&XT)rZ1XIBq.^{O$F{ OM ؁Yv_'.c΋ˏ6QYgڈ|o  U, wQwE*6GlX~[D`qcPX8|N)'DjI`6 `fjdӌDq35׈MAF쓄Mo9ӝ&ʪ s3eUeU%q(>BV(6Lޤ>բ֐ARs"#Y WiqƠ)5 [u9CEqǽI! ).gɾp3L;4QyNH,8'v4ڐa "ƞŚ{(z=dcn>J&9VnQz◦-ۂmLfZLX%҅W|1^St/\+uDԚ~O΋iHuԠR}PSmIˬtn/xOm@4+[W=w|W^" ;Ԡ*:yXHy4n=GHdO`f8>lpI҅ 6↡wPyu.aΆX#xZ4WںfAվ<E^@ڸ|r#wV+ʛ7 VJx;YG`)%s`dVbL)Gs`2)UBbй=N jO.7Ў԰rnBGj:Eo zq7{hf>C.)FfS΋5g0F cuyP0K/nٯ]gua[bc Ѥ[@hD`2C7l V{9D}`9)-d j JF̃.dR R3t<&F$i8h 7\pg"p|nȮZ)"- TiΪń,iχ9wȅFM a Ll~(ހ1pZܯ5JIi>7ߢ:zv,;kE s3!$Qj\Ob%6[XO6~C#fKlC,"UjAஆP#I w^TOЫ%guyL8c.PҒfE7r-PeNDzG6jNҕe^̖wKF0uh$٧ pUt6Mhp6eU&'IUY9ƛW6s"$u%毻 -`Y )N_K0ԍ4cJ'I"8UN` n8t" &.xUeg3N5Ѫ1RUءwU-DŽX45a1i?bFK<^vFZFGIn$'i@7ӅAm1 T*VXa*aω-(P+Z_k$ 9T c0*/F{$= դ_*6  :) )Fb0B/.b(Իh^_IkΖTyh9EOUH:;~T7T~U;i25F Cgo $XX3e ^E\Uu5ډ4S @44B*nu_W vt4_Pɣ$M߂W7 uR|>Bv0 Yer( 7S2#&gXu1.Xh4K9|PF^YE-ˁRXu``*9" \ᜓpi^A7"6[ E;9I%(Fozʌ'g}ağ0hlnY `F%CYT)0?Bк,Ry YUiڴCw 0#}zE@:z{J_N]lZ«ʔ/Uؑ,ڥQgSL HȼB'd#ֽqkt305@ +P{C0`Dj4XѤ)C Uv)`uj!*^.̱gvinYO_m8r0{71zWZŝ/5exJ%EycQsvR&Md.,puڙAi`$ @LtQocOhq9ˢ0F}<IT|ވiLOzv)5XJnؤsn8;EiVQiwz%7Vӕ:]f77N:G?-=öY`әObjD=MfwtDw/߮腗. 1$80KZjvMr$.96Tm"6E^s&%hVE*(k7A7b{rָGYWg :'eKV=y!?@Iv[el=VC\pџϵ-1q2@6mG%fF&TLu̫O@kFV !ޏscEmzv~1[{VBuk񏘂K.uZ("HWQxKؗJ7=āo qEFb j/%`LXB%}  &m$+ DA~-(u6^zׇ:0> 96&M/RGp"rDK(>#:zkzyGR9`_SWzU9iW54,ms,AW\F+$VFƃJSHئNꚹ=[}sF:p1 ZxX)#@apYCH3UXҨ?8Hh@L3E4A'*]7 m % ܯ/3<4 mv44QpL0'z[;WR>O&k_!@Ti rF4v{^vbTg1Sa!K?^S9O>I\^?ƛcޗW|3t=&yWڅ<K,?KRP-kp}&ex4$B=c`@&cZ[xt[x =V&xN1OgŘ)GPzRqi[HM9,~':v P.YlGf |KeS ,hͯ7s V}QLFMfK§{rv%RwIŮ鈛HmZɽ0P0:@zdLUJ4-5>q渑v¡]Y^u(dУ0-_c<[D*o0*aa<^Ty7@( X|z)V5[}#Ml@΅OAݮ zQWD.&9jB+dak(A'& ۨ(Etn6{ɃU}\귉 ~o+ _ng&YPT_40A#D]bzY]_50AGh6_g5Ka!S޵5) `d|ڒ:MZ`%d]zhfŽB*1* 3^^ߥ$q;$N_=t /":y Ņ|˲Yv 1,KFC6ؑ(j&l%We͡q,[I7 t{Mk\`]߁lXsWtCZ^b1πLnϥgW+< 8A4uLik0sC+&|Y,l_5M F! r=3 ܄>V+p'A䥞͚u S|kEOWDRMhyQuJpJDiĝeD*d˅Z\|bTmȜ8j~Oޞ=n8i5aqy0clh <33K)ڊ;29 =[>.TUw=Ԙ/Lދ JTQ:MciN6ˢ*.NR2iWc&Qut/3N)d_w2kϴ~飙TY_ R5\S{1X<PxA=z+b-`52n;rաF;y(? 1*]@7"{RssX`# qeԩ@ 疶+}4/r2Zp~핾7b1=Q3JƯ-ו5im"n5/< O;V#Z͎SFb,#rG}Z0p8ة\u;f-.qw~??RSֹpUD5="GCDd${Ќ >1O<.,a!4l3$#&HKD3ׯln2^m BS nc2tJ$?.˯\~RTBvMwC Ӗ\a#ktB^+_ÈRƉIJ({0hZ?PGG> B lzYj拆[)\ŏ"mEP WQ# aAA^ a>I`cu[쌫oc]mcQGOVufpnweR4 bkGmHlp~|Ji~rn5Gbh$ȭ dȿ)`a;!뗉mh I}b s@oP;Ji.rPSa/ݪeJR0r'"=n9ISV`8E׬=֖x3ƌo]UΩb- ̀ʔ2~0u1]C™Z,R'5f}Y-ߞ+Jq|L$&_w[*F=3IIQ֔MWnRBkKdzn~\e왭ߧΙ0`=]G◝Y w\!@r1+gKB!Ӗ'-]^p)&ΦѺ3䢅ǫKv)G343P0~D#'+*`[ƙ(VjMC|@L9ۜ%b}01(5euEs;SE"`JwWY ot:~ޤ!4,> .kcQK2h'3"#d; ںכ\!] \lMr X=zPoJ(;񷡠׸R}&(!RL(x/̓([yS@pd]].#J:SÁbz MS`m`Nh:ύP)kٔ)p܁4moD]ja4φOoިƒCF>luʁV¥Ӻlby[lJ=/s=qtUd0;Ӱ/84rg|VaWS͈e럽{K}e5X߮ן}Tp&GE,ܟf5ľ8"h9%ڼ<5'93O@Y$bJ—۱2d77etI֤i+"|jM{}cJ53Azw'z4Rj4 Ur"ᗷc!kb7Xq?D 㛜{H:$D=@A\J4IzGXs2A]eL$@y@x[ڤ˔̛E[仰d rl+=Jr@ 7zٙ(A6XyNU~(kn47fN)$ -׾KWs'HF]:<4$Ֆw8ɾ1hq;PU#U:M 0:Ӊ=E DIGKGdD  [SqxäWqxFN~Hpho;Ar%˰])]f~R}3TW oFh9u/{#u]7:gtpk(86 ƴ}% wFIIϫs-hJ#W!Q1`!*#aM&F3C32Dz.y\3|ZzdFHqBv-,EN D0XJ+|V@_3ҭ\-`?> P 2h>GO]@g f;&Iz0I܎}K~hm>Dnݷ'C!QZ@#efVk|TлDN!1~pɝ,$^~|-˙jޡb_䔌.G&^˫RN>.E+K8E*.ld:zł|OX$lRzaC$$]ƥ~r˵p]J>'k3R.Z1HMA4OIhL ('l(*)v@j.A1#6HS"ܚ-A!һm=Q _3/gZj'ŽyFe8۞9B #1T*Ό!, Y opKd|,3(|/|1g~մjSmKtԅ[ϥ W,bģ@b7%ݺA;SFqV߶+\&B]abФlo"8^/`RvKCB{AHĜHh=G.öBѰ`?rsМq q0u('GڠG-P~cu8Q6 -hwg+11[O ",`6u5F? k[%tsWgր Ve!3?;:AӥBm qVTXhFԦCIJ)Nc$|lcߦYu8ӛ2D -po$vH6b!ˮ?ygͱ$ܻ?!RE.xɥ>гxi4`b(^k5NrV)?뿣ml]vɢq>\Hv:ɀ`Bif`[ f2 {KaaS"Ȅ#vZR4BHխeGӴY~r\2>IF:z 3,+r, V'k(`i$Jf11V:h>qz/?]+ 4Y+ԭfWMk.XÓR+ZHЅ<(\;Kz{ {´3 UxM : T:";:i4.Ns*:ΐj|&wr)'0/!:&ɍ(q>Lnd %'2RiAvPsڔ v])d@K)@` +Q$vуS~rdЀ2]b|TMuf:$^S)u6LGdouzqdN99'VLotߚK+I"Yumd\Aq '؅']vz J< j0gTOC3RFI4EMIUA"j9G_=#Z=ꜣuf-ʌr5w#=+T K1:,1{n`r.RDkuTՍq/o>?P~"3%pgc=gE<3# : }ӳ#_q_VrvlEYy?  G,HA]䯾MXTm=;CZOd\@y5T*tl4|CBScFdo t:~wj5[Ax8?Kgn7 L ?rU?j" mdm!)sfycr-:> L3Ǥ C<۬T"`E֌ym9b"Mڱ~G{iHzWB/LW  'oe!#`B󇺓p~&GDR\ ,B/+!L#/>ॄӫ@gOMYVht4{wS,؊G0m\ 7z<#^)(z+NKe M>b;BWO*m_B@z:'+"q.ץ(*Mk[󺟶AE=?i*Tݶ21ϭ)Jv=0ݾrZuLF5p7kܫBڈTcO.RU5I1HΑ`w6.{J ;ƂUqA`P gX{1agZh$0o_?X?W ^׈ۨ}ThWǣڈ Ah%ҺPn.coH|!eoi|@W0@O;-e13d4z+H߳;rR^-]P빼D`OT8@FDZ#&~. lwU$4q߮J3u!q)J?K.SKȯJYUGɅ 6nţ4J4|z:^*14u4˂M DH)pG'*:Gf91=6_ƞ'.-E'̟LfT`[BypLťr2q]d4,Qf6K,\L͓M@rYklJl9Yu(8R=~Ȋb)܂U?T;Rnn :#(-d7wXXo"u(ȴ8O6k't_G㟛ն͆Euq3_>o}OzRΔ.aԊؽdY+ԡ]e'}^$TMQzE0f1R͉|\+SXygX UN1Ui]_ϋ/ʟpϭFzt' (}6( Tl^NrHVE=*/;gRwDL_š/ 8.ÃGnN=w!5QyDF+LϚ?*]UYF9t#.dLA=LCܹӌ#;fb.Ge~Ir)( B 6d  HGTbm)`[|t?qˉmNΐ\HqrחeŕcQ8-hݞTm灥 C Q@ ,]CMLoxdO.8iH\N{QDqIcc1T'Ç *O=OCO3ݞ/r:4c S=;?R~BnrfpnM=s8̞ڟP5߿M<.Q[Nc| vG&o0%9(hb680/MU\ isY&ܵEwـ-qV\OFuŴKH\ª\{ژAJHl\3t˼q}tP!'O퓓в0_;(/oψ7 Z$Z 0 $σR&(i.T'W̺Iؼae'DU8Gp h#Ϭx[KC Hu-%@㼞L䟤۱kUO٨%UR>Ozfi"?Gd'p2 w{|$͋f^PcH{cg|/ǿsn,o-#/dV%P|W:GRLM7(pQ/<Vʧ$#"}É?NcH\FxDpIu%Lke/^~5Wr7:-ǺȚpsvP7' d3Rq::{OL^0x2ƑOP|VtOf{\ BwМmpN}_ZHpF%' ol@rfe]R40QPgO@, cAȌb'=ɶM[?YgQK)׻ǃSB5y1"SK CVtK',PDZ/B"Bt.E}N53q0?\&x|Yh?V0 'PU%C3:M)6 *pa|'v=62[ ˿GO=AtCCIK@aij-MOF:c ߜꬳ6e@_ԺO/t. Zl#DЪ/@xkH:qmdy8i~DrB|hμdڣ3#t%~:;pSvq0*B!:II'ݪ0~\N EyGTu[岔QjN&]~4؅#sȍ}#I7,*i<ҲCG%Ǥq i nvޠ^_y(y"V" $'. Lt[X&&V 5b\M9Kל!AgN˩91Ie'像ϭ*|1 6=DP{[="J4<R͚cr߼Mf7"Ϻ1(4ϗM@q(Aef|z~ ȑ8Q!TpNMl !쥽bM g aPs|n(7%Aso#8.s5YIm?yvqt9sUmpט >gd}~Fl9GpZX w LFc <}[1Op9c>y_z*{"Դy0ëL|\<&E M߽'~ǫ3,.Uklcοf0)9EпY5\b!(< j_qرv]Gq0x-4a2oU\M+ҩ7o _~|MX$8OB"^lIߌQ /b@>M2-WM C@jxvE`u;N6=`gvKT~׽a8˖ôT @NJPI D)<1rϦ:p| -q%{A4 FFl4{'y QS_aW1PWҬ?gK\,eg+=+SFܪ\ K9Hg tiG a䠎H_![cX=$3f&e$ 5N?fXCxOozH:qN+пDXQ+Kq/rda[+A[$]|?tJi&A⳩MC'+z K{P{T~*R\:'NbEn\.G.AN[!\ ,)0D]\A1ؖ֗; ˊ^s2cnI#BzQeG.*;/32NG'c0{KZ6;"Q(蕉Xy^Z>بJmk0 蚞BO5ԮnjX^RKkt)tT𮀱|C՘"4;_"T7_ ǡ!.^Bmʬ@&֕yp3&+ tcM9VDPt 8woiC /l)^6 ~|g#R3;bX>Efz.|)sܢc?^B{k:qkK7lEӌy );{gsgd@d`VA;5j!?z`̱tɪEGu<kіR5dLeK=s)Ȟ.O#r+U-ad"MDnij*ujd81EyEVd29cA e ?.V/ m zڥZ$R$3hBW s6!l]?";]t m(yG7 O#3v|M##Xr41p v8"b@0uXAymc!iEEPhHI6(I~@ia t1np.kۏ kүٝZ[N(lQwI>2q 9涋'-o_^,Ԛ^ yTZ9}񖗿,) e`цvp7v`92`^Y5g JEaE{ u 4R`6xap9!sd{k1kO)PXn\CN=@ڨpqf_$@%- oO|~8fEg#AMXAbx5^?崕(JѕaM:І_چhB.J:7\sM3`OHsjG5dL\ {{{VSgBWŴkD̘ڟ=- y@M% sr^ :7d$cҏG"5S5bTlQ禛y\y=u}*:_D'aLec9+~PQYpM@[)2o_D++=@KDc0)} ͘NjK^E*@! gJc1[KWe-p%"} Shy]0v*qqXd}{Ji5ω3-]E^CNf?~ԈӉFEXñA 0ܱtn7}@DR9"Ju:B1."DuesGt%^a@T|/uP"Yϝ̱QT1/l9B f$Ag??u7kG;qPYFfM!>/>S]O0"އ7J<,,L{2 Z@!b)|T헖*+aR].iAzvp\0ᢠߑ%;^ҳhNaUi:"kb?΅.GM!gMAWfnUc C5V:B4quiT[e/WAȏԙ۽$@CTcg )TĂ,|?GW+(`!r΀8FU8Z0##BΨ\Mm=q<tK N;=E ŵx<=  T) d&=|(Zl?/$A_X:Ҁjl'(ԃO n @# ^ӆʆ~kd `f[7߁΂4.1O$#A3pkAq*"ag'!f0B ɓqhf@St0D`R e23VOn ׁ6IJ%h*ōB'r?xVJ>u?+CaGL9>큁̹_± F {jib] e/u!fj^A=MMw/XmGd]{%|TF@rڡJvEչuk|֒d䒝P;)I!.Hjp%~Hwu{)yD,`eN_ȖLpi\Z;,}zsw=w2Ak,xׯۚ#ݡKQ+.ࠥC\uT2#a;NZqjj#G-3cr8z޽jvx@gKh} >gŕ^ 4Bi 벴Q^n|b$oy8dK_s`7$HܯKmUHEѿ!,:F| ,.ڥ5>Em=칇pu[jlG% [B<$fL J!@C|ҍd*"_|gCQL:\Y8 +E,|m"OM8Z.D[_lTqZ&6&AB{Z2n<ҎH" jk 7jؐT{ٍ}t>1JQM (+4AjY)/[#t;֯yofKVbr8@!/z'"eqΠ07X64m x/ p6.!hBa\34I`Y?&Fyk5wu-vSXϺKZ[O$D"Ee<9ĄluY^R}MꙹC mM?YgX:5J&%%MїjON) YnŔRbؘNլ⦈M|K"z}N8 v !3iS!LvW,42Qou&L*'Pi4cp yZ:: rw?7LhK79ɡkC{ w3(0Ug|ȖwB_ !V[Gu%72Xʒ3+?#럁xmAB[T;Zdt95t1%v9 SK#6byw78= e1&jm~* +Z[8}) 8#/CσoGř[(wZ~VJzEM;]?ße`70Vб`,zL 唳:Y%oCcPv&b0ޝֶm(#`σs4)n]՛I`.zԌ^50_wY-ƳWU6QF!~+òGd@T/ý]zrOөBBqσo7,Gޤf&i%|5>_X{O'9@^8@׊mN7gSWш,2$B=]&8|'$? "`ִzj2>VUM%fjbY:DT&˰qqsTtq0ZB}UTDx. ~^OӁhiȫ3\PNF%8Gql,TGRJa^z܈gʿH$>Ft\ T xrzYl~ͺH/c\&D}MPm~Q2T #}J=Iuσ}#rY3 Q1bCgY\&"%ԀK$Bx-{ϺT|0(s(55-{ݕ Ez#0j 05m QU<Oci4N;bFS1O{S4K?0H37<[50u|bʤ}F0j"IOPhNAMd0*vހZ#b^Ξ=orBzT{t)rn P) 6D+ݣح;dmɲ~ `6|遝moP)0$z,HTSNmp{_?BQӓ%gI1I?$ 4R݀ީ6:r=D]mW6W&J MI]$5FP#5qߎHMͅ~s Ii?S6}D@Cڸxv۸SBɭ}.np>|Csڴ&9_vN]T_vn\*#=ʞ^@GX oj:dHCǓ{웫*A ]jN PpPO[mhe$r>|ޗic{g3߃tU \AfBhfm %rvބDZXX8t-HP%wkt["V syZpt^/?nqH+va7|T$̈qslgm*>{ M]Ok\xoKBV0v9` Q evfy1f#Xt }P =lUjgJ ( >1b&6-nrv'dv\DȬNʩI8Zk$@<{x]w6xV?Jw?x;˩zvA KލG֖[ s4c/[_|oUWobфjX 1 "{CV^w $+8lLZlA4E˻}%҅RgoL׆RV[#Q҉C4c֯(:D# P)Ćd8l8$qN1"]/Ld6\*>)3OL\T$gIY8l3vyAt8;i(=z(ݳ`Ճ[41{҃V^.bk#F00`q :] ܗU 6ۦ<>iPbJK̿'~e?KyF8_=sİg*"u[]Qג"g-a`@[ڒP+`Rc5h<Ĥ̛3Yx{{pz{CvlnQ0l׸PG7iWG!Garwmb&/d I08֖ܔ 34K{I_U]HgkR=KTFu̐3;i: jhf1VJI3v$S̾jQ| S)9Xouq9b:iV|vb8#KsmK9~Z\S! ^G{Өk2ڊ ٥?0sOlq.{Ƽ'Ì . ;Ɩd*Ae-J:kf[&u}Td\R'SNT,*JP!nSIk0r@VV٦6 +R&–[BΡǻ&(t{ cT! IU.K=.'oݦ/ Mid$^-dL)+oM gd3'$sqk{ӯ6tB׆7M)(1|n;ӑ-#do͙W$?Xf#VaUXEݼSZbS-w} K z2}I#c"; = 4%"J  Qtm.Zj%08-=sLCkzl|.yߢ ( Kه^eR^kAܶZPB e똆] (8wg'UuEփbvOsvlQ9=POp'^PEX Z~Lj]fO!+(USI,hD8t[ɷ. Q} 6IuW>CJOx^YKXR >@+&'<<`^ǓIXSem/b–y;'BY{ 8wD?IH0|Rzez ~%+k]E;|im:-3=KB \9y\jK=JҘBXA\Ou/6Kz* ;So|*ԣxx AB27Qi#юNe3ڎfit5F'+tgo2lyޏ,m٫6+cdke2)r`-˟i!4¶JL}wC9/|Xb?m^䮙!+-8rP)%hԋ*D e5߲A5پe{ b27[9 y\.ÍDY&bb;鎘}W# i4M\սɾRx̡gVS?ZEJ>| > 5~xy;zvf2p 1ӘO7u1 ^ ǟoQd$jUTJ< ʧ (F)7lVBݸ;|V9f w$>@_`6i+A&X"8&᪯ctHyq\O xZ[|bn6˳OL ͣe,'0NqJB1m K/ڊ4$-b%&͉^?va)ހh:fԥҨ>L6 W'mJ,% "k5%V 54bWcCe)HH!zIx∳zMޞ_ y q4?t'/G nkim6\')&"X%͎Ӈ K\=-rGR@)1n#e#'Տmp%l8hq'm?&$_*&k{$=8߮ f%*+[?uuyvHϢM!!ׄ@ۗw5+WѬ#2_L:z'`=v` 1O{sMZs?a([6ru_2@߫8NZq|)ףC_a@0q]D#>$ Pub vVυ_ ̔I4 skoC_}ZWT+fz-3j?KG}1e, /49`,뽞WXHaNq]G+R 0rj@b+A|,8jG1.)+;Vfo P!sg6WĶ:iDiQbV'pd yIG?|TLo_)3I kOoi=YRQzXI{|^h-s%pAi| EVde\@f V 58"~%2\R"=_(y S;P8,{C4тTtͺA8R4FR\~2 (eg[/(nxo)[@:;}G6ӞC^gQ0$v43C83Vf1$}GC`h 繑z\@#%PjpLnКטXגY 9PyE<L[ңO5z-s?'=yԬS0AL ?+K|xmȅ5S6a~w3N=BG/]fOsgrã1i uWx`NGCv!adύ}ID$ Nӵ ]dE|egJ:P)ڦ$S_x*|p1>N-AIV(OR%2>s9^KISM29H*Ɗ ~*mA߹CG @mRSz!o,<q\;N+fܻ* 3lUbq;{,a$Nu-WK TvpdZ6Tt}٬_dZ-&y RcLiP[>@zM'yӼ⧗|oi5D"5#WzCrXq6>FӹٚUdJW6$Iw]I'"1gu:YL;.jťՄ'M}=(j2}n|H"zC^Ob;(8 vPnp1KgtQtbML`C aN:ffnR#Upյ1Hu .EG+{;Tb\n۷ITW.hQJ:vB̽#UC].F((\l6F~WWOmCs4B8zۦ~SgeĜ`xLH6^ 8.Dc?ӂՍ;3e%Cq7ۤ-0Oq4!鍈uq6dM))nq'mTC8pҷrk:C~*ge,&t}*|Sf1Ϡ{ +N gDLa((洈 t-/ߔ5*.FDڙXj`H˞-H+LtmSQNӴ T| U~jN}Ri!;ߌWuŬ7dv݃jLTo8Jhv߲,,9gwՎeT2};|V7zb| -WcagU{yTp!)r3!儩r5'V9cgy葲؟+n6Y0%C1%q*[7 2m(ae-nd#vf$]_evÇG!OpI|@_dݞZkD[,Κݾ(RըǨFnZI~#oh6:B2WbI&6kwz̷BR&Q1֟t\RnMP M['Q2V(%^#`By0 E]| A-uWI}?\&/V_DiaYBvJ: =S=8`-@`zq}eRIU$N¬Zg7x<',1,*K~x)ݻIimܜѾ@&ík2^3YzoW|'K'N&n8.-}mX p*brߡ+)imޫ{ܵpL/2%> mfpߩ=`c&e\@{bAwx Bkxj P@j-b(t*tCH;qN"+{/4To`|ݙqD %/8`HQ%V'Xuy֗j_zIh摼4 Ź |1+ER%3d{TYT AG9=K[v&-@5qՠ2\U'z(*H7Fz8ī/2RHP<+I4gmY,uUCbRk=^;}M|дъXqA(kR1(=DI)#[S\`.;4q )~pSE=2\W*{$s¥Z.3 Pc,ǎUk4f7)m2EY (\zx*r팵/+-4M'˚Hh6V,lIa/ 76.~agKYcqV VI%;NzF\͈_*=ݻ>ς3e깫X74@27- tO[rR̟-;W} JTS\evYYϨ7a8x3 YVEBή<ߛT9k% !9MH)@X i_ &!i3,855"C=FaAܫK7oq/R\uSoSꗛjsO_Z6 . ˆR3[0Ȯ_ IA0S.'Qց0 %{J$ؕE1/#0"\0:Ǧv?<=࿥5xvH2!ָUQPyн2C!1N?u9o+,S,||C+COBqM$2JaK8=v<1븑w$_w 6(﮸~‚Զ*s` C ҂èޢ<V*>]VT,AZ%>PdZFnkV+"Zme0Rhi9c]E_w;J}鼄r_ ]=CH8D^zb;hHvhqXFT&U=Qn{[?]THIwG+ fY2s_koj<8 = fSSy-#\[mNeDTGH*˃{b+iP uc$?\L!"h?ƒ@~DaP:fDK n6kg|4B-wGs4*p<NZ^0@Mw,#'/7媾K&SZ5ǭt."ZxmTWuh5؝1ϦP]i$'z^s%; M6J?,;w a CTo۫ʸ rWWMB?1 &Vɒs'\Ն&;~^=ZX:1\Dլ%l֘W.͎揗,#Z?rw #=d;,G 8]r g)B@'2/1u33KtϷX䰀aW!FQ۬?c@i'( QLޥ/{rd,+B!⫍E#H]gBQ+~ :i-f|)0z`5@c|% Qj!la; ёTܩ,5Tr:I aQ(Ǡ'#~2dl,MH]/& Q\+ N0 wVP ;~u蛗znp^|J7 F}c̍w~*xLtzjÖ!,c7:*9Bj$BCniAHnF8k\?ʗwqfhMIMM lc#iNBÓ>q]h$/B.)w/O(p* S` jpcw$S=M~9.,D ,(Ϻ446HLtHfb<NewU(Ansvi/޽ivPF0),dP@R:+tw3LL;uODvX5_m\ZG ɨ'=d@,1[>^Vzz JdX5JF?#{/֔1W*> ^$1My}M`oe&_%w7%ԫhƬk诜y4o!wiOù1|QpvhX sք$5|*8Ϯxl/_4?lgQ ٣o› h:9ڞ+9ސJCCP=:&MseOr$h8Sp1SB9@i!cxg{oJb z[Ed]2{/ihmhΩI i|I!'a`y~(JkU8=hꍺ%QNo40i m:IT;^duc'fPKm|xtL )%kG a}ݩGc7륩?mp LBƭ|lU:="hhHtRܮd@hW3T9?Zv {9ǨdaygϙIêVďp-ދ/* _y1(A:I#͎~~'4י䊒ٶ n T! F4[MFߴ&⎥ۡH ]ˡ Ukhx=0g(3 P#& '3,zS QEfBe2^^iB@doO( 0y.~P"oyn@;"63p !)0&EdGrl<VedƲmߤamԒkZFLq~ _뽮&Lbu\> T Bhao @F[T! vK-wzK1\]cQ3ʓMZ1?T4h"@P=>Isq0jh;fy6`)͝c:#3 i?S53T܋]kVM31ŽKo8V{J(.MJ3fLN6{L[:'}[g2|G.Z/xPng\v,J9T ( (~cz^ƐMT.wx/!C΄mLJ1~J,~z1VØD?'pi5~ՙ+DpDI]4&44Ȫ*K*5-v ^[OǹiΧ),JJv!Qm^+ZBmcf^whMWxb ک@\.@la$SNNڧn ^Sm!&ȁ Ȅf}Ԉ f y.ඎ9X_B(:L*69uuI;Yk6TtQ~Q+\EUzBozYb^W#M;ЖJb +_:C(#|7[eyJ1Zm{DZ풒GKNQ DR B2؏5t\>TdZ*R019ln @~gB~$w5 73k|d\V 5wv+W&#;yGh7A3+;JP^L($^ `f7~Sn_o6]꭛[b؟8Xq2NWdzI%uo0i㐥%N9̛|x_rN~qTt .j {?v^_f6X$UF/lVT鉘hxژƇ[rTPd;f~@AQkYĢRQ?RL4u{}Y`el n&6Y $*=u&k BO:]f_!.(6~HGb @`y]$F"SE mNORgO%׮F^}?[s> 3")qkX~%,ƩdP˦W!8'E8K)sD@0R:ǥquF޵k"~R7Q|0dS`Ai%!gymhۉ6u`F'ّ8xY'%9d>S(q25OO㱬hw>\}J_ݽه < 0u~(#aC6蕾HϓjYQVhRpMd9-:7?F*E_sF0 ZN(kebJB|bnQ}t6|aT0(WFF@(WQ')EœUil6#m8A"mj iEv _nn"~Zd/7!}]t% vHK"1 pW(eq :zpWDi׹55Wglf r /U'=B) p> ghxYHjZOʯ+/w4 jD{W\n1Mx[z2Xx>[ѝ/GA"f$3i_e[z6!6k8 1͌UHmEN-5u4];i-}4HW+{yHv3pMLvK+QH6yKQKD~|)1(`DF?VtX#Ob!ILլ ƀ7\BKXG}凡lJޘ2")O]L->i8C'zD vezl1zB&qB@-djn! -SJx]+'^kRHY'vJζ'~PEha0@xKos-$ĎLS |3uS} ǵw;w ?c5[C>#&:@dЋȩppSJb)o턑Ay2R>e%LGG4OSGzJҦsޘ:zZ6s{JGdXQX$ mzdm,w,;`e˝B<' *@J~7멥q.7ӎposPeh5ka-I6LɧFEW07|NP=ӥCRꈞ'uA&Xմz ~!t.8I3U]KazܝuLK؝o2%=oL1"@݌xH\ݧw : Hp[HMUht.~v>/~Iqԭ?ry:/a/EP?¦ Q!I-)'J8Ȁ P 5I]$/J26E@}p53U$f.a fku.a&V$oIXjXiDd#=0iӶB}9@km6Ci8nt7Sz6:6:STVdssGFFm XgϴD[@ |2b~8fx5ꪁ)c/tY(diuA$~='ŢQƋ-[xDN?lCh^E8J?.>;!n{XF-ŒQEL0يke=*BuM̰?"/D[JA ~h-˶!?&2l&% |~; 8'eBI:DiI9<ʦuMm-i+㖆:}9h/^ӂDC"ve9"@7ϔ17܀j$"L (/9=DQ7 ͅ[}LtxG!FUXB!:M0"zWEf=+2.w28'*|ĵ$JfNbmvM U/h G=Y.q\c7\@+0{MNN<=Z3 ;Z/p29hKMyܦ~`1qOY&.YǞ%+K[\Wʄbkit-$|Q5Ig5XL7YlvLz@K`jT.͍o&i咶wK*i?]6[00$nN\ G#E{>M"ǃj 8&_7;7&淋3z=c"3_͞w6,-D6lUA ᚟ Z)DoV_RF=)Ghv6]ƴ}MP=f7n"-@B;>BLnutSdVɽS4*85sɃ,Czc]|Jd>)hlIVc ):iC`5'^>@6!TSv6 havsvXmis%5GE*=x|1H*|4 (叞O?EA5&znCh!Yp T C < 7T 鞂w2dş+37akkĸ?7W҄[G6` G2ݑF{89hvxXmњ{e1!RzL4h{ <{X(R-H Gc鍃u [T}yna$X>}F0Sgs>ς47:k,T1Y &m=%c.C˦%sM#c.Yq/qB;tDӓpX\򵜰䅥!n,8o$rIU9 /;舔_2=,[67Fz2_&f. Q& ؖw.:a~DdL],{{1,Hf.h?5p11$-hvЫq- e]Vz=}"M4,u,4:{$6 ~V۾^Obxwe8EG-$O8W6~_(IͻAT>Y"~અ]ш(qLOEOLߓ L"eڜ; ct3\)ݩȦf0A6tҽr?ŖkbLujHٯlTs9FouVnKZ>_5N \%\8ԑ&4, $2k}Gb}A % >ыw"7]~y@(Cy^|$k(!ڀ^8Tpʜ e=`n90H|Ej\>Lg6r0W֧*۠z+Ki1>C%娅"e`R荁t bծ((;9 TR0'Z pMS88C|)[U1B<ƺLm}u^ϛ )O .5dSiin'rm%MR0)RAZS>A1%yEFcnH)O`weq2c9D/ۺ6 7[F\6ipmb,&c7_S¥+q/fX;6Wd%OTN5eyypHlA7H\7d#4%z=vP%5|"}pˬ9n~ThG7tC^cr|ya:DoX(is f~zw6l#TFOc}4:(*X,e^HOxJ39(l%0v3c[6 ͕yr\`B,aKAQ3>n%8$ mf0Lv'NA"J%g{KUTv4|=8p,j 9ⲩ/L]n:C=z%(?eMm[Y_ ui.@Vs9+"CR]΀*c}peeEvj>Ht8)wgKĢNY /A-+_1ˉTpT4?(݇A->Exd/~pɼUKF4:~=LوeSh/Z]s"*]/F$бb~BJ_R{'Zym2d8-]%bڊ~Bq$$)]V?S)ҋr+e,?cc UWn-Ɂ ɷL_.CX#k/Ӹ;o)C岃HK/OfM)ڨ&s7BiMcbɝ#脝v9E1SN_}2<|ȥl~FMY f](ȵs[x>bB;6]km-5űpݞ듺>߿t1K82rY9 G`bz/pE/!G21.dJ+=uV[Jڊ,C_/<܌dmԋ޻ZR0@./ [LjJv S_8>vwdzz2ZO8ҭp;3 h/V\%Q ػ0؈၂%WDg8 篑BۺR_ǴܪBf Y|}!XZV K|wFq_0LCXhz#κʠv].{Mi2A7m<_S>[>me$:tĢf4vHX.jN3eeTzŅѨ'Z)hB =V$OcRKv"-z!eX@k).d˃Nʖjοߙ"hi}@~N2U)#G/~`8~1eҖxᾒ>ْ`bْKm (9HBM"4yɟu€K,fc8rĒ_iF xKX[xA4Ib?~%HnvFxK/ȶ(dw$ uû00 n怺 πJo0#Io9*k~}dj;~2وnk!ߐ28ghRK ZM=ˀgo$SKf-TuPD-̠s㖭:6m?[}jd1]9{@@|gxLaHbvTMYk||;f [i 5ٛS@-j).e#8EV5*$jXXq Z׎nv\"m3 ۟qSOQX/3Ss] ,kNl~Zc^- ¯poz S؋ *F)\\Jyo\(P`>BpB8-:/|';(K>5>=3IBcдV Im†1Dq&( uU~9 A_4*m\x?Vo ɏ [[=JZo盧,!]l>9p}uYB 6n pjm#QHTug TO"c)tw<>=G&yRP?nىXWt$%]OZMf)%I7#Jϵֻ6? ,Ǡ4Q5:sv]G rj*0E_2rRdA샐JM9aWk wc;pbu) (":%v"Lnݱϡ]=[̯rV)>*s:'-t#8PZ@#f#j$Q7/iKTOu;c@$`B!FcH'TO~cÙd:r(9cG敃{:ٍ9#T=<&B(Nu $cY9~X7Tp]XQ !HXVpD:kIK:&&OH:J}Lbrfi ,8ƴ]PfXqݨm{>&6mzMi$^ʏ"r72p&tDX~߂]0 5 b1+tѵVT^Aŕ2{V3U BcFR<ʗqHZpY+Yh>/_)HfBa#Rr=dB>M 5t^J=Qbf-dNSU{Tt#IbE;O-* 4țIWO/W)M^a 2Z!!܄:+d!4`ͫw>0f.?Jo71Cf׃2PRODp6$džMVߠݕE .q<^5=6Y:`Do Vx,nk|@Ha\"s&L3ԣC M%wEc˙V c?~! o5=pF.J |X_7c4ɡBbv^ZB_Q*%O=Զ.Z@n G:Ƌו8LlQW6ՌyᕤJ=ei[L~ݷԒiv r'3*|ˎUJQWrɯfk&C^^%/>S2]uE+ơY{*.6GZ3SvC7+US {բGZVFOJmryy"DDw9/1CZwuHT"dݎ>ڷlJ4|C`kn7[Ww$9ʞFr3? <bQ:bW<؉im5ؼk7OU܇\w HAܓm!robY-O[Y~B~Q8ibҌ?婌z>GBQhz)s{V `['ijNFٓKـZޭ:,%z$NV^uy<y7a96 "&*ȿl2]qB^XSm:+ta{p9ns!FvLr-%)*MG_b@{4dX&- $UBxc&"WG/ 1ɞ)As@-Π+MʉDG+m9ߙ/9Ab;pw1;N-X8X ;^'x6tCoC׷0@c9T `~yMqWY=B+[kLKNms7Ť(h`4^(?Z뤗Z*َ_7ɬ6]{*"YuOAz DǖfE Hk:{㧽x"xeߵ| yX5/Wɬ>rj Zk7)z%;R~v%ҵ ~UxoP!xE)1&cvI7-Y~a|ӰěmF5j$}vs?SAKƾPll5A!X^s;.4# V&cWGioQ7VŤ%PH?cW4gPco~SwQzUr60iXQ |ǼqW hݓOo(3 K_A5Y1a }k']蛄ēO.ߤ{Îw1&7$|pʁegZX%bߏԿMt͢$`ަkס^`kptagTq_ExPw/Pxby >@W!D+eΟ Hc!37)ELW4!7}evtnwߣzVއ%bVyHhws+)+ײzkN=Fpq`R!} i|_ 0*sWR~G'!h“Kшt?y LR2[ x$D댵PwK#Yn{( ٕaJ[r9{^(N (6O l tK }br}f K )çg6#JPE.)yb)lC!JSJԫ 9OS=3Uzpaρ݊,hWE༊hO KaԄ!YJLqvIMz3ʬTOcex%[ұeֵ(sxkSxR +a5 -7 $bΉlN1UE A`̒b-"qodf{/N_xOY^LEGߑ2 v<*O Ĵp6*l%q݅VOnaj= "/E?KZC 3~@b$GwRx2_.8Be!i@D+%iL<&syZ'/P Bekr%4=;TM*-v2-l$8'ۘw˃8>'^X|`Ṯ`Y in:+->_#!M'IPy ɯ4Td|t;V$O#~zS6v39nr+͇ bYy@6j"]5}P|nT(0\jO KHyr?m* ]?J:=Cp5=++g:͑NĄJ[ZgZ)H|2I=pɼ&}3$aq}tGM<'4t19W¬|Z{B<囤? 2*%עOi«ӂiARi(9.%Ĥp:r5ƎѤۆnJ x*j[$:jQcXK|{z3< = ,vսQwy=82([(;ޭ;.DjɳfjㅍBa ܉5*̓nT}8/Ri; J@]?k`OYZzy |MN/P-8:c=qC\6۝p lkNуla1?~žL˼j}aͣ<=Y{v/zz  ֏nHh) hV\5B&;qoZy-˪FiBÀȉMYU$))=˨Y*Go4ՖeV%!J<csPs^|Gt l`bAV]e}{ڒP(m}.gB\R  md&/&uF&Ѫ9~BM C!X\ X͑B%I]ܓb@D"](9( vBS@O2fbY> ,aYѧ6&_ Y!rE^BIE, *4jt%~|3><`AM-49B >[^E)'$~.dp1bx Q= KE>P:WI eLKDfuM6-ࢢO#: {c8⚍J⦥N0:Xgr+p3$ܴ ճZYL߃rrҘ\P8gZD_v`0ZhivO)bь h"ұg\Lƅ8^a=\g#}}̱ `ݭ+tqB5RJgU,7qRY9ќϳʏœ ?WE4N22)xo,voW'׆3~J^3Al-I߬gPUm_DK8EOC$H6Sy8^Ƣsur UY!j/!ƚ1BhP Z?\S4G\t,OWE)41|wm2(6l{J9-9DpSÅ -طJ oH[:fÏ* XՔ43':nYUQPujye} L8] 2PH Kyrn`vJب;7pIOغM2ِO_|+IϩbZྴG ~NMXg̵'  RUa:Iy(mDk]c6yᔴk#*XpČ}A], Jt|&[bPfLp(5m㉔cȪ$_Lq\,mW )y,oЩj [*'^e蠧9Js9_J! ]C}֛bFts8F΂UDlwqĮW_Ӭ)Vq8k O}{:pHfO/b)'8N){W[P8_|Tb8ZM?99IL*}\LHF'_oY = }/B<Yc*_1OR&z6`:ezPtV">)Yލ axR=`QJl3>w簒ÒBfS5`w2=epx$.a"1ޔFQJiP &tsVs0*֩ʪg[t-q[ 08Y4buTՐse*-(Ut$ FCam2ERL&0c~@2NC͠W{dpxh@w qzvG(Qh7d@갱gS5*P΢}p1YC}&`eHD֛d55JaL|ȥNxkL1[/-}Z.)3D̀pkH#$qerZM%v8mNzȵJ1w,2).!`/$m/d{r$ ɜUƖ/-g=HZ>U#bx@` 2G^kpᧁ -txm֡ھFi qغ}tyDž"!hHgv 뜛mX7_N'eoxj9=f4!UV|KV (PyFY"W{;`ISlX Nαt ȯX 5s!KuaK|9\n=0 GYCD^WBw qyB}ȅHnCA{% crta| {ZV챾doޟvU_.M c})$Sn0s([ mWnR$ap 9RA-j~ st("HrGZ8G+oXk&{jUϲXIZ=)Zmӌ7/fD)kۑ8U8H1d״^-6qK6eJ:'jtjz,WHcP.,@ꖻ,w} W$)A]Qe4-wAh(bAj wvcrX!KlnU-r ,'(\8 T/sZrOTYfOE4:?6 'y/[8XeNoPp(0 MS~0!2h)q ?2spf .PͲ/.Ͷ 6h/훉 ^_z53u%d2K; &5@wH| )VY5,AIˣ0]g}(:BD63~TAs~P$!2 ?dt -;GURZY5Iqd=%n=VW7&qCP6;7#%,F7 A5GHBcӅ8,,*bcyfX##9YU}M.3YZMû7?ḇV~}e%#Qs֨ rG"R1ݧօI@Y.RJYqδAΊFy;\f֣^ p y V7$oVEs&Cb&N"{Ҧ2 $De$j1JC3^Ux2/z+dyoJo+ipEq"YdU#q_rPfvՁ+~h4y"#@;db[>-,P oA/Rj6HX}S?6JJt2ߕƝTd?LY@-ƜͧWe%cd 6~ouicDEB?/VMI*Z4ZjAǥv|>X,Dƚ5H.m߭<艁+(d erA-8#<]}A& TZ qv!_R$75L"xbi^LJl; _xۭGEɸ1uLQ9rBygb4(9IGJӚZ!Ǡy SOi +V 빣Wqb-r'WMQx] ۼm?q(!&ERKi%a(l#)׽l/m({mPZw{|5*w[ \3nsΦ~1EW9\ϼHr[z&QV U.|jXw1\F{P( SKl\)h7W>PrE~ .0n!0D~8#㰦Q(y ׳ fc5KIKyqv2Kxl|l3eJfh<%|5UXhEG\&sfkfPns|a`=D:8ۿN,:V\$q.1& ˖Tgi@uY/sHy#fݵf<\}04zgdiвTCٛK';Y½@7O狸Lb̐@ƣcEm@~yLwqF,ɚK75]b6R7DQXWW<-2Fn3oXˉx_ Q5fM;X".%8}w%7K' I8R*vQ|)ՠ,LXZ{WCZѰ+<ó e]!nfTvL|(|\N-Vl#ى0j S W@AF?4 ?NmSZVP `"幕55'xзAh8<={wᘒQ4U'Hwo{(6qY7L[uOPh] B?L@y؇ɉL:TuGDdVz=]雤bA֡tȔ];F0$08T$# )e0 AJ>C?|ӀZzY8J-? VSZ/ψ͊qKtȉ;:ㇹl3 xqPqFc,]TmCϋ\ەuS3Z % DgARw8Aќ9=i+6e L9m}p-CIik187ĤPy\",AK>laԊr 4Rguh_OQɪ5J2-8H_jZi)}F [I[ ["ہu7/KCiWdTf59D3iqXMpU&%;HtR!u@N*Xx'c?}]5a~+w/|!LGdFEud٘ҬRl+hq;h &/0ʉ`8{TFO62>Ei&;eOPREWKSȭmPg.O DZ'.y qW 8v諈0Hڵ<wN> p$bS!f6.f[?Mv%::@~T}Btjq%+[ANzed47Ⳑ+7.; v@"7.BmK.qrAU'_&j&>Ta@ntN}3[b3s1;;Kl}UH`@\EL Fy^\:&5ɟ<9Y.i&DŽ@k! l9MIJ.qc7Tv>$d o:Db2H+?LYC+wgY `ѪN g1Ү/ !:J >ep3ES"{PǺ (},^#/`t _J/wctPbk0+!Y1[-ܸb13J}5+5Qt9RIHC]DG~7_al9#SˌnIV7o[>I[5``)zHiL ༳k\sN{@vtFQ’ۖ~957W>}TA;)Rgʯdihzw6HRKW%)"IUwAְiN3 _XIvR8yP&t۳ެwVA< UeևlӝSgjNx8FA>bo'pSUu=JSP[OL8fSƙˈLBI*pĶs!CElkhC0}W˺mԐxdXQnH@lZ b-^"|A9 ߾:vwp (p^%TBDԝbDXsA[ԏ0lUY~xpl{jn}fv7JZړh"B^_}*JH ZGMLuS'` sn]5NaWjy+k{BGr4U& =;3&RDcoQ8`g4HvKK ͮ_+]D]з&nm=_w{u 88Tx$&p$~b|ni[wD +J)eyVp+GmQ k7ҙhxtj6 ƾϭw rn2gܤW\|Jo{HN4oβe 6;Ҿߨ)1FC3NJ=B\/23rO?WmV9K dL-JuV˛l3<-K%9q7cyއN7O6bB9='5>{Ow[f=ˇH졚zaCgD c?Q"CCЄ06Jm\r8(L~839N$ ÿ}XR48\g;P6V{,,=^=jtaI[t$<|Ww?9N|UțIF吁[Ɂ1ӄFXX3e&nh($]aC$G*`Fd)0Rƾ#;0{蚤ᖊ9r/zvV-p7q|$`#^u(z~M&LooCκU7hN9yl65?5sF0~ [2,ϑ\fA8[QYdD";󧔌z.j6CI›ˁ 1nf Ԛ_};Kla%Sgz| 7[n2rqO1E[ݨɨgÜEoh5tIy0`ѵCA#dZDؼʚuhNJ"PI-ci 0w(8Ԙ`LuD)qǪ#OdyXW9dRTK3+luf@i"{/J 8eDhV^qmR:N`s +K 6DP DJk)4/ki?pb59)>!2ڹ῿~p dqUj!UkexډŽ߱[AX !z)SZ8fU4Z|km8@tb"Et ^Zw 7N{;K-nw0gmjr'pW#*;`7S|M _iP Un9<'}&_mt,t"lˢ/x!KP)մQ9NgWTtaͫ-9›nl@ʎ8%ki&qaG\LB(Zc?La%-H.殫]u!wOBHp#DԖu4ֺBI['}  J6J{Z= "pʹE ov9h < ʺlR|c* *Y b{#Ve1 Qjn?2E Hd39ԟuCȇD2p9\ݞ`u uc3lXп[q)^Վ5l[\c3$8G$,[aKRzA(_eT{UezgΊڴq狞Am$tJo`' Bzlߑ!IcޏzOTY֕?1q(.RuH6涍s 'z/Hj! ҊKA(vz:6 I#뙤n“fo(0C5zYΘ9KcGVڡA!Y]–!yG߲nCUWXf^x 2v}gg,r瓠6} oώX_\!NV:܀);*7ljeZ@:í4A[3I99AKnt!Bxk[4vm!leSD~4IG?C8%GSe ] DŽV\Hi uj΀}!ߋxK.A .QD>=uΛgĆQʇxUF6ɡYQ!ce9w|[sk{ؖ3xPqDgY5/kיRh^E5R_*"%4^1/Lkb`cPrc ]ryݶ>Apڦ ԫv.Bx7A"O86IK3n+,QM}_J]Fp`LT-sTJBS K-BsOdl4g$UY ݟݥU=KivXgqrLVxҡVӕk]卥!Os$6 HzaW7(^CT@ 寨;rC赃+bzVȝV3XQ|`&ɿ kizqtHQ#{Jfy=YK+i`6j#f@ ٮOAŐxS:EAysP[ HCm-#2g/:f k=w%VD^j $/sG"3 \uUUr(950h& `D7lڒs7j_BX5&AՊS]%&& -3u7 5ޅT~Q? ''˼Q_=*j7bsccdc̡U;UX9zb'h?OΛA^+ \n%!7Or"62nkAOD_'-^fl& JDz/HՅu `gkeVOeldw/zr4Yi|+;n_D,JK7Mo) 7ׯԐィa!X.ԓ"/H2olZaۜ טiO\d m K)OЇ4"(VNXFhՁKO1@d盔\HqG.q&?fzx jt\źJ@P"Zsm*usaZqGTa'\z" #N$`kpʄ PTE{&u0X&BЀ|{ Rs^j?;~j̨%8mѲM#'zYqʩPkGn4/, /x_Wc҇v`r ݟ?i^, ? LQUB ֑NARQ/3~X[ҧTq ٪<`&rgwzŵbk?tbJ4AN@*MՋx]z4XQA`]rC!dȩD݀qpE!Y r&O?p-T΋vW l&QGA6yV颷챔-%Lա_ň ;j$cK"ί#Q=kA-q]uV&+ yomQRH|*'QveTqi 2HV0ŗlD\]ZOU-19)A $}n !,$>sZBESj\l?_&?{Q&/ zϲK b{?ka *᤬ &ʻV3*ֈ:EEPՎ_hV@W_ {G ;e?Oi+z\ F5pw^-zjҗtp|RaxFr&]=2:^^}k(s-KL^|%wL&UG[0b3 zjee9x dٶPqcWQS>4hAW3lEcy}uu;֙Jυ)j3꙰AgW3]&j\~ۈUkўy#:-eD+6p}LxMڀ-&Ժw'~/ZVsp(E`XP#Q$[R=ޅ5Z>2|*~g0e,T(QX.h13N!}$*"`<}V 1+HƉROar?/!W[#b>Fa}긿0:1텄.Lq>P9h}wϛ_Ejh5%8Th^ k9tZ=f06hO+k&%ӷfj}!$tG3#ϗ7dc#Jje GE}YKGPtzpi} bK1ʭ"dFw$EmCBԍD+"몂e~$k饄:5&W\uCf^O;~p'4Ad\ ُ]Dɢ欤PcxZ^\V9"+ᚲ!DG?]:?]n=p4?Ȍۓɸ]FQ!&8f9J-FeCft~ZZA%3!o{F@GS {jpϨ韀;C 3[ٌW;\'oߙ "iUV3bi Tt1ŀ0hw~tk&4UI wD;2D( ՑL~kA[5{1Vbaφ*uͷ[RK/=¯F 8-#&PӊSFEm~_`" {kRO/sKL-QPK\p,G`T&ʓ :#QƂ%YhCNu,lPQ"X#T'A_ñ_f41/ԕLi ?Q?hjiacfx zxl'cW$ H&!)eFrgl-h]e@x?[z:$56^N'4jrkm Gfi*jhsI{($qKCGhA1S~[ђv=̄{LG4o ->`ӦIl~nRiH2* sһΒ*k%@7uJ"2QO|UB6-]d._VԦDžF@pHr܃]0HB\5{=)oa&FQ0kB[/ y BPLpâaF(K[ W? {TD{Ζ,T 6i?IVҟk4ơvT~ /WǙOWSQHq'!)Ctq>2ƈmeY'*bN>ߔlF!F-{AMԻ<zqnH{cv~4S9yuKsjKE;$Δçk]NJB-q-::[SH=2RI :I 2)h03nR|0ʣdDv:HK\"K[%yu & RgeHE1qѣeUȍsƼj3f5Q.͞D=`T!V:\&<ڹHڧäi88Z(؄ @T[jϹ*se8Ȳ{r5fG0>8K hY 6;k=QLǿg1yN\X9c/u'":脢z%^pl2;7DYt7xuKEFQj "UtlM$YK"cM:Pԍ'EDTk 3HsBg%G3i>?ennvN{yrm1x&v֪_ A9A[[Xꐯ#kFTK& 'Em^q>"08ń]q~n{Ta؜)^OٷDhcJ Tּeֹwk]x_"5M?ѓC6y}`ЧvJ\iQA^/k9do4pymNьIXm6t>ȴD 68]dGoB0sCǖowB)a " U''F|y[#\p.<IűS ;Տuś%wX 2BgQTv{?yJ|%?P:NEF~D?Guwb6bENG@jH(J RB_S?.?5?jPTXZ>t1RBɃT1e|= } .VY$*k+4zͮ [hVKh#fL J(盒ѼsY =8Y3TR&DI+"mTMrd!ao?2~YxzE?O6nwpY F-_V-[b$c:s=:M- 5OUlC޺6NͱD-#}W1NҖXj~/&˜Q{"ƊpcoN-kM0$sL+ݷ^")R_ܯܹk]7jH,oSHyCsȡ+wڃ-n)@vCFb"HO=h^uv#g~-.zS e2lxD^KWhc3Ŀc>jtW|qS'w9@ )J.6T6lÄH.c h$' Y XQ̪ο{>K/-; Z7 BԿCH =?7\|6,*jgz V)N`3Zo{SA147DiȬ^8/sHVLGB! vŢ AIBŲț_`#0C/..bќ9爊 uC7萜ja,klb,ne-v#kbUPqqѨoG~x& Q#gy 5*JD Wǔ뙗tJMeXݢ^424eXzf[ .Z[:0P^¯;:/{(v@|eLz$.ߢ{g{ l{ *eU5GE2E`JsA^Qa\ږU|7;ٗ[ԃjvt/aFGF tib35eoozbEEz]x?Pp)+76b Lč(48m mRʔo7ū֪7#V ̙Fa&Jz!|3,jGpaK^ӷ(n,IbvH`n@ś/hx}ܞàf ef0 G~]!zyff{s"Ӵ;H"OgKd0m#ѯ16C7HxI ޳2.Ă,? -D`ْ#?.EaÆG `2 0+!2G6XV%Ts;ԆUv]-e.Qi{xEgF ۞,1ձK҈(=`xQvxJ:4~}*2=po? KU1RP޻qndDtˣ)@&mWy11\Qߴs+ {n(rKR &W;ѩ*j{vɘe3 YkJ(|vw`&j\E7@94ݲa/χ plY+ Ҋh_ٔjߌ<*~] AOZ~>XRdTPx ׋/D' e"d>9W kCt$D:?MҌSH↗󵁳ez ] pҧZ(S!r6wgC:N+S;3{)@XU;` JoT빃&J>lB{CEHK4('Z,Q(?}Q r}SS'JEƇqdipJj66'޿#`Ύ0M& H2N~FFjҁ( w.Ba<,kɶvMEuk4ט$~ay|B;vGrsE-5URQ ks:I@:qg)0.r׭7f@9#%߲{'2帙%tN}:>Q0`؄vfsҵ+<"V*Ǘ9x1HzV@j+Rܢϐ%ke$ZyZ7 pAcE?y( TPCCcoDl`NG,_-6I4yu]|wu,q'iFm ka^BZ8ư{ )<V &TD@&.sLkc,FPmjw1mΧ"^7fK;w v"AژcV_ L]m2Hϯw5\L݌<܆?H4q.'R_#!=˘2 To\b,T KW$HFJ+5# Kn/su7J?+yK=TiC!]aSݱFQ`OCYG{k2b3GtYA+%4K'@3wn/,\X_wNCB]BkG&ޓ!q;ae53ЍTf)[$|Ɉ@|u`M^EW_ot'ǯ%X]O*`J}$cc`RgA_TsnЈGe n9 ;D-(:MlXl\9"twV?M~/=M$Ni&[Dg1iMK{ k)VC\_Q,Wq8\LFj"<,C.`3t bmi ܻb'%=7&^#FWx] 6uqoB)`Mbj:~BČ#v~ŃO#l81!AQiͨ-&G#3^l qd|ϰ@PF)}h%Z>İ̭i<L pןj*py` /F + k"ЪgDt(Y.md!=˦Q$`g*D1sea/nE4^Zn{qN~K=|_໮gX;儛U&9T4vݟnd珪KzM@l\U-rԝ1@mfmQ:|pμ$[\Hk?̤.h)JNUѧFYbݡ &fv{xf'>xIe+t<e՟qU I[IiH$F,*l|>Q9xm%;Ϸ s\F-('YCBH#c</YK8MX'ҹ D^DCf;8Jt|q*2rby'4)%h|)!|M#%Y7IM`o!}y`lAaKo*D{`2%qxz:8^Fb"1n{5ȌLo'ʱ"y3"^gt|IgaX[);,r\ 5Re'+lysJ:,]tB C4I`2 ꭞHAKj=688X e)<ʗ|^F1čȏ,Zƅd]Ջ, OTf|1; ~ n@伇uћh fg1l٣Si"\@tqޱ볓/+kHo3ف}q=b0 8X\d5.oHyU酝[A4yn,wHaU[d3MV^ވ%+2[ 㪼+n* ՟"&pq>ౄ/C~7p2؏+ UY_ l~NweEr@0ٟ2M';3lD8K@3UI/sM4IcRaiYhMMUe]=Xi*Bn! k<\~>mnf:-Ͻ7l87$1\ ,.pd/9m}lԮԔM< mېPq/oIeUuAPcgH_QwWkב /Ob{8mև7pfk2o)`I!#Q(t`sF،pRTJ FheTaUAy P,G`2C01Co F6)*M2NL!"dGb ty!q#h/F!Ye?TgZnUlCFDx6/#30h38V7aOmq EZWؙDƮAw@tBmOoġU% EޖVp~ ?&У'RV6x9[_J-DH͐[xGJJF89.BE #WH48nٯ8>fT^)W M(7g`4lP=j3 &PKj f (;3lԄgNvap-E{n5@Oє-,MlP {fx?Q7?;8"R 6 2QpJv ,d0s'UL+iry| 0>p9 yJc J(8c XKdy~_a$WؾnݠӨaz~gihU% 9?$YmӳG;pɴE@uh4N. k-Di3tL^v/B [<Mgwi?:jطd-^&gN1bڱcZ,p MXy=p7r@5z9 M'u= gxIszrخUѠCӾWn:V=snĭ>y%e`d>4APIxY蘾᪙{S ɕ{,<1WQ-g*s|fмn/*m'P\-s CHxXP)Tp פ+~~M/[`BCMڡZk+gR,nBl4Y({?])ఛ'WsiV3tu[Pp%C\:"bDږ}3QljW-EC4^;)dq08Ƃj>'}ì6[M V1BKDf:NpLj(njAYdLD&nVKW&XZf]&dqp42oasswwr7CPNBH$.>y@-x=~o8}-nege(wK(6H7&0-uZ2(b=s,vZ6l5xxQ$NLT8 5:fSL!^haS8,nP<,c=Մ .*p(p7 1%т'*pfNJ SIZhlmZIjHE= ,m(״[φN "F \q¾{]S𲴇0nk^,KGN8!;j?ֳϔG,"^l /Җ+UT01('nɎPHJ3dЌ»gb<w7VYS?#VU YǫIK$uWj6WKTYewIkl>p]6.]uz8yI51êoe7#g fGN쑭KAr?$/]|~Ira^2z mHA.1;W>U=yjXE3I*O^sR_)Pfg'6C3l1ʴ8W2}+ǘjlpvyBn)y|vv30bIΨ>tͶ#G=.L\ظ3ve\A8b\pS_dH+)7dV;S~GPk4<4R@eݕyqk8)numoog+\j@.kv"tID6޴]A $޿z5%|Šrr SeO]g 7Z/iۧҿ59ύl@p.{á=EZ}6~ޣ2&I_ "%k:sO^  ڴ9,"nՊ>N$m:)ϘVY] uxE4.ۛʪ,[UNeVN]=&Wu| e|~ 4 %VO5\[0Aeh^.(S ~^F*<rZĄ {M gJʄGNjV4fט!Jm+^ߢ  <.z߰mvIwQ4팳?:'rSJ*T^yd-w N@ ZKc|W?RÝї'qhvze/‰?F*ڣo6O[h,ǹVr 8ւ!4n" H{!) +æNӗ웟)w #mhrMӍne,)PqcZ; ˝w]ݤy<1O/#DQp{ZNyl YZ^պ Q :꾲O& n ,uS1Nߏ(Q9՘Г2mjgIZrM뙴;(zh6b3d'QD.˦Qˢ !Lz9ӛLeYwצT4qk)/!~'}Cs.'X5iX7 OaG=ĴXx$ibV.n(nH7}I(DmڒF5rC2bL FIDVPt+3gqo6P g 6D54CŴ44O1X 9d]ks t41guxQ]_b͡]>g='e Trn3d›؀i`f. 1,԰xh23¢䘚.V,B§cr_ ~D0KRyȐH|O&9Mb*Y`4lhn"'Wp80:6s kǬNm 5+a2{JH_!2X g}嫍|DC|lIT1#x~Ժ|!],j¬oh;Z|~coBvX:?bu1^cg:dٮO2$pFbc,"'/8CJ3Ӹ_TR7 "<ۥ+ZlxSs3ŷ l<*MK]][£h mMQ.J%.oAU&ytAx2=> ۷yjJ~eJ1l+1L4+/tLZȘ?.]pQpx[J]* +]^Oaބ6O֕ogkLߚY֘X}Lw[zuk#V50OOI~1Q)Eu=m(Y 72Jh=iW@~ XoT? x)$8jv@ ˱N[Q~\@զ͓['෬tIEB[Vt9(aLu SHnš4Fs3($3>F[֠:tOcD|?G/Ml7Ծ:e['mb?5HF&YBHa+aRQDyy԰ c^CVT8F)a<ʍBsaߕYxDBSpP҅9j^VjC5[@W4.->wy:_+g*}AUV.ӓ xS? A%@Iv뎇$o?.ve>D*UoP"ڻKm;1)zMpamtj3myeೊk6=L?ULq1>'hV}OQAz?/YR:0g'mFEbկIvZX1?LDDO[!AumB-Im4^tP, AT peZT?WC%rh#skaR~]֏)Dž%>}Ȼ^o|4)ӈVanLw:F8s K8O@W(Hxq+Lz9M h2 )~a8z ;4V#pF+/qE r$FݞOdXQiB䷿Pkz'Hi"~M[hBNDJqr,[P)>. =YIЛ `Gy'lyJPuBDM]{`yj?`15͊GN:qq2&)}tRȕvlGږT& N0aqC[9B? ASA^?QZò9b2~~ ~8sy\r'lgPekw(n0"́mX׫4%=)ⴱ=ӈôHCJ$TV`s q:} wcM1VKdŞ>N/։SyWK C7&=5l%S(d}q0/ӂܥYm/7i>:Äg KcK/e]<ʸů*t&ouo 4&خ [G1p:G:)+#9D.!zvT6FYs l5j4[q0J}Ǜ'L0V6:+K4 .,o!LpV]Ztp_)B^'1wRv_J<=b3ħL!q [Іv?mbT?'RDӘ$-_Vꓮ~c?f!Nc$5v`WنUNLxt`"Q ϛ#u(CNTlWX^dYj'%HRcG=\Ks5(Sht5FWkyc9F2bbZ̉_'bs ˡ IWsF x=`}Hr]FFN`/3Ҫ _v.1};'Q)h0m<#H``o4rV r q$ +lǶRMc`*7 LFw T/ DVŌQP2q,phf:w^JqlN_2􉺶.R\)p5m-! t ϝ WͱQfDj˝ ub*;~ ; .F{SVj8[/8"I.ⅳx?;7dX )͋ ;:'nyP+hg'UjaE ZcoVV[^94/my/X`bܴG'~藢@EKYEN='| `"nVkFi}S70?n#:`?0R&oNtB$ݒa]P.*Ч6pfҡ^Z\f.}W7, Gjz;#_a-(bC_bݓạuI^Lnսy~̓1 x'ϭs$p[3\줔Qƍ.=rH`NY-4DSB[[t78+;"'\kVÓ2}ҵVrc3[/p09g] D~ZHVჿ`dX R|!ǘ0h7fF9mJiN N~U>Z~>-'>޷&o޻"Q/n!WW/S=h[bu`h3҇?}\-NӴR| n/U"Gu$_ςHFX| -OtT /g狀="o f(/ߪxXɨNǯt(xuKsZ|vبF!4v?R"^ %b>lj;.Nfï?&!h2+]lư LnN'"=>Áeʤ_r}݂1slUx j] Y7`jQ&boA;VXʘΌĢN# GV2mf:xÃ17R2kشS~5n+§)ˍvep[}ZX ǵ[Mp qԴN^;SYC2ll !AY}埄6bf\E_MZs #3)Șk2 k-jQz 7 LxVl4ր)wYYb VNbwQbNҳ-3BGo<.:WV(d|ܪp^ϕݡisZ1K yhX_J|a8Grv"aC!# h j;s \;B1Ⱦpl0z:6#Ⴝ)0ģJA|'y

Eg偆qfݚ똯%cl}xgb!OI%:^S,G$dd˴T(QN`n >Y-3%c]%Ⱦ  &2.f,-+ڪfl3,'s>F%/˻_l)k`p)rF>qV>瑾`JR:L`(* l,^N95}adfeʖ~P6'= SxÉ)VtM~؊?(ZRa:5-]"Re7x{h E',ƻ/'@\+AVvN#GbEc"X}#xGcay@abыًy58)!; y !*|LdY@=C 7q,1N!ټJxst tg?ڋ늠ߙ^+> = pi{P;޳f*&GLVѷ>|%E䂳7a*@Lp:&y&!rXA>Jcx0X,ԷD$fiDu@ER›µ<&r[NWk~t&vu?h❝_tI; 5jf#Hg!11͗OqA^H%г ?@ܗ@4sYPCg?/cAaB;$n׹LlF՗|G#_TR.u!e1k ًbҤU` a)vG?IpF7m~^q޴TXvsUGfHKIE '즟{%c2f4$G5)EFt4qY)TUѬ936Jz@,e3P JHو A }H=N6cהr&v-ԓ.֔) TB0 6<ʽ5@+&,ҕ{N7EKj.=7Q:M#ْ,mT`%Ët@%3MyzѝX;'4*Kj I+ C#e2'o>v+2s mE9;G+ֽA?aTW)91 Ll/残 YEN׿&W>t~rd{kp3g|ZKb34SpCpu䴊Ppʽypx[GN94P vDʥ$5rbA'hqoxz49Z4Ȩ:n`c0J?E`v(|Ž\?ìҶMz9?r"F;$[?W^ɸD3 3н"+r=4ҭReƚ"wTlyEx[gA4FySݘ땊H0hN#W |euvtCRq?JjwX1G 1xR]T;j~p)5)`29i@EAGY??sF \!pr5[)dH^BBCE+Vs&N UVakn`8SEQQ}&睟U_esy"] zSzۿ@8a1EײSf7!?AjEe9zU :!ߓ5&(/dlG]ʂiyTr|TN.b2m1X=-hl'qۈՇm&G֍s ٕX|Cš) AuڅY-Gr`C)L6. hv@hIw(01vQOЄ-55NiG&e K&f>&[xlԊcRK֤l|3սB&`̇W^d8fyUST>4UF֘nYZ(l)C"G*x[yQ`e z5|N'0k!+5C'5np0L͸-v'U0@`2!s pg8]>b^ݏ(,N 1 _V*MDňė1Cz Ulq1NubWDKС=tOUԤP} YQ(!$-U/]sʕw 0&l%nm ;FK3%^xM"؞)<) X@Aow*h{8a6z#ٳ+{*f߃2~N쉂9]eyw+;/L{2eխ[T˄4'D7v```3M*T댉~qZy um~|o[*˗U p)9CY@1}2: S~ 5L["Zn,/ P'Sc @R{:G4,;|OPvi46 dն@6n81]F3G11udt=Q*mf3o_-{s jZ~)V黓 nky ,ڄq{%mATKސvG)X/n!J'%m8LzP$/8ۘ05V9u@Wk͚DB9t.D".fp;=O'mȦ i!! }-z[nͪ4ὶ6cK>s0ϐYAh:ԓ28f a/4k#荀!R},[x ,18v|VYrR5`/3+ˍH/ k0O) lt [xPESm2GP3W<ǹmЛTGKC+٢]H}.vW-ܽ݁C1rxcys4eID 7wPl;8I qx^-n_BiM˅e@L%4dnB=i9>n@RG]Ck®:IO/B+D 3yŞT:j_۞ 5ne9a]%:nZӭ{Dz6Yaօ,=sk>u&!0Gd8g8}`mr&팃-,8MB(zI )-Pg1r ܀.Y'x{`!5W |W{\wɓfGfI ':qŝbpQTmr=@ݜ`r6%k )~:  l,_SAB&0Kg|Kw6D,e(7~z _ Ӏ(-?ME.60꓊Ļه|f?naGEeE[AQ'd7I<sD-`'M",`KhV=C)%0='Р_g۟Y ,$"\ԤrOk$^Nk/4b߳ mo`wG>6;Bȁ2CERe?f,-i Ek90c]g?TpMtXmZ`SBEm&@k`wB::XFBP;"%[S{S>3ˤ:K1 Q~SIS>Ȝ&ߊg: `&±n]W))蝅TʋX2ewcnoXx&cFd}/se%]#}eUbU1m~.F Y\{&/?C ;f]̴hԡioyoEb%+n3I8eJYC2>J0yӐ㦐@Cx @ +l爛odrTY4]cQ Ysźut Bq.zQ?GF 8S,6 &+6 :pD)?Q%JoB\lepS6M(8u?exMD솪~1N;yЃCT')M*y!*3O!+KeV~d Q6PM]৒èdM V U6[ g;t.+eHd1D;N;/w6>G5Tz1jl Z划 v{V̘Q{EVk ;!Pt(#p U LjI7-*d7,O?KUhxzK\c1ך4lhlspϏJ5m$ͩA}[Uԩ0JY-e**YL$Q3ɝ3=s^Wj: J2۬dJӅ>r ɬWoMW7M<7SF-u;qI4uzY1Gi]R%MUu+AmTNÞ+Va6?c2J,;3a~?z}t L2Zw&Ts17Vc8{go ?[9Lw&6> )tT^?H:%15KbBl-o}=qu< ^UNۃB`tHMt27SJ؇q?/ 7DKs%/iqb|!'< ̟oF TuW9M[Qں::S*S-C7 JdQ~ܖ jK7"04$m<}ᱭoϮ_Pa'z:KJn!Έi }dKL6zwqOF Kuيd=:[/zZ: s`_!B͔aT9 >L!W_)dK} 9 nQN_nϙWO?`RiޮL3؍d5BU$혞 A(_AT韯3JkP*C8ȷn~`"6a)MMOIM tR!w_kK##1q| 4jSeZD㒙Fg`1EVO(7z')~K}~vSWf(#|OowfGLIW$ftq]qb& =ѻg%:|~.CC"ځ ;1 6S=5…3(PT&4:Bom_1yhvTJ<^t53u}}[J$KۺWQwgYz('֮Scue NU>W15Wl x'@1w t(- [9jչ ;!\>}3-0;}Uٗ5 #D;n>~~3jd5Me;^VFbg>湷 6 3@sQQ{f# Z8ʶ%A9{AxT ]LӏXǠPePG}X'kτΙ6;wv~$ú-1XuU4k\TyJsob!<09x+^.)P7&4A& D.h$۠ a0WwϚ66!vqMr4Q1} Y-Pa" ߭~W${;w5ޘϾA:lmgڽmFgɎJ8a=HFFx@Ti4p軤n0ReW| ŭZnYS6E Kۉ@s]|c |muJ1ݵXHKd[9Hg?1C LPvN6f16tʦju05N]g­nv2<y쨃tMϻ- ("z&dĶVn ( )8 .OcXx1HKzt4BsenI-7)%;+4#Y"cDE.hVQ<'syPEILN(Ls"/B{䔞Q)ki>[\zˋ1Jy:iEeO U!I7><hͿ7o vϷPQ^DRfͿ$]-UZ`.y$ vT&z]6C6M!G0L? Jcb?7]~ @u \á,NSAΩ/Ŋ7Apen7s$5YH\^˨ ;C+۟X|]8#k$}S|Vu_f(7C4KW&߽9'9=?<947 ? W: drڌe$o9fa^|,NŎ},xi0ٺUҒg^QxFJ _9ҜG] OTmEȟJ^PզDwv4((9vGf$/i蟮s$FLKd ǵO6TyXƱWcQfed ,}cqbnid:;&"W^ isYӝ]D߈ݠ-kD `3Su/큹iZ0r$K৐j -P5;wpr NP[YjrjDoBlM$< m{8b #RVV7zhlPۗ 78 A)[nPRFlէWKa8Ͷl ./MǓӡ 4tX=qRrޱ\xnW/7g$V# ,*˙yٯFTbF|f`Yh`ӵga#Ǣ=[^O lQiw=GyS ́;劧6m9SbW5ӢyC _OT:Uʹl"2̢u֣y%ux(0 ;Rx[/K"DqTdh;e1Ӏ4ӹԱLvև4TOjBU!YxE^:`0ٵȋ erJr5ٲz202>2}у,A'_[) ߯bʞkgufd"`6W3n0k*Fnf&˲Cn~ހٺ(`Ji&~U>^: BP.?6X'}A=)A3f gX Y4 R$h? YJ#OFz-\n, DCY]LM;^#ǩxCuVf&,}:V.ed?CƩnhyZi;59FGago\6C [uk3=,^rr PuF{"=ݾқNDc y/ Yq78IƄ;Tq1ݧY"? +RSS0q Uz:?-듻()Z&* $w͐۞!@\q)e) ~rLW[gI}+CްG_k+{aB9wl!-Vtlj uƝdk(ׯ {p %^+(FMc_8y{8r;Wp"osYh$,z([Ng}k'OEtBj5]PPyv1k l ng9= u@^oM(B˕;:+JJXWܸYVrNл04g ˻q7R?76>-q5}~B3C3/\=Xl ׅG>ldy½Re kWڏGZ & 8 Zs P?5Ԩt&as)Fu";R]Fy^h$F"MCwVI P,M%J4d`u}%:v91!7KCFs'ii)B>!'氉fM!Y L?/hV('c 7?;Tz1@\׶fub),pĥHpM09R~?]صxsIW2h8\a}ӟO靃O>`4 Yz v;3 vI2h1qbx2-$I~/44=sFwʺ,?+GDͨNuNJ-ՐR_@J[jQ]A\xu+v(} .KVh)`R8VEtkގRuBJߦY┽Uꃓd%ut2]YdIA5X\&[h哼z):H&)Lk*\Sn(<|ϖh71-IralQ$g.b%#FF90Ӣڵlp}?]~(M:vPÜ.*0ܨG#ZA@/SbsR;׵u+JTl usөRX-QںGD$=qUA'xJ: d6W`<-O{O3gû.X}&#ٜ{v)@Q'so\/XڧXͷź7ڃBV9",͚'JDpӸ2Nzv(s^7MGepdiVT-˷~xBB,S:kWA kmjnoAպ y @ + U\ڣ7~NKP')+l}Ս53BC5Иj뇨s;VQϽBjfOx}̣H/p{AX'Tp &kP yee7'"E]ѨRTlXX:fnխS+#a?dnwt[dY66jǼ(-X){βGYB Na*A}'7~i>nT`bʕNыfukq.i!it2~hO%:ȯrmJa'8Ae4>PHJEA`蠃Q65NS&yaRAiII+9w*Z浂?#mۗQ><9by5(͢fSghܫEn!6; z-13?#Aљԯ+r`qK ҌDʿ,L6۠1{Mh>VPco@;p4)\@wƐG|O_:z { 2o8!r0ֱv+tc.|O U(='l]W!bH#cL(; >*0#Dg-_t 8ALd ZUF8!-hL4g[/LEfz1oA;3٬fRokz_%ޡ]D|{UsFMz#!hTG["",z/%_ů.# MM!/ѢIL;=ФmI2{Jo%+8rxS˴Мg~ۯ&(Mw[EٲD>UuιU17(fq>4Psq"8 }W ) LRO#FNk?Z"WޜOKK1$aJ8'C>K,muƖf]+Ž}w5 rȃ>j5| `7xnVvVE!@Jrt~_o>a. >\nW) 1GW+KSwހ wQ!ꏑ%ms|^:pi7>YwͯsvknmT7lw ^jkP1O'pT&AHtPdU CC(+F.20xxu^ej!z7Aڍd= j:hث⚓vuUL˱dA8~5HJucU\dmky"C@2`gši) iy.f]f$wϩ˅$>wMY\Ґ%zʅVΘMu$V52LqnԶ[o]2qr:'+R"&5剪7i{6gef(+15ݒe7h63wWi l޻*#3ltNP&D29Ԗ ɺ*r; ]v"{?Kĕ{YouRz b_&=I6D3hornbz5 3 S7k=pu2Yd&Zw r,] 7XP3X&o/DѦٚ{ݻ1k&޿stca[5eGA>"$ݭg=Aڃ29ݱJ}m$Jy k'dͼ8 If'^=z"ў/vb8-X[]bi>1 ^v6ݛ;8@LbbEװB81rJ:%:diR]`(VVȾVȆl}.$AB(]<@A*yx"BLk)\QNNݳ-3v0 242drՕ 2JEn ǹ]ٲ0V`hO LbZ>̟6ASLyh`~HgYuuP OIŤx(fjWE]Vo꧘Š'| M5TBeջ'X3sg Wښ G{oJ4H: N$)Q+A6GRϯ=0Q0;}EOHL -%-oÚ.LP4 =߹YG:O.h8!:hdPYfq̉=f ocSH@**=O{EnQC2C-ƪ[E&B% C`5[{}Tr]qKr: |k4EY> _i;;\S !i^tڠ!>ghb.%[w\S`ۚ}59c&v! jڡ ݂%k[x )2 W7'8MW%%\LA8A`6Q7f-xJ0\F6P Ȃ [{n@A҅@in0 a;K= AZ]s&k)7 &)c_~s {ٿznB >o%+zk^ uc FnRvlF=v.Id ck)V"ZrQU).|\<% XDD@ KFAI^QU}p M#~~YLIH;y&k>VM= S4U/HiQg~0!.Q4:{XмΜ,`sg M2i*qBz,RhLsbTwk3w» RZXPӀ]'Ǝq~7QYD7?g;b(e(2W3l YH.?;:d˙MVvTi6gDp=NYKw+s^HU}nm.SXw,=> j FABiɝP[UARț̚sf/?=G!+u5jAk`!F-NUW-'Tg~r"#e\/ # 5.VǢjU2̣kg}5;G ag͈6E"lXBH<+&{t P?**c+4奙V(˨zS -eOt\`T֌[gf}YTHKOoQ"ڔl[><@w@^ųIjwLRKyECi24H^Eۤwo>KO8U&h|].3&v>39:/X=uwN[$ =@.eDcR(s,v1/Pٟjm`{p:Cl *`aaUfxm%[j1BEv( w7WkCVxk$ye2j\ 3[@;dFNskrŚY$rGQTqnEACB-&L-ӽfa}oy??q縘1 Ig'vjy峐'ےprm9\{:l_"5YZ&W֓VDJm#]`2}hT>^IW!ҵêƁ{c=dhr3>eFeCǯxrS4"mF}(Oubg%nco 25@BӜc\m;˳qc E#Ne:}sK5:~WwY4Bw̮Q47e9B"0w: hoh@OfB+*ue%^B-g9Gϰ,ѕn&%K$' +![k='W]ĂOR,TRo2fcn~K;sB K+~k"NpW$4?Ͽ|#ԉLPLH]tsV% b۵!Spƚ|da6?VRU0Z͕CYj!O{𻹀py'ք % V3\V8zo% (Xu9 lܦUޖ.62}~W {ڟ+컒 K[bXIzXl/lR>#aP/=v[PvL*"̿?Vl>qҳ\1b}َlf}߷Hm 8B `z؅v4^xշIPĵ*E.%MA,knŮG1+yK.jPյGLၥ",cqS:w[NT] X֡D6ؒ܁L0%~i;*~NWpᔵy*V%z(g'fvk͍L!,a ";t:q1UbK: 9~2O@`0VotʟIܿ!Y%tPvPFEp'jvMҬ0x-%kϮa*k|_`blיt6{WW&nQkY2VgVq_iwHCCp30FMѦ,qfH&E q, 9t_GчѸHW՘]*j_0OMS&gFt``ycBFL ]̌֔tNsrT&pʡyCN<-}*i_x.D RB' t2z8|*VS -b'y5G k=d ;aBb1n(BVWw.FwE;VE>T 5ЖLR G/$(g“ianL/J:vH'mg`ET6^yq4xn75S @~j*݌X>3';s5ܷQ.J> !?v s1o[ INoόFWoZԢ,W/%m'ίrx{eHgJ1Pޛ6dc8a|zϩyaGkEY.x0,%K,˿i<"[>*z;A\Yod/01OoOmR H8ˊbظ crl:C@vA1-Hnw-U@bh s"$ n(an^-U'9!rqhx d`kU5$vֱ̽k#;lb\V16k.öC/L¥K)'d`+iOP52tқ ̖WRL bDX40v, ba?zc`+%&PDX35v?֏!33t~Hy|I^~In,eJȄ?h 4-¸RUk~ZV&qiȭcJ<ݥb_Q3?/S|CH}8|J?Xg4k*߼"4=BfR#$Ӟ MiHIg}kQ ˲_җȴ-{PVŤVm9 7ȆUn!GʮN RP^΢+xOҽOչ -.iڟOM)8 ćF/kLc޳T>6I-e&Z[1+7bQ=l:fEux~*2-RN(ZN`3/ak]5U^fL|o,ۉ+7z1}L3Z2gO q!9ff;"d<{t*tí6ŏ:Eّm*U̎Y[Pz:ŠyeY.uSMǁF`ydTho>%U{áVnFaҍw{Yjm\| #wkS}E^r!!z@N统cLSlw30`h+Zx\Rȳufe,Xa'q fbE4!a:Й 0s k]%ÃQ>iCjЏTaЭ4$׭ #\ qo>?E+UCHxe7 GHwoɯ (Ƶ0]?5[VyʹrcJIoyVI&.|]qf@pߤx?X__"#ƣc]Hכ/g~N!fMJ0&t$`(Ul1ҷ1>.ñAl3,vj{DX(G'˗k@]ptȉi9%V;3VVcZU B8)Lɷd"3W=NŘ{B* eU8[ߟnKNKY7hO]=G@~={ZȒQ_yץG\to#mK;~Qɑ^T1)`rZgj0]"9k|'@ȋS4qC;I8^$NW_,<ɻ$MGT R ۶cfS2)eþ<\wdM m]-$s@h_X­ԥH_dn>@a/=Ջb׏a-o9:"v֙ Q!-\*R &LN[>tf0t;H9&mTWmoKlM`7.?6{#Y#X1~zg ]u'߱es6"@TmktcOv/[diW4'p;ˆ#m7ۖ|y5֔Όi ROKpYW~+)@QveO{c_RLN i"ɋ,p 5\a"b"ҁUn[KU&k?8tK׶vZ:nIOtpƋl 4溚DX-p"9z~$@=`M`լ dD'&>.}b/ރDzh 4RIwd B#TCR7K6B5ʹьn>(αMӄ9j ,uÍʐu—nIXm_O\9daJTu73.&Kk*F io Q*y?fi{l@+/]QR)|~33Y`wڀYd(򖢾J^1V\qƭFX׉pºbG/.q{Yԛ^!-6,31bXVZƽ'wXnڇ= xh,'ަ~ w걄udSU9]@t&8^j~[0֝ ;O}6=3/roUV$ք&YŸ38y5C ₲`QkGQ:-1QT\R r X{ <G$f$q`y xB:-N8$rE`ٱKZBb:_]y>[I1a^2C4֪8JۘQVͯRx.mݥ=3??.EޒlF+߂{{+B7%(Hn\B.de, b=x쁴%-)SZÇJJyF*7sѓwY *9Çh%a]!$ ̜3.% X*1SH`]gi<Œ4OSsѼIn񦅋A!yz=XO(@/01 /$ b ܥI ZS݄.#,Qq1BJ֓_&e4Ҿf֍Ǚ=:JQPBSLM){ޠN2/?5?Exy,J͌q$gs 뜥wCsY\`Ȥđ6j'h(ho5oV5܊XBj).gZx _&KF6b ϮB9!B^fxmƗ0iũ_z4.xN+ÈT,Pp!"ߴCgMK+&f;g@:$:ע>,K \Ę_֨N G(F+nҫ63/3Il`6Ѭ \>?Le#Jh=g Dc.5E]Sf\ͼ!8FGD5/ B١J7F!K_!%9/x%נA8S\4W`}BѰfb1a IJFy{}laX轳5$uRcD,p0c\ ]Lr؈Pr5)'0!v ɸC廚0}HNPȍT-۞}MXϋ5g8S_?:"iw2_-AP>Cֹ [&##~{&0 '['*A D'Ezn1|z[@4cA$ W0%C= p4}-n#]f!=ljϠB& $SN`3F k?c(}`6x?ĕTu^?ķBMٽw-P?o~-W] z xyB'u?p~288b6`ttkL_sӡy7@a㊚w22'a#޲ivyEvTsgK(TՊtҕlSWw9xS'rV/gLGfo6}B;sgґ %77U=<[%Sic,n|{i_܊,^:d6}d, f\ū|~~l,wrdS=# pDQH,3eS83StVL],nX%j8خ_p&A48wct7&@6$?fcQ:]cb1^#`22G['pXs BeL֐V+9k>M^{J-SfhAP@ j$;$.9P^@D*%#MJ&rK{' r!wHvX41`l93ͱ)-JODC87(H찴wA洓T 6D1Рsg|C lDi"@Os {}̀FA]MUcy,~#+893.0LvN*>} /EAI/AOj , Tه:Gy%RI~z cx;߯[ήknu(//fSIkE"ǝ74 [DdɄ|w*y&Gԍy<9)izz2آ:Z.>~ Ǩ+[E@A 55ZCz7^V5hatFNMV:qkE~Q.vݣrq 0)5!.6Z%qBtL{P'}s-:k,y}WIA]\I啭q"cx56b_'~*%&g|aT5edkחIbk?-Ɏ~]B* M7!8aw`~0?ֵ$D 2D{P{ppI^c &r]= KrW-7޺.(DWAU5UD7aZ8 +<˵[fSS v:V`}"w@ʨFRhh<$"KIAtw/ר|F{<^-B.rf+\="[zdH㔇չ]톻۴?PR9(Umn9^@ɳ>cЈD ՠ5`IaiXZndȼd_\N b`UYyihCD-LDxhdT^)K?<<=f7a4B"ö ~{dK#1WsۺWˬ@trlI}[6+x]el"gkVu]p,YӤrn&|7E~ .L9n3x{S`+e#Z{'(3#Kl%X"<*}1р$FS ߚy%`N9B&W t\ ,ަ'ˎ{摦Savj5_f! f\@:Sǯ'8i^KDK?ȗr"'l<\rG3yrKv\zHG]}`'OtoI2`'2`ǪX‘RD]JQ MGzUNHP_U?/`Wpa4F̸doo $)P`Lqb wQVLPT>-$Q2+N'W:(2p0+Ms&:0W{$8y;oR;f ^[?0Էw'fbχslo cOC禉]߂7?mˊ,M6 c\! *_aC*R~(z<7?ĝň-ooKN(U! |8zd54ZIfZw!2(CCcU zW_Xزy@`_ZP||IEm\cz6I\دXA~`OM{ %FfUQ;kR3ԏI+!&85)g)x\~I,WZeCqˑ~ٚѵKCjx\NM}1M;&AqWB4jIkl=.`Vd8E]3ܷ;{(, p( G2R oJIR5+,w^ ^O?z飜X4өqz[86{,)"?j,XmP3LY?&_O~dlîtJzBmUqwgq;D%\O9bO_zՃs-- c~ g4YEBRht?PPZ_h-B'LW& Y850R<8&cezo pTKcͷjtQH ~6G+ 4&oMvp0e^;hQT)=TO0U+k"u|KjhT Z_;I2 pBe^ϙE+A7ZdJz~%*H3r4f:s祍k>R)+^*`PC \1I Y >1@V97,% 3"t]Ծ&'4Qs!<9 SRJ'pGg:W;C#f#ʲR.-aHT 9D%8l=qزMg_pcV>_a,u\0-iMb{.7LXv*ngTFrɇZ\up#5T&W~#h v}-tALӏEM{& ?Fsġ+O{y+׊ʖ8UW Ko}8(>*tl-Zt Dݴa֧1aiSgV֣FǔAq8<ՎDn=ZƑ}):W0=ghX LXpf-jC2MqA33"|QlY))Q\F5e~kf]朇nmf1+0Qg0VzN*c ӯHfJ4R HȞ#y2.Z 5Q>=HIS%ϳe瀌,ɸ4I`>drm 濥IYވ<m930& H{U&{R?2ƈ4zzw<02cm0I:dz3L2Ν^?fɒ-_G!:2ZdM5AeNpg1TG)r:N? mHL vcCϧ7&+ⴌ յ9G:^LCby™;ⳳXh{Nlԓ\%>4$>QK\xޥm*XJ_ z s0Rz|dn N)@C-D]"a*P8STj  &o! P0jfCumJ]z.1y#dyp^A$!Ľz gWY+:X3w%h;gS :8;OvySt 8h6w8{iQD ..WSj1?\AdlS&ZW͍Fy$#V- u6j"Ʊۦ4Z+ ~ȰsL}T~vA_/hB#/r]Va{ܺ́Upb|!r-a )nWQ LWxAA]9"R|$+ϱe Q%=qA?3(>fS z$p*3T>CTFٴf!%jF5v kl-|[UȿLfȖXk\N}Fy2.pCJDbw\ĶȓOkN6Y(UAn D&MP+~ߊ!ͷų6 cr0gJup+&Y%Y/l [oH9\1$p`#칦t$J8N%6FctY\̇q}`«mJuc$axg& lu8dFC6#1V0؊1ťo"!L`'5FiJ[wkl; K9#F qH{Z'H0=X`FdK"]MO=~!!K  5z='WvjmlN-Ȧ,{s~skASx ja7HQ9VbQɬ K#!;>RZ/@.ݺl`:!rjz}uz`(.5X$;>1kmbJwG+y7rUT bhȃȩmًAD.~{Ҽ`8V$?p `%[=E8XUz"r/xpXK!DYߕx,XI^bsY̢]ztp,tp".kf|Diu`ڷx!aF,'XxO|K4 Jf_Te|CA'0>f%eg9 pH7U>H6D֛APSJ;u\L,7Dbܠ]U2./[ʴ D}M`^,%% XL|c< 5/AVyLoƧZ ہGՙʎ[Zpt4ĕ녷dGGveS =f%#w9XwǼ;\9o9-2o7\2k|yU+FRs>3DK .R E$]trR$9*.ڎS1 Fޢ o'𹈞.#(ӪA8*OVdV[׉j?p )|J~KSzzuc#}Xz >DžoG9/)%!HjMqP Y|^Xgah-,9E}malߩhfK &d.6BM`z4۾y"!HHA6H2c_InZN;X%z7x[̮L~?E k5PW t`~#X4~ KĔ2؀"5Zʿ2(O|t#᜵)plIwGW{|pͧjd*Z5glL/Dp{vD::[zTYCz[JЃ(zZؗ TBV9̩ۤe7a}T_J4?3L*mۏW3\Tw5e|z5vq& d\؉Vr p@_~ojT۱Z%%(8M2#DxA V՘Gje"x S,Vj<9&i5|i.0?_] A̖vf9' UX C͇$Nؑ[yӰmgP9in ^ h ],Uhep浬꩷Iny~35ZMi}%OV3)ag¼2OTFcn7:t<=<])2X8;i DmS+9g5m <8@늬҈ACiՋwmwTv6o$pIP+EP0&$WL@( 8 LfJ잍LWQ}}k*8 ro \=M?=7Dsv {Ɵl4R26JY$_1݆.&{?SȝfrN (&ci$=~(p{dcpb 8h\%5/p\\Ui=jʃ[o"$BU > e3(d SJHCx]N^.D F&j砗W&e]YLc׆G&b&48Vv l?/ yGU NoQƉyI-o륃UT[e{h7VzYz99Pd!ȞlTYQqo(,x'rh՚L';ؠ2yk },} d}I*QO~-:fqs*P Lc#J7@`a0ƚO8 Vf>H2VƞZ\H̚P%o`*W w,Il(BML3.(*Cc'L y!Rԕ8@: ܷ2I࢓0fR Av͘R nt:7٣yuk{NS*KSظ:f".n6"K.94W#V%}XKp/wGs?orphgXr)<-)CH{!N$Xǭ77GGWq `#(lb]wmP=ԣu!"ZZsQB=;>5eԶ R^8Yq&7G(^ Tl>_Ht0>EOL/Bb0wRgq SLYII1-{Z'7^0qDpl) 6<-YMJ_}U5e:0{zMa\krTh9cҜ"`Bxw<YUBMbjQIfi2[`ٺ -q@QLg:<&JR+]JMSj[NG[Ul{]-3)_hxCʤ3Mr+eϰ1kvbJo-kBG)IYzvpI&~4OsNi! k 3qW' x.芹Eϥ#b[/  4% Q! (] ^!UĆ z/!/vq8&zѴӈ:@:e~]sK VmS-;c$@L 91q1Y&۹wC)BTFqNy$Z3tSgC shc^MxIMj~R?@H0ׯ>-@#y D zk4(&3qYân+ġ B0]n5bfU|v,!S9jx]?TPJqƊPQCNZ{ X6#Z, S{qAHiψ\|( d P)&Ԗ/t­S -F^|e̩p>HNSD~yo@e9oh.jԭxDBbH}LüY6-xXGB1V**ĐJ"ր~\C R|,pfmAVCP)sG5 {?'гH sTgLĝrto8n}Kqz2`P< P׸Nb[{ƒuv䅂9rxx-|Î#Ad7|Tgum+yP+e;:B[ie~K IgZ/8x=-Ez2c;al= #z ¢ 9"&N:B@Mh.@4V^fB M4dwk0 -eNg0R OArR;#;s>Pt l/8#}rpB4 ROry㣲+jd^+zF5%#۔Lb'U~lPlw*i)zsn|IOUwm ŬQH 姓Y>E术Ck!325foZA9n $yLh(  &\q~zC7WOSiz,j>R a`V^o({?Ni bk8q`#pcNGw[;+X9Ru~_1[ϴ$)"OΆ{(#དྷYP^ؚ}~R̴.3Ty ߘGp))zo?ak_-"cRU}X;joIHi28L{́cd.?^wE1QLzfv+鋏^1ߎ=Мe ,,3[ f9xƜ8NΌSuaZj=d!5܂:K?3Du'E9jgmKB=D7J jf{o9soo@c_ s .վp!0Q#T*~e7jAC. ?.n]hn-jPy+f8L.FD|ĴE+Um3 ۵s{\A hG8<ќ hRňA9XksRhX&%ܥ/A$y1'qݭ"pd)j>[mF3+@eQق5QL7pDH 1Yz_eGڞfKVLJF/w\+R7Csp6}M-wLpKiWN\fwqsQ'Tڡs{jƴURΓ)d׏P!n.қ5҇%dW1ir~?1_떤q "t͑lݲd@\{" d 5AwR^@xUm̵b%^*8`^TWTaLВ4 1A .>hm pY2+B qɰcy5¾)4Ʋ:w\c7˧&;uShƖē;E8d64fCXxJ5f'za"TGF7^*_U¹HI ~A{#2BMp-/Ty ":)~oA(CPP@XHۜMSDZ1 zYᗁ# Sנ\nDl*X >rW+|c"Xi,987u||if"Ũ\k>u [v3L?eZ"Jy}Sכo^Hܷk6I9?=7eӍ Dv#PXL$Eӿi4* C;qz&!nd-=i/g/ϯb؜ ݾNx- AN 2R]F8yϓۥ })f9,Sz%u|'U8u(sӿ۲A=Y Pp9#EƎ;FaބkKizZ)Y{"WK>vn,8˞ u4RPɁ3`LyA?F1ʮlKgMIAS,{l27 _Zsu8(^OF.2s㒵 ̞.ܾԓz)iM;]E G@Ҿف2֍:8V w6B6ĂTEpX&s,H!AF%c-_j[MF2$ ?Xgvj;[e =&"^1upEW sy@Ԇj70^>ז_]ZжΗ0{hkWκ&h玀Hgf {I55ͲJwkOyiK2묭su6NQBIfLHjlO[uaJQ1ZA AxYVl$QqU]Lܰ R'b#6F"U˧2CcaDi FȲb7,%+$ D󳁠HyzJ -'^͍ A-5I:|S(D~%nn-1ݬEPTʷѧm¡@-a5VV UZf8ȇƁlf*Q)Pp;JC; ˮiU>#LxlRWʑPkL%wvL݋90yWfxYb#hgpS: @ªsh1IÇtn}9aFSsqk@šLvٗNKۛf1& ;$S~RIݥ+dF eNCd"ՓHL(^oߊ_PM_[Ž9GE+HY]-~>/Zmc_rIb? pxJ?.~sb%־x #!HjB광zE+`OU̩kSJVxHTnI4+1ĸvY+K $G鞜Q i)uj3 Bo|ҽ]cF [[سR>zYu{]֖%EP65((爃lfݼe%@*Ćg] ]Z?(%|q. ]uo<^ٶdYAm(ɸ(!ݕ+_\Awʹ%k%850д50YO3chLLC:>a9]Ŏ I/?ee[c{3\E(dH O;b ږ:&wdWr=& UʋqR~6#NLG# S2kՓTWP> n*'Xd,#6bf|H*MėX}jn> iB2"!'0<2b}VTH6; x3mDf޴&=/X^F́fnanC^Ӕڈj|*尿̋i'ԣAIOT3r4:uNQ #R~31"M?֚5^JRғo ژTDmɊtBumSIu]lfk 'uI"2$~6eDZ|57v<0ZQF(?)D*hcϹ^x3Bj]Pܻ)տ?/j'&_-n1(*شv'zL dN+b݆^ KWNQƲnU>F&NavlK$1 ecl8]TՆ,B0,Ik7*47Lrb8?7&C}X><+la਌?B~ԅ ]y [j9D .M34the|8i u6941^BAQi61{IC=oHu.&(9Rd ##ΈJxm#1r-gG d;]zꌧ{~QQ!DAB6JJXv>NΈh\;sI=- %zxF@硋7TIpj)LHTF&A f.b|%L;jV$W {czb3W~?]'q>b1ݸFLD>T~ #"YUs9)KUDkc"f]nWB0@c3WXʇ~%vk,s'u0?EZP.>vo7B˃Sv=qi>P.}Ib(ORuFZ_7oJ+ʹ 6c-H6vir4 7UFv#jD0vi ډO?Hdpd3s{%N %&t"+XՍz6DCo'CH+۰k+Aُ el/Uf6,1hWl|Ѭ@7*S0 +wG Jv+QG.j]gΖ ";I뀉e=$5y_dR] ,)<| tq;Y2k-!&y aICW {;Ў_FpDI=}=T܏}\leͻB# y> Iʆ}U-aArCĻ‚M:ޑ%PWp \ .]ߝ|7Β6"0"I? DWf1J˘"2\ ;`Ccfa7ur_MÏ#!4I]CYdVTV޺Wn*T{127L˝͚Q{D}e0=^Ϸզփ8f,vG")B, 9O+wa5 6Zg!u~=.986obp7 g ;Lއ=gh퇖3s¶RVi7)_F9ã]U^ =/݊Qղ >˚e6$gm+ i~nѠ+ߒ*Za C 3 ^ʜ$b- 7 DA{70@gƙ]^ -IIׅ*jHU>t0i^*lkp|7 !Rt n| GD({0`glZw|E^\;Κ+4 Y}q>Q 6k֑Olʥ 42sf5C|M5 #Z 6N|G?6Oj>}7- wJT ͂ bv >..o1ʡ049#CQ%q/vRAُsɗA6EN#c:J@n!17Vr0G^J"e3cKxY}5N n5rh 0 Kjm[;9$W%ȥx+%c@1lb i?yk}c5㙓\@8ML %G`CpS6lf>SVQ%C%[]r.$)Qϸ}Ipȳg}Q56Zg ;o8wYkc1#P}dz [^[es;A ` GKe:Wnj椰?*AjzPmqO!_b/0Ѵ:nv .Q;P6Y6-4Db^Iʫ-$dJwo<HλMm Ry#Y?0 ;]G8{gc2X;"qR1{Lo4Ne3:=&Wz(3D)UB} vpߨeǢUOx{vk!_]݀ИnQ^Mp) EʹH1N !8G8Ȇ|Iۧ?8pvtRh77H.\f?cU c숺Cvt&[>n]uȞGݎ ׿lMALcGjUZx:هfrnqjXM7d(qɌ6w}>~.E,"2-(͹ekVdO.\O~%(|\1iuT}J"VΎKv;sR %_Sve0Jz 5*օK6>,'mI3ESoRV1(erizh?m'֌Z^+ځ3='OVHCd-$`3BqK#?:xcsTB( a]l ,]w0ܚps4 :1L!±gt+ToS6]VWs;SlcS22,>$`&>5d1H>4X|A`^!s!C#{sb/vo1zW"+op-Zۏ9 Hס¢]xO5[zxBpM &i}=g$gCiBӍҍ )"th4Ƥt>?%bޞ"4_^-,Ա0VM!FOi0Jqq ]8'ɟ`2-t B۞Qiߩ 6l[5뜝TTԤvm?u>ǿ9u|Ft/OĹ?loɆGז O"Jsz\{Fu2 =_]СΒy&^"sQ[v{] %)BzbgF 3Q z\~kjAӨRbئ%dE dh9G$4N20e5p' ?#O@V+pr-2KPۊԛl)Uv_X77A2_l2(p'^xRW67W;=?^"o~dP?cde>6CI.oע*i:bJnTq#Z+нTL)ccr:5w+eݞ@T\^ $fK8W;m,܇s7(; K?af]HhYa5&=Ksw4sO6ߝ ϿW֧q|d/()|g@lV̎իFjm=;S L]mM*֬}RaJ nO!5YWl'25~=u=Ԇni= 8(MU=^sh~ŲHgaGiTɀ)x"/4~/m SޤȱZDtLSM\巠qs^wXv(3R81؝`Ty47 XU!;dB\#EyY-lo}3XE3MoWRژ/b$?Rjg0c_CO}Pr~g9봫#Iʺp'D%k#y(Gtg!8?e.uT˟-ty oh; a Ti:53E֨k"TF}ev2 fP|>d Ü]^6w,RYDi{'OAPu,AڴBr7OWoy(U#qy!PP+>@”0[4aMh3FNQ?poVT VR SniF}"hl5ߵi"ȥp >wfHx#_LK77clH-z֋_*NaM6 pEk yb)PFU5RD&*enZ[/20#te40S"x;G>E]md";y)~11s3mcZ$ "s-<*,4q$][0'Enw,̠磅F /FUJY(:E̅ôl?89?"nL[Gꁜ?O[a7 -RYT2, UXOp~q?ufq_AxfO/x]h?:&P<Vp+<ā5˒"TM穤N t?mG1-_mp1X{b):C FQ)!*LAO/eR"\*wyŵQoRZ+97!r!4w%޵f~$lE.}sיT=|R✡LjƄM U^|MdC+*y:]pzlV(}H/ݳsi@Yįَ}:j5mi++7ZŨ80W20IB9DIVgS EOkgqW/Vb̠~*5}>p S+K Lmh:B꾛?Vi;jnJΔ*_KYǙe/㞬}Ya{[½)vǧ_8Ǝ XQ ;S/XZ=ew9y PYΘ[Ҫ$,㡵EWO|]tR8fu8:|8{4n?FdP1{*]ED(bhaBR{:!ġ_>e$@[ 㮻cUG+'FoOYeX(@c~ue8Cb$J 2emPo%Y^!na7Wn!6>aPFnC[z%]n63H -F -=+:N?Bؤ+)/^;Kt4BB]9G;p@BD/fA0:Z;fD|oO]c|k7*WBL}zM"r~.73!`:ۅQXok:~^8J2E[Z&MKX-  c5VtpEs+9._崷w/f{^P')P=*rX5$ݶ y{1{`Tf5Ѿ yĺou D@1LhE%XRo40igQeX4m2cƬ>^h̎ &3G!ιzkzj<]08g)?xjfX5!Xh$$b!{638Oμܥ4EZWyINyuղbOIHS ^ M(Ϗk^0*ㅼ(⤟kK:$iJ.̽hi uv9SsJiLٍSva R?U.$f4,†x[BFʎq!ll'9RxOnRSV1EnUqkX眥*bëDzތDR)iݖz6kUJi9T hx5w)N?%uyZ`K&{>U.zb$GXZN92*t_I]xmWSѲCcq-ѶRD*RzX=vD%M_*ņ@Mp'>Tԭb.%y8Uy֮9AghѶA󋠑?' Qݛ糲%bPB:NHD*i;Ϧ;h]"BB,!ǯ}33fS(m]q+MZo^t<{8NSY-߸7(v: yѡUܺ]nX8)Hm>Na(5`lɢ p_6ڹiL8ZV zą H:E 0|3`5`=Jz\9v]ǤIlQekF3Fzܣb@ֱ{0_k֓I{ۊL󌉓Yӄ W9TVeK͖y67q*GQg{@;WHgiWK䆻,8&ۇmXIIQ_j XP u!hgCYkQ;TpbX#ы=תE~LlVLZu\9QĨo4{]% oWَ}5 zPxZ"i十YTE;w;3F 0s{^=92L-]#.)&œq)%нpFqk zyoi=~xV(:ͱ{ys4`B/;B.4:={PpS^7?|k`$ґ2CvBj6F/&}С(%pE~$G|W3٦8}וh$pޥ܆ C2 u '|Bqx+1* Y-SUSWÚ6]붅S_3a-FV(Դpa4)bBRHA`'JA;j^o8swgH_o~N5% GMS̠ Q'ȭHxTE]^Uj*lcG:kIQ{Qwz@ _ėw::^iْ"H촄*"8bGRqGM4\)4sh d0H'Do1 B&-IOĂmgF֚~0Tu ]zlIn!lUM7C}s5zK<ÝBPLɃ)9ƦηHT"ǛmÌ=Tk% NzSݿ(UTe3h@"q.6{k4}QGR,7HOUV{UcUr[bM29BjL=[%76ĕkS M0 MP0X!*k-S'gÔa3 QC4B̐>m/PN9dmfKI+45ctsĠ~eFBM|D UUdžMv 67f4ꥲW*foFe)WЫ0] l+Z)_=h?x2Ä\f)ga1ji cg4==좌R}^L\*L`3ݪ&8q;M=|kF/a&D$$*;v+0"3z"jJ`@0oEG!lβuN0 ÅĦ*`*b:NEXۈ΅W-v mty{CKp%MEk8.?* cb,ג/Mł6W*5%gTބgD@WMzjg fa_։k8 ]Ҳ;JbR4{?pSu’XX,b\ð4 7rAq[._5#cf/! |.aB~OM+;d':u7hyHob@v8GRvydyT2>܁I~hˍPzT?r^ɞ@o^6nI]pͰ]+4XdI^1i"'chC)Jcurwͳ֌5[=?V7#9+U _FK7@ ~{cxzlOŐse™s=1lXanb%r`Q4nDri9*Ƚ!ds&vgI3ծJ Џf{d )ٜʚɴRc0;&Xf9yز?c5c}?UI.s5WXNqrq'Ɂkࢡ;Sc4ž֕umN3 ,GV1:9T+lCOEns&*̘@{CV.X`'4'r5aHzG=j 1Rk_Lb 5opUm(uO70JvŚ)tӕ-~oy Mow\Aa{zVMEpOpq~xȦqN?76Oɫ%/'Dq:n'tmh_,ujPpZX" ܬ茻 ʅff >CJ] ;<(ږ4n? Ja#߉y?ys+:jڄjӯ 'BdƖBVq᢫ܩ"2armI{hYheFLѡ8v!*)lZ 1),_3YԠ#AViE ugarA};:j幨MA<|?۵;Yi|WQ<(<(j;#\5֢kzC?-Th.԰z3'He#olF 9 gW289MGO|h(nc#Bd[%g % C%Lo)LwX!nU ޷F9`]D9@?]]:,:T6q@TL .yLJU"1} 0\1\R۴q^+9BuROrր#}1rm Z}f7I &;|nҐr%2^Gvd$*jA6(LPi6ρuݤl<[ttcQ?ap."K_cwuXN dJǼb7peF6O8Y.n,,"h7]T>aY\aTY+qd[ed[j> WtCw+3S';#}%I;ĵ6"gI[0F|%X3Z߱6xt9X+9p~Ϲ3r](b>kAgcDhc8^eyγ4Wv yz/=ceW_4PP}{hm=N2gRm=m[v\WMuwMr_ߘ4C-D2ajBmfcj o[ B%9+\1dY+$^&o8Қ6Yi3ERGPIWI4(ݢ ۱ n'>^_ﻁR/fGA* J1% EieH-q@tI +>E[mKj&bAl?QNn"-P #IR&#O'Ja@Pj&zǒ=96_Cu *29$2V1_j:G]Mzuߑ'漿.'O/W̛m)~x0/X#׸w7u*jG=pqWe4U۠xs?l44H@̕ <0sn2fh8mScdGz^T/ɅVהsХRJ孮DwA2WW?U7 &(GPX֓Ix-mT㈦ľTM[c܍J[ѳ_B?bb;Zߡk:7Go9C:΂gM!()P>"h`1P&yh!jq+$zEu$@Xz$&usN n/eXfRNo>`r>zNA9}TCNh~.FL[]|MXgO3@OkaH&w0#Uck^Šh$B`6G"Xoz ԋ]WU?j1>C<Ljt!{M.@h~5O3Xzӕ7K׆rˢm6iigcXhփawTf56I:%µD``2t`5]S/i; YP # @:F2G5X!#Q,^}H(66$-gC)(FB\6gnN{&f)-s64>eqsv{k{J[78IPWF͙v?!r@j 8 P' oi&aO3@ν7ܿ8[(= 5i=IA:pk>ԷǼ_wguo J:S^%(MFI&LZ$jK) bRb`@,JL^DZmo-7![gG\v½٭]5t/, FIņ4*;3uFkS!׭! D SDj +.o ?v-?yDFBf,5"-j|zОh|^I7sB ۔1\LCtO=foK/Hip TD~(42BıtHZM}+"!~6%Ov=&k$E$*CL5)P(!2e )G,\]=v ]֫4(FMָKҏ$4-/ccJ4zESnS,;C+; E1?WpFЏFI۱Q'}P˜ (M>nV?O#1Ӷv}J*TδyĔkC|Dmke Do?SYS;] }*|"J. 1 kg밌5u:y%߈Hj݌ZVbo֜ WGјB1wg̰rXr*ʏӣ^F.ebZ E#rʴ'XqJs4fg|C} #G}YzrӝkÄԪEk˕iG<5RYFAͻUH]yx`+=1aQdH2= _a(YK٤rZHe]-Ĭ5p E O}w>SQPj4T *x.rczi{G`g $A~_ڌn#3wnu\צa|3KBhx¤h ~i[s}ZOҫq^^%kh o1'S̲ja"TXg;UC' $7r `M IDo|L@[@]56Ć*bur@!!q[Q[{ZB6|9h"ALS(IlO1>/|y/Y$gIm49Wߍ./w,<T!.T0 [Rؙ 8e0V#^N6pϫ;iµ&?_&raҊ9I>~USpfdv[&/Qa|7$=m Bqay?UAj|Ts *,V6('BC" sU`sA7Wβ Pb.k֙!m6JerjїJ Bӿvke╈UDT2斺YuJG@t[ xOitg+7b?z3|e ?9PXykIIVŒޯrbp >(3ʰvǫB-ֻTD$z|(;B(x' AE&Ga]d bX|_߶^>i/٭i Olߟ(BB}JoK ue[z,;/RJ'58a_74'7' OIpW˩XK55c0W ( 6;W \JOZIx!I2{}m83a'ӗ^>BA`"7xy"EncY*q G>^ rr)tX,(w 9\Jo{:#V^\覙Eego3 h} 0XWg"IS/j{˫[c-1lV<P%Ū)!uX4+-)L lrDf{Xrj,;[/(ܹ[%?P!Z*9+294P^c[l b/m")dj2lSRzZgZQ#Y_n"Z zS>~.r-r7"UBXkP_fI?<Iz;<2P@e%y)pO W_^]1)ԲLI]NMEK1#C4 vץ< Lc#Kp!eb7@$\"o;߰( c(7ڎMdi+0EΝ Ї_cs\L ~Cd\ 8xQHF3_5Eʉt:Q 2o(JjɈ$h,/Ƚf\/kj.+y\U4B~ 0w )[pBo?ti>9iOob̝O;5S)݊ 12+Z 9]?B߬Y$dʓS8M $7bm4aK~I @輂̥zWBu* e٠pEcW䞀ɵpZ6,>d3؊AַQ0*x95S^8V? 20+);˿pxc'/7#GKQPV~Cgmp;q dmEYm^;kX: ]_%Lp(.{ cmb,o ux@[2ZRrba&]\[J5Y2oX0,P%S i_F۔J4?-}JSY<̻ gPzExe_wXlBEF&tܗaKIFU{$р@{hسpʫ79 M DdӤb$nV Ս4{1W,Z {5@9)>`GWQ؊I/>a*[ <Ϝ5}0!ŋd]JWKDԝI04CK> dί2#%Y}w1GL )ˈv|ڡ;36[B  I\ d ȸ#=6n?Ch IOC;?â|W~5.xpj:-Gs{z-KL+QT<x0.T|]blxV\kd1Z"FIA$kRYB9imKIU A"8-,rA؟;l9H(`mX4:} VMRaܧTj`|W/1RxUMFX ;(i 8 -/wӤD4n (_&o|wZ$62PſFQR*Vz"R%ApȰc=ic}éRj͌z$D][H`ӂpsGmK?)|>mzK!@&Le̙9*W>#'b9Lu{<hs#GF|KQ.)t1 "_wLb{| Htzr(&ӲpF$e fxd^f9e@86!ؠ)\BԢLy듟zR'IX/{D& IE7#Ziyd?A6eo^Ұ\.@rqtFU4GL+x}}`׆mPt\:>WC= lM?^i5#"lK'fO zd^-eQ&rFL P8Sdv6)>Ŋ7IEe_804QTL8|$,QV &`81w0oӡ,]@ԸW÷|{<% $٫Þ dCVU͵/=o^O=C|XGwe(˄ Yh`~$ZK: ֳB0B*ɔ!{3YF6# g~!zȖ㋢~7y|8hrjb7ck[G$8^̜ƌJf!gE>0'ͯtnܜPVxNh*C 7c,[X+G#h,5?._1r/yǎh\yxG᎔jk]7sz=s%3+4DoX6q7No"hddǧGY^kV^@/@7<_e=srB9+&'nyJQ@^Y|=r:1ߓ_D*n Td9U`p="cI >tj-+](+Wk/ņ{N5OOs4ym襥Kh1 l^i"1Qu?'oDT s:9Ge.VrlDl$)fB Sdv}G68:s1fg9[;ު" g;jVӜe3!*ACpΉh#EnTlYcl|#cNԸW]-ŌG^b SYy=ĕg+r|)L:1^%`;}Ď7ҽ9`d(Uc-5Jbv啉EQ A$RsVa >s<5TD?§1*w@E5:I"0+N`H*!@g"d3Zl9sZIEqEGKH{k"hxgͻx@_atPys u5k>3ʇhgx>y> ,go!T3 }eʽ4l$3* `"6IvzT@ HMJ!)fxFYS@b'Y0Yy`d2XXWG?!>},8u۽z 8{l!JLBqa$ 6}Ք^4gBWM*4TMU){N,"~ΟBnNfJAQ zehmㆁAHd:gf< T_L"2U]}+Ť|ɪŹ HIl'`XM)5{1L^~+!di@SELFF4gȀ<13O5  6W; uu>wEڈDV|qHW5OMb :ae <*s?n!{6&1Vw*Ĉ@FK9^ rqxK't Z_4a#bթ{ū|%|\c{~ 1?A?;oC5*}=3@Qg1޲_𵩰 7Ӱr:e1z&cu9łX"Gs t^'yїg^lG@ aQZ- !MaB kL>bc!%b6Cq56~CdV ^Wవxt,u~VV2T}"pR4y*7Ȟ̄74bqM:emvR(iIʓ0j4᱀e(">Ssd -X-@!b[/ Bh"jKL3WM;_4/ :]Sѯ64ťn%t1I W^\=?3'=&AS&36[0[7y?ES#␏2wږ(\ ҵ v@^Ҫ`,}yc&50`wrc_e>OoY^ܠvڭpEXҪds;k2ʈ_%k$Ř\f^J[o60I3Ii6q{ 9h/c䝉 ׯOĉ+%]xjA0Lg%P4iF-[4GIMPAUYo6Ha7=NE|ʚ™ ϒIOF]=W=J2Aj_S` 9W0a D%a "O9G5RsAlȅ- Ţ\ ʲ#C\ח` i=5u욂6>H*tI")҃s2|X^{Kx޽)\Y]Es`CRӴiGMvsHGnV2- Y4/-m4lK %C5-Z{|ձ8w"6kCpk[P֞ 5) &xγdN&cx,`{ԱiZɜ&UD @L.hPک&ss8'{YAq"ҫSE%5A-{  @6v7m#4 ͵?2 knI$0O[Οƫ>|g|.x)ID3"9&6gpe1WӞ~q83GUIQ4t}h"Ad7L1-_ug%&C0˦ a^z&CH' % _v"|?&Qɛ'縻ZAmjsrV Gk;ee/ & 6X9cllaSŠz{^_$y[fTTo7㵓jz5BYG<]饌g27CB}.$+w!A,(˹jwK3A^ٯ]LC(`kLEYRs7MY?yPٟ0.1,p GM=w광cyP;W׃7J7 &,*2qc Ha*f gyhnjyj lYFfl{X!eEmԹ 3Zqm!jG|GUr^(|E-ͣsA?`gᲶI7ӕmd$ѧ\$P wShmyƭ5I^o: #/d|+]M~$<3>.@ =<~MQ#%/%,}E<~DN'jI{;ȈʳLHoX{R`VMh 6 w?9h3ts&֬UwH"L<eZPzR:i[2y&mM<1+.Lu޲.yUo[AzuUٝ-dgܛ0!B)]Ե.0|=z0pͬtX^|0N؂PsIf=Z&.K:_t!ل>T:> lC1uھ[9vg.}oBMQHR1 42׾gk*AHbcbİϤ~Pb:GBMl, d `p s{FH87!:Cf _/)ݓ뙼}Q524U#E,RŴN乱\'̇.^d4+o_;%F͓Vm~Nj$yhpwcBlTW@aJzs<ϤMN݄YiYGGF-6g[q1+ba(3̡@Zk51b>2'acn2s;o9h>77(Ecݔ<51KF45eh(-:iEj٭M6by>d=%_៮?_7zC)}r%xո+Ys^ֺh\Պ,ҸrR"U^UAf"hIH윰OXGU$It:bwEӊ‹- wZ8uq7I1rǻ,sV怤fixXdžY}H£ /0]9b!SA.$'wo򬈣ʽ"J4{1ڍz/i#l1>9F+SC\*%}Lv> 5zo!elyeSO/ZГrF˲TpG37yXG_-I֙gSu!]_,$NG y澋 vIYެOt7%ːtW.ǭP큎' ̣\l+5MhEHCC,8T݋-B*%\l2"pbr}RRAi3+qa:9ʯ++Rj W6&ͭ/rHc1=x-Ɋ5&fUt!rS5l+dUG:=gno0*m̆,aK?9mJq?QzӇ,~?69Uf/bL:a?)׺|9>2IlP'c1N: ai0׌||ZӊYMcyHۛ߷{A88S*]$$c|R2I<,.^1 (tV IwޅI$Z,8IɅ7HTsnkLƒ?l70›seB /i#|+~dzNaHC`gq ACPi<7 oG5.6?2?{]3gN>D5Qc hO`M/h^lFt]YL R!J e@6aJg[[SڭF$e1;qz'f1agg@DW>q?$FGP̳eCjFUYO j[7 D~DS7sXTuvϟ{$x&a@N2?L?:Z 65thZ2jyJF&@~D`lQ"dh1B"csY\X\v'g*sMCs>S!ŦMT"3|s?bǁO8UnaD;'5G& Ck4ޮW|Xn$tרx~[Gc sÉ97>%PXieLƕEt5NsHVv KՀ/~CAxy]O܇~;fP?"$mΑdDz5; ޥAen~Ix?LC架zBܼ CaPLX ;v%H~0|3;5-(P;%{뼲1pRʇ=Q|-roZGgw]Ud|`7zk&kʠ6L'WuL㟰 V -U.$>'5K+*|IR#. %,}ֻ[zSO̗w-Z5SBAqDMapZ_6-^G%{+?1{FVt9lݘ*: fwnHO{晲I+{jq0L{|Y#9JX%hSHS5O^^<h6bѭ̨CZjˈSZ7DHTm6 xlQsbD]T|Z=__SɟAihk @.黯bu~иX^5\)*Xk-IΌ}5!WcH?H[㈾~SuJ&]h}RnSYO4> 8} }ls$]AhtV5PV+ sK30zqy65i w8ǎ񸴲P AVeӄ`-R׊ ya%l.["jNW[HUR:_CxˉhdIcP Nuǀnac -tMț?mk_~sUT3.wA,)K|~%=zHDH|e7?oi BRdIۋifnyxSMNO㻺C BZOn45҄Y}'{&sHI$%O{ O5^WRG7,gzbӈL  & Ȥ<g'! ASY TbB@XAsK)zt}u 2.dq(#o:"glOg^S` so9 n|Bx,ʫ#v4~OZ+Ԏ `H[v@R>:|U2^Ĭ;OjG إz&yn z=[sH쩡Jn:ݾ3RtϚZ"4Gi2}ɪGfhf03t:d5zxxYSgbzGvܝ "[Þzz=[tDn^ι˜"-$CL34AG@onM9f"ζ֝:q )BH/ 3*M{ۇ|>%| dwah˛Q<^45͐\.*iTp0 w,cl{~fvjKQs$uH5 +R 5NI[!E>'5$etFƬ!5$rj,}okPBBCE*&NC L\E`(iXˎ~wKzx~7y ,/zݝ+V=̴_^Fl-Nqɰ>k'N <|V"@a[%17"f|Ưvl7G6oCLUkŧ ;eA%FO ^wɧ7fK?#ˆ(,sg֧谼)l`J(!m&Lp* b=ryJ[g䆂,>}g϶l ]$EnRPAd0>eoL тBp%%d˱QqfVnE&9ߘG5s i-ܝa~.)'0a%󂟥lu"SzpRܗ5 7ueXFY~Kͩ(CQ_U2C'M`ӑ N?gx 5Ms~-]1_7)XP95+e~Eh!&q*j+j-A:] b{[\-6Zl۾ Gݟ4m΃3wYHw%I C箘,0yPRGeR_FM&u%\ K{9(5dR@B8XD$FJs\‚n^O*K@ KȈc')y NoSmcX!~@ 0W-uh>G`#vڳkB3ls]B.[3fJJCS"q9'U֖;le?j@)Bɣsq];IG #): a웃LMN#vfVe ĚD|߅  T <%skgi5F9c YjуR4Je2Kw"!Rb@/ /l )i^ѓ}TmiɚEkzrcԟd4׊I%\*dMs3vbmdHiӰ*YtyB>"y|Y ~`t LMT anUka+Kymp7CÓ R]7Lٹ^~@#>i,o2G*+ 9\0y16^<08Sl:FB`4!PB^-JK ^Om&"_ꑑ L~LL#p7Vcٜ)~yN0NmC/ INNFPƮL{SͬeUuS=\A_][Xi lZzv,vp|C m`OB i59C4hL#{x@yvKR#ˆxTV r"ꃰT,xݨ OWmsx*rK&{'=B/,i/(\'. Ci cc.t䮪YJ(Vԙ jmMs 2žCp[cʱAa)>TIMdsqkzMQJ〒O㖌[G'g/܀^"}B̤^rbwOyBG<@=MjX+жn}Y|+S_]Li;zCd˥Qӱ3ժT % JwGvQd~Q9oc`ة@PgݓQƗ8Toâ Ι+qAif"$_!P`gOUf>#ӄJ8RmVHN,fk$uP _3*-H=nb3NhB4<ڣ3rj+2Gqx^b~[L_ itqEL Wchx\u+ڲ7ju"I웚~Di ^QSk헜UϷtZ -W>AR3 A{ zzMT/';yI'9qj:cP_GU„+U Hgta(ѪN,6mSLDdNW"WV+tg\ "b#;WyWW2e 5ꃵj "^_U'GE s@oKUF&[XߴOe6cKv33N䂚r! [9iĪ#0# fѭyd\<,![9SE\>yM I ; t1\9ehQkNė-7Np6%{%*o~Y>@ ʟvLM#9tUM A$|'YE[4Yy3qB1[%_I_(#(7Pq홛i f IHf"[=ЯgyWJD/3$_ FD盧˦o^GؾELc6RWO0nЏR,~ X-E<~%Q-1d)蔟]P*'&%֪-zqǚwX `&JVxW3p1I ?dl95ӪoP&V]BzӦ[- NLY^v Dg>D,$?P<yb)K).1ur !٤~Ba_zn{;e\l}3N85hS!=矻9!rDeTm7_uUWrhgSy_/I>!^cf66J4+c%MW` 'PY  U(&&9;r\hx9pJqI_]bQ0K'.}ȔVwf2=v'S9D!ax>qYxհ$3V'f/až$9ɖ¢BY3 ~$Wզ\Jenb"Fh!@#p2`1IA5(=PƳUW-0LG'ӺYʕ<^zya:ʷbP1b-J4xL_9Lu<*G(sξ'J;1ԥ yyYc3Nx/>5KBeD:D-gCntХ yrB3!fӃr ѐYOקH I-ʜJn"mp[6tT‹x]dYFf)8odv20lQyt%uWhTōdL:BUGXcN D^oN # TNR_B9O<s>I48(w#PE`"8Z\îX7ARq: )(?~C1V\E֢륲t\5R#_W?}y;TӀ(]Ϫ,F}voNջUe:IqpIaf)b::8A况Й:DG$FlpBા&6f7s١ng֥c-]IfF`& }^?_ok楳teiX'`PmsTjk k~zC '+(&/Qf 0$7b0! {G(Q҉AbE)ӵ/a'q\*i~?HQЉr%\#ى4qi OD@E43㜝o{ dDZAiщg/U,YPUU0b},v Y}STm3t}:*G#I;(nKw6O^~m|Ǥxp%DH 5cTҤyS&~qn\r]-C鬻³D6@g!)֏R#<CXK N}VIP ORʡ&}LT) f^~tkMGVv@H4X.+E.ݾ#*I9e݇.2.Z{;KjbWD570] \ nX8,TWms_).C} os+ea""zҢs9f?Jݟ]Ogd6/ ɹ `a"xЏaˀ{0jT]zDk`돈Y^7SDGL)jܝM6nW~d}:6lr}0k?;Wjr~~8W`]?4C|if65ߘ d !md@ˈE0$\rk۩Dh^w O6Sk-EN\9XŤ !7|Ԑ8&I,2P]{0-)ӸCb + ܈9v\񖽠ω!eS*uDO׹5,ŪR鄱T5U&\[T Ă*k|z#?Z-ዕ2#cjXЊgEZZqת5E7 5j)gYYۍ31Ç) Q0-8saAw 1TS̛#dӆKf7fSyC7zS}}+ b@17W ӑ 3K9|@ӝ/8Ӊ {Y?SxT_"5 kʅrI{ g<|S(RSԏ2B^:Amd7R !BScϘ)]l PH`_SM+]Xc_vT.y [[1\KH Ԍ^B@)N mE{•~SuTzٲJe;/rmT(@e0kP>3nnQ~mQ0s&/Z+wV=&,u[K n-4QвwN k 5!9*;>`Ӓ[gO@NlaćAӖU{Aۗ:h1R?kP&x1 <`]z1Eat iN{%/x2K3FHXyR8o8HU!Yr%H#V͏#i8N~(mǟ0F(rZll5F.X0j8p|pV- r%nP5_6ՙyM8}IH-wR c1|n(8d0#9~+80,hyCSԷ&q*I>|x&V. W#`tݹ/ߖzƯz߸5c:`&c4zzu{D `?)U D k"rk4ԬwcM6 US b{]A!SwϷyť2MWd*.# 14k;϶Xh1Dp {PFaIfk$Wߞ`\=Ob`L<6Tm- zpoc~K7sVJ?)eMZ7W'7_ t-7l!tIlGx3QLXs#%|[3J-wkC' կYPN* Xµ&X U Se.m#kM#6KNc#`!R^[얒4Q:} P PtkC:=-nYh - |.kzC+W 6snB/++Z^ك!b=P3Χ+^q럽 Bb̖sť^2yAǂ` 9]K ٕwI`ir S} f&Q YN9yR,ےFMWIU[œ!T믃"!az)K2; !$$=:Zx@5@.ˤ4bd-& .̴Xrd2բ {̻^ e/w_.&"M{z5kn0%aӛB^iq9ʆD!z'#dS$Mg LAlga L5i^y1'_D4=T_"_%MgWU`1vL/17Wo{B0KA9.=\HpjhQHJ٭6 8`*؊+oд{" O?%KgUf O_Zhj%Q Wؖ)Iu؉|- 5;Gd| rq>^oIn{!Ji/I>P3u{+T|a;'_~pf4ƒuؐƔ䔹(On&N(DSǖ?9J 3'H\3WlO1B=Umȫ]8t+\_%PT#$%@utג8;I6.6ABxLIKlq5%V:v'DI@ˀqWHyH#bS܎ qfl*< DJ&CPj C ^uLq G9u{R~܀: -ޏľqp?y2]Vvu]P.9C~Y\TwnN y0lN@0LSL@B}]u:jRPp#sG;Ӿ2 h摱aqBaAt2U پ6ʣ{9DR(t|iOxOwƜt hFHO `u9`.H{xLl-MFvPLXfNEX?:bP!a ߆G7]qu92Ƅ|}uYl,\Mwx[%F ;ܮG(2҆ît0YJ?Y@΀ǺǨh٠݁tL>Rpw.9̚%$J  phn ,d\)ZjlQ(x]8#R亊VIu@C靸M}/{T E.N\MY-MySc7ŝO Tndb~|lb^s+ft]UJs^mЄcXGi?!!6AG|Y҈:L鿨v28nD96Dѭ9:L+-`FsS@SS@ ڎ@(hƹMث1l0@DP'{NNfBN?r㉻hUg ĥ{y=[5]^/z;dRk.Y񢕰J['Oh)7\ԾC fFI8<;bNjA8t:3+ Z P/%" o9̴3dEMmM6ٝV7MV.x)g aA=lAͣW҇-mQcEAPφvS{C8H"XͺbEu(WBaߊ5M5FEVp^ g&u9q5 5, w=Ofq!] {@p[M O27 l7/̬l8 }1|^0XV"eF f˞gJ)I$F'=&M(:6T?:5zNAvq{Ч6yFaq!uC__$؁י/~#3s=*3'Qb#7fTC>X1Xܽ.5ʺ+r ^*J6kfY~FҀznekBǁ5bOr|KI9[>TmŠQ.sOs`!v O)]I޽dSrʸ4,G} B,17u\0/Zx []+(w@pօ/u7ϨŪ6mPGbM%{)xD>udOaX6_>8N}i q]^NE%CNwg6=D Es`Z#|ُ c W-'uJ&r+E6ruPa[Jq"?637pwGK!R57}J}0LEmIqIvͺГ }D1WQs'ᮅ0GO7k]uH26Gv 3ѴbbO8|g`_f$_ 'Sߡ>'m />C*50{GHqM[)@m+d#`d|_#!?!wņbb_caHe d#G`؃NN:s7rgr-/TsV׆?:3i@ch }2ɕYŅdfjشض7+e5u}YMՄhxXXщ][$|h+FY/s3˜FƷy-ܿzT q JpBGB#ޱ]<ݺ "\d2> ;#Jה裣9F'`  ^~1fg \i_)C§Bu?r*q x+&Zi؉3wv | uoVRǭnKC8bFA쯇A;/89hlԤXwFnW%TIzx^@&rc sF$׆1zg^ MtU# qPjDme#,_'+ɚ 8g}Ik%ϝ!LyǧjLDC:YM<|k6*oT``îű ~yЭ7C s$ʆ=nrw{V'2^_KY @wS[T8]Y!^ :آvQ?|0Tm@ nR׭}ƹ{w.?oTؾWKU>,gdsY/*gSVTد@;/Xk5{,|nX*71{dv0p}?ͦ|=] BnLd)]]6~vkZ~]2ݵ&_P4~lm-7vS& :N`J .z1M}׫Z-hA?._-81ϭOkԙ?a2y̳'='zLsVh(rK"hX6g\𧿩qC'MnMi˜K*rnfȳA;RY:}d]Q⬠EXz;2SB*5k$Lvȝؑ>"1:& EbJ,.nAIEFk~ 8j6pFwv5K9h*kll 5Bxf܍^a?HPi`M|XgsGI"i;SLZ "/7]3%5 x7NJ?s$3E*:ss5nu{-E6ب YZbY[n{TY[̺Nz;K\AYh)"0l4jRy)bdm|>,^:g8DB{ ;b$x6#PWh㼺mX#JNXtK꥝.}[7U"+><>lMбʫ0qb^g vv A*I;&h`8mb.V eŀߪE6G:8"u,",xq*rpr=O< Dl#F'|մIZ$ϫPGOVu'%Ct$ uz[*Wx-O嵐>J[>,uUJML38 \8EV.[NU}8:kʟLt w ^j*A;}He1q k Bu5j:v}VIc/h d;0iZl;S:|MZ~WH<- wk*@6$^0_^ٗ-ONG5HvGOlQQ{*Y'|(ZN2V͐X="wAOy/rljW|M9G+hWvǻ@ݶłe]S92%n4~qGOX@fǩwUv"$ڌj/f#Az=sભ3[V1P|gM($5b^9"A< o(Oh32ڢp15+0X× LYڹ>9u#fJ`fsDQFBڲB 0Enk/bj~Y>~7P!dH t5(PYr$kd,*vޘ-۠Q8lA2^9Ԭi3kLT$HoM~>Uv0kBU$NЀP_'_D~x'USg\Rd&t}!OnMEhWpP<<&FnG(.7\szkSs'QG,EMl{ *]OFCۿN<\3ϣL /,kJ$ײ;p@ ] 8Y5WY&A)fGF/լ*tjAsSmI>QNX3qIa]jls(n>OYY΍a_)K> ƳN1[raw5bE>6&dAO]6(? wO\m4CEXM_um )S)2F ́sf`Ud{(g[\=\~X⸌`s# )ȭ}4i#SC+ :wL6 )9cLOW/v1h OZWU,j0܂<,#r~`?Yo/ < m5=in!;o>*uЮSd+fUÓ[y!,NJa-c&o xpրX '^NsV8]NMurrRY8HN_NSjB<mV_*͐ 2!4t/bJI~u-GRV|9C~gmd|^{ZP ģoYj#ہ[sЉL2{Yz\lIar.X}/ ={ "  +Ml;G-Tԩ;;9ډ,cۅny|,RN6t_=PE />\x%fIVՁ 40#rw\wA W3p+fV2ۘx駫]?ddsoonw33!~ܤaMĆ}OfHJt I/gqiq䡢;co _&&O ਊ>WFAsVy-lYXKJn!d 艻͟@3;?en~| S,c-tʢl+rZ2{r5~@7J7ɾ0t2> kvXzt%?dtu*gc9q<^=I:DauQr~^"E]L.\{MSio *,̔{JsItFՐ] h 6"P5qE;w$ffބ,\Aƀ%<'ˈ#,1>6}XC5"pwǷ߈g٭MCod a$L"[|`OM^\e7(RW}>D ^^,Ym I,Z>\;+Cw23)p_N^. 0fBAf)7`s-JW=TwBLJ*n%$ ɡ+Ɨһ1[aHU|z>-?M >D2=bΩ3j1Rd]ux#,Mޓ |KIa>Qc{v9#!ڨ}Bp@u7sICi* _ZVyhҸg8:c4(uO[Oyc&75=N%6jĠߊ!Zw{g,3(w[<<c]JNPChF& :A*Z()]T7B,($㩨3P%cFQ{G'3XMk+ڔwC UiF[emhV>r#}MײmB2 ːI^XzO)n_a{[: [qmib \(67ޭ2QBsR+Z'j/ǮZ֓~$EJ@/ Á+De;FDWfa-U#{Ns}N{BR3i% VppY1LhK ڭ MGjhlUy7!l [&,.a4m]c]Sׂi,KJ0՛;JY}wuM^ԅy:]H_mx[{M&̋"FlsS+]-йs7SΜҶ4UT9f-1dL9\Pm;S[]u}$;48d}TVk(ApAeEQx /7Ml$$jindźZ- mfgO;xUW8L1zw=yZ3[yX,`OwWuiR'1y4|D&*3))d КطkT⩽/n) __f2jf:8Oa60F;a .kh -?"]ҮzB7 ,6ɝƎXjBlp _cՊM+w281~iSzp잍xb"cvX ~6dr)If<[y;⬭æ-=3#cA>LhHUϩ]MRO M FxL{apRsL6K7h_)Y$jғ !k(AXQ i]MN sT!X$W/ݤ?mۥh>9aK Y!4xh#{Ňf*c\HzF}}]ʔ*m %yY~;{Լ@M2Dŷ,bMqf:5Sb"$rF討ӱ%]25&Fأtg6 ɔ~S^Dx+pv5K:?+c{#--;ԧ QobAԼϠbbt /(@ uk,s\P>ԏ9d9х|`$|}ֱO%ej,tMn0 Sp ¾ p6ϐ-nBIv5 qI(mտa5zۛ%C zV&ATd1}8SPu:ip1/n %%f~vܭbO,'P{/za#~BɊp\7qqrO!.c^'25Ĭ}kEsFGA'x"&/AKMf]_٪޶Q k=&w׉K TÖ,S٧AegXx- !g[δQ;(n#Sbwvg]< |}y"@mzy>˳pbLkD,A=R|:xv&""NsT<*`N.Jq Y!W)O! 7af+!1NE!_`z]섲iF\3OEC\S$!xo,`S_FT~vygjn(0%Fx#lG[ɃE+^8?J(2| >'^==Eqi)ВYAgFNj&G1ȏPǤi_e\qDD9 FTN^F.P~# r,""Ja|Tׇ2q5"tNjECQf;)n_^ݗgG≮/N/ŽA\1hU!p#z'Qo5Z*(m 3}lY/K=ݞrPv&%{ |ݿs߿2 9*VfkuN!;]w>I~SNq0!\~b(&vqV׃?9F(".*o MāT(Gh-)wXmJsRۗ'&NLeM8655jjr̈ql$)^mJ%~ }v:}*zs6>eG 'هCdѹH[m3̒uA]TK%YÃ7Io]cΨ99΅z#a4~K 9%h8NN{ i F]0kF5 cTD&DcR)=v$"ړ(}DFw\\*`ƛd}ȩ u'RVJ!t3yOT~Es}coF&զq49KcȝO67۸D>Tf_ 5%\"D~77YA%<w;9{L3~I7Bh\^ t CY0Z :N3Xx.:0t{!@˵nc/G1/f#֥ v`n#{Va5Sddټ KQQNkd^ a.GAPHd*;M uN\cSeίg|*C`ԙ+Ig7.^gUC ,ؿ[pGIlcRc 4&E}+%,׷?0y# oP;C7#| ЀȿNO6" EH?m7EȯQ#:B=b10XFkmF sI_afx*S N2}x%7~8(P}q[h"BSJJ ˣ*/#?g\rjebab- /NglP:@o7/ GM#Cצ_$-7^axM/cuXbwFl̪4է&K*YWg?ug}g>CfXdM}Mql*拴C.ZY>jjb=A"Tmu?/w: :? x]6Ff:<{Q[#"y Wz_gd(F= :G ׵t5;M!VrB44}v`Q1P j׳M*h{IFO"zN񦬅䇿΋F"=h$S>V]DRV=tuN1nQ:&hY?r5H?D[tt P#lڗV CMF!x`}d -!"F+G jkv;aHh섷"~QTvzh+\xdݞ˷oPUT߃/gbV2woRL#byuj)LGP~2k_ ⻦;wl ]Ad\>cmYo{D>U߈ céq?}jm<س Գ |5yb昩/L˲ZfAЪ4!R ,=فy ÛJ:LyNҶusr2BFw5fZzq~* @x%U~$HixA ܠe#7qq Zuc \J U ظ$QR\d%TM $|Sn !mZe qgM ǛV`+2R&K3FE4 h[^PūN<$ŹQߡiL;0p8`,Am A4Im.TBݜuIteKUKFX8()6)r`K1,Y&A]ziUg1wzkQb1 nwh,x܈<c'v EQI&\!hf }7MrE<4Gy_oqvel-0hvbK_Xd>q/Ѳ1Bh9y8S )ДGFs)fT1ޗ.lPWoR!(}v:@zIVB[j9W?Gql5@5MwGHq+l8|4Rp:Kֵž/eN0wϓ_G%,!*_E! [gנ4w I $JX̷C(>0naSC =mDh8sw۳Q 8?uL mf#ScewxFZR)nT\{ORoũݝAHRNvW%x\ކw6PU2~!8}´I ʈȭ৵)\`](H;4&#EQRP3x5 xs;4ghP39b]޶PD΂ޒX) ̱+ą> Z}9EniqzUŽ_>QX{CN@iX&DY7 ux9RX l"Ahذbp"I 62*]W 9VF.xX>$a|ҋvDE* F *}1_}4Z<3(NNNUgВ/ YƟxnvw;r~޶Br_6P&HSEt^--]LWBp ͼbB":>w,>v+EF&dA)6!Ze}שyVc++ VE>e/ǁv6QA'a|[9# U\0"dI 䲭tj;i^cmtI^Ѕ9T9M_beD~ʡҊN;JE=qc>q R3v`Lck/RJ( Ӹɳ[ x1m#,Web?J ) Osr-5X ֎&3ӛ38)ӏU"H>7T̋{&GLzbk[+@ Q3jp?ї T :#Hy쳽PZ:u֧6&圁O>Bg,* U [8!)u֝(6>7\. /7`F ؆=nh4#;G1ixv8S[N;j.3+ ccHb ±^7s/?qQZ$v58 !)iB#Qeo(/]^} PB0磎GU4FDO2ѵ)Q7&ٗ%Ss7nT%1)3A%p&sچԔpm'{?݂֥?*hxdeZ}TbuIs7eO}?|Ok% <^/&fVx6ȧ}y53~5tf[F,gp7!_"$/rElU IezNoo^U%z{G@Eo]bq 8K FH V/"B-);ڇ[3&**3U5%W2y~ +ZJƔdǘRX3UUɘ'Jm@a}IંH_(KdњO Ct q lg;$O=im$neLLfOBH68X- K\N]&q>!PgUg,Nm&@ Fmi҆ݝtF3F @A&)lsDEe볘b6ßO;i1M/@xr:djty>r˅#Pa˚1egpɠԺ(ԛW{ dwTpJ9D뺂x\]QSJE9@m<$pijWz=8^󻔬("辊GTRH7^靫/5cƤ!~0Xt[ʲ<SC^21kdUxB%GE4VZCQh RS{bN "˓g$)NaCdy נG@^}9/)%E"xW8ߨmHhή"7>/BՎȵǤ<ڴIƐ3s /!c~qha(~CcAڜ&A%(#GOh[(d!QҪ4-x7v%v!Fܮ6&CX%t e.qϿ9MJ0:">nww/8kFB;Α: yXOa @u*F`NCt=v1?&yG S +_jLo D4mVf^nŁ;ȉA z%x UJn[pJiS혓$Š 9j9޹NcvlK=!"{VJ$>MJF_jC~c,LO 24EF-Es(@j;d tmQnP8#&`G -k-2<=ox}Qa%S' ;W.k Ŷvv|C a,o&|h*6_MLM|ܧ U۲_r^bg[NN$k[X0Z Zyɳi&>EpQmL/(rͱYyYjS .NJl0QmNB.c@ c&?ԈU@;B<P2G%Ծn? F5i)8SgOhJcq \q-vOUqwn 1>+=~V !<*AIIz5ȲHWsm xR0K<} '8QNkVcD&:jI8M@n=^ݔ%̫Tf" (#ĩnn> h!s3}pGAaO1W_d YĹAΓ2NVqX;-0u]+Ŏыd<.51"o&C#f-y-m6 Ⱥ8duْ|fVĉd4xtV{6oCSiRS-UUn豚 OL1ţ> Yipm`ڲ IpT כYj*c2ynLf~X(0@ ^=̈w-@RD"#ovm Ժ CmG} FGH .N7JHSmt[@퍳GoT+~I~OplNFtX;?a #z͊FDk"@/"9Q?QB{Ī~ו /ToN6|ZnYS 9(Wm\T\˘wJsd@z.ew%_h"kXr]Y7WF]kT] $p7^4_[jb-" p5-|Жd{:Ih;& d3pa/l8+D iMk<7LDr-MNVUt0;Jy.F}]}Cޑk⹚Փ | 6~y0_ t.wC=,2$k"zS'LQl>B4γ2F50HWMn 3Kb [Vgrؗ+D:~R`+Xn 1 [i?3W`A>F&wº PwȰL, wv_y tkkIJ&1`;U[D5&2SNN1Qc]mǜlPubE|mE^Pk jb ym1Y߇Agȯ謸 :䫦lz֯;nʋ<UL9f?6s8Q[ZC!l(_"θos^ ~jq^z[v5C9iӶV͌8wTw4^ްNM(ki` ?zZ9+ 3['^~5Z:ח L;}b T^1|tBԋrўk#^B_a,&RlXP 8 }"+mxɸdJz`rvZ-s`cr.C:Tӏ|O&pZ{q+s"/ sבFS^ "8VAhsMӂ5=6(U'\0،iUTJG)c6(0\5"9ZB)٦<""qƟ<&]8Q5u&ASx(!?d 1}rL* 4)z8>+l.LM+垸 C%.u!X}z" w͏=m3 bS*0ݯ MU)xq^59UN[{~Bk{CКўR-"I}ѱq-3}KO!K0f:(wminGMj"ŢebH¨c gů^*ԋ26YeSɲLG6`R= Ino$nKSc.dqV8}FJ1%ݽ eM]:]HG! g_5MԊuĤ{ XnV(}pBmi҂E~fxC՟~J8  MyxƠbm@a>x}nbz"iFn51_񎒪lpNnγ1RmD(DS="Ҥo}(ٝ񆟥#%]Yn!.0@S}D7e>7b tb>U!K5z<κL( 2Zb8$f6tbas$^XW{ɩ(ayLtMF 56yAWc%`UYMi}3k1ET´OZ9 ߂0|=,ИڰB;PiFALetrIKK±,oڡ7$yk}ʶ.F4ԥ_!]f4(3ub &L4kh\BLGgr/A)Х @vm7!z I cmma:vY s}>XmgW|wieTȣ JEĭuHmYl4Ӣw+%~WqU&R`kf$2wƐƠl KD Z0>2QD[ c-9Bb8 U2 o#ʈĨ͙z);Υ_!I%}]Z]rvy13R:qeO2Z6lq&-]d,7QXc {U{`#%ȵ[v 6 AlŻ&Re]qjo6jljR>Ja#yCNaٜ h!屵"SbMMM\ :(H[U*'u1C%mml6H|h++N}klQ@WV3L KuB L1nCe56a%5޸Z ȊLD̘ш`BuXqUlGrrPqTg+S>QRC ]Kyֻo mVBcSB1 TW6NQ4! */"IGu+I'G=u3&=:jQ.3pT'~.$/ QCA^woCzb-xb E vV Yܸ<; $G;tjVL?Rfu 3 _T].n"iވ(HtD"O cx&I`wg\ot0OĵxٻjD:<a+Q(8W.Vavedf7\Y[gOS:+;G4$yN%3وy}g-(G_dSbDzBS좕頍oAV%֊ǂ ~I]Ŵ\EЗ]&"G;'Yl2E5#dL5 býr,n|#'ɋXcO* ߷C-Ys1.I'<^Qц:q tŬN6PqW9 G' #~#nO, [q_ t"iISuFۥVU{:I=0Wt>cPUy@ips(^ лFH AHF< .} ͻ)9F-r}sqj2ya)_+DTҦ)`MA)U3bU)(l`-[L\8xA(i4ѥ|ox[~ ֺd!'gݑeu~yx- xT(/ J?MJP(ӹ)_/'AA-P]ީ\;TjRdz_y&%K٧ ܦڢ^AcPD.Vm:@f4WAG%h'ӜTsq*陝 r *,COLM|yQeG30H2lN- IVK |9?nm aI:$0M^}'BM:o0}G~$rlZUFϏi5p,>ed( жw2+rlU㭵7񻗐`mgqY@GdP8c(>gLRVLc,k_qUɕGR&ˋMv"ɓ"m|rw^mL|hjZ\c l[E ~MH"ߵȝ y,K{J͐2ZNCݗ l8(ʶ0Ha#7DBRƶ;Y*iˌd ?PzmL:To|^z nu=_gO⸋'rۦhУQB 7zs?I3M;pwscc&BBtf;ꚒN+<\Íj^'r4ki]v^D>S֜v;cmN5m] ز}.dӪawFڗ@qZ%7OiLL;b7{JP0PMsZ/\^N߬ sDc 48F2h%![5$\ʯi$!%}AW8QCƋű낑pn«7eV{]9ڨ  Z#4fݜC%ƇݰCXKPZܮ `ՀR =q<14z?cNf)zk{)y#ͺM,߰+ E#\q-=~qms4FT܊Hbu$czd,EX'5+I3XbUXa)KEV8c%R%4pW!/!V%1=cRu 3GܰCWQy|Z`H\|GacLBQL ic.3A=`5chv"HS=/=Rt-+NM54)"|;EᤘS#GfxYT\*wa sCS'Z)2zw7ASS?X\ԡ '1O,~/#, bb`M6Ëh-Sxy!X4jSbY_w.)Â7׏(|2cR9n YZ