samba-dsdb-modules-4.15.8+git.527.8d0c05d313e-150300.3.40.2 >  A cڝp9|Y$b䰡{O,nߙ]lSA~0JqDLhcsdp]NGopV%\Fb(tKNSs0[{dd/%ʱE,pr:/qNK1(a>ޫ.W*o_Aˣѩ (`T^.N︥R[g(#_&؝[11I'rG,y 縸M|X '? E*.x423a4f78b6b1c059486efa81dea8a9b21ad4733d0346029132f6c36b44b13f6a0c1a3f2726f7e1a38d20e5b26658682863a736a56eM̉cڝp9|!'s4j Y}e,0ZrcNX*\v)"Z R691x\h!:& XRcg<'hl*&l G#y~@-']>D7/QxXIn=%ryB~&wcd㇁˖S[Ж?svk3*Ox" N2N nOnO~^?f1sSϸ>pAl4?l$d0 > P ;RX^-|- - 0- - Q- -4--0-vv)*v()8)9-:>>;_@;gF;vG;-H<@-I<-X=$Y=,\=-]>4-^@bA cAdB4eB9fB<lB>uBP-vC-w\T-x]-y]zkkkkl Csamba-dsdb-modules4.15.8+git.527.8d0c05d313e150300.3.40.2Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.cs390zp33SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxs390xrm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigW7Gw7gWWW''7Xp7G'7GG7Y@'hpWi@G'''77GG'cעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcעcףcעcעcעcףcףcףcףcףcףcףcףcףcףcףcףcףcףcףcףcףe24f8d9e6b085d48402eb26493546bad7871dfc18df3daa06bc3a24239d0bcb4fa3d13a9f2f9321178be5eff0f4839fb06f2f020dda46bfca58aa97d652e950b826b71ae09046566917283160a320f3da14b13aab6f7bf8ae8f8a9f667cce92d91e93d39c20349837701667b8a80e95215d9455c9f21d7e3e8e80ce5d23561e1b315dc1b46443e501d0d1780faa24a9249d2c27283bdef46348f03fe7cb9a1379e029ca39ced8bd34a4a32ad919f5179eab1ecdd5e235d98806c23cbcae247b0a289ad4796c98fe3536247d0931038a9b7d32ac791319adb7111a1d51d90d8347f7df768178d656461b9ad4edaf37cd69eb83896503eb011c0c00ea1787279e1244ef8a8e40c92b2c8c19e1c2f5a27318d20c8dd7bf83272ca4e393dd7f31e129d1caf94a93a6a69a9affd4447c3998d88830f45495437f55be647c075ba20729f7e7fb3d237c5dc3a25d00a154d8b7d0dd3949f3e2f44b3e45e3ebdbadd96f871fae769127ec2afd86770c9ecb3ea7b44aec2f170897fa9cce0a24bd159cde20d9d61692ee055b90fb39014c66fa5a3500d550e0636c7623b70bed171e3718c83d327cad0b186b4ef4e521aa6b53a61cdbf816394c4785df50e2e77aae182e212cb02c1429c2aca313146bc2ee3dd51309296a5c1f4fb3eb6438b3e012249aa154f62039b474ee7d72cc677c41aa48afab787f11d2beb832cee87021375690ff6b1ca0dadf80b0723b5639cba77ec5d61b579d38f18e5ade85ee40dde5494a0a041efc0522000cb19eaffd1f1163b5c2b57521b52910cf0792967a16c32da81f3c32d80a5583525020a615d3c802960bca84bf8b65529bf1554dc549e07f3ffdfc1d48c05aad68f29653e114fcd19117e7019b67a288b300d91cd261b90c018e5c279c4b402bed163db8ffe0f19dba216b66957248f1b652e2183f1e17dc1b7eb123373b2d4776a78cbf2f20680f1039944e8623428bc91cbd3ca2766140cf992e2ce2e67e7c0291b0e469a39ae496e5441267cc4080cb93b30a9fa2fd0bdbecf59e928a1b47487ce3a03ec707cf8aea2d41dfc63dd4687fe7ce5e1448967ef4792d2fb7e4ae7bf9e8c3028047b96d968f969366354e502cc1ee47d450577e4fe0b580aee2a666db0b2d722331d676237ce0a4b49ee28dcaf941dbddd4971d7a5530eaaa2bba7f774b524d4f44f8231f92383fbc9b05002bc767eea684fce7c52f9994fc4e2b7ef044e4997398877923d94a25f54d57ab84fa22b3611a604583672df1908ecd5a8609b6c55983feac104cd6d2414c684befde808b2ad6dcb06a36c9d41f47de852b613f6fd492ffb3a9df61de995aef687b1a75e76c39604381cc72174adbe8ac7587eb2e450c0ea6339aabf19b0907149f052a970c8b10d744be47b2625f6c9ad621e09d872eb8c170c0dd551f78359c63fabbcf118d10887bc13cb2c689447aaa4f1289b9e7d65283fdc4909da8117559cb264816f4564c7455c3325116d4a6fb17649fd5e080f9d15012685247acc36228912a7310e60328045077ad299d4ae0d359cf8e45594f1729bcd73bfcad0b64c60bbcb1e1400a628e0fb30037f5aed3979bb24df9d4bca8bfd6904a0b2aeb24f7044cbee1194da7aee6d923d7e223c439627008a9cefa244fe55f9ba7d50b2fffd5b71ee00f92fb9e5f0ab974bb878534d6a335db01c8153b7238f852bb7be7e689b38c16dfee473f3a068616d5282255b7984f4ca013f5d9bd492e63298296edfeb5f246ee780d66a2c5b1155cdd8be98ef0fbf076527f69e5657f4c898caf03ae3e195a6546b5c68542162c8ac5b00d7bdfbac166c877077c44a5999ee33650b2141fbaf9556851863b2fbe1ad5a92125c33695285f9b01f591b9efa0c23a843904a403490a4af454ed3d5fbb0666d76e865eeb8aed7819eaa7717258335a6f4741c19920fc7cc4e870813215c7ecf5e4842fedbaaa7e062c0d5da3b25e7d91824bf653b3ea124767eff88d2735d0fd7fd4e5b16f93567bde5b5f7fe5637a9a0b385f0a53443rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.8+git.527.8d0c05d313e-150300.3.40.2.src.rpmsamba-dsdb-modulessamba-dsdb-modules(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfiglibMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb.so.2(LDB_2.4.4)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_S390X)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.33.0.4-14.6.0-14.0-15.2-14.15.8+git.527.8d0c05d313e4.14.3cM@b@b@b@ba@bascabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigs390zp33 1662113814  !"#$%&'()*+,-4.15.8+git.527.8d0c05d313e-150300.3.40.24.15.8+git.527.8d0c05d313e-150300.3.40.2acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:25692/SUSE_SLE-15-SP3_Update/31bcd539228044ed3b978b6d5b198532-samba.SUSE_SLE-15-SP3_Updatecpioxz5s390x-suse-linux  !"#$%&'()*+,ELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a2d6f128515b366930513f74b6399244bcfa1d7c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8f1340e869ac1e97b488216733f7816b51f08c7c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=82c991a579a87fa1b28e9277989a7dd0b66e7858, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6e5168c83f9b5d45fce8d3b8fbc2af80a398bf28, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=00fa8c40c5e6ec3aa449606c9d9cea2b8a79e831, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7b2254a65ef2fec598baadb2d55afa3c31b27821, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f66b7c33e793004b7f401ace7125e805d8451e84, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=63e2e84fd4210325379fc34b295b0c86890a78a6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d7e4a5e37ef99b25067563d004417f59e0792490, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c373516848affcbf25483a0ae3e7aaa7d95f41e4, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4008e9b5c24550660b6b1350484e3ac6bdf64102, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=33b78ec3d14e4b3e5ce3092064ed85d85481bc58, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2aca0dedb38f97591ba6b4a4ac0105f18db46173, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=dfcf2709d81b99f4224236922ffe114003d923b7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=96232114099938c78dfc508ee4d9a32a2cb53aa8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=818807ec33fba5f01b361981109d1975390da974, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=216102add310772c963d19534f4546da84edec1d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=48b4671a01ac001498adb8d8d69ec404f4310784, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=268fda08e6f5552df918c59f8f619a6b11cdd7be, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=753ff93df38c46f5e9aa1ba6a51ed381c6c451b0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4896dabd5bab3fe1443157c44f227286d80929ef, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=573b37031ae3b72986d792fe1968fcdf840f13aa, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=33301243f035308472336cca6e5a81f94fccacf9, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c9763e3703d6c67b13858f545e408e186d8602ab, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=db5e17f49cfb770edb996b1d13dd6891d622658f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e196fdeef6c9ee189aaba476efafdf2b73972322, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b75bb8ce167bb436333ea349e222004cef639603, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4afb70ec2d862444efd4162343028d7005a2f3c5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6fc67e57a984349a9d21e8d6eecefd4d23fb343e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=84ed0d18a01020940ca9afd24a08efa0f0ef100a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a172c58daaa7e22fb29699bc78d3f847acdbc096, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8b8c0c11e4ac93218d49f4eeaec7bfe5ba27f6d6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=70351ba731adb086f60079738c1ac1b7d995f424, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7e6f481ee41b38f5349f47aedc42597b1f381ba5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=55c80b3b0e82d5674331cc7cc91c32d2517d1991, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d829e79c629b6d435a78c7a02cd5129fcd1c0966, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c92c1add61d35ff6f16e39d4629baa0df605aa69, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ffec031e324228c08a87e71afa62c07e37cc5a52, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4e8592005f5408e2fdebaf4e8de211f83bea34a6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a2fbba0f1f757e6fcfd341aeff5a872127aadba3, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1ace251a48d599a3a2c330c6d33efe43639ce148, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e529c641180a20db00d78edf7b7301db883f8364, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ee4200f11021db0bd4cecd59e4646e583d2431ca, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=37caeaeeb651f87467e408891cb8ee1c78942c4c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=027ee0511dd65955cfc90cdc61a556017b9a0a23, stripped7Daq 8BJbn#KW#-7IYjw    7 ( - "  R]RWR,RR@R_ReR R RFRSR*R0R.RRR\R+RER^RRRR?RVR)RdR-RRFRWR_R]R@RYReR R RSRR1R6R7R0R.RRXRER^R?RVR\RRRdR-RR@ReR]R7R.R0R R R\R?RdR-RR]R[RYRWR R RFRGRRURReRRSR0R.RRZRRR\RERXRRTRVRRdR-RRgRWReRiRSR0R.R R RVRRRfRhRdR-RR]R R R@RFRGR_ReRSRYR=R/R5R0R.RRERRXR\R^R?RRRdR-RRBR]R@R_ReR R RFRRSR#R6R0R.RRER^R?RAR\RRR"RdR-RRWRDRIRlR@RnRURReR R RRSR0R.RRRRCRERRkRVRTR?RRRmRdR-RRR]ReR_R R R0R.RR^R\RdR-RRORFRMRBR%ReR R RR]R0R.RR\RNRERARLRdR-R$RRR_R@ReR R R7R4R0R1R.RR^R?RdR-RR]RFRR@ReR R R_R7R0R.RERR\R^R?RdR-RR]ReRR@RYR_R R R4R0R1R.RR\RXR^R?RdR-RR]RWR[R R R_RReRRYRRSR0R.RRZRRR^R\RXRRVRRdR-RRR_R R R0R.RR^R-RRR R R0R.RR-RR]RFR#R@ReRSR_R R R;R3R0R.RRRER^R?R\RRR"RdR-RReR_RSR R R0R.R^RRRdR-RRR@ReR_R]R R R0R1R.RR\R^R?RdR-RReRR@R]R R R0R1R.RR\R?RdR-RRRFReR_R=R.R0R R RERR^RdR-RRBRFR@RUR R RYReR]RRSR0R.R_RR^R\RERXRARRR?RTRdR-RRGRFReR R R0R3R.RERdR-RR@RgRMRWReR R R RjRiR]RRSR)_V{0\Xutf-8ca8fa0018fdfa69eced599af5a9e4c4dc2cc7691df43cc06e8ead116c77ae3b1?7zXZ !t/'] crv9we߮sL/ae ]Vnq`hYaV ŧ:WNOMw{ACΌNG0qYE`kLrLŵ9g:i9Vu-s7(3QpeP;KS>M)#ӶC2biN|N`HIhsP `6ο0 O`%ȑ`| 8\ `$d덻!¿`{ ?aCtZR=iGqXTarŐFh'8rSh? ;)R >.(+}b% (05ju߂\6=4 X:aaX3c2:9&(ʅ0b4c|8Չd^.xn^ctN6@K\4oF0fq`dވo Nf *͓}َ}5[ŔڭPY~HhPk|r7vnBF 'IOBSC9! -Y7/ٻBP`9@oAþ\k$ W5n0O pm/5BNMԹGgf*rɓ:ŶASPy| ߵ9屍Y>bv5ͅ?Z9r)ːjƏ}qP;=wK3p@s"&%x5,Rs?>HMlxaG H4ZKsv /-Ę_%뚍Hޜ9y?9(e m_ IɐXB\ nȮ=޸+ S4̉"xܽr*B˶ր\*n_6|KA@p?sm4cÅ A^Q{R|~gh?قk%^32<:x\G^U][m iK_ьKW{MUᒍ*#ָV>?>\7ȴ%˦7hNf8P,@7FϷ!I}6_w<GHpr4kt>dc#(!2wb HJ(3YcЭfFc{A;R 2. d\nB,oޚ.ǜ{㎱}P;ޫ` #Őo *r6Hx?JrM Hlds]+@#}?ixt<&nP$g&  @N!n W-@}Rֿ@| $pk=yVEijBiT8jSToݢ&{MU sn'P }Zi< B4(4Ql@RDF͇U-r5Mإ%~a&'}M4eǾ6N>/ZXm#W|ڴb]K^EKj_F 7w##]G`{΋U&ݰSyŇt"9NhYx^k_{up@t}ԛlA-i/փ=?u;7!.S͢p;Z֑ i 'УVoR:7~ǎasaQ\A !r}s) #NL K@0,;z`{-ʠ^2'4.v`'-suhQAؕdkˁTnx1UtF*FĠ㍀Nj6U9<%˓> ._0j9r)O-aS6'Mf`ʁe=˸5bN7Igm}@7ZJ#ޏޏ)(TN?w:uy (0 }z ܚFϜ⚶v=#!0JvРgVv/؁bϭ'۱F\"R؉n,gb14ol9G߻ui x-לʘa]Oiv.w}`Jj6!2:R ?Zb=IB#4jWx6Xy y[?^GA v&K>u}$94>Cq+űA<] ٺ]J>iԋ܅UFZ"l v3d?,Xv.4ڻ=QD:Tw!`䚆}[[@d瑚9䔧i=}4O~UJ(o:L[,sӿQ@<5إ"?fs6oEȁ=*r»CX'Œqrt"<~ t|##G uNIqWh6 y_7fn2"z-PV6QJCUZ#v9[և m%V'Y`rn!ڒ; & >eX7]z2FژKw0U)%i}V#}iq)_57 _\:IAn?<#۳i(+i!mJ`aGQV eBRUBhmu79$2p!NxxiUm4w^=i鮨DɴNi֦JbnVy^nu51v荭˝g *- \ nt̛ਊy+c#ϗxh=wȮ+p soi=h<WPKVXyfGh!1 JuiP%5*BƏK܄6a= */;rPl=DcU.e$_s`f'HP~k7 &M,կ~vـwϪon YJ6|祠5^dߕx?zgox"'=rXe c֜;O`^RD.$"lfYl]9q)Qi-_WS:(zFŠ,ҳoӀaN762?>^;vo`y3fyvpCT.Ef5yH#;ia` %[P.ڇ@i0@'#X|Rx0δh7PC(xHLqLy˛u>>Vj;Gxhĝ46]-$U2vrvM&Ot.w. S`"t6=[]*ז qDtr -?k-޺VRY>NIW֒p߯# ڧlʫ VƷp5;3-£W*LcfW*@EIN'IyO{tHXϐ(T2o?Ye[+I5_r%=ORn)wt0%zt.Sog7;s= 3$2)s†30B/{*auBp,TUpaA]Gr[%Ye` c{=+vl--FEQuū+ҖM3?l9m7ԎSy,'_@4oyWDPQ6覲(޺~#?9>`e`vc~lr01=(qDb%X@Db70iK''^1a{67Jx/SsmsNn ``zXg{q*"%_Etmhu Kik*ښaVѮq=NhY*l2NóP Y \H~q9~_r0/AK U#FuwPrӮKHRJWMJ2oad;*<*(B$\\IM|c sT8>slqqGnTG`8qě?Mi2HG WC0]L>xː`FۦAdS>]4Ãdr3(Qm|YObdLiC# %|~gT L 灐1`aN M;5\}WĹXwe@UEo;D=[Kt*{0|q`B<lj0⚇,!v$EрzPY'1`j \nD@.!Jb{75Sz"Ņ̰ Ay{M&{Ô\]ik!~o9ĎucPVZ*FQAڪ-ԫ}hq:;z}QX7Hy&9_! 'bI䀦) d.`FYQʽVmb ey_cblƸrFi(^C».lR;}aZĦU{`7̞eW/@le*Hb6 b@߻3tj)~r_9D([^pQJNLJLA5c_VL"1@Q%4'bwNF^u3#"@<dԃe Y{NƉːcT#eҭ"ϞMjedCEOJy9 kt֫#Y(j*#kҪy)STqIB-xgrsVq'bŗ3,ҫ$_tB0b2ƀtT<[H>ʶȧȏ{vڍ>gsW}ܡ* +LgE+5"3^R ɑ `xmƂfg.ɐG^k _ZEbcu/C[tzk2lBܛ+|qQ~K0L* 5]D kp4qaJOH^wiZT,킌Sj(Y8`zk1*'nt=Yn'9k2I)'*S>b܈Q4Q}9:aeRcrGĈ3I:si4-t 'ndjFd@c/"y Efm,V60zm~  *[.ƕnv@q(1M۷~8(WUpe$(tQNaSv*;iw/)3H6Xa{tb%M:莮0LJn(IrS6Wkם6-$3/HΎ\3eAHZ P^9#CX֥u@pUxBoKoHzrE!^K~L_[+SNfm+ebwsΞ78 GL`KXȞJ Z56@Fwsj86Ȼa9C/m7R5{̰9 &恀؎>ʊ[0I#m"SȤ 7Zꍽ`\/OY9:)= I~ԈS{3͕4ۥzHYdVA"ɧrpW]j#j)I !=Tt v婍U 5-(7.CBmHyj=QQ2x(4G[ *s\d=E)) ӊ8ֳ0!ZMM) ҳN遌4޳ž VИH1kE+MKf \ry -/ASeyQ_P]!O->}[^ YoeU[.y*!t成ߎ9_alJHxy Z `:#U^qw|!wdܗ&Jx!2q@~GzޱG) Iar3%ɮ.f+( JG:$߬uzϥ?wY[ pMrxb!bc$# 8#T(piM]o=פ양ZGFkI-KDneJHzVumPHaaG 4^J!YͰ&Q7q> _|OːkEA`M#4L*sߧ&;O-tj$ƈjγ)8)*#ӧ@ϝkֺ<֔LcS;7" `W#i1PXSbDwaGWKdޡY3઼:7ZnQ͘1164>^xpСpAG(-_=~—CtqHMֹ0Ovp  uζa@R[xrk_F`yZ] ꌽqNܜ]F2R> {+lEL1 [QvCrZcV R@LSrRU/cZbl\'Dxl&#UN! 99)mp%PfAhu}f  6;rP ,4F_>A3UϾՍsNqqٕ+U_GհJvWt"}3cMAns%=`/s` 5IhrS}だ?tVa#|?\E+}wF2\S\$u77T)^ľP~S ڱF63%^f0\dL2$ޯ%];Bөe&(+A#_j 8ݕiiCa憵NEn(`ȫY]"=Sdy#ִuAMpa*u8AjG^ݴ͆<rSPeQvmEjU%ƢϜ[ɢE"k-fV7̙6^a60gc/lyxz=R]աKfI876e9nZaT2вdU> qx)ajV8r6qp²͇'7 Rd & {غYa$G~%u{T])|F ʏ*mq)fD6'6ۃ]MV[!-V֡kG@m &7-\B4_`6vqPVŎC~VcWaqg #1hUy o @BG(>z3@9~ns䴒t "!"x_Yu\{bTWo/=@n#sᵧtikh^¼(^;fѾt!=Ǝ(o7{&]=-:,&IHM[/tBcqo_aSʰS5$!p#3Oe#FVr#ۯS|IpBn@84N7$mԸOi5"EzϾd: Δ1o'kkXɷ%T%ufEngkgqF:C^.1b (H_6"[=?=(q i.Z _7WZkL!7֒[x(:_ 煶œ$G74ee!!Ԕgn!||')CɜMgSQˏ>qzcPL2GZ:{^ 2Afcv*Q|8?E"pCUFYy(OB~w,=႞&х&ɵz–hc:C|Wo6e-S28](r$H߮b Sx-X ,[!$1e`%=噇Q2U3VH,nag܅B@i+|)g, E`Cs\l2PmH$/վޝySᡖ@(@d+q1R845mjxo[8?+ZZ (?/f+5Z"٦P%? /46v/ȶ 3VQS6X޻5swz\(˫.ʝlzFͲ N*ެujM^Jѓ ėI˕bj;l1m$땿G e<ϺmU %gX5Ek(}Z6:>v2Yq'D1׵# S ɠ ;\{Fn =P.U{PqSrEȺTq&婦UOiQ}[Zp&z1T[`!r'ƬLMwo0-3|V4;YƻTyUGmgU],~ ~D 022"qCK~+xswəjq1KX{efo+{>{!94H=@Ml<>+ŌD,A"!wk>YShcRPR&[cʸ]}4I2a8pd2ҙf N ײLʟo#YgE~H+yWфEPN Zd`;H~Rty`"pA ڭLWD:gvؕe;ܕkYnOjQ>Ei=,/)^jP%.G[+FĈ cqaf]DJL x =] eF\y²FĿf㯱Fl-ϵ\Y8:SKd$(طΏsT[g-NTt,R'?YqJaXqzLML&FeդީU*Txq!2y[32+!mPa֑MJc Z-ȗWw X``>œtFJ>>w(,kA)H~(=(uo^L5Ω}8:Usyj[J?zyd .xA2ㅀ.+ i#l1Nn%vyU۩h^R UzezB1S7}4uTol=h6HV~3lh[vhטcEЬ?XւS*f^znc]ԍ>idJ>*cWm[[=# ^J B˹"R.p#ӄ2gPy#߭-`ʹm{$t:0|dĊu( 6y-ݍNZ_taC!5>=YW8rvUj޸2 ]!2(8PO&(7,Szi$3Axp޶WB:é⮑ zUI*{u{zЪYmlaͽ%6--3_|QG"Kǟ"s|Ά˱D:o_u0Q&CC= 042NIHe,woE%Jot}AХhtނK\Nڢ'Vae Iv6/US ހ8 "ϡxS©0 |-u~K'w0P&~&nfmic;1t(eV{л"z'쫉ߏ' R%(<{|c[s'; F9-`C4b%XN96d5׶hX]Hz@&7mJG'ROO}a6{=;7`f)ڧpS*U~cGʃfAcKzf#ShsAWq!qO VgUV7.q3kc_3bŀ[02}&Fw%of ȟ i<&NUDxs nKQZ\ut ^?MH<͘l1; GAȁqWP2 %VnKGwxx w27ۤ\ e]E 2Ҹk葻:y@8"=["+_Ê7VW7;~ ca7xjU0h_ӷjj8KzP]}ilKa{ .U'|ޯ.!{F!+" iV%l؋G#W }Z6}s!O$-ޭF"r&;PNr˶Ni+]iG 'i昢sUf0wh] Ħ lQ%1uG:i>v )$r)Qf㨡|+ɡޞE & w;X8uݢ"Ԕe_0U~W ˇk技 ) UhgJpr.GLCnA$)@>N?#dx9K)ˈ {<֯`;ZPĜ] j:>`Pރйh*K2 *zMԭ4:g-&^+wF2gL)߷Ǹx9Ƙ5AbLqv+-Dq¯a[L! s ;c:`縪jGyŠ:\K)HG@E3~0ȓEQ~eL1yE\'(Y:(ݽ fڐHL~6z'M2\cEAtSZ:B9,57Km_+-KߔA[FJ٠TV^fMg^_I*v76hR54ҙT"_@ui@в{iyt0#\&F*ى-}bBpx<1lRm頲b0Z\bq 8rw"%Mg eo8kI2a[>]䱾BwQÄiW=jf;UP+++xd=5P)*m #BxszpvyїAZQsp&,4,Ka*^S*=Sw@0t o z@[~~1lSTKX .[Ze_*iYfM6s4|ݹ@DSuA$ABr^ȅXPug~ ;ןۓk)4*fiY|}]blAC\pn$#ڝGQ` ðVLܦ`1?rGﻮ_T=Of6$@8i(kԛx%1fx~M۶W?BOug* @=k{X$fDBi \^ U2T^X|r 0d(;O15Yg %DS3)MA=+"+@#krɄNP srBP=QNl׭m(vneWnͳyj^"Ʋ%:˟7}]7)0jnDSyCg}sou.2RƏrӓX-cE`j(h2Æ {n}8&/kxn1RN䛐8e2:-B6bs|9mA_a].@OXʮlbe3EnsI4 6Y-c6%ۘ؝-.r!Ab)K\Q٣1evΔ^)X!hϨD A ;]Vۈ}{I*/^&.""jjG[ oǫd{֘˥ rONY$ }@P0?{VM4z8WrVڌbjLqL͂l8ˆ'80 s y\Q #tSjA{c3#V6VCa0 76<~L.\ ߋAQ6%"֢gid6\`$ɮv"m&>D{NxLdI![֚ͬ ɹ< \O۲۰M#Fڲl]XmNLU88iҞ0<(G G0#ۊB҅>ܹ$k2Fכj3-@_  Lv#b5C7#i  dVSԔ3Lq^.I庈=+7\Xj֧mn  Ax6" v2jKQ`܌t,~eYV%ycG UG;M'L>Y: ,ȪchL 4-sbk_(z $3I NHp0U](tЊ7)wZ_SyTk%\8D+Ajt1Hd9|f &Tj]ĤjrV`RS̥.-GS)aU|5<>FDF"D_:~X06Q dnѳ-*rbG/:uHhy>ܬmk[.O'קaNI=*`ф=;^tZq))@ o3Gxk޺DtW|=eddvf%_|{+2R t`X"'¿z'c F;:>v#C}^@۲u9$)Ȗ^ yU$?)qa,yIN<{&ߤxS&E9m$J+ ] p/Qq-مmC^+#T0>!o/GkfA]N`&ͳW~bk4w J5qEn0/8k@ Q c3 P?w/[}0+k ƣqt-q;JXhjhH`,ꇟ]=ګ ЕbI @8 S+^'2SEc(h {F55Law2͈RX/rn>f8Tf? gX^iǾEhmR$05k,uv. f׉zQOG)BdŦIMoqH#N7p&|P?QU> ka}%7jAoGRY2fD0DV8ѕ젟83xj TE RLŢ9,D<3V FEIDőZ@ݪie۸e猋8E]"}P;#ós`ő[ktҲD :.k!A/ PO$xf&l 74䢋P&Z=)HV~X/OUY!/RgMK20ӗc8픘C}sRC{L̅8~mb~aA6yR0'psU({U|Wfʹc#o!Tjɍe]?i;7l7|v)Mj"~1WSez0h̟]9XqY $*vݥj dzfҴqoij :alPk9fI_8ɿ7tH[ڣ8ODN>g 2e7)8N$ *eN`Ywl[@f"Q/mZҍz^E*Å-Co!语 RMPCM{WU0ϓ9} i@1)ѻ35@YZ E[W  L:5?& @[U P$]G2L鲢+VtLԗ.AD9Կ]@i^kpU!Y7~(V!ndUg:MHhr,Xf(8d=I'5EsBED8P]QX)_$?nv釷l]-oßȰ `]!ߖ̰ڈ8-| '089mY"NӁ?t7'E\q CVp4.r>w6;=SDBIRcMt~/wƆe._m^r6S"A<9eV:2O{kkJba}v=lٞ#AT[w-D#<% 5?3tTvֲugԐxTJ_p@V; 5JG+K#Bt i$1b%QchoU:wȎ6_{LRjdo2BtZAM2ƌ75yycr I CqXG8ܞ N)'az;Pba؇+_I9pLwi@瑾ק3h Hpdy$K5"9 :-rZ;yCbAmp' r\wRܦnNPۚͺl&![&9 4?>N1*}i_VRjo|]O FLb}y/l*Gڈp"0\%f+ڶb8};A֓psN)E&6"m֣/pZ|lNcFS19sZ7Q:d+٤Y7Hh\![2~E!TB4p~^ = /riѪŌtꞟ*`!J5Fj)IP+'JQq6.]59A5'^'Kwku8 /55NOڠ.c_4 -D*gP ?<@:g"HWge%z|Tb* 6-ꂰjuP#<ÚIuA;=m^ q={Q:%+g}QozY~ 6 6FQɐ;_ix󭻳 I~,Oy.-,eWph{ڷPChl-!"X8 ?ms֏tMdv c,N(l!B~?R/Ƥ̒FKKRhLBwօG,k|5Ll&ێG#"h;/]7!Gl7ë5B7@{ȽD%q ؟UIn0`-tG>mk!:Kޞ0m_Utf8τw[࿪6㣱,t yj&pUPMhH #DWpG̫]Y=C,ݫ!X((pff?h pL)+1T] K7# =Nc$Pd^sowH q[+x|e9;zpEo/>ZIMkN/&?%=KА(0;g|>s-ZC,څbIX8UΫMwD͙䆵ITb**rzFąm k7]+~j{/}MY6XTƺ.iS0:sC!r\.Ih2%xP8[3~4n+zq/D3~Ȩa-OMhǰ[]grlxKL!vLzUj5 }l3qY / 3ko93_'Pd,Ud=i6sM;zJL%xZ HpGzMyҽ&s.nl* _.D @=3*)ʪ |k;rxT525!VYjF_Oބך7g@UeIPC/hg tDiͭXI^Mu!M+%~]]( 7cp/Q#'}V9w^,LEy&#S˄҈PetL&=)p^%k6 U SSV 1ꢴ\ >NU]b;ad 0]$PІOç2HPT$RFX2([(st(68=B ԱRΞ"Qər성(j'/l9{.C'Ph8k0}gxT`f;!&䖩[Muhޡ:(-(2M ]]x)tey}iDy-YA$,C3=J%& 6kT8P\ / "#&BmJy(ƙQ5 #HXuO7-N\|ׇ#=0jODF?TC9m|PLq]hp1rH= Ȍ|iZ`^1m8CBt2'}? ]eI-2 fIyo ,NՋg&0m4="̷-cQao*{l n(Tef*{:.R::"L9i(q߀ZL8^\-(i"rCOip?/ݻLL WuQnz bg`js߶,݂o=J"]vAPz ]N{Whڥ}tUHXU=͠<8jvgPTPesP(CeO8bih k!Hd0kv].Gd6Ѧ{AChZ,±PCT 65*3?&}G]oM,Hq@'x2݃h)q@Yb\LQP&QK|Rar|J\_10`2@g"ƖRnDVJuo;=j#]@ !%IMT7aAPNi-Cq/}V||5f?WtvɦTVmG ]KO}|_+}rpߑvlQ!҂״]o_ЊGδF*0𝏜z8DjYGׁ? [6$!t+-éSSj~Bw?{d? :ܻ$e:<◑u.ׁe I= MA$J 8$Y_ug^ sERx-T@ImPeyz ;yM0UՐf0!^Xd VV}fOB]Dn>^LTjP(d#}}&=*k;M/cd akڱ-eN4Lqy*@ ] 9~ ֡`tx [4\Թ@SF˾YR&"T&RmBr]zyD}9GTEt,$vdZh>qK]}>o=At%'>}2Hj7)lgАfډ^#}>P5r-SR-egh]Mn2tQH 1! ,nUU-wWnfL^M FwߌC{Z;=1o }B&q eK(Җ ]"V`1y`hbJ)E1/ajr"[ѣaf{ѢoݚJ4נ_g(1>$S:]R5طlj'K˱U3@/8Skwr(>ya }% =8XRVkqժ؜/prg#t`84eZ`[1þtيd|gjt0Gza`*HZ?|9/A;|ɟx^kD[wv%b :! |oq *bT)=:DKY˂} 'nr =@ 8t]"•~i]f1lUX$"T_y)`^v:Zla.l>۲'?CR/9BƊX$3I+s0FTv1( (qu{51A#6&*"f2& a36rTEX}aOy% U1Eg76_+NqP%ݒ`5;MgHK6p9FkƋ棼"u&Z +-v֍ɴp\*J JR v5:Lg"RHH8XE+9UFTmuZݔlbb&0Gt E=s+{&E_8rOpHN#Nr0lpkL-'L3 }(E_oߤBI&CHRu.Z[I ܫ+".H^;oLfɶLfl#KUrjbzZYۯ.K R'w9&k?2s* {[֜PՆ:L3R ޭTmch$`QĽZؽ҉)y&Hȭuc7 WO\{uzܿ?<k"\s9*P(OI2FWWw2IeNw-yA+wG_a!ipW+Ex̻ZZ'Rjpg-D]XT|E,B#JwD-%HX]%ʕNJ-m`~z&T:bI9{i-Owo"}9E37s /EfGSP\L萝׊spq/jꨶnC5]PHħWuD8#N#y:VC3gU"FI Vqz騵BOU՚hD-xAHXS EG\0&/[.SP}WfgZtmj!`&yx #TGGM_A`2`v , Pp,˥Ø1LZZK pJ&$v,(40܁"."0v^}sܱhh43L[h,#-?;Ͻl2eoI3,ذM]w0\qJګ) ~fLMgޚП\A D^vٞz*i,*\PiS~'n\ۘm1 ׷bO蜫/$lMs&y3"݁Y#=Fd ~oV٨/o@= %_!U=]@8-ݼh[wLx|zבQ*tJouY6,cafN(C Px9ȡ qj[i])L&bJ|L`cƀZ}y@?s!+,| RsqE͘j]S8yM`ҘC%(]PYB~>;C\Msֵ#OIBvGJzQ+lQGp.9 hG% J.]!}|Y'Sm$$4+ n)w L%KKֵaғ[L!K? 5{=/p*k:}P9=̓rT5^x`9h3H0o䨳 :a㤏Dt`; Z|8EU;0;oA8 GwB{5_{ K׀Iڽ8 &#yfpECU0:c7T|:v vҎ}l965]3v h>a«hQDfBh7qudMO5s3B`-jx+i&%{Ұ8Ez7*We?yN2v\jHMgFCϸ[IDW 31nۓU3 Ξ#>;MhLFpRd: *3ŋF wuOH`0ٚv88u<Z> 沈\JmAMI#i1$W'c6Mʬ$&eKjEG 6oO(,mC!EōaEi?;W vU{ꄓ( ֪<":?-X4%*ۊ31"Wv>cB\U 5e 8#M⽱8PmL㐪 (.`T(E{v; +5FܕN;ND em거 Z[*RBp*it%ȕkq6uM5dybT : vBf.b,җb\ s@_dqxj'nl}F Fsm)laΟ/f錦Qtavlz0i eQ>˦YN \߿M]Z/QŊ>:WGo̰eWų 3_Nx : 1ՕaIU{!f;=KZ$8Gapcˑę i[ݟ^(u9]PSq1@PfSu,I}vIK>B%Yש{<_ cK4!s%-JuU:? Յ/=|tj5Z(εK#+}G_g`Hkցn eB5NM 4@Qז(J0d,sS xK?(/Z,#B,'qm~8S.XenFjƵPp;|4PF߀r:ȍFGW#PzuȤ{`'JFw)BqbM1!/+hCfD'8'kS*e";Z3FMl $pɕyt^1!n2P"CS4g`F={ 5f)ba/\E_(=DEI ٤6))iL1'<7j*9v_(#t b0e|36 #<mU uOIqt T޻gWQ?uX zt,RO Ƙvܡ^4.!ON\5B QQ^0L$h\>̼x kRx$jEej@R`MtDsE5{hY^*몘AH;L89Y\rcofJvzXfvC+YwޫurѨb%Ϛs~3{Z⒢P;CuA =x˪K R@&,l2jcwvC{623~*ѭT,F p#gt}BD0Ҭrp3.OD bNg2yckU$:[o< #5 G^#b1k˸ZrmAhn(+dV8iDz>Nq+S>_:Z]4_UU SꂥL9 >_}ہWj{|󲨈yo ]i}7ȔKf)w޿J6M Y?=^GQ?4hcѲ~YDQ{5z ~}G}w᱕@r9_ '0WMh6#4 (,X t;´xULZSH=[(JǝkئL\| ~ES3oTqlG04`<,R|T 8~|4^E 4}A1꜠߶0~xro0JN"#^duDvX2JG:Ob&B[ -o:ύ/A\(;%yɑ#H̰sqJ041ih\3>'_a,\"eYG0A me骼=52K&`zC]+Ԑ~Pv(-Ha] K, ]C[y2U5l,Pq(WW7rwJQSz=Wc+^k۸GAЈ5F֚fR@1\ XnXoj 5<͠=aIԋ{K#ieןǔUrq%WxֻquܦR[58'V_F&pM %Ef ҉8Tԗ,/l+6<|j~iKC؉2v+M$-B*,뚛A?1Sd"D25q`UsARО:uyiʺz_<'!pQ'j0 S^aIm_sSd0EDբ rSgCjVH[e5z8^d@fv${"K"~%מAB 5έqc˭-eIh^gܑ{]MoTq+B\VU+o`jm#:Œ|t$5h]ascv0{G Z"{1MS~.@ѥ>H׀gms-8;3Бʢ|*DL2R` AW_-_\zЭ+ٷtX.TGs>2.lq*uhJng|`4ĿߩHJxG EQ~p(ufmb4@q@C$q>F773lK{>;Mr_-Os*o޴s&"NEspe1 1_ CJw@PlYlۓ6GU[mW- |WA^^k|xQ۰=Med b'\x`2-[#Eb24R;:4Ü7-ژes9vh#tx9 t=ΨR#qY&oj(R$6{րcTӺRy.D9ǭ :YT9bҩ݀t?3o4`4k¤c)6À8НZz@ݦYP>))?#sڎ Ѳ]<#Ez  @B U\m;}.EE^iL( 6h荾HsY3*lfyEE'aebzywҺ0! }t_Wkosbukj9+z˓pXKS6,h7/t!<7} ,OB!ulpWdS*bdn9V #ݠ#xRo}pH+ZBYa*fndf[Lu~WH`}GtGۧMWxkϜ&LS} fԫO"'6E~F~C1+%75;D+E1Z= DzQ0瞤0 \2S::e# Ok`M4h;qq2S ( NWSW|BX SDjAw,&=Ou=#j8 l'?Z߉1 ځ\[ ,7e v*"\ؒ:Iy @Һ_ #1scTa`AZ&m&ns3w`WWf,Jf(A`M6Tk>&jXc]re#oWڷBQJW5enɺc*,wRP0a`#>_uaޣ `7gI wZ`g byȇ_#Lⷃύk#W%}#諱K&fjkr15_Nc_ިcf<_Ŝq&HC-(lBXEOc%J川1~w?BW3.GD0zZQu04*TJi<$ YךMUɭP?M҆ޏ.S(r“} ޿GN[Zܾk [up('~>ȊhN֜+X8>Q5i 9Ta}^b! I_`J1\ށNwq( ysƹksVtR ^^[-K_N'9-r J!lcKl)^nz$t|]G].;q@ ϩBq88 D/n ;tC~%aD2ZE5Bc6.7mKKRuqe럡~j^%Γ|?RLjM}y2 l^24_;r ;Z:| fH5e xȆu'R7^;v[DBiZ.Y[\1i~ 1DS v$˄i'T_qTvWs ~o&ىAX(: U緷LDV"؃zGl>IVPy‹r|ܨb0UKL}εX-ڜ(D͹Ĝ3fS@ů%3p:зYs0~˙-vTYE):[KĊpvB4kv0}p57QX"/N”|t!1$.28/cĨ{JځqHLv+-8sg{4ihvhT=BxWQqNΊMCC%:*z(Vd4Uڊ7`f@sޞ?!YP Ox_JL8R~~Omt}_"MOV#-MXi#J5 *+&3Ւr:=9^5q̰Zevy)TH@I"@O|R8L X!GM6xwkwF*ZaPBjxP-~CGOԱq1҇n{ gn!9fAH7T2JFbD:)o|הq_YX<7).砰̓}.: s]Ǧ~H|#KũȸʠB|@m޿Op.ʺNP50ȇ,QvҢH1䛺Z;siǡ\[~Qԯ. P|#&~pLM.sTE֠i%3FΐO~;*z1=V02NZ[;a!&EwQ?!}-GW\1^sȫRk5akD0M ׾ln:1S[\YؗFν+#$U!KkҦtjzxmAbeWZb!a뉽Fn$Vn?>ל:PY\a`ӻ؎Ԣx i, +Kqw HIV{tM۝xZ5 w0[s`waPeI)bkV~)@ ͯ܍&~(9#J^sXHS(JhkY~j>Z6F>u»P1lx+dЂ\ $!=N1wYǔZG(2uoChNi;oh\BoRT (cÕQ boX'Jr2jTx6('\P跔Yu` ;}N<1xEh5,Ī㚼=K)&Oݰ3;:2U761HoyY0@=w rNi?(jGO?Ʈ=h+O0p14+!hRı]]VסbEѩ|NJ kyw9j:.d\Ya@V82CeNxA)P/'AȓD Q୹:7ĥa}M(ǴU"(5*˷2jj:b16/`>.ۭ_K^7ۛ#yE ʡXSau}* V])l<zLٹZ~=h0ocPamZ,t.ti 6-όGN.|7GmkC@ofA@*) K<4NDbdC^6g+$RXOs3JM\~8I'~F^|3|?Wo?M:@+|zzT;/KχWO#{D,>m^m*N0dEא66KȈڝ$(Ӕ s }pl"?gR0:ϒv1twuBViӝȜ TPFSqu䞖WOݸ۪T-xE,(O(t?S>N¬eDEÖsI 7f8H?jtM3lCpkQ(nd۴Qz#/ =|͔<{(sB- }t±"]9&<@i;sHfأb׽ID[c1T|dūM UVik+$?k-H }nѨ zVJQr\y^oq12I8ҥ<`-+l?૲4S]IM1ǂvI :Q b0@53:+|cLj~s'~U,{0 %*m18[JNyZh}9@#`[sxug3_r1bp 嚣%ޅo§yHEK$L4CV9YVN9惃 Իe3[n:gx$Fs0f []ӈiTfS9yg– )*$1:s,猽J,<޷W\b*?rz]_/&qrbog]%(_Z^RU|[(BrQe!ԀK&vu.Q*J}UlQx].3jxt?4R,@5LL=I23X#v,' n3 =I"?9fht*}R||ۙdHAY,H((EE}0FSѵb܍WqpE}-M+f`ӿ~K% AOHǧ)ԌY|-E(ۣ~ S}\޿?[I_.JIPV h EAוf)}Mm1l%& u EГYgy{>]ȃtuSm{Is؛q¿.W5mE-!^""ܤ%1VGT,9H\cQSFm7ĵ+0R0OWvS>i˅0)qRn(=cbSDp\Cȶ 3e#Bo&O4`xb'Â<0Nfy9&ʶה,a̫3˙\\M_1*iI^T4Di$^2c_!Hȑ2$z*Bbn9+tk3&RX}H;΍ϟD8oѫԚسai19wg6F0s+\!.E̳Fvՠ` 8VCbi  *s_'z]V~52{><PQqbᔝ*$PqFWEJgw؆I~̰졛-roYY5:~EYd.ALvL%͞!ݙ5I48%;Jys pxrEO^Xa$ -eK#bg/_+K*y3rS7ӠPvK`c3Jh޵no8c=8 _08)$)1Jm9BnNJL DɄ<AJj@# nEkD8#§ycő`wʕ17| z} xAҲSAo$(÷+@X#TSƈ"Y Z~@/';j\!AI yn0{B삫/hOoPu.@3 :_o"T ڃk69j7ӭFɪ\nѺMRkr%Cdt?Pv+2~pq%_athWLsV- 9A9Pv!OR}g2ay<33VYI#I~&'$"Ǥu7o&6q12P|$˟ RԎ=k']I= ZڹTV/;!l7zK`x3h񄽌 hPgpPhΒp݌ Cni]ɏ'LΉ'9jAT\> Gzoʫ-@_D[aRFb5{uMRBԘZ b?3O:u{Q =t?s6jR冰hOS3։t\(D/8Di G 9 EfkAq|R ƺ^81wkcZB-KFnW~|KSQ"ŵYń`'p&c!N""h-ʁf=o׻Ppd__P0E {7};46*8=} ޤREWD\1o8Dّ8CXD "G*p頠1pS7j^\oE ӝ}hrz;a\vxN BF {gAestOC=RJA =n2xw&]ږ]g)p^DC6lcQuX\ 4\:Qr[Bx.oޮ=YOQPeW6iNГyY46pqˈb|7-]ĸE%ַIĶ xe8m{jΤAS9ǽT!6`a5`﷣z jW#:혵 {&X(OD+̗#߁'O=/H;|tL bL H|[Np^tfA+!cVB}L|V?LxSe9@4<ذ|@(t(7Iה~]ycT =!~FK̤dy]th̞mv0(Ӛj[Mo| ` }=G q7{ġ|Kx`13$~=βYG7DL^w=ᢟ哷Dd5V]a͋~8"۶+G,Խ?”JM[҇,M=rL >ʯF{DSC ,cp)tNO̺QmJRTy>8usz" lq`rm,R""斔Go!gLt=?*o*w0WuPKL/U7~hMdLLq0 azdb!w>EjY;~@:7Gu#ԑ{5J_EG} b^ G}5H xüPydGe\y&}1-6t:R`J5p;nj//-,\H-έ8BM+Bh0 ^]a$rX(zlҷT1* h88ĞE[@|Y-N7M-(xVq֡up$*5Sκ!3N= ip"U"1eq_I (O0E٨Œ^P_`PV3aq w"39b (:bJ5_ǔN _Cb$|s.w!a"7/ "wi(1.nUn5eKo0=בq(/hW̘Z, %N1J^I@Qw^T=xGjjW{ K# D( &37n\#jdϘ-R4S%ć}EY)i8m6Y1Aezl8:;~ZhKŦaw]\[ yAvCrg1AՂ=//ol_AY$mOT 8jNxPDQhx"쮋KLUo*@7YZ {5iyUgz~x0O޻H`If i6VO8b[BCl_n,6xX"':g6(Zk?<5 uiRį}S$ʻMnC=> fLĽiTոERﳏl*Al6mm?,Mc#%1&$.q\{Qx6L L #{ݑDuB/kdl|ȥجF+CSa\ hlC3۱$WׂnXj#f#Q(%B#PI?ڕt++>K Δ(`iR d^l<`M aيﹾMC\,qt~oj4g pwOz(dpNNȖj* ԅVG KMî 5[S$5*vӐC؛roDtRF8n;FQlrbQ+D*`auAL-Ȉfj7yUIH4#p^Or0qSxҜ-I[輭hmVNpYL^3'b-a%^fTE OnD=v/yG*713k!ǧl ,{T|Ngj#a%)wü\,^1 2."ޤ2J{ *\Jҳ.o|e(+tc}F2 sm1^2qeg6H{I3̲6<L"KQ!i/Jʺ5 XB[Fk\-&RֶĢ5ؓ0| B^ꉽaDž{.j?NAĉU>Θ$: uEPD9סWO[!f {IS"$>@ȈN7[R Yyo %f>! ilIJa >nR`(&NX W'ң|5:&`,%ZFW)BE~zXggv( ,iVp?P BCiHkypq#irJri'YNU$6b v릩_ hKY=/u|*h_(wTN4 74'.0thYC\ŰRhwjZTeA)nOP ሉ٭:ģK.\vcPs0*W}CuhCrdt1 0d$x- ;}d䥱ZgIbv%F|p̾ kJa M,6!qaG={(jIýr- Vy/$$#W^p~jI:g7j˝?w[d _\"m \l.[J44:{35؎yF^';AtwLcUVjtҹ%kp|D-zx3αqH~ϸApe@ހ; ,HjrT{ՇMZ'pݔ~t ~VDچ M9~9bf*&;09Juʠ!6h) <$\ QX['P9rd謢 s_RZTSB;@-hR*]~#*"=k wwQ3/.ݥ/+5ϓϲT^ʗZYy:=?[6ظ ߢr 2}a?NϯQG8uV[0JT21W"%\>lYPtBsQ[˝"SAtMÈ1#> ^p; Jʎ[Jm\2k:5U1xW3uks]'Q f12lZI$WƤ//HIMD,3~}DU{&R֮] s1aNƀUc~@bh/xuIvBY$& ,0&6Ha s/(ǒr;GXAI*:nVstiQ~VOCG_ޝ8:SӦ'2v,n8 xXhz7sXWe\̽- q3K4,: WnR÷ }0L D^^_(~`Jx}]+QJ#>QU49h1;D$5O$WY媛:.6mf9h0F`wCMW r~|4!T闕%;\_2e=EgN 8 =r n_E) *EaF>t%oz6ǑEwTj=nD{Rt f*sE8KnUhv8n*c{:OcqF=,B&q}ye#-aPH6"fNUR\#pD-=r9R؟{a%NPߦ&= scydqx}RCbTєAQE*Y{MwfW2~rM|lHnPFo$pi (m Fp~3!㻗{RD@w TLt2¹ r2;A~w\mU bO8k 0:bZ 4x6XB,IgOM#ښ}ByصU 8Αd% MĶ

' b 4_WâF0r IpP;Oifd[wgyr&za^0>1( Q9퇈I }fw:T0 5NJr:]TnQX*`!,IM@_]YuMK%H&uyb@sˌQ?c+K ./|B֪G DaUɳٚ]%dY#^kHgޢ2sci}<>Գb {0CAkbp<M\V'Cg18/y?r ɉӚIlxA_[F>=Iz~Ylj>afև922<wЍ3z6-٦B/sV`5tBRyNZ]'-O>ȭU3{+`SnEk.E7%2#;=;߅. &_3TmָX%¬+~ ?:_f0>1oHn$zհh_VFhi%~B^޿㫆ru2sV>^^TZ-*(wҕ)&p `~5By I񝤮% ",VCpX/@֠iZUbcyyZoCy;F/G) f^_pka6jB. aV25ÐD-yJO)WsY>{mOEh'AS޻PsH&'mvl2؜~2MLzr giexu;-ϺWZo<;*bƇW@qH^ehJ}2Gi֎E=iNd~ 'U/v[:ZxYEB rt(Oؔ N @. >"uf}{Q*9RЎ|W ?%LTkvClI7j">t}q{UomFGTp s]lsԷQ5SԢm iWH^%TKMS؂Z]T-U+æZ.Y(Bo AzXW}X'vΦS5x<ymo$\裛*;=R\ y '\u6_s%ѱyOoq ` {UY3{kurhZs(rݻ/Ek#15@w VO`O>Y%%c qIYڍu&\Zz^飖)I"`n$a[)$!,P_l&)*ubvjHګ]3GDt#نY#H /SCH}ڥ%nyI8os]K kj5'5J}bE~52D &Rf肣-{Z|'Pd\anD?Ql͛U{yjg Q$cTŅP$Pccjf?u}$zV9— ]Vi B3 |뜽+?@:Q?$!:ʐ c =8C*nU {*e]*4+VkZ5\*2p !ʼXXE/#@$躈L9 [_HPLBEviC /<24" hE;GE9!gendqMU<=8JR\"A,E+QF *e0|Q+~#av7ٳ@ޥdu"/)PUHt0/[Ɩ@fn66QgpI KsQ8lB"3E B\~Y|GOx !ʛ|@h.ruC%I}X:Icnd,bWQpHshWӻ8;@* VK[_kw9`|pM F:9*MՃn7+E}F' QSӸ,5.WXƛb,1%wl.,F(ٯ-$/6>#-^ѿ`hoKNW,[,SV˚ոNQ}cF+R8|#^zie8g8NTێRy6rXa%T;4!RqeSab;eKɍ?a ?!a ZڲI1Tۓ͝Ϭx"hgL`E[LΕcgقJ!_ 4hUK; #$S5$q|x(;P]9 K?oF1mutFLDzQuL XKH{?VYjEC -$Əc1oMn&hdIkIeaƉ O):Cmo5#ŗ.o ]Ʈ_xΘ9ڨq$p`7S_F*K Ln^$AN3~wH oSWKNpqV *uE2טx5 3AcGqaȀ6NP .: 47ϟF!F&tl]SD\w  A/ 6kȼ;dA4ͷzcg$WB Q`izyp KA=:Ϣn=,W+cX_8pEB8XCǮPiStb j }]_nO7юs\͢]efPWIi>@ylL fg?huhppR's^M7(f J$2t4wT&Fp dtOΙiao\ys.?wnnEkTK\DqϙpnfBJ1W:[79Z:E]I SAh8_%nƵݢb-)RsU_8cL/i-.'t`_pUUᢠE+ A8JWvas8 ҉f'?M{e{<[%[D)Fu0@+I:x S6^aUoECh3}RBYyTA"uIuE RDh!0΅~`96 yT*.?GL%[OZe}4+EpTNLԷAmޝa <]А]W .ka]}Ax h2 Df#yOAlkdnN !/'rʑF EA "ox&&{Y*oT̜ Sf]fR,.LrdnkπrGu,XM?:#(3v֏a] q9ق6ݤoC9̾wu9{.:Jmg(4kj!΃t͚ITbl5{[-xf Ucʌp"()D0P9ؼ?:?q; Id@$AJpd@bYk&Ehoad`ak8s--;"mGؓo̙wC%a[ 7r}vYD@.G[T`V*7'(sI`]ԑ@p$#~XOk(xP0h]5Wn>e5z9'9f-8jۃ~^]+PcjɛDIWx s&M9c[l#5DAw.HI|1 XPŮPͱz۾6 ?ĥB=@UuzFͪ:n_+q$`hAF<JC?P;EޏtHЛg3~,0M(R>WQNI \ \?xPlKӤ^kcn?U=:i[h}oMqK/J= R@!ZTHJiU&)U*t3-=%Wu<\I%!6>\YF+om@u2x NWIs:령MxV`y=OzƵL _b K,Qj]֭V}@s?"B)0͜3E0LM[`eZ @r H9JtӤ fqX95c^>bmF1wvx9&~נ4U~#'>7"ՉFL>ɶmR'S8ѷOP] Ec+;ÓϥxN&&g pJ/x\ctjjmhds&L0-bh95As>%'m~%j@#`aoh"8s߱X(fRHqh/8jSz8 NڀY>#&6VӥnjDIeUFG#jR)%F'?(tW)cL`wUɳة/Ͼ~+u,U2;=+ QgsC>~Dӟ@adHOK#ٞߦ1ϫٚ8O+1`|DX7pGoPڔbcDatbPq\%>m0i;2ݩ'X{Y.~#Vp)GH+>tZn(_bϪwJ3awqMw\Ì/j¼+HpZBU:s8^2 Џ xfl?6L%vBdHZ$Ž I) YisEܻ5}|9ui[IUG^ioXGM]|ɠ~#@e2+;G祁<ϩu`Kz n3/ᩔ ``:47H͓.w$}CD;>B%I̞93#lRt cl*TtTT"&G8E{Z<*#Wo-EncDeACdv7ejo0[0A6x+(Cm@=C6E 1"զU?8T xd"̻j~G(NW1kB;ϫU/6zǁs4s,~&>OH(kg a.&ٿ֣8mtEiLZ[.'RfdK>^:nﺥ, SBnLT4'1o .iۮve{Ľ_i7mnh\񑪺*e F F_xc)5r+GjhzplK )U҉BgTs>L̒w]96k?Ԩ2P06n8 ffP- 6#&ɰ)Aȿ6ƱIp\%A%,ln~z0짧YC&{DLW9;@ mlLQ'h ~E|??\Z>Vd;,-]š$`pח̀ĻʢSanՈ}4H{ :~W=M`\md_:ZNS_Ő9և(t7Yk859Ԝ#XR}#&wm6BINxaY9=X+c O \eBXP3:D؈;Cp-u gV+Y_ Yt\V$"oTzH>EO9j'D k6d]6%]les%M~L9DHiS\)_emvp?nT2x9ъ#xPR_) (z&3|T_E×f *^RĹ4TS(F:Vӻv8f +sV.rxDA^+c."8N@if;ſǒެusH#P=}:BE̞%(Iw : п0bzga-F\g9L2g1ta fgn/8ps"0s~NuyZ$ ~z=Ynjr\ .81ۡv%J, m\#:rU_-Hŕyղv(d+SgvD7ps(W7Ÿmr.apSiG{:0&O*Kr a+X?2wz']PjkˇIE"\W H|_ʍ@s3툦l] őfW(Zo~UZb=ݠȁ="]l:(Zi3'yDzxEe%,/\+9CjCg% *g}y02&= ]kz>߹ L!/Ɍ?5A6,Ї/4PN)8_-0[\NNMo#5ՇB_yJt`b3cld do@_3x/};O-X×\Ulh(bs/鈻/$W]]:dl= U<]R3{ئr2ȣ6wI$BeŃEĒɕp)E% mhx1;M=,x3TwH|Xu;TX2~S8r骇<}R"\El&&kF/uIjqi&46K@E瀟{\Bp`2"M?%ȊzcK.ļ|͏"场T.:zu|2 3|@O\`$4f͓7J>27iY(`hrwOهûEpR-BaloKrر=VQTol x"/;Z$WBz- M8'9[ Y2uWHv2a7}ʤ٦~ߛL-oExГ|$ X8R H2^?qӀ2hlؖ,UaAap4dԀƿ[y 0sTlKrBcذ='(4~8P|"9qpf9*:")Qu&$WCcK$6<}#D0W8vKG{zm?k}ga@<8{ۢ,@.uz"2f­J\uIiB"z|]+־;#0Eu+P:ީޗut&Z?FbELkR}!#~GG|-]cVzjC f#gy/xǰbt+쟭5q} `3)@7+]+MrR_V[Rse3"{D7t UߏǪi]iWdr7v}YS iD+;]whI_s C0WuN6@LwF~9&NɊP]y\?$^S9uP$8JBT q..OK?n&^.|TmZ-3.e(]KK۝BNѠDvȵ~!Ծk' >NXPv lnSLo e4zNMD 3nG/Z8;Ny̏48t.$ o6gHN-zlKwo _G:0o]r] z6"} !:L$7qz6ٗƐ&9GjgiEEN۸ߑyBQ2'r.GuJ+)Z$/Y@>ݲӜ \ݙ5hb0swލXQ{? ?f3=̹_1틫V"oarS\=[,33Hퟔ?4/ 2(v1eۅuTu"s XGosLzek$dr,"@d/Zcszg(H⼽bAx)F/Fd+{M^%ޏ$~]= \<$%Aw wd"oHp7;iMIGf+~U$y-|E[Ȼһg]DIHovM^SmAu&WuY/Dcʻ%7P@u iG ){`T6?-FW%F~%HV+ ڣv/@#%<hF9iޓLWje2_9]қ1~b0+=VᔜXߟnq~ԕ;4 D)i}d(t&̜t>.Yhv,FYK.klf̻l ~.Utho7qwVcj,6o+sˌdL$(ZhDlmurOCF1IghakȈ"Yx3WcgI,'_ - 5N@/3P Q+5{N|@W_H7OŶF7rsS` DvD\`MzEZ7m/ipfPgf9g-7kЖ%Hsn#fzbC%c֩ c{'/4+B8N%F?*Idݏ5>5p,թVǼk$5XQP x~kOU4V'?&޽f^Re?m+-Lg5-%ċNlx;>>e d@n&OO틅/5- UK3EWjjZX@?=t ci/}v݆6 Մi+9eƕv#S:Dh;@(q̞A#oլiW P=MW7-*81ax'2rjA<^ܻ"dPz[O8>Zo n?q=cKq˺# m!aP"N3jMtg&PA=<4%rC`G#b6Z 8 Q$וc,|ְ23"X&u,i؁?Iut]ʮOtL%1a˓:1tZ(ڱu,peE -f~읨f*5*=XQҳYEDB4(kCRk'=|h<)V4{b4 ++ SH r7v5ӈ=uJE\᫲Rxe97% [+TMHwtaCfO e\:*lgH" :i̇J*)@~ u9G>_(U=D?o<ɩ9&*)"vL7~uj5)/EHݐ\'&MpdPe+mjbSVڙc Ǽmk9'{M/k:sZ0C v* =̗v/@1_r=Eq`/ !eI0io0_HpQF kYI/w%Ai F]jftKg0v+V ğkWq aJ_͉oo,פFDab5l*w%v~8oi_F f,wT0_HV H=#+[ dSg(|= 3o{:H*zCtJ+6j禐h{ LnN+ApC19wQmtumgw9AJpB\Y(*J*~Y<ґl2T69ձ&hufejU)"gqVF/Btpdz 4U+hNBT8JoGݣ-+H 6SdQRwdD=F&ȝf" &i_E&?*j|G%%䢑"e d#tYnʫ C5|+ojP%ʚúg@ˠܧ{w/ i]&d&jfnY&F*LIN+iHdH0.y]06QLQ[y F/Ξ9;7i<)4t%Re K= AKF<|zV#J:Wb_WFqCX==u G 0GO>;JG8ԳC3:!o@@s|ZꀣEkw$!F3Pw zi?zsI.-I=BȋMI"/1VDH,7e_I** ImEMC{i@%ʺfpH)ߘƏ ,Skfe 8oyruYM1;}=٩9] RĘ8KPìl9ǔV^'`jKNd)-*f qM!1_7Xn| $PM#5N6i:%\r.OOoKh5D+$l/wՌ пZn+ 3!h̜jďYV9sI:S@2]xY0"`zN8O[m&VTPmٴP2g*1хjܺ|uhD<idZ~P͸=  TRɡv z_oG)^(` ٩v+V֟N-Z`A=nev0%cd.C6ᡝ Tv؄˖iƸMh/ HfOɉ&)>{;PʂA`=WSV?:ڎLNYv `(EiP8r =aq%'aCL iP)!^2PҦsdEsPpWs$xFGy^noimu B5Nhz+G6 aKXp~NdizZ`E8nCW9<+B}9dʕPȠcQ~hpN6DT tpGO5B{ThQ,w:~{v4Lǜϐk@daM $ĨoxHXΰ@wm m"WRԽ -ا*gNm-CZK _rTLlg?T4FWk͐qD(GUxϺ2o  ڥU1| j,5SGZPee`0ػ޴q %EŐ@}8FgT6e 'et}JYrBJ4'g34Idlh]}FZfؙhTcU@&H`0͠s3ʳbN[LȎ΁$1rܡtNÿZ u缓axݐƆLxi|#zP{c~PEGJ8j%ܺ*ٗ\z`}3ZR'6:%_'*N;Ed`M qF4?Ov~WuUɁO8.CT+V12$c S+n6SXJ $طާc=Vfju7z q,N.CO٥+XMVw'qgԲ[h7bax7 `$yV[aG_ |A:2&u%q+;LM>hAϱMVDm|/y_Xi%y.7"l&\-J# E`CǫTt=k &SjJ>04%0LIAxxbL0F{?dV.цyRԝS:⠃挲FSʱ"IDNgύ,j:c{wg168A}yH3{6qIT6pPi %8o+tƶC vV>?acʎxT__/'c=t*2|[Ԥ~ɡJO0We's SQDMUq9z@2JzBM Z#J9U#ZA#cmy~-&Gz"vs|̙V' $ 9E(^>~`?ި]̂$a+Ox];}]{i_ŇJBa| ʱCb-[H"5+*0% 1;JeXSƫ6>M~,qQiz+Z e;7|&L45^^:B c_[ue-l|Ec#wS.:U7Bf$G.& J"Mb0691+Uy?0"}a| GIa&]m?pQz@EH=4z{6֌҂}"bן6.J;ώ/6(\:Vx ʙ[s Quk.Mvu,@f=#0H9;(> Ħ-֝ ܔZ Sch\zg&N}UolE1W'X60Vh*ґW#oC%ePB5>5#2ےA{c.'D/9o㣎NY~ kZ"W?[HȀ-x޲`L9G@R Oh[XŽ%8(D0W"w$A>6)[mb$?wemiI-;Y[f`R{"G:BϤl0T e3;tA:‡I=h 4Vn*h&ڱqB̀iʚ֓K >8sÁ%==9_2'b5?mw@enHQ&.l0$^W51,>! /iM L qYVbL"߲C{"5'JmX% *ߞl[=3EUa}wk?&, * rQ&I0[A"9^`ҲٜA : n\/*L8јi9)"E79IuL55֌Yq3TG v'j\|p֢(0Ў- _ʛ0ğm {ov twÃOܥBu!Qfjegum0IoASJ6:YmLR>p+O 7HŒ9Coj܃'L7Ak, sMK\@DVH֡T`Grc z ^z gt#̾-T:ͻ|5?_w7MVXyQ@^/gJsTZ-b@uY췑rFn8Ök`|*L뎌TenX_jO"l {N42aߕO;5τN;HtjAv\YxH[[KyO>.p=0RoP_jR%RJd8-,֝}A9[v̎d,|$<j&}B )UY\cXg[s)0P]tW UjtY4Sہm6@ *FVTui.@ 0 Fz%uX`DJ >c@cܘԅLVYoA$wʜm-*< e}-1>)D25EB,8lPbЁf|kҎоm27]x N_Jbi=z:d{M/`-CjKot11N3M+c̀{𝢦7\'O7m&ʬ}u|!󢊤E*SբCW~ie\;vT=r暁H3aCݠ6j_ruW?%b3sA^W(JS}PS8kq6\͇~GH{bkzst{ٔ| Nyq/Bp+B8t𶟽j}O8k !dIQ=\ήKo@WSjܕb`J<=Z 觷ty[zӌ, V0?6_El7.r v%%C8ioڍqX3?5V<*/TEe{&#Ӕ1e^]x8t P߅-r `Oy)9vs7D},ݩ] EAs 籠=u>0Vv^6_EY{^s#}UƊhǭi{QzqQzpTRv vTe#$-LFM*ti;}+(KqIgDR^#xNFXy}^zC^zC3B M@ Pt4Pr7B\b\s5+xM>yxjQ{dC-dXqN[0M(g#C^=p}!<w\Sct۪*{E~O#F.;؏cn.4 ʋZ0V!d4J ovi=~ 9܃V۬۱@SqzӍC(d׀ۦ7m>4줞ۚ7lHѴcw tJ{utd (ʢ|moZSwoďq.;FqVQM^;j'0>ւS ,ul_ztm4]䷍Q)|n"918ѡMڤ~~V@A䔆Xn b{fχkT)a d̒ (2j{uJ}1/=`94|PteFܾ&T ŰЏ\O  R_+pANukՃ!鷱uM[T)σC#[aXF 5D,%FLwޅ ޜqmC23CNS9ܖkN-9A6?QĞ+,o%g||Rob_n2}w)بVx-*Oo7wVg@k*+L }V*FQr~bXI_ k?az~UrKWXov>pM 7suv̰cc;O 5pCkW%#+BSZ_3IhZ"C=RAyuqjR۩] M~w}3;0eG8aYOc+l_4!}YJTN1=A}6H  e Pmrq[t<+ 1g (yyHFTH㔻6Ijl_h\kuy@Gh&܍kMhuiĎf^D[Dv;4ԅJD4f6{p#}%KNzL|G8J>;U1hTEjHEHWIU+&/;nիrVa>>Qkp#.b 9V-b( ^?@2_(-^t$ٜ$$nk `%4Lj0 >Tn{=Ԡ 嘿 S(MtRO0) x/b͸IdissF>T9gVmJӘY(4ǭ]iͱ/TUS-Cs@SƫPza7;C4QPKo. VMc!Wv'jRƜ{/L]@Z1™Hh\\;KL-rz.s[GkdZA?tJKC]tV>xUq6RGF:us_Wu՛"\%Ư44+jO`('|X} Z/ [ CN[14HjG٠ ږX?։bLYUprq4EEc Tm1m1Lt_f|j[{kύd,<3 Gh5n7hZnIaH+:ΗW{>CMv(1| 'QZT,(_ny[(4 h;kcT98٫GSBGq,#璯+ש/Ljtl Y DoM#Q7?憎S+n#e{%icj13.ṉ=7F:3#$s_=r1ؖ?+dw;,%o  3.Uժ/#)r~c:LߣJ?IX~iL3S~S/8Zh8m슛c{[$JFbF+cp# &گ׫U~Trf4 SʣTf8'%(Is=NlڧIMddXwefX*va_iA%̦4Wr|x9D)-kK`3PYW{\7INc2*lKPj\%TkICd.5i_R<|bGkU݀.Peɭ4־{Œ#-XR#^xD"j.!'-ˑg.L뉥!9Hq#4p=$'CžDEk ~N/#=?`|pAE=%iW&V?cT5&BDJh[63T4EE Be,El]|Y)o$MQ:>$['5UjJ3BVShh;^̗ 52jr FHsMs`&Dɷ:ϡevχ$l(Opkcp(d uTk8 0\t(ʳsJKo#/Cg bمdOo{, 48AU) G< ;tfުR; 49Ϛi΃BwAv%y)ۏ봻 1=]-) Vet=Qd@`7w~x gJ4 lFKH1ӹ4Wvpt|kPE*HOԍ\]Kмi VlQE@vgRs>֖ZZ#?eFz}-!֫6yT ީȻ,\Vx^Uovi̩UfƲ\fD[l#Ov]Y~?SڵC3dr3Q(,}.tHLK]x&B' Uxθ si_G &$OYؕhamS=<~IZ\}+)fe^_x1!՟@F<' oR*N~uK- GKPYobQAǾߝ*7 YexW8c GhKكUqoǍB䧼_5|WUG^=%-ɕIO9ַS ǚqɗ=ROV*nDOy7|Ix _쾪C+|'t>v bc([%Bϻ518,9 #Moг7[0RMQ\~ЦϢ^寮/.xP 5?=x'X,o`@yGu"h{bǫŏ t:N-lQo Gss|3(-{ t(v5:v?W345>4nrax^jWUxR^ʀ(W_ps_@Q dMÿ\T e#yy [ VvUH b_"byM@Hdt E?/47';ЎeO?#'b /לֻz%E!d)&-4Y6#WWf L]'5&#o^n?9pr`^,ehr9(ѻ XF.@suSsQ+j@Pƭ;$FC-Nt~c [Vgܙ{/{-v妭C_'%X"©RuuRX`B.T:ϙ3pI{'q(%P7BOfӹᥱ+5|*._0ZO(~j^<N0KeqXP4@Bčl<2emgDP ߃7yf==Of_$FP%HP5E`u4*)!*AW +fنr2GfuU?ȣ) u$Qqmr0\|+ՀȉPqW$nC9j!Il((G,ǥr:.CfD4(.\TK^5]{y>n#F5 dz 6J?`Cm̭o&-EP|]7J?twfV{U60`dt.GAelzz ">şF9CfPN* ,MEt,̳~4f,;l#lXqf9eP'!NO`^:QHiT+V~(|er!65\>^0uNjAnaPFj];E!at+TP w uhŋ/܃5+r^Q*._1xytIhV\Z?]u5]<] ˮE]tl%igP]1[\ o{E-ϫٕ"ٳyC6VVz'I|F3TwaXp}_;\ɣi!.ߑ8*>م\ -d*d+PX DE\> ,􄔏֯sN|-Y(ŹFj$kr "+5K4bnuӴ\"GJٌ'kϏG ) }3܍lvbI:`&,bYF)BJ4׌[GE5HEfy0*YȰ7EBL|c.9evegf3gc|^lܺ:' /eҦKX5=$MD&bOer7:G!\`ʞUX^3lp)[_n᫾oĖ%x[`BwKaçQ.chS+mSTLd{Gv78jkho9#Tx5ofpy I[uf"Z?(Ewp6[A|_Eӥ;$0([r/` np${9, >wBQp+:LxN>Zsxġ^_]w@B+pʩ$KU=hR \pE/F`bNp ^*#vc9QGOd! 6SNsR玲=+C] c ,- 0H'sTΞc}<^^zmQBK;"&]~X#I9{HV ATz&"8?AP˵UVLŻ@,XsPwd^ݧ)~&3J+ݮ6c6sIm\/(o-޵&iAXo]7PߩVCg;'w%@);hbC4Ih+߭n*Ӛѱa`ۙU~lb7ʦ?qz)&3 ͒iS%- Y $o%ZKa9t6@N7!Ӧ>gͫ 6DAM!>[}"7:2_c؅~Q%'W`ܿjfN}jxW@3tD{֭z5v{~UEY]g`0ȍ <֯{UntԭN{YvH4ȴr )ԝ/rlf&4n)zV^&`U* {/ts:%j^M҃⿯e35 {ui÷ˏEW6*fS/yP%f0CH5 y @4qe7KL0GQn/ 97l'GWOAk1fVʁ3϶XBQ?"V /U Hjm f8!eؚFaNt{*]i}p>bf-[\ri,)!='3ugt?uXsFAaovx9N%HݤjtɶjUE5T8whChwPõE.W"z7?J~qaQ{3-C6yj6`&9NPhv8{dCB9~=ؚ旊 7 RqERn: >7CH'}>z]EP!hݠj3bYahd_ũSdəqF8\= ^\U9aZ#EvByў+:J͡K{^ u+}Zԑ`KS vZȑMNFޞ 8W:I#EU653$F-&9TQB[t-T#P2B0Œe$'g0jҖly/79+TVc46.Z٪+',~Ua͢Y龾[vY/[nY7烻cJ>V+G(8Q\>氌+)2!޶mk\```K3"Lhq/ײA)]M)@ $K*XGHUg؊Yq áȻDo}?jzB7 ppXTņ"cG]dґV,˞TFQt_Sh SyWe#ѝGP E^W,DJhcLj0,zNg4induR/b(LwJ@)(,:5|H*-lO[ERR"ԣg$O9Ř۬9 ƀ @$Y4Xk1HSyA3Q/} _v#sg/1zGԄ% ])k u]c'_fPhٱ#왠 8u$O,%&-WtkḔuPJ&!`‚,s;]}nw>~3R{ "CU^x4E#+7?AxZ U%H.lƘ|}X~ (m׽sݹ.yXR_y~TmLUaGO8zKaQu9O- WjOs#=fny -<^%̶[ :#Vŋ9c3`,['GtA椚EW(Qi{F:h҆\^$^~5FҁNHsӵQO~Mt]صߨ[ĎaEȧ/Ff5I_K) 8>bDu{UrvԶ8ƥ/s&&., YA4G\9fJv(lʁIpk;C0ꜣCnggI#ZEa'AH2펯1MzVwkB1D"ƔI:&4rtC2iw t; sF@P lv@˱PŠ;Dqΰ^>0 Hb1w+a-38&MS+Kq+3ӎҭ>3SʡdJeܩ1Heic` %ӸtO6v{rYpt~Dl^-lF/͕k"t/3$"^w1ײ Ji@_Q˶8U}]3]2#zo:Khs9V;P9BiRy y'59g\{'kCA83gKƿKHCy?\OREsr0]ؽJ=Ց@(V=M 36ErLr!h^=75c>;|Z/jIP<ߎj+ Ƽ,UW[`L1y|#[pT6F 5F0odAUFRI[GE~+'aTt38M@\iU8&fNk{{ ʞI:4{:eTӕ|.W0ߊYrLq1Eqynp^S*}xPޛ:/fmT?з91G#zx]!>:I`Y죖8XgyP/6 вԃ5'֪3HT.X~ナj>QүTtm!ͪ9!isiK?WA%+^nR!>n4@ QJG{a]%·!JzU`ͻ\7|Tp;_#Λ+a2Hw3*5 o\x5gtFA x:_h64Y- w*$2;I&>yݔfFwɍy|a C2ʑkH"9AnN(;¤D/(jjc_<$E0i[sjBm|* ~Fl+3 a(xTBJ-0Υ5FĆHsF[)/HtQy LdrB pc7l.b*Ы8KD7-,Y\F} ,f#|`7*#,Ր#uSr|"&z=`Lr arBەͫsYM=V}H)B_Sym^mMyɎ^7DJ(W'&Փ[}1n%C`OFۃ6$,WzpAlLS4~>pr,\=V*f YFO7!O'RyzLlɵ^9¾9̺[pTK2/Ģyy:PC^$u92t/ 4##-3E)Wc]~׾tY[C+Uӟ#͗Io&}6l`/_zg/)9Pm[95}b!Pxwx]@, ;g;4D(\_-S祈{ͩg PFk¶Ѱ*qϳAިuF6 9gE&G$Ȱ]+!\# ߹8>)bAHP;Gf=:X "0V8[;$^d~]s]mS#@sxW,eKv"칔W%*A/XR(vtήg!k%7VNqlC1^$ im%$qխ|J u]튒w'w7UUyKoKt`ٍ@-V쮵:kcNþ2߸wFAzOAF! 6o unDLJה3fb^_*.`YosjFѤKi!~E`Gޟqʬ 85~f<{fw!Vșz/E'%Wdzxևམ~͋8|'1.hdgPP O2bI܄=},# 4SfF1~1.ӿXףBJ5[ Uhpf=},3Qն%K ]&R;|ʣ.%nr}! WRh,"o5dj Kp8{z-t#T 8>=vNyQHx%Ȃ _. |Jt-Lg^(Եbwk_&JC!-s?XyNEba_ 9GϮBf~'o4iz.("m2#L jCqƁk@Ӌ(Xe+Uxcd@L}qgtgr ޣfdy9OIЂ 818 `VgaR=e N ^(b:IΤe߷+wjf 37E_'uٔlTZ&9#I2Ytr2oCm~ xqIT2] Hd`zWc#x#?\DCKMu3kx+|.Q7"6/@)Ů{v.BXѲc4=LZY]z鴩)zvڽ<2d~t5fî [*b$'8_vYfF`m괔ja~+`}l9 {CpV+>ʋISYQNx\& 3>l/\$m^캯2]i#DZp\DXݲխGIP2>LrCwY7|F/{Q:Kgv&䄠 l6:3lv,<^@j[}+~k;&#*^'.{BYme&4+6ٔo qR8Tv1GpK}.壩E=ٕd9Hfb` ~ȩ_B Lnyy3:Oˏ@<0I~;a(ó4W h|$ؿSQbtoBmksIdo[/e)/N)'`fEpŽvI)'.&\:6%@Az=0̲ sGj%*;TTǞd2Sh8WpDT\QӮQ!7 x5Y@_;ɥRaRߦbsq94LJMX?-p ^ ȉIߌ/Á4&Kfꜵ, aOV-K;-T\t |xO-^pQMCPC(.p$]7(z'S gVjnV(]u|irXuBc#y<-g$ n/SȲ<ٻ8Di-'@C%\\Ki +0dYOUP|>ԭhomyÈW(z`wm:|^htJ0}>! 0=>)fv?׭y #%j aU/ x4ZVl:GiA-~S[p5Y4,v=.eeUےO`lk2Ss'%=72% {7$uVOԸnY6`_;^E UHiΏy lؖ&,ҢKH2"zY0sJz/YM'TEe\;܉12@<{{*0Q岧*0{hNjW{*(@:Ma S\fc[bC"jv뱗܋qcC8Hud<9J~aZEb?;d?9V5QN"kkG%5))6Mp| :8l];U;lM{Tw6Jw>ǃa?݁'RtҸ%&|pͳ4"|R4{e}&kB 15ID yƪbgj)aZHUW1.$(a]#M4 rTX1O3i7Zo%G[@ݒ~Q[|w7k4qQ%v@dm$fC a[/2gÆ6KsR/կ~MXůtvEv,IE $ 6DE [JDu`T-gPx kaV3 z{ՒnE6¶XL qm%i2 -$UDAZwy.T~u2G[WZtI _nxykl˸qB0}}Ps9T$][d!bQ_[I3? M$F ^(lR2\z{J_g|;QޜwW\8|VI'rW .LgJe4M-L lyu^b++F)7797 X+Xx-Gge9\#jMrqW2RCxo@ v h&_`pY_:B^yE/knVD"0HF|3uĎAf.)=Oe/ASO_Pբxm=jv$X o'(о{ g ~j "YHo䁩GS'G1a?1ރ7L(Q$ b[g׌9'Y1Mc jسki2ׯ%۬t:Dj2ɱN5W gk@h֕O.se*IYufͿ(>Sgw@)h-$x0gƔ77_$~x/(P9m&0 = #b)J+(q7ov]jmrT ɹ;'^G]*Rs &ڢ]'S庪;A[Hܼ.z>źxDjm{b*#Ϣ>!R7&`%9iQ:ԷujUg(&WTt*8ж\uUp-;IWp2 ӹCsJKk2:y E L$ttǞV%znLNLJ3xQ@ţd~l6364}|140GnB\Ž:h<]<5ּ6'}Uk,N@1RQDd:=g殬0WɌFLbũq_ 5L^N _ Ỵ7~ߛD,'dBˮb/a!xo;訒 lcij_h"]F}]6OA> MhmKҫhjaΝU{IZ_m\d-;c{9rEl&)71;@:UrVS\c eɟ q)eƉ lgɰ3x0_mتU> ::~V&Q zn2g_!B 䡢M9d|mAC9cîwSL˟dK*1!~M yEN$̧k+ז(:PoPNpIS_sELOu&lg<5Êeбc7f/7._vsHj'OB agu~!NnYw*z?Г]^kGmN̙sZ.Q)ìlo{u/|d+w%7ilr_Mݑ$#Ք׼Ǧaۍ{;qRo`x+;$ iřLsUlhO6e$I?Tn]'S?-z^ɣGnfo=Wg^w_Iʕ٫jo@VMKٛ/ijǐn}N_Ow%~-A䧏i6YqZUFƺiO|"TQ9 cO+W<^bueJpH$CK'Jƙlyj?7!}9Vw_(<T$ ^`ƏI&Zr?Im ElF{v=m J]iYnmZ9 jKN=r*é|z 쒽-s'vyN* iYy)=q rp'YCq:cp3K7WO;1цKdHT 6dn*Ӡ R})lYa;ijmT}lZV:EۨeDZWP(c˵lf9 { [fl:8Y*= W[p Џd@r m%=GhXE1OpgM%JBvXԩZ"! ڋ8{; I߿~JtܪjJoکPe@EYI G%3%]`MabR)Iv[/ nj|8Nj&ϒ=$&5-{ |B!%Q}ʥam#0$:=@lLEݏ2*.qs4EE\ sU?LYm*HxxlHZPł@dib9r_4ʻ9>EE!^C*WZ;3r*UQ?MDTɔ\zOjbM[hcxQb,ʋ _;9?GߌEUx/`O2aFiU_V{ ^IBF攥}cNpG ?x:l>ƁBt\8X#$+sYKoY *) Q =99&j{TvSޮyUb๴~6@0~pTJbEyg /<;,,Te[5k y8LOk4c*ADx$\,<&vPgCٹNS_*mm /Q2rm ՔeN<~ pTO%a*ٝ2`a1n.+A~ezKNcXN"C1HJph(=I31_],oBcHH:Q:ʋw_C6)9nRQDaqF٠C)aȫ֔xUcvJYnao) RcRy#aHZ&;<8-ύv}%udڈ%uUVs{=oO/y^$ `y[Eӣ7eHqBQNY0\%dgXPMg.2Feb6B&F:3nWOݢSO,w21k[S?4D;[ca䰑}_3LZ[si?ղۮ i$P )yh*2<ō//iup>ej5 akqK3 i4g+/~V%gС]]̃"O!c0TR&pX 9n15;(zn0읷l\ GQ}{#41뷺cdrt(d"!X2_b@pb+Зppq|]7E|]pmDÅh]c|l 9_Ep v2gd;-;eW#H,RQ#^|q 2ȏY;!w#7Dp=(Kj=+Z&_KW̠~ڒ{.d!=5`"Or@/BdkۓHeC>.u8Xq пheôYL9qJ\Nx{5?u2ݯ׷K ߾PmSg*3B{ 4 l-u'|fqɧ 5C7it,1+n]sdl #pT.W W7f#R)5}&'.1 %`9ATL-cQ(p_o(ñW}h/;(s-ڿ⚐'O?ef65FbE"E Rqf\WJݿ 031KS,ZLJFӊcNք!BXgT3߳ljUQTo&BrvVVS̡I;*l;pfN M(P9RE J]K*uU+|-)Э @+ʓ0}101}6NUS?CM~փꎬF|2Y)i2#{_?OF&qջ@ !+=){eE)5ՠp& ; LCds΋,{N+H1$@7%u] /P"h5!$~@LҸĭ5E5/{/Ip c98ku`^%e钄5L-WtB敝3\K~r'6g{&kxm%M5ӽZqʥ+Z?b]” X[*Az41߇3#P/.MHvY-S,OQrbaH/I>#YS^:xYKI#e 鉼d JWs3CC*N <ÒM\$0(pλ(RkdT#!㺠Tu[ny@/ӥ߾_ (IFӟh[rg98"j.WyN`-%WPrA3XK}NXDlkơtS<{V"?fD%5N ,۞Y8HQ1>ts/jf yU\%i `?N#, Wz]eo[pR[A$yѢ`{/[~626Uy^)HoI̊dVM3Ҵxxt @\,g[dK",3CušKXj?R.)2Q 8ɶN'AZ#8 :(ǻ }cN@+xNʡדÀK~l攋J= ۓ^υ< Q4s5dM:{{eMl HSxHBSWӣ fݡR%&LC8,z۬(ădM|}I1AvM4F͹O&Kq*k#\ʷWHw2@xX[u"u^)r1 (CtÞg QVA).v<=~A7BALs{'^&G*e/Nꖉf ^ҙCK0[*-"4{ wUzy|RÇCM,`/' ѝo!9^0ݱRs.`4$Yx9N!=yTfE).U, KdS?hrњ24zkhUN@ '| eO =er#A&T]*f~6Au[1xC]4A?nW]beߋK7TT[F6\b\u#EvQM= ^]\"1r$5[Z /Hp 㙊*I)a|ٺ -\>eHfFq6V߬TȮ[z_-m28LPuvNhڍ>LG'"JN㦅"9jP _*e؊B0c#}{mi\3NX_<)N9Z$gݺXq!MT6r)˷~ 8&jTڑ̐ЭֻpL聅V=1Wm /ޙmIu@䕗(y2VȑS;GQɇs`ymlW(gv0c(@Ͼ}hvh#35 %"DꌠFsSga+\g76u,JoYf+Mba$ә 8[=qYR2Go?@pg ]ܥ;,Aᚾ}˯[/#oO/^:.]by=?KY6X 2pZ.w) 5$gvY谗H|=C:p<@xjmy]=0Z[tR(sgqxNHk|8RNlT36aYXlgb s-l*po]MAzܜȩ^|W~8>?FpJ5XuIF *g&:7`f`p"-akO&t8.H⩶^f;975ВBu|)Ls`X-ctM>+/<w#LcIJ)ruaۓr/.zLe+?fܦSwSe[sng/^5 pvEEJG5X4 Tt^ 9=(;.Pb`㻖ڃݦΦj:#v3ů=+[1ESIRJp|u~4Kl !*J$zRn:6P z[,gj?h 9bbQ{ )[*g_lS.JmP-0{A?MgE&۠ M1AiTHțMjͭ@`c-Ӡ^ ;M:qP婄t\߾ae%3zPJY* A8`Ʈ Z?oK@;pŞF2J6ebͨ蹊=ZU|6tΓjb4Da-[$qf fңm#R-HL,Uj"ƄL_FlN6N:jn1hLԺʣ|#Ʈ^k$8țV<q .oAE.[SS:rV;z&!E`V"^rV"W -A|uwz}q(tctnEhP.[_IIntգ,[TH4A|+N6D7;ا\<5`? hnYTiHr"9gUIډw \tq ˂[:F-Si>\&Lay{v)CNCdb.?m~~u( A}>EiZ4 II5X%|(c~eI>wvj:-4 Zj!䙐}9vx\__kTwڸ}=bC̞PZ#O8w4`^Vq*K;>_> ;R0QOD~V>cwG p <~NFw ie'£TqKp!<`'$e#$x^Ψ>+%Չj? 놑FY 8(}+\jS N;q*'"F7„ydOĝrE2.g ylP.]?jP@* Bs߱'m, !Ok!VH.ut>Nh߼q }hd7PӸ] !tBR<(K>/#o)=E{ -9'm 4_hd8UEM1b$wM|~I7?0fo4x\1t.Uu0*XЄT [%!avPU|"Rз70DAc ݙ, EbTI%&>#0R ~Wz q1};3Ѕ"Bl+<֏PxVKG݌m5y s@N}ǫw&k"vbRxOYQ#\:!:ũ^Xz1kd9hq[2cHB~Bgt98#`4G0%箌u] Нݰo`٫,>^2NdFk_T\g΋l8vaCzZlvoDDB+u"aWo}ծ`cǒ7+%B@mOއ\" θlU¿ E>[gy*]3Te.샠Xɓ<#HgS偲 okXNP@TIBZ֌Eut2{BVmP6-r>p#?K s^B BfKZ]ʮx~ E-C@ЙHLm:KNՄ[>T xÖGČcuC}c VrZaAYf|MQszm}VBR&_ES,0*ߖ%%y<a;4 ,}F@[_]M{>%"TB@ ffE"#{(#-)08_g2EHS#OM?0YMЁ_=KT&z;Ly^7[/' $J:S2ߴ7]|$Nc[]fԝv`8Gp)Ơ%}ۿ:/D&+$n>'rkoTzS9%&1^8v߇%YND#"Խ5Bw7y񝹙H~O 8A.H#p` 3@[n)={tF hS~C.~ffZwS}c0`>5"Wi|h^甐KIȘpATSJ{Dd}Uc>>uIv ӄ CAK"2^}Цt[sڞ@T41qz{΍)"IO(n/rǂ5jgyR0ؔpl2jsKLeXwvY6͎n3;0BLX m%.m:^8DYI0%4bsp(! 7ɴFfR9WmV`O|NLVƯ;^6*Zjo4К2%q0y Ē $ t7B"lz57g㵀+hNY[0/whfL@ :|{{I%c%tBϤ& mh!/x6@"g2⼥yk=o 7#7FXkE)4h1pl(}p@AF OSJ_a׫D@.;[s7Us^ lZUeipN_S|7i'[KW tG48.JkI|RZsƉ X#+#CQb hi?ۡXYŝsώ!9i- WO^rZnL'|;,]5U:cl+YGb6!@.:ټGk<8vEGPܷz6ŐM05WD8 12dGں"ds'{WsO(uDjTZoLk`r$Hx^# *⑸^qX"S"],9ķk{ uks\&)Qpe|upl?jPj7.n-$⺈0PMG#Ŏk'"(soْͷ;ܵMFRmڛ4NWv!^7`*&ބ s}q5R|~pԮ+iV|]T:GB̎~N%[<{QwvQ{,̕Ipit cvgMJ["'Ǫ-Ժÿ3c ԧkz";JL_O^eyZ4^z-!;{~zקwSƽR|5,L4^ic0c8MՔ57tBmo a JXO5ݏ`QsQP+c;UkNYΨ ea$]qSkAwpEsB'*Ja(SV"̍Aʗh+B^wM ڮLni/I }$g/hݠ~tlYZչ+PgPQ,V߮uo3\>cpA K K"Mp$3[ |=屩("?}tpD.(( h9klؼ`,A9y<`ieKy_jN80J( 3ere3$3GGrxډdhzU,VGɼf/~ _2P=7:XcɌHx ޥGdMb vA(Q=j}vgсf< ?e>ڇFØ,!CZ:zUy@7Q1:5zMg  `Vߐͼ7:mKu `b:Y~?m۔LAc.ֳL/SYt_jQ HA a@dJ$T?Pq8ݣ :󴐍U'M#ka Uڤ+:}tFA|ll)ҧ43.~g lg6s~܎>Ͷ~wʜ_y=ӊBz?kB1MLO(VR.aԪ]~,x_üG) Ǭ+BrӐLLo4tﱮ/l(v]D>r&?GO QZy+"49oZt۫aU~])x;J`)&P#aW,= 86mPʛV]6o,׃T{ xz䁼yG>n+c۪XMr{OؙJ%kB{;݈q|ԬaBYP HdTp)u}kr&!઀'ߪxFqQS#Th/;26.B_ƐaW R\hՆyn]/ketq_ 'F>\*@g* "W,+y=+aa-n\S5$89_]Yr-z߫a*vUZEB]G&)f 2h U\UYDW_!^(+3F$ tZiZ`X|, 9xFwB?0:y垣TF2=rwHV#%"UBI?wj]v:- $o;P ,WG۴wSӝxVS jӴ)/ڇ@ٞt!ϱmk+S33eC)  ER8dmO8挬/& \(w*Hh?)=S"'^w7u9N 2eB=#C1Y]r6B'c!?qMIcgE4&k qSPfISȮ 깷R94&j ߊ+U2&r@BVۓ}ƭ8˒%StLFUHCLY"ԃ6g]wL[\΁B=DDǖjD7#[ ?0 FE_At#a\a|NB _tZJ N+:Eﲆ'u$"ɑnؔ <+ڃFpIDY*Q=Ih{\ 伋K$;; p75OF,f7Ym305\\7KQ>DA~%)š`#\4wBk&'Ĕc7>DvtrC:ï5&  t82O\/_)(\2Auog㗓PW;_eRn~9ā= !bL@ܯքxDOX?;ޏ)ok]~0Ţ|0n'6us-%f0*=M٤_Ri>^ĨJ*2c/UnVm2O .#x"m#Y (#3$H( M؟t[i㹀K,0v|J(QE8?:wk-[ɎN/LPGnm=tҜl;V~ J%da-bAk (u_xc#(RT56G/<SPR(yA-}Kˊo`ȓ%70E'%8Xk.Z:Ӥ#ԻCқM |bRk A2 RoqReoշd^K~Z䈶ݖw̯h̪2Fݡ:f &$Iz)8u]3&䝟DYw٨$ܣ+y!-nrKer5UvH pX4ŊFfsAqA1cm8gveyE Ѓu5gsq)kR|v'mq2Z+ 1^esbGC=#v64~cp#kNs)f15SMA&h [eAY:)81Z ŜO39O%', rgj%|y;jJX R<9VX`jQΚ+f}boJ Q8N|҄52##'iPϳ/Ǵ;7=ߠdBL^Nomb-qD!=(/ejvuB̈ y{#ɤY6m->~;!zϺ 4P`v_iR[ppXd8aY7>YrZY{ rBԞpBUY][QU%r 1li#6-`&0a=|8"}N&> ^ Ɠ,@ޔ̌#z8aŊRHYՊv%qˊ0RDX*B5o>vF+z nҖsoo+=;3-@,^H(tT^|^ *@J.rAƷW5l/BJo-eyK_+g4$xR=2e: xzyi#}זh xOMdDA]~F#4*1 4B++Ak>&sFBo(VGj:AgLRУHM)fwvI*"\z;=9KHF/84qFf''tfdWTq)`xkH+R]Nes}X`Hh\[xG/< t "=_;Y2`dsHqّ aR7J5+_1c$cF7ݶ>HblB]Aawy^$Qp:+$6"1ޫm=MK1Q?e7GLn1e?2R63ϕCJncji 7N47MP[?]٭"鉢 έ䅋f>$WEe6'8ӳE)=rvZ$psz]-KU>׮GKqauR#z5bղ.ƃ4s}i`4'2Z>JpCL<# %Ϡ0h1r]o߬D `L\)S,gz+]߉gu4@!@S~w$3h:ɑROErT[l+I[ wVΪXÍIsZ(B)i_3LHh"#X #ZCKx)l"~ma6oc\:0ќjG~yQDP˭7s^{4(zq,OyqIWfz?\VϚJYm kFsH럕3<5jB4O˲7\A1& h8fXb[\]F(q(,l}ZF5u8А}K,#uVx^: p؀-{y#@R5^msWkM7BռEc6ՉCz1 WyO X{yH =97N&BK>wǗ-ǍL9$gvL}a5><@:O;EyteHkaWZk<"}ӻ_e*^9T$e)<+0 *u(oBI=qsℴongPKXM(RSMc s=|ګ@CJI3B$hM:M`y?kh+W|o]g{|hL;*BrZǜH][.ўYfI`]\oiC(" ȋ]Y0ƣ\lapj#d7۠-2LCyu*0 a+A"ng~ե31YSA8N |S1_y?)M'i;!SY黹:;q?i=.hAd(+d 3B72;Sv^j7&lH 8.v]χS(Bn~\Fohv}ZXVm@*RT?oJ<.>ww)>R"5 T6'+x,'>N&4,fۻߵJ&si'2[x sU‹3nț,C_cE뿝T&k(Vʺ~ktXH9I4.;1c=G효6LO䮋%rwd_T@|u`WgaP& {?F>jF~z9rsOt&-HvY@d7Du"| FLv|Ng1PFBf , 0̯Ė.(Ӳm\)qꖿ11B'Φgjtȝe rdZs),-(wMͻaD5" `9r=Dn: NSQT{kߦ|k逓^iu4C,LoNf( k(lSɭ5RE":'#4aaL> &.&^,7n̚XQ 6r)hR %Z9_z eEҟ4QNU=tޔI7Vm? lIJOzf CZ`Ɖ0=a š:&~\G}|a|ox6qGhj 5bY'X>="G"U t,NĂr7XmrPId]yǽX P-]Yv=7`&I`~h`r%&F(h`d% "'4Ugkv\E`jLSSKx{Ti ǛWҹfB{Vrɜޢ kPA怲lx!yxPvq`gd "j 7߶t~t5Ѫc0d[2 BԽ),w{">bkӂB<0KCx:$,[15zѵNNt6?'nE O]"Zd a*K)?:W(7*6 sdR!`SmwQxP {cۢUm5hD$:㐓E93#ZL-у[RmNUPQSZLv!u,r D L'}H u-8`(;۟P]$AqDXP`ڝnQC+  AM38xdE9-ЫRΟ |%xOO ^5U0ԶQkNnT\+T@)1sMvy(seU _"K~ne0Y4)/B$o9]gaۇKz >˧JUavi{/z w5^ZYf]ud@A܊C=s3fe}pm16 KC:R'Zƈ|Ӗ&w[+?x[_h2:u}Chu]?s^] P*Z%Uˀ!pTaX~5LAX2Ea76hzկd\&? e-&gvc~[BR` g62K,T v#hӘ7\MЗlЛ=Mo{TçqJx))&0ȾߍV1i#2.̀UJ ϣ4[$`;c2JtAtl.ܿh89G Cّ+oL] c=d]۸e4%Tv؇`ɡl),{TqIFCBpz]_K/rS%4jtsS9G E$4'v%pgl9+7"tT}Pw,tXUW\DwfNrKlw Qt@MVˏM-SiR×㟕K5M&mED}Z͍7Zv*]1˅( gP&e!|k+ 4춞*P(6k%ITA%7}$d)2ɑ=:z9_2d<#\TvV4*wGu1U@~vv%ᄨtp)ap6YeUd{NhhjU!^ k. -^V[sD)?Q}og@,U}&Rrӛ#sMx8t9՗Zɳ i1A<.߷dPjqA7Jf\Wb捉: T 5v758 4C* w~4tJp6DdDS\KlvZ-f,ȶpww۝BI[dӕYtD|Xuyw4([63xmq,caYCEq)/s\VU w(HP^:0gnɝ;y5k֎y%cg.+ Q*թ|}6rSa D{*?`Gޡ&//6{Lw}~*2wϤ͈ҵyv9![&>Q) siBΫfUwW䢛kEc8?ˣ NpY6ٍA1w.hr.6|s-W'˔ObT@5'jvb#y\fNčρ]YY^.}7w'/!,j ٙTԀ;8a!!/co$oʫgk,Ab@'9]"׀NdMAK$q y,8T.@ 7<jŽnxoy^-'>^M9TQBP+G 9'_]oXWPY528z}n1M?ݗ"bcvOJ&z0XW/LDskUg$ |NGoF`n)80Π;8S-<`;+WRpz۶B/B hݝy|^nL1G.g llj3RZ ݂a:#B1y+GdKq?7?d0N~kb_ v»v  l߈v #}eQˤPwo?{ 0o.b5fGCK$?9B2 ̨.{'󿇌ՠVX/g왨)6fdȀBɱĻʎ[|Zc㮣(ggK)r9uEl2WVrg@"H[`xy"Cja0_R}SٙB03g y UD@uVc_K 9ۻ8)G˴u,r*^# TzˍG[GIk\H0<84}@:CGXlddZItE-B $eJQd45ǦrbSY F;Zw1nPki`Jx.*'AڂY;ŋv]Zś -<%JAg̓(07gؑ(:|[W 1n7 ~9IvWo#'H {NKB–Jgt?>|Jn9ݙ/fqOeЙXEǵ X.BbKLzs5vQ +h4rȢ̍£; B-m&U#CF8=2\$"S"y/W;6<5L:I4F,>k121&&;<{&kgH(N5PB4YEڼ|o[_ :SfEk np%d3sUBN_ o9Ľ+`f~"jG?KW\_a'Ԁ|(!5.@qUV}GS q&_ '1|=LXJׯ׿ϸ'F҅9pXЃ0Pܪ82+D(0p,:g#\$uyoETO S@>G}d88ܨ^9α|9TqD}iB1>8z4O{, ؖ EX73 CX9WK5KKP(ƞgώ}!ܬi;rw~D &ҘAZg 3$3z_cV="<)䏋j{(= t3{"w\3Ñ^/'?^BO~諾2u |Mi Mb`ՄC_9%.,@ rX[Fx.S{,E~,dZVZxjHQȤj>" XCq]᠙E>{C (@ȱWa@T _OѺI*塺A)DnTR]䵮&ĸ@wff$#}qNV9L`T],[/]IݹЯ<iu tQ1%>;).(4Oؾ@+R"UE#vkg dJv쉰awUBUԋs. Y34Hc/4v'ōYh;9G{4٭]ϝQ|8UMY+qIwj^`j6/θR9Gu?"Bqn! j2"d90`miTw/Z6x%>W{bw5zp%|bZ_ܬq)oR/GJj{ A;܍!r~TϬMOMu>n^Ϡ(6+=UXsy%']}0JL.rHv~=_^F'<vm8I#!j/B_g} >iĦ-ٳ9A@" ܧo\$I~4b~nhB: TcfurD;R7Mn>,O>jcb'foQ<r~7}@wiͰ'EH)#p6A,XG3]iBڎX8ðL%:]mg/])Aj$(`|; @nN%dXJGkvm.ixOdX†dnwRr@"%D^*4@UHX;=犻ctH/'+O|]6pP5:3I/Cbp>A X|϶$0ˤ~ohee5 T{LyWVXsUBpEt37l9wJITӢw-!v*WI..AfEV Ej- ܐBu?_5BTA+ 6%⤙?Ȟ4t TZA͘Сr']z%'PM('ԽLAN3Y!xJ'E`=-KK:Y]p`k BfIm%MПGFhT^G 8Ԃe F v?~L$ Mw=2B7;T4= ӋlBtM oYjCtpU}o}1^Xf z XM͵:-r2xSVWR{ Zs6dHV:!h%+C{ȧU&_mfm!iil؟$:!AD&*۬d2c7˛q6~u!LIMz]Lw?Y5iaCaIpQqL!rkG9v5l4M!"Bm>SQH^r񮰼SjQАʟEͿ]3akU}Z4D'T©zgp@K/]I3s @sǗ"SWZDr Bz#ndbuC)u)d Ag A ێTwzsҡѠ#ҿtGl3%ubG[$-L;cT-y>O\T%NKm爯. ˼z _-@2; $%0Ru;?GWZſ.\?ކ8̥:(r7]B2lF3+hp'@Țl}OH6aֱVUx56}C,\ Lz9h!CrJ]%زA2jrkUߟDI蕧NDoRB Q @6H/;"5Cw4 sDHb$a!Ϥ7Y6f⎨pSP AtplXicd ÁgY$n=Ĺ~W.|RބBfpgN7c )VQm6L2ǯS"NjҎ$ * [8y,qƙ!)$8:RTg+`4ԭ^H,0?3{ךּ mEGc*[~B[ x\R5=LV>匬@fdګB!%7g𽇍5E`a6'KsnEaV+8hYSJg!=4SǏlJdּB=`6+//925-$Gat<pw nաr+)D^U9] ܈ҚDnNIu޳HEcOsdWu[p΃iC_l״I[Bp4)<:|IAT 8ϐppR*Rf@^5M?ENE:Wk$uTa`s*5l4i6DLR[bv4ʟRX=ݰ졀<l)_Ө=Ox, a?%BAbE>L>({YVZW=HLDeCg8_m|\R t뽴{;n{ظ'`F&yiiwV66S_,kbM{bAO.{S hznÿp@ŵjf^3F(!nia)q(4@Y'CޅaZVSI *ӛG[b[roia/GwQjbf"rDȋ"ص, an>Ysv4@9ʧ&x!/G :>K DGQ6yE.aأN2w#[O;'*FXIj>Fq2t`<}PP$-%Z3!X7Kg\:(T6Ac+Pcӱ M@~{ DH)57^BC18q~H}q IJRF9if0 { v1=V%8a3*?1MZmBhIzA*״e`P-O,<"N.SQn"/Y'>ηoU‰(\l(IpYXw P[!㺒< GGʶU#13&>a 0}%)˽4aSغMw,r)j_X?&i{$ H]&C<WaUJ@ۦ$)u9/,? >]3 D2ُtMs,ƶ CG Wjع>ԞgҲR $1}l͇Lu;NŖ7¨/`,4*FT \S93[?P-qѳ84Ϛv_tQi(J8RtXLs"2g[7̉N[բ|qxm5HlFyimjo~ԼC >U2ti=Ut})Os捉G fOY]C]9/tUx co{+dwϑ *)o!*3 GileOև9j-H&tD+ڦܿ:HDN%!Fq%ywzi roS0#n(":2\Tp6*0oΨxISWyc<$hYV^A%c:￘8Z.~m R"`M`Lϋ0H)Zr_Q -K3nU!J)R: jTU'to/wąftK23F8J צwif빢CF ݿE796EybțPOWZ%$#3f9=hH!i!e`[=E1$Յ;Bn~(I+`2y2#6쓡Xz"d?"HgB;g$>¡nl5-dcYaˋcʅ4 )pgKq 6i *G[W",'MZ 0Ye0-53IUn͸1MW, (\i'瘿tL:_%a /m A!Q579,` g>TU>))zO KYDռe3:eǷaR#5˦Ed='ֱۻ%͚ ^du7"\eyŕABόKl0HOҮ7փ@&=bP_(rp歒K,BL'4p!*_*"& 矔25LCZ_sE&DAL SnQT!{G+6qmp?o0+jR.*oT͢Py5GPJ8UM`?Y㙽 a8ACuod ‡,`zڡ''37 1,e0 /(V(DHƾLZ܏7x%Lku6hϛPB$4 [gCpVRRw\`U 0r ƲiOp&(wjŰ2=yeHU~HV3rqP*ɚ[Zf#Ec!)un6_H4 h.6G\/tFBBAQWO*R쵕'X}z?6u eǝo!-5v ] :o滿aa?U|D==Ƥfe%͞1ӽuo;m}ļ.'<tK垨9#vl. S䱲b>ߧkNn*J[ĸh'+?7!8+<)ReDD=SgؿeWN?@ubx}HpDqSӱ's}|AFG¹E.*'^!(thtC[wauܸ`}-,g"ҷI>/mSd#K#2UƲ eϲ>rj!˱E71-&BZ Ck|ޏУWV-j|AR̄C-t9ϼ-}&A= @y I'llSxj%`|b`~ :Sl$,t5&&ѻ܄qܞ=}q_%5rđ{(-t;WFsѺj%_( +tVqH,y @VeYVN& [*)m dBE OTrܱf>$w"\ sVKt$%uG@#*D*y&B::5p-`61c;_sGƄȾ[fYYDĤA-j\Sd%OZUfY2H!^di ^a)̿p\ˤƖ 4"ƶ%AEEB+%^P@칷,@B57R8L2<~726|s8a5"oxJۀm{%8>L4jp$1ru /}:H"G"-Y Hkn^tsAQOҤ}]tn#z3̂*_X˷JvJ^:m'b񦈶;?0 slz,)D`sKY fֳsOQ-%'n>]7KQd(v7/dІ4nvÑtzT}a9A~4ٞBEH]i};JZϠKsPW?zEAzudTLDf6~XwkI-됶$W]C0-BƖ? v*n9bWGsޓT,m;E T5kW|Q+AxPQ< 0   G;@q t~C2q)o"8 ȋ쬮zdᄫ}kmw-}!OlmDA1&[_ ~TKԛ7SV4D9)@7k%+]*2Bɢª8H=1(R4D0:t\^q6OX-./A$0ڼA/ސMX ~*eF?QE\`2[!(9rh5^"} 3JxOwǨzulgD߹>I_g{v.lH,18MlNQcJLxVV&yl+&+=k(=̰8:|^> ̟)-aVMTt%i"N G屻v^  ^RD>k7^b'oUxDmTORn룫E+㔺f ZsgJ Z.>dYp&ޥM]ұ1^i-&Zzʪs51$̢ Zg;PfXC0r#&V;o&MD.Y4`R (i\DŽR2AQ"Ұe Sb*-GmiCO *n"s>GS,Q]ӓhP/mit 2 %GZ藉Zc%~n-1NpPa֬E<TcF{+ ;Cmֳ1 C\+X}qN\9 e33@ fmc lZ^x^/.jr /s|[9dZ>5.ӹ'*Z[v}z]69 [~CiJsv0F3V{ |+dLV} Sv% m=wr>8[q ]G?AL~2,t`L<[d\Y6"1t=A8|FCj!Fc̃Q(mɳx9?c*C-dR)(j J\|JT+XCx".n:f$4p9(7Pڿb@~Vz1kgc1dq*MtAvU0r=+S;[ǖ41Jkrf/M#_7 ;ĽSk;f 92B=H &{ *t=uCug\xhtj!`yhki_!fMheiQ:SP hQydz-dwR0P" \'!SUІh.:_;C -9Ћ <"=ݙw[W/kgP.h^h^( 4FGy :T3ѱhPfj '7huIEm|boA8k~\`YvW=/ZM7QʅMu#-KCJ3k7IP˫-IJ~C,~#rX8;ja|nə!|=pxt>*b;T'9x}- [hz#ci g+nUϣ02!7&!$gY\sНȱbGHJcMfA߁v 5x9GVl(w'q60>27_&8aȲ~.}] R}T\@G1ak(LT4YYGpPr>/ۦ%=+dR~&bviT[=ʇ.6̹xC5 ^7@EEUd PQS,u/E5<߄S5NE NCbGI1V$b,w+0l 'huVsFǡH[Upu`%|ʇ"7c>O-($xe- :Tzg./yNgW{/=S(h_La9ڽn)YzT&X9),rmK=poYZ@Jr@NT/N5 M⹡1kQw^0@9yb<LoxE'qBp&u:@%̘+tCQPdd:N=$b1+x ĕSYbȖ, Wh,^f^BwNYĬ8T=S;DY {J '{xR܇1p%-j1E m$wGT][xZ];V}MۧOBhXTN vzV%Og& OַnGEZo1QԃV䈩p2%=2|ʠxWT@yI{'4S ne2 %ԙ=H$4nf7NTS@|Ӄqpm0';K}x.7jZmzso(yn,5ō"A!T]B/`#>KL;Vw`AAw@;`iAJ/l!UDCQ@Xp?fI? ~(2; A)Dzѭ [^d<]v:m8f=8vƻ1(׎d W15[%0Ch/cj(W9p(6O|*r'kH PB_a IwzND]xCڕXOqhޜұ.air=#fd2 J;q(QjLW`V=iap0Ȟ]&h\%PM Y܌L'i/ ̓! ܢ,*A̟x.VmPejdRf,ZM;t02P?ޟW؂gu-[A*1 fף qjqSuq 1!mrtEN fA!yE<NNsC3x,oBUD0?7ZlҢd_eؗWԣ%z̉ CY7„tՆYbr-YnN ld֛5IӚ n58ZM'c/QݨWU,?*Z6>J ; p{X/"T2؆8~Ghm eR3^up>[o$<m.D˰5+fMK{vDNcUGȲkp?#Ѓ=+M򤺤҅v&8x #҉ t:A2H.~KMq> ,x,d |d^ޚ<]4 hPh7 ̴dkImOyC"46ȇC[#sbLUVIoم]&DZ/^֗=aTlꊌYwב_ zn!YIŽZJQ'`{8N]7(wV1*>l.xm:IE)jŶ >1H^c_Ӓ!ΨEf&A]Z-U8}ͳztQ+xJ,kU%QL7I@~~ ݯЮA0j~:D. 5h1=azXP'khPAW~rpT2fFMwrf /A´ʧHFVT&왷0O WCLݨ WB?AMTl4HD_^&Co6fm ?O(^GddG{.Kt_i{1u ;G~ϺpA^I9"T꾮s1] cGWe_! G:L!RVؓ -cnlegAj7)pMpo Nȝzs0+T҉cat0(Z:|A3 1 񫁣8|fwYZ"UPGVF0(x o,n"0oYU353EV벢[ R= w4݌z@]YWhum3|y:N[XrM:FY3ߍ6VpMcnr.qhCi0L 0AꃟN0XaEuL`KSiQHq;p(wky[ :]kiZqK陨{O'$ճ.ߡW=2!!oX*YĉcI)e˵̯Z%QGU C%f&?0#UUShu"L~wrf)z^ȰBY˟r+a(;|_ƌjUD  Ү;a"9@eya:{w^R(ՄW[D?Ii7UUmhDbZJ @ uc#ogVriZhv+a)1lf6a籺CFA Xmht`Z`_`?KTvf@(^4Ōhh EXՙDۯ笍ޡ+ӯ5O1VbDZ K:r=H;GG)lxpL)kN>%(|S@W0@r=z:+Ly c~AzLfx6䄣G8Ls;}ף,aw}14knn6@ &ZxzXԪCB,%,4ζ㼁"'q<꾤`˖rXu`NYxг[WHǐ\P6mR뱈`QtMi_ c7Ytj} Uv˥Iʽd%ܞqm@jyOǣ 5K+[D/&x"׮Z5t)]"ߪ-xbvu[ܷV"3Kcrٺ J,_8L"L}"Ox$ѻ&, 8[sz1Li3Cgw8{dp%o^he,"=ySo)T*vYghA X]V4,YeݭT0~v p3fIgm f/웅cI_"5SL6tDFUP;+8_dͻRETST ND;0B:6^TӮm3-R4a5[1Mwsߑ:4ZWt{pM`X)A+U~_*ћOxx2EA9S)TOs3t* nrs)g4c^(%!;3PiюDiԠP%&(&qר~tuZcvQ,Y0si= ly=*\/ ,JsҞ޾޷ ;Z&54vksI Wi8{>he`XҪ'BlĝtmT}Phd9<ܒz]Qa{_k0PW-T9 ma1TܞrYZbbB]A[_xdcd ܝomـTe*̇]?%;DPS*oC8UTzx|hٚ?1cdLtRa:X) B7ъZLl$ZF1iy,{oȗgyt':KfFOַ*w9ӼlS~tGwXȆs!r &ܓ״^!X`P5hE~9?qs280tda,V#H6˲Q$eEaۭfO͆Ee9iZ.>#YJZ6y+HKHg  z/ԊSFw2RO*[cU:me՘{IPJvC{xbt qoku]6y}a _V^U7űb] +ڃgUϮ 066I($bbg%e2S=:fm?}B#Xh&'>d;`˥= xb1 7mҍB@!^6 LJKk,OӃ@2jak3ȨG|,.zJ.PrF撊Sӄ-lm7?@rqZ.YH&6hؐ{u +c%l3}q5 VKLFe쭋Te6/ΟcVhv m]\41S]PxMAg"༱N.1' =|- |;48/xDQ2lx-+iBgVhN:f4sUW7UejIЄ9X `w@)r\`у&X;#A"go2zr.^a?"ʌ=El8.(l7ha1RNboq2i )\jyӵieg$(^^I'Zt{R:Hb]Ϝ&f,9dJ4! U!ӦA&+ NѶkYx~ΕY`DR<ĝt풙G8X. lh(6*SRRx}k.-&`l!j;VO/hPoT~FB?6bu<*Wum:Myv9ۮa& t$6c)bw}@ce>6XyR%~9+"Uֱ#([yzQk[Dӓq詥@3ȧM ^)5Ӆq[M>Ǒg7i.'3NEI2TE܍*Qff ukjYŝk۲9)mL=_Qy xB"0o\s\}a,Q#Mq4gFAœ8<.mP~G$mwde\q?3*O]]|Gk@ؑ:~` N5R&d7j#ękYC>\Fw8$9u,0:C1BL0 ]Ŕ@άdoG+8<0mɁ D6d#_⡨'[uW-'< >3^h%I?XYTbd%+JPܩ![Xn2@<ȐPLxaMOUXF7 odn f!d"Ŕ Bl=C5)ic ng1@p7~qr{TzjzQw"#n6֠dBCa@cI'#Gg3p\VQ ;W'k] *;&rŸp7]Vi{jk[&',Nۈlr11I;eouLQX\_q}#i Y%MVe+#~ץawE HZbf(:/yv/%[wK߶HTͭ6vap=85mg-B.|!"[㍶۶&rn_{Kݙ\U k.}eܤ4J! :|NNH0ʞǽ/yԳW_\fr f EMY@CoZ"GԴQ)*ˊY`, @ w3+](.b +==C1D9YJAen (M[)OGAtяyО@RXS ֌0m.-9E@=X==r9'9\'T&~,-Ԅoi=dotGbFĄ/Dvd kXZySGz'!KP9s& }߷+eI&?vE3.C`ziIvscSRMG׷'hs;|+qݶAF 5ϷTX9iS&zR "69v05/ ?7 ?"?dztH> 9G%-pv ˑM?a Íg;22;`;ca;?A;aǃӐo#!Exhf4tTY,4~#@4T9 3*zMh[FȜe]6ϟº929o1kiSc拞FaM1y6{vYQK^L/)ԵM>sqFƦei+9y21,ocT7>i|6SM6 bƁ :#|nmXiҡzd 4EuSdsV_E+%Iɼ xL&4(eϟGK^ƈeC^܌K$nA!2`Rn"CHNtqp['d-T63gn/+`QD()O;2l:{+% \FspcO|lR ҵ7`X;) TOk\5J< iڒ'Yt?7IרPbjLğ2rĄr6U[z5 >Gs" naDGq^_C:܅(9jȴ2e8(Af^^~~G{ia?SMMfb/G}eCL[ٱ3Xف̍2RFWMnzS&<|DsK^(}{8v4N]' Yd,tb(}K:.:N|VEO~-N^AޭFG DjzZ`_2w!1ҟb=D)#ɥ&pJ{PM,ɒ [=Tˑn<%y*~%g܏ 7_l0Yn!5iL`3DzDlيz<biXr9G cr >uH˅j|>8De f-q~2\OPnKETi$āR"?)hf0lmocEw9֧_ e>uz}Pt2}nQ>LjZ!|fzǏgT$BWT@O`JoW5bԙΣ`mJY͓@}ύn\bI!AcܽTqcM5_a^_ϏW=: $bk41bG̅lgZ WQm;Q: ΋cz$U2#3x *'I-+8/ ̊T=ѝ4W=7 F,2-vq18\}.{$m9}6^3H^7=6| 1 k\\@uiLUYΈќ ޒ8Cyra4>51֐$NZJ4>+p6|僡V"b15$a@`hw40 F^s@"?r{A eH̵|*vgZ5LO`' F(p9qVk \p-RI*E:h}'KCD6UL o)-&A;Q0zF q싛-*u |O݂{ut6S7Us j;G"%@J}š-g /}VH_Ѩc%؏ikE^{[dB3VMyՔC,gYVI<_쬐o|cH<5N+=k-]tBW+$^c%olu0AC5 xoXrfI*c͑A ??6Ԫwm!n #Z|xX+xe"401' zR(t&9ʶ7X=d0+ T m!NFd>RIkO= V!#͸ؔU~&51 8Y_4 5}D5σTڃ:NVW:H<o>TҐCǼAE 9+Rzƽf/R/Pz)|Nq! ߁q5f(M>«LDb3OC_p>edRh]4p $u~8̥?|?@0-T)~,Û%s6.?]jj}2jT#1ٻR+LefbGգcagU ~܋ƴ=T*[ &QEtZV#] _q'^8_rߖ`"!8Ț^^1+QԽ{.Dmޥ F^8vDЙ0N@ .S`>mod__:@`}Y2X@(H6Sg7{0u~Ɠ$P;c2l&*AAk-#9_`pk$V*uЅj"f)e]bx,3ee0R9rdeP=iYQ3kǃәHnZ6%p>(VoWY|(!/.9 ׊8ЎwZu>LJ8e*΃Fgd"APCoLCw9'C77E̐d|lJ9ĘdPAm#Kæ/iZijdf&}$0Ղ6:f ڛ Bc/g|'ksW) 0qG > Ff&XsDWj4*C7=N&?$VYlw1ٿЅ{pҭ* _: <1Ѭgm_6:FD0 KD.[Q/KԄ*nR]mzO֘Vz[\:u8P"(c_ۿ0r,/ ,ѐ8cؖncЮd%cܐK{u[`?W)a9?;+c3WU_0yAi#f!CN)5H(GѼڼ@bP*>'CJ9Utw2^AE4}h:"'+b#Ih2Dfwށ{w\CbTm/Pg&K=Ta.UKIcC6N ix߯'.0’h ؚ[HVDmpm۫X$u$P-D d(2*v|VJ'd46c*|?K(O$Zh!{Rͪ&G%j$J7d0٭(S=ZSЬ$/=eU/3S,Lz+'D9Jo~d.묭qu b/y2 @녶1HsˏGƙk=ن76"@ }fO5M{BׇP˨A^ u"=m9A23{l8f p޲$IpDa=;>'P!E_@*+ BYpѻS$-_,>U#m4 ʹ30O_l;5M@{:ntEQfB^ 'Z?\D.T@4>1i`_5u)ƌ+'Z-uJ: zTG44~zx!:ʣ'Ytazտ J ${e`5/uki i <џCMnh\;@vK0 D LQ %v &-&rc؛&gb q]n9 = oyĒ\lRe WigyF%&_0 e}m+# Fd cnm,]ͦ.'"Mp*Sf뭮ZH'%.R a7`0f36 gG[˅!3V$hY(!!P||AQ^bc7{3SH 7Ta?p@wn¯vJӌٚ-OI`rz)t(]"r ac*Naչ`4ctgIdu< LʋnTA'+fBX.m$78mĄBmN1Ӹ:h8En@rT#18^W33އE^E (eKl&?+!\FTSi ڄQQ6Hoc:9CzF&*p5A4$nȞ$Am 2z 7$Z$4&v|͹@?ߖU0yFNѴC;FY sp:Ua GVd]X)~s&LJ@M iw;{Ң`ElQvab xz:k]<_z>:ЌϥQer.OZ*8Je1l$@x64HN:^rwhub/b"̙lVm͠!9fȢ>h2yCkt ܗuMNXczVzgzREϔsoVh)nL鵸0 b/G3Zv|6hvŠ"q<NeJ2)yd.kHZ<4RplqaX[0ˀ4dWZPjMihCԏ/d9B9G-ŽNN7&O:Ȫ))ʠ2S%>s>!!2uX/o4jk lgȌaTR 䠦H^זcڮVE!N-uoփX.B1Q/"*Ur{89HȯA2k$_pH3uF)O"v& I[" a9:ڳu|qk V @ {bZ-ڠdsjHB^?byU<٭DԞ󨆠Aj9c_˳d&O* -ٗ@; EBk(|bxb} -$5KHlNq5WJ"ĦZ n0$asXc%*fGW\c1\h@)XXC[E1\/@Sȁxf,Mq0=2M܎<:ȸF:JN~7@,fL,m"T 9"O'("{K#917i ƍ'WˑVSz xk G&d4QwyБb*p65qv_%Q }>ά?Orct\,5;qzb~~B)a$m&33DO$;HFgىoUCZ?p=D_ iKYE`wOlF"Bm(x^9.%1OUк]R3\"t;RR}@& N4='_ڪlXRwVp |Ĝ^I3e|ahy1m m)c$In$ͬ^YDz/A hisIf2}k#.Sl< )ilbâ5ۄM+H(8H+jd/Mbd^OwĠN,~3Œa}Ү(|Vy2ܼ +a)LqM8i4?Y41yz$;ARoR,o!)*g9ݴQVc֤IV;fvlb09i3F<yNH?z胲_m(r]]*¶ݱgi45v+Qo|lhi%6E^XNVx\t{#v2c; ,Q[_,|ohm<}0n$JDi&\R~ZgG2;@[H41p8= \Wkd[TFG S﬎]Ca!RǒgC%?o8j};"Xjry -tR[U2tbAOjv,ጬxJ;<z(D]T[hHvBwvc1{"Y&n)Bln2S8lޓ@q&Z` ö3>W?"M0],%; SKd6ⵗ\b}h2ou0QFl^._ULK]0AНx`Q\ 6DeU8S ?O:J-b[{<* ORX89?o,urY0aEBw` ;[ʉD'Bܞ/sG7w1LlLo˲Z<-5KP]/OWoU:6|,>=@*︋ T줕a;:Dԑ|r(7/~WWSxN'.q$4A.B/7LogcLg@gϴWt0Y0ѥe@:G RXc={e-Q%K䍬$2Qb,w?cP )7}p<9U#PG,p/hw)h\hflEț'ϩx3)wHaaCg!q-a5$݁;|w  O 0:!f?0 D=}46Ł ~nGWYnӌc'jJl 'a /N {eLvR"I{^}^ ;ݰuN1'~||to=#.isl:15UDE]TL:ꂧgVgvK~wKqpBdnb$OU!$<(>|$/y陸q~-F(ajη[L)Q͊u/e4wę,@mѾ#Dg]>TP~BGS&&C_W==! 0n8SӷbJ+ N_s;ҏio,ډMo(7@Z[BcMߑw;Ђ MWNQėy?x!h엄f1E{{<5gwZLk?NUj A7gP2f&\'v ̀A3wԐ'u!m 3JvĈ(f.*ؽ֗m^;iv+9G{7[x{]q1[ܟM^5U /+G9*p'?vŒle H̅%XԞX \㩧ȻdF߆1ݑ.\,D;+BS;Hp#y.܃c-տ@I? 2֤eZA_3Ђ"%:pE ,7k ̩c1U~/G&+1=վ P{|y@ׄ h}pF/KA&{K\*(IAn_H9m+3T$HLpSՓ\ , ߯ lղ[LLF`'tw5uNLN!EBu9aS `6OV</[Pc&!t [hLn,vpA܊+qa| = H57ƺ^ O|"zQ]R`½<.3\@b 8eIc곐P+ աkdIq^up[)awk}~,WB$΋F@+K[=%Ve  UaP P뛥3W`ZxzmM>}f=Y#yMԛm"@N,a&;l#h1;Ͽ#KT9:/ Xj͂|o iRGQbO|H4QX8 s&*MW]Of4YŪHRV|k#gHQ a)iUK?J\l>1xh盾ED}*q>^B D5AMႼ&k@KӼ DH>6W`!#I(ZS5bD2:`2,/_!#7.#]q/h\/Al`eǶ]n*2%le+?_YlAO>kۻϤJ=-"]cZ( PΤ"rjy^ݺEb:L>L@ ;6ĎT5O7hx Qޱ;OEAN'aFGNNǚ ľ][kӸFAJ f03P(2n-0Eͤ=.2˶#VMEgzgPMmvYs{Bn ՉIEp4۰* i=JmҖLX2•Haic[(hxY )g^PRfLf@FKchWH耕6̜ie*qRV rpBSB5Sշ+MR~Qr fI3iKƐ§:jm&s4UjUWZ 1)=5Kl_@QSto"!QS6EM&fW;jL{b)ev]$DSĞuf5>it (>5/ry&Æ\kB⳻T!Si$ܥsͪR~ <,z,I}YJ*J{Uai/bowJtQ 1ē'yNM,wJD͒j&"i唰\/y[&/Ķv%3V֕-x,X횿F1R~IjKr4Yo!z,)VN*ws^yGl2g Ŏ 4*.< ov ljAtל>X:"`?t1dF7FLC}j-gXb3W}ڬQ4^r̍,l7ȀQ :!Fd6F%c,L$ (v+'Swщ;i ~!&O;X(`Mn`wA8.NWEHMy#KPud!] Z*2(jrj,U?C)* W4bt#q41U住ǤbFVLO\f.HGH{:B?q'fДaGu8Tmst-WmyAH&3#.IL>.UK j|\`KqFb @2h9n >4-iS<>~7@i%}\Et&KA{b͙kV UBITBVTWS.DWN5+[YO&.L&%Z e0z$w JM(wޢ(:i9vOږ&c==kfq 9VQMeW*z}1 a;׾v%;Š$m5H3i#mugGz2K>fp  CLoY{Ȗwh]ynGғ\T5 }l~G/uP!+\EJcyoJc~q eFisp/WTgq6Bp+Om Hoy:ϝx'G )Md@=wkbڮ\ݦ>ˠүto5,Opg phRp;qwő^N6gG􁬔=o逅V9,^D88ҴI$QMo|Ȓ%zGB9kRYnrbYeFOx/ɝ3[;Ch/1>xo$.TmċVB)w~:$Ő.'yD5 Unc^#꜓%EORRU[Wy^qw b+Q :EӱIi:E:g 3 ' a@\d4#sjckNs3,%kݮ`Kqlt+%xaodL?b AVN`n!__]*ISz|idOwK}c?GmiAdD۷uM҆oםqLhnr; @RhgD/h0χB /HZ.Y{ˆaBt$+H;V2W"z-P Op2G3rI#\x{adQt"*@Nށ ߄)m@q. =[ Hىg &DDMyE]#}=Pw<|݇D_9[Z,(ΣqBpm|>c<\WKn(r,sa.o| El+Bma7 -=zFK8X9~C|45G-2+`^?/n"{_ "Iզ'!qpz.Vg8eb/c#`Epޝ~LDw|S;qsYy}U'Q%6c;-jk,[><|@pQj r@l +JB_U KIJ2C+etKxAC60Kis8oH #L!+P6ɗ4aty_Fs%(h^ND݃s@`b.p&) W\h+K8W/1>N?1CNBDw1HdDb =Aàd)HyrX9 E|U[] fQ0=o)%2Tr^4?Uh Vɋjg"^j9oGr$\dy=/,>AyNhSnEr//fȷ,wpPG٠hVS@y)^b6hp0 NYtF>DTBiTb6Cp۲1ӷCp:n [a.쟇YWD=(}.Rz1q7o,4-|h8W:E>V50~~YriB=XieN{Vi)^݅T餀!C'=VbNo(51b1d^*D{)4<ŷ&}5CYGojk޷4?ԂĈLyA<ſW]-9 LwyQG[!fۛw8wJg]1mf}ӎgVw8kh61J؎k;-eA|;/hGW DdI9!rJ]bqYMWYv:4mwqbQ@v?H3(:$"p7Aڄ!'"ЖA7&SpM~6omIK$K-`u38\8Y!;pGofcS Ge8_ '*='y娀;qf!NxpL_xpjAze %(ˋ!.$ % K;u#K`&^4b3@A?-/F4s_+`EOhY~J)aسV1ʤ< ZmB=bTc]~f^.BX-۹,h9x4|İ, kUIUf-AHfA-xGHsOxt݄Ic'ar@U ՛1ş8KK:n|=A&'*|Tb<]q/楋Vg ëj;G鞵ҏIdlPmgfg=xq~!S)Z bi1ċRVl7x+}6f]յk_c5&thEE^^_fJ$*"O $.q8{RNLN :4(K{6aU(`2<((A@yU@1Y$U3oc"Xpdm *^XU$Op߉"Ej mk~JeځId'MmQ{C>aj1]zx$kpv)`ΚHUۀ35{LzAvgzxz G;k:=ax!,HuVJ$y5!ez$YrM1?Y]ojA6w$yٓE|sZu UMְ7@rpR[JНؑ] ~#8or!}mtVYx/̉UP0nHGS8G`Ƅ*(MX4gn?֨ *|P͌3˜ɍ4JO1.t+/tA+ Y\}H*l͸0+tq 1)npx!{V|9/WZ xisb('p)|a8͆Vy,`?ڦ1aMڼ]X&¼`䢵Q%c&_3Nc0y<t=>ē^w(y(6ٕIma?C⡩^ lsK)(<@A}\)C'Gh}Ze Iq=<\1X\ k5vDqjY[008Rc&iL5[e 7šucC5ÊȹPN-v(%rf#gF0k,t,0d/y 㧴E\:tS{GuS !/fp L IJt)'cAC/)}f,ISCWP@ K|ra(|BJ->RjbLqvUiq717׺bDokiwqE 0׊%*f&Ѱym,Cd2v+ a4B r1̷A]c Gwy`UZfX2LmO=4Nކl_6^ [ǯ.l!lXج0ڏ0E z kmo!9܊❍+͢oT$3_Sލ[;v׌crIU6k-OQ oS2H+UR8TRY{TQ馺f_ݝvi"C cϦ]$D-뾟]>4!Żrp7LDQ:-'plvPas0:unK b ThVNlւ{g`> JTֺ[Q dL%7ɐԞù_2{<ovQhԁt^M3ٓ \~Ji&G9zicT%+/ϝYXe$9t17IɋT8iJ֐/Z kYKSC{rz):s|>y_ [`W9SEI'oT˳2Hϰkn^}4[JQdUmx܅j2Wz:*)AQ-чLDf;>{SW_L@ _VCzwJ),YO҈ x{_*b&m-P6EgTJ&jޜaGI }-V*tdR ̎k_&USu Gn|OOWܳ\,z =% |m9Lȯ|Y :O4T 6ee?GC>`HS.!SɐoDp;*8d 9|VE8F*2-oYm5^T-@QY}THo#â_T} e(XFyiBNXq߉))ʅ ؋"[ SI$|"F=y22#a?"1U\aCZ+@D PCxVI"//j ĻWi-(GjVU5FQS!V?0xܪS'1_aJ;w)O2 /ѥ'E5BITYDh/}wƾ*qe?&ayjˢJ*[eRqesL^LJ.oNGتǾ%(& Zr4B+\1gS #ٖc:Bq_ ؀DO#Ӛ̡vpm-hv8ҨSEv&lm;ݕuMdHOl9[}hڳdasZ: W#M~nz KA;; wz Vf3*;=F$pQv$`eKzB:0P0@nbKN3[1LzQ T=1jꓬRdz^N,Ux ($+03dS 7l Qn y XN 9p L:2qᷠ/*aǦj?x>7,pxJ2 Gܣ1A:"mrq!2M؊/oz = w!21 ٣D/ڎYW'wYq9| 7AQg=^",K,M}{_JHB& FXWөiWU>|Ԓ-pwW꩗6{9uI2Mfv?3 }3\q8joZB{_dlȦ7 v D-X~fD w>O;R?+v77XR Cstؠ6tcJ2Vz&sRYū)w!9fWX]:sD\O\ yÍpn}8hzp l^R C9TfL;U~jh^_1{\/ Pb`RFnZ!$?ᠧ2agL'BOFv !lTte$37Hm3K^m>g-&#u} =Y^םTw&u`NlY,X2V(ܰx234'8DU-%kҿ3CHP*-DQ@ͦNe3t}|kC?VןtQ+/T}A+ce8mK|WSfPDǖ@$n%4㤇Z\S42XoN [X1N)̉8r^m,2ޮ[e-€*vܳM \5gSn9V9:Wt)_W+fgȄ6kh2`naHR-j`nebX'[LEx20s3,^Lc__=\ wCi>SZ۬˅tˣ$*kk*NPk9ZT} ar Z]u@8_sÄ\)q3cFm`?Ygi/(^~)Z9kq\Q16cuWsgK}[Y,埥/'9(-' s  0j9$㰽'lA ѥ^9wg oF0)aTxm+ko۷t m># i4@z_Ed=}[ir =ͳW#[bcPF8c1"%rH\Zh^i-lw/.k^( ʸ?z!ZKIIvطN@p!SU] EhVݫfy@F[ݳ#zV}=x,>z6QxKse=N"G'j1R6SrK= 1GL:XQMl/&~f<䓢X/'s/?E%]W0cXPp`+B21|'nũ8cSopy̸ϩ*O#T J%V-R GO> ]i+/Z{ԭb$!^-)+ykS.c'I4*T4[$f.DY|#fC(?Q4Dwh8 h)8j&7H~U+;V _gBpma0 ޯB~qYV%YA=Ih'pPR!wAR "R f<+Wv|:67G^$r6<>I2pǺ5?y5V:fvDJxz80W M2~~8}ky݀"HI%` .s¯D`/VfXiϵ(~d/Uzp:Q>ȋ'|ΐ`cO|k34>럇53<❰} !(E(} (m+(Iݗ?$5b?1ʯsgJ#BFC[#}s&a-e1Ds08>!5 qdz]pٍ滯 sZ:n_=P9Z\b8 =8g |Z@ Jn?H":y{0skclyPͯ͑fǪܕd'g0UXobWοpG3`b8^]vd>7$(r ,Gz(Ħ9³~$F\5h-y>{s ,X (ȩkLeڭp`%'~.}K8Gu$1dQfQqLg{ #Z l0˂EYg~BcϔW`H#-2 J$;2S@{%%^%fSsIlpj7!ՌRTMFyk>&@'d\oKɯ uhIn4!]#q6/CbgLpLN81m߬iza%o*7 cCJCPb&{X4 %+]%z†`=(H(ʭiY?Ÿ"jsKiT,!-CVYú-6f_-w"$j2Ewل ioBU-avM-7~1%auE$u/SeN["?1X: 9!`{= n*=8H^F45Kc V1|PcB(#ag8`/%.lYSn0K&\~"_l[ݟ\5Տ>fO'=|wX 'P>W4B/ T iyt_b<]l# EU˄ ;"ݰTH3qSQ[']T{7庆QP^H13OWj|8Lln@Υ.^l>CV>޵>T30Yc9=E.ڊ/'N?vY1V7M&92ه 71$zy܋9_ֲoORxCy T(y&w #]vAZBڞ7͹ a).sm YA= Ffqwe{j%`P5ј8ŘLf :P4B׳s"Oٶ(wUJ 9-䳇: ~uA 1xc%|+~Sl=Vw"?q}E5[Sb{dK>جZe])5 B#ns+%?XwNsNk{F? #(GTKmb;ݏrvtd8~NX>౗5/C{ESBצ]IviRr*@=ķDSj}mJ<D ZJ.'ab|~a!#t. F+m|2ż7趢찌ڏph-~8i_*N+WCne𿈟D_@V5`]e5k.{B_L\چ392b)k]h=1/,1lpK $ė-)m+PHAjXdf!ip5/,)Zfh}h&)y#tF6J엷ԓBsVVBX.Mf5/ogG$'>'d9UC{?Bt'`ԂkSQ9D=OlA"? 4lk#} 9LZ>Y|jWzb1"Dzb|чc+ PC$NJK>O>Qk&G zz݈#^qPj'Z'wn2y)lHE]2ՌTZ\|eO(13zEˈ4:-vVDN9ШRd2$+_ }츀,NcIp}U_I8Q~2&1z7`W,X LO%\s[`:0+>/pZcT^WIJ:Xs^f0ȹP +ϾWeB O|&)5sT{ A"!Z)qN hT &#"Q[}~#X8n_M[ż\srZmáĠjdۏ{KF7ܛk;oe!c(ugh;e\?#FKLy4ĝU+Qv|ckx {BQ(6kgdFD#;xYgI*jX2MH[Xmc>vffYo<9qypҗf'<ӁF!^ A!Db+GH`,#X@9=s |p4+01y |,qQvEAӥ{@tCo9A"w*ٛ5\ >lbF6m[+g^oA=^ɩϲ3~"zFR#Qk6/؀T?^qdvo$˫чU59+DDŽYiG<o>, Qxfiz!`.OKive:/fe_}9&"&f;aIUMfyVR;~ĥ& ;<=!l -qGm'Ź| cYz]T&$ٓD 8ǂ]oEXF;dl5U$ ynʹeXu/.X.Z13g!OT:swL 0 GMM:ߞڼ *#Zz!h{ PnhPsI/T]H cboUrOà3 R)ca;D*Nb8j(o^Jp.(-bԴroNKc?ubܷ-oxF^CϑdG x ?JMЬ]X-fYt덂4:z@~tHލ"xmiuPE4WDbB7dU9'Rv =~)\HKOn4tE3jR_?ksEW'C6 뾂\u|}0v6)b{ܪm崬2fN{R)*=-Z;u#D,s&μEe&ݜ⯵Sd#^{`>F'a z SȪD] i$7c%bW!N`_V9V@O;eȮàZfrLQ*ҋ%,>ߚ2Wz7g;Xꦦ@ƈWeVId" ]n^1hh[^o`XR"F"wqz`N&ZH֝ڍ^fbYJ7U,G5IIj ޱѣq_Z0bG!t'3/`hzGmpO) \^ͪ&1 U4BW<̭s#FF ?UX)mD4/ˤ^4zR2G`/A[}VC!NN4E,"&<'J%O(gdO ~56t0 oHzN{fEbDZ0 e?3C1)q}=7Gw5!3ؤM#%*K|K~ 6u2V&OPdUrI!\,Jpb&ݰ6QӃ٤-IaߺveH\)rش.FF  /y\euw݀P+U07GuNTWl,e ;X~_rs[IGA*0ʼn]m^澤La,i ;80b^s:Hz^JQb۴k h(*&aKF$b\d ;(vHu&geoAĩ&B~v"|'5Л %C"|<8-dq O[uSev ?T]ǹ!zxDUD~ߑVWR^AK \Wu` IS*|/7Q&1tSktW+jk+3ϡhʿ-:vaTP5^b_NE Κ`&W,03{i ثH;蜟>_€ \i zހ?,+szG%>sٻdژYQI<$%xѪ 0~D*SJ0\ XrrH6 x^TT6L^d -ztR +ڿVtd$Ȗ4,8/BeRPDwn61CLuGD $G[p%+' WHGAL汔HB׫oJhᙈ׿3V%90 $=;9@CL~=Fɼl/d \rq\,0ɽטs:p>%j{V1vWF%7}`WѤ&a q@#Cj[HTziZ-PZ.Ip Z}VӨgiO巠m+梨K-f5y1:k\C_F#,Z~z(xM}2` Tn9_4K'=2'h^H/`CdRLׂJ}hYِ6){)=ʰ%a3G o}gĻcgcv@]s~ۢY A9J'QRЅq̒3LE}n#HZ7:[e Ũ}!rȏU^U ! 9}`y[3!5 TKylM!|.,ӑl$pՃiU)&@5 |v@am \߃h iFkf*{]CeNB23;Dv;PZ䍙Ilg[/zشKࡅ<}rF̔'c?%);.&q}fUŭ~]3HIy%%itZm*G.~@ Ϥ5QZ>+A+F *A_w[?|zfiTL{s(-apI 5ʫ 2[IM#({a.oFޭx!T9cΤQ'0Xc̓QM||U u*ʈc #E+ nGZlfxO>#LtL篦.>$B:Oͩ T,zp̲Pi;gQ|p!1tөm)BpGlօݴMuEp7d6v>65,ܡ6j栬h!MHsG)oA8:bGG"sMlq-LHpNa=">0sX4  s$e2 `ͷZ+s/J|M q#W0PY=),3b *ij8VFӄBQnl[T|~x;7*NZ'Ss21~PDqj]*'O-49w1PCAW7l{g; =zB|v}7^BC\["P^͸4W 6DKsQΏviH;pҝ0 sK ~&JR41Ң@BdH2?dބ!9UE'1*"9K`؋ko9J49*#:b˛7<RS/;J^iT;*&?D0ޠ0Gm |p~EؽČ}\l1U>Yߘ JJ< ')j5"ObJ:U V.8]$x^\1وrqED*{:BjQއkOq&7܃ :3>WLRlD5|@8hc^MmAgC#Z!Ք *el!jj>ʙra>{9IkS?uRjQ/qd-oIF\::Nr6[㴣!IyYBϣD> #msM`gڊЂ My* ual_n O=jyZh͔7\bwh$EW@ wvC3+^1 b}v->!9hSM Z@y+w}e]MK Xs|Q*݇Q3Oq?:I(H$-&oW*^'`˴~!<2jm gKW`O %..9(Jt[IK3` yTw:̪ˁo$|JiLεL`Xx-@4uk&CZQ 7خ3֗#WAe[!XkoJ!zGӔP'ݾTwc&h?d{Y჋g٪ hEfj6 Dϗ6w+,YMln%Ff3]*HiL\~Gm(/FBiTw^y#WPUyt Sm~;%<\plB !Ƕ@/TׇtJNKR W)-)a:ͷ 7^T˲X>EKEnzC_]i gqw  ֻx+@M4P Se#6IDso ;GM$, |Bij+H|F Ouxen4]pdV(W)V՟Û(vU3C)fNև a;m3jN<8vlSHzmy wW>Œ7JF;1۽,ډb`=^OQw_TmoL?eKm%Bц(]B|Z$Π Zāۑ3Z!<ƥ##\.Su5őLe~5>$j!=Rz`t#r83'7r)2)aޗe,>iGif1xPN+]9_$JMl Ot+wUẸFBFV XGvrl Q&F 'XN_G"8[$v4s^͋夔`Y!Jq,=,tj^q0.hբaD +iwֱn;jVOy:)#X3_tYBԫ5o^_7(ʕqB`Sj“vƏ#jH+o%`5|KFvҁ5K$vlFh i$ VnhD1g"6t+J#M\/ErݐS[˝!j'?բ+-S q􉆐ewS+jKTP9L+ kA6RCRK*Idg0!f) t޼H m7&MVM:d5QJo$`@mn e@[xqYYt^)ȋ_+&e͂K詞5~QSpj/_5=s'6dDӾprnߘg0O!g{bnjsC:=U0En| JdSr|*[4eWlfh\$Z =0_*A/BQEO{V^i/2tceմn%D Ŀe[@NUWHpfA 2y߶- yY]k Z?EjtBEo>| FِMuFMxpX``jϧzQ´>uO_2s VtQ{n %Wzj]ٯ޾u%ٓ&+$,΅l207H1*rk*d^s5}Yq2[T܏xۘI9>:mʵLZs0Q,KIo]N{kа? uFl%܅*ZB^"CI}>k\EV&yTxP):ɤ5$S氱@}9dp " -|ўaIZPRۜ]^\ SWp)Kޤ:aFհ[6U 6:W@4T'=EGydaNC)vZ:jgc`.yx!Pl |Rd/1/q֥, !hY}8{ p՚KW3X ~>ϐX' ptXanLEJ-3E'Y/+'GYׁ%tF/\Ӷ[FKp{mU('\ rMm{YvF͆~v=fUgq {*y%3CA_rM[p@ Mp3HX0y5Xߠ^c#NKl!fy*cHxu54]Կ@NUvU NCB@>`5'aRC9FqawL %wDM(޲k(A"tnjQKA`*|k4:?ܸ2, =D;3XLLD%!*i~`Wu \J(^AY`~OhY.H@!)~q_sMU؊Q|2W&<28O!-\aZ$B Imb##O֔S׵Fَcá;![깉Oڴ°GXBr-ډ _2$G_v%QS?Nȇb۪wH9[ݤl{Nf*UC4CT9jCG6!Wzĕ%0>3fLcH>:e4U1Div4/\n: )p@#y)!\$@?`nd{r<)k`R ߀[X>Oo@M&'\Iu 2tx}:3-CȧI\OOb_/̹Տ(fSl5{x S½69U^ ֒BKSCSL*K{`a(X$# T9|Tn]gXqd|hJBfԭNj}iAy$ggI k<[ Ч6X2N GkPdGH1+wԛX8 i ;Ƅk}C( !d%3ﻠ`Mqن YkIe[FP7^Sؽeq mvP佁 */O{Z3V3n/kŸv$_jf9)n3EDn§0&טy<d,[C5̃fXx/Qm=:ßx=t4AǬ"*4Mb-*ek.ƆXdŰK"PuSZxVAx+o) f Y%B+g 0E3O=^Ͷ]0G/ECzgΗ|Hк3ʂR8ȶ8\ɧ4muE86ꄩ9 jKU1&Oo Os̹5g95OϻWbQ5%DD-1Y93([]ǦI1q,Q{Yg],\AoKbQR"T݅h.h/П?o̚kEуŒjMa^'arВ 4@S6PNR[{eb%[v]7G/l .@PWZu{v U^S Bt ^=~c'|I6_o5eD1Ʒ_f@$;HF9(?@Jv ј[1ĺi8UCDI 0|\݊cPO-ּϨ 7PGk\B#[^ZXՃH} 3s6M k)O4էفK$-UJ8yF⋦f1!_gU>j\dVk2\>vhQ^ Cz}2Nr];T D:Zx8`7#_jXGQ~d65|a`[.ҡyhq.$>)Xmd 4R㗆0=(Ј@5^ٳLr6!R`۰yky[K2a,fWAKq@*U!2S\xΎuL8q-*T1Pw:zIrRDN6 \ 5!QQ,,et~G*j_:K Z"4mxr#lZ$MV }-w<9~CUȣX FA;6&wp#hİn.C toSbA$sMuހ?oV>ٌ%:vZB)*%ރg}~jOjr.bWMC㈩/|'0:oZTp!^GLw蘠gC.D% I06B!h>N 7fnozh-3-{.fza㝯 8 E%<, Ykh\Y܆vW2|Pzd3{N^?> Fw> =7vFz \[T/'E{ iݶ,W9Tq?O{FIo+U3ox;֣xA'LoN\WWj4 xҊVGά-aǎ&\.@Ʀv)]'(%sb&ް3m '}`brrMPl@GT,:~h9dߗ &Ot8@tm8lg3R=hysQOVZd*-lN>-և I˯'/7i8j&Ͳ FH5DĤ3Cr"]ڕ(ASG3OΕyl_1pzHfv{\J23 ~p&d28(A:Nw58cD @nڄ>6\#\4>TK"~,]? FOWd r,VA*Xۡ 6eЕռ(xq>\k! |" ȴc_󠲔\mG >u(C/[DEӽ5ϼ2d[XjV,YðrpY\nr6_ww!t\ Ym! #%0< ǖDz啽 a98#nƷ Bb{. E(A(I`F.Fcucx5KENUl1%ّ=(Zj<ʢ%x`ӽ&Cmec9q^-+4l֎h|n]g0c.N=: [9\ޑ i/̃mIUP-emq2+-~ Wa&`+3&1ywoZK5( <6TnO [&YohQK+)XjXtb\$fѬSϙ`X{R-Vo(ueqz::7]2Mx3 ?v2EZiSp9>Aɽgui 'P2 eҦD6F찦$J S~casr S]"[.m4I?EAb/ &Ja!!^ \3&BЇA񉿖x̀:Ԇ8YL>,=E3.@C>\#^gY2׺Ɨ[(5ySyo$]"6n21'ٹSg5";NWOL $1b-@"yՄ'lPQJ qHӤm<kjmjrV]^4? Kc6핖L>KKW9L ˭Z_'#7e곆L+=EX8w+ "y5d&D5vy#l BVU7,*xKESl,=pތixW1}P,g%tÑtw!TTPeti]6cJKŞ?'^TZ*D&;JP]# |렲pRIxaR7RFR_?ދIS`#c~NlVOE TJ=d7 wH\Q߫x$UJ߿C 1UZ]X ?  w/lvsu3J`<*(>Q:|Ow%?Llj :L(bj~GDR˚V9#`x3bZ} 5楘FCqt*mEx.ILyN]29RU`8i J0@ K{C2we8$F&@xMF#-ꏾL|znߠ E̮=0zMCVeӗoږ?OіV 2Nk5=h/~wI^ll`L| r&^qY ^= 5&ipDqQ2ӵ"A8ve`G1"SUƧvXZ]]3C?DGCLv|7/-BM3=3ݪ&3(&~*2 CWm> J/JJN|!} S-ĆBw^~]%;9,Fd`"[C8yn7P3a16PIW@{60esl~li,dž(k9m fɛ.\Sԛh5Pů^WAlɛj<׽QM|3FzTp:|n3se!gSAl7 hM&EKb4 :@c #J=7J3S꒽4 n3CAa$ "R+b&3#ϲ13@Ͼݶ_j6#sqvpM$l`$3J EQ0$ko*4o䪗no^XGvbV ³k~lc(J!wss>dyJ*;R2Ǝc˘F, eK_cv@ z4[y63%;5 8ʼn<8Hn b6}U `N9\ײB^B [J7 qLth~egG=Nw-}jngO=Yz-̞{m΄C+c3OM&y8y# :~kɿO+f2 ]6IsTI8Ӽ?ޭsF_ Ҿ}hE&BW B#ԥz,yP˵q]^&4uS"޼7wM^*q -ý^)L^ݥa}Hb NkB `uCFY *[Į{eƸLM2Ԟ=M0?a h@j֍]V͛1fb 5l^."2}8nLB`Z|:_rÔ:b]nxL]K70㴡hA BDI]?.}Ĉa:dx'Ɩd/IM>ET RSGm@Jx S+渹^l3dRJa>Dt*Q LXB 8V0~w$<3>/*^H.9sO:LjMoRD庎*ArvlߠEWŌ]xRY9cƻ>mw[`n}6s:x+0oB:4|ԪL[}K.܁+tҷ嵽EFK ҅N\N73O;DRa&,Ԑ6a16A<> WX.+NR] e&)x{jDT}^ $jxϓjdGE_Hv{!@٠m3hQ:._Sf%PrBjՄ¹HC]0T֪j֦y#>H%\ܿUWBD !"=vnk-; aiQ(xY ϊGŢ~v32];Em{<i%J,<0fxWmӮ I,/OU|3e%hI}6AsQMMl4 '7s.Nj$kk{4_S2NQ ]Dm II[{4{BL7@jrzb~7*qF5S;f pN!5tNTZ , sH!pb#s=tSn &35#ˮU@ː DͭR8ym"=DXK"$I1\MpeC])/U[<}u!T7oq |畣-潆.=Qa9hAyR0Oٙ;A*I{#C, NJSL$zՅOl4L٥m nƈT&JeOo@ Wevv HzlM`Z^\ qjHj踗mެ*lQPe06ʰ/R#ye"v]"֩-XYwGڍ;#p@q#^Vܐ`b<: R畬Rk]Z1 BL!OG{lRv?%^RaC@'P6F%$RAj"k- ӝjRP#C鬋nF,+7J]-ϵ4MC亥3x91Td)~AEv-k[3c;v.!_H kC7[FxDi­V.HQɪ[_$Z,{Ύf„,NqUewCK7-Ljt4Cx;*MD6_F0 ZhfYO{uJbXwfl, z/چe|%Sȍ7M6H^T'rZ )yRXlE Hp `hcA3Ss]"^34H4-=0Xtb,e.Me=F0\jEm+$N!%%>cZNwг6AMtAcUlSTr,J]ĞaN̳B;,*ŻDwVG~kX6xk?Ar(**/.c?1VHd(~e:f~mO*eަYy: jo(p;Gs/䴈#*CG,-&{r[xfxnT4 ь"?x Ƨfau2;. )|= @aD KߜbHÈO0zE0n/F)msZ{(,7+jtTҹcavF :%ʽ6AWO&7噲|7We@\SdBp|i3WZ UgY"pş<$R'Y;Ő8urς?AtS =94ȅ k}s0e8$XHncBmچERpA-iIiHȧr]p8>2alJ iJD'*QH۱Xe\PXedm.̙}"{z3 7y\\N_\I݈?):n;6aSa|3{sG0lo?;2h#VĤ'daY'\Xƴ,Tι2X3Z^ەoSg5)H+}ÝqW Ϛk"r' XVFN hK[81vm @]wn8=Yb a;$YF F^vQS1u0Qgmu9xO͙YF߆ܴd;XU.NDs_I1Ei7x}ڥǽgf}Jʤn.X{ѝd2 \\b'u# 7:k=h7pcUb69$$kdY,?Lw]nY1l sSNB5z04?AHI:X8wDƺ~aqՕZN'Yd]e ~{ qU7d[=YLp%іi]8wZDW VE&zewd%V Щ^,N&y Ux_$Y$UiV *)jjt  SHyIK؟- :!6z1B鳲OQ r,1y $J^OwǵͯmBc'H'򵁶G=$s U3^N)K‡ߺ?D"xG\}ch(ѬJCQ߬uiDm#Zv.I1n͞D (tgvtF0dP>QzsUIؖz 3o~fqpW '`̾2Lƥ$ˈA橱@;Oz{@iBZnckrO>Q5 E,3Cy/ cJWy+9-rgcOv`]%FXn %Vy霊D+FGr4_\fĂN<І |Ʌ|5^cys TxX], A_[_%juftef> X8:1f) )Wjyu7Zl>i5ճjmgӪ#2VXXc&0~ŗIDzA]c +Q)2|$r"ne4a\w!$ Qne.Þd/ZR;ZzpZԍ ME ;+w+JzMjn˂^6seB)1wĻb?ge|$J- ƙ9ɣyM̓i-gja+[:nAZyE&\ Wn51q[xgc0rs@uXS7 )8iZ"?N `#CDBK+92Rg|_KI1@2+uBsuig1͘h3q/-4"Ok1:Y-Fn>P&_ 5e~(kke<Ss͚Oh!MFV:Kp{LmgSܓRxŐ*M)AI%+pY|h{☃Z5qKc B'AԗYX#h^1)ԋ2$f0 eKW`P='̕j@wÑn#讴;C 2W?t%}z=TK|O`#a4UP#DbF繅C j蟊oⱴoU:IISr;hc7vf=zv*/$̼sѹQ7) $|g٘*$>~ tBOqi5¿&!qu Yٽ5F0kkd[*\_+zSV0}0ٝ]nLeL/sxt=\"*3ȈΆB\{ʽcY\f(Sjaym̧ wJTbZ@W3hM}1ab)vHm#{= 6τc7l)9XSl:NńXEf O,d6 &9:"4 lx50EJ4<UcEk; ?^t+*C(&3+>պ38>)2wRTkv򄵴\CfV";쫾eUx >*3M cPieͲf Z7Ptn%yC1]j&ƎL#k;e…pK{*>7r qA6`-obSEgUlZx9=bUsLu 5vw.V$ZGٙR*3KkxhRnv5K:YOk!48ofL40oEbcC?CTW亙Hq&^MQ_,t 1~= p2J̬͠όJxM9 8C aЄl)@gq"5%*|XqUb5S5P 9Koxwa:Db=0*p&=f]~'f<"c^}'6K%Lqmݧ:s)`P߄h`)P㗶Mu6aQ/n$2ul`\"N̚; ;sܓpC]upDM]y}bY XB06> VJwQ$2v* Qw3;k.!wtxL9 =3Kk2T|3¬lAdZ5Ed7#R["AwG8T2iC02>IV <$څ)h2t]|& zI3]%u!/4 ڢw71B?z/sAP[<0,:#ۉ7&;BwVc*@jymD.k.[[(Tb9 8ΰcmugV'] l$b3:68t*6,ڏ(nf!e4& g^B &(EB7" <>geBSQ0ɜ<; ;F )K]%!SHW  Ø$y-fZOTcc YA2ɂ ^%V1Q`>*` 02W-^>Ui⪯3L?2笠ѩUSFO6J !ϐi J"է0$ MыG')7j1B{y|߀1V ?bu F`JMZc1Vt2[k%.2;tX3t<>_^u5SqN ~$<ՅeD6 Ԁe!,ҿ ](?Gq1 =Wf"tgJE" J3K:%ya7DlR&uIR.hl>[vϩ>+JQOb3!9A!lb~$>WS&6< }K(OciVj|QJmw3fϾǫ=)Ǧ$ٝI}g*xjm% L<yˠȈ#;m=63wbr *0[,`-c~FUTйYUϳƛ Ҽ})ztN!2h7XiX-5sx|q A=te=^sKm)]WDPL eyʳ%3KZle~}ϙ`Dv%AZaY*Tm;'UFq)[h8Ѝ@ Hk5|j%[LѤsj`;lR+M`Xφ/&.^W 'WË8}NbSHYY vn$6GeZ7~wbwSgѤs쳧.Y|f1H1_cni +S(+4;[?vdw!w9Ɬ٩nB/ }Zu辱.Vα3w xuXw %s2Ji'H4w^_)yړf!f%~葟 *YՊܨ=_;` ٨AL]|U5U O|nJl g6F^|KK$Pݞ FRW>7-g^ɓb{qnf@5tEj:: Y$C8n=7M\}DIm_`MUʯEGFf{U %yMPoDZ0-wRdA%f$ 3|Đj H 7HxrhH\ۦ'w^U7t;}~יd) zCPt{޹Chhoצg${Fλ^ []<2=?ϽdՔ+f{w zw"[N٪ܩY# ~1w_82ҙĪ2#oR+$QJ3M7TMw Cs_)d<>}M*tD磧 Cu~~T^T,2|@){\H\p%*ë\T0Q狻q8V%ސvTs7LFb5MpkI铲"2bcKD[/+ۈ0+f9/CGp^*kn4@cYK t5|pSKqY~}~~gOfǯ OzlOGco!-UT85'j9`y4Jyp֩g3 4:M!03+I*M~9 7u,/ 9ת b[߳Fp 4.3zPhAp==/'Q"0'#_ā505?xۉ6:P^Xkևpgy˨Jv\ZEY^|@ J`qrݢ'2teڴ{h3LLWX6>H[o"9ᨋ[{dNkuMS~k8 Qq9 JuO( !A HбڦHCF Q) M*;{%>Pͭӓ|qHaf.MOs9Ʉ`?q)NT|jyI܏|=g+WwYQO8̈́_N[j{8{>y[rZCp5=/¦í=4 &{-*pj4v |p\`^=YU+Ο,Ǐ;khuf)_bd/f^|:ʹiPDHÅb;ƈ&@% e=>$a %вe_knHz]4Vn<}\6}Mj!+eb.rd~Pdc-гE~m[_7ƏR]ge|5؜W$?'"˄s2lLJK]y9, o.˲Jwxpy{ݠ=,D~0,'O@V"V¹oVCe)n@❥ڊKVhP՝^ǑGo;\\ۉ?#,t `5)>R,ZjKX fy;iU?H4EB 4O Ii8p6g@7, ݧE\BA`,[œ̥eYc},["SD@5oSD 9 RV@5Z.ĶUf1 ,HoSi 0yy-SwʑzDmf_S3\+s*0\SՊR޻J1_yXMVLk3A i)o#502fXp&:uzT|PKՋd=Ut7KM8і7O2a+?dP.>{sBo% 7ktKNM8<$B8#M=E#hWI@ WY98 si|f3"ys]pV0Wv}L5oHU( 0@7ΐ Ԇz]< <i%ʥ/hi/qGd-ljIύ<#&bh1 844IpY+|R] 0o״U4+֦ :A,\.`y!‘`IH2~5(HZO_X:%SrpY)ZX)+T 9C :!vTu70J njbZqm̯Mijj"BiōW")^mav-4991Eȵr(F 4AlO{oțzJ%OeR``53hr3SQ1> 23uZ 5aW8?T[ڠDJWfBMGZi~:,3 ikE]7nHĜBHh5WC,4_v|̐G_E6KR@z62CraL6{KD%sS+Fqzف20]ʬ5 1,dTTL8aVt`*vNN9dhK0U6вجPl:A{ai,\7=sY?".-R֟rff&rsI QF6Re#?$.k[?P8&ƬzIJ^*׌Tx2tV*$K2a>,Ro| MDPfΣ{y;908` /vwo+.2]_o.xJpp} :P^ _~| QVf,3:~60H} rӱ[g vaLOrqC_sq^"B%k+"#ʏ8öV}fdNrb~l[Nۺҭ K;1O-f%O3Ai|Wx;L9)T Ֆ :H⺧qߏ O\f['`z2oˢ/ghO.]|)jŽ_HTzdI*/za2=9A\͓(kYD6$l&&u1 t 0SAJ}X@Xa]L{Xݟp^~1S.[TXuM~j!ٵ=1hXL-T3IWjB5]lH^^ph)[ZJi%Ŀj[3Rx^|P44|w&(6mO}wG[ (@iwݰ~Y:52I~5,L+ immDmVE(?܉ԻF#--_Hjk0ib:񿵈zlVC"ZEϙ n}8CJ`g_`+kк܍Nl`!:G s:F DE s`U@e ;H4հFf_7Nt7 Ipi׿Ԛ#<gAui/W4 to eƲu"-\F>."L-.DbgE.rHhlͺ%hQhG\ bD;J2MIJ<8`5V^s/dm iIȣGtnޓRaf}%t:R(P( Y@VVDf6|iƝjǠ 'SQa̺LAXE X>!璞n\nQ炼" .HFL26;H~bOaay &L8yjwLY'FL]Ng<+iWxBu#blF}.]#z.|4֤ A(T͎ *֍E hJXT1rrCaic!nE蠎LRy f4#>4>W!IݿOUSJ!l-;] ,-T-NӷRł<<}Cgo :ٰJ8w`i}G1QmE^ڤgT&$~q(2C`;mJTޱZFp]ױ9(b:Xj@5*7Eca_Čo]7SG0gTYQGg{ V܏qLQ#:"ɇxcON(q8`B/N b>p8*#F\fS ʘCO3ȍfD pQ]H˭ rN~GTZ%L"mouZ2:݈nx"`$!6 9Ӄ ;%v[{8Lfe KDi̟a< `IT{V?p} S@nrXN|Fكw H\vbtxzs$fr= w>%Uo PN7Z-Ƥx; -?㻆_`q-۶x~ՌT~*aEy})ul&W: 7I.g`e, 4-ߠ e]OA3'*o9A,R-1΋kS8uubd?O` :u9 Mˍٛ^Uj߀uٍr+*bbsgĻOVnwpC%5yR `/#Ψ R*8 CA. <3{_)0`ap{4r[8QؒOvGB:~Ys f4QuթHdf+ep6mV%W^HcVEw^g0U7J~U񝛍8y"N/MH+^0x=am)X6ekhxÀ3se3>x5H$UI6Z޺d/,UJzl"O,-s^>0-w"[aBE<2Jղ#viRm&LPf".RpY)\։0}huXS\%8!9tvF7|;dj]aZE!)\ohin)iUEu{vtӫgёF[tLKĄ hЂ.Mʳ+Cʢ%Ś8aYxFt(f&sߠ{B,aec8qG:kdH2!45x~Iڔ椚gg΁<ӓhiHb\2謙hV~#mP%Wi}&chQH|$ ~yZf [O8deeEeԪe,q%d y `D8elh||n*c1qigSmZ/"ڜZw9f$rW1R^bhvNHFޙu[?xH?Z$Nx/!Vܥe}ɳ58|jnD Ov4f\i m'"2v>L P…[)l8b#}l0⾱siR1ڇz Rn{-IZ%~m}Bտ{ֽO zQxS܉_ !r-ȭeoҙvWu2`A'ܿHis:(¤; (:%ʚ'o1@זbG^g(%r“Ċs2T\#o%!6.{B0 AaTlKPf\îeXjNMWsO;c.҈iDِq'fe]PsEsZe:;oa>%T䒍d,U *n_o?)jF #ӯ gwݮzYv2bxJ|=͇閵N-qǽ")_fQjmA v.kLIZZBQJ .Sy) 4cm&.& ?amdM78>-0C axE҂Cw>'JCSI66|0H\'_CPMF4r,IaXq2"Фl>h[8|xH`dD/:=,w|qb[M{v= *k:d:GDx9*!7bRz?`MZrdc8Z~-xԸVF㿵:s ZeKbqRYycɽ]qyP؉8#9~7 ١Y{Թ>Nuqu*",d\hKJ8X2ms#2aa oКPlyZܩrdOsk^*m4اr7~T5S:$&V%Zxb}i9<,v\SںNPJ_|Uf@Nm+~,XF$ͱI'*=-f.c:Cn硺Hb4UC/̾2 ̣>1E`,HN}93"`,9RM g6SÑH ?p-%dr(B9}SsRXXޙ Iy:g2*L+!U\oJTP:|%Y!{xx<#[iT] ]S` *@q?K4]lS6Nl9?W&͛F^B甠\^Dⳏ2bhm:/bG Fb%ocUWXNTضüDN⛼7Ct,M(ʕ+TOI4Nm`:@ldH?HSF%= x$Qʂ!o.Q_Re@aږN-•B3N#Rn(f̷g٩o&mˠDɹJ- s  hg~D 9/UH&Yl%%;ğS VsrFlhdQaq- tBɡ^o[=KU~kgp}A0J0fIse[ A@7Yth{0ZYM8>~0 b@5>^֫ %vPI gC*\vde;Mdϣz^{0PJ'tzFb8wiu)sd+n8ʗ'QZ7?⭟H:OqS ݿ|mqYp]:@wv޷e S֗/jhtIC3US5/KK4mdP>- 9lM2tMp'"m e[o e.w9/cv|'M4hKc*cQi'Śl cnDP` 4=ѵ*{ j/5ߙ̱!`~6O7ddMDLP-͢YDv{tş\=unw/ela˿!m m~v|8Fv~;'@2\cei $v .G.9b E Y&=k4miՌCR{hptQIZcPc* ۞yea} _@"j+#HiQJca_=b-SE}wX0߾+@K5,0&_Ԩwj7J"nN͖ WqNuM SVi>?#\/ k %q[$Ft>Ge1f?ÑT]dxbbRBQκӥT: Q6Z5;, $ɜA^D1N{y߷wJ.'GeQc[al x:'5 pu⤚{yNzVSY*Gl$6 v'M:nJ}P-nuMrF.,ލ05Vx!бծ 0xP>>;狲!yh5-.|9w"DzśB"o(>jSi{͠eu(W".Itρv\Cezq\EV=쑲bBd\!ƍb#xS*~n;2'؜0vt_(2>'!P'lc-D }i{OWgT !-W f{# +{%6H&")U O9ۧ[W"i1=Է7 ;Be דnW89WC [ uvphILGhae,$5/ ꇥc[4(Gkjj4=6E_"pMaS%FLيv9 vⱘj0 =,x'A _&h4l-c i\îXXO"܆;C Cd(UC{Hw:obx\byHmF*Fʁ>Iyw⧢$-ʈu~4lor[}E$|2ؐcϐ]3CVt3S_Es^E+̜EVpzEĺ¢6T5kVdJB0vCm hq_ l@GyoL-R6$ ?tiS 6^8cOpS,ymT](/s5gH:<}<$ 7cDXTɢO̖M6B:;CMz5g8f*gQ~+Qx,॒,cZmk'.)vDʥS!9\t_RX-K=;;cyI/Wz_&UM1Zm|n*N]}a=0AɣL'!Z cT׶RN?N%CY}^J4a ڳn8B˥lj0Vְ"l ajh]āfj_q){BjNh9t6d!}{XyOV˅!Ypˑ&tc_&#lx{(YS FFֲ1ln;})1R^Zf=6da+ߓd fj|'.Vتy5 n2SQUzTNeim+R.}‹w#1! ej:[pLYOr81kxߑy)?=Y(C6+j%3I(tPf0,:So=7b&ց r`Z t7 ng. S 0,\ iQ7U*5y}V-~z4?*" iyi YV_s6.Ddrڄw`= #\ 'AT\xcuQ yu Mb5L4EEF/s4vh 6_Nj#%24Qy]ҹCpN gx\>L|T,pD\+/S-]%x@QۮyfŴ^8WW#UVqݟ-&iy$3%ORe)AlUP5?+}sʦ~.7]#]AFҎy `WM%e`%E:<1dqG$$ڨBYJiHCHp'7/릠%_GG؄Eɀuʱ!Ѭ1\ӳ{GuZ5gpQ9=̜Scx{vkJAk~| ѹ \|aH8+#Б:kNoc*&slodU;oy`8TGEOR}WJ6h03?O!VpvW<& s@!E{ W9י~V𫹋MgtW*|\PLuX-35#y0pzA'QSӄrD-P a$ 5H ({CEvξ}J>0 اk'73 S>/%6nxr`X6Ϩ]P`spgQ{"Xw ٣xUN[&eX*Q(}+IITQ^R&q8'şkx9͉ʴs{TJ|WSbBL̮=sρU.s1k]X웬~uѓRV"s-AYD|2" u8iK뱻S._#`!UĦkhf{&/w060;0dY$kdDc{hɞhFP_cfCÕpyDd nX|'hF VՔ;\{~I=0Ryrx1C܀zIS-իU02q!?1ϢI+ІE "(p)c^ks3$L.h{M U x][ t zT[[}GD8 QDgRa=~/,\8EB`Z: + D߁G4E#\mu_iD8.Fg JBSuU3KQ[ۺބGk]SP/Im[7_޶V@WmL=q:B4uzYQnC&yRX'l) "WeMPr%BwI?Vl\~7H!#=`z: &{4Ħ1XFZj 6>L2o~nK"U Rro,ko11ΰ El&21 lՙUCa<<>-c"~*5 #-*Q'G ޶%C<񝃰{瞠Mٛ $%[F%Sn­"#w~h?~)=,(x8xNvd%+Y,1%w̡n]S"O>6|{xv3SKl )|3;*"cZw@VdPHɍA[`-/x9eBA1 =zJe=b}1>;юD}v4W|L0pw(g/4?ewN@T>hriYËn NE'NXo >J=ϡh W( BQjTĖ*  P>Lj~RxqY[GOUΖkM팍v@ȎϱFU{M#혈r?b;T|5YMIl(ﵲ1.5[J~&D6f,&P'E4@f٠T mOEA$GD Í$=|VENQSّ}:blt$Fr*G@a4'<34jwIg~ [IgIwKS'K{T髬Mic5-=E .% h2!2W~oc7êNNslN+y ?-e{ik'dz+L`e%q Qkt z^q `8fh>_H#N#) \HFrqyV͌>e`Q5zd k9b5#:y>UdWn9c^kM_%2zD(hVFW(؂ whsyGӕ@Kf R6aQ4THќA#L?)iҾgkX1}}D@ILW@Ǥ@ /rgf ;*IRm/rDV#{  U-cI%81rư & sK8ko -Ws@$Xs|bS41m*y=٣ߒ6e^Tlz p}~Bd;Y^yNJ{Z2_A:B.[]+OrfK6 \>f y>Wٌǣw=2OI~湴. ;k|M /^gJΔ "H^Y`N3'[;k-7hdfy3z.9~ :V·ZvN O奖kQ| نU1Z ÷^ ¸sp &VVF#g)xVBYD=LT?#W~*5Ƣ)~7to}o(9\`tU>'$w9,9g(pu\d$]\t=^.ѫa턠 ҥ@LPtZմ)Ov^AZ4}*$oo% sZRWb5ܺ6ouQpghu $T5}#FU`'QW\{4ٵ2[ i8LRnsbOiʼnx%nȰ3:5Tvi2T4ԝHc=mrw'ܳj=CX t-eg=Rf]%̒.htupkw5C#%7:i/_X/!D A/0ȩG,lyN'cb? k[N{vqI]vP M [O#Z̀~z^B仏rᬕ Q_Ij5eP2iC *~únAxdHsZ7 \w P{ PRgzso⸵]*o_˳Eaa?P O^,mc{)"%H"ӫJϨ|I Q|ve{0q1[ɓL.g)SFhB#N{{͙G#F*XFs"zh !r_$OdQȍi'Dpڀ]"z,SYCtp-`$hAD<]cZ]LDŃʎ-E,~F<^˂vA`шOq7,ҼVZ&/a%ě1NF5!ZB[j7ƨZ@XwɁә,+aGqV8`Bh+1!PAesR:o}g|Ψu #S5(kAO+aKpn~9jn϶dj"P)z0"ݑo!Bk?Q cĥm|HT-{/֞}=琀 Tϔf$!Df1'2[|o^%KK&{b ̌؞++3nQua;ah-K Z:*7te¢dc\"']X9O.\D]m@uqpx6}A'&05vRJì)&g70{ե""ZD)Ú62{6Nf iD Pn->4+G#cb+]&P!˷j#9po]T j=a|p6箮2!{3Y ٜ@4&iHU z M疷X%[h]vjвT}ͪ0Dr4A|CDQzE;/іk/pw6PᲉ'ubC.s_xGոf?bpd4$JUfCJ Y6zt|loR2%7 ߴ"k6k4P=!i7?UVBs:\c0I3MI,ϭ\2`L1ٓ .nuW]h+3Azd6?N3j3v@-crAccaÁve՗A{ pXH %$V$4PfYcvjp/ Ԭ#Uq{"\ß޿0p#Ԉw 'Jbi|] UKY0ocyxWǟC1Xg0-m'|[OFyN*I=|jǤ|Pب_gps]$i:(_9AG3-?34:-[qu=L*GJSJ˜B_UDIT^`0R$%O rzB5ɪI/H;%(06`#Rw~#`5&[. >-~y(W_*Z;̸M?NH#"Y ~[^գٜa5ŒFQe+LuD޶-  hW!Հ4ek\+N 0= <9yd)DmJܗVc07QGҐeSʍj7t*udT 'Y#^/Gb]§~{)7d c.(p~)3xPZ(By`$^;':G9>G_oP1*GWΫpAgHI_V&}E$VdN?(Io{Р_"Ҵ1pmd ?2H`HM_.\gK}ßXyTJ8Z\0Cgi, -Y >gW>|,jOuxJLi5*98:<%zhʰNH39)T"L?qdAVuqriU,Ѿ֌VMD>  DpwGZPw׈YL9IZ ~=F9`-6"hT!]H|zmIwxpqqG8J~i VwN#"BƶF첳;?r-71 Z&VRi*XXE'{V٣0kI ?!x-[J1c(mF:EƁqڑfFB9s"Lk;|A٥'sj0z FG?Ba _߶BUbkxWY+iwm8s)|!09Ot +sD"b7rj$?0Sw0RM ms,5<2+jkRLǎܚNzd!I\ ~-Ko c`rn.ì8+"&I1 x։NZ_J(z]W/ N.w?h׹mO/dF ;00r%縎2䆁S`S@F:S >J0(9WgT"Vťe|wFR8@p<<>G=cܐ Y;wyPH2u~pMԂ3=o|]>e 8HrGzn?l1O@Zt v N(z ^Z ON˹0:~ERFO|;#a蹥EΨ[ NCB.݇RMOgV@S.a7 ]22JS^ rtdfHw@H\1Q@,*wAX&̢6VJ6j( Q-SZxHdr X&`vl]TOa j{À =?nY Cf)f鵠p/^},H!аVNtiXHz35n*\j ұ3Q7br$" XuQP ߙ uiy ^)U +et pzL:3_6?v%L'K C)*@.Jn٫|dHJKdg/eRH,z~ètt125?3KSdE>wcj*9KfRW&rC(.B|H hK߃ϟCN4޽Yxh4CS.)kP,R+X!h%x;߸9ĕ@2gӗ}*%MtkiP߉Yqhyl:<+]ϣ5ZLWE;kƂOC$Mq'5h%T;Zү`~[$4 0Oy;OgY`br 1MozJBCU+o&x$_d yk_^r6ܱLI.H%`Qzj'N8|B+ qS i}%޵i#0=.[ļF}:!Wώf&aȅ|cAHAn;ЊYr',:tRaCZ'tJ6Z(@C۔fÔr9ʏY7 #HBAl9: V Xn_z4ߙvCS1ASc\cPO@yX8.vjM):j2A8{orWsL>mBol]R+&̻_A!f#𻐅l]edzKEDtLWS_%WI 5r1̈ǪA'O9_%eǻp(y` Xw$.,$ft1^=:`E+tv1+TƩVy8Q &N"_2&!5Nz{+AܺO]Y w$E|*QHElYsn \OYȷU/z[($XHvHuAY:@^ y>O%x<P7ka8dkkD;i;Hb-WCdtP|CsMC&֡xYz˖$\ds:ֆ^Mm[*aCQtdZ&0wd݀틠]dv;{**¸( ;om4 өK3j- `Y3G9RܷbgR;Y)~"M.={*ľۯIA;8;skؔ[8<1l1͹H2l hV$̆I:R&K7t8qXKsp<` 9zp$/8ZO| C#e /oNPEKuVڏXC+V %1[_3sSbl&<;ϾשuNZ,VDJgb; uKm.ƻ`EɢWKArw'SZ ] VGmVfJW$+AԾ6چva*_#Djع B^0`5km҉;r|Lg?"fD:ˆπt#]}aїt9!@c!\rͷXbٙ`A"œYNё *{tRvw{-5P:p'?|{.hwNOk SuZU ~B(=)0onU$~KX.!9hs/k"gc%>GJ- rabn[4ī *wrq#Ny0G 5j40ZgtS#\)H.7V=3TSEe8iz$E4]\pFTp&Ĝ}hrhb6AZR)k5zz[إY9LxⰤr-^5[!_ euwɓ<( 88]0$~PdZaԽDJ9jѨkTxc_ xkPhq]{YyzlLiDVM; M:)aB+8z?0RwW  10[~c~ Y8_`MR#q|e#pC"EYW'`3Y*xRxHvGur 7'_Xx51kjY|Dxh|7nٖt3*1H2+T![{-Gy Y2@2["0zW Lʰ`iyĤn`CMvϸ{nޏ`doR y JUE,jFK6QX/yܶM.,'w񡔤YlŸz0-[ LjN'f 9!3=LU8N@1HkYN/HT9y,\:50ϋ֯ڇ.χb&os+CCEy uւ|0ۖTTQo\ZMyM|=0d 9_J$4XͶ ۉ6lI LV'NPd}]Oan6@Q2<_ aihOݗO˙x9\@ұ)KP*I v W0~a pq~aŜ^q,4vFP_^F:$1r֔3 ]5w,ݠcx21gӶHŠ2[W7AYzq$ǯiT']=Z'cmxA_^9J%.7f`K{2>`)S<4s;eo%ARMswV}w8Βx99#;,o/!L Einwgw< E_*"%G—<8Y1nϻ{h,3E%, |D7x.W 49ẞXS8Yfgj-ຈg J۶_3џRpVF@8H+ON<>8G–7LI_G&Z_ O9VdƲw+FZD\yҏ]YtbSb޴.~ /ę(a׌cB g~KZB%zT6ܒNpfe.AjzlAJ+5}IQ/ϲ(E4w0/F{xg/_ (āᵍDFp[<[)A:]mz[)M)P3H$$=U3hYwZjMtNj+)u$E<1GFSUR EW6_9X?Sٱ.w?|* {L735Js!K<+s?q2Lo^pO@ūO!$R2`S5?aɳTcDO63 B|Z}]M$_%**~MRy#!]!Z,h^c2#6 [%/YSO+F|҂*{wREɎ*3͢ӓ23/"8ZK0M@?͖7 W^k s FHƊɲ^-DӉ{nGbƼ 3AoX,k9Z1~{ki(s% E<! ?< yP=,ؓtފboI7Z/~ T{EXj5=l۽Sn2*/*dfqtL2~ϷԹH5cq؄ѭE,"zb0NuTe66c`/K%3Y>T㶪DrDdh}];: vkcs&<`xF gH? Np=D[탥_;0Un!qӊ(vtvNwy \S<*ppX'>g-īkyS-zbzީ7@<6d;8ĎA&Z3쯕 ƿ'F1fF"ˠs-1XۡSН(~9`zbrw1Xj /b2NLq@A-xvWp7K iPJuJ]L[`\s'Z~Y}zeChK7ۻ09sZ&Ͷfç/8q"tAfσ'ꏲۅ=Qw˱WNl_쎽:~",>Yfx^PYAfgRC oB VW/IF|W8 8CeqBks1EQfpT;١sA@n>ӷ 3F'MN4RygY4kЖ%y8뀈;ci9giK-*+qxutq%=VCsg:  mt`s3Z5z\DW@F`;E<}":h@xS7q[87y{'Kp @!GLFYC&gSjT <**`Hut=^=HgR6xNKŢs^B̖S[Fh擗 [߻+!ds(+JwʬB!6Y>+o.< 'OGdoXFmjh!)|D@sІg7lم:9~t 8 ՁiGҁ}ҏ8pv۪MVCO7DRLX}}4V<МPlN;r P4caY<j:O 2l71"~LįzPzε/ˡr`/UmIa3ڡjN"ꃽU;ZlbK(eZ/hӲ瘟0cW%y5f zI,cRZr$ںjsV I=B0 /" J>9{*)6amݯQ1EPfA Ÿ"[_گZq6 lm ]fFsᵙϡj^OPFxZk O?( .tiR4Wx z;FVE2ے }D0ji 0uj;ok>paVw5Κv6 b zɿ0ܘЕpۆUlk^3vqQXhH;CwJl+ެƿ1oڴ옧zp{^ovD{Jfh3b<@e;WLouL؉S?L~3ۆ#NBG4grÐ|+=;'Y~bS ):@M& )(<1!zӘ%w>$j++nȓ6?֒oSݔG\[@PztLN\Xz‰lN= c+]ܣ0|b]/zMc C]P*!a+'H`*k@\~HcytNO<(ꬃF3IGlZaI2`#/&$=ecj$1e#4YK7b+t7Oxo07O 3%uɍ鍤+X@Ҭo8['K ƈeDm2KtEdH#gnjL?iԞz9ܸwbtqF7FƷ]\m0pc(xp|?leۂ3"WR6 K*+jau^AU/|'bM߰a\UC<98 K:6R19xp$P7zjQyh (-?q0̼VwFk i;p7+Dx(oxG?2Cy~`)Qۑ6\+ ۀ*md_|H1/vny>&Ce e!kKyޮ*nYlE D?Tcp ZԶoMр1VLzEۜ(%o M$n/$R*.HF6$H}ʉ`ֈedP9`ވ7}7!c dfFzh R M-7>%6bb΃rEy Z<|E>eɳ|D)InĞË q-ELSby9JiGO\qd' ;rήyX*rWSXwN>BS!a.]\xZLmihArN0;_F𾶁քN*5;H<ܬ;̿4Z58 /]Q?jP~ifepB#1Nb/ T_NԊ[T>vMYnuGA..&.#zȍ=1, [#EQI`Lpa 3S2ەKDrW+qm?pyQ5 B61'RѹYbW|O4C^ e)TIZ5SF;k(C /ƏxC= mchp2-d]./>:^Q Ƴ}1}D&u(<[]ܔc2LOّXIyŒ!| O>sZdXy)T8w4{zP^:յv= CAs .<ڵi#}JYD?ƕi$V7YQU+G5lH|2G޵ipTɑӀuv?!Jи[Z_њ?rR{{{,]Coʽ` cl5zmn<-DZб$6J"6RrZ -."R 8MmۻHt"fM6'`Ob\bxCm*ZLbD{ <-SĨdMۥ*蜆YWw?m0UL27NKG/s^&M2^Ӝa;<:v͕c{rEm˵S)A(JmLA0O`5ʮ{X3 Hpvo$!B{*-7M󝵈i+ձՄEn3 ȬYjFܬN(QSv|)w%yhyqlf!O\1H#~X'R`EP/.n.ܐPjM!DL&{zqkt] 0;Q6ZdG1!4#݊§&g~^!Ew8 ifQ~GmSyc:[ܯWymiy=JNKH6ȔֿD?f{Kωf$ׯ9E\֡cHzƙ'=rХoNEoa)M5|^uՓd\cGKwA9H4MdDCVK*EӺhBj%ɑ.+;?"堭<'iZn5SՁii+yU0 \ )EPT[ }.1,K`E ~1esHo ;aC{#̙U3RX#pYg52FC4d|]`zNaF@KZ0(~q.nQɕJD5(ZQ;ɬˑO 96c _|tVwȓ$ҍu #Nx>Ü26'tԚ{i@ܓ8Ej+`HςW$g␇[.3ߑP!] V L=SFFѕR,ca:HZBk,ՃN]8lJNM/6Bf+arPp$\ A٦`" w[ Y 6jUh7$CNX; I ZA3Z\MRˈtPtX]HB4CE\iqإ0.ej|͆ӂi3i0j6[H+HhQ\d-=NPFN+mlOCC-L@H/>s,t1+-ZˆGbUbӴA\Kڠe5BOBo.A84#΍ 9i`BQC&ER.ҷ M=ąʠP6b5Y\? WpS-L億yW`":t}c>7u@"hhPq[ݹ}xT';UG3P9D&Rn^r ]JaqxiF\I;?C:{+ :qqrM׍-3l<Y҅Mfb3*qaƠVT;ME+>Q6<6O^xҸo;},fC\1XFK0%m tDg'#Ӊ:)#&IAB_]-i7xV4%>j6uy\=28|ިn]F Y~ t7L:{pz ѱKkybFf\ P.ubjs\rc!NyU4{0tG9QGf7Nmy"rVo{6s.qBRéx8Y{]cĐ^AS(b珨541Q5iRL%?bRGemCŝdJM) o:,' >y 휵g`AR]D~gބs1,u\Br?WtYK !_ b%1[rsTfmD$D>OS{H_G~G>EZK|ՍOD7pQm]t LHh6|g ؈B[t;Y{HE#ohlsM/ʥnf㎈'G~7dZ&+Pzoպ] -XJQcϪ?aKDR'MTtV=+P4YiY4kz^o<:Xk$eV #j-g[+!( gs^i#|ٓh=:(SuRiw[SF<xR AHSD [Qa\XK:wMxU})^id@j6yr(GTHs ;sweMiUEʯ(JU Y_U|q٬lW,wOPfʶ#4iW}3tT:ۚx-T$nhqȩ{k.!NsYVLA5Fm7/5s b1BZ{=e{qQI|*6Lk3XTYIfZFf3Zࢬ~-00u{C]KV?zVz@UW/_xf(csUwcRΟ<@CtCI 05Z*rʎ`З~('(x=/ a&6T 1)k/AYWz5=fIWXItAI.9RL?ҩ]~<p&NG|4HJnEHh013+,d3RZ_UifxA/E bF95L;^]0އ\RհKF(x:(6p'xst$aCXc ^ n70]C ڰNbM/nwq~T,(Ps,u99n*% d->iv*Bޔ 'VvLakW!FY*Jga}%KAedAa4OG3О?U٩,Qcȼ­͟""CPi~*BB*h f=\axqSPu+Eʈe%_ xEi oC$~oҴJP|{O7!h̏y %[N ^c py3?=[ 3xQa9vsϛu_3iYQg(A}6 l#^,O4Y5xNCv7>@^d/kiz|/Bhl("%Ykl< yb )W8DZɇH}җ֜o%\N<ћ.Z͑K֥]eˬC7j,KKЩcH.AdTfďuXL9wx7-S$!NMxr;s&kkhȨ~r ޜ!r꫐o[乴S._9້>s;mřBU|޳GY"WZ%(^Q[9}P+9']3_Àx >ɑY^$qwc^l{s fZ94#=pUGVc7k.\L%c.h>I.5z)Eu0TS ȞIkq[XYpL&6][*K1aK@SØpWc&;)j0reh5?2QBה(}ϔ[` Q?{Q[9A]vԄr4H dIFNT0ۺ.Ev0`HZijL ˍN]p60,ۄT.Њ -\\4q.rB" EUYm01]lnCI'E6JE89q둚O=du2i%\~K6Ro(47L;&:3y>T]'$i؅ &Gn ݫFX=v0>210@polas$nd;k.ߛ.1ߛҖ0>ܑuXCbk~bhނ-|1G+|g^^Ԣ>'ܪ4Ouuk˺AFxazf9t`&06EP@sb2dNb G%u3=f[=*? XpB3ӤfONooWarm)%z +U^khM4{VxE?HvV_u] !!PH:FI_ oBؒ]KZA+/>~s]W-S}^:g*CK 6p_24L6T0Jim][j tLb1b+"t EGp `:AP1(.NG&P r3n h)Y".,Gr:Q4}߶-,cg'DBeA r4O Pe9S(kMx+}OƈceeL,PkΒs9OkOM>9PFԡ+GTB(:1\{rC[ -KO^.3s=9PKhW&\o$aR+$b쌿(.@-d-4s7Mb@ K踺 )<]x?Zkkmd@Ei<ʲX&PЅOZV Gcn#/k҂C̓5VwKcΊOks&C8\GǁT9}r|1^La&2'6?V,ヒnm7s<. x wG[P=nl29PFJ1<̈RZt3x^k{:|sաu] /f#%2uz.ƹFD&nwPCܯ>!g 1GD]BN8#L|:KNb%[ ML2W}9 >9 C SJ6 b;61A%LR4'8^/P"&TNGZ&{OU|\Iсm ڱL T'"C6QTX6r'j\kXHc|oVP[2u V,(Og"* Z/2o=16V,bd[pt`/d3HMS.m۽7&tjTޢ\ZDi&kE=+k _hO{l!t8cl@f@é2F@*>f3z3(s=0''ƶ,}u3.5{7*Y*3V$R׋pyqﵣ~=MT%8s4J,(uIss^=a0AnQk!m0N˒'j hHeO. 9-!;u =4S;ձJ슞Ϗzb% Gi&v{N=s `uiG@?>; DL*0Bζ&qMimR"F]f{hDwzt _Y6i4Y{6 _lWSBm+@`)o;Rz=0?M+IY3?:wJ ܂Xu$g\+c!37L`}9"Z(jsj*n^j._L!BHa2^.GH=/ZJQ<.]5J'nI ]MO GiU`vjth5RPqLAK+_t9 F}A]2[̷_6(ՎPȩkC\xK~7"0,$Hj4&ȤŌְ\J纓~A%M]B~А-d^v,TF ]>oB!U @lht%趸s(@Sʙg<gf#-=l[MIDW#>5Av-hMϏT$T3 9ߨ&G@N~ih;3<݄z 2+SROeAhf/z٪ Htۯ$)}Mϻ_]f{ٷoZkh0ܥkf؆fH4Xo @Ϙo96KLC^Gy;J͖U>"2 ]N=%Y1|В,Cqr=XW#H9?>H5́bd7r}Lt6UzL ڳp5vm0鱃}}\f$8ttZd-mLʔH^lvce`7lbLS$@Q4=`f$Shzwfh2vTF?*+m_8QblC0>ǯK@0mLP<"QG F&Pt 侀;dzՂD|uB\,xMXL]_ ֝u(^uD:T€Zﭛ86C6\DjswLx5vEXmT~{ m[8)5 v2{w/y[qE 3@ 4S>ךe }s5D*i|۲3LEї;y@Ŧla 6g2L̸xznHw6a7!.兩 (.9zߋu'ΝU74/D? ߁OZZ&EZKkГ2` &tu__`<&ڻķAW^R֪/?K;ӣi#fO?*{ܥ H:dj}iC/eo|ފKs}|tm_q`_@*|Ig]Pm\1TD{9%ٿdyq!_[n?y"F@W.8Yn㊜I.PLJ>r%atxftBb<㌬)DCI_LVב_XDDH5O;\.{$h ][=yJoϣAꏄn-XEiޙc狒By1Ql%QL\OZL$m`jW]/ oŮWwgz!}WXEzEPG| Ab< i|S+'{0_)ڝVܤň# 4;nFz퀏<3Đ8"K!StVÂ+,IJz1) ==kK@2n} }2 S:.RA*|RW:Gt-+?}0ޏbiXHݶMؘ+ཡjj7s5Uj3*V1nF4zI oK=oYӗW7ŝWΪ3fa~os'zo+Pe/u)_Yp%gk>Q<oR x1xPV!A=Bd¾nV ]NSaY{[ qa^fpnY+/ҧ*\LM Hoä"Zb# s Re9}Boq躕%4:hs j)i\ҩ_2)d(dp Klid{7aDCH3c#f%ЅUo~w5$VG<]:X̘x HrJ-Uk0V:Q4ly_&,ˤInIT<)~SJËiIô=E/𑈐!N}?;哇lN 1d|h}И^EXSȪkK,[Zp/y:n {A`@yvjYXAIPffY4@qWf5r g.~]MWc:t?kzj@ۂ&L D8oPڬYB̌{64c _ͩ"*Dq&Flù.n6m:e7dI:*qГ% *Z"sӄMPeZ/Jܯe,CF4pX-7J9d- -$Ln㊦uXMtNdijssbe`a&MCHFAOF}7mڞƯ?\R+tA!{M*^<F&VIӆ)Uy:JtɨHMF@-?6nxW5*F<{o'KV<)b8zcs3ܡaO M8HƓh{M)N̿֜Xy)4Mܮ㔣\Uw9]iÄw휣~ܮNuNca] ~_t ҁ]c|D갉Ud$ xP]9Y_y%j4HSR"ߗC2PJ6%ܧrTю)yv[m@|7xH5kWY%&o;AdBYSX>dr03ͪ9VrQfS֗T'Rb OPj<\kwFOvىRAJF#!!N&P$ue숱 OU4q' #9u_%Q,k)M\䛪9 "쒯smn'dR qF?|< &]Q)Z"';RlvLV4lДYIN] +04Ll.D*͡/ biТo\*Z`W[ nH<VPfR8 tz!Q-bKeXfL? {) t+A)HuMI#9dC๹k]"/{w|t S{ɔ\->UOX}$s2OVYeo(:_6 8Wġ7h٭]}ċQTn;k_gvvsOk7b:ٵ~ď(a_r!=WFx$v9W~bH<_@8>;Wo4׏L8tnJbT,}J+l\2Z1^g"cђ`*f3t ;.m+U 2IJլ팲d_ڝlH"+T > ̸V:KGdL4rceLp%ˮ5S,{L6+m[ZYwa<|} {rn6xH ^p31bW ,4w@}VL0SiYJ+Pl̢5ͮUt֒B@]T ]z WcIkpT4{Uҕ[%DM3. iҢ8$#uaFIH ;!tg0eAo/Zd&|1TPǜb B|d վJ6h}Rat4Mf~mPVJ$'Ӻ-,޳5lK7A6NLK}b"VêiЀSb.U9\@L0]c8Ut?,u 5`'~%O{ rd۾tI& ;NFsbZTs wgy+IsfVDIFxPU{N騑U+/)R;XlQG#L7$kF|eQX+J|[ s%rɪmܳP`pv۔9T{a`Pd{^,`_qJWAHVG $'E0k]tgA^ȕqTݩϒ1 tX"99R#l`U>T&|hi18CCs)v0 whmn ](80%2rZU=eIWht+j\4P{!> (m| #2%JTp#KWY*ir]aByBYX3v1kT%Zj:$pw#yJ1ʑml\v h' .mdzi1#c'b6$`vQa x4LqqKBcKr,/q~Jd"B; LNif^0bl2yP{f)N%|j  <'ޤZL놾pĮ-Y^/.!l?J?kf2KwNN?-Oz KEmoQe{^X/CW9]IW[}Z*<DC{/˔voV[ؾ៻eμOt_nH?[P-?9Fh*bTF-?R,cd<nWr[ßr+7_uşs߆cE @U+vѫU?b @A2C;1ͽl9Ku]$Z'h'TꑎMoU;ў)``pA]Wf7!}L)&~>M͞{Mr):; dR#HȻm$]NP?쉐2?ΈQ(JF[:!yVpӷLlt!e:RXMśyAg(ue6lղLbŞFfz'7'8 u2O9(_  E={cevXb Sq0뙆V~8rHdtEKr (wcϘM~T ia  N3F7Tr@ *,' XGu g(9rB20<_o~H0#>T&7p7E0tSqxٷ6*V겍uf֗)mUT&aWSC+]ld/7/~*}pѢLGu "N7ǠMcZ %Di+:"K:SŗKG{rKhTmI/ dPg@pȔd))1} #peZd)59jB#KPֵHμ~^/o+"GmpxbV$cgEw9@錣6s9|d96@AmiNhml#&wd^h;٣7$C֭Jh[BAJhR13sJ\gvIdZZq\wN?qmx@̜'61UMBfV/esט_gWZY#}wS;鋅x=7_}NX/$MЀfZqQ2Kuuc(UEalYS.[V\/l@v>vUb%_rd'\4h{7BԠMD~=1ϼw|?*Ģ6sM4'VZ_I:S"Yr_-`XHzF+XTR$:%I{A.?hq3]J>Մ[D~w y;Y α)((ň*y[`wGjtMA. V*}RϏEǂẁ!+"Q3sTm԰C$-{ t~C 8]g% }~ﵽWmi)3)bSbkAŶO. qT6)KSt{hگaqW&`G =i IӨu3 PErbJyc_rUΓoD; -gu]n</jw[f:7j3eJA~]Y Yxv wYJz+y"+&܄oT|BbYkFtN60"XzyK\\my0Y<_qVs#>jO=A+$,y5ە2%##X"7XS?LNJˆ|?&¯+waD|Y}ՠ/e%[ѐEOdWPґ l$vsL-_Xc4 WxjZfl_6NLo"3?b)ᦩJKgy=Xv6w\pde ulEeIHGŅ%F9역@*2IagX_ci-4yjOm9xk%c}op)~rlq8Yꂑ YIJqy~IMŴ6 3)d4]WcxmYm|{10 eR,<տ+2"oN[$6=!>dU0T;[ ߞĵ{×IRW?KÎ`niLog{"QLUo;νf{-JʝP䑶QD)5D/<7Tqu"l=Cxx@k~sTeթ":AW6t{Q϶DwJEl=7>jwҳjJ3ѱ5_hN阂Ѝrh4Wޫxx= Jghv f5ߢOZr5~jmNiDMbbn%J@4mpP"C >#"m;Xܹ%F]ϟ ӧ=<8iQ#pMs scbn&7`ʎU8RوXַ+ȳX,*c +~JۨL l) s :#ht\8#=# ]#Z= od+>j4.W$k+8X=:y'Gy. :| S0n"×}@Xq$&, U(1PҗXWxYfPTs-EVxEUMf8MW݉>@6 2j|cμ / Ӊy.p9)"?Yn rOo.Y|c֏wg}]%K˪`zE#(2m߀Njo.pNۧE,_w0[Q,km)(y3>^zLb :C3Ό.6}dYY'bdpwzÑjp%-'x0p@8=SJ=kMPTLES(baI |/qӚfVyX^Gr?]B P>ҡD-\R'`"F*i}ӽ k*fzk(B PtvwuPÕ~vi2;~'zX&{2zՠG?ϮI4hU9.0uI?&΢z6 ^nk=sj_;u ! -S^C')[4Ŕ}`pPvL7/͔JJsgT!׷1*ٗ'`XMk9nkSd88$ k }4li-BoO[HDf 5.qk`wookPanD)5+䞷"@f6*E̡2ݴSa%2" .5BmtB镓uh&ĠVR2 a5㱐]مZ{Uv6`#(}a?^sŢ+D[g8^ܲ~BmQ`/Bg͎%'>x9}`>FlF 3,'CX)U!\F.~!N` Orl|_/.@G nVn6e;%r<0HjFUzR2LzJ 3>;,N9<+҆H "3>kz!*]aJI"쥥yzwƞ ;XU3$Htb׋G8㼦J"ȶySpPX`-ДD]o }S{,RjRY zK O*,#R7n`s8YyD.bjBp(`T(bǿJK 3xt8 QF6D uĪvPV}=6y 8L:QBf̮8=}B%`MB3 ڛQ@inrb:H|U@^hS1K@];jDkv>{xT?)79~ږo%$6B)\ QnojsG:ƱK)ZFi7"貄r7<}5 r`+d ۯ&XQF]G7Vob 3X۫.ڑ+1_mfk7ʃ;rthnv%_]T,[dm.eSrjF/n*+S5/``r]WD cP=YfP\ V3OzJN4ٽV$D1w*Nk?`Avr,ܫ(TS":K)ЃǐtMtʡ+g*ds;m{ԆqrNv>PFO}}Hp7NiWE5;;Z je:n7`H ޘ6bL҂ x^ouĀ:2ACXI1~6<,"Lط93wPεwdl'd[z K۶ȚR󈕸&ϴ7!q91 giufBv8 .:qNBO¯/[q}&r(GQxpyH~eM8lE7Jud3#z)dfQ6׌*fov<թ͔З5+zO^fIR (uz;Gh0Xo;Y)$:)3,r|w;D.Gj/{$0ߢOY*VRfoؙ&ݲE+zskQv6Q$bLPKi6|&Z]0mQ˚i! _E~H19Ța8mէJV2)Y)˳: l+L_ !kA--5 '\WE96̏:7uP^s/a *H2&duRY6Dgd c)O8|Ge!oHhXvxCPY7JˌNC/)". t&'K*pF[}S:/>72͹\;fZ⑷Hj6Mq7ɝ~\xJO/hF$}rLh!nQ%ޝS񙱄ՙ D"kU3q60 ScMxy@kbJr uysm~N󔄃+O>^V6 4>nZ`'Ȼۉ BmЛcMՒ~/ 魆)wҚ=[0c3H=>`/m1XD ,^>Alik#;w4gt6_@¾Y₺?)Ȯ;L1B.Md8͟C,#!D3.tyAOmx>8(t@ToQNICf؝W;E)A2&g0n~k(te%a!oPr \t3MڟiS$P5<*1c !աeL^L&j }oBBH{oKdB*T3kPJDwb:vx(P ֙ A롣2çR C2Zgu-@z׊ S .`7/-y4SY.ޫE)h@, İDc`@F.Ē?"Q^~q`mI5A/e:׎5%L_s-}~1( vaOs[N^ʜq A '\Ob3N no"8 =((ž>9ZQ{avi'eFk'(XS+#ulwX7 D&I*w GhrTtB2PNɘ=7ƼD3OAߙe S]wA֕}_.pvSSv"J$J* KᲓ1B.҇=\˫~LA5_ 4*ο65ܨn#z(Xl~@S-Дc#ԂX@d%5EbIkXJ( LQv՗ f%SQD,mS(A~ D}/y0b(NyJ  4b*jH!V>z6U| tbD IH|Q)X_g["]#3 EcT:?ڐ=tγR' Y4ev\sUzlj4&n?^KCε}/br.R4.c>v̍;@^DnylO>;sÐ$sJ<ʤwލ/ NgH䉭â.N8 "cE{ˆhڷK$Me<@ peo4 Dj+u1CRn' =z%Z@f)]=^ $9̲2&jTX*c,m\Q?D ĝkՒ.d*'Ui7l];5 0"S^dhTB8Rg;נSMhz)&?Dy ^^Gl&Mv3fq@tdrРFZ'*ΛUd$ 9RH@+W`s%*GKޚ Vb 4 \Evv+TYBiG[҄/V3 Jŏq?1:ICT¯:ۋhN큷ųrhðX4hJQșUst`- 8' #|5^l_央"nJ^б!aM8 ]_0hwa@wA) Vڦ- lIsV)~?=vT:@*%!.gnP̅);`B'Iv@kFүι<wV,Xd'OFTŞ[~.V9]kh1 uPM6YrvmTI;M1µwWQi7yyD_3 g^4)jϏsE aL!S4nkȑ33K\}@.{.Ek|?m^@VsHdn];HBIZTlcE-.1F 8 o Ux_i+]UT_E$#LCZy~[ /6Ͽu>arD<=w c&ů{^40߉m1/ > A bw|{;t H~W<^#nD-Ϧ . ÃZw0KVz2[7*0{qޗ}?yjnk0Cs3[u3`~-?Ap֞9l!N(4P?v0"UOyK7К+)lŏFC?Zڼ}m#~+Zyt>HX3L|B`5[g6;p߲SVnYFӪ3R{)J !]Ec2s?@+dt w:˵Yzѷ)` BkQU11 #~ܸ{gfG+p/g6qe+\i>[sEeW[>/i+ˡ}>ؠȃdn,8hAw w- abc_h=j &?dӮنnejAmsCT†*V<0ays /Q=L! :J^At Ɲ˓"(i2'Q,R w;Il8ՙ8Uw<̺*ZOBaGi_Ry?ЉJ7QNl.Ģ)thH=Y]~h4C(쨪(?ؗ!KQao0پ2& KbJ}Q)QVNw>ֿUN;-* N6^KD V'Nbm \&Ĝn U"uMՖر?b* Cê?PB؉{-aQ}_K>T`o_*^i)z-!@A-WQ|~rc͠rɈ؍Ċ0SD(7uLӮ XYk1{N!%O- oi%х:A߸vHl߼8Hf|n*`Y\{ ѯRWF1/cAI2 y_<` y\~xC(3A&Ip& b8U{K|Cj=#!&C1ӊ!84rj,Lp9Z{p$8O ˛sD3t-vG4D9 OEE!g ܘQʍngϏip"TL>֪m6Eգ0MV_Ҩ])،ͳ.+(~[HS傊~ T$BY.Uyӳ֣C#*Tબ@G r`Y{̫3zFZ.3WIuN vn|rP:rkXҀBa|W# o0Md",qm"wo>|\k"`0 Qp~:+w?zV4)-);ES]vm( ooxnk* I\zjUmс' (ZcUU$m|K/)mk[[*[6 !%(z;[mvJ!r\Vx92T_Y6@!?Eb\uiKb::K[YZUskĮ,Emؔ]r1#ޛ>-U˂KԂVxt*$c-&}XWavLE`R.DoG4ՀζFy--']]KVU1i#1&Q_ Iyh*'9W54SQ ؟`'m^\nct})kIxfҘEhs ^V$h#fQ*F`<"eM5>=+{Ͽ&SeQz#9װv ǖ.+}T>yPˡ F ry9׷ԙWPO_bQ(XEm+l>7G41:qDfy=UY~pUB#Id5q oҤV@P~=QGq p%Ñ͝K[*q9jnG^<%+'iwOۺsH˗,6QrO:J/7_lsT>3 󑸅fN+h;֣h*{WJ%88L~--0P"nFJ_z ,B}=!@]@0şx9IHך_!TPJ̗I4F7<ÆJzOQI]OEՌDMdt ϴGi4A7t~kWU, d=yzj Ohk\!(kS|J⌔1Ƒ 6[%r*)\X^*oO@?!v@BTuoo-khs}(FͶAOmSbApq)s4^t7WoNr8J澏MgO8q+=:v!LU|w;1R5#ibSE(ux_gj߰Ц.';t<<8eY&aR>625G7/(WNNt! Ƽ=-Pkguet 3C楀]ZE qK'kυ5EPB.MQJ "ޞJ.ݣ:1:ꢠIGѾ("ST|xfΖ :_\ ގP<6OXpiÄwfWuIIun G"ܹ7A%-O_a8Y=yB՗9Tj} Bd͖^-_8g+ՀY|VÉ6p E{wCέ2鳿/".s0 Ni?O˲?ULo0N:@:F1%"Y{8tS"8fpgCuY}T| j,i4ys1=->T>jba Ef"[@؟Ɲ4Sdn,4{yӻ:n4 np~"92eX{V1127a-\Ap[w4~'_lDm)xkťE9`!նTP sNMX}C \)ڬj=xn_'9|L7OP?< 4mޡ[RP5M58vnZiGSNKIP/iD">uqп.!V'"`0ĬgL[Cd_Ts*cAȼƀmckÃrP# !dn,^".OJ+u'>!h0TOꊊI|o*[_ C^V~ !wi26 c֢(_|@CA"?JmSGU̧o[ e9,z}Y7sڝxuGHMgɊ4}/!$@|g g= f\VmJVd6qN$7hϿe8_&iܢ!M>x}.tvuA1Q;RnOF=6Q9eI:"t]|W~ vk@ۅϓHke).RgǏ=m5{~ cءKETW~ KȂgYg̰yMd5EsӺS YZ