samba-dsdb-modules-4.15.8+git.500.d5910280cc7-150300.3.37.1 >  A bqp9|+#{CS V~)y @/ۉ#Tc\SޖWo;;z$ "0FDG"QXOSxu _{>_Ch[O"6RE?r i Ĵ\ hωyHl]@ u8џj;SG$|1#>${$lAa~%?KC2hNaAgEta_KpdiJdv^4OmY)3kCbf1c9a0244cd4ebf5a03955a50f29389c5e0c30595b75e3d1505c006b5d3f37aa44b237e6f75d2c26f84b8cf848e2b0dff205ecdbqp9|+6v[q&Vp{C0|IBEwgJǰ_O&4n*e&M PT̓N=ѨGfn mo7'N(ObXA&Lz7il48;~{zG4L'Cǹ-)0GC/*x:&=F1Ȝ.m?8}֢q8axмR0,![f3x?* X0B.aOg 5s[[ĕ c9>pAk4?k$d0 > P 7NT[-x- - ,- - M- |-0--,-xx)x(*58*<9.0:? >:K@:SF:bG:x-H;,-I;-X<Y<\GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxx86_64rm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigX7Hxx(h H HX(x(((xH@((H88(8I(WHYH(((8(HG(bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo'bo(bo(bo(8b8c24995a5acddcff3da08553170dd545dc75de80ea81cce655014555abd5113284c61db821c33f4fc290ecb30ece9a4f3fc1e67c3d24a73ef95157161e6f0030e7540311546891608f9e0bb1dfb48544e9191593a9cd2524544466c1e58d042fd8ad82f00307b72358344d9c0ca1e8a7d0a50e5b64186d8be1459c5bbea3a08687277f643e5594138bc6f8451dbbea05323d5f1337be511b09a97b32416e134e3b9e98406fb1518daa49996d6c3de6cae5b48275a8ac68697f6879b798013b48585657a2de1a4357a92be70851f09d1686260038362515c8ce313cf2cf1e2fdbdfb56c5c70cd8a2b69c3632c8487304da54a9029de24bc344415dc973682e00131e77e2f2df2db44684e6f014ee43b132a652c9762e5ce933b0bbd28415fffac8cc09bbab4e9867b85cb40033ad084d3932b95e4c361180a9fa7128925e606f327ee333212c74de07799b3512272671cc3d30ccd33519d1d814798d0273e0bad666daa2e44d0832e5df7959ee02e8ef34640402b9acbc19774478caee3b75f58db394f7f55a375e63f50a87b218a8f2fa28ebbf32cafcf64e0607ceda5344dc5f4c2f0353e35159aaf36022a30145cc0cf1bbe2db0e473fded999b1c559e41d2cdaeb9f0a7f706670ce8e42b23216c2a7cfd42e453e3e61abc7eb317f6f6c8cd02839d0cea4b34e5cec63b2d67a4aa2308a1691ad39876b5de6a1262e9ec2bce040e524abcaed1afe33da4233a59baaedd5484fc24f6f5a157e8a08acc27fe1c8597b8c72807f037da064a4ee3540d135f2ad7b551fd0d704ab76f11e3634ff8fc04580f5392cd33a66d14e0acf438c79d778e370c5bfe401b0529dec662a6341585eb0fe676c357b77067b154628255bc28989ae1a08aab5156d7ddb5bec1f39c58fa9365d968366026116f41f8a48f032a78433ab11c500f82a7c6648d77246e1335e0afe6ec22384a5665d1103f24e2fd297f3c23cb44742e6097017ef9ebd83bb9571ccb95e9bba32747f19f0219d18b89c16a685ff98827ed0dc86c54dcbfb608e8b445a38264246ae4474d8257b0203666003993991d810a676affebc5295e408efd87229fa895de0a50348c9d9fd94b47e72faa034798518ae6ae7bfc1023ac420b10a65c89f5f8d6ad36110fc96c7ebf155cfb92896b243c956fe7272cab841bbc18e219f0d8ef73525bdac70906209e6fa29e0fd353883e69c4c3cd8acc764e8de87c496e32f54d0487c8129d4f148a0406526d9677a7578968ddaa633bbd5d3dddf05c09f1bba618eaaff29c40cdccabaf80152f824ff741ff076c02c67c259e697aa8686a501ea763e1a82c945feec965075f76ac6d3528a4c5dd88ec0ed66bbecea7add5f49e67b89ff90d947a0d59d4444784c11eaf82582869a548a4042ecae7096b332b471032ce13d709ce29e984bb54e0932340d8138e521725014959d0a63768397b6566c418cd3d89bbad4080eff63449e536ee9ced0b8764c26e8f5d079621850ef331184ed6aacdbff6955b1b9abcfe90e601630276132cdd37b920b4a8ccf0e54bbc50c3101ae5a9fe769ef596ad9af71d0abefe94d998fc4f6eee44961168350133bbcb71e82c3169b8888bb9b6d2b41fa5097ef87983ea900d284a06994b6224f508ade4473f63520ec0eaefae31fd1ea60496dd43047b93fa8c0e5918b694fce686938021639ae65f8d898e04db04163476c46268c7c546d6fc5d55cbce0148bf574347245d56541024595aa67cd1f3f49548a3a4921084b3fb377eef81823ab83db99577049506913acadb7c8cb869bed729a96a9e3c98cd3692acb3b8f5511ff46763f48f9b95b4abb998a86f3a460b4598e53ffcbaec462065654b527803266766dab2e8ce01f0a01767e1071b60103e15db5d451c16c2e8045d76c8313045b073080731d2459e10e5553bad9f752fcee08064c5fef717a5d50b8bb9cf70a44f7eb6227f8aa4301b1d330a8283b82a9343537c5a9dad287dfbc6e18b003cad014b3c6611f494fea6356c48258f16e92561rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.8+git.500.d5910280cc7-150300.3.37.1.src.rpmsamba-dsdb-modulessamba-dsdb-modules(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfiglibMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb.so.2(LDB_2.4.4)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.8_GIT.500.D5910280CC7150300.3.37.1_SUSE_OS15.0_X86_64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.33.0.4-14.6.0-14.0-15.2-14.15.8+git.500.d5910280cc74.14.3b@b@ba@banopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigsheep18 1658744685  !"#$%&'()*+,-4.15.8+git.500.d5910280cc7-150300.3.37.14.15.8+git.500.d5910280cc7-150300.3.37.1acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:25011/SUSE_SLE-15-SP3_Update/46ed53e08c5a8ae9c26d6056ce02cb4c-samba.SUSE_SLE-15-SP3_Updatecpioxz5x86_64-suse-linux  !"#$%&'()*+,ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0362e4b8681557f06e4a97df4bd0444e24d22056, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d9ca37bd766a62906815ec52223b287d8dbd15cd, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b8103f54fe08fc0d9482f5bf05d070061689d688, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bf5010714d313a579c792353c868f03c06fd697a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6951b59dd01e6e6cbf9307097a6335d7d1b3cc8b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=27859c3c729d0c7d92c21ab0a240454d4057d557, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0aa5c12ca599334f5cedad85dfa9d88c075f6f0e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=770ee30a993c9fda0dbc4953b6fa12edd620b6b1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6ef32ec02b7e190ad70484861975c715a73071ac, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7dbd3671fbffa50280d07d32c5a22357a88bd740, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e45ad60542beb224d2f129016348ce883d572688, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=66e4cad65abe3e6474448f4ad65fc17e13f689e2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0d71af28be52aa619936dd3c7da95aa9c4dd2dc2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=76d8c8bd37be4e49b77ccb300e6c1b1b37f5140d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0810c38ba5167daf9599d6054634faabfc93711a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5f08ce324d023beb957edcf6ddcdc62074ee0543, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=03f89fc08714b4b3c6171dd15f0b39c23a4a60ef, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c8dd9919750c672ad137f01dc75e261aa8d05e6a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=13501ae7aff2f26476d02215c9fc49e436cd1707, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4e319d4e03cfccbfd6914a4da4777c1979d0050d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1ef1bee4060f9b22867fde42ce6dbef8e1c2d1c2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5b6b40ebace6ec44737f705c1daa6013f6b7e6aa, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cd975c7885785447fceaaf8fb61c338425d3e768, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=29e8867b0e18b78655295dbe82d94e6ffcaa2fdb, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6e3f8998d6d629c91fb9b345664154ef9734e673, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bc58b4f34844f0ab98999801ac6b56ce37e72cac, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d173fb018dfea034ec0a16b0dd47035e9259069b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=681549c65966bd43dbf797f0dfcab08b4965a27b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ac7822d7b01359efcbbb164e86d8820b368a99bc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c06ef40d7880d8915205eb45d3c83d0b6d1ac366, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=765655c974ba3c1edb7dacc46e42ff4509a95765, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3d6d6bbf257ba07cc7192965cfda5cfc1486f1f9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=75b098b505cb59c9935ca10668649ebc929303d8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=40fc8028a323d150ac7a6f0f83a38afc1267fd68, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4724e88e3a84e9b3ddd5f363e3f0fc93f40599ae, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=37ddb0673581c53150b1c24f3b3d7bef74a924db, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=13afa7825263cff86620a584a013048230bcb573, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=974ba10badd8dda24002e2f15b4f7a2127325165, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=30ee23616a791fff07738091e650b945c37d673b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=188571a92816d4bdd823ef0ae9cd1f046ca2f919, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=185e94970d174496f03918a1792b312222a55a25, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=83af70aa9158e6413e0b91aa10098bbc84be502d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cb525d2c30f54a5ca1d772c3658e8cb51ede4ec1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0f8b391fcdf0c96d3562cbc7b5d70662a06f97af, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0107b18af2d0f970c0df16b1a990206106143422, stripped9Gev)DOXo{.9`m #4ALWj{   8 ' . #  R.RBRYR_RRURgR R R RHRRaR,R2R0RR^R-RGR`RTRRARXR+RfR/RR[RBRHRYR_RaRURgR R R RR3R8R9R2R0RRZRGR`RARXR^RTRfR/RRgRBR_R9R0R2R R R R^RARfR/RRRR_R[RYRHRIRWRUR]RgR R R R2R0RRR\RTR^RGRZRRVRXRRfR/RRURYRgRkRiR2R0R R R RXRTRhRjRfR/RRUR_RBRaRgR[RIRHR R R RR1R7R?R2R0RGRRZR^R`RARTRfR/RRDR_RBRURaRgR R R RHRR8R2R0RRGR`RARCR^RTRfR/RRYRFRBRKRnRpRWRURRgR R R RR2R0RRRRERGRRmRXRVRARTRoRfR/RRR_RgR R R RaR2R0RR`R^RfR/RRQRORHR'RDRgR R R RR_R2R0RR^RPRGRCRNRfR/R&RRaRBRR R R RgR9R6R2R3R0RR`RARfR/RR_RHRBRgRaR R R R9R2R0RRGRR^R`RARfR/RR_RgRBRR R R R[RaR6R2R3R0RR^RZR`RARfR/RR_RYRRUR]R[RgR R R RRaR2R0RRR\RTR`R^RZRRXRRfR/RRaRR R R R2R0RR`R/RRR R R R2R0RR/RR_RHRURBRgRaRR R R R=R5R2R0RRGR`RAR^RTRfR/RR R RgRURaR2R0R`RTRfR/RRRgR_RaRBR R R R2R3R0RR^R`RARfR/RRgRR_R R R R R2R3R0RBRR^RARfR/RRRHRgRaR R R R?R0R2RGRR`RfR/RRBRHRDRWRUR[R R R RaRgR_RR2R0RR`R^RGRZRCRTRARVRfR/RRIRHR R R RgR2R5R0RGRfR/RRiRBRORYRURgR R R R RlRkR_RR>R5R4R j+w<6x(GM^7)ʕ})ƀ&?x~͝I6xw%F02i,bJ)=8?4woSDEvD 49QN و˓Zߙ9T9_b.Y +a"*6?[zwDDfǯ8NT3%_ԡ~3ړ/?UV$)-{ _67hEVBdNRM«e^f^$wxV1fY Jf,*"1%5)͕ۊ肔!0c**{"m_` +L9қX/,dgBo6B'Cb(wR5:TJQ {u]>1 G@uh[;ƔO+ Eк4&V_tiMcApDU%HƟ_ R/ĈܶYqؽCE%-0 mlv>v׮ʜÍ5_XNx+,'q\`+4de-puQ6>4&5>.0"y7Fc9fQ +e8urK,ŤGݩ a+GBl<;ޜYvj+5Qu&({}?4=L(Z? R(eZC>;݁g $gb% nƞ8*jZ:^߅T-x& kLt?3vS[)4]Te*pZz]Rp!uv[dt9%F +te`njXrC'qU^G[HZ,2}ދBmœ]s 5-^gd}E+rC·PhV0?`u 4Jŝ5d2ݔxlGwT@Z- ħ{b&GlA`RTW( 107wFzD1p qKsʖO.b]CdhjSz g`PO1>KTsYaA]:]*̭t ܐʘhNZp[b@AIOj}$d2-l8r,i7~,WsS eM30*m7ۙ5$ܒH&5%8ٌyca$Q%g(!YWrL&˫xs<8709C[P{Hf :OuskĦܤeofC/=sfRNubc;bhgAy7\1"3rtuFyqvZ䵽Myeu|_u)?-x E3`xLfሐQ(BCGnqRfϳ9 =Y_$ўЈոo-ݸ.J4bF`ף9O,&\1aoˇ h kqZ$wkXE̜(e!:O|Vj_8*s%WB鉼xf3 G&Zޙ\g|rH?o5 ~ntְ5W/;C!AO(*">K3}(_7fǸCùKD73X5gfBXAXD]O\ wnSp x( )D fuЌS\?01KZ'vzos,DNg4.:6 [&rPl8؛]%B*cfr<:)\;ELdpNh\qV!(- h_C[b<3.7^&*Xjs+#px $n5wD\Wʪ"睊JZV  5_ PjÒ;$ 2/+'?đC~о,?*KExLw×m#Zf_M2S7_ٺvBN.lns4 [}UD|ػbC [S)"? K:#7#4zZӇGcL՝ɰzqb"Ÿbnb.N˻PYm &_x`kST:EDNʗ`_p+ApGU)U_vznsaڸOĿ|aN~"b}0-|ӴOz7 Y;Djx5 'Bܺ<`~QGaku@cHvk/BgVb_6\ZBo"X _˅ ؿG %!u/"TڷWFI AO@!1:GRPK=h`՞E¢ԑ3Ջ%{ FRŻ>1mDAa}F3&y!gr-jGS'8WwQV'V; OO:N%8r@&.zQiBC- j75OY.=;3O#=suI {K=Gmŝ)4CYB}\vAv/bd)?zHAp/ 8x0@#W )q1^Aѧ%sy\S!x1fG,,M Ǹ˸CajhR6ͷTI 8$vn7؟։ŽQ!IJmWUi X>[\s-N! ԯ g QyL:#u>AD D/3J00%4YhEZ)PBYRAͮYQ{ j_1+9&zN+s.j`;Mvݝ[*hW}ػYV ֕82H>N HjiRLk/'Ϭ<0FJd햯F6awlOO+eH>O;I_G7r) *^WooX 4φ@`Њ.]x -ퟰ#i/L?))k35gߜ!46?TKKPG6jnMln5j6Z'7ݷw%["j]܄ x6$7^먵lD!Ғz-cjÍ>! RُaGsk+G޿ ]еHc?Wt;P<8n9yVGfr=& !/~FU2L 4'Pqjḿ+TH\J&aa?zߗXزp/Ίlk᛻EYa">Tv}Q$gO˛EjkbK-~"M'~6J[}+^8wN?J f*0a2U m~*Powi }<Y5ˡ+4N.&^*D .޿e.0:FPEF)C7.^i;dfB Ńv+ܗ 0>ZZũ{n׃[\Ks( Kҍ4fM:ܸʙ- ∆73T/.d,q`ub~.A1'!TnuTy!IT%Ao= ]ȠC<ܲjl#"{(6YIKJ?S7ծJhjGTZ H5ߤrL+_<ړU{5tAӰ4æU(mQ% f $llSQ cĜ.M6sK!!!xm$ڰ^]J,NB|&T@ N4'!6\;|ZY42ѳ@{2wFuЄ# M}{"H#e:$3)11Y[&o?OADLy/MVZ[n2B17f0k!R@vu7J>XczvP^]ŴPʕ:ECbT;poq/z 946Wlcz±n1},kpK9!hcE k I~]'w3YO.f W€s # $(jl̘Cx뀙VKƒ_>µ}YJD_Օ?W n>tW9VY3OO*">Q+e!*@ ѧ5VXu*siDo=DҀIa> _g`)4f)j*DdУVP"w2^d~:ÂX,LJ!7H8O_x",*K`L%?2Kd|.]'kFI$c>Cw-,HcXҽ1uU0Ywa[QVd։0((e[} T 0'*4!{q`y+P!M%5ђĢɱA<7ONՔKtlJȊzZM /Ǯ*(w=1ٚpP+EH[ڿ HhW'S&ԹzɴL ـ\QY_D %U&)BB@ QSVÃ! 9ɈM)jM7#]f? U) Y,X7ޒF@T%R7.jCfs/m"bs[WE:!%&GU܊O~ޯ2!yK}8ΠMG5_ cUcM ֢|_&⤤zT2{Ҫ2¥/Oh/#v0Z$Ʃ(l~`6"ԱgFTڝYikRzWE `hHJ*dLf؟+MWmC|{0UEhzL\Ih/id' 97b?o'R Tw;$S/yO=Ri3,b{̱p[}WI82FhI@+dPlsSq+9'2֒2nP.3QfnI,8Eas0zhޥ^@4x\ m5B=yhqHMS@ uo:#G8jͥwvޢ\iJ#7,oOM \R251\ mGcqJ*ךGr.Uv a Zw@(D;ZT xl{ py!lAא"V[R?K̦q}_p V{TJC fH<<, *ڪHtcTK_=  ZZ't ׭N(NI>Z6;[n63^'8pMI%6QhdZF-Zt~_ u!K(8 &a4aM~;RdnCOҲsJ I$<[Lcq>ܙ@f4md'3!8K[T@cQɉ'P(<+.Qw0O`|t98I+BVe)܆ nRlp^.+v=ARq?5ҨmÍw"^Ƚp:xG^ $a 'CWK0ڡ;,Y O kV^u4>D NAz[ku?CyJCeH9cdV$&gUEGBY.RM?炗Y$7 ~J!, D4}8?B rynmG&982xLi_jۚ9|9xNaO dM쐷z4ci6fBu,(4ej(r.(Dč| ~tr+*du㥔_a53cܴ=Lrٚ^eV3p PɤU讗w`A;6WcV `O@r_pC ;wNCJdkOD sjkMg#K}nel9 E;ӊnpᏦZ+zp\ɚ_-^Fg15%zLΉdX 5{Xy催ɘt'.LʚPC~X9˄9̓&'>/ \2S f9<+CwǿY1ԹޥQ\[Kf50/UN`wΪq%uHKd\O>a4yj|+iv> #gFFNy8'}ՊUƂv*xp* `0pac(RTJHtO@^pбD7nE-;ieWg[}0_*ùh N+Sw ΪMYZЃjb#IO8E|s8 ܭ2y@cIa8jt:WiLdm4W-9Kle]uLhfwBOy4X~gL;J!b/P1?IIH+x[(P{&~:b[ w3k*sb2,\AmWJ+رHpfjqTίu)S}xo?IY+'L/!$}C/gҕ֏< kdF.8tJ$9m+c@#a@roNs#/S8[-[mH6Iӡ'(N##SqH ED] Τ6*4;=N#.YN F]Q.z{4?au|ʹ>{QɹZGJIM&-ĸrgbʒiw<I17X۫s17.'{$a`ب水a]#,Ȓ_Us%޹X||wu%|]&(W\-]<*Ҿ]akpX3"ipʙ[FBg JK8,yK1^ipGSOKY-Ϩ#YΥ>u?##d`)sUG׏3QL:^5(hE]OI+ɲj/_f <9Zxdӥ6w]\~-$,)stƳ3"춼z v_YAҔ.\1ozyn@ZXyüyݕdY]4I!̇x&7g`(i a{o9j4$Er Ŋy/iQ KH:P^Bya9[[9Źyoa؞שTjaveDÄ܃ȰBC˒>o-:=! +7Feml헋b~9ojQ7xǰε}`}`hs*qQ44>+EJX嫅!E4dB\7/t Q,6Lˇ+X(̌yQ@}jp#9JJ'5Iԉ0b#qr,&AKc859:hXV Y:A9(ә4*K$L,;XjG39*,1;CL%v4r#veS_x&UFRP~!Gd4rD&VJZ[#~|BcLRA-|&Dž(>5X# a {êIyA1J@=a#6;Et r5r93"E3wL/NovOMz_bʙ L|>P2,XitpX4Ȫ DVRT=%# Ud{뽙ͤzܘNG"ZuR?b\C߅/@JW;;v OL{H~LRuphkYpÕAiniz+A)#Ć@&fbxQ}VX<\T/̧̖r'b@3s?K;&H)="gufzR#: 1zvݬK(FNQꪌ4ɮ8AfSHZL&І>"n{E-cRԄr&|}! 8TuIwD =  3$"Ob: 9Mrͷ,r`CiʮZfͯ57|7E6!VL?ZD<*@=)!?/'MG);Y;o~^o vJ\&⷏No*|fXwO&mֹ(^8Ǩ|IXh,I[D}Va`/c o= ~ &ϳwQ6fgCp*7,~ ŮR4IOH?f@F|zN.|HYPvz*EZ`)MZ0 aXjsvdo ^A"NC\ufQۮއ.|C;v9[ AA xcz"-#8z'Vn$EAKgVbtZ"X؇zoDhmNgSΑffˇAwV[GJ18z}RXs.#YޭD[j*cU`J$C=Jxg*o'Nt?+<8ה?8FwY(MḯM ^x @myl{'d S쒨[<$ȣNƅ W @ gЁHCj\,?+TG41* {M٬6`>Ŗ[lY_bwʧz-vb\6Sr2X+Nh.S \cW7dž [:q GMasC̱<smgO&\Q7?S#X v:.1}Ou6ݚo&((nS{S K%wR2jѪ|h {7Yy (Y#T c,txkPk=R#tUԺ H%>*}\'$=s?zU(Ozs?_-xw/4h&KQ F%eR@_d% 1~])j'j-_Zth;8'ss슅eeXJoebmD.$TZCKX$ik*.ů@3{mH?I뫂Ks+&j.wXB؎*x܁=W739̌ct8B&̄@=7. ulLcG,C Ω&D pίNCsB[3(oTԧN+UNI{|XG삤u,ƚޏ1}hΕMJ*>.ͨ{BW/:54 a$wLg fp9SKd.ZtCL\Pxerl.HC"$E&އ/Rk_s)Dr1q4jtB,2z Bm>4Òڤ nK(\8Q>gtȄ~$ξrI^­(AwIm=dUVR)ȴPiDvh^UXDD:A.^ Y醯r0)]Z ρ<~qD1|trG,!I:Iëa5y%ac6N>j{̆?M\=,~L{V{XDw҅u@%Eu"A"I~ Y͉mR/*I1V疙*s ^ %gzʙ|i\Vւh ^S(@rJNDwLX,r rUhH9^EUZqO>Fpt-_o )R4$K$*-%>"h5Y6闇JpcIc |ېy!ޣ:Sw8M>aݞ;ݹ8 d]uӹu9F oIJ~ѡC߈U- &t8 }SRdcwӜA|6MBAxW`MȖ?3Y8D`jztLl8 6ql `ON[[^J, M?1Hr1.݄m7 ǢޝO蠻 lbYC$s%2ʂ(eA'C hxI@5$6O2;p']$Xh7|Dץ W =c@ < N0* <)*hެ?`(!<Ě}45+U L G BR)^ݕ)(fU}UgaQ#E!Th=9b'p]Ej!ҖVq!hZ  \47j|vw ~G4Da8@)pRxSY-yhm၇O91 R!iȉbz|Q-6ZҚdńu|S% I<ȊIkJuczV,b)".CnVP˫SYm#讓1^Now{q{Ԭi\ht8n['AMs>D&e.+SߧĈ9@&̸؊Zp^I/eݐoH+a32I$E+# %OxSJ)$ɜqާM%7.jλ=3C` tyj""FG}л 9YZ5'^A?ʁFdۅW+fiEjؼ86>h d'q| }6lKOSV. X˘g:A9Dω;Tuزg4]hU+Ho=ѵ ݌'q]%h*/N, 7sX*JqUHďU%6pf~0YBl)w6u3onQ7=\@jY}V[?_ 4+rzl3pց0TtgTτ<3+{@4e Th%X/8r Mc #_ jӾa51kѐ{a nv`sw\J[[6denTiRr49/7p@9 H3:LHy+$Hח.ZaT/= (uz}̗ceR&]C'}U QgT %+65V,[wE!qɉ]+ѡZm%cyƫo7אpU*dVmeo@~f8U9 X*L2[?N.7ݶG:8q,5%8{flTaR>BY<jDtK]2+; p%;ĺI^?'\ʺ7pM,sɺ/svi@U1eJ<>R8D8W"Sڕ%TLۦQ.&|xR\G#с@3> `#܇EGAPhT+Xqd=-]&+{X&xKBy_segaqBSdwFbDM#y)J5)maFP&[aL(w)?.@W*Jn`+o@Zن7v]쯾,RzHل*&cL4Q'^QZ{LZ"_=NufMj@Њԃ{?`WV!b(&:7Q5_sKg0("X} w,xifc^p˪[-j4NXS6`ee>GodSgܹR?(\9损W g^-{LW5;c6DED"U|'KӤn?j$ Fxn-bBMo+}Yx//EAs~sgWk*H#qZO+z{'|f3V-;7Cxgm0 s|ؓ!<ؠS⽡xWG1m8׬Xn(7.S*[=?KGؠh2&I󶮦D[dt })@#@9Y;P`-Lk# +Q4\پ &mn b E*hփPd&7o9`}(#˗6nm?[\8.Æݼ((̍(_ɒT7wrG' kiys;/As%Y_{1"e};HQ#d&?GC i73ˮ+(A>ݺEI-?3NaΞj.-BE$.S6kk'"8M}uZG/]遛ˤzjuL-kIiB>#ZLE{0ytC1[+рqQ50%o'(zkj$W$T.u4J,K #;13M Cx. lb{3ܔ&&|sS]=%|l+Ejq9j+RCݡnҊ5m?qjdI͙]{謁 rF2U= gm=1sUjyͦ5Gd[u&vƬ\zy2+BJ\mM8sN.[ RG.%[J)$z*qs$^6c{q'-?b\, da~/ݰ *ʾMv [n͟T~P:2}:OԆKX)5/e)> 60oǞXbV@MʲXbl2SLwgʒl9{4?/ <^N8a=LZLH<e\9 LwO%fғ ;\S]z2hU"l?%AJ_L@/nItc a72B{lAI"DR|BWUdakNi5n[c3;/XO$\Kw0,u%asgUh,,Z+n n9I?vڽll~5R_H[g*j"#!׍luNA͚m1+O/`8bg ;je ,gGh±&0-{9i o\͛_ #D>T0dM+b꓉)PU83D]tbn@n|-]$啺Oh$u.ͻ +PiŽwn_"IDC jhâ%<ŃG!CY8Dv82,T|Hl@朌X5ǻ19o(M%oZ܄=w>ZP)ؚ4]6g;)p@.=v fT8~N١TJ"ӽQ$R9 GRkCnǰzjOṏqC>{`00}+P7 41Ki5Ksm%:7;1Bg%@O15c 1,'[tAW="Yu-5{$~ԠDgnwozFx/شGH~p$7(,W4YbvLXPWBMbXm\=gRxw>nɰ"4漳>ћǸ Ͽl53 w&˷uvH#96($ٞ Q e`ln!fo_>aBql*uG0Ⱥ"`g1 a=%_y(t>O&>sOǵ۪dNF!KI?aD틍Ry%{tqޜ ش;x!pzhRUa}1R`BMuU(fY[޺Wfc:f!Z]o AO\ Y(ӚU#pM:{w %ZbjK~GI.R j^ sm 1Gل孟WUN="Q8 ,\6`g&+n,qvFX7 k4I8=M*0#1.RU͎MO/gv3UWώS0턏 zFM܋O"J95Gm#p^Bg#iͨ(l&Ă6Hh+!.}2P deD!4_)%_D'ksa`a#Jv?x=K]s\l޵Qb\c]lGa+wD!ʤbc0yٵQ#WElt!G %3d!q F Qi)۷^mJ_Oʒ=[y}YYk#߾OҾ.y7:QAT?Ȓ4D-+pp!,1Qf_ 0 } jQþ?86&&ϣkэQ6,79433'H(VY.Eυ-:"0KNd!3K*)ZFP/]ɚo*qZ-ʜOk@~^\5(E{5x8AäIGcH 8V ;V:4P^AN ȑ8?s~en<,Ӿz=BjAE:0&t|C(]H2s90lö@@!'~]*ZuF//BZBO?PrJf-kuoiŃJ϶n'v+T 1%`>1pfq#ot*`#bc2;Hld7c䋈Ύzyբʝ=. Xv'@qxV]÷'nAvЂZ>uJFFNa քD` $=`Ox\u98Fpu50d" }D_UaIX4]psd6u~]vKS0k|[(Xܰ5AyFJi%j U/Qc}!g}WmD1s[P=Bɏ7B /5G qwt !]6:LPPXQ'(bv#N᧪C_>L\ R *7+%mcvRJ_=-IV,eڰ,BeF7̪\c!ܛ[ zGNϸEmg2)ʵiqbͥʳVE'N Xn0 }W2GPx؟%P($KdI'e<wfgsɼ& _%^:lĵ/t E&mM]a³X2'*/KgrEK5A3C`<٣T-54H]1^P qC6 ;[Q 4bFu5/>\I:/(e 6U)tP(6w nlukºM{~ &MW BCS 2 ͘YD٬qӭpc $`A_e K; ಆT]gc:XŹVSG'~hWD6Ds~DZXD#$a1}ۺ nZ סs35tS/)hSJҒL*FNV:9>i_aoKT#u$X.w#B'^pm'LW #NXkT 5y"*fc-{bDhu!9f%fSF۹ 3*'IIfc`$~r̿d5 tҲ$bH_5ycQGsEk(7C!yIEp&-|lItPz*!NTۮn 3,N7$t,7iD&X\fdݒܸ =].( 'z~^)dCq)E0vf ՚%0TK~R6$j)~b>K=j`;<{#P8hJJ~N'^_˟?rE&KU1saÛ@~E"?M4$EN%E_|{+r4|xml&`4Ο"9M;hb0 ;%8t@sRa*[_4-NR0tJ@LG+զzr:ŋy^r3~k6t7ƫ[p ]?2]jqR6>M0R/1Mp̆\pVǩۮ_w#wlCabs6G<х@ .''r4 ':~$[b'pʣH~݁c$~)UB|˔jni U3AT=FF7{[Z|ֈ'}L>q=*,[~ Z9e}NPHZgDgԇ.+7d7[';lK#WTAOcX 8c4/(6|Ca7kA_+ FN0 ;ac }'M#y`Bo &,wq#%!*V,C4{ ?0ƪSM:yUr@S"uL 5~l/+]ߊAEN$B?Qv#w|c&: h5~! b*TefGEW]!͛ |b %Z[윈۶Jܐ` l&ree/IJ[aaJI{z*ހL2%*MC dh$3%Hqv37s{ATsR+#m,ڜJI)^} re5jQaP4yu0  5 R]n&*/[_!o"㳆KnT$R0۟Op\lEf5YUYfz,z;6W/KsquY d!+FImZ8{{uW]R5gqB, i *sBz9<H4V9f'nP ၫ&WA4jBvΐs݆AV)7Km{w௾@B;^ &U|Ui<ޕln^oCBm4Z#m?`@z_G W t-*h 9JFn QTHEy\?p#C!:p3lDVЫibs翹DHfHwH.h =ʳ۱)I,<K+sqN %azm},X[VaNj ɎK0Wz2&&0 jKeERdFlyNN>Kɳ@cXo*KEj0׭@4FS-xM$?Wn@jlQW0)ߔ[$-b2ũ*=@ !t^vjq6tu67cP?MM4ٖ˔aR[ܯ8㼊L{pD˨%asqt0lw&՛'WcR~1_mT,ҎxۇdX3'-Tkmý7T2]sdL nxeJ8쵿, }h_Q38fz,T lb< ᰥߤѯX@S5v:h!!aٯ+wGgr͂v/+]&Mz(C^V*_\̸C m@Z01hsHjciH(Y3Y,%@y{uγƒI-?ZXȢG95m"y7 ^̈\Zg!jUSEJ7:U}LK&y!K@YIVG,0nKDԽ2 ń{#Uu>@;4y~d7:'t9I[ Z hKQ%ʎwv5?vMm_LoAmbB2-F2ZN~k=6aK?1&OqpfUSmJ g[ܕvkʊW`D`^JSёi5MqKtO!G^O=BJZSO}>W#K-?q v3R #g=6?N&q9x UP&xy.%aUd 歲.ˑť#2<=?dkKX@w̦-\]X0p}v: %5XI4,5DZk!d"{5lNſ1pyM\ SHؓ YWp|ЬT?$rݎd O;KԴ{:TjQ`Ek@ڢKkq4cӁNvR ncf*vS)8E4q㋚!+7բ`}V!,9{tqɾQM_ED2GF|mòjdwҾ~moM|n U: 4Hƿm"iIk$@`9Xa[p/9~<3wF SBmu?6H?酛8]+37lC .<(8%t^rW)_=dSHZּ2T0j:x*w16n2Z1B[DbrׄޥNQ=@ѫR <6QJ \]I a"w\a*51BUPTj*'.oD@]ZhCb {`N[|$WܽdljFި$&Bv :jeXzn;]p%s<,Fqh-TSy9%Pמ>%qd-=6/!R"oOUA ͎(C;byJC!py4@K ;9l1E Ǎ{9q`&J-m1um8>#oM+BSKn嶚uT{@2^"\斡3?l>`u:L*7&!.iQՑ$r;y<żJ$Q#8ָoTM< 2-J73ȹU" |S떠1V"& n5E>C 3[]|dž|aVyFTRfe!fhD=@i"rfr3uiyԧoMfxe1`\)CzR}}W"_ߟQ ZfE ;?:!8rhXG}BLNŖOO:ya&3{ô})S1 oxo+]PRY~*:H:[}1XjzlEzQd8*HwZ 5e15&` .Ƹ}UY9,#͓+HS0H4|pзSlSh\똡yaE/9PҴv]lj^ZacUẄ訶z<=?'9Hi0.2Qؙ -GG[%>ys2|G1{œqZ$#-Vo%}-ԛ/|Dр`x F%yg0%G%J_޺WQ. k({uGI#YXk PF ʡ/f1g/}bC8|#X+XK_3vt"!>bN>V8pa49яIPV,x۰ Qؚ|~8zi"`)n>BFT7#Mgi ,_v\Y ؔkcI My@ݻ)6d 7 =YaI*hDtT%1Բ~CrZIʼ|IىKe9]RCo Ƕ*|EjC;p6E *.8I)C`ȋ3vI RаPɋO)VFd6~a'Cy%kVZ(O|}fy|-4Wv8cK9 Uܘdq/'%MdsF3 kҶ P!v4GE4r/0G`S+vW|čԷ<8++n긝0;1Z*#S7T!!`0N>$hm(gǙf6Wld¨7>,O ukY]@c.?`r> !7DbA8 o ~CfrT^T^jWj,Ҿ뮧{_aoǴ'Tfѯ]O} %m slbWhJ( fС׍s6=p}:/UnrP*rdƿZ믥Hy?u\\VHSW0Oȑbp~vgGc0?k'7>/U1;7<Վp%cWLnCq>$Uhj]&m-oLȏD%\V`?VƸerСU:P8w9|z+ǦBb}zSɁ3(6ײQ2mAm"g*E }AOb|BILohqKTF+ĀϑB1.=$R{e8aA#rp~=EXR((lD/L}pJy_|P3=U!BCY<jXJtg<;T#T0/ .[h }S: 8X; 3llN s'|efZۍSJ2f @p|N"w1km|6:ld. 閌JQq<6#cHqw>d޺K{Sf_{|\wIw \/ٷ _?QMЛѳet?[/X. ,/ vs;dZ]{ |0AL@DaϬ %Q9IPbwߤCQvu Ⱥý78t. q4t4f^Y#ǯ(-! 3ۏ/+s'T`XO "s(~`=tU⋺Bϲt iv$Ɛ}eB6t.KC&eX)A-`6cK(?PPJ3AlbL_- Y`mv7PZlq y2U>Ȏͬ!?SUD|)rsIٶPx.*OLҒ#)[3fz=\x.?Nq5Hh%ANRD}e:;}zo0ym`S>+9`Eb~)봎-,6F06\ 1-l>L8TN%|wu^[OcUp@ŧAf#̉㐲9GFe\I KbM>3[da䭄Yb Q.Z) B!n D_7${ iV{5&t-A/_$а=svI 3zȲG@Le⋾76B'u$dLQuA(Ag8Ұ`LO]AsrMKMŠu^=`u#"crSj7(jl?"^i(儌M[-BSF6 uǶm j@uiny %ȋ |oFTKfS @`Λqt㾔u&ƧlzL8L\GƘϨ Sv=@Ҿql^*]u׃~GyZκH>;2L]gq}QrHESFϐ /hɴBlMT=w' ( xik;9-ך cr5W\qlpp;M6!h曻GK쾩+զ>7^[tl,7-gw\ڥ:x+C =22זQTJ*.ӛGҥEocմ jFh]HQ`~|Ur^6_o 6i ε>Ja/Iw\ĵ5cryOK՟߮xb}=D5 $GÈLғ+ӅdÜ';_}W8h B.f}totoGDFg[om] |?iD*g@1V6VS궢ajEtʾ.agF[/ 2~4 $S`w51Y`fZ:QiaI`Wwhk%vhU!Ô؃d,V<>u§C{fï{r IXUIMDVq`EybAA_3M)j}pQ3U6UkIBL~rKE|<A(Pavӄ@_S`+*R/Gbp^8 8%5w&"A !u_zG'"YwN'ApGBht')=w%JWATQ wOƟ5&M ~kiPWokrb%oHUBC[R4+vD[ͳƶ۳<]E5xZIHP >zo| M 'YxD&͠>aivb\A0h5O1>ul|2o/cmXn `3Z:FtK5+ z{jiw{~(.&C} }"n 3 ?Mxa3^$PYК‰Cʝ.2~4Q*CY$V4WĎKG3c7Fo!$ԣ>k-*]tEkC/F"bv}.>ĖnߊhFYv\R\^5bPH ZD·{ 1x"$qVQvQc$_UX6RO>= Y\yo+#PFzhӮWZi^%rY'\ݎWb&E];8 xg~}2_!V66ppֲzdPKrj٘@ZM3„_"!U,P ?` B%x\[H\IHuSRj([r@i=b"jIėYJTy&GYlה>I!_e8oNL3,4ծ[A?i"^aQ HB=G*R?Bxy߁ءF*H00-Fr UA#xlNg Dzc2/niг-K/OFy!OͶKEaی-t.1 -1E 3+e 9ꆮ%Ja L@P\sE=z㍞1u‰vi,nRNtQ6~79k8AZPV$kHհ?{5N-V1hgLQ7ɔocqh;du5pK%,kSY`nϽ=[uEJ݅& M_O%ߧ֫ LGJsAI(#!e;0b:xu'^!Gdyu/^)qH/ܓoM.ɠUڵx~+I&ԅk U+~s@StL(H@Ke(O?`"W_׽9zz](Am.A%jC2gKi8q7~\W8MEޛEmd,n(,S svV o8`3;h7n&lhO 'uAO@sf/P7/3 &(ѶdtƁJ~aF:z@p!\\b&S54[ fH`p.f"b9'HFѽ "3&R_n9\+85wZoI"K-Hqパ6.{hիl06P')G)mSH&֛͊H|.4(޺!##w@O7ZR>uN1|a<%HGh+R؅\mLG\ 2UEb*L'mPʈTy C܋6<>QW?LI+7PL0.M9Gw3 G!#ۤ|>kv[Ȝ9>~s{_[aMBZaaP<.a I߂29TίiD8K[R(2'ڸ~6 C2NY, nuM&dFsA)yZ2k>};ōG -nҌsi]ZZu7iT8VՑ^̖t_oŪh{uP6f^+1*Wrж,4Yg8c;/ TTOn9}eLr҅/@C-3|[QMwx,jM.dl(}q4ZPNX=' /Uz}"*V/ 4ۑ$4o=\rBv=YƨLE=&&<\Բewq"Em: _@?4Xh .u}$w 1d yIP^)PQhIɔksRyu2O(e|vI O>^,Sg̝PL,GR {4, 7Id%X}+jB@XI&؀jq 0J4Cy_MP0DmhhCilQ(x͂ZO E QTt 6*ˑ#y"d_}ɴ/{oZj QSʯֹ|,f5o12r,xgWN 5dPco& :at c|U Lrd0L.@栢鮕7j+SkbrjW~YB ,W D(`v_#Yߨ3 +.s-GxJ_IvO^1j$cӖ/?G3zМp!'a^us2y5 )Z^ h[Y,:lOA$G+]>{mBCb`Ҵ ɖk~e5.rfϬc_,mXc\UO퉰 55 ¿;)Plju3uIJu[M9&0 h(`Wn ;l]bns RBS '|UJÐÈXŌ@|AFyn$[`rQʻZWs6:0ta^3nSu\F$1f㟔pxp ⌨Y{Mz<0Ŀ !aGx! +_/YDψI¥*-h|FdžUULU8֧WzWL TnB ʟa-[n54\Al8)2M'J$N.$8?DK7y#fsNK2Q΅.ػ$}qf,Fگe+k_5mB.ӯB{.7>ಶ:.xF}D, wR>ٗptWJۢ8W&gNP T57LL`?9Lf|(8ZB =$ Te<U^B9|qIǦoF71BjN|0O_$7,ө੽"rjOZyr^нk;dDQ: ~ `{nwO7>PM*5DC›O~Jn :w3-: JخIFa~J*p*K򍺶w$Ck\sЕ*?8vN?iTu PcCt[w:l"Hz>W>QD>u 09*n,xdNA.ؚ3Sžf%lu5MnVŘڎ)k?ûզ S@Ob *Guqp3^/?n5 vͣ=l1 &g6}0BrPOvuGs;i,=!_Pl:D ?q2J>Gi=VopU69: gq9 ,W]ǜ |{)s]h̤9<;BIq]24Pt~װ:{6nuHjKA]P9+WyZtN1FsF> K.r@ds&n?6OKww6Zem97Qӵ\r|q"F0lA d{'ҧnm H:VQS23 ש!=BFeAvIDH\eh$4$0YZh`f5L!RG36#~bA-m_Z@;됌_ X. $tv9S3+u.#/n-$Y!62a-{O-Y{p FJh4V5cIdP\!Aiމ5wwQ:!iꆥGM[tcgL; KmQ _h' 'ǒҮgjAD,A/m,9#sDJ1FLi[zŵC\*C MKHBSQ篤W85NS`8\y Qs8紕ɍWsHBBT*[~ǜe6i 'ʄjRB(Jq(6zhO~`s[epĽ4ؘzj+#@՝tBIC dtN>iW.tG 6 amR&!,&ͬ0m w9n* "WB%Nly)ꥱE r<Ѹ|om[AeUɳZlҜb쭃hfWa1;?Ry(|4covޏ.n[h.; q0Hvݣ<?dPMI2K̘Cq~2?/./zhbd[׃@Mf `7򧳈r+4X*#=VBmf\^B uTsbOPLaWIV3ء1'ޠk7;| #JAĞUl_mJKSdT1ߔMB;Ddkxy|e.Wyn?M[F׊jO-uK];Q4X59i˾sj,_B<8\C[$b3ʹm켱MCg(@J+y&jj\'cʠ8:/}B0YyKS“$ib3ñh( ͚zY>3j)9rr(չ5Nˆ,(o>wA}[ɂKَ#Ah94{He?'U@|^ikܙ<K Ytɂ!AMkΰ`hrb9Q[ _i$ C_le8⥣ m'Cʙ< V"#}2ۛ7hCMoEgOpG#2ZQF ^ƿ`8f6H=|x.T@TNL ^)o`S_kx Aq=t9>W,(]2<Ͼ߰JuN}\ZBVϱsJ!ecM, _4sh$7 ـS!+FOO f! ,7Gϯcv҄KӬ`&9 =W%^ƨHk0{ j3el l"'L1r/ Z Ч4.,j /YJILP{؎:jg$"\ntږ?UK^TxOXyyrH'?z:T2( D~8 O[Ƥ7*`%XK!Wfj4f+YX^1'.Da*LUk%F#F'q Frgwgn꼲SFV j׃z-q{W+̀+}wha<䶅Mj~%"ҥ&Ŭ~0F@0)q!~!I:BGN\p#!r]Y2ze>V"rZnkh:`J}"WsPtun;s_uL(Udk\cLZփхpDMFt]Raʚ\U9@^oK^8}fM-ڦt{ v#f.,{ۤ@H{= , pۊ)9U b,Ff|s c }Kԃ^3%4rGw9n/\[$g9W&9m=636漿cSo!V 'u~$q&өIT 0Nw{pP1N:ahnW#XEAl P(,/UwaErN()l gZ+۩w{go9w"#`tkSS1wtXw M,~,y ~ Xdb3@?CR^WGY:ߐ8R"5[wgx͵ 3֕ϊxGT`Cs`vM$$-P6=i8qmŊ¶'=N@ A.<=.8r|[ Me6'wL{Jw 1ba?knD |Hǘd cJfDF:N&W ǯѩ)+<ջVRo\HOf֝\BIk_= ^qnp"iFU inlQ"3ў\N6bٙF1uXm:H7m$:\_S+5T"e-kgGvb?;P/h9fR%EU2MCPKE3HI`wsm*{>:qM* וp]v #8MoR9M=zPT؆GՈ6%͑w{~gkP!TGH$W}kdj{gi[C_[vpjK91k(Kc:Y}Z>zfKzbj9KqU֕=dqQb?hNE t[9mXbArec*Kv&~̅/;.1umFdm 2WA_F0Ƴ܅aɶ ۭ2eB{jFvQ<ϴW Yl[Fo$cK}а~ f!v- uP"uJn ‘b/yJMȐGƿFVロQʹk I N@!a~ڱ,^FUFxuVoi^PslDzVCg0xD0_a\;oJ<7D:pC,ayؖBX B /FSЋvUe}7Tldtj#- I;oԚ5$T kW5 )*O9({3RQ gBjjNzih ]V칎nTu i&#+ J5S$x<& 5іȍe&μTke ){!#%8 }V}0 loˋ7z0hMN.{6KJ\uŸ:۠t읂\ NK%{|q豿[}k&|-i'I{W=g.bC҆3C'w؊rA~#/|Rܾ(ںudw >k]1U yϡ͂en-SM ^PlmT](AqVM<֛  *:m:/#7pgFԮSa0Q%ްF0N7)<5wC,v8<ދ;zopP7zB&oy.oFl ם k)zw s ks^#ڮUk:nΙ~_#e*DO{&1CdM^_"a޴^/׭UYÎ"("n+c@-z)TO.^2XvөRdE!}iNY}{ѥ__٤[-pӤ[f"fo̠y"-*C NE#*Dydd2OhO.ޑ ^+5ʚFX𱞃+s&ri>ݣ>C26t=gA-j:5Yۗ7)3?9X0 g|Q |=tq l/feE6џiVa+QqkVO?{)U>1P.ң߄5 AO ['>[N(e?Kܤ19 (5!#v֯@ߍ ?y+g OQ[i^#PÕ*:,@ GWp+g0ƪDnpƗ!pc`p_a[xeҰ6cLVɲb;:p:U%. O7F fp%Sq`B?o)|A߱=H#.L>u7ԣ1AGz<[R+^Pd(cU)EލBd[wi'5rSFr]2tPҬ+~;W2DG.{$&Jk ,YŜDԼӑcs᜶g )W:F6A9+h lƺ: GI!|Oi{֊G PU ,J觭T?1=k:z F\+sܦi;(ÄG e8ޗgnoFQ`kаLApүi~A@qnMTm (;&~יf':p 31PrX;NNsSTMWX8.rό|$#+찓&j*(kŽJ{ $0vh`` T׋,<,]O3/*kk~aC>!W-4 Az-G Ȫ‡-+=?L}o^$_ p&EwʚXEx9f811dj&|i }]b F_e;y3㨤Q "GPFmyzȧS)a~QŠvWmd}tTCP%Y3{% ڕk)ej#Ω}F~ BR,]g 6VQل+O2@,3E>xʰ^C@F[QUdR]'o5hA;t(&wB5/NJ4b[ 2,secp_4iTRPv|%}o_.J_M!q)_% Ȁ#:5 /Ra;GUGEdf zLJ̘v-m#NHzHSXbĕ/\ID RٵQ|ªB!FDzпkv/0hq#./BQĨ0{m5?~8m7ߡU}ၔR6ֵA!loa*0~K(zm ]!+޼ր)aOG:w6vR(t i(ҽ5-,ti=Tz*./Xt FyDz >T;|Nr ؁ۺMuwc=CFQ#J{n׼n!P3+qLjsF el6T5:cm <*9wxT>qD a( 5%6\ ɳH!Q؟,̇IYH,ոƯJZ%[9斎bDGCDHgXI x 6y,?|yƖac^,ܿ2i~4%rRl]C$O{qEBT98CO{TbS\E>ȧ5zfM>2X".k"2/mTUUBt8j*MUz%`u`Z%=>ږ7M!bqY|;ri3-|!%Y:(ӁYr)r#n]:#-kR]Jk d`8H|Ю|( Ԭiq g=FM0p/[FgSP8F0.t0ʢu%@&(gBswioN`OqwbKx}6yXUolͶ= i5_^|CIC ()sOݮ.є"pnzm'?rmKڸly! h%KW}G~2.-/G˂6zKɑ< tWBDϣ%$2g2J\m`ou5 l{sxIoHT :{Fn#ҥ+?sOȟqp.7 xFiyB F3T6I)&)\Zp=Ӯ\y`'$Kh愢+ƨqq?#۸2r:7MP#d #EdI1:h=d6y0ڤZ]RȋdeI&tU҅"1[pTw'BFr)?:gL?Kƒٕ8H@_pf}QeQDg5F;8B^F ng%shuC` _!udA}s <_AϺuG$aI^ >̑ŠaVLgFO-fqywKt7R2jȕe,\>2="j|r&Z=׀3BB#? 3~^`ՠ|{NݵD#aTs0MB SZۗTo$gPV uW<YI"{ԟTjB-WO <ޕA7jW-k TKWs;j y# 1؃x9`X2̺;5AذagE vfMB|bfX䅭 --t;zbE yD9GZX{`ف T?4'a^߰thKn"?VM-ԆJdqZ/:"ŜY꼕-c`Nd͆eB+U4s=r_Yd8?j"mWpԅG3ţVYcUq[Ik0| 4EdeWQGR%(ϮYP~?%-vWWU9R _<Bʉ3e6 )tlƲz){[jn'շHIU} C!Y zOb_33ln}=kPRXǢ!P趏1j*!R:لaU V"Hj]Id=`x+8JX,r;QW368Qsۥ>\ %SN,KaB >Ĥۙ5,-!•@ZlMĤ'0)+=i ҡ9Q\Ob8ݐ[B@]RCYY2 a ,B<&3NDAʎe7}yVGu.'(2fIrSjPJ؍u4vtTW <' +Hl3APo;lN!Y (9a^ IڔZ7> 9'FEW*_c}E9}f)>(?!KfwBݧŒGcϕ8׫s$:mKVb"iL |vbM Kw(7$)FJ_K['B~w{/ Zƻ~E{IPiJdFO%;3hwXK:P{| KgbFN{8lE ?BvW:C7Ӆ=+$g =2YBbk|WՒLYELP-PIytA4uF9{A 35Xe˻b8O}!3bT*=uL5-po)aEamZ*{hWO=ap fHvCpssM *b2q9Ҥy/G -iFt1Z)M2goMUhfDܦ;ޔb3 a9FWDž) KݴN?[7ˎPV ߹Z [ޒ\@A?rLج;V:fFwBzCog-Gl=@5[wbNA[~m{ AQөzc]JdŪỐ%Н vld'?<9e3ӈ=wi\lP6 a~8bR1zۊ ;buf.K.d˸ٰ,FJ0Q3c]ˌd拔BT<|ڟmMHqiyDt'gEO{,D'A3c;|KiŜ/hPLz{6-S4}Ϳ>)HnW0_q&qxSǘMb۠VZIO^GPqV# el۠^A9lzEykQ:o>ynŞ7ܲ ݏy `'9&WeҠV| 3 _C╣wM[(t쐽ye2܆NŶE1_LFRHzp6 m Mp~sH7;eMg@zC*O+A;S;Ьts1aY@-蒳33ܩ ]Kg@0_4NV+!TT+C!OFW Jk9E4ENr1P3ږq%0&Nڱ_2 &{otUVri8'Wz#lp3b[zX)7xeP:oYtSg$Oh:BˑɿnT:Ͽ2˭Zf8umq˗Ц2sM@{dy.T+[cYB&nx(O -dkkWnS0>&T⼻&&F,s_S|9'W`o q;gF =N43wz,m$ya,*NԺsh"w1g#|I·*Zn,0 bm j3_G][:e+ltzoG,pAAcgJֻr'pC v_y,9~bLÙc<6U/<=j5UsaBt>wuaXLo# nLŒHqu7-O=ĉ&2bHvw>#ڟ9}<F\GMt{|s?4}%$5x,Uy]/w31j8ܺSgbӄUd9 l"F-$kZ!,ud>'ןq"0NPԠ?ج*j?-^Mv$)-! 8eS 4xΊa+'~Eu| s2DHpI,E|OhҤ, L=}56P.nЃh? ?>|)ЅL`4ЬqDN=<=&lOwݏ =8LԨFimHԞ;|fǏ693}0>%Ss_ R3~][ Wx&6FCJZRj3tWkb؋VBIZ(e]y=NK֤B^OqYznnr=drR ye3B7 U=̓}NuZ!8bU8{v*&]#,;@_pd?^ptAB҇dE'I@"Qۧ/L~~!.<`GcI ?;gC;H5Aj|1"w+bl=tXB,%sXv^"+DIB,ג!Pk[b"Xr#jyw%APm 9"Aè{ +3!}lŹ3l (@1"vei6*_HU`ɘ8q7axdELX+_xWM>}SR64E-jOw=& S6yRJ1 qUSĂ>~C/Y5t'.S U~x:! Y6!/S(:@z÷UR*;"ϓ ]2jMVE].W-u46ᑘCre؆D; /[݈ 갂L9 p \R'nXf-)zjt7GyOT nPaH+*ƛp~Q:JWuR7{] M;HN3pWa7^AsG16E^[XI8D>DƦyğZ]dS:7@y>K8+'9f`^3#M1ĉ_U=TF/j<իJ%փZYؔ]~/1"?!J !v.@d"y9?~h\*éK4\-1A d1qj:Kw;TyD \+ZquS vĬ(jd5x28*gTN7H][- :/YžD\;Dz]z1 na_iŧaW"'g﬐ m&% ]*ܰ ٔ!LǬߩ !8lGqOvHzco^ϕjggzyY'I<"WPT/E;R9pćPu7:' u~|s['X3?2j֋2la.qudASp@1C ϧ[gPCܼxg2X8 __J D#8EWW-ڮ! iul=0htQNj[B 1ǭMݞg3KI8\)N a44Iw 5M{{u摑h̄mfA1.CL;o1g+I7J!œ0y;/%۸fO{.[PM_2rBvxʢ^apKAƘ"J۝-gzb=a /#}nj]%g]}kd˹3ow&+WZI%(uM?[Ji;c:e!⚛K/)q'~_lb܄h ^|c>soa?F !~@c4λu0*}#٤`!zS~eo_!UGNu^KߑuQ|y ; Xɯ"iH .\,In[_I Ob.5>9́Ȥpó\'",ܼ-8jBW\'[4Sv*b78@_ؒsJp'nqR3e9SEW./ 3Rjh]Fk*M0XJFيwx@G4-3h3YnFfLl~mWVp?ü E4;f3j?l͑wR)Xsa?N;5ٌ`$^J\2dJc|)nblGq-cF4S|S "j7]T:ؘ飓C Q4=>Ekɚqeם)PEWY؈\ű!}vWzU&Mz}\+u )*fʼn[;iO:c HWΎIbX:7g3袲Qr'+-ab!<t`+J !ob 1 ̥YC:PN~,2f2#{>&@ȩ2ɉ[)(]\S5ծEaU5t\̡'I_i{IoqhZ>AȕK( v_ysd?b.;"~w|T3h("\B@.5,HG)]QgUZ&ou4PZ6RϾb9NP&"xͫIon`t/;X{*,:R2q#Ih65 ڹf_JNmģ[R9Yn#.1NoeVSP偯آ[^Y)cTMk]i5:2j^pl /뙸*QuZd^xHX r mdFw@ vIa9N5(=5,81׃Z"5T 4J*RaC.N#dHgύ& QchĮhOJp VϏgڬ_lWu4A"Glʚ ؖIt? ą[fyVWF-[DKRPbnR"#8q=pG,<Ok].:27ћ#};!uO!&oѩq~'8JgYڨ ڛɉ1|YZ#Y1UX!@zdtV &w+BǖA4xJzm2S@(:xhF?Hp0LP<#UYgd ??x,%"]\[EH;d3Cl@.)Mr""1{yb? 􌓷%WEdF18?k(w86ݎz) u]> 1 0 @Pl0Xh!UcRr=d# l}+rjÄZQuvNƪiAGwZnxZ~>uӾgR%#a z:86q0w*d\j &9QM O';UJTeo[qyfV 202%OO.DOMMFsmZS?^(9uE9Q[YDlr>{a0E ۶q(}ME!/X'c$fP_yDue 3.~%C\FF8M?GQ{ܨvL| B:+߭cafۤh}/*RYX~<jw29}5tuY:gst4XNXEF9/@U,]&9QiRva<; d{*+zf+dą 3'P?GTsyr/נkY#$rUIMydqY:ڨj!3iYT: b =_Ŏ w^%:=56OXiVC,xMÏfj}`:M3K$2ubk6 ELvrԍ,ÖNV/cX9mc AYEĆ__F-* r $bE3~[ ?_|RfWdȟ(#$Z ¾ 8wOP!sA'5[,fGL 2ŲS8v_@d1! xrN戻PgߘP&?qT[j~M C - b4 I1d  yNzjR ͇En6kϱqh]>%K4C !\ MO@*?qU gih7H%W&oJ1A9pC=8_OdS;^HQSjq| 9G8JMC h&B$ G-n"^R&&KsX6iWgT5'nw˅;4HKօy".F,sP_' (r!>6]nXeVGpՔGPHq.oLM."&"}\5fR*CjXw1.xbee>s$&r< l%w8_ ^P-v:`^ -Qk`{*gIjU4ȎuG%]j| ~;؆ P4!"6LTR(vNu'+0!SQ?}oH#~Q]|Kdq7?[^Y1+8gIAWNӵK!d_I LuXwګhɖI3Gٿ=,i?_$1ZFu4  ^$EׯTgnjlQǢc"=XY !!yL>C(5ֿXR /}h0)KjC7D/Qsi ]h_k6Wv"VpބcaqL "s#8k}&c1M\wh&R΂Hx>3AeWѱa/ZėTukE󂔛X`tvVڳ/gp_e{Ki #fΉd$KY&c_x~D"?~Da'&a8ѹfMlvN'ΰ~/{({n3sd y\0ڗ^|kP؅*B wbY+` r4l܀t^uFOR"Aq;\K 9o8h1'b%qL-Jm?F]odǞb* x<|p*BM Pʟ=C/w/*p;It2ϤV4ؠϣ}R=="A{ZPʢiUes`OшUhatܼbn9(/2]amdX) *)p@3p~dyB:㆛Bu5r .`gߊ0gRV ®K$E.x]wUw #&>+,hȌcDy gBx;gi򯡒6@$Hg`U"p BNmU{iز^d,vS83 O4 g%Z|1t<.6^2ҡCUq-%<^-vBYmty[,ƱYUE AH$姿>zdCa8bF 4N$@>E]>9p+ɼG* p!_eUV"S|ZUԽqħwˏu)FGAgS  c4['owcm92KS_>C^>||6@.s&  X25`jw>}w:4H?Ϩj8Ȫ)‹*26*G^q~[ۢv0v;F-s#+!;:.{4mBbk)ZWݐ^‘Ҷl[tI7b(-<o3hbJ|9P\`mzWu δmzaPFƼ|Kג7FW=g !9$D'ik GP[RM:~%>aHdb>j/坞 ]N %l}eizNEo!&K@וQNs_ FrʡsT̠NPvkp߮gN7%,uQD&`ziũ lFPlPD 5._1]a+%~dɽ&t㏬DNVnʟ\;q@I/kYj * BIwb4]i{-wcXQ…Ck yZBW6_!\>ƛ^6rhl\HB&HK! %^q{EN#I fjSWlSt9uզ-b[HT_}/Hh{3\aヘ=0ʽeNl I,%2w/6yCѨGHu1 D2bKC%i y]b~9DtTI/fC4-aXOoo9NƼe?}$J07HF Co4-*R2n; Xa9t}V.-vhQ}D:.T{W>[㓩O8P:`dGg%I1 5ڎapFRL.7' H)SFx DeLc7%ċ%BdE7hu9SWr\>>:kDS@ 盇?22,_;߀6jOsu94ף1M*yA;F`~zYyMrGn5 {GgHuRh¾Vz0zFd>91N-rިbX;xή18>ϯe(4 V f:0X%R`s؄mٖ`I&3Ɵ*!#f[9"$Y'񫹇Bidy1GUmb<ܶX}\ vW}<"!DHյՖjG :"ydT甞1H""C{^_CDc8x"iV3Rӄ3FDY5e% 483IM;-V8=AM{=t8G ʌ'/@67zWX`7 av_l4 bBP\P8A}vق:r=_ D׵ ӆв$/-_+MHо}>rޡ(:j tbsL/Y3tg\rw"@:'P SYcHllF4:cn(‘->6>!oqpۆ)EQʲՇXUQ凙sV梦7hbzbCƦ3f98MLJp7~<ʢ[wbpޅ^8"[y^ i0ð$VKku䌃Zt^ (MAt?P ':( 3[pN"&=!q%<ϓgd!t35-6`7k2͌Kz%Qή;mG, 6c"an#o֧~c|tݫt~d lx\'%)y$?>KF<_\ZQgP'yǝ(X+D.F3/L9G< CKO\>a6Nbm|*:iUnwBMN]iBUT1Q"&fZqfKJ6鑴Sr?9liidWT <9YTZ#Oὧ׫2>"~N3KJBLQi!=ۜz7Ӏ@HcZҍ#Ery 0sd闚NRZJR$>}1~gE6x%KBǴYê8AFI pX#_B,Hhrnqsng1!-lVcXa4ZHkw? %FqYTfg4o*7(P T+B%aWxMQF=*c/|\+wxE90 yX1]j—MiNLEC,m% ;2@M~NQ&ʋ; o;f,ljgK/JqU_V7 /0cn{ԉJN7no6KV>EGti&*yB.,Hf+Tٻ̥ xG$۵}5&'CGL˶=@#Fvg̣ˇѽ%9 >mvx|6/ eak_i+Ʉ}5S6#M+J.Xg3yOl=j3BVPA?7'=}߄[i6vE?ni6긺Ð᠟| 14q_lb(b~woZi!s5?4'r+|u\?}~8QWj6uC5F 0Xfw~,{E0]JCD$@^%o fdu~*boG3lDX:Bf6rVn7cEPa[aW%[sFr WiQAiĠڅlgrMibTTCcc~~YS1NuN!zYZ{8`=OKĿ6{S# aae0zD%aUn܁1 gc0{:v腷q;{J$G _jHT?{&/w!trF>qNKpyB|eJgV&K{;ȒeKp^{"M&#/({ yj<.tq+΃>6ˮgoIF.A~"i<^BQr5b/ Q S697(xLi1/Z"227Bt05y uuS 9bU ӗ{ɩI㆑v,7$Mb zC,wWliДOdLW.8҄(L fmA<$u}0mx"Jm7TSVf̤y Jjfatn+EmuCFqpΤ+dˑ wЇ #D. g QEUlb?P=:0c\[2yϿrU =vaHo3m_y|07 d^OGQ>뻤,'OrAoݸt>̈́AB~8P#[;ҟ a@DX``}[͎3;n;VN!gu Kxz:V9)`f P xxX^⢒rIPr ,;u'km #2`޶^+5w}-LLz"V`Nh^Oc~b}?,\Ө,tʒMdnZg- KJP.|UƵb"x|0WY)زּ x P7TzA "-`*Q{;R~øI.iaEQzB=.}šhoiJ;aӛ #ñwsٮ}}Hۍ0—$l8M dtL K6:HgTLtԛi|G绋҇qVq>,O!X EDLp=V\}buݺMx|Ahyab5>ս8m\2*JjѹiCvzҧt蒺DT3GY$c$X'3dך%]OLbQ-QQz}=N=nqcaU"|>&%{Mn?7#5A6?덧)w=ؔ5/.鎚|)j*!қR]Y?kO.yrw5[HuEw/Yqˮ)‡7&/T}< g_BO A`CᏇ<@ AmCB?|Qؗh]W=x"Hp\BJ& z_bYO]-C?Ħ2C0 +s s+ڝ{qTt`BI!LN"=)Fq7?i&p0[~v-G khҁUy6N`=^ot|fߤo"8bjDZ쉓1("KZ2v0@g˖ѾM}ƴ;sbJ?<pzH;p P˪} YU5jZPv!Lv&g݇4 vu 99#8jW(XA1QN" eUb eu&i#A>Yq:]d=‡3[_=RNc]iO:Nt}a D !N[IZS`POhRw-4P/|P5dR<-dJHiDasZ ;k? =mS)-!uVL]GOh`h 8" {Ur ^mxxHij+D2}J? h`lG턩iuu1y"5`~Kh I3nbTbԯ;?ߔڱ@ %&ŴzM2@bĮjiB5V@5q4-~&ol0y5^:;xנ1+we %h]:r0w 9i`is'pbB =eS ;G >渿_(q~/>W7N|4NofK$7wai0if~\PpC{{ g@{ 9[J} Ƽ8ԡphF&.` y{24p{ at~'Ēŕ;,On6\УX[PG :mGÑ%.-bV}N6M:k v)W0Ӿ˧V־ȥjPmaW>ʘw1:W.R_q'p* jPsm(]39v5J&䈩 ,gCw}hcD$ra^F$.r?NFY6xB8t`"5 կn0&Vٕ\ ]M*`A{ :/,Ttj}izINViSRRgN!ZܔXwD6Q1#0;?>(4S#&"|>| _ɣ"s$p)V4ضxʜ`.-o~i'%ҔvQK[B]O #ofſ鑿ͮqcvsPqĖN:)lEP+{G^-**#$0m S `Y JA\F/pxZř1O;/P1s7I}ax.9X na8}@UFdeԘh-t$!`+4M/ nI]aIӛJikPT=%BGy{)CǍlY}B)iO$PvR켑6i2 5TJ)>hiOąx2@l͍W&}4Ä}{E>H+?ۮtQNC:(5Sb[TVAqZ·婬UYzgָ0zVZw,W_S{hb|VǧѺ~M,U9u)DqԂJ\Ј >@>zxh܊i#ĵmǹ  xh@~6+U1> uD[& +Wǿ bqnRg$$PUkK{x>iқ?Sq6vDKErt4% ,ˮnnTI>cw`#AH :`oTi N}pٯdUhO(3& }FTJ= i\V A6;0c H gCEsh#=E-6 dNVN6 >Z6ݹRp22QP'w`U[CSK=%Vr%^de^YD9uK^{ fܖ _hbzdà"2ϗhmUlc @ӪBZx 7#=%Go,8NjPH6 o8/|6|Oڿ lZWv&\ڙW'}ipD9i]LSaANz/ Vm.OQ]:> w쑾5b?D< BLıkjO3 SxQ$9ybU ;bWb.yq\{;җ$&8HUYҦw)" hu-ZqC<|df9EDVY!DEPX~8R-{R7jOŝ*b}G5jcmQڈ)w-RHW场)z(n|dW$yAb ҺD Qdee 1d'̈p$uH Kg7qI?U5-%RcZ1PO=\qUInʿ @P~6:r"ЂQ>63Mjp U*¦O$O'/[S 02i f>RJgۋGzTQ߲Tyz1lHV.)"}]`Ɋ̋AcoB$}]" ;yT9JXþ - ┮ 8^%{>d{:I Է2+axa x򆍝|^I;>PC>WtN`PAf7D8`Q&k꾔V';Tk]Bu( |M`ZRG֯Ĭ_un,t@~s~~5c.)vVmb8狩*vf>Mw}6*([.0w=PǮ-b;򍤁#CJDXM S΢:PTx5Ƃ+% MN.2[.vsȈ]%ϔʂKrpM)q}Lb"Q爆g]8n^ũAY*o.`wc{TwbY ވSTC[}=O.h`㸄wJ=5E."%Im' F6C"ȴPsmG cN,9fJ$ŰD,E]b6 %#PxBƺˇugކTuwU]|o 7+-kRȼ.K\ ࣤ ړ9=Q;Rl)mw-5vPtS~@"(G uPFC)z<Ӆ=R>E9Q6|Cy;Rr9A W8 N,]h]b"o:*Yv4=fȓh¬/%`[PlUsD ɧ<9in5x'A*JVp6ȅeu"2ƧWG_M>P-z\[P<ĠFB=\9^|r B9'MP㨦>'RRe{XF uۏP; #J7Y߀UWG3bj ):{/X_8Q); uh?Ws}S Jڒ ɈZ۾4Xg"{yY i&kb=iq[1HVC!L[A%z26&-ۋj-f_L&UL'Zx^RX}eƭ|8<m |V_n-KWL/LGњL5-\<+*ӹ/J*F(Ĭ;dw"^◆݋;_"G<ZytKo~)n7a߮JSYz|m-zKP9rjf*_aH&lȞ^*6_t9iV6S]xwv>u{LА[5/.bv I+.?vݷܷ>"$ VQ˗q\5U )^ n؊AbuShž-oZt 3YoeS?QHo&ۏWwoӧZ*\YosC3^M  tnl#vJ;gb\`:%g(9 }gĞR 9cۥ\ňC: ?6RJe:P,v-]U8XWIe7+6? L# )슡aOnE+It#ɒ-PU#{9ᛳM>[*KAg:);G&!#2ul<"/S gapPB` g$ C0LI6XdI|AYB8LM>iK4N$s@U4r󄧼MrSvǧ'Vlʭ }* !50VkCUGJT݈$_0\MםcU_[]ϕaB$DIHvwr:xVwqI";|(H3f.Db]FO+pl2 ElOA앁63(+{ ;T|PAËA.e7[k7M7j"͜C!(A:60as< ;[WR˜Z3q\l艓._9ཱ]ɮ.b&Gџ?$=+-(Y$b7ՕZN.Ĭ4bL\7Q0gh )_!<] G&αP̖F1iI3ڂBG@PK좵SXΈ/V}c##Q[pk.#d4_OVC + i(~ā {Ȕ͟u[ʉXVj!Ѭ~"!C-(aۀ{ 23&͟Sxifnx}ceߚ#WwhUd_AfZ՚+% <-)s,l.$/ҬR:ҽm"@24M3(lX= Cyn_ۊ\!(LAn~ Qp#_N[R^ݷ4/N_.M!%𥗍sF]H5]^ſQ(݂/c~ _I}uqSIe;9)*a_~Ebk?[~I^`&[^c\z-†\F'ڮ pb2~k⧷OEi/ .DܰE2vu]%P0:dA땯d@w\6mqUtPn'<ϽU R4 [4rCﻞ$('t6ez V,SUJ IٯRN^^Zѥ$Lح;9~;apӅ)vPvmMjw⧧YalW˕}>.tI %ɋHC3 oGO00SX0np Zj"hQ#c/.)"IsV8xYLfp,i8eDhXhG!NM֓Y8dyƊ:b^ps_GN;DNj LpEI2w.0iGҕbaPj ͩ2w) %XoDDwFzN| O,rG7𵧽rP. _j +֛ 7mH;Oeҝݚƫ~9jLo;kMJ#2YC*ݾ#p5.KlQ+==?T]=9|DZEsGYﶲt=_  ~Wkٵ$FghF1xrېJpU },W#ܶ Z1P{nV%0y,HKDZ~Z U@&/|l*4$<^ч,KOmRe'M$ /M,w}sȏ(Q7t'\*")1;SZFm|taKኞ>em"Ei_pƨ1]oW) <lNoZgY<̋R!ڴ6}aHqCNǡ0KAN3#xEUY?dnhPģNrc;jPfHRX`ã:( `պ/-1XDb DcKnV<vS4'ݕU/gUW%PwE%{ 坐@-CoCD0N&SBgϵSbJtqR$%RMG4ɰd檢m(IgeNU 0wi.a3 ͛IN08P HNyJ `⽯fG;۲N]9B1Go@<C%" B?{T 2`Π[l(3vQC:){X>-d|nFl$#_>8xˏ %M^?c4ˡ'b_̱ QFAg?ЙL|)H(㤷-cgb$a Z -BiPЩGȄQ>$ߋ KLwdOF1V[yKM!dI|%;Y3)q47% =SVhzi #*h5/Zp+FΪy^/N>RRcwCB_He!sDb*]vշC|Px₼wȍ.ч#4iOE#_#'36Ӿ"[Pf+-SǗr siWOHN aRS5_1O+7g>Rk㍩`=ԫq"`DBuZ VRto ԨE1W?"2B,Mb<Ğ'Gl@$myx).wӎ+) iI0xbR!er7yT807F:;  s!R6v(ܒlPؖE?u7S\;xb&ۡfr6{^KeN}ҨJÎg<<a=f ?Xn&^;$3_v^_ACumq9JT-{gzkiXx$x-5r1vmc:~J\e(/b9UZ]Ha[yTC4dt+>f۔<:ׂͰIBR@ǘp7n(1ǐJ2fѶ`<54ײ2F&ͩ 2",-";B(j/lcaq+k])Kq^`V?lWd-m e O:tgEw= WIp|l ~;Ft-Nwk Q4ADy8.Ԝ ArqFy ȫ=ywB#@ĪC1As@0 ±nW33h_% ޛNVyg#pлüiZ#.?9Ҍ<)j#n9U?G"<}gp4/3_S/]fq ['è a8ܒixI8#i;ǍuUa$UFKW{SPT^'(/'3w83WѣH_҄ϱ)q`#Œu'<DX9 0n[x`.8{Z g"˙ނ@$tilj/Zh4j5UC%@Vh.o⦩Uh1c|@&c*-jB]E|:xvSl]?5|Zh7FekOԸEcZFWD=2ID<~T7TdЍX|2JTɇԏj 07p#Rjᆽς,@LPHC;nD:뒏;Z["% Hpk;_-@ ُ*rqVBy۞Vp+c>^@IROxCT48 ii[ό`,ۍ;m*cy¡@lEP- gȵ\I3mKj┕"e`H'g)2  i\7S]) $ZO@;>~cA}ȝxVR bXPx(?t3j)L.h uiL(4FiM-JDA(%RC$qp-VڍdqI듳HHJYؿv>Ə9ƽwa%Y#6=*d*s]FLXSVjN!3](5b֜U.?pNq_BGp ZCD` ^,QM}3JZTKkݙ0~sR刴/ua| !{SgT*g;JV; aX_ }R\/9VPRy.@-V摓̧T 88';܂%3V9CRy6RR˒3/>oq7LxFV [ˑ_D@+{'w"5cZSډӽ*b Z^H?i|~Q+C 92R\5 6 [ J!j3d&;)|^%`-N )jt7R`}#Ѕ@*)OQ`pV=M=wy/j:NpRla.1P54OG:.q~ =QKXM`D{ZuY.pfJQZP')O"&xm9IgP qm:k:ć#e_EA$k|4zu{]dH'atɪ6`^4lef&7O[7y'}Q ֤^FE^]%4[L BdoXw^;B 'Z&عH5GzI'x][wŠ,:vw1.NcK:(14L4HJr4͜)VvD$ I:lL2! J#t0xjYgcF:P⡴cQ\kGz !p)l n=dLҔ=<}@(7|CM|BpPҫDk.o'>*cÑDѲUMܙ~wLυ&oMearD;qM %-ُru1ƆsX3/ tY?A]6{2.(z-?8;FަjDMW{xB׵c^f˄b㗷aԊE@oP:ubWޡvzdc0jΡ:K_ ]!٬ \9B䬨v Vj>Z {0<*ޯw"3a(8yzd)-LFd3RDԓm+ b&_dWc\-(X zcZ,"O!p -jP?iW]8{mPg!AB>s"R~dDI%hzLXe|yJqL}ڐ 2&79;ܘC 퉺a_^lUR6rGZA!b2,Y +;4MXHwld9io=0kڮ(l!\f+W_[S`Q8r*9F xଃ G3~6(i[}RFd;#%hݱxE:btڗ$KZ|-bztzx3ixUvT*l/<Ԭ&vXYr^!bUi},lj!mĮ@Ue xY s@z=Džպ'?$c~#2r5rT˒iOITmeA-q͵ !Hbn9p;|(+ʁ<.5RN90U: ]H2?WԝtTV KޙV͌SѺisH~PƓ=~&]r_=|4U?عi^ `ڋ{ MJnBQttxIWɹBx8 #b>eDy A DfUUoX8n2EŻ{6ozTW|;nu~dFAPc Z&kƘj%Ob %7ſceD5TVFɄVH(V ڍυy$I}Ȏl> naμfig.ufܰVo٥_\aOa)8O{"`7R 7֮хYJʶ#C\腗͉ADVaDJ7MHZL3)Y bg8Sh2|Axku 5qy݉ԋiEJhO>TV\y|Co $~ar[n]-&FI.TkU|O, N}3>j${| Jțr?ciufgg*nVmLFH]c B̵R 8.I^,rCx L\R2$e휇GsΟ/ uQE#¶aEvJg}bV]Iѝܾ&~U,|>:nFNYU#u[N\memC-;&^k]R(vcmItg=V[SyuCưܷ4[U4 4=*b 1rۯv -nl{s;ϺIցQ\l[ւNAi+CAʻ3cNX*Jm$e7dn ).8MycpmyR v4W%a2Jn,aE U.~u⛽ [eg]h?6ҥJv7⼔܄e-;9\Hf=P)K>3ww'g4Nr&c-R2m)%6$_x_Q(}8Y.-W&t) #ov %.W%x̻xTٞߚ'oY.8S]Q4RkvK2TnA\/5Թ3G=E֫{80t ՊBH-Ԭ,lGԬy*E/wA< V ebPP*rx~=eaӹ(?.-9C&#k bj9Ld0ИSJg2k&V-DMo/9t]0 쵮DC嗯КTE$/~N1ss2/w<鹿:O>m}§cl{ +C]?2$24@_j@0Jqw;M.˓D8&0ovشvp 9[ߧ'9>;Z3!LG.*Lo0>U>Ҏ7QBvZֲqN2CP4IQ:sp8. i+\Q|%^.l6uAO3PrѢ GW<':)YK==}Pם^ͮ_Dnt7s}A}Y:&  ?SN}!aG݌m̽$)l< l<`х}NO|u:TE)F7owvvj4$[q08x؊K[InVwJNuȆ^"mʄވZnyl7_ƨZvl8Oj~4O[?CO}.ԃg%>{U󠲕1.|7ZaQTNJdXLcIzn҃I_N4">7v"pi qԗ[ls`'A9v16ݔꌳTw/qoQ:D'ˑA$ {0fq&M- :чOU?#k!=SIX[1m/YTCаnWs&ոSZ${~M~lN =7yp͌it+1 9ĿM)gF5X:.IYo){A0f7GH!LDCw{e~UDq1[|rŽ NPh4ԓ+C'4usVQ?MܼQC*`,Jq+DMjALp +Zg"NƇճH)Pz&[Kma'S5(f:&kri<1$e4A.e₷*]C 2hF+z9z 33Db $8Z= %dDV 4~ Rܛ\ 3RP|.`G%r(.cr)~T`BAr1l$MU;'#K Zټ)x6=,~r ~]vvݠQ $]F> e"7m@XVH]>!7HD/x9etSw][^6LWƉ^b-ZCDX-_(m5} >!;в='CD87SٌRgE?np4t7a}Rz>*\Kň*.>Y)5Mlg@ASWn5Dpm y6o]0&fFj#ӗE<Ƥ]]ad 6'nЍs*O0˃$S ZyﰂIM2Tp_'Jq%@ J#yn6::@C]ͥƵM "tZʸyoo]g}ر.2ǫ+JPx3~na]= -0Pxmy>Jɝ^~JnoPak`BMoji.!럏PMDR`><Mp5i ȐOZ9BhӃPJQ;BtG1VYJGl-KZdU~\hO'*@Yy*P_Dyϩ.Yٷ!|a<_>_Bp8@%\ Rar@AEBW5b I g\EG4Kwqb}ߊ²$*gL-(Bgf*s߱0„ IjM877W_Zw%$/. mB+gia6q.":wKU"$[>+߽A/ aCZ̓($˚EyxX-WDp<ϓ+)''8D軆6d8_ R:W(9g?Tn:6]1coJͱmSrD(af8W,&O%~gNXs]v]qr-Y.B6t }#Cp,='x~ "y>GaaGdjTб@`iwKa<>1j˃{ ,d]YLAM b.d qEf(pkjmCej|s|QCΕ #= X o36z Ч` Y.DF:Rnŭ]̇~IĿ5Prd∁}\80yWowhy1œ+HEm>s%+Wma `@$=?}bAU 8z~pR(JU,:sXO8|:{E4,3"w"`2+bW[ؗn]F?8ZMŌr~ȔI&t8 ƽ' Q ~qXA.rMP1_Fd!`RiV?8$v 4 [RqWJOs{3zrZZOv}qB̧yJýQf0{!Y)JS_aL֢ "kD'jN($o׳v%E5AwW-)DQOS$-J̾8Qs A{PfB΅GFIYnjjfV]W(Hܲ,5G,6k}d]mS<ۂz"k՞&"9'3rsiW*@o#DEɛH *L}6բXK {. (U(۠JJE:}$ * sKҀFKE, !p̓t7UZ6<K{K91#}EV@()_q >3@w4tr+Ժ:O#X:c Jy"^ք3uLux&O2S]yl>:{n؟τ gޙ3\Ѻ`_mX"ae#ƴ>j]gI,4ώ 44+0 I5nunc~0n3NDʆq!飐p4"ۢ6&RqhpWb'X-u6qف%1ԤD]ݲΟ7H6pM@A$/_[5IoȘ9wTW 1Y͊U>g]qyX3n5HI95q3LP,:,dʣvxj6K|!XDdtx+oV+?tI#O35O!> @tܡzSLn>JCq-Ve LayFJ RdIG)!8eYM{ mJ IUhP8h)~cC-:WaNĝk=pxF˶!gi&&S~rq=Ȭ 7h?k 7 Pvnش}C)[Ue|SI~9g t@g!u*7$'!#M>"͉;WA:؛2)^&"{Ghç~1ȷI0>o8OZwջ-5-InN 4R叕gW-0}ofٰr.kd Gt mf]e+;6=GIm紱H5$~7F[ iOw)%D#󥲫*Q_H Z/g|/k(gVLmfiS/0.l U5-dykזE!pԁN o hTXg 7XK*n5fNTƠH7*_@HRV!5u$'ViB2:bIj#s hKPSF "6GAV`VVn* Fy7 C$8`䊆կuMZ%$LӨ ,{hT Ǻw<>bF?B%أhUWՒ&냞 JPwnA8ގ-݁ș(I3m -:~Vy &:QՓNW YFxa]%kg Z?yaUθS`o 9D+B'ᨢRof^;Nk+6ƀJ [ng'A l_E<" +7:H) ͥ6fR wQ6 !?{0>LM',JZo6I4 Fy H畔?%bLs$8q[KvL\ϕ)4c{:J%>ׂxP~N;UyR}}2z6.A#9D[d*&chѨ&vSW V6vdh"ز"x0Q$VS[M:ӶuU|7`+!H8sB5T5veNwϝPXS\0ױRA͠S&CvmL[ H#Ӥ镂(D4a->0BtCa );XȦ?xN0uI5F MP:Xe v4B{>%?qwɠԊ.I]zZc/){|hRR6eԪ.2z5/I3魱B)Z6#F|4:7je&* xJbT LB,>GdU)b_ `)$Bv kMeF lQH?i3ݢ63ԥ `GR\){=GrU}gIG G3M%DtUU-˕zԍB5`Uh  D5YmT&m`Ӂ &XH=ss/WKG0-9iMJ.+*l.CzXȷN4`TIO`MLL9zP6O`dFʾ5wmˑ&g2B@m`UB+Q,l?dto>x_DkI$hw+b_䑦™eQpº &~7܂n[~՝(IYuo]nh^L@/l&KU'ݡC>ggr1uq&W9QɹʍD\*ƣ:Or Vw78A3)_wo"M,ܲtq`-;nbXK-'j%L 75:%øcâ@wh]pvf{ć"۳lm@;`JBVv#dyYL+$yw FQ&l໾Jr`WCCE7}Lxͧ^+8# ]v,N\J~9;_ZR0-PUs_!$K>$,g4|MZ=NkXs2Y=,{Dz X,mغMϮ#ٗ n y31ˬor \`FIuZ}.|O%X DR}N A<*9Vau ۀ%@E"f^elØ"vzҡ<'kWt=֌mƇpǶO/=sS4g侂Χ,hQ;IWHmyfKCnpH*`_5T̲IUn7L׮dci,oyܐa qA&Z 1ܥ *.@?_@(N & ()jyg+M^y!{َ%((@%w~B%B[2zD:}jpڻ;tR8ѱ{ |if̬]#PCߧFuQwsBkƦSw*s[SQ`^!YL9DYPMqr }f4>4B_s' f#f3cWU-Fx#>\bvKKkkj/EY9u52Q직ׂْGTO?sf~i2fv:h6;,g RkMqث3" oJ p꫺RW#k `>j W̭y{ˈ:@LRz@U!8 A7Ad,6"al:*0#Mo})#Whڛ]H@e< 0UYaA~2P ODhe3JRb}ݷy%I#$X"&#r[xF8X8&e *2 Z)gu:HL6'kȪ9.x֩lU]z,nv$4T~k̜p߂ċ9P9>ߛ_fA[FfXyW3%*<gL)nlҭ$V&l+WBrS7>sہx+QOnI NnK,}ybxUP(CDCac"[̠B+XV%J.F{176|^tn5A|nG+8JEx!Q~>9#SߡJyQz A FXNjf篴3sIj۴ \XDo,U:V.-,0IWu;U|n ŝmܲ389k#cLH}RcpI^|:SPSE ДB|㕟d ɒ$u! ۰d@._nP ;[8VK޲H߀?UB4k.]Z&D>(y>PwӝUthn?%ʩGOD @M1"z4М~ﳐ^?U;?zxpw4v+cQ+2Iў-P1"sf#Ѣy5;งY^jŸ5wwUbif58i{ȘG52D>MRQ0ii\+U!UC^HK%+"w}`+1@HC$}P~$ X"&KUA]Hk!Lg i>FO}IT,&H[{%FlN#`Spēxz4m\}͵pGdh1&[=Wv]c_;Bb\hUCjsGfguN:ETG^l F1gшn"çNSD2Sz $6<>ezA +ŇسP1B~F%olFqē.`IJkLme#ѓ4<+)7t(<®ICլ%?J0 __V!;9ݛ'Ӡw-3s0B'SNa50fr|(Qc.4Jl'1ٷ _  UK[bf+?ƖxW5#Xa:kv$xߖd}*⛰1?G#0 &‰ଊ ;S2T.GؑI!1H9ty){̼&_Xڌ}Y5Ctz$<' oz ^4({e 'kUHm[,[wP%X"#?o (ql?y)a.-Ԙׯo^ kYUGӖr{})6V0鯬DKJT%;wL4z3K*Tv=(z'ѵ%\kS ƫ|c/2eHn^T|ϔXJ!q/mWH!9;hUdpe6^-|d4?}éߢ0&O):mb'GKqGԆAZʱ|{ү9 h(6 VK[d %_$Z՗فHϔuV|6 }M7*ۼz'꼄=#=:;L~S֋8Pjs!xJ4SZL4IQէ1 #}j/)9NjhzccǺ?,]Zu5hĈ$r8 /(J[~z&*8bMO)}嬙?#1bk-EAV GJ*h|q=pBMfҔ7]pS!UR+l]:NjH!R^3$(I$n6@&`D[3p{)|2jX*εػy+C*]}nWy]D 8gЁQz ؟Tx8vݱtшøn dUVS)JX7i7wjշoO k$ %u,oAsަ)):p3{PYNB_`-_!ġxZ@>/I9 /ER4>o7]Hq@yï;x+),KWޡ2hXVn ç*ͮKyIZm\x]pfNhRѝ wNz\Cm"{8kAb&z7sH+B13a! )^R™Rol`ZWL,2(! .V0$W=>7+ia| DOwv8|.xx,KK6L+_ԆOy EG}NFr=B. rt=uszQwŇcwqUPz#ńr(1`S"v[ Gq PD詟YJ0͸KT;MfrF=UL«Th  >̻ )dh豂> DRٗubmiTM2vZ߄$jWD3-OxG #иRh:h_YF[4M4I{t~Љ^Zh\JH9&k`@mKU0gb R7g 4vV8*rZDldz}(PswNs0[fm`}Kqs_#gHNZ@~"Ofo6V9_Z1Q@dw]=䲿m-H1bUšIt5X!IoCUݽ >'Gd^Wھk醗 ?cn& L8E$lWiHU>~2hͫ!+"oX~^Al%@$ 7uA@k6z7w-%q[48$~*%fc@zElxKP=4?an MOӣ GP(=QɅ#qcK'l<GH08|WWURǚ>hh7ے 0nl`Jե9i >?N&_:F5̊vf96Hm^]E5[)g5Ёw𥳐EG /+9 tMf`d]OmϊhoB{Da\cJ*Ap:&`AgfU8ng dr7UV=m8g yiHC-&,1G_%-zŻJ(61r4;!ƣ-m!;#BqX5 XV?Q,!tp%*Q%D/*vbL6zsm5 7f|AXs ƼpbqTpܙW:H2%?=. JFre&nt(u ԁ+g6rUy-0eb؊;aتP8A](7 (AY"7جx/Eyu"z.Ycvd&:0)JMxw3CH{HarHs3C:)5Zÿa5<g0:̎Zs}{VW}G.dYa3Ki4B(jb]vAgawH՛ëwK t\,(\c!? esjN2DGlHF$F7zg]$n-7̮mL 3Է@~1@4/Y)NMTT*ˤNee!Ѐ9nK4\Е$RMFbB?rK(@%9̱,;B:+YY:5|NuKPÜ&L vdGh| 2rƵM΁[ >M+Y$ܞCsWH쀭pAlZ<[TGx?U\4f_W&nF"2߉L3؊JXiɴwȦS-QUr/,JԸsiԇ~)cFBQke)jX9U'?F^8O b{!gt&-Y&/T Q׽TL]ގwb;LRʰX$ A6qvP"쯶hmP$s xG=9"ӋL?yq?ĻX?qQ6Tfe e7~!/5%~:GHs{m=ы*ZZ' ameʰg}0\_-Q)[z3e/] io/>pd*>9"+Z 㓶RJ" 2ַzY8(ϵ=ӂ$zG6,b>ZZxN 5bcP?U Ji2RO8A K4/9a %Bx7vW3ҳ?)YIwnIsqD"ykDЈH=sѴAL8y,}M÷u|WkaTx"'t89oĢjo1aȰPǥbWb&Az?e/,4,pkDDV~yDh;>mQ=2s)[vkkKWMTi5<l//@1Ml{-˖7޲9+w""?z ?"=MQlaN%r m{D9FMiQJx;{"~@sx-3%f%fgѭW<`EyeeP^oE ;֔v" bwVRƥA6Q8Ca~3.7_ byLϏF?e#ϮY%[ L8T#ªG݆}S$\gʾ]4I'˓ !BRhD 3g~QJ,x\Pz5;+D.[$uFU[JIaZ5iXE/X ȮSRú:~,UGkw$dW)?%]uS" oyXWs|ENX ?IOyh0Kp`.%f=NPs_1eڞZKr #K-#1Fw6nhȑ3B kz0#%00O mg4KQ\e|yP{uTK+ 7ՓӍ]N$;?a008PJ4ȿH*0t%J! 91YL`ځ';*6ڿrߜ7ofr1dȉD%I/UQ0%pqi hl;MۅAk}cШP2$=+h\n<)whLkA b7V ;ݻlTj$ 0f@q#/f5{wvY戨V~us}|/4mb0"d3"AB8y7|a@|̔,4(kq ŵnH OPoYHN"*v՝1=7W+ 791򑎸K!>L^5hK6ML]?-5ZDpLI3zN-;ệSt8_oV]F*µڊ~iF=9OGKfa= խa δq,=7(DN=ԝ/0IL Qgl!eld{|k'k*N+%l^ILyP2Wd\Ag?(BVėR,n~mxeBInt!O<{3?GVʔuZY껁w!NK 8㴐hٝXCс7&ta. I+jW} 6qj˱?ʳ>Hm.HTWbKSB#[>`C4VS9 huU\Dy[T{'6oևA+T- n@0 $ЍZ8=e:aSuc[j_Nm1y 4OhA'mXNZ%JP7_].MLnCXL n\C=f}fH[T> ͙ڨ( QϊJt`g x3h@BqY8 H1L8AIihDiW/E,@!;o;"*UNLJ#a#'B?J#0 <;0WV[Q>wTĽ_JNnúK4BIW3OCb1Z)u=Y]p\ #: ]$(1| cIHVlی+v Zennmǹ 7uaNP0E$#$kjC_h.aҤ,k-'8E,YiL2>/d"]}(B+Z@T7Xn#y1DZSK?wԕ$$eF̂s*|1u!" }CFW/ٱR&驚O1^2 àz& e` dҡAcˉ2n~WKtnIj8;s a^53]GnJ]LMeRLFOtÞDh=f~z6AYD!l %+؉\]L30X.[Ji~Dd%' o}9o:_^<ϭFD'tM=DdVXXKJx:zs ܰ۔ 3qijԘG*+H$%ćy? ;hR'zcTbzL}L2ه?e\E1z_%O0$K<'=Zi{O_kž 0; Ʒ}[agIh{ % anPaxxmU/piVr |/h[;X,_kź*q}FJv94,툊HȭQ6]ۙ:O®{2^Xm%J+T(߲Ҡ ]ZrSQ: NGؙ('hSaR5bXD ;Y.r忨JrCK7̟#&ު^d'Fa&\טM;6y)QPM^mK8;_:#"kej;<ڹsLt m=WY#QrsRp7Q+67 }UaQiBa40{Ņ'NJqO"`t0Q* }ͮŶ[aY Hwl0ž uPq762F\Tt_lxkU$h7{"2@>C|q,L(*#1{ؼ#-7t1(f H\73K_- '?U]ȃI^`_^[홑輳=YmUF"s}1ByimU?L͏}ٵ|P1qGX1CTߔ(~߈?:炙d%`wBDaSNhV9T.yɵV^',?xP(])+ Ox(sH_y.`0rf}9= 4%Iqs`grlLOs[hb_Cϟ"dCd6=̆7~g,)Cp҇eo틥 W5ek/Z^)9mo"^k\h`O_J8 ZE*d+n-S,牰bη4Ze[z0n.L€7܈94Tau(?r[.fFfW~oֹ y9ZW=BJnWz-3pj|Įҁ iMaUHI| Kòl(9*R^ ͆tD+JM.\DO@_-\Zz `X J)W ?T_slj##ADSHP>&Bgg[FƒCki2OiT%,)6/r:dS]yÙt yF4iȔ(O#|ő[mi]0^eK*\ aŤƊjGH  \0.<[Нԅzl՗Ci;*Ji0͖ *q[A) 1H-h75[#L@lr{߃?_YFog SLUkAf#t(.qDYu_ N@8wmf\_-Xp0-aI)2W6wZIS^TT`2;3~1vV?1^YP}INM; ,0hTې[mwMZO#n:qmY:Pyh"$NRP̏JOky\wGʨ jF"/ԫu)Q?-+} į V*=q}G>Ӵ\;6*AM6FڸKfnOF) lA!Q =Ke֩qH.֛tƷ_7YEݻHށ^&0WrL}\BSRcK=jIUCp Ύ%0'8Kr5>9)D1_9n83BZ/n? ʓ^ɒ*Gr]4X⹋w \K룧cJFggަmT_M$eYS0m⍲L?XG^;jj=0 ɒLkƓvG Cչ `{1>: \ pU4Q"$ 8ެD`Y&51{ 2[s-^{߱LUHm4CYJ*H]V@< Gya% đnasH2{;\Tt!@wx h%Fc)-yWp%ۑє[GBj>E(0.,z~(k;_E0):>w|x/矯;qkGRj諁(k/Ye GͭFv|(jj܁ũb JVߊx\U &S27︄w9C;pXULb_Px:%cp/Pxs =K ],?r!4CGLӝʫ&ZkMWS}z!L(78#5 b@"lbN@+d~/LZBt~u0C.;1J9e3]Lԣű}=МX@݅M!31?4KI~:t~ iM >e+F f 7PFR1sM8_upb6 i|Xxrp%οnh3 q! UTS%4bl?̉Dk TXzˤ\ň Rڱlf0,s{i:XK𶼝eqT}9@QAJp&` a}53#pI|sCl%[ VFroQ)~ ^hU p^T{Zi!WU}lJsݙGL7m].Zi6@`7:|l"'6@ޡ >Qb̍$؜ؿzېiyybT)LjTb9trw`2~-{C#Ms0D ð}$ p #VS;%MQ3ƺ B0Sׁ֤b;^JƑ1vbLZxv;ekFIo=ׯrjMhaVι&1OO0.$"HE}f[^Q[#A6Yͺf.hT jqQ!K|D4}(B-嵆@TW*DMZ8#,mj|%TJz)9Kr@!͔8δnM!l\^~lSv}Y˟@hS؈@I_PIǙ'.scdrSBa{x ;PcMF=g^|Ex0Va:RILsPߝzfSk?M{X =/ܔ_ ꖁŅV7vSI闼YJE4]EYnǶvpVvtU=A} 2g?HK屉;'MR?  Ȉʊ'xB*+zL?XK (_tOS4֧23 },>$I'lCh0ZĆi|} G"Ḱ)[McXUŐy+"`_ ,H&3= ^^ NɃ Œ͏ͣy>kl$#?CP-O2jPb^ILwZ! {Cod!FAm hB829-H`,[3oMRT V͘ZeuņӲ QP\L=jz/a~dWouĭGkп=#2 GR%zD*=mc[ (?˾0hhG+%鶦'^Kĝ™0=Rzw=FR6gT8Sې5 T w d^@-(1AIev+3Yz0GVne>Q{mI lz?. B/@+qԚ\>YW*?eBl?^3sfCpYL@R `r2Mɾza?0);(0R9sZc|:?V9CCC|[㜩uM۠ɞ0aKy8z' dH,>*'9qm's['92w[˟D*a,'}©7ifPXbY Z.29Z 4෮Y'-<_y+5Dx:7>&rl24z?~.-_%-cX`kPdHuXdOhM[~O- 'o+LSP$O_ߏɥF\v-1M<{kk"uN-pQ23ͨkH6#zƢ?9O[4֫.g%yAO #>;q{w/5x74҈; z3۾EUe>"dcXZjU&_o_)! <˦s%>r q-o1zC^Sl-DvLW & k OϬ>Y,OXNx<k0QA[ErjLs DW=.@jmY>7t-nr?x2,9-^3l1CTNٕ&.rSj1|t,5]55_W %?yu= SGlL/WsWhu3)ic㖶l\1zv}v)Q ẛ 鋷cI`?F^u+A3R!kFMDluR%;7 Pc(=} m=_%f:@֟ @zLypC7#hz㳰L˶wv 7v:z㷱P)<%ۇ*fg3-J! %2Y%͹HNBAӪHD[Jz;=>$jߘպ)shƲ/.7~!9:7LtW YTG5[`<͢ N A+:C\ e_|d i+*0Ƈ bVh* SWaTm%po*"hI+ ac.Б!{P~IlDuLJ]rފV= , Duj>ϼGR;1 ,%U !weH6!^ }:Lb S1X$\9{X vdmC%FȦCXaT)|/Z|( ._ (o-:etUTۃE1n if^k蔰FB0' 딱`O}wH1Pj:r႑G;<_z!SYmjf>TSGn{/g) '>:;S[$9]*F>oШ{ KhP#%e:fNwV'Yp#fGZq7sҔ;2_"XUd kYU?'*&`Z;]FA%' J G/9Xb3zM+J`]9su[LW*ձ{tR㸖i#F]BMLЉ3/ˀ_^ǐ^^.Cl@Xx Qk#s9ӛ.~Ųh4i͛$y'arc8p-+7Pϙ"ԇ]&P1X#Mrp*982!@7ʤm1Cnd5loT`u5mihz3efF e7Ud?/iK"Xj2h/YIggh$0lߢE:bb*XeHhPƜ[Ek3,f5Q( kctux@xm.swq2 ={jK8CC+vЉZ}C"د6:-rBՎMN6?7Un_7(?a*ܦ XJqWiw ”ƏMvul\ FO5:Fh ޾1݀`d]vaZЂw9dx,G1kfjJ#*{m74&.Y'yfLyfC2h_OhK̨4LӂG MaNP k:5X]#5$P%y4ܻ';Rn`~ T̔/n嚺c3|y#t5? W x bh*)N\bL$y aK1N(r,?$WLb!,X mV?i=tl@s%l6}M6̹x `Cl\)h:І`8?gm"ozw<MN#fAa߅SFɭ-o>[ׯ%:Qκln`|hGÇA~e fy)vPђBn+ h (/yk*NԾq>^~Tq}6Hw٣ҵDW_;ٴA q-6-]qDWӉŴr(ro} 8 W܌[J}Ҧvy7^nY }/K9d1nK/LvowC@P `(-dC` Kisrs'`غc?8Pw3?&dpX__t ?-MUL|U[;.nMR,^JPPd5X.<)D$Aտ['_AÞIN7p֝?DaGQaOt)Q%7vѓIpj@t\4Slzդ5pt߿ 9קuHسk96)-|N} >Jts+P &ߋбX=:tۆkzNθGHgD```rAIRz@?%3vGnUn6f1+,wj_yYU[^|>TeM=ǘCH?3YZUt.<,2,rrEdt,,3 L4A 2_*Szof[0~[3f9Br21|y ʽ!tk)u86MXjin|$o4~/$Tmr[&KVwoɨoX U@T1u`e$Iy_Coi^7a8Hqlr,-g@V_a)xbh vӤ{~1z8b ?SfY(p?<餪Ub2C$u]ȃ5^0#Mv ^8&N_ ڐvb >sw&p[8 ύMA6Tih GJY|qXy(W{xfL}OtɃ"(2NrbvRDs*yuz 2*s`,|j匧\qhak?iȎrbfj0X)a2eh*_7dZe`.Si'" /zeR CfI+t:oeOHԩ?|.\yzzh(~NYսPCM^a !8CZrYh5^ RxZ֋ϕdbRሶ/ T{_Hj}'hj GLzFSiy WfmOMCieF] =r$.K(* RlFkc5!ka6E똞@̡GI: 5|AԑvUS4.W 2Zb7[xnƘ5j:|f}?g%:FLa1LED##iࣉNo $Fqd,zƺʀ;׷\4 f㤞 '̶;_,Vt]w 2'E;GeĬ\ΓVȡׁ-!ye%n .M "FbD'Za OXAsR;otީX$@WہtS`@\]&p %YNl`3|yGeovQI#`,/#Ey9ܻت P&ae Yc 0ͯ%Ų_ _YGo .w! Ox\8{"#ҰgsSmb_ k0ͣM` y5H3(2 =rXA grk1G7~c!4NDXjFxC@ kOIX D!4ڝ= fMϣCe9ΑTmv[)UZOn*Mg3L&!iC5XZ&{MKgGWG6)XzA2%ti·S@ BB%)M_M&K Fv+>^>u!vCѪ )D MRl~_b9aIH4DVo;Lu%^64+0Yr "@erp.M`caj戟ղ«gB.tVlwqЙs 4$<ɟNTgRy60Pڕ[y3|ҫm5YW܋5DWj7 " rmcY*Y(/M,i\sLD5Ic ٝ룕cPhPF\֙(7sg.crX Ԁ `b fNTbCItふ{_S!2Hf"#:R2OV;޿@qy O`3NP3ő#A>V}ya-W]f'4PfE I?2IrZ3.[9mԠ~,eo*Ut Cgcefb,)`/˦׉'`D`vŤL8 I״E^CZp?U5Ѽ4uQfZ9SիE:Y#fBIl۠3nxPذ&p-󮾿nL`kXd8?n{7ގC@2QDSBql^(htcnJG&6ފmcdb7$Ċjq% 1^DXQ6~!vssS)*~ .q,~Ӹ!+RIyݯ^lcbkxn 1q9"pU|];T6]4Dԅaz#hWTUhenHW%I$^ؔ%ypb/r  )A$~yj0g؅d6dlaCn](~d0ЉbrD @f*mc.ٙ6سMJ޷2`_eMxGG7eP0"h//tG~9. ZiE1Dm RA~)\̽;ꋢ'Uěa7?b'ZQA;a2K 1PKf+@}i1.K1eރzVN۝EZ:i%"k^'lb*Y7{<cŬ:PL (4s KJO,s$^%Yc&(۝_M#ki!"־”9>B Vgv|>Ǹ<3UB:4}?7g Z$\d i}fQ:IR=˪. ΢"x~n5Vxp9 ʠ=4cߖI19֙)yʭv>cE9|:Z|dgyazxaO]!m;N N+32̡TBd/AF,SY&k)BRgcmGtBwW:RԆW˶\Q(&WP)99rƒ&},1w'8IO4HBYXK5z*&YPӵ=Y \u8i3 ==cg`e,yFH#@s> F !s\&by(S4^n4Cwl Vx;6L_ }#A*)OvG6e)e1;~A&fqY/nƪeDekvo0t}^ȩT|>vqV?l;ޞ-EK_ 6mDn(U vXvSyՃs㴏ZDHw.Hs11l'<3Ng}_4,QZVNiV"%NCo%>boI92Io/.lsvP, LYe=фME_2;TuHOT(9HJ4-1WivB:D}"'a;z՘Xԉ^#|-vH}}W<|.CKCv)^\|}m82&7+E9=t 5u*J堎 hB >[l7d&p {% #vBrT]J?FmN\A5 ԢEߧ~~i 슪ݓ D2Gؼn40ʈl!5h#pADyLQ.ZNSI 5.`NU䁋7s1J${=a{ZLhLWqm+o Z2ɸMCԚ#J Qʺ]S|.Mxp9ckޖyp83V׋]^nCOBV>$.*=.9Jϒ.$ h+tcV S?q$ Ot*h;dX dfZH~ |CNƎv-k}nYg_WΈMY?6̱m~Lx5گ}"tbXDZ"Nc^h_ sowZeXF`ۤ>2>h:jݥ)vױ}죓~У.lMcF4}L` klޑp7~x`Q AoGPҴMGdE)4", 'bY2jovFO>y?zDa筍l`@*5Y¸c%FTvDKnNkҸhHy'ٝ3z]rB ܧ^`$6Cw=7Lff2e׎E klTBh1M:˭7(ⰳϿ&,2h:FnSeX$r tc*O̳ qJ$>0p|DQp,)}Ǿγh#ޤƿEiZzwP ) >tFIkjҗo|hFֶ_Y$OS!Wֶg2?_@* ۲&pK{XFmiTubm)IM7Ǯ $aQN4Hiyw88-kںq,.D ۰;ٟ\`J2mifr }wvaԂ?.p$KsߺMqM6o4ca BB b ට\nbFsQosIVZs,F}.I嘍gc' X`*4nSiTOz~dssW$zg܏ C#+xЬJHͿfίj)ʜ-ƦЯ+S`݀xZr[ <u`蠰Ie$?b3f΄%e PZ)aRhjnG/Bh оV@D"ħlQUOFHbDS 丐iQME3Jq7x5RmL-?Vi1H(Ԡ^lu~,s@^ $jo)/hX/53ۅZc4s½&olk8Mˈ; 8bL7}y˲"mSpJo0-t9 Ll,19l;(2iiE[{_bl=-zǁ e^6: pz"1Xoi0.Xp).XbnSNDoZâ^Lj;j-7J/1j/ΎaHzRjw9$MS)e5İ^ .u⏵IDZ4-&d/g @ \qP 0>xO&۾ "цė2vd/(`}9(0wqZOp!HZamp2G$0bepxoB k.-#(Hh]Mi e@n#_z>wFlO%#]UL !{jɕ.ố*ۿ*m,q5[NemNNh{ dp;2~ӥ԰Uwed acvDT2>cB2ҷO{K\=6㡯LKm\0WL|䦮֦vog\8`f.і ΣZh8# }p#C']OzK[x81 ]ۼH[cJ9;mi'Uѝ~?-j%Si$Ynsmb\KfAn W&X'"Wuqk8#5GnCj)AjT Rc^w"R}AuS]%I^E7=sN%W/)˗լgRvZ:Uq0W '<&10>lKېPFL`W¨TK4,SdQ*|+8)Y̥Cxnà"k3Lq_ed%010Oi|駛Yna&[+ th -2f9ݳAdgE%=dBd8ʥMP` +JdfW{>NcB 5~q^()TT*h +͐hOɚ 5 p`jac'=lI'@o,vf~E7Sƕc j;gJqJp7D4Gt̃wolRP7GɂLof~<81F`R⧛/o N8Nk}yN?6~ӫ=kKaR]E/?a_1l[0hlmy4pjQd/,/Fߩ;I)~ $J:Aֽx3-{ Ԟwjg/~Yx[EI#ʘH3}c^뚞0Dkd'[@ΔT!p&iX=;8}[`r@I5`7V:Sᦶ6q 63M3$DOgpW#wU)dGzT NNN-FHejdA_s*Y [?Ddy<;ǒ<$&2+*i3=d%ֈG|0ഢj#wwk ̄VN^ntXc>-N^5KΌ(~g6T6vezl5뺧($ $BITpхfiþD Jݠƫdu;c"mg.1p?-8WtyV6W$V7tVc7I:gZTlg~,/9sf+yvL*N*A*\ >]:*TGwӤ%osVͲ|,EضG8rzsQ\㎀|ݫd[ZPTB<iW j'qf-#dZԽI'0)iK KL*T=ЯLnp#HOa_=vҌbx ܯFϳʫzO=;IRGrn A/`/ Tfl7쥹Ůrnl(a OC0һIX ?}ކU^}HeKY]i[/cׂC¿q4]ٚv%fߡIk|,({~8Ty4L H8GR'R )#] B1Z{I"f"^rEwu? \F]tO5ԯ RQ^)x?]+`f2(\!Ji93$V]a r i5:b5ԡ1XT$]ئe!wXS_G: B"0 WG!OW[So[/l?eLzKh ,٬ʼVU"5!c$I>B*{p{if_  d[Xъpɒ _i7]s|􇈓x锐9O 7):p>3ݦV'$1̺sY9*#1]ck<h(98 E y?Wۄ 0M H鋶90aMT^FX{Gp# @N9Q2SI".a+=g 9… kEBk?%f)Ow+G>50RzP!HwKacYYf !}%IcM+mC2㗬*gfEO_^e5ć@u \gO`̖rhr@%Nԡ5= sIt;_ wοEڿSxڴ?XGt.*Z'Zt' Ten[^i <=VTΝ&DpN[_ XTdHiݩo6iUÄu{_ qi°f.D`И2(bܤr `.0'*KN̕9h=ĺuR"xP6hf4^W,H3Z { OxvIOq\_(nj2r"Xq)̫) yU+׮Cb5Afزi  Oj8{YM)S**;UC=ٚiW}Nxs" af(Xg|J/{I~4Kf/ڀR@N?qbG BXm ig1^_ 彲?srKXmaٰ醣MUhQUk1:X7sҽ݋u dF#+ZWj#RHJaiz׽9I>mEuM vt6V-4Қ2a'>?2eu) &HSGlMNBy+QʍY,NN{j+eDp=`UIzbӅ7*`i1b1aIu/xvb`$wsׇo|iK#mWM~&_7z%6r6ܣ_W咯&·G.1$G!V!id$N=FoK,9(8l\4~%mmbi>BS@Os$LU'Q h{%7V{x {D[aۦCঃ1@9u=k~1(^ꌉ&r7T7$pd?:م) @i,چZ ^^6O -Ԕ?8@Y [C /-0ut3}:u K='o/`˴Qi\M }" " .RAql9K8 6pEaR.tTsːxp،w`(v4*za(XeUT Ĥ! ^$Ju#6j5H_ǯBWU㽩:pjC-8H`y LOHc[l)NJ,z8#h^hKStAL{EY#27)By@]ݚqۜY9i%rYO{lp?:L2,>pjkyK}hab-Vno3jh5Mv]U@FGd/=$V4v\Bv=ّZ}8E6n+2[Qk"u{ժz6oV] p1ZvA1-yz[&6T9N$dNX@<$݊~Vt#Bfc%xioKO k($~=~-l? -7w̉4hgg{+ts~5!kTyz3Rq!N,g/ViǗ˙f,Lpr#J}IF1j@8 W`@e)llӉ<+m#SkǞ4T{6h-obc"zWLqIk&מZ|=gx-:ã<5U6w 4R-0zU6F2݉C)tco)}@arEFIZg]4yl3, tg@^tRO 7Y.mT"Tj9o 8==/<2ivpTSqC)ba0]);0,6a\kGО*BP3)dh$ 23Ugar ~]ÔW41ÃKgw#C֝UR[Xuث}oSOPԄ| Nߊ#G Q3peeSqa3o2Lpk!8G4ͩƗK±cIDG+<.%_1f^yؕ ȵa? 4cK)\ {~rс'}Ae^0C<kbWB{22Gꍫ|ĕ r( [!supMNbu(hz[W>YX@|퓐v;|_\y'-3p74@ E?0>8o /TsLHP0\{P1] ĖxgA8Ag~ĺu[bbj}O <':%罌 NWQLNj ˴;zƊd~Va)L<,z5i~|R1v<}cNMhk0@5"f5"6K{M2F 'zyeבyy cn }T}l{E>1/iȗ@c:0zU/H _YsdZqЇ7 f_@pAqJupx7k,`+7N; 'άp:N*DJd@Iݟ9IIQ١r+V6NC;)7a\M Jx D=ݠuq3}L"q48Ok1 HިzSѼRCv_i3ƆrLX>h 7J3m,#9;Hޙp߽wpyjl8WHnO=dR]81^D|<}ɐ1q쏎,؛ݔՃV|Þ!u?e%d.0flz~stw<ro} .$t!<0Lq!;2{TMRX6RJl6z/Ơ隠q"1n> Qyܪ|Fg"شff#e'~)ȦJ) IZŐD5-#:> A#TJ$o=/ˏU$/t_=HE:3^ -ڤ@ fVޑt;׊@`y< 4+ɝߩ]I< <&._i. D.>KKV%xja,/>E ߧm.7Yqnۅ->1@xzsžC^iz8 00V+jgTw(~>"3D$dm(!54&4#ݥSNiRFLMncجX^AiZ%`0. qqtyBJrïxig"_뭟=RT9|9#sA3_)T=v~zyPo_ŲaInI1Bezf`s_B)z㾇KN'AA.Z"VfyWO ! ioz.TKŧs #NꗫK.N +r~ F'q)t֋Dַ%O9] ijIw T*Хw#h8~ۿ_i[ gL߹!YãAi3lp25-3v<, C4tm;e/uެzfȱ^:c nAyQ[su2^TП-,]-|m//=Vf3^~{!Z) S b۟) cZ aLJ3'yuZA~5q=" T 6g'*V*Gj]Mi4@ك$@>ެu ݄='޽ {дMW#O{Fj>p6R|u s.A7=| Ht=?s\ rAEv!yM `DBC!z 8PN F"!!"]F+ܥ#F/Z_̈Nm!ב3N;Ļ%̴q J|g`]k®hN LCJTF͆%\L(]*B1 q%@Ȉ*uB!h dۍS{XS F&΅(۰#o-U:3uc_cq r;>u~n f$T2A@ČKL'fYlH iVp6k&F9,jKb&!rv6V,2A]?0&Ւ.i>JCn+Dj=v8qF{ܸιdB$GF36gqԗ3ct:Rs`hpJ36O4}VFZ1t14uóg d6@L~يa ؝btEd"tk OۦL Z- `eSN"4NMdopIvnW)>ϾTL/9-)` {A*1P)ӿk{KJ RRو}8`<:!Rr 86ݑOR- 5 ?`[Wv%tOfxS"HyTyD\w^ e*$p|+{Ι?TcGqc..2vKikƽIr B$5?b}$aЬ~@:*!/hҠ$<'LQ븑'`r ;,Z+){w?抉^6ýL J%o)yƳdޔ0YFX1w @b2ƔTċtUVhc;;OĪCyK TwaCYxO#-`^|anbdPP ƭ5[YC&x.k#;P48PG؁Ri;=t #maUubG9܀nWɇ|#(==(h:z`kiiЗ20z඾f1}ÒkЇCGM-)f%?כfHR{ 7o*C @9͝N@>tc=wS?g./ش-kQ 3%qs8>r>v'pGBը^ێ0GbnfFL[)4ߥ%E}G(& TTyQ=p<_@i?4{eWU-ʹܼP%2b ]dRo`磤kٵgJg;ֿ(\ dFlTĤ0D"9BI"}Z_r ^L'StߞlH<Y*;Wi:}qtxcqܲ[{!RhxG:&T"hOam攞ׁeQΏWUMsPkw(}$bM 9Wh-tgp8j;J0ScO7Vdw4\QT4[uPš@A+ 6&CA׈D]=K&jz~mkYytO& Dfx%5S@%#Efr$QT$G9}AR>,9{,"K*1#2j4 OtAz`Gw0ޖ:B_<8Z?WO7R [:v JnR85Dr3E@ h5z8z?&&xrʇ8uBF~a%gP>]8f9/[dVyLJ5Bw7w?9%Nb6ld9@nߍ_lڤȶqKdWr LuE$M%1|&[ j͹GWaf `G!U+ D\':C;cO_ضW`hNQΩ$MO:[37.En[V\x%%Oaq)w8,X'9[ưJw8-|:>[yB m /EMqldQ|!6q&zW!Z~ vέwW3Xn͛(" @ڮSΗHkUhwCW>vn.r'%a$P_^G}F%_(ma;i0@:GEui亢dP>0yX(5M{>Ap6,Bl)hڨMXXuݢ hE"Nu8h pW -5Z>ڃƭCOz Yhoxq/zC,wtFl3~KLj%d^0fa'(b6F|ٍ:!z>ԝ*{yoq|yw_szF; |!tme6дt[>D ~thϧ~H]7&|q+^kc# ٨Jee ;zchXfQ,V(`_o~29]UAÔw 4jĭ|<}(c-J?c]+5~5)HcB/qvS WO 9&OLv(}-Ob n,3G!oN5o= QלGE$[(v~%y,,a䳜ž%i!'y6<2 WGn;] S djj7b)/חsTE+H1cʂD+U}W7~Sg,5gؚCAwR\T$x}5ae(+yQ*rpvaaT0&[~ݾDwMT_ $-oή72Sooت(qwjٸH2رnz81vӚGdЯosC}F;YPjMI|Mj( r~Bb+5Ŭ %HY{ T?>ҾUY6$2,e3kV13=tU<< 2#NW#.T+~\= ^\N'gL[6IԪMzHڞryJmM3KPYB_7 H8vv*jgC'۲Xa7,F[B-ʽuƙ^͈]xyI'ôQa%UY9HOr_[q-iz2F_V;LMJL-<{u`&Tm5O g;md ۈU4y oLusQF?5_FlHW.DƵ:Oc7>h~PaMȠS&YGkAw@Lp<8:paI낆ϪPPZ]'$<ԴZHm77~|\8,J-瓶8PhBw*߳Dvg}iPY}ޛ m!Z*n<k1Bv kl/;w\Tp o=O#O71׸TˢToSI_F'7o"ʭ3UPGHչa-6cCDU H>)$5%)<oKpXZqR*2-ڼ~@k9EUtLlwauq5-?L RL(E]ǖ{2",.^E6WZ9FZbJǤZ#Zpȱzԣ#[Fۅ) qV =\wѢɽHg`ᤙ'-qc W`#PBC̢P`gnjV@sO 2/a-7ސ Y1rAu'DQ9a&b»"-m#`E1 % VX^L+7,yW(s7FL=пxL9һ(n=,L4ۉnl06*WҥX0O?{AEw qPU"Yq!]ߺJ͚W]F!FmddeNxSa_\IjhOLCBu˄l5G%?z&Ј<$_7y(Hi&w OZ+| a?H{onq<|6]inZ8)=NC2) 4Qx MuۣZ|5-gQ}u Ɇ #.yCxXXM>y0Đ _[XjO>*29ucjdc%GFYt"Ju ?TigU"Q 5h/&}L۰J_ X))d)p*sc:mэJ"4Z`8aeHw4$:XlTqK\̟7֍KnwWaꁞPE <5nTXUK #W˸'E/"OlǗ]>*oF#s5@^8]߼;,Q.F.-CJ_tyMB@Ke%BcocxƩ@rʣh6+ev5Bi >ᝩA^I$S"vP0ds} <7 BߕxZȹZ#KdGtJ|wz"~>(0@peNfKdr=߂YfWU9ڊ#M.l ?r|׾;,] -X wOu`1Pvd-*L= )'^)SDLɫ9vf.\AFq8=shwݴW Mc!IbsUfE]>']@M|!/Ħ6obmѱpg 6MT$rBa> [u4ϾVx^{^-OZXUcZɞa?j`|I,0m5Fc'Id3Lft^]=( X8* -ۊ<!bbs xq6C+Pm_VAϵb(Cg- qWŮöH9}pyKYkD)4n(u7֤]Xh(~ˢ,[ tիN uu+̣}1-D1j51p`/Ď*E,0q w|&-A7F.B$BHIcF2<9;G$Y< o[c|U3= 2$#eVoGH:E eZa7Ld p姛 WEι2-%}6p@G| bL@N,UTr zg\αW.+gl Doԑ`śnARBH'A@ˣv! ;25XSN+錾oɉ"2^o 9m;͇SxS1lƠ9qIIJUPk੤-VX:lmx1*,J@˩G1fh{aB^Q,CM|f&+ۯ8猥Ĭ Q~ֶ=rf5ܫFK`I.EOҍ"%'ܛ]&3 l >(cvpЯOa:i shb΍UYD/'~s'sxA@#KKˑj!A!uH9( k(&&JNdm$ƌ`iyFxY(C+ҷY fUlBP4nk4'P4Y+(L"¬-K?S10[|( xɾϓ"[sYB=ya,ynk e?phXNDc 3j›t"QlUxN1bm3 т!,R.α^YݙK[q{gk v82y!lNx-8~Z$< qc\N۵rc|R_e_qm(UH7CI߂{!?/88MN{6;5NhO={h5vq/㓢!#,(&4g stHdwW89B-LttXz z?@qQ%q.Z|1=S@j,m,O^IYu\`9]ç)3DLJD.v9hEn~3aBo qVǧ U,@u7,H+}PWаHឈ>rEG $-* N`JRLP—*#|g| hFആMK1^1A_%پ1ړ@ \LjH!ej]} kEZ5=ΦT$yTnݕNm6 Ÿ52Gc`rEvU|p^]B{C a4R޲p7CAaeDdBD+wꢶa~[G6.c 8!$)B6﷋ߦb-;ږ)|OźfB1vLT`jQ "y؆/hDNܠYIKŢ:n&eyvٰ )Wqxy{b҃ZISCsc"}@KY z+[⦆)j˫*I\wWaGc_45C(bʬj{St)9y02c1({;+e*k4*Sj̳f#INɭ,~B1gr ?2}p*[C-ɠ%~p"`Т]\Z}j|„LvGŠȱ!chHg^L`SAg~˘0H=Y.`u LnTN?`hgbL "` PX}\;$}sӠ@!1lq٦ q<rHLv_=.4hi͓67 }=J)+nR0J%2(˂B(i8vוlE,_@Cڙql{˹5O = Y3o`fgLʋB$a;N $x9v+ͳG>#T ztOB: 5Ov5U~^4N@n,LN=L!-K,sDcnHSr-e*c§66c%اy@(r Q/ S[Y~@Ў4߇4 /9XjW?-&vܨp< /;V4:D/Gov7<½]#NxuLt4(*#)VS)`'N+Lם:p2Ja^N6l(M?UeDrW+@Zy.EK/WY 81kgl qR@8BPpM-֜zh$2~P6͌E7cJI,Ʒyu ;5T';J^* prݕ}e\}#4ARr4=ͨ/zu 8>/7םX gO:.)CG_VqdFQſr,Y CMBG(!KU"Itߛpq>HhMOlIBM}ш |w72Kcӗó4H4xlOuwhQ8N-)B+(B>-N_sUJ8`)BE-].1'"-j$;`‰~p:{qo/=8"\ F07oaaIM_XsNe6:NaRa*h'\%qC?l#tͥ2LR{VRvrAjh 6yic_~` "$?/{0c{Qe6j}Jq{B _ej8 MoKCGCDt<iGgns/*#eyu&FT?Kx9xźQc=.;.D¿W\L'¤7e"c:<$\Aƃl7zEl6g ς#('9 +*?tՎԛq=D -F\й`b347>h~Ay+NiI4pvR^X[&萸#>wmyNS!n%+<4@HEѺo3~1P* =H{N#Hڳl Q&}_m~N#Js bkoԆٖ{ʜPcd|3 el-^gd>$GaU/]R]L! 0^u\ "Ì T˜I}uEoލd4.0xppGOU{`䫏WGmHiz7?'qf'rR/1ICOk"M8 yFAdfBM5 VJ-**sQnԘS0t9)O.1o&\W~2/M)|jC߾ S'3ٸ ppd8g.4X-J1T>:P-h7 u/Npj\qT|@?4I'dQy:v$cV$>5RDzKui#dk":4%[J:&sg+j*3 I}{,)  E2sCIs~qUY_\կJ6[{Ӈ~.jɱO{`mF@"H= q6S,`$=2A( <Jᬇo2 &[wI.n$WIFh7ly[zܒxW8z~IW{~ܒ.]ВmeM""m)#rKU];߹C OJp'M1b '#(dvlYq)z%nфHQF406V [RCP &7K;I:C*v\SH Y@,1 s7kR־\@\6.\"ώh5nL#ju @czrADRC=ľ',%-kΑ$hw)6"]%SNA뮶 ڎܓyv_W`xKsRTFtbP3;J Oֹ|] XMgALk%ڔl#V# ~+}:N'݈YfgTId@n@n`Q}QV!D* "VHvydu: L8>Bf@BF_9'@ }`d>(N]d ״q*s͏ I>TIIc0aZ8%8ԟZvo١Sd)^#̜iGQ G~pOT2BЯΥԖ!o_zl*MHꤡ$m-OAߦ c~ZZÊ_aT9-n6@P G1gDe:{kƒ¾2^113Q2 fjQRޥI7jbSAI'B̊M1v+>^sĥXԻU-e xGGʾ !/{Z2T>}60J ={Kn?uMpw 5ԩD|,d&>9hJD)Ls*-T-rLR;C.N|+hd840Ti)E[y&oc ֫o 6[%Pʠ[gC/"y#,PۆK}> BUD D~-0Xٳ X Ws*ohr2TJF>ݳg\j%ejҀI'ho:̪#D<]%|ꄰ3)=gBT[HQLXz?/'?N6 & >Duy٪o6I{*I>XUkF;X.NLgRf FKC:M:zU&QۖS, LIOa=qO||cM"SZETzkBٻΰxl uUk odx瑝W2һ7Bl!jqfG a4tOd▼(7 QXi<F̾ S_R݈~3 H?$%V&Sbq7rCMȤ($@ҴBO9 ?9M p/歝vLZ 3N3t2CZ'n 6l̠_PWiٜ;`7w*T MӌftTmշ)ΌF(4%hee˜TP4 &;ʦ6`fB ;1kH2%AL72v/ K N.%@nB:{Z=cDC2}/F*}YgO1:nF^ј+:.OŎ.#qHg V+<xn\ӘF:hF\㲡cں) n_)r`9c/*g糬ޮAfnptYgAi^7B920/b j130Rd=|.{`+^ vece>.apY}HCFxVszZx&+RI4{/O\Bе''!C|(*/;bD?2_>O=2צ4) &IS2/X5qOB+U p6$@GٻRnHͰ9GUE_NرڱP׵e?$^2[[O@+<)=ۤn&?XgQw|u?* Fsĩl丳ǹ2mdfh D.;Iɦ ҂ZwwwtW_8_dK&~WftaD|^DOy8CnM0;O6J&ř'|* L{CFe ZjʖHE]q,.q7jlrL0ώh6'H cm7b{EbY4, 7DAO|+JK1b dD h~#mAN@pY@}hR :=u >$ ]؄ddrY:m4bfI_[\jŤe4#dּ4.} 1+1M-&y^ꠀ=O?m*ij *~z/ڻ5ѳuX 7=J"߁h2 [_wm|#Pq( 'ormWu0il $šH ô]y|4Y *f:,h6OGc| `"[ґh෇I=a}F3|#F֜\H]JyK#ժwxӖ[$x+:v [z nQdbokLh>s9`#k7]82&b$ā"H:1*1 6Acm+wtagƕܑ4Ymw7L 0p3 Ls z 77Θ4;I؄l){CYԪ)`gWߠEqqW>3;pjOei;y:2pL(YgNS;o1GKvb~h oE]_ry3Oi)AVy/ERhoO!:cA]6Ǟy!$30ycH_ zymgvۉG Tm`lw$}ܿ6-yfN,DD ٗ.(aU"W{wcd1t>H灌3>q(*FyxY1~6;[TBI- Ѿ/dثuac̆B4A ;FkL8}qX(} y;"^&6`]./u,ۍGOJ(à?J+&楟׈Vބbξ(~f;3C16"T&U̥7u+fu"7s8dҢ%$WŃγU]RW_+MZgK B3 CvmqsZ#%oўDsOO8^l-ya$Uqm<▔uߟ^? E0q9y~?\9]wBY-d ~Y~bFV-W(7:nr#Rf:o$;8W{KUt==Fl6X{`#H8`hgL?HJAO;YP:_,"6DΑtŽ<@tL`ȒcƃG>4錤<}J~K-K|w?x`¥TҧE Y+``ilYl ^36W9C4opmToKTrph}tBWvGUn W$m*;\\516,d1T;%%U>/%Oܐ1>:!4}4iiM$٢0zTι;KXyrEӁԦ Z;e>Ho-ed/[v4)ȳIH߼#c({'I}KQab|8F#8/l!s[XGWU\(uE=g+7rF @o X$ I\\Kt2ϝ sc;zuPhQꊥbx 8 3(%I1Yr79p.z_uSF'vIC;h :HQ肂[qhC(z1M!KGGm@{T"vі@  'ŬEqpᓳS@ Jz?Tls=YqPїY|*޳egfG4._*4ȅ\K[/IPuWu ^ԯyhD߲$Df/YoUwDT ݩ+SP{)?{xe^ $1IgBZ8˓9{a5C*!HC*p۳y޿0HCSF7ȅ.IQMvP&yD1A9RV= isBQ! Ώ P$:nXn?s^1Iu>w'кR1}f+#naې8~(wbzoPˌl}0 j+}TgΖkHy=WkDeViK7DD16TdhIF IIPlW;T:.M]OKSy8r. oH*2"#&F 0΍lGVִX=TY:@mxi߀ X=4CnOY_GL GbցSW?b^ clo)(9N7ICx +Xg;Ёzk=  {dQ{]/aH}.QW (@Kj'E{KXQM"dЎ`;wdv sC<?(ʎDuM_ 1hc Уp;YDXʘK!t$ -WO\^55{^>\xO_ uA58&`Tgn={Ķ4|i? q ˎ=N-#/8E S]wQ|CEf:臘5'QsGyTRYhM~+ȋF; Ʒ|U2 9N9&\zCs.,ҴXJ{j6&*{OS3(-qi% jJIyd:zUy~z)rb t3lj"bv g& cx3(of-s]Gidr>\ؔP?{iL@y%~>G-<9GIәC󔂪: /\W[" '\ H46p*0S>ޤWĮXI&x#DEseׄsLi55aigQ$xgFQC u4 ~Suj '-X(Rא.Nd[*;KkBVkD)T~()fdvP^q4}4E1HuK]#eM!#q|heyS)=41Mk-4͞BF&ՍL+ {8̹8xǼ~Ҡ`wo+eXʴ|\"&z%άkw Kp̯> w7R#(mGӎ;8\ >Z{͌`eZcA>d)SYP77o=(Ì ]\ޑ9QBLvnJض9ړYs9o`νCM}2} ei`$?VH+)wf+YQng2[ X:0rPQy{YEhӱ.rr|2fW5b,ۓҲAb.1!SvI;jmhU";@g)Fxbę fk)ygZt򊶢ZPal ,RG͟\w Jiq$fs*aB*EAb^H (С8ܜć@BN6^ PaE\r*yQ QL+jZ;0Y"NDeQΤ^ Zϡ9^* jW4eur7?r-(-_'mo)o ntAo{{tlj γs@k(9x&qRd|_CQ.~ȸ׎5Srk_0whiWD;%Vr8"_r$xiA%ViqI̋ 9sF'4]gĖ!h@jfu[`nrub6p!|yڛC 7&ר}Gkut _Ayn/3/DlYPv7}b+9VDyֺwݍvM25GlN4!m_sOIbt 8VCA .t9jH#߹'x ܪI$R/>.`c] osh^QC'D,dgmEq^bқm*[O&4Q#ke\(JQ jط^o!uy=@@fr[≭y o~y9bopZ4ȃFWl{ 7\8G OB_@W,QnY MN^wg.v!-2 t(FGs1=Ҵ42$ Oy/"e3c2U!ӜV+l[`39WS@R3}Wz=8VЕrnW\0:a+Dc ?4̨l}!UIďo @ُ摸 VI7ޝ[7ȬQ *oo-19lF(@.n?jV.QFD>(cؽ ,E=ÍKytMm+<& u d ;nDs.ewH a0~Κ3՗pƘJ!.̏\-o=ҫTeg.kˀJ52E+xK!H6>wCl8 a+;@3dnˍ.q9w@Ƚg..> eл O.cpU5v2%E(}(,YDhשƫU_C8qfb|Sc /5ù9<}պj?*=eGPQs$.\]R2D:E߅WCDMW@u9ðI->89NKɽ8-!dA?J4p4>Y1Cj X詛"}sKsBf. Vqvbvod@ ~%n;:uFhJ PɶQ9e( m!qő@"o[wY>ԜfW)QWai;0WMdG f63F m|Dۀ\?ڶm0۵^UNc׼'*d7gqL6FdJ6A͢H3I ".|r*KvəD%@}pfq}o7J+KKp4<.\W5j2 uKٜދF2rjCo#t#u[*6lu:i>sI\w~pV4Т׶ѣj3c9P:\Oz-퟇ ZT72 ٦ӌlx7X)aI0v@-XGc)tDJ\j $#Qut&$p5~SvVXn ~ܸ-OS;@}95{ŗLmXP)Eo,$$Q?pdT"U;+#khNm209! ʬ`J4`ا" ?P0D(RZVzJKeywֶX*5fW)_< So)~#E.*&\ #Bt:Τ&5's:b!?Okٷ*0oGqDiԮicGȐ7[&cbv2;rQ8:*173i@`ҺaiR_̘o1Di~H{=nsCF{.)L(ՠ$H v(}6o$~&Hc YE~Q:Vm^ \JE@hy(Chv1i) 12H|Y.7{k҂r̈́ .[{/KКm9jqFtҶPf:qo^;]S<꿓W N8חj;Gܛ?l_$d8]=Ջ7n”:pㅮ4$SB”֗IYtOy1>Le~ԕD-p'UOTQoSn;92@垨8FؾpвH /?^Z5?;[]y -n1ŦvF7qg$Ad֟|( # W|,^b8Q[}@6DE*N`PcZ.ȌZ-:M$w8ɋC^Z㺨/tΝfӇ%$/~hY+R\d^o"l=mE43Pc>>L[F)%Ñy C-ADWR9 Y_ٗN}CuA )\Lh1J+Wh KmU0r_`u| %笹md`6ϥ!A)p%Ñ+*AYޕ_eUb, &{tP'ŪءFlw,yɣN<2tzNF%RSwWE bf lUu[KoHqL "W IT(.ULH`?d%w؊x;:%GDA~-SdkXh /jonAe 57{. <IJ>C9Jt'>SGOtMxcaͳcS+#SIVE5p>0L XM$9fRWO!멐sʟ?s}r4]Y_!m02]SbQ9,d - DÛ\4*?,Iqׇ vf`#aB7|vQ W$\ŕ$={D"c-mFd iP>P)09$ Vfudrӊ zX%$ɐED?ԱN<]n@{6$y'=Ҷy`$PPM)If.ˤT <Zb*Zv8.t9HԐI~2Wۛ'޿IK-g&kpڅT"@=`^]e L;zxG̓mdyeEt nOp/į,Ùb $EIb𴿂?0=C[1+CC=a4Z,4hVhDS!~G3PMm6&i$.,aHu0>D\}alH|"jɰT.4( Rٌ-Y5 o?yسnFo¬"+w:> ]n 1}\CN%cb<|dd&tc$~&hK҉f Ë/zY-VsM#3bͧv! 5^-t? fB/\-i4oq"\W`C( uÂr!<ͭ3}+j,aT<; ⑈+;MtKz:3h3]OC>@ [ Jsi΍#HQCjZ(˃S5: lj4q2;F-7uk Kc5n#" U@ε,r$gPCՊ6Z l,{Ns̱BݗEzvup(Wj߱bZ{+}DЌy1;uJkB(X+|Qf㧷fkv^0oc P|& x}Tkʱ$ j.g''aȦ _s1]: y7&+"=|X:TVB=a/.+!g1LVd[S,Y@Y;DfDaO~SAKޕ bm0(&ˎP.J݌ғ*xqs,csޢ zvS!4;h!ֲOHMˁv/JUgon2P&ՕDϕQ?_*<*&:"!yG7_k<_&l-AdHdؤAq"k s|亙{GV,vwLJsG;?7H]g)*j 9~ /&e XU*^jvgvQKZzsr׮Tlb g1X|> g7`G/N,Rn ]Lny=\hXgsN 5t_jԇEShL@X`1?{'kq B0"ɹz^dHd1*.LB|X?:cg5˩Vw`A %Ӳes1#~+e | t0N,zؕv SBA@ڲ cps CB70z9Cz)<kQW 93hx޻7b|ۍ;u/[h{E^*:ּằy_ťVZUw40ޭ^ - 5pv`5WDxsjٽ|n AW\LjlAeפnȥ܃JX`kePHٜxU1{s~N>$+\& CTlnq#C{,aa$LɎ1m吸xgU΅SAD#=BQMB%HheͶ h^,(dnfw@CsVg w6 Ct Ab'fN uݪӠ #RUl[RC]x_={)&3/dV˭cϬQƔ4(ci0mtߏ3y4c e ^"! ݆' ߋ/kU&_,GW>\^S#{}F|Flq#aM1,ˢ?ˠkvEm>桬2R_j1뫻lX[܄fa1&$cU^Ypi6 \_@#Q ^o0x]%i(gW{HZLID] ) lR^ؗICoNwr0i5Lr7r,푫қyC.!?oI߀ {MMp1bH VX-9(cҏւ X T')M\ [n?S6c/pM쎘mzz6k 8rYܽ+CQFg|Ob:ɟ0ϝ/r:A|A\7cyN4KzQcn>6-_U >@@L+em`Ei*e pߝ#Z.#¥ V<@!>VpFm2 4zV\,R* n(.kkpB$t1_5c"tAh{fmkw?j3Ù4rPŔs0&Y#k1_ۥaM~iiuf̲74u;Mu/X뒥x$:թlyv3Ͽ-V磻ƚ4%X\!$ S~z.Vs2xksM+ݴ=kLƏni(ʭ}r:s$HD,1,CyU !R{iISx橘7*5hWl5z'yCdUO F/)gH,r- &`^gl:.|<Zf\>gRUhj? a ] mu1gta)W6!>Q6W7qWw#y$%Gl Nhb e`E_\fzc IDEt5>oк!&Uj Ơ&ȫu-ҌCEն Bp ɛGёeh>c=cwbwir$!2kAF^ 1$xZ8Hy]^%G`[љg-c6kjbWz(ɍw;6oilx)`;i|Gw;.$  -pK s/KcͶ)@k%AzKqsa1#H:6X4VI,բUAG}x~: vX fNBu"IwT@O{Os>ӆTRj00(0šS?ʱfuutahI۬gO/]Q re&,{:bdh{ߠ@%TVXP: /Ӫ |^[1\uȆ&YaܨnXjݪgHFzHνeBkaX2Y|5Kɠ$͍ÿKkg2QM8̳om{j;o%͑аt2y#\GPGC/@VdH(8}  fȆ{~!M为L3%؉†g24I'{S2HYF#t?B-/׊̢6UeρVؖj/5K/;ĵ~4U⯫)W@Eg]/TOk/WgNw e}MN\qMN|ÃrXY-9 Z,z-C% r#ؤ& 0C  hZIhx%x&^|3;TC{FZ=?,uرF0RhY"ɔ׶XO!9#%zK*vF<ρbQ@2U?|B׆0I@%Vԩ $ ,y6}h=ءS|1Br*Tx8#q&&=4p#VK꼼[gMc:Pea sv6v,{UF%&)dtAj s[ֆJ*URb/P }){rFZp.56Aw^%֕J4 3.)W%Ix!Q&e1c0_stSb)LW7 <Y''_q=n5yff >T 7zJN^*Z|*v/(.잻?,JĎѴU/~CȰ#@RAf__:j{ډ^gb0حA6cm𸦱@mT@}OQZ\>0RrFO8C3!ě=7?z!d4NR8dMV{vǦ& Mg:}ivq2#՝5O{_* =]|nz2$Z?{u|\:|Vd?6T:ٹI31^"Q)p-Qɔ\0̯Oyv _``+ I#Os6 pvȈww? ;AV$7~:8`7W:PAVG 1fDehP e*lփw->6"W/L_VзHzYy u;+G 5KGP1Y`K7XMXܲ[hw~O%tyG{ժpCNT@Λy~Bt<1ɉYV(k,35& `}hRaދDzB'CP6\siFD0g:?=Ťa7So' m!b;Q;2E*{`R3Ţ't/ᓦJDXe_:ѓPG7hW/ eBU/m{B gV [-J)Բq/"U}!ؽY6ΒQހBFlTn_ˤ _UD)fDP|Yah˾G.qhT!Psȑ3 3iW9"gX pVRѵ\;W^= [d]ڬs(p"Ii!dEvn'o״jGg)W( l%Y9irNYI #HJްi9ik;M 9%ѓ>%A7Ƙje_3pԺ7c *{ys!L ?U뀞u`#`'^5tU(c|VѴ6 n gXm(j&$*^\_Ɵ}7)!.&t9[<0{bϐz*w+ æF[yJػI\TG}~{ x1uY]8~5́d,ut/CX ν̓ă>eߘΉAqu!̓HpN N%giPtiӻX[$JMg0{hJ7Iuw䷶KugNz8$& u0B4˗G.o7EwUM?'Ep}J 8m>:zVB\yxOJsw;c:s hlp Bܙ|}8#^R q)Y_HMu#rE58z7=acQaRuquݶeԂ`)Cz]8DAPy1U__bD%QBI52t~?8@6b}1 sG] t8B+d=oQo3qC~Hʌ ݛA6/?epZv!/U˞oE\!\K0XbsƤ4M&)ͳAcYF,SIy-p}TҶelU'pXm~T" ~y2ojPE<9T̠b/}P::O^ Z9I uGE+wM!>[$2cr"+ƒ^ R0O UxY7pb: \fi@;Z#'(yo-"~;|X;LeϹ) .Lx"W&dއ'FF5N 7vg;9@N#Nk:[#)1/KDEv z߫ H|s /:e[C*zLb?|#f֚\J| wUKW.a\ #>1u=DY yQ_ R>v[Uft!qt?~T'6\3PAm,O WiW>6zX 07ž1 o.l ͫz@B l~{|r-5i7Xi-t䞰no ڠ^R(O7CSmqvTİcQoSaN:gނl"OYh*pTe,+??Viv龫+V!|F<Yjʽau[IyZYa(,"-cԒNQ7/"N,?ol-zZgrhiSâ0{Oyt]W9 d!M}Yjz[$AFuc)"̀)u&&%.yzKQ3Ԓ7r$.Hr7vn|eXp@WI}a>fQEv8qM_!]@6hlMF oW]6 6Nw8o\!rt" hR\m_\w`V{ .sFՁS4/U V8'1 σ 2}4zcv)^`c$#+tPG QCSbg/]=S|usN֨*y{c~.tGY)_,6l cjjP&_W\Y>*CkMZ 4\t[ڮ=}{:_j\vBnm"UH6ws-PAx_~oĚ qE;lh9cVYjϲ>P@4} FnL@fun!K7ز7\yCI]YDf%9^(Xܻ!j$`IܽܚqVT272(4ҬK5HAplZ ZTOL]BwC|c2VrXvJa%8d-5_?qE }nݏb1=ܳ ,\`-O\EMq)LQv>Pza~N*S*!]53HŸL>I}]A5T'muΤ1?yH'!愋(xDo,De l] ?~'X}2/N=wN7903QyZk*ꄥc0i0*CG༗3rM-J̧ň5:9:kF/c=+Eu O4`3gbвb/4>$~)mbT7 8ݢ L{I(dݙX͔NiojMTQυ}) s͹B(JS6 m P'ZQQe87z2W$rW0"w;ڔ_SogW:AXv&1W&^J\#W<%+|/:ǖ'X굴tMrqzN {-J҈lfGRyK!W(4#2Ŵoё"`6@uږ3j}ry}u"^wktcQdc;NJq WdV5̲?ˎ.Nj'xГALkژYS`GgHZ|/S9Caʔ_@xP 3{+8 ;mDskbMy.G2D '()7y-4 cA"xx&_SADwB(iQ5r(N_G/\6uI>ap^-B(Hvpz']{N4տ%o ؖ:'Y0-DBd8WUNc1tf8-}7Ƥ_:BI|@Em0a o3RgPcwd6gE %>:mJjvOL\RxwAg\OM:8I4 1|pnYP// o ])b))"񖔆TRl X2A,9\*$$C ^@Z(*PduT {J?Ed2I 9 ĵmS&;/^En"靏V<ܙ%{'S}j"v3´ ⏰_5$g\*}rxĔb+6|:Y6NsFم:d߭dV+^1I[#GaDJWoJh?^a--]f`Լb$Ioe0W ǂAY -ݬX9 l5=`.]!?ަ^?,iL=YbZ ` &Bd= `EDO!0J6%/%(qV|liql;NS Ssks^4<'UP$jh I ^?0fH;(dQV-R=Cv$y҄TR'?žY bғ;!LAU zUe:n{ uʩ3U~Hۀ=o*murs%%A=iفprDu&l3z2˗IbRiyuMz'C}nX:"Ic34ב9sI(aGqu5bz ΂ުf{rq&)Jz^w"=~pwU1!v?Ȥ&ҘKnAXeuFq,(DVg#7L$**1grts^J~l['Ck_E!WX]xTWH<]0¸աj&_tc&%:A$\ńU w ["&fU\2d3zg_8ΑAp:08`zGWGK)yH Vay!J)8n"y83fPW|ADڣF C[":qъ ILpj*d-iJ}0r>}(C:1*ͻK6-Z٬xF>& @C-E#z0EL'FaFTA O/#IHdi4:!~Ϳ_~P>}M bl cݹE.ˬẏ±Y,:P3M$0NiN*F8 :H4XtV)sԪhEj2-׍x?(h lɨc񟨨 b{? Xfym>O>7L2)>%~M 3HB] ' X7贯{p%k3G*Try[ZebҔ)LN+ GQAC/5\)IQր4t&eB)L",]-Qgy;&pzPAцŲ_K"k%os_9vE$Vm3ēMN_V'k]Āu ' G)N.~rW i7fW慢#ei?4_ő[ ':b \FP#ǥ fnT WzeMe,)m iJos8Vb JvKipѭ/y&9ߎN#p!0Pm%kéo:pnBȘXX ׻Sğ$Nf1=|cN唥leI߷t4pW^FjXR(tb^E}:w&zn>/=6R<ʹk-dr$]cD3{${`[ʗzJ$U \ۦE2owe+ ;/(ds*39I҉?-JEp5b(Z2V :&҈k ]hY'pَռV (! A[>&XN7D+ğw&N!"__4R@9G[D}ʎU.\jyi,! 6cKv, 6$!kTō )9FH`6]YEY[f54aٜ ^8MU2xu}M{=I}^= j*3&Rn(r3'M [h"E|ȭbr nӵޮz9ܡϤ MaC8J!j*L:@*|[|L 1s Dr~ )&HPW(ȷVfq Eo|ҁA7U=cnW- Omu漪hz3ܳddiIᵞx G-"3c=Sȋn; ⺏C/$4l[߲ V@z:lc_Wޗ#H>O| vUnUJ='R jp1xwąNGoevT^1<W6Xݞ:el]s>aDHX rK }YUxG\Ce2yQ*94rl@WMgx F%XPfQˊ+צgw*w2h4aa^nT8\R~B,Dy/T(X)hLF$'}(7)sK^Ze@D<8.P46Te|47%GY`4Wue@a虣J

%zZG3#cvhV6N<%6MIA'ndzztB]ve;stgj*t cX[A]]*B%?3 QH@NyO<8W$x-Զ){MNr/= nLu 5o7ǀFxP^gyjbc:]=;i'r(ȄsxSqgP oNRipEzbU eA"dCMݶj;U2cxp1׎ʒ9JKCO ^Ӑ1#W1R8zGY['MaP4l#.x4(rRIy)҅qO6sZL&.%1ڗ"p%D~3\&vfX(ɜ5\@Up.[s$zPm%2%YH ۲jQA!0Ѡz>cW4m:6c,dyc/Y337/89 UFZ]TL@]pC6|`nwRF:99)I/eV@mzx<"YKm1ņ8==S6wjrrQ(w!(%эA&NLQR6l؈.':~Gxk:ZE߳ Yh6ճwgM n3eS?iIod( ÔDSUrMl*X*<:ãOެ6u#ϣђ8foWڡe?LX.XuC!,嬴F#T[MvE黶l):.+}]FYhת>&cܵr N1E@۶Ѕ4m=H! B,d`X'eR4^ ? w;J]xJ6% IܵQVS"E[{v P27/MPfG,K<(Y:Oy|۶fXrV;OTQ ș_ JhL1V0OT3jzj˿"^0s : KۘjCoHAֈC޴C6?+ (L1BF6}WB"K<6pmOa"1 eNҸ$ab#Ņ:!G a@/a@EjgAޭn2Uu43rGra{BjU#g>(P.'wz~05WKғg OSC1_G7Q9҇c,d<Β·G-{<%f9W심%Ig[N /Y#^^t!.k\Cuhpfz S`:^;=#rYb*G7驦g[&Wrȼl{Sl͠deyާ-|S[ɋ:ʟDWA\_gL;# ~M_7<{ٺ䈄#Yt^:G\ WMs(7[oC GRAoO^W{ԕ-(LOi 1oa #.@)1ޏ @^w;~i)V[.U6 ʄ;h}@Jx>J I_{qysSC U]O4jǙ?׃\AEtA7$.mwe0-yߒu$^%dʄ]3GN{oJ'wUfpV м7y5+rwq G|+ȍ''6Vj2!JQZxL'o҄Mgҙw)ʂJ; 7 bl7~9N`"Uxۙ_Pq$3%$13gJ8AxJ DtKx_4#vl-?7 XH_ٍpnX_γ8~;Ʀ1&Ion]ڶR饿24@/;QPTI2<qlϏy2X_rf]Z-5ǒkOͮ8 ll};TL:itZ(Lk=8;lXA5%Vt` [_GJì67է@wmWdh3_yIQsc-2 ~W*[V:y/t]k?!"C@ i&Չm8mאٙ],2ŮdmSD)zξwf#qןZmnN\v?S1 3Tѻ;ӺS Xk~KVicӣ֪`d7;Ϗ ]V@ 6b y?? &ڜ!5dןjyk>VK_=j}-`8sN^NzU"EI)~)5^7a"]VÁwòQ& H?204X[쮤ZaIX_[џ*GSzXLYkK|[FJ\0=\Xaڰ9MZB!9˾v)D_sXSWe MD g $:"?`jegm_lgҤPg^^U*?;ldpf*GPxqD_Ex۴A`+O6nd]n&,8Vب`\42"# }М.JAi_jLz #w}o>#~l:}OA#Bo\bûu] 5W9aܻ$(W ڄ.}?A:ZWv=4moeFS :Ť=)#k#7^??$sފVkNM]xa-RODY+v#UGN(np78*q?:RdYKևu'߬YʆMGPXsC` FP"0”NB{mXnnmƁ&t`[.!ʑ7{y9qp뮄,NAb|HιU65tGF3Fй8Mɥ12E#ŷ%뙺UЖJP@%@#R7~o:k]n燤!SIQzJď}3pk4~Il뻹 vqBVKCJ"s,]'/13_f.gp>B~^S1aUo]a_ngT0H.{)ۻ'JÑ2֊, 'ur=A((Tz\?TƗ2w7kVEUJ]Cc5UY} YP*'7Dv}T<&d2:v[I7*jjKflX鶚Z&zMJ"@~1k | qޭr[ ND4[`񓏗?iv~ jmFO|@f*\yZ =3|) @iHчiVp jV vrK,(5G 02;`:ŧЌiuQC28&T&ui㩈wB1qhr/ugʹS/4gC^Ykjn6m@>E!F;,]Yp o%c DH;l@,:| (Z|21\+{#6p hRKR(QE$2$+;4am W+LmcwAH*Tux|7ĪHo:ݷcIg%e"Q,ԤA )m'}9u " + gRm-qYPH 7(d"`5 ;##|d\Gӽi|Rw;P!\mEHg슿Or[<:=f(_˔ߊxz4Ӂ!Amx!mb~ |8+tc=/(Ek=_ȤQDZշSHU.ad,wbʤJ?jx!xpAhqE/t k)@ \ȴB [?S$E#ot洑bgiX;Q](u tT&R9z(ahv+LP0MyxVmw\MtHT2y.Ж?]%VEͬ p>t |s1[15rsk g"Sfm-WzwWvx#O֮+5Ta?^:͆ nJ&ڙK9eEuM7M"MQ[vu$^ּ:Y35`R]qJћj(0kw 7S<5$t^VUdN{KiE5 !'5< b]4w.bnvlH^)\H:;z;*y_A+.Ѐqnp;z A]g0^xhՓiۻ\4!VO(θ[e?*s5z29г]Ct:ju)b^>!%zb m̐ ~#;In{V$>!o솀= mQ9n_mh.DZ^u%m_$:C~f7ńd,B "6G{k\¿ z(Nz*\8H4q'[tw zƖZ)/W^muZćN}5p,$o[y`~tZ-1]TcvgdoӐz B5JuXɩKG%9וK&yUT- W-U{AFw5` Q;DGZ6]|,vz/}%۞R_36iv婓]_; -= o D$}`W:} 2J2 6m*:ˠqgETe*J 7+u$ w+>K<}&Z7pг Ї,uf򕥽L _? *.vʝkIRl ƪC.Ro#?Zh2D#2hB]=d*^_b(o"hٞ?-mܿ)OygDcI_b(~HoA^40ǔg)݄O2Kb$%oT!<s|:.>+ן2)ν`ő3o.ȳc|#i׍' > 67Ti w+`:[ǖ/pVLPcjuk,Kho< YjU+x9֒Ŧ2L)͢6=Oaz63ڥt []̅&pr_ZFUNrdq_>z%L"Fw$X)"Y*SТZ ~ ?U$JyPOMj+T_3)kӇ  H4wltN~#c9&)OuTϝ[8J~L,g /v>V?QHX0):)y!\ZnvRxXkPǃ>'W],VpJ \@@q =򱆂Xet3Ba5h .ƭ? *4% qʫ`s'صôصtgL |:kUbG&|+\ ]=w͌0dq|֘}Ivi9-2oܓ4[ taUJs@:>-E0ʉGjArd˨v@\D DtB)9y+8ֲ[#\bB):1I8 _L66r?cn~T^9EnQQ >Fl/5R{<|}TvM`nQ2˺ğH V "翓5Y9N)b.:@.b{b6]dDa\)̐1k";ďIXy[m'0Ǡ1Z1ȇGh%tX_;R],{<﯑qS]M79 G2  )YeM gx3kv|E#Q6OxM^F!Zn+*e?O?P0u(0"qDاRsTXIƀjC S~4d 'FϔdͣH!cNK}LJ{: Ԑz `BxDKás?lM݃{$h*@"U'; ( e^4!?z-hگm9m922^ [PexцfZY a*tGKOC[)+h.v(5+\! Uhs}dF9r ѺͶ@4 G3P9jwp9& pGRiOgI_̴čmlt+5O 1l鴡(#zWǤW?.nFD3ی\r73A_ʯx>0I | >?!])/ J5wܸAN*mC,$ل؅P $dxXS&ZKX[ͮIh=1ezsx鴿jکg?QldxD'=W/,Xhs8%ԑgόv1^D3-.g (Ϟ66G*:|x ۫0.RYGs ^ ^*4CǛ4?ͳSGʄ,+QPC!_jtOXDo|©^YYn"6\&WbGQa_]bS D Kkw̤M+-aHEⳐ`\*YcT+ƀ7^02i5 qfx"F2ֺ-S h3|mjʷwPo|,Fx+~AVNyi_z+\2ݧ"ⶣԇdXs6c@PƇGJy';P:NG jlgª7H/kzO]I CRJ/3\n` wԲ/6M2 l[ֵunL4q/eLBT'SNc%G17&&k^" ZL'i{lwmtrL &q> fxڕS=+WL 5r} yDrq3R%Y #|;. 8+^0ash"6Lnst3փ4kiPm>RK!] Ou/82Rae02\P[Ys)|O5hz-xw+uЈ:Gb^,΂*e^:T]b3Y7NӲ~U> +)b ]fV6u(oj3`Eb@|oM)g`儭LQkaǖOB(7OvNd6EÀܛlg;j-awβU$O,#qWo{#`ֆB48Qx .V.I/-%9QSN-JS 0žrr֭|0&ʧi:FY.=E$>0n1iá|9x?? #9R4`a9GHoIPx1~;U)R>E˦)H=?|Eq 8 ṗ͔CQOQi.e"e0U}XrK*9GgKŇK*@nXN[A4Wi$ ]F! }/Âs†'{G,'( 2^z,3]oҪ7JDCHe[4?xRe)xFZ4| SSŽ_Od_p词".s֑tz@~y?3  4=3LkڸS_auAU<DAmTt[c{5Wt@$/f|TygokOeßLF=*"t!j bin,09 (;ǘ"-9OW=81DxXv^!k$H_T[ZO1fDs3r7SM7AOѢ!/[\  &~У;Ymя~Om9|lp!g.hqcGrDst - E{ a\({<ܥ:8W.!Y\+JY>N,*B)lhH|lc3RQ#%gN=my,0}xp.F$h\npS]3k4\ I>)@ۘ/wjѱ=65X/f V z){لTNVkB"KY% .~vmw.;^QLtcUg?ɘAM;VPm_~BH6Fy8gl}\WXFi`^x k b)/K[xTuag\*қf՝  195uE=t>b}gcgY[&<](DKMK$ztEH(fO,ԜimF\&:H{A gK :Xw9po:{zԵQas@ݭwb8݋z.\Dū6җ:8 coA1'Y89|^ g Jgք;??yB{-5(;Yޣ:9/, #J;Vq_Vp?x[eg^cF_Q0#ٗ`>mF)ёiS,,P ԶџWeG< .NS.z| oS iߏ8:cQJ|cdXw4ّo V.H\~+=N֭V-z j~zGk5Z&vY2<~8Q$#Ef(]/,<RU/xvhȾ̀]Զ2,'" 7j+οnn}e=,@%w ,ζZvpKG[9 [Hs8x}a % ?HJ|)wՕ*̂{M} Cd(QOYTTU`kRhoUTj.d0(@}8wl 8~Abh;b8r7 JE+f 4ͨ5U$hI׭cy2OLohr]?f.]ԡ0sӪFs[r,49 φ~in\Lqɥ_kl !0HOA6&ea¥SpQʳ.g øмS/S䤮T9gxtQ+%2\bZ=:A^9G a ل3O] l.u'qQ^P:{?YwMq1" $G˫[S=RP`i WFϴ~!-AhbcD=D])95|"gJf[_$y͟>8P~L4-Sz}EEog0ע̌;$imX14x3 ˇi93xpȟ%_>RBWu1ythn ̖P{L~Ur܁(7oBxs |%ɱ[=`87Na-_]]92*P j!d+!0LXs_hXI!ڸb5و1D~}M@#-Bѫ'=䡑8< z9c"`1r {ӟdtdS19<.H֏a7PHxIH6(r#(hg{4;ge#v`2r촉} j .P!hkU= \Lk' lKO_!B"/\;Zc"C?\ְܺVR_㯖hhOԧRkݭ$tϒ3Kr Sqm8PX5,;K0 3PU(lN{)XzB.8]>1kt\<ukVR)]^C\wL>iN5Z]Y A.6-# 5<͞AH ce^2E @1ZFۆrکdiH7J)Z7e(;)^d9aNRM/6iN<t~>\ 15E=LEXվ4,gf7]FURhflّ -B@ `iaUJu Wg'1}Ð@[)( o'v,Ehe'd,jr_"Zv4i ==d1" :jgf7V)[rr^LMmiqqQQt# 1IK$֞%$D$s! K`Fӹ8ҊK6 uJ׎ɜ;Rث&9tr৅&^-B1]'Ĭh`J/C-Ɯ'}o7[g^yu1اPB ൉,nxGWBO-tfSqPMaJݝ*]pZ䔓mcq0tcp3p .f?*)o*YNYܛ2CqF/nLEDZ_"nbulsbo4`\ ڹ9&q M+9~_2%I-4>S2Gȳۍw|ؕ~,礶pLo6` ^u+e82眫/N ML7^ϲ 3rran+jǘjx 5&F(O/n! 1 EycKfY(J|$#.+EhŢol4u٬ـG78MXIa7YN.z.V:4)GfI0 MEL4P@;IM[L@q!S%cj-IxmOAD5"[ ^!\`F}eP'< EPQʀ "F zZ )HMk5ƱP;ʂ3_bmKJBuy^ZQ̭9\rMtzaq%:G ,䞪 ~ ϹmRn=EIOWy&r+χwnYͩ/_P@ q,F9ZNX y&Y6B!ESDc]EzO @ǣS|(ŸG L\sdOV /<״,}Cnqn.ťT+]Vy΋ߴ] VĹ`LOTީmy+^iyg!ea\h|4 27K#ByYsUI zzy4uaʠ:/A4 .7Y{ϡT'Gӝ`1qff/pDLQ "ȆD7U_ CSV0|r?F֌דL2QdٸHO Lp9~gt;v 4;sٳH ojpR~a)+IȤʋ`ZFU͛RCm).KO0t>P665N~mlD̴f6dDaP4; C_ƀ 71Z7aՄ%k{~('~<(`RbDw#7 [mI:I$,QSP_Q K[gV4K=]LD'Tj &J4uj{{̹8R[ n|ܮo: }s9_dž Y+µIna]{ETn Tz_mJ+_wxwjH7&E,Em8hf@>|ݧ8MВ`GRO$G6ҵA96շZL C1~$fK53WzjS2owvV*.c^2!Gy<;6 \Ћ 7")We9)XN5|A)C9E ,8HIv79@%h0Oebect:dAk @E5BϢ쥿l\_>Ҥg_ri.񿦣y4ъoE=Jv'Yb9G.?B^7t,xd 5lmZOyk jԸDbtL? _S#CoAĄ$Q\*b]JEsjo4-T֊h5GӚWAEa .ֺV.4fR2A"~ƗU;01$!v(DYd5r[N;ZegD(y^~XC=;T/³?.KlHse*c2Nj%ҴFܡBY% b CK'!rl;(iඟ-(VO+VacD'oV闲Xno9t- {Ca<3A6`~+Q.hrĽUx;PG~X 8<QJT)` f92o[9M`̩(ᖤ=vڜYjj9p)g=C`pxТ%PfU:8f5x[q)TNe2iy.JNj( +>5 T`'1[C-gJmY-M&EZavU[<:KUEwNw-%,AۈQv)L W;Is#qHBm TvMBT n#)^`- Nz,0yD#rbGenq}!QzbU By{NnUh튏e@c*l1}>D:1>j.\!bC&Mc{?Ȗ, R ŀ&l.}/Y}Tʛ z_tbL"QݟѸbF5v.V`:3A%>/`ė. (o9䚅WSpLDRف|[`hnN֭܍XE*6^KOGF!F?ĆS[э(R.zSNnE{kW=C5vmJ.ZM\LJ cMCځqn!F{Dw'07ni5XȠ=P3==}+Gbwʠ~e&%A*lt3O&8F ;XbD_&>':R?W gPAHMv%SmiUAR)NEKDX8D"ɍ qpk0sT5JAQgDiXJOʮ@d}z̶YK"B odZ|?0fZ 7<'N$;cC9E(v+P!Z^<+<.PRr]qX8<#/^ϚR3LA4_v04aav8:L /NjY?hDf/<- l-0DO;4\:΋ٰ0*6Ɋ1BnDDw2cWa3{q}y!M3EjY@@GLؒ mi;6zsRK&^ 8j[\}3f|AIhuǥsD.rdUc &ϙ>DFNݷC9`K+MaRU$(+NzP7 q_ǫgW'BjAe*CRډې1xBZ.HGm;;a% +v&B}zQw}m^2al͚o TZU pr3fΎ"8?40*nZTN鈫i#xǵ-s8>5[i mb2T-7 ͶԔat̽3*lr5JՎҡ>8,C Xp4Ppiu=B٣x"Q@> ML.1;%, LE]jW$+ܔ8eM[zR UTS̹Y+յ6xf[٩ξW~K5'G^ Y >h]=L0C( L&bp"udu:%]2a } Zq4J`[J%%ل2)6cRBr_BanT -,2Yl)b"VЬʑni=N.7t$ !lb Qu,N5Ľ g*$F.l */3LvU<'7mȌ\ZnɡVoDӴ0.1AQ[sWV! Fbk3wG14ǣ7\!UH=`@ "<_Kg=&}kw6 7aAuGwe#8OÓ* 㳩e ~#t[g:య@{6AMv/4\o$}X`7Lrڽ6,IAȫ頰T5_^VgYQ6q_J[RצvK}2X*(kٴY(vvn4W%QkK'6} hpoOeq?rf*oY$Ӆh܈_Mdyf:[ `%O9~9> 6Qh+aOKq$YW'N1x=7E4DnX}-7٦\dCJ5ꅜL>lx%R'v&ʾ[l_*zGA(#w+1&I{Q >' bt%75%"o!(> 1:  ꇦA~<:3I ;c~V{QPM+!O2~ZMi]+փ1ڿ/8v?ayRf(2n!=J ֎>Ra|d]{#ξoS8=ZKŽ5<颦^E1iqU͞rγEB$qz"ԜI xcX %@ c!Isz+Fgau񴾭W?SlRA4ԔQ<]VeV^aVMǞ=XFū~E S/ d9A")o?.P@4_h3̬ dl]Y#C2dLjnGrN0(ow)EÏ|X[ smJVبZ8Z8/$/vS1; e{+nX!u/ə7^Tl`ҸKJ=ĽgariIIJ DERb$;t=7kxW9p荮)Jl*a 쫋褞"VQ*0X"҈=T^iDY5OtLδy&wbx`N ipJG%ijts)4bg H,}(5Йt`.ze\2z~ZOoP_P~>TʒAW˭2++fbG҅3V'z3̵oMvi쒌 %2vmsY#71]b I<1-?HEa)6B||-5&2@Г]D\Jӯvh[]꫗13D @騘?y6nIj&[h `5зEXs+&۩xRn`HRVp!Q )8HuMa0M@MeլS>FF@k5?y`b./Iukn?^xީ7TuȺgf_>P8ƖE*nmrYA]@cPyW 'Z;܏Q?樿ܥ10X?Ơ ?yWHT3Ѱv"r-ȶ߂}}qm[A6UV4D@3v]"k`4ȗXz;>e ? u1 9([ f˧9-?VŸg2zMgusMKvhǸ[dWnem6 ́nu mJYȎ t eha*?/aץX'H:uyPԝI]5q Ha ߛ}$WB6,ݞ[G0WwlD_oIC!Hq )u1gt? 4՜$f`dڷV'"\Oa`jf~Su pT9{iY4 )>㐋+߼u%o[5ױFV.]7Gm[ҏhwvbMN$ש^^[ xk"I2WKG;}B,u*k.vLbݑ3 7dNEMeI= 3]*‚ert^y!ʲn̒δ[!V-)mÊ.07@FAGZ]Ohyc 4(2:c.(赤:ك\ -`R=;O.=a'6y`?j 'e R4Z Z֨GzBQ[U)F}1LØ~"R;#9 #'Lv (5lC /R|eƚ)/_N`l5Ʀta įJd>:IKbj^n>#zQk :<yDzS\[̤hSDɼv\ 4u"!2x͘fs8m,?<>#êf?k=idf6"侵2-$6T˅g]=acxMiWa`:?X2T{MẄ  B!39nJZlcA?o6`Mn3 eqe!fYdr1]hґPNm`՘ux|qYId'X C./BgI>jCy2m [0wd~qف뚕j>dfNC+ ,@ WI.&6Bd}1uJc11UGKx 8? FNM:W˻/ͧx3IfT+dˏ}%LSM wme9^Z<[sZ>F6xשbgg6umG_H@0xK .ٙKC1F> ,پPN({tKvW01H قpQ)iBsB "%ekԶk~tPB==>.o bAط.$Z݈u ؇s#JʮU*[('z7bʧ*^w+=hsa$9$EyrLAY-G-:"%0t1(E֯aWD'">*p3*yhdl:<d̙T!1[Wiҟ[edޫ{v"+OXP!D -.8!84Da!`o:* tWi5aAB4PQw*1gPd4a~dd=٘yTҡ' *<ۆFl# nlcӯ9r^TΘd# $W=Nb(*IJ|;Lo()F8[lG6t d1_h8[9 {zf{ꁈKub ӏBJ>4ul\\D\n jqJddu5U~w~`s˟6X\LgQM>524"Dԍc``dž?S1$&gآ jO a#Cl~ɞQ>q;m^w )(1vӋsXBQ~ئơ V@F\t< e`S~(?v|Z- Ǔqe߼bP''8څ^,{X"+Jy o#چIf7:\0?50wϿ0'PS61]MkwYi TGx#zF/W2#3o5=Q"2HzcKCa'Y@S|-xvh$g;ߡpLk($Mlz^ > n08՚N,?I/`t:ԃo# `wYٯi)gڜRTlX0lԵJxu?\ -3J7)Pw'rG'r L ps+)sՠ)Vܲ6`ʫKa!ͣN?}debHAϗ@98$ao&z| &4r[>&`26o6j5;vPir2E; PJM::d[>UlLlPg<N|RW0]C](B,9|Ё)Ps11m){x\EWXӾ)KuHtH>A>س1Y}0d1Q+An0|_?4i.vHsօN oL~C v?b0< @'YK:`(?*|`M~PEa WFnv\ڲB0X-'ϔz@' &$4V -1;'p&+?;9PBɇz:U$fҺEi:>bJ5^_MREPa!B0@|AI?2yVӳKN㰦t?6?#BI*;v>SP\w ?.f)+_*z7g REmI"% w?Yz0{9\۳S}Q͙Ӻ,frK |C"7& (ޘ}I٤%;ؘ 6Zj`` nRSbDϣk%K(иv\1 ' ?$d`a] @C1m80$RVKfYʜ`ogE΁c =3uT"imQN٬YBMPI |lS$WAʎ&0 jsNǞ6޷XGyXg7]gMڰ%07h'Td;IEʟ*ٯ|@$Xҽ*1lŘ@!4gRbLL 6'msNZR"mZ> &5bhgOۂ5{$ <0լW@_K:b˓v744 @ɍ$т:6(^n{A<&="&\p dfiH3LѱYS&T߀xΑGYKtkL:@y bI 3r^ Rz,$(֗EB<&VX/ܫ}dcCW+saz)wXm7w;zPj,CVO#Lnzv[EfBw1a3+\%8M\)"B^5k>["Q d4PfB[@ds7Tts` }~ OX 4x\1:D}%ҬE h;lPm| X@i^ 5vX0#ͱW%N_[c=o#cm2YMȶ:?e#Gf*s(4 =c\s2XY Ӝw7ivHΐ`?r'RepK/*M MJOX=6?HyzIS^ՙqP]/;(h6*Mu7!A%rR%;ul6^@:h@5mY&V>=VQC@L7|OA ފVѕ\vYRZ9{}`ͱ<~IĽ=e m|L^~ YA :v]S(=ڶkb] :k[ЗrrOxs5P~gc%400hP𝽿<BDc-Ly5C=p(%ak9fͰMNNYvea/dgdE;You%ɬ/]JL 3d DX ΰ5}4#sGrhBO96ľ:]a]r^> (FК yjϸ@O}X]02bc·N.]~+NQCauT?xR mlLDoRO"5[t[CK Tٮ@* 9Mt?-U'g64@rw%o "dMg`uhLH4F_!;4u%ypɐCyrB6H˜Y",T[QWͪ!ZԄspֈ |Ch>9+伤v^[۸yf #[@(ze_[n=EU?cdM֣q%pSP~=% Tk -|%;yb*Q6'ܟ cBmFZOҰ~~IKDzavbY/ n^wR¹BUyO"SΟv`t i(#mD BT)wʪWi$)U /PDVۡ#m* ]%0bo=FbT;(hp.^F1Hj!2}S0su?WW9oױ/i|$Td/%z߾ܣvxm=FvZ ,h8D(`!àkU< G~<6"|L띥Js֑y9!yџM me(W3)PSaϚ^yGPҊ%?,;']mVql7KLfυϞBCKevgL̽͋U#tn)2Fng& yΆz29rkG>kԔ>TDq_ZKn>iܘKT(:̚N+?3;߾֯W!䘏)A1kh$T oX.(@ z \x9v¸%^}QD] ~<ݡ3v*էBu%`X՛ca?17 plۧ0RZͧԉv1l"MWӤSjiQ*謢yAT- \mqM|.RSWU8O7d02P5Y c's fukQ|F??E\Ր7ݥzP??9uTS&!>F;y>99\=JciiA2E$dNNJ&P`_^[Q]uqBE?@wvZ5£`:܌C3]Yax~;D\pb4`#P\/cd0(/ 6)'&JS]Rګ`2Ą/@qfW7H5 -8N61ƽ|{%]nJL*=beD{2@,!LLN3׎Jȧ$e.S0?SRT"[& su{Ą !BPvU" |0I"zgbhھwx:>|f:K>p0f`ӷlˬZ jD?aGŐvB,QBU1HFλ_("JP3 QŔ[ϸOC]%uź`F'/AձW7 1`-LgGAIFX_~kj.#?5tw%6eRJ*XN'@qXIY5H[ZkHl!T=V#F9/^" q+ E  gJvSDQ|1-p|~:V>#oB\vnjn{1?%b]U%[󎣝W.D,,Eb.33£)ܥ5x%\Γ!X| bt[)j tT?1>K_؉q1zV6 x:`V:J#lt OCMޅs䰽tYW Jc)wrP)'B< ^$lo+~n1J>53/($HTv>;0A>U/S ExHmA e6E pkpKsc M[KʍLE!DS^ OG8\n(āRS] ƎTǗ֗lCPVXvX5&j4;ŕ]"TW/8 91wB=]'*a\SbHא@C!Acj;Ѱcǻ8Q7Pxj+J4i3jgdm{${#|'O.$xnM z M :ʎ8c|ƹ<= 8UF4%K@b:82̽*0*=cpZIJoWp9!Fad@hB2a*]bw.|vC!Kp9.UYF,,0Xnc\ !|ܭSwe{lt %6v Cz*hY_M~+\ 4Y6hW52 2h~:S 0z)&ArvF [|= !v[g<20L_uVTUrd"%t[C"K) zrx&%{}6d͹]ddKw9THaHv [PDKHY xv H#ٵH- TžIBM WEG.ixc|Ε4CVxwSziKBQi.>~okiuw$c.-AKMㅗ[P;s/[~ yRmAm7 n\AA\&㐙eYm®(dH ?~nݜJ` Μ%_3#[RŞD]}D\vX@4!K0D n99K|0@K:*U襥^$3Xe~^]fJ0q9b8H?v4V\*inNZeC#ۖ0tؑ$XzL;l?݇3Â6!diZ b6aam3Z~rIMRpU3-((AbuvkLv{ȝkoemcz̦m|QH~@Ff^xt;{0σt~VFK;ʊb[1&|wC]v& `gN?rS#1f#dT .[htq|Hi>sttV#KYL*#a d+p1 ]&I^{k~X=o@4C|`d,#ÕGsI*3V#rex邎k6i3H^Scڬ討XeB_B_X03dԆӒ) 5fA"a^ v{x`ʾj f©mRZJ 0%+ YNH +c3"O@ROG7ʭRFZ (z !Wl:6(B%,{'p 8Oaf0s׎PLeϘ[叹OQ<?xiC='-Jt-Dێ({SIa)ɏQO⪺Z"M#Yf9gWÙ "`ϱf ]D~WyÕ}Ri^fi!10ͻ؍7^; q+xq :9 :w>:{4~O+d#L>ba(s$O ٚJQ)UԵ <"0Z";?7doo(3[G~z U#CU[dJ\"e9|/qK `ZC\8|{Zg2d7l&*zA6Nb#{u\ɻ=2PcDqيZw|!T3ې>͍SRhH/Hϻ@"L?SX. 埣kUZd!ҖI;v]}+pF'p2CZ1C2ƾ z_<|3rS3HFMp\I; = GtȪZ h-!v^y*p|WM@Hmws |5E7aJIW',ʞ APJ>r<߭eF%?㾫}mQ퟉xV[3wluLex4Z '63YlTy &jY!FgݒM;^Śy5$v/>=(ip}MWyylIPj 0szs*bWȔ)@J/;ERzOe>k!4jDU¤Q=`*.ʲ%*!*1 SH?j5 몐bKϨ!NIhK8*3bM-ywB 'DD[AYHd)lH!G^YI`/2a2k*ϊdZw IRįծ1I!il&#3էŰxgH_ʈVC*zF9Tá)mfvb S#.Ā>8`PݧiP%&V9|2쮑I,ȃ`U?b{hw0q-#a `JC"C5WTt?&yL6/'3~aRY}I&IeZid]eХKX=2S!S'zS}.Ps%߳POXa+BWPU 4Jx9Ki5J>3qEu2(\CH]oH6b+`u:ӕ-_qp;Xv.r5nq?AW[ Y,05CXxn=GbxT*4,z}OZ/mmhLJ0t"Io] Jt/uN.t$؊e=HA1Z0L#1H6c-WUXom˷T6L+UyT(x` J7/ƍ/`)R%o6}]?hޖNӑw* 8r*84A WȡOt͕_wO XKApL,d]mQO]0+(4qs.\pz!Kyޓ/g^f*2=80jDdF=~ \ýt'MEWؠ%0if, DXuw Clk!ŞWI!xAvg8WITΦIyHKx3<:$liͳ-Xy;v<;i2OvzՌuMfгٴ {|t`3a(Oٻ)na I$;=2ǧi@B+س1R _qx3;o"˯Y6 i1AeU/c~Pn~_bG%!xw5l&*30~QU~B||?Xզmk/g[Wګtׄ") 2=Z,uHLPɐ,P],2&/~tKz6k:d |oͺ 3WtC*$*ShJb5se-P1!0)'{_#b7{];_*vg6$æABs7 29:{z˭4Lůpdpy9uv|:dPgmæYy3-ҟ|%OE&P^M|;Ag6ꫨ/-VyBt14օ>ybrCRfj)h5ƍąM`#Uq-YU f@G)@q;`6e~Y/.YqҰJo&?tc_IIڲPɌV2nmqX}gy^FrAC)w_=OgШgBH}-tlToec L+Je-jeZǁ`cYM%@XHaG4[C7 [,}ur˶X@TQteŪi*ri٢,d*Y|$ ",vCagrw]1n{w],R'} W8I u;Ick׸eУoVP&.7,x! m!NV0KRA Yl ?$-Y"@uCjϧ q7Q#ِ/vq+nN`RQDB jq{s~51:}KCfIQ^jkx i%_^Zi"6jvqIi#Ӗ@ MZ5A :Beĥ1 (N=S }c[ȏV7Ot=>hDVyX L/ڊT $]T݆d ֊# ?P yGػA'%>Y5uڊxnnhcf#*:P)E!{w^^}bjj,zeg HLjl#qϛ ҧ1ZLqǰիXa-[HCkq̽Jx囑RmQʄRp%c9Oo۾T?徙CHV\D#{2uɇLHڄ$mE TQ@QO# 4 Bn@Ҋ3uf>La`xۭg)畸a?=`R8DbLT(:*)ɟ5,OD*>xCÕIyOܤ\od vgJ UMpu3hR@3I(O,,^Kɕ(Z 1(\&F|ޗrt}y҂pvsjx( z%UzG&JW:]}jng*Y֏3NmOE](qwhRq㪈`xX FQ*۸>|2\W(D:x 7q#K6 1e^EoftK.2|[F>mv+2mЕK\S[iGtqNgr 9l"A=g79u RHzABSW% ?S ﯏ Η:Zl 1@H]P..O@[-Yꩮlyy0H;8K} m_; |] R W0uǸ1PoCɔ' ʏ%d5D&FM;ٗ2Dz ^\cK9K]?lwF觨̉l Ăp٭WbD. DVETi*iU"9ڣVF$՜h E.'IvKP tP lPU " geSV\ZM~2~5m}/0N{Imا M8ok#Rܞz%=e }+r_wT2 vdS @5kMuH[J5Vyh'e֨CKolf|f9_^>gGGzTj5O]ʧs \`|Hg5xr?傴KSk@=n VGd*&Nt_)̷*mY .χʶZ HBCB`^$򍫓*4A# Th+4ŝhh,h Xjk*h6!xNݲ &%<䶘Tc?BO70j-;c\SۃԾ]JqH@iS[şs)MirnBY\n$*MN@~Od? kiMgT 5hhbv%p/Xf17qa&@}kFN!-j`!7`ȡޕƊdI3tb}6e%V>̇|d(ik7OwrEEl! Tk}rbO _M`5\aӂ'x_׽ЕHselDoHC|4!֟q#~kaJ(⡥thZKLF+LNDH^ċD*,H,M6 Cx?٨߹7aW ǯd&ؾx= !/VA(ώ_%4x?]mD\Wj6~䜴GB^E_!N)9)U隞!|tt핑eP=vt䓟X: tKK <.zoo y({x-©D01fMnXsl7-T,<&D.ZLJG݁NtTOlaaL XRe'!3@LU#7J2 1P$["+SK2'+X[د ma bP(әERgS$X3Է[pl,j0 7”1gz]Ͷ.,2oe}TXɡ}24AwȀj Ny ȩu%w$$Ysf-yIkѱ~O T,i\u(^LXMagO"(nȕ;?)#Cɜ7_Q,/Ô̞^ܯtɘ@ &ʮݩ 1Rvr Xc=OMbHA waw}H9l\m${ѸO[W K@ܖo2l"8 RIO`n;5ΉdFXְ;2d4zBu>dh5~jtu<,QFm@lwRIq.wt|AsT 0՟u]A6H !6'Q7Xsz b*oa#QDB4:xws `G1al275Nq vvmlsc_ywAQd8$ǡOx~>gVe(av<;]h u{B哺&b\٭Y5|Ű\?b!׸T2"0> Pʲ*`ש 8dx8pF_U獾`syH׻V7zZ0RF ̬-;o8BP]S.-|z\ Qs k@<Ŕ#ԧX@!8RovltI_fK[@<4Ypp= Mӭ1|!So,򋰻ؘͅiϙlWc\wtv(Z/ypmpGIG pn\&,F@4(frBe9΄+"vmTnz>P[Ȕx93,X DVpJG ZM]GY 5֫_.4"пWjQ[O6f)e:fK~GPQ(*.ʃ?[P =Qd5s7tc .[+n&Z<9 sP|񒌝>vTf/xƢL ^%J쑲 Db _3qG=ng-wZSִ[~Bt}`/[5Th,Xo>3d|fnIUӻA2P/ɲ,wCٕCΫSsMM&s5Άa| pT*hRAHjK !u{ſ:ė4Ə^ٕ4HelJ}-%X=Z~R4 ӭAnKZ$[<}*|3@2Ta=x %g0Jc%b}˭nQ2vVt T,n0rG6hIp ܑo $>| 8CaBg Om2\Ob QE68,if-eܝWX}#eo/\p6&zA8c{g앸6VojP"SD*cB3&!/8ۍiz0`Ő-t!w3w*ye*jL`}S0 LAv$2 pT~ýx (d;+UvCd͝ xEQɓ%j cYW&e,ę7b>/9{nby^jtV#+5Syq1:+ WǐbT(Ac䋓Jn< օIs )G.q}s<}$"+,J?fe[9Y6xR6or||҅oVKqgnSc r[Q1*:XT%O'W;6q|S˻t0$z:*ݪ2{U_Q>Bkk-'p&eL $.=b<)Rnb;x<c  e, W<9>CyHl+5S,T ڼɊlA 8Ѐ 4tBM y6ʺgªvWQ-=0tR4:/=` {(_Ծ0Kz^L )EdѾwٿ0XTW mSc {bv 52{>OVhuݏʵLH.S!i?0ovf3,vKx:X:nЅ)4܌$t+vu Hp sT`[D}S,:F/ &p%@/I|o:آ3@&V\ MܕxJk*KYbeXp\ m35vS` nTtOg\`fWF*^n!yu-CR!D>p"{IC7hi[-~2s1##y(a@GH`_ZQ(kd6L=s.N͜$0|FGe۵{(j|Æ6۪0 Ⱦ`FmR ޫ<%[hq3>SDg;zp\Z>O5ճ0&Q:8gd|kX,2V˚4IEMYFL*<9iGar񋞓@~]tx 7g|UccBͅ`AU/a[F(GaKczD.H0;^Ju0'ZBST,&ij SGd ^6kO,!N#; C+m.SZ?Q`<[qA y=l=^ſi$a+$bwxldjes(%|)Piq97'\[ŎY|W2vPU ť&^]V>H攦h)oۭZ:Neb+5&%)2󺵆>Hvk@,_dQg0gҗ!&i+i>ݴ\ŀR3;hM_P) xio/(@6=1 =O7Bqv[\fzKh;Rt;xLkon5n\KzP$ 1(+&qa݊S\;Q9CDu<;? !SM`'xL4Ҡ)T$VJҟ|2{ur}6qZ D$9G^]N0U@ Cw*v1KZDH_SN#6P/ ZڃHCH掁40ӄ3x̸*AvԤn/^/.z&6r \vst"4y|%$6/^-.OzV>Ipa]b;&0Й(?Bi 櫛c̟|,%\~<7R%(f6O[v6bd)1=f;o Mx/%Ǡ2뒣pڧ4єnÏnTh5d k^#7W5IIN6oh^a!+MJOoˀ.y% t%twP WŅ *bV`^x{:ek0$K$jΤg\W`%c "ʢUl9%0VYMi'F;APPAo5v94S1új6*A-I9:7)U !4WÛ%iG3x&ޕ.r܊<`4Tv&ddeK%t=e:+1 ҝ46 rw$Q~3i>N~F['4?!yʘZYCdde&_)>;kRUwIQ$ʺɎ#!H.Xzȟ߀:k ͺ)e? Jv8i$SW'G}3:r7o*К=/y3+oYYz{)a|E dII O#7,̹k-]s)2*'^GF\jnu$MЦxsI6.wu^tL9)$6`eDVpfGL3.~γǽj4NҾ d; Oz+܍ - Za3;E#R^6NH Ql(ɆlHH>l~ï0=\6@vgܙY:C6`Hȯʓ0:|9&̊gPG8٤Tר@)#O,L\C}R4=]xNv;! *lt.å@||tq@9Xʘ/9^]U8iwUr)iݒY>r&jAT 7;TϮ$hF@蛥,E ZJY\0GO3?.4a86CWUֵ#RM[ޫσc3#2S&<ê%.]p>3Him=/eo g33s A9\ U.0hwWx<)X^ ŏc?+bG 2l#}J)~Ԡ9*g&'bo5Ni/ W\q@7(.g_*,bg&hȾQ7=<чޮ:FMo?;Ǜ_rLWNE"t3͒bXNQx9~XJnH0X9]:|h3REt)`ݠ6JWӎa  Y4 \gQqQ`*M8n #N՘۪˾VB'DǤH3;,*͉-"4X_qnͿĒmX; L?tXB"WM7 L)3H `35ض! Q0E1hRFMA:#_cn8D#"{|jBw.mcµ7/g-m66W`ҳVƹ͌1>O#㉆Pz諾b)*CpkwC$ސVdɂWqsJ,%9w%> _sSsnC㬉p,P+x{pNZx8:'VlQ[ko¸*;ۚd\^d!-4\:bbKfqd >samch8:dQ":Pnᓄ IOǯdL ' SahJɇSq7IY;O@r|_>Z ιt.z *[qQ!^?bY:;dT~76ĺA0~Rb;XÛesF^YD}9{@0|c3ѰVpۉdFZ@g%?Z`/ ߫kS(Z[.nH#</ 3 J gĝN8D^fzų N +sWl1dr54 P) [ߏ%>Z qc;L /ɺә1knhŠ0sXRF B$L8W7 Q ۡmsW/v@M E# 994N?:Va~V5U yUUy8أ\y&#2о]uUspL}ߗ 1 Ȓ{捨Reo"L! T_*\L6O7S$3(r# W%z Ŷhx4i%{W;̑3n7âHd\<(KN/q@΢ gjf`;|Fѩez!gpdrj{JQVd)zl$`T*ϲXQ<~V&nC )x>LT j+8b glI, CtSm\)>qQeo^Ιv(Ojn8>oɬwn)uH>~hySe?עL0\1}[~XGR#[0bHO!PA^˾}R+"H_egDJ8d妈I]z5H5?ZýGú P;w7e:0HC(ûaݓN5/Y~'1(!Rt+ (9pf,uH a%XUKI|njZ4rtrPՐ! |a.]n37($_.a(c\5#'^Ktn`XPz=ifg(BÈhu.vP=ʺ*d.^ ,n*\Sz(A{bRt CP,Mp $`vΌtc"*pݡB-L+C1{#A<p_Hy.K5Dٻ*8M"rf~YW#q 9E%dBfӇxzZ$8.VN@ _BPu\TchJ IWT] \ ۱ %mBlBX'8ĽDZsb(ZB{i:Tu{yVX<--t/X^#E6(!X[y4h/mBiHp};6M;}^aF W?⼴gȳم,Ҧ! 0>`FR{iKZ')w$l⌐g ܺ6P̡ce X7J3_ 1#1r*;!nU,ʹi5瑬F+pi5k'.qৣc 3&kHFR:NKC~;2Ɉi "w1Tkh<@IGkͦzTqFiwGlө;b>/};5Yo[Jq&3 {+AŀV~1 v)I'ŵnV es%<$x 5htt[#*nv19*U.ǽOY K,r&9(BmSvЋVռsoդU?TΔcOTۧ+ '\)'FbK<R{yuo"I&7kiw>3xgx\ sq}y FhܗC Bqk>y|)KqSz/6=u&}sa.YڿC&yKBT'Nљ!8/̩uמC8$afR>$Crh$#hZ[F0M߻ EC}*ӆF'45P?,Z#`8W!)аKvTh4(6gJU:# t9>3HBpdUxyKAd!(G_)sFq7^U(`Є(]XX*] @P5YβiU/ж/_շe$O+Ry]w"\~LG$N^16}pM~9eS:GC]nU,hٯ츃ՒX)zXZn5tdB,[q*z$娒yu'h<75>ݴrعE&R'k<}-L\sXJsÒ12Q]s,9SP>{։(PT4(E'& rKME .8q[_431'‹ۀ{'%c40B:/v*vs4百. j-˚\{Hϫnfaah]^S*|G<ı.s&-H,Z&Y~#D~ŇC1^@]{n/"Yr~cJTd-Q@QDU6{Eѓ,HÁb>:ћݎ= %6a0[Zlҙxq(G"hk%%^U&𘇒fI0=UI؅}C1SCآש\ArPI A/L6|_Ul6hNSE DV2w*70:Jupĝ5DyjvLa>H/D˔.sA{_UY VDkJ멺O :UJ`4sgAY.Ӧ@/핕^—۔wDQbGo8"rWtUctsuudy Se{Ww`"HKkbxÝpZ s<,y͹'K- #9Б|+H?IAb<6U祶/DBჃbmE̐+U 3c,X9E,nqՌ%F|,=}(|iwɎbCht`CQ 5[2NJX(v f&_ j,$eܦ%4~ nI"7>QAw&mW' 0 \-Sz3"UN?1룮E[y$JdѮ4I=Jn8T~wWr@-jjjd&4`3X *F++ p7n!6bV:+UA@ʵH7qrLl܄9h3 Y1 Y;|f!8%~eڻ ߁etp=mʃQ}!Ftx8 ^FbRq^qQ," Q)[Uڇ&-=Ã;!zJZQeZT<MX(()9LQ!zND}{'>Ent/6A-u!H./?-5HG Wy"Ujx`X촃% HC8UQ9YN3V cgHDsA`L xlAB[?T=KvqE8,7Քǰk/,PG |CF>5v%ҜIbVӕwœ\7/ "| 6m?<2hPwUpc){*0H"pWu~uEa&T4)܄;)"u 1q#^ tyEI8(ㅚr#3L(Mb- n b! z:{5WYTh Xoo A?L.d#wp'εSSJNumN/EՕ% &>ij<˩ 3-*<`e]ۧH`rd?Um-g4(B> p]6deYyxb.}P,RH Qv44գ)199%̯IӍ:-TZh &!~GF x],@o[0 5fe9c\nHnoHnnua,$z {N-(_ 9Js@NOI%vdS vcrcԿ4(cM'^J ri⬡Pҝ/s8 Zّ}ͬ{Bt>X"fC srܤ4 " S]ڧt̜DqNHD\ćuA/A&W<؊߆u%וNPML gB|f':e# R#1ș>AJ-l\1lX`\N8i|#ߖ^#襽3$ y+0.L%p" $3)H$>^Pڥ}@|q ߦ;"9XP4mߠ% 뮿WVrq5 ~bu{tlUHJ$%7%)oFL[r':ߕiK_teVT$͸WJ){Yނ:Z>nMk>bM<'e^’؅W{g;z/m~6 :5s6^CjM9Xe5,L2EqF2Zu&J]fh0H(c@Oz[̝aSQ~z?t93.##_E k5Z?$g>u~|9ǫk4# Q>-J n}ЍC`9F :o>vfg1A}1(7ʍN WP$ i`rcJ糟 gC7][)3i.RiаMijf 6vmL> +dCp_lS}_}FxhU{dol ;i az-^HJ#O~zcJ.M> t+9%2`űz(y86z`uF?^RDwaTkT제n/3߸'eP*maQ3{È_vldeR&9^L@.\1'kk3_MؽV]ԜXR<*@.nH4 ~T/d9tfUj̆a;Yl:WRr0(ؖhLEQn?Q:VM((;sP^T1Nd9nZ1(pPF(kpoט™ڏiHZY)ir#4[Rzӵ59r[ǏJF0P3{lC"2]RFXwYY"+؊7IUy2&̗KNIhQ TOx{&5E{f_\ <` aF&o- OqZc፥ HͽR 4W@@ӵ[#4< ͚x2Nn?_ZrWS&JWF3jĩSZ'9 fgYc\l=Sj׋M1a] YprUVU!KɱZR.䨈+&Rd i*Zv 5VžH#5ґQ F_3d<R,VYf{1,f)FpR~r,WI$O?MQRjc_/XmKaWV3ѣF򙈳gX1ܿBBy9OzRcWbw9SzD t='ߟqZI@P^ (MI#S1^c3O\wsа{1gfg삅>uh86?Jn9f6Ψ⑬XӢAAH ۘ)[qOpdʺU^]_>z+b* -zp݁d.ly y0ve5aBO/PYXb%B$~k$Bў +Ƶ[" A)l ǀkE7ܻNe0,fai5  a;[vQYuEt)3SX :J#i6<s7Im}1%`7U! bn"g W]WN0Ǖ|qclˏg*֍%2@&W#D|;'.06:Xiq>v:2i2(ˑNڼ Er.)y@sQ3s9JdG&LYTPH|_v>g[y#^)un#U bjURwrfC>۵".Hʲ;j=x (MD(sYfGDz=5kR\ܬ6[2'5"!ۋXm1?N'ZH餕8S*{M1:ԍC+%!DcnQ)%iMk6met{}]3e(tݦ#e?y])cآi"# N Lٗ= zʢy(hDAy Gd!@!lzw:gnS:7 1S(< */vK1S'{ z~% PJ}v5҆(:Z*AN3oW<ծ81|JyªjJ ͖$ Ud ߋck8F0H5ѳ nhB+ IG@ğ9QKzۅ+,^=AߨwA*i]GKg;͸r V~ -avnd%XTin$F&5" R~1 w<KJ_QDei# go4ɮL;'0b@XӲ#{'a#{s6(dnVs +߉:O XwЬKŒ.]4b}GsOO~50IYOֹ?^`p;`LbٰLql{p?ź3H11m-CJ@;+9dZeO㖠+ bʻYpAYTZ.\3OIoI@vCzXڞ9Vfhrm*Sڠ׬~Ry Xd VR fn5zbp2H4)/c"B$~}D3f׻TbMs=KZYV׌@l|ѤMm:2.SWo3 '6~I - @J^k;|sVHo/&!+wUFyC- foK] m;@^x3}Mh ww4ugR@炕HqyXȡNbC;##PXvf;t7tbg_1פ"rw(/h*W b|QNP֖eq~. ߈vz \lOIvHn좂x 7<$#MeV3/?Vݻ׾,Wլ₲: 4Ǫl`eV֝ZB /IU Υkvt^+!K:^#^4%ҵ&"[)Ij~sMj[aWY~r%<9w-q3M~~%1g5!So{N0*㫨!KcSiko:KŎ=[?TS+-#"j1!Cn'a &o\ՙK+gW,JnƐW İKJx'`KSmN[q~:ˏt+fcU0z`/Bnf* 53qq&9m[CF[O?$G|t~+~?c޲9ztXџA[hV$c/lD- ](HRse-5 af!a Sdwޓ4x%)ERMrmB%4(rgR٩IY9GwJ.4^vA$\W7B`czSOlӗY{O2W]",A~ni7Yn%^0\z@5Ftl l;ied y>,7~k]ߤ`*PGEt k^lN)Zsw;1k:ɭ hE5Z)}l `qS?XSr1A0/V6TV]ynFA0<}6__-`>ݮ#=l åG@1:wȻT$bUlN;C&RтvەI*={v"IIpJcPȟ?KDIj8&4DH A @zO@2Ec C饾ʊ=׌ <|eC\ة9Q꒒݈:}wv^~ΈTq_5!+|V| F]MxO)m$uReUj?O^.Lͫ=?a[̜4Cg(C,UJx7kR[E7a4aq]BT?J}7dҩ=Ї _k!La{9)oְe 9tEVYLjk=%Yf sVFV_v ChZf|68]o$iqa;(jô^OKіX ['i6-=Es)/t1Z?yjz#Ɛp|ԻpPhsgΥLB7G4HDŠ7SJD'eYg%P3@6& .G ڡW2^UحBK|QDsAl+e{\dH;J-HLY+tVLfqϨ4c;;lay=Ë$lIk m= z1齺1J 9[l לGnl*KAޞ/9#)=کVdtl'avEJyU05δUfHWAN Cncߌj鱃V=@ C_殜5lL\usÅj$} wp 3ˢ֖H:L3y v`Q_ _@# 2-}̽ݪÑhOv܃_@/bd'̩{$W&qrS&ᑐ= '|ʾ=lD: 0޽<+o&(tSěGk:itw4P^M3:5t+,fDt g|~a'v'g?=9?ԭy }q!4V,R[(Lzj=A-&SW `psʮ@z-5`t;֦/l,2o5^)<p.dFڎ,o?cq赳,wsQ:KQ:߫gUy 'wMC?a|WFFC8z}'J`n'k>EVʐ.q+W)W;= #؄!Krmi+_PaE@>u!ZJr#nwR'^Ox`p;g!ϸ#(rR {4ߓ/s]\ 3=I6@>9WK!zn1Yɮnwk4l| 8ߠ;ܰJGˬamXg>M/,LeD)O/nSf^<q8Xfo`X~9v~mR "=j!BhΞ3m*Ӯ9f᫓ԚZ I 1Y6fϡc-be~aE|i 6moՔpu-z -? %V1u$,VUhFafh`qM>'t@l`enC- j'g HO9pzɟzmE ^(8LT.*D_KZh,s<>X!d~Z%` ˏM(4hJS_I1Kog92xYcbʱKn,.fZsDP Y =n5t?De8 u\,ZJJ#!f@p8a2MRtq8:6݄8ڹKXp*g>;F0bʒuU+갟`ǤУt {0O@ 3Ti76m!ShbުNR}`%#ۀH}IQpez4edt &P8Q{Y7mES<=MИ AS*RĄuM OLcU[lCm wr,C$!X#MrШ( sl%'sz[ w 3(}쒮sz8RRk8+,57+=7 QL32#qaX0(|GCA!Itae<)YݍPJ0ʴ55tUdVݪt]p`[m|.Uџ-[#JFfS-jL?ư,><^k Fi* QІバ9Vr&6(t2?T_+ yD徑50βFF:x͖vQ=NE-|mq-@ vm~)OL?ma c/' ~렫1: l>a$KYZFw}FSl_s/wRGo@$AKo-ɠoaoeҬXX;v?R~ʛVY:xC^X@[ dn=BiVWjk!߇ܼd949):bݍb#;vb? tXWH:u+/D`~/Ȍ& c=lJP]V^30ODXy؍G||U\b!i^⻟a @mHZSбeP#ZoɵίR4Xt/-d`iGvJ@Wͽ#SM(xzBμb\XciF2VUTk\ $PQu#Wi Qh<#{Mnzn +Q3ƜG3@[-4xx(MNXXH+ 5isy!0̌6V)ZTA G<ɷҽkp;wO3S3 !]EaYM8U21~a[j0^YP^Q@j2@xԋ1WuQ5t837Y&c[ao;{ [\>[j'$@rĵM%Kۭ`8Kw^ ߌ"<|E0wi$, +՛zXe ʃrN3I#}{!*VshMw<Dw;՛sЉut_ )D=S/'ly\]εXcv;&Y < ;o# Tt 4&N慒]LmC+{+[2<1wZP+H%P \"wĽ /T}YqJQPe`x}~p7WI/5WjKy}Rp m%}P5nZ=8֒7p4}fYCr,hF{fVQ!Tvf(Z\ySQCm)rh%VFnqgDn82@,*'ezYhjy`"댖z-RXL8} *cHhC-d R]3gU̡йsV#6@EnqV9Gm}- )r|8 ިѥXhP3`  ,ӿCe83t @@EXS=)ඓ\\тJQC":6s?u~ntQE5!d414Q7ZKB߂p-'e{{=\{=pI b u[]m1Y籮L,:4>f$X<}ùԲK`?\͝3 .{uE♴JiV,~d mnūZ2VGԵ&|D'n_G8Qr4nu:R,Z(שG;=XJwݼ( WNb 夸AC\cf87ZL=͢MjQ8qF'(p/<[8W8MtBqǎ 0lvÐ ڐY-aӦԋ'bL3 a'H)zuT2؛0 #e|HANqIlHt䜺wH1Rqx?'ߊ ƭEr 2.LB;&~[쑕"-3ai$a"UwLgC3/=?c)g*鎠ݢL]o#R;\rbCO6tOkmEPUعAC@͠3\H*Dհ )[:At #UQd:ZўoF Zld+iX(tn k[\Õs-f0h~4ںR6Of0bv/\Mz] HSGGv25:D2 e MV/\%M(pes=.Y&Hv{0>|vXVf=vύdM+hdFPy-!OU]=`ޟC[<78 wgFQvIi1:HMc_8# /A<5iX6OBS/gI;Fz"#V % ]gtXpj"0ĖH61k(;I<&M|}=J{a~#Ckv-4`C~H| K57NOC ׿EM_VIVvW !q&abr'_oiӆq/'áLv&fj~&s + \ucPvwۅsC+9|?1+#{XYSJ*z/<|89CK_ߺ$ yB{>`JEݩVv@/f ԝ{:܊gbW'=n3ťO+֫ĸV^pp}InjD`QguyQG>W r1R_Sw*ދ07и&UȠƇR?,Q:{qAeɃ (Q76*s!$+ `{ܤOED\|҇@֣c 9XAkN~PtnR(kOªg -ͣRV7D̩=ܲև[/Џ^$I -wm/[9bހVY+ L)} \e71"D@Գ% I|c cu<70Kn75a @ O/4f{#epž#`ew$+{i7_m¡tGrm8;tecF%ҾbwG͵>A Qft1SB?2bU@ۭ{m`fC:J(OD!v'+N%m&-_w+?ffnA:*^ؚ(E(X}c 2/B_̐e3R3ؙ k ڄúа(i(T$ulQҹXPVxp G:VSڠCγs[lA#3O2p(%z-V]KA,c&ڒY K^AV=9]* ZM- ~Z9bN*jL#Jwo]&@* _;`.;H K/5BׂJ7+ H5y1ڈD'uBT'V,@dәӥ Ru22З .@!Xؘ8y}: Im%ٗ/}G$|:i{^sHe0fzOge9\6b[Qv? ygö?!uz{E!YfǬsO{/K2fpZG!3ta"ɴ$^&.vQ*KBnKبА" +FǑ۟g3Rzְ.w"`Y%xCWE1mh$1{4yg;嶐v\f}ݪ ^K x[G>n2XPQA_{ynZw%FHU 54xWJ|v(gL% ͝E)*bp`{7=(h 1x I4 @;iuy>kRDyQj-ߌݙ$3PV 9l`'/R-!Zu)[OkHZ~$67R3:ez].aXDRXFUQܮ)5_Z8=)w\?T#ig˖K|ЇyTR ٴ Vރ`N*W,k9xeb9ĭ>XEL\7o.^&7,aw@dq\8rΰbO"'eNŐ[nrGV5Iftr_D 䉒 #ly 5<D>H#6z@AU8ϥ5`'FLDZP Y#KJV`& gEY9AdP_if9n.{ULg,^wL1/UDV/׈7\Oܳ-B).sזF:b,$$.cd٦$Hz!Aq^kܦ{,\;qZ#; c=vMb0i!Ҿ\f Sf2]qcMQEmrZp|6F| YyN۟@!+>dPA֥^ܧ>7T$jк&I]M0to,0JKrg\1IwXO^ xz66;TԕӒe3s]ެG,%o:z-ǖR3_i<35U,3Y'HYZ̩}[ģ+ mҼ+zڤ2 P@(#[?Bh{4sK,6ւUиO\o6=ej~9鿓 (wE΢Wbʕ&% A}78lDC}4nI|:3 g>[WнAj2RZNX)Kr.wΜ+"Y1’S( ѥVm]e(L~J?[X֨SҩZ/&EYc ngrM]K/Wg\xBhKеe(n D]8CW\LkUWמ]L$!ߐy`4<~gi=FPvO;]kR`? :}wA-Se>J>lu) "o|4>6^vu̪Bţ# њF:C7J@ӵ1ᓧя=u~hlTU`mQ#>}&ι޽T۳vmeH&i) +JsdT鬙TʔEa9-E5qI}T1exK3;..}Cb1NjV F.&l@^m C$/(t(?؍NǾVmтQ<-E'a2 +L+ ]0+٭Y( ! 1ON<!zs^!lT䛲s#]6ks-=#^a0:O|NX-5)TKBVMl02[18o M>CaCIb,:Y UBu:Ԙ G:J}2D4oEx<ɢg+ގ ڭ]rvLk&4U6x+p#?84t4fë%O`1y(AfrH%ZJ=R tCO4 i+||_% kBN6.>a5k<1!9dSҢ}r{SF7%{_MM8[>q?DS-pALLఄ=}]j? ˷wRMe7Z?P W6x@6@ܝ'Cb}$ ccjfpl^TS>^B) n]$dTWTEO*؁i/U6D( ,ޒ:* [#ޔnZD>p ؁M D5eRRwK@Hb". 0 :z_gdAlfӒRhHYp˗^rb!TVĀF&j$!]@(nC5宦T>ΚYl~zn vA|윎C-DħJv W_@5"@KTa Gsv7eu={W&el.~R>B1*C28flJ}r &.RYj,qC490,- %-xcqMn:_5dK I>žG%>k 1jH.^gO@;kX͕8x !ճ,O5m瞁,HYb2˻:#J8db0f*)-ߓs '!1^u*0(VNŭ1M0\)r9`H;8Ec!8+w%Rȍ`ԇޖx5fi!|änQ?f8aVW,*sV^PպޥzƦ0QQh Ѣ=Fl#4-xPv {4fE3#wԮ +Fgl'E:_ҩ ,'nDlz?e÷Zo,/@M:/yU<עhvHv|S+kia HoI#?>n<2!9¿ doeCC!Νn%-,z@o-gHadWe 7|hԂX F% 4Q]2r^:"(e%:1iNCRںS-RجzsR^h`y-K 8"3F$tFBVDp '$hYe |0jfÓO^iCP4.勰 SkdFxΏQ /I4B -d  ;NXEZZRrYk%eԋHbB ׏z nEAD޳W 豃U2YG~.F[*2ډb^ 5_eb<ȍI ;:y8Ga{><-"偐َmGuT3u5(ua8{hޟA6FVOnG~uxp7 z@4ށ4R:%w5':pzJYʸ^wxBaX7ݜ /(Z/F"' Cxs{@mƥ#]/H+θW͖*z.Xb av5~?gN@Wna^ t"0 9z{Wbt3`of/liv>G~_Hz3f\>'K89$O_/m #BChH\]5Ĝ^Dj2z[VyN * " f0.<HVB'UvkJK(\*rl8P똎aȭ=ѕ^kd$ /oiV$%"!^5hmu@nrd$>7~%wAoj갆~h!JM}j5gv_E3{W@^sw/jsN`Y*% ܡ+l~35V1G-@TAE)Kii/ , 8;/_=Dcm[[)ޡXݹᖿ@{hwB ؙZ v5 Ov͉Bv`uv['pM (in&~>qb[BXt45 hv(#YC?˶n\Uڴ{Gˁ胸+;8[m6b 7}<,P/s8I  ޠZcئ4s ,EmdD4hPZA;4?׮Q7+LRf?\\&dJ` ٞNaҖ'j+@VM] ;G2Uo 7XU;$GOrTkT3UKgg#Bǐ;rv7v@m821T^]Wh̺Ao̒CY+<ltVNDij4>8+39t[`ؾ6v2N|g)dj#}]7.p Y1JvœSrT0Bq]c[ˆt<$M^ v59suU^+Y䶋vf(_ zw{Nke3T̟r4{֐ۓ2bym"P ޾gуϗ;rbHh^.aW'6 b{bÓ%ZUO#AW{^@H!DJz[$b1:௧q'ĸd9r1U俿غG.# aLs1hiHO*lSYzIՙl (ՂYa=vd?C~d0VfpbSrbPUDno!/sٹ8HZCJKN\Q'^ }9vMy9x M>N='w< }\gZ2fA2W"'!,z=gA[7RzMξhg~4X\gZy(F 7I//]˕M@\f",{,݂ enwx+éfF0B\>?+Ž%7T4h7u1)A}vSt90tY l&zoY" .=V[i aLE.A7Fy56S(=^Ȍ3~kјIG+Z\ޫl:+"ƖhSJqJw C(EvCBWf5}c[@lԫ\ĩ}~A5~ߌVAN27p fI@MFM1H:";{jvBd̝gW;ϴW;/'cդq!׉O.Uq?qn(mIKZ6,pF\ض˗ά[]NH 8W)W!BUsJšsK 6=,3Ċ f1 ʶGD$R8 3DI6ԏd$|d`r_F7Z﷞lc>rfr]TLVװ'Ѷr Ӯjn>ʍ +>8ց|oN0:~Fv[f /&L6S鏑bNH6jُI%wR#%v'-V x̾qv#G#rT]#x 35Q9lw1|V$b1X}Ƈ~΂ nNe!%f]ف_2+PxOvK?y rlN4Mi^CW,2Z3:r"%s8AEZlƝ>.+ȧ)W*<%S AuG5 WSIԭ_l,df|*>6X%P;,M 5U û>'Ś‘e?{-`rzϹߪJ8!Ybt[{anqi#w+€V^n-i`^(t<3EzLPۨ'Lr9(TFѝw([/a4o4q t,Ϙ34H] ,!N<-(v N$ZKnanh96#7])&q<<=b%" g <& .̦Mjc,VnP= uikᭈ!)4t{-?>^FG v\|mqzYx8LҔ.Dd:m9$΅3AN{ ]lx]<_FLKLpPm(!0Z> Gj|uT9}:t3qY\#y򊈉վS}_w_%,e.??Lr?U%~~S& $7'ɑ4=tR#^WUE* *vbpm_ݚKQ'X55ƒ ֿ757'j,6* :8"NhFtrsbBB)׬>sqB!u:҆=]-, Q!a̕I|5$܂7+2B BX}y%]#2t󑖺!F%~=9]:ʲ5izjA/Wԇ~q]"LRH2~ :i/Z}u|+;{M&<%vosnù!7;NKe`Oٸ TMh/"iy秩ZmRs麊Cb[>I5>]WT|vG0;|h싄,θ@j5i(Dڪ3BhtO^[ }+չpn",U/}@w`APSiZv9z@W"J9>PcwK_jjw BqTZ It/fkU*8 UX12J'=ĕLկRǛ=`|ɝ&_uVM4p4&OgH@_-$(̠XT~ŮhsЇmQ[۰h1ZY=BXWR_NIx  }Wi=SCCPo*}l  C 3{g4W(_k d?ЯedI6>="flR+, bWH4TO~& 8n&Y!VvӔM?Lѓv% `GpQ~j@r`w!w(ʝ\XKf6=՘ WY)MRSYϩ14OHRӫy:n/R;>sg ,MK1 ~-zDtaZ;^H We4Zfq<RMș.0Ya Ru]).+]Z1ZBֵ\A GUc!.9"H<7i3~LԿ}ekJceč.DR|@O Aֺ1k8.!1eJM"t0-qN(F'r?fE,݉j^[q,."&-spS ~y"zdK|>\&(FgF:L1|Hqs[y'ra5Ϣ2$l7rMs0_mqovebg`"WgڕoฉøT ,XXfo1u?;AŲj {wroQo·_gbÝ:lMe?Z"@@3#nTM+mw]L_=bFU3}ng|w Uv. կ?֤= ĭ'*pHbvvAȅ[`;m ]蔼#[P$qR[) Km61Վ;m7Fg3VsAf`$-geqԲՀԲ_saݴ0>D5fIUhO:EM?rG-~{ųt>TxRׄ80Tsɫ95м%0ڰ-B-?T6L.p[?u|I\B#RakuA:"K]H2R̷) ֌](G7l\:9h M*q%_zv6V" eS`?d*e[Sܞ%A_yy\Wd ꃶ]ET:C~kƮ*YfLJVWC;@dLyJ{"\+Q PoR+D{ Jч*85%|(yW\8)ΰ~A3]]ڸb\1UCuYD|lq?4F[F8ڑiVM Wm@eZqX;W+ʷ#C''Q-bV4IvE" ^tŠ.*z|n(N'#=pW+%Wk8eQh_bw@/ }*^tn{Z;?0X Mzofyt-'7=$C}=Va198FrM`ѐi\5xZuoNA $n]SGvcUY5CMH~{z5^槽jU *8Mv@ XZP] ߭m>,m!wEu%g=pzn9=v_K *Hm߻&>5|Buwuݞ-(_>DA)}\|=W*jfspvZh! $CAHiQH(؁9膀b0髼_d |b4%{f\l׽ou wUbw5-; am= 2uy7?0b+پh PFv+Fcgo(:qРcT):U_)._X‚;*'82MO'8\Uݍ4\h$F@GM,/ 'ʐ`i?> w Yw,r,8+?i4}'J5wSr"@ J7]vtj' >-VAZ$;Dn.;#a5.׃q{P#yrp)Kʕ3Llr>_s1r|vnjgL@9f,3Tբo=I㕦yW@eBV𒂯@(v YfMkzPfI:mBi00]=`W2{3$!y} $ Lo :809ҼzIF*ہSdmYjPK>#6/'EoYZiQMmCIpoZUm# '۞ y׼13{V ϑe=&g~\p"@k8ROK; Hi[Zǒ}Q[ܝN @(bD{svYCQ}#;h u+x0 gx૟ǹ 1M^j;[F=o5:A_?}LPav.oq%Jǂ?V҆aDclXe ,AlޅOMl툸W(gD<@0W#L٤S iJFs KndeFȆ]w^Z:h%\C2ecnda6Pj!K=jsלIAQ30\;TBt-Ԯ{-a֔G"E|}n"S[Kǡ/JNT$#ޥl*z=enQGaA֤[Ωbԕp x=b& *+" )ךaj8w,p ƱȨ۵qDiZ{F9}l6yLT4kq4&$ |_=tӫ'٭ 긴>u!Al`" zV9k 5ڣ[8 C#Ro.r !ϔm-{ehO\O`0ՐDž^:+;(}S*:ӑF/=>ᶼEmˀX^G; Nfڟ1U2%{c)/U2% !DB84_"j H^Ȃmi{ r턮R3|kC{r lp~Ikb-TŸ<)3ύ )<2UݝHzFl 85 nM2@ˣj> -`d l׆Cbl#YG~[Go/8Q{]_'4m.U*Tœ&%%vrd^n=99Ok|,=*T 2jBI?Z (8%4ɔ9(J a t7EǰB`ESsR7I><_$ۭOzW";oנlJy\銛ni^lſ*Rx !XpVN3ZldP4z觝 N45|Y$AB+L,`U0 A .2wwER}Վ TF}莿`iGDz60&n{-: PC0R;؟;#f^wF!T؏* E6@{5#SCw9?<qaڱwY? $qc*qgUN]0w@ ޹:K-lcL`5ş#a2AƝ(^G s-O gF6 X*8a=mkϗY$%A.i}:`[ JZLqL@çw O+0O1}/vb'2J/MG%ӫv#finu:7 ÕAU݊܌.H$@ -떣 Z !,3[La1|B?ٶI&T`  w Nb Tky ECp6®QR-Slar 2/?͖ɞ{q /eM{/- ֣RG璈-6\(4ӆ.2KVTfJ w!\/A|ޓ(MG YMc3drÚ|?(\-XSs)CU{^^sXj}x[tw =0 *MGa0(|ԧI>39/Pt|`)s\'JYѺ,jYULQ& ⵅ1Hfy B,zN2Dzʮ0k.X1ଥdG%y&.fq4LO;@MSAҎB\E2_(g#o<vVт~Kr>kFC12 :%_n-Ӛ_a3;KnT%JV2d87EtfH%ΊsAh(1G)/GE([YqW޺5!e¸u-,gB{Kv |,sF?ƃQ 5ЉtRqX]AOws}EV)9Āo1?_%A4kHkx}<6ttG$)GZqmk>Os8WahXOב@dYڎ.>`@Cz[.3+v(7X sZ{iI7CkOtx?&a9pkBS~¯Z3͛ a8`;[Ê28=S6n-0+a&2d&]w.nEX@{ 3Y* ?VJ6g(rxQV>Z=ˌ'vNGM͘Sl+ؠ `pm*zC ^dĖ/G K$,T _"ps2iiUAWP ܖUOcэKaŐitWl$/B@ DZHDF02ynRe jp׎Jc//4Q$"7$\((`n`2ݖYZc%a~Jwc{>޴V3sCZvvURQxg,w IU!%!EqŦJa(&abp>\iG3%a'\OMJLa{9mT ϞnWAT+6eSn증0*Om# .{M a (x;]ou_^}v͖͓<놤kTXZS5tP$O.Q$ьIÃ]^j7DlDn^lLFó;7i纳])qt 7j6'a@QĶ]Th¯%cnpn4Oil0cp!MǽȬًýDJ`$7ăo,mu#L2!ʘ2rld+`!0hu\'q7)Ubv$!mx-_%?qn8rofY,: %5쮋|NLuK5+ 1dDwhhВ $կ#w?% `]N,٬~[EH_)xW_zyΙU>mWzY)L[4?oÌ4dBC܄ϧt#P_7S:]U@1b 7]nĊnEmP^GS}29 \2NIBXr0ZG`6S՘ P-021G4di3Mb_Y 9\+ϢMj-w0&"${'ّ ;Ge'tĖ<6dXpn:Wl]_^ͦUU#F8Q1G 8 <Lɦ)G"(;5 ?jNIcl09 1߳JoMٹ԰p od?נّEtЌy^#,'1HX#3 <:'8r\y1y?C>7SWQ5lQ`CTZ)]Fo\aqݣkuxu= q&ox-+Q`x_foﶘQ,yvᾛ qĀ@&Q:=0iEXMƞ uivE!eZi7(D G<*3=_̹EKkSFJǥpB%q=udn^A\Dâ3*LBcЀww.D6CQxioh a+=caj7qܞǮ7OE^iO q JkaRiL<Kg!30 Ҷ7KqNRͪ&֧30mqS3CȳΝ}| wg ^b-b +PދLV:2 6U3 ݹ+CO|QtatUQ\#Lz# g;Gi>wV9rp8H?s ZC{gqmѽ2eǫI@pvOʽG}1Y IH HS3J1d7!Bw-# *&F5D>{iLc at>+)e!Q"rF Hu5ⷎ-m"n"p",hx5 19J!~Z q4lʿK^=3Dx k3_bE5F>%Ʒ2Q 5b 9v}cFFsû=Ġϗ~#iP^n絤"u©LY@m'' p {mdy"ߩڅ}Zmj۳,K҄jc9MdAu]hIиimZ#ϊy@y>s1KF{O1SX(< P\Lq/v߲!>acpSc-#&Et(Jk/fj[}DhѝLٳTsK]wycRR4=6sFP'ўu  V=u|Ҽd17^Jc R-RH>,ʸ9{Bh DYaFk+E&4v Etg yk`$^j@:ژH,46MOYXW<F:J s #2, WcRoJ3l&$T{GA,oVk7}5'PY%@ $:}.S=!>v ;C[2/th ؑ~G~L0h&L;\rrY):dWbVߤJi/A_7 ަ qo[v]lDoYA (ˬqpdKʝ{VmpBlzM(a6Sn:[Xoœa,QdnqX2@_[O @C;+Q}m܆sPGk;Ptxz&z= [WƢyFGf+ ɽ}}AѷQ ED#m$w{Bxq+@}J1 Ǡ>1N]ܐѭ7S/ ]W3hR JMN/>xF䁖:O. awgCHD. м`L1jMZ{?<0!/n!Q|D͑i"Iat@0D> G,b>XGndU+U2-z?ka} B‰,h?_hPv?n90ŞVO痪=50ߟͤT,Z*cjٿ0q\x;CvƉ.#&Lew%5 ')!AG@lj.04QWEB;Z͊ Ș]N!d0;W:6˜DULV3^Hݘ)!/g:M˽tbWUXun]=V4T&6[q2#͌[L|r'쿅=1]G1C5[fB~/Jp.'.ecqy>M낈MH(zu)P/~.xi5B}6Ց!@y1$SG(9b okr>./u$KroGz0祿*F>x ˋ~M QnLP]H% /ΐ< j. qK$P9kEx:7L x?[paQzaY„,@$-jhAKk.@PMDt[ۅPCQ.ڲlvk}$ϲ 2OnQqsMA:UO}|+aU -:bhT(ٌ&tP ucΚKyh)s;Wh<T0FyN/gF2Yk9 w?(;xqgWMf#/|TiX:`1#;DӔ)Գj!52 P6(_TR)q?*0WE}@H ]sgy&ddΛL!r=&U?yTBϘWkkᖸ/Rۙ"AF͢iN 2yFWJ2W AFUs垒z!^6b(p_@]]dfXXnd:,}Eex@.-\%OZ3SI\!,^qsHJ7p^5 V6OЪg1?C%Uxq>]X[q^ezNwSWy 4xarbx$#`Lu|k.^ :|/ȬqTQ H AYW[ ٙgh 浌-G/j¬8_6:Xs=0S &;64_1= &s\dNъ֨RoR"'et<]ޑ2hc]i9YZ3 S q)z'ľV}z[4+ 4[#8]%<~C/ X4\MkdzBS9=i[],"i#y} G==7I*vcYz+:Q-v` KZ_cWN,gPK\ 3̆izN#.~YZ)yi9&dϦ{=@ Mnn|9m C-cT1$ \4\ӻn4  &{zHf!„O#OkZ/u$jDh|mdteenwwֹN44 }LBnېFd736*_=XX}?,PД:B(4,]Bޘ򮊟D6a7+C. Gc[3 ,jHSjL6rad{F13Ws )pxG0UQUf&D_S0&͐E0J ZO`x^P&DXHw6ub OUE PBی!!)˗hѱ_7*^ji#,2n(~PdJ%ڈFҘj;.g^zRbr!ښȡSy:~WH* Q-5g'='kΞ* W}!4ح+bb*5VWvSGsTd Xlw^>f ;?3qJmU:nSxUt0 Q_mqME?m>5J4Xھ7S#8^:X !wSQ̏."0E )R< dtT.#p/'eJI54泀/:e-zueZT`6Lgٵ7>jzNdf7{~SRWt 8,̠F_0aE7۪YS~jy]3/2fz Qz91{^ ShO>|bÒdVo_Vpe 8YYGOUI Auch^J(:H VdiO{n,Ø#b.h y'zQ{{;ѥ~Ŋ <L] .I8 L>`Z4Xq4jtgcM/&u1(B7>ˉ=:]GMWe$S O, Spk/z%YL_;!)^ք? =dGΝ-V~KEVac - -Onw6v\q.f-<@km鐭]QTeVR9)1MvxZ=ž(e.j^q6KTˎgW,QQԊ2HH?. c q~bJd~8 spI6uӬfʄYʔx̖G 9Z*QA(aM>#jPU[;|z$_1Mo<-FND {cόYg~Pϯ3YL<]Pu};%Z2ae*}M0v,EQ>m>u{wI#V,W 9d;Zy_hH1v;:Xld NM3A̯ 檭^qcAi0%`Cd̉pH@.b S(xcad*o@o]K:,+rn]v Olݓt9Gh\o 96zpA sp >[pC|GΘއ w3n aMʔf~78|ܤ)>.HZ7(1я^ҨmTyCtB x2X| &Jxw"LN"r`W9QKD:)WRi h4 9mK%V.KywN~-8}Iɓbq"Kyq^^$Ew4P$0A;< xgq/T K]E88 | `)-$ifFL-lA|l}7}TGJVu2 Te=ǵ歒e6%;nÆ,z`ў)_,G/*BzR.Oy9UG;;5TdPƷ#5\BKsb[4u\ %>g\Kl6%WBw/%BT ([fPf +{1P-'rX]*HU<n1RE/ʋ> +/'cS$-Der4HaW k?;UGtF,/s߈6Bu-SZq@ eں׿:TNVY#<>:>^^hCI SZ&y?%1*OG,񣞃i-\7a1f⨁nOaԟ Jvg(\0,EiUىDdZqFWˠ(~8gP"Zg/nz7ۏi]SrOܥX z@!kiSqwbQsߤ&SKbH#[ EM7b hKMh p{uOxz+SC !ZV~Wc\BLe7q`|V)wwu{1Bh8p˳EJ']zd'aGoC6Q֭dwˉ˄ʆK+9q)E8_CV enBT j>.|/l~$V 2~S]6[؜dowy%1J뗕Xo z`84))Ϩa%K덯 qbK(3B"͗DJPד}Yа{lC{5NG`x! d/@!%>(is~Y%&Έ.:=)W>N_lFYp>Qr8y ު}GoSW%y|18^jJS梗VVOt}6Rҍ S(/wR\ZpÑ8dk ?|ev hVݡn6ٍð`+B Fo &>ʉ\2I0LЦwuND0 ت4@PГ$b5r|4!H}`gHo޴ 1B3B;pό_+~:=^[K)=ŧxI>@̷|:l&RF摀 Theq0㯪ɃXc# Bg|b|!'Iי ^bZ<8L4ۡ"f\ c<Լd_pa5m$U+r~|h^Qw \I\BHJ܋\ڗ3Wi ]`# j^ _?%FsC.kT AkyyCbx> !hu۟(-ؠ TP>g7ـ U2w1 &;Nj5dlqjV2u*% <渳>g'&MijGW}bDtH]n)]|NL=VQpk/C&) $iOlPuWn{s:Tmohav5ms#d ~k 2Gŏ3\7]Ĕm ;䭓emiN@; 2%^,ʹ7ɝyo& |$;UNYdzYoa'%0koU nQblɵ7jSth$x`]<$Dc}Z v9aIe{E ǥly(Zmߢocf-23xT 'jdx%21y$^蛐cWx ^@Z鯥`!!=}% `I܃O2GDL YZ