samba-dsdb-modules-4.15.8+git.527.8d0c05d313e-150300.3.40.2 >  A cp9|nn@I/X2.\~_m%ȏ uJDfϳ,>b$<59=lRx&'߿j$'w˞rCaxR nF~ׁh>/5"v`o!841 s?qcjX_o'5nTp lX p :[VLQz*:"*g}.9쯧fi+P\)m"xzi`f 9gݓU^ccbe1c7935af341104a17c2b89c265ef598e842ae75c296b5d2a920bab969dec7d7b74f28d7b59b76e0e041f13d586e38a165b3c8Tcp9|&U 8̺`E4 _0 LU[o\gʤ1dYհS+GHs>:Wa[dJB͘y{M䵇LFJyO bʣ,H2ӑQ ҙů?"Sg\sIznvGYcKhS/J]S9ӭ4(4J{:QY(j!6~] F6uҭ`Kc\R+hsv9/F}q .@9cGv:Z>pAl?ld0 > P 7NT[-x- - ,- - M- |-0--,-xx)x(*58*<9.8:?3>;@;F;G;-H<-I=P-X=Y=\=-]>-^AQbAgcBdBeBfBlBuB-vC`-w\,-x\-y]zlTldlhlnlCsamba-dsdb-modules4.15.8+git.527.8d0c05d313e150300.3.40.2Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.csheep25?@SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxx86_64rm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigX7Hxx(h H HX(x(((xH@((H88(8I(WHYH(((8(HG(c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁c߁a8367a31fe22838d7e9df7153a7d8037753111d2faba9ebdfbb72ead9f6eabd71e940cb5e9955d87195310de972939c42c7c14c3b2bb100b6be3caa8cfac6db9779ecc9de9d6ace7cc04bc8f8e1de4b92fa00c49b5a177cc6d2161c1841b2702bd6ccfd515a686355f07f180a58faf523787352a18a9ddc7c3a3c0d66fe261230bbe68c3ef738b5bbdf3bb36122c56f5e7ce4a63e3e67c9a28afd5b07fde1ead4eaf56ac7d5bba12d8e16fe9890992aa434cfb56753d311b006e78cf7ce24366d2fa35b202baa42b85680c86e8e4d00aaf2d1b8d27ea3e7938e9997a4fa969c1af15d06f03af807e14bd119f1a5ca020a35c46b73c9ccf67e01c51144911fe15c47ab68257805cd25089c0608891ce905cd54217d0a1e8b88c1dc3068c4d0b0e627316b772c8f283e73010f9bff2f8dbd4e1052c6fb79dfceba4588a3a299755d1d77ce699d12cbf5ea032ab810f61f9728bb9e0d183d10b9031701637d9fe86c7b91755909af26a930d4933999e64e81ec6e94b7dd89dae753879456da24ebe7b39910b15f5f50944ca5ed42db81c894c2c341feb915e722c5621765ffed850f9bec33943840bd090494cf9e2aa47150f21007e97b4f07075540be596bb742eae9dffc567c48406a7981f4923647830e054e6cffe7f846630e70c06764e1bf1b1d2a0a047cfab45a401d2e800639ae5eba9af9eec4e13ef0daa4609a560021776ed310971f8c4422f7aaaf4942455d47c307d0c75d70d6f16adaa2e75d808f87d0239a57e7ca360df3ecfe40319622b396b405efa1b78d162029786f4c7d98de804880490741ac906e0cf7e0f1609b94779bbe7f104ea0edec4014755f0681bda63fa18b5e6057bd12a4fc0b21adf1ddf5eb5915f8a2eaa3aafa525502537e69dda481abc31a992f0f549216bf95e608bbf80e0b8a1ab338aa4abf050b0ce472fafe502742dd2c5a947565e94161704b0a04a12123430c2ccae4f38cc678a06719101bcc81292700afbe53eb16693ca047b89d428124132466bc71e609574639563968dec8470ecdc5ff2d87f6bd8226ba3394fed7ed712632bf901d30a41544c60a92ca1dd480b06bcdd259e83a32dc2d43dfe77125e6875454d0f46a37b3db56a42d524d730cba55b0b81544199a408588b9ebe926125130a8fad843896cdfabb26d5c82242cac27c297d122f88262d87f815ea5d183889ba5ba40340f4deb995141c60879e8daac6c753c83e11c1ea569961c13b2fb4103db0999ac0dfa9aa0d658e296418e5abaa499531a89ac51c61fd2907786713745c80d3f411a0a06d7ec4d47c63a95dd49b8275d9f23c1cfbcf03ecc6920f7f7b34686b8b8fc9cdb136533f99090d4ab3724c4d63fc27688b560c1c92fca1a2d5b1b1bd727f03c0616cba33df8b1e06ea6c5a8394c8c178663bce51442e36996fb48a7e4be05d25a3aa9428a625e048ac306453f46b23caaadb1cfac8003a153293ba77e6bb82e6a0742fa503914c7f1ed479c6ca5796e44d34ec3773452d73e8f2bbfdb101bb3d5c4519206b7ba07b5f1105b858a9bb7b6e3fd404af9f563ccc2fbfd7059062318c3b970197b1dd081137ab835034b60b1c6d43c4f39b0f829ac58beffe52b7fc3b5341d5f265eac778e2f7f1403df6e8626a7e2d0319cb701bb768c2e66e6f576f2428750868c5af3498a1100b4614d3800cea963c16065a9d5d9fe7889874aba6be2dabedfbfe955de8c11168b91e55edda1f165fbbcfc4b923b1b57150b9f87055bf9df9b51f1eb252fc11b5da2257b34d00b848d7e05c12294f96aa05bd5570783766495f067babe0788f5fa312dc45b7900cedb1d02ee0b5e2a35c1f7a76c0c344837593a83a9fb4f6f42d3ef54478d853b1e21b9df3214bfcf0025b94b517b77f400101a521b94fe91a89e615506cb674ba9bf516b8b43cb11f57d844e3ad3fbd1c045911af30feda9e7a613a0ab8b86d93c0388cbd78cef81619e5d83a595dcba571ba654c782f645d412163a0f9e18ad0cff0e049366de2d842a4ca34rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.8+git.527.8d0c05d313e-150300.3.40.2.src.rpmsamba-dsdb-modulessamba-dsdb-modules(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfiglibMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb.so.2(LDB_2.4.4)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150300.3.40.2_SUSE_OS15.0_X86_64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.33.0.4-14.6.0-14.0-15.2-14.15.8+git.527.8d0c05d313e4.14.3cM@b@b@b@ba@bascabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Update to version 4.15.3; (jsc#SLE-23329); + CVE-2021-43566: Symlink race error can allow directory creation outside of the exported share; (bso#13979); (bsc#1139519); + CVE-2021-20316: Symlink race error can allow metadata read and modify outside of the exported share; (bso#14842); (bsc#1191227); - Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- The username map [script] advice from CVE-2020-25717 advisory note has undesired side effects for the local nt token. Fallback to a SID/UID based mapping if the name based lookup fails; (bsc#1192849); (bso#14901).- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899);- CVE-2020-25717: samba: A user on the domain can become root on domain members; (bsc#1192284); (bso#14556). - CVE-2020-25721: auth: Fill in the new HAS_SAM_NAME_AND_SID values; (bsc#1192505); (bso#14564). - CVE-2020-25718: An RODC can issue (forge) administrator tickets to other servers; (bsc#1192246);(bso#14558). - CVE-2020-25719: samba: AD DC Username based races when no PAC is given;(bsc#1192247);(bso#14561). - CVE-2020-25722: samba: AD DC UPN vs samAccountName not checked (top-level bug for AD DC validation issues);(bsc#1192283); (bso#14564). - CVE-2021-3738: samba: crash in dsdb stack;(bsc#1192215); (bso#14468). - CVE-2021-23192: samba: dcerpc requests don't check all fragments against the first auth_state;(bsc#1192214);(bso#14875).- CVE-2016-2124: don't fallback to non spnego authentication if we require kerberos; (bsc#1014440); (bso#12444).- Update to 4.13.13 * rodc_rwdc test flaps;(bso#14868). * Backport bronze bit fixes, tests, and selftest improvements; (bso#14881). * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal;(bso#14642). * Python ldb.msg_diff() memory handling failure;(bso#14836). * "in" operator on ldb.Message is case sensitive;(bso#14845). * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED;(bso#14871). * Allow special chars like "@" in samAccountName when generating the salt;(bso#14874). * Fix transit path validation;(bso#12998). * Prepare to operate with MIT krb5 >= 1.20;(bso#14870). * rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb;(bso#14645). * Python ldb.msg_diff() memory handling failure;(bso#14836). * Release LDB 2.3.1 for Samba 4.14.9;(bso#14848). - Update to 4.13.12 * Address a signifcant performance regression in database access in the AD DC since Samba 4.12;(bso#14806). * Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache; (bso#14807). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Address flapping samba_tool_drs_showrepl test;(bso#14818). * Address flapping dsdb_schema_attributes test;(bso#14819). * An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ;(bso#14817). * Fix CTDB flag/status update race conditions(bso#14784). - Update to 4.13.11 * smbd: panic on force-close share during offload write; (bso#14769). * Fix returned attributes on fake quota file handle and avoid hitting the VFS;(bso#14731). * smbd: "deadtime" parameter doesn't work anymore;(bso#14783). * net conf list crashes when run as normal user;(bso#14787). * Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7;(bso#14607). * Start the SMB encryption as soon as possible;(bso#14793). * Winbind should not start if the socket path for the privileged pipe is too long;(bso#14792).- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigsheep25 1662115781  !"#$%&'()*+,-4.15.8+git.527.8d0c05d313e-150300.3.40.24.15.8+git.527.8d0c05d313e-150300.3.40.2acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:25692/SUSE_SLE-15-SP3_Update/31bcd539228044ed3b978b6d5b198532-samba.SUSE_SLE-15-SP3_Updatecpioxz5x86_64-suse-linux  !"#$%&'()*+,ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4390551a05bdf664a06f50fd56c09841d4d54cec, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=de288372b34d06201696c0de2d21f7fba100ea0d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ae234159430fa8a9b0b0116c65ba7db6651d1cb6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8b706e1c47e872153df94ac002df124ed448d1b8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=61f7656f7a5612040fb7a04927f867ed831e764e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=00d4f811d6e64cc155e488eac76ad246e6dd28d8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6633d2f6c4941afa8ad717e058942476e3deb17f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=242a2fa071af235a8406e9df460b15ac6485954c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0740149d034ae20d4a264654af5fb4a5d0db9f35, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b426ada63f1087c65b6ac0e80036a1d7b84b1283, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ec538c239f368da36bd7e122a1af9a82abffa6a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3761884f7f493a0dc0a5993a4b2c4f51647b41a1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6fe7548fd7cf1f8bb919c3bb15b2cd87232d653e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a0852779e222d594f0b98f85bf843e2fa73ad404, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b401d5e7ae763e0162dd1aede72496cdee59490c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a237eba29ebba6da27b10136c45db74eb5868fe4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=656ec0eb67c17228fbb853e2db2442e240afbe25, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ed64878486c5353ae3b6a52a1108f812764807f1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6a04238696e7d615ecec91db2e21de83708c6e54, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ca70c532937fc54f5d62d835833da3c56831df83, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a7bb128fbfdfcba67977c92ea544aa7d00c68297, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e1792d4cc59da34061ba470a3025b13537deca01, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b794e005092c5998cf6f323cc24697e121104ace, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fdcd7779d21ea93cdd8e16047993b9ffc3d5bc47, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1e4b9c70b6d1cfd0ebe012c1683cd1eff47f34ac, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4171e76c778060c1666fc4193dab7571287b1631, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f55a1dd24a944246dae9bf8230e5c9e6cc0d6ee1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5b8afec51860f10bbb599acd7f5ad52cf1a2018b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3de3c4cf634e731dcfdd93fb08ef2b90ada4f7c2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b0829f9c7a34e96d777b6f01b95c8613b1bc47b9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=eeb0b4c077776c7ac1122c3290594b91d79c8541, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8e790dee4f85a482d430d33cc9d6ce4d370c2675, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ffcd5a114aa6b43d3a3e189f074458741cf49e00, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bfe49b846aefd8cf91e41fecf1d363bfd635c17b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4125aa948bad6f8b05dde116c736c1fe68089ba5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2eb3287c22fc430ba35591b948047def17fb018e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1b184219c0f805feefb13c83db69d7fc3c0d243a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d18e54b00b79a5748963c8c25e45734a2d60ed5b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3b1e09693eba6d6e75e00add02dbb1409e31fdb8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a4a73b4fad937734d8b90079a5395b5b8490bed1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e315671eb5b2c962c059a36b473e99c5ea8d4a79, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ac685823b0471dc15ff6ab895d1dc16fab642ee, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=26f88adcac7b99d729f0022692743524d17f0c15, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=151f98f7cb85b6de58b441f7a04150c0a3e12c04, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5b7edd9c47a4e9c86cae73c11712553f222c2845, stripped9Gev+FQZs2=fs+<IT_r   8 ) . #  R_RR.RYRBRaRgR R R RURHRR,R2R0RR^R-RGR`RTRRARXR+RfR/RR[RHRYR_RBRaRgR R R RURR3R8R9R2R0RRZRGR`RARXR^RTRfR/RRBRgR_R9R0R2R R R R^RARfR/RR[R_RYR]RRHRIRRWRgR R R RURR2R0RR\RTR^RGRZRRVRXRRfR/RRiRYRgRkRUR2R0R R R RXRTRhRjRfR/RRBR_RgRURIRHRR R R R[R1R7R?R2R0RaRGRRZR^R`RARTRfR/RR_RRBR%RgR R R RURHRDR8R2R0RaRRGR`RARCR^RTR$RfR/RRYRRBRKRnRRpRWRFRgR R R RUR2R0RRRRERGRRmRXRVRARTRoRfR/RRaR_RgR R R RR2R0RR`R^RfR/RRRORDRHR'RgR R R R_RQR2R0RR^RPRGRCRNRfR/R&RRBRRaR R R RgR9R6R2R3R0RR`RARfR/RR_RHRBRRgRaR R R R9R2R0RGRR^R`RARfR/RR_R[RBRgRR R R R6R2R3R0RaRR^RZR`RARfR/RR_RYR[R]RRRgR R R RURRaR2R0RR\RTR`R^RZRRXRRfR/RR R R RaRR2R0RR`R/RR R R RR2R0RR/RR_RHRBRgRURRaR R R R=R5R2R0R%RRGR`RAR^RTR$RfR/RR R RgRaRUR2R0R`RTRfR/RRgRRBRaR_R R R R2R3R0RR^R`RARfR/RRgRR_RBR R R R R2R3R0RR^RARfR/RRHRgRaR R R RR?R0R2RGRR`RfR/RRRBRHR[RDRWR R R RURgR_RaR2R0RR`R^RGRZRCRTRARVRfR/RRIRHR R R RgR2R5R0RGRfR/RRiRBRORYRRgR R R R RURlRkR_R>R5R4R TRk=~@y9,yزU6\U8|F:*BdG| 3Էd+g<$(Gł2$KvHꌕ.m&Y`sq 80- =jO8HS*E|ۮs\X"0PK;W?TWTGp{5/ G^N;SPE'㹫,,:?NRzso!䦘r8P#hb>i2/@T 8B \cM"D}ywgBGFySZ,jc+yg>Y!f T725\;\qE滴tyd#VIMkwP>K"pj0SiZV(Sv* ouyꮤ/Pwyɔآ)5HY>n-#FT1;q9IWNj֫<(@l7>ңٰ1n$N4sh)uk.E 10{Lܤ 'u^>WrF#BPS/>CuCy0`fO"䛛(㿳ڙlt$=s"pFhh9%ԎiZECÔߝ&/N}Sf F{a+lUI/k@UA\13E[p)BΫi#q {>´wļ+d j}uUp)6ٶ҇] qaYP_xYd&:*+f:UIKrQ'Қ a󪈕Pb"\Qo+E%]ubtN1 M 8feÆlmDFᵻj[jy ;X%2w-rJJ{FpHe8𤐻=׮O^0%p9zx'u(RtwI!_7BW3*D`@i(>Oadtu? AqIVQ7>ֺh6- ٣X}͂>*^^2MLd mݪr SVaKX%qEMB8>GSeS1JSz/FrAkhlԫ7"FVu"%͢i"vj -Vn v[d' Qj)>M-Iƈno U(d&N@eQ Ͼ({=7P qe #ꏸL2<06花*ךf2R)`W`L\ O'g>ZM=zsr3C>䵵kIuӚ~a]uFˡILv7d4Z::(qq4`)%ۈ)8 3}XNxvm<8S4ND蠃y(Pvk0MmBIaȹ ٫DN$lV J_I(kC"FDNnneR)g' !{.6: 'K*-?IgP%*FK,_qHAl}RjUkwʁY2."~qS(vj*0|%r<PG_jY3fhE=grh@k>C eTW6K,M]؄~rLf&x|X er+2aRoe:>̎u}jZcj)`@둅"j̻=P]x[|v4OD'KDu+d 7yy.J}0:]5)ssQϔ$.Ҥ3י%ĊdR呦qS5 p%^H΋5tQR57O~JZRVU4]ZRT~BY;^Of뤷&Q]CBY+R:M.=?=W[)C:2PB.h_PgKp]ِsu^1+I `a^ -ꄼX* 'cUR,*$5iqN{i}awI>9 e+dc#}>嫻Z:/'oX7Y~z>7`WhN Gu#$UD~4TOZ0֜lN/oSy D]kph ³8?BR\;ld':e܌? y]"LaubZeMi X9$\x/ =`中zF!BtfP*~*)[u;Jї-&DÒ.y=BHK>sRg1(cAQ'>iDC4% eCy߈l({60xNazkO8QBG TyP]88% /,nˣ7yV1XV{#2 ^QtyH\wVWBLtU.’{OoH 1{*- '>*OulاbűbBXp+*nzA/JZX7qJ!f㷦 N$Bjln{Jn=vŎUa_̬:fZcͦb|<o(|f TFEԶX@brjXd[z[V%wľH/} NU Bpc94uW]"ԿsK,j9f[-lys[Ezo)pUek 9EPKgKW%u`[ȟzG[H &܊|=lUiސ3kaoKxl@=|Pso0cn RDtc:wtG$<1n?z19͹,ǿX藛`JtbV*Մ.H0YhQ=[UbE;IG+!?=.b7LO>Ō{u5{l|3Ju{ Da 'd>݇ ˳îQ YwqshYLL7% %Yt9iSٔD8&xqP{Q}@BMvdKt!eU+)1 AΖN֙{]! d.! ̶>dGlVH3\tRC8'">:$ft٠I ;A(P"#<>z5w8  ?HER)WaT0ߎI͛>]9{jխʹ9T;'B1&l5n%347 5cO/ SѢO<& (-.=ӫO^!UµiXai-%dz /{'r׼ccHtέ8tRt6|bI ( :j̮YhP|mfT>V . 0w<\,'}܏-'>a@0Jw3#yB|z;8yX$r#V^bHGMps\{bP 8)7V;F6u0Vu'"DDfJ>ec~Fd~'zY_Ø|O+GkHs4Şl,9ѮN԰S8!"d؛:fcf: TVo!4O\,a+%{ħ[r~STEdP89oQ:ǔ&㜓Sq|!R$4bTs'X7 v%ܷ ӴIRV5eĢc;T310a,b4vvdU;6eh./~p50w)2ƞ }bI36ok#B<[fd?OyLb2`([0# eV^SWbǒ3 6\.K:> gQeN#Ĵs{$KL. NUfBK]iYF(.6 6J{򠙈 遙X)݂+ݨYDR`haVcd.4[n.וՐK{WB[ [uqv ZǟAgo<Ή7lE y 1 SmcV-OMyַ4}m ACH\ Ʃ6oYIyf*#]aQ̕b0d'h2z:.0VluknP9bڃ^h Q#$ ,sYǒ@֗t_C;"iXɟӗr+ [;sFNA =4-=$B&㓪IYd ^E|r9=џI!D f'/{dIE,Iw-15>D!!ם_/L; d1Zg:u~\aC Wm> iŸulIߊ%m"tS nP4xbiH[ɗs]`YSo`f7knA;s0i|~2*mf))Ymow%Guq4SV7&P$&7n,!_{{/Geнkc1d|^#*tZ2SCgyJ{T-#f&좩_XSPX/5҈_VOdh& h CuNCw W8FxR)lvDP@~5p9 ҩ*Xm#qJЩ ưՄ@y1-"5uz`Œz *iu%WX%80gKțAm"ay1)ֻn5_ow2`Frupg]MkIٟsNFv@˩e4FԦ9Jf\ q|_DKPk 55 sPV6<2#([f+bSv}ZLT,Ѝ7R?>Wok1UzB8ֈtItg"hvR OeF4/ӮĚZEYw!I~KOщVPs~?Zl=N"M8wNB [PR|NM$|O*e';% G=n; j hV , Mm;^PaIZt,dVTVMi*%0J8ʁρ,´2\ݜxbIL{4يz)a }!G-N|kH ~2ônr~(9*xR*8Ҟ-ٶv- Ϟ$6z]-{+$k–gA2ΎdǘUp7 0mm MuÄcΘcŹjtЉ H &CnO$<.H㡴*OV=AX#/Ҁ|^iʆ2) 9 PKbU(ί kJBK֭[ҁ)TOKw'J=#!Ts'p X,;J:P)^#etalCn'#PϦf@-{^m\™- ߾ 44y EI78(T`l_ߥixOj~T0{p VO#kAGZ*,!MtW|΂#MwbOanbie~ Z̔~'L@1].|W!=bxz[:}o@8(p4q'1 sO|e'Y!#ty= g;?33pb %W.CP@B m2me(\rmLҎT^O. t 5˹hF|Dc=[ːgq)uĄ>ėhnSEDda&u 4.i^wu>JPT ֬4w~"0OHJQA>ﳴݭ#zz0ğضIˉQTLfqudy7 leDWv~; *?:Ą6~E3'La9oқ7G yS`lZN^k3<\EC8Sijzw|ZԥQآY>Xph4zk49+>PJc*kiyZ[U}ӵ$VgSy!'kcLTw 2qp$Q1i'+?\']4a <[QX@:\|â )OVY-lj7 s 2bc+ڟJ?*dyگg)@%KLɞpD`:[gVa"_b/YQ(/ru:nMCc&=z$ٯ]Pa@  p[>QC("j~KsTOl.9!ƒ۳133?f}'-k)5_0Iaj 9xn74@oHl$ly@6ioLE<+V6r r+3~Nv@DyLnMv\*P۽Dy|nfbC\[50)Ig h/&v%>(I]L-;3SE]2}q>m5O88Q{E/4ox(_MTȫ(l=Cr&LA ]%ngZ7kZ6x\~ RsI̾E#ǁ]jWlP}O}h?fa0 ͲÍCٯOhN.!;YVp/Mk!yй*DC<烺cU!i'!Z<tE  @٥j#t^9Hb~^>;Xodg!ϕ6< dO%K'@0!vd"aPƄyC!)ډJ𴐽VLN*y}ޅ%fw &2ׯ$ڀ Knk/9!|w嵈 KN+ٰZW <ƾ, ڌױ7,g1uAuDe}&T$!3Eo$q2xl,lwӛ'zv"XNC+9:4y)0,B@`ՌgdW.v?f 嘐^oRi1#ΗF6F :KKiǨCV)j]Q`,$Z>^iD0 FJNcƾ'AwT[<!]ᡟ9(RKmI?OG >IIl2L-ڽs=lԜ!\rgˬN> qg5MA}ewZf׌b{FMn۟_?'/Cۘbc,'xѽn:&_Y#䨓70:n]n$oL Axڦqz[g䗣)5N;˂4 ήqg+Z#uoq*1>QAss=B:ڪiĔ*)ULhRoVUj^@(|ݖv:b$sV_ʊT.Z_\z|هs\|Еݻ&R(_1F>X?V7BLlHP0I Yސ)GdBONQ_@}28W f+B _q(&̼OYvomыZXUq{K5;;L8;yEb 6O9gwO;sPd1'4#>G;n:-Jzg=iqBǟրbA"F!0qb cBi`*De80_+AzȖ2Cg;9\;i`("-3-6# [s A;p+WA;H}Qk|feXB#s76xk '6o\ROlz^)ΤXnڡ \?V8rTQą R7'@~M?<\?OD̩YEoJpZ99#6MSdRR(m.nMeKIrCaƪrz-V-'{fh2hZx׽#)^U1 ,pZ/k'GB{I+@8g:7j:mm3Iq$t4V qoG4'^:tߨ%M1ݕ3aָM;TeݵJAN1$y#-^XhO`\6sN* !R>w+$B@Nfk2V7bج{T@;e|T5 .ZkE]]Zy^ZC ǂ Kfg㐦YN'0Hy஑GpH"iXsXkX49M敷_\. Oзd"PI=0\H#7dթ5m!Q;9:`ͤمf#tr2=j{4&W~p"!XNfQq׬Db>./0Y00hj&"_n ?a2fӜDE_$fKӷZ Հ iH_yCHoJ'pΫHhEL)qCqkϩM]_rw*=ԣji-bFG>&]Zh,{vmso#up* 9oKx&dkXC /)47LVhDJ}O`ݒtyTU#XxA-5VZLN$28w%:bJ92]332vWA9>Agj)*AhšɏdO.LM6.hFuz) zIWd>$u&R{ϻzW/OP㔛T -Mg<#]+.=XoJҍu2.X7}%h~+oJ >Y]=d4Q9ʥS15UiC7Yv'vh ^r1u{mYPL}Óu,?F-E2;,ZӇ@C /"'*WB$ 2(w\)=S =F ;zآBgo3CIsf~ *qe9l9otdh 鼫Ob<ydYi+,\V\gRn"ujj-%=C`&~tTvﱡSKFҼp!slrn=_Z oΙÙMw0#l:QU]5W![d5;j)!x=R B4qCH@;1E)#fSiVk@7 ;5Q??X¡RӭґiqtŁfU(="@\3賙l$,g!ɪ),6j85ZEf-xmPaA;oSˣ\C&JQE˄XȰ9VZӓF]  7ft;TK""&Tb/x\R|փMn5}BRݎYNhaq4ZD S kr`1A в/_p]w?聰QOX"ڵy/wGM6(0ŭ"RD}އm@x% SJ++뉢8%s'{7&Ыrҙw5R۾<C,-}P2o\'[Ͻ#W]x0 hj3r8qOtKe14R_L3`ew(Jâ|^|ws(3US2*v+ktdM  n R)vߖs2E' ?0ÒBY{2 I=*אHgHR>qJ7e>sx3׮.x\{a ,LFEu1 oG:V[Utpp2LJWY9ˍ t, m'Lm%VnԮ, ba^. r$!'}(sŗuҸ#db._-D@Yz{'$A{?h. TopvM{_ TQ8W и3nx:w8t t! /B^&vѮoO8?ajplm_>'6&e&}'m>K2{B!m_6ҊEɡ7^QI~4T­inj -60b'X{$1+LylO#. E* \]j .}&]+_@O(ʈȝTvay԰يQjXX8mxGK?TjBP{bUrauW Bq=l:5]R9H<%#iiCkUR0Vx-&= ]r( ơ 4=+)e^Tnh2ʽ#B9?Ou2 o'P+/\ѥC0rH҇-W7ޣ0?/"e/\$pP0Z#.Vm?0cT+vU#UN657 !I++~,Jv[zCf_N-eUaTU5q9|Yrw@{Dg+o5FPs}ӹ:>ig Sr!SILZ62y.Vưr?:5T,|AϠcf.R ֭$W.nNOA)O'<%PŽ I- ܦPE%e aW>ʉHwr{8fVh}A KmO;3-['崹Up'iłdş$68 -Ë{/QIGrL׵LqXiǩuzX6 rRNR~}E%!]13~;rTSU[DHFG9kl7lTrh,\5TP!Z] ٶ y 5r +іY^ZsF> :0`%+4%aGAutJ(T&zLscɒnZK^dc]'BNP}clz=p*7th%n>@p#Z`d|JCx`MBC|BAOÝ۰Mx<`:T1rhPn^y7/XWZIs]:yUN3މ9}eIy; vhz ?a?VC_p<ǭS\#s+D9ܵk̻7g-B+rJ'{f|J>5/Dؽoͼ ]L??\_iL(}Au)i\E:j4gt4"F04(]=R4iڋ <һiuٍP "dđ4y,. %ތ"܃]q"N1S(WïuYK *f\Ks6]2j[VP2= /PLi7#>rRj_S6qig=)* 4.R )SKDE su҃?vցa8EadƦw 9ղִ3tUP" 49)lz"@W=¾$}n*w{kX3BOރ*lGs^@@t@'$3t;X| PီRD߫Q{M]@_~~|Yq5ۓ20̛ΆK\3[@E3F4s[3r/v zm^h%1&0<G<^6",<d^]w٭53< m_븀jlfzx#]ݻ-}8,[_W2 ;UAXG&u3xuء+k@}ϻx @7վW{+Rs򹏛dg+Z ќ%XCZm̓wμܱHv<3<$Ldˑ~hr@5ةߠ8n'&CSݺ;iΘ٣l i_ `hh/YmBUM8{g@`˯韄sZ~{kNwqpX@o HoJNuï.5wZQv->=W(ݬ8>'OG ${kQ DlAi–ٞxJoX!2Dvp42z+yF p)EwͺtJap}0#썳ŷ{(eno"n0*aװtWrK` A؃.^Diٰ$joFP .)%!buaی|4ֽy/6W5o[DkN+F6k`L0$"TQlaELD>5bAlq(i6SPB랷55'fMkf wȧ15QȈṮJu_1d|y+q٬jBʿJ[x6:iȵW U w7}#IGlw,|_Wp| oa6oQM T+ ,]LeJOv~yAK$tӤL:B=rzIS$@V?:j16%ebk[),Mb&/QxwRuȳ >pK2 l3r::u~rvIGnPzc®o^P'J7WpBc``MpIߩ%F>;/wXڜbCմcБ(lzbU1pH>8V$(vDAirh=VG^AN&QG+=Kj`` :ZB.yXD}ss!05hՖqy?ֲFǦ}QMzI,sK~-jb13#j\ՕM-թT'A_ntuI?-Zv[ȰTsi>]xjs'ģ?5(_Bl}c=}"}bd4]'6I=lPpYB .GWzպk8KA  ) yXdB ppz]K wCxJW,f3kXN., `}F'r $ǖ(cjʽ6)p`9S3?gOX#BNk.}aM;6)=7AUt%Wv} ;8W%rAϖeYc!s{fѩ3B4[{q/?˴}SZ /qG5GXgHw_NlsU5; mÖOcDnyNMmU{N|w!Ӏ̀S$.,ܘ}ɹa:ʮAD&%=NwFpXr:KRNݜ3EiCN(" 3* JnBiz>kK2P6j9OR ŒXf 2n2/*)(-rW"6]-#\vxĽɞiJȯV?yiFYʹxEs锇~Q4Mss !z6QtoĬ䑁q~Jw|.]}3WoPcwa ~nwרTQ$-I+ݔ DVфه0׉EY/\~p*ZhcixsX(dW蟰@u%q56'Mȧ_?cMwJ%UC+6C7d,Pu;iLG WǛ'خMq t忊*}S4P#__Z#E_ɘ< OM6aS@3'ֽ򞯟|,_sؒt@" ˻tS: ({G_d,1L>ZԖdSj\?/KgK]`n($2aBe?tF|Yk\#;Udy<]'IpU$5?Ot(tpG"O<GάwVH&Vوrv;Gnф{6N[>rWƄGuc\]*6 csV_pʨ8DEDaP,0(}G?knL_FcH IDYx&0), NŽ@WW8\ljl~j Q=,mty+sbȪKeW3ۑ1BCBHѓ8T+XKm %ٌ|A -ؗPDy\lݜV`NrL6~6؀:*.K'VNROӣv-އ6+mwvM[wӕhN IyR;G< hg괣Igl!N:G!1K}uzρ,dCA' ߅XFrӡ$zh=]1D|E)E~wc'Smj}}c ̳vqͨ JVq?>͕ĀeE&G!MOVaq ځ!>, ^Ilޱ N\SOG!qsK8jx/IB,XQ)/ljnj,{cŽ G+](fؔ TɌo'-{;Ẅv l`h:guyMZzxLf@2qa&gvں!%oՈ»9&ؚҎn-xX>%-p~瀙zKI[[KKZns'?abOrkMb1EVuh㸶2;ZӴ`2 }6`f:Zu68ǏXy3K[$g-:?~?bje smi}BF@!yKKQ>m- _Q<OtyLL~9ekYVq8,\s shZ\;+Na:G\h[܁dC)@66ZYTCwb ] eF76.U LSv#ӓ_,5:Eus94uC9pdAcۃ'E@Eو’KX{-ZK 5"0S x?q\qMgG7 {sP-%lUe6!)Hg?E;11^- _Y]f>Oa>Ӌ;|zb6B )X$X_%G]S,bLBÒaQǦkޢb Zɧ}t߳iR(Hlpoe!;S5|$>Bȅ)Mq=gJ0wŪZC`ttԬ'+]ٟ2 \.'N`p_Upm+P&TMA)iZJ&>3+y/yg,cPB/oA\F/ eTnv'YRdjC PT71`6.*eK1X<"ˏ%Ўgge_;ߧ|=A*m $A@߹lmRMd%FR%Q`V"~0`%!یËdNoW* KW6Ka ]44aEZ=m\h~#rfJA80LCTGNqCδ-@woJpr٭ ]cj/l?yA x7 +O䄸AnB;Ku1+Ius0@ۨz+NGnSzz;Q- Zbfy!wIUe^$,{NJr88f ğVKt2Sݜ).Cl)+^2P?% qؗ܋22A!^A1[CL9켎lX3cIȹ${V(`&Ciɰ=oĻƵ4U-ժ K`mzUIO7* Gw.Ae̴cwCCĐ_'T ȐZG0n,-/=l>8r-7kbnJK)linQ]#S A3& S'9 lVL3Q aF]:U4XȻh(|Fϓc!ԥd.M'x[WVn*.sW+r9ҙv7qwUoGϻo߂YADm89d3 I2qBUV*o_j*<5܈g(Q^(L:nͫkX_kh$#G]>v.9CE7J`' l0Eh ]*(]"|]TO!]aL6yX5iNd# \ARUvQs *"t~ր FE2Zd}FFzz.4vѐ*yW Y< }sjU@ 0MWkݘI~!j^$t7k=$)>3pkyZx[(3̥+_eupȸB1ȹ^g-K̰ۉ7^K)'9hpNuu RQAgj!Ϧf@Q[nj˪ (mӉۀO߀$87( 0v_E6^== ;%;[U!ƣryE&5GwB'.d;1AYQFj@9V Ǎ-Yzo@Iޙ:´ ښ*_e0 Qʊb2PāF= kq _,veN8 #OiV%-Ygs䙻ϻ۬~6Dnh+m!Tx7+'L8 F- q'Us،'X[1¥pk-_Т<%htމtnAOED$!D)T" ]=;?Iy3lu{3\TL$hͱ8A/]n=6/]AfUtF 掏BKxhtPYSb>"| ? .Hfg|M(^%8 ~c! ߝ `= ;s0-`x|nP ldQGT%F˪2"!F%T<Le5p@6vٕ ~L (]Pw{'+'f$GOw0H~:ac*_7y%V6#4.O`7W* 6-Kn1SO ӈB5hiO(Xw=`Ff$[+̓3FDz_ӝYm]{/t}#c:4U<ǞOT}E߃v6/q7&aCV 5=UD\tl9C7U\.ƯMA ]8򱺔,3* R?]R]]Z@]b˞f=Gfo $ q*$x./M-qeZB`kVQ84N$~g^._'TBI%=6\B|M<#լGӑ4lIDtW-JϦ2S?IB_h/%E\vN a ,E]nnp}|U7!^Ԛɤ,C˝4ֿE#*>r@OmONB~r@q]O1l,DJ@Sr'np؋Mvnmo|XݑYe DC% ۘR]`TC4"*$߰끫̦=r}k5'rVC͐%RIZ64B)!zEec~*^ ht !oh ,9"DuY6ϋ47(AzCo^l5@{<;{0#+\Q=4^#w"{B@Ec`k#] Xp\4xԑuVrF4&Dg;<}۝\k\e {OY4$t1cs;uFd֌&%1K]yWh]E_zR^3 }f6ݝi҂85׀Sl)nl!Q%K 2B5T&MQ>\Sb^x[HRzB%pdxj>vb\wgwsvW!+Ӑy3q|PݎL~ÜVcokQj`eFKxFjdiL <4 H"", &S:7=‰m|~RyL\QOVﰂQ ycOζcfִQ;r+)g"}m-Yt9\8O+!~*pg$T\y14nDd5l< 5ʏd SHWMZ\1ddzJ=vzn|@"+dZD2]\typcwwD $%ʐ0MoG}3L-*,r1)_}Z H3u'} Mm)# הB,鴱idġ[B$M`bIWGBo-892Pad,!F5|fFB߭E7@c6(t0q7$v]%Aw(L:Q㬬W.GIR E>cP/Pe9U~`MU8SZuQL""t/#e x bDa^؅Axx_BAG9K\-cdnZyu2G T;n}tR3,b ((޿D1,N`=rn >zZ&R ah'iB9pD܇ď(Z⁔MLR#H8"DV[o"9eqpB~?j5hwo>n^I^-2Cԙ(op-5Bד=ʱ+GUÛ9;2bl#hXM6u܆֗D[xsxy~:O6GɎ?ᕇPmNnfLq;$Xӌ1T;g9[yv>kE"Se6/#^LDc]v+ƍɕ MA>綔,{7[Ea2p9պIۤ6\;8A=9j1g ـo9f_6}'*Avď⥆ юQٔ3oU~$}4)Q1^룊ޯf⋗nrSGJzի[B+&"nUaW2j6%Qy~rGEgz%lF049^qBg1 ˎ)ҪuKLǢ؂XOtD \poHs"en)10QS!lYKqDj?p d0D0)X)Zz9&[v2  v\, 'n\ì+(rLi2_)?7j`mcmo$ǡ2$p1Cds2<A~fp. ͟(OHL?`hҐMJ{>Mh]^"C_/WyUqp5vZe-Ql6$ p:+߮؜wO;H Q?""_}< ҇+ Вm?$K^i?'E͇Z-l5ڮ\{0E _wfi W`qԛ<\+_}ӏS:ZYByb++d'6="vqĪr5 XL.~1һOf9slp(ש׌ uá”[7({!0kFmZL;>\>^=y98~۽@5/ z.Q Sfy^&r4lT׻n7Y&*9̽Ku%5X9GVzlt٨G16P>236f.lq:S![OƊX8z[x Dl22f']'-5ĄGQ_e\UD1چ{iWKwF2(e~~0Y`ֆxYsf#^CDTwqs28S?PQ|X9##W qAvM}|\z0趡ɑд0ꋌΈ!щOX7ߚT{ vC9/ vdO3MK+kcWEn\*_J'xisdb s7<@D>KʝBHl73ljt,ʬDy4' |0֧C:pL V͗ BޱSM!8<懞5`{P[r+)Ah(Rp{iʀ. [{+#<%z0%+Zٸe9Cm 7li>vsYl<<+Dzd([] 5WĚI󼞈 F~E26JZ]*TT"pUS7ٵ򶰸U+|R؇Dv[(TXKi%77-FL̹$K9<:0 E} E2KI\Ya~Arq'ju(ꄵMB ތ'0 /{_2"y[]|^-χ UuzX}m"*OQhd ̟poQY\5M707MʿieRzJh%Pީo3AB̿#÷H#Z{c* 18R; AdʊTa"sP,ǒ=eCɏC['4ɊA4αfܕS`MGRgDm80uA;dp' KTwfl1&Lw6Ԇp^[BMUaXk$熈QS7e2U u0<BIf'n>JVj8=ܓ5Ybi{__5l`SrYakZ|)X-I{ $2.r_3K1湨qc` ߿Aح-hy[VX7sMKD#ƃ:}ސg?gj4N{8KT 4.;GPW5| αW8A˾ɳ'6¥dZlq= j3AZMmHvS("GUD0*ϽZSv!R m/zp,`a>+"En!kl&Cd κFP*@ʷHkl1кG"s{D (>֟#;n2\V[3B:7 72?&[WOV^]IЄ=KIV:)()J[H^{cS3YK{~|@yޘOy//*#T8pҩ%&c_'gk“9.d0jh4 GWu@*fW#'&zv]48ڂHVmfCGɭA*uV_N\ҏRGMz|V7d(ʹcuX$Έڻ8+TN$ }41sjFi jg.h9vg36Jӵ粁cWBaٯY 48!WL/"F mE6ŧA >nM< p@/qm}vƥ+!gG9RiBZgegwKB3q7 -(OPɠBt)NGZ7%%XpPVۿuu2 he#POKh~ &rb#Z tW RwCu!C#8~j,$5 Ϻ.6Aޗqfox퇅lLډ3fcq;mp&xT PTap幨6eb0*b|s\C-`60Vuju's,! ^gVbx:X;.nP=N=:,>\VPZƾ-'w.|&q'z1\KCXN7xy AWND!Iu*S.C_#H*w(o]oa—ߤd=qΓ4'9¯E_3qV ?< 9 4^\er \X~ƒ=܎cZ֯:É6=.w];rtHJ ?iB @2D@ 6q"a8 >+ZDžⰊ~UW4a _B+<ǰyܽREUъ{4z{Zgy3u@QZ=JN=;}u+;F7^z,n뇲R9.plőC,,n䞜[C!)rwrJ[&IӞEcRS|~r13#>Zuapu+A%;.!z3I+Os)jmou]rƓaґͯ8Dɚ'?FkAG[6M.͎Uto9@Cwp`.G8ӧ[#h!9dюMչ:qo.Ոi\rwu\*So /$?3UA1xT̿?qRmMNҞ\DZ:})бl@DcG?\ܞSȢ'ObJݡh`S̷~Qj T _azéixe`4oHxkDGnӊp!~-o`hQw8+Ao׉;B sd'N<(D(Aろ⌗w sLlةј< qNj.@>1>k$/Fpb.~qh ] ;8@>v,6_R8~Z:TaQlPfTw'LxLUY1ԓj3}lۇ2dr|;B2 '[&D91NߤS貧+3;blQGsUٍ)z)۵){3 a#K_0ގ9]_^%IťkLZM0h;{U/dMLq VwbJ~ad2tЛo |'9Ӂn3ZEu0kMhj謃@7͸$jcof97Aun5** N1C]p-MDzڡF+ݷϊe 6] _Mݹvvf=~dDCWnFxQ11Mvk0:y'+9PU,]I^ףlYK'( -4`g\^cDu{#+ &.ƈd8( F`y5S07Ub|*d%p"9&F#Ĉ-4"A H T1Ga Z@_xXd& !B 3+݊jCŒ78ڟ퇤j(0}b>4@hhg?*(!? ܪlF;OA0n;$OܸSr# YDjj(!iZqoG$sA+* M[TC jhibǦ 5cgolol}I== vJ,~BY5, /܌J3@qb{A==<*x 3~}IMPYH4>T?zA):ۗW(Nrm.CTi 4X|&3O_rw^m(n[-gɨ4 /KG~iKr ڃx ~+RAĺSe7>Y>`-~R c4"4n{{{YKǑep@In#3; .磔nu{Ács19dp X:_ &UFbFgX?GC }K?@QNm^x$I|uy Cv/G} d {Sw^ΝiYZ1U̗aC֥ؽ(uy֏6-+:95Ԝ| \ z$o- ګy۬rd O'= Dzn'$ ]; 45D~YqN*];iC- 0h`I _vm=Y$e,SO7ix̆fF5qy*f>j}/gǺ+ ?k5Fz@ = +MT֓z)7khB#vQ?+<"˘˜X [Kg* wi\Qn(ŁO9UoUKhs'4XPHbT1p.]9|{-WCg[A'YJr`!GE,!xP,%8Z~&$<ߴK?ʿzf-+XUzX}ʑɥKSn$[(Wivnur&3 M;j1"sVccҹA``0:L.ExEWٜ|W;ۨo`4 @h9'x}ji_i'jŽ]טTBVv"X`$j@[FmBAlIFbwbCLFzj:VXŞσ>za{ ctI6 ;p%,}1OrEtn3̢jj"jXj-0&bQYKSa{zJ\lz͜8 PKnJvrpyX l:-j1 &f?h\9fpD&rf.䷭г/ܠ%Z0QqdS}̮_GHf߾MabqTj+Myݷ42C  ub@fӗ$w07k$A+E{A_eNQ{"˯x7[F ~'h}EU*Z@<s j-&V52 rg.,.J+pn~2V9}9DRK|pݵ'jb4gIN. ⎬_]-9z ;.)\XϺZfAVf~2]VG^s9e'2 1Xq{<E\h@|ҫ*M?\CNgq[s" =ӂI5e.2+~ 5LklvZ@א$'}N7O@@֧?gi_yTZϺXrHs?]Cq> ?d8"YV+~whn}@o%yE13NLբ%dIu]ˉ~;-zK `*N/0MKdy^z˄#qeoiþqƝ kbRxDV2hzh3PV- ~%3nkx!p{ ~㩹% g,<Ư)H3(:+>Xݛ=Y]E~"ta} ri"FC'`*`G-w[E]R4'NS`pNXث}$R0:Ma9eO[X7rWxG@aSNQkGByB%v&q"zp~BЕ\e~SZ&Me(c RZGU,H#eQ%8&a1 .\ kRKGyQuyZV{mҐN}#2Ng^ξH{sI\ zV5|"I1-J ,œ{DžAv mQ:ZA=4ȁISYOB& &7ajy$LƆAO.30t [<&;gS:s)%˒mf+za(KNPD]woxA׈GHSJ*AKBcӞZ)+#]$T-w܍3~s(+sy14D̘j6Z+M lvޟJE- 97TTn[?"*@h-KTRF 7D«&?"p`،1.A0qű U_R.K|b͇[PGmA42 3~L$rAWb=̌15hUZqY#\+Ʉ uӼ"0: nip=w! ]'AeGjT/U}%VA*Y)<-މWJھIA:#csU(|2ZD,QXdRjAP{|)*Ķo&&oxPkl!*b-?Hx?皯Ref!JZlE5N[JLoY>@[mpw40(C`7qN 30Ux14 .rG ?AKg!x<`R%Pt?I'oB[Fkh# |ُڬ?J;ٲ$di 5+4FRF/QmWg,*0sgD*-oBǯi>NxЍgP~^A ˼]$5rĂ͈ 3r| J|'t])Rmw~bP| _:84U Рu|Vv"ɹ@#/Tl,{Fj#Ҵϓ2c{C2 ? ] 7mWUer[|WXQF#/ Zl ^>Ufygղ<ȍ(..RZ|[̫q9{>!A>xsKv[rclIcr%hP)zx5YS ZwفLaj `0v[2<<Ʀ_`!;Dd40J0c 0~|<װ"j=LTӳ.j z@Gk`QLMDυEW*_חn0^& Za_iOڿ)! }n `ֻEr7'5嗺'004 ^ r4^jJT](e|RCTVZvXI7$YCk/+U2}[׮cHI߁4|MzZ^w̩A!1Rg$D4닿no\CmV *̎C!ۖĞ ѱ}d,K TC+Vhͷ5D(J"iBX] "s;t(jSW@bz-Z-XN 7Τ6L,*el")ʴ"iR Rw}4,RTV .e @ϳyͿE9 g*>K-YwQ_@9 ad^BգAir = Y"V]n޼ζp{ 1 IAi}QvqW/FoltMњCD>dw%Jn{V}WqJ޾JC\&mnƆY_ -VE*\ћ(%\ey䣚 >ezuU8k~M, r-; Naiˆ+}-:J7Umܶ*pY$G6)c >.bDF}8J&P|.YZ{*+flPN_RQ̒y NŒ o(SkbEhwz[>(gL.1Go{j+5"ɚu2]pNr% Ux9$- _deJ]Asu38=&U|C+YX8xWE2P>.j9s 2ܿ)ToZP]+g?i &D-%WaRWCKuXy|-/ǀ@^Rd8<7LoCNˡ2~E*6EAAI_O y z=fKp7tio($`*/vW.FniݡI:x(.$+ YJY3_؞ fg#JkQIu/_z;T7wkZ7k}a f KL]2AV`Z1}v+ 1`kԭEKl>]rH{n1Qy*x"&o5¨t}d@S-"h :>`bwބr=FgvzT&[uݘBbzVP9e"iZ]xt1vn^wo pHiͪ}i$MDoA7kӴ1Bd#y-% 9SτD7fꡩ Ro | .ED!sal7Ҹ|HuJjLtT}aРZ yk/1lAGtYOPevL=i\a҉Ql4Rh;~6a g/1-$ @-9C 1Դ6L*[ѵzF9֪"DC'slS ̐4)\\mK^܁2[s,JFhX2\F>:£}@ѹKLtZ{0ƻ4EFgHqe2avy@ Qi?#:r~gZG ۥ69;qW_>>: qf\ !¯ mV5( !0@N p:{(ZU~L\/^Z S} ;dwk㼛# ԈY?b\촔V'qJ("iyJvί3uX{o_f{ ͟wZ(lt#aOcŖIYzl!+ƺY[oUȡ_}$G;{J7mORC ?Lo`.t)XuHخ6}nC/+ .:N"R0Ir<t,L\ʿ1e-p%8Ee1HވELVF0h:SүwJ6Ɵ ږ`0ܖ`L/)<'xG"7Wt`N @*MYx)߳FE|$0lRm8 5UV.kނhk OhdQCX?S{_zѥV%H~9Nwg^O1c/9dXR(0Ez~`@a<*{zZbrã@A]tq_ u6/)#G+׀JtoM]hInf_H} 'Gu wY'-jڗnT›YTpFgYЦuy\i~Ck@+x=sX :[4IHκw)ϕ@K#>OLb: _Klr1k%K렫6_[6XVFgo]ZauY9/_n QӀZ QL@j~O 2ndw LB2j,1#ݐ/6í9I${oRX9cfP@d2 S'z@}jh,UǮ w\WA 쾿.L+JCla iQR !ݑ6r[-cqnP̂?E &"lD_Eyθxǵ:50= F F}zI"f NiEux{up7tbts m[]<[o,k˒ "tM :5j`u&d>aoz‹_Tooj^T#|y, [w"ї*"́|^QzqF%`%89fKis ju c$_a ߹{wi φg׭ U'v#'s^B|~HH/)B$Rq bd*>cOyZnu$LJ⤇soݧ?F=U<8Iۦ-%0L~}'Q# % +M}& GYdVH٧0@Ffbk4+R~7;`.ERш=AC\#AE~~v@ߢVg7s2m ?>`[%*ãϜ[.C]Zq ԅoCA'v5E`%dߗc3!j>?tɎAfˏ-,IL Nm[Yy;`BЭ[v s=.?<˗,[%w1sӲE&E# Ġ5-Kj^xwbX%N£&a8!g-@rTJ#t#7o@'9d҇8k^v7yM]ik4a7hC8%TyR {f)؞eb܉!1UCW&s6{.bM/'%cJ9SnVuur"XpM4oJ~/Մ-IRk(nK O%BU-yFIƄ(u 7!5G܏6S{hTb:_P@@y <)ybۂRl 0Q9Og/4sb(q,Ŵq'#>m~RB,UUAk rD{a?Qt]Qxk )c<2s*@N= 5e[JĸCMOP |Ywzmkb ăhvQt*3"0 @&6M'T`cX3|=4t6SVdjAB^V6r:qdE sp_JK0%ⲦĪDZXY7b>ɋ/îm0n5ZbK52E$ǷGa_$P % a}qҞ B=d3Zcd=Ux(S^JP6){x KL* kuDb;؋N퐟泖wLYOϖQ;c`xw +o0N{?=M#nU z1h60=IF9;WijW9({p0>R[BCԐ&&jNCa5qQPĒ,f\2|$yI`(_!SdrQ2 %o`'aJLX cQ"{K"7)Hؤ31Dޑ ϥh]oٓ6BqF^}OCIhV v)lmyRW$g6ص>ǾnZ͝Uo;0FaFUO8H6K맣 r&lk ]rhD4@318f#T瓥W}>؈Ial*tľaZ> {^Eg f_TٖIA ؃xH SZ?A!oۣ;rͅb׫"lՃBܖ7mMD{w˒i8dP& S~PUVT)0A$YZӖrKmkO:k}ҺҎf >Rgv>Ul/Eq `NE|2:E~W UoGL pzl8N@kpL4W _3>1$>>2tɎg]"f=~hO+wͶd)ieL8NY2}!ur#9@j!v }$2IJ\27LE,~EX1d_P9t8y(Kbb,_8䧏N,W\"A~?~fwcj,83PrFShx7d}_)RG𖍡D! c"Z\3¼|nŜK " W[ԉKTLժCTwD@ejAԬyvt|w8<&%sɓdzn@;R9vO᯾>f}*(n@ˢ\Bf) tg,;:!IA`c^4` a@R{yEF9y hL!Vð}C `ߑo:GHɗD: Ji5ǚix`o`RtYFGHۨs%SLڵ.uv FZ#~fGUh?Zd@$ X->~z;4²a!FS`;"i5شF<RSr,oאr!( Y1官{HV;p)WG@R0^Z]^1{U _֪eyv)*KtJ|bJNp*ǎ 4"l;XhdT/MvX0WzC4_#HxcܖA?!% 5m}ό$$j_=ZQ[ W]1fXCy=?mRLح͟1Wo Rp[nmLdEg2`<8뵳 d#|㧻 (Ω]+UWhDD/d¾zF/hMQ k(:5,/e-vNYXHxZif,+ JOqA2;5BAѽ.ӢRJB^JX/OH066O j2u29M'b&$Y~Mɴ<؅|0vo wtqԹ%ɲXPCx|[dH7KSkfỴVQN7jj SHtؓ0'yW&U""Pۥ# u%ph Ql@t!;7DGgO&}{ _ji9]fc%BUZ}]捥NJi"nWU~<|=b QE2i:Kz8 zf8& 1{rpOجAֶ^,n99z E`,`zV,!bzqī]LBP(l=Y5=o9yQf\#RkGON%~2C;ՓUqf].4wso3ڀΕ2Ewb 0Sl 'q31)Ï0"i0)VI,F4c~3AUO>Oӧ`ePdzgn[?gModY tŰsMter `=fà:cFxf]bVTO?LTIe$Z9Zxl+4ˇ.uGJME.\44 -~KnV8}5d Gל0Lzo֗D $2UYQE1k KiOc<={ 1Lw6)[Ε{;i]"aY-N]-Nnu؀0NyiYW96\qaܐ&}P;\Gޥ?2zj(GH !@8m<ŵMI; qSeEs2W@ĚpbGwyKԞI$Z .(/KOKu'`+HŹh+ҥώϩ2Mi~6rHI<';@Qwc_W8I鿵C7B]Y_Jd}Gra Iy3&=r6M {k1l]u1,yH5VHW/Xtj$1P6`G3r9ZAW:Q!xt!"0ӏd*[ `6ղi*Pstg33و50OY*8s _D(\_ o , -.XOB A GNx_6͸oOk 3Jú11i*%esd=B2j*r{S?lډZޒNw~؃ȗ֐A2zڿ\y! 3ˋ Yor?`)$M ;@ Ѩ*2vp 2V PdG+s&F1keV8}m:-y:T8cALen8Ed8Qc>i1cœDd;$$C*}3mQr]6(<;}y$}_V //׈H_'a\Fd4룓SZ \L]\n?KUTAes%IC9jjW[*꼞 ޳Sݰ$~l'#<)3K?ȭEteXgMyy <ϷG,]XY|XA>)"XKDVCpքu(zJ%J5Dkx4!EޛϺ }#P7YĔ,]ciK>4AU(\AWMo.n|J,Sۏl#7 ̅YHֈ@k1,|&h"`X?}:SHb'*d̪i`Hx(ZRo2[e.BquTG'fVwP\n0}el%wjj﬚04#w#Ofk]3"t?@ cu@*$Fż<V;2ϚCD#z n~ &%joh|mz[n^@" q ؠjyvPj",A&}.Y?O&d&ťIaZU97IZ2uvT~qnkKi/H#0)4'I(!sJà/EߐkE%+o!tŠǬz&zEz U{+Rc R{gٴgB^k}I]5HʈMzM᤮9jxtv`b=-AB,]࿙rPDĠ ˓S}8ra*)ݻ3n zik&σxZawNIa)Ί^_HA`>bPef3U  0pcF<gFGT?- NԆh-Us8:RxWupBa~uOr^T0V-91^}-YyFz}??Tk;ǸDnCzU砅:\diM갈A)@־f1%;̵#C 8HAvb߯ ȴ1w#jU4Jڲ 0R ?= f GVGo+ԡi9^b_TF?mU{;QE?>>ʦKsPKOКu+G}zuy낙GG >].})8g J Ѡƌ1\Hjeha4H[ɑ &?6-o6yX "`Ūoɜ;k54HW"Fk7Kn&mp-'/.](A,%T۶}Cȩ#z9\d8Xr'H\SY Ň` 7&;Tow` t8,L΄* m piy8?oɦv'HAJg#zߜ^/dlʊil})dVNny/1Jj̞F Z5Iv!=SܜS((r=hдXQzf5a"ja[=(E$\b_Awa+ϘU 5(Ny/jVU5#Fݵ ClO ivs0?C aKca@ƑIUK N꣉$R z^FO~I}{ )9@HdZQ3#Q#p]CK:=@tu6 ~nK$\#+:f8zWY±d)w嚪2|&ޏ|-hHONބ$KqXӭUbxЕ}O`9s-g=,(2n]}{K|#!TGq9>b~: @^T$ VdMEnwP7ps~\I:+Mlk!|T/z65" !8?z hp5Q_\&ZIqNghh@7YWm(?I 46i5uZ+GJ)A1sYcl҇f $;{n%~s(j;mrg)/ R)rmۏkrOB): 7pMRdF}>&I#"vVy=w߶W38uA䘌eX^;op{^AnσH\S>ujtpAZH(+ٓXVgq+%n2ev -L!2^.Eެ4 p^y Ğik\tAdR%ӆq4oU8\~ahVOofKDeTFuOv(z <F$!TNcޯC};g#Χ !IʙDss CLQ6oՓ )N>t 0eiGG] ![3oSbZxP1u7X7M0cq߀G8#9PNfH-xmr_пu/׮\$9GN^rԇ"=}׾鈹=(\DwJw7[ Aajh33ERR2(B:_>=MW Cwuȉ`o= GvqӪkC _Aa&oj\|4wq֞'u'2G=fsi_$ d'ddC{B Y ԻIomO4d=o%Jw-.r hdkOa?M͏ԅLSa4BxE;Qh0UfK@;@QɆ8EdaLl8t5qzG=ٕ1ڎ!1~aLA~ܩd.SvU.qHBGņS-IXa8+O5s Յ3yz&;‡vt'a^~4uF)v8a@F~FkO׮zK7NKXK右Vջ8 s0x\J+'YNM[B3of.PZeSh2U!҅낧 2ΰCCRxf )z)+r{#0fWќ)OF}M yoRЀsx>[2__^+-B@q<1k(8ХѕG,G Cl2 c!$ U*U͸.:de˻=٦#ud8cP~*%`#N @ aC,Ϊ$B4)wL'%aSAc,K܈;Zd9ͪOȽ2vjs$)20XKN"åE`t!(}~EŰѫ1:2VQsܳttU J\`4Eo|`w9B {E>^*p)XsYڍ})ghoJv0W^}ԸK2 M~` Tz-0kpB7 4LyYnɩ2Z6?YgP+= (WiVG+VjH^Z7ؤ0sM,jun*L>bY}٤Qh~D%|PM:v"^Aq,`}iRa"^zDj q[ UtN6&F*RSDI#<:vwc7#[sfBb58}Kkւ_smJT}m eSXZ\vg>[>p5p G`VQޙ8X8m9Nj{\'4(>-, qW:kF0{W\ܟԘ<(>]`.`:t>!(Łћkؼѧ~%Y/fD|s HC6\aҒ t  8f BuW* ъa~%#(C3*i\;i.\E g :ܬ僶 w\#?ϧժKM<|p)KSڽdT {b#.Tsr*CV!11+J{8{~> I sTB Ό}vZ #3e7pfnsQ'S nǾWmB'VDp+E!-s,ڃIߑA8#!#Kl&.T 9=ա7ZLhP*5F8+syFZ nNde䩍k&YƎ4/WH R[`1Q} bq7n?k!>F&>_ <͸&N=xbb $$ı;=V nFo8& < DŌtQ]pB'vg;jB/ _ZOcMI?6ƻJ x>FW w*#<0fq,n[4[o.0KOD2gD:Ok;*%8)[ǷzwsHZs./E?c]|ulH2qNDHK73&3j9c(O.ay>_r;!̮ DDe%ecpv+4ϒ%OZ0ra$r$-YkJH̻hC+bj夷F5 &l|BV"j0Ny!+2cO=)ZDKϐ^NzfeYSshJ&}#Y{DE y X"SB a(;D1Vc<,aO]^°*R&#y6(&LjtxpHJ4|nżȩ>٨5ݢ,Q2Ly;i}1Sgu?`Ĕ 3!'T~ sU 4OyV xw;8Շ=Q1ԗ\ȴHbεZt캰ҚoE1w K$1rq)g~"j.j(52^5R<1ee.ѣ&e4XՕDQvK{p2޲؆'8l%s qS|(j6W ;55PIeTe>N)M‹9k{X*%zl?Kͬi[T\ߞiy+ݱ9ӻݺ5j@uW>mb+k;;FZqČp#PqZj>E`>rKPDآ#,pa/McoⰍlb&zP=BRi#vPgOe!oFx*DJ5^juLN6r[+sqcƝ;{ v׆;Nc(Ȳ=g ߸o~ߏҮ,hL#<.8v*o]'ubRd1[7Y{uzJO6l.ӗdg*e2OK9s@I\[4@e,Zń섙b hŒS1gIiNFUߚ&(Fi{mrD\դhz-ܟ_K`H7Ք9ςabANc9dk)>U>I` @gъًIai^80<@(m)#ҹ|&'f8%@$Ykݧ:' 0œ~ t&j7Zqo18٥deoEIHԯ3_.Ŏb Մ;yzNO:Z8_m: Zs(&fsz7( n޻㞼8^ `&dV{fǵrkd( ,I|eDUY\:'㦲_…<ұjYnc7$Fk !ZQM~'(iju` SӲy4I<*g*^ޏ?JUϔvCK\:&3)A׈To@nPƎѽ(mOoLHx8@s0/mH_0 rGglvjP0^SPmSz\!1~u4T-\_XG 58cS͎AM:פB'5dӿ=o-/ pWNl{ ?[K{= 6LI h{XwDbQ0% Dhp9$pgBevɧb'z9b+0&xISdcPްӿ)f]3@zrNv>s%O/Zأ)8+Z) ] ]n)«FFG-'`<%{sUQ8)/u-u59~|X&$pQ`|>+t-Z84>w`S'nFv$i$LNQ媩#_jxm\FB ZVZf*s)_B}|Q[ÓSzvpg޻=-)1c~qhm ҽ q"&r6/S+GB9DM`xSɞ'b )Tۮ1f12N_z5W.h޽ & ߡ)C`T>r MPEjzAl{ )j½LT2F E,7S$P"as*!}dL:zje}ni0dO#pyRd\]˺V"?,!̥f DY&= 1n͸.=KHdpKs=Qim%AO/SXΆ_dy.C\4g( ɢa&r$";ip.iz ̄ĒV ku.C z$8,`nܧd9\KKoBK+uZ`SW_S }V7ClӤPzrqmN>C0zSB.U! 6΍h:xꆗrc]0*ޙ-:]P+xV6'H$\fDr١%;2<:PS!QAąuyԈ_m :?CΊQH3z!OƭZ_V1 |x|F7\˙Z*)bo=@f}:hM*uG0i||KO_vw 9cޞٔ~l~ΨE|war3'!+̃=P;\%rHB]nlyL-ۏgHJA!O?F$s?R [#{Q8FbA_j\'"54 >Zzӭӽ4ZkrL_km3*`yǒ bZ|!OGE0Sz LppH򾯬zzsTsu/k3|LiU~AMef&2ah{M?#)sdJn~ޠqQOMA$`,T_"qjNLk__OU֖Y'VYT2RWAi{{y})H[U^ҟEH`GXii{1cKw,[ _!: <lyol /PA!| 0q5:+;{sq _9  $yzq1ੰG>>|ְ9 Yvs$8 rf}aY Ez6Czɉ(ېn! VFStZы^l:2swWy4 `2ߺI fldWe<.C.Ƞ3Xq,c<$E ᑻaАY#XLňsI1z};{V7.M;[V-)6t;)\XvvУ-}l~ ]g /p!(a2ϠjO ~hwĽJAHA'pG\ YXnDgC~zM湏"T>׽U 9[kT5&B ֙xY0hHϺ8itv\hOͷj9"ZWa ȴ)8sRDN6_Y P!֡`ʃwXbM˜$=`[rϋҴbT/C]/vOlV;if]?-dplZ.y:VL)v%:yclFVgiuQ"̗A+MM:#\;Ҭ\_q ~G)QcSeiGn Љ E0(xqG:NOs@2R*|j~H:2g@BWd`DQ9TRJE.iׅ%"`w~\:>'9ߏ- ܼ;qfGy1G1$e\XޤC+B[տn+z/OMexr#Ƹ+ǓHZ@ʘ\MG=Nu 0.%Hex1pnIgjLv)T,=YHئI1R?' Jm۫v̒)^LleJR5=3_nqbھ7THj{$GX0DS=d d_Kat/U DdBݕpRt;WY% Uy{J^M/z%nk,'P q ݮ0N(lOtO! ,U"?>\G-3k#4)~ԼO)Y?H|ב 킇GW%k xAq}Wk{0Y0Cg3IXv\d`kxվ863s *J608 }a2ȗ6bwX!~KN+zns&i),p]0 "8*蔇ǝF@ O m))ݕ H7L\R݀TXqN9MӶL@9K]"Cr5@IVPͣͭ8rW 3(+ߋ/gJ[.gǛQ aNrV”jAv/1H)+,U'h"o+c>B%1Av$6+𫸕5'C.Iό:zq$-t s=Jy<ꊟ0b,)w0`J,5bY^ǐ(En ަFf6la/.844τ;T>ށڋV_T`%^ B7RsSD1d@?J Wc\aP#2{GHE;L UhWJSWo }GU~ʐ%X"&$UuFO3ߴ;Nvƻat)ļ{{观~{\0~b#ulS ΅#Ȟ2qd+zO@0KZGu_٪C"t|[,]S#t:i2@,">:udCѧkÍH{Gt 7i`%}> >pZb4qX5@P]3 *DCdg9 w!XfMQU7MXS_W7?:5ĄGT%okwZ $61\V&=N,9dl3;{ ~+]|kZѳeUfp<:}Kj l,bгnR'k Fve&q0Ycj TjI}MXZ5!KwFh~-zkG3)FQ6+;!A$wat<``\Dkc8WliE¾ɡEEO;vp^TX]C @@uKOpkz ]m哦2%$Rq/7b;T:ԎSS_X(l}LE._dAPSWS5 +-]o[J$l],$sgq,=bMʹyZ/~}1A96KH`*Rؾ5hu #ym"wM!+w< Û.~θ1.]}x`-vntH0g <|A( EUy*YC?^WEPObԮbV2-(aV1-:V&yɃ(}\1lr1F4D SlŨJUI׷5 T nJ7AKc*3CO^'gKz6PpĒ&gW4([dۢc!л~J ٽIiA3L8*LZ! nd+E+<_$ԷNUJƏcHMjhin$A'=#h'a ˠcrF|B?u|H3+-+99.A)HbD4]/|2ڭ sw0_%ZMO [Jҁt `\c߻o| wL4A5h +n9z̤(=\Dx8)hԻKTj*m_Ö (N*[:fY"l= '{x (ۄ pWg:y<'6tHB>jF9Jg^:!,ޑ4tW䀵NT!BYG$V|Ǭ-zŚ\@Tg)CKyPwrRL]rR<,-e8[ *}X㇠Û({)km*%-X0Qus5,@ 8%=IJ@=+ɾwC 4gj&}e  +ySTB51ـDCR\XA.M!פ?㫊 6$)~OH.YP)K`^u",e3OvmVP1& ͹EsUno%Cp:@j<ʆF%Y̙ߔWutp i P `zTB5 |h#e >9$Rzz|wNW='FR OftElK|vs_ɝ}rSqwGɇLPTNNt ݚ`zqTlΒ{fM׫Mo))ѤWm|?CCq:F&8nH Fn$fKGhhhv0s௥kI0 v92:EʵGj&g^ {ynH7Fal.wh* xhpbed tx33%$c"|+eGqLIw>ِX0P^j` >H-.2c!>"OcWK^7xC VǭEv4o*#R`*TQ9&A. P/1\ZHV?mܒUjYs_JQF/7$ǭ42fAME/-ܗsV}qv ox oc,nWVy"]ʄk> hex,{Am4P-Ju`aJ*7Lԏg-T!P*α,c㋝P|1{ ~*_7x-ۊf-7S[UD 05zRIU7gJ W%\:k^)dԂ|tM3e*Š?k,;;#j]n}aDŽ*9 ň܅i8b/V`٫\n7ٖo=||(nTduIpzm L>MAƃuc[(Wi4C AgQ47-qqQ qw&ipROOx٥.7E.0JZxך4`I)__l?G>R$D^vl[sP3QnYQ̑")lNwH~l:#p,(GݏL@K q#it7/0EFjm imsU_xij99.Wƪ$Nb ZcW'.?Fjy\ OtJY7zi@OBs*mUzXq:r4ԏ:`[LOrעA f/c]dU\j E~}VJ"GPS?K#'-&<߄w;X:+^DVF5悫޻hs{ #@ ^Cg,7]VJx iWƁY"[cTxi's佥bah?{~@ ]Ӟ;$vBr[z,66OFVO6ܓ#Ib_ f@A<$r1<k2B)9T"s# ZA,NƓ[O? GZb17:2*>{.&:Bv2M3= Hz lE*U񐑹mlV(l#Ea')w`ܛ%Y dh˚(]r p0y"' /=lƍE:)TQ} (T+?p3vQwJx"A?ΜAn`&,ūs*W"w鸋X5Iqy?T"HfˆN]яwo`8N 0-I] {,)?WB{5{T (nL9xנ伋A6A w%Nwd?>/Xu+D[oTÍ6aX]PY U,#i歴6](iq~4:BZ~U:_hLhU:%4Ggi[**ܐ칹tg ýhx+'sVu),{ $!TϿx䎗!P{*:F}x$Qk>X4z ^ *T)&55ma&f1r _xoWGMbн9s\ꕳ8X I]-]&D.% Snk%̐c`?dd|Gz9 4Y06λ2u$37w#@KXJ&zҞm@f_Re݀ So{`[:]"M˩ ZNZ.ޠV,5 ,߈5扰=]` -=9I=@}ܦ:QXE5d>W'6/z,2h0qG61~&'ђh e;ak#PmB[s`l(Yb0NgWo<i^Fv }jؗBalo&QG]< *aBC7B,":$w42PG)K ڵc'=xT;H>T:zⴖzDZ݆kugea<_i՟/H}pM 'יG ܙsX% YJz9ٝWr6;C!g0oBZCp^e~ M j JlN{q/y9yE$;b\KVЄɧ1Pw+W]y~C"V 5UL`룴OA.$j(54m/v@kz(M8:H˖|xIӫ˩EƒTn.u2&ਸb˝) )0-\4|e'5HYZ8zޔP54Ҩyse#HJ),K7N_NhSr QjzdC՚ns$_O\Gڙ6pl 4 ⶐg"i 9uLDhk fc* -x%u4#-uO"xr)\PX?k(`6e8sC\DEo0^F^=[XvZM1`oqxm#epoFlZFg3wv^sExu (tfחfr''aN 2 `[h(Y's{/Lyg'+ꃕ<#sm\3[5 ÂȊ`َ[hפPJѡ)"Xsxx yAc *iw\58ZWI˙!̿[i:z(GCzJ^?X-7H[BA!wRLu f 9eR)VucPVv`YcBR/,Nyo-|N(;zUs UzJ- 40GX-u>u~+KtΪ&e(7@I5v~aΰ_Tl8BX+gΪ!@\[썅!]سpy|[vxFAoz+`E& :H>%y}llzu"# ϷO/߽ъ:v0 6"v$2~,d|sΰR(35֯!{:ә`(XglByyVzYOX 1A(AF/1屉.! 8$|MbyQ~-bF${K'y&t*ƹ%Wįp|eU)?G|tK/6b'Sr{X)]UK(F7FhMkT7gjح?DIrN>nLtaQmUJ]Z䀀%tW[Xb2m}o[gnDbwʱaeCwZtsU7kqT Ka3b5QqpK?Fe]sC,pHE/%0ݚC@YMr6Y{vP!_BΔ,I;uSf1z(%jgJPG{M؈wyЉ(O$G9yXԆi~ef]>`j,,A /A7qo{YEDK0i;²lõښw~7C4aT[ 53H\ϥfmhc7zwOc(WLY"hww{`7١  ~6EM'fSİAz7^38I=VX[֥[Or -1c FIOu3PL^&DJ^)#@L澜s:.oXf7m}Dt=@jJ$T"w#ɡΛ,`dN}KxwC>bKv^k -&m Wh-Cl4or!]u:'EcZS|6vefF'3#p63ol)g`VUP}lT8TozngL :|7) g^He: Hv2~msG=ڝ c I>uӰa&_W_GlRh!2/^X)MzZa7& &KH%.rT8͓!wxȻz}zd%!Ɍt}>,j?gHɲV_'-`9RZ=g႔]ٷv7.0{aGUKUL%HfLqF9bOb +JY[{aUp{st+3\(M/?}Έ`Qsi$^iQ?]$QѤHo\O*ʎmc h|igEx© M'[lEX7 ]%z7lbzsGWn+TT u9pUT=̀#B9/e}ٸL'<@W9Dmr(|'嚔t~1IY;z棍Y`mmeeX<6Kv ~]j)/SZfE5uPc^Rk yNIvDHԺAJge~YY?#y7b =k`cR)4⬀Ec#y.΅+7S20޹w H ^d=٭G6u@ɛC[FϭVz֍v3)YLK::b;Ci ?wxZ%@۹{ pKAx:(@?`?xfɻRp\ޙNnvu%Y,ˎNW9[ݲI4+Jetn!N d҄v.Z:#>#'f"[#d.T.q>'U(;HRBYթuLwyv=J}ʸm[ϔ5fHU?b/RfRr.a>E_s2[?zτ8Yw(ϿŷuKo*IOM~/exQZ0D5\ޯS%i!YM!hxG#Һ@|`2@[F\}E!z7bNjQd$ޏ|iqO_"|x}d2!P:0~8DY ]55w2>Ę[xdUiSbڀ^Ȋ8b5 a@%UxRc9^(Q4P!Kw)tL/H)ie3Wͧ}&;PO\_) ,4YorԯE\Χཀө sī}sHv+^ȞS L9)4|dK&õuv}bL@ KʨYǯke2!5YW $_(Oy#s U"g[0|m"=hJ: $> Bt.*98VHBB#Ͼ^'HTEr$9ׯ^!8ˀjkB GCMfD< !hA*3~mvUNQYFᛖ :'{z|g^-b} :ca6yP'^īdFQol f*tC85{-xRGemT_ej uGdR;:7k]miL\Caf,3Q-N j*`33'C@ׯCKQМh y0'aI>j|x/:)NB|1R'$O/ւP W=#z ;m0ߋ}OnR@B`7^BmHXF0D|wZy~w$Zd3ED10z Qkܥ=qժR"IHHCX`UhL@hP5P]8%v9]]\`8q9cminuü…`},p)=F!-LkFsnl%Q[֗I;QlfEn=({ N0^/VpkGA -w@>^?Lb3x'"]$Pί6Eƚr :Ri,~t)8U^UrȐ/%Zn@gG_;)1" Fi+b0A&pf@`T@L +*Vx#f`rLEaFTί kJ+\ސ?W xK: 7Cۍ]kzG[0G sV~2Gj4ˣ ǖԙP +ޮ7K)"#UL`I·d~ҋGfq5cµؙ-4-w**Zoajk `Ҭ⨞;}>W%a톛?wc5QbMB<4$"dv4|$77'&+ U;IC\1p)N5Y#@MM$6bH]ޘpNol`vUR^:WWĹRT&qH>ϟsM(4)uc&o?_j+ZMgp_>UtuOxa3(/!3nz~e٘`e{,1bؚm` .U OȎ(lPy2 \!I {e8 xC~+VBEF\VȶFi.cSzS/J{N z*?#`UΕ*]lXip{QP.lR&=!Lyq! 7P}TuG+oU?1gҴ4wtkH$X=\^ߊjwk7W Uj&/"`AKoŰV&pt}08h*}]Q#]y*W${,`4֢9F _싽5ڪOo˙WYlMrUzp;X?`=Ȩ_Ӈ(XMcp"6\F?|ie)Y|A Ȯp.C{0>qN<"YW)YN)p/mB)|'5In}kpv5$jILr)cUyEZ˘xӴx4!boTqY/Ȕ :bSz"Nh`U+3bHY+=ooҥTSAwNF4t#M[Y+X nW;͖@Xi;wG^|b.S ]S+LK ӡAu3T[է܎Ō / |:hJ-r.@sZ[eE~ ?9~|oԱ%as0dP[~>"[`(Ѩ2X&0/9?B1"fj 5+S sa/㕤7T|TR"p-N-Xݼ>'mµk!ɶԣ1,xCVQ9& 9V=fۘю]%:bIpV%UϚ$ETgf^{1xGGR&)O&b W+ QdžI}!ReVH.ah\a>A׋Y[cqwV6x -xr~3huL X]'FasSl,V+;4#7IP@"1c+B{innz D+N۰(@7M{."=l)Q&:XA<גˆ PV Oޭ(cŴ=C9<(P4mT ڼ9Jo򈍵w-,'e[("M3CvTsQ7xņ[jM7< /"!D%ƫ.Dd)B۷BuU ߑv 7ӯt؉-W]_#̓+Lp .ԛnz7n8mar \Cf5O{. 0<7 ǭd>SIёߛ APESzyZna􆤊 M|]$j39 /BO)AHApYZ;\mV,lUA5ܯDave!4a<*ޮ9VSEI t2:35N4DZ$?0 Ľ+ w-prisQ: ; Dᖆs53Hz)wvAȕܢ `KX3!Ï iG]", $O C<׵=L6A}"2}~9Nyz$ L .I&9筢!,sQV|n2 |7$} Geab3OL"oV&mЬH.{Wޏi I J\:됖&t(WF^1 CFldYqs\#3 ΄ّ**.{LFPGky^j:C8ʜE.p'Iwe?r+:5XUPīg<8-{p^0qduM)-g@GОLБ .nj֌ ORp.AL3wBxDƙWC~WA8Zgϔew2_P`L9.NR/wպjVWԶutY}αTFE)\-6 i J3k@7B$J7l:FTGLrDODtUKmZFi CB &>&k3^{p!M*|.^7 L3T>#ehf6mp Otr!?Q(7>5C5)z[w?a] :b>srY PBedCC)b2# g R¦g8h>✑j1 ;Lh2:W.dޗ*p*eG$?"Z˺3=hӨ,CYz: .go@dK|6)g"׈je,A8l`4Fy8KCQoP.Wj #,y_x5#ئTY9ӣY=*azlbe@^5릙QS{_V-isE1r{Wln>[85~f%PSlIrI]-{v$/ԝ4R 4!U/*^v8kUwaWu(6%< %JM>]'eΑ?4vpY}1᢭/@h0!m_xEaRg_h7wl S,6uf3CxOg(V )TvOts}V,EΡZ&u9#8Iˇ ̚DD4YFA0;"lǝ-Jb[y rto>ڙnyƊ;LŋST ܼՖJoIVv5GZkګ`Wv*V^ g̴@h+}4 o`W0"NLұg/r{_$Jo~Ϳ\vZ=ǂX9rDr2ir' `mf *QNNfͭQ& Wk"xztȍWy"t=T˚ub 9f;K] ^+sBEW\%JCѭ=s6'Y0YhHbQB.VN>v6__#b'Y7?aPd!m%(:w]a<=>7nҾ%Sxx@vň4XRיNOMdꎺ%5nK6jڬY(blD dڮUa$op '`;f,A[O⯌ׅeؕ`wyzSx;M2dir@js. |V$$Azo$T쏜'f2OQX6ܿAB븅Z3F@9_%2NjmKr'[I}MffvBάgwu W Hh3|/|3PZL=FdVU 3'^Iu4e,yv!Oҡ9c1tK1_z$Tg<'=ہ¢摮+xb!ցeQ*Ƌ#h*"`|ry,]2o^ YdF;vt f,` D=Z}Gf90 I65}gJ)\׽ъ9r]&}]~ZgTI*HU9tࢃhS7VtYFn``bB p;QA"[y%Z IjRz5Ȑ"ҺZ}v4gl~V5%0a;Uq %i9fy4;K3e;&d+rf)ҫBŜ KO5M JSnp4~ Xud,,ʖy%94.pG鬤di'DW{/ΉSv2'BRؒ<_8ODOY7[Mأ@)2sg4k5wòLbI,:ssآ&Íf6CXvt+ ɻIS 4s7wnA+Z֊$=$d"c)*k}xm >&#= < mC .2M=$R/?wi`aHG0M(._W&؈?C6̯ر9<`1OZc.f9^[}1F(9ԘPk;7YqrPy[|YҝKL#A_"M㘣?aoչe<18pE]tI#)<9 T.K;Hg>ea`BxTXLS JjI14DR5^퉢Ϛ\>C!=B !Bб\J?6O.QTtg%z`尃4p1BTxRH`+ۃ6a0om!m9eW_WS-|F69\ 43LUL\'F٪B4\cbD*borR@<"=HE?h #}i]@h6握CqxCzxVRbHa{Ñʪ0Ax(cҮ՚If )E Ʋۧ owA(#jz`'"ܘoAuR3cN 5 rH\"Jx4ծvf2JB"C|/fYpbD-Ӳ'csC\;տ<"$E[pe\U9c*ATUe)Yg2a[U sӘъ>58}Mc!%;�(,_O}p'eSix}S懲R$˒P9gQ哅pcί\ѲqeEa&T )̑H!XU <6ݰ\f;URef`AY{IS‘7SeCws2GcwHkySƋZ1g4a?@݌ד)Trj݇Co c^tx-ѵ48څgk)+5;zTS $cuuw QO?PvGIMS:ft4Ov<c|CX"Y"JBرOh-w) qzu%*ڢ&2`8e =Q*Lk[ *eDS e)iRxsګ:ɟ!c a i?6W?=G9cx51QIX0A*!t= ҙ,E;CoHc.7$+ܬ,Tʟ((RVcRFI>W8oz[Rph(~>O:U KzV,PNY@ N3F,+`[ \1ȏˣ1{-鵒*(]PS秉(`H< R(X3s8OW8\0+>o[R1PY[ {Z:d3Q.L2@WD0zF=65yi*9+*DS>0]+}׸]x9Dԥ7@a4N㻚aS%ğ"`'g%\:yX<o(4,15q`' h_AN3E0.&rus ﳼdv{xmTWj5bs1ICk' 2)@~g;H;{:Z䀡Oan }fiy0’ۄiH. X41rgFJT* se$׀&-ύm rv&ɿ 5r% l9_WԶ$%\|yR <%D1U-$cs4='M(ݾ܌;kp ߙ2;;oT䀷p:ʡF>L`QvnNF!Nv^ON `_3,i;(wȻ\eo:"}.C(i`VU~ng {#^lSZCXةb:\4,H=rG4Oe\BG,S1I=Lf̵$FZFY=wFKm=8f'AR|1#UϏ֎玏.cЧwǴ $ EQ4Dߔ7774#>J8S laY|A (Iř{mq*a/ j'FrXX%,.ekMvt1;fw&P᜕DOtfx=U 6 /Di>Y;X9sۺux#H7-.o_ो,z2-;~LOWNdb.3#xi7.\#dshDV!ۃ9mK27%`<]/27RkUe/ P; ʲ9i?MD`Q] {y>NGPŸ~qBO2fЯ-ӓ/%Fzy!'do'Vr3%~J!:"WՓM,LI=eH/w3tmJ.t> PaSB&v-7Li)<en/N^:?.N%Tݢ) g>2 > !vd+*q &S1D˓{-*0^#%˗,?W]xAq(Wk(uz@:җ1BE!-{otf6D,Ǡ s[,Ѕ!=/rLLB&h$(y; Y?Ph}>rJUGsDaKh<pg6 %^+[#g*3 #lD֬]8K[kzPVu[ɯT$6`Wb @/UqteZ l};A1G/ id8oXQe\Jot9?CNS'{Kxna&Jj!/\%0OR?eǚ]>lm`2 52Ώʝ*IwD7UC|]=9\PңrF149a<@.slt5Jx(7.'P¯a+XSćn@))MmM|ɖ~ZƂX:0/Nƫ#(JqHPd6! IvAC4_kfϯۺYi|\ >h"@h&N~6e}(M(5s+A0Nen>vR}PacgXЧ,"s'0"V(1 A?*LC}=SKsKOcGIήDn(JR5 U`L[j \| 򿤩fU*X6/2xDU LkRpH`y H ޱFҺ=S-"Rfv l&j'tcAp>'UY'9}^AI;ݭL7 Lӣ /XF8Ӛێx7cJFuBҚV;?), 0-KM% Ld?)O_v75prSf8kAfyǘfTlK\ksinײ`) FLAp23撤j=)jS0" :"xGYm~ҡNckvFv Mjզ{HOJlRѩ *yqW0L єLc`#~ w-b lS*y y≅Ka(:qg[Q[([p_*^4ӍN'x66*l 7A{$kcg4mp;F`$Dq' rSPQbYbMC!b:B@Sr!kXVeIE0Ǫ9T^&JNA-|W_/'W8 }!AR2M+~ڔ C.Iv#Ƒ TAHAh:T7gM\X'O,f2:+TU4'B,y?~ݚ!IV0$Fy_ܜ%2Q_9wyb= (\7Dl AlL,Ǣt)Q{[=fz-^1(6!t^P7$T]<:onAͳȝG)v1N^1NWv~i[?\P'­ѼdM}۪H 7ɰVZrnRi;!*-O\9TJ<֜Q-D&=J%KyjCO M8=XȽ)&[+&1@D|*|z*WS^DѤGGx\Nu~lta45GAź1D Xg6w?*MOz'#쩙&ȚĊVKP+P;7MD1DNԧ`gm7 (<ɺ>ڔkF AHyK1KBqJE+{:mgL@=4b~{3@:zvPRjcW?\tXFRޫ<39> &G >w ˜w([M9!SxL<  tK8*DOKNtѶz`rl|>0t&t' f'ذ gyHI$ХU]qSH@Ck〿v 5ml@r>K%WΫwxbݦ@茐>^実U&_Z^=O2 OZ^Fq;{S<̱ =nRiUFelzڍ(#n4RY{i9[|pvmh |k`t|jIǥQg1j޹[@h922Fw; `2x[; 3 l80}™*SW.Ne"J<' IEH6Kq+wT/\aGi{C6Q<a8"ŤfhjU0>m@B ;\EsmG4I3KU,m S 3(B[\HS#}pz<1yFļ`<0+O,UY'R#WtOGER<- ݰ';MK:ڕƌe*ӳM4-hace\aQMkEF,AG~ w)&X `S9u]x8E3n=sJK?r,r;@b ~r:sp6_j|A'm&[Tl@vY/\] LV2):c s 5S;<ȸ&Aڲ&)q⿌n],~DBV^ dd}$D̄J._N \0WJX-?V Ai+Cwݧw(6P>E_xUP#4I-- b%W5qQ8)~s޲]`~TQ& &g~K{IF3r^[^/$C Kz>0$TTd_([KB#@3gLSg˅:KJ;x̡"%4RSo%(u++ slo  %&5c-$u-ܾ 0r<֪w\>7Rϑq%d7UK L=Uj#@ ˭@z !(MTd1vH`q>+dN_RN\jkT1G53,c[;Jcx]u'}baַ2/M 5rSlymIC?aa3㸻#Fu|Ig^5|{_K6Ќ" hedt'lrkIM2pM!a( ;Cw_ʱQ, ʇHuw3OJU`A |uPjBngƯ0Q]H8xzL@}0J߶ted;!00z䌠Olom qF6&*po5cB_TQ;A!}yY>e $)ilME #MR|*h4fES.07rV犟|ϩ+6+dc:í[Q~}G>]bxf>=˫OB:v`Fh.KQG>\Yf0ž>XY+69{`}B0\DMwn o,lzOŨO .2oN2پE#Yff]_B%7 '@dIй=n $-zsS*a^VD= XojP*X +6,>R:T R*4b.g8Fy}owm6zC>~ )+)Ltk |nSalY F*hV}Ga2P{ =k̃#ӡۚZ? | #w lMes$N LMXY ʙUWl!ʑݨ%*,_v~ _A4+A@F`A2;f k_KŨTHյi>]ˏ71|گvTesߥ'KXg`HgZ^u9RK#B?jFM,դaC/G&-ѧ\]K5po\K}J]$N%p6=nlŘ_+@9 j!^R_J?T s֎OQKn++;b! p?WpN:95̷t(jwTsKM[٬[(wӢRo.0&(oףiIfEG6^uyf!Uh!m3ma~e)l&t>L`c<9H X\25<[0XwD<$9bk@GfџM#J޷_9/"j6d6qdND:pfל[P&qznZ]l +bPo/!.bڲxK4iËlөMWӚ ^;";Gwn?!-=d(Gq,<Í$ 3P^-&{;`H f/7xl&gv z>W?՜Bcj^bOycZEgtm$ b 4ug/BmɈ^`RoS8l. jG4־ͅO"p&DZ4n#;ǮIFrNiE(ZoWQּCi*Qʀ٥2b*!6%zTـ^ٶmZIm[^!ݷûQ dS_~@V ǜKܖ+GEp8TpJͅ⤶<Q7|YAQ Z8u %5k+B"ɪ;vD}Su}/bbm^ kD]6t%Gts"xk nx)2BX'LyڜЎ6#4>o ͦXe82%3jg= 3A1'~_%*CÃ=XZǍkZ9%7>7Mk<~ =Ky[:QofdBLO V2dY;ev`d /:YWJ)ŁjE%$E bkau%#vړ܇% T5W4nxl*?TG`^{JZ'ЩJE\Dnú3=14 :) ){x=m]6]*km#kSo{͌T*Rˣ'U'Ene27-׿n9YiFmGg֞#?vx R<uQui9 K[,y>GS|$k6k ]P-elgEN.JC(NGXC8Io+m`oSQm^<1S;Fw̐2q8rϩoĦ+\.В=4CKH<*Cddg4wqU&*;%QιD~Q? Hd,4scNCL4:62FMC K ^Fl|־3ꊑM(<ͅwC+9e? hQwɄ `X`/DŔl- us^}9+141!ڍҪ5Lξ`N~AhI7~mX'iI' 6lS-S oji*}EWDo##JPm\ܚjq,p 1G/1,OB*- E@,Fz:F]eR tMJqM|IGpb>)mj?ME?좁V}3m/x |.do p25¹\mN$'%؜vH-! b_U:o&QC<~CQ,lڛ{a%K(?ԗEkw!-sD$uA@"RƜrR$~@ԉ(meMF 93p qᘮo[ԏQU\yuH1_ JX;1W6'0S[7^t!X Vf<2dDTvNP1ҟ*02DD$Ұ!cř*uβtډb.X͡ P& J&;qlīX{}DJe^F_F6E豕nҏe".: =P^,{Bbj?UϒC6 bH [CfC^cE. V]bC JQh CVxGǹuOI+fޣwk%;*r18%cmQXhEnqqQ u`\ NKr֙E簑mtp0eWLihJAU'f&\Ď07pN< H|"غ5[2')=PuC~3(!V]Q?ui'5zo Iv Z5u}R1|ET7s/KuRSی8_6.B[Kd,l OکS}ND[=]T|6o[3[yM(LJM*'Azc'>3v=A*p΄q1PgFD rp_)™kV.Ȃ֝bgt4.8J`Q α>t⿃hmaw$裷f%p~z<ԞS^a+HxK*v꒯{'9?*eW.IeyTش[L&C?k(`"{4؋:( oϣ{7˾].?8^1쓔HY "YkfR'|jorM^uF,0uaVt3qj%Y=lK^l ף CE70sxT!gn{ݥ-xfèX.0]MJ#+p53#z:3-xPGO+LQU=1dY#x,p4Bw-/"`ktܳ޶)wҴpe07 B29,%#4lSn84ћ*F :3df\j~ohHЄŢt6@z0/ auO u(&&g:@pY W'k͞9wc knE0ԑ9.7ў'2^KHB~yɐ߿cjz⑼>*,1̇i {vhFB'oU[לHZ ^=蝬`^OaE'g 0!?pB*6o1.;kWQ)3+QC@j9ZRe FI46"bbQ}˓QlHӅ)xPJ[8޸s+1T- V64WإVX7<뢭evH[3JmP2.Ƕ * ,"f/G|nJ}eA|@elbm2<=w/=XguW5BD=SX/{ NsrH>9l2JOA!Pv"Vތq-e<AL)#~Ca^ midB[+\5) WB:d~J\̏hџI^k$\ch /xwf >*=iJsam ;"+͋*z @2<%HeA>i'A{LP#t'Pl+SO d2uT[xd-|̇oqK`>55yRW 7$heVErrPXKS5׌(״W=;tlAl'W`sJj&uZxTC)́ WwklP>>DZf3@D?vN`eWnn$$L^ , &Ӕ2o,>:pdu9>nG<1&\XdF梡j$ v:~_]'5v<9H6Ps@} Ol-%նӏSS"8c@Fܸ&2ĖUFk 7.V|_fg ƈ̳_7)}DTc-lj \PFiB@[shpAD(ǩUd OW]H "K-i{RN #/tA<B9@[}O,cAMp=& r$e}h"gTSV&w{ E;ѹ-u3L*IrIj 0(s+to=SQx|%Ld5lݜ(S9mA"=Ia1VwspI{"DͲ6#kuJ'A< t՛*ޢnT@oF? aF2.b$ )%԰L$Kj J|T>TFm+❎Pkdqk_6M3F8jvٷv%4[: 6u\tQ|@JFyXג\~zɀ= X+H&i>k=QMK~ìiLv=9I "idTK-| vC<Vi_p+s "bC?ƀ-Ĕ('o\j+ʱ74ՎJ5ZbOM)*1R&ɠr|f}sF]*v#[SgI t$:-}c;΢󘪎ϻ<FI㖁[0a`*r+T(彪ȷA}Os%AH}ZIh$!6vǓS eÝp5%Xs)nOCh3w96C3轹%_LsD&VWI#3ۯoO*//ʟYy 6{(1?5cY@+= 12 JZ-cɪdz0|h(yjj6#RH ^b`kd<}ݦ +Zͫ%\N#0WWcI'9 m9fP5[٩)w3pwQM)BWQR>w ; !os0\Z8IUug4hwL\-֠Bٔ{7:)Cז˻̉ޭ\D?۸,]} @=ybAi2Rb}fH?%V0Q z?U}_~ޖdY|@dy gw?ᶸzIREb0P6jپ8my'_t[@*=9$l~lD H^yT]v(+e &ܣ?p]i6xm5'E][JG#xĝXr)YY]*}g :_rU1 OF=|e z;.h%0hqRY{1yzW20IM`  /^C o%nx`Wuoͷ0gD>hI2ttnO2]5g`]r#gBAc)%C~|jSh wЎEK]2&4 5]$UǾMaCJ{q}/I0;@.>Lq![M!E^*L:TFjtۡmԤų1Q{WqxM=C7|TNVs-H ]<Hıa>`8[^6 3I?^&uYj{Ss+ E\vAOb&A8:=فb!|7|.~)e*v%Bշ$/hxH0ô UC콧H<(Û#2Y;XyZLBC X ¤V+6⼞MyDTs3Qڻ+(/^WPf ڔN8,7ݵaԠiH@PgTBD!θ1!l`&ø(UqxVmF H~@M_* N0ZmHr#84Fn~؃ϔ~aki~ds\]/|> #v 3)bTaNŇa Cq]C9ndy(k=H=_ߞcQtp2&&^,X|!d@Z%)G;.OkW0S=Ɋ0NUQ4 0j2s4?SA1ӷ@#DeH w#Hط gOH5KAM `&P^{vCqn(F =bԄ5Ynoe:p2r$eᖵC;}AxHtAv[Mdbp,':O3]/B ,:{RlxKThHj캋GbbA{HpYJf.|Ƀ{ŝM{b摵*Eperl Xa'N ޙln[8w/ۓ̛h #zXTf$S67mz06cwvG9w7HP(h^&yn_qA/C9VӤ 'P^(n>nN wo꾼~BpOL!n{L~ҪZSͼ2M)ZP&ѐ:SG3Xj u#3ӷynw3(5 \ A r?z Xn s+082GcCɧ_7Rύҕ{łM3'/ʛ,Feu}y?s# !;feE%'W<jϊ6.ɔؘm;Mv/%'[ks3|ň2d VppϏ:G-I&m'o^Hz`D]ATvCצ+r!9۽6M٣ FRg.s;q_ +'^ xao$w*Jpvg/a5֛n9VO囯Kԗ9@kח% }Vk OBVD8 8Pidu5b`7(cPXf;:5)8ǽЉ~l6s} Yk'!v%2x>k9\^*K_Q !%^v(>@s-Iq^ʚ_"d4[oDKb#UnOɥ A+k{ɗbr ƚۨ}Lc\qPdʅֺ@ʷ2bREt"X϶*QWȑV=c>cjnpRk KWBNĸQSݥ3r)B sq&[.Nk!@iU1׭. ^T}f7zRuajA/i9[& I4j}(4脪oxl3:\56n9Ox|A>Ƽ˷Dq2SU `^[sqC"m2?3D 11CI*" kH uWʹԄ6 41(?=peo^aV3Խ982leAd[B±FUc9Bߝ¼7xGכF` sw |T:aR;ި ]Yi[snE<|iWѼY.giڱeÕ+ Ws6f6V_߈l;2rz swUtӤۢd8qq |pa*oHߘ@2 pbpjOI]gƀIM 3x6२wi:=8t9ǧUv?VۣHn"H^3cʭ-anz#\L`ޖ";SC?ᶔ%cWV1a[Џ߷3d W @xΆ@ h གR|b :Q'Eʎm#Ĺ~^Z"E"s>HӚ$|jo xD%/Z ϔEb] )ӆ"c oi#5^@e{H[mox]61AFNzF$9rƹ$6ڃ~-MmAg FIy };'e40`zOxFA8+ p!}H*^BDB-\/Ђqy-QK!U(L`b sif۽b-dsZ#ӽȈwHE"42F;i?TURj:M l_/ t\+m#b+-S|Xv^c\TYO!&FKGɦ ַ״QФ=t4Njk?@Io*<Ty#(sMUO{(>T֥>8/05xOiy:Ի ?17"335#A~bEʮػտz}\pN>HZI1gF)b S̮q%̀H12ʼB gތg~X؈3hʣL}Sf iZrc@fhplYȞlFRx @j'?b`].)6%6ʓDaQԤ)E&ǡB}NpVY2'LAhzZCLZܮɳy,[?;ũ8]IZV6r~Z:dYmHBϽ]hi^e}aUˑB;&g1DAekRImɴpdEr_Exՙ,VSPZb9ZN+n7{?QOߵ  F\n#ߕQcy #^m7}UwVwp]Pć)zYG%D;?Gh'$R&BLN.o%ډ&g#:Fh@ Ȟ3T!f3\ xnKx2)OLP4ElA._| =hy7~8gjI2FvjtD!۰,|htJ\9i{ypNSkG"t>jv_@CcCUw+>дB}Y3+U2KT9 rM0VU j^ts" l-E۟5xWCds:a 18 7%3 ;RYE3{-ɎF翡&O "%yHY^,qk^NYJ읹 ԸS|J1]ji|<#bc6'KN]84%VmX_,gۿ'g*\iu?vd%5.P xoqTeRbj\_mۏb]8c0yJ &Y?8 {e!5_W\tkh7={Q$arKV5Y\tߍLbuׯP|'}=m$#rC(_8nT)R/tid36 ,_~aR0̬ pX :o{J ?eل =k=PcY߶D'bh ɳArD P?$l=z|KeŐOcDɘOYi!iDMQUD=9;bOu[ۑJiPw<4[8ć~Y\sN8#^R`@Z޺VwyA^tENGn2q0D^@X5_.wHl!/yrsd\qt1/96kaXC n2o$aVosKiv#آPr/ꜵǫռ儩> n "YUi~M1 +t) 0Uwej{vq}!VS71H'&u=2k;., Ν5@>o-WC.pid BZt!=_e! X Dق0loN"ƳHj! z,jo7Fm.~xI`rǚtX6\"<9fxMmy0(APի0LFCKg8bIпqZ 42LxWD|a8 !!:U0 T8{EIH힩7+=jbc5ɕRH1@@|*ʼn9\ i& o- @]Z3M5"0 1N?*A nPɥMHo/G_AT1a/ a[ϸ2S_sz$FhGVGdrzn)&p>3icp8["^έ#Qt#U&g V,ӫD8$ OVCЛ=|+]##+x)`3+ؔ(-vOD0g΢:kàr ]ڞ.h`xmlU3fECLxQ+"i^ ;ªvYa~dChd 2? )b>#R)>*myx!FBPhTڼA-4-}t 6$dX[r6U|lN`-%}mBULƖnbH#=W81 T(Z7Ci2npklţOlRL|KP}R2?B@c!΀qG1[Ѩ!Y%)Lpp"46rYxȻAe~_%VFTc-@5QE2*HB%*>K- | k ۢbc+]O mk7<^j?lU@} mg GpY|Bp|"dŮC}r> 4;LD||WLu`8|gh&*Wa0Kl\/Ġ-ڟHT1 dP-V5dkMDs/Gem# ugQ>eT}.NmNB5J׹ HI~oD51>!~F<q]: 4^V*5,S9ÚũPVea5W#_?OT@h4(yrK9 1»*(5sl{e|݊̒tPdqqMaSڷ"r)e;Xꎬ:vyWX];OܗB3ߨ P<>׷ )QZa l(;aYU=hHx!B8_l&#׵!biAcf`}=e͘ˮ{q" K;C;]KQS U$b4&igEi?oùV(^#nDXrj|5|ŋJ-tQKN/j3;@(Y!^sgH[l*8lu XT2N zs}Қ 2€hF8(9AoA*?g6tM2twP+lQp 8\!zR|  /AC 60p]Qwډ;ebgM{y T 'luxذ:aEIZdmZ`sOpM͏z Xlߟ~, Q[KBxtk1"E]IpG>OS, :HfF"Χb+;."$g8\k~o$)6z s~F8 hB}|sGocP7-[$Uh#7/sV)+^=Y0]M{`x4 Na x|/ ~G\VO,~% XY4nX{&}oF{ Ai|8`y׈|W =GאFw]3ou+d-=2bzmKcQ8B*0<9 oH9FDMõ8f$yn7; ,xg*ݫdӶ8ǸRP G[e0@,:3, F'ˊ|c 2dh(S=RO|%X]uB[%hm t$=AcBw!l|J{R߻22꫒U!E uq!?=ܢn]-q̠ ߏ|8.T+KviiLvVq8C{<:(`G!# /QQe`5eaݺY?E l`L _38;mIZXdr ҿR]Wpr2J؂AH5HkdݺTzeF% 7et "|@:O/1'tu=4kM_ /FE?~dLv 'Eq-H g(v'k6o pze>o*da;M|pB[b9nrdU' o`a4?XGKpEZnAPU.H[qVQdO ?5Ȟfх9HoHB⬃OpV/rc,t4OSՉ &:cN(4^d"Ju R{jL=לн],}קh®FLz(׿6&lXĒ g }=835E9&x"d 44%LTJF'[m.>U+Kť70Mtƻ3,șBb%C>)$c$ eIrS%R vT.nAófϰ>QOUrם+"UzY'~ta_Յ3!lٝXJ~<_EgpM'_DrrC`6y#0'w9AJHodj ZzcU /Hmx^3,[QukH.: :P#- )GCgc-ߓnY Wm5|mzZcY^m"y ?;72|>x Zt$1¶F1b=t_ӈss?(ȋBŜ6ީ5ב֛Xu@?r +i.\LHM | :bMܠ -?D{_\i@'<J[(ƨ刹1_FI:}; aN q+e{JX9ܔZ>%xZ=AbKx]K񾋸Ѳ=`6z"x?(JŨaXB7Ef[]Zi^?c7Wg>O+6;6 s\Ga4Z.3cQL SD cՐ3Jpo2]~*I,!5qŢFnFRh@-ZB!v(QpVh lG9NMB#j8VK3jL>e쮢v p*za) "%0oTVX0j _SU[b-9DXL '.H̢iշWm>kH|ь"^7h2r_w=gNegjs/cJ?7ìvg ]O&ZC#fS'Èi$Ts:CD&lNXMM6z+~A2vƓэ O;*0;!kUvOs2ɠҲ`)t+|;x) )p,}(dɉnf^:; aΨ^R&ȶna%7HjQѽ;}Gn[֩ E!Ѫ".!%(EAT \ewLK|*)L5r~YY,[9iSqjh0*쑌jh'Ni^[*[OB8C..jP͕UaoqաlkxU"<tI:_ï}Jg&{7أP L;` CL}JzY`Ox]㡐)1AoUT>*Fn/ ;h+}i#+;8x]%έ)BgULr"`(Mt!LozlWK;lq sV5gJ$,'6 %OU헿GҾSükO%1 =oC$B`t9lTt9҅tAԱlݺr]S韦b㮛ޱX#ott~zy, nBi=[Ցw1b oYN@x/ so%;?~dQ^>~t~רXsdql UiGeBtrc9cd>pј\9|}.jgQ );_lyyZ7p=8jvM)J6gy}zΑjX}8Z ,@dKD8ams)OcD`u#@}٥9bdl͵oAg7!hY\PzI(|lHpJi3({]O '_7y+f.@7 ?2F)Y Ta` |5덟31)J;.:O7+|{u+;"b܃`&<)v4]d;?L~'q7so@ox "I$iv3ҾV"g Q 02)]e=7| WH( In2 [S Tn==T*pe E|% 8C1455mu #5Y2ɁGZ⤄ }QGu cIeK,sx'?f5H't§ PWeR ׫1](^$Vԛ"J#TύϿLu;juE AN- =]Pv8eWfZ]kS_aVNr^Wlqb>SmIa?ynQ*bP8c1^Yoa1"MAh:ϼ*J]Cr*hȪu}`$=i`fDdnC j)Va[֢읎XD}>\Q!7AWʔr['#ĥFV;=qau8|vd<&q (OYVvCCiG>Wm@b ͎dv o9Y?pӄb'ַ93Ds,Vmkjh]oxB i; Yv\WpH2-0eZࣄ$wUeM-8΄"GL/"v;ۡN?ޕ݅KSQߗ='R^$]D3T'%8IqMSs\Xm?U/V+90އ ifϳji͵3#)|*vk7?v=OÑD RCH")1qFUXU}DY5M? ܛ ,)ʞm,@B)hH1 nԨv&$#Vn%dj+(+,q~(~*9?Xdвt4# ׮X,\XqR'&sCĿ :MlRR!QnʫrC< Mei0'O= "9{MQ<ƭpg*JMns[]uؼ?|1=jE[N=WTU(RZ=YG0)%{q>ENBS֚(;JO'HXknp_)Ha\3)5>鷬ׂ5W>X+%W~#]KZG,]Rsj^Vg$_%P,tf9<a7OSGm(n+j5X ̤sh+c;*IC`Wm[zKaTO!ą~Nf0Ĝ?MJӶ>i6L;6Ԧ,kz'pJ!1) F@%0 o;!i%HUrKEʢ1砮dfEMs?r%@aXXb-f.sZ53d耷${҇8@nԷ]cBa|kͩ0Ͷ`]N|k}9"4iDEX '/ ͅ#հw/@ sU&j[E*fw=/8‘I1FXzZRP_pu?ZFabAiҳk< :xLQۦS` ^|XݠBwG"u 9ȥO_m|pe~ ħu0Jƾ0RcUieoW4ʓp8A6Gcף) `hLh.i!:C腪fFÝg;r݅mu|9oZ{\rĵ4Y9ߒ)S/hZv``ȠiF)$Qq7&'2ti,)؇~خh(Mc/'DGbw3hGTc1`7\Ԛidw 44zByKNwNd[(llZTyk k-C#oņ{l7߿(K{}03]tSV%J&YϪZ s⥾`Eb!uA% mlKIz\ kKR}uB8D/N\WMoh%t\ģa1 3,bmyr"W ;7b.iڝ܊ORֲ'7iFii{Hhv% VXѰ-BЀ@aE/m  Fچ~5rJ60Ȳh)*Wg0a?u=tg},*Q Nj*01 Ra$)IX枀X|,9.Leg0 aB.1šX)QY(4R4FpMt#FY}cְ9Qih}Ϟ% zլe9jcpr$߾ol-_rG Vs1oZCi)\3ˁ u@tmoI7e?@SwSz+MCLqӠƜ2N?KͥYh[ kgc%Tu[̏m詇H6W0껱,;cqafsHHգ$0Xr**ϹkbA:l9BPo]_:10bl?# ?/f5r-ʮ^ d-U+ ҫ6эh cr ֍,ͧ3$6BӅG3Q`Tȍ($p&RMa^bv{VOv&l6 "6i s+&&Ut͚5cF$MF6jh\!K%u>A^}l;&5Nm,'+ma[+Z94>\q+ vtx,e'w T KIzIfF R Z3qo7jw^$<*OMm& 䁗*T=HL͘%x_:Q[,u[M?tz+̡p)+x^uoE ckֶԬP[a} chtxEx ddV*v>B|+QfЀTC(,s(ULSKZ~Z&?D r2e06ʍX pL0 `]rfɶq\(c+ԗLj?Yl]ߥA,CcLPTz3J j1Fռ%z3$>6'.p?A5ͨbL.PS4_ ۧHw*SaLkst#M7nQ$ 2kӒl)aCnK"tY`ߕԵf8PwgU#Jlb a^UlF AFPG.x:}-\y̤['iז?b7v`Nz-bDkeUb>q{/;Sp/J/8#LÝH]̑N3ߪ5c{\^+@#9o 8\ab\?~6-.!mu좹 S)ߏ.e͡jDbp:;)sKS5*!;EύoB خE(lFwCnyd B 5"J 9&Fq_ۤ_.+Xx|7j~MK^5eaw>FN }76 PSX[A`+m2Z6gUtLS\E 譵7SF\k2NDB_E:4j6%vOAMWP?+:[+>@r##݃ =hDN;QoˌZ>HS2uc='S4>mh6#*;5-Yޗq!"#i-ė›e{h֐f;>|gUǶ !C6*k^}>0&Ck$DIu}5k!E^v9/yvqG??WKF&.& _;DIJ*=rL2n9fqt$4O1fhnn$f<*6~S]9%1Ʒ.mB`}gPg)_Iğ#(ݩ K͏;u[1~;NW3]s (p->r]eg|1|/T&lM*[gRfL!esYx.hAփp $P1 ɂZg(^ P䶹6ZWɈ#Rh׹^[m-byw%Pfm&-AM Ӕ=>ٳϭ!&/GK_y  `jH6WFMg# %'՘~]#(qv }""4X&NShgKKX #hC*4D9Į7<|lo._޵IDȲ-&yn~z%<O.R۳ bsŇvO~W:oKeP&m]yn|pnV X4Yq+R0lrVfS#?X7gצR ޤA.AEAcr`zhq6iUAOC2ZB߉ &zgYU NO n'rtW 9 ȳ o>j̭} GGC t52TaB(/<^_D4_´UvM|;>m~X0!V'='p.ZT02q]a*T,;M Ȏq,O etz<Յw0N*xS;>5N *!ɒT{`kr5_CTxr~ PkFCe"9!>'\հ쑏Td,#:V;9:~V'kׄ*~imb96 d,d:IbhPiP$0ݮ!0Nآ@ ($c5peYz9:zf<}MZ57n_/КSXc2kkzsDs 8 C!b˛EAK 0UmN#HCI%~wqB ?[L|zO#3C0- }lIU܏Yf!]c[*qo+. MIο#)p)H=&ԥd✯0PcL&}R=bցR.Oji˧V kik]٧$!Y/qh 4nzCtEPFmڸYg$^H+N@z6svo 3vKƣu;&UmD)3p _ :w"gq>Ҋ} ] "e}un~Λ&vU}syoD].pn?gm;+qЌ.3{UhrUDJ2ͥеZ#bې9 B.~:_yl m(RɚqĒ~#FZ(f'tF@6 P~8_DKPbt%?1fI24G ݇nx(ƾU&3s^%9~9>b0VJǃ> Iww<ꢚrP@򀻌}Ⱥ cӦ#12 ێ&a0͜Ok_;[ |N3 X0~Ouc`v&2K0xa0ggT.peGXc"ʜ*Y7 8n"(\igxw1JIVhKjߓrxq.?:|&J\kOql+|]5mV+YsjfFBI*|&}NN7&6.8j+vZڷ*׶8_kb'Lw x$UB#\  p_|.X7֓Sq,9Wʰqkha$ɭ1U&[RH<;Z5z{wC'{TZ\YO64œ_1DzpϺ|07J).+y=1;@޳!ZXވ%mU%7yYe'},k,}s8 g7`PʨoC5X~O6-C%Gԁd!A7"b8U6/w$e.D/jj}5 |fn̖ATpgĆs[ij.:.Ӭjz4J~cWbJ_C0.vݧl3ƏUXwt3槼y eiKf֭\:Ul_r}_I$#Mpӷa]m¸ [ٞRn>ޙRP`c(.FRׇhmQxD;g=O Q]2T\йN*F'{!RSMf3TMB .-{='g+l3xrgkju) SK,0˫ESJu'E :#Ma {Y.8>B;PDcU1Ya o~O{DA H$S| ʢ) .lrSt O&b8wR ﺞb^Kv>hqSf(ʊ_lM%@WM>F3rƮuO̼\Yq'?} [rH<%AE5{S?[қKPsM ߛe l%c ѲTck6F"Si N75 XM nJQb2Q#ƿʣ`^RR)RFD!"CX=@JY{,ueV+I_L; 1W#(t[.g"g`MuZ'>"d}fr6ROOC$~X뉯 WA\B4m[&2u:dLboX2 TƟYOoK=;' z**PU[z5`>jܰ L pH=:I>`1"!tey2<kb_^|yM1(Fr]c;XtX? I)DĻqzN|PL=vB*u ڊśђlRo=Iq; m֟RfZfۼfM<ݺ1DԈSBL+r )kDbL|x*G;iY|=K3 < }0u_ujj%6r`07-0ϣ0DG"Ac5S5=$ު3_c_,6ڀX5CE0ű{@zd3<~dLyp*Cj{܉HZ'k0.8ϾMK oנPC܀9t ʙ_n0 j Y΃r1oָH4l)۩2[/,L#0H)ʳq#=~g =swFo!1 USۄ Rg!5>e5+&渼:h'֔TqQr0TIJ%(f{g¤} GYD1]_嫻c}Q}ncy#{y]1 OEg:.jM#&LpҬB;gvjkHjP[mh!%#RE<wNw0hJSnSxL0U5Il/n˷DS&QAC=u5䔐ƪtO|v+<: @p3 t`FRIDMszߑKȶCt!`<,!zYtfDzwq+raPu54Fn WSp.v%rWiP\jԖp)r>(zTHk.:\<5NA-vF@|2bzg99 o% %M1?[h1xak:[Ǹ0itH}` 4&N k7~^(=*ץ˥n(|Y yH c:7g1 *$c##jBr,LjU._r<Q&ؠ# 2D8X1RSTm~53hȈ=^3/<;_;"ANaF:Ba#{T(aW06T"#8VT:B~¸b`YfyN/|ç2DݴP94K\K 1qxR.9ᄯĆfֱ*N[.K@M@b Zœ+$&:> <$Wm7܏O`M5I{-&< >+mCc]; ;,. h}T%2w/i8i{_]{ȼ3귞 y3!GIXQ5iOC7HdDc7WX+gUAN+wL;F L2$7*ֵ+Y]۱pNyH8lG\h(a(d=qTwmZD,6_A騩Wŋs*P=zIT{Byj1Cj&B&H>Flql9ɃBMv@BB6u@@zR}%&wc i]|Sx]OD; ]%|A{*A4yW/I^ &}X uiFk' zcr\h˽ݮ\=l |w:L&0C /"'BW$%f+56{G+u%Uc `sD`qb~`l]J]#8i(# k&>&2pA LO;>sُ !HcplA$2ں-*6e aes.Xvi_9no +7$$(:yw 9(>c<`'נsC<ĉUj[ 8Q0+V/vҒ(!֝p6&.l ",ۨ.^$_(=1#+SrY#Xm.p묓wZHr>+nLAxA ׍Xs68 xg ހQ:Œ hJZƲkˠfEC&|/f'lH蝱g)5bH7gS4u^Ea({hu"-C8$B)]@&Ŷ&^(_ BKu)(ڿ I<77+kWZϝGRa-g`v|D@'N=KLb(;zϓxmOoj0Rלw6wِAA߳ˇ$V;_q{wju:tw*Rr` O.HU< ^o%m;ͫ YL-?蔄Xy(uKQe{ W4R).lm%4RwFT[@lnT"X-׿ʹI=,3I?L>b #C[ï"pHxq3E$^E|]6FP>){jQ]a5P!D&{G5IEg|=8I\wYsSR-h~}Uvq aiX987aF 韰=, 8,*FRUkiI-Q&M~ XSA:+]kmnloՖK'-NUkm t舤}bCV`axL"d-?~f>(AO|d͎ vsu@gKDN8?KFjG\-z@Gq_\  I<ydPC5/7:m0)=oWe1/˥x/rAgMףQTF'C01GU˒ < ։o9V}s?@+L5Pdc~N/\DJl)0NȱS/dZqsy:x)D^by+O*Ʃ\:utot8EZ#>SZtk;lQˌк@!%hJg9 ŘѸbY*c_րjު&jW-;;īsx{`%}ԤdCFj%1S+{1He ծyAbXtf90BQ]Z{ w:+iO24i^D.{/ c<}_m9἟%$R[cDIt|"<jf &cMlbq gE92OM?^\FhKvɬ_x̲':ҳ:aK8LgVRj@?umuo~hʕtY; ^Y4L"S,Oc'Q@SKhܟ❏Y^olբ36@LS݊8rBI$5#i]Xu g)*f-\r0QJj8@c$4҄KJBN<2Oav.\Pr;>mlI7/=@ТEyrH"wD'3Mk7,} {t'!o~|\.FVjd!W],qL}#. qlazjo2 fJn(ɫ'홡}GsBy}fP * OP(h#!d`Ѻ+e0{psmQ+FAju b`v EhG =&BwNH~ Mi~90bGCP0ޠv0Uz_qX#?San1Vqo 0Hl`.:Gp!o~T*R7 fʗQ┱(o>md5>CLL9~P> vt+xY+*$̜FLwP]1DPMk%?:y ӠrԱBexm[ K6툩bڈsf7H\m'3S]BKݫ ܆Z%Un"k[[] -\ZgtAhf4).p Y6t (x5|7L$TӼgIMDU` v1v-,O"6̪ 6 kJs*Sg$ ԫ[$ʌU}l) o+zHr:{;Bd E,#tfkgIPD݄UhUaWГodi=R%QB8.Ouo8{Ua"؝f4B; %ء76 "ᥔ<'i B5ҷE8/߈&TM]΢E}T ?2296{Rd] AI:@t)ggC苝MI`PYʠp+EC̣%rDZP&d{sQ7s!j3~$IP:&R"`׶>Ӳ!Ff~?칊g "1;ސ0-\Tde PsprE"jHbT2r~$>=6BIz8]+nVg!8!gGE4`Lyx|EdvpUp\xUbmF~CI]DnKnpՏ@{:ej *`u}%Ifv< ;okGBO-j߽D܌`BC)vJ,d.yGw]{%dog> 1\z͕,^O~{SՄ(ԆV9Lp%,g3ƍ>&(!.[|2w.W3p}E/+a ԦNmmd5&:ۊ" Þv`GC8xyJ-x2[zi%|윐 >J'Fʇ9ռPڤ6~] ' NGϬҠk53su! $UHROw*o6rkS9ය;v%@|}]@b=gǴ==WUi&ּ=۰ 9}L%;vQyGHW7SY!SᩌԌ$?.u(/8i gl.Pҏ.`!qjq-ÚSBMJU]vFqH "PېoN : W=bwS[15fCȎ֞* ۻ7(hq'3#%9kxbYo "AYI&%;-,j! ςJ|Ĝ]}hM,_Ib?jY9,w~p> 3]GoGv8262go \w}˕ta^Te-H%ȶ;M̫pTD Lٸ4Ȓ[5ym"ylfxf7օ2S#UH*ܦ oQ8=6G*znG<݈rQ1Q)jLp};t 1R"u{ qqp2"b&hTIgHad=97DF-`rTJ*n2xm7pK̆ s_K ZM8rn5v=  /'vӻ 9m=NPK;M-ZU7qj 4*i4HġKVgŒz1X+x=|e\oaE+HO]1P, daIԖLKi8ӄ]],Gk~Na,̤PsQ?f6@+7"ns-|}y֋_ @@XL*d>vԩktuoWHFι <٪Oml7_xWKoȚDRJ W7,h2Αeq>Q%ih*M IfDHm5@8lֹQ~>n޻%2WdHz6o Gpje5Y 6քBJYg&quNέYX@5dfV+P)nw_^'w*"*dԀHNn@qf{R|h0VۯQ]A^>-᷿upVA;DUK2!ׅ3AQ0 |ϯP_+[lgH\R'd^e\)wK?](FkI"9ۖ*xbmU2 KN&5*SWU7sAKPxD:lXfo_zqǴkw9N@vhy]V wU=s7nyDe[CѴXdp}ܟ12amh_-S@tڤ rNqP3*Lljޠg ṄF 3`,I(I59Lkֹ8s$hj_~؊$gClvm̈́Ub:XgMS1 *I.tQQu5r6"A؎{8![8 i>-*L39G]^_i3QRj+VduIvB(njD) hr@DP{,\"ɍz3vj@)Khxf;ˬǚSHldv: XK34v0B oY\CH{aw2"b3пgwLcp Ѹ/?9.&Lf+:QM|#Aj1ɺMѫ2(؇ ۍJ]!4L&ñp/[oR,ZJ5Eg%tDStoo )LLKgSJ%١Fy!?^~6+r@R(wk *&pHZ"Aa_ױ?לRH4NHa,snU &d ^-Zt@ߤ;trBc egI}AZ bh TaicO }X5/jxy;ue*w(x0Nu^NNS1xbleF9uQP Y{aԊzg+Wɒb Bj%)gBh$[.VξYcP4ݨǑO|n*W ÈnFOZG ɔ7 9_0 t*3oA;l&X_. W"I?q R\Qo*&)Ln&+Fw11" iYEV쵫Jzlđ8 GĀ˾_pcY<ݝ! K\Q+Ynq*REn.FTotT\L@6C•o*3ǟY6'a](8cx9mQݹp8Swݙ~u)ƝeE9iw#7yҗ9RH&_] @,Zpk!=v*y&aK)o<8r 刐7 hƫgHQgI(F'Gv5awUu*8T8: qR"-w rm O8 &gDNm~͚f Ƃqb! sh:c6'DIgP]լYZ40fn;?!]ZnX0"!DB: =Qq^Ɔ$'89y+t_\ ~b ݜYx-Ho-BxcK?ɶ'(ErO2r=DdxVLzaf>KAb+Tp{;cJi )ҷCcA 3 |',vUsy 27*/V}Q?v&5NDF4,_wCşY@V5 1Wx0b7=R7sK(ГĻ4C m"+!dAz e>kGdyWQjfr0I^,ux[8wS':*{aPi99TALXif8^5C/C9hb=Gl7$vɄDKQ w\ KI;R7>$<)\f8q0}Pir?{REUN 06Y+sW&uڊNCm6GtdkJy_[DMfT'5带+ۈC1\=۩I{洇aoMKF?cͭW[5uʥݓKr6֒=\'LܢM@@C,p&ټv=mx%x?iWn]7m;Ȝu)/.*{I 3^%Cvy h^kXO u>;ojASͅW߷41hFǰ]鸖z(.1m`u%0:[y? -֙w3n+NB=pj[ =%$2s`1*(*$ S.{/"MDTOnnXsXl]8kQ~9J߱>ݓT.6D)(_A;dx$HIQ=8\)C<"F:f'*?''&ӣQUi~?a(T惹zY`&&9b߮SH[j8g~D!?\ +/@ 66G;H\7; ҷuEܬ)UPwiLTs,'6z$grU*"D)/Ld0gr6:ɘjbdмhhTM '|.x#2NrvZwva;f=2:40ĕ5V2!ps?/h\{V՟ۇ:A~1> T%R/TX濴 oTuqc-%٘&iЂ]븦z0잝8_ҡ-E(6d+8^^Ny8eE Qۚ1-*E*= f35!e$ȖTx:QU͘|or0^Di@XT&վI bq@,6~a$%DK[e5'~gjll.X -` É\g+ 8ڹoIu ϐa׬G9DiFsXy*xF繋n%P2X#`s? ɑȥFhjz׈nL6kфL? .n]ֽQ>=N}BGV_˜7'>3w/gZ au[3B'ΡԴtp(4, vf-u#n1B ѐ#",HũHU@L͵Df1݈7ybXucەeMe|g:~'cᏁ0?3Ft]BjďBFeļR׫A.lioK_m2|r?JMhVL&F`eňRd]3~ WA ߱'_CF.@ߒ l/eBpiΰ(39>0[dQ]hHa&;SyZ5g \ZR>'`IԙgQ4tXuxTDf=:w_؊m|=ME}'Z( ŗ|BR`\Ggí Yu/^!yC谫Fl29&FQ 5ksCEEYKnx;U*ڒNX.COIu(y yr$Z/PEt?u]shL>c4ZȖ 'FiPBo5 Cӄ@,ujȆΫb1SM㘅!'Ֆ &_p+yud>6RɺP2 A.nFӡ,]_%sbPC[*Oׯ2􍓵[aηJv>AwGJO#h1J3cC5)s ج=tsBAgK z ̉M P2(cߝWniM]/f]b~zEmXsc'y&;"q\Z{ vb?eDjYa4_d!G6-+9PMbO2hh6]h]HQ]p"Yb75^A4=´H]{^-PZX/C&+ &'σT'so]`:X4nmq'R\F Z1dL`HdC*U ԰eMпSZt=/ l}z1H. ͕薮aо b@T`?@ t 9`K'ȹI 9@cuҧpE\`qFdȅDb !E=KA {}S Akμ&"@h9@1an^&0e/խCftSɝB%|@iJS6kEr3ZEC8ʰy}yjzs ƍ:w^Oiw tL-LL3ߵ`"Mg7q)1B9Y[Y7F9IR v'[`5(R~aͺo BX%ۿkV'[Lc/"(s [xM6]e.m_c^bXֳy.;-k Njej1n NB,p1܄>0M3%'z}_~qF PF1(}k ?+Eg7Ȃ̈/Uqd&XC%UMxqϻ'3+}[f5]ZJIpKgQMy@MsȀAu U@匭hw BdVP7;z.v}#b5tN ?-<Q#4/ 6*=`$?3^CuaGaddwr`ZI!i:1L BMdY٩7 $ M|@pLĭs]+CPSm]AشFC\wr6DBkuPI"k\GxK'"֠alrKb _mkF7~ 2<]hxn i(r7F  nh8 @O=%#dwC^C3Iڣ `ěGx' dN.P3_Tub$,;؆ bvbcf' (.5YV)0myĔXHoN݈BNAӡtZ`װ/*%BMXo&v@@5 2MQ@1]j˯pK  dA0lU0굀+gNaI 5V9u`|U 7K`Q6nSzS) (/aNjvCRa-'x28w )n1tTNX4沿SNSWv6›b?Fj,Cvt@_9yZ\|T_ۺ 9܀#v]Nz)0w0͜ђ<[{$,MC ]^Qk)ţy:e᧏1Z&f=()|0^chLmzyV}T*"gmeu yvN} 釕NHھBfF;#@@vx+\շMy`53W㾁ITMQoTCm7{ɶlȱBgz#r(X@I{d[yɼ#xO{8.e9ɹ+wl$jo^}H{fVsLT_S+9BRbQݨyU?K"AaOt2UC%s V& ؅{bUu?g:=*J63g>W#Se`GPȉهW]%z}h^ZAKVK'B'nR6=$ӀQ=Vbi]%}&g~M_%ҴG S{PTob=εmlza$+ymVZAL#f q1 o9-mDl)"l(Ԁj8Z:8a"XX!]afLuPC/ࢬȎF[5S~7QC-,9`"~I9b5IgqY̊LL1xK=0K+;$JG ,ՈMPa叛,N/Y$->dIrc`^@Hb*)9:Aܣwt栣\pr|xw~kqW$Fkp@m+^ ai)퓴aW\i"(@ +5tyIyLD$f]°E/L 9+/S qʓ4͸F׹# ~[%U9"$-Y |'Qݮȍ߳gfۭH8},-ư)^SEc*BU="Wl >964AKI!*+HG| ǡȵx4Iy?]g3᫬ ^#؂uB闙bZd( NgVw\ĸ&wAtONS],rqYT?Aʎlez˲d O/ęFB33m,GįӔⓡSJ) v8'z2#N>/%k֫VߟP]+u&mLvٓ\4v5![-UbzJ&!"i`d O H*n~fW3펎$M% bej6۳xN:Sj/v{Nז9-ŧ^}>QgLWԏ0 9V-݂z8:H_Ujc B* 8n^-Vbq+:!]1αz<;[IoL`dV*_/X8A{꼿%7Cub# X60χv`<#OY:7dpōpPi ig*F2g)+NYb->8DŽ Me t[ԯI~nr$gMuz 5M˻aGLg6d$:heZ$ y:0~n&D̡" Rtbzaؑ9Fs,[:&s@߬Ov^lG+~1Z[/k@9r ȥ4赮x,ɟ3v=~' Kx3_+ʪ(o)rCk +Te_ww S HH.y /\ IX*,;+ _*Lg@E?\CDX}C_)u//-ea1@>'@V s\1TGؓx%sW0FCs 9`ᯌlobARHaNʓKhtĐ~bGAS2QShxq2i=om$V6D:Q7 \僝03) ;&ҵBOΆ,p\P7tWTHF_D!\i/j_8}},>km;1#MXtXk~ (~g:c\BixO: e&r."ܲ,cP8oQ^0 UrEZ@aam:"iTͻc̹c վ2<9Y ,3 8} ƅ3.1٢'`K|rLk 2(FjbꫵV^ @m5 7Mc5(U&&VOA }^zJEks;hal8Y~"{+^^xSv/TMp5jfU*iMuo_M>V"ߖDeamc=qC~GZ-)d-w Ѣ?nLO!O~ 3wŀO6H?aђrjj%?[*c理%"Iph7][q8. iNeu*Ѹ_߳$?vfy:qFpa9Qw^mb<~Y,z#9nЋkPIufOɞne20 ]9Ѹx9 sEpQl1&Soq,}ߕ =PeӦ:і' Jyxc.]Hd9^STVO3־w oDDyvz0%d07YxG.~sEky'Ԋ?05̲5wfB.bڎ"𖋦ʔ#;AJyK(iϹfdy}j2Q0PmJ\IG),IpI? pN>v`6|$*XnG=dQ 9$#H-!J2ǂio ):#XMăHD46y|fxѿu*it#t $xJ,wf$P>||Br-G[) sIбgPh}/2snxCg3&,=ҶR˪͆y+>Y2Kh}'vEBnkg0vB1rA:m;fT(<k* e8'^:cZ߫YVħM?RdsNuK\W -XUC8,,D7㺞ta;;nӌӄ6H0SCj(H5&kѸY~vj`b7%5 ZiIx*ˁjUITw^7yT "$=ݧOU3/qV ݉_'c]ޑi߄h46eҒ }0Vվd6L8(lsD@wՉZRQl{;uեtJ4I?p71'J,[4HUL:9lPD]r(`yr<$R,t(YW:,J4g3nk'Y2sSpZCFwBui}KQez>ў?;S _~}5i~;EU#"OҐMk񉜺,d?7_{oPpBkžKL!$C}#߉~_Qg;lX}8{o蒈+),~tORr3λ$Wu򔐫ڿ =[7Hj|ѯ2/23&'e^!,ۼPP6EFиbgbkƥ'O[ch-Z ;X_3:} V+08$m>S Bp[d% h,nmNT׼\Ӹ ?H胍fhpÇޫ r$m̕C*{"KhDze6+IBh &y&)rTQՔY܊Y4qZbޢeQf Ӯ&fc EgM=9#*7~Et]m /V[dp2±c9 \\|iRX7SVe F8t]O'-sKWP"ס#wNHYECK`^zPͦbF[x5Z^wWa H }VvC)LY*ЕBHlaXQVyNM=h[cB+KS /@[U7x§I@ۭ9nId<*ɭWY; ^*Ufs<_cT1фH-U -6-9 Zb|CZ"%hhQmG]vv<ʄя * \(seC[g~lnbB1kCD&Bn=OleSW6!^p6WZ=_PB(~:~5uR]& I sz'WpP;t#U+t,%0'hҼ#͞[Y@1c Uq3 ]D_qoAב.IB6 ΊocilKL-r/5Ӵd01K&pIvd+6Bbe/'!Ic`~:]̳:h!Bh؎qi,lp m,~{ K9ܽy\l!zǧ.q]\(]B$z &y3cknc>]5G}+YЄ le/`LT3AV,(_wx=RvBinlկ:| c%b·Xg5N9$D]ܼDy_+ \ VrmwyYge9hxꐤ\E]<-߹jSoI-sܐ }lΑrEAִܶ'Oi Ap; &;Ln9VE"/4MA|v@3lZW!,^ Nnp^}ՓB\Qjx*!9p6B!"ÍQ;'6>Wgo5?Inlcj @0q׼M$j̮"_/#n)vjĂ1pȊ.ce#3 .gUt_%OY'9l$LiOY%(_HAe +8%*) J @\Ik:1̚Ix'\ կHe*729A+q!Ha558&v驟Ua s }F(EF2龜4.}nH (fL@v_o$`Rn0 Xg稜k"eQZD!k|璟a^n.8w|[OMȴt5y3T % x;Zt7m֎f~ПT4Pml}s׎CUݏЏ:`{ܦ>ǝiÔw wʦ~{}fA0WgZq.XHA86yrX{O$LCHy#[9Mv.&DRjiڦ̄X)&z,9 Ak !XG'*^ow22CCш)`G7 a", "؅yG&-?WZpQ;W:0 U)PZS}JTmp i WA"8W8Z"PgoqS~6AU 16yYKfwt`t̓U+y'6\Y %j9ɂw+l42<*F*n,ƶϢ~Us]Y<,fFA-}mW& 螴&;JXbi &ukRun\"5Nɣf^GҡeKEBiUA93A #'_A dkH/"́ 7L0YίV;(s~XjϙP9bʣDi1&U6؏Yty_=#؆75x fznvrrxDv~Uim>jQ΃$h(#\QoIN16 IoMlE Zsb!m3nŷoܠ $P66SQTV|||Bص2L3E6}b$CCdgw*%$WE Xi2vL' VDz _  G3ɆM4+T3<Mx/3l,&Q}ImAd&ƌNjcoy])}7jsBVe*j,-Qp^׉&1Yq1hUIV ciZUˋU_c-#dX?o,:c^al c"P!sMjTX5`]hns5TSv '{Ί0 iקuf$< ٍ mj-ߊl2at++vH 6mv7cU~CN~p!dq[ʿ1r0im/Yuc̽A)i$@Z3MiO<fՀ'BEbG^y[yh,Cxbo70qqx&6CmqHZ"fR{ZƦJM<[ ƒ'\1.O^1-Y>|Ы=fT;|y-'.Z} eJj]vu@ц! 2T$-тdRWoc}[H t!))- 4ora,xo*3{SZh^};r|7K\hE*jؽHWzN!QxH ;p:]qj#ƖcܬZs%ˮLu(yz;obQap~{(;_!bESxzr۵{&graqɊr:0C_בMN{^c0xfTUz 3}ߌY^EkDL۞pgW:4O lx0lda nl(tS^`z\ЧylsJWd"N\[zidu\uJiԭK_VVQas,T>oYn0e0spJfX-颋d^W/'`tZP&4h@H־6d*uA0⸠/S ˟ƾ_Ү.q)L*$~4cꇪ{ĜY鮵DVN?5@Y4{PUy`DH̰KįxDRR摚4dXtdӱ>،8]^v. ZjapɁژAH"WMF &63W& iHJY7QXF,zGď.tJ '\)[HHJr Uj+vLr%΀˘/}vfyв"0 N9L,|\wȖZ\6jCrMm_6Vl*8kZl>nʄ*Я.ˇiYB'b'ʊqRF C!վӡ#u}EBĢԞa5CuBXzZ Б(N)ӽPR᥻+Z-{[:1o!gY(ˉ w_PڌPJ^dƿcy :%maMgWau e4`6X) 2T8Cat3)̼CSSyf&eI, xG4ԷlLUO?k}S@>̷~njm oCZMxEa^ѩӖn$`b8>ߎ7J6ehץUI m #=0=֬39ψBޭDB'Ztpۉ9#k{|zQBjJ(9->f0rrRMڋUR_c% Hqs?XF)zɝ .zXn\arőRVeq6O&}5Eݬ{FX@h! 4@_oqR/.o{qdXʑnj V^<9Ҩ,B])dG!X5">}s!PRd@*Md"ϊγb,*8&;7{TZqY:&O* u`,9B |tD\D0g;ϢbQUoP_yZn, pol&UէV}bJ Nc6?+~[͛]x+5`wb*8V-{Z_HZ \=mk@w\]V;RGZJ&~_~t9cQA*S ƹh'EL?ѫM}:䩑ٯr׿3O6DPynʋ{*ᲘA0CxcՇv#^ʐZ͠r>Qypf% P0&’ {M^O4`O?a`_‹鍷rM#97Ⱥi\}> |'Vzdi!ս{PpNL31$8i(>1;o쓈8P>Y3b[7\q"* 8} _2xߓ,/MNkV+R*P^ .` t}Ei-7V,~AOq3W3vnai+fr7pkI%6ڑTaLR5j KYP;6({EO˓|RIv%bX%΀AƜE4}4A{jTk #zc"7caǨd G @qY:gEsX_R {z(_dHD|9E:錮H͋2O;S'cG^1{mQ$$;9_l<oRzzQ' @!Z2E_Gf4ҁm+mvegn-!p)ij޵{e 7+p9Mb! ^3l2Sp֟. Jx4ZPHi^j-Kj!fXbF~n[B[+ MOlbrߠMzm23+ ښZƬIO}8XcZYE8|ưu_nr(56?Iѡp[]}^Iߜy .vSiQ:<(UʶwlbU<>Mi.,l ~QTLyr(Wp,=W*Cf/h>U~nb?n[z]VMOI&zk8=n?uύD7.bZod;%lKc6ε{ձ[BcM;\%<o-\#msL|buSɐn>b#]ukF~GK05Y,zŞij'Ar^Y(`WcZPXC:]~n6tw[V'bBCF/1+9Fb^*upqѠ?NЅ=XSJhebz=.774m#L k^A&~V 2 $1p=nz&WGĝG.o- )tWm%l=Nd0 3~9IfN>.u`bYi'3IZRn98yE`[l犡؎G[VInC"&b 02*#ߐqe:@(6W1=o a (=Z,k_FP5a81 E*Qfjy~0?9#Z*aSۦWL4(ۍqMpX]FMd /lۛH`FfcT"L! 3K0c X-1VA&C)G u+,ԉ '_%SJ}ztMmcgc("ft$[; rɦ Ohv/ iDFu:>]3 @+ `@]R/~/v"N[ovw?jDWھ; On%5tx6[t:fw})'{8zW1"\u7}G#X~1v8]N 'V:Nei)ǭxS#6 ,4]@;vCJAuօ }V吶MY('g[blJNW}- >۶W9pͅ_Ȗk|׃)|h.rHyi{L_. "){큓-X ty{غEw W9f`}9٦R&|WgwV0bۍ;lgaa3PB*Ⅱ'<)pe0;9٭B):ƨ7 VQDڵ gz}iz"\ڥaQUx ²&Gpoա,N}I6aEAhn."6#y{l3N5!XBQ~ڴRQl=vg9*LJju #hoVkI [)f=&zWLr^5SqF;Tt6{Y:}o,h"")xX_<`l&|,4'#} ?iXҶ"6> ,Li41[&]3V6(ui{5f @@~fa.e ~UxExuP&!L^Ġ@vJS9}}YY10*vDO,f cf;\iRZfo~za/8=_/-ȑ)5EogcnwI\?ϐuچ݋zK8m%TܢY©21=T-[-WLڰjvAfޮHO''~ZXʎ*sש7pa:tܘfEFfʯ8RɇSSPz"D`>7/2kx_1^ 1jWؑ',SAB0 H9oImr[B@Nk@x3U\=4$/^(Xޜ}1$a!\8 tgXbnѲ;3͓]Ui~ܟiÜ 7˧,4iO$3?Pߡ~"jrC(٠\Ez*&^e.qb[ҩ|<LʤΜ & [g8SjUx? фey<6B6` yQ-h[=l 67I -ދE֙ zà(nL5lQ|olʯgܱ~| Y{ͤk1R(1 ^ah#f^'<-7O8U#ZUP&=vu2 40:dgE3VY]ZzgL"l {BAbM@Z`>Pnj`9ߑH,a &/4kV3ss"^b>GǠ\Y@6BcH.HZs8"<|vʻz=4 wKRV[3kaiH(e& ހ\!a^l4$9 d}Hdi6:M:!/*W 3HJu 3}'fdz&M8z OÁ33^5y7`r!(lc\[LO:JAގW/aZJ#Z4  gZo@yq2I2bT 9S~m?{)yLgRdĘ/E,oMɪDAeƋ%3@,O%ϳ;oC\DŽq%_u*cUb Vn5zїPCP`QwWzTc%IrRlMp^† <-c= w:[x!a.װ}s_CUxޟm#d7 'ՌH#\X`^l4 $`H*>IĚT` QC*s|` N:񵆜GXypZ >k> wcV)^`&756L.*)vOL~Z]{0B%s3t[f߇%?oVB0lt=(g"_Q77`rrZ&F1@BF6}-5˒4< (g1W㞴HQq ;kzd %" ho=#uQNsq%ƛ]hzKr+bg#ObZt-9fJZsS 33x6盱 t.9<F7|S0 *Ϟ#Ã' )u9_i6&˝Y'e QWMJrKt1dMr A&x7qȒF-5"j}|J_O$#6=6!g =C_Tx>Y}{kPdiVWeSܿ9D9B*فN#i[t3YBvbcݐ9:ȯ[7MDR>9j, ^ \}tߴDDd$}3G޷@"=wm|s:wҐqE\~{8iYԭG]qJ^XHy{?ʏ&fGi3'3< Sw欎Mo1 \?'+qWӰN5E@RBJvn46O+ 󈙋R$b^5$iZlEf uİ)<,^wO;o2+y_˵PPaGb6?lӏ?L&':JV#'*GlVp`[NЖ-{F䊻qg?%>*S"W 4 j%:X+:Q\0Cy-s0 3 &}=e`<_f F󻥻HK`>epx2hw"X"gWu"??.E=,IuDwf/3)ۥzkJ c, hKpTd/.oed9ZFenj{w\&ڇF]R}#ړڝ*\5xSpևKwɈ:+8Μ:Nu #Q[C&Ȅnxt՛OĘ8"Wihť .uY CCD.syMI2#,~^SQMB lc9 U\Cp.'q`|Φk:h^=,11!|=u)v&}elhu]S0V 'mgh"aۺFO]CzʖŜm'={ {veCnT2jŁI^|;6FҨ5?"t#![~D$ջcRj V =h݇ gMg܂V&^ 7ie0Wcπ}$g費nLBD[ѥ(a*1;)puY!>8o! 7*#VG{NFQܼ;ךL#Xd4qP[F>MqӨɷ_k-jf3TdSge8Pn;1:MQ&-{-Bd7%}$kf~Q )8qP>e !2H:AmG"D\Eye>N~*Uj#iXh$F#. W]ҖP6Rb}_YDk*miw(t={%A}k,Q4rZ_jBV`$baG._4q"(KUE| ՔPwjTjtiXTvߤ-!\^]+RT?G@Q:󼼆*c)Qb%FIwoįBzUa5Ђ&]=k_n/SzC- g]o23ő{t_`L+&'򘫤TQ~/_ ׫k[k-VpbnKD±CgB@X pCg%OM>&4zåFmx֛9k~Cҕv=n&*+~p}}Xgu#T3*zD<G_^fzg9zF^^aؔk2^6)䜝i?|1q#5r4^M\uz"Kᖉ@v&Au I JiA*fDΛZR)#1='n:%" *4@[1E.YbF0ͰʯPfMuTf PB7\i=g%aQ{ l#:ڬJiE06Ǻ"X}^&<#tLػ \~"-'}Z*-/_#HsT otQx7bՔN9<'b}mQs*X:c-~$o斝5yɇƼClS~rᑝojŀ]gb4ӗS e߻Jj ZI9-(l+l[Xڅ UҜ09LQdAu_Ta\y\-Sv!~b\f1*Mt5q2O#z$<`k4#ߖ{ıʖ#ty8}v[1B=&0<-#p8wtˎYz`GSah1؂ cFEMm%314b!AxTYxL2B@)QAMusMa @Ql}FSۯx6v|K{POXp/#T+dYqoxK\$՝4śIZ"*NLAT*R:𫧏ɰ."4gUb%ns?Z־ %j5u2Që(aL`1((Ӓi%U˴aRFL)&k^3CY\FVz}߻ut2KWψZ+iʃVޔ֖-N819~eQwG*Jn XS&o%Xxr2=(@Zʀێ{؆"Ms άHCXzFY C=Ac!j 2 Eu2ohIjrZ%O t\EEVɌ.9Hz#J@?`Ǔg\,Q*1_пSQNo@&Av=XkzC\( /a=Tp ;P+@]X)l9#8\[roYb{< \)|Jw(gh5d2/TG1jy1,#c%_m0e0Yj1kcA{CGCm}AQ_]5 A ;u[NV?rE6nUБ]o]T4|a ]Hti,؅ XڏԁjW>54㦒6R+d9$m?A.6=oN4f+\w6>s >4$BWM Ŋ1Z̈́gmK915›MyRzű Uf k )toP q!h/C/gx=YR{zua9 -U'B7i;̱wb_.t!qp0;WrcXߓ33,}a[KSe1τw>]=/M{GU9כc#l M  ?MPϗXH!N"xECnXKQdu_*P!>3-2yh[ zƸ 33x=u H9D{/cTs&*V <ȸB. SPQYF<D6G<}ŖdQ>9DY6`W YS hǝWͦn>4[ -̋`e6rJ-=,C61)$H̩"/onrp !J'`-{`Pd6sVhYo-Tm D]slDqAf+R]gPMg@OHx೭㺅\yy!gnw\='M]5 t5.l4faK0VtIJT4 5u[~vO9TxjLޓVrׯgYȝ$+ߛttm?ksEy]b={-GZ T ZWZH;`Vdv2ĸ,8 J@M!Sb{bOaL[cյ# Т^7Fsm#YPǒ's%4BG4Ò䄼Hе^rE3'pvlC69rqr$`55XISLBMtOdVwVFmL/xBP^SJ)2 $PN9iQA< sKk*:uֳb鵸G$ە'M}dٵRmu wU?Bd33O疂4#QF`L'h?~Xɋ }ڒ*_ CHժ]9=YI mMX$DbX2"0Ћ{i| O25-^[2Q~Yni;ztp1Fh=9 0n!vJG̬/4WqԅXsQ@[ITK. Y8ۼeII=ϟz;%]B9m0eIq qWVTa/`bl_riG-ئu" JJM_+FҎZS{\ @nfSv.{g3-@?ǡ꒞WJ cBJ5 P9*hJ 0 !\t,m{UGͅ8k+0e W3:#L۝w@xitDQ*ّq<ˍ *Sy'^"$;rە'Zh*^ϝMDUubgH;4lNjL*MP_i|'a)̓tzt!h7:dn<܌C)P%d:4_3=txěV1/dYpyN, r utp_glM.p|g_n&:!;i>L H!8sKAX="#|p l9e9ohS@~ZbduvXM&D6ݱӡܦΏ[] oc`:@ׇ.g#fAPpf!sN!4a1YΝZ립4 ?2+!u{4AZ ^h"Y[|#aCgjʧ^c] p6uN  C&PrS -{xjS}Wh <~w 7Rjw*ϡu7oI~qS*; sOLlH,3:e e I5s(.?ה23qRWC"{H\&~w H1RE(h&䕵GW)vE{mVQ3Ĩ^4J hSx_Na+W-R r PY V|'۩2d0TȹUG>dln^٢M \ 퉵)1Wh _$k:MSK?K(30Kp>({=}'"?M Y20!-=AIf p"ŗ,0gbpqЦ+1`%numo|#PD7eZz'Y)(2w|>h}Xb^TWYyVbPbYlEUe6[EBI|tq9Kg(v3FL#3w-*wD᷈Mzߨ=!-l2_&M%"ѝ ;0<75V(u>f$YaɏB %}I2 V'H>9X^bQ,'<ӱxv˲0Έb}-o/8o^RN{ )-)6qwtfClQf ?&mRm_9Hd>ų $Ge<ͧntiT7v5Q{c}VXK] i Q2$dT.z-XӦĈw3ݷ^be-*r~(]¹%u;RR_i}NNw֤^KU$wDgj.`{ހŒݴ-#Ә c⊄&#[kY#M+PGL9G/#v=ݚ  =/@w0 :&C1bi3ζw) ;@q:M5DJ&᥌vW s'} N?PZ+t[!LA6]GwnZGqR>GmI.?~IXM%;,~|:LP1g9Xa3sM~ TSx[Cj=p]=Ӆ+z#~vCў+9&Ta*5պhPؐpްXh3V:dzSh hsySrV.CDeW'6Pô%ZjL'a@т)1us*ޥO&T>RS za?^ÈM'+U$30j+{|:Vx 4+-+BEۮq C?M?P ۡB*EzN þS#q~&h8cSŭ0'/hpC@Zh6\OXWweO.W|ʵ,wxҏ}xMc>t+xW朳EIBzk/ NP)ӯdqh`X\c8ogi {2]ae2BwU$Aeh1O*xc; oaXO ]'pe#W#b:GۙrqjACΩ`$Ӂ;9<K6)}H`ECkLb3ISJlwS3,ק@ʼe*Z-<}in3o'r}L*>j׵D/&(E-%\Id*-ݏBpG|8mfh׿Na-ݪ>1${?R|rɓ`0)*O,ue?5ˡQit D|+]0ټ/3 S M(׹JqgNCZ,j >L'fc6~(rs-;ne\)a3Ȼ-85B[)`_<y6\%c#4wt/ّ3^!7˅z :wm ۾zf 5|MT<E;ՓRx9Xs S6D]M(`-V},HJFlZ% 0(/lΞt}kt'xx\^EriyL2- }- W}Weգr:/h_HnE,fPEtΎV)#걖FC=7yk7ĩ P^ Z,pi;7A|&+U>.F>nX -;z1HJBp,G" MpNաY~~=um*owG!>AgqqeWbݑLc,\[XD%uS+$cݠ ;Ɇ~emR)&S«[ ˫M~3_ŐP'x2>V$>{wՇjmt{hOu_a%ꪅ;$6"|+t*pm~iO1- Rb CE\g~i|JLd VUh"*@+uCVC﷣j!fj9hPPdo-PX$,uXP|ĎhYM+U;k<@ xPj{j'/ؖYvLRAxqDnf#%x| NtC2c3\-OvN ~Soo3OꑔŎ9X7= UG/pi_c)3@v_k^HXQ8Ẇ~+ƌM{S::ȞxidLW$GCk2QgG)7HdΓNoI!rid#vÎnwBzwn%//S?ӇI*DkX[д']0U$d`˶U{ABrneyrdpa}YQO{[},^; 4\b|"^"PE1n1 vzTwfct0,uq1p`8{q'D[*hhwCZ:PVQ afͣc5Jm@~-,#2b !9 ESR#%G^ј5Yg{fx7.A+ .6L96c6t?+Fmu?Pl,{Eal\PiBĄrt7E7(o(OA$JԂb(sq@\Y]D `qȣ3 Z7.8Hnj-*0hX2 0fCE yL' at`tY\=Ra 3qk~(. nچjəj4.]Dge'ͅJ,E: 1h>bRn_Y4nL k= '9ܐkŔT #NdZg[Tp\ i_3WpLPAEΊfvPerT˥3lʄ t^ҁ199?w5r~X~<gzZOFGM2nQ|ؒKs4?xJ|Ja~07皢WK3ut`S # 83B&YT4C1$[\,lD~8GWX8![iI8DNiT`0ȥ\™!T3 #)@O#1ߙTG{i ͡RlTL\$=&9`gO?hh=: {}.Z @+w&<^;ߛ!Ǽ.M0©{Y͌MLP( O:Q5}GÊסwgc!400Ţ<:dmFXzniKc %,0LʷDa@oC}ckі{Nn~Vi뗳pjR)Be[~ge3F%gR}nH5RccO;0*g5Ԫx`l?|]_޽\_zM)X QOva*}voaRɘ̕X*-tKJ6^f' c6dшD' -* LTaD7rYF|$}w}D-'Wqo,jyOx s1\.OhŜsƔTmv=7&W)>I?nm.2M ԩsdyDhx&5lat (:1r3`W]M+̱A w^9o9-/Qx^kØ3KPs ^AvduA>o=c}RxGsf|l,:BӫKh܇H5f6`=5k oG詘0W& t8'6J)Dd[]M7 s]PCB\5Iiçh!X)@j$bnY Zk;/tQa`dOh^6yw3846f UeZɼ*&(ݖ 5#ʳfci"ϺҐ$pMfu^21ZzBE`!fBGzْ5O촆34Rmo+TւZ Avm]ZE[Or|Zw]< c?]ig[ mf-C˃rmH,kijc/X$zUā> sa@*vVCFV>pɸL$AiW`wDY. x&A#&a+ He5_5! d鉾("!u5qkO;MVo~8bicFF6yPf'T5m|z(30Q+&Xϑ J%7lbJU핺!%n{('{V\fmHly@R PU#L>#S1aYk7BM7<62 CsNQ.~LU-qJ_:|8{KvelJF IwG_Y@*N*ӁDŽ@/R5Iʴ].D>zWKokYE%w9ޤK;B)N's  ͂k~JA.D"߃Ϝz7{(&ckGt=9} so{fS!r: w eq- !k=/ V׌M-grjAMns ]J\JT AU 7FdkO<2 ,wsKtYXQ#zsĞ@KԦB"`_xhbjԶe뫠A~ذYgwT-az-qˌa~iF'v2ѝʾz=3 S_\d|I_>bf8 >5 R.'œ.{jsρg.:kɖBGɧyY׾DNyS *btgJ+`,К4d3 ~*=ci1xO:s9:[0:#Ga3߇X2T 7kU{Wߋ 0!ܦw5߼(d뼁'Ϟ:hӰX#KѬ0_yix 5&h';r@L%"#"WƁz_iK+A/Ewm$~r~**\C 7ϋvI0&2NBD"{ArdO˿:>=8P@js' ^~4-VS)v̀5IӇ;_XxYX<<1'z 0 dyPQyduq#Da|p]C.,/?Bܼ VQ6vH!ԹkMLlϩUh7,&E+k "ˏ`oMwR Nv/j_~rD{Y.˶1;^P /Z>4+ЩCYtb /smiH ^R̴,^d]*DYŎ9Yu 9c`΅b?{`k7mzeI#6X>TYAca`+|;Nh P/# /t*8!%,A`L+'577]udw{#?>a ;̻"K(LhoBی'5N5#Ը{VP~K7ai= VWċ%mef܏Ҋ}%[{yG|ǂ!?d8_,>dZv&C&lB%r{zcP,CbYK7UnX*LbtcOh MDZ㊷9^>zE?7z/!A3Ïx&2ZuAlSs#|r | (`X' /1ihvKo /+Kv>ɭE)LLcw}1e˾n*UەwNotKt/$#]e$\an%iXRq L/cJvێkX&4r{@kTtرϔ>0-v vi95 Wm8[D";RF-v_fC@z1""QfPkpGDfR54o5mY %˄-MBXSj$d1!2jJo;dF ] )tyv{9$pc1d&@+EYF]=G !73]% ǖ U/gŸcr1{d/mنEUrC-Hm!3>G,OﮪO^3XmH"@6r"\ok|"uO>[ӱT *4``l^gUɤ aحXG'kD5|;wr`эwb}bHkdPSpnѝm:Cթcrߢ&DluK@n14C)Nge)&vp ±tlG EJb̸W")$ZN!2N@Rwl텑ﮮFRgsһ۝a4D4I<!HZI~Ѡ&$°98AqaK1=Fi2—L DL销$p D`޵\Dm]%+E5eM_ EN4c;RA A)xAEGd 'jaW'w&]Cׄ@,VxXg&Ibo.üB kL9INu~: eM]r~&Lt[rp؎e[ܐ6 m}(dƆeo^:]Iq7u.Z/һ/:?'ŸEދ2rDoRvDU/F϶D㒇yNG}ˢrV7!b 2)@3yʭ6Kebn4EP =]ױ͆+ҀFdEyoЊ_aV T׺팁ah=lհ،ӜƱ,!m,˫鏪8p)Wb ֭cT~ sM=M:9YT=Q 6W:[9rGToS06h8?gIZeg^r!7冖C"'[Y=,+굾*TlI"Bk1LVny?Ky 6c6PbviWI,fŮ:\K6 nGCR,sQY@2UK`jxNC-CŹ1x-MQT^IIjV`㛉 Q|tƊAVN{I94zyc2~~rWD&r ?j[ ,%gMs43O%"'%C*I3ŶjMӯw|w/9ҏC '2::R.+@hkgUh+`8m5gWju GM`ߪKA!|;)>MԙXHqIf}GHrB~- ,ts.b69MgD{(^jv?A5˔NwMnk:Q@Sfzpԃ@h.fh>L S[B)8 r3NYOī;_ᾊ4N [c<۫]v` ժ ʂة@f-C5 H7 s~`e^('heN Y<6l#8wن) a Sf?G< 7ck@Esyt{g {D(t}s~C+v CԍN74"1LƱҁj+:u ƻ\a%]Sv!EV`/=)D^#q\qA978)onu~rVS]6i|8&)d*BޜXDe|K#Z:st;NC2"ڇ:o> r؁Sfьe,LMen/Ni;v3k vؕt0LzIa3lse{pŠυn}L@4h_B{Ljn Hp7C.i!.*0^4n_BV$K4<`(?RQ;G-c~>;y&DAtuP42FNELgG9fl)2,_㫙Q ױj0haHL;qpHp!>dyըiqHxsȻmS m LMȝA~g`7_Q9N=Ie*ױs?gO6L*LFxϺPL Y qX2ÛL-&Ȅl{^[2}0Zw"&VMrӲ {jJiGN=JRʪh JRr=R';.9[y+,}3z_03Q3xQ$hA_+Xfe@JK,N [¸i XŇ> ح tf(ЛX>]F&2~)۝[GE-.'$-M<}H:#CDJT*owNZzɂT H8cè`pB?֮4rr$}Ʒ.b1(T WwI* +56`^`)xt8^o Xh[h;STRuA))\3"n$)l&Ba{+??TZW1օXN8 /%p ' 6$ /MTxTR!+j?Ԩ,`dKlw!OGyAcBXLGn=+n ;eӽo-pq*B^@jÖ&# l;/~Z"֝Qi}J&BEOpvb2xS2SU8TE&3R;ٚ/KC vk,뚾#N7_WHΡ.rd$E-ЫIVkSeS @!&~.Y9<^5~rO/xCҩ@@B&[sֳz~`4ЦxvᑐFӥ5'&~؟n3^pAy ) |idai"L$6?u܆"P07%2'y/h("6l@MRSj+$@ALЅaD{K9&]0]N&^^ƣ>k6<rFVCxD]9x,ЋcH2n|ByPzȁn(fd]GE{Sٍx?(nKcQ+ ,_7/.Xnr!vUhGox>b.K#w M(ɯ ŬfYS{Ixݽ^>q&Z嫴4&z.@ {LV<.#8:lWRQ< LQu{9څ.}quC]×aFFa l'z]//tLWJ˗7ykV̓t;DC25-n:1pYtfwCD{(/[qt(l7_FLJCZ oC/bN{&[eC,1_첮؆eޟay9F9cY,Vvd_9kaA` l5+)Dgz& g1Z+&V}G#Vmw|Ԝ!r lL }AhMjɉZ D"QZ<z i[Æy#~`!ϩVGCfȃMê!%& 2b8`>>q C#HjdߘEJ;KC<~AEo&`BBE4 =z;ګT5W"LWf  Lq:R隸֋nt ~ѽ*t;.w5}yLpFɃ>梹 [T~RѤ\U< ݭ;`ȍ9_1&Jݪ(jsiM@^'H|FZ{@OfYv#FU*YJEؼot@ Q(.dЍ/rjϘm]yAhpƉ~wIJ=r~Ԣ^+!Jڶems r+'Y.O(He>OnZC6 ]~':c<Э^ -wj|Gؤn7ića7hXɘ{"iUI(փ I0e[Ʋ\iu788F?Ȑ2}M\ . 1>Q3'T=+rR+$._Pu/] (w$ăXdLI+sb!Fzg[T;+nLjui'06DL]LA3e2Sov!m -J p&#<8#|f%y/1:%ueݜX*ylrvu6y{ |@gSVu@xfrpāGi, lo'vu8`Nn/h5IA1KF*xi Vad Xe媤7ؾƽk>9 5@UmOUݗNqS(NYZ;iFY1V0O)̮<75n ^uJId@T&acGK9?Z$ !eD`.FGՠ(h ~G Y.rdp:7UM0K4y,z3d7^ErGusbG G"BeapǝՖA8IgvʋS;t#.޴*URrfGD4+ΙV9e)Qblpg\b3qW,,,'d !T۫YNLk<2.D@0Ua*9I wd ?W-2\ u}'b! \d-&{jf$ׁQ/@Qfiַz k(.b=A|¨'m6T35 i*{ Ϛr "Ywuq<4N1ANpw"&pBsq3mR1 {>6UB: 9jϨI]Ŷ<͒s_{%7O}M*%R ߿$kbBC'ޜG/ #C]i+}{t?gX9 sCD>lc**LT(L1܍:B~)sKĖ|EB"GRVv]tYD]g^c6,ƍ|9n{ydn@YTK=!z kRB8iLk2 KG3 +bSPw!21 MQ!442r\p_=';ޡqc!yy ĮCEK|b;tDqKR.IQ00 /MSH~+H0c$4P3m͂++(xfcf-:TimnH${M1)v$10Z*οFi[oX0rB˕!Yu i'9MF́;-D<_-y~KG4|s<; PYVqEC}^A<{oL i<ˮH:Kl=7Y5E5[Eb37P|ZU֢v¯IIs$2Y[i}*51lxEnJ;8e\*Z.zGuiy}uA?Yy|S`"!m~hmOIL >1[Y"/ݜIaŢ.OuĈY{^bF ppV\fg+D3Ia0iRNtsh'noT0Ѿk] 4si rxͥݑ"Grɞr|Ea2*r`dtc#nM-7V:[}u `rjhl,ik+ȾV*UcP&]݄ۅZ+WibzA9jDfaMu{qᇪ9Ay1pn{6HS&!ב4I IVOPp=$uxϚfkn {qXbxR{=ҿ^ $UZPޞ4eȟyԾLXUZAѓ_пQzɮ],_՝PSS[rR"\jW>$IO ?NS8a$>kP $hzź&V߄TVerrlպ)72-zDǰ~!$: M0mcdS>inΑjKN"5L(~0}!Y$ߖrMg*T6a_,قZŕ2#nFo1`$ HNI'9|lCثljp/L9/SF((#YVY5sʝKެVMȶ:QZ sTN~Hn sIB $ؘI# FU4O# )n׫p˛yx z@־4FJf !o#_Α},!FAkِtoSpv'y(:oPDY^D콨N>PLK\A.Aq=lv/W`d9zSJej$^8SN@71lFIt2Rqny=:ruQvJK n|L\$ M_Y]ٛj'&ϣ$\ ^i&F6<'gLHH1"sJ5V`ps kzwYZS7 E1/4e(0p O!-~/%v5gfu$p:*RHIS,.3pLO{.3Tt\SaLT"GKI 7!Kd1I1c DuRx 0CV.ՕQ$}^ao/p@@ҒV,2a{ aӢaBDm35Z<6ZJ"C,&Oѓxb+O?e2<JVZZnM Ncaz#_'$(ھJ'c̥] 1!~%&E M'̣(YB&>ZPG ({bu@OV$8*o=-0[jDifI2b _ZqXQ2A$ߠ`ܑ'V]2 yFjox?:QAFk3$h,$:.%Oj1z =[i.t ŕv}TGKo; I47'=] @Iы{Ok==崋ӓ:Z]J81:RܟVbU5b<M`S-2NɿdGvP&ְ5D[I s*lscɅ$Q e-hk!Z<лuWC<`[RAɠ7Hs@.<;TqJdF׸(8JPML´WR+/K7YjuJ+G=w .\OBzw+p]=l=~CBiߨVKtFgD?Ɍ4)8×'1uŮۧqEƐɓ4y;SÉ|ކi ?zep6FJN'r]y/UXFPιޭl?fFQ#aɠL6:{۞񧓙SQaJO5ɡU4{&wSZ Wn R) ?zwLVY6xI滐ѫtw7^p=Ŏ%lUº 9Ģ {r}W..`2'2hCڢ4-fJVWL_Ӥh`)~ʹՏiᶮڗmyӕkwvZۃ*Lg0%}XYT)Lio*v̯f';QɃ QZ)p6^.髠?s:;QX'Yikn$8ON&e@ldzY~zF[ّ/[V?eloſ|j9wJ1^sEaה{(Iaa~|>:\EQλjm5 WM$=&]i٘9Tzu} z<>;.LENߞ&)CX# %0(( i٫RÝ⽟w".شpTmK6x:&{*օGKia UuTMmc$5O-?2fL2\cM3Ѐ1p|i'I<1 fVXξToǑDY]%ۭM |c GRw+Fb8K}"qݍ*G7 < Œw;SJ^y9'كz;p%.#zN&c"A O}Od+"; @' +e1d僀kMiQdR&H_:"j NUGxǸPRx^ =Y Ǘ hNݣ-!R`-&|/0ǯ 3c6'6 2@5negLe`O#7;%'|c.QCU[=rv%C- Fq9QVڶBZ hWMq:ԅ@ݥOtzsG|]ivjB,Hђ:5ס&Թi2&n`15-~6Aw_~0xm1奝(mEjnH dߦᴚtDR8s$_F~ԜnJXnmZ} -eLL>Z4]1.<05E\6jUc#,Z˓(4Fo6X,n` Mvxg;]U rk+$E(99s&ЀʴDXlPp3Dt|(T7|$RIl(Wx/3jm>z W/"&!'r%.X< L:/ p BS_z>,|bDDpqYR !Hw*_sxOh' L1!].0H*s }ʈ/4rε.h3{OFkv/~xt Ğ$, I 6 `gʪtGG&+ߠo ʥ=J5fi/of@7ɆI,jw1s23|rQM{7TYH,/'}8UG=!8M0h[Ԍo2kвDnd8`e)w=ot|=^2yU&>f簖aM< i;qe>*/8{ bϲEWд[9vڥݗ`ky '|0]=Mñb(#oj5TS~]!&I ɚe%L.'57wF50Z ]^<™LVl؎ Ppz/g>xoHmW`v@& 2J'B_A=5x,2mZU3,Ǘ)V]$&h2# =9ZVT8̺-]Y?1;kj5y̋*{R͚=:i2'AԍG\Z~sju=2rݑ|L/70=p *N ģIi7$(:Y` t IUվ#gHy N#0Ey/=9~rX 5 6ׂqtC'8H|?ʐq7yS 'uRU҇ԝf_°N(+s2&E_t2wHF/F[5tך@ZGE ˨M͏-",CM4rgy.L ߽3-)%[0| t8e.[?m2]>@+H27Jy޼a¦8͒&q4I?G "O'"m0|]"?kXq9&&$UaC0ȥ*K]*7]σw6Ś^5rO)-a3HuȚd01xT&whZ6蘇]UFwb}bqCM[s8"q)%+rqEN#æha5|9mрWd'Y{el Azi},GXZ} -78P60Y* _m)?NUP<{WWG:;"j޺%4Û Q0z";#P|L_1"^&LP CZхmFUta0x>dTmJN~KiMxB&PjT=&8hBp< ;"$$qvtJ>>MC7Fnf w̍n^:bVvY(+ &EݞQ/1;or"B ZTS9Xz.|!!-fm6G+M|RX8 . z_Ut j3%b!+Yr0e#[gJ?QZx'Cʮ( *rNI&fdX̶ٶ24JT jxն+bF522Y{zx<gHcvv6H:I5ZZ/SFhuڲf 8$^tz6DĔFMԘ% PZ@_:t' YQ~r1 oC+WK2?.lQmT}LRr#H[vXS :lQ}ѲJǍ;'|/یKxSS éf:zn+MskZX= ԵK28E}fy3㍈”I ZŐ Wѷ䴥E(rp=-Y<3U߯(n˪VQ B~gyo&aU-ƨN:`EOPQ򧣮2 D7sw E/~S!W-ث,mt)I0~pUczޮ8ɒ--+*L.e|gKOfh4s|.O:6%F ;?QHomnOSVyP0MW6*B\c`*U#҈I4fqPs M΅O}eA!idqd,+Gq\;ܽrN P2&<3}W47!UnK2:}?L.r*=׭=yϖSSb15"_)`Bh&TugPWEȣg[oXU1iqxQY[u?(S!2| [X{q=o{6Nf`xĀr4˒}d/S{G|UZUm &Qxft&ƶ}g &i1e}`֋Wa [RBxKޓYtM#~_ؖu@ KſkBBʇcA0-K,G T3u\4[܃f,EXLozMaٿ{!]Ɋ[; {/ךЁ\푾O92@_ lD/2"X2i["V76%IfJ0tK6!i [{Sw+P19(.ʆȶҬ gǖ?s]>01c#hFnV(`Ĵ"9u  v*ަ~7BեM9lCnaU q"8q-+6 ƈq:=6׍¡F|iB.:A}F6-7[JDBl]_z >^ЯD5"9$ 5Vjūw̽R\۠r楉ø@ibjUM"Y;/Q>=>Mp6Ά(HK&Uy3/lz,.5GBJ48g?t,53|xN8ܗca SeO ZIBj ͬ8B|O \DbDşe{o2z"jH Fri ddnFioG:hz* 0SoXYy.nY ?\'o[U ?$m+Q5 \sL3SQK# uRM/w0PS[jpZ4՛m˕\w5T֧9y|c\h oWB$ʤ`ӗ9]C&*ץ"Jk:k6`D& zۍz#UlOr/QN_C-L%fX*1U&xcjR_& :XY@~/!_Kp/n7G loNE\G  ;&6Tٖ0w@=c˭|eI6KoJRz@ڶ`i͊Ҭ=C<~&/hX\ƾ!=oԿ Q+h+5\1e$d1/FiُX(*#fMhN< )ʊ Xfj-kBR0+l8Hu^~%"M0&ދie:TN;)[xBb(5: enq cI[񺊯7$'sݥ&/z阤xYy[M.;H*,v6TQuxWE9"nq5;۱n9j1b1 c>3i";K*rJlΰ6\,/Í($PW^$i2D|7(|a>܄OeLnRN+f.wɩXs>v[)y&FdfEM lBRNsn0-&L%?Q8@`2C^ ȉ酉t?Z0/B[PfпaEÖM:J wjc!/6zw=@94Ӂuu-"vެFƴ$ e"fzdQB ~\ڤK: f7ƬΓȑl}-bwB:d R_E2@+k)_l#drħ(8pID gr{e{݂&,wܺF@dDoV^ xR}pZ( gKPBgq@df(a RL5GQ ͅVD Sw;>rVi:>E|}LV~P/`Kz .eu#:nCX o:Fk?tHT>hmaY am˰#YI#9 E:0ܬob_#V)6B^1%_U):A7lژLҌpZ32t5_uTJ9n: Tof[q>$P0c>>"zcئBwugh.J x~&Jas)q $Ǖ8'eBFm=[.Ƴ o̓R|7-H<:B^G0,xqjz7ɋf3aKOk h3LLVjk%n/-|Nҳ o!wԖQ9gMS sdbdAM+.bt5==nCg@˞/z5PcNhƧ KmȖ EI8.^vzB3g4T,sa}SSOIvC 5DBguhHImPA3e~uDY;fTpe'N5jk`{NhXgZG): $ rLϻ9BQ̌`Z';% T2t}VH_JtXM-p_HЧ`1=\.vPv4?xf5O3J4LÛ:<vC{#"&dG/–9Q3L^}6 cPE3#G=Ǡ} 솽/caw $F#I~f+2ဈtXN0 kQWF, \1 yGKAT gE!S`];/(x947w?iʘR3U/,Xu`U2)t|uX3h q#j(dĸǚwMtk 6h[rIDmZ[3t16Hk@@jk׫.yr_(\e!1gBvז(5[R*Qa<#f)mƦy°}*gDoxɠz)c6`DSf2U#^boqѱæ6pty?KJ3`-f{-ϲA5)E0VyN8 \/!13ܳB٤LZ{vÛP=⎕Yόz!@]Qc&q:-/"[%R^LG*$D=${Rco͕6vuqzلHd"3FM꽂 ޙV ~ w3B<4,wu)X!3 =aGScT/O.O(]vmnΤNV$s9G 0M rV6'(eEJ,i̛w̭W<rVDv%kc%ؓhc,̧2 *dt"_MAP8zԬƐ[T`)՜7'<'R$Ĉr)Eڇ@Rѕ]vEN$1e?@Nӓĥ*f([NQ0QMJh }-3[6Ē=~e|^Qn@ݸD ,b.AXJt&^l6  yF4XA6o BU7::4&wAl8ʙ|m)4 >V9%Z|.f]S2αZu91ȠN!P ƷfKv-l/Ih d@ل ڥ BdIEQSFtBOǥj+oWT((I[-&;HpO@^E^=“7t *{!T6F` >ZnlÕ<}*`t͓O{_st fv`=AIYӞ8tv#µRRy X^굡ƫ$Q<|&41Cg+c~zdtbag\ -J2Wjj,1ʔZ=2uGt:/W :mC%[~Јқ@.;;YXsA~ ӈZG=̣!% 4$## iM!%19%E'Fܵc1Y;曠7:eeYJ ׅhީ)K.pm}4uc⒎L {m:̀sЉ $  ?'I9Y%~XU%{)WteOa*4C҅j'!)>y* (6Hy)<\doOoRgՀ,~*K]R ާiHyL1-#k՛E 5PM)!|Hh̥:lyl:UFA"RvFQSir,FJ6 zxz'g#`~s~TZ#=<e}z1"gF?Zz~RRCc0"@͌9 68#4HϹPLZ)MK$d6gWd ⿻8' =/raFP`z9&D9ggc)uDh!\MsW+Bu]"k9c٫90z!ǹ(Ҧ,"L Q ?ZFI/@<o/(sfW I-v+=iW#JoB\ӒI%κua/JHh[ݵ>F.sl/C 'Ɔh}QӎiXjor,p?|7:I:;vE`$%sW)8}LAG?'Z@K#~ٕR%ь;m#uȐ%O!9( zP[r^G*AiAO X|؊ MaAWe'ABw\-D_3Ѧkg3NE̒lG[7 RiHSMr\p&ܠd.tfc22tGlLÓKVEY8?u-jѰi]_!Ĩ#PA Joc뢥Z+`W{xgγgLLJHk٤#~h#CY2*RDT.!Wg(s޲KmVly[5B  #e1xB/tEsuP5L 7]:jŹ_ƻTL[CͧDx zp_*跊EgHPOݺ8́i_4U Uuwj@g schf՟.NF"Tiȉo&Ώ5uJNJڐJkTiP- ;t9>yzL(~L?&d._>Lu[6_r\F|#y-V,9zgdVNu—axTO ZsjD^*~S()6^ dU(15wVD,} J#hxx(bCXe28 ٫PY>{s yP-d3;\o/w㚙8謏J!+:w"Pz^wStKxf#0"8X;~I6{-,V^Y4x]4t3LoyWw#0|}?rg/ύoN5vuq5&aR\04 ((<%6?e;J]@CY('YV:!6M1ԧ5R<~JG/hzk<Rk@%,$ L=x|T"+ *!;P#7D}g`40$M~8|C|<2\rX3,!c=w0bL,$;6yR~0"0?<`TGaҖYPB̃, UAc+A1`mC:+ΖMiN޾{wA?kc V꒪lE wk[PّFc{ƺ~Cw`){HHs"_@ZwZF-d6 t"}&NJd?^X_72&Q~ 6u3bL|<~NkqCk.ϤrL.L`t߆#w ˔}eŲJzP*E+|Фw>tmODӞd^4 wI=nAĨ%s=e|my c **KnCBr70("4fIz^x>B3W/ƻ+kCD?g\?bN,U*p> y9퍞TFPʼ6JkAl"1@}̟Í֛Am_.f9$n:=e\ CT-q),t->f䥤i[di)T;3` ̓2P]NJUbۃuS^K4/fY9ʆB')T v} U$U }BNdw)]ETycB6}>x+6 :0 g[H[-h^w6Wf0h$TFڥe)n(q JhR[Y:_й`%\G%+k"P?6W87L i,5/Nr̪-(;S]/Ҿ\,zɲKt2D>E [sl4TLir2r2UXlB dN}u ?p@а"hm GUk+?wn=1F?Ûu;ٳwJqJ@f]N{nC> ] $[SyydYAhogP-'HɅv<(e.8I\_NTKfͼ?Gͤx gC7Z)=!s~T/L @w-piH,PI;d1csZ,SoUs9m*C&,0-o](k0#W:w@.)Sy NoH|jŔQh$QoMHqy(dY{!ubznJsYvhꭌ^"PDި;ɰ)6]K*XwDKIƒVwfh "Ϥ[&K{Oo1@^=Qq .>~B u`HY;Z`xA[XSoV1t'XLD<4~¡}?`S݈ˮf YWagd[\GvS1 1J(w2ig)#4 =:E iGpI\ q*&s~C` 8ӽNDqtm@Z]éׇ 2@΢րȴ%l Kj q[y'Xmn1ힿCusl,-uG!Y>&tu\Z?1kc L;}\ɲ̴UIYxWs ;:LpE4‘VxAY~Qn޲ d-k^/|Y9ϜJM[AL ũ#BF%T'm0>CԠXP8(ٛKЮ[2YӥpUYQݬ;rр2C,,=.L>@\v<%"_G+9ḶuuΕyd} 8?gc\Xuc5X}9a|>7)k:!|[ BӍVvBAA2qѮh%/:vT1O욶 Zr\\qԻ)|>{x+󖔩ZYˌ%hM$(p nejhP9T;&Bhw+p%W+8vfB7rlZ=9Vr‹x[*y D^Қ>DFgKi7s7,~?Ь<;~t@c! M * Cn4tsx ׳! 2c8I/h^ưͅhlKهyM@B#ZE.=Pxumȫ+d)9>qbI"YS^]_ڏ$o$qbRqtSYX[)K:$N?tASpv ?y&PU|vJ*Pl|: +"BDzZZǗܑ\W%h}mˠޞ'9!:CӬ?: pKR'#fFݑ[7 "Xi\!NMR/h-!-⼁*g$OkD'RDl6*JrkWH:9@c⹧5B˿;"Yb Ok@6-E-Ҭ9۞W !m:@FV6[X`xzB89Xr@]̀f&y24 (}OcsjĉEl濄3WxM{ʱۤ5O]ࡄq,8C9sY5$|ywp^xٿ:NSWhE# Ԥ<-y4<ݳ E*c! Oo`ѯuĵֶc _<DZm cH.D;+z*,. TqߨΩC%:nE Xmgs} :ϯ9Uho*_.g[Hsc== Rvu8XcD}:(%Q5>I;oQ?V,T3%+;2o@BLz6~9R .g)^~gA4>Spw }1Nzkc*1p4 ln" @`$=ebZV+qaG_@; +c[FY|?vJUT16; cg9 5贚=5 n(,ɧ箤OBCJˌyaQTUR.c]0w-Yl)Ap|unM3/!띕ïМ$7͹RRQY)[׽z;{aMƃJ75rMŻyL"Zq'p'[E7Cld@;sIJ]!k?{H|BN0/]߄apyn&QX&ih*Ofl MSTM_ / :RW1w(X 4HsT"JpĹ 4#c^bam9@# ^G2;U:>+ղp/~.#9eJCk©Q&7ac8zz%|JXG[WVyRLy؇k.!9\z = \@3Nf""$h9iZd>K7W(N4{o>b u8jEbK.ܴ #{ T Gf&W,n2,r%uR T_vC?E)z? ®yeT|>7"#6րGzptH,v] ɽ`-mSUj}U|\<~9 vF/F|i󺄂I̽z xT؋=DpmTAUTTYg/W9ͅٻ<\Z׃%jLWXCI cs&(mOt*kpz _vcR\Ri/6oD9X$c7rxq/Iy )ϤzI:hcW*C`y'!3?%S zr\LJN"3,Ӻ'38n qvEdd_S { FDOTݭ ǽvZұOp[aNF*+{a i(w5)یnt/XF4*6;,%mƴ+>V_YR?S+hQ:-h;CӆT\ݯؚrM'z>a`S%^}zKZONLgI '76X 7Rh -=&헃sh5^v؏_ɛ>pp(, ۂr3DBgZ$ T= q*C@{-Q@ +2#Ikn@v3'k_¯O$0Gd\I he\5߯Hj5 I8Q9rk5+K]+XX9]dخ YmojeZg J~b8=g*Ƚ iސɽ6F=#fsr:= N, QАlhSxy"4YH8>/5_z+wJOwhU-Vx'g|ʼnO$\w|͞LE{֖4l+`&%Cqp@[!wHB{˧1A^U9wS!C!Q  |l҄ P/@n><Hr\Ev$/$W-s7_(ɠ^v_DIeudLCG(e(#7҃{MC.i* X[LxЕdW75e|}ut T]-uPGD8 _Qv>՘*\j+Y)C/XF&+\3:I9Ýi0+?}'0x[s9 .؁[ߥ)2e K<+= ~eP_wg]ML4|ȼ!T_F*<)*Hh>2ZM]AVq$!E`S,㈾%=/ ۛ=}x:'wĢ}L+$caqZ1z̽k?^zDJ3A+uGmEj4,u<5ȺCCɑ ᥝ+j_߅ݤfQ[@5 y91 nD[^URw念 9qN}њ(R_ xc lb&P}#rb HNrζs?Ϻl0[CX~,f [Y'C p~}-r"mq! H1tn/L^qf'@63y#MQ(#āK!Jh9G$ևgG-VW]h*8ۤCȴF[(sX2;\Qnuڄ>պEgoz&I~ƚfCZgh 03p}#!z3xP[^ [TPY@83 ZtʁDVVDzgz0#v`r ])jaӇM!JFià;Z$RTTZVԻ%u2! oGva fegTcroY].’Q(lip5RoSR٭/np`vM+z=[7xmV:\ 6Bp AiGiAM!:*ҭF(lDVK2NӬШ&4?#ԫeZl:&mY{oC]W[DWe]X7T`C8u&9 tE3A=sJӷܑQDX{]9g%kbHw`]d @ϋKs31c<#(~ L8ƭt, 5Hv\f*:!-T2ߴ*+ER:'z2pm^qhL36w)*e~VP{y_8-.HKA/ M|މAuLkYBzn7.[VBBdmfKw?vI7W>HLl66!pW;k~q [&D%s|odu*Mpe8!ΤJ7ڠ4<)6fZ򳬕E_닒^N]PCo8 Rpx<-w{%R9TuvWsu)k*iϧ"?0ϱFo$ϡ:]*.\66G`F}: Z'\+L8n/WJ;KLɑG,W*etWm\)vW(AT'lQ2:sX}Z)m$PM6bxN%`Oe<*ê|"Kl(}K˴CQ,+  ~]y,ZrXv8758&(׆9y3=j}D^Y,gٜbgN v±W̋ ~oF[\`\.׽;(Fm EÜ8e0U]ـ"D.* M폜v药x~\>T墅*E+{%O$DxA~x "׶%.) w:3R8r14jܼ@=QRFﭫHfbб XPw%@ B/\GvԀ>r飯~w`gfAJxE/hctKhG8zVY/c=(V\f.ezXs'Ky.-Umz =Y c#~" _\9u.8Pb4j/o5̈́g͓H,ghHsbK ?3)o=ڋAz`5a sd\ؼV~b ]pCGDxy9$-iLvh֯bŤQV3U- G(!^n? .1Re/U=g@Z%_\`7!KƮq*в04z61?pṞY#|OƢm ?}@"|V1*zka^z3pE**y7Qu0?Zum=)nH*{f}=?(Simdo~^t0k(>Z%貰#k>(ki`:~nt9R񁛖Ic &>.2O$vOӥZ_N#pX}8A@C]WhQZA"c~ǣ"ŝSƫ$J9f(9 t078FaU%E)wִqE2w|O3I=FN>Q X%0>y~D-_ķA޸N$sź|V%FMb*+wF۲ }rU6!D&?ON ߋXGO;nQфH]NmA6S|YܰɓWk%_$zb=vۑ!`Hp6Vw*"7\5;W=<&vfurhr\Ct{JNfsR|[BCvGB~/ @ x}+[/DDP)՛A</Nσ"9)}Z_vlVpv9 ~׳ Z=xN&c :>a_=FCc=n%rVTwG'4l6HoZQO,7 @W¬2{CTma pQ1gxJ:)nONMKC2 N-qBGDKb%kjjkJ!_Vo 婛KWe%=è# $1/̴ ² ڮ1mҰ=zR`%V ܛ FJVXbF5KOVs r :w_<(mg붢۹I'0ĝC9?}=!wCWz6Vr]Jahi>\Fd?]YKFXh+匿(ta}arHY\Ery+5ODuK^Z@FP2ץSJ+&FI}*J"Ti|a4 (5QT9ڋ8>^J<awܯ;3[wuq=$ Ge tb\m^k~ٿ&฾Dk%%-,Q혗͕\ R g ۆX-*`ID5@R/@M[eЅtqQԠQX^?q7sTCD,y|-eEXwLhS3 HC[m3.2ֹ%aCrdp< :89n#D_H8H;88D} fxMw)Uʪ`@::SƽN0[ߊwᗗrJe"t0#ẅ#r:x.&(4M*!ie$B+nZ8jK]EUR{n"@ǻE!sɈIQ(٩*RA~Qn?|>(8Ce!.( 'S/ӌ l>,,]ںԱ>=A#&آDUr,y}=ڈM2bQrт,̗#-;hwSsWu;7vkn^n8)˱a׌rMM;wڙR&{ey`Cܾf'ezjPym7QDgz-^ 24+207OyYrAnϰĦ0.|Kb2J3ljfKi㽐7J#$0缈 #/G;ժ.4Sd^Y9T}-6e VGqʐw/1?;_n%O>nb51G6j,jQ|q͵5f6AYMgk+Py?%#9&"XS@ p̬Wz$O).*su!v@ҙ?sC`C:-E&2c)kZh .M#uch'sF=j_,+'W@QE҃v%0J_Xvԧ&h0JQi1l2zs {&+M@K7Y*" G~5oc*T\}g~ck!ks![|, 8)-݉]ط,I)ES|yDu;t徇Z;Ƅ@ ijU,!uf 3+ -qϋ9T_yREolkl!~hP (eڸ/L%WvQ"Y\07,R?)=܋¥Iq Ғ}Vw1@B;5 I^?}%JK)tY/J^9::璠=.27yL6D9sdx@[oB H[ءآUY7,b>_ uVN]Ny0^ qaNkpG9%jtON4;ttQw6~"r/$Z1}/7_2!l 7'5 +3:oD|ia ;3=#&H;aHse:n6~C.m{|e\&}S Q9%LE)x@4}H:R?>r>z}D y{MUך 4C۲0"4$(+#!|͊<{(~b6XT%S8'wЖ{r$t;9.03ʤWV%)'o<-oW9x/zL@' .,5 B «`X~ B̍6X3 QtV64h, 1>y0s*gTQUV0*HA]UBs$u $aYHϪ5@5GgM߄cuu\U=,$vAzO#4LYE=_.Mphq.+guƇRWQ{+aKHg^4PH緷D'V>D{ϡPK~ .V:—qoY:,B.2^U{u6c9]^S9!X~e=[h! eũtȟ:/s$"` 3 }UH߃W%wW0% o Up'"8Ĝ!d}eI3DAcOҤRx(!w!*Ϟ$k Μ>b#ʢ|[KX.d(aYpʆ. `-JuR4o$rAMVK/fi̙>]M6rɯ]l@ wC,(&AI i۝#ƻHz|$"|tfG:ث,8^xfKxoQZ+ O! +{j ]vhf~44VHXhOAytC #fH ދB{zF 5\YQRyg|}gC^ vc2DTD2%F +oV{cFGk g.;jg$Q>p= >k/GOOtFGe v4<%,I[eySR u817F"ƄDoq)rM=OQ`|g~PbD"UoG"~]:CѪ`]r UC&F˧Maq0NSU$ԨDܟbӯs01F/Lp}ʞ@9CggMfLġR@U=P"r%-@Buy'V}c`)2SA? 0hWSFZ] NІ`8' 01'f))'x`Q+^ܫMi;,F ́'xwH^mf)SΜ/77ZsLg|tLdnKIf27&ӟc^F1Nt-N@sq ZTc0B_cdvSͼÕ;6ufJ2Jcv[qq*{>xAYKZP-k΃вqqNjV<%0'BZI"/ȉicٺ(;J+SoW=Uj,8)v#{ ^+p[b~uLT y ^#fG3f>0Y;ИFݎ  :oQ.S1պ%x!R%YP/NP]&23>`KK?}6TSD Έe[qy(^:Fn SeoI-?2-g*#\{kKZQz-x";I).[n}QҲE5h/,I!7|L nçGM&?l S`ܾ(-4o JH̄Dx HHf]ƚ )^)JkruK=Nlj&vT6HjXQ|;Oyb ^}ιޒߧatBL[NJ vf%`iCns(\E賸9G+ J\j@0jzh5e f"VQ6=l>N2W?ho?Wp,$nBH%0*}ڰuvn[>S,E9Nҝ oj0[iu У,s !J]\܉4M4Hnh4ۨ-T-1oiS-ӵxW>* d0&6J·2`H(8ǟP7@&AO!W7xEMU抐f',41zg[]܉Ӎ 6^~By8oGRcWNlĥ֒;8jwWw]6//N` E͕W/Lg,EӃ9ȓZeiAկS^R:#pS2q)Ƭz_[na+.$y֚"{ZylwH)ٓŽ JA"䭶ɵ51ɯ#/Sh/&A/|YJ^UZ>=\ 78sqвB%(mi`l:DKugɍJ:; wF{S2K45ѣҀo2﷐:@3R9i1nՏDdU`dITL?l}9v|lP`i@BvZmf V^/g]Ⱥ΁o8Bs~u%lv5?MuEmgLCf^Jj)s;C_E< še43T/ԗ`55؍W>af`FS2s#= ?XS=nx[a: Ƃ(XtZf!=DO.ܱ7W^z )HF4ˠP,DK3F_QAoRRR-(CeS<ԅ{4IdMx9 (VQS]>g3(p7fQgYU9] ב.ڲ43`hCfRMP߱kTPצMPTN}bf6oQ$o=A19XsMDy-1Q.0b39w cXߩ-^qniJwNJ \cwxn{.i$\>)B.dhﮭb5ڎnIx|=m}raZ8s %YfnLkE2;|w|ڭ3FBvVw.vL-QCp:aiﰦ[`xϸ7XiyjmF(W9++_UU)E _!gZ-`q_]YnB_[ӦsWM$h/3)m%z`~&<*oBvƀl]şxV<}9;`vK*l\텘J}H4:{>1 <paFz;73+3!ܐ,2S#Vdĵ#l/^y߇sXd ~j#x]u%d3M*jMRf1zvǣ޼Mm6:( '30> z8c?tofպ>+ :cCA訃Jmō\ALJg̹RWP< V9Q:y&vqE߮H%3 J uk*,nú&cA>jj!2lpҼeBAp&ř&(u }L6on?}h0ޙZy NSFX Af%'j2ueնuI(b.rNӽ߽ sttCZm[JvH=Wܮ Dw+مpdI,Ƥ -`YM"/R ;G8?A*2}ZjL|3^׳5lsё 6K"9u菲;!K%qwyT/Po YwtPCyX{A&V'ԣA{X]J5 igU,a񲒘ߤJkPy4DGhɽ JXtnQ <ϛB߈oa@hg=-Q]Nw7%R0,6\Gg::WǓi?G^-R7ɚ`T.Ɍ WDD~}^Ql ~zըI+> 7 LKw/kLgGVxff%rUؤ, xKZـ. ]979l>q=vmWGxN?{Pc/-jYO]W2K+ 6T:4ЕCsx;ϯ.#lv~m~y }rjy»M UFÈ@›[5 yYBeS6V8gMP*wza\`cؙqu &`_/T@uR.by.rXBo]U{t9YC/wmwas+/],Ycb=I#tc_%To"/}xڽ̫YXtٻu7 D9Xlv%,eĂJP#KdTi>X NQOċ\.һjuRH#o48jl]̦a 006!Vq>͸UN%}UPu?*1_ݦ,7"9sRkQx'Pqjc>("; dʢ/w5U) zI05Rb:shE(pHIZi; ."04@Ҍ-h AչgLݭt}"=zl,EV?_|Cm3 >I#CNVJQt)}v(r 8L-0%C+t D֏%Jp Na\]%~yC}h;!2T, CK9|W46pmCϟ`磯c+6?a°?D;6OBA 1rh?x={p9ŧ63E$ n_yDq_o),ra=x5t*iG 1F> q%xQkbx;\Vw2жe`ab]iZ}Ce# U&eBcxvqq a|;0K;ήޭH2f΍v8=/%/\N]s9W!qm0Y2;ϊWBeQvx߱cpvdVh=&^l#xua 5t!B:,+Ca:O,d h"$u%ɶ̓O=^[ד̘^VrWƩ@j=zo#ڄ!9šFLa٣e[ šq]c)oѸCy }Pa{_-X>|;gN™}Z +q_K6iGa@M_DIw4t#ygJߜ߳hE1:h_u,Mp`s߹daݨ>".F9~B2(ϻ$[*D0aMI޽"?,7O=בmXf/WXۊYBK0a)4.lTDGǙJ~u)&hPQ!Ni 0QcɔNصq&#\umdXTL$=o!nҁ|κBc?tl 7aS.{Fq֔t@eD$+k. DK;]X-WG3+%;FOcb֨Qw&XTNy>;\ǘܑV^a2}~vC{r0uvKRIclCAPXmn'D D qoHUc7ga:UlTSZ[pBtHUwowN4{bΎ5+`AEG7 LwsݓŧY]Nٖ1ij=3CuQNhbԃӲt}7:[~Jԟ'T_+5=7ԣ[zA111+ /EWF}uآ1I89lGyJp- U05bkC ?B7r<[P;;e؃3+h[.;t_#@g<Fp|k(\9N+ WȦ >-8vs>**|yy{/<21JG߂%=r)< yreCr+:Y"&P}9+1‰odڀ¼spޅga9#V^}›%E3{dUЊ`tUQj&ęhťF? MhgǟUi5N/ ":)ZE$!^>?&{ Bz߱ 7e *p=GP2֌(ױEe]~mQw|Q9pRV?c-o@gb fղm{.=їmgBTPUoƚŊ{JvC-2PufZ[|txKh5+\@Oޤ9{[5 ?͐+X LX %2A%9Qu@uxl`SkE@E9F̔Jݴ<W1yYh 0{lG`ƍDL53uE|&vO%Wjge:f'A"Ȕu Dƻ!SN i $."sRG@1}y+)3㶉 > >$lFVMm 8!#/mo,oupBjy -̑l3̆AD']vy4,W]dCa_O.FuvS&W)/kds|”^z5F[:sqn@Q8O8D%A JuU@aR pnqucplo"[1z[z6]5&Z <;<.:%*h jRjr?(pX))ZDH8 * (eَs[,:]x lBct8i4Z,8$';1x]=cphHgD|̓&-ӄp6|}ؗeC.dڭUCv?~,5r09}dcSMKl Èkn樿ȳ^MeNЁ"r~j[: j`SO [y 4Z]CLNrM)ۺhM.B*=f}Q۹S YC\3$"p֗5m8y⬛˽R_c "&)?MXmO1@Co'uQ꿀/0v;I[} !Uؗ'nu3-ǰ/Gj*&>er>cnD8;iƍ֕+Ai5ꩧ wK< [@d C !eր&8 o2%l-6ܠE@ͧcn*p q_g*l=/>!v`2D Ю;kF`G/aֿY\kbj{_VjrξEMD9HGBԥR4FQH`ȪdU plI=ױňEB[~9WAv@苺{eHոk1+0 !h)W\klm p̒-"TxJw.fZ6Bfo]"G ~(|x{&rُ@$FExP;N,9nm#Α݀4qFmb>L! R.Y,gSyti&?v9U,ńӃ!p?|[!G2Ĕs{QUh\EGB\ȉi(p b|p3TU/^}M@G-Nf79̓T.0@C/o]rUC듿Ny({qrVN>?l$ˢ)dkXؘ`cK!Zԧo޳L$491jdX4SV5}ݖLKiMDbL3Oi"Z qBD\̅є An) ziC9ݓC[Im@PUJ{T+#dZ@&T%NK8v?ڬ\Cl朰ucwtH"q>h4P@32(o% e/T[h&"s2_VQYF/g"[~8dz#W]{ Tc`L.$jbęƍ«£.16kXZh#'@vMN& rm4s:]9QI0J/YpW gZ Q;i҅KĀp ?-%fUppF< EibE'{(!=8D<'G^z僭ձ.NTV:}hLTҖw)56#KƩppə #c\se?6 Q,"]A ^mߡo&"OyXT`Vjasj -tJ$;hG\vkmGځzfhΓDd), H?5)I+MԐi 1)I'qlxd]w2aa[RՃ<)NFWtkzrٰVir>rtöB'BzP9w˸aٻW@K>3,59Qx9cPίZȾU Ljտׯ["ɿ هOx6\/)iNTX} ( Bͷzy-v&+uF o9hakiJwSE:pDK5x-)2#mns]N> 3qbp л pVl[4}na,Gܐ|~hוA¾Oc\K0?>NR&kVKtN^FA:?S5usZ%vzђ];*~ ]$P q)d^j[1yTrH/;.Iݤ%LN(1-WpZP_i?ܣ ̓v+ΛczA- Cn!b_FG_^l/X˼N{RaU`xt2QJ&mqbkFOc&+#8,tl9$g/4$+%#KF׬ V#e1ڤ\m)nG CdYKN*1OFPr FkUupZY* mFZa T F15*[1Z/Zoj͈KYOD1ɺhސMQ4Ѓ`VN8@]>IdJ˴(GEYzz:PֶGmy73ۋ}?BLriD꼄Ρ 8y0  y2~mٴ#qځzQT·rN ƌj-DV10ХS٢,tD֊\v00!xPa06<[k"$gG9b)jm 7UVprX`i D n:++]~dQ1~bq.E^\fȐ/$?6FL+z "^GҦc6g_8\雟f7['@5[hJ}$,ci&Ќ>d0CKY y*s$IJ8óV}-: /z!.a/dfFd)X`mvcK{C;lpxuAP ]`*d=h/|A_AanP|4Q3*Rrӕaem7~]`$jT={4unB72c`nn>GQ3af];q_dF5::B(.Ug;{ΓttO{/vME z8ȥo"ѯ035Y5]fXh98;sP3ezfV $3񁗥#o7V󉻧&Rd|Ti2N g LsmFrĴXͤev"$<`ʼn Qe?DֺszyցGz'5ѝ2=j ĦFDͣC2û&NA߾n%[KWo*ÌG5!>- R lr±$p# )΍'sF̷"+B FI'lnfxmޅx59%@iCT4股KӍrIn~;K(r"IsDRj$@/cԢy1 3ec>VezkZ+-@~r gMiLŬ`oWhqP:oA+0l_w>~?:@8ෟPGӛ QIZ]&G*(n%JqÂ-{WuN4ƒF^;Í4U,hC+JbU&3ٹ[ Fҥtj%,*|V1#6 v>8ܐY\n`ww^E"K(Hyj^ƔRKȊp9O)Y_@ɤ^>`I וL+k{XuU)!%Bq;S,n#+4r*u,haTx[?;zJϦ{fvL_Mi)CJ;̀@>``Vl'ޘC~y_CM[N0\{RT:7Wz(,i24\OX:T0f|J om-\~ *@tyyzBv wcNś062^2ģuX]2Vdά x\sUwvmp?D p=)'oZj M,vǽ~@<*anR9V~Q5ЛpQ@)XKWEBE—c9%ܨ7_xjz:e97瑤Mϫl>,Ao"waShֱ *~HPJO6l(u"lJO1sm5^ۉdnX"8b5ȯϑe M۴8tg%|b+yĕcEm% K7%qGݝ!o^lJđ'jDuZ2Hu~JW @Wn(fL=tEɍ83ގIGtՇ544 y^.Egaz<]Ӣ'bm?)l'^=vG-XOSxe)B'V@SoHd] /GLsb)'WQU򟮧J`o󪊓3,uhm"uЇҟ"0׊O̓ SRrU9lDk{c!d|LX^ǫMM "P" P:*/fʨYEAа Dv :.UNSI „Y.^s3 Ϙ+sx>wiUޙx!HB lV^eXf::ʺ:|2_t;/:ʺ }rbd}N{M&RQY(hXZ}_7j[=v! O7k'DrIY99&~:8_0 }A ?e(0H_6C_Θ̪ vhpa ^ZGPtmB]?].F mH_#呐6AUa6g6v;elI- +ɔGU! A@9S JQeҸP[8T+BAdQ~1uƖ켤ĝ#nAW: b ӹ"`~չ?^ S3!qؒ_eeһ`@dELNpF#F13h6$lǕ3 ScL@@uW!h`Kj Leb(R'T)pb7|~N f(îkyo*8%fJjM}w5N6K$Fp?ov֘GWS5Y7&tS:nXe+|KAy&^T%G[ȝEbŝЇk+Dطn~q\pG5(?0z*S<, `C}+fr កh0 |Ϯ¦K3 (Ae632M;;L\_M8&CIbH:\~;y&ӇK0_D~ˬ10Z^BF3U{%n-t'b-tjʏaΕTQ&IDL~];dbMY ĺt(ȀڔaPRe 'Ab0 ުŜ4z?*T3{cQfD&F%My!D[CDz:dۆ(toI) ܍|ڤ+h h0y"<^@s9y;!Ƀqb`klJ: XV ͇0_f+/V;ZÔ?[#6[_QzQZk҆%dC@h͓߶Km\ǫ|h\UBhWysqK}.g|Oy&V ]aXx zY2*ʂ&_%ZK,>^vj8K1d3|٬4+`ehVjv<=.@(׮`L\VJ59F.wUw5w2K{W0`4M96oQLZ6ЩBga*tГ-' [tQm>I1`;[ _jjp"&TFU:nO/`?-ɋj,̧eLAOpL\6<܎ VD:qc %B֐AK NɒDglj{$ےr"6 c1e {!?[x0rL-ҖZI 7Va si1dž+DGxjۗbԡ&{A 2~N+'ܞQ{_}M'ju;16s 7,~͇6O=z'+L4nSCL\7S9r][cQF"UGəd>+vhb0s\YS/ɶ וUu8%=<+LyYx_:`Lͩ1m4УnK58D7ɠ\J ;7Nߟl(ױ\?ury(TڋϹؿ"[b+M!I |y(dz=3`BGl,oϼ.l,7‡lx.q27YX$Zp<8y:*x"3`xgމvX%AHd.V`ĊٛE0x7)Eágg`8 {Wda :)O͎8ڀÜH\Ȅ-:fwxPp=F ꦉtNYJ̪ Lc,{НDX'g#XҨ@w{Аo;W-tz -[=~ G4 LqD\MUA7Ή Zx<4a!n= }fڛݒ\vzk;xH 2}{#I8g#ϲHp+_qs0m%?tYLJ2yf0m7i@[sW'Eۓm8̖С\ ;*p`McKY=WK4e ""&IxT0*XJ>\?Pt\h-YS)&5ۡ ]%W+p;N8!n-)?KOK.c:p&D D"8팘$T*٠tjK|iEF#"׼+[&c o3*JS,šrrCsСIJNAͽQ^ᐉ:e3,/'ה5N[ )GJ ;m,"g&VYk]e2zS#kE %}>7'ˮnFv~ 03b;Z)icq,?5$\yEWDK҇#]`v{GciZۖȿa!ȕDG>72׌_ˍAؤHkJ'._auka@ջ23`YH0lXACOAeN*ajKq? m 6v2qA@' )#/~:.Z^[lES,TaӠ-ͭrP蠣 L :~d@jX 4&r7s=ʸh`TJcL\)kt\,vo4r{ʞgZ+MlGu%1 ( FD6@5ˉiZYƘ2&BAY%5Fn !\mbUӊz /kuV.XEJv\% 5LrdCOvynBt^j0`HO7˽"5$lMVV$0ŠHvSM@:7q2UW{لD ŋC%\u@s:E Xnx*k=J,Go("[Va9EBd|đPz)UȮ6"vfPfJ^/AG?9]XCzQ|V 7ޒS҄"Ilu/0Iape[eF%i,Ⓓ?Vneʞ˫ Y Su dZNNBdYFK`ڊ:F~Y<жy"VQ WT+ =ABF{8#0g u(IVԴ{;cp?@yNo`g,4慸>D0e+WOR P[q?'LPDHqc̸Y2WTo[FMo{ԛǿv6Pj.E f1"¢lL?%! zI]|z ?ꑳIc pЦ+_,$0] Sf~C}./NG?0g>V3D-L#?2| +Nk!RE׍)*UhE_ep--GQk@&Nѻy3A4~LLiO-7ԷXhJQlWP#\=N'ɫ~7 Ч\Njvg5UFv!6V"v^L>h-i}r,[ù\G8|Í}F^肌ݰ!A$`\:ɪ` ;Jx%Qݍ%kF Ϭ7Lƣet Iq^$X"i `{#kevqe ,%.BOKj FnLXMb|?cbSB:A?na鄒PQ+)kx5] s9hy9XM%"{#cHI6q'dcx#u;j2`J9o4 ( %M3߳fe{pz#d_2ǃl5@N1jq?61u+ܻ\04MwѓLf`!>b!xJpZ)qPt:l©i=4c/;F憂 T#2NN> O`=XA1I,|6dz_RͩK!@sQOO`lrfQWCu=э쇼Rsmָ؊ qbDy,h0qrezD lhR8h"CuA,NriL'et71x1?h7W UVS!Oqp _ KoGtmE QDh(WH$߉ù[[lgSuOdz2PR$D.wdz,-.{$max#hVm$kl+~To?6:jf·;5Ih9WEpt!:ˁ vF櫱?Eɸ6ҳ%RwMD; BqedeL59A(~N55m!aw{6i">ޥ /T0:wS`١Pv`}Gb;9!]"?*<_or$Bc}T8/(-H:hIV̪Ay(p-78>j0*7@{C#3)Ѷz/ tyt}&x*u?u`\vF@-c+j ǫpf4 oR:Q]TwߤƁ ֗]/3D싚cB 4,jL pO0g/Z>>~47ް3ASk~6 ĩK\$tg9مXb: E \LBnLSc"@G@b-Zۭ>Wf޲G=6耦Rɍ.RS}nѼUcL*;y Ffmpt'It-V7,3&/_֧'sͼH^Е yZmީ.B|ztNE@ " C ç=P͞?@{"~7^W[kYK-۞g-a` ؔ Ȧф曊XyP0YhǪA&0F#\jl h"fNxz!p2B| D ƾY Ojg3R ^k5dV;@sm$6-M=` 5aDft4i͟C }vys2X3Sa_GiV5 (ۍv"0Ĺ}i}͘,5`)wM%RnI7dWd,֥2pycN޼Z+kz3P=>!y+c,Z*̄seEVdssUS$[_Gև;Fe%Ҏ, NAd3q`3*`uOS,\A!]Zc !CpzE'gpϠTu6EHC1'J&<HJ+<ER=V'sVc]tepltA-?G{OݪȞ,+T著 gp@<үѢu2=BNpTlk0`0ˬ 2 *f6<}%6G8qMbߛm{&ۭN"DGamW5|e6,"#49fWPN2Rٷ1K%eо+B>IkqxO|6Z߇5$Gn(6߾q{oCSմϯav0tۃ EWZ*iqW=/v/W tHK.hw+lH#X'nA/#b`ҶJ  _}\УXZUp`TԷnT2^KQGs[Iܙ5qwk+"kjg `J>T8 PjZ̿-4) ahݴ o)-e)It8>>sBp"Q)2~/TRKƾK Lkf8 y#〆pֵXn'!&2Fj8"M! ʤ.6F1$&](׸a ]J5+A2Gp4IHWfкdZ*;uuIcЩY:zg|İ Um,-Em9ONb`@sRmVyޢ/bbx1;p UC.Ù+*Z<˸seȆ֘Lr3?&`# D'vv8xno^ME+| Rbc*i rLbp{ JՏ G2ljM{+4ٲiBlcc1~6$m4x@ |.g=KylLxǢGn@VFAM=[F7@wMd${=k/Cov' O dq/k -]=H9Gs@T7Ɠ_w l7#ָI)r hD|+%&\.GI? v$ogݹȵFRp.:܌ ԬɾLW/+k9wtą=3b+NNt!2{bs- vĽkťGdFAhEvϖdԠg֧wjꭙ}5\Wu' ] g{ Ji rzь2xIVB ܒII凬FJ~e$;q` nzdtC'U _/V3 n]ZXwJi3x[R .ٸjqB79ILJh}J% |Rio>P+% G Oh=͓$  dpv( l0w44™pI=;qup Jd9s5^)yH R@u4br`#tguB:‹N[(ɇo.xX(-~$uKrZB䌂LC;70u{U7Wѥ[ړ͗CpU\arNsPRvL@3;ذc@pYdg; !@D$YNj@l}ԟxBueGӊQjrqJI&܁PߐxH葓]?4k{N0PYhp(Ąqi G<"`&Kܯ)fk%g >w_]*PYYAGyTG`戼*+W V?h)}2B1])L#89ZvQ LnjEqsܧĵs5"4F u h!:v?IȔ#FLlf ^+jGeb YM!V&<<:>,$ wX.iT XRQ2H gYg_Ih[?[b<"oʅG$5`s!ے'*p-N"j4\{L|WG N,y˚u'Bf8y45.PXgB(L[>?Ԅ8Մ#U:v$/Ѿnt QȫSD+|S<$Po>Dݞ[GGZ5rL|`%3F/Z Y(DɻЁo*L5GIQߺ`q~Ԯ2·L0P#0WJjW#rHr+n:.QZ^۞ f8W\k?P",1"g+RNל#Ɉ: !5;6I~뭈Ϭ_vm.;\ZM>8DP'2ZC3z_0*j2G[?:XnݒS/{ȶkDۋ2 rD,ҷ>+07[/"~Su;vqhM.:9u^0gԭ%L/QZ!;9DA3(`װd3z*obvh`;#R`_;M4mVjC zk9Eemhapi{&,az-:16 m#:ɒ _UîK4SՂWm`Wa\ӂ)oMǸg"%,6v\U`o̐K!Xą=f.BgaXmQW(\tY\-)N!o"+o>9lb4 rKvf1t\:WRW85Y, plIuƺrR0aw#uT#+6,ce\v4`q\feUz eFՎlI$8/%wo.)5mo=ZaiIQE}Ħ<]ķR!_/nU]=Yi&ET.el[ mrbѨ:[O@6'[f0CXK}qK@U'RZ:+,3&‘iHZ+5Kj.mY]<݀׉㛇cM^G'MJ[9DX7Q>_ɸOԝИ@Um%%' Ti4$u{_Xz1U<`jo`e=L#v3gtVbj8-*@HbPbhX.d ;#s/[2ڶ)G:(.0iYO]H u}ÛXܹs 6ZŊwKĝfm$3~YL.QP|yL`WD@IJ} *K* QaAs]Y5χ_NvPp+evM~Ln [c/xQ P,LVUV\ZK^ITJ<@S\يÃ]k^wchOTe:py!0V*x8 o9B~LE;[ C϶J7y9b]=^\1R.ViS[!T';J*fJמlpp`pQUHпn}Ql@e\08̧Dg+@Y_$<D8n˕PWŠ>9la P5Nی9m.ڗ}KA u-v%nMq>97*Wo[iGN~08h?od gTqb߯gy*/4tp26o ) v&5xSov -&V=E kRyofPRfH*yUK!= ğ0!(f 4z,ѳ/hh󋟑Su)퀤-Q֔.M;˻mʽLC5']e9udM_&݅*WV(y7TWD p]d`զBʳD_(ߊbheF(@]g٢Mz`s;,L+%]1JX-s,L_D  e>e>j |xhZtv԰ҽX 6DHQmAAz-l}ΝNX@ȱ-v-)4&֏#Odd][Nv1%BTX؅lӍ0Q ڏ+p'#<<I̜pd<fMW&TcX5lIxnK\iJ4lMU؀^: <)rPV׷5E70+MZ,;]Ec2$SgpNx P҄^):'} +r՟t̙+ɊX*>gۑb0?‹.KMA|\T&UF,ewy4x1U]ahipLl _ x+ 0Ѵ;3Gq؟"N´HV"]\ts$B:&Ӄޮ28ܮpP3&|b:S`TŒr r1mMD ȏy"&!$WR@.\s&lφ IS~wBXCٲ.\h[sdt/ZNwhSAշAih6 ?F P_8U կɒ`tA.BByi_%GG+ ֔ RZxxb\ ]L?x7|𶑬 fCV*oļTXa4tn.#E.>n 8G#&&U]\{&aQ7šfLO5YsͧӥiicM9%2A\&X2.3mV%ν/gԡK2Do)С5EqyE8,;鷦 "KT^njN{@Rh!=;fᜒ1C"qs"d iB-HzHP=~h+ƃ4wXX2N V7(ŷ!Ȣ[W\Wț&j* lF"fPy{e ћA쭥SDz)J⬞Be(sd́m2F|)qh zZ|*2n3C>gޏ-͕u  bC:;LUGvrnwRl-4%hD2>*@gj :1ͪ7x{13^ǫFi\Tz0rtNx tĩYqÆ7&̃8xx0`x&l90)tDAYdw_[S & !BڜC*PAf(!/zWKeXVEEaD@f?7 92%r7kr&i;«[U"n^6ujk~ɎP\ )#qyn)U@7YK?IT\ tWQ-vJɽ/LQyC7;o@t?mDybE A>H$߱u >3ϾA?oLSvqz p #"C"TcQ22i/N+sWn<Ԏ Po+> pQt֝)ն(Xk im4@݋v oPXsXkj ElT^Zi t9 ht,Z7eLw 𠁝^$@>= E Wa/aP݊ٷJY@/d̚.׾Z3YYXY@pPrfaVg }Yiy79VI+!XG{Zd; /<ϖ ^.ְ%' @P$癑Yc{EՔq_|?FT-Y 1zZ5;gH,#{O 󟡓U.W}H FϪ7Lx`L'Quިo3> YBa#o!,+Ko3bx7Vz?>}h] S ,]%*d#ē`CnhjYR-/Һ*oz T)넷kK.~kV7:/ӻ+6/wuy>͖3L4ms8T9&Ԩ\trދ5+xSͷVM4! :A(;dmEob]ѺuE{r{ZAxwz`fIJ ˥>nmGM|wٿVnjpbcnBU \劑5d8L[ vv5d2mDwۮAyS4eN]Bʢw4]'+m1A[?d)ތEH(\A'it *d*+wcNFdhrHǙ`1V>)/WjP.Z*(ӸlU'rmN.ar[cdQE98qj*ss*dq^z% P] Eug6yo6=Lz>2ƚڰvoAڑBDq)QeB|eRp#5!m^cue}x}uҶIg f yqYzrhim8 <}񮧘UM"XŠh$WC'1 o3uډ,۞*"[CS™-όDX.M{ ]q ﹨T= "(fK>bI>k cȿ|/H!_m.FڃC,ZnFg,_T>wd@ח= [bpn\P 6dnCHՙBoQ~Aj~``/^%Ѩ>AKz>iڛ ⧃WRkCt+%~ XIc9cјv}v6+_-LJNXe}:uL O47m'K7FNt-!ԑ9F fnDݞu'X]XX{`=T4;AH  T]}Z -ڐ73}$GrcWnΫ\ J$`KE*TesdR a~9 K@B,JYԦIۥ%sV8,u?[vjS<[ *J>*^}a"]HD9 h!IF1A: ֌]}}NI:D:EʸGz oV~B#̤WZ 3. =9!Ij^\VR_IE<xp0 碉ř#ak˶JMS4~ZJs$~bwJ}oIQiQc.@PR^?R"KL3MM ,Lg(2~PrL~𐾟CƌX 7~=i4Y $ K7<į$D;m>F)q֧YS+6+:ut-4ymSq$R)dBs N/x /'zW'ƶ'xZ7c^\fR2"W R.&Żʪ5vH_4\/|~~.P}x [qiٖNݒlG /'Q4AjQ2Tt;BW0؉ i # cD, l>?x/i!dn;$7<]h?H7jEd=Y>=Zv$#k'@JӸVx቟J&Kh%H߼¨r͋wm0&w]z?ڧôD)6;yh>5%Z|-+B9;q׹gy SåHDM*.fb ٕcXnKM"B= W sL`sr n?F:,@h^wQ1C8JJHF=K!Xgrexv$‚g"tz3K$B> =7X808}rУ nj#Pd-aG6Dl6D-Fw/ +,MQJ6R$_ (xU,kj S37b<.SͳnFbklvq>R_죾~(5S+$z^ɅцWMCӍCK]cw, :jCV .j D՗d ӵ~4\o3laȇ+&Q+(MF<1#tX"cV* B1sG2mGو'EN,ì%*VdAՂrq2^̕? r˖*ѿIF#'bYՊ;5wH^+H=_ҡ]h$^y ZD-Ͳ^V/&;4:~kKA{T1jChӪ%*fgs31 S"2JM\Vr^kJ"VΞQS'~tβt!G!}*5h L}`kr=3`f,Jʢ AOOfIKؤbHDLAKZMTpT"w=eu$ um+bW;).Q;!Ɔy(rl"bxycfU0LTŻp;{ij!l| q0l( Uyd CkL-űJ#L^{%.8GZXȿk:kZdׅ [hgх󸲒`rS?z G;SHoz?͎(_ԔِIvB_(H2tAa|MgnodD|}Q&W2_Q0(94q qUUɋW&D48۠H+ b1[St50N~Obu{Үį5XUTy+aKa3`yVChuঐ[R,ݔu_P. zqVr^zؤmӏ`6HbBTkB_qsU!$ R|VXk&JG7U*1~H^6" VhUJpk%_D^_0Dq"BÖ4ivJ`zWרۆ 4^Lș96mbmݥr-w[^ 0)"oģE)1oGwoAy7VS^gǶ$Î wn-*K̙zuʪ3AbM${L&:0m =4<㕮NEΛFg(Fb{f= $X=Nzv;km~Rz()8w5tncw0!(^N3dPGqkH *dC ;]pl9CG<[ aD(nw̛o ،pɈq5I@ :b twvl!eRԝ2.G:>oT42x(㜚.R9MzyٕfҎ8l"h8 _ Q~([.rК)Aw<u9|)P"4CuKɕ mAV3NOp6>"yYGiFv?4_A^@rK邟Ƕ kv%ڹ&]{ O,QE<ڕМ1HoAVe+9`'`gږ%lT#?E˦i/1on++G!2kdx*'kv !\iMR{X4+bƿֳw:RxX]u̠<JХ94ځfuHqƽ=YvM#XYP&!{ w&MF_w[K%VSu+ZYeQn;-5)KV}m+[@ۉwՍD}`ί,Ohm7q68گ8tS E3(PP~y$!3Mi s9u֮Tѭ:nqS9ZEFHכwګDz ^6Kw!aCˋ?(88dS\"QTi:źC\)௺^]v)E+Ջ>PbT4U\,ݼ9tP;C^䐉%8.z;0O[W5>O ]Ri6W 3xYl&ُhxI9s;Ub>B5Բy,ZʖgK77jlx(MTlS30-=;$V]m:c $>\+Қ w 10{l::[oꥻ-oEgeLJ_ez6W˦4yP.<{kNoT7( M:lA3QgCYE#:@&>HYK܌dڍ͉~qRvAh$1`eXh1@s٬z Lã'  C$ ;da]JՒɉ~5WEr6SHVN۰s$}Kܚ'8"p Щ-ӫT8e$O+"熶PNNa̢ iN˖L+Hh\4fƾVf ;B !M>RKJUVYv۾!؉B(dv (Vy|!UrvZnn ׾uNw񛡖ͨ.-rAFy_@oSyL-DV[~? =[a \] \ގQ:LWc8kp:cjʷUoaZ9\d٤ H')WKaqoBt2nSDAQJ?'n΍&x5 BW0>)nB0 =Hj!a!<%_>o{ȁWI#-6'6ws l.t H[wF ʕJEa!V y$?)J)"VVċ Vr{1NqQ&Jksp">01ੰ1P)s˗Xf <]sy  ,FP uҢ, - .}#m2RZu2awէ)&aMKiI6DŐpR zOԛ_od ğ0EϪ0(#<%Q )LC 0hlDY7elV[_43i~NR ޾r0A7(]{Y+IM80hdGJz˖g ?/ۊh05C0+(͜Zx[ӛU3*1uts=3 ǒŮ5ohy<)'n0.rٰ`jmmTR# b~)8NL^ գjުMTZkpv S?;*Y,I5/ZJ[^j7@$jRLIhb<먗Jɕ )rA%uO~k!?}X-ԧ%kE/s L5=^Rnjwp"k1\XJPҊyFs鲈1}z+b1i|vUo1@t&C >K^U_b?8ck9Am ?-{Y+7(6G߲i{< r@ -}@i*A^ä.)tTE%t|tnwQROԫHwuP5*uWy[iRذ*HZbOl u+/5;inUkg[nͬ¢u7 jV^ޘ e/Y#F< 햮T˶LEm[kn퍯7R˛ D@  )ycHW']DۛNGE~xWfP9OY|Af4`5"wP̦1b} f~`R~%}wڇa6]x*px'u[k6j?G}}NV{SEp_xlի8^Mܢ,$$&lP/UpJ"r4R#ff< Te&m.,J#sW.=-v{ݼէ }Un, F(!>[ m0;'6"4N~Vg?V*` ͵=Do틎qi2@4a` tr% }*أ8$4 =u+ [~d1QWOjq , )jc^r GT&Mt2a9|FUz4d!Il!p)Źʄ2B8B~j<a]Kl/qz;[ c\=kK[^6%nD.ߘ>S>46i*;Q=TQ*{#!O !x'H(*N@K BKRSsǔ_}VKS3*^piLaeQQtmyW[dvF_#"NᅜdL&|.t0J>)ұ(-7׸/2 ܏hFzp{= tx8FA*E0#IqN "Q8wHãuW}w4o(Y+<bQnD(8P(QX+ 0V׻XPBK'ѾJD'5 M288!$2<ޓhCYQ5߃dLuQ 9|9U?zh2LROeyu~ ؗkVI[u^L|$4cpԩf#>go0ȶ@ǯqq <<dhS/8$\ł%4q I.⼁`۝BqɅ~XDX(t2pێgotiaxD8%Vl*۝_1wh&Vr$0KvoMN$w!s K)S_??c.c3γ)҅Ҷ@evL Hhn<:nRc]mb{Gy΢J/٬?^Oo`ᚰ~o[IN]\P)@Ȥ%f?)k9bYT]HxULuRxIcǫGw1͂dރA*MƹTәh)CtV Zު…\;Blc:Iv|uXJ.<:^!}/fFng Wo~i`RHcY݂ak*P+0M \O*쫋J9}v{ia4ixJlƘ$&_+cJmaČpI 8Ocg:Pe.׾~F^j[U>U\󢶉&d7tXdF$[p${^I,mt)!lpV/5{,D5#,]Sй9\ Esx/Ko4N]d>|hbS4/r$B@K=ô:m!` b4_)!x( p.Q}ZDxRj!\QL$ɏV4e BeIwy7Nҝka*[bw XXܦGID@EwGs9dNՀfC0e:{k^u`1>wBRa^PBvndÕakayR7q6 :8*b=;3C?ZZ^>gIhcr2b‰-ZGN22RѨ8Sy q4h3$Fk;s*VMZkLa[xԿcȲm&%ˤ G D# \ ^]sKa#Pgե ~ 3Y'@0cd+D\u oe E+=`Dp/Tr`4UqX"TCIn5Sy!$mMVhWy-ЗIqLlt0[\a~Y*]3-~52p[ىf A[~ߑe&/"}svUi(nZ-&&bC:7Qy+0?C0;{|ƫ|. .6n)''a&p>11? ̬}nnP5=K#sNH)=V-shUҩHF”RCw&4ٓeGZ!|o\Vp 󺪊? RݤPhmA$(OQxہ&tw޿te .8%Ki,zP<D!c%mgFeex0eE;AO^!smo p~pFXP̸79"Q|vK5".\gL],5g͓& DD; p~v/F~dcp~1^z.KJ7$vʑD^ ݆0p%6|=صFEq}ACA[sj-]&.(TpiSXrgW-f5"IKZ\,*"ř7  C;5:L0i0|QCи?,(5μs c]H_쀽>S%BcиWL_vcQӄL?Je8X@`Vj{U_Ɇu[Pͱ#sl.s=m{<NVXw}"XRvJ֍fX?0, r)KmSaB vQt 4lZϺS{u2h̉_ bxPs$>PNrJN#TE9o'jPtr/Jm&K mϠMNư SgwuըVW'q(L=9HGgqB3N":(GRMgVd胈 $V^,OQeHq% T ISx:ɪ.FA~J%68w_78 '-u򊋪ѡ0o(,ޭ2 5hy|>6 +̘ -'d(IwFOs<ҏ:'> Roym_m: b7)ws0f_vrxmZU%|kܥl^ɖZ)OrO}M8]H.ύ Y[D徘n:(`Jaީ1Nkm'=/Vr?1T`x'\&y#\o$%UFGbLSF:bs5pm8Q>Aꪱb>JHU{Br=n jqf  +gМj`ƖA"%wW7"c9~POKWnP'oEn(mC@A?uOA: A9 wKM|4qTCU12FF>L,tnYt|uy_4تz"MyiYz=ހN[51T!oק$X/ s( Â0I<sNNձ˖?*Jؓm:;kҳ/8 E>J{Fv|ڸx}oעb wҧQYJ؏6WRw MdZC)Kf聾i# i)G7uʝDtkh718Hڍn%L1zN Bz~X'h^V/|8F.6S1ۿϪ9s]٣n«ŕ#EjtxwD䲋PYDs*VB^s:k0?~$>il',%J۝UK٬5;Tܵ#pGj1CJ+_xOyNx4N\a5kUy,d4>0̃BsJ)S/e.k _Tݨ:%6ڪrL{A{"6;akC9@Jf OZZ;C>pz6ԓUV&ebp/,J% c$ P7&hMT|/WX182rΘC}d,^|hO<Ŀ__^񧏃_p=<.V}eH+0 R:'AZH$ۖ¸WP 3Uˢk`hNBՑ_&ȀbLS ?kZ7 mxby9-- { FټMJN0^ CT):ӌy2ڄ=J nh>)~6#m\*ЧKf礞pw6QD zDHduyi"3~fɩU$(LGgوdU3&+8ӄi9Y8QtϳJzo؁TIVAM.)<y&c폚 B>W9 i  ;b>=&xxᕶ_3uBlЯf>IS%rM.>=u KBA,0=EӌtU]Af 2J:NA[VJHJKie?~rYFsOX;~];(} *ttd"D̃WKAG;և2Jܦp5W@NJ$2G@u1 -AN$xAh5]=f?"DgC 6LTͥѦ8יt8!yYߧ\ku`1'暨w%6:moo#0-1B+*F>YF SlxΕ'):Ѐ,6\N(,ͅhwnj{jc"Pd:?# HOAjR۳Pn h1Ÿ Dϡ|bq۱}GL J1;R/i 1Ml=$UK}RiOսcBN 4ڀL[vo^F[pN- uW6Nͣ@a2UX#pn\-TV 9jO V?0@ѳc*OҝyF!{lx{wm[áHh W.$Y,:d  ~Sz}$FW_{B ,հe`M- 7VL}K,SНrO~(b Gs5Ïm&,[&u4" {Cc!FgqW:) qܓq0D_-#ɰH?*[QJ c ;lNi;>v|0hp8yqy\ 1!rH׳4.>0 - pL@*cڋ̦ar"g:Mtq׳ztڝg < !_4cSwTh J(Z@.mu"R?y Ay$ ZU}I[3 ?Bb3&oo&U^>@*82˴k 2kPCS82ޢ~IIjWlckΎ/pF4 dMk}Hݛ,w׳V/!BzQ2^GG/L:IxF=#7X-+13"-|}gJJHB?P*:/ua%aǴvjM|w8VZ:C$s#t<td<]p>S`)=AoYIIHK| (kw@w ]< Lh2) hdܴȬЧ?07ZX}qF-j|&ML]* ;6 y9"+'rNot/#:&nUHi|<]wQ~'亻_VqV9=jke45uy!#-@Ï # lHH$ǜpଔ?O UAB>7< _k²P"0BgT7t' rMMN Ƕ YZ