samba-devel-4.15.8+git.527.8d0c05d313e-150400.3.14.1 >  A cp9|ct[\C~F EA(@r^sWj+};/𔟶Ul~ztGoSga0q"N6I=|մ3PEJ#Òr n_Hv0r淀pn*+AZ-:/,7fxCI YCIr62pttci\}5~ rk9^|kOzJfec4d2c9a31247a5d744793290e7aebc53bc1249bd845d189639888348284d2b8b349623c388373a299b072fa8f6f1b57e865f86߄cp9|41 q''(yjŔVu$w͛kIIhp3#9 0K>=.+a(.2zpZ{]14srS楸{"Ҫ$i U v!#Af\ * 7IM] VOIZDuG>F&3֏nBl  h3уD/;ԟzl$v#yTv e(^PK3/ >pAl?ld) 7 e/ Ee|    ! $&(+J+-$0l01(28296 :GNBMRFNGNHQISXS$YT,$ZV[W@\Y\][p^a bc/ccddXed]fd`ldbudxvfwgdxixyk,zl<lLlPlVlCsamba-devel4.15.8+git.527.8d0c05d313e150400.3.14.1Development files shared by Samba subpackagesThis package contains the libraries and header files needed to develop programs which make use of Samba.clibs-arm-4ySUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxaarch64( p=A@!1N  aF ENTv |H)KU +d`@t2!CY~W +g > v&HI!>,'I:l hd Z=1y<u .Y3T4&{66)w+3'A,;BG[AA큤A큤A큤A큤A큤A큤A큤A큤ccMccMcccccccccccccLccccccccccccccccccccccccccccccLccccccccccccLcccccccccccLccccccccccccccccccccccccccwccccwcwcwcwcwccccwcwcwcwcwcwccwccwcwccccccccccccccc57f48e6acfed5fa9841df0f458c77820b6e24ed8279bb23819c0698df22bbbf19a87ebf5c3ecf098bad8fdc2e0c08317efd3ecd4947169677feb755c5f86b325aa97c3dc8a6da5e8d196a73bfb4bae250089de7237665a3a6dcf5512c71503695cd7da44b981f9782081d3d97dc2d2f26726208f56b10bceaaae6e1a3b497bfefa19c5bf4838b4013a16d205238e5fa9819e04902a006a08044a0da795cbaf34f53c103d9d508de1883fac4df0fff12ac27300409f3a1c8edaf31c05c054340a1dc2974d9c574811447befbe13fc0f8b3d8906fa58ca173857f5b73359ec30f161766db604986021c872a81bc3e6dc403b8960c06edad4595f168293005943b8486186e935623059f05839ab0f3604f56687ceab73bf9ad6070e58a7161041e32e3a21a55901cc3c7a46d6560c167ecef63390fb04b124e508eccf8156fd650dbd572ab4954abffbeef5c35b30e8c5806501278b70a08d6041d8a5685a69cd65ef487680f99891e461bcaf8245acdfac7964fa40fa4a298184528c2fe2b51b3066156e28d7375c095735fe583c41fe10f68711a286dd7616111bd0ba9a6c39eca72b30f0da89b141671dac7d0b96636639545a74f12fbbcc745e7e2597d71b4c7bcfa6e9c2d3666eaf6fbe6b63194f9d4b8991619ced1de631f1d7c854271bc4d7d6caed90f3ed522fb13effd5b3f9ce1d10f57b87a233f8b1cb8bb000a06b812e45f1d76df8d2fe7405deea4c26e6e1ccf3951c59a55836952be0923e7928b343892fe61c87666774dd2e18e31d70da33b45c5986aa1c23a6a853a6cecc906960aa488b92850596697a2ce4811cd350af7aec0b5278c15b3700ff5759a3a9ac8a09b87e376224e944e12a2067e9fc485ece8ebfbc7d5cf0bf573e0500c5bf24c38a14ecb5e00e24e7947b8517b8f39a652b5a4a7cc6ed2dd04dbc35210090e571af576c5ac08f897ec08b3d0d2d5d40952aa94d082f5550483c051b99b33ee65aad7a50a60ccf805be82f6209c702e0e7f73a5ae774d0c68b57b28dd1821c1ab067bcc678b898c16d290afc34539c478fc1f6b47270a45b389de9fb9ec0042b98e789e2e76a17d01c1684441f27e27f5c54d7d8d1607fb9cede012344438922ffecaceea8800ef2175f1046485790f995229035a56992eb9f80f586460519b697827df8285c4ebf06595b743e148919677ae2a40442c80549d7aba0bc0b696ca55cc095723a52645cf7513c55934096218760deb28a607b5e85f82db7c1ab580e91df20133ceaa62399bfcfa07ae216642332bf119c5a28639f3e6841dd74e2dd515f2b48efd9117bd5054262dfd09a3617405695236094798559211d988a68effc888123ae63e8d2ba5b96004c14b3356dbf490b4e731cfc7a56467079075b6004265e32c0338f01e95f47cda607f72abd98a2031f32f45a1470dec6e13f4c8e17e93041953c7a33ac4dadb193dc843bf0dc47196230f74fc5a9c4ac1989654849afcccbc35c0a397ed9b8ec9579d7a3539a11d9a1f4db4d40dfdf2846bc81f966b17d69a728af436e405c6653b76b8b1b0cea1ff3094b88f184043efdeaaef078ca39f9c1b6ffd2a287d8380c0ea5cf53ceb43040bca0c4f8a37c75c1cfd40923c16ebfe2ac820e071af1cba5cae4b019dc46eb22b6fc37174d15ac7b72c723c10d44a520b2054944d0606d29c16714a4196910a433f607fed4e35d63918562c260077a6a23b99eb7ea40a5e790a7d97b17c8adc0fe8152598db810a35a439e0fd2184591f449c79b6bc5b5468443920523ea943440534df04294b940ce1c00c0a68cab9a5eee13b0a18e6e5b9d87693f25c1f804ac1878bf03800367d25438369395e7f2006fb647db68043d1590be759478e33b123ff9a54bbcf1dd70a038467eb6dd4dee91c9309efa27bed7b9d371cc936612a2998c16e815dca6ab2131a2f005b7837ddaceb2598db386c1d34c1a777baf0d741ea2d153c399b4b0fa22367ee1921737df26ec3e9fea81c7f525ee4076db13008901c9ca9f404a6db835aabe1a026f6f3e5c05cd08a28a339b762c6189d4af93a1b6a87f9d9483d5833fd883506b51ecca8ad6df0baceb27177fb6499a7918703b897a45cdc7605a9ec9315a0f82f2518db30b753b0d4ca10b18a94c382f3ec70dcc443437b2dc9e3ce610ac30bfc17aba981efd38215a457355b1f19ee2e93d26cfc3f6127d4e633b3d89ae70e214c6869f39c6eba1bd4d835c031b67bc5c4f908e60816711e8d87e6d93f84fea1eb1df4a7c2bb8a671480afe65f9dc7f671e0e15cd8eea8e37927520f3ac8ae6b63fe8f7aea81f7680951eec3ab67f4383db52789c38b254cd5a9e4766b17aab8a99813258ebb4b147bf98c9f0b9ac8e9e07ad86cc4811fd17c0ca05ad6fa67befb082b2cd23859d7002fa75a5794f15fad8157402985d19cdd5acf644d53e40a42be401e586068bcac9874c7de197adcde4b956cb267b54aa1c960c1acf956f394afcde8741c7d3eb9c1f0d24e77ba69ff7eee8ba90786ffa6c5f4ec183f16ec4fc964c65b35a84e0be1b1f830b8494c8e895196ab132fd82e055cc808ec43d0bf84e5bcc059302e71c0e23a257f197463a9ecad24f59aa597f875a287795dbd2ce8b56438e84f9976bb4b587c364e2b03cea9ac7bfe92f670c4d88fc1b382789f66d991a6e526f4093a1972e1391aadde980420a1dec670f3549f87169c890fba90086de0d8498f0fb36921439a3568cd3a29c34bc8fd9c25772cff89b4edcc989ff5af4189ef2e0ce0e37872c17ad0196c4101f1dab6f2233d4987af03f7dbbfcad01f857b4576ffbb67ed2f4c6cbd9f0a9cd2192a7cd36f8201ae7dc5c1bb59244752a7c96d0bcd9f3e3ad075aecf96bc9006c8087a428c2cbf46832f58f5a9a8a1269d77685a6ea46e21b05e9d22e79fff5ff59e2f6fd5ef76604c85c807b4e3fc0dd84beacab1ff25be2672650e35fc5a2a04de281d9dc535f9718a0c12832630ba0008a46bdb263c2610acfbf6da60c6d585687581e877d06ac2587e1c560a57a924744d428603f832aa43148df878f81961c305f367353717bda17d2ab1d3df620a04711fd5a61149d16c19f34a48740662395d01a17ad400b8e6af775cd8eeeec7fa786bd0c1c686c5562fc60c40b7f0fb213627e0208eaa36a7262e7680bfdf38ab43a302de7a5ee1b18fb5e5a69c693660e5ab407d1696c7b4ac8f6ed075a178fc967e2e68e1bac448bf37478948a1f40401d26eab750f4c70faa63142713b1ca959bdea59f5c83e1d20b52792246b46127464459c635949c3f779518d0e830d9f34a33bef4b8d49477a4a648a2d279c88584caef10d814fafc233b2ed62e1b088b7b99fc6b8017b38dd73cf8dc94a4e97837ae5a7631da503521a5133a57f0445a4dfa2427eeb926d7ece4119a01cd20ba4acec5db90984ce61844ebfb044780a402cb880b08cb0e3b6d709b17117204b5ce3a21b987f0c33c9147e5197c8e52257325852c5c181908a3f4082b5520d1cf8599ee8c5ca7e8584f8e6deb53c1682692aec09dc7339df4507a69a44fc4e889663a695d0e42c4ca1819bd7e814f21ea857ca7a1cf61daa69affa14cb497273b24b2f9adc344da28391ae7e27ea058e1909f8fd85bf9eb7fedcd7dde1fddb48b6600c8b61eccc6409a5a5391dfba7e45844c4f2da58e90d275e42aac178717449816161fe77e2af95aff8ff703003f5691ae2280c0809d15386619c3aaf0620e8697c3c0d494cf0d6a2fbbde841699930bd1f5d8c43118be577f601d6cc6d9ea72bd4e42fa96b0bf03b1764946f28b3deeae86aea0bec44e3c3fd05afd367128b4e2513a6a73ba9cdc263d00d43eebac1c05313154d5bba4025f00fba9ada003bf6e08ec3717c956f9a10aa3bcfaadbe145f7723177bebe2a8119752430aecb7121eecb4e1998b5a24b456197855a143c84f2ecaf31540b1f5457c0a2fdbfd8f53f9b9b119b1918376d12eef6aa5248f7ac7d7deb71f336a52fac364750774f797c061e915eb24775ae28d1738bd86f5a5b902862b25dabfc4618da50b85e66272bf52218a6cd2e26338d04c25404fc53d6b230205d0351470ccd8809d4ec02d86007929edab0432c4386098ef7d1c09bdd8cbd6e9b0ff02a77cf2d3de460ded50b04f15ae58b86ce48bba579542df1b00f69e97fe1427fb1031f6930e7c3b058c09850bc72e8361579d8f0b97ce6c33df91db1edab5412d88550bfe89e5d34a73e8be26c6cd20a922ff73294bacfd6ab37123f9f6304ac62b5f3f2c020b7cf90ed8279bb84b70e146d0a47d12743138659271122b65de007d76a54634fb3fa657a0e6c8a3cd600d4be43800c4a74bb5e41f57bbf05d01629d0cd9856ca1c5cd05b52579c70d58b6328de9543dba02672487939e41e910f508c1dbb0923f0726dafc2b4fac411ed2b40275fe0fec3322730f62b84daf91fb23bbb081489863168493d1d893df191dd1a0597fa2bc7c08eeb7f3e7aebc136e2d47f375bc7a94c423e7e2038c997b11696c0985d79acdde3e6a92416870ea45c96d1bf73f93869406507c71libdcerpc-binding.so.0.0.1libdcerpc-samr.so.0.0.1libdcerpc-server-core.so.0.0.1libdcerpc-server.so.0.0.1libdcerpc.so.0.0.1libndr-krb5pac.so.0.0.1libndr-nbt.so.0.0.1libndr-standard.so.0.0.1libndr.so.2.0.0libnetapi.so.1.0.0libnss_winbind.so.2libnss_wins.so.2libsamba-credentials.so.1.0.0libsamba-errors.so.1libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0.28.0libsamba-util.so.0.0.1libsamdb.so.0.0.1libsmbclient.so.0.7.0libsmbconf.so.0.0.1libsmbldap.so.2.1.0libtevent-util.so.0.0.1libwbclient.so.0.15rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.8+git.527.8d0c05d313e-150400.3.14.1.src.rpmlibdcerpc-devellibdcerpc-samr-devellibndr-devellibndr-krb5pac-devellibndr-nbt-devellibndr-standard-devellibnetapi-devellibsamba-credentials-devellibsamba-errors-devellibsamba-hostconfig-devellibsamba-passdb-devellibsamba-util-devellibsamdb-devellibsmbclient-devellibsmbconf-devellibsmbldap-devellibtevent-util-devellibwbclient-devellibwbclient0-develpkgconfig(dcerpc)pkgconfig(dcerpc_samr)pkgconfig(dcerpc_server)pkgconfig(ndr)pkgconfig(ndr_krb5pac)pkgconfig(ndr_nbt)pkgconfig(ndr_standard)pkgconfig(netapi)pkgconfig(samba-credentials)pkgconfig(samba-hostconfig)pkgconfig(samba-util)pkgconfig(samdb)pkgconfig(smbclient)pkgconfig(wbclient)samba-core-develsamba-develsamba-devel(aarch-64)@@@@@@@    /usr/bin/pkg-configpkgconfig(dcerpc)pkgconfig(krb5)pkgconfig(ndr)pkgconfig(ndr_standard)pkgconfig(samba-util)pkgconfig(talloc)pkgconfig(tevent)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ad-dc-libssamba-client-libssamba-libssamba-winbind-libs3.0.4-14.6.0-14.0-15.2-14.14.3cM@b@b@b@ba@bascabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.libdcerpc-devellibdcerpc-samr-devellibndr-devellibndr-krb5pac-devellibndr-nbt-devellibndr-standard-devellibnetapi-devellibsamba-credentials-devellibsamba-errors-devellibsamba-hostconfig-devellibsamba-passdb-devellibsamba-util-devellibsamdb-devellibsmbclient-devellibsmbconf-devellibsmbldap-devellibtevent-util-devellibwbclient-devellibwbclient0-develsamba-core-develibs-arm-4 1662105452  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e0.0.10.0.10.0.12.0.00.0.10.0.10.0.11.0.01.0.00.0.10.0.10.0.10.7.00.154.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e-150400.3.14.14.15.8+git.527.8d0c05d313e-150400.3.14.14.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e4.15.8+git.527.8d0c05d313e sambasamba-4.0charset.hcoredoserr.herror.hhresult.hntstatus.hntstatus_gen.hwerror.hwerror_gen.hcredentials.hdcerpc.hdcerpc_server.hdcesrv_core.hdomain_credentials.hgen_ndratsvc.hauth.hdcerpc.hdrsblobs.hdrsuapi.hkrb5pac.hlsa.hmisc.hnbt.hndr_atsvc.hndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_krb5pac.hndr_misc.hndr_nbt.hndr_samr.hndr_samr_c.hndr_svcctl.hndr_svcctl_c.hnetlogon.hsamr.hsecurity.hserver_id.hsvcctl.hldb_wrap.hlibsmbclient.hlookup_sid.hmachine_sid.hndrndr.hndr_dcerpc.hndr_drsblobs.hndr_drsuapi.hndr_krb5pac.hndr_nbt.hndr_svcctl.hnetapi.hparam.hpassdb.hrpc_common.hsambasession.hversion.hshare.hsmb2_lease_struct.hsmb_ldap.hsmbconf.hsmbldap.htdr.htsocket.htsocket_internal.hutilattr.hblocking.hdata_blob.hdebug.hdiscard.hfault.hgenrand.hidtree.hidtree_random.hsignal.hsubstitute.htevent_ntstatus.htevent_unix.htevent_werror.htfork.htime.hutil_ldb.hwbclient.hnsswitchwinbind_client.hwinbind_nss_config.hwinbind_nss_linux.hwinbinddwinbindd.hwinbindd_proto.hlibdcerpc-binding.solibdcerpc-samr.solibdcerpc-server-core.solibdcerpc-server.solibdcerpc.solibndr-krb5pac.solibndr-nbt.solibndr-standard.solibndr.solibnetapi.solibnss_winbind.solibnss_wins.solibsamba-credentials.solibsamba-errors.solibsamba-hostconfig.solibsamba-passdb.solibsamba-util.solibsamdb.solibsmbclient.solibsmbconf.solibsmbldap.solibtevent-util.solibwbclient.sodcerpc.pcdcerpc_samr.pcdcerpc_server.pcndr.pcndr_krb5pac.pcndr_nbt.pcndr_standard.pcnetapi.pcsamba-credentials.pcsamba-hostconfig.pcsamba-util.pcsamdb.pcsmbclient.pcwbclient.pclibsmbclient.7.gz/usr/include//usr/include/samba-4.0//usr/include/samba-4.0/core//usr/include/samba-4.0/gen_ndr//usr/include/samba-4.0/ndr//usr/include/samba-4.0/samba//usr/include/samba-4.0/util//usr/include/samba//usr/include/samba/nsswitch//usr/include/samba/winbindd//usr/lib64//usr/lib64/pkgconfig//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:25691/SUSE_SLE-15-SP4_Update/b518cfb68f7ddfb5e239b417674eefa1-samba.SUSE_SLE-15-SP4_Updatecpioxz5aarch64-suse-linuxdirectoryC source, ASCII textC source, ASCII text, with very long linesASCII textpkgconfig filetroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)  "&(*PRRRPRRRRPRRPRRRPRRRPRRPRRPRPRRRPRPRRRPRPRP R0]L{ Futf-8f6e46bf32766235acf04d0a1fa6618b8ab3390f378869f6fa183a244bbd1c90a?7zXZ !t/]] crt:bLL t}{5}A{>/`.i3ž ^YK:;I;=]Tے&SiiewԾ>f@2>Fzg<ɊG~Wc"Va⩾>\nCnы\T쎨@!Xc#VP{r I#Nlu^>) #C~A׵ɛz`{F'Zb7zVJU0Sm\,tR)@-,rA+Ha7.ъz 1{{Z M`r֘e48A_9R!ο; ^VѶ~HR\A}Go~Lxa {_9POqBN/FಡN;rUa|hkv$7RdJ4,(VL9D1P4VSzœj9'ҩPA@LYpg1Z!H%] T+hdCuS Q4$@楲^T6,>A\;|@\_".a;f׈2ȗ zk {Ʈĝ$tU匍_3," S(U"mcoDr=a<|EJ ;d 3M$#I;Иޖzts0`}:ԪD%lD8D)`1ݦA)^s7( ?"[7PQ;9=8 &0?AD*(8+髈NWRbTlxojh=j@D@@n[el{п2K?vl=Cy!j1t ya,Sk] ip~"<J4`?XA [p􊲧FU=w ^6$ Wu+KuD\dC8+ԇF>P8u}ZtJȏH+wafhbʏ8VVm:<,BÑ-U}Cv%;GiD/obi2-dn7zl5)[B"=dHn( ş?;y S~Twl2`mۦzC7LD|榡Xq #vG/Zmqh"`LJ'e +*NT}J[ԟQ=jE7k1::D[3hNxI8Ǘ?eƙ׮O>jxC.DOF. x[©ڼJ"+z~U/ a:8 OZeˁYj e4 [$S:@$i'T;vNdnoEr F+f !L Q-P;.,,q9HULqP~]*- 1tX6'qjI㖬@\΀Y R]ҭ9I[]3,; &g$1ѤfGYaoj;@ (g9h*'.Nw<󋟷_yl.  k:WN:fokb"49͚'%v3>/&\hgn =9Ek~F`(l1I2BNدm?įpח;Y*-BC ĖM 1ڛ:΍2*3,g(ؙ/Xv\P^fEyA|uG-VqY8fʰLrn'ʄs.y (ӷ6rGK]3hh~t/c?mJxW24LƺDpv+iUjbmׄ!jY,fc:zP+9j[ >Bh p;jeD m:z#!Vq+_Gf. ܂t&gB4wd.ys3YJ&:Rv"t?+4}w-Jբ#ݕ`(һg#HR}jYx kauxs"_ں)yM 9bM(gjKQTj>prW.dB};+ĺ&"[l%Gw8&]UHWgWO5ng{]:MFx DW/aN Kh,J.X$=ڦ(XV&w &%:$E\GhQ>a^s0dε 1Qy3v=-cB<+ bO7j 2"_"{gQ*!ެ{deh\voh@}t"v'_u??=5γa%ۅ`cפ?5"2SΏ%[ }Xplkq5/H({/yC87&]ซl Cy♒gġpK]u]1LfʃisA|2 Р %V%^5+dvVAs1ocnd&i4\}oil7!;Y_darctH倩(J#j*hDu ØsQ%o 7c,S:"o{:\J<,I򱀸ld>Z8زX=vRg.]ظ 㑘0qh$Um'ʏԱ;0]d >`wd?U/ ][ oy.b2v7@bmLk^ m?c^L]xUtsѷ.ԉ8԰g76:gfƊgMg . xK@V-HZ]^W%gt? @:]+& (ܸR؆f7y@>/cT70حo7 ttf` uz1f؞Ed%s>~ZvyHX5TDT񒓞fAY}j.]X2m+IG/UX ʑgC3V,HA\CY)mh9gG7SN` 8|IYYh怍)s iCFc뷊=\ QqwR4jl7eh7~}XV{9֤͗lc~ @(Ahyk,ː=rΕ64ͫ|!3cLʡM;gYxa^?sZLNjƖb D{7p2qZA8MMs%fm#699H:Wk$+b>5MݍGfy]0ф,m :&ZN0#V:'4i\]L1\jPJ[!e[ FcW?qz+jZHo(Oҋ+<7u, n">clx,$IZ,%4wSPmܮ7:-~u?"mo| ^凑r"&P*#?vi퀐_M- /'"~ߟbkNd&H%L"%FTk6sD{&]uwO Wa*=5-?kw]*\ ʼnwf8Ա$[\|nMщRn/2=e!\92c;}wv;|_=eltdfCBsF=L w8 L&/)!~H!I2]Hn3-CO(K n el8:’˰2Ja"@*hqd4y_Fh*HJc8%)g4%p+2n v;)d$J(wr1 s^N 5H RC?V;<0e˳)9E~_I7q5ya!זl+Sh0NcUb$(,Bj,@ vg\Aa KiR$UŽZQn1sxA!v M;nզ)//Y Mc̾/8< S$` B  X4 xkj0*f+gvzkiC[Lct_܋~[_7ƶ+;0<n!+b4 Ɨ*x9,Չ=!>Mhl?zrPT73[$3m_ 4{]h58B/+FmSkV ct7E%dYhnkyB' W삈r5?fmzֱv\E-ji؊Rrݼ?{Μ3Nzt?%E&/O|2vOU.p*zC=I5 Gf%"Ui>3 EF|ވ@Wnʨ& 9ס 5ѠnHk'O ,-VE0-+LACֱ ;U>o_96 2QXDc^r] HTN^v +^(ж]rd飭^G`mG7J寶)9y<ӛxP*!Y]TJ1봤X NkۂJ{6;hFlj{DE,6 բ u8J%Z[S"9ZḦ٘h0|bzlD ,+`6y\M!4[K?hc+]s-iL.`' INK1lXWX6i7),J3 E_7r%=&YFʙ56+jkh䃙>t;$QJa`˵Z#uVn L(7Ί3+hK?/v&%stj-,eKV,q(֐ aY{=^qLjqt`~l V꼼:"RNRBjCϟc܂\e)-7FԹ.tDZ໖ρ4 MKoʫ'(Dx p4w|0N@um'T"GFy&1̐T?2]_9浀Mb7 .X%,`GuM!\޹Q,rE 5Ԃ̰Rq"}H@T0{^αYovLyfc 52^|ԠC{ŧ @3uȒ?FDUi͎s#M![O/*$7cHfnp3:a{C=J.i %+yRL1yst?Zo$Hҍvh?0D&um,Ծ{*'K2 % QD`c#|K:spS^g(q p< w@$ݵoL͜ Mku>(.:2 zE]Vf1[.kyuJ%8[m+p^}T{5&yҙG!b%r >oi~eT SʲGG=?ƍm)F]k7%Njs!'uIR>*VLoi!Qi~J$ קߒ2g }U~ıq.DW/pvb'0toA/3QżD!*'CS>TY?E~8kkјA)ph$-8E=N&Zhs¹bP4@ALl& ķ rej#W.1,(ă t"+d~9#Tܗ "҉;!siL&*2)-J ai ܨ E)?g|Ŭ9LG*ES^PwRXO*%)7F@u,.#QFVUwp8H6Y\j$=A Q3@<܂RMBеgO&{[w}_DEb#9G\vȝ}0IG5+F1D;=ET]J>059G'xz@kZh&!T |zcp-rт2.U]f`]Y*;j7]v\*-ߘ܆;a0Pؙ{G{!tu?]Vxip lq> *ku<+o|gH$c-mV7Ǽ$xa IaQ6ǩaN<-MނXGG]r\x'~uQ9q|'6m+ `W/]Ho]:.^A%%U3-hxh6Kؖ+cx_#Z!41o/c /ǡ9{e53 Am(_\vɇ$|4D9KX0*g, h#f.S_W7v{ĝy\s.ffYR$pXޠq>-͒ =:׌ɷB4_+sױG/T!#$|D 0ϐ 2/-}]Q@8t#JTzU܁DiT,G{ bαP!ƙqPy K,y"(Gb "b:6 CNB.U 8^1;㖃a!͠<fBx:Z&rfN'=\fy LVEE5QQ&Q3=Цs{B,F^nϋuKG4L)}[vV'yE'cǖ0t #Iq;E(/7/! )_&>p4ps CÑ j gWa? '=o*ń Zү(^\%%cEYWlK,ٗ?cyVK7oz7:|z 9Y~q,9V(du$F?ZAa܉ Mez¬yu y%p{@˃ҩY8ޙ1iw|80 !eŦN4# 7"~BL.z %9 ieꪢ8w ST!grw>v>p1BDŽLd%XII"KŌ"=Mhb kWVQAnR#$^x؍PV py:g?b%!1N`aaM UHԂPtC 1Wqa{+ޗH Z4׸ ⌡^LNbvZUqPnSYw[;xŠHeupΑ<;}OM<^"p C<@:RWw& o3~mg&7ΉEA |d10A se]|qsv(*-]ڪO-HaVw{,?ʤ0gXr=x_W<9)TϘ4Em r|_Y^[xYr䆆-S0z)ϊ>{{DtANǧ;WQ&rີ}й&fnuv/ܠ*2/\U\\ Y'a?h A,&pд*tޓyTX! :\\Q-.@Eé;4YR-B WfWpV߇^W?m|LYYw!*LtQ  xhj I=(1XiC\b&"97nxVo|)#b 灋! \C/pǙJ^Uz1矜8@܆F!u<[aM#~cF|wxBsaN?Yq55AHqv-Ui!'7QT>hdh7֊lҍg2[{Z77S2>q!,$dn_Ёg)\_lQlo'UWt-l2a-Q*N̓TKӘMfy{oQHcX )h̽jz(+E}֡74ickzy43͐L9a55/F/l& 'zz8#%T>~f}IH\Q灝k&3_IP<ͤw̚Whkq㉶NBwծt1;!|c kǥͶP"VޚEE9< P6&0^_&ZԠx=`4*%Yd}Z0,n{]XrjA*F k}Jj'/]HRy)W{p2k 4:oc{c"V A=." VP srӌݜࢗ\ $ B(,T5kCMwVpuY_SΠc?K<(šiv z0 JBXmRXZPWaHrӶ _A,J>Yu7h h"Brnf*dE -9i| 8eNAþ3[ӡ^* s\5+B| c0'yǴG8ˣ}W_s.;2` cs8sJXA֝ RcKCp-Br_uȵ|Z>KنF\Q)ΫTE"UbU'+bqt/],>ؕ1B?jA=¿P@>a-Ɨ1JK] vH(FzrHy}E WKctih[D:` @AfAqŠ߄/ܪœ$&1vv5kSri5Dǩ 17nf`>Q1^.6kM:g"r(H`FNyםg"a׎=斸Xk=@< cCVտU r$sHV8?3 X'y.m-+chqԓp̿TĴxqrZuhr\ﵲoL[/Gfd9v jB.VJ惠2}7tLԞρ;-ORUF@M5&3=AHHĨ~ʏcf4p@5W8,MV2UGbj ;=s.ٸ=#|\CպUv5Dp۶ L|}_24d%OcgHF1q,۞T$z9/xp3]hZJe"޾!7YP╎~_9忾oUXwagy]=eH% zX_E6y8sG7( G%7/:I$hB 7hƤHq^}3gj|jz'9!X_<5%}KyC墭oCTcRfW0_XMm֭hE JLO#Yc-I%O^ 8Rze+R%p'xMp\[5F` '*:BٞkL!oWV@H .W`wlKө&eFk\gU4ݖÐ|n_m?Ч"Q>Zrik: hҒPբ(X #<WՙYd<>$;s]esU0'E@S-0s^;[&jS v2gR[~Q>SN=Ada!צN9`ƮB|$_W vddB!}YR>Y&@2IE2ēW9Une FFYc2<.}7E(#怿h5 &>h42w9`!|Y Ϋ,f#H! |bapmt ^|I/H:OJP<:C~ZF Ժ #L{vGMtQFU_e"ٿΈtFo7lz1yMG('_~3y*gwQkE]sinJ`"!{wKq j*3&Q,;6#VgA\^H90-+7Z׾W}*ꢘb|v%l/ c/^4!C7 8w,^Cej=~eYe68_`UrȀC_W=v X:("M<K<ͣSX5=,zKܩfj1~՗rc0Bu$8^<}/Lqjd14D .5aD2IZPַSc} PWj tvzWTp:՝mbqn1m$v~{[E8H:zIQFL BhEjhIBzᡑϔ0:QEB9V'ZrvQmSgg-Txa Ml(Tn"NRѫy I^ʋ1mw|S arsj:7hjwgt[0&ݜ-w%?5:kz|P.0%A)rkؖɞ5yanu(yTV9e#L[8R*PN%DeFI"]}jm1:<0O^cWR e3c7#ESκg4{DӵN.E:.#)zy g1Qr,д\o3{Ba`/HtcCR [LnnDjݬ+UTO ƗƕkpDH=q bW?`=)bsp. <$̴N@hvec_FP.ӻ= `VT\;~fMccS%YTM\{*1 8 q"cAy!i9؍+{]wߒcG> w|Tb:8 - DGuᖾC/u|ㄎΝg:1o% d45& G`%Q$`xHiBvE.Azu{kI7y_JR *|GFXFeLs;[>%&/"Z/;yr g Sٱ8.SQ7=|.iX쮄yp#Ivu{ ,'•?U*UsW,j~ $Ku4L~3ZSGc TnnM oo$(vĤ!Vsw.` *%YG .?O/)Th ~w$Eꮿ8;/*lqLʺo?F7u1jtq\џ ݿv7Ӷ!lF2UO~ABIm H \X=9ɕdV":$ [,wd=2MV >s5 N֯h/{-$#y[C#⾻[srvɦcc :t O۔8y6΅2O~?BMVG#li=IMޔ:E3}A 05;LS)o?@̒+nM^DقϣҦ' \$vdoL%VGGu$t (8PI1΢z5,Pn͸}=|va ؔE\Gگl#UTPkA Z'Z>ܷ}c# 0[ x[yS!#NNc-25Sy=M5YiҝIB&Mgq1kL]@1͟L>&ޕF+My lZ+lb }Hm5G[P Z{맽°SF;%k`ZQ<.;bh!!dW>by: P䩞%?6/g O+/L pR0-zE|e i=*gl;#.7 1~FS4ρ8~lЀS)`1NSiIz#9.G4QԸdJ6Uv,"4Ðx/[xݐL>ѓ3Sq@*}(iZr7_.3.b0bRma9F9`50p ?rIFČY{+(/)R~ -u7DQb&UeIȘ{^ c ae.ALq{Vt,M)&࿵fXAk˲sESA}+ \Q[ؼɎjr%xBY91ng`1 ŊλbBAVrT Bc bBf:kj1PT&KR׹`B"}̣eK6 `qkY3m%QLt!3 !9.I &O͐sʽ8qLsKC(/jƔs Sc[7!30=Ϝ9KjdG )CwJZŕꢋp%V0/w1{׹&> ㎗ŬH@3Nj R+b"XBhS *Lc{"|:FW-@OBW6r C3 -63,[2"m4wd#:4{cmo/{ͻFɾݙ?۹QJ4~#-Pwb@簅dVs'd;/k9v *KU*i`h!: W*N'X~5W[S_E+ [V¹2dgJ E7oe?TZ-v"!ަ\g'6)xF Ty2jX{+jjizdrcۃvQュ# +~3G6DEBtϡ|hセn wuUL4̃Wr]r<Dd6#d48Rvp,{/xOԌNghH`Uy jK$%dGծDڍκWumaqm\p)Q 29K3"=Պ97b3.%&Z-6L ? 0Sm.KOn ,J0J.T+TC0ji Hc:.w[TM c'ӣmrfOk(i!EH3`}/ ΉFfjMW ̼ӻ|pToX-kPRY2.(^?TwIƟX~ fG{/W/.6Y0TRqDp bq_*V䈴@'yZҩbJQָOrHjۗfҁ\669Lثv)qۡa%0ּ"&vQ:s(-6nҙ>6ixL38j{bzVW )pWtW)M?߇ҸROQl~VUbG(\8cs92 <Op.HSdT\3[o^Ol׭S6{=&7CI ,z8?:yM׆㜼|{+@/w;u*Ô?6yDU0뾯 9 Ax.v>&]j %͝>*JZʙ5U8bƤRL`"jУ{8ZLK ˦0 T2F>gQynC+qe냥UvYןf=֣!Qk݀,қ4Z.Rh^nᴩZՈ ⥢c! s\%J8_PYDzBjJ}JH=&15@,܋tQ8B~V72cgYXd9ЪYiSoh\4h  AmywCCP()Y/9'Q$:R /-3Z] CڙTZC&CA5q}_0p$Uhxlfrݒ| vWa6̪a3yXgOLo(p|xo"3oV#u'%xlЁhy[c:Okm=Սv6T^ u%(p\.vL_׵C,w\yL潖jFw!64)oѫؒUCdHID,}vV}2ıvh\G !a{ kIF>[&7fcؙ[D/XH}VEND˻mZ;#8ߥ1XnkުѮE%3j+Q(-Tvk_e&vZWaܹ ?{ԦJ^}$';HD.TD3_|Q:Ԕ ^Me>]. }/jcƗ8 ô6(XH3] (77cNat^}`? }FW960 b꿴ks\z*ԥS3==Zqdu LM. JXuT}Y;]V%IZOU؇Cyc[;@f>c65\;EiuIqy& =TkzЗE7aAf& mpf\ T kc)<̣^*uTX"C|!$,&phW2|бmvR)sZp4| %\J7H@tfF۫IAv "4v702kh 5- G,[k}hxZ'e}A2vpA{?/ɭѵzԍ 四I)ط.^MHNb| 2͟s5i]?<]Sb2k~(f8~rT@oˤFC*~#&H3WߢE%ԡ>|,Ң2&%v5`.50Y9nYۇYǚt56Og >:VrE-WpeKw_DM]&@wL%LRɕ⣺JU;DoeF`:Yjm8D*-;?F>_e/ ijZKJ$3撤OtdI+ Erhfx mxU۠k֟zr(pȄZryCB.a9*'ƼgE\fMㆢ\,,ڂxXTiץ;R ֭R_ AaIyO7wNia] 􇮼/3Xml*60;8AD=k=-8l4ቬ 'j xRI=g!=1pSVH$FQ9ըٺfinoẵ2 HybDUÄl L4FuTkB{paQXql?8zUx h&Rfݧӳc+52QG4~ 9C%Ei#nXU$UZ,+,tox}Av-G~sF_V$Fr_ vPL nUЪOatD~{7ϗZMaJȴ$[-k~P3DZdEu:D~ g3 RAbu''-4F+Dťk)Z{WЭA7p81oȅ]h_8fKے{\`-1 ٵޛy]ˡ Y1+!7_bmVrݎ҈"ڻ*QqpxpC %1]J2%z$2؃vN ivGW⹽D(66Aޮڇ<\K%,V_ X-*F i8X<@hu^،SEJ0rpIB~Ɩc7-) wʬ\.+Ђ&rPy2&uCNH䴪-MI.aYEE*)YNnK:ܱD>9!UO ς+!z*L6Uq^_;ȗc7CDiAHsTؕF)tVWݭ M  *ͭWG^z8IC%d. yVDRK&nƊ"'4"?߈Mm.V 0 QS'w.[!j )!TʪC(f1a2 |U;]Ь㎑""-@\̋x1ZƳJh$3l=Y[%Sdދ3. }u*jS%ډBۓIW{S.#_UoQծƦZ$ >0?E}F%[ .53s e2%zדCSN՚,6[V".̓%X*{uOC`3A(ȌշxYi1|`[n9sEC(HZM t=e0ܿh^GzC1$ U ҲGDb$ !oQO{g1*0Z;O03ŠRw)"Wen\_^%8{Y+j@\tQ)5ա,C;֘Oi&^V(Yx\~ SKKPʓoU#14i9?EE5̀z@qCN߸`JRc.I]a,@c%i5 |L|4NȭY虆C΃1@Ll^5RX Aw,ue DVt*v3?~6xد <{\ɧyR4Ys19Ѥ{HzMXTݾdL؍ T) ]Crg)S6Sq(@yE_(+SmRch2ap㝓moaֿEC8[b Oȥ!&o[4M}H`&?ӈK媱cG-6֏tKE>IHZLHOc!> to v]oLVYV8y&4&e(}7©@e腀†P}`3C~tx<.-)jT/XRK9"(4cls*=/ԧ) =NRM1j8t5~=HB6e'H㧗{VykN0{NU|']$Y  X\]˪d)'gf^Q eu&&2ISx%E0ɾVN*rcYtSu32s>Ѵmk4iHE"'̥ =!ъe]M$px~>R^N^Ѣa-w䊩}D/U'RIAI*Y֬9_l1jviD*GJH6)ybyジ'pk37Ώ兮hjPcYf2DzJΊLA xd>m28sT{Y NN 瘼2w(< |\r o]UDfdv_TF.+rx<oXcq )m125Mn (I%ƐXu7Lk-/\@62N^ޤ؜oŁk»s\gO&z&jh7G{a. L 5fn'P[FO.cvR5B-0hsIl!]:|׹N{>1ẩr qQŞlMVZ+T<쫎od#4֞MZ8K!k6;O:|b).@'} pe@ub  XuI 2-&J\8E$ eZ{p@q޵R]%౪x`8g0jV|cҴYbovOԾ\ [Ol7iiu2Tld .Rt"@w2$?6ЁrxfeLlsp\Th6m{EaO(͐b5-9Ԓ3M37AkfM"B<¬Uh>=gk;~P@d:38sYlE|ۿrfZCX 딮ˁsc;K7--5 TEYP."*ǥ[ͧ@ðKDj@@go՘'⿅zy5h'Wt*)a3 +0|a~/ t ȯ5Ej6 By,zJ${mKѩ%]ۧE_JU#{("| kdIQ?)1$($\p9K"ܓ|]Ɔ:<q9^ ԂuE؃jt9*CNNFoA5h t&6wV汰20B", ^-ƐOpEt4ysOf/k@iU5>(=R=4. i;4 "'29z :"E_a}`6,L#/˺)HC=n#⺖,@aumdçz =@Ǡ*f!޽;t.3* j\3v#} 7ITKYp擕ҿݶTJAҀRw8 >sg40JH!!Q6m wBsxݥlYp|GgW^^ e!A'AHy&1& s>}*hRiB6(oQBbIxI֧LڇE夺O\-IiL ,QEy%8'2q%tN+Ҩ5|Dhn/!uYX&h5}$I\#뙥E?}5uh(d!Xf? A̝@S8&r7uԩz6l^+PgYP]ٕȻLGn5>A}\Q"V&عsmwK̫W0v'`BPIy1Be_@ܯfUD?_`KXV8h;S3"s)WѾQ㭌VuOLsAC'\bϸ8i A }Dc9jq`E*?%ݤaVӉ6ںl͉"dN} g(^u]HHrU.Jvm"n8ߧm m3F+o9Yl4?, Lם~Jkd0-amӠ X;Qk_}U\\ro56a.u0PPLwC8. n%.ʁ n/amR OzbE&R"NyU)(֨ ?0EExV1!f2zQ$"LL!mӄuYmӂuX{ýf`p3kh!/ fG~zE<%BVBTz8 g2X-4еI*ySIK0[ϒ{g}wh1ȺūEAJ;xLyn]I:S.JՈ0\[\ф[ImUB*!Ǘ\xM4 Vr/H2,ϳ/KЋDCې^`/Y@T@8,÷fbgLAf}ew{F8UP(H^-b?^HA|@\ [up%~sG.م<͂ᇎJQ i:YPv԰&Z#Z fh3\NZo!Ig@(Gw:8  JQ?b@I#SܽChɶsm ϡ:=t#'}7 [RfnZwFB"Eoe)^ҖbP5V:@"0WBBb#N`b ~vQ*UzN79#>ifõ)s,N"g9OkUCngCx*&x3t1`؋0cpI)K9)PV!R!OnbovY`֑o_[*]=ŋ5JYûЃ>d;ŋdl/m'W>H[jL끓%h+ ;2$_?px3h0n0J!6ڰB0n a3#k{lIulƯ;Y@?5p>I!94kTПn,~6n,|x x_H Q&hPG3H %-S9hlB}W܌lݰx٪:3XSCN|Pb,]T/?T_JG[s=ՄيjYJlggR%gOԻB ?=í73Ϩ4wP這nFF|=iN6 jL߱ d&/jQ~U(kq-aA@Tteil]N^)`N-_u. =|eX!y-~Ӕǁr}gez ZcN NMn*dLFmh]tSڤ 0%#?Xj6UeZ5;K^zsT% Diw\Qـk{j'P)a/uE9pr-ۨmYй,loE3)7->y;"WOv-~yl7q8Ṋ!ĜZ=V,GBv_Ql7Kđfy}_tڐC0؀vuFu>3Udoa5֙9`m1ǦK E C*BF?fpa>~b>ϛRCCarhT:(ұLa>~-,_S>sqҤ2iEW`[W5n߉i"H/)M״h)$a. MI{O>MV?>Wq?YdN iZdقDcp.v,^7K*;cc,26zk<#B/q)@uCk@4jN1;"lN;l3Bb\P aZvW1KH'm nT8n/.0%(yPLVE 7 X1 Y&;HO}O #b|k6Ϣ|o'#j$lzcsA|B `B,|H^Q *2P.>qa#X<È&p里hZ$[&Z5s%}K%ڦ[|ݔK)q~aU@t3@L& JFTN'(sp<f\Z_:^UyrNpص:E$WoBD T B-wnX}D_# Ǭ$}b<][٬ kLo ;qpJ'e D&<)}ըkdv,vOR- lȕfw{;<۳VD_nqڅ4ɘfA~R Ad &^!h,Scs++gۄE&⧱MeB ][|S?C%PJWBZ2 ' *>^ +1E?:@# G&>/=jKĹk7cWϹf3m%ɣQͫKmiJn\؄4MbԆ MWxBtEP/䟗/#^? Y<RaNۇ%AMN%\NJNQK+f ots~HuPK[r|^vYA.8[yj“7¯;Kz (ʜ2ƶOyVr/<dF &$% IHhݍ1C١Hu^dŇǘء u @o 6ns8 ֘xf zFR+^Ʈ,~nuez+eHM q-I:of~ުF.#jLt0ʥ߶(9_"]UכN-t $9 3 sxfݕk@lhe_K^Iz:;9!?\Nwhɮxft DX wvpmӴ`ڭ1'F2(kcH4f4Xu R"7rRy~>_^<_P]Ejek!PG+V~7fE_ޙa@fQu`=5Ed6z/'"[8 qB.\w%N?^E6V2QJÕ6ƣr+PRzWR…d%xwtE16֫Lū*ɶ^Bq">uh@F=Rë.m-|ޖCЕwNW{TDgB #]0{ mĘ#"(N6fbqo(*TJ'tA0専ͯ[%W"" I /sTPfNƀz{J n}=ԍ? lt P%>7Zocw͟\^ݿqAe5HKgA~o2BR9ԧ,U!`Wi(MhY5u,!ƶ1"9[2ެd!1.v#gWd=[†͕=v>[xKH !M8`hS^JpO)4TdϾdy= &+G! M%k,bQ){ 12 gojܪD*Kz_^Y7蔶"W}hQmJ`\s*)?_9RZO7R$ʕ$9LuB^`1֎0(!mJouZ0ջkJ7e@x3,V g}UbZ~x—[P(q"a9]%jn)0,(.}iЁ}-XTgK9;}:2q {3^xXK(]=R*AxO؄r(~H 5P^<@Ix#k'8k6wzQFuط0T3oh6B%I|++ؠJq&:_2`ȝ8 1W h_a Qy!Z@ߺnVʨL7 d 0AJp}W=m*'WX6_y;MFn V.XA y^!; MP`Eu\纩b}x٬aFj#'Q1y8zh=0ieTb+T;tDy UE4>:-•poUIv%y}ednv,ߗx}i 4INP̼Ԟϴ[Nj CuprL斨Y&&{° Q^oZ`#kێeK$WP@ܯ "OyFI\+}nk$Hfi[IHwL]9h£ /U`r ]^honL6' [ܝ^A $ XcH {QT緐؞Z@DUH8x5ekM0ץ:-Ěf)znx<, H (Eec 9tՙ>bdj [[.qj@~̂VnKX93UJ@{'X.CS&4<#aT2Eݴ4x"7Ϊg!3lz e;l`샲;Ԕ;`1vq1=Иr7?^.lT3&h#^g@~ۙXk&^ ]3nrnIu&ܖa.ĭ#TgB iF$'V .<$CgI8fz[ @$S4iӞ֫~loAcҷ1ބCz&+"Q Y"EuI. G

'<ڑ+dW<,] "z] 0M`{\8*鷶TV% `MsY90iNx|| 'ۮB;&'ES\''KYUY|)la|W婇;y27?$#)dO?p_GZQt#Ji)YF0Tg-`oQ,§O"gPm8L+[Ĺu4eYùXm !腄|n!8Ew ^'No (O'/XŨ/& w;N}oA?ڞRv>iABk۱/g jI @͡aݐCl̀[Fs}"f22Pl̻D(4XFLr-q/.\2Hx}`2W $JNBl^bQC۳0aH ͫ,RW+ֻy Nj wr2r íVeMRlh^L$AO3;M-N L~D1-s Xd(>V U5+L?tRfafŎWAO?Æ:>prPJ)r6qf؝snHПFNC]JktE7ۄˡX;} u).9`i<^{sˡIj0eg^:w+H3^:0JkGp.jSI랭^'Vds?u73-6J=  },yAQۤ#$nyifgB^yHX h,]+-&B(hgnB,VMwyz@{F=:ɿ3Z Ss76T)]ePǘP^IPh&V^3ĽHm \(&FX2sҌs9]bEQ;M# (m?mg: Ѝj̉4𻝩$!nW'>A3`0>^j!0hl݅ΰ>iA9{EuX]ۖ듞D)XE69PPPЧ%{ >PB:#Wr W#͘{%R;.$ H߰Fߞ#Ŧgĩd/lHm'=oAMj!r3$8d1ztpq@z/:kX "D=!J0ctq︤1v4++MsjJW~ok;xUI ". AyO`p[&gaN+m*J'bPekE`wf4~NÝ!kc#Y"Ef.^A'(< O>WN++0_nw&#S)7!Tl:YN@0/u% |<6O؇5fFW1zt~v'饺GU! Cn]s KG0,g C/\ Q4'^P/?~r16ռWldw7[ƌLwX8dv1 8zoxkj[Sxv0lɹwh}M!Q>V ?g;o fr'#Qh"JAI^͠g.S0juXgAd8_iG/&󠩩!,ߋ #-) ו{\ҏ-v\+hE*~/o5`/u0-ln$#U qMQD14pmxit `\{]JT9F-Fb}o᱁t)oVrU{m 2Į{+>De zb 6 >Y+zN'5) hxFh7;9pP+ w:78덄 2Ba| H 닂IkW-:Yt{v-7A 5!*=ͽn@[.>Q ҫ%F˓4GLWGlr;P3W:ZZ^ѥrQH3,hFdbb1y29GEzGڧb b)ԢvG[B5?Eq1>WDki[ /j8xTÇPbq|. ukm:(lwFch^/&I_ !! pJ4 * Ưܝk_lҲ49 5KצuGو9e:wH"TO^-U w)u4ΓhgyyF%if+-T8a2/1i!a'vT) ۙlMU@4rK۔QiA Kn 1(t|"xfV8 PXd Ąɪ8 cXpmq^Qu~ V??FXvZ5_7[m;ճXx떂4/ sknIJ J= ` CvAOv\/h栴 ?C\Y Ռ*`E1_W>O9 L ×ۆK CUN43dӳuCG0@dŕ;X\h>*)̾y6on1@lpm}5/U^::AKhTj( 0 Ny n⎶S;ۻX|;-'IбaW mkQV/rnw= T?u) f@nM( +F: Px? hv C`W[ jЬmEPS=[̳n}J4|ܨ.~#30V!s@poXy Tr7Yt^e9V!G[t wEr䧽)-gD7Ly='s.t;_,42&ڈXa2]]lۧ^u|O4HuAƂr#D1MToGF=Pk}o,FNNTUr,aqXL)&kHJ  Nub.@ `9?\2 GE/niRo Yy5D;n9"Ie% ψd5JuI ˤ( @U ᗒ2#4)ޯCҐ .w!\IK'8 (y W,=ӇyQ qGN<?"#͔Y2Ϗq҃[h՘q7ބ;Ji85Aܨj|x'dL`ThBe!е o]Nglqd8AjKUTI[[T8D:ɤ}54_I; w%}׌:$p/|gL.n9 e(SwXQ>$߁YV, MwE!V̾XDWR"tSEInr,޵{j XGyС;DشH)<! wdh}M6>h]F0)e$U]o]/tr* Mn(\b!$ɲu+Ak ՀHؓ˴Ah)!C{sxzD^G &赭qCԳ#;hpI,i,J,.;lB廁gp,-p{by: mN wq)ELu'>q5~4^|1oP%ƒuS#~陱܅A#0:l6}) DY}ǐPPU!<&wjT|g@d$V`GoLL@)ܥgKɥAv:oB)l=t"Ƀv ;1$fN݊2] t(Ζa6pΫCa dDL[4ˉt+`'!l;  5;(+> *O# E[PIs]P@*}̡.7 `!u|RBp~1-Q fmM?SzhU9J#,>fR[7t%6c %QVuZJ?$Ip }!o1A0[^*p] ?>6Ep'sP,p'䓛V$E2LPw3;5/ m+AI;7 uN l:7+>Cz;/]Ȉqpw"z͉}𜠾$1^-"+߹Yf)JeMS]Mӆh "Vܐ}7iA&Wr@]Byb1Ɉ65l2{/4A3'klMS2/æ?`Hc5HCeX TPg'A4#\T7NNҔ.% }_ -8L `7OWnG {=hf}cz˔~*eoY䃵=#bЦX)v7h)3 4d9k -QW3 *pH>R-JK +roQe=buOeaB78A3 ހP\Fu3f'k-k?Z__[)>K?*c5¡5E"J &雇b@ڄdȨ[/ Kea BT@-R++Ta+0ֵVctzY[j!#M4Pd h-cgٔB !̘H@?T_꩏Aunٓ=^{mhDf|IZWe\-;*8 \c`DPXw:xS1ݗ"lNEor6b{8M8xWGp[Kj$*_V:%N~&bzxsZmlV6 N/o"tԩ @Ss\.۹IXVEE)sNYi v6CZSJ^3̐4>՚O-v8.JzhMᑕº۱m8v6ٮ%|mv|UFz"91GWbW t0DvEU\{mb5!3l8UXea*AyzP*|Lg'4-5UWnOtKvº%HTsڌTaa]D[0Ӫ@̯J9,&wtҘ>J1|Ճ`iM$8izbzP {[0g.ieOG#{n66&5O;Ň@6-W\,YU=ռnժ1B:TN϶3U'0CqIkM'% i8!eb ԙ+($L}T #%}fzz񯈒n qslSVpwkˁ1R o!Р]\X{[23źlK v(0C>ZXp܅V\`Bkc<9'[x~*5{ȧOGnrѩda dF\̳eĕF4˶ݐ5X-PrR %x=CQoWi^܆#0l;~xmU靱7,̽|E+h\Ep BYd^:}vy{2$P) ۦ63#\"(1l _\ljm>ff];۪"9GA^%қK[4OoM^ϥXYيCb63Hq ɸfŧZ^1)Ce5ku~Ku߲z0ut:g_:F={WG))O_yyANr wq@cq1GM!֧Ƨ#+];šK#}O{k1Uà1}E97g:2Al!M9P\b5.IЄnD\F 2 ,ž]Z@T~}'Ѡ!-M>jre b1WHʓ 4Ru(D!F,̝$*~UvH*P~Bʺa2katd(΂4w+>O'vR\}.HUG_ cxlņ֖Zm4 Ş:%KM.@gj$p/z:ApO$ĊZwcEEJo^?k R'_(]CRk#g$2NAճR3 dÎ0܁sy /kScN| 'w6tz.D{68kW܆8l1fۭGl++ydiVM^> +btӑ-g4i[ӎcE]cOPm+j簖Vm9NUe2_DzH,MlBh KN i*K,f:1m'`xڳ$g 7 b_^w@La@g*A vw*_̄@&i=?؞i'9vrڶ:ܭRgsu1fy7Ko|0Kt/еrfߤ ;, j2ϥ ֡*)Թn?8$ی~!#T, `XNWۼB,p8:_ѵ_H.\#:eiq*{au[+y)[@> !,}h(8vLe 5e|@B&h߲ /khbp/@t~<6dյptYd즑}W( ayuEä9GS}h_:+颵p5oR2 DC u/)6f#c%9c aQk@/f)Ь**=^7i[@L ݈_=dL"lA/< ^@&;Cp.X:lȲG|&++;\0۩s?R4~u<yIҹުѠNf%Ly>8 D@ܷi{  >؊mT EP$>Vn^CSy@_ V1:g; #^rqG_N$vVOL_ǝE>0o__^'4#Q־->$-eyȯ ~Q}Aׂ݊`F 1GC* ((BC?}|CbRޮCxuhixx5ٵЫ#JIcN\FW!li7d"o#HmǾB+lF>`:lߣje 򏷑-pITd lѼ3Yن<ûRr3E_, `i0)w=ãK`@(`tN"D Dic K ;KؿRAD;ƼꉪsuGn +-;W;puӶl1]Ih_3" H Mp h+NɓR(Ee[*Ȯ3+D :Jm̥\&%u!ᆔ*&tӅ-nO̦ nМ6A3. "/,*6&qE&4ӹW'UMaj^9Yӂ'U:6揁 =9RrjOG''3ި|_&Uee$ V\#thǿ >fdq>gpս2S,.kQŚ=N$-mMX{ Bn*=^s@6jF(Jx;yV2W13mJ*FӒCP> Gw 뻷LAa7 Q/Q||+CsFq$\R/f|!2HH*(#3p:RIXi~L“X sQ*{ԭa8B\U0.e"Iy(q=c1NE2sq|Fȓ{n=hҴxۺ5JcPV#Lt}q>le#]+H茕Z(ݦz KWLY1zPR>v^o$szD֛ P LX%04Tnhkfq}fPfƵVc?2QOcZ@5nHQv6-%  fpO.>1LsP [8BБVעV;^b(a3J>n*J njW[A iya?7s2_i+oǘ~z.| ¼dȤ(UK 6 y/ O&Pxs_஬hyȐ˖Ő |UBL؂[0:ml= AJͳF;fFJAg7Jr7-|k͚T2Xvxi?#ہf!q!,&^:"[GnY-eGYϤZCgmlAŸu7 &&XC.όEql6f".{foSSбXʪw}k{D *^۸􌫎=E i=XbŤSYngڰ,F'h-1c9Ep|mE.td=M/-SE rJUea9OE GVbgfз'l%$pE׷aAx%U/iM, CG؅V5 )),Z}!vB uxƪSn 5TʢdiX&CMf[)Ԍp0&|鷯NLڽX]%<#Zܘ)U{ J8IC1~ B"Z[@l7tPrj:ڣيI9;E$z]Z^xÉRu<ߺ6ξajKQ` XhLy$dP9n9"ORM0\< , {PGE fZN~8d8g!Kdglj>EQ U0\͋R[[9 ŏ:f>5?zL/K't^YSl!1%LjfXM}'v\LE1ocn5c:dC>wAYԄjGM_9e(KWs[Dw؁գ?> 'wլ;n7BZh313$7p!-'beC]?jFlF $&`SgğW%%z5lہ&5:R$5R695QxT7,涥}ڥWޥA/qwVcL+{O*"x[UMTp01ANip?vҜ Ex}]8PlOᆎ0!sˉ3]L⬰Кɟc %5'M5@vBK'h~]n'Ɂr/@mpIH.hоFԠ==+3uG`n}>4?0HYI en'+ZU%؈$(NJF9VH8x^1Nb:8]ELDeBUL@mb@ʆ{u} ?A*t.[3WĉRVT3{fp.%-EQ˄nf :B7"@72A n;|/f_u! {8kҮVC*Sj*ib `3֞P'bΣqYɵ ȌRHb[u6HN͟ (@y 1j+`P5E=|:4{wlMP˽V4y@|" 3 O}ZwF7Y.>wk߷7Jʅ@wIJ^׽C /0I'j5+(6Xѭj;'Ly&CLjxv稿<'6L kRw].ln4dVC O<}\hgc8Hs7}jYL?! .WeҐMDARvB9+؉s?f:%Lj-g]{-HUT9&Ro_Ҋeg++ѿF_ϲ$ ? _c\j({_lѳ$3c 5 p* 6'>j)SC &X~ t>=n @;ډ-BRk i5sW1 1f}⓿ɾwOx\L+pT2Rjta k?Y -j q]_^ u7$K}ϯ#Wq]Ѩ.0/=b ّndpG`<|ƃRVEUAg9N@L^U<In)q*hߤ#wV1YsN4l(dH_/.M~0Udpڨ6ݟHLZQ2R0 kC1Ї}M[:*ͬ=ׯ5^- @R~Q.} KlI&nE`9؎EFM-3YcA (TYꢚʌѰroplNkK<SL#T-K$j;/~i]/FgN+Cp#zUy,F۱W ==IN6. TIAJÆ;|kAʋn}$„X-YkIr)N^I&? P/Y{fgx\E -2 Д1'tH H@{z4kA.R@0o~Bs")G@VDlGlw-w|v7$K5:pB]zՄ 1Y v.C}Z XVa𣏕^Dj<(׼wi $y>EV"rwy5}qD9) `Rh{]~ɂjcaTPРߟi@sKgdŔc6q3lpIie5"2˸`1v i"$J%tV7Sw*m C޴͌*L~a m5k{ؑaDS9&S$ҬZrَs k[?"=fL;؂!نrpwԢY M8d~ݼ!AB+@E@IKoqDH5nV&}Zq{z!Qj&TB<0txCoo/j։PA9)Ffn#~tyJ9+$t8V u5pwd|ɜ qaЈ)C@\ʅ ^4ژ8y2(Xj8plT3ڂ\.`mM4vD8qw2ȋfxHi*rm9qX ƍz/[(Yn*"̂OD #Шo ˫S@4xd]aɊwxv\ >PJ'k'@gH"X\W⏕[KA[ <=KЭG-H{S 3ꈞN}.;~њUbX0F4 l!Z*k;Vo!FNnhWRajAp7q%9q\E)<+GД\?wu$W: /`GGXQ+=zC;P66lėJʮjDq*ݪ@Xﻎ&}Kb-&t 蛚 Ѓ@?3 JpqKÄHV1fCrFZk4 kNc&Ld֖W B&7>Wޅ ~y6vD*[sK^jKvLd3?-C_q^¨OB& ,/}f{%92 RpvYMtB9;p$RJjz,L~Sz7Xˆ;v0*26,DñN9j>^_I ?f.ӨlpQgu7Mh_QKه2Ui5m9UIL: ҨjMwJl$cpAny t~)yL%)qaQEP7_?p➒~[clγ'6Klk+5>tG :UK ISuYGk@9b}xa[o6zD9V+*lsۄas}, r~ZF Ǧ8s"X( 0)?Vrx r ԧ7< SX15fC*mӨ;58CNB7:D^|k2# 2ӫQ\okA; 71$Ĭ83w9lUe>-%0vPLcxiE(]K _7,=fH7D[Ff%$RVOQk;WYor{&UU٬uZYؒ];8voC΃#.*nF(+UX[=k-]2n9^j_]7];j$jWŒ#Y#Utn,> jQRHAКkPm1%6d-n'qÑ]7l{8=1L+})|Nf7+k~x[,gR Glu.6$yN? '4KJ\M[\C0P y;ֳ&>3BaJd~GQ"(m >s|lC,J/XFX;c)V{`j@p|ZCkqX`rs9-(\ɝ4(1{_f*J?fƸ2O1,Y؟ "(Re*-frm~T+EA|J9cb>oPFH}wD3:|D:>]iZ gApHҴy'$J +Z_;HB3#=Yݐd?=Qwe/vHIfJp[,RcBE*1*5 U4.n#`|:&vg&[3:8R*c}ㅠ  'e]/x) fZ>M(Qäj|lO#IZzJ{7#CȘb>jDRcɿ pZFdatp(c`ꁦ?Q6Sy윅cPSW?W @p1 3F?1%h@Q.6IK?+^r;|cRS!B#~ˠI KRL^A'P#(N\КCS\C.:#嵮į !H i61a=3[*ť00|i9hd4`j % uH/9^:ɐJ3+o@Opdy6DھрK;^U25/o6[UAcY|Lu-;qiU([KY6/g[& oEV% sv/>"gWlm#3mD/Nxf (OGpP>3yed|FXC&tܒ02[Po 9?)bN  $ଫQ|]6>/*&!ċ,T}4Xkb%Zp'~ {A%mVl&k՗,h*j σ$ٹs4C!V<@PaIlp{^ U2|-&ȋ O3lmܟ)RZ+km/;'9Ed([%+ƂkW{^$п;"B;5 쌈F/k]ޔL,ޞr$e5Oeaȳ)L)K^FNhs yUr' <@~:ž !? 3 |JEFs}u11r Wdc8J0e2}!PL7D*:_)_uUgkpGq ( ˪ :{dwt=ۯJ3B`h1 d77(|KieQ:C#}"m[D@l$Ǩ_3RH¤jj 92L.. JӈE|pKehuXWH#H)]`2vGDιk5Xo\c/EǦ{޸! FCfJ(q/c._o(ΚƇ7K4ۮy0^j1k󳭙Ϲ[+2i)v!j (Crz3dl);WҸc(f_Pƞt+aUMR,dڌi.aW- ω78Lk7]xl*E˄IU{&*l朿۵>kV~swq{j\ XA<IzJ[[=;x"3N+i@G'O[2@" `v[jV a",nf5-"F3G9nؒᷫz  Cz=/&Xe3EDo5%_\PZ7+˿E]3Oüj!Սg3) ʡg(8-^M .lL_V -,tȈ e4܉ޯ-7hF@uh r{~C֌KCKM[Fc$nPx17OXBjE I 1عm;f>,w LW JMˑZ!/Ya5.] sET$1Kc5#!CZe2LiR<N;R]zGF[ _g##i-VNl^%q[UH~o\UG1&RA "nP4GMf?M(6>S+NFn\ .,ёyHuF\Ix/zsx9|Cۗ Qz1nG:?L|O>"I? PɣnLo U_DyMNOr)U4yHt[ۿH6)UÇI:.%z[띗'b[42Qłz'R>~Apȣ5~u=:DY|ZلԚloro4#.d2ɷGkL4X$ ĕv@ʩAXQgV >y4ˣ;`NAID O jcb={ nU98QK uyi0ZWw]V -%V?mVP;g(N ȣi} Vr$yUdc߇sdru G!{]D&yXߕ9߉>\*cʄܛt Eͽog6ͮ˸*kXh^q3+9Oʓ1nIP ,ɞʹy֧zm)\R#Um ][j i9u[P5)MMlnde4 /A"4=o)a}ŕ˕GEw&w['4yvR_W;=(^vcAmqv[fBɉ|墩F98phf*/eП,O" QoE x4/݁Iehsu9)#Pv<%|9Θqj`8; dtA-\3389igqน=ruP~Ph8E*:>ݨo%̓,8KrJU(o"Pg 肊y'^ԒKhQ7`SŔ/%Q;%θo*"1qodmj~GqZ\)\ˌǼ+0_L+9XC^%eΏF T .N3 e`'KuMf*hĦi&5Heê*򪶫UlBJ&TH)@X0yy}ˋp F d-.cnD |Y)M0UD$%sm̲?( PqgKBOpa7CG1)ÏI)N&.X.끴zc3 Sbz:IArҫw ټVL*FϷs>[%'x`nQ>JՔbU 7܄8Z!iz̴ʎ9w..}_)΃ *iFa3@/Cd\xLCY'`<7bsHaPu.\ SG=\$ZIGqxݼ3وFs۝@/onjb-< ƿxlpܶh?Qyeٰi)}QjNG#Ys8k=bE;A2hdfTj+{V^FtEq6xqэ;_ 1|z޾'Y]U=Ľ઴1-|8bc/Df{ 0_ﰼL T2,lQ;Q'n`S=0DPVWvϥ1~vaFGPU ۥRymtƚth'NbCG>kϲHXc^g40?v<[s[ ʛ !6^ß_L<:q{Հ]X I el>ͅlHFrC" jGtO'ٸ:gx݇5VZ`3x&t&J/N}YiM6/b݈6t +S>$O7 np`QoXҙqlȏEC”F?JR]fsLVFqc 9J_Ԗ; ,[xl~xjm֠ɂVmnvк,/ {ItJAu: L>4 ߌ[+  8`9(9`,ZJ#k|Ug! dԿ4~_\3&V;Y8)Bq#)_>W;An(cB)Wf7}&)ihߙ7;sxA97p )TT9.:\H!\^fʅ|hDY8=K:(: k'QEVSkQ+XU&tLtn^,1l~+_X%{1$#"v@v MkJ߆P'RI-auh*Hr=tN`@vn) TuDЦd{mM{@6,7$3*wf]X-A&jB]qJ$1Az 5H{X4_FĔRb4u8; wX9$`0zDT6/ͻ鳭%#5vCw<=:kn{¦qqT*B#Kм{c^QVY3&j7wrUzglOi45, kmhl3 Zڧý냦{foyWG#&PsXKE.̪9Sh4Q"cgWũ0E/swA5BL=NrN?L<5#!IBŌlkZ`gĮ[DG֪ȹnz xτ+OSHoKրPm/ A/e b$T` 4KD tbZ-]AђaJNސ_Ї)7ޣ>z2`LkpMne;.W` 7kGs4!mh0$=PHiAPbbR(zjf*~6ْ:һt3J(vA-<Hk%G%x [>bJ# !$E ,5Dc@0@s.@qb|׮E1vbL*ܿjŢTP Y( 3=@n4Cqq˴|*8a{^ESō'}(M1D"3xksD&3I{D$bu,wK$)UY%J|$FR&r7}:Ba˃nT6]X`i'[5s9 Q[<ΰyNj?Okr\y&1TJMdqk(Sdiw7HYJֳ#!HߍE2&sr=>yud U^1򘤤't r}y%lƂڭYy,&AO;]|Oץ.t?]bñDTI6D_B\j{cIliS=j?ǽgaYrM|[ r-~ʰKC+T|BƼ1迈Өl琟x}fa=ɘXºW *yԵRCD:M^n,U'Rsc qH:vI10s9;Wٯ6D0ҿݖ"mKa.Jl@Q6;R5 h5 =KeTy-#^NA s3;$pڔFxڧd{lRK5rZ8A~,< uQ&N鿅H&oeXI)(%#ks:sݕZfWWy^/}q}رĠzH'[ P \tp KivЈC(J&NCzݬq-/2bYsr+9{UVpjB1ο\ƊlJrLڸ] f sv]\uyFW)^Las{L xAs\e@20H|& I eBÎx)K4ѭQ8$UwSY|^ۄB>WUҝwPcZ/CW1;MĄ0GkUcIT\V'z&T:QZ'8sj~M%}k#>+">!ƚ)çʈkFa,:엑LJN/)V7t9 zߑY*ss7-F2R=u;4*Z2 T$eG>?[l"s %RKy1Toܟ^e߲*v> o~bxwAȝ~=ѡ&\ JJ{6n1 )ܾ1DpMǾ"nT@gL$. -p+[-%:#|Lހh`.sP ,E*Pi"(1=^!?=E ڬ,(;};fֺs-Y[JdgP0t {Y$\8r@@]9dn ,5񔖰H@$Ş =Z~sjvSri`ry1vj 2y!?O5v;S|FnBx>~65w)alZuq> !Q6?+/M+I1:ƺƌ.jEDeT<*6ri٬?6ΎPyi_RD _.yC8,p0Ll)|(Qδ<7BDZl}G.n3]䆨;Q19fGW˕'כ,:]G0Уw7J6Y:6C2v_9<o4%p7Zx6z>:܎{G:M VLq cp|uRL$7-Э$6" 㳓D5>dԷ$`i6]_Jn@WoMpדN, poXkHD i)@oW7.)V%u#}49e A,A\ӋTK.7WY |&B$ĴF+F3e4Tq[ X5K@_0 /xD+{g:`Qgq #jFȞt7gSQk<%Pqrbswh݊쑵ұޛzAe.s4Ї#XZi_L.9#̟3c8XҀxf3_J}E@#+3H(>̐PJWɏ8+({ʪ˪,fm_4Iw6. - Z BHn瑺.Z;kذ3G*ᘥ7%t<O(L|Co m2PZ(G2tJh,?ij)zFt#G*I^;RHIj!.i$d^a"62S@{4h=6y $b;Mn%JR:woHd< SٍV^%q&kXc)G L4**MI OzϿ"$b37^…X~7+!ŋF/l5iD}`S-.8gK}'ކgfR+M{"Q+R*u;y OE2 WEދ1 }ƙa9:qsEXîBlUQxH<0ݺ7I8h4XJ:^HR!,5sys8w#ͤEKl]l_,κY*3D86YR+]\^o l8KCsh2Eow#5btu<ВLN'! *b)'*CUZ77Ih`Ѐ "~$<:.:?b%tjbC +dz@1̊A fW*5mL:qPP(% A|h,\#4g]UD3Nr6g֐ݠL-9/`چ3r!ˠ$/0?Rkb W!4gkKz̤}R8ffNwSi}׊ lQ F%~5<6% u KځN8J, .A(r|O1 3h͝+d_xlSo[ cK? u֑ lxe LF L.}h@? ËnEOPK|cX|NRAp|f-8 ?jK2'5D ^;aeX(O f t PUjZgy %JnDp $ 3 B]IG-jh"'O7YD,\:t6^- F]\HAFsn/#h>-lJa9U'9~!qViܥö] ઙ"F_5VSň>`OMaGJd9_{mbl%OE6MnN¤T*IEvgvqTYJTEzjw7hWJuGMEHi1> +vT4$Tr;l<\Dsl]#tjH=xO۴{]> 6mi+8&7-9pai'*,Vj{:2hr/t7/=UOUMވLg59|ܿTNjaJ>҈#gI |w0$ ?~o'qR[, |Qiz&u&+lR}OXLnSԔUjڒvEvӟ %Ֆ[ˮR6{D؋foK?%n(Jާ55=|We\:Ŏ+)W!j!0VFmLSˡ4۸֔D##6(4. qX/ݱۀBoԎ<2 e J @˳e+deܯr1̩ZxV@g"X]m / )ULaOo?AlsQ5 Kx!5Q9K5xgmݣtJzZULfzs*;5^WA e_ٚs *JtlIφhWu#<0VfF[K"^p%W%C-=/=Uz} %=ci*:Oð-m!4!OE`P#J͈QCɚār=FJHrg:GVjͭ`d+ﮠ|ȢBn~Xߪ8{?&Si?TOHm3Ke遈gsã5[D.Oę>d o@jHHl,s&|~-,kMOmM+z£=Qd'zΦ1(S咿|ssHƎS݋ݚUYlWeB5/N/.><ɪx+hiibf.c`dB|0 si.K\嵻{Aw~]vA.-mk7w=uMӻ8Ľr6phar_æxCEj^^[eaFRڢt i^U^m'P%DWetȲ[\AvirSJG^*}?mæмć;f}a4BЪ7-05lGlZdj"`sp=gNT+M]Ll3Psx?M۪{bB2[b9 "L8gLl-4$ A=iO163CH?TMUõhU4e*4N}NN/}.˛" VVH!Tzq|SZڐ 1E[JR'hCNYӋٹ`T:R9E)'>N02x h s]LI}yO^4^"سgTJ..9 ~w$#b415qy;bPvP`|=:<7YXj>=h aPvĊĿuWϹʱk>ag5(t%h7A)Im&cV .N =юndNpE6{._"/Qw}d+ڔ@xH2mS*)`,nsog!ѭU9CR| .#tcufASy:DFfr4'(C7K)ȩ#z$ӦXu^p4`*J{~\idp´fgeUdr![ո9.v^ $Bp1aT,K5ɦg$ëFˊ߿Jou ( P|,&Z7]Mg+ExaBc𛋨EiG+^$DUrL\:I Pz+HR垞K'o3~31ɝcMOUih4@UT3pu,0֒tVyuxm;?B|?E~/VF,Uқ۫RJޏ%Y:,W]%pTi$ L| i L X Q/u W zչ>E*xzޞ^ݛQ6튧e"1qP l ac 6ؾ"0m:n/Ϳ >=ռ {Jvj[A[hf3~d'J`'6~29g8"0 ]$$FGx-{dR=!M_#2 < } Ufjj[:گnH2`ЉBtq rOBHNo{Z*c^\MDGȯ]bzol{ús DNn}C|OCn%c,In:#]!ؿѹZzw[w2Ǫ)pKp`vXby*+'~6@=vn,^y$}7A.70w^<렕UHh._ZExֻ_lk{-UإԽ1XzчR);=?4}w"'8ɻO6.׷lWosx֗`t悹] ^PN`e`Y`k}g[L/3b{.\A,,^_4|U2flO-+2ߐ?VuJhI& #,@g&Vʹ^xQW E \XϚ4v&}H_O3k1z:CfU'v5(V+ڔi(a9}11³su\,Kf+/{٥y;QZ)>IKv+"z/ɂ/+nE g'<9Üu3~y6hW H Sȣg(xNZO'8ꉠ9?'6)muDigC@hYO '2WQ@yFlhLב#ZmooDj'QaNc#xazǚ \Rk/qX2m+n#5\w'sxdDJoK#1NJOɻ5Mp6ZVzkwzogVm c>AORX lfhd{iR7ˉ|,V:y~ 儵MG']*x.QY?5X 7d~_`vpCI]s rckiP^U;6)ZnV/.xk8R1B<АMKq0`Ά(S9nmG]^ 6Jh{BkEQ^VA}ؕϽ;|P\Q Ur"$U7MJ7[ v]!oU!Y @R tpk\=9QߨfV{:M_'iRxLJ Rj@Ɉtvͥ_O`4C0ª(V=nb!3RN5OT`)<8Ν73}ߧ-8Jaxgawe,9S:4_hwN5^`{( <2F3ѷM!geb~ud}'?5Je1MsRD{xчbO+ON{+©jYcS-O,ZQrN-$k毼2䈜OwAOk8dOS%3Crpx>bԴ ,)8uJx;0C'L k[N@j[+kٸf#8g~,(Jejue /uVpDTJvqFrg! 7-h N.a8ړYVN7p R|Q%tWVT#er=T=8^%Ӝ:*\ sMN|2j{#xӷx?V(-=LŮL'Vә*sؿ6*O:W rI)/.972?Ndɷ zeBBgOzR4o뮓nfhysh}1B[S/;ފ:+APgB,:}E/x-ʧ(%|De]z fЉ$_6}{ R;y+[f5OhYA~;߼PGċc~^ wXNfSD 0r+HJgZ}ϕ)?)X1N7Xytle6\lN[[ FS̪%eRx‡FpJ&do[^R^;!ت$ \>(~W퍧` O*X]U2\BSZ>s n\Z>Vc)i#NۈF#ϩ PxCm8k^CuYHl$Cv.i9cd^~^҃^ao,~<#eZ;%5%r Qgԙ?6qd;>đjDb~!*5 mq^^٪z,6zӤE"3QUNo13Z`0r$7eҟ{MP7")O+MUwQ[mgX+!$`.oTiX"fZ؊sڦtdL4މv*Ɉ*?zy峖!|[H+D5}'(XLʘ)pCh_O6?U/fCCQ_!!edk+LE}aXzD"+؄z.!YsIƄ CRL "GQOYUU3 :YLvPM=$`ISfmc!hre}k!(=j킯 2-ԈLWG+qR|!K/?9cRd;ȯ{4a7~m.*۞W"ﮟy[t8>Aj?ZBmZ /QczG ko40,/ 9fٸ~N"RBbS7N ex.T󝐲 2PmxsU ;۾uO(i\B_|iNCΡR4F"7[ѵ f9@㺱m!bnkgєֶD+્Z 7 |b?1 *TnʂB ޸)5+Llr 0"?S;1]dfm٫m@wGb]䛘0d+FI3csAB[zuai|:jѷ~cO mo= aelyT$U섹xSE%N j(wr>kygg kGi(\$c8KQ˻ze̬;5ya+WL.23uڈo_O[U'߷H/[-( F3n[+Vcp 3-m>It)X ZD 0ÍV՟H`Ln=4Vֱj@D,.J@4Ʒ b,5'R)xA{yy Xi i(?IҥznFĒ滈ȓ+%P&ʨќe3n\*GreS;a,_LOSQd7 z4'UBtMKೞ6F XEL؇*(h:0liRG<Iޝv=ԅ[:B?_q,zN",~k{?ߋq#k=O."v֥d}ʬ:E,ZU%"nɔ@wQr CӅZZgmD\7M$_2] lSp2yG<"X$V-r;6?$\$]3nfw”: ^(&=vOOT?t c )Ə* 疱= Lo`u0UoAN QNKF<ر>2*ԋIXv6h8ƥa:ED#b/J8fqfzXޙp#Ђ+W]M H/z >;=%?ƃ)'̦2@Ί:YO0{~YPo"O2 Uq}IJEq.t\C7I xE7lesiD.]r]H%&R?Zd!^o!Aq@!1WH_2m nD;۲{nY<삛;`P,I&21s`"s7F 3PEn)Q/~ړ#Ҩ-~\76`W.Y{2_?:^ZE>0ܭAog7{VXL 9vC jim59/ETV ;y~]e#dߌ.ȡI5pc_c OGՑg|0RgY$2UxTywۏnM35_ǦMPc&'TW[>֭%#,Nл. ff|ìC9g;0Ʀ/#:ٲSOQXe/o>wQ-S#B8ZP:oХPNYMR \gŬ~- FaMǸp.JܛtdnJ)bDѓdhbSc惣|E8  y v2;G#{Rξe~;}sG-<2)   BtJ_T[EMqy#u/ &7e3uDv향BR$!3VdC`(q?9(|80G3*9zt[C f0qEM@9bn 9bีy\Y%MJ{$ޯJC 9RqhEŠIyL&R>M^~5ì3 "8GMR<"ށx5y|\Бd|6:#_i}΋Y>-TۼXணKjXhC!SJ_@ݜPOmv5b.^it6nMӎDvkT-84A46e&;P*)[Xf4QKe&„hrV:*ͅMD l4% 5H:X3DZZzȅ7 +D&vdBK'4T'5H9 ʵbgIrCLDe dsIλL[l?3r*&/6RFK' 3ucG*FI$),"FGzfr- |gw\~ zmD`:2:o Z&PmTe:n^80wUA$5xe$7vYo@)ȪUZSyeL.|.2VfOyەR7,$!<Vr/"~bkv6y (DGFqp*D~θL*yhT^S)n"1U| qhi0 * ¤k;9l; Mn'ItJlVJ@Dbh ^ S^;)))9xlFĕ8H䣮B4(@aa_f Ϟ@y!dm$Sax { 7J $Jny( n!W, ɽp (M"vE邰m!PeA"=V{m2>s0V5n-E4@+j2.`Woj-?KF"u'{O0d>0.oin]_Ur&iP'pZXa]PֺzzcB[L)Ok)J\Bj, wԏt\v9ޛ6R/}bq-+tl+iD4s*Qtyy0ЅCa ]5+QĆ!!p~( Ōnվd/.i=1\])e49`U|A[:URYֿ~h;(R s$ƠY+fVyr`%EVux|"f>W d | +l B#Z2Z8ϰ=VWM! ЍPP"y3x߆ID j>ίp*-HwLXt^g+bӮu㺈ꃹB- ^T+q14I}嗧`6?x Xƨ͎& KS4!f]5 'i@mtZh (+]yh%'݊?\t=7*+t F+;es׌]%7 YBRm_p5hB]M ɋјA\1i5aɘ)Q)jtF?e2\oh?HTD VJյ9>l!;oF'P~ʚJH@qt4RPk'F,UD0u;$cܭ;dH!gN۵.{+u`\9ycyE '# 'K&hW6"zQ8 \5z4 $!/6U=2_8B=J#@ rH}tcMn5Ep^_VsYoäiY`KkvTn4,"ٜ>kڔ`|}/{P ]3Պ Y6Oޅi7;cg.I_4iUT ytR#X3ky"В9:k>iH1྄fqey䙧 G#`Uϙv0H*U Ǒ.%ZS6 '0_ RhlWn.q8ź\P@BCݔHѴ|n;QVT윗ZgMZ4BkѨ=,I@Loͧ)}Q`?K|_h?Eʕ ,~.knsikaA!cȳ.fU ִFa;eAk]zeZj.Ai(vqfV@$ Q~mFgidm2<ڿ1p+D;D ~{Y}@u SUob|vq6֝4S߸y ~ k11O%ogJU_q+]zfc+*}=JB!kU^jGdtia)!'/3C\/ Zy\ 0!\M;“ ,{w5Tsdf4?"ź7o½~/Ge=30ce~p}bag4=B:2a4{!H_m+tsN70$[DY G ) D:J5@+]"@rȜ gJ/:82Ι1 g.WVϣpb3"*KρD2:ūKj~rzG🟿0Xo\hsdΐVd/A~F>Z>kxsJY:25lI6M z|CCT)F{Q'aH29}rqBޟ U+:&`q`r?㌞1Zߋ&0k6:؛QAJ=IhbןL?'СhkuxqWRuhEW?jX |4v:S 1P~n5J! }>P]P0C09!unC@E寲ng59H v޻;R N= ztQ9sIQ "DuQFF)ZT|,¬w|2JqQpP cb3H$ RoF[%WK,$-UXkЈچX?ìϧL@s+5RliG dFUZO'-E14ᶽ'lq!  Hz$2t{_A$<m[x:]rP!}=,T'4,sThޤ/H i"i'!(4)?g\✞ݶګs0jRInpZE }󌱔 זZ= `|BΈ6AGr8.fp{,qq3QWeVaUW:$7,+¢pܲS_OʧͧLDhMX ktIՆξ9Ҽ*^a klomC=(n +j^5[#ۜCҍ I b ͆$)u#zGpꭜa߷%v2/JKe,i@91}]$-}M]Ǵv*ҀjP-2c8=e0Bd%.5 _N}TWdh>:c<P}Zei'REx@^29Tr=/@E]Pw.W)&Ffߏt_x.XalUtO22ma!E7G>'[؊:f!vDj| ;47foG+('2zNn΄vgN꩎1Ig"w:fB*Q4;nE? -H8⓱a4v[u=˕U !,2 @*Y*k6H)mQe{Pd$z%:DcYf_AOȌREs;$$^HlB]nͫ­@_1RذϼǧuՅ }ﻱ,ws0MWz9>~M"z1J*;`R@69KAHQNR|YJI=s4 = je.?V |A@~f;s~L0I*-HsY.8Jlמ܇Qh 8#=4_Q:e_ pEMZē]ۙf9Pa? TJ۞@=Dh>Nۥg!D<C85xȟ,QˍUb+,՗Ysp,gn!&Kr`YȘh*֭ - 9hA$\lV>Լt,ItBib1[I_ga#OQZKfDž]?N߿3Q9(lJ ʯ@)>U mvR#THdlh8N?9A$0ПŊZ}*3ptsj64n/Ig17>^-VYXJ"l$];9h}a,i~%|K]ٿ31Ve` ,+a9Z_{ɼtF Yʚ!RiF@M0~4dCcDP/uWDpO(l+ o#7rTIT 3h# 9Csؚc9#aqϓus_GZ Q%s&Z}W\#*>XO`OBw| ZQR@imjW-5|w\*ʰ1*ZWtz0 42 e(E)hIldH[JW/Za'.2[gteϦF ~[|.Q:)?2 KQ81N`d5I=}4~*{meS1ƈ uV9rIW2y0FȧQ A]w(60_IQyЋM C;_>DD1Y9֟9Ƃ5(YM?)S`Տ\=~;{ՁlW sl=hf Sh;_W ׾26V;->vwZs @qP͉Qש#p4I')-Ӥ#}ؐPV$a-Բ ̳q)5}x*I<M(vྗ M5P`J7[@cȂi l涚/@tm:u#V6|klu-G ZB1Vj vyX=XFdmqw:ڿC&C5Heސ*R[-_o@/)ySd)B2<Ʌ(1}]/ePu{^A6MTGHX3mcUޖ6bMZ{Ff->\x|Y\+qUm2N1L%Tѐ{VPkC/>= a5J 4LTizx|4}NZW,}d z/X)6e 8~Rdi5΃YH| {4P9LGk+[ogo>[O ̏.G^\qڎgbrvVd Z 'mB ^CH qheZ[,]{K<*q.G46=-vzٳ"3s2쪑 {vS'L56Eo>tp߄Uv*5(lU_(I .RyZtP45SX VE+`PLfi=_1' ]z#:Zb5ԁM&W,>4aÐM] S7$?rwZu=q"P gݻf=m{pr5Ƒ_7bs#·%´Gex$]B\BBSP'#8/*}^cQ7uk~Cl;a`·{(pU} 2t3xIc'\;q@ȇU5WǙ|xI"8G ?Vn|Z2;S{-qGYb|P-;^ty-gM/z_mH,Mvn剤`UPHcuРwʙBσ6Wxn~ݽ!Ҽ4]]nNVîtJ{@nlUIN.,Wp+,zxA@BR}b7k֊pVJdƌfuJ儲h0gŠ *rC.n!P,OcwN^w<?)w' ht/~d4wS˓0rAOlS ?l3Τ+5:iw=Ugny=`GOQ U J[2HP~2]g! RJĆ؞ۜŏ\t49Q&*Ds k}OV1;{U<h*]vbgj,f֞ukff)d!6Sʚ4\"k9{W!31FRq)|@OS5GLeMI_B'Ώ5B !p$&i_y"L)+?HԪ;MpzI}= $w@\B#,K6'_ȋq‹,!.[ C Բ"c՚.9 5L#ݸ!*bR0s2,|Ns '3*?t! A[s"亪?q̇( O`V[[l|`8KT[(Ļ bT#32 Tx/лꝛydc]L/W}qi8cvge26T-CHP,||w].cۭ&IfUGW_@dzg&ѕMzOQR$Cvȩ Z/[D|eɖvyVGT}$֠Q{W HKh  q{gt(+lS_hsp/}>:S8wX@(ys BT<ZO´ ޜ!̆64"[8@[-Gj3)yɲy?J)8yVUp`hW;3`/!mnᴬZt?\u\>H-}䧲Dg1Pk~mC5Ud<ǎ+VyO| kdTs$A6 P.Ny1 Öl-F6z H o(n`%rX&wY=kUt6п\ԢF5Y^<ł1p^k@jd3zXO9nIز]Ve_Ia_kXĊzN곊^Cn4wN7>V"BƵȾr'  F;S (._pedngsXgrS-7Q.;q:9ψ/ΑEʄX=@ѪB2F7T5f*k(R΃%x^\%-4=Iw<2VnKʫeⰨå2TX' ^=/I([ /t n_oC]ʯFZHBEmPf9C*.| Tz駆Gg\2W9N[Z=\~ә`00ЬuBBhHj?{1mMۆg |_>޲S,oo/"׉{E_ĒGq#|@=-VR{gXF")|\|)>~wҤ2G S[M1(<ƣ͍+<痒Ia`m|q0Eqn 2TK&Α_V@!XsKs*3sZԱ_7x0?iA͙0C]qN?U)*`#xYG##hmr_l7/y]'=f pܶ1 ِ„D]nh9[#}.o~3yIյȇ!Pܰ+W9|7J}>46F AI7}O F b᦯]<ubMa4u^G]R.v"?e?@QssH J" Dau‘ 37@KW63US'q*7ҥ18]i  L*L[Sw?!y`&X@I*[Fj W::hHz% !)ј A{pCqЁ!hAf.Uh:S2n2.?t?]sc?$|骭m9CDOx5Ҿ%oj܂όe\zX+!l}nqCah0s6wԦHehrF]Zګ[Gi=~x{RlOR{/U9l{2} 1 b/2z B/na(lD"}SIel*I!AgН|RYg';M*6I]*_z) ֘_/#z%Ģ]kQg4 T OJ{p !(y=po@G!YGrc/w NVVU`_S4맣CX?=Qȩ8 yEt^=:gm uV^&G4cxS)NV4Y5c^2g17M.C"Ka{-8R*76Q.zfڔå (]-)v*R4i |"n-:ܥ ʔ*YJY6*?@MGYj\*2췲!pv-{RiW nxP:Vi˜P,|;ѡ@kfw5SHAu>ϱ Fj_7.rO=0͝kB^> };a.Crdà 0MVZe~w/#ghoۙ;P+&i/̠m.YY(W>nPLo7EnJ?(_#17p"븂Tͱ')l:b1j$1]j^e-vߦݼ lrZݪZJ2+u 5'? cZS\pNR=qҀsfXg[ʥ}Je 3}>̧7v6C_G@O"&4no?*. qrՃDog:rV%x#㍵ dMMZ^UuCΛaj~]'Ǚk;"hAK35M\P:[PёDv:Ge0vEdn,K߻sB*yM)~CR|iI+0F)}ݪtXڭnt$w!S- .3mDJ5ؠV@M]Bg|5w\Ϲ-뜋~d˸ܐkO` ʢ6rs ZFEER+J2F1ONՊڭ턩0sbLe5aյ' T}94g[Ocl0Tp+l~pz:sgf}b:x/jmHl 4@ag'OUΤ'{>Fpu{N5(6##2]7a RhwtmˆCz/egAg*t<] Y\0%_2V]&pyIԛm~ ?YuxXN?ѿUZbAdWA,چgJ*k" e;IeNۜ"`rrl=lEK5ߵmˑבh3y3|護kW? B%xUrXN d"mNb)s֞j !4xѼs/%v{8gS/~ڤZo+?up oB9 2a4Ȭ5+%[_.J-I˸qu.jE;.zz>vAx'tS2_26G -(mަ̠vl!@]rSԨx=$Ƹӗ[0 8f`%cvɢXސ~(t.~Ɓ[wgoym4vc[nG$L["w7+I;Q]~lMSE tvxYyiEET> %a WSS,,173ͥFoK 42@Rr7 " P~5Sݤ4㊷cu,ϵRbetT>CEu7[(Mox,X3ؖ6*.P3?Zs^ ~\^SS{f@$a:"rt/fYUSDKз?$71>̯!nF:~N@PcA(XF :aO 泣HCVWp!Y `za -7ܣd&UZ(RNf,:CV >q5:A.E2U8ڥ*B6ݵUn(/ *c=wS=2RȑW2}p>8EN^)"#vB3oOtpS?Ú@Q)0RD^+srݹ*ٚK>Gzjp҃B2oFh-NrLj_BTV(݌p9f&#璼Ȧ^4夕~GidDt FM\K>xML?kF *Q#9_ V@lT6͇ Wv4/~m|\9\ 6x~-%_to:XD0g69M-Wf.} S|/ ~^\.t\@:L´.C;z 7pݝՐBPNCb1fS1-勯a=>W %@ )~;-tph SCdR]2u0;`!gԿv;BfFfFScjPAy/}.m.~iO ə7 m(.nwBJ2xJAA;5"m'X4DN/K>F [Wt#!f|d}zƣع*Ъ{d >yEviQkZP^g|Vsô!3LlLI_{ ֍Z} 87 =YC+̌щA2 Y\N4Q\Ad`<@8wkkbRv+Aql'_B[f6X̹'I{!C%Dm-$>κ 8*t-p ƼI48NW&)ʛ{bʫ.>|&efK1 n\S5?ͳ[2ʧɼA|gM Bб٬̣1_W(- PJ˿rz3n #ٶuȗI}pJBuB699bh7|Q$d/ʉG AApf^oO w\u~j\sZ+"']KSU n4aNFHtTT7ʱ0{ mo\vO*B.f6iA)>d_g~>G{e#@jIZ]$[W&>$uŋ{Ʃ*6dCD9nZRt/'ڼ:'ݴ=NaKͪ=>D+*o !%_mگ Dڡ: xE2ⴏ'Nϰt8 dg0nM3|bt.h&R CX Ԍ}ũhZb*س1 wz9fPi#Nr)% ndijj(3G҂"Yڶd"kIT* @tޟk ;N2_[M.RBatk-EìE-=|pCJ5 }BRJ0WUbhPyP@qU4ZSEgz~b̦OʊGhA!gNS3D{ Z@mZ$E2"vصfݵiU}фoI?.eX9¯Yg-7wid/j4  }/PFXw)h{ EтWjqh-VD>/&gIE{zrmA5Q,KNNacF[$zwg\K#,S(.Wz%Vqxͪh8,=nkU[S:A)#%@&sutV/0!-%m}ɳ8F19P|VW:]u4%0.g^|EL'h?ux^[Iq]%5!kz{Ƙ7s*,owYuee7>{CMIIhCFk["lU# ?t:t6Hu,&gu| Dksy/+qq˻VS9%.A F3(;_Xu;zsHU"tWA# I|{/qX q­Z{Fk/6kTЮo,d%aNԡkY\(i/. 5hxyۨ 06>:4&$Ό*1+?Coz!ݏN(i^ǁ`Mi@-OސK<ט׮QqE C;:U[JSDpMI`>l|̹t ٢[QEԚ@k}ao(j< 6}%3DZhSXh2r"țќhoUX91t~|D.Nmeݵ6<{$KcNDLɊ l WfϮFkJ }[ao3Pd0/쫇c&!9b8aἡ_ 6omope,*UI= ƠМ~Uӆ-;9t6D_b }%9 sf`cF3 @F;&Uϰc2fd@,/Qmz+h~'xhhةckJ̖8Qxfm}#[Jluad${p.  O+v ǘ Dy% eB%j-SΧ[vd+zkMl{5].h`٘'a5"ێST RUu*HN=Xu~=ꦜ} VBg<=K7r? z J-+JH7z攪yqY9 ؙ,AYVଛڳlUI{/ɱbSs涟S:R߲ QL__:撞klEFQH>]y \2Вa5֚ 9ɑE @SUA-0AyG)^OE, .2Nk"_J$! M[DsAq)D_L*#tOP}wMzg'Ҝ}tTT#xԅ?I@`7hV`:$G7oIugb[FoaIP]wj (ekY~R6eHo15j;F)`2r5}ovۏ?]}P?/.>q\͜W !V*pc^fFSg7E}贊S,B8OSV dt]4}:gyu "D]qB?,qxlnUH>pux{ub/snsegu:9& >B`u3+!jQi qAPLIekdHm[*zR_gRQx$j[=6/B?告r4o=k˹W>JMjc^4_, b)z_$%~1dmfvԈk:jNa6,JhH<}cVɗWqb]+mF^cEJ*;L#B Qwݦ!fIcbѰy1>9?%d̟iYԤ4gUkTү,%6\,Sgd@u|k&(}KF8hVN ϲwvtbicn7dn0dKA#icpO+ɚQDm.N Qj@C՜-Vr8zNM-(Afw$yx(ȑ(-4Dw4afsh2 iLʃ0䖲A% gM !xkXZAoC%>*(湢 ZhLGDPԙ-ʞ; ][1vU =v4 J;`EU^ *[A:DɮAjS0{rO> DK Ktٻө=UB4h1؜$C[L.,sa{.rqiUuGojGZ&YD|h<]Fy(z9pd$Sccr$v,Q%NكV?&I co?Uw 5sxSk#iǿZs{LR?z>SOr)):xU]Y <"6X-0΃Aj=ٰRa'6F~e5#.vZd77_<:iPCv{eIns>{:7B@eڅoّ9xJ/shq2G\b諚_bn=:Bz7aokEqHiLx]aܜi┎*8"mȟvJØp!RFI !Jb%E\`z j9\>Uku8 \ԧl;]f|C9q}xiXl)^b*c10$HT&_&hYCCNGYd:.˦x߉c?#6oI.rZG@AW@F'r|@T~2K\ s*HMeDk=#5 })S'{:,Oz׿n 2Ua|7 C1$x 7`^,>K:!h˘|RЄKgwdH\Ŷ H@yO,aʯJOE"1Zq yWZ1簛fܠ J$?*^YC 5t'wwO[(H~1/8O%/Gs#އAi΋SwZSN;WMJ^ͰrءX|V1m9uoաׯ%QGPSwG2mn*MbLA)QW'_;](pw/B neBPm=΢%+WtQWxp'o עYQ |~/J7݁8XÚJ :MJgJ1*Ӡ%:]1'[+?E,sghI')kya(QR T*Д,fٜg 7޵;v҂(ϸ'nwvOI9r9uk|2WOQ.`2߲0HMϸ2 d_!ʣ5Sc$U(ӧ %UCʩ`7q*j"/~!k}Mlb.< 릐 bSyŅ*!۹ N[@6D8,zU0(vl9~gÆatĤaaV(VghPXn:2n!A0|K]{kڅAGS0LZldwL92NDNQk\]KsH_aT4Llk؈X 8c8]iQtxɹB͸C7H:bP|D)#];ǞJ4n -J%d%ܓ$[~= &'8PGiz[qw̭Yi\Ϟdlc>b0+xSZ0'Ȧi,&r7Gu*T 'L4ec( q9Kz5.Y_ wu-򏛔b<0QauH2YdR^ד`j9 8V ijTi48Hx "#Ԑ:6LE0BEљ.%L>q]3:"[n#oc>J(PWlzm ֱI@~4D{oo(ɧ߲giS[p0!3sAy M ^xL\L{CH 1E+DAj<<lDBe!yv_[cf/Vj}QB$|blE#Նa  gOOטZ,]1WB|Eʵ.qߜ!*U($2Dԅ%-[45*5=A-n xpՒ9.r)aaӢiNwU,%VZ}Ѯfڭai%6b|frp>tFN˒lZBo|tQ%|Ni "2hn*e+# JO@7ݩ*g DRiL=)yXm%mZ I2 WSX6ys}C"]@H{i~  0 7S%dDBmfľe=*'&_Q-?'||@OE[kcN15ٲYGr[;vlJ pe]l?./`8)iRjm̢`3?Xi*WeR*A?dhL?jZpzє?I=P*N7Te D^[S6+PPJqMk'e ?-"VK'%ovN7VUV dB1EC=#D=4 HCbڅWm'PaDzFpjonlh'`NGy@ i"ЍQwg++('SKW& |v@2$MЈU"\nyk5Xy}43M/nwE(}6Z&Pln\^H_ _y8b0lM?jt9FMm?D37J)jէ퓯 FG7ep(ȃX})ʁI%lMm;.fWn^D>Ib'#މVNXY٘gS RZi\ ~QD˻j>s#AY"4 cRJeMgC(nHSÙ,5 9|??tB]Dɳ8 7VTޜ$~FZidG F7X[O+d,j=R?#wDWW`E×7#!ΞMȫH2]Cr̀@hO;\zżI"┚feՖyÕ FUSCj핏̝ˮ*uּ`X$x0or59<jo1{A#* \ka<4Eg 3#&㭩9AC.x$㵑bj 4֚,[P8L% ([-BapV|p"@i,h<)L[aah30A d=8de`}ZgaV"rʲ=k(RR9G<h*F -ܿr!ɵy~=Q9@olLt}Fh5Wh-\Ei?pV[\$[ i8F6w"&23HU|ވRo˿kmkꛡG;4-$;p>sx$S1hxeIB ȟ긷sHYz<M EY,c!iQ0h4]!ι2 Zכ~%ZO"y 5|Әig,"1@w|+>8T)n)R;ohBH#B7 ^Y"\_w;ω0"05Ҋ-+\JЏQI~GZEU<0MP֥ۿ\ qP F~ } OYH^hdɸ\!Sp3C6dzȂpg]+?LX9\&|#RLÓkySomyzзNnP`oݽIC`'XP.&]h4dnh>-cH [~ZHYXH7y!ۯTu?/7zOC.a`u\!vtƺ \w !H#&ћ{0 r5V_^ ix\ fWvI=hVr6(;"M]Xt;ӼRҩd$7Z}&2$<4IݟfQ/C&=z w~˄sUFU߫`P%/Tdb\|5K:Š4Н_+d~h!KbgDq-6c6]@:a?Ndll|@Tʜ@ܱE&)@t$"Y8+r]ng _^Z);k)$DPwΓ螑<鞶JohmJkVJujp[Bt1Z(bNDh_(n]71gZHtVӺ!X<ϟarEj+EO@Рp]WܬCx;TBD%z-R)66X>Ei9?񮳋,8sP O8S.nWM߸ˢ̀ qA:L'™DxL)YE`k!y /t'`$0.6N9#W6ANQehQ86VD[El&t#1_;v?%}; FlP٧9жjNIQ^L%'l5Tuq ,y9|0Y㏕XJ^I-LjWZ=HA= ')H%28ouh\5gԔpMZgҀGoCsFh&> {IRY.w=;u}8-egI{\fp4,E]9L'+(7Ql.jMT]O  dFGV!{ 4bkIs h"Zu+ kHEHVvj>HDɝ$cYLkD&nayڜr| XUV3}̔W.;Fizw<ٜX!zӖO?(&^_RZTߍ,*2FC]feM5 }tX!{dVRf^&> әWobыjzkwUK)עs٣?קn$`h]Wxy;ޙN kx@Jr},w9)rmRxVCæwQE@jA.l=s\x"orX{ȼF-QU ٦C1qkYKl˴LL_lʕ ʈg!>/:k5$2lGLHz `P\G)[d1iH#N[>h~38 Tlɖ_ fG`G:H^-FXd0rm.d羈TțqwL$L*$mKT%d3MuvK;Rg ScP}l(XtPnNĐ 8V㋧ޭG0,/0Պed7?mGr%[@Cq=KW1(QBr˵7HRSѯSkfnmN5ooSB[TUlӵtNH\vؖ{v7*]߿Y GeKTXzQ1=T7?ihУ]izL!WsqD0WPH e-)|? 5Fo=T\zfj,eob|췉rU@w?c-Me%>&1 EgڐkG͎~B N1o< !!̅lvP@Ա$,K^6?gȠHDX[uc=fۢꮿnʸs mQpSv kKIHms$[/GX4;gRߔL@zJ]kfv2 mI&#N;%.aKkNNr ݡ':v$v34(rWnȲ W~&MZIYN6,8}ղ}ppP*esce)4PZwWEN94'@5};IŊ [\7VlO: Iv.c=?ZN3Vop $_;!żc㿘z,=!ӯFY5BE4d[{+5#G܁7P>%f?Di8iXe)IfAW(gkg\ ?ݻEt?,YUa.Rڲ{N=F 1:&g$SIC;۱cJuIb88+_O+-*w!R2@pƩ9Uu |&3F+POa5ZPk22Oh{Js0qbCuNOAm`39GDQmϭE s1^[*h x0r3:|`{py/;nGX&7%0[gx.6"~`u@ўWt,Ke 0EƜӏ2rٳ48?^Vꭖ"!cohGS7糈lVK+i1rYjpJ4&hq9i@ ~0b>>1CXE1)w5XJP|Oedڄ"\VS #?WCR?R>%aGA R`)B'9,w<6'S-2h]O.DmB m̷U=?8dzcގ"v<@*0凌}zG ]`}s_,X7L߭9,2yP|fA P,?`@QSN;,E-PY Y Wȥૻ SIař|Jq1@_$ f>;DOPԯfipRsNP#dw@Běh0]9iN„j|ݴϗї; {l!+po3k%4t \Tgro~o 4mװ7+>F#tv-҂`%73ImUhmGm!œjuS`M\)hn삺Xsl8$0[8i=bм io#FDɊI-ϔHsЫ9-bYcR嵕VKuLTFwZ~3:Nd㝄) Hh*l4م"SZd_y~'_|#4-n5Sod+ދ 6瀩z8ɮjC1cݽtFp[4ܕ[6?1nE2T/7Ėǰ@Y1 Orol!rp,q1֦ &`52~MƘ.s:},Rڠ#})]68Xˊ%tǦZuR8>%IȚ9َPM; 8cV?odPEO2s(oehAPTX|:q‚wDE?!`Am~F+? {ѿDUZYIxv/T,']#l;>K3sg+f*>cUs41 '(Kv){w _Sald03.9O>9&D4|LAi#L#ٯt"]Kژ=i]NAP` eHSNg5 eYdX|k*+B$MZ.d F&2쐺%'7EL/.5พHh Qw^N{6$&o!ؓQ\+dmy{'̇5ч} ,DH2lca]s6SOFBJr[6ScG*-MSon |V] d\~G*WڐGF}Y:OF;ϐCj2A>O&s3Yda V e{wY1? *w选}_M+I x7Hh_AA܈ΔczN$9|.!1*W3B"3RLxi%TThSXZEiK| B 7~7C7"Yv<6 "O+*lEޛF@AχKձrov1bܽGGϑoR'SovZuKҒ/s1 5JY->I3}L^TK[9-)!J +ߙ$;ٻFF|2ǔ~K Rx8NakJ񰒢:Q@U_K%p2Q+qܾ*5/um& dq:-8ݭX́ }WZ  YIG٬OTTB$+QUQ}~NJ o.rM.7Z#@ޠ| @⺘\/+0O,y"G`DlvV&G8[.>yvN4*gKnD2S4=-*"x>/Oe>Dž3qYFpU੽֮YDVÚ`:'6V6d$y _TUMl_$׶yZ#}T6?g5H݌ !T9'K%8˹}ȑ^Lwu^.qUUjYF>5|; eY`b}) Ŋ9̕t!^(!2]_ǰG{C|ýJ?u,cEÎ"]8ګ?_>ص0Ǒ}&v ?c~6Ͼf."_wp", ٖ([`ٜhu п+}h=9-<] Bc\'s8JI3AE}36^jlަ"YB cKL(z񭀼Y]RThдZGmXk.^k ؖqXnŎdyTYh: J/y*ʞ82#TD; w@a6. 6qj s/]>CQ ~ȳ|( kbtP,q!kFmpaPb $J+;hWlU4ro oW #'ET.‚̽}6 #,~:֖}a\ rg,mXAl@/VS.| Y7 ~Ŕ bs0fmJ,]bJQ7N _T,lQ(p \ŻxLQ׹?o @Y|F~}Y}d WaN *Xf01ᑖت뀡oyS[(#.|^1})Yu.2ǖVLR湺)%w 5,o:n+m(rzh~?NJ&AcV!)-RS%]ӹՒ䤈Xrv2d6nh/RK4tpgsi>'LBM3!%qs*-# 4n5nfO SmQ^)*g#@'mWP"?|`]0K2ƒ(>׷/"]7Uҵ[oEVjҺhgqIUg74.;e5ɃĨp[*n*}`uCmDo.ULy6(P, uoEpR"i [V}u~SZ4{DwemZh?g3v^D@H2ez ֛qFIhSh:" Ys\ߪ1)њ5iS ͆!~Kŗ2 `sps2LgD/ӴRf? CvPJ]zd.OE4udrO\1EN\{kFvl 9hO j}*oXO\NtGjpKHo qK$. wǼkTẮb>AMoɶW:?徺 IbQBGU]?i@:MF&HjȃN~ 3ZeG1_X.&JؠV[An/wj1P}%\It@\ÚIǃxKN.HK̯.f[\L8q"EX#.vvD+ςT&tD֣V ڿ4UgkӦ?FiXSp *X<B߅2BJSxYJ; ioߧ]9)AHVIto&} |*6;eI@xZSc`<AMʺ^%̹A(~z^,zbY)IvJaĖK-m QL*^}v 3rbed.ՅFW:TI.aӉzFط>QcAN65 km'A`|3/ 1 4cgh| {[\Xr(% Q\ibYK%o֯md΄;1@,D>ɼ(Nn *2d%_ cw:Ƞp"V@wF 'uərҘ~:$ tu2S̈0̱p75UỴpApU,L!yof,cvI'qS2~z$@`ts8|MUɐ A8dwyzEtL=Y? 8eٻtTl=qU&#T) 3F(-&Ոc&*6Rg߾nwϱ:҉(fܩU)ݒk\MTi]a)>ݰگ=ĹY$ 8Dn@8=#v(FkΈDg碻^gE'qlYLZl8䰺DΏQp3{yolNƼ$@'$ck%j7rM}<ָ 􅒭hx_|0Ů␍1a4HBǾ-'9X&&ЌءT#SyW6}jP]IF)t_M2R1枖YI&<6I(kU&T}8 v@H pbG7ۭ QяbQL*n;JnUm:lwlFR||. 8vutqwœ5"iS|0vwP.)،QTͦgX"i&/a QvOk%9|pFً$']4DCf I5gl򞏀v+T >K֗v ~T#)iLy}B h ˉaI7dqXovJfmoۈphX?E.p Nr$ώLήͯPfv92 u'IZ'4\L+7_lH:G#L"^MDaΔoNw4QiJ۞'1sB˵k6=`, oB3o|tQw9'PG;J1kyQ k=@ VJMH0#-DaU%Dz <#XӦ Y]_3g * Y9H=ؐKtP-/|yKt#P#vG~r\J,pS5ZFMxtzn1adi'zy@>"v*U^=ʃ0?Zt9gmC+/# 1 !P'. ʐ0GACuKgJ61o%BmUup?{tUņuhKrƈ-_j8 Myq dž,*#v "y8fgIͷc?xeBS'_rg-sY;JEe # \.\}pX.EήIlHr!>?さ‚\{e/NuFO~&-goE&;FYV[,)iYθTٓ?]" *y&Y#9j ߈\7*fD$RwvA{MX _X[4_oUf63H䍺V] ׭|,E"k~bub5&M@~7Q0 xyF+hHB)SO |c%1r+SkdA9:d*#~k |_{\zHJAQKHi|_]q/9QyH= z_9lUw*iɑMJ=>hj54cC`8@nI.;ilQ܂#jNiIL [Bgi)?Y,C{b|Jҟ-(?VQOt{]P16ুRK!]moP0o0Ge Nf]^$#iHρI>0=rԐ7.^zS}۹Lݷ)C&J7K|M(3zjЊ!:β ~Vos)Z]&HI8 /κojk$:z. \hް tǹ.Jj%Pgɼxe؁aEg:؛" `7(T O-Ǿe]F>`;*q ΍0G>-5Bq7 u>Z$^ΏlMJ(^ YQͺdЪWOwW $pntpa&x!q ٳ{ >\I&!\C{F*3@NLI hGq/lBհwo^QtU'+̊npò| %}iKF(4vkBcLiIfh~lUzj8hz-S/_shB 3$;B8ˁ(6~ʁNCr-6S%PdtZW0O +Hv{Y^:L%1a2]iL]_<[z JWq]ǃg%hVGZ*4e]u^pVKc&tb)~„cwzeˣZ'g!Ov(K e%̈&Ӯ0-H;,U~hK޵8vT ؕ:KX)T\`~01`S[e8mw1̑k62"ǁDKHZR47*r1ST3,p 㗕J&|+ FK7bﲭQ$e, jG;JbQ)9!FF=9¡\lYLH-zq ^SXWCAQ]=lrk#lY~]M?1%EEf&~"J"a4ڋ~1IKIlC}slٗH@H]⛗UnSYoGWZ5ޑ'wB}'5<㞞 & u ~wtmMˠ>Y@2'jM6$^vq,]K(v :|ф}M u@NC R A~9ǂީJ$Ebmb~y~Ɉǵ}{_rǜ{LÕ?hg,L,'MgGǃw&)\TL,fZ"g S+II_;&U:C%>DXrrH$D "SVeȲj۔4,RqCs AGQS4h tD3ŖLA;sK}D =]h|했xĢ-' 3LRh.v6FBA8p*m6=itw? 9Tb%[~% ƌou3q TW%to:HȭA3dߎt}M= iOcǣ<=.b|f6aCtdr{DϬeDy<+2쀔l$8%GDA 0QDwYx{o`3@t7x2)VjAn@=BYQ^BOJNe\aCa[GT;̥pɴUTbVu RTKBc.4 dži W0{G2KP7@m 13!@q3ud"GOw{\JMY1KA`#<,rWr}g8hGxZu>SUus^(4; p,:+o5Bh\=sxBW2npH )mcuӉ&o儻̤^Hj(ñJ7AH.05+ $7ƌi|RVAcK<;4{"`Q1nP,a5[ڜCxW鸦='0ۼ\5΢Hlhi f^YɃ3 r<ޝEhŋB0b`pŒh_ZȰN='!('qv2grV*]<|VU>~߾<*sckWfd5aӔ^)/+}ru& %V0l.qً菊be`Լ!wV Xދ4[N3P Qթ;M#h#ƿH@ء2Ifr!9ϼN` :x.uj $$#/*b 7 l?HA30O'i6uTaO%#1۠7N,II$%yek۵mEҨ;04{ך:_i3Z&tz,Vtނ |.0]+Ge˚z=1]ӿ?bRblKxe3fgNOq ;?l.d0Q^xfr@uT`?\>*CDȔKO=\09'B$]fHw}M^XDD)ǨgMՏc;YQ$>P]eS,rAH5?*(Y ,1R ; )י) d%ء: ҙ&sEB[goM嬘 i^л"cr<^TxCn'Ķ=Kdo׾,OR軏P(TB12߄ 7Ӽ$)ƥ>*Ȱfb7"aԀ# Xk}mm= ˏԮ~_,E&BTV<ڑS0 } љvL |>Y$(2R1ް0C8bSputTXxjXhuͳBK'jU|QY蕠Gvпp:AäDωn|)Ӱtj@en52 qHzO(hoK#= \K<|s$ƪGjÞk%~5&I7xQq貛 tN#J@gBPyNlZ)q dzO(&.[N$9rbfiǵͤj@:}}- кI Ll5x,7"GuR.dR3,n VuttqЏyN tLCMjb @6.(p+pCoSqB\a{_p뵜[4RF3V>bJz@2yƎ:0 Cq]^Wx3%uI^58 SZ!BCPqi?0)7l[OkTl[$D.~8wpT昰ՄJ)|?]Z\I{[[qu,(O E|?c s 9=O(!$ yVu@[kNº /V抝}˴[ G 9M-jzc:(q3=,oSvpLׄR,/Uʉv o q٢_FJ֑1Syqo'/tIw 6shs$r!׫wL<Ox r_w y4\׎$8Ox<EVp(aUTyL8eT?D\iY]JGN+[(?;ұfw\H:7>ـA<Ɍ:exh!{j t?5v}SDk؃$iSnhnU8|[oϸmmj5ĺ!D0lf}yl]x9^^Il(_%4Ӧqk]G._N'nٹH"/뛡Pq .gZK%W˶0W]0Sz]sQ -B6Ō븷0pr7Kc#)a'/<ؽ=1 :?UPn+xx'RӪ{Pm&ڂ0gؐݽ&2hQ̴F=20" EUՖ &f:L*)Izz a:ь Ƅ}B(ε'Ӡ`$.XܢjwGK]a'U-pNkL!vq'x,̨7;g"^+h.Xof1PnYb3dO 鑂2]t?~I >QN9d+7nٷe=5nEeW1 JW`DTTd^5݅nAVOy1&͙ k#Fb#VK%&iA6+ekj ;itrCg:a]e{fE;d ق ٴQ8ى-eE/mb *D9{j(qSԾ5{u]։}KD U&ƓQ">e(q/+ m)QpK55ůܕMwK*𖐳,'Yj"DeV]~ɲk/"28<}fN*0;"a?*H>d}mma*#z&Ch<$ !~xt#nʻoE^.A ߧWc5ǫօK `uj`)C.+߅Y-7/9dK[h Z8_AW/}Ym8+W#acz<.jop0ވT"D_\IwWC݃"B)c3MXbQrn{al!O|vƚrgCSF T\k?wz[j"~v| tHˢ&7AZX{% k8VB.Fk|bǗsq^t@gY %LWIكG4]Ni ȴcPx7Tg[?h1L[q="Ju n[OAtf:Evh(&uà]6B_.}3o` #{y?t[eX#Qgd!c&_0d\]f;89E&a8/p(R.k:PIK]"H_: KÒ1 q~LfY<KLKWلf ȃ9|0;F$ &|\6?WoW*svBkc%@[ndY Dx6nt+-Nfڳx,ikh!YH֢QVhM$N?r}j,whxcsBiVJ%luMFDfevyZ|bק+dM/81I]Pye՟BcU~b-"ab?K&G[$rY槩َRB v2 ]V9ީ/ -$)y 7'Px%MxL+|0>% k~sN7 2=18]T`T2~aMM&j&4 |wKx0m+X ? [#=>Gs|ʶau67i=cxdfkB+%I4*u׉ [| *Y^>ZHN5a mJC|SfDUg1Ta҄9QARM=X*TvRX/'/NTږ|A fNs>ǮJ/Ja"B}à :w)5P(UhzËE\n} GuJVY3JDfN<ϥ{o siǙKIl~/2{̬$vZ3h%2ڟ#d!H dPO݊YWqqcvgl66BLޖ{vDže^O ./vDb$!(-p( HAڬ~juJlSu|wB) Flti~Ml1e%uxI&?u=Ɖ55ˋS*r!:ڪɢs*t82|ad {S4D[â+rFY_ЋKsn4.1#4G)Bny ֞(ȿ,]5R"꣡ۯ2+һ4C1h~8E @,-u.Tڶ:ԕ˕m*^-4MijE9h2rUTUɱ( %cI%uаNz6)cʿ1LwP Bjrݫ"HÖPevJ`ʵ 0S_+ n&RIBVEˣX'j{2&4 ȯjBtJB3r3tւG+=9cƗ <*qx;_ۨ͜6G)/k7jAt'&qMֵ?̴uc[f-WOd]M /S (}&nTP%sƋhks+=<`Ӽa;W|x!A\' |jr^C#ަw/PZ>F{o u̗sPG*{rëp~ fV_.͊B>ym{c!tv#0$=[Bq@7epAʧZxMA ;VٿyZz@IBed4ج"H, L30J4aOn SZJ+h~+2"!e>[rF0)S# ^y NxY~'`Ǵ qN5) 1b^ \^0P|dJD ̔/e겟Dƫy:CIy )CHW쯏WV/A[VԊ[`;oe.Xp,cra$0;jϠNb>#dU$h#(q;=j5L-];LK íLZ* 2yxB T=!c>r[u~ /k=GEl,6[ݹRyir|0H=Wh:ޢyZw7񒢬AhODth*ݧAȜuOV.9Ȋsij~rezMz{#~>%d-EE/smXq>LnLAqymBKzuR{bʏ<#~CӑCpADʤ FRPV>+]9 #t0P֐5 }ϤwyYRKcEWa,٨+B46xO8fBaK-g +]J(Uizz!c \[;K kTN 4Y;wDe@GL"ƓDջA?fxLE{@WKɣẇ򥭒IO!2ZKK$@=FE$:Cal_h,sẀo*sW}2fpC ptWMY=GDsuF7|f4㆜Ec3[zW0NrI #Z;>.P͖x5@mĨ WEڙ"Z&l\\-H>vh/ވ"[UHozZIOdP_m9a\׈*v b@#l{_7tnS wfZ>>J.7.$`e3'e 4&'!.~R k,8p|D@'[QS$:" YZP,r8qt8%(GPE.ІxlfZ 333쥒K%+!xa&uo3!0֜aj)\"d8_tYr.򜄽G н]I^4eq9iKq!0]=Ȇ7߹X_i+x ej1AaE$aυ ->5uUYv*jai$iܨKJVmfmb)& `= R/L@™XJ/Bٶ.Zi#/c;"ꊖO Ms2-NW t0> h(&9ũw :۔ ]Q0Qg옫*bd꾐sB[-0 މy@4d&NP\btaoG1e% sZж1e[.R0+o#Ot_L[9] 3-Z̊+R旴KZC<:zn.@=zt. 6d1=mԒh a=޴UNP)dVuS8A+%v):ع-nvsѣOMPՎ[~:2+Rd阖+8Ӯ# b06^VIC :I /MB&qeE Utn~~V'R& 29$O(NߣxYV|ujpv ԒR_/4.HWze3j7x>O^'4E!"яm`U2`fԱrD7! 0y7`*ݒg; w`pǺ*t-`#4 ۻ>ȅ=BHw =Ȳdz EtT?{?O+(n>\gD:_tDԫ'ocv7A2_8#e ͱu{caMdԖsUIOv׎&UE J8%MW 6q%1XWp : ƒ#cB91-rLJ3Q좏 7$\GJۊԫ7\5o/gBC22jIE HafBPA$rUN3]Ef9Xq\Ai/Le4u9B1ːa.2!0=;^J&֖>NFB nTWpcrz341 q\2?j6~= ^%ðS[&5n YSufB`e/[Cc_?%F[Pe_%|dsQ7;H4]J_$35 %aNֱ292rU>Ó7qxZq'I #AU@\dѯ( Ԫ| ];A ii,Pip/$qFSAQ;?7Ÿ֍~x%-Y^/8]0Gd^45ܢ.t}ÁG>0_ayq>춙?8 3O_4VҶdMebe^JGTSd+c~xֻTJ7ȶGcKN68%2 ~s Y߅ʹ!"+4ʳ)YT-}'Nn=q.{r>?H{S"Z*bx-HKЮE0Id*$׷+X$6¦H5ڃ0INባiΔB?֕튯.L35P ҷKܝUKbPF)~a?.Ui~ m6!teEY;C+tψz)_i6`?!"]A|_uV]Ŀ;ݿQQ>)eg6L'U9 FAA{s$#^*KtORtIJ#Ymlgs67zdli}0JA Ksv k. 5d{^ }9b q9iD?;_>J,_ɵpAd|+á%n"ۯdY ] x,fA,t3~pV{x(^<=E;n&KB+uC{k`?$YJl{PU/U !w3dqN^GFHpqOFօcl Xz]1 pّ`cH{PޙKnQtwd(jNo0¦h^oXf)ü"OGQlWKsf _yzcddawuatoи0Π:%r?Lj)"js56?BL! H?nq`5\qkW?|8V BVǣ{d_pԌhՌ|MD-tܴI]g?Cⓧz7 P/6_ ?lV @/j4x[dIڌQAp@GȆDȿDϰG\E׋MDxutY9 r@)Y+6OT[Wێ&te1`?/5o!;wf\ :_9@ (A2u4_f:m龜p)wB+{+?qOAv%mvY<¸/\SYj_>gg7NK`-GD`B6yoaMו׈a7@T @tLi w=%(sR#ֲ;~؍#4 9aYVU@kFe.`zF꾟Cn"Ǒ3UPX2IIBK4 WCROn݄ghaP[n'&ؠaIOjfe & ^1H1T뛸;_ | 7-nѬ6W_}stV#/MY(@N\Z`fDJR/ q\Op(8r!Ie=G) >pY0R0x<K=`AiMJ<QuxeJ  8 zet$EaMEXihW_t͘0礵Lvj+>rؘ|BюPLC_0 ݶ xgR1,'Ċ~JiMS%}â8A౩ɈN`k1J8ęxČ섗ne$ttV9VZ:ya=T+ V ҂Vzgix ֔ 0Ħ/3/Aj"coظN8~wJ"68j7ppA{3HLlgG0` .^H%U됢{ &زPߔ)}͸PW{("AjH0`rr5Ko^,um^I#lꡩ)1083pvtBKV(CZ/ Fk &]k^QgZJ*A 9ɱp1x~ gzoVKKc3u]/5 Y7ic{r4Mn'@aU D oke+ WV CG[ȹ5>xGLG?-/mD쥹#8H:h7Glźx:CMWbOHN=U|.["/"]g/V q@R^R}\tmk5B3 .dW*.Z)9:oWe"$Rކ' ;:F`Og[`ϺU 9PYr))50j0~j,:{#P–"mRW-i &))ԙ(O/:q NsE`V 'k %5`JvS$3n QIq[ҽhZwƁX~"ٱL$&;ui"i]X!D_AvQ; ,۾8muEO0$+G쟌wC}G/-St{KL{zxZ'(e :2_I Og=bZK@+~\ƾ& A+,uZx\cfʣatju_8XNHv*8̇`0WPpb]PXxΆ YI|U|2m0 "Ɏ|9HI=nj؞pl.`&&߄0-3$0|c]s9|qFj|ͥVq<` : beY1G&vŜiҌ1`eU0?`lc%ꊗcEđϦu1JN¼YsVr  ngjDp+ΖP:l{ymlM1LUs.Kɢ@N4~^A7zH[u\@8+| ,Ý 4SFRZ_\z d=즷@Y dyNõHKt.ΟH{O+[qf̄.RFxONSsQi83c=+~3Rn:S#㿎(Lef6 iR;| M)Z #%]K'D:k8{D aˤbQWXC-+\HEj&ԟS$iRyY* })Qy`) %kn:.3)Foub'MW}6jMVwlﻄ̋"MCE*˺Q: T5jkz5W}1K-qVI9yOd=-K۩TX~C-ʹE깚929#AaDxi 7dq4o 0̩ oo%%،9݃z[ee'/&sʝGQtQm>sCy))y'_" G9M5H2S縟) )4\4>[<&a6":]ў%]OLѓNѾRrS]u!4r;L9P ı 0vb)FPM^xSPRZ:_*H s>X2s]ѥ\(CX?6D+ T9Zh|,NDt@]mpMX0URn ۣ!CdoHjZB-S(J=n٢D!ޤH'9iD/Cۅ,2/,Euixh)HQ9)0J'Djқbi$n-)#mh&AXɱ( [ `&/;TY-5Ձ[!꺴b tƓt9,x22GtbLQj $h$>vtd[˥0,\Vjw̐/__k:;,WvUcfÄ5D'RWR.Pn=1J"`6C< KВJ)[]e*J-Bia%=v\Z?+%aFZ:jA#X5#ƀ -gMxZ9,@ & dVmgVh+G5@cScФyl&X>Wb@wp0\һ}r\#`59)D0tg*'tuh1" ׎uCo@E43we..v ba2.uu OK4 Vd@ df b4v+1; FHxw Wve^f×|$14R,YpV#ԁr?Z,MTZ,#۟JXo4,B\ΰ'7B$"]11k"9 w_JN ۧn_@D"ǩn-'Z}t1W!NJBBg!7#qNf&@65Tjo 7VkKQǢG )KgJ Cwza9ZO}p8 ƣљ=ƋgA $q ffB~jЉֹ쀳2Ib0ܴC@ta7&"{]B4a[5 >=?4-u+M[xQ R:C vt:1 Wq4"{G O'Egb*}}I|iﱎ☝ ʅF(ĔeocOCE"?1JN&8[U BQ-DYhj*ڰlc5"Jfřzad޸+ĘJ3W(u1&Y m< 9F$"u L̛ڍeǦq^[sr|V7q.@&00Ur_pXrQM@-eӈg֏LH)2[Z24^J,!;6/dѼ:Io-G[j+;D>(uS$J8]nV=" "d\FFi׀+HSZ4T~jHYoۯ@뺰j碘=| +{Dni?cl&6Cy|{ GCFs g'$MoK? !Q!trJϕ/O(Sx6%@~P,w^\cGK\%vͽ;CM B4ӘΌ̼<܁2;[tVnWaL "Vc ~|/]iļ^0x\TV58$RRU]п/~ItaڑlN4Z M'."ˑ4!F+A4`[2)f}ʘ}kYJi#́a mGw=șgS Ij/hDkɧAо؅.dbgUb>-ʾb)xZPE !ñnS%pY{ò+rcc?fP*kC\"ۡAqlA Ӹ2-a1&4>ސJG2a.ab8zcR*yX3c_W~]Rs7(4cChF<≮hpv.O1LzJ :IxȕM>ܔqc%c\$N9[lﻲ[)|mwE#!ZiS*Ln:?>6uF`8=^ٵ{eL`_Oobe=9$n'b},{ózQFHl]4Ȟ,d| Z'c%SdpO%iKsJ#ExiԲ8cXqF+6dR;h638ȽHqHqwPܻ-J$_F 9:Þ9ނc͞ې:'2WܬkWCKPSÔ6nM)%o?X8rAm8$(T } 3^gG,g*Vsq&zFNADc^`HXX*,˕~!#PHvoVU/!y0;{ÃsG ?-\weT[)7nF]@츥@w;Cn;\MxuEuY6"LP+:1җ%JX#W:9&5ܪ`@M:ҧ`50F51"OͺX)4FҗF  F, jV\!Aq-2Dʿ.690wR| = e\NwĪڻM@#(t@+`/'_s@inx#w=Fh V8uFH jYʫcXZ|A瘛%eG!QPkRndG\֍1!θc+poJ6Q.Lky}ж +zlḅ75}BFn!E4?Q /LD!jWpsʲ,X,>0ݪ\Dm(UÃU&fH[̯Vωosa}A sU$>.n,X)QRufZu:x#IHi ę>q򬻯Wx_&"15t# -lr°ձԌ"h&&z5֭ىI6mPV,m;y5)|].^Dey2.:>tkaOL|1 QTM>Nyۮ.q5}Jvn@*kadQ9"􈸸\HĆ aqe7x08l1ȗP1px  6:dVHF"m IN1E0(e%@A?$Rơ|慁 <2~EbƏcۿQh`x¤Lbs針'Ӊ4W6%1'օЭ-0uj4Od/'KwGKNB Hik$,3*jbvRI>^/f@P׺iم`|rPmL ("WYH zd1ߝ$0FbSN?HWHU~WRSj׸QbW(2_g=oZJVv moEo7!DH\f?`5 C_Gܥݥ^DNis*1`#trݬ"}\w~B2cң{6i,2왭PD!D#mtk0 S]ǞcY/h9.!^{ W|fC^it^~ un3yg.5=-.oiA18l sfRs9=:׌CZQXk t7ҔҵIOL[ cNq[ϗQ'H$ װobEu{&}xFw`>0)d!E !+y_P|GX[IACDg֊*WdU>̎c:m[;TB#Ɂ8F:%ɫtZy:%ob^诺,0W!m䦞Ѹ:x 68j=aYG-a=t\R>f<7w - >۝2A UBI=~_ ).(B{jSQC_T-o| {):rg>a:N  j ȳj͆*TݴB{iw-s̆i78gpH~c`x?B>Q,:\`FNQ0Ny p.wwrt/ធWyp/pαzUX`+Ds+"o 5R :Ku[x*^,/vZ$4>TVյi-=} 5e^> z҈Djf#_6kܳj1znbj`%;+\! 4I' + ~몰 ]Dʼ=gUj\!tI5p1"ԙXlNI{<LT[lP9 y!ݘxQc`'y p~C[~WKaYik$wnVQ,lsTޢIL` FxQ3j`3큓5.ˇ Ômy#E 3-$viW6l')91C֊XA+@rꡄ=` @DUnVfǝIڤR;Qw]ֶ_nPeC&o1IܰvSɪ ׍8x/Td^ ى~Nl.;]+c#nf#/߳ٲYU&bN  d։~;>xmy5 -NjykBïw\>(Rʗx;H^=K.}A 8+CG-iD+Lry,- R+<Y )A78ZY HxOeW3xe6ϼ%~L !.<-Of!ᨑ$hKٽӒVF ;x4QZłhvϸlvvTSJx1̗c (a͠D0 O&u9_۴Oyz(5upmq@V /Y==66}+!;HnƋ;rA=gZ.y+·U7R[!hƁX$wި'|m`q8oi+mT>:w? DsirJjp( 9??`~yK=n Nhġ-v)8?Sj SmZPzGhF7^0Xչ<]-kc]<|OswRRo/mB[$6\2gyJVQd d[[#1!f-Q:W'9r5gB$iRw.$o~Ih E/-!Ȋx:,C?KQV5 @?˕}riΒub`R(152h\k&>_E%L{Aҁ5 mᨣ:b]TI(XF n Zƌ9\=*քpx{ 2XJLߜfP.FxJ0e P"|Hdإgِծdt;&Z טTp}}Cw7z扗V+zj;Yh%T VsLH˩Wz[1mT/YbK´RA[Ƣ|ֳ&J޽ %xǫ16PX'iad tN9rD96Լ_h\f Ouj? QVpR‡GDY(HzGBdmHv:!xJEOA,3EEJHK:(Ӗ4{8K&`|`|9k/T=xdW^eoRCc.hPEv~>RRS{.2h H׷GF*и R>?4К 3|-4?}3+}UL{#vKdsw?j[\2%89:DHCEb4,uchל\jڥ8{D&Jҏ8wjEV:,x;G"\X[m1Z]zW! ZpT pQQg0AIÇ.k'7kFl;Qϕ$ 81`H+LL_.JxsZq; dlr<r_xqVWv1b¾-A`S W9G)GlwkBD'(Fvˬ^-sZn:Cn @ݤ<28Y"^7QjQr [&UPNCC7]խC#ߵ$݄WEG;|MdÐ>;U\|FF7B~ Þ'1%S~\>yϕ?wuiB=)Ʊ&3-q dnũh˽.d?ߚ6'kʺ$NktlQ7A+5wܽ>Mw&J}[D}Ӧoh.[:IoyNW, MV \0HM&}GTZd& /1PGnw޲qL?.J+R/ :8qQ&|Mv0\1ȹZBdBp[52tn05B,џ3R;TՀ/E :obxefR+9N]R>O*y[Q4{s+EoE c5ct7(guK.?e={ÆIg~9n gyBģnw+, 8; )(ҺRJRj{UP9URad-ɔm/݂ ~`.* [+S)3[b9~ڤ[x&_jBBr2(<%S, BJ1{\Kh/wVC , }Yg_,oƕqa _>9`O_7Р竰)$pN=mz٪#f}ÈU"$ʦ`:0q:n:Io9d[_\7WJW̃aC ,NVRyo 3Jm=l֤m;AB] ? zU+̰%Ҩ@'2D59Nu䆠ҊR^rY؉gQr[2Odg|'YF# 98RWQp~\z9NH\j(új+Q̓)Y!jPP؈1-bŰG`)ܿ\8XQ5fJSEgӧljܬd53(հߣB`1ut5+@u2]|8|ӛs>#0!L~ZgwɸWDaH2pof&#Yd3yoɾ޸$D<֜Fl$J@;ar @c7Ye@b1J+t${  2a k!OhqSNZO88N7LjdZ[7m7盛'RU5-2{"N$mrbdm}#Dak.'X/Ո³73"J-P*h/jJ.JɖZbjh'PDO1I=nC =.;:zjſys&zPWL׻-rtܭf[ !*7L]#>u:GޞoٮA D)g2^ς &&)tWġ&q4`~6sژLUίG/b"ZK]/0e_/M (#*dG3Rߟ1ߑ$o/sN4,2 ]iq]nb`HYSfRiQkBVyi6P(OFADz:;|"z D^90Ζ5OfʻeE ޔlh蝑(a,ϾB=7KWY5B E9&ti Hm@|YPTsI6yyp QUsȤK? ELvM&;ajֹG[ݙʀ$g/t9YhK/8H\eAmYE"9_P 'R a[5v n_D̐LS`:{8Rt\c8BC:\P?XZ0-'.pRν$zF dgs8a0H8D[Y8mH<|R(k 7g"hx)v2bC*RgL۲aU22>l w0?N=c4Ld2VlǵrJ9#9 ޞN r@|9¡:y= JI5SܛXflg V)9%!JEf"0NIHVw|M:BLoMDqM *;AwdQfH舰 DRҚXPcuz7w_Zp]݀N+u#oOǺә6Otm.hj)!]4c.{ ȍްIw˥o},ät) '|O~Q&MA1$U2GS!ې;+էy.1z՞^.nt mZW8; ow_xI J,a-nRaHZaKX˒z/DS ypGl  DoAd9 / =Y49 ` XuJE >=6Fw[t]ֽAC2m&&6ft#rPK}!Gc!$ wžON7]b }L |* XCk17Ž)~2_=Ʒ.9ogyYƣU- 'KD鴘P"n=˘JQҖK; 7$M<ht %GR,T;[Yk^~/БpnUl^"dѠq}X,c5_;D#.`6*[}E~QZO!1 e6&(4iH-F!'_2ZVɑ|>ǵfV)$ILj#jV߈Y%p|>"hwVSQGXs%h%P< _guᲳi\aB>O*jZ\ƆEqm|n@ ȗ'Ey w6gcTK;(줦rMTil+hR:l`ZNq  b+Lr}iC 3| ۀb4I5P4TvB3,ēx~bKKNZ+JA8!A&(T0<8btqآM+78^Du;,,A] 7K`/ㇼ^p{|hھ3c @'N*`Af8㯣K5.xcPd&C҇Od:tc1[vnjQ!<jmX$Pbt=׈|OхY!p0'0ǣsG-9xNbಃh9Wnm77#B*xswW =9"$ܰ~(QUɑ \K (=5sm_m3R}֓pw0cmi%+Ql Q H1xw. '2#F-A5D(Z ,K9]qYc []P(IӔ7ZHb+&jH }#\Gd}9ɔF&vlg  \] kgp]@${sAl4Fe`">O^9k?1ҙdGRF_JN]i{Z* g7 si/U {K 0f*N4 ՈG1 vi蛄> dv PXÅaC7d[P}U K>΂6?"DЙs Sa/R=ԽJ9|ރ^͒C6qrq`Ե{7?p8hiɭ$WԦދVnO790lϳ;ӁD vW\qʮ^S}= mae3 823纯}oBґ.f"UǝG`J<E{e)|$Tŕ u]y7sAVM&C&R<:ݡ(G*\UOw=]U@5`n( @utQy%T:tѦ&ήrr֖Y*䡳=5y.[qQ(%mKkPLͭ"sQ \~ţMv{KuSbdC:Vk״iA<<JӇ-J f]y>_OSS+@Mٙϵ\qe z^=]o{/|=ߠ 3+"RiX}"`x/,R.gb3#o9MhvUFU~=4lEUҴUa.GM;ZSOEQMrҀ$D Bhj +@١o(&{hz'*Lɥ:y{1K3#$v)g%WchbD1? VpGuM/ H2}&ppbhu)81񖘝u0J~pY1R? g4@~@ A,^3+^Cqի$Ȋa `7c3NW'@|] F'T ҕO8C1 mjͻ|B<{nrx |P^ wB1]73z3J}H 'uzO]Wݬ;f%ʀVP{i0ř9KUU Z>SХEa/7T@Vz6{K&naTw1C۷H6ʉH-O:` dyiف9FlM䏥_5Kvwx6y* rQK XG18{ 5dF B Y{9F:L0Cc|c\SM$HDW}f<: ~_ۀC:H1IUJô:|˘-`C#Rx먖3dfT7%OMDb,AgtGBlw$ YLj=(0I=3WŨav岍CHjڡ'} @LOLW=mOR(/q|A+Pu-{LW9 EHՆߴ_GG?B /~E|vR{=l>2 #8xۍ#@C94I.X|M+aY٥*4߷EFxvwSVr=bZጀ^7"%( -5:=,C#fʮFH9t{QëHS( wL#8à*I2(8,/wTŲQrYw 3^2|k.41vcմYZTl/?8 m9g>펗{J]xQީ  {7 pj5EtfU'jQ|( W*9_h;Vln:\+™10eL9Fq7d غhuJ,2`ZfqsgD.V&3jO l_ 쓘]NfN^Z Uā5^qmAibWMd>:dLYg~&?'+X-H. 0WK :¡ YoɕO\i2W%vq}X&?|%/3L_Q[*uƙVz9o&/R{\ּDqȬ.a’hf@&$#ɯzKM>{U@2ώ0+Sbokc{8(%RX b~Rʧm.ě nQK{ B&= bVPA\wM$2El?WI`^xz8Q0I%9Ecc?v 'Ci|޿E"Ck-)K,XI7nq,#=%r!p?lzV*?ޙ&gTo淍n&P蝭+BŎ{;1NR}KO]0Vum,um PΉ?Eכ qy3,m:/r9__FHO]AZ '&al_JY |֋Oz [-#97{o'U2L۞r^@+&N{إpo*_;bh\.P_\spfdOu${ІF~LX(cn"@d/k5D\ō^ 9\m)jS#vѶrE+(tVϞ /mh.Eb{ipLQvL>1R@YZ̛EŤ쇾$胛}(ɫ\{:U&R[|ոܝ6V\Bj*,Λ83/\`tz LIܥF^^s(/ c%$!K:KTӢeK*a+`D$O U%";"UJL+J2I76&~дgo"ZFas\1=1& w1uI^Cgh) LsAW&ED##|bґz㥩`ʡ_~"#գ xvK[G@kdpyQ*6@ʯ\* 0An6Sw@fd9m~W&P Ok(1N/xkc wUv$ /`MІ>GZAq.mAG{o\-)Q)`2Up1+uX}J3K~[n68^޽+n62b^#ǭ 1QR)KnOlAՙ [?hٽ97:JN*kʱO,uZ`oJ}ZuԓpfJ iwjyOD͑KqZɈ.؜èLJkg\_Hה a>F4wbEקʱ"uXr *MP_2p.d6ݝZ]OSj;+Gz<[$7GM!es?&Aj&yQQPTJQ zYA(GvB.&=F~ԿjN3RKZ- væZ1эu^m+mL!P<@z.RIdA;D>ϢAJæW" utlTJZd*Ive𬒡wJ(pFȳH0v1 ?슯kHg)hLWbamk9BLׄ*OySn&KƖA#* a~ݴa )5¹7xL ,ŞжO'ɧf]Ɯ(xo#G(KϱYQ!X̐%{ZP'|83e $uOdlmp4L(N":>9L`:ŽlUώAmG G<̊ W=>+vO'Bq `_c_zȥ}Ñ5T EV%O"UK^UZl 3ci ɀf҄^G%SW+y(Fo3Za'|_.|&D ^d}䐨??99/MJ^2s)t*۞b\|XwTk/2/"e#ypi"8BYW&ƮLb DSj{Dɽ1q@iP_:fL<E>򸓼ăd=I&%Ppz/d*]r :;ӂecٖun=xC < jR?B=)TֈuS \zgyQ:B晉CIsFiY+KZˁ2b#ܬV6Q?vUKQ`W |xDg]"{@T1[W^5F΃zۀ٥+~"4x]LQ_`ύ8hã <f,:faRG"!umzFiHJsZv@~IyY?(= [J__B)4]S\QCH8e0A*4%Є"3SjX,k!7Iy{KOlxLq(t`z<_r.<9&S KK?ݟD1ަe'[n C߮G: hE};PvYi.=*ȳ(& E٬`(O,EZ8`_~j4sk6f}|+FRY.(Tڿe`92 D&xp'SN!k+Z ;|U|$2,37h.ep/F$ZpcӮG4鉶pVS$,9nk3@kȧʽ^r:?y2\|e!U6`kli\a|ÙQϤRʬagJIq r%hqŧ\.㎜׬SFqBxSV^MO?L} 4+m@ GI['2K'=[V[}8߬]/dUEM㵓j{|f.Xr @Pj ͚a+ \x,`s4 O&V5p*#HÀMN8PӔAH̺x`6{7)v!@ PT8ta4sIf:8覜A#PŜѷ&nXI#1w4ڃpͼiɄt0!P,@I2I#аcE9oM˕*zfpCҫlj'_> d§b Mf9i,j>GdXZ,;28_c!l7cRhh՞n*HKz]=p>U=B,h{l战(H7 dԫZc{y3c8t]wMԊt?]/&nz&_A:IȓȎSvPCBNR ۇ15Ǝd-97ޡRMMoƮi-^hG){ C e8%pθ6ؐ -സO*?K桮ðm,2ggԎ&!4 \⯟CD4j!ur@BQ/ӍފfTټw |<ˁTL ԝ(fR𺾿[b9mۊt P!yݞl 6&@/FuԮZrCCiKȭ dLddOuZOW Z{Q 2B@Ӛ H/}x^ 5Qa'۬IWZ>[?ʔ"KcPLXK0C(iʼ[,QY_VJ䬲(5?$k<#>,˪+D?q9僰?2IQ#TOcr)IBԵ^7Η2? U<4ejN6kK}eÕLZ"FsSxlcij‚x ?W$qJ&"]ڵKHU씀/>.{': Cs>M2vT&Ԁa:yV(} 4=qq "78^/Cs^ *FuwUd.<[qpo9;4,DzͶٿYNG0Ѷ-[O>Xiaszl!Ցyp,6j:؇i2)Z8<"6o~-vڢ Z'mxX0LGKd|@YQ$>H'$Ff(?bd$!Bơ@A4.Y*r$z ;i}q{QIwu ZȠ7U!o DGAE T$AEp% Pt =S(ޫ_*-_4ծf,d\RM-:Usq%`LqtE+%*GmnXǡ|aF}y ۯNaEh"DT'U}0ƨTq#zK m K!JbehnVixj`@V,$–wU+X9.YFHlmiS-,Q(y,|_/>hJlC2r+-J`0'4mJNӪ@On&\xOM]]Jq'vEb긖PևYseaȤx^N o($;ZŒDJL2 zL*3O7do %B6{28-eQmB~k83vQOsWEqxWPڀ#ו30!,AŨ@ LRwl{$3n-?D$UX ~9(Y ,0ֺE߲dpYrŠȇ[ǀT ,g^ⶲm/OI$l^{*฀'K Ր4䥕sD@Zƴ@Nk(uw3oֶ=jahK􆨽5KoǏ`-bwEWDD!kw ^T2߆J%c( "d ?M&J\wvvQU [@4.+R؊MJ~N\u:l<Ԉk@v]tUHǝ7'"R"Br)ol&N/ 8 ) nwM m8ƯO[꽽e]-ۂ\:(frg*~^o0+B1Z,uZ mSumS~AK]?zvur(h`s dzD?s0WæTO\mX,'7ZO,&hHDQܠ'BmHSz0^}B|T5n;s3-=V\|˪ZWǡâ%uNzjH 0`W|}`{ dZFƤB5YVT:1 0Xy@/qd7@Jܵt#X~tu @Eqΐ F(R^ɹ UºP<գzSۣUU c T.@m-s35,[;`!iTF7sA"x; -\/Uhn3].g6?:g*yH6߆dևO7"8pk~Z/EC&V_ BPv[éѸRw<`Cdn߉Tuk`t'j!J"_1=1LG DMbNh{RΙfNcZn8se"8iCVMȡΚ(+3hںF$k kp|Tiee`3 @elt~Wð,.^E`n`8eQM%Wv[3ahG,Um/rxf0&NڲLj)8(]>]KN B4%kĎW>'z{ o6H)I 9TJPSūZ YM6xm'Ͱҙ%[mVhwK$&U*ү̗I=STsn[\}Jg <_=l{id}l3t5N U^뙴TWrGe:CK< '½<[x,j6Bf^6xb2&PApFqM@M,= h1Q. XIe>:dv11w{ÆIdIQ[goEt _N;W|% %9=pZq4H;W=-n2cy.TAK_F2@#ƿDŃÐ;ј-tQ%jc!rH3&9q׵NWM)2`Yws8h#FVb.Z0蓎b$G s>%+kK3Y{.kzqwsE'ߤS#㫄[~uE囃Nr u5E67A TG;0A.T󒃂 ِAS)^ohQpĴEB6x{^Е]B{,=:R'u`1 h zī7}Dw.2CiԋQ=1}GKPlCE_+Q&FއU vJ<*M24|&~"a4\Z#8 &Yḋc]ׇWH&( # M02Ѭ^b{chYeA\_! v */ V͝Wkg1(^au/1ѣIh=z9[aVz,WJsGyuYFzG-ݞjU9"f\ vM3F Ws]wra)ډ#1z>P`40Q(Cw= en]`2p'syPI$fyg}9$I~wG HV*r,k9LӇmnhs'}괛#J CVH5I)3]nn̦WЅ,1_s.UX@klx+zRRZ&K'StN*u)遖e(W/{K;]{Ž%Qd4vA֊PL>IP.89"CǒGXu * ?ԧͺbWK\81L -v4eYBhl~li{*iF٪O1Y$,|Hv,ܻph]^HAԤ"ɡSl\c 9Gݷ jdsoea/á,IߖO( >ȭ- O0P4)7óTOӰEuDu|R]#6yi ƋigޙxK=a@TUmPmyTxRK3,t|'kSɐNh:(Y*!biAǬ= `*̻笱yMJ;.`kt&MZ=UǛ6PybvB Kzn+^Grtvo/MYNO-oˆ $eC̷J^%U4XK>)Ǻ~6I;y:NDBßg<1slV]C 99s=Jc=E1󊌴T !И8]c* {ۼ"yhZ^;QB$֦ـn0Ň,f##.% W% ·Ԉ;z9F,aZ}ov:#3fځ&=Srl8!.#]=c=Pϴ4KO9/gMZᅃp R}} cu؞bWXc_b`\3RBϨgJҌwGMPq\TK?f]\!n]-QҀL5Kz6$$\畖& w]/g7P$T>-ŷO`̏Vwn ō2¨A}` WbAΓ 77;[$:ȃܑ`ʭ6 Nce[W. ;68B*{- 𷲌sj§?.GDD£`gU*y ypVQ0{-#'3<8i;? cctY{=nzzU8ɣ}fR0>ضNܒJߋ2ߵ}'u /,ZtB\,lIYsa铧&l -v抙r+~c%Fi }Π3iD 0R!v1竬95LWHpa&y0P@LL2&#ڱB2' ɕCB D>@jA%xBu!jZ‹Gd&]ɉuT7xx}YXUx'>.Ζ(\>7{ BƑdQ%T<w` ˚PNP"}>E|uS6+y 1J&A TЙmlj-[0i>m_"PRMy\t[ɬ#I7ɹ-.]l }!15}}[J>4M0x #_+cF@'`; [}e$05ױe}_yhGQ'_{kKG*h[\plDps÷B(j˝Z 6Z cD)2G O4d9XՏbSF|4'^lߛooٽV ^7O~O3("ì?e艉eAкQDg".S@cOÀB`Y;P)d% /TIIZ"sM f&Nt.x= s[%VH̍EXq7ֽUP Z:a7];u#)KX4H))ƌ"_R"dq նI9߹W/hV& n֢@,@NT;#^6Ǭݞ2o|p#s#66q;휰 t6/kBƳu6=y/0!H#ڀ v,KgIU@ fuR#˘58*[YX.m,vTl 7g% k}2?nWm($$6C̳?7%pN JRD:x /^1XS&k̮AvŃ&&w8{4@=t$[DmD9:"vjŮҍy.>D!&lMuC N d=߳x4l5ՌSaӒ쒢iV$={ZWw,p*5N8cH:YRDƀτlіUAMk~W:13.p[]N4 6&@iэc<[d̈́Z[Rb Daups(uMP:Ssي_P]6>M zsa?zO$T 3$(H [~m4*~^w<WpsɁi-"z6z8O]`a7 gj`pZ q>N:} bGî횑$y}ƒTz+ Zx ڗ&  sΘ_jo-$_Be2+diȖ\^M+ϑ~XcŴPW%02%g\ɪYkJfq7mLtD(tTaX_xe@}zڄO_,_vXw zRuƛH +]4/-7c]l-X샽JT>FJi,~pg>vMyS-(@K #'8/Wdž; f!ŔI{\w%~uc;Sӫ!UÑ^1\,?$}=[e xim,93S },@H"o7Ƀ#CU+/rw_X o˩nFWn(fdkyy7WYҩ1 qMZMH;Jh%%Y"X_Ԅ/\Ԇ:d;v2SlٻmQ򶪲ީ׻8]VO?u$oPŇ 11^?{62,nDJ6\, UsQOS؛Le<͕:t:֡ҞOzd FS#n92Ź=r%Һ51^Μ& Nak TzFQ)vV 8wՌ5~ge'֧0)QUѨQKMbH)EdproyI[PZ5ﻗ3 >dk@j4έL,uEԠuBPz&:46ឱ _ qVOB4]r[4Z@o xwZF 1Yt;4̇?GVX3 0%{L\}oMjRese{b.nz/옇CA;\iŽ:m.ry,1jTȠ[7&O|j9oMX#5 Ʒ/b¦fϞą\cYi>: ]OogM&R_21F#i)= F:~]`QB p9=/Јb@oN:[&W"IbJCB'[ l6x c3y&vzUilb4t4#́KbR}}G|ɣF60o_}] DynLH[/)<V'*؆aCx"Q>l04O] '`WAFF}S.waf]׶S%e73@tN$+:qGl0+Ϧ >v#;P F] 2Ns<<J*=^Veu9mejFW  ZƞGg)cVࡰ{$e}Ox )8VanKь s#㊦& @y' GJsep{o6Ҷv`]O'"2uR#cV/73pwT^Gu^BəXN-W757l 3jw4qa8MĭAK ؍oh=;jޅZ}p z'[Pe5О n&[du^lK pNGo +1 %~w"{}b~YĕV}~gl"QТ DPgKspj,5ux4B d" %S _t<-- Ͷ|% "Z^+úQ!eJ'/hUIA.~ E/BjbkБԮNϰ kU~$&0vۨSmoq0/Fb_+"dǴ#5&*VoLNeCHB5HFYeEY ϸ^J"Ͽ58L8^ P-ԉ_p]n{23m;y)Lآĕ2 D/' yD5/XjTT! ig댕bd@ҞD IJ9оfdyq0nȃBPn u٫vEHxj\ԦGmG]ug dA2w>n2^N`5"eU 9+ ñ~^6qo8[!vQx;z uOΉ[~kfD#q]Od鿣GuL}VzLƙ'У ԜCbJLj阵~.!"jX y6HͪE#Ge"aCzNapP ]j<5HWzR n~GPrNX v6,T.C\c=`wUcp M0eQ)aqҽ›O])hܳC mGCLrk.W%E2ӰqpB : ֟i3=lLXLo6G+u8}iRm(.j-Iؐ9%a>C* AM^9ٛԏ)&mwiCPk&$P>iOƕ- #H>- &ZϣA4$iI= `vTuFUkF;7yn5yu]2xxW_/u7VnAAm 2u/0|>ܩ0&Dg*Li8P8\W}>-!ߵBͻz f]8 Bs/6 D_msw+쮒&V=ޟ.\z2ސUOK9E]#1@'(g]ߌuM~+4F0BHSdʼ<\.nk5bo9R:P0̄zvP@$#nƘ;ǟҬH/ҭ2|PġN%7qe07 ]]`,uUKu ̋ ilPOk& Egz KUA6 tN@^ 2Txbg"bTp>f`~>S;E3<(9Mr "9VMH!{[]#̴FЎ~ncZySh l/3~ph3 8/rQ hژ;+LDTȠ-i^/fxVτHLN'S̖N'ƚubc>&U]r&MZgKnF!t`#5Y;\sMSzZDQ NczU*ÅČ,KYE*A'͝s2s%N!D!i"`B" ߮3K+x*϶t6O9m:;Oǯ]BWs) IИ~^(TtcbY&iE\Yo~* 2u'^`viVXB â97Zb"eP%0.XlS4YU:P었57)Tz.N!$:Y%mGM8fRr̷^k@0^/ԙ!Ÿg226↘C1q Ol52: (GG2Bł]MIbv'&s1i$FQp7vÑkb9^b>%)Wx1& 1^O" G>o6Dpf&߀rZuvAٹ1Tҥ9?9Wcǜ*blHuYuXE]~[?-{\T2fR t+.2~Lg3_|&k/ւ!gVE/?7EKvn]}2x񦺶 7_xϰځ8 1%EP@hQSjڿnBچkxvyF*jTXPY9eMsƘIdzŶ/6HG'ώy a6X ?BQOV? WS, -:-FFX6H,>`KN?-!Qu_I${:aQzj#DB4/i|Cu6>ىQNCM{L9\*/>N&IHi&li$l߀Qհ񌠤7,I\(gk,H&͓TOd'mlz'gƟ)xpn1X3RՎ$KDd/!-DtH<>Ie -aw6v47>Fs\2dǭ.` 5r8*8:&E-!&p@qҩ6v2j!`y5ߖKD,%sdLk/^=2m g#?ct k\taܟ(?mðPL6^3zKrtSaMݮبUG0:K!c@L3tw2{vWn'skIԉpwҨHu" 606Vz]?}^92Iu4I81'Vn3:L&*S/cw)P W aă@GƫjR.1j}܉x]ܦk)6/2Gxia7A`i`$G_$sXlh\|Ez7- Ƅw=ZQP: TGm@ $`>Y O#|)'!AmyUaq7!cpV;Z7ĒU愐SE|s7iKƳ+~ ,5 2DDOtFCjΑ="N< #}(̩8_D+blq0RQT5b-f9&oVjxi j9f8pup:hz&opBb& lq1 J@R8).V/6syd?(2$W,= 0'_ ?6 )m&+aGK[>'5|;F% I)3I+۟I?ص,ʍ] WQKq{va>M6zCKvTqBjb|g5_zdJQ!@9"6jχkZāmČɃalNuҪj/P`xmM>M}"õf+m,FXVcB'Vjׂ*I$CkjzUx4*"ԘMa1!gJ]. ^^:P q}!!z(:XIrJ|Y푗nϲť{b-f9ʱV(`p?͗a~Bm>}3>f:oe<0Dq:0چ2@c:t9b{3jJpYY|%}̫A'] ~#h|eV`Hb'cS%l2/s.qn0#J}ݏuah>ăuzq6A MgVL'J"Q3 0&P"<(t&a!S^Bڷ4 V#)=<\~58*+mEg2 '1 |<Ʀ'/%ET@G=Oni$FAG#`֞SP/d,,ϳhpqũubD''7=}mi#=}rheߐY(~g еarbe*t X5(YzoK[nXD<Aw~$\)3 k$ 2΁LkV<(mf$ïB\$V[+2*5A"ka ow"Cϓwbr4[ojʧfqņ٬ȨaSՅ" J^7fD_EqgcZl5c_/-j ":L*}CٰfKPR._旝IaR*2-KkgiU- `ϡ%3v>v/v~NY\́"ݐlBd=Pc{\b0"5" #(ũ \L^X=b[ دpqȠ2m d&6lVpfܛa9cUJxſ}z'cΦ،X Ts A-έl)^ 9<Ʈ^׸poW>,mcd@znY}2"&Ѱ]{XE8/ iIy<ڐwMs4.0c&<F@q hNIBǨ虴l'0lb>(ź_5LMJ1q~) nLޭÙg53Ev}x]^]t(rC1S;eKx}_eqh26٪~y[JD2 PQ-'+;"[BxP,.?omG7T"Ռ5IT JDWKY,L vEGL2+BpdYO@|}K"j|p4u!w"Kz`~rbjtuVUgjtE{! "=4_-mz)qu=xxgE ̃^VOi^v<45bC:MHJX*;Eo{bRt651.{V28/p$'BCN6D *;Y7y10^0rne1z[ѕ p}iϮDw7FO:2RQ(т@xgy6<41\O{o3x/6 5ka,jVx:3$U Hi8$-etN}2KI$|Ԧ2_In_n 3e>H E8tuCx=I6B ɼ;s /~4ъr@liP@(FYDAĤꙫ&aq˵v!_%Uhe4 ɩC4d+r&> ?jnV3_1RF[vA)cTۂW ׬ {fb`7֬gS.|+J?T&3`X|1l_ O@ by_y{Y̏t"r ^ 4吨vAPˣYU6#yV֧ B&Ry5J;X+ ӯ*FF pg|RN3-); n7T k*N:kVx_0$Ii7`ar;wqM8ClpJ0~Fu >vSxSn4[ݽ%am4AqK R 1*gљqɳyś]$V`7*|M$)z;`_a;Aڏ@ӠYa0Рb#n89j@JZaγt€zw:7r'CVrh 6E(2C?vY" slI?VfO >ɦ ma`j^[<Su9pB-$_Nm,DAG[f`˗5Y7CL`Ԗk(,zTN\zgnAx9je|쥥BACs9T}"sRj.G,ƅ&KoA(cGwHփ̶4]*: ?ɬt hJU{thal-TJ uO^'ni;8t?u9ʽ["hamCp,=0ATSGn@F_JCne7+uU ˢ aB-'V&[d.WxfwZy;&z?Bdu-TjZ|Vlk S?vIpfh}վrygg]_ 5M_Qo[ttrÏm9 % h<5HB%ǩ3@PE+{;xGd/459烺33P&ɻ|^Y|إcƩP=3- tͦv7}k[$.~DF2:_q Ht7ӤKe"j]C% L< u^6"L2Zh! o0Jbfȅ N*16tQ_P ڌ;HP__!綷 'z|\j?AVeE%cJYd ם=Gj=4E򺯙K`(@OQFRߪsfr F_ S) ,)kaո=uv$+ץCR0fk^s1#=< Iǝ=UDs%.㥅4fqT;y5֝rƪw؍.6^rE=zLQһ Iz`u(nܾe ) BMugFpkfaT=|uSogϡij/qU BJc/  5HV>HC T`4VEq@!@jP~0z_Q l/%=tyULBL}h")9Ǒ/2n}haO?gM 8rl?7yYU?LU[A, vؽv/*zBOx.پâCG)m'#TNva~ +Vi+!x ۶> m";h$6(/L"ҼĮ]1?"ĶpGΞ6u@0S3woƖ|yk9G=䜽p^g!$BD>qz[ 7kF_) m-GYHic~&gXC!/㺠P[8S9p; TaF!M)ҡGr G&eP 8~{[#2PKçjP9sd&)~׷]G-cgb3~v󏑼VOJMH fNm7zK@9ٗ ']%L$g@T6ū4L/-O6y7.6Р׃4Y R{ YO{ 4݅_5/Bɖ P<] a.;MHC:-N {e!!KlwK܇RohpFS5]F":6usz˔e5E LRD/~VKCI;+ T/7049v lQzool&!ؐk .,,aϯ ce\*'qg|Ҥ]9~w)g5˾*5(T}ϙҵzdnk!v&qaq&9R٦kq/Y4],NEi̮ƴbv3C B:%.᪴" iXøOHaF_ J0^D[Z"fhYۼ$ W'ۤY aƞ/.' $EJY@@5Ƚc%PE~E uTWfWď1w-=P~ .:6tIg6öZݯ[- k\{w,]{c2$SXˣAElzBFۢ x ßbkLA+4 TuJ~e0gOI8B {ԢAS~Al[% CE긃a-j+z;$PT dJN"caj?f|Hck]3=g얡N"VWp{yzDm')znۻ 6Cfg 88%hL q~T0()$Bb>TھF'|Vˏ€6lSCiZf $cJM8v6HExm*"U=NK̝87L㫽m<yCߝWZUxͳZI\a|7[iU.Q0,r,];M_tp;$X:(QGhvӈLZ gKMđnj~CFp6qp{ϕp^'ߔrq֧-"AIe*wF=jE8@H& g:DQV!7sk>ZGQ+l=X]UuʾEyۉs[ܹնC3 y:YG=;~99'J!{d}€L_SL];9E} *Pp+Z$ W(QxU e yC]kzr*Okel˰HnZ*Y~)Gvk@ B[+Βia,#fc4`27UfLrmVB_7ޑl %?W8w+}h15$J͌t}d䢉 VBm$=CsUZEdYdL0Q hJRB斞[pܳoȫvEfͼ\ÖZYM2J_I6tj]]qAB}j*4r<}9LA4b p`0{]G^i鋝V9mb0"2lOr*9ckd22.gJכ \ o˜qyK';F僖YƫO {/*Fr9D.Jys w-oo3g5(FO d\X.lPDPLq:;'ʦ/:r̷Z>aA? bw[ĚR#6Eg݄wpEܣhS]J|۹dp;wNOWJɁLք7ME%G>*5xGCבg`-^wm _#TfLJr8 D]Bg9nn݄ vŌms qd`~LFYƧloy @x_E+"rn~߸vma&kNzsG,"ħ{tۆl]+@Ֆ>I73Y0'1a c:d[Rk4exi`zzp}ݰBa1p`:ȷ e$!㿽ԀL~x obtAEH$aUIb@w&35 ۫2=OPjil-UD ޽CvnYP[(ɽ?Qɹȩa\睽G#=Q$_'Ɇ.N68x }2gvahI ]9m"3sy#ys·UfXF6H%U(a U +Jz"0,gK&8Irl7uehS zeRdG4Wg\K=5\8q8ebGjc !$O6d $66ԅF3zuЊ^ ?,1EdYr^%T#i+5A؈N ee]} B6 #ɹV}o)s Y^{S_ҤڇG݅  z< ,Q!¦!cM|CΒ'9-GdPsMvzĤW1,f5 b3+VV Rx R\H? WDl:nWK'F}T94s`H #}[?Fֱjݶ6%u.-G+J[%[rf쵉7 Дo|8W ~Lbx·/c*Tqaۚr>Wڝk13xr"Θo]r:&Cu e'h]G_;S @j=o%EK]Cvnldk7O<}QTEIt?1`K╍'2UjP F Vkz 32 B*FܯC|P `Ig\ H&ԗCT )$>GnI.u!&s=ƣ,.s'7~,g$=Uy2qX5ifDONe4yWϔk="͛sz^?γ6~f@Q6q:~s8K+>&5,eHGOf`AΥMlb*PlvH|BB>ZߪVZDG_X%L%ZQ^W\5Oos3VݴCM44sV q9-zldn'lĐ{|>~Z@AqGJ.;5ӈm-NZiƐWݥLI@1D:UĔMt mDq;3C `G}W|lU>pWdA 9snj<EPg{:ZD^*s֒A@s$Ԝ"7F RRgs7m!FZjTLǮS?DFL Z6(d*.u`eP Ee,Bts<L:)AH/w~>$PPRL%SbgDAd9xr-:epJEDJ adi3Ԅ$ (87'g׀Yo"J/S7׵k uɜ^td`8+Cq$p yWE&rK45O182WT t^H*JD^]wA3U(7$yQ֑{GeRSV'Q>\Iaѥ$gdzዺ?Q 6Q&$*Y)M& I!8ߦbn#+Pj'!tF2q3qV7EM(\j8ߦatc/!; y˚\e',n ^5 .?ٛb:t*wB aE*4u.J~ֵm\+Őt硓I,EQ|c1 ut mr7kUϞ9f`.rTBWo1ۅ}6/6gH%j@9HnE?INzeg~4C3eu*s*VB0r92 HJe@tJRQ":Mh\uc <[Rd$MGkl/t0lkA՜2}t{Bl>. ǁ). |!,̮fCձD }t ,I^|vX>FP QCZUMf91/3Z s{+^T*wdň깺x2v`hsDt]ۍg P BZY]?3Bo_ w]~/gva1R=Vo%i-&}qqH,[UmԉuR[ ?NaP\PŐ!IKm-Ș̊B ?jZ"x [Ժx*@yE5~86Ji`*M4q.5 <$Y2tV?<嶳F}ѭPd>K%5G,'pB4t~fX9"xZHSދL\TGyr $dC۽hOT4 X2ZЕW`=:]MdnnZ Tʲ>Lڶ-DzXj[%w\7AN|y͟\+&K07]9 ΐAr#AwNbM4KⰄB֨{$3!]n #:i2~ÜjwlfL*"7qc-`pQ:%xLۡ.!xڄ1\\?9>Q/GIKz%zUzw QEh22ؔRJǒZ)r.3'\-oϰH| [>zHq#'C!s& s`<>u2Ж6,-]8 껚=Jp ł7AEZB?ƌr,WLe[gćA)8S`6'{Xތ;`\SӺ$_sǾbq8k<-nY e5`FecSYb3+X Yg@RRL`^s-Jk!FRĴG6YS_VJvb6losASl16]LW |~Gf((~8[? Ѳ.f p>E03;>`@߁@M#O{꺄:뭆q'`+=0WDnzÀqn#$NDWb/Fv̂Ƥ:G[f|T[IqZIV)f&_I"\学Lg4 \Npf onߟ5kc=_O~>?sv4vOT#kzql #2؞6Tu.S5Ks;C20Miq*[_77n"V n)5 B''f\Ond1iP#hPbs kn/B#fܸ\\ kmly8 -4F,GIEa:>@ezq\u o G"9=JЫV8%9F_ojq?G+ә=ן؄b zP øch3 P3t 4=` A|A3Du`c֗Vʬ_}#t~ִiDy9'M#Y_zwCh3 NZ$r"#PEcIA9v$W…d1”"9)qj\csiTyFu50U2[ױŚHȕ:̀ty2 ~x⅀EXg wȘgGnQ\#%74C'\GB!Di_㐖ʹ'&ţhh1wpk8&qܨZyg'J6EtWVZ$p\rzܮ'|RR9ů?M|jr:y4bI"9HuҼx*J@ot/G[ץIIBB */ %On;tvO ^DSU{9Gjt3&o>5߯Ӆomq/gUs݄_M ryuSaZ \R;|0"]I?Um3|S| ˓l$\Zl[.AdzBA05U%4dqM/BRZƼogo>o='k 4lB^ِʔ/(J-|eݎ271%Rz|$XDAr8SP[).3vھp4>+~`QAߣI )_nA/6 6XS'>׏<fKi,,Ωp"nsy^΃@`zNIא"'ЩT&OWȶMb~Z[5^o!i4kfDݞ^XKu4'U+-GifGzx>$+ޅO~/=xϾPϢnlaJ׌9,yL_sV).ɟbxBxSt܂RBi&{GNx 'AKkHJgAp؝FQg$N.z0nXUX/;5!8?l>'ǽe&]J+_1-2xZG-yM^є:aR)}29م#ĂxX6EZ,6̋dae^T-I6#BG$6k4ծ~kWr ma9"tAʸ% C:F^&ahŎbǹzŜC@o[ugsW><&E TRH/'3.X2)‘bbix7++.IN|RoJoME")F}=wJ'dr f߸!(-BhW['4҆;*b~HY@xֻ0>qǓPn7x隌U,E#$FB$B8@g)f[ +Kcgc'ٮ6u2d[?❾/Wr%9Єf  y#ge@ė^lme4a YVX#W$"SA"[.~)Ѱ ^Sn;'EFG8=M q^ Ԛ-?f[|o}6Jbvvk h TӂM?5G)ү}V&?䁀QnbVSf2QFLxV|S׍"wz4oec,LS^8,\@x/GA>V^ &liI'x.;ћ'})fϤ),M#B`6͟HIbQr^yW0҈ IY0F i5Ha t&kF ,mU22 fPQ: TNsd$-:l=Lf{;|'%S!4%[gl5b8 }b8&>h7tm*GFf1_(oHhcy`A:`XI[Aw<^MV(!7K׶>K5۝DCd~nS떘thؕ5b3s|4uYie* |orRIz@NF$% U *ܛՠx> 33j@UQN.l'>y1B48D'ڝ$>>Y{ tp X=1y'?R0Lls[Da|JI!.#jlf6 [ G>sfDۡvWv㽝^\;BSHVIU("g&Ai*xzw} *QвF(<:Jƅ3 +\:s_r6b;-W棷RʞVQCSh[Ёѝ'@(9n נG ~Њ9^{ZD!(kHzuc|5("]Q _&v|8=?HdӼQNYr\@ZzCb7f _HQOVer/<.{>BQ#bϥ cspJn-|ZԻhW@^"LTNnY~8+#xQF"0=?g&G4w}lts`"JA }EYͯPymL`i=l:sRIiU))#}tvP_ljPJqKo"Sr7usmƥ)j+Utq7A")w,@"-'f/ift5-oc/6B?o@C=H`NʸsiR!IJqvOUE=dlx?"ЍV`~kЀ׸gǟ( |fqU2.nqڶ>jemWKD5'OaеtM waS&S&AƗ_뷯:jw`Pn_1 퐴`9ۯa@X0˄8(`e؄xr]+$ro|K̙(?ȶqY$c`͊VF:M&OK"v>^O{0E׺zo[gmx߃ qEtՊqt{yWIq 9U)N p䦞7^ yer%2ŕ!^I뉎=PW 4r=?ьQyٕ ?]@u`.|w/Y'iLу3l_s"^< #ǚ 5oPVɡe<AUeCzđWҮZ..< YJ62wZ|qJnęPVDrT܅K{[T"-)M(:~t(|2*(Kՙ*k FWKe'uC;p8<ձ_u9;h}.x6x)xyGT-xSbϯR*nP.?j A?4U 3INDO8:ݡjjYQk'ůaA}3$Ծppf*!aIzWH".n{˽xpkN*)GTYS) B9[c'~KN{gIN!OnN5{ĺ #- G~ɦH5iUC_Wue'wtkNStQLl,/)9;"#}u aؕ#0!N㢉 ( :$$l͛ YK>Ս)e4WV? =P5mC1&g#H$svd5l\f`x /q9t_Wb˴cfQXmYst1DB_zނ-:a?deMk2-fw3j(=lKz.FB VP?~`!$ z{ϙ֒/E* _&Gf66KPsԘ>3\%f፟e:mS'u= 'ϊyTEe. D0zONI&l@YVwe.XMlr%O}߀Ȝ:]ΔgWIqK ? ^P"[ʾ$^uF!$ 8M'68ь#]*{T [AF`FyS΅p)4*@X LmYqL X9f- oVKL\" #󊪷U81bSvj-yG&>HdGj1?/BY[DQ2H*/ז /xM_\%a"S6laRIN]In:<.18rY$_ѨԲR ph Y^%a*:L69 _ZΊJ>DoBu5xxƇqQ_/De:g:geY]M֗@II=7 Dž-J 9ʮv4X~Oۍa{.)ѫR| ,p]|Ex0wߌlVݒھX`/;U}0ϳ6 uYҽr=71)q Y@OR[Pb>:e蔏m ("Xg_۠|;$ 1 b0̼*ŞeQ7H9T\ bV߾,]|/}A.^P_;Z>RRtB59fY zs5k>'^bΫ"ڀ0f%P!w[YGl^B~@$~Wߝh$U1ѹQrWmf9?;nkʚ 8!N0ƤvA]琄-ͅ?u6=~^G]@HRb\m'u=Ӈ F{d7d;mI&Xpc1Ӟc8'Zx5$و,`9j*WG{.>#+*]CRʏWvxuM(3V̈́?i*L ǹR ̈́ȎV5 yaa/km0zU?e xm|\t{<̫CJEP3+ !6||0h臫k}'ui iۨĘ}plex?ޜ,Cue4>x/ds עrDëw\;vvQsqO4Oo')(wD6 )FAhI'JH7$6j³ vYCXJnq򬿘n~dу&G y{џzu 1ɫr!9y\8 Tgo+Ki tf@~y\I,"PM~]B;Ip͊ɂ}0"v{#2+"85^+>!fQlJF!fqR*:-+ *;l'b)Gv~YmIgT@Vm*$8zK廊9ޚ<ψ{:mFh9)1 &Y^\kʌ[ e&Zs⪹t%ʏ.^[y /=ƜD=zjX0o+D`q փ8Wsp-;PXcR\π 35=i|ˁRn_q&#Nz6 )1HkTӉKs Hۏ wvZ Z*H怈G3/ ,~Ovut/;9ʟR #NA21p^c[v9&YjSFk7n@ 83:Va0#c/dZ/;ù]]6}(F%EVvTtu  HkE?87̽M1CW:3p(!*܍x׈$3+H6} `F!6n%)I lA 0WL‘{'_Gpf EPIb'rJGTCgu|\1r[2X]Lm;DU5] $;p`&3kްq=Y6hFV~U%`6 `4_m9O qA-dψRxNAv8>|;MPص[ 'L}vN;jMHtdގc0/e<]!5!L,G-ٴNcE'gUltheX 4w >b6rxrJoW=9Ve[1O/z~T ߷C%+Ǥ \[#,{pPSH9{0wV{q(׬U5 T&isH g>Y f66 <е<+?M)jlZɵS1K@Cܴ}䪺D~'J. uFavzF#qWePz/#ٵi e8A sY l S|U?ٔ/5:;MKB~*X[JVq.+*Ŝ"^+Og<5~se|#k!ˍkgX\ZGkjwLNoQ5&@w`j7M4m齽nw0)"{J~G֕ vETN~6 ;ujю&HW9̥Ȉ uyB >ժVoW\ yNt&fS/f.Pi$MSD(Ka6Z</%@2@มWpi[R|Q³I1jwٵuҺqIװRLa!R9IbP)2l*j3;R.Ig:6`XzTB69nnED3'O:н(yZmP ns I,ɪs NU#XN:< 3.NgqrTxpR|5T {6(lNs>#U]5v% Mw4,Pw]kcv7JЂGr48#ek=A{n읊߷XGBה-dÏ+Nuupi7.:LCC(Kxj5:nFo+i{qk@f =6;bsr]:+@&#D12>QuRR+&4Y*x 2wK 9DR5{ =K F'r`i>]3ǑfZ{a(_=2x㷱1\'&煶i7r4SsXy1aݺ50H{<$c!"_PHѼN ]y-7aũnZmk$d>p2O|?A;38}4>_޶gA@h)d̈Aґ B]c)G#[,{47rP@Qo$C5ʀtM BBh©jj`HP|PO骖!ÑRgg1Gx"X*uVl=VհVϴhf<J'{dH8[ש.@U _/X2 8>e> e%Fc y%pX0X-cǝ(I:B\g(V"vzTm}_z7^=QLFBW0/'N;qp6fwnNe\#DfKPt n,X}:GnklH֦@XK<~݆0u--rGh&3*BL>gw$hG6R1,O^54l_;/y_.eqJј`sadzbd#˺* )#N,B CUW?|K+5 j1^|MůX畨TqfTBr`u[Pɗ|s7eMYPEL,=hC=Tp߄^1pt>t{(Iw!5둣u7W;wK8p](#ԚnTM!yMmr_kĚrZ@M*nVǽ$Qq5 ŭ_Ki5TUz7sϐg3˿Wig\tل],?~&c5 *yOsx֠_6K܎g 'ڭVSHRv3;Q{?g/ oLH] ~\"9y}*'; :$X*my/Fg:=LُF9VX`%[w(xOUs}7_u5Lq J- >~\ ^Ch0pPv\7vW_܎ n= g [ HHhP| D8H lgxF&+&Jb\5'nɵnvd^iD,c :DIciLۣ#f0 GʔtɈi E*A1ҵtM jNu|wݳz!3h lόt=ԋ}\q R e?&Y'9c\Z$s&ṁk] ^H]I+Sbjrm:̩3 L}x ^Cɐo6PeUr3L3+IDpk3m|bQ+̃EI(vs~Tg&,.HE 2 g0[,%xZyyBOlxpsR+bRsBm J݈<#a*hc,AS/.hBC⅖ǎߗwȻ0њd `>q eg[T:jjl2P!ػ' ,tA?W/E#C8ƦaGvBQI{l n/Wyb-r!関-/Č9VAj+?Q{'Z~KF#'T4yLWPK2]ViDfҷR E< -|K!,Xz@F -+e6N_։gZ;Jjw^g92Jcc@47f{ܫr6s};ָ՝-k 5\R k|1D <+'GA*\e>} k.)OUei{gEVmbx^OXF<(U pS>9rmv~}{h? _7ED{ MC|;+R+% ۲J[$F웆 #֖vHT^"78OiUɦFZH-7FVj (c0xȐY6`4M3uJ,Xupnc=^u$Č*z9CjS@r܋1˻s\h֣i]{_A=^x|+OtlCG?L\/:)@s2,] fĭx3etem|ƻ>ŪN=S1ģpJ^ .d*K0?ECW kWZOV}7v-:\Zp b5L܍Rm1+=12:5|q#N؛=aDΠOY+p&!U=54=ɱ2nۥ0hu ww%*ΤE.eE=, 6tn GM|BNPWε,*A %SH{@Gtˆ zBy X~~ 03E[GF]!\Ʊ#n/bp#_?>Tve\aKs/SO&zO*_Hf+i)`Ph/VzӢ~1&b_ՀGe87V^2N(gJCVfsfX'&av*45 w&<-OJ;7'D ]QZeo$fG#2 Tgי@ܳzHxġ5*6}$M4FbmOn5qmkj P@AgfGj vގCkE۲ j*;ZPd'}U'4J}LPw6ȓޮ,\v3kDa 5vI5DA06'8jE"Fwȱ/ȭ߭ƃ̰-:ǚ0'\(%}xއl*vO }j~> _Wh}7tLӜN+$Lz0ZTȄ6b@8h-o6uiPsCBG(RЪaT<-#6"qS#q I"OuѣgzʽJe:]om>o3 i=EVJw2? =sߥ:V˕C|DU-@=! TGScuZz~>:?h`Q˳&u;4 ]]ݎ?>JVkZ>^28@ՆJB&" )z|p$8,[?{{wwv)SL `f@'BXhp_|mag IIhWŬ;5Ϸ%VbK׈-c"4_a;bF.Ӄ3"gYDF,?:0x4ŒQ+%' iNq-NC,ݾbC!ic,#,+X β}>s~ۙ\6YH!힆|*Ews,nXr-< f_[_u공,1hiX$ $ӓ ~"u"wHIN (mHĪom lYQ?yS~Ƴ2rwY w]!KOjͧ3'`,g;m VS<$xE2,zhxg9>uh,xHD"2Ю>(8<+83UWo/,a 찕NL1sVTuF4{I=DGY~~^]i_~*`if@(e!Eê B ;Ujykb'|9hmT: +P_peӨ?hCG~u5n}xZEsژ‹GyB;g,*FvG4TeřG0Z՝)8!%Q*:Pۣ k4o 5pf1QOlm͏$:gL[MNs}5>QVFבvx3 pNn14xk;'ն& Xָ_8^zYLJR.qh'턔q@|/xfU%=^/ŞXQyY "u: /}Ii!>2a;V ;oޛLSXO~WZAǙE!sx&0|ɒD3+L'GuGvLORcOd$ u/+1Zsfm }tT SIOcf㆘Gl Y} ;a&Ft6N$ޅ;R]G:ɦ4yչBJFū܍ÐϴF*-n!i~STVRXtCP]4ğ0>2jƺD1n@s|Dra)@3W3=W{Mi hayxcA,]5ʝY bLk|]܃`amfB [R- yMug,{!נNj_,e؝$:]G2j 99ZC@Pin:gbmk7)`(r"ӈ ̟9B]Tj; c|'סݧ._bǪx0mђAR0CP,}b96;VCw8?[4O mPg †Gu(,S6Qא[7k~:cHDl<.!]>+frej=ar\tҀrg=<뾏~h_waPj \!b]#I}5I׀}!g0ʦ*QHP30U[{w]P2yDߢDp_+JufjA4>I LT^wWLYX*p?zQ.]LRH4^J1 @&]'_c tRkƢ>N'Z6nTbc՞/``=ke|&Kl~P=oDЅ[Jhz{%9awds6diK ?irHD14I#핏E>)*!Ү+6_m-ݓ Jjx jJ"8)h,(ަku×-R=KrvlE~Gt%$S54NǺL[Ad7"3:M\Y;+#C^eUN@Lء^,@v::HRdVYqF@5T[D_=jLH텍carP*"ku{u-yJqX ?6N;Ϊ#*B\vrgcfWsh^S%dr*v>ru{E3\t; )Bz0YI6{[p愬2va?aczMж+%PP/\ tn\Uw!?d2߆v@J܃aFglGg7ڜ[W `m,Ћ>Dv =YGgnmDMA]R !a,33]%]H B.}oRBqm/^N=4!`ra׌9Tpjj,C9jx +B}>ŠޕҙU 4`X1(Z vVsCoɉ-~sQdo$?yDsX0߹W%j[ T!pު B)ҡtϢU?ޙ”zʭM%)k o.jA}tR!7wvߨx:Bq{I!8{a'ô_ֵ(H5U+LVq1ߑr&wNPF1`L{. hTZ!}-_&)oΒ9 u$3XͿFi z|^ -! #V8=#A}%< ;Zvxl̬UыwÅӏ}Ǒ)WZ}?T^ZϘܨ1! )ߨޝYs?^:igZhFEH/cF[!NR" PEu>fuJ&2n²>8fANZe |}*hi`g c!}&zx/TR~ ?v4֘┨.qNjtڿv*" 8娑"~D:kznj(vp3>uwHjYfxOIM|m~24-Bᓽs1-RWV% 4EO`2;qQ]wf[i9Hݸyr&o`\ CdNfέ,oWv FT S*z/lA/ JS׳-4%ɔ=;A"PutcfקeS<7=y_;ꞯb{Pq҆bQ,.\Z+]'xb+ޢp5ɏuלݱ=[j.3-,[;F'xU3p]wfN1}E.nY2W!5:V7J:6J4m ;=)`1{¤TG!p+$"`ΉBGx6A ބscfSDHFa,2-7Ki&rZޞѬM ǃ1*(KISW)UG^z?Qf7t_0Ք61MLsUBUވ[q^Y\a1eșPW3(.Rr ;D9/Mx~^#k0;C_51t&"5y}of^C)I5M V-,{̚;dLk0}\Od N=uyG֫U|v;y7}ly[;qNƮKJ2pJnri&sTe)kѠy.57EK%FA嶂p@/^69 m#(-mWu)d. YyB<\>!^]˄Dkm;PVc0zR@u 18|JuN y(dT_$pzQ<ʴ Z|@7,]ibNXoC-Q/t*V^%.4x'sf~|t^GAqJ)+tPnu)vZ!Khӈ'~ _뫊V?"E)"a Q 4_FSHXD0uJxPr|x+߁Zi:^eL'֝w77idQQJ\!V PgsEXSǙ'(ꂦfgݕC=]vCkiӗ/ks~kv }{ߎRlsY]HZC%|݇ z֮)5!Úr;ĈK&=Ma*ԓ#lr6>P!" D/<1z>Z6e;POڽ;6ird폑pRwa0a+c VC.|vAM':BnHTyGA捎ft1%v UI<4f7KH&ORQɏ"xҟ` D't,1V~G% *^?lŞ*Ӿɲ/P `rx'CnĢAgA$>waV),.U3S Zd=Cز R7/Fu >飏wO]+WVZf VwJ ըiÄ_IS4Fӗ&8Qbr\TНoՉ`J?}z DI)fz*2}EbKNkjiv 77t9ꞻ?# 00dY(n|(neAt6Isb9\Wmv!,pqAoMu؜[}0_Zc#@RLȱr[i JMHm)SZ"\"wW.NKf ? ai݄Q6tA pMq`&JwFMJ i*$ >ku\EjU]38ANl12+o04G LDɖWP,ģ!3gBWh6_)B!۔ 2".nTh4!s~A<<'q:hck(Qa^4}|Ylx8kD %anwYE7MzpԽڼ_ӗ{n,/:|3/\R,vS/js*U`Q+ 3#Vy-P1)]0xi5. 0΅:r 5|t\ zo(}%-eÆݗҬcM\7 5Р:XKQh6 Ʀ${)kK"Uh} 7udrYJN\n_T^MoA߈h$ECATGj%!*z4*%XN}-)hlﺠZ(yҦOG1-&A!1քe>Brk O,z\p?Yr@Heҹ,Sբ_Z3?8@|.q> tGvA aD&ZR]lqP*u9hrqtMp+ +&M̩$NUv\n_o2b4JuRir.y7$·;)f m0ZT짊;LOL:8. 7UKCd 3JEw}: }Cx6vcmH |y֛2yRSss ׬5(dW)neMAn{xc$噅h}>@rlOS(晠,SZ(Vr=:@߻KXX39b<{J\=^ KVY(MM@"WQHϨ50C%}O"B([.ad )WP G_,|}Gp\ b˃w174{b@}q6ӟ'@]㹡jXFH+' .DNMf 5)G=o7R?8 /pG**J/R]g5*mBy"v#fKv[S=6#h} DF^.1xT[(7^9,Yt[_r F{_̏dI|Z@ʉKs &j[ }'&FJT/׶ۜz&o.bE͘1)t8zEpcHW_ zVJQ#ԟ֯yu\Si=.7C9z!5&ּxM?@+'Vx84oPKP]Kϝ"b%ՖMO 4_ =YռXaV{ d@i\ @p )O_xz2usT+?\Rhǫӎ*Y_r9 Ί^< & Maj͞ !Wwc7U[(k LԁJ;?e4M+ p+ 0`-JAIZTOyE GcwޣgF_kB$NiB~ЕCڱ}TW8?d4 V2mn>gsXUoYhO Qd<T3\( *mx.~33Kjc^ U2xTw oE鞌8їѿJxkG7^ClJ|EnSq|ZQytt~Qrz}#Co1rua5Vrj-싊[ʔQ/~C|fsSZ:KyJyMx[ZLFm晫A%M$ m- qI²RrWNUtԱQ<# n+"X d=^Jad3apu%Jo3bg0'2=KE*9vMZA#$3\;̨O.&~+esp9 M0/=F :?y4}%3"9I'?.,fa;F8NX+Ko|ЪD4>h:MPOwGQn_Bf^ =Ӥ`w$( ;(*!}e>*O!{EipoqxZGۮ:zwRo)s>%Y,ouAn|~9B_Qb y)aQ_C`NJ%ny݁AW7[T"'e%bAaLKam,DAra$(+at<08e뻢mԤ5(`3J =DW'25L(N4E4x8e0 Er4 _/}xڤ=s&]SB<'6'zf"\c: FХᛲA@ 3aC=C1$TH& !{#9 -)aC4b]ٶ|z! EV~&}cUq*Z1IKVm4%?n8y]N̦N{ɂ7c3`^BfAG~n9m#UVmruɁN}@5^v um?$Ұc[k|L@q抿5[]qzvjXX:L=NB`["DQeCz9_decw_ߣY`cע7z -JstXN,b;''hUhi:MzGW?2d0 (JSsNW AdLae0Kl\$C-[ywt{kO1<2?(NRd*n+719<ɮ}OOh8ZV iu$Nj~q6hWܘ)r8{*]:d)yzٚϢdk7λYFD9p-A3OJBeQ[Sb2D|a+'{ftPK׎ZBi 5!?v0,1+Edz͞˕>zOp o~~=V򦓬[@2H33'mT$=xQwTHQ^,CXhL%.0]b&qTDFlnu]56p;umvۘat|H~ͽHWP8mj=)mZIRIL9+h PιΔht~%dUNj!$X+$ߟ`r&[U]Fh[-/%kG-El7n>}gxq U6uxba?֛E^/hޕ,uŁikZ @Z!!DD1b`|Ɖgx`%n84)KfeAJԹdVmi^;HMJό<KV,S\d~M63`wb@3F'dLWЋE{3yzR%Ⱥa6D{Ű0Ke&CeW/-50ܡuq^8{ï^sֈړ\"| 0 YG %V-cvJ@5O*q- e3/tTwV[٬HoKTB7r-kj}MX6 \޼lW3IS"$說\/XEm+åyH۝*H*Hia\^8xs\%F8t,1\3Y #9Y`$lhg"mL_D <`蓰QU>z%5JV2b"M3UH {[ph?NzRK*)a^ۖHV*C)2v?Ktm0Xӂ}"=۟ct9`G[ӐQ V{2,n|$ttxMN=I] 6gZ@m$"(4K8 y_~N>ވn}d63%\-gz̝-* e wEuya416-cRu(M&m1-5&lwC.ohJ^8Osဗ4(o>gcmﲛbk09CGX-[a$N \K(糔Fs,lh'QJ}NӰ|zuP/{.b=lbdSՑP!? (2]z=}JƃbbJu[ʥWDK҃(m'.晕}j3Շtq})=s~/X8,8USWZ Ig4o6ъUv1K8JM&BA6hl/d]d2lsJ+~tRJ1.mGxX8MhD\kfvDD#oy1<[ R+ms_hbF&o⟃MKk>֐Z+MX򕲣|WjC7kgJ972wT!#WƔCLAD9#PkH}'a蚏Iқ$u"e|,KacTĵzM-l͆Sr E0@ϻQqtؽel= "C:|p1B!/:ďkRS|C%H#&Id5vjStϿH!h;\`&b&~[: 5=jnTʡ%Oy2fM ux^p2G-wͩ)8 kY}qTN+4+bBU6!dܺ&|nM5T+>׶bs=Ɏ`y* #^R*Eaxdw}*Dzp.@c@[bvaaZN]|/ {tfCdT /:c6J<݂V@Mo,o_ӸZMrUꗏ(Nu4mXu1[*o 55ncCQBI=0}yνA7[^ՓgjN|Ơ뼂s&,IOڏѸ$/kT@#:MȜah .Щz>Oj@J;:m@߈H'mQO{JEfkⓈg5ho#dȽHo=D WHy|m&X&D '6Y$ecAȮjUS>Edr&-::rڮ9 Eˍ!YB"ϕ>QuW%) uxl# t5̒QhE{+3BN[wp*L9J,3)}D>eDg qIA qڡII8h0#TFm݋ξ:| "2o%F^%z >;+Y-()mjNc,ŪhIxex N-6Uuf@gN4B k෩#*h%>b3|oXV.$$ap Ijsu8dnO4kKCDM-}?hPFd{ lޅd! ʊ$tI CǣC=setychP"7[NA8=3i NE"fQɘC1$U%7{ ܭΞ 5WӪ }V#(Z1~If=AbH @:/\=S9N $DR! (=)玭\v H1A%8ldRwcTfn6.7IU԰+z6[&\.Nd; #4{!h{\q;/;Л砕 VVKm?^>si;GJ7LJdNA֧Mr=<jkV[5|bk?~3xOQw\]V0oA(ꈼF0=܇AbXAjX!->DI"L dc$'=AƠKHŭmϬbY-׀H!1%;hGA:L`}!UYH9ޑ B4Po}{xuhnR:-5MzKG!V muʔ2!=*7Cj33Ǐz@3e-ɷw_H(\"r.3SDO$*6(\o.`,&5mgN3\aN=nE@ɇU~>5plqكTOl\#00"!Ҩ xJ?Y9x3 V(yL1HrOGH x#1EdLɑ6XS2NX]Y!Ju/.g08'a%46gЂn\̒q.F oZ ѝt\Hx/̫>R߲fגn%//'Lrl] !FuKM0̀$߮@;?)۩bw 0gJXg4y1.\ w.ʟ~ 8}7}{g;8q"D^CULT=o,3O!^B ^ ?LD"'&R`Q뽂zupnOPecסӾ*<[ȏB5j%FkPq?<` ^9R2K77p^J &jPOWq &{wWqȅ;Lg~GLS9f#K}>z=|﵆&<>՚.qfwnyG.QZ$N1UWĈ 1c =( GZY)I=0v[.BJ`8| ~? ,6 !5i]o ڬL,fɗXbێHCVH݌BYu΁ٝr ͕Ey3Ó΀1P =JZR_քnRz\ه;`׵J_B5X k}KR$%ںGo`y,ݯtYLL `P (қcqU[eTr8*$Cp^Ղ$5F/s9 Vyn赖UN57sw'6[aV;Ur3v&G{j}FX莛BW0L;w*u=f/2g.Hx lb、IHwTMH%*r'V;}N~2Rݰٿmq[%G@ѫ'a''hPC: kÎ YZ