samba-winbind-4.15.13+git.591.ab36624310c-150400.3.19.1 >  A cpp9|oUء ":K$#`'mDG̛QiGW46Z&+ &KƄQK3BgD3Y\B JV .3z !pN>; ~F^7xP]KvZ"2I"Fc8˟Ki} nIFЯqr: D˻_@$w` X\*E "oima>ymc(n[xMt u×rZU>=f1d6654ecbbeee9f69b9c5223eaa35b9852dd8ae115080d7ba37410d1f92297e21c0aaf7048b7c1c0892117494eeb29e9470cdaecpp9|oSo5~a>GF*y;xh` .[8bl.B+hAcditO~ːӠk@sWN_:d9==fei<>T]{tRE"6Ep q!g%Wӽ=sLwA4jX{Z^cu>pLp?ppd, : R .4<.1\ ~    T<88(9899>:O=c >c?c@c%Bc-FcAGcXHcIcXcYdZd[d\d]d^ebgcgdh1eh6fh9lh;uhPvh wkxl4ylxzoooopp$p*plCsamba-winbind4.15.13+git.591.ab36624310c150400.3.19.1Winbind Daemon and ToolThis is the winbind-daemon and the wbinfo-tool.cm|ibs-arm-3lSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxaarch64# we need this group for squid (ntlmauth) # read access to /var/lib/samba/winbindd_privileged getent group winbind >/dev/null || groupadd -r winbind if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : for service in winbind.service ; do sysv_service=${service%.*} if [ ! -e /usr/lib/systemd/system/$service ] && [ ! -e /etc/init.d/$sysv_service ]; then mkdir -p /run/systemd/rpm/needs-preset touch /run/systemd/rpm/needs-preset/$service elif [ -e /etc/init.d/$sysv_service ] && [ ! -e /var/lib/systemd/migrated/$sysv_service ]; then /usr/sbin/systemd-sysv-convert --save $sysv_service || : mkdir -p /run/systemd/rpm/needs-sysv-convert touch /run/systemd/rpm/needs-sysv-convert/$service fi done fi/sbin/ldconfig if test ${1:-0} -eq 1; then ln -fs /etc/sysconfig/network/scripts/samba-winbindd /etc/sysconfig/network/if-down.d/55-samba-winbindd ln -fs /etc/sysconfig/network/scripts/samba-winbindd /etc/sysconfig/network/if-up.d/55-samba-winbindd else for if_case in if-down.d if-up.d; do test -h /etc/sysconfig/network/${if_case}/samba-winbindd || \ continue rm -f /etc/sysconfig/network/${if_case}/samba-winbindd ln -fs /etc/sysconfig/network/scripts/samba-winbindd /etc/sysconfig/network/${if_case}/55-samba-winbindd done fi if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : if [ "$YAST_IS_RUNNING" != "instsys" ]; then /usr/bin/systemctl daemon-reload || : fi for service in winbind.service ; do sysv_service=${service%.*} if [ -e /run/systemd/rpm/needs-preset/$service ]; then /usr/bin/systemctl preset $service || : rm "/run/systemd/rpm/needs-preset/$service" || : elif [ -e /run/systemd/rpm/needs-sysv-convert/$service ]; then /usr/sbin/systemd-sysv-convert --apply $sysv_service || : rm "/run/systemd/rpm/needs-sysv-convert/$service" || : touch /var/lib/systemd/migrated/$sysv_service || : fi done fi [ -z "${TRANSACTIONAL_UPDATE}" -a -x /usr/bin/systemd-tmpfiles ] && /usr/bin/systemd-tmpfiles --create samba.conf || : PNAME=samba SUBPNAME=-winbind SYSC_TEMPLATE=/usr/share/fillup-templates/sysconfig.$PNAME$SUBPNAME # If template not in new /usr/share/fillup-templates, fallback to old TEMPLATE_DIR if [ ! -f $SYSC_TEMPLATE ] ; then TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME fi SD_NAME="" if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME ..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ "$FIRST_ARG" -eq 0 -a -x /usr/bin/systemctl ]; then # Package removal, not upgrade /usr/bin/systemctl --no-reload disable winbind.service || : ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_STOP_ON_REMOVAL" && . /etc/sysconfig/services test "$DISABLE_STOP_ON_REMOVAL" = yes -o \ "$DISABLE_STOP_ON_REMOVAL" = 1 && exit 0 /usr/bin/systemctl stop winbind.service ) || : fi/sbin/ldconfig if [ $1 -eq 0 ]; then /usr/sbin/pam-config --delete --winbind if [ -x /usr/sbin/nscd ]; then /usr/sbin/nscd -i passwd /usr/sbin/nscd -i group fi fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ $1 -eq 0 ]; then # Package removal for service in winbind.service ; do sysv_service="${service%.*}" rm "/var/lib/systemd/migrated/$sysv_service" || : done fi if [ -x /usr/bin/systemctl ]; then /usr/bin/systemctl daemon-reload || : fi if [ "$FIRST_ARG" -ge 1 ]; then # Package upgrade, not uninstall if [ -x /usr/bin/systemctl ]; then ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_RESTART_ON_UPDATE" && . /etc/sysconfig/services test "$DISABLE_RESTART_ON_UPDATE" = yes -o \ "$DISABLE_RESTART_ON_UPDATE" = 1 && exit 0 /usr/bin/systemctl try-restart winbind.service ) || : fi fi<rX%0I^큤큤AAcmcmcmcmcmcm cm cjcmcm$cmcl;cl=cl=cmclcldbd95eb7e0d1e8c973d39fb53be9be46276b21bcacd8b0ae1adeeb63651f6fbea676af835bac5e037fd6f6d9950ea49ff3f39bc693d479069190927c1c53083993a1caa0988f1da58a965d7a954f36d791af7b63f8f4d458a49b7b48dedc79096a768cd7e7771f3655e6155ca760c8795c4548dcbfbf1e00351d2a3a443990e4bd4d356fe6a03982af67a5680709d634820e3dfe129394fc32769ba965e4226548c787a47c3127f9c5fdde2848eeac71a06e22cbf997c132d74ada549c086e0dfc739702e52ee5408159b19c0ccdec8a91aead6a0b1dc48b84c7fc39de6c755d9a16eb3e6b8e2bf0b1ee56f8a98e8ed307633badc5f3c02d8a82a4293ea47439654f2e6c4d4e86066844899eddeb17fd8922f45e27220eed40940922ada8bb1ee4489a14f976a3396eed8193d25504c7fc65782706c741c391c03e86bf0d60f2663631fae574a953f96d7bc29d6dee34a1ad7c15752479a1cde0c247bbe3a7b2c6b4b0325dd3211474ac785379683cc4e7f17e211327fb9d536c1ff9138de03eservice@@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootwinbindsamba-4.15.13+git.591.ab36624310c-150400.3.19.1.src.rpmconfig(samba-winbind)samba-client:/usr/sbin/winbinddsamba-winbindsamba-winbind(aarch-64)@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/bash/bin/sh/bin/sh/bin/sh/bin/sh/sbin/ldconfig/sbin/ldconfig/usr/sbin/groupaddconfig(samba-winbind)coreutilsld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libidmap-samba4.so()(64bit)libidmap-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libnss-info-samba4.so()(64bit)libnss-info-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.14)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.21)(64bit)libtevent.so.0(TEVENT_0.9.36)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libwinbind-client-samba4.so()(64bit)libwinbind-client-samba4.so(SAMBA_4.15.13_GIT.591.AB36624310C150400.3.19.1_SUSE_OS15.0_AARCH64)(64bit)pam-configrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-clientsamba-winbind-libs4.15.13+git.591.ab36624310c-150400.3.19.13.0.4-14.6.0-14.0-15.2-14.15.13+git.591.ab36624310c4.15.13+git.591.ab36624310c4.14.3cS@ccR@cctc5cM@b@b@b@ba@bascabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2022-38023 Additional patches for the PDC role's netlogon server; (bso#15240); (bsc#1206504);- CVE-2021-20251: samba: Bad password count not incremented atomically; (bso#14611); (bsc#1206546).- Update to 4.15.13 * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); (bsc#1205385); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); (bsc#1205386); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); (bsc#1206504); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/bin/sh/bin/sh/bin/shsamba-gplv3-winbindibs-arm-3 1673948540 4.15.13+git.591.ab36624310c-150400.3.19.14.15.13+git.591.ab36624310c-150400.3.19.14.15.13+git.591.ab36624310c-150400.3.19.14.15.13+git.591.ab36624310c samba-winbindpam_winbind.conf55-samba-winbindd55-samba-winbinddsamba-winbinddntlm_authwbinfowinbind.servicercwinbindwinbinddsysconfig.samba-winbindntlm_auth.1.gzwbinfo.1.gzwinbindd.8.gzwinbind.xmlkrb5rcachewinbindd_privileged/etc/logrotate.d//etc/security//etc/sysconfig/network/if-down.d//etc/sysconfig/network/if-up.d//etc/sysconfig/network/scripts//usr/bin//usr/lib/systemd/system//usr/sbin//usr/share/fillup-templates//usr/share/man/man1//usr/share/man/man8//usr/share/omc/svcinfo.d//var/cache//var/lib/samba/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:27433/SUSE_SLE-15-SP4_Update/d131a1ece5f5f825caaa77fdc3bce37d-samba.SUSE_SLE-15-SP4_Updatecpioxz5aarch64-suse-linux ASCII textemptyBourne-Again shell script, ASCII text executableELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, BuildID[sha1]=8a5ff032ee04c409cdb917f0250e242303011ebf, for GNU/Linux 3.7.0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, BuildID[sha1]=c210442fbc970f87167c88a7baca76a18c2b6b44, for GNU/Linux 3.7.0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, BuildID[sha1]=7943b3d7db074104e0dd239f8d1875278db69d82, for GNU/Linux 3.7.0, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)XML 1.0 document, ASCII textdirectory3O2RRRoR RkR[R2RRSR.R5RRRReRR}R0RqR]R_RYRyRWRRiRnRR/R4RVRjRdR\RpR|RhRRXR^RRZRR-RRxR1R~RRRR R RR[RRSR.RURiRRyRRRRRWRRRhRRRVR-RZRxRRRTRR RRuR R,RRSRQRR R[RR?RR R.RRER;RaRYR3R2R0R{RmR_R}ROR"R*R5RR]RRRRRRRRAReRyRGRkR7RoR=R(RWR$RsRgR9RRRCRRwRMRLRKRqRIRURcR&RiRJR RRR#RRbRPRVRdRDRRnRR:R\RtRBR'R)R|R6R%RhR^RNRFR>RQ5Ѷ1/;>kW̐6op6lUk^k_ ϛ #!u(<)>:]"7ߙǟIv~=*/(xA[n5<5;U- Lmm8 Cg_$<(PҚn~kyp!3-4tiW_FL&-;lutܝ6la+72\!k/I)gV1UQRE ^Q31% Oy#\-0JUdW=i<Ŧju3hI fj}Bi@kr:AIQT,ޢ\EH N5ӃY, u鋸iL_4L4♼&kģjU!i@wN3TsFⷌKi4Hg"'y{4צ4}1;h޵j?i^q 6X9Zz; |2ciu}cp5uv$o-ɭ=2!K5Wm:C8Hܠkn#h1ߴK6٤nb0HrZ~6R-H(cb堯@w|VWN$;@aRy q2 CUQ.l2/kM"FJ3h#aک{)oJc^4>鵈}QQD! {➂Ma+잷O $; 37Cd;r;E ѺHU *Fb[C S O3tiO9Gtb[#lwIw1h\ -{RgD=_6qݿf{ ?*LX"FG~tp!JQF܁%fvFP`g"qt,(;WGTg ~Ex c{XQ!:rܫ?H'b16eDa`>FA5ƦPR`%LBNuzXW'bG8 \RjdXMNifM.gr$l 4WykB+~|C@]'caVywbAXEaa]4n^$ d z3{[K^#~hyQa'f&ܧ}m;k>=<ƄiD>[2P} ,_9] Tl[EH}xX CLnrp7&mu$9ՓDW5Ͳ/,P~[٭B^b1joUJ >u S!H&Hߔʒ];veu!|r'[vЎR3b %<;t7f87"Uhn1J%|lըۣ YA$ubn !ƹ 4j۠P5f9bC4DGd˙#pϼ-6Bf .ԥ`me|5/RA qVō3(xgSY;%&eDe'QXW |BFtzTR#֣.PZKtd;A)μl3Ι#7o ^'ps#8o /nzpT.a%MeE*ZVDd Uʜdy=_Euc yIC$ZlPlMz@>`hAd*Bni{2g(MilN RrƟŸLNd6n!P(@O4d T/RgǷ^Fq8dLsx['> df[83& fP=*vaՏҍaO\^$I鏹@]3ypppJjR_\KWf?DX⦿.gs@ۮYHZ;SZ_Sڂ+MOmW/N\ eΥcq2]*q!~=UEa@{B)`S! Rz E8l@CN?b>}!_)? 5|ߥb;MKH%@s4209بeYW$`w[KAg'үPZkjVӡ2ȷjuI+<ԣkNIaҐ"j3Eɶp ;tha81-[^qm Xw`cq-`^Y<?qXŞW/p0 FCگ(;U vxd/1 6O=T?=2.6/DvOZJ'ܗGRn֨"0j㲺D$0"l+:G00J|kIetQ)yk)%`m"&p(,vk :SX>`$q=J 7x೏d5 gқ_dڕ];;$!#mheF/43n[X.j؍|Cy(A=I)%?} ^jL_[ ɺ,5$a9cw/ϽyOꟋ˜MT;-/JDž¿'my e؞x80iUZ Eo7mPӴ|%6WRíj@w^Ub*jCAY 8I9)]4$(Vw_p- a$ ,kdzs&&̫RӨ=wbv1́W`uv{RuoU`RCS3=`͎j!rOPK5:@X7G˰B 2(h)F ~^|hpm*Ob$&Vf?4GX6Vb-\VWdZt\"i]\eWim q24tgJl m*1y ,rEXh=X"(ŭ+cĊVRHiEG|y4V4aUeQUuB܊mRI)3ӊtO]|RUoOB` sq?F |V6=A |v^ *Qr6*;Z4{+ϕw2vj6=-tTaYg]m4b0 #F+CYG&k.D&qCX']¹$ǥhYuԚʹѹ 5NVkY Bċr{1¼G\#ZhV&m*c6꟰U 4NЧEU,O_(2 )cy1v?=\g"*BBZv$1sB[ \v*b= H| 3veIݫP _u ~="qP0做_+=۾CD(FI w SϺETp&,U*ccT>ۋ9"dq5M|b-ODFWOl]+F^KDef] 5w^` FYUXǫ>|{BzY!TQY٘S.<8,ca~S# En_1_@S"s^ZV2Ȓ8GkV¨u > L%yQzSP,ݔ'es>8 pSL޹bȐlZƎC +C([-фAkA0 KQc"Q%+؎v't2V'03%r JjMT7bZUaڿFFt`ejvڹJb?erzsA @, 9ib'#5G&SplxSVz(M_Td_v=R鞉̱K Ȝ# ?HxE <-RBMJQJxL'HwO9֞́2gvV$7>5z״PTF]EwE9 MۉS8JyM! (,؅󔼄-L+mΡ: "\təT*{n$Jo#gɴ67A'q}gzK{T|,85Q)-IYgd }fQC8^Z3CWN2Ȑ\Y>`5}Z|(u ]ϔA.A{ϬWEq>{$a3`z!O5?o= * >vT( :Tf$>W`Xq%/a:SPWHbn(BΣ'?v6ΘNlU89.yG]͚.H5hfB7,´|36O+]q0YMZP{;eF·gѝϏt\6Qp2 *I! ['zhRQ`J mSoDBO1Gͻ6DmzQ34ݎ I* 3@"b0y _]{#֦֌B<+#f?8BCKȹzHf1|dP([khNJ;~ԋ(.s2IE>L FvGl.Yv岗JBǭeb+Ҁ= 17J^FRmۑ6!=5AlZ1I&bY3WH۵zF, .oC#/1/Az/SNzu?в;X7W ii 4;bOO&  گP궤8#H\;vQZ׉I>F>׋Xt8Mel;L z^:*rz^^YٷN bUCh0>Xb t<EKgyL^1 }X@o#rCҠ6Ⱦ6_)E}^[T/IXE>$0יN0m41*`ROCװV>ֵGS\|SE0V_8VG%4Ot8#Jz%/uGWB~%s_ߺJ#~:b_r>m@,mI,R?5fk1.C6BP|";/vk"ܰFJkP~yVTX_TAZ{-xjSH__-+wԸGv9ff[jXUehxwٲG> ;!V0ow+.@cT>tд 0bj ~og5Iɶ͸Mdpe{}:M]:t5э/-u4R]ۇy,0%10<% Ttx N;9y1!RYlm頳60{bp}2vSr!#M&RmԹ B{[vBg+`|UlwIEb*=„d;>M~kj#{m~?1&⨙v/x#uL!h\nu#P iPJx< HAi 8χ4njO+" &2hOe$6NGM\~ԁfx/h6ZRaq^c|#ݪcYoVNs*q.~&F& GSYT#U[ڙ35<ٳa<7_ $s{^ a7NF"_#f ;~cB (m2s;CTkP+KFlnH\r0~HՓxJ^TvCy4hkMR\KOSTo+-bˡ*Xշ~Ox@7d֩%_`u3R~CK̲{uG S9N&Z?׹ɔg|+7`ThMFsIePޓaE~$V #NH_./ʺ#9䖐lb3Q@q3Z>5+( 72ME {A0p v ˏ0lܹa d]q=t{X,0Q@ʷ#x^>Z'iq`Uy̶i)zhEc~)7ʿ-Rgq胴z nf:DYP/w~!c:N2OugHE&Xo {-s9%FlwL]D)c~RFe'  8m{K}HHz_4f~ۜ1Qm|lusO1]P;tz]iZj݁|2jd@}WpeF'p|;HRl邋6V|f~aJ6>cB@Eswb: X3Qo>փӇ+N0>tZOԲq}f)b.7=14BR}KA$rSI.X3:=B'W(Du p#vv:)Wi7jBd3?0 QoLc[CYBУ9g(ؿ'ww(_[he0_C2kܺՆbå@kRƈie g/ȝ]oC߀.?oA@j*bȽ^%0w&}\}VZ1{Ů5CXDiAW1{Og^m+e2q0udN*ږD~*aiG\w#<4h/ 9[mB: e?Z dtq}{6'3KseKZb{mg0pJxtw\w=\*иuC^,:HWi_C-#\9MzV"QZjau!+~]""exvk9< l͛iVζIa#4 dBϏf`L U5? Ԡz`g FZ&Bp"-@3UO0c^& 6җC hH  QO\uD9Ϝ!$.hA_OIx*Me9_[I1vs4 _Eׂlt;t(PvCbe2P3o'7YE׈N 3( \EFځ_n#v5QKgSALQ w:3HǢ}Ua sH^%Č$E|6:A)b_wpYPN1sT\FSnГwz+ؕ-~FbOҎL[3Lel7u%Nqc'hrŅ`:>fJ [ HSx1 1 ' 8mhژ O=:&5@2Fjwy}1~vCxp*q?p]Wŋ ~+pZ׳{;>xx^8C[% udT>찪^z[ro_ -&S qE Nfpb=}lGw?b䢙5D:4Us}^A:w./6bk( *[%k_r$޹_fY.\_2.*SUak|;E@AeK˹j"/h0&|?b͓b@XDYS M@?Ѿ\/F+p +CU'])H=a%TO҅(f'4HZLTX79lղJQV{F/3C0F 1# s%1N^#-R:D; g ^FK@ bqw3jtEaZVe3ym.+Ux/n|bm-cEpUK<`UI[{?7U-w| n( )oVWMhNm~x4DAII nr2 ac~Sd>6es'% 1qPmrR KѷG}V-.mkUwc}%~s֞n1 c)ClspQ"*LGoNl#ynrFQs}ǫ&[!fK;Y8JΔ#-_֌wuF68KaTUP F 䦻CBPmjpFWk?jOfcpmwn&ߍ%NEL1Է&Sii סe$00l` 0jIFh-3CUZf#\m[쐡d3j s}]uVgZ}o6Kxt@T&-c}o\FI7zo 25_4 P^̛FOMmjʖ`RL?%tS%sulYʶsٜYzrx'h\NcK} O 5cHCB gH1lɑ| a?9kYc&Y'jvUygTGW+{w`Bj;b\,;&ޭS.ŠIiaR AAC㔗}uZQ1շ(|SH>#h*Kqy/^Erc]=*بwãu  / 8vv`Ւ{+ļICq낚=t@ňO;L\qd96"T)x rM]=Hmn3wΏ^F9f|؛kmt/꣌Ilg6ou2p=*1 r4[<{rY@qR\v$eW4jT4ܥk-kSaKLytO+,cGMXmar>MJ YA19eZffIBMSvQ17>鉑S=j*Ld1d:#Uꮪڰy"PA FώΝ^KxTDh)*eVd@nK mv݌_Oa{:kpS͠TԼ~ib"Z&@c5ukzk9$*m &SKs#gռf05p7nC<{Tk>jλvn_:[,fT\H(z1Ȭ#.2ɍ&$@+$31§,-A~׵k5TO d%ۈj2UzL|y, ei>jF B%$uw1 J ϯ]v;6JӶ?34MLJ+A}+x1#KK&*w\A!Y/uX1|Q-][QiRc;a/$>oihwe3z1L=tO T sW ho# pzNy"Dfǫ`M?xdذEZ 131G96@+dEM{&ŠԝWn|s+&乄;Ln/fyk.`k ?֗\)ꆫ&$Wsl=MT]8c]ZP'^ЄKdo@ ӏD/klm@̱jfg5&7)_՗??ԽG[D@v# .A BJ_ps~n*}[e7C'5#ZBH1K`gM!ր$S}CcQ;[6?,pYriԧDFx3ghɱc"QI(ќK)\}=L|Dnq_4gn;Э~գacdk])jkJuMn'~pI/{Hnk4b;>B~jµdBj!$ŭ}=w{u`bs#3 A]N=D^l\QhU%vc]B5qK %R_9iFkўAf^c1F!+ަ<"Rv|NTuX<^\E]tTyo!GSƳ&{#钙++}הE5\RS QȹxLƺ=#4z6C&1'9Տ<GsNdN:W)b-"EzKLgQ$zHڻriN{1zt] *nTH IlK[dO'ͭ~R7 qg9-@ ۻNjѐiJEFwNaӝz_hM6_6(B6?W9ut(8GRYh])$lj W e;\N=nOijIfH]k\OJ6Dቋ5c-_衕c1ޡZt/zU> Tfe9g. aͳHvNZCx"'#G(cpMU ??PdJ㗭/28\s:Oy8"'k糵-`54UA+8FBy_(gV4gSĂME.S`&mz aj+9KUPZe?m3]B'׎{M)pߓ7$rXAru VٛnQki*TPMثO'5Yw#o$K;J⢉,"2q.^CP鹸d 56'rhߌӶ͡U/Ђ"m!qӬE'_xmojˠG0)b2OkOZ̤X4E߿7nKz%$eLu>Bphh~QZo6Mwsdvo@2LD?%qb/ 1j%˽]s_ 3RGwXa<*E_NhVDsW 9wB@8*kܭqȥ\+`w;]@\حKh脛eGB"xNs`mB%b;ƾ>moӧd--!w=VǁqnsGc|9隙H<$csn^n-g.C0z h!O#I\bCF}3x8^L) FkRwu?e9Љ9"bȹr3w%)4ПҶё -켬sHn~B8UWM3_y$*Usc0ePM"xAN6Kva$5{&iY:#y&O+ܴ2\iX7r:: DfuV{NxQǷ2:1T|\!Kd9k龶ChZ%$FC/ŏ_R6gvTC7dc|i?^fiPQͪU3YvXgABˍkͰ ,`& 7[Gfy-]iXpz=~p_fpNs@ e;b]I LfQ** y-S[7 M]0=8=tl(jTH @n&I6V{.O 0ޣ:MuD;l&c4d$P6CIC +Eѵj*~9fp96i^"ls4#o4l^{-2;h& D9{We%,^S7+r2U%3I !ݕC> .}Weץ%$u^TARf>͏1"Vђ +ž_֣bCѡ>\A 8ø?l"ޝx݁1_T`tR su3#tj(x^ )Gvu{BED;JkAWzC৊ {gRO8E]fx7QM G4Ʌoë BNYMi߇̿0h==Է09:[^Z,cޗy0B dȉ{\k%qE=ϟElz60ΰ)UCPժ_ZQuס 3SNcɤo Z9Xp5I9H^'re6 @B+ybQ!† .>˫0ԒXRFn%m\k^r˙j-%%rg lȱ( w cw >+Iݠw$dD#A5,`5,GlҍfkU/B ݸ|gUL3xW/hA&mFTْv nMʩ:#)T i+\o( GB3E%p7rf{d)O&hy!p-kCQ ӿ  diQ|l%uI|[I[h.a*",PR%upwS`Z=\XE*h*^[QAY\h THs[&D 0A @Dߒ $9`// $Sb}0D jq{Ny„uStaOE 5|ltʕ@JA>sPf ƀa܋)&zڹ kD6GтGŦQ> S=9NI;\?h47)DzJ%@r!>t\gRү~?B2d-75[3 8 ̡]77&x3',u&R(f3%&\7a;T0n.o׆m&kE)0bs330la$KRO 1RVy"Q-dx( Nl$4NV8]A.IQCd1s>A ."g#g|6јFcnUk\_,1׉ 7h ] [^ҒAJ%)ēFt>Ѭ ^$|9Yx~*:=3|~56ۼͭR tN Xy rҰ0m+ZRi̓W.A'u=Z] GC[" @(Jy6oô+)$XttA <M=_=t|  s|ZBhUEPL1#QuqŒ  ?Tͺ\8LBZH`OMC%)z$dԑ]sXM]H\QR>LWSn3ӯXyMlxH+3E'B#^yd&kɚmg@xEtnTR(k{d)9^0"D $ yftꜩ O4)jlY OfHtd=t=A c&e{kOkj&yJ3 trxKz"Ji1-?#<YMYi6Ù->Ht͸fKgN!Eu^Ѳ=>-i_/615ք+Z$Azhсboui`ʾYB%Xw8`kM*Et5ƆHשȿ\N~l.L圵:s//}GYw9G^{TMWF~вNTWIFEEDZS=@r̭FPI@rI$t 1iG>`"WGv>Q323_d21Ͻ* R^tvY@J\&o:i@czBڔyhWK/]H]J}xAN-R(RI(tyǃ/o'Nk?˖}12nhY \* .[D8 ~ԚAki30ctxH-bitXEnЕ,4pv-~mlRPh?j笀qOM(Fc T3U̦,{_-E)_b*2+G &q4GI)Z[qUԆ*J!s4`߅`}.yAD5NNy ܥ+ez0l9)s!΅2PU0%W2LPsڞx\K^Z7p! ;ҷq;_he%38*.\vVsF"%֐ /{.D'C!-SwLUqf YpF0QN2RNXӎ[*w$@ҡǮպ ǧ# y[У΅}kVod1t5ֻ&c7iO E8qkSEt12SΦރ;) utQ?v~gKΡe1&͆?:A\bW7sHq%8f >P?BV5 w7 _ٱH_ pQ̅I}6sl/ShVbRὴQ[8g.*d?bғ*4] Xj9(ׂ<\%Rt:68T4"F>l`R0+¨+9/;CKQ'.m+/XNuUZq`9,)VY9WJupMp>Ӈ s2n.Ei*p_vk2̠?էQvg,ǬP?q{8H %~Tqt'aA`27f*I l=/*)wi1 ~ܦ e%8w;dw)yΩ8~ L$e~!fl&iϑr)Wx:J-nh}gf:XD4F&9j[ ,^[/ʷ2 3f(A:N]l idEe:3M>=ے>Z/2h>Q5%ՠS Nbm9gXy5S t]>FԋE~.֎;䕯-gد-- ["K6T~T*+ 4:3pu̮2fl##۰%u[<Ң8* tNuR&f#B=@OQpb55 Pnqc=-{e6▱ )3V],jq xz[4#n^ Ҍ<V $uT(L9++un7Qh? CJi偐f#o;a{t1f5l9l*­[vۙ Ȱٔ&e7-;<~jImbkAf|l[:S %W|x nS`SΘ*);[/m"/m,%K!t\uѼ06zgb@w`.EYɻɰ9&WE<7>I;4DȏꊽIw@V:I‰e܊xWG*z2WCApxԈ5 Ҡ }3 O_q/dJEFqdۄrr@iO{g H9pSGq(Έu7eBAG&pa !(Js7U!mߢ=u%?9eה3p868RN5,f/oنnB d\#ܯ8n{gdaoZo~V&|s}?c1$-ܺmN3&mDCX.Wv2菶t Y`ʤdֆSDvKe’]yl~\29Pĥ]BtL6([;JBm /wHH/#: V)%v_AV> jx 47 LN]y%L6SqiΑ=90 O;} 3R r(+"CMRSٯWU2iPEa Tޡؾ1]@׍6Ca8࢙m:ޕlbkZmey1U- In>/\?4ܕ&DP>ڮ [y"D^/$!o\R]7c`́x PI4~㼓a޻Iv-\l()@zߍ D )`U705[Jɭ2cuktgHE,kk;::~P&QBĮ^nE9Im\lhS'$}Y8}w?P'8m<[`*zdX ݡTK9za`%@g|4XO-tc]^v&( I$>l#A/$r.mĨc0kyFXppׁ^gJFVOIR:tzNyULAp/nXR`0V3ɗOd®YQze ,i=2QyT tKj-xCs57oXn>Duuv~Qσ(r+1ՠriiJ<1}}ٮ)4:m3:؛?er VMhSu q%)`ˉė"!|sç=%(m-vB~-8` .@S=2b a[X>?| sʄG"qR`VRg%vDxf@|vx')Xe+=/19RʃÎM i@GUZ=!GY#g> GoQjt:nz{vڅ/>Gb"??T vftfoZB u4h@mkJO/Ȁ+!MI2[4TH;*aʁ9U*ͤ ͎OE KmNFOL:Ӱ#ũ]zVawSW}ԕ]ӞeIEYZۡ ) lV2K'o_<.z^XSњ%A*Ko@06RJ^ {e 6lO[7{^Э"K7[hj5shO|з Em{@u:ݠbr@in-7ّD#^W >c&STHZ=Ng gZ1BP=H!MEW̉ᐭ JP SdԊÑ?@z U'^'l _C_hyIg f%'zкe侻ӧNYNG e)4z+l6'Tzڸb՛ɩ8o1Q#<ʧ*kcv^@CAs @3VW:kHwe9D k*Dt-S=AQk|?ᐮ4zOٯݣ"*scܯ&{2G,3ѿZݝjuzy~RЍ|Y`jZS2@X +Jx@#_hjjMDDn;F &H8#]3B\~6V |MHؼfE^b4F[CXPrƯ.uܚ{'}ھ?|f6902ޒWpօGbr2V6N!x/67ޝTbqL39l: m'df>kPyE'Ey[̍@$yH,[H7iֵ0#6 ׍@/Xc^..C\Z$wfʨأdb(+0+GM{мu-|D1^VdHAuK̦!ͷg ;$ ځ8 1wz:Ɯz1-Bijv`;]VLU.R 1 s+mJXs d츿7,QEz3~W¤A*I4(Qȫtb+隣7둶ȓNPuI-#M{h&Zʅ9LRH!O{@#uȶ⫎4 0Wuuokf[آe!Ow]wUG̤\C6䤈[B_9?2g6d8h^-č.M)I|(NmT5/Ry!&{a+tvA_mp_ \g={qW e |."3bLm :(8^ Ɨ5jw]ah{ *g ~>cF~h'^*74HƗy$ωC3 o[W eh[HEfXAp"0-NK(;F~|B@cL: yừ]o<7tz?E5V6+/@_g8!;?5ߜ'ʰ9ϿMLpA%K_>U{/ePZ[m@kIL' Wu ^1jv¦%xjGM]_VP la { B @5:7i^YȳUp5Tx9>}-ǵs;W5Օ1@ݕ_HN 䮅 Q/>JDLkb@:h @/Ť) ~?4엪3ܱF?`Z%[@Nl>'bLzSQpW8@w0MGA~ n@ܜ#8K%e:ߓ];˅POE"R_Y^'e1<,g_ ea_:/U/Uuj]d@wOGoGӭr54Z0WZBb80 #{voBj1߲ȴۣ5T޹/ RB {6Z&_s6]b&V3,KZ(-Zw'nsNbYH ebԏM?T|&M:-||T]s!@/3\xn VK,. ]=`R(Ga\̧a.wPB6^ ]X(F@gYאf3J~/ ÔCų#}K_^3l РEp3,S[(,YS@ˤ͕/ L'4#6'7!LS1 ]bIn1x1.ͽ ӗ|33<եfW;Ȧ N oAeI+PI/˹{yl0 rUE,N (BR%)9bO GJye'ywzfu*i.);9].BD%Ɨ"rr|kh{'((JͩU[W`46fk mY* &~Fqj,z;Ƥ?KQ&XpN$Unؠ؍k S*p cYc^ '`D:v?ٮ!؈ǵImqfyT JMWK38iW]=ku5m{ WqC~hpH^Iry:rȞEjͰUz~˫JBz@Mj >2<@'M`'XC-f`HOr?Y4o =n"ɘ'…hK~iAebgxO_K nj`;HcLito\F@4u*_C[_O@565*YHoځ+7UFK@Rf>Ҙpۺ7gjD]aFzgNu`<(b~b:Su?9ǐNBn8ASx4? Pt6Pgr (}8֪g-"vT|*Q4dm|5fea1%e 멊]4p^ jw֒wA^.RIG^Q]B4wa:YfByߞNMy7p0n*C<ڿ/c͚Xj%,X|[Y^bAJ(ʃkx#{|#Ʋ6} =|蒭y^,c崵`1,^eS!V|GL~}9տcϦǃBa}ٔjjC]U%h~R>& YFoEM9r!^ܒCi{Mi0t@@7 8}ރ H;}һ dcd"eB,p%\ !76ɻqV̈Ib^BI9];_/»eWU1)TK|n3Q)#v x#J6w1z[bV%`^Pq?!s=2̐𐁠5!όemO#V46 pWV@t =^ik:1Slشq~֝"S@{oOݭ=:33N?6/!~jR|hZ(& bW"}W@W! ݮP+t'2)"Ugl>ye ,Is7^#cnS4 ZۿEd-4 A¬mXצH@Z4@@q]D*㐓!MP3k/Fߨ] uEG8"hTY$ Na5i"8LBBv`݊Z$ɫľBӗ4mF*Q荷WL'xΚPr1 NIo0s/L>)MQBXMNq΀ܦvu%~cѵiY:#őqXg`u G2Ӎ6/u`lܙ^⦌0'Nx-RӇ-fֳW%BsqN0*{c{a" )Ѡa)ҧmҹޔOw8 WgXҴ[g#[^Yޝ EzУ$HJ^8f{̔8dX750-d_~*Lr ~ly.N-7黒Ԏt/"ύL8UשGv#锤ei r#׭ч%rƅP;6]H6]/ ?S@}'sK5;o8C<ƤQޥe͚L}dsPuX_&ّUOჰSm&@fa:O0neP;}o=aбÄk|b:έЅ,錈ߏ>f=dȐlj,VdtN>-Ѿe2Q ՙü*y{"¶py(^_ZU〕Z6[tj##fÕd;[̻/M>~6zDqM@I.NĴ!u .M+alM<s`Za6LYBSFvr0k{]YoȂO`0#ziPl=:ȁ&"VǢPyvw.r$qT"Y@ >ՓlpE PZ8A":WzMAp;I}Cr$F&Z<˓+xFk ِQ{oy@&UwU[/1XV$O~uCXp0l FRS`xP;΅I+&[FϏ"LTJx+SI,boDntѵҕ`f£.?@Z!]08k+(+pؖo Z숁q5e4dffg>)RPz.'99R7 =,uuExs ]0Ѳ#&|snU~0`%%1L^_hw-Cm.mފ>s r_)1vy5e̵ɔCV90_c&v\A3p Ul״b\%G(6jW57}ihr:g )ITeP%uA xx5BUwr!ë~QONIkp˒i8ԪwSwjx ]TgG) ȕqx۶>!F, 9髉WvC=~ՅLOws5MBkD?mx#xDЧL]2JW;5J#^ L^SUն5W*좔 #_#oߵQ!UkyOZSN}*\I8 r_O %0J CL )|r{UjADVȬx a\ `qІjޏmo#۬vgەfJ?NbeaF]8A|HYH!Ʒ6R @ ܂)$`w2bm4O==w^=ކ nrt cXDQ{a@ȚB ŜA?ex/Eq3b_sjF&4u-B%Yrw< `(>asF~C^c\pKU ~oV BYi!1T5G}', .BM50֐e2I-p6X(4Fámkƪ"eJZIR;#:!TEjBLYv$j\Yn3wN%.{Ld(z bT3=plIMX\簜!~ќ "cN`ɉHZ.noj*3qy668J⏝ܞ\MgP"OΉjzLK)}U]13#5=]]AfT q+1p \Rol)RrO7F] a ;zw5hIAXvQ+f>{T V)4{X/:5M?9\iCAڌ*[O㶸rMA*%fo,ɩ,[ [qjơPc4HgES-U(,?Od~w U)d;a(ʵSŖ15zhWj{f ۅ'f~뎰NFøt-ӺOE':3u.x0KV軈dX 1dnRzR9kv)i%݌]I,6(I!RLM@nSj譂S . 'jG"J _;e/a/ϭdx)G#k z{RE!/ePq=_ iyOG9Չʸkو-B u$m^-tp օvtI.3mO,킮1a٥e~iem9/BiW˙fUSr{uU V?i!445ek6 ȟF䪿jUZc5fQFY0 z%&C2"Sn14N: I)s6"arQv ](v¤yW~,M2XBc"V7➐x> ҋ ֏.Wσ%Iu1[v=i|@ \YfHCnWlb {`jS;bEۇ( q+jBr?ttpLT7cܙ!'l@LϠ0ijrMY19X L bgaPAp 2d"F+aC7ڀW.v%M !yHkf.pQDx`9D] ۧRTZ5NK$fD~B^.LVx-KoƸzx|sq@T;"MPڿwZP |ll9\)[nS<$pIq;\x*6'^N뱉k#jI%yuV.o}[}M$6/^A/y2Jl,Cno#Da4DY Q?T&Ta&oNlB.SXGCMM@lWjRJq!i{n/3l1(~EەC4 R6{[ wW=OƱ^ڰX% F7r^p.[䠨Gխ\wG)R~wG4,A&f/v:悶 LZn:g }Xǔ7mQi;SCA-=D%@ag3oD UUOß'2c]Yʕ:J?|:*ѻPYKUڑy8l<8S&'7vsc顇G>ZvU$ QwE:upg㐫&%^t0FMe@Ү"L,#b{ub(楄߲vF)Ӑߙ%L;B)=YLM{'Vϼ|^[e\bҴ$1,}M)ïΝi7a28QZ͏Cp>e$\>=,[*Vu|i|ʒvCgHl j OGvfmXnh-!&cM#Foħ#^g!UxwT]!+TDb*q#Ѥ'ЏA|u^O5F(B=w'zRڽc?+k(q%^ߓ/MWe|DXJ{kSۙS&OkjlfG`n1z"%RJ3ꁌٺto>ue+' =%1= вz=#Z9ujUxwU-mG3w%O˓y 8 Gu SxhkSkcbƐgrrZIZ46ˡ/7L~^]u޽bS[#=0m؜3eaz+#"vf<&>|T}I#h {xQsL ڛ` CDxetUhI%6ε{Rj#dM9| 2lw$󞽳ډ6.řaz]fݛT}!-dR # V!K_g}nig>~Gň6'3 AZ%|ĜE G7u:x⠮˲o'1gn0UɆ#m P8y: a i!MTQbCхZxQK %J'ϴM0UONv8PO½h;f@gx$luvE ;03Ingb/ BOKǕE \ uh껚ҢmӒ[E8ҘOz w݅<*`鼬[1Ν#B y̾{qⴟaf6"B+P=fFϑ㘌H9)JoIu)ϕ-⣬f՘ oK~cc.Nl?;`?r@ɠ6}R:ГV&YƀfJʈ")7C` L(hG od QwBA@c޸dWVB)n(2݋͌0;MU^An$<1b5`߈1ֲ8?Q,]N7^–XӋ s`0 l%`q?ydH?yB!F1?p={+TsZ$^e,l rMKHٺ{މ&`l?M:zauб$> ꯡGKKV˰Ȕ`_LbzQOދdžl.\3Ģ l,Kpg]B+0#%huzR0)OcG$]X wIX8e*3vKQuU!5 =DVTy*>&=r)"r0e8~ ^ EGaqhKT I?k[fXk@MK 6잚K;fW6H;_(;oQwEIFB^ O^-"`tDXX3߯)w5bK$oYW&sң t Ly6qma{ɉ÷M>w8f73SP_YiK;NѩfK-6hK):3i_+JG ҆+NYɊ&~bovk6@pHkl!R41щZU#I2<$KYF^I'0;Hr%"&h&4m;wGy ͵, [0+)~z:\j DmZx_ZHFMSkjDG{Qz$akFw,\X#P|xaR=y 1GX#rS ;1 )`A_u x7(H/3Enm(R3Z[A[2ou6%@YaMץicîyWu$nrqVۛbT(oc.z82(1 'uWgWy#v-+meɽ=ޮS}Vos8On'h|NsyUf -xD S*Qw͝oN|ޢh^uа:Loߺ_.P{gk@j!b;u˨[1bsl|(nhvǞo%^%]ʂ(#yN,l[d'{ygʭ~ fFSQퟟH?\*FǢZEʗ LJ9 :/7sőHaxbRөqχB &+?7,<3> =g+v:.u ՓFDïm6_ zɽM 1Kή()8q <+3y.a*g^Tc՜D@0.1|}r8{c4&Kg&m:OOgLTOoV{n{ݴNn CwKf2I`gNaP%`QﶨCɮ<m3`FԓMI1D0!v^Lr[H2"j\1ųu/-x/NTp/ 07BJyGGywTI6\'v!TQԏSQMP,Hё+( A %F]A`?K"eU"j۱?QfPdm%sa/bRxGatKAp@J(eܖW,DkX1(;'V! Bzݺ%WBY!q''ӱcD|<@P1r ;x1*փlN%tS3, hmkq*{tp5n̉i K}X1؂o[p$b}!aKJQ4]V$VƔ_o8~`!J&l\G(մl4uE&s}ԺBPU?!-[qka| a ; ?d`:T =GN%ټgCszF,'X+ 5ضVcil]c\5Gn{fl@qF20GNѮ]U. <D8jr7y\M RȮ`i`~rٜ /o-Hَ]T'ᐋWnk]޷R{|j*d E)FU0 Zzp3g0- HJ՛ =MN79RVX!WImla#7At~ӄ:TNL%3.pKfsFv "VX)&M,S<ָPj)jN*V߅1xJ+˙ %OH4'U%x.rՓ P OG6LS&'(yh;wgaNO^*2oM?Z)lC95H"T4ehT&_6*A0N8T&HQ YmmEr9G2!l@'g;G eYj]mڅlƹIue[^ !`:͔]#W,TI|+*>mJLllM4 Qkڄ@ߍ>7eѦ~^]2عR݆ c_7Oԅ͖<鼇˙59GkP"dW4X]ɔsGd A-D=)\`[$S=3 FFZ$AYQ%Ϛ"z؍=74)R)(V[B~Pu@ě"# sJ{P \ `8ԱMkt*BUĆ"%.0nās٥/Ru= :ΚmeeryV֝)UG,cI ^2d<]-, ~$f/烻b?N4N=xGXKz+VF݋ FMӌ:0DWbeZm^m%*ͦeT*qF>4ո?_=ںp ADCE熻~E<5zOn)u&CtE?'OyYNՓmʺ7~EsOZ4SB|f0f"d-u؂ Ľ`mHfX>`lѾFj:OYprM7'ћ\ C M|hR4lPKw>/)9F0`I=O_)r2=iLL:ʪ}RdyN7]'|;:^@N&֔Ć%v[O(n 'A b9t!:=Gb4&1I,_{ ѰH<ݒɑ$Y1>[)xꔾF ~L.JXlgKDD|\CFzS5;XqW~9(#H$z†u %IU'vsBW: {R]n Q@)ŵ>t\Z;vm*ndYexDe]~\KJnബZKpI:GQ_rY>)0\Gpn|~:2j{ ?+8Cܦr?] GOՌ[NKp6+G0hgX)i(7*ޜ/gmR< y^I"cKPxs!;zNBQf]āO*z/ E\wqdR]q8$>L'Jqri1>E^pO[eiV_‹>Oj< G|~`F[_VHYxkm ܰ `_u/x6I\Ddtx,SVpy +uŷ#Yv`( \֐`]?8%بez?d[}~0b;ht z %@fE8p| :T`QXТJa<( q0Μp)'}/BW?$0{ZPOZXh˵Rz(qÕ8ڒRTg/q˙w4Z +,L.ăŰx:cWc1ؿ 1 ZD]43\SM$-$c2g[\Xa}!;c(Vc*Wa͹=[2 -Mm=69+8驗t0;Kےov z  !NU--ю:`d"\[!GZ0  x3&T#&C>vǚ "@LTт[m8hpo^-:("vOR)@L )=0 ]qlI5mKa3]RY,AJ˜5o=> qN2Ȩ$kfJoa?E NIe*6=T1MEziJYHDV<"m$f?}j(OB.x(}PS+WU*M];v CY4R)Zrp]dl$PkrX Mf~+t~xFװ͛)H{ x*wKicZEeqHmd%Ww ş2&Zē7BʶR[EO8 tH'?'d? 5LjgZs&+8|myYAWq;rHjЫ񦆆! /\[4tuϘYN"O&@bs x-gjz`1E$sBQAˀoIk}|h{sy[cB 57dՋz࿼P9ifwLDK^MD{#0*R }V`!vQhi+f0wiTbUV`U1{Fbҭ$zrj ҃#JQU/7&Q]tΜZ8T-:+#_ )p^~_rF>x >[T8C#YE J ΡQ<,iW\h)6N ^9FHv|![lG^e*XW EK 0&S ;jµLҐ{\Hz?}9ujlcV9ФM;ϤDm0qQ$\|kJ-t?vըqK50Lo ^bt5{‰KxDK sV$Jey{VVۢZpzNL`2#5$Vx68mķťu nz ҢϹϰa8CI2'κdl43sNcWw;`#3OU*]UEi{OGmo]~GU  FkI`Jp0r!E @ hmbxFCmD8 ZK&}AF-|儷 YD!+5ۀ;`fp /j@.&al?#xQ\KyГܔT/K/}e3TO 4de{ٵ0{gɸ-ǬxG6&\oo*)> ѫ}=UvDkƤ!ʱ''e^ZYG Z,ǦZ9ꑊvCCv+ Y:(%|+&Z^_J\,ZW; Qsy1$X"Ia_%D}_L٧RVU:*lr钳1C/osqQ*mȞKłRiYla9 CGՀ6,Ux/^.TL (no˯p|[Q=CAu4>)B+!Tͥ8ԓJN}|5+R+?B]r0?3ejVWGVoUQ]{lGeB]N# c+c?u瓠qGN:V ([9ў#s2$tx7t\Zx$VkPŶ0 A'(#74Y2A&j ?',VRWkl5BIylFimm4[% wI=.vѻ#_ߘ.g5\תqdycjzM}/(;)[}3jKs{;MsC z;lY E8$}U\율>N(L#I_. ~Nb.PSqР J,uT+ !z ˼̘2\v14~Q2x+%>?HAMe 1_[&\3 v":"FN]  nl #r1ɉ1Rq.JQ sVIO%DDϔ2[HF ꠝ@PW{D2cEhv (UQ)ÀŎZU>c1yf,v E~Rb2W7m^P߳\XRgX.mD/ky:Oa;/LP[vN@;.;l|t!Ju3w*B"N^WƙWrZMc=7|lh cOID \VhCw ɴؼ@ U\|JEZ# sp 4Nhh#EvNoE!F^­6K8ziQ~BoA-ݤ(lS,XFp9Jb c cGYj_o>V3Ǥ3$5%j|pT:`X 1=IE*#19iY4*%9"]3y1A`{ K5WubJNij]>D$h-,.:F9~R9賞 jc ][p.ev@P䱵2:wz_2G]ιj\5KKJ&݅!m>+=24O;brSނQ;QlC(u5R/KnT*qp,֕|V*&|AbyB7})/x3c?IXn7FUji[_S \sEQ@]CtX#e+:/]zʣ;[mOg|6-B Rq}cKwD^M5[)qY!t"P8_6t+ oGcil'depڻ^H*& '-f(Ӯr=h1 fj_o6;=R0#CKSHcq9Ta[N7#Ȗp@."4S4;]\Ɲ:ՑL;56Ay6ĵ(0jIQ"O:6Z?qi;Zz^ա=UayDV,r)J6VUMw z,UOi,w M&1V}3%}HI23 ;Q\,N{TAp6, AOy+UYp.Q՟+k=᢯C)9?lJ<:˜~!ӈRyI#rxL*laqj_MGaGKZ93H'j˫Pưƥ(RђQmknj+~ie6 R{qw`:& l@wʀϿ&/Й.rivPƩEP#~=sVa QO@1 fHn#DB,DŗqWj ~TOVQ/2`~nXB|qTU^X=ezSg;Kq_fVڀ=| tח'PL,*^]PTጓuD+4@v ^x~TJے\ ` EG/6Cty}ҮE:aJ % uUϳߊ"t>ԓi0w-:cc 6zپ1 Z@w]HOuR2\7#P&O^8#K,sJ\g X9ud FRIa$XVib/#o>*7]:ǿ7lb&UO "ԑwҺ3v!Za|+JO+?]?R6/: Ю;w\wU:<~ ,RxyvYH=0}S|NOrwOuH@rfH-9{-➰l$Sم1?9 Wr2JG# AخN 9&+}*ʧ{5Av.;¤͋u2{\-W(㬲ݼfW[j(mMPwl˕#iJZ(QwAgCx:(N8AN>bPo6HbQRX|JkM$|x>J$ ?7h%QöExM΄Q]3I\D2ƠuRF¸Pxϗ?^SiWSQIl`Ĥ7qwv˻WؚMᛜ#p!M(NZ 8~Ve;Ёu5HQİH*Lin\V96! zԊQNR$GY_窅 $MPģ@ȁcR04shγIܜtKPDbl):3n8{r,uhu!lTkə .e& D0ôEZqcz: }+ʼ SȔ:,!0_䂋o*4̙#HѸS)!PG~q6e(rov<@0߈ߩT@& izzp%vu%F!xxtЊ h7J$6,5VHD9gQ\gf5LQ2+n#}m+8:`p$lhѾ\4@ %=Fz5w.0L-jZߗ="㈻>sVmV@+q~r5=iHXV= "eA)ĒO8EBoPaup' Rnj8gx奥.p(TQb*ɠϐ/ 4yz$u`qjc/o6:bn2 ̌uaj$P7}KnN[ģRCܢQFjLJº*\Edf*bPPBOn;4`GPNJqћA)*ŋS`-])<Ǐtпs 3sj<{Y4}Ȧ3ja8q>eFhڑDpuZPAQ:ȸ_5]CUY3k%t\'].IR.z 04rQhZB ؚ) Hļj,E /'$0~1:k^/ ,S}<1-La#VB©Is˹+8v==2-DtjmPI.>gH{ILXt P f_Bz8e !FϘƲQssas)i+ oN﷜y.${T ܤ$vm{ӗT6 Z>No̷M KWRGz##*@$d2bxbE4+JAP.凜SPx{]'϶A-flcRo]^T;`]ka;;|l"x$* Wzy[Wwn*ώfj |W6ʥ2MUlf.ξiy 48N/VW#i5rVN:S\íYtŋI] چS3Y2g6M9ՠØTriQ{5wΝ(zqBrjN` -bT]P%0-JYcw΁޽׊Ou⌱fOKu+Rf!c$óNBh'V2*npoY&\mjڟ$4An%I>l?ΐp5Ӣ f)>5)B,<1?ܱNp3ղe\FΆU ! k CVސPwYͻHk=>!h f=e WgfB鬅ez+ [Xl}eP.]n)y(uUoxqIu t֟ :S$s ۆb3=L9s1 w^=Enxh5/q빕7 x㺢4yPΧ4]:zE}ZPRt!LYc NHߪL~wNL'QkH9|1#!Y>vڰƒkwѳ?sF=@H/bG ah 2ik\%*E| fI^nm޵zA'nqd5RBM`BxF'eLaC3Ҫ  Hr &Z\!m#|k4Bh IJz$`k E}AYD?U!8x|I=}|u/ˈI*@Ku ̶x+I|bdS{y}UҤ=vE&잟vUmG '>u?Յ*YviN;TZ8 %271tzcm؆][W_E8`ra]jHRA[ zaPRvXuUcIN('&4E]o0M_逗.n,O9F'&Xrj~hać<5Э7/`Z`VbJȝpU?ܮ B9𼡰+i1g]dC%`xePQEFcQnGtX؞8 Lּiō 6ė#9d]/a6y?3j4Cg%m^q" j;jg"OƢś,kIUXcHo]D{7(rũBen;å,6?~b~H0w;DokB'fFژSYz5RϥTeAޚ4ǚ2W{ ю5jYyE@F=ww~^vp zfDr ;l_<(w;Xt!BGTe:Ӳ&̹m:2o MkB)0 <9ڶ⨀+I$Z{]F*lwbC5>ý4ڃB7#qOF]U#{`q]A€vE#T.[}3#D+ A 4b F /-YI>+OED(%ZJrn<S,vmsj\}Lh^9}*z⤜Evg(6xiͯL+RbDv#3!%tqs8xHo-ZgalZr̕Jċ˺JoĐnC߶aaiq!@6o>S Ǹi s4q̈ͧ$bP|;YgЧr[tFɻ5&&Lԃ IFʣo!+{_81y_muځd0v4wf8E0[ \gyd;w&WEC(%[F C- TؔD>lbGbJC g e}hC wwe{" i't0~Tgq N{&` RU~-tlѫ:~$ХO]BreL9p?mXds,rxζ|v{jW] gzZMΏs9o~r\m ~hnV;a[g{3هJc* (]߁ н=_RiQ`4U{s(Jc<w+*g`R qd=mG$&YT!Cc{`hsBw9xqy]j3FA^&AƚwQ?dFcg3ԲB'yNclW$oFv7ݛ0;\#.]mEf]?b7eIz-mtq3~fVaΌn 1矷1B/7n;k_bns2Pܕ38vb,Ta k;o`ɍ^JG-zK]>f落^I"ee; g(1ܠ Wѡf*%0HG6ihV+KdaC}b/uk1>d'V*˷N*XO-zZbKa1%B3_a5OθFIm5,盄j ed@t3WxsQJTqiUc]?zYE1TU@'IA ݟ^Jw`Ų5r?4 tdV>'7biǏ8,, cnfEiRR;[Zol%9vϪ@=\#/ضF$qUC++nDM٬VG/dSSh{!E= ``AjV=+ p9ZPmbfʼ8֌aC|i3*N7l?A zH2^@Ye!Mo,01*Lir4y%Aq͂m5aVR\#zcR띾Xh3+rKr0|>2Ǡ -O;2J7*آeh$n.;Ds6÷ fz|ãEb%Nu c_ _3(6;sOlTtS(/ds/NF茿D?'=Vob7ĬrP)!2#fȀ3%ZѭQEDDrC_c>TsW[X21c5);$tZ׸~9 LIܰ{;{nT)o~V c}˻ _!t:C;UH^Fb}(‡2jsVd-F> iXttR ҿ\,&ZX- 0/ѿXYpB|7D[H.[҆jC3PdCOX%PYҎT[}vY65iSЅAΛp>)隙ᩖaFUCT|GʼnԡnUžQi-Bk`|AW:8zaĆZ eCU5pZvE{@C^Y1jbN$n ucg1!Nui̹m{V`l4fv8嬨in o]#C[9M^t?Җ׊ >h)yn# w(0s*>os`S.Ԓxn/mƱf6xėAAM U֭6\ bICDz,Dxxa=ϙ8x*ՒM$V;:\l9ͨ@xxVt[ſ#jzϐ9 {RqtG nX[Z cŝCs$؁l!ft FBq)z g#)>̅R6o?`:!Ȑ'K "A`DL,KP* d`**s@Z]lc||$H="ag6D 1*L6-H+$R"/Yd5R2tdƯk-:.5I^Ԟ >2ii .&aj"o8Q>"`^7C0b&\_'^&h+?DQ{ȩ.J]wlQ+Ŷt]}^ӸH=DgdJ7VP,} 7phxL}J%5W?K:&/.@#Q|Y~0V~ {Et'43x>sKR2$q"rl3aH%AU$&wns.8]-|*j碍3X|Q5)J3nzDddbr aòv' IgwEZ yQgw1!P39r|l"x$ dpSdtO a;3W 3q lE>~G&y»H u;=)ͥ| gj gO醽cW~C]H/pYt_;H1:eӞ 9-?$[ŊiPs!AV <9 gۂ ph [vҡ/{%xxeXy\ 7VQ,Y%DiVYNN9 oydoxJTNڶ%A~ QEW*%Q=lA 5[?.dOkEjb'+.ZY+ v=8/8PVnǖ ς6oۗ}VQC\=+G'TIdS[7OU)u31/HZ GXwXtv^ y/U)]i'Q\gX ]D  m6~"jW.IG|Nwgj1t `:MRpTF:-2.$Un<=:(pMW/sX%0 ّגhv.ɛJF&C3\WS=ؖF$X7Dy9"_%N1xgYd(cԷyNL{A僵 (nQd_ٴ1r%.tϖ!HsF^Fw J.ԝK ]a4'H _kq`>4cD[a˅V96-V:pAU :z3Ahsn;h=zSZnt"~oQ qGb¶qգF07A…6Z(CȡAϳaDBD혺lPgjG?GskpyX )jRCcFۗq1ݪ$-@tBv/PTsq\wur)TZdOgAK,2[/5̞h$^PJwU_AmںvjA!nxμ|vEАT6̤ AnyoFMUß*pD"ms>L.2;N霢b:tD~`!lZo硭&aeyJ[Y U0(8RVg/wևwN5FP6Ox]>=c`!KlirC-~LxDY4@M8&MT-plTxz5aYu9Jק"H7)%C 0 `B 3@܍iꢊ%u!eF| 0A$/ 4ܓ%[N<,w"OA,- @sKrolF8ԭۃ9q7O%j eXm,kc\-e -QSɄP |ږ։ C~<7]+,4 H-U _1:a+3KoEr܀ϑֱjt>*U#AѤMLjU$EE8A]B𑮤J-w}.L\ial/EN.t%?Pi_:r]/䞿M վ</\k H2vAc}bj P#sOhg{Nc;`b > >.]GvGc#,GH <3:j m+;pF9>gܕR%␪iGMv@l9c\V>uXK $T?"Wf́D \~Op\aɯ{:lKNԠlc^Մ0T 8!LX >"nƸCp)}^5b O.Ц:join4*1ā6m*rABZj'[Tm5%A+]Pr33 G*wz6! 0Eur`_<>`[$Q>""T]AfN4TT(kT`:S@ΉȩE،|)hFfD}}-r0\ [( AW4kbuhhm{6 25j qCv0܅mjnr@JG'iq~)$@I5 M6yX/Wň3.ߞ$/"'3jCK5xD[}E ouUݘyYXGѳ[o37)P%Q!;=(n#95ȼvm6QsU4Nx@w o/g9܈e~|,}6(+Za 5'XTwּ4P;TSŇh`u}â[nAu;D31Mb}$emƼxyoA7|^M`z'd6Cͱ{?ۚ b+g 7uCp­ mf`4;GtadA؝P8J&;7]A0꼢6g )5zR'XTnj¾KKĢ:+~7ecvTO}+BJgE3@cXڒLDi!L#;.~{^G=~=;7ОP!<ƇJ jqҘejzcF&j >5+ƭTF3[Gm1'BAM鞝7P{Jn$|^:@}JE: m#bN!yr"{G"GxRE"""QI"9eT=cFnB ?>~&qҀn;+Jjy2jWe<Ĵ9O>umGQ!9TDݪ%7,R|,9cM&l3WwСuT&7漹ĥ-}lJ_(.}{}_[ó Ewx!*Gp--F0q-E<_Yo6UHB $eį%n.Y?semǞXd.L\Uw5(h>]}UD\(G@赢9.t<ہ0׺b΅OL~^8x@~m L<{Wi]f5z!iuR:_殠-WtlL'Gx} 7!bBJQ/Lop(=J*YBts^^ȳ8*mu{QKZBzYOwքq:C 78m>[ƓrT`̓K'N[]1CÚVSSd}SnW"M̲4:Seto9"&%2+;ɞ‹$VvŚTX8 SBŸ0C G]x#sΧ'~95-DfI FFѭpරt4H$OT _Xas(J-Er6 NDTe 싣JfCGXb,#̧.jH]ӧ]݉z'"&MIߺ?)C\@t x;тNKlP.IJ,H:3ȋ1~i9| U|Eue1O # ہD/FQKJt$ı11QH@{9TB;26w"5=jL99Ig!PSˮv),j|aeښץ!9~B*xd UzYfW|o[9oLJ{>ȲE^̾g!)Q|hU$ Wy+&:g[ߏuB9cjw+dHϧ켥V6a|.T!dk3\g0b*x"< E?pU Uu}DS1d<2 S٧k8qqf5$40wP)>UcYѸT9пX?Tz)g4L}T`I z ouhc}]3}JI(v|{ѵ"IOf)V_q۾cN(u=ʢɚ:`1E? 7Q;? 4+suے|R㜇=R&K xh9\V[Wd;45U@  ^^ҨuMW &9 ) a$r,L`BJ&m?S>&lo1fsPfET')#c(6m!\"ꍃ9}?BƱӞY9xh@1ʩ!\78wHP G*%(/Te}LsLZN@nD8B q|Mihr\>fĖq&}0׊ oz/N9 إ,4fis@5?Je t"ZUr҂A_`!Z.@Rj1|,!2l73۾rIZRV4Z:PZnN:zVRQWDQxH~Je*)RUm"Yds J񄃣9l딍v9Pтq6Ɂz7ں,Sɉ_ FC rg|uQ 47Ay^|ft-ѐs#cE:yVMmM1>%҃MjLScpz{1Y7MBeaO,60Ռ|ڱȞp(0af=jUG W(Kz=9=K|_*٩U5)k77L 46<j|b4[+qqH6 c:l76_3;YUDYDdg<tn!kyŽh fXΫ ]>wBe2%4|.&>^ ʙ3$sPjx5̕'LH"L6ֶjuaث9PդGz[J^Y`*Qʭ]!G#ZN$2$3.#ٶk3+hPLT@oWܱ ^>] _m Bk|ʝ}ݾZqCL$ch!L4Q%Ո /_a-x3)can%.mA_Gw]LB* 6g UF:vIoeA8@F\xdK tξkὃY@ɐWƗǧW( ZL͏A8CˈXLI>lE7bo~I a5J(S;5pdllcAᨃ"oL> O.AH~~);-DŽ#.lʦrSZW3x8iIH^81bSfk+2CyWå8.>Bw0݂$V/ v1Õ/:(ehu@>|A9>c˓~@N\Ȩ׿.!KWm8ZD&g73)3w0a?`@FY N J? [V ?"W;5dKw| qȓ%Q}xoU@yoy %H,`NE(0[q6ώG?O 9G5xUeϵ-'Z5[&]JqH=C} `$g,72^B/ǫT NMPaɨ%`oKPg}x+ǘc'3nbAsq zq]vy!$ͭH$%MGQb+0Ξg7,ٳKx r08G, J`BOtl1z+Έ븰[R B^oQX+321MX"Mg'XR^)1XdwMKe3E)8J}}kEg8 $rDjvI%V,<7ߎeR]aS.j81G@yyF{%>صAXzwFD5m YX̛J2ң $o6Kiq=yq3"E#N4q `H!U0$:u^ _pE 3L=6n`bziWe x YHh* XBkFr||ԝ]nf X_am0mCWkmJd+jyC Sĸz'6bx1?T8_$Mf:IY3B+,!u*6 Ê46ޜ~bնk-iA"N w&GWůn߶2haHXP -a۵Ũ(੍}[i$<6/̸TmeڈD65_ s FU'Tt!Kw#=Xndty( < 7l2ݧ1!mHZ."1 \ g%k2)70^7\j X$~өZcO۳Y~(I2Gw(pfQ4 to^mFmOgleJk t;?[A^]{"VL`'C^LOڿV^bF2~(XAZO A 4Au[3OszF&b z":V#ŀuM 4+u_~a Vؠ۾h8OVcHzsCKE#5NF:R]e Y3~-TiIY-PGgkuAt߹T,6=p쿗GQlG*DEMy]̗jBypn<.U9^`|*P (vZIA"u LPT-SֻɈSͲ<ҡ3ɍ?+<ǷFk';CDʜZ39@e9’Oe0ψy/?wjd5zRf#0&SF}?n0:0mE'bݳ!e"kb쇝_5ÓFC3k_͂!ej:蟙h.FNƒlM廒6-*FyPHXj }lږh/W- *`\fC׮--1ϐ ,<>)̧ 咋PiʠXr}_ں}^i ܷڱ  xC{hfoŠE-Dɥo^if^xs^=w]')Y=E E8zis޳/\Ҏs.KȆv)%ɷk>9WX#o4P)6DKe.gWs&h@yNRUDx4@wpYlEPILK̩8> ~ Ibzj_:g:\f[ǼT6/5u)&a aȀ *%oFFϳI6vZ50 ?xl,#x*/Sh5"K s!ݠqz?:̕|dt&L9O#V(ӸKtX&;E jr{H-/+q}6_s bz )WC¹ŝxFi .!jɄB''GyO(&hѪN-W2q-m!1pV dMqQLtX^#t"6ʥ=^<5ZNp;tӝ-һ]5 YU9)#&>4Pn}|w 0ejZI~?Qf'iMSRTSUD'޽kqsb҅T)_^NjR  zQ}}dIΘ +g@7?}e{w%!'[u+dž&ʞ$2\1qU2GauOy@YvV@pBom؍)t P$hkԡ7\<|ϧ܃: C*\SГY],$VRJSU#aƌ'M|`zTRŗJS"^$8-]EYd{}^.eUN6 ܶ'1y"9'B 4uꃄ߾EРlސVn8PKNJp`Qo}|P͆&RI>~a..kB>$A RS=O@t]EXp8wQhmo#>㎦Mh;. "KGeDצǸG˰HT[.d@1}('%x@e_8s]F/  Â1;Řv"}݂b ^^aE1ŕm<ϘuvR ďw2U*4AlLU0@ح`.os4iT*}]d=CXe8ì⁧Zd) CǮh,%$Ls~)@uVC {c1&r4%%> [Ta*?=$\9{7rD}U7g * aBxdԠ0=/YШ ȿe*T# $ x ?=tOXv9U4G$_;$s_IԂYbԟK"Ūs0Aad}D~Z}i2IHA0>ugÈٌbE֩lSg.%R|9oxV HN5S 'Z6HrF!X\"O u5O6dc^ЌT|ѨebcM|-K"~w9lG.CH'WU4" 2e&;ў< O:5MIn`B$%TɔQA'5ͩDFx,!&} I^~3a\ФM|C 7r4J,V$6 OC A*rLog}ȇk+JB>/AAnss$UwFqSyOA6R$Qp3$F?hկt+Aھ41E[b Euׅ6rJ者L6_G YlԠάD٬M/!YݡÍ 7볜J)-Lbfˎ/ ptb1-Qb<$Iq(e*֝(clcxo,Cy3ͽ2Ҥ%']μި =JhԲnnOי$I.=6OW|6E _hc|=_Z#PIHz͛Enl525eZ *FxN&z CJʎVҌDqpʃM\j‡Ŝ}PT~2 >WMQ,P1M=sIۜ+7lDS٤W6$^֢IX2ak9\6DZф)<+"T? cgT~:ԗT42VCP6{(OtH8!`;7qAޖz^ͻTpvn{ WJ 4&^ӣފ\hXβ ׳L3?4-rΈ{z+UՔ)%^ZDqBw}ttoGS}`P?arH$LH [݉*P YoG";5nw_2m O-/eqb|qhZJz\BdHUn;C4R&Q08[$.l!k-͍л/5z 8OD cnVSvVb|#HG-3wEF!Շ&Cokon9m$fׯ,@v &W`'Q:"j6LfMҋ%m80E .|'ˁnL ET/xӸvdA|߁nnLcF6f8;Ѹ*M0ugYؿ6H)/p);I_"2;^F;EupmAk2h8@ZnzŘ:!\_GC%|D6P[ёǯJە (n;0+FDbMϯEi4WinY4bbꝑXK-)ce xnnx&W!{q+ط &4DE`]AdS6y4p V|Z) JҒ5#; e `!՚>&훾SWTD^k8URj35a Y/& ']Vm30A7w#=Br/kHEKW{PaVX3zo*z F0{ޭb F*B*%ܦcٔMdwl8u,P=А:t,qi8Y-t)ǕInev@KF!'mMg|<;˘teyfWm\qETM^Q>^@ /Ǻ1lD$VtuI Ƿ%#ӡ \d{8M{N꠬A2 2i+.<>D Z=PH E+8.s NUsffǫZK 0n=@~"`9j48;Z =T[("0TKW>i*]׈)>, t{4DAIDA=㟈PבOrLhďZ)H<d Y巗0pH 1LJPsNG2$ KL$ ؼC "6|I [yJ+UEՒ#xjr+Z,u %&=Osƭ‰E"НZS(nJِ|ŏCBVRxlȊ=?۽ A^+T/qK J>[]ۚstCŸqZpo4Osj4HRrvRWbI,AЂU7y{И[NQK]9G\v{/*{ NbT YF0{aM;"ӓ5m #ǽphYWf7j}#A:\9% @WUPs$ FcvjkaD.  @Y#n_>WHIȹ tQvWuXdX㾈˺CE JPTFPs^u4]ή@wR SzNjCOѣX>fFfnGbYOxW|Rwi堾| Ep~見E c |ɵޢ(0zh?^$0a;=9|g>ӃɪSgo|LWwAAO+|tKr7=d= .*܈}V9B fk;cةAgSmgY5(KFRώ @B2MC1)3X)_·~X?jՉau߶Pe"o{4 d0S"H^xR{$"iBLӎЏnd0IJTqw dr,ܼ`zP!]uzJع<ϓ3c&%Tgɽ@&# SJ9H*! d֩,^瞴H%0YOO%DG19hv1/gΝՋ .z ֛Fp3;N A"0{m4c ŜS lPgO!FK5= Ęqh>BV@Af-ŜɱG?ṷIoßvL=qޏd6|{꒭y4%=AI2 ϽӆElՕ<^ݎ^=OfY,[K_Om(n؃|B8IyW0I!>4#|(C @$ 9PU|hǴ*?K2.U,5mËUp5&aƑ8]?Kfxo?(Zz2&=Nj^/Lm|uDWS!.Q̢Jga>oب"^klȕC׏KѴm,%hn+TIkSMYxV JnyZI&əʢ+pobijQ +̂:^p"mjA5POU1?1yx}PUR1^ Up<]Ky,]r QBYMsV-4 v0Ԩg `^ Oq5:'=dB7_!u8]ĝ7(Uɭz_&ْD5hؐb[ܸC>kXYbIsqɡ: )U1 퓇bdgWd%i-+P &?IU2*ْako:.sI!}b}wseZt̀p\3_|#LBwAN&I AlJ^]( FΙZ]v^ #zab.V .X.Ƿf2 چ?Ѐ/7ΐXt"nVǵUV^}?|/yiK6̻HR"&oאIB~ }{@uz{ϙ+shE MYKV{YLK( C( [Guwśg\ye?JY@ *|RX cNf)_Y{x ;ўy̚|q*_DOG,z܉U_(i~Lᇆ/_A< d @LIu@cyo-[~V-$401^ͭ3w 6.40vZ%v>^릇:0*᩶,G{sG)dDOH (~!YB$F\ n޴I|~B 4A d?H([Q ME8x<IncSW3ĭ+8k O59+j^5z tP.GFdbM"83r+)= ưl 5pSV5F׾:jn)Yl &b%I_NjҖڄѣ[%Zek^i~;~K >1%1jhK]V =U}"lo|V:m_*-=Q {[=ކ׹j~7N^\ށUn> p Dz^r=Y! CFR+9tDXn?Za+fF[x(P35PɕiGq_xi ʑ*!-Lb0~-?.Ec k!f:"ޢK3#; 6)cg|'+rL>4hvbA=cII# {8u_N]Jx,'ÏC#ɤ%xJcZcB\,C.^(V Iv2"T2 ͎,_ktɀ*Р P5'?m h1k]UeM撕8ۦuN@pJ c,ʓZOE?{/ߐYOhȾ rhE:Խ; ݹ%@V5}Ju;Jl63XID)3gv;HbLgq ut$ ț-5| Z!ק^?gd/ 5C-|wȠVtKwI`S [[m[~=!k:Q 5V/a1Vr_B|kll0)ycxhHW/W}I^XЍ%|c^s`vnZ"zY9pÚ'CWi| K\f ?RVqT)?*>Fa'/xP7kHl/o|g?ZHQAK*S T\D5㉡$JY}i 6 2Rw=<+$d|~}.q@&z:x="/E;1hsĮkXy(8(7`i+Q1VGR; p$ Lf#IFʏ!fd UЄ\xNl(Xu[Y xYED) Ao:cd Ԭvf7H2::ZͤMIVI 0~>s>Ѹߕ_mCf$Qoxl@stYA B~an5>jY%j"/R-T4!kFa=(o> l/fm6gDK{ꜘ/TW=l { wZm?+Ɣp3ݖrԕ $ԓͺq,*|h\thnkEK/yD^H뢸x0v  |AkG)ea"i ~ 4p9K8#?D  C K@[!K=̠&?$g37;&ͶǾ҄Q|ڬl3Kpnݟrpx@vdbi%PC۲~3uA.ǩq)[/T1R(5gAsY9dFWl@{@d;RYY">H0׽ ]&tp ɞT?7 0F_v4ή4~gwijlDJk0] |뭺{-}*QC~Yg@=wx \3|b[uGy@~Mb}Q#kK> aM6c2rLnTW jmu8ʭ")1ֶ˿W2.)񒀱kևvlKma|x)c@F:c3+:z/d!+*µ̉8$,1LUb`?JIn Y(KLXmRva x}j4}ͫ`: {:]|]h"&GE&|ytCs< !THqm}!OZ*y9>$e.TGSm]=C9mig6.UuAHebg\l$zf <:VʎEg7끅5$X Eη}y-˞ISkZ;UWfiKiFbPOyG} K+YXQ=ޫ/84bs [TAHLRiߦuq@:󊗣Av~_Y4dh.ͣh2 [a.[lxej|.^UzZl&wR+]RN3JLȫErΓP i1C &DPOx_-uScSԖjTe*BX6_7&Z[rq pv9"!:'cM 䁞L)3?wCKHg*e' nϸYǿd\VaN6V4H _9u0$V/ md,>ny7rě4NfB +R^y SìhN…Ʈo}0i!7a唽#tf%ܴBeہ 4_tb2 `u?d-4,,w4i"DQ!9昐e?vK/?W,.oGШL9qU[Q:6tؤ'tw{k2W d\1}xSR0Sk_c)uxcAQڭF }7o n~.xVcf.V̲q-V lK%{`kG4;hY8#J||i~ы徃R'iN[rnS87A{򒫽B R7gzگ 〩1 oXZ`3 ^%^ Z=/JVMTG bLt9Ǵ}PmgZ3/jl콦tX/25 'wBmEiq:0lßγqCĵߩjֿ0;)gy{X P[a%֎iզȩ1B4ǑBW[ XuUcluepZ_][fŐ=v_ƈJS.}[]ũXEB.KVJ`Sbp~ϑ=E0>=(O~ALÜ 'C) I(H=шBpiFU5"EXT# tD W]>QI.FXZc0gN^ʰX6SKfyB*-D MfW<ď|5ӈjvPxE^Lk٫gbA&4gQ)mAl񗾛43b` .LyfW(Vέ1ڱxS;>;bL!_ը5">6|O)ͥ^7;ʊf?}aNR蔅U&^ fbWأHq^ xi@tpL'83w~V mc&6&<{gm~|6.Nw]O9'و b*✞|hJ*]SV3wIL/pK Nruur MSfV9ju.)!H|( ~S\gVFRLiŰ|b7XwR_C`]XaeigpF:kWUrL 7xTpqF9}y%mpQX2mZ߉4g>7kKA3xWtw\ Q{_5NWNboaW>dSN,Tú%2Y SDj RƼ-z-&K29top> ҝh J,@.v 0P0O8 3zCxHz+1hx Ns2Fp΄fKHPuQrxKWƄVI]*h'FmMpr~u-sS1;5ΰG]P7jX:''Ncyr"NPY Ou'c2rgu=,}osy ÐJ]gZuFۛEmH>}V4)($#SسQy>{aOJOzI~[ n} B|I9|4 _kOAE;@kП!pv8V4kѠ,: SUrJ.r2 nnU_+R:C&\Pҧء)Z N"\Jc鳂f/'{wf?TS8M"d*'eT7bUҋbW3TJE G3ՠ6>G*p}X S< $n^cnҚjhѭΉev0+LnjˆQK-@?ǥcD,CAOlO *'GOF4ސH˥N'+DC:YtI "TyĵR5J4eSo- o+Jl-Oxf͉l+2{cY!RҌ}Sgߙ(lWKwc/iy!OxUː]MS4qNkU11 0#cB RJ_9ܟ/1$6oVkd j_ &tŀ~9FNmr(H(ŚYMB9sX(#Vn4(w!OEЁ6ƣGS_};^Oŏ+YwJqG0Krӫg l7 "AH Y_5X$zNQ sURѦIV<‰ȼlQ ' (z֘MWĊ;F>4I̻2aeFɇLo{hBs٭ӜGi [9⇬P*w7N=.öOC&GJ"Z4/C-ej/Hۑ,l*#}$Hm֨ ˖; I w4 &-I4ick2pcjZ.+CϦ06tiǗqAG̀-,FBKs2Y=_*q{ W4Uk6P/WfTuG@޶i jMʊ@][ה_ײ+bUcws~c ɿ zo[??OsjM,"!"V/uP"gԒ\lx)(S5>8 蟈!be$RV;XҍTFQ`q󯱀NHHZR[? ?.Y3,T dRebƊ*cCEi$O?vox0Mۖ ,i q6+~q:(a9^/aplw⏧ҧ=T \q@ȓRdގtv 9:f?[ʋX$b穬c%.<&}g K&v_pڢV9_1b-I3w]ǹ]'*҇M)< ֔|ݨ.M/˫8>9XSwކ>},FZHZn&_`77\\O}_ B$Bbҫwƴ֋O+ym3IrmE.\5Dp?cO6-V-0hx2~Lw daZ9=l>טBRvIt5hRN92ledY ٺFfvq^AO%Tc5 #m?8xG zBLԦ[0bힱwN+bͅ:WOSoj,EE؇ y!1XUmݡd܎4;܃%;$XW8/CRvc5H6Xx7PJaq:5G*{"R+:sUȷ`%iM&iG/J*1ppw/4~TC(иڊfim먿hpN1 IH}Dh彖aADƽڇ T@o!l\l: NO$ t$%%#+㰰ΚjH@BޞNj~iR_`fJSL`)!c[iB\qpv܋` { `Go B@{ xmg5]܃hA% XP0E`PEII1qnf!>Mp^GGm{N7XH$t!OyEWжjVףi uXiKށSZF;gaH?֐aN=tEli)|N=~Xj_>]VxfᄊovG_GCi"1Ϳ8_:0~8uK (NB#·)A]U^D?F=cWRSC4R|lL8i:@EC"cx sF߿vsRrDV?OˑcwLPg`KMPwGyћ /ӞJ~@3Tr!!Yi- hiV K^J xxߦz6\x@ Gl,^#eJ*0Ak6e|Jߴ R>ceА-ꛜF VH֭k0D\Ӣ-*p~H]LS Caܪ`7 4dBsO*VgDe{5鯯$kAl1!՝݌ U{Ld<9ȁ}B__΍]03[Lohz[ nʝE.xeJ}R7;%URpnFK|7}X9@VYb6xDU4!q^ETB1WBHfX: cza]LU l't?NO]%9cFWz%$̖W64XS f*FM4cŁn3ã}Tg+GaTa%SqzX_EJ?u-r )ib!]=8FGl>w^5;a"X PF_mI!F_l =rx Xpplِ)kKɞ VK,< 0htŧ؈q\eDL5|XavZ8 ]y"}|2!OB{\-l,oC_T O(_ej;&; Zİf)A3$C7G,fצKiB>/+(O({75a(HlE%yX*wA{J1sL睑uYI%Deڮ/pkR}Qo%! \>(M;e}69PCd!"O`!lY<+tߚ;ڿv _0W |WmbMjK2MZ^$>^ƱfAB^`M}+=UrFOY-ZdRB~OvaBpA%O:/xMך5#'a'pv^Dڛ F4!-8\m*I=c%RlPe]iE K*+x=)+s+rK@7թ#(۷F1 +ݮ`74:WlǘD`떛7c|T,D$Fˀp"znNLAL}}&|hNڞȨB`IЅq3Hk{zud斢20Vhǡ@Sj;@jBOL;`<ۤUiͱ Lrˣ"dt_|`tCA imu$Dʗd6YC@02T:6\)>G/Oo[mƆ&eMt)l4=V7mnz@-n_LG̻珳g>ᄇˁ.l#m`7K=wMgGhYt > m=[4H`ʼxnW" _?z>yu -Ro2(Z׶_B6=dr y^`Ǯ]˄S{yty3ErNChV۾c)soeK[w,KW5 ^kYjYFA[$t(܁Z̬X![^kaDd}+b0NVӿfo4,Um!XTvomh8QXUXLdI7~oΟOH U3;Kj3n\o)_/DLvr ^pi_:Pzذ]D[@)Vqh_ FA]R0Ȱ |";+W1AHvȈBeZޕq+r$x<ƽ{N;a|ְIk/$ЧXܾ;W8""F:(T72Υ5{Uq6uӌcCƭ sKfD@2>$6edhհ~zΈs RKT&-s yzN~\jQ1pu}T3 FlSVsl=4C.fm'C࿹wȩՀNh3OIdάp|U"&MmNYEhd Qt*'Cpߦ 7+ Q@8ӛ1iOyZYzmsw@5kfң8Jb! xXXP_9')D uKNZ# #.xq;;1v\ aN p/Q;[W(>|\ͣkx|dfw״J@怏ƧvInBB3?'ujU#*Phɧ N4 C_քD i;0*ԛxkBO~b+rׅ18,p7mT/jU^LXL+$]$F3]n} Zxa|Ykb#rAy,^R8!5̞?xpZ%ܡG/s~;ەC9tӈ^Faڂj(N0Bgq ykf@>; n쫺` -$2.;ո^LYV#|Mh<H4p؇ r5{l>t/j}JB-Cot%9,q\&@ZNN9ҋ̴UϤOMkIK==%Xp㏹#FJ6$=Ȑ^f q`JWYAбF B|Ch aJ<&M3%Oj@cViܔ H&e )FeCʟOu?75 Xȹwn>?}{\&H`sCn6N7Bڀq=d$P1) TT?Fzi,v'*gT']@0(ƫ} >浕<)һdDpu%0S'% }ЦUrӘ-}I'o$կ4V!׼! H$˯~^WN/u>bI xËTJ&큾4mZ[ȇ#;@ȰW؉mժlzRtXg't9G!t.f7[Jw3GVf1f7%ܔ'5V3~R,ؾ-bdME%`\ uvt އ3΅;VKT}ߪ,ww(ub?r;@;yaՕF Lvi8 vXNAR]tV33 ^ !9j(6 [L7 dJWQjdAPc:mfXɕvw H;'eJmV8;Z@7"?#AeBifLÇ .\??[ZRF\UMky YiQ?`8F[ZNz15΁YENHu6ނNWa_!QWX9Y X??#09:#^]uaG %xňwiFK$V Y&Jjh+>u4lNar8qU#Rc?np Xߌ]m|W BG`P)e'zBU) ,WNrѷȈKMg4zy#PL<ѽ!e<ʂJSb\ʄ5~xYo6݄C^Yh_EZ)eJh6oȔП\s6_X'@}$KCʨ=?Ϭ^@Z~Ua揵QD)6uK&X%\  Q* ԫ FZk-=`UJ<4M-ex.Msmf6f=XB4'r0D r|Sx1ݛɝ6_qH!0v} ABzJ|^Jfʓe9gF "oI@&zyqB Xh 8+zY"ʹTyCO?/2&;-jT i\:}.Nޣq7tIʝU%7>tAHc)K2Ixh${Gq㞰ɨi5Ad,K py%oYԛ mN"$CjQ(pzy}ՓՌy{>eτ3cCDD9}>>fInK0چi4aq9zQ)_Y8ZZ8EI/ˁmi$OZrXH kf~h+tOݤ*LBa8X{'כ~#i,, CR镂 {혃b|LOoZ, K0N[}㱅.+#D[ $@&L6#nb="]չ#2,92.tI) '>U#'F)loxp 36SASEH TK,Ç F9KKͬzjPaV:gI(㨆rBDZVH܂.aL$XZ'!0Ȱ)[p(S҆&@ٍd2KsG=6T,&oA۱s}Z G3-8џV^PBT%]2Husp fz [:8o&:Fv_"k8;Xm.U~8$0ھ`gsgߞ)}/&TU`tpXSUJ,#[lWd1ضn3) <KHt;%RnJsÏRm0q;`D6Z僿W&rʃunIh=wßBV*sǐ5V'sF vn P xc.ţ yJgk0?|$Z4Fdo 2̫V TPZ(sLj"hǒ g2tUfxx)XU#㚛GJg H2hz͍(/ U|܌$+wɔ=:@O! j"M?[Z *g/ ԨEa\ ڭ ȏKĦfBJXbFCsgο*\Iy*37z-8yB6/^t<Ӥ!Xq/x˷"jҦj:Vt'lm,GN]?чI[}uksgV >ԭL%ӓӷWI2_0B#t~S\޵CUu28[;Uա VbZ;N-/"`Uõg傔GI7 /K')ə/9⬧ˑ+vjE51A(?ZSB/5ȼ׎6 Q晝Zy m<-1n%ޅ5lɥBG)(X Hۙnt`Ll&nw(ƔucMwFĂ0g\sfZɣTfn\)3'H>poO8bRɿ'"*ng* t3'Z{q`0-¡LFV}`@C=׵m&ep-vꖊ L`¢T@p)^1fZ+"^Iwh]U5Em,8/(tY[J͖ uUݧ*rgJ?n4m秷9=d`yep=B`%'FP-и:U pÖ9Aå:j.ke Kpϯ$n1m'+f!}GD\tv_]VJ?J>O ;_35.WѮkXu!E {NCtT(~;*c,)gg|w&Ru*~Ϊ9(<2/a\SzQkIwjR_̧^kar#f}=6j.[ 7uۣШP[K7@ i;ѫ,"(n3a3`imc}|Gԙ5x"K-T ܴcdؕ r,%Hk#L0ޖn6,oB3ҿ+qEpdSqK|g\~ N"LxmwqdF/Gbx{d 0ܤ9iheg<(!H\"t!v1H/OP.X'YG^mbd| NmK -aմQ3 sinvGL% }rvQx5o_!\?QSH=bJN D<s*x C'(xohrB2x PhUfƫ96z[wޛiq :wO&͝QO {WxGV-5:z:CCI#题BWV989tj݅ʦ9TDp,lD@!1J89Cgo|#XM84GY` 5in":X CĆL7p3{~N}~ 0P\j2i2G3P=,H4FXa7əRO _ lgM D™~"RBCC8|+xbϹmb=1 {޴bEze:ߧd@)/B/C\3Y O >(?wZ jC~<șM!, APd ګ$9Tz}w4W ,`cb>dV d-X햊Koy7tѥCެq/ 0 -X~I~'=Mc|;4LwV$5cI݆؈Yo9( [i3"9ٚ-)[kGHvY`K4i/f0uwUadpbY5(v8hnW[<ͭa=AHVEW٤.ײYR8pQyn#[mz%9?@D,v.'5f00>0r8ީQU`~jDs:TR`grwȪ#\gGm)`mhmiظesD<ǁEmCZ3<$4Nêo<9N ht *e3U "Pr Y˃iqS7!m0 JK1 ~{ wyjMOڳ>)f9+͌;?OnGo+UUx}qI4I̔|az6KG,4ZZw#a΢MzB 9؄9YXthq-΢הdiyz0#JWAҾm"pl2ʈװ(I]FoqC4"j舡O~4~525BQ^&R@$/٬ꮃ4^$Ҥ]RԀ}am!MͺtԼJ3w6 k 4\{nx:!i|GKHD÷'qmu o0Ϟ;b >TЛ>WcP)?[J\뵺7%z(;8=*wԤȌk9+H9 %|iZR 3g~H/ETvZMpmi*!6X:UbU5/*xg!DҪɑޒ[M Q`F }ʽ]dE3 cb Ƞg@e"ve6$7Эz$]*%j~ \zh(((\>|(*?;cJ-?LcN2I2m3"ɗsԿ x4 K hFݒf#~.CߟT ]JEE=3sCےwiTuw_H\#6 >  *3eЩ{4q _աĦ4j96*ņ̱Ꮗt\?`WI`NGkgKT6Ը`'tUҩܞXԮas!ü+Fa !71PA'r'ォ8Wd'1¼dSFJe1,E+]$V.^b!Q}Ɗ͵<2UiI U$X` +zoDʔ|* ϓ֤_{'> T ^L,7Z _>Ly ao(soFMhy)ٶx:+4PDLԳLvgϩ(&cC~a‹&> Qhd#,iJ PMEvv#qAm q|J-j[n ]q^@X:'eK!< k{xtj;@ļqZGcƜ&< V$g^Y]b+- &مi")U׀3{IMs6e'cveA^a4mP; -]mYNWDjem{wkZHѯ0aT.= :*pt"J>PDQiq2ZMAx pesK/ߢDI~1Ÿ X&ԺV.O,\X3DUCg0b.g{J@9{_}A!o_Um}__ ϙ}hpR9>V;WN2Z_GƗNP~2xFcӃ/Q8/~]o+`Ee= XWq,<իX0o3rd^֭ C4:Q'3`6R}+?]1!| Lެk>gJ1yZ֠ZGwĜ5EyZX%R̔d Å|pJ8ɐAԴuqKEn89P7{Qxz$TVLL2$kB*UX7H;]Pz.C9ƈb zÈ.}4q oZn:`ܤ\ z\hB`zWe${xԓ#iq?>R8d}SW4.tuǐ僈~i#̝lmџ[%"?E6gYkaP(u[lNIz4X\* xgtR/]x^YԿNߐ%Ë!`Lm2GrYiy1h)z+D7~56?\M{uM5jld}'uuů[ѓΙ of;ٲVjBdkU&Z0:cLiiaLSvdP,")]w<=RwOji\n?3˔,+wØ K8{rumMxiEr\VdU5kF+١bU'́C[TQ1>jIy9[ȥpt(p52חfVzт6"ݵ hU5ɉefho;kx @~xOc2IG2ft4e(lTR=V!KVGQz 11b/ZRPkmBq#V:klw-KM Q-o9Ion.=/0G ~:L<03##iڧa""˥6W/EX|-;7p`6lsIQj?E^?nAp:/CEzbQtx L$>L~Zn= Q2v50dlÈ.e3ڽex~^ Pdٷwf2M1k&##ׄc[|>v)=ll.AcAYVȢbWYݔeFeXWs*n )u, e);e3.V8m&`zC,jy`4{hJQa=tŌ.qa_˚ q$R$uwN<'r4>sO7Dy襔:=%, h\͕))hnsOD5-FLφϺTq|(\Y@f,آ,jq]j}Sݒ0|gW8O*1qit^{/BLJN;<"HhWy ,Pкt µET|} UuuS|fzR]Vƪb.OhMʮȈ ܌Q+e:<#ڳ>x._:kmı_C9-:]B|d_&fF_wv/Wp. =ua=C408 LS| 84xp%03҃@pb7HCPXfVԇЈSN&GDi$~bRY29h ?mJz'GہƝE6]SʓHFk^ 45j(GVTSL ZB <*qL1|XY$ 6˩Ur|"q7HqFf 0?V9 I^huPNR1:S-z7𳩜x:l07/5!~(&\!HqWRɇ|h<"xQ==@4ib-V{u5?~R3Qbpu}3pbJ0$NV̜:@y'B\aUA:s2=.]K 5 lH tviZv:;׵j4B~!p (fLmf{"3\*4( @6>/gryAsa-)&;e<7aQA3E LN+9quAn[=̖6Yz RjiY.^Ѽ-ut[5Be#?H!z[-s3GF)MbGJ3ߓq maG!#ˊg ߡ7piث )jY\ذ)u{`s""l*#S89iZ_d5'dm8N\$ʕR V+j|V*Er]_$ou^ |SHӌ7Co1]],X2WG۔QWS%UR u{߄- }A40 3ќ*^}VIKR߮VS0%{NZۮT(Q.NW~|i+ܱRD ;1j D9̈́¤OuUMn7?o2dR_ <u& y8F8& (PjAӤ<~3u$ܝHt^mБwz;JR#b>DUI.rКRg/sfd<cdB[ @[( [랣_#χl39M4^T.4X6n_t[=;@mTSGd ave_Y&soY9(üϚY[=GCs:V4n.*DAPzO<>Dvje}?%Bg.dH xFC6#c*F^601uMȊh\PSˎ$֏Wa<78`a,2,AErGoefv2aL2˲u<}C\O6a"=) 76 s{-A8X+ W/]P*Gg-Y2[&4BN(vͩ<&9<ܪׂ =}ǹ*4/YTv#wN‹~ާ  qȝg?TKrZѶe۶o1!wax*wsZvȷ4yVQ`($EMMFE[iqӬ ˜R۸1ֆ<0/K gW$GXW =FnvP0b6>}Ag|+/kR.(cx\ȦoĪM~ L[c*4> Ca~Ixې2 ~&SsxK56O9{ K`#qcˀN~\H,./(%C }aDhX)3}{OԄ:(my7'PaSDHB1(4f,mJ~%/:z!\m`_"䞐_Ġ:d.f/QUL0~%'9ýsJDmS(3,͖ߵX֣?Q3{98˹$ S|a(foI>x=%;pd`v`/cU{Q1硷Cm3š+hF7*U1QӾ{BPMsr![cǜt͆(Ћe3Uӛ\lN$Ccvc2zMEpgd8RI_We\g_[[˴ ѯb8]_4!} `uju \|&}%S&,S:,9"gQX.x z9rOAM4ҎE~joq:q(/֊XanlpFN(@1j#@'eh9}Q++tKջ 㢛wOE TA_?nV+b"1"ZέW!`8)bM p#ޫ1F8{K~`.yU#pR@WMl2D<[ 0kfdi mPBKC0[t9#BLe>Hmr$6S7t෸]Ժ@M!I>=Y~L0A\dR=K.ԂW^LNM<ⴶ~/AbT9dzVrиJeWDaPH1`ͨkgm[y~S\;ТfӄXQaIr,moup9䧺4;Æ+ߗ^ͬBdK}01ż sF&vKA)oCvO\x9qHqɖ;0ƫh?IX5Kxp[<g h1uILM~[~(9 #ɭx97t1솈`=4-V<;VR3ڰ.@7ksm@ ]*dJK-Q%h|{B= ]H$?<$'w6T;e2M["f\5qTLEKGgZ|BGQ*p<}6eda0 ihMu DJf9u>}Yr9Ÿ3B\%+PxP\^\֢b41b:aTʋ+DDMrkJNNPyb `~rQ4zR_C5cІc@"XuJS<ᙧ5-!-95?toqS}ysuuȳ.`>-k$9V'].$)0:QQDѰ %3]Dq"GB~N 2߲f{҇E}rh1%MC}+,F`T}cK[H,t&FPp.٣jX;7 Yds8q!_Z=t6O R|jiTn1~-{{ƒW~{9)"T_&*10v #p3=ϊvCc1{[BΤ6% {K2Qv\kS8$;=A6:D}X(IOcbL,C&qTE҄ 1}c;N2:ߞ2Բz6Jsk:Qka%R[{ʼnψX6 Ss; 'Ɲ 5p9)|#DoNSQ>{(,;L'S_`oq h,SgD `';rQ\QYztNqo,['Yu2xs].=iT'x% .﷍Yĥ#ʹ_8*- /@D)]Cy;>*>OzN'aoOIF@t0rxS7.+*b P) kMZ)SfZY];>Tc+O d[x5/3?iJr ,Ve]BWD׷7KlIQ_<70yM\ggYT/   i*ovٶ; @|U _b(m]In!S\+Co*B#֘ѬP%2}7:y{tHZߛܦi7Ðt kae?%7E2ϐLo_(KDjEIw_{d>Zz.n՞]i"Đ؂9$?uS!mZU}koqѱMb1ڬ;݊ܐVeOjGEsFNHNV QŎ.)Rʻ5՚FF_tSӆf6n_S=ngy1ނ[Ql֫d,w(r= =USI:?h.P<<4`˿P c`$%wo?>w< :.vd}"MFRNgrvPˣ-f~!զ @ uDhP4w'"- ^pe47кG"U6xD_=$sY0v ᰣm}n}7g}gddư4řFVrčgS݂ 8*p/x؜E=fٳd?V Qئy\awlX<&Q[ƻ@ i8X+6?kNPhr먿oάF0(HnKE"{>a{Jw@E{AXTjd+`,RL]͆XsvO^FSR,1zokEvV)4tN4=BRrM̂bk6v$JoNc<6BR/[' BɐnY!=0qa@Ωl`3Fu]ܪL oj;BBNAoexE\*c1w/@j8֢vYNс;.ΊJjJ#LI; ʼn:^ nDx$=5Q\ȬҁXI%y\k%X#08Ic\+>,ՙSUȕ#T2"n:Rj{@Ƥ(驖BiP/aà 0bӐui!"j'}mG(5PBЛWW)+jr}^Y` tОCW^sukk{)ߺQE5]Ɏx.:kk^aETB|jTnl˞ΠB^]= kب̓o=I\N\S?~&$ WYTLЩh_Af+|NU߷ͧ2o zFij=xv<j?I`6U*Q`.=qq?k@XϿkN{Iߌ=_1gUѨ4Brn~/>!t: }G 8 0Q[i:y-0q."V*dZ6DO&g'K54fʶ-䍱,F'8+"1CYy\Nftx7ER.5][(3Z -X9HsH릑K}[M^5c&qeEqƏOx ~YEYЭCNU$]]cpR3{HW^.81\˸ <-:zC( R̸-N'K n-4hm(G~k<:A 5.*\Ĉ1'>x.Dj/aZ-bM :%vɌ&a 3&D0nJ|.:dhP;aI+\7&[#**U?ώwP4+ztC7ެ XU&]} jFQcFrlj ] twP, `4Z̃)0#ݰBLFLt )ch"F Hl{F6(Q/f(*fBq)O ۫L`Cc I`;+!͒jqo"{۪z‚=N:4-g8*X@:gj=~T'ӓLjo {&ЮA=r~pFtby(&` 4\Go~k!̳kݛF ap&Lgn!ta'e:zÄ~0lDO PI*kI)b>5re⫋ȳAPJ>]%Āwl` %*~(3V4hپZ# v,N/`R"k<[b#Han>UUGVq":÷SAN dؑ0[Ni]*.1&'%-JD Bs>K>Jo`\m't!ز>#yPh`v( DT0WaՕ?mvn3B|tfU hA!JDXhAe|hUegi@8&(|x 4U% A4^,|\8*?#+ac_T5]f2)5/Rn"'$E|jȑXawae`WMnիwg1Tޔ0 >D>XZ-4?aWS @>S)xm2v[r)'j)B4 )Y[Hr@(~5Df,m7BLl[ Mp^`IZ&p;:NwZW$,#TGX#tf%N'G$w$aè<5⻖[ 8j?sn+KWsswWfA{UBS߳µtzr *I H<6Op Ubeap[X ]t5d5@=a}tOcYL{Jʏ$ݳd!VV!AG oTݫ*ٜhode֗l$R;3ȓ qjJ#yyWYXLhG-SpMfc QyO-%|X&޹ [38!{i|TM?FV*R{mymKQGdaq}Gp^6؅ ,zObtF0i؛" Su~h Gt {=jnhnMVdۘN/szN[, p5qMoz<7:Vm ,يLBDc@cK(74 G [5G8eTvt1[-&o[/.>?tcғJ 4-j\kkU-TҰ8K1|:ko 9"5Pb/ Nk'%ܒ5VĠ:WnQ B٥NƗŁ̣r6g'z? dCeuwqh3tkƂ]wr9ö\?]pp' ~K$r>-:0uv#'eD=1ŤDSu }  (˻1Ėvoe.1,u#LÞ)N}%web6AF`|.'D .&4_H MUd |CY?n2ͥ^\eJ(h-rFXsi+.4dP|q<Ø8 9kQIg;V+T`[-F&;{pQ+QSIS2r^ M3f6Cl:~ ('slΆt7;GtI=J&JMq_<4{;xVBUNR@B,OD:9Bn^kޒ=*+'yS)ONs@k_[a,N׳RU643oa+d Ok3}+eƉe' ɲaiLHX'}TNcx M?;!viiR»!^pp5g4U/!dxh-+/4!{t#caSדhmr1pj7M#Ϲ}}b#NERצ7]:. ܟ&t)Tuƾvx-41iV!N8ؤ:ujp ExƬ0RW@b0Tmi qbn c9ȫ%b;~{#JO-/'=g U@6) a%1(BsFI3 Md!bIX~P;+fGvԖDt?(UQ.j Q'*D3dJ* "B,pLl|hXr&ITZf՘u"Rs\38<߼m $G̓bYfrGlX6*8;׺ R*f(Lt>gաaQȱ#iFOIl9Tdd_WCsY*;EJ%#X]r| \1{7Xl,h5쩸H)TAIGE*{dzcQG%nv.E"C h%(v˒Z`9qX>*=0 IrFa{2'lSJM4DǪvMХq*eثOYU 1E'w$y$rM :D:dPP*&K!*u7#0u([fjTPU^lr*+׵m'刐~YՂdt+BH65ym>=r/Xg(ՈSVoTFfL 3mKNw{MiUClYl.@Zcؽ/ >>)1f'MVo]gGU*&Y[9Dl?Em㝩7e3">kD!KP&xS 3ک7%FMF,#.[-6J֯-9[hu]u͊$Mt#1`ua>.&b侒}ɼqVRj3Pԣ0DC ḅBxX-ZJ+҆iGz An܊}%}IjOj hT٬ M`P hnnM?WHcᖷayvNu?l<[AU$5Z\vր7Gߡ <}.4xm0 Ǜs9&|Z7?X&G!!G]VY^an\p]m-JjQN zq'Wre(r q7iCiN ",r5H _$Cr>W`BE'89" 7#$P&j0%9c8lRo PSW#3i{raTƏ@H^ΛԀ:Ks^ڏmLڅTŔ\2lDOOUjDC* 0v/Bѝγ@P`3ZIkZ1` ux\]sG K#K ^UX=}?X2$~A@mҜHFlN(D֜YԝWD*A؆( kw,iúh^$v̴.TrtzX׌(̎J-_}οP O# 7X>gqؒ!vk2?NqI4di]}䓳D0wbI0Q0$aZ,}ON6_؏ފB oJLCBF~.op^DQrAO*\ۼ45(uLAY7 ig *瘑SM +˄eV WFyN@?cF8k Ȕ5n˱EN&@~R=/D#^<-jU9%V8L_еmBgE?rr^TL9םI+nm?+ejeVz!/!{*Ky}s#s"XłtY}}#vEf(|n͘<j]}Ijj^Mڰ˯[>t6IՁܳ,tzV|hFǏdnoU?: 7쁑}hFdc"I@>ҲژbW%%5t.Z?5OK[E;u1`Q-NU O4LrrMy3Tj6~CO _?Qc2|?~z NrU;SX]M"-F>?Sj5uU۷j>>u~΀LPKO緣3SΌq^I+XF;cC TC AEqc0d-[bA;=bۏr՟@)N0 Svtb9rMJCa)5I P}Up&85◰ѵ"^k]);e7IO ~n64.Wd819D%~{dZiƶBijѴpItąMU9Aebu>f[9x=u ySA+ L[aS®&%_0b/TeκF]?^^<9 *b%Ȏ}SP+Ǭ?ETW:!i̇R8Gnel˥P ϻɤn1S5|C@ŝPMQg kWsћUe0:~EVо,#+깖bpO, -P#w$ݦK|8Ang-GGOɳBd6XP vV!,0}~fZw6o Hj0%B@OCƞ kf]90_ ]|fmШ6m_Թ7@iP0o{'VEC8+F,a0Xs0xEG0L̪ VͱO 01V I otVE8]67cIT&{|~`ND4'ի%`$+51Љ9' C4y^\?9~}sv܌;]C'j# e@I=ښ1jT~eh8F2qsWdi"!QѢVjKW5u3o oLFYs0iꄐ{qW*YvL1ګ^s_%HLar 4!&05 fā)oliC2 fm:Y K(`Sш{c\m凩J3D Gs5&HԈ8'ž֪K?3a uSyPRMDOpF+M-]||qˠj0_mY4|h(98e^sةXz-s!ȀW>q8>^H ZXWhEAu""f'2mOAB62my6]SO<H٢@+n}u)vS>l:5FFiJj{4wv!4#DcN$oNL!CfTQKx+I-YOL$%@ک12!6έSxRCY|Rl{+^l/IĿ]nL-psP!zca7OM1dL7̾!`J} ck.xTBLMV rHDpe*H5諸 w2 ##@CPqp=l[yxD2f6f{,Oңs9 зWeȖ Ҫ\)?hJ;^h!iIGXh.3 WɁ} h][f4VH/ t͵kc#ۆue\wL䄜#mZ3J78D'Q! 90gdGY]2])lֻfr(JtRʿ:XbO[8ΜU%Hx&LQ1WrgXi,-S<"oQ<SƬR2T!Ž킧* vvD%GAe0# :wќ!OVծ>~7ʽKBv'!i٬}j70ã 'v)TfF2O'aɆCg䅮mNhn6pIS$w |kH.[uGs‡ĐG; p#\VJnYC|\ltW|L=_XdEvL{*{ #:ut(IQ#<_D GSzsl)`|*Q4BGm 9xug-ro ŀ~H![a!U}e+kB]'kE3V߅à"W&'w8)ܚR6|1#ES"gf @Iqe/}?ob)~?̃Y`K9PV(̘(]vD&JZ(/ 9O?݈8G#>IfnF[R:qY2oAu b#-+47܀CO/:-6t>>, ؔHۤK@vAH(mS minZ92LAc"O1o6q g6BiXLi#s#WFދ;‚뱞ҧv)IJfC| i'.})3w^@|j0y+FQhխ #b;r*2(|I_^u6]]<6:Ľ/gY!hf&_5y]t.J+,F2,5 aNt =K{7INQYٺe`0QΖ(©ss;K; f@)34NyӚتA5\V5ygmZ 1X-̰O$==ދԩ7 }0څdEML0賷@Fw&dE<8ۮ sMpỸvӌE7{k?٬T%k4=07n_%GVvj+Uy(`2o}BJ)zgwk(,Tc!!n&hD -v{৕BqT^v +68].<YzS{tm~nteLk/$,3z?H7 r&3Qݪ*Y?@FFHLEH4,(_xOi}I CH# QcDC*j U(HUbs˜(bdC,WMo8T qX2ڠY/ .;6Mq&8;Nbj"ٿc;e5:'0ٙ{-WLOpidE0m93(xAC$&MUٱGFd@a>c6€G]B!K j 2Cw>h}X\ROq +8$=UpmUՃ`k-9Ea'!+ ") a6>bm wOƆ~D0Jԭ-{WHFR )(핥5+b0b[6Eق~8hx|JQ zQ"Wujt%xSDMT\B8go1%5IPlcWӿVZ@ƞ9\VS_38,0 %x: QuֲސhPxEkȯeRP G^9B?wamff;PMfW]S!p 4Dɒ{}P#{BBGg!?NBX(3sC)%0 6%17!h/8^3։N譄zL&yPՂޱ;yD)_|-"δӤHVp+Ofl-;d]zyIĒ菊AӳpJQYv/ [ d樳M|-_+DWKTOQ 4?ԇ8ع~GʒB?eP"kf=2*X7[o7DJ)3tzsE-,>&m8 %ƥTͺKNJP857iAVwr )fފ,贤pyaj͝/.qt$GğOwӆh_ J_ꐕ1~t*v.#~T\\U#ڂgPlϤ\P=Lx}$GT9!V.xcFU珰~NDtU M1MEO w XxލM#F^Az>,Az*>4*|?b_ߵt\v} '>.6: A9rcfr uJ\MU'VD͘7lCe 3B*)K" T>AF Z(sQу嗻ӄdy7sNҿ^U[G+e@,Y0 iuCQ~1%UH24/KMQX$$H1q0{Fsn(P޵YҬ1|>1; zM]?~8h0LېRME-URdzߵU&LS$}LWSU㨮&5 y]tF*ooHbԵ,w4$jo?79ǭA2$m9hȝιɤw 5 ^I}+jRRaz$:i ! )b$Nvr!?9Ux3D#}ThY5&< AVTkD(yK.{Vn} lzoYn-_nAe6=d`5d@4%n˔,E:_}o#ܪK[aHSL:dcT7)thia}7L1x \^/*7AĩrX7SޕQςeসZ^"&[r hGGe;1H=,}i0;g3dJ\qI F'JI7贉X ydn؈Fd+@I4Nw:MIN4 mɯ ӑQtHel+_ 5df?+*3a'+w72&R'g*X?'?&??}W. CCwh/zt!7)n-7lxyG/ sVFJ`R_1q~p0V^iHf*W ?T~e& Aя©Rwz_XV'6M41I.5qɿSI48`з5Od?\cί m*d bAC쿙?-vUC`Vbul>|@/-N9؇xrSϨ$Ƚlt<@GdzaGfSpBN?b Jpm3?}씴kGpܾa\UqNDL~=mv=OoW @94DI-ާЪ_P m"SY&ܼ"*q z)XI2ۆ\1pcџ/[O?MoBC-uKQsAEСG-7\މǡ%Ȫ<XY/bXop8p'KYS"ԫ7$HK3d"AR:8u5K@0k!d)B3G3qBQ 'BbQ4c{*8 >[z`CBoqjk瞩Elf8IXZ(u)pco5sMy&c{zl+]2m7RN #Qm$@|MF>P¦SfKF'tSx3Ç'c5 H{  w׷oFz^?!]C4"d[CPZonͽM%gƒĞļYOqҵ8HJ7xآuLJ*4T_K.aIDPs{8D5LZF\lc>xLDd.O D ,+6Set>;eE]{5MH -R%Q9 7頲Ae_\~N_(Eݨq?4m+ўyֳ;b}:i%ȍ`~λoXMDUх!2w=J984D"k}q&jf=)󢌏k|d_.HǕ).n&sK'*!u`\}̲R5?4 $)2*]qQ짿иMGf;ɝ{({.V( !8$no`y缥vԆ$UilV:vMcn>֩(-thECt3oՐvZ+9w :j٨>)Z~!dՃ] Q_yⒼksW׷VG q =RZ:?<A'gG/|ixTTeDn݄Fi{S%fzmOlZ <-o{U z7MIo+(X32}q܇t6Cdžs ,aFx+[:m9Yzad&KG[K V>3'I%7 --)pa zZVK] DtfT1t߮b.r۟uNb;IIB^iٛUAM<ۙ9_F$WΣYpOQ?oSpcV^' 3'򵶊\-@wN0,<Я٢CmKDʹ00*aGQM!Zq6^A _,?BB>C돑řc O>h[|Ub֋h|{ /ӫݝ&)V966>ѷm]QkЧ(iZ*)h-Y{Eu,!<5Iy΍1 ޟ Flb+yM-يUo E}Xb\?H6xrG%# q&@@l/d Hɣb}[48ɘаr97$3z>P5vC`S*/}hRℛc]f1S -7XU'C)˪=ѳ׺?:R^|9{0u;@C'?yM f?zfvVHK=X5?`+Zoә2[ٰX0QEJܧY)Q! LY)7 t#2BJXuc"KBEjϜTh`TQic+Lu<2Ljc' y.m{Ud톾ݔ5(gz@ڟL/bH$)t?h/@)WRzZ#Ӊ6yn?DIt?y<VQ:(DI% qtnmsθb K OWL.D[, n XNDESeJ;m3 #F60 J%OyavJ6ƵK0~d(+iڤ+g0pY[F͕k%|~,H2gI=WR@5{w^þznЌy0 ?2r{cԗ3WjlT§{-bv&%N.-%I.=tbrzq-LΝLwF]\] 1ӭ8)l[q۟6Wb9QElaUt0m[ymh#C=^ĤD3D8}?./^ʿfH Q> wB Sf:8a t~PmKRNH)LMeTa.[6 资bvILv+ԶQ8Jjzit - _/Q*$$3kW}p A}њ~|c ?s|7[EIij麸)ZMk1AXQ{|Biri4n%xs{ScUL*8x\R_.\L+D2AL|6*#sTpZ64.N+%濦M?oA ghcL*EW_4gb EPrO@El sXA;\ #2ʢ@n &Nm>ax75*]I^",Z_9§L@>ܭM&ޜ }%nZpY.vj{HeL!O屝%/d3;Ath5ȿ`C,y(f=NpOem{) "7.LO:ԾߦDo똁f֨-]Yad%'Uó\|ϥL+SB .7f }U4Bu M89O:+3C-[0(2D{>;av*?|s&B,cu-ᚻ\hٌd4Qm,J&>͉x!dF3~L!J?{ԓD žU;JЀ3@^ i_'6)An6MAJ;lO PE41 yhg.p{@ %[[*!s:K߄hoAfl, -P7:@aOܗ:f>L-sf**G(hNH^9uF¼=q2E y.n\+< _&GY $? _j~r 76`0FәMz@rGKb6hTVN:; L! y5wdc+tcȣ`/29h-c5O5xy;c14ST<}={~cDAѵDg*RidS:,qȼPd8>Qd ;r-RmUFJs%_;mb޻NM<y-xgH@ϬjM*0)Zq,V.i? ᙪq|S 8XLp`^=yv,ѕr ?S#a8ZTb8ry]J\=Ofr<4}:k !f-4)S|7qT# <|ŌqX WC7[ `@ _zQ2~߂φNm i=Da-_)tIyŅrkmS/qݝeKI:hPͩ)stzˊ2dhh.iՑYw")I-ضUK?}pbPW;>65Au}wKQp|e(t*αs L„|09߸+t1xܐ)ř*r-K!Fg ~t rzn1ͧR<$ǺG=n*ӷ͛z"kZ@4th[.Ì U9ɓ0cSIi+~ƌ-&PV,RYG>\1j DJԡAc W=WV%>N[sG.]6ڵ$οPevt?CQ}#crV< ٮVmsE]bǂ*P< 4?G|Y|܁ ;r9bs^/qtm>Oo=2>p 9Kq"hD!ăOǝ3\r Ҧ ?,*I I Nn]mUnhe޷ LVH _0߽ٲl,i >)Q|NG7*"̬1}Xvr8i8fkd4A #, 1ڰs"m4~~k}gnEO(i k&$!Xyh\Y2a,;'وUe8+3n~ = ^ϫ^'&sy{S10] ߸'z|; UCiV A[/&L B yao~aB0SM; Ž9VQ|E5AFb4$L\D!GU*{>3*gI]&0~fN( 72yLI3DwSpoۦ'6R۳r@D&ݾF&9~$[qV뀗!L)+U J7:KKP(Ɍd HҘKp-~orFDB[m.C""]J'/,zVs6>`D3C,.~_HIiN*bxmd'f%0v| P7J0Y:[ΙK+7wϘ8:$ß "}ZBD(&tD&/}_i,>x&& 6_Px'G h+EFlֽ]{J(_?&P_Z ́Cٔ2ͯϹ8MSU^ 5:O:U#RKz{KPs J >*]ȚyګpJͦ"Y\Kq4tPW.x C1IEۭXHS.+I1[^ A8%;Ӷz !#{ro1ngvԈ#2ۡn$¯^c3ǢSTB!:{) u+[5o/+|#Z{wP"g[tz=H.v ;M`<YQ.V[~F<j08)ѲaӰs,2}"zu簿yꒇ* K \.juD-Jf6C -έ/9ןhl`oKX}lr`aʭT2/6)?G[{ H&U@^/okdC$Ŝa\zj.+mUX-$c1RJvYx># 8U=)DŽn"Q?d.~O.EFVoL@jQ.t oݸ%stEZ(B=~2Vv$3_ :֫줶aBUFPCᗾmb,tMEn~C()wʤ^^7KVelZx\vč*Rֻ+¯Ar&ͽN Ok$^9?Θ1M3dVŒyot0pk%cm-zwO?tgoGD9y%8vzU*d='4 ZSop;eʹMO<`&LA-})?o 5&^?5UB%s۴ϥWr")!~|ǜ::;|\:cЙ 8VB PHC+{ڹ5)fV"'EHZXmE.\ ̹Lz$:.ʦd6y̶R zqD.Bҧ(< v0ye*LZ "|!/ Gyk2 -_P&0ۢEh` ǛH9P_,a:DzGDmY]Ug{xCV*ʐ`+4K:*kZS;@KbL tR0xOA+dx!X!%6I۹fHJ@2sTf<+bjEhCW?}Uiϋpg=}`u;*['*ɾW5+7O~aZU1u[%6R"pE.s3kY`n6lbƛ괿Q;ԭЊެ > 3a/ns)Z\+&2p1MI,< {cpp호1.?u’!)&#[`yQy{؟&1Q Sf x~jZZ2vAs/HZkP?yEh<_ZwTc}zYymkWߗpaZ`E)1F=ѷ2pn:D&z)9زy%JRkƦ\ho|d,FV!HYg3L![\9^l!Ei&kS#?W3Sf+5{گ X(YHMEQYh&Cء$ݥ$1"؉sZNi9+/6{"\ʎ?)n$ Hy>I|BvS$D.]i#I/A9enfZ5{10 ~V%\c6u7ڙ_% |gy陪)r ^vA2XGOG;V \eݯ&IcWE`B %ac-~<33[k/(73C-{<~4OY{x\SDGXr7XF,iaddH~UM(5sdJf3Bel'_hN^1=_J z % W{R;m!XL6w*gJ)ۯs314u +3@lєf<Ȁ }+nrX\~6327lPxZUSbvԆH"\}h/'fb5e|a;{s~aK+6y>MD`~^ԣ5D>"^EY >fFsl ?Q8<._ݶ 9@#HгOK Bv" x#]vid³# eyO}3lsDo9讱yk"zFpw16quuz+ƱP)(L\PM<:fWST~$V_^u١wa=[W/xB>K}(-JY[*F erdZ s7-E B,܅NzkϬT/Bwq8ڈjb(5NB 0vN9. KsP%zջ}LDEC9 QȢb"}Ealf<[0(Ʊk6Z.ѭ~ Ƥ$$Ú4"7pfI7f2W4$"SlE %|q5qZ@&,i6' :ƀpKʗޥ7r)ȍ_,3|FQ]o5tZciFqS/uӆHa4ˁN2ȩK.!k_&ѱ'O12<*Vyj=/7쿧c F5+"6 S୶f>8.žs&$$rk ?yx8?>hFIUufӋ<]cS3T܈:@STzJ|-i:̑2vg p{*}'r$CV6'b*=@}G9 nbM(voeqUqԖr&"DVYඛڹu˙Up)aOL)%A 6{܍ 8 XErV[A?ȩՔN ϝ8j!i48!`d7g~7עgi%"v"8>91ߎtrpc  Ǣ|WX As(w/z8rPF[5X幮0xqx]82|ukPa6YF(å ˙:1nXU>f=?Y }>(}_tJ [H$6E_#;iHDoVȇkߍsnsLEޥן6heUQ~.r":<"kXo˯UOŀѦq Jm4!c1q?x'2%3|N> DX#dh:n/fvqsfyXHXoz?|M?MNe ZnUvd+e!{"L7,ۺϞ} DEWD4wiӂb<~YlW)~n=:f:$j7YAֳ'Y=ܼ6/z7-Mjvq(CeʞnL@׮~V rik0| qdb_Ҋy"w݇ѵo3I9Qd$Ě rS|jl>od2_W)^⤵ ށUYH2wP"g`(ʃ+/"<^ȅ J$2As9P!>X?[̳Q$0$Rk ZIЀ~424Z;a_IU\V,Āv.,&@ P*O), As\2p Kt\>Ȯ0dP=AѮ٧LR ~*Uoڟ[#iT2GG2C A؛I?m-k$QR pl1)~f^jpb=sUS;_ۣ藧`]ѵ@6^ : ?5 +e%]h` T, +Q)HSgcSrDNldbQ7 :Q3a}BhHΜd}^8mPf* b-9e1'tH'ZBx㬻!1"k1y)5N||H _Fay0m_pc'z{cwCȌ< @IIlQfnx:ei9UѹJsmQZdgmS<޵Fw KeɜUi9֦V➮3FlwM8}S~ ʰK%sVҙ$ "leN. ajbo&9bK33V2v˷6kdPnU ٟήV\[PP87_ȌF&M$˕4Tg־-Tۓ;T3z€4Ch9.M}V`P{dt<|ZGSu:8xZ* p6R=Ѩzr: IWD| hW!bl[8g$ %,ìYzd]Q"{s$14g[5X4B]Ļx3s[F` 7'e$*\AIョdiߛBp|1;ŮASqL5 Ko&n6k$,%# cy߅[X&> cͯ7Li%qxc0Dy+DK[ `og,>; я^ɵq1f0ALU=c D=%|Sg\%FQCA=XNRH~~(FJ [Yj)ך*Im=rb"<Ǫ!>ęHe]!AwMĚu VOh(?Vیۅ!?"^}H5(VmBS0(\;\,;!ֽz~z"S'Ao;m7^f4c@\uv죋ߒG:'ܜu ȽlJJL_;3q~P(Te)@]7n8bO5ex 9j3M)MĆtqN=Pu"?\B_}^+N,}}MhXjTQ(6u}..]jl[Zb5YUm.SRwT;H`>ger>Vu.YDM+G6î0|):'2 9hzVi4RC:;m%Їz52ڞ 88t)[j j 8An8ƽ[.F Mr$3Z&ұ@8CMPy=D4PGx)`3e|@:Ҟ*`BNʴ/;kZ+WOwH5O ?_g`k~Ϟ&tny C52";K?D t'V* WxE7#~R{.O t !;tW2/F~y!)lJP9>=Q bB/N^ogk2y>McBX"teqb%b[^Ċ\K<n;nNg&0V 2R][]ʃI t d X@׽\0XyJd-Vgf`0nckXkQ ;%Y@bvnedg-|ç\|}좼lG? }ٶ"ajl}sKhf@>w5,!-omrҺޢ`D1Y渥&O]sZx m\q(t5#x1XcF,VL53{9o E΋*aQKYfNfbTsgS%xCex-' InM.:pZ0Qɾ74YL0VqZ.3rRK{4Gp,Nf tNi\#@qxۄ-$6}J͂l[݇P?#X84;LMZ_JZYP\w_\iQ O/eSv^w;K ~BrΣ0U7JB2:JJ- a[7ևpjYJ&rP2 xf(o30$vʀkSa7/"P0x \?xѶqױk_dU#SF, /$c4)Yz7 BGӁ|S,03h3\W! _ՑV|x78 OdlT36H@,pIG>m :+[k( ->۳';'~Et+$&mUṢH)!74l[>.gAQ|i Eȣ+&n H-N@hc0W?mHY3THjElqm`jbU50dDr) mxHOXu@7[yIG ;1qԢv*5\+/4}xrvJufOȗhrXl+2\[;h :,f^y+;A(5q" [1T2LZpq:L1ba*[Y=y J5 >ɌWH kㅾ, ds/njIƓ[wٓEw,JTnJrLG ͪ͘ce?1L>%ܧxSm:ivgfi2ߪ/D^)n\ГyේG;'e2scgx$70y/Sth\$1݆G򵤯4W0閊o\tg[YÍע\\Δ^Bff*2MvԠY6u3 'ڛ҅g\ v|C`vx8QFId檅MNd-ͽ*/_*-%7?*PDqM'Nw6`0ʰ+ Hc^@܊RSKUFݱ!tYtjl_%̩OJd[ܝjq\Oޖx}j=l$fv[-1N@_ pھ7.竊C 1/A{8{Ο%/f>.sґ{w:++;nyVu QcR3`2gl5HDAծzV]ͧc,$RY tD(ۆ}GO;͞ l͐s(S<|~`^3 "a1( Է vF!}ҎoEÍM FBu"F7 ۀʷ'؞JVv3HJ,3f$'ї)[ZÇY ݓێyK@<}[.=>ߩ M訅@鷱*.nTc݈fj-Y"yk+R>7qU_K٘wM:KHtsʗP* > 8|Օ͢T{XEuL~u񆪃,!_'~v%^UYIKVe]"$e֎}g&>,If6 R$$NsLۮ8I|PG -)\9" * 8K(ܤsLq7e~fʏZS1PQk "mKtiIŌﵪO톒8YѲnFQ9]$WD aB sxb|2:^qEftZÜNދAQ-;)~<և.ypj*4v3 hYxUs omta]NڸpL *h( ڇgDIB02989>ńhSn*GD bQ}Un8 c3s۠Rc :&3&EfLaWd(]7wVn$*s>!@'ؒjW>σ>dUIv砺8-mZoQw{l/#;8 !OrMirkS' yejAe-bꅖuq"15C9hb ~)6dJHP?#;I߭;X~7,'V%B2 :]ޮj"LtUV߆W6aC&)NH[iRzj/f(Nur]wXį~+i82ɫ~k 4h~O]qr!-}얳!8PB2(;CńuET{?3VB A@ {^m&ܤYTD7|2` E՛'~pzh*|ci zou_Ҵ =!}j$H嘢NKrNq`Q-(' T-2.7ު%9W޲('!.u tkZd+w'u&D-2IR n\Zt|~^*nuk 2-ɥF4D.3+!(=rAukf U35gHhJβs4ѯlrl'y!wFoI1JbqK嘬ŮOGK90:9[}Uv.i@Ee\v"iL=H|Fd>k;%\-hYƹX?5DQEjF~m)FUjAmjxX !=fZjSULnT c/.y8 T:k u@HO 0CO\NLz򛺧H_gPfN ss]AG% 9{gdN J͑ZItdUn`"^&\>u*Usxq! Ջ(;,YTz꾎59B'DPS^?g;&(>S&_t1{EKBҐzO %! Z!*_ƉheAo{|VK2<@_$ ~ )}E17J݌L.(g&);Ln8:1==GXgvoUK %0Sר} :]ǦmAILpXwRY2^UoXOowWRH0^HGP(;x +QlCXy fuVn4RwYU]{rҞsHr8H9*Y˃#v >.D rrMTwXQ]rn\z)6N,0) f# Bx} ?xد̯Pu~dbbz8R+br@9]>`#qdrg"ԧd]O_)k!9 lTH]0DJ\ON*;cT.#+4j -a*i(MPKL1[ԍgn$Z K韺if?;`§3`/ߤ^8KX:pv"r##!$I[?za'fo6ٝvĂ39+3vzd/F"0t +ɼimK9M`JbgJJpVnmVD Qr˷I\Nð M1m,׈@.'I :m~+RV՜۾5yS73yca>c]_)blxDjuŜV ƺYF@KFk7#= I!]Vnceۚ3[頙kp*+ ż?U2Ғ i}a_tpj%b+C51{B.= "̳-ZE1 !c۩+;hد]1@qJQn ;ӹ:<9V( *oN2GŢ6T/vpwv#Q}ci>&47$+Qf:* w@7ѕ85> um܃Fh=M6^АpNqdl@|H Iũ䍹3k;IGAI2k:af 3YkKcL&mLbv +#5aS# }3qW~㹚? iAL K:ÝzQ %+S)d1oT= #ɳrR]^>Jr;{08o:{v_g*1r EF8aSH1IąQv*7#yR??!/Q08 61^qs\ˮ!#D #m5#V5Su[yN65;lZgZ)jEw㜍xvvahpli1"qN^!,wsf@ 4FuH *;N*ޟ֧kS9oz58EJ;؃FW/FTv<3 @2X\{u? BSzAYVv>|I/b"9ZٲigKOUkӌ4?xHcRyg9.3 Q}X-}d\ndI9\7J}ĤUU'}UNb15#gJA C-֨(@m ALfXS&oƨVUKTLzcCoZOzr;8KzՏ8_ƈ𰷃}͗0 LL˸u{-jJp2\O,- A.{0@gFYFx{M%m\%uBNz`{dCfDnjExlux1sXN:u]sDu&%n٤ƢԱ KA)>&?;W0ƫwR>`K&φ¯.>^7qZPQ_9n,_[l Q{7ǽAnQgћZ_H$e8dN>Οt;͆r>>a)t5m LVNKlvw!(WƧ5%ly:745O`lMqfԵ.*cG֑sRjE(rSF!'+f)lн`{ ePr QKn3-$mNY|PQ(YohN<+v1g#`t4KI:TD>AÞ\y- 2x*Чr3ZB,E XfH, K%YfV L)IO6@EoA-c΃)ifuYF x9 O#ڮ*6,3S Iw'qYR?*4?ZT贎3CpT_acFqϵ;dJ+ƫ/SR}hP髊/һs,+)Ӌx}vQ} ߶\\:c4"J&ԐZDh{Z8EVU]4.FW[`Ĩ{=ݾf2 ߸@*vX^e6'ΜvgN!f xٛuJX(qGe?5r`RZ/C$|.Htͯ~ZFP8%ޣKQ`.?? iyXHD:EK(dY`ʓ5 * .m bẌ2CbpwPÕt `N3\]I7tY/5k7/؃Nʺ.vi'[;Vھ"x-'0 $sNo)Zy)g-Խe&/& 6Yդ,HkJT\sQ IIRXR=]^mmݩ:\FBbo+8r%WLep +5[&ʭG#?rnO ^A PSᤜX&ޓj*D YR/}#C;бڰiCj(ܙ=#jNp#l~y{6g),gּAәz@p;HMW?òj46e3] eNBj SrY?sNoPz֧H1䨥'Nx2I7B5y`;” RT( a @$7JU]o㛺4ߖuj@#Te2`%n@x3y9tsV@e#,C$h=5]qd=].vnO&C6LHqqnOk91!V'6)h$}q=@uI4+gc"K+'ն@sPJe#/T` @j=ϻGAOPGy!HZ 4>f.|+)mv,Z&323Y'~m Bɵe'Q)X@;)Ehn FԞ4_K6쯵[ޜA%@+{]L*7kKIȥZC=3)aZs.@pZ[ kt^F5L/A'> -P҂N`i9 \4jaM0|o=G66:}J<5ޟ];'l\P+ʾvxXȼlTxu_dC y({ل~)X(hLJ;F {9s&Ll2 Z?NXi$}|cτ+79o 顄o?GdNF~Nh"Rss}m'quQxAhOhrA&;aD$ѪH-"o'6_YUCӉ͢cWGk03E5iZLJXc^ݪxFu ˠ6JeJʑB%l{4G4c]#h 8~y`#%}7)3>J7 QeV%t`e|=d* ef\:,n-:JJnIkJImoz' x'w ]Hz0FVBleNM"a*|G?y Ȣ{CfVN[3! z2%gSٮT~uјhEegNaMf!W̳t% V3"z!H\["_~ol6.U6[ ,um0pi1*lū6J r˅ӥ\B=UUJ2 -,ADžXvbnnRh1kU 9*]/Fe(,D-ڿՄϣ{S:%uS_]OxM[z=^iB i*C<ߢmF BHu4uLy`$7mK u"D;v Z/Ab3GX(6Tj(6fS3u *lXX='!ZKnzWŋ7 pp[TӘfY 9bhR?;/QXV@`"~Q>|H?wtN[Sy"^w@Qh;mtp\Ѱ$JrZӀ)[q cj2 $']Ot[uuFwL@*,neRŲ&t.Dlto SnOH[m%܆f+qf}px!.Gpޖo6 qI?cX#O/lʉY9%+_Ld )pLBͭ~w*-hd6NKmRi^U"J S ;>$s sMP!#ܮ iW1QRAp[t؈j`Өcr*(%j['g`rG)mX&73@mDP+쬋I X#/L; ].pv^ȩ@ `@sJ0-6nNVi4yٕZFR "7Y^Z+3w{#wklPPOI`fd3[Vd^(D \sRu\ҞP)ss8uARL*GY debaYys{vRًRo s\癍F«QE@Sn1{xuΆsHSr7/@,GζnVǜyJ'+9>,XeF_)8 fb W{O" Or~sQUr½Wt憫x>6`cem\|I]KWd A7l Bq0uտ@ #O`9e"oJUyDZmD͎d9v2? "a8n$~$zѼ` NᾐWTָ K)&J^h9|݊9URѱgq9'iC#a1m'4 3?/$l2[ɕǠI0lᅖ悭+5~FpJaޠS`X+ϊ0뀓av{J%鲡zm <1vy)#ⱪ/?ࣧYȼ_m>`Nyќ=A%S)q@j;HG^8k_͑Zȗ67.Y3ҭ#V2H&X;z.#xaV*?#Ҫ2˴$aa4[\3ߎ1<&16<w:qƓI@ bcC FojjbϓRIxSKJ9qj$)mWC\ T _թ/q0HeO${$b4)M_} m@4@Ekz Ffs?) #Hld,$;q{\;AհA`2;R+ k c=3tQt&w؎W DU wSfj2{ɥ=5v(~՚h2cUr6?*mg֑ ]je\=.BK87^Wy!SG%í+zZo~67m }O@r"!fgS\80Ard㠄ɰ~8'|/~dw"ŝ$"b:oPfRȸ\\q`? eP_eu|4h[]j1rgZ֪W.f =e*)r L+h,ΊE*'vKָ4C [cuNyk*سQ c"cǀH"20k_p>G_i'X/U(!ڭ&'nAzaSPFьC63ǭeá\ȮQ)rkGJgT&"buEyk }RO;Y|?ǶwH*9&nn|n7ڗ_bQ\45$P)쎆6+;~]ȪI+'b. #B}fWZsYCuMا~mSdž 23LDs|a)k%r(UgS(ā>}A` K {qUƩ@>L\PpREG)m|zIp Y>M "]PdTE֫8~;2de5.&9m5"X!?65<m&Fx} 2UqԱzؘ액*sHGZԃNFZR6tu]ASo,~r0ȣמ ~K2f:x ̉QнzgaaJqrp/~3!9R;<dmצ5 8X] 0%pzX7g=wډ]^^,ȐIa[.D?!xE6=)?О}vK:uYcQyK4|r׆ZSi<5΂ )s|>s7 b&J<5y1+g sKRm78ʃ!en)`GŜh p P*!mJ\nj=q}T1rg儘KZ_a,`[Iy{!GC҂)?o¯1 1,k G]jF*@r I˜@A:\Mda6»=Z OeP4q&KX!FRB"rZbҡyZ4[&M\8#ײG'T;Ҩ̛ $`7=EP(fs ݖb,vD{YbЅP2 3JB~cղCaʇ Q*`TU1 lyF͹kB!IhM'6JX 61@[/9] [-Aŷeɶo[Wy<: DOc),cEHS*4) qN @QeI[Pjftg$c4e,*nӛnsy^V^NLZT&FQaYJ4O8{,4gl!K2B_Fb@Ј~QjWo?PhH8/>)7-**KɡE:# 6rzKPAW8wXhsN1W`P= YM{-O_{RPaQKU;̆cƅDB. $Jko9 XW7⟈lC20>ݔxizf*KnW[xZm?tjcW Y]T^&E)軤[EO|}CU,d;wb?;,B)OyjT(7g ;RsV{A1rpa6B܇7=8Q<aйQ .NB:s=8|%Tᬕ0.\#?W^ѶWAWPL vdB$8aP؊kqB[_`UnRӟ7][!H>;]ڇ`K ` |0XǑM e&k &p dsƭEҷ"RZBq:NP.MjŞcGLtU+-G~^wyAPgBG}DJ=/ /Lex*eήQ;fʾ'58D܏ =j 6Wt>aIWu7T˘p7Ds-4T {n$m{-3#ߦ @s3~nTkkvAa(IcU>&pY'^M`Auϰ;p|?w6 s5=m}5K9 5USZ'{25m}*E)(a'3eH-.F ru~f™H-ׅ]QڸZѕUֻ+4 ͖Jh:G_I4:0X!dZap ?O/sEc9iI}x]-c2ХQ÷|k%'yLn x*3 }PRLT {M Yuh \7z( %6ew2D}kwB^Tqk /BP^|nag8g0}7īؽQO&Ë?!}H5S ϩQ0}2xguۙ .ʴ|@+mITeLix&w1f I:*Bg%{+ΉBAsJI0F ޙ[3s9, O~q<>ѝ b<0āVr uud ; e$ƻU~QYzMnb/Ͻ[D[,Ya- UUM8 ln usZ=XB_\ > :aOANYf 62ջ<{6=1R9Zq-mߕ\*{r)X]*kKFeA)vr`a9ԁ3.8r`/}בP{hyS bzqyݿѵȆHˇ# +UGe1عvs -Zw+K~㮤 рޭXMßҥlhh8u2d k&à</06p+|'W6׵s˱f(n-^kpb S̖v+ 2o5cKp#ZVg ̀S6kLVNH؇KI/׏J'1FEf*^֯j{1&'!w-)iRWAMכ;h]wJLze?G wzBU|ҧR$ؙ {Y;UgSeD]@YcӘ c=E^.0ߴIȉ"W#ʂ?[ ̝0wXlR>NId}DD*XTYSmaZDZܺ(F"&_ľTYjB[~C2o@Iw *Q^iwX'K&6fR2uĜZaNUKy :',MOi lԫ_uYjOeRRCzQtE%&iuI<.,+-RYe{l\zدc?Kix=E3ٕQڿYWJoUx bNUOIih)Œ(LO AW9Zf&TzKć-h_ExLiT⴮OTQ|jĆq8=LXKiPy:2BBFTgv{Q8G#rzqER0쨵B&l(LS@ǑSa)4oؼT2| &vJa>)i e )z`rjWOAvXqiBc{Ē=d1ޣ6.:Dh/=9w>hd3 KzJqh7YWuVyaLjg4?>˛THyO #!22ۏzh~j"X'Л"D&g 5 ]f=Pu88`UM)NNL#dYLMjݕ"PFy/61Ő  L\%>B4Iڎ{OSCYyC#u_EHGj/3t{4Np7(m%jU.H3m][Oٛ& _^G'`{nTB֞I:~jdtt>?tO' }IE{ vJvJ8~\QWRR/o=54qD`À\A=3iDCG:^R^JNitQJ 32A1CkFwvCzBcQabJAз'}Ic 9jLy^F Ѡ@R ^ L2#)[ wU[Pr >8%{ET[27.T$P)Lܓz^/HP'E7 69~# !x&2CcArc$%ZP=bid-o '# zY@InlsCEB kDmXyY2n)i?.F\3td/"d1JjܿC}ԤL(^ ,.nYS6Ja$:75n[({oFLr=2LT봌l FϬT`ez踲4:%LqU++I{Fܼdq~=q^ aV4hk;5\uJmvw8aQPDϨtQ1\p) LӒK-gB ZI::WvW~UAπj',pQ1 Nb.6EBY{T^29f'AۥGȎ4 GRƇy JFe #T~d\وj~Լx s:Ǻ b0L{D|f3`&E6%a /01j2~6:4h/39gT*rukS$v6}Ǩl<8olй`}Q TœAYC7,{yzWE8 c| Isc4w?{#Q!1,ߢP-0J"De%O|W3eAhT4&Ip+voOS;fKM'RqHҡ`S0u=-z-;$&uSzZG ?Y":P Q)mEJ~[BTrQ}|?[NP 3 dS2i(mS #Ib:죷T5}kPaT-pBYl8hxU;AulȺ6:1^!b9AeHWچSXOSy:R()Ċ^(nFj"[ 01Jm'LxKirXs SN`<=41׸d.%>,``Z4<.أ"3=DJ Xe;_h#(:ä1" )V7~l\z/\&62C^6ҀuSP!5 ; zC]o2zWZw< `5hS4q]!k; :l趋bޟU~ XF{D\.2cڴnr"Mj85I;5lFRhz [cWNϘCP;|R|Rk} tk{ps ҇IrZmQaM>Ʈ!5Ң@$K_cBS,8w|II'Ƥ{hҞSI~Mv+ *M=\D n|h.Ȧea݌p 2{xXxNbum5-;╕Ė|e =D+/{}Y6~7OQ~Ts`e|>%Lgj2t22BT arwԧ6CkR"es9_Gl&uQׅmH<˦Jp< D38Q'w.G`QQy(HuQ{\mny&??T5QikrF!C//N,ӞbDcuEn Mܸ>dG8kC9Qb! i1> =SytJ)ǭ{'[:iqԪY΂\.eVx1NIĖ- y>>n‘JTYc<5_Wu-Rr@N Io&Fk%|1DIyJXy^ ⪿vq.k̵Rḛ̇3ֶ| 14, U3pq<[3AzXFu稉Oʌ N]q,~Lǃ)L gb˒"cvkNh"B sB+|AƇ-:VRABoT E2!w]!A^Wh(_<z~aMYLDVῘ@+0u NrcrO Nk`wHjr6x4.W{q I6&?*8:v:KUɇ ĉ'eqpx%\X 5e 7TmX>Q}N@*MCb<]oHYg<<@=K[ZI{&Vzi-䅗ե.| ]ۄV;gm6AHD%ѐat $yna-Z t[em${~xәҔV"[.,0gFX Uep1hl2"/8yr[9ܼv{/Cy o5OYl8n +~E.rG &hhAM(?1[ۏE̯C= 3v Y*BZUj23;R7_Jc΁!ܐZɥ&H8[Oђ.aT1HR$4`C@GTΔ@_̈>5^FG-`_cS%tf61sɖyhBa>FJAyޭL / =p);NCR߽p4=QA!h"i#B ǮA(|r0N4Ma>.P|%󒻊T[XM8`H)bip$^O2'}_uPlN2Y^E3ث~\fbp MsѤ]$-V҃Te-X[a0VPR2 lv\PֲTVqtTvvc܀ZgA(! Ϋ'åشEmHk}1,0 )D%7:zDQ-ڬ'./b >RO:X3#5dv##GRKŪ r쬹T ҶGxAr'W$scKQpUS'9^C"|bHeڤ'z֥(篐pYSet4kU c3S>wOz}Zq:YX?6|׬~FtؼgQW$_H'3#x{q -S l"a;S&у߮,@FpRk2T竐RXXӢ =Vۺl㜣J=mȗJ_d" !;ƃ{I)oypٵn> CٕqɯF~|xi)2 djLR 'U/(d|:Mld)3Sn=}N88ӎ>՗'2%k])&Y~-.օE(``wZY-D<2 @,Rѭح*A$D!"(@cA`__BC0F%69 29xbsy)뀌2O|*q:߳ќ/, wWu^6#PFZ˖ZҶmC(}•Ҍ51KiZ33մ ΑˍZc sjf+Frٹ',5VOc0ea(nh(n>iw)j?Y36hʣ5[1kp$nڨKݺg4_J) R)S}ڴyb(\饠ktNˊg^6?tׯ:!gʋṂ~~RuF47)2^aDZK91#`M[4̨%HCx3LYʶt Avp5ttfB^6/0ߦMKbŘy((LxOy]WnvWsuDsnB(5bʤE2|K @-Lw0[UR8tu#GWbx1 &&r Hf-{\YIb٩;KpIϘ X3$ކl* Yh?wF 4/ ɋdK?z@Е',v@Sx4&XU Ӂ7M^,$ceb ;H^AP^[{b14V3ܬ8mS@cwQ(Y-W?[LQIVaydBwYwTidh,5%$1'g\Zc4;3r a3=pj 63]vTefiUknZs|@UGFG{ֱldk+W`q}UK^voN]{+XW,4M1ɴDIy? IvI|¶psfrݡbʡ9' /,w+rQXF'P`{ܴ wH?ه rp1}a^ơLBQ UdGFg"L]XihPiXt_hɉ?(5INC1s#QU&y[|EbFsb^ q7烷R'x0aQia2j7x1Xf̝cR?q^&7gge7=O7e=Wk#s Or;V٪~XVT)?FBuE?i3Dlؗ'cIĮju<̄[y~7_$}|N8oݳzzU!E($b;vweU #Z$GRؤδV:ji.APCz!/3oVe~$d/X9O,>4ž%,g[ <|O_ lX!21jEjŒ۬< 9Gi22/N__A4]:YB V E}>sq2-5Za>%NOa-JbA-nsD~I n 6Wpъ5+xg Hj+k|B劻V)1 ']man^&K6@{1e9phһ=SX$oDnƳyܦhnA\  ̤>Gwo^'ȋ/塮˼uQh#ɲ7N6\[bWJ(&K`E^H@ka]mxVTc1gB,"d]z; +r:5CH]ߙCVr1ȁ_}LHSnBjվ6ky~O i2߳yqGr4+=FQMfj9ǙmnN=1AFГǑv@U}EuIDqƫ2i_Lpէѻ%Ӿ^*_NfS%j'әʰm EHSʶnZ $l,.H)[AsW_UnzӉM "UJԓ0-w swyˆZSd1@J-ظ%:RtAAL?d{뢖.02jjdL(r\mYf$RmUk:X!ׯa{S2+X y|m%t ĝ{7Da7⡏R&-#'@J p '֟-NE[(F+UMyyXe`–tQqĻA9ܽ+h#rfaO?,Ύw]o8 / X 0Py (ï+8AL2h񙚩:9RX(lr\`3T|R߂b1D4WC8w9`'kWطU?;CƏNFhgDs&᜽t7mKuB]y꧘+UWUxì8ÌwBaO+ґN zj?ʐ"zJlkHW8%O6 c^ȅְ:YE>`dx^uN(Ԙ|;j:뛂$+,iK:G]# z62j7 jFJTާC Ty*~y@]O9/"aTq,ityy\.Dï/HN]Vz?BF^DIcS RqH>o;Հց-HYtpmy!;J/|@f㝫_u)C\B5^"DV˅he"'~op 6I͕eI P S|?~Y0|)wc*,rq3_@ _- d$x18=FBT+yFy(hԗbdCi&r̠Ew2Eڟ+WX#Hp_<(o:d QtDL_%r3 rB9Wӕmi߰ƪM]cпT.k#(Oq(q$!2ֶ'~kDD4!F1wPg2ppI}m yH)Y2cV;̸rȥ/§S N*pX p`k?)3i;.u͕rU95$}^jXm[gt_- J6?`a|hTH!D;'I#+.f>bB`UyO|` om^ZРv e}ɥ#bNޕYUjCJMW /Npm$NhDKA4`%7@i`~@bo}0X_x}Pew\~~"5;. ghp 5_5S䕡'VN[IfqN !:*XxC+B!:<m*$1_i>{JcUR|yfq9nC΃+3GQMPI;~`vJxF!S3 -T|_de]ņo_j'Dq}iz+%[c ZC#"*瑶zf6 s;AzMwɆw>݉9mG^O9kv3)ifMeO##4G`oFkpR avj -)'?1޲HZ)RЩ EmwR nŅu{%9p8cOw+-{8^Lb?_ &7CN}ArP/t# EJ ~0yLk"lvPܿ b29j 0w%-јB"<`K-9d (=s@Yz&Fr,*1.L.Z+>$_< RT{1Ls o3IIimMr>ajOsO`o;n0rMw}G^tn M/sBkSֽLDh٢ >t묢k{;=4Mi]& 8J=W{(.O-C94Fs}8ʊ#T }I3ʝ#?y6N-3b_h7K{a~ Ec?G2u>I/\8:z>zd>FʸrC(*&X0(}RMKgݘLByL6A`ap;.HIW82b(ڶ"^ .MMhC֊47%:m̋z 3[,Q"!U*Jx?, jw]2ӓT[&2O⃼!4Za9=^ R6L`C;(XIYvŠxD-#rf? WatӛitouDl\l?~qY'rHO̚I 5V%R{n2%̣Hʔs ]AQ37(' /^q3&ũ7+p~տE}<뜜zϯcJ c$^iº6!^q`bî\X =E/ +59U4;qwJ~Ү9L9qr(h E {oDˈNFNaW y }cUJ(K)d)n=vP낤fnfsAAsNWe3 JˮNC o4J|m4<ѢB쒵7bdzBn?m_:us4gn֏9AO4FocH37-Ek<ߍA*@ȀQnik=>tYWCNڈɂ=o 67JWn JTŇ7Hb}"*{.-pB`z?$^LWazI& #R(on=^jkt׃KKWkCh90EYJo3՞,VaRpߑDb!(IYEbmv^Qƣ$әa4BrGƼ- H\P.TbGڳ1`蘿B X߽ryNQXO+ԳѕJ lo S"c "Z4CnB' xH\|:8))`"0s6ǴET9#GsQ$^'&Aӡ,OS< ۊӛP;Y![̟藔T_02KޗfuyoҟLYiT ᢭])2*'xGs'6 tvpT*m֍omۿg12Z 1[g%QU VɃT1Ɖ!g2!] -S4'u\,͌G1mFbb=Aݿ=,d,@hU^k>ʒíO*ʖ3mC-hRDحSal/mЌM+gB;:3 HRU}6!W!E(<= o([1çؘvJ޲S=KruLӇ*!JZ._@+ץ=W〙II?#y8uBڶX_M<80˩~9T?;5JZpHgC]2q)s/,Mg2k-DNclRz'&^v tsY^"!!ťL!Vg$^6j$"- +HJQZ#=l6DވwNf\#W6KnF?ѧ|K_жje/+͓E<.5ϣ]yh!EUiKB6Qܘ@NqroŦC N;ZDRj, Kr%#5PC/|%Zj"0?(|g[Cj%(K"6K@?5~% BG5ԣeZ,qȷd Z J9e~ b co\H%^j k:5sY1U;tiᨿ̬YIS#Fxo` 9"'0)96V!lzv3 WCSb>GmِZQmzQ`dˊLCd#ն9TPy"1aFT$Ώt/;jtPբ%%lM ?i씹W>ŁpBR!G4QF$.^{?vܾ3M]!F7}`v}?C{[*ԪLi9x pDOR; wW/aVbZ G/X| &O /X|@Edlc~J Y!ʜPUo$ZzmӿCp[{ݖi z>\r>8c7MXj|lSYvQ~\ύ]2QRͫ6֥uat E*CpSXKgA'=ߖTFű $WpZX WlxaLNC;4q|<5U邫2f $@pK-wu|14~)R9@8e$ !CX0  '\U+W9vF W>"V$@l{H"t-ίhPSCwbpEޅROٳa"|f#jLK RfƢXmXn TE閐8ǝWLhiOIFK.ᒻsC2<glz:+]r:r-`K UsDq2SFt C-l[2JkQx /ocdK5{a\yzb.\u{`ah4t6Aྣ-,@(W?]]hx3!(2coML(m~F/H6@fJRr%X!WuJo.in:E^E]pֳU_ރfQVDkٓ:&}qK*nN`NE Q(`Mj?A!vu[k*LF\6%;$&~;!aԘPjG#넲1SeL}3`:Q&^wQrr+sMᇢNiJx0Z]VˆZeR[İ%m㣸 : ,\;|1ө 6jJwH;m@"۲ROtR4h\P0wfTWzX#s^6 ^^5I3Ol</UɖMRr6S ʥ "!ŇcX Aw?2:F;w/~J 1f!`ye –R[N0pq͎Ra!YɀK5K9/FcɚUKoyYlrr 5 (Հbr]BM[I%B/Es(~^ͥΕA^{DE>Y)*1^;ؗ(3=$U!U7x^| 4Mu5m30hWsz$7LiUh^<-_*:RnYjnӀ,8Ka `C7YCMx\-.6D.w9;ɻBw0o-בcKQWDW'fҩ<8$PEG9j ,C(`Ͻ5ş&HVʫVmsfTvF@԰y񼒕h=VI1]iLll)kXiوD$lu8HHY=t*8TfFd/+"#O"o0Iou>܈Wlgt昜bbС% wdut 5Y˻m[ocvk0[=&P)X[7,' J^aiwL`h1Tֺ`!ɋ0),"CGpreq N/ {߂3[I.=ᭂQnm˜wE7TlCEjzPmK 3  nˋbgP/E~Rv\:wDpd&& ׿RJjhhRcߥUN@sr P N}" pGlAI"tt~r FM" 12i4]ɆI¨L’&rÌZ5$ߍ7Ú,lNuBmWBnZmP~(Z˳s_AP o0G3i@[d~4I#ㅎcڦsPt?>}b=De1>!c gԃ_Im6}|9WV|]t[V -s4пqєUE1Lw>@C C<5c[Tl&.P+v߀`3q A+:Sxd6џ퀶T{rȩ| 7`gm{sKRo콥se B\XB+b< ],T/d|/h/B鴮"gG3u '8p0avHV8N,W1S~2hz;':꤆Ы @aa,ob v$܍vME?^c5 e6=n O&ZZkvPd?%GC+YD`Cq׶\޽'Y9Q~vqM?7jOC@^GK)G77AS\|eYn%p陖SNC)*[FW$W@CćUd\A~ӯ7α&.rK\jrC4G{2*X65Bolh6t*3>]Qp8څԢjN o{zT:KD&޻?*E6s\tu$|41fX`m镪ɑ:[ѡvvTm/cݐ^`CZٱzWA"l\e5fHV8ꇕKlK|E\c 9\E$ckH;&zfN8e en^}eTf6eIes< ]=ʀC' K|*Μ`Tѻ?S/O-PؼP11/c Ůyp9J_D(cǛ]עx+lDŽ]X5`*iUCPv:qw* vâleYxX$[yT%`0 HT`ͩLh;b>j3,CB4bܓ:! tI6kABt_M0z#~&kv L=d(_-21rw4W&uףm5pQyyET?I& @K,.FWhw+@s>ӟV4ҹ7:4{{w ɀ&#󷪂,tPxV%<M]{[ႎ.9|oq3sFnDTK"@q:G3= @R#;  \snt։eܫB0L3taҷ;@Nu&CJ%jyAꕮXJjB:)4uoq(j%M/##/@ы"6P!5zaKAK7do1c|~7 -6l\OZDZ$2#];Q6HMp͎ۢzZm )}*z5)b=|Vw%~ *gJ/ѬQp/Q5;!Fz: .%s'[k 3Vc'0!*xːRZeE!El\BR&`TImlrl#]֚^gwB=ɤV4h2Yq`@OBEz|?3&6)Ui̹dWPXЊk[ni25<. w6XQBd951Z*q+ @XUq 9=AJmmaEf͏􇮰q~mB],>o/ِ$}kscj&>x*,U۟빩#YqsMJw CiL4CCZװ~pk_[ #M$5*~v%#bfIoϱ;N_ 1{vőq n~pc?LT;퉞Qӎ k9*[j&Ys1KjnC-FrV #+ddSض(vQM5nO>Yʼn>*b 56oҾ_ZM.KJe Comi0-yoFzlT!Fhr )ZsPs'Uh)cwrb$RXx>L 䑄oǥY`mS+dA*AH4j',T/wM|+Щ4@Z *+t ]d`,6fiqZ oTZ [FPP Hj,Ɔ8o6~yZV`& k갏+mRsO ;z {w/EAds*ڱ"HbMt8wIʿUH6hO &\CbQEXL®X@rw"!s~ǢX">| u[˖?Ѡ|tHC܀Asɴ4ϨU15Z<\H½YB|jâL}}aa!}n^B/|@#ͬI"4圉+$Ieuk.&tiF"66y˃o N4i PiFD>"ek0ea.76fx ǖok]8vWRDP<'Jm e4|j?%g`^`tF$΃i@W(]XzWJ/g].a4 yώ cZph?+g =l%Қuh`boZ3%a-S~vQM/1rq(_Qig_[B9[91-oC^Ѱ gHK:J<%l,h_sH:i e\F eR)=r]n(|ŴQ2n<R΋zttRobOg$P/˥@ɼ|*U5I6RF 2 ]*qV6vF7 pe:W"Zd6'7I-ҍRmlz+`qPNlN{0vԇZIX{S`<keQMuc?LQ9}2PI9,MxB0EYպ4gEaR2P̰;RUuD9Eϣ^0Dc 3.Fg^mu D\!٥WT8TJfM=yܞpe,vCo{Z]وָwhDt $}Y=ՠ' [HR$d6hT.ncYrx=(m69Ū="paj %(  -׼AL.sC<ǖ l; ˲0(73~['Œ7ŠA„qdWDk5dv4,CzW \-?g#J!{lM^u.~eDL0S=y*d}!7pIwj)uQ&;CX8}&SrIE5tbSaCKN^O! l~J 6Oq=EFW+Qwś+R2:gO +40`sb 9A#c ҉7|܄ߗ{:nsj֞dEQk(Wd=-Z9_<{V\QVZGk6h52C3Nӻ8m[-'Ok#* [gr{J6?4lx'Jg?q#ه}vtˡRw\ _X am#SXkRT GF6J! =$eKI5 Ӓ}K jRE4BY&oCz LDH/Z9TE>>dB$xjX0j~S@dD T^ok7 Mg"l VT=NL,oE))2]ػ*FiSc R M.3<[A;Wg'܈&,<gC G b6Q^F[U *[Xh;6tƒQ@*oi9L7vŒ6%eKDO\aڇKrMYR,WjPrClbq0bqHy;t!'L:$贺#WyDU uTW$m 2v9y17(_I#Wd_Dؓ^CB4}3S~:c"n:2CCx3CڞDB*~j+%YXc1K\ߔ_ fQXVO'?N!;qBd45d,2{%g^tzm&l`18y1Xj?}8)WDKOR35LbG9L߂nʊHґaĀkxSȮ/4L.=qs;bf^Y$3pQn+Պ?{ۃ EHmPcPAzymL^){=Iepᕒ>YbՈJ ݆I!B#G;Vv0ꙥ8_C붱:KIyF,:i"w#aiUc"Kr9wxy\W:#55c{ :P7Lr͐ δ qb{)-w 6gۓtENu@Y7 ODb71ť,4/_+L%Li;r$8@W]*ZʍKM:x?Rƾ6Xuޠ-/LV:n@ ,b(sA,<'5N*ىZǙ>!^GF[cĒ6SHsm 0=wX>$NJ)= J}~8`D"RydR'3,e.Jʹ #S7 ] ?!#юI*ͦH }1.]Pi4˱ԐcPzY^kJiq}AB)?Q)ƅh裈#j3n6mxRh/X0"`;X=%]zN+]}+T$-1(d=‡䒮 ~B=7;¢WY 4"q%ZyB5?zyű"HH)'% SKdz",K5bd9޶;٫asik]2j9/%X2,;|]x8=NyUnIݎ:a.C8i{QZ\k=HŖkgXr?lpfdi *z!RbsҢBQi(ۅǴXm󳣱::ODkj=OKZp o6֘zKMAc&<@B+ e梄J2ʼdIJI$_PHrtJ^<H8HNg3*vookF,o#Z|ļG0oTfk7;4Y08Ymᥝyy~:O97|!$+)K :ՇEY'9З-ٗuыhqrE5T'}'aI?oV}(%Ϭ<ԠDWb|PUݷ.np54%40A*$;5j7, D`e;׈"z=NԂ*ói1L% Zq5UWUr2"6cELx"DFOrQ.қEDX_N`wo0#[р"\9F|߸֟. Ԍ;|go*ËGGRܰJxюFR_`fD.$2v s-1TqNbGI#T^rhBC "~4˂;܉}m+oAd&&`0ZΒ7H;Dঢ়VD:: aPjx4D9 Gxl_l} A ٷe30f2a[;lJ_2v81])|QIGaB>gvUʲW;' NaS꠼xtLl,Q7GI0]L9pDz5g+g4UwiQU5.RtOӑ`69x'8ia8CnO(%9FxO| .7zEPFSy&#_n:J".KZ/5Х) 1@χ9K\+gr5NAH!v-IF ;H[@wI BA9Vn|hC4"ۿ9v_#*F`"Cs̍؅ŀ%n ,\J-jq|si;՞}wS8'StU%@3Tҗ*(̖ȊZLD̯KJ (' F?To$YJ 7:ߐBYv~DR*zo23QݞM<;@v%~K"*70M?$ulj}`9GniвȟEs`ljv|.R|x߮aɹ#?Y!bY|3[AN7%m/OjHmz,;&Vů#|,C^p J"yd$'=e"-Zu^h%u\0͞5|Ue`[-==۳j ZQAE֗lzkzBVZMrD o@5̹P<5TeFO=h>F]9<.)ujˮܮlh ;i3\O z3">㮘l,!U$^8ܿԴíǡc NJ#Pgy@3e| ==`$(N}kD>8&`FꂬRT|>!ܽQ9K ZEd nٮ[EIh6Чwά4ʎ @iqY#"=P2Y6 >@#bq-B)`9>P 7Y5y3CW.GD,ĚX)ϋT_vJhmXՈ#!y*`%u[Uݪ^5+,g_-XEA^neWZwow\^e/`5!29BH&@e%%b!!Fqi@_SMDCz;#-  ~@,f)6 c"OͩѡM|_roJ51Twd D;w'3b:I\hۂ4ӰcP/+$碿"6'ƅGHp(ey\.j}ɻpinB^`` G:bz2ǻ):yq^Dj+bN^9IQ`9eƯڵxjܬ˻0RA֍Ċ`;|;rA˽̠Z;mVV '\vN21.,c`UnU(L(j?e5q;+I3W&K8 {+w`~| TS_:>΀ݱ}3s< G2,Aef!:.",W,~:14Um l3*?.Bg]GB/5|o8^'҂& e9G!^^B/r bSPZ13VgM%PcjLד>*x` vwi'Fz~TSu$+4}\*9HQ?Ž>`]uen|qҢ41)8QH։,h^2cd 04R WkC6i8ߍ<SXF'pvݧܿuyEHF )}vKU.Շ |OjҴbQؒA]qј˯w'e>m X5`VKͿAvpOKuG >܂«ۜ51y=.^k ,gv_j$5x7y% Qxl|*|D<5Ԕlب1wl4܏S""i3  VHZRqΑhl3}t`A/ZGGJAFm3fqJ%cQHJ{^$(c4uZM?gExtMASoO\0ѫ`s$rbo֯k:қ7_I"jhꋂT"ZHx'm09ռ'+@,7խ!Izwtpa=_^Cu2?F-ݘ_L X%ogq*Qaa<"d6?V1Ec$eBd;ꙓe-GqeK NwƾB/ jG->j*ZX~?Bk7樠B"[T%,ed\ C TLx 㛫(ҹf~}'CK߃EMt?\o3?S>*NX\H:.#J3c\ct\b4@P8udEs*B\o5. 5!L$\z/4<7=u3^K8 LͶ_p}Hڗ!Қ|;FԬ+G+fT!^9Тb^RbodpK7\]`[+Yz:L"K{v LB~h D@Wzu2R @ ;8{5;3ù{yQnz BEXNjU r_' 'K$r}[vP!(<+2HvnDjZ:y4'GqE*@ğ5[}YQ}E(u5l{2Q1jLЌӼfҢI ) KF0["R3 m{nⶥ&ōȆ)РOs[z_eЗ j, Jώ(KbN=j%pNx둹(F2SgRp#6aTfny=Z hܦ;ts  '(XSI4Sr@RG3_o Z*8TEL^s8XϮ%<a}JI ZFMbВG8 z ?6% 1~߬SQ[t:ku2%eb ώd^KcS< dFO-O@w kM3l>Y5|迅I\@RYu2e|VkG{Հ(RyDOM(%8vEOwdmG\RlyV|]wJJwGsmI%?k1>j0f)Zj*|^|?BJ ePw7\RYL5  ]6UPPP$y>Y @ p,H+6U9r{d}N aĸ2`ˬ&g)o"AcIzr"p\]3RtwX}d ϵN]@J P:gv{<"Hӗ°kq pi1li=vBt"\W~rN.)qP YKw կ j:N\Pn4 ~={_=T<"RyS*6s\qG C|ds%XBgv^aJ:8fc t|z!"55& ߇>0nie Ծ$WzӰ8geٶ`a^ ׎ݞ0qaBGF}BuGfvA|-@Gِ˙7_rG`6͌Q hŻ;z\amWtN& q50-T*OakӴ 4^>,3KIwvW=I)a`  fDzp@-MӰs3:d&zj6/j_Rx!x8ńF?&dc;t>Zh3#%{w|aqx!,Lm|J綬8J&x'ȱmUI}Yun+k^jf9EQ aޜR;D\=&n=*+ ҿzZJQì2hey z_/&*=in[u.z ҨI SfsЌ7IRW s[}Q3DM;{~iO nݓ҄/R()1UUkՐ㎲V̸< ;G5%ws'.*|ҶU ˛ݏgu2gHeO!B;|[ޯ26T,+g )~B-I^^/ߢd}ey}Iz yw܎5H:ÙIǨk+t00)DpQ hpͷג-{Fc!;^ߏ$-;s*oOvֺb]ـ [}ylqgKѳ.|l_(2 G:r~U"0U|{I '-%hpM &  IMo`&_ I$v^n~w+2z?lr"U:J=j|/M$56?S nVgGU_#X?'|o>m3D9"H4bN?>PեF{McnLzԪ{NRiI!*bb )e}CKDwE^ݿYrCih`$Gcm}^JGD+ dsOr9Y>΅4#%5_\+ x]T}:QQ*)s->. CTa!/312",!BdM{F9.o#G_$,&JG ќ$e!Y7{?yEt\,^b__̣]}ŠkiWmտ\} )秸:}m#7@v Fp聝,H[X PC2#m-( z`&WupF8(=YۣHq:po+(g+u28P1mgxi$0FO\/(gb$T(Fq]'H2\"q(ɗ ^`#s4(:$V(܄ʐ ,|R- y#^Vȗm!(E_N6 _1OesE`\JFMi㓷Qr1(0Є\|E~K\l!g}S$*z2ipѴW~z*l{D)2M"rQ5ȦB[yT[ .dvCvϋ:K aU@Jj 1r1?o2hPmLO 6 XU&Xf]5zt0'CN~7q%8i7p1dF s_Q؝L$|/ l\j&;Vn^ |@^mѬLr$ҞI}ϩ[:g!l>8޷ĩpN,~@ѡzj:rjsaɻ/e&3/-NHI,)0wh,[h'FڲNCj89al^- ׻MQ,S<aoHJtyY{4Ky-P̦(&D7KT^Y4jK J jd.O6!NsY- =h4Y?F3 ue}gW .z(.6m '6}cB6] .P.&Gv{?Tăb.\fA#oO5 Rsu~bʂnkc+Cppd4^-maE1Я[;:sY4l9v:2# »a{C? !>G/bS YliK$ d>o=5?0J+gz0mF]OʟҺu gKܥ.ih>9㗭]er5ĪxLrJ?6aWmcԞCR+) C `N8!: .E0WבmeHa9'4qyJt];p̹U$T\MT[#Q&>FsMpxNk\Xo!+ $w j姥t;+p e5KkCVdL-gV#ERrq'`qI@$o@lHٷ805HVU_7+[{rS.;a沀OCL[ "E#wb5Z|@hROQ A@TMV`qP.*T:K>4l@5ڣ_0刬WKu3w헨L+69j-QeHn.Ji4FD+FEǵm\]w%ccOIz"^,t^ceJ!?bua<(9B"Nʯ?zw;Jq7c*4iko^] rm1V;SѠ+ Rp&O\ _)ZXCϥަm7yb$X%,jYg0YnݐI96d˜d-̙Cyj`==Nf-2NI/jr>ec!_+nCRp: a*)&71 C tG~wޮLЮCi{hc&_n"s$͋twzU4BJ^!g»x^8SaWG9@3ʽ#@hKȿ'x) UwxN<Фʐql o?e2yUDV_\]G6<:78"LWx +ww.zz1eveH?/ sƿ5hfs7o+6nͨ͡23fԾ&~T\ȵ;vfqxݟЗnٱ O4ۂx nJ(^sjPB.+Ky2Aq<71[ߜpy:_U$FzҎ`ߡw <`O("9J3kMv%[@ۦ' )";Z61fksU<펖ͯ,O6&bN%jAn|ا6r&QЖ.kT_ g[C40" ̌@j,M|CaJP?WwDDV9ђ2n-M&9 lX;<.%{yl>|CʫHUnj s H{&OEÅ vdQ4-KYR'7>Zzz@+$S/Sǥah_5hw`n,! . |( >j,hKC_H "Ka0ᠠ/+zwRU1LOc8Sn._ n[T}%B<PR s,VF_LC>vP^SVm@X?En;%9+=dUEbk@WBUfh#) @vEaYjYtiL%h7:k<&~1$59π }" fjH! UqLr@cK(Y{SS2zpD'=eרw+n"-W -Ja&EIM,TieQ~K)?'1|>+,C$8[KPH,2~JtnRl$㥜oZ.){U _'*tI|g{GLK`[UNzl$2YX!}jT6fsdm7e[ ɒ16x _dB7laH9[ (@(إ,BÝ/I n觨1`g3j%3]$6-ېfb6T7c]7\;yXגۺI -ׁs5-$%ݡ`Ri>xIY9$1y&\f$b9kIt_N0|qGޢzŴeIB"ڤ5:Ys݅|no[?!Vl}.J+WV~!B?y=gϟ~y06L -h$9&,@wԹ-|p*GݢXy:[O+8z-NK .: ŗXtaTNT(s")3k"nnYAw~B߫S@\屹'Rh)xyWNV\ s2)Xts?vwTV߼Kc٘Q+tx -2:9,0P4))2իRr*աĄK 1HA^Nצ$(Pu$Y?㑣΁#((PVQ@chR7?><ˍXf+ǭ3KL oQI@]aS~;ݜQC 'b',jIӱٽ@c$O$H ˆ"zc>哠oBLFu,NVbK?YN`AKɉۖ%j& HN'.p+mܨ\1"}ԋ"h ]v>1 [ŏe> 5!P:~9 $p^R%|L3X+Aw sKMy,m4`*nTot԰z\]/(C [R_R*Z0dEz欖P/.;)XBRnV 6m(-DmM #'j$i5ѫgv7C6!AU)Z,#ψ>(xԎ͔.J;%/u#SG#QԻsA8~ }\Vi&>,$Z2op**ȓ_Ub8s'y\ZUwu͝+9xeq7)ܾpr(n7>Csm<h=e]jUJqE Gu%o&MXbA6t1'1Q~Ag)146KP,{B@a~Lğ5;x)hTe6+czb$9F'׫ͫd "ʹU>d;ʜȼiѻ>3q` {ӞA,nkb+E?!E|#h[%D~<δeˡUg+fR(8 }#:ZZN{e0jo!r-1d,,5~Tko(/цSVbP¶p˶4 ux)欭J b(Ok܈Jd?8ʷB(FySW[0(;ݷgq,畝v;ցq|R ̖,P99MܧH#>}68 ?Դi~OeWe^ ^f,~գWY޼Բ˃S g0̾:~48U,5[0k:ѳ퐊\t"ֲ̱ٳhҋC8 AfFUNF}V[SʭJdI )#=hVvm$yXA"~$D'N[0RVK,5L/@g^ܒm=2ηzމ&1T 92ރ. y 3MP{BI| ?eW%˹~$&|ݙ,i@,Dߩ]ghָLzAe3)CA9U ^ cQA%XkU5~"2qD8o%/z<|M<$t_mӶK:Y`6G p O 0,hMpAtjGN$%QSߐk|Pke*S1 z"9uՃ %y瑟+o qq$PXy9 D{(^n!/ꊜUH~5[};(0j ̂RK/  k'K \Ҽ=e\tÖ1(e'@8+s\Qša}q΅oËN@Ef[-+}/pyYB5}8Vق]ڍ2CTU2Y:ZbGhdީ /NMhX|g`iOץJ^P^15E1vi.F'] TbQ@tDpώK Shs*mͭ@dEj1M=̔6u<,ZnPL8d=#þx(kϠ!6'ij=HFo,B~Vّnqy:<x ]ް|D=`5W,]HD[y8x(YOV֩cGs  -uWLG~-]bskڬl]stΌ8ݧaB-bF+7}s ͪuU/L̓6#̣wJ"{*lk3"(0 #nBgH*r,V9j{'lT殣Z(|?`&: i?HVKcL-g9#iMTKC-ql??͆+$-B΅vSVH-3"x~-l%JHRquo ))Hx12L)UaKqe9b<'S^cXr̵:fYy>3'LQEN,*&uW+7wSD{m|%)CpzFt9bgㇵ{HҌ %)Iȯ֭ jJ "Ʒ&c#@GLcGo-\6ѹtEQ @4uTg LQ(Ŋq>kd-HPd~J8ٿ. h-ήOӻy"9<'zs_3Ð:w?pR.•Cݞ*BNqȦdoav'DlȆb5E2 :4@aGnxOKJRoΧMsur*qSߵrSn 7Ɔy2%]i)xe5Ù:c)ܱ}c{C,F a6a. EF7 u"s{D64\qJ5E dӛa3޼"lj-֡g8K6Rlf2)Xz#8BM"ҏiV5g*^滕w~`Rzxz negr4ڛMg說ǰh>I;2qz-7l2LK<24=FH3  .-p 3u e0N6Ŵ=KHڜ CJFB}-:4ݛCPܦec } 0"r'`UBNӋ{X4X8J3grguzu,&ܽ5]Y;?mll֯'KLk?zph!f?\rz>+n]qyB'5!mf95LT۷ixqa qp[6hXx&J*}0_\0yͫr~$Kh>#޳M,q:VR#a?Xi^ЃR%'vyc2:ugzYqִzUxvmaзѽqcj|G4S5fӽ0 Y~&fCq^UB0`\CSǰ20ƫ"Fs>`7VTW}cZS,&.;/AaŎ4ʕ}3$ՇOQ%k<{9 oI|岈I]2j}HɎ^iqt˗)q/7U]0mD>8W$+zHSe? 3"ܷ{ŽjڃJMdݗfM<0hgu)g-nAbꯆwVn{kw- <{06BL\sF#1p~hJw zZ8NJ;\ NA,{m;iz{>5-E"f巜$Y1c"Y!Bq9r<,0veqq'[g^2z'x/GF졣w}[{TNH"[K;mH"l˚W `vE0Cchl'N)d#{S+Oߌ(# W=a_mz~ĚTw&%bz陧 e|5T 3ul"kF15!B2JUdPW׏ir8;ޅ,J޹T߈?IPJ$l;V<%}k ͌&ʏ7yUf3.Z]Z ^ycM|#%2VTZF[ PH'2Oh{rhP.|955b 0PCy5|Ya~#hKTV-bsoO!\S>u/!]dG#3n$>*mntLfn|q8CO!&9*|>V nF۾D!=mϺ=TZԉE@AdžJ]} [Wa,6w{RڳgK{4Y\$S_`E[AVP.YA8\cRM "݅mYLXֻrI;y<VgaicL0t =CYGB_5?!zDi9zŧoh Țs"%ӼVji(/ܑ+u^Z\M # x"6DSe6Q1 yYC7\<~zAN5ⱹǼsnϑ9OQ ZNB6[(% !С8 EwNWpOvٌ l ~\zUñ ?`)!PT2{dɞ8 fH9ږOcjC#Bͤ6t:4Բ+@u!"?0<ɶh?*ޯaP(vC; y<v9Zi[x|ͳGp̞!FPZaCP8ѣgLcFKFx+9?"k&~7ɅruݰϪf+e^c7Ĭ` J|oHCvf=UG$e[gPy(9Pd"u~Y]VΆⲂ7=P-V L7,QGvZ~CTw(.O" =+6.hE/FGx81ڞ6 ;O:(O"2'\)gمU|DV_v~t{AlrުCQ/C٢Wn\?^&y.!; B?("껰H (l$+%:ZquB %s+n[}>4bFdi'mv_ˢ8AHH?^ nJRF VRuYA{ύN]hSiv%%+rUzcRvq]W`LKsRH#VQ_*X<4H{VNvb/.=ꭗy=pgFh 4TgCLyIYbX]gRck ? ʇ(宔^R=>,Ue\1}H{$ivZƕz=pDah<_ tjU-KY5-L? F-OXX2{;)K&>ԏqG!8(F y_#BUmޱUW >cx (6Z4TڎW[gN:gٳ3@*, kz8quj[hw6bS!Q|OWcI%J?J6wbIۮޜXBU1x2G' cS=Ua-Z GKh` 1eegu5F __3-eP&n>* ۽22E`8q¤j^a2'*.v߹iN객T&>c=[o \ wBNڎKIQy,ΉS;(/'ƒ)C[mtZ:ސ@,QǟiāVGMvqWc\kV,G\6Ǭu%l}z)U+q8)" */,Yr)k/S\`]{y`j_aU.S\… -s=WQw|&kIH4¤&-ەp2?/ퟬZ#8̞*ַ\CqIBQ\:rd[pW8f{8!"աEm$SXfX,%qo<;oh3B86rVP##X*ޕ>ԉTZp B%;19Rt4\H N,eӻվ*o%g Zs&~59AttV^oyewǡ\/0<|#,I*ꕧ?Y.2ndϊptnV"~!ծYdeZ))T[ ~"]rZ{9dCP'Ȗùҹdn3b2:AXR?uCFg~Džvep)g V |YȰ}Rd83۳x_f~h 1/BؑGl&v$Jx-iL:Lb)M*/vc#I2_B]6Ə(0ķ00(cڃ^ȅIHl!@i+Q\s4H}aDBW잘$W5 |#i*^Ul 3ۑ$$98:iG#m"$dh_s[|^T[VdGH.E89͓4L#^T X8d";0t'mc4!Zk,x܃XtuO(`C†q'O -]&P`O3qcw˫NpI j Bjy{R2LhΘ{B'$/-uX:1YeC=Fҗ86O3/ +Z wh5pꞱ>{lX=$"٣H4Kfpm"ʼ%hlTDy RM-X~wK[P?:X tgiQi6fՖp^=#H "}Z vJ0)t=;Ÿނ{㧐Ѵ ~ 6kuʈo_ FyLP%@M~Dy.[l-k,7yRgT \sYu建*^'9ƑvaAiBC[ KE$DtbR#QD)\L` *Q+!N0G9$io9,fܭ !24hRaSk9HʧNK=1.bYNWfU߮_Z*DGm]&;G ́ 7 ]UGb7(iR7m8@~z>u6Ӣ":-pKG [7 CaC =2e0jEPDn nZV ##6?TJ%WȤm`(u 4xpjTfnh KLTTW=3OڔɧCOtwqy=p uԟ<(_8tBdyFדv\0vshΕ ~vuOPC<tP{V,n~#~/_Kk@|EM S$ Wiq0W ^bc%pEDCo;ݑjnc,@Lĭ}J1X Pgq>:x+FCyoRn$ܚ]CV-KɲfB-1$_{>, KaJ,lAɏ;CtǓTxrI8&LIn}uWh46Րk!£PleZnWY$_!8ʝ*M8"L#PQ޸A[L?6H-[D _BD[,/`_ʗlADaOE0ߗNc 4^|;nG.#?66:SE_8lA|7f¥0Z450@ئӒV>\)ccNcWqJ~yD!mNoŭڔUb sU}TJLYQq&kqC`Oy䍽ZU6-yrD" E$F^L{gQIuDSԸAyfO0sifZgKe%ѻnJpә+8Gzm1*g 2 ?FrϖQ<-;H 1i7|[чDdLK5J92zC bJL{1ξƘvG/0k7J.N]KoiJ,m+˖i|z/sJZI15p{8>j&@_i)I H"zϑVyS(np4u3{IUd1ݧȗcY-_7}mWe~H&={k'NOۗN2 tNn걓äE.B*쓤(|JOg";7|u a9CC hm摩nxOw-~ٜ`L̚sT@%?h,Е+@\?𩹑ID"V\{`r_@;IǖKϧ%Dm!AX֯rp=EY{,/{MkUz"L'iiْgL{XY/ wTd,]Z5J{ >V[%Ņj'5f軴91}ώY9{c6d)_2,ڢ)*n2syCL#N:#nSm3۔շh(99UoU;}nB w d,ͻ A}FF ϡPt=J #!%/:*~m^vS: ź*l^Nk#?=);2g%UnTf<`ceZ̞&> L=h7O10kjeZڊ/{Dծ>y3Or]?US{1}*)Uyᄷwݞ~17Y}7&}J1}u'LJxo]ٕczh@{Y!ikD@vx' S0wL|uNSrH}0a5N @$IsX+<8` n :`N`ѱ]л*yv91M=0i IZ"glR`2M.0$BL0.VggT.`%OZR5o'=MV حp0QXT\'E\K: ¯'ǿ?eZ](mArԉz͚\Ikp8?\')/胩ULufG|.@{hxH_Hn;26|2eX=q?dā >*n2pY %i ]0%56)d˳߶y>gn9CC'dRu98_3/u""H>90o_HGQ'G{Ā%ʋRnrEEc)Lqs#uG{zl[e+B\YO5 uT{q*uxe ˆ9ZGl{l{!7o$ÆU?&l6RP$^~"B.DJ +^RmF8|>;3lbghĦ@+3U9QAּ} 8-.mi<wVkj‚$`,W 2^R6τZCEM0j3Vkk%Og v g ջx|>?/c˸KPv0x)"wƜh.j!VeߧAU96ܱJesݧ k| jd{'R_焫GfWJYP6Y-̎_ i9 5Yj{q `m">n0-?VyX8+ɟ @ (.ܝpѷ[!#>m0/Op2kHJThjξz`OcJ ES>oK? ҨAU}0n8ik|{lOj8vN~eT5G #RӐܰM T4%/&jE*TIa(3d="c{o6KIX=_6AFYhъ$!9m~?j~y3y*~~Z6igiU:oĆdULهt(Q!ȵ /Uǟ]߬s*!Mq gEw}ƭ|myHx6{݀bc{C2?|~.Ffo,R0EOvXgA 8dX8 Y|`@6JgTy6yPx@Gxm1U@GjSt% 0#XG%Y/gXvEoa'h_ fx䍍w <[;NL6((*5K]kKj9_~귊U wY;Ϳϼמ퀾Hԭ{[ R ;=زw4j[cdK?A7[s@fBh-0Ùpdâ[<=dޥYrYAKU褉CdFӺ<\X" %UUL8;j?mdv,{"w'Vhx;[:an"[ .=2_UjL+Es]?^އifXiUŸf#{_UqB QC2g–{1 m/U;QGYJh2X[v^#g4z˧ 82V+XzHU_9Jul|1;tXzGr 7Ka.6L(}\M˚<2a3 ?2%> 3;TuS q+㜍[la&\<c QuszWC,;v i-0:"lZ(KԬ$uF+:QCO >YѨ= 9(4 C/ 2} lP:6Q6dtl3txV?x^YQKL9khnP74Q٤%m?F^M>'G݋.xP[{uveg=ɰX ̞|EsÆl'׮TME &eTu@`tk`zb,T=ʛ 5Xd_L?U&y՗0}pzURl[ D C#mIH,E ;j7kg9"afʎTLX.Ȟ + z, ˺Eڿ%PQU*.#F]D8H@'2/6uG;IIֆpA3BT$U|dz9|;;h7D)@ 0wǎcqē݃7)?rJ37L;}ְgY/9ii1UI^hl\EyO#)` 5zJGlGzGq9Q،a a~gIڎcBLmɭ{h 8>Fz92xǒ:A%Mfv87Y W ,BjfQ-{4zv麗y!HӔ`Ñ*)-VBUFU9 q!pnEï4 rupJZ#j RŒK: %ergT8!n惟Q5 QFٌ*Tf]$nPꆱh;KͦëAGj aPxpdĶ;ǷKDr{.?Ov ( [$Mn®/_tGV,Sn΢w2lP`T@#cM0`f2Gİבe,׏/dMs ȌAAqݵ"GF3b]*, 5X !BY[UXYɖ_Ckp/ſaT *C4dO`|J$ZP*d]EOl/:-֒F>Dvhk ~^%:$j vaIaǘuVUĭ萗< ;(аD*=w9T tw.agG~eX^R6'כb3`$/*/5w1&GZPv\}31yNMXLqK ]&Q&MoυT3NӇ)ɪa3OAyl1`v9^[#UTEH\|mk7u :6j\Kl+F$\4C\@`*mUƞ D`|i22 I'/PPo9QؿaqaՕyu}MBb[ڦ÷ى."mЭ.iwk[*wyBO7QʇkYGXunvnX5JWS>\x-DŸxIDQ;<<ύӁ5_ NBbĩ>t@Pu+[ N/Rrޥpdg":p@jAFڛ>b6"9FoQ\C:oppm2zNA GP&މ6x%iE*vei]Yу/ed5R?^G߲~jx\vG/+sF~:vbwT 5#c=uk2|їqi@ s"Qρ.N1zŋ*-;5% P.P|j*o3)1ӘPq%,V$7+fQ DaFM[)}(: oEl1Bpl ̣"}ki2 @+dћ-KƧo4 /*k9I7qg |b\gً4f`_rmؾc(ףfr& 5oOGɮ&Ec_OJGCaykb 1!ۅKPG`Zbn:<0l8Wö#hPT7β˝e);>CEqFk޽r"fpP[6 CN4<$` $w]Z{=RIҕluNm+,p*3d9 ;NbJb)h+X,3gsHFЧd=h/P \P"sljM9'4@uPyޣAȍ;;x 5ʈRT5-D0^t6.9iᶝҐa+9fk-%…~ +;.>DM5XV l< 䅁<(\ n˄]8,(XJV8EB{6>_aq{tZk'Q&`ţO9Of@P0V!@""n}+5&wgהI#1BrЦ ;bzlxov;9c+W˝֏fU_yA|xvf{Tm|]͎H#@]Sbv>`BE 8͟ԣ<v 6!v̠)V,{B[pfϳ1FTfV3҉W)hEc*<= )N@ Qp ooOwҳSX@{BěBk]-`HacMV#x<1+& 3|TZ!ɀĨld-XZW&-?A#ʀxNgjWI^G{g(Ρs\<?voNMe0.tf~8L,5jA++)N38q/U0;RlZ%Ư@}f^tXmH!7(I,-̩Őp +["!ngPotH,v( u$UIf9T+?V wz P}g" b'"ǚ2Sm{w7xf2\?@ԪZfoC%a&Pi хB׼N|# ~o%$ @ #XP0hz"گ:ٗRγ3BQ\Mo#tY1@JM㙉v'@!-}ypP7K!3.=hS>s>Rԩ}kR@O4'N%l7{5EfTaˇ m9ܧ`nBoh8%k$:=qzGΈ%R 2 }'fjyɊ>X4F?N:kko{w~`y8l1;dNJS VR@t(׉7F=fPh8ȧE|yun(phSJԖg;yPQ(9yK`m ut4XqL5 eNAHŹxK+`Nŋe*F2 i`kX!V,+l Ȃ0ES17d.Tzz:ցY}ȵdgsr+u#4 'rvsϪ~gz|$00˷8$B*9~rj|\!04O*Ę!^Crktq%Xn23W?BYrʉIAR1&u+{Ka<6×Qs*kӌvBavB@ؙ_,rfҚO@#L3}xyfbDDE53ā`W[ w)5PGb3^^6\13W-S F4GNχ~t4y-^ Hd'½V_k[˷[Ⱦĕ<2M+X_N4Wڼ^bB,c,< * Nj_OzoK0`CxbH_L+%8=;!uU~_þlT3*{<}F`x̕6mr7,̋#F~ȁ5t"dkTPRqg pS5Y)D§6uAk,(l .šo Ys{"=v{(u:DJD =}'m^T,r)pGcwl}5eMVćIg %zT8H\O-\R#Պ/m`ֹ022 KoWV8tES[i |'܍"D32VҠqAr,QrD%82*ݭwUU霗~!?"0cdق.q)0HpΡU qH0{WL9%2gSqoMdںpoh)H7p#0CC]wZCzJT|h:0,$DBifDT'K"57beẦ_6\41z-"zxBVZUk\Jy6b἟yi<~zt>m{$mY;.IE+`,%]\zRC2ߎq4cR" .J!o&7yFID#ʫkB^JHL%et,>Mӵi4CJ ?_S(Z8 fk5T"iV#`K+[۩| LW3N,u"1IJ72g5ͥF*ˊ&yu22m"fN t6V6^Yx)Q8}qΩ$FM\U_ Jİf[L^9QX #7nT ) -rڊP-"Gѹi%kL;bQ6ai^#4h)dX)`PX&Jx,(tOC4y}SERlY?j:2oH3TP Q$-7ZxN҃<}3M2h-O9l^iV3!Ndݒ=";Dcwեjm/ڿ,^=E2z~꒹_" ODS8Qw<h*68'O)؉km5O_|0, Ĝ:lvejucωV-;&AD֔r_(DĉY92k0fQI ISA'%|Bg5pX*%ެ"9aFTjbveTN&ll+I6i[j)=wE" }*c` yvՊ2ΛiᾞQ͹Oh«w-Źܞ*72 \rS6JX,U~yk .?S)0-o/^RfhS:U&.q[gCh#Vk~&OzW+ŠU?-?A<0-j 3ϔCHbM:`ƒz*1^Y#ҨEY:CYF"셢B%4({#\DbQǣȆ4ǑMO[1 WIOӂ kstD]ẼêJ nȗ_}R%)ajAaE,ޖvƉjE/n5 GNvnr:8ֿAXbl,g^$ʷ?#ZI}B/* [O< JE/*2 F B >>Wn K(;3y0J/rOi\ϛp: mC&J2&6쯱1G ARމN-Fͅ}b(m(nuAl&o?0RAS0 ;8K`{o +Q @l:ٞIП yy( Xa ڍug2t BhPXZ8{8n"dڮy*q $CuqB0A`EKDOraH?uJ%mv\$5Z$`2P]yXq~ ) ?]gm1Avp!2`ܧMdDזm=IE-;3ZM s*1ChBX!R̙ DY/pIbN3@tS9M͂]DsuL ݧ/T֪eD߬ycȥcFCZd yF& b`ʘ{拜ͬdX{BgM9 FfrQ)E$Xm9eodAvoo;6YSBv0/ǒcMnDkg;ZKj s+PRp$n"jfq7-?CA@xA5r6f簂WIqbWEcQ=d??dSDTzH$=7 P @]A/]+y\^ϩS0lKwoU~Ѫ6+OW)X$EqW2' ǦRhg\Rb9A]Uݻ qR̡e y^ѻzFƒ\_  ?胗ȮVZ̔_:fU2fWCFf@Cj*6>Sռ &WVCmG@n)B[ iI<(L9rYU@Pdq`@gٲ()uY(sfwA51mˡ>JU`\4oBaqXZ[ ET,)E{o*H?0f$7Bl9sA^!,OcCEviwsW"?kGFNh8!5xZڲQY2^/WVF$r"́l=zOgRZWFxdbƇ̖ n!.W;^.p%2ojU:vP4ҟMX=9%]-S.4@I)_[lU(>"HN]2ߖEbt/c (8Yb(Qj?[ ?4Tv/Tk_E;*z鬙EΛQUsvmYz{^YN Jo9&I4n:|:cb\7B{xu{9 m|=ULy20C"'R7;jviWjGĜHn3s@ >`}=}Fz)UˏcP&UAl!A8>nML gÌ8}i-MZVұ$fFDEBp^ʝ56lͳpM}h4H1/}pK%xl ʧhUjDDhwgJ@S-OaLí~?@V9G؋߻Ei(Gg+)aS;#G |z?ϡenT=&K)"a0OuhAjxXBn?:.p oOXFDE0h.{ P"0?bj{Z)Cَ {Z+1DF6[y8¸e zH֨2pa@ s) 3M**6}H@3^ɬsx{)4rJa1]u_϶"_hqz/KNrO#e9 ;hr7"l ߉;!A$5vNXw|惥H'HrJ/;]Ljo5/:vo:i^b3FPKq ]فDp؞Ó5C εZ8WY"-'}R(p7DQ^uJX/eS TkyY[n벑r@Qc?ֽm.©{Ď-뗇]V5߿̏ĺ(n)hMKӂh.^.gn>~5ҭwӺwSXN,B|ttLX>g_mNV&+[lL#bmVfU bҲkOe>59i"_*3X<(~^'Wa-jg, 4ýObÄq<*lP#,ϤaDubggз]FGFsЅԴs=sy/ ":T/\DLGeG/+l<^׵ˉ >yyӲMq9ke1?<&B5lb$(9 H=z4%SNCqR>R[0mJOůzԲjER͋ӵ+ kYVE:Z _thw}D AʴDU6~YV,OPX .9xz~\%JWNVڲ6к v3lG26j&k %nILUqɤ |DN\Awu;?k%[T1eHlVk܆0^7qS,#'y~3Er{\ұz"?DFVvҥΉ@g,U>7xMzQ-՛߳$8c 9=N\@\ғ:JC;v24!!~9pꎢ|]ZU]s pE9hi$ xLתf/q s cy6SHA8YF\aKߢh} F_)a8Lb#沎蹃>}7ĴF!lH>$oBZ vdT)`x\qǠFI.ivOtNѰE)] pQ־bw/b0&X2 *H҉bP̓/VO4l:|Lxzvf8<2(`ʕ eƕ3։Vd\L\}u v BRyGG; J n”4u)8S+e?M`/7k+DfGR~c͜#a kJ$֬f@֑O)vrU.؞9| y3\>Ǧǥo8Of40D poVM4Xzp~\SCZ[Zחپ|{s(7\F*h C Qgm\`L#wD8^)mɢ}+w34.Ztuì_9*Ӥ_Z'tr3qhضA(Ko_iFjO*T)ն+RB蒃oAٳh}`3^Lf':˝8Fj &o63 PJm53-Ԅ,*$]2-?YEJ-A7\ b+>MU @߾|Kd\E!=(;` EK+dV}J25%t ;]dvtw|;- /%Jv!^RrC׵pI&Gz[=%&&>.h?ás ,\&)o h>򵠅uo'ȝsp;ɾqȢs}}v36NxK%m9YHRw[o-\`eaqX}$Nk%Q}զӘSoo|>BR Cx![\ Jҫ[A>ܸp({#z*˙}xZ`"9 (& `}p.d-H'.{V]\>SVܻv{p:fܰspV?_?Hra T! ][C٩GCK{Q(1R Gnu9^͉]Eu`toIniE<+B?6gu%4 ھ)fWd\+)bb8E_|ˤF}X0BrǏg9$}[HyKTzo˟+oP_2@lQч.f mqO(1mEPx _Ӡ8CorϰT.xcMT i\iJusK~FJz1r2m܉ep>p$/ݜ.VM{H_Kc|#RX#G2u%QKC8(2KH 2ByɅ>@Jt`9}4FwY=WMT2d>!I'DC(8`2pE⯁lxY =ؿm`=#} %| A]lqɯ h╮?D-A@;G;N'PjtWx*q B'r,R,]O`fSjb;ab/d5%3ŷb,a6Oε&\{R5nIB.LPi'8M/V>E$pA ``* 1ў{UcWXl -Oƍׂ2RQQɿDoU’R#D!}F,}rὓ4:DJ\rO/v+4J|uY<$T??}\8};-B5[,8hAd|[\4a&Wjb٘7{:X*AAI |/0v[ z!})C%Hq_< ^;ӂT-' ><`J<_~~GLbo$ GW- "#M 2{vV:rSx=P%FZQd@E~ց͡ߖ]9O˔ºB gwK! PsW|G$&uB gr1 HVi9b8C\%ߧsP Ddz_Po 6hX¦2樅j;֛}!7?i[<,  kEnkMhѰ+01**ꝌH3pT)M~E(8^>/OG`~7vLVS\Pmqls89 o¹ϓ M7;.*z`‰p+V}XYayqܛx;@l,}>ħ.^&p  go F[+cf[h@L N*DpGݿ;UwY-^*lD'=}HF]RT3В9= &BG5 oɲ)6!CP#Rǖue>f=NH[5ԕ #A}55y,8JdDضYĴ.Â`gz(\xNq9aAmZw0).ĪI3ג!襃sFR5_ %:׷@0Q1|sP ik!?73ǤR~!=a2 }99E.tXQcP*<0B繻Cp;㈣r F,[`NS7 s js 6cD]-_oiEćw䧣/f1H޼yyJUpҳrT9oZTY42ļz{&?s|+k"IkVݩt3bYgd{jy<񗕏ߥTd0cxFqz`4mQk  uSE%1_^ æ{-T5bsh~]*.QrLV<@CD! >MM1-𑞤 +[z6^X;ƅ$!g(1kzQf1p`HP^>Δ)1S*jsX.czH' lDVky\C'f)ucx,2x}]X6ﱂ dv>%29?83C} Kn k; \{fnPAQOd;5Mx6 a8ns-0K.Msvņ5~#Bf^&FVCUrRTJcav#bVpGÔ52lu- A"J@!Sz |zfvsQ DLOf'̷JП0+b(O0ƀuHQ.}e"C䎧TpZSU-k} {F hvXCYPjpĸfv2OTd)|> W怅u'qjRe6!Mԯ8iB x,Ec}9s)_1j6>A%&xϊ٭t:\p:|ϡ["]}Mܢ).O 9azFp6!,sR^  F&3Ԗ+$wvL)"%7U,Ps>cݓ16NCl)^ʻ(Ή%DYx;w/0:)V虮"N+]L]o/0.uuCu4ޞmܮjؔt@F/Ԥ0v'=BXHށ+ ܤ$K_Êע}qɢ15l#ۊ7ݱ"}1}6W'=gѩtHXkU`l:qJzaj=tTBh!U;Y5\>HaA_ڍm]VkM;v-&> ,Nδ[)~T%(^aђ9>qZښq!BĒm%##KI?PEx%ydB ,+E(aSyxb49uuQ?o:Hȋv?r;U2' ɛCZժ $$6yzWy\wh'Nפ aN^0 VuxO6n@[s~=JLJ^ܔ0~oW&J#՚m41(B$Y 4xњvgl0n(9Z]Y9f&Ҏ뙧-ϬEnᯓu?gg:3 ڡz-IՄuVT]Ĩ 9p2cSൽxuQ@q5֊$@Y&Y׀ ޺dF߻yE"f[P\ *Pɉnƀ/CJOŶ&TBhgkӡ2-s,ɟnl-"h"0)kaʺUQ~n^bQ632}GLhj" } @PRÐH3xI?"|,tNO\ɳ2s)jB;eh(UleocʼY?Qq3?e=&SuSΚnuy־pLK4l7s~m1 (bsK{`Jj #DѴ/;eN6<~D8 f1u5 Fk_T{ @B9m&Y "Gew< `̊Ny$m!^|_@ EoFnq\SV w<>h~6v&zcݿ[䧯y//e>=wo<_hP'KW `9PPûߍc!"R I յIg?g 7,,ENfwb6]#rNx{) mXi^9Q"lO}qC 01ΜX0s]) %uLˆbW oqNpN5؈ 8y8,' T ~r Ǣ"0 @-23,vUnؒhNgR;/k:: Hئ,K`T}$zMFuH灱}- ek y揊^58=XoJR[og64i'zmdnRbpv\f\ޡwgl'eWQr9MkTˏ庋 YL% .pI1/qV:x`3(x?Lg38K$UxqywHy/߳F0\͈~B  g({@uDVI^/ΐk>SH'f#+B~%(ꐹ] :ⶼ1/VnOI] 9fQەvT ?) `fQvQ[inU6+%ϐIdu;ə곸_S-\6NRp^!gc4f! *)rn_Xk6̫ pd\;@krVaZH]HJ21U^cfƹy8 UV)L!?OÀak;,p¹}؍r^0?$eI3g~U쭕:~wѓ|RuC(2{cKG[r[+Oq@PQlt0#6/qpԪvID;l$|L](g6j|i%ҧF0lzVۺADKG0s!BlRA D@OƁq(qx_fo C#}WwAזT\BՋdK,z K,u~,^BzMAbюԳ#UD->wW$^|sW0AQb#W>g,RX?]Z vPKn~2QAliV#ǯD=QY$醟;^2(5th!upNXXBUa7V V_@bviI v߿V8OƢEs<~AA`&@ok\)NxO,ŠA#bC[:ڣNe"Xb8w1v_P\2 ^+k/ q#SX? n]t$󌖤Ѷݖd<ƻ8،4*NB?ˢKN$-udi4CڊEFs_(i돱lVM5[?ktϨe^x_1/F"~8o{4P`')/|4t ˸ȸ6 0&¡y2yj"|qV:߁{쉧\XHoB ʧ4%AYS.wJ"X1#sޜpPBÃbV,f9V"C6Zuw1 rDtr#bRI#oxLo6L)y&Fx'G?Yr6:ڽV׭ Ne\ {lP9cc+KhMوi&j\uT^.w&Yfohs0)AwN^!^3|P.GBD"-jk."K>TF0rQR=D=ƘdvWؾe/c'SMi~?ͷc?O 9/{bb2S;{+>Ἣq1SdL?%f@\آx`Τ`=ޮtο)ˎ"4YF;KyM5$@:]/KzƔM}LǠ3bZ'~(QF& (Fm5 `C:E,[i=q5ɀE! 9,Sίc4 =SGZͥrbe~yq2d0u`@J%۲Q:n88$m rCZu2AW!9Qh@ÁZgnIl{Gv6p 4AD{ө*0͌X7D+|&ce$ mo$z&쨧Z4e"֎-jEx&laXI\מ^E1& SH+U#%Ż7SY,w#WDmM9U`Ο$FVn$1B,G~4yub %0궑tY~"8{wYϻcp܎EsCDIgGbr ЬaGsgEm 9-n7h\;%ƶH7.)Rik[L~'^ IP0>"Jh{H H@z^Enb25pFCA>vf"# 2D l[S/ @<^Wz1:TPf'0t2}(w%;cv`~NIUFH%+RemH.;5߄։\^  "w-IJ,4M DWNđގ DaG t[xG U.{շZBR]IЫᨪmʚ#y$aj'yb)SGQD';/V?Y:+%1$<L52/E BtA{L;L/<1%2RKm}oӁ2CW|],xNǺ r7X;g5oPp@\ٳl5zyw\[ DQV Xj1qlI nٷtnV" "J2_( h!.EHȜD*^4741*n(T4g>R6qkhS`[W ݕ ['!|wWNgjW`J$v9u̍PLr~!-\j 0ߌra\ASVQmX'F!R,#w(~\+kDu *5G8jGUN^qv|= J9Yp0\)Z9Id<9;䋭 MTkWZ {nox ΃FJ9C1wNɊPGFsk9ia@Xڛ%\dN`0 3695p\5qu)ٰX ~3BPWU٬-UW4G81@ ziLJ0/83uS1[E\Cāؐ.eʏ[IfcA\K:ъCh|@ !$l o-XZ%S*ϑcpzꉗti6To=S9t7늗2K/}xya p^ 묆\7w<~ Mr  !S;h?!6d vXWRBçEpI"ahLh cV5'2QY j@psxkso,1^dUaRX2s}V<)zmWu:bwHo+?|r*e T4_;w)_YShPUwTL`YlݯBsڿ?$9Б|VkO/4 QtT~z{FU$"͆ qx,/ $^96ZPژXSCcgr 6eCYj6Ld ab8#2paobuM3s"3:~LZyV%)XEPk/%%~-Ax%8us;!#fQ+ًR?I~2q+q:ifldT>Yv,Ӄl!|C'u-jaawJI]fj&"LE (G 3FeyúmAb:26(XmiJ]'0ۢk0U)̊hd~rjM܄*+ƀJ@j+Aγ<e~q4r^&(6bLX HbD8:{3rV^VeAb ˍE4WnkH>CP!Rt=L?Q2c=An 1(7=~{ݒE aI|Qq,x_~a y fCsڹ,nrցI_,sn<9}2ެ;`o M(v y2:Cr"mOE)g[Lͧed9nɔ=]_+OBi~K'`uLM-Q:M |,.YJrE"d-AyE:@o0KW6nʀ#͵ vHS%'P.)b5{"lJ彼} C ߳,JOk8B} sX"h-/l%=b"lڶ8}޺;NOא*}]\9Wqfb m' ;B$$54B饙iz?eLUJ뫡+٨t1h+7.hOt_F 2b&%Jz:1U G I%uW@ r g;tРKE @8 rwߒKa\s qT5oi|2K!q#hVE`z瘕6R (7z 2`l@߀TAf0MD|zG rrAr:&{FwF_;r%)Rbm33q|i*{dVRNE {5Gf{J۫n{V05I&Oj=B}T?~N#3ր̬Q!N [goaxO i.8i}1mIi-uaUK$hNwS%?b-2]psR?/Go u ,}ɧ7d3[s$ /W&v;2eaxFf77}aػE"X{VŠK`Y `,YQ jUF֙GQٝPw| 0wKVՉ͒) #zRnܠ4#qQro*wKw`1g7ךy74}@2߸2e)~~9-{/M2~wxL'&K?*ɪ9E%=XUk02Y8 Է_P/J/Jظo%L)/ІbLf U"3P5oe.[@aALF<8עGvAEs*1viA$wx}HHcK5glPxAmzDd7A8SҥkU&TUES7bZTܓ)j2`xM|OJ2ԮT4{`ƭ'9>pl3 ;N;w{"m(]93ʃ~OF>GKt:!R%r'680/*@l 6$;fx\@1>!JZEĕ;7\/M\+],J<&II-yJNi<Ƃ&l=nߪ4_A8(*i'tE4[5s eʭN:G뻾{%@yFb!0 nRV%rq&K#OAɃL@YAəLP/;6Ͼ*nnx|$|[) W=&Cɹ%h4A*g/kO85M]̬aqbK8nh/61s4!qY9 XXcYH@sL#F JӁ֧ŹE߂Z'Sn."ï֭}vK@<J` 5JG4/|6@ x1ꌥԂa<#Dӵ7 #!e ~LvE#֍$KnJ}{M'etz* #To1h_&hB%c4L) `J~QOߒ~BR2wIti9kS"LK2a|%ƀsLenVd;l48y?~^pb,, ݆P&WV[&#lJK-9ʆKUx\!&9PANHݳ"=iU=6e$tk>'u`.CPM`h(sfyDŢej [\ 7$\D.۞ 嵭)ɻUpܬ h{v187eQi$7~G!? KT/ ]q*Y a͗dw`d 6ЗAқL ͛~U62SSXX=d[UVfkuuۋ!zҧ2/ ƾ9XTdcꩤR*hT8l&"U¶%֘O,/OMԱKjbo?X)2AV?m=ӎ䓴޼/W87}4AAwя5mF?8X[`9D{%cLgN~Ư,5L-x쀶tp`sRO*%]?qQqԬL&)աw7),$a; |i.|T3$2gf U`!y~#*~ W!duwM';Bހ=p/VCz⒢hvU "8z"{8]#&{!ۆ0\ O=e TS3D]aC8>vRb)8E`dqD>l5=7z+6mߨ&vզ\N~d_:Ǎ)NUٴ(A@3 ;# pί)ګ3hG%!= 1QUE[ɪuWZ¿+ňEvw?H^7HREk894hwRnVf4BgB6?>q{w>;yt+:(py 1B^r;xReGd-;l۞nK+k w+ -aT6D'T-/%,+G0ngwOa"Xz%O+&'J:juΡ+~p~469`i[E 9p+vg[NLi,Uݓܣw}:s@xʗ F2 '@ʠ`\ۓcՁ(E/ ݹ>/fG5ϢtFsMBdKeJ(j g|/Uh}q=L?04 ,[;)\1G;2`Oǘ(]>ȫ4!MԐ5WQ4qZ1tpyQ< n4H Qc+K8@ 9%b id 7 t2?)T+9ZR-! d5D+%iyݏx*;?4d>`n+!A!~p黽W!t!|ؑq7y{װF~O+Xhݿ9vh6ϭT .m24sꥹ JR}͕Bo5O79$ ^-t9χ4*9Qᅔ&6N6rI\Yo%4Wbu5OcÊU.kWIfȀ֥v~HLDW luqL6k$M("*] #dgIHB`ed08t)ul(VpaʋMIq_ْ / wfWvBIytNDaKyǝ E 11 O ;{¤?|K?a^K]f^ p;J] ޻|˰J,zh~1oP!;1Du uYyAPwЦXCv02hkzH@>1la0X Jc (£1% >[y| Eز}f3MZropAlxnb5 iK &[˄/PH A"3 6Mh+q-wOB^5. pMhz_$uR}+@[VM=?SR5;ZhuJ,.«,;ZfP/(3 @S+퀫cPb+ev&Ƣc8x6aNnKNEwZZmr6~6"u 1FZ\K]7^fU7DZ-E'YvMj%<@JHdc[\g=.pT VCadܟ1L^\n+u'5 e9yo^WCn.B{J/ T iӉ/B7r JrS./Øk?q1ьjS"b⇘}19e74*v.e"c_۫XyWuK<*{F>Mq_\guC.dbp-umיU۔T%.KD3Xu۝ڬHFSC3UwfW tT/5p-Ȧ!OP9"yJ DeO17p5N`p(ïǙ,J#+ĠUQݝ|ɫ(h; "Gԇ&x%n)ᔼGHGȰ*ދk!E?Ɇc p_b 8$ܢAb-7i7ACՒ)-v4Q_h?5Ro{ jyN:?dIyPH$SR&,9ƱfXFI2243(%AnM5"ɘ8}&F.bR.[鷛czK\M{'p:}FJjl1X5,Jn(K?{Z=މ@.mn",{YP `p5Q8\T@4*PfO3L1L7X÷5Xw,7ˠ_j?Zg*fRf9_{`sL7SAg9Sq39Wh?ޫq9ͨIGƵ</\H&%8$c4'}4ort⁙nN͇zoݎp%|^@}ht q:*\{;Gw\Ig(nH:~kyu%u\RMoK5Ɍ3ETW㓣u-{3䨄mf")w.C*dת. ,aЀX2%6vtDRDt,73Qoֈ-/hI3rdU |Z֭MB嗆=MTcsśg'~ZUD4 `zx*h;/rݑ'.oD}<,M-!f/ r_`K43/z%r(WY ew '8T-8c/BFo i(%a2@9Q/¢]5Oա[qj"oONnEЏDZgC,%:Y>{[!a Bf;ȑt+* TbX=sx34zF:9/nwEjdWH9y+?adHM ;k!eqG:DzCE%Dɝb{"?]صs.YBAz&,o R &`oT=Plʓ pf$ͥ 9KvO -#h4ZV\EɌ܀q)E{S+ tf4-d5_LWb4jMv}AN8W+ެoE`C]2?t b^64nV0i_#L=~Q< [; .̴ҁY|daT(Pw鄃ށͪmj>Og(&HBecvg0UbeCG ވd 7LS,F=)2=*ZAR2E7L0.'WQ1L"l#ҙ;pMYBln5Nk(,9|A3ŏbL؂-me0 [TxBczK<ܹ7J{5a eQop|Z@:Ć; Uq\nga1 Kּk'R[4/:*{`Vx+˜ hjtׄ~.'W/8[?J&5o Q冢l7vd$ls\ևCUc"Hd/ w`NWobv҄:͢u1h]) b'bߩIS,`E[E2H ZDƸ"%bc5m5LsꅌnN"VQ_%Bא.Yaj'7Z#cJ@ '%dhejWYO2&pSl}+n;[`P勖bڞj{>@71d?jzh_[;SoH< 05i6n5%Ꞛ 6t*þ,YHRײX!EOSUO8J,cEi}ՄBޱe(w3biK%C1jMJl| " JYqP$IGR c| &m#nj>Cw+|DJ sN>x#G*a"%t?zv %fQ@Q9.~Y2Cn #DVcFmzQl|˓MIUU0liPy>.J=T?\S [M $G&]7{Kjϗ#?T "w>JW ]Y<! |jď &%g@/XjJ (K VF=g6ma<e@G^p)h& 'BK26B,(dyW2b&1|e9R*;UvCtq_3afh܎L4ACufCH3cj(PݟürmzqAJux3u|y1fWjƆubDJ,b-!q'lxկBrv7@+9046ߊwӞ ;W8N 1[1> ɬ@S E`W-8es% R* _8`Zeܯ{N1Y:h#ѓk|*_?~e(KYt22-̿n5a*E:%QTY(-q(bt̒kKY8Z x`>gq/f%R*s" l2N xsR̾$N|)9%-th~jśQtC烤^l2 /rI#^@'"s*LCٗYhXn5N@=Ur¹m*G34 t;>[ܐrED轂9ZÊ {1]ne  *1t*Zj3W:pV~a{T0\a^VXk <߃\+Q-Z"c@c?ؽ$%+ gؾēOoUk*J\#OoZrcܭd[َeEú^Ŝ:sez܏bI ;L <%FeLP;@J<\l?D󉮍؍`$ap)ŶDgl} tg B),AXz>N&别,0uhgufon+}_c(Nm<, ڒs{+nQmwRܷ4zu}f.̨ ώ*Ѳ/'TZNX{SWpb`A.#rdL}& 6H`Z |8vVneyÀ^^PTNw 0b0̒CP&#mLd+IZe._Z{x"MI ߞ׉p > Gx4(LB*gb[;wd|^X8X/A BrMTe& (ݼ"?;#o=*v# Dg+jLWliB3z>l!NcGǓ~/Fwߺ7_Tu?e[0 `\;1H剷W7Tg\@/]՗wC΅)c W6ųHXfUBuLJE2cCGl<.~fOb1Rwcr(yZsp* Gr |wO=:,Xi[ R֒ J1D<]>']ګAcwenhp g:+G{9\2T/vWIBSPTi12eA/߫.B/:KUcBCZat=1%PQ⌂c,~\@D _:e|R%!2IGYoYhϹRw8?<ΔrV?YU ߯oi'ba'gCdm\ OlGX#Q4,Ԙ0V;żNF>NN 5Z .ܷ*q= SLBqP/ <5( }X2 cJ8sVot\p0EZAϣvbw>GcQH(yِL&2)KEe7>}@2,4jGNO%03]Wq[D85<.Jg;g*}}T}AO'0]E%"UQ_aEًb  V)a4 r{#lr:iZ \a*Oj`L[XV؏8A1"T C;%f74@fN!Զ*K +&&U@FaB১ ꦴv;YJbC_#i7lϵ2)Ν4!PD{ # ؓ5b\lTVSb9:7UE7R?C""eh [zW^Skj_26!Us)A c3M&>b QBg҉:+u6Gn2Ka#_W<;QS+0ݢuٵvf.9r0Qu eM:6tҍ&M񛧩7NUE3V9%[/)8 O2hř8Ji "`2c`3фL%?7wk.E/b2Ĝ2sjӻJ_8:}Tϱ…"lNk@8Ǧq}́,[Ly51H 7B5LJ[fSIEl7H251UН`c-3(fШHlY[ .uxzEQG*0捄ꍕꃒvB:^yFymb(v~ě o=#|PkzZ$?X#J,GrF<SCf e±+#Z'%Xk(w9M&mekp "_A=F±ZԘӴhJ JHLUim;Wȶ1o^ ZN {0i5s [^v){h>b-Ff;>Q C<7Mp+I=J!:`9]rvnW$] LW{?Fc a؏E!fCb(f#T4:GYQHHy7|u2xpyW*XE< v2|\wM'bK@\YT;̘QIKIMuA-6*XX #.'5?=ـ(9&~0Uګ=v.@xf;sW@nTF*y [,N#(+/=zv"bNvQS0MtQ~v'wM58guBpi5#!8Nrt.Т|B00:nxbdOԃ{`Ť{ϤgBl`RmM ?$ZZW\JkTڇ]MwO\ >a;0:Ce ,+-31}HL?>Eַ5/_-T[X Ln // %sH6C9=9I`!jf+ƝLF`K?݅n DnneZˮ w5cM;я![ rnoN`c3-mI.R\R% 0@U&TV-Cx=$͂RAw{f8;+'(p?`!THf򔥱ι2]Zq8QON |ϖqFm,X,dػר<* 4.CjV0pTǰz0˔z<]55~jwQzz3Vn o?ׂH|i?ExN:}PåB8&M}͍_([o-}xXߥ (WCJ ȋ9q`5hmc]6?f`6{N&5X/$>CB5M;6JߑNg1Q[&Qyc _Y¢B(FߊU7o~ZJ2=%-"x%:֏Lj=<:Xij,7itU0RvcG`ag?"g^rljnjsy$TpˉC4p FVZ;R@ =@2E5{)_ 9f{p~V͒D)Pzw75%u0 r(aI١\_xFζ-cR{1/VۢŮ%eoyKŢ<ѥpdE~RLk XƯS)ArD \FR- _r)`>xT:ESAGEEeYUtqQl{ ϰIz!M\ (<ϘB2wf{'UV*PFu+ nCzÙzн 8>I:Z@ ^M,?hrsd]{I#_ VJWB”#I*pG+ ܣXE oڝM7z!Ry"ZvF;Qۧ/J#D7Kvf *D:IOw(LaL?5.FNv1vchJ#kJ|Khr4.Zx̦)Tvȁ(kG0jAڂ#z@$e4i1Cr|^4X|MKJjG=?EE'Y{^F._Yڿx}W@ |Hp "؟Z`xt5aa"%=|H΢-wZ{=7',gŰr!$*aIqy yK!C3JиWE9L3&m#yb]Ȍ)1@pĕ2%0~, mSu6N>sm1蜖[dbS ylG\E,F]eCwdY60U&إx҉˹ؽå^/J03982C ՘y1"s*bRg|~r!-$hrf+jM1^\6D Jo$]&O7A Qͺ Tr&d V w*YUI~ DNjd+f:*=c.7LǢL -*[[Gǩɐ0fyc掛'")Ԍ7NHH*}4җ1K1 kb 6bJI|D<SOrXccm_ފG >hpu1Z2|A4,!G=(oJyN3ʭ؍ [|LMy:ȓv^9Ir 1jE9Wi@;IX従5l'7<Nfh5 t^yaŶyA@w14~gwxc9'Sh1KZ`hWb/־ӒE$k!/A_n*dxְe0oĺi8_jr5z-gF;또 [i葂T/J!NO*6s?(KUc>y՜!Vx`h7~%ʎK6մevok3ZSҽsw; G_ k<%rohy* q2n`N@9ģ_K-}/ KRiCf$#Hu CoP181əڍՋcX1{ ,~KB*+0֟N.κ^tI>9-oJ=$‚H̕UP @,@O|Ǜ vWbM3gER_xpAlgm_!p|_R{RWgEn_RĻYbbc窯G?S^bI9XL f%מX52eAjZlj焌817;*iC<.$(v.61d]>^9)>3C&/eW [rJm)0"E1T߀dXX2f8qGGU]]eH#,G\y^'$)gQ*up0B?~ rR ٨(y6xLVB{0̋,-㝛2BzUW!C4mh Y/?h|H[ TQm>p \`#E O0#{Hu:_] qSu*NN<&c.]Z)ă٫_G^ p(GK|nbH:&nj/- vnjAcY0]OIj> j4 R.U\7Eni^KQ7bdFl7)+FD1]|!&bIB@)5>LM M3#pĆ-B'/__$y#2 φ9&]\}7u|RN;$\HEa"ah(%凤md&j|xGv00qA<"Wa,9- ӝ'178( e4v4{ѯ1?"hT|Bd^dy-4kmdU;Dqh O 95P,ѩ#%&6alC#} T]gv:Q ̢KLg3B-v\yUw%:,mzk+Lj܅009L,@}}Y,RP}M;SPޮ cRE0Ww*S5@C5$nhپqSx⒥{rK%Q\kXg,Vd IGC LR܃/r Ղ*UC} *-ƍy̱+覓^`nuu7*VK|l&] {[p‰6f76#e>xٝpﭣhfR5 [0C\%r̀z6ZˈH"EUhQe90•aPZ%;(-O`.-̶OrmT)(VAO&S6DoW!@4eZj\pݒbm+«MqU N0L`݈tzR2"&߸ uK0Z߈ąԓVjzȚ30>]B8r`SpBl€!a;w> B$@}5IzX[Sh%?'ۦyCՐ}lrlbn'2͆^o!P~BoܢMD捳nz~ȵnW|gnu Я`UŔT{ u)hl<-c8i"A&.J\>v[ *p|Y4G: Ԉq w0K" (ӌ!}&G5{a[suwu ρVTU@ vɀs;l0xF @pxe  p%Z<.}~EN,*S?a\|]ю&Yz=)և }~}A4`R$I}N`PQ)/ A W33~۩C=56&S10]aIow_vL+,)3T8/zoUy :-DF7ߠ+LL-3i|(*IVq | Dm]`+gg'c:S#==l?kru)65˥KjJ77tQ1k" i_8$%QSViL_x-5"zn9^!"kѐM*SD7Lm7V`:=(=L?.4@ځ&b&Qrhwt0ks(z+RW_F%ƘݝqTVc1 h8ɲ񳍒jhzX!vɬ7_baX5m.eyyz_ȹ.55w|iR0 +% ma gID[oj4[Al1N0a_ + VC fuߘt%0wdѿf"ed33m3}D݄|LP8wJ]\>5 WMIA"Zb99_ڛt}=X\4WЀ#s+tD3*n+/ZLѣh9*0)M9,SnW[YlQb2/`>X1UMق cD-Zs>G:1mPF3;[pk_]j>Qu:I|>$ Wnޟk t{CI貌@ o*+kRf% %KDd>rR* K~t:Hf yK6x'7ͲYyU4̌f,m\ʕ8dL}44+2=ܡv؛rOR~gh#Vtl5@zΉ@ <061I`~EE)O2Y׫G-f`U"(2~d!Tjuұs~ٓA;䐘[{_g!A}w.F`9CK6dPC| :=t,R ;$#x6X"JϽ;$rND9|D$U5IU.-0q)mB3q #Ckή9~o PxԫRWĒbɢFt^3r(Lgq]3-Q_X5^?5Q1wt,^+H8wQ"@A I0{n;>$@z%gakԍDoW*[ dG8UOoL>rLJ% Mx"k?0 L{(q(Ys`:jArsIHI4أ*8P]Sw6'`M8Q߮Y%ü?aG{?[g g"mz <.|:[u%Rtd %}݁'eBZ)C̈Il;bDw7_«G<F)=X[0!p%{珤塰^YȌ~g Fv2/fvh,PQ7r_~8Ͼ3;w^GyDהxG,}+*/h.3iN8>\瓝u<ٴ׌Ha ֡'8]Ʈ+=h e;? ߽ܔT(s|1J('ڜYQBɥ֢Hy-&Siz-d綕ټqYo\ whhq@ nbdxxq';[t8ʺ<ֆ\ φV+qNd~)gIU0"Д <VNV> U}84M\ٲz{j?Db 裏- `5G@aaCFp|$ b$iB%D;)ڞ*pCDp%IfX~4&uh=,Ern3"#W0rlz]M(^AKuP+0X*$v,jϤGHEJuɘD-a$f Q$7a׉|9̞W>óBwbX!8୘=6QƢ#&ڎbSY|G~ܛN0v4 }˝؏Of<3%@VYH"<0CM`sk1B$ =%o@*JuOo>TܘGUynj֔7Xǭc?(b:/x}q¡c`ARl[̙ʽ@iIajIcPy.ҫzXݺ|[;Yб ZZ XsO2< mqaJE?dpF9~"bI>"-V%nG @>;~D6*~bcUFvxc$ZV-fg푐-C⣃͈k2@ V##5ןP_ĝwͅ ;[dW͎L ξb=˗>"<_x ԗڌܤ<~?Z D`xB Z$1jYń@/^T>A@h  %O^J={GtWl mKg w(~E[U4,Gao뛼? RI.c(u?VjM8 X]PZwS=EU$5NͣO|Lt@hWJzBVP}>z_x tF}?.n+ݮ'F8 p" /elS?D-[U̕ 5Ò'NK2r>5_>ځ)r~ ߡm1Vlf'Y',;yMrbm?\Y:#4/MVO)%LU?Y)G90+^nV~-f][8ÈUnWODWN7oMweIi-5]5pm44?z(mqճ`q}-C\U-3#pi 3L=(\$) DSP60 <66:LeE-WaP-FQ(7z#dM!)mAZHV6$b ާRG`M\\{%t@ 7F?`JNC>?³P*-C9/ie4g,r4 ]*HAe_cMgJ]`oS!0B'Hg}ѾRh,1fuoصv,PL8qilgנuoʴh̻Aji5;]@5!=)~qHw=eԔM}[@0q:. .)?J#/z/͍#-<mz vsl\?3f -\Vm=4`än"9bJ dDꖑ:7Vg䭐%q]B{ѹKiL`1(CR:Cw'E ʛvJ]3-h^p+8b#X\/ܠ >9-Dx5`c)|) @n jó-h:E'7 }XZ's5<ބnԠ/L_2R[/@F! 6ݐj=Q/.{O6hax?Xx`&b)rEyj|,(~[gpz[ $&2cP2{HOklڎzw[ʜ_ɷ_g}0 908M18 W>\v3^z_ѐHw8F_M $B}3Kq_yǘʤ-ryӀG%hpU;el*Ɠ>]meD&u!Yxĺ 1EWy'QU9\+]bI. ҆?FTkQ @PkMZYUeq'R UWV{^n?|]\dF"!3)o$,EOUe.<ȌCd jjmrh+ ȷVH'Ft/ a&Nm2D+ bfB"!'ݐO 7S͐ҭGD^f|oLW1Ɏ5ݘ2BP~&2chɾ8kwwP.=i:WmSCmĶx{W#ނL  tMDlKRS ' w`~_Uf~L> ڌ#DPjĢRև ǦoA:`E/׊r1r9J9bw:q]"u1E>pN|"8PfĔsۂsgK1oPy\nm=2{' lS}dVlZYKp5 qp\X݋14|C9 ВκD18ܶ)W)5 $t,̾lcOsyRs-sQj>LL Z,`\I\K!.+2b#ZrMww) ur;sמ aZ%d o뺖v z "ɯ|͎hg]^=otulZԉ+R:9|GLmaecє~;4Ba]ly&j:%׍!Ĩ%\fwͺ˾ AX[Oޛh/r}Kpt((K!Ax~\zM+%5 E"}蹇2ibQAI@2I d`x`ӗ,ն*DǴ1m9qG&i):,ƻQȢpvC9Up.\*oH@5˨øՓ&1O>i"+t-#xىGPfMg1 vӏMNouQ~%UW{;s|+6{Q=PQ# AY)X(CeкK\5mJ.}. (~h.bE޿Dn,%Q]^ǔӤc!:7 ;C7^N}g F-`S0UK#VuIat'ʵPT^~*#]Ğ7O)'C}]\4}@33 eo_vEBXH'~s]P#(e8ѻ_Ю߈з8 KzaM ۷]^S]\%-s~qCܟ} 1 ϰtfNYI)n0U,ݠ ׬rr,j93vVu Ӕ^ ՙbT'EW$TCý^wps -1T+4[ĤoT| FdF'ׁPSc }vJ X-OD'oJeZѨ*MnMzЙ`u[ݴg5[yYQDӹ|̠Ht -Q.C>/·\YX\dx%ڿ"Hj>-/ 0 8\߳jUGo5jrRnaT/ x޽vko~p@||0,yXJ2V)z;E t|"I䐙^x1[c mY /%3I込kk*a@ɈLKG %f4,ªQyhRn;lpi]ϛlhm;^cqj0ys DcY#$ۏe=Nz(![n 4$1y>n4TAOS`߷ϿM@ m:.I1q NeKhD 0,ObX4蟺=^ОDZ >2ۜw-1S$K*|*q2n?5:(wj75Zpp{h=(>_c"JiS߲%: oXͶ 놥M>9SqLوsʲOXTb[Ah\mP\| J(#u+6$ϧyURt(*n"@x)S{ Iuk@MռarfFpza{|&% A 梓b*!i߈X[ha͜3؟ˊ>Q~wȯ;ߧVRБ%+w gt]+flWZٰVk@C΋5#%iicknQ*xBBF,Pݒ㶇rO{%,p앉{qIdBb ֜ |GigbK %a]ef~fQPX8;C {Z{v'^;|‚X뢁異˭4L5̮.#6-mcFă[#ʬ“~gr|ޔQʣ mUkeg6UxLQ#f$Gdco-eupisu_@a(jCK~Vd\NbatJ4`W7/7{]='*aҶWȀ*J Q5(Bd}cwЪ/T"N$ΟBd Bdئ#L20%s>M_c`𞭿ȟ) Q& o+<ѩzPdrU(b}ځlɜ⠅u[毟l)_tzu$>PAQ#G 0pf ay8$;-` :>sJ9UL4UHp 9F);MH$Zw|udt}`C1ܕYԯf䧖tG_ @_9S"L/>dt6D( с3H6A >gXvMDe0:4o1UMMhsp?k鴐۰jn`D!癇ary~țj'l} )>pY( Eaɤݭ.jC -Ҟ^p6ƚ|ڝL&w%ݫ?ړ/|L9#ƈo fS9HycV0.BxV*+_ {MZ= ayv#õ+18iέ$$ [ 0Vr MP~Ֆ;F5F Nz5B":%p)̆i1Ta{t>AϧQQ_w)}-tW(uF- ݢݒWCŰ^xGL*I[@6$ TF eMe9U'JT(N=Ie؈.z9e4PVC-}$Y>$>X/D{q삈X#7qCgl"`qMV/G)w|b.G{8lo8ays?HKI7D~myoB`GM0'Wzo:,KeZp;v0(V7jb{pFrr7Z/" J \i{ͭs#"/÷psV6֥ؗwN ˢU|;0S.1QwezH/NggC\ C&E"BBW !dz HЙ@x::+f[h3 Q H(s^0b4q0#GUjw/M(ß Пm3aC`urͳY{ϰ5|DaQML6IW# DJ<|USx۠c=ov|ŽjOp`5Wv=RaeEuItppYY+ݩOeͺ Q"MZЦ GHg(?n7+j j1&9`7+I}GP-k.ŷ![}=83z>CdL .nǾAF^=fn2k 2EPZhv%V8~,wy8Uj\Wx3iܯf_GYO/W6A7zE1MRjY-@B*p`:ױNUIcv թG4^chy!`Q쵂X6qUSΥuG~f+ŸdRTwXOzǶP`Ej\b@E]>* WSBq Y#ɻ?< W;F$(q X6fk9KB7Q w)[}kFe>7PܤUvA_X3WI*)S)2JPycFA`RN0D]^/2$PHW!{HWP&PN"r7ʘNT"Q rmZa4]^=7d:-l!YmNn)^KfQux% ecȃpy"4FcL QG} T{QRVlt?B1^:/|v0:):;ZD_e4H7p0Ec)1CGA9Zoid7n^qmbٍl޹귍@֫cn]1 sG1V̍NQsIwvpq ^~;I%MQz8r[Z0B @!'!8- YN}:* :4v*FGqYJ+ ?hP}tacii@Vn,醬 rThc֫M] #Uy>pf,SQ@@`]|sUC& %&m8,DN_ :t#K!n4oM'8gJ@c`ͬ~*5 )fY(9:>zi@|%^{"A$ؖ[ Hc̬:oCn s:'n |儑FP~C_k6D-cdn`Is[.ܗJ*!aOO#l~\/D*Kk^f$٠ 2 `_J$~'$..rWi>ϴdl\ qŭKzYЙ\3ѹFvս=#eRs#kFUޑlA5ap |gkO\F;mŽoO!惻ڈX2l))2@Qٗ4fW!R7X*z6J]a_1tю@sCwDUΖ^"هARA$T*] zXL` [5jмvaO '+a `dPL/#1g =gZkӜP<:߸ &tZ^oܞ<Ȧ _f *.ef:z}2F(|AB=xH, Ȳ='"{ڿpEKpyF ;dv4tyn_؜$J2 G]@q.7]aQ6a?gpאߵ=dJ̵56.[ H2ޡ4\W0yl? !\ئQۿ]OZTQ8:9a=!tXݷ%IcX.,Z-n"Lkޖmr;r ')e9=6]Q{+GZbS@S:CEO1W筪۹1H*4 H) "7L]W!3)s>8hFxu—DR)E^B+ŗEicp;z&[0)I\ǡ! gMOml%94c^bS§Sm?ߩGKɰ55igw0 /0m. }v4ƣkoa*0 Fg}m*ǾuAR ѫZ cm3iw9#ᙰx{R}Y);X:w}'|z1_/:BW3JVˣ*C!C-C![Op>aJ`4{!5֚9 g9)Nhʼnu:Ix a-`/-ֱV:mOŶR'/jC4gr}֥ݩ!:, 氹6q+ A|)UrrxN2N1/z""d)Q 1 St$YpOGP(׹31aع?^ G$_j_;L6˴=톍ygQI&\ohL"0O ͼKW{rTElf zf#[ƹ9/O&-_{Р+s,۶9,xqA*܊569f57HꍭK<^M58>C`x;@.+ }ɮbOKVtAlRiP) {|% l0wvwݻCRUuEQ^)ahBd@#+vomw'Oeic{"ؔ$!IdS`] 7gЀJ&#?>ˡC#h,,7r\󉖚_ #PlO5u7F[xbu>nmN9W/OqZi#?ހ5SDqT%ù0W`>$ۇ,G]BhO✠i.P2?<z,C HMuBrr;_$o_YQԺl.Kzaqmx܎1wf&9|kI!b3u^[OC-[ڨ`JiTٳC`5G,}n'u9йobv2#GC Zn_4Xc ),MO_ղ 2COjg emSNaJnzO6K\(UA~z<-{iSW\X wzvOڍ̞ ^K^PbKWА5 Ș:U+Ns8+be9rI|U#e늝c&}5wXG-PVI,l 7*+Y=հ|4 nI<7z4٭V1KC7 >5!Cd.z8\TۂXT$m+^^ ,>)EG<=8!ת"@_xVPl_* LUB~ $rFAѩ~B66Sdv%ڵ8] GJ>ntBlx`4>e}.d|2حt$z!%LYlW!x趩LT^k&/,"k&Yk+t@Zx^ɽ:OgA mvܖ^s2bj:ɰ^^.W3s$˧<u{ZK.@`UA!|jy9EvN>j,R;=q6,ɯ҅QӒB("vb tmրQμ'.TD-K"gK"K0y%< ztk5DANפǼ7.U\l,ۆ~H;|bnx'P߯e#7NCeۃfg5=- Ҕ3񟔣ͲtndG-0(n)"O4NPjUACw9SX r( qA|Sr>"cd)=8i41_l *#ʋD8ݯ S5$ VNMP:Qy(p飘| 0\ǃs ] ^Cۺ޴rDܝS(90lG\'*bIr#qB?uzGC=i/[g0UFvx6OdƋR\y^{U. 8Lpe۽Ŕ=}vrOIIf+ihkqE!1>^hAɂGo)j⡗.v)Lei^$0@o>zCu$O{v 4C&"~jX2{N~vvb< | cR#?[#C/6Y6un];r|GXpi~{F0̖U1Ie(&OE1^\IOwV"%@qC2KZִ E UO`>N/s0KDpA9-̧1DٌTU>d?! X( AGi 3b3lJS*/)}9\sFh)tӸs+5@'3wz7qky:!x(wg Gf,DS o,u\sYJ8~ͫn Ow0! N *R^wX#$IBGkƱl9K,<9h_ LW1x kgm2M83+2=xw%>Ѿѧƃ!蜀\ȉTrnqƄiZ}×w(J&˗1'RA5TS7cG+mJlaH;Y -{i!8m,.E;L$A*)`̦b֍< >6φ%QPɎӵ`HҴruWoQly9ҠB.5~3(ZujkV~Y! װqRގX3"c_#vT<1M4ߵs uŠ@GXoOyYCߨ]R!nSKX mD-y `T"+m6np!deu?܎?gzr(8;ENY3(2v|S90;^\fTgiEJ /LPȨ(Nc@ `]_鵵}⩏&\uWeyO EsS_lb$rYAF%laJj'Z'9uE">Evtwbx[B1p$Q| D a|]"z:nˣN~;$}0RGK/M 8rľ`PAMi2D+ ѣVob,㬺YCM4oΖE*9*@+YߴPWmx_@%N7T{VVzu-C5k3с U-c&uI=mڇ79Ej G&o.+!m[^u 6`RX,bRaCx0Z=>zg'XZ6d&w4RfOCE|L:K: 7F6jAH]Cʚ40q/ ؤ3&ޯ'kݠ4mP6x BϵW2_ɥ!^SFM_>WSm4y!"-m- L0j3-StةKOb0SJf:l*dz#Zh i6jV v${Q"qwai 2D7Y[ dcɻCay8{g P >`R7=>Dj$*ssDw? ]ҭ8P5/J+Of@Sۭy!&0#𢥞@ևw[q_[k X#-#?U3rXR1 nFGvE'9HUfeYJв__? xp}YJ:[CE)q&Ce vL[Onm>1jiˍP5pwu3ZBܭBH| Qk5>'Ccb+ʨ&Q˳HzG7fl ~eNZIIaRy@8.:~@TD<`bm6,# hj_b&G'9O ε+5/ZdF:Sw$=3%US JUKuަW_f:um/Z,'X{S+^d=l XF1THN<}uVUu6Ӿ$0҂A3t9NC=w5Y̢oU\n< ^u/Oedw t9Hc/ۗy@Εz(ҙx]3UKuH#-/uR6HN[#׭{j}BfJʥKWt,wYsEzrk ֝ F;:~87̀gˠ^.ۑB'ۇB>fc; Fhȿb tp 3ϘѢLuIPT%V_٫-bnÄ!Qce .Bd<~(?_WsڏU]ĞI. BI^ejP?ʬ9S?unI'08gd(Ud6$ 傉ՠo sc'H:}JYTT7EyCB_YN{ȡp{iE`4P7h%O-!fi p ruVr&1QoĤ2&I_0O"jrk,٣8VfLkʾ2y_@厉y:smB(ATO*xD@ pc"yYF.J7A.0N%2Ęnъ'/IyͲWjt6n#uI+jL+@uO;*POcՙ3cE6DlU[}m&_8R׌IpuYJu Jřᡄ#;:|C]̇>gW'}0 0XqÃU=r^\sPn]#Z@>s};6->,`E*Y!rkF- xJ@5RS"B 0{-3~ͭw+aFuh\HG@oDBKe/CUIo%-Ҋ=}g:RMelw p‹ ,ֻ!gwCEG}*d -]놜L8']>%0唇G^;*p#=wU^n|mJ2#"ҘPՒ.Dܳ7v,39Do,;//?%lU*AOwM7-خuz~6^_fkKcab`46t[vE$-dDP&トg~nPB@ 8[ӆx>H 44֭H?)lżil1ʀ;Ǎ[bAHozb[Ku7{dC#gT:a.jy/^hy+|KEғNQ?BDg}S'BRC׌@9 Cn_N wv{dA ܒa9J-buLh=e!6D.>r^W[G{}ֆcG^VKx:|A(qAA"Ix 'wC.uH?p-2=m|nXU{.M@?'6tci4X 5߯ 5-vwgx*rk7z;^6 v5#_`OЂ~Q:ݙٞՌpTG'!\ڋ{NX יkJpjjrN<+7&[?c] -8xU8ߊtb)`)RP5?weRgzUH: m !TC)#~S%Lp%gRKEG,IyNuѬ{bB.m_7`svT~ 2O~,KaF2T}[dwi];8+t*^n x Ε]RH Wz D\mV_E4U|~ˈG_Oܩ{s7Sڕ8y5<_ 5Ն’2 ~!w@M]Gb{)=TGN+sOfA)֙r$cEZwĠiP +*#[Wxʒ.k|.b-,XABWb&B{1cR0*mĎ fs}&4yv(a RnYushr}1|``%erFHkCK)iVh] QIbCgAin`  жl(5X#i x|3NE\[Hs q4piYk j`h:yc-b8ANLϛ GWLwT .@H M$p?{'(Pu%ڗFHA(ZA5e,j+م=_5'ΓBWbJZCvmҿ=@l/9i{%TXJ ;l$#1rv .v sbbgnWjQm5&Jݣ<0^L̓pG}tuxlCod)՟Si5v>X"N@W=Gvp_ Ch"u=7ՎN%\B/;S I#@ g,zܩ)Z-qPY/̏z,= =I@rVD&>oF+%N1¨bidOҠT|n)WKP7ăޅ'\p bZK1#Dvr F#zw +% Cox.os7Y.8Lv_\^-/=7?ϛYZl_QlO5':r\'bƅ_h$|TG memuX?$IvRy9:eP7Ӆqܜݕgloadzۈ9k^üJz8;[s:Oњ~umm[ڿulzBnL>F2ū{:W]plǤc~c+wжHp9[O%Tқt_#(sݣ9C hr Hv[im5*xt=,Wp2(I4c+Di/J{jn}l"2L9MC) ; 6FhKμqΛ/ѝL&B#sLW@{}Xd:FGH4 Zp&)#NPBe>ҒJD+f1}=wg6dwVg %ݻ3Dzm_B ξF 89޾[]MPg:&gî[*K՘ ?Ӥ:W(&H[R9fClI^"KEH$ݍ̸FOiw8$8>}=[351pq1LSAp&sifY誙՝ \5u—<^dgl/vu`AmJ)[hee| f VKIQӅu.ܿ;,ӛ0NМj%!Eo]?-4FǘE;N .Li .\BӤ^$#c?f+4,"hzc0}AadǿUFD9Xgs vf+*6cY2;Nq=͔GT7L*wr^Y=W3Y}8_VOG|rUW,0t$Dkfz-6="# 9F{ުsi]ER-tDL [R?oPO"V=Cw@M80}Cj }|>k?al_tfM]q0GIjHcvV|Ҋ5םBo9ָyyt /vC x'ן_'O({VKYZXz(#l\bR‹=ǟPy~b as0n更YG8TCޛH8dR5XQw?]'aymH6~K WI 0_:3<ڲ:DM:PF&g|P:zQтa ݦ0`oM%4+x\75]" g6w|: O7B,bp9yqjl5rB/'_8&Ɍ9;&$of1δB\YGiiNs&dwݭO&>Vڙo{DQ`>ELɘCQ= 8er 㨶AQЍ"YU#YL8/ϻLVIڂ$JWh#o̎eV^f4U8dpSgMwQjTZ Syr5΢U^̚XŭjNIʅHlqu}L&Q/,܈)i\+qZ6[E/f+1hn$tm  gMYJ!r<{hcW)Kn˽Q92>:^IPpf{@]ؖCWY>1W# x(Tdcs? 6Bٳg`ϡ2K2'08<3@N,VHٙVdo} ` ,jHroNA GDy(8(%q riۤsX< `Mb! rl<J:) qS}D"{Qރ\(| ʫ`SL7y j?cG/e+  8GxƱ(hFxx; 4AHx! 3pop "9hyb<}ޠCh4o E)Ӯy?'2rP_] fh}Ejx/yyY M7ꪂn!ԻݥP'=UL]~߷UIQ=73HtFzxbY a+R' ɐ?XC~ I r5\faAĉa־~pm֔dMݣQT#}h߉]vdPHOx2?HT\6a. o!M O Uu@VrD ֭{zT0@hDv MMaD9v8Y-B Kn]C]iz W*ń拯( YkŊ3yTz bpp-q+LyQ:§{:kx*&3RX|cQ8шvrYWUD4vp aCC'DdϘ&FI@gPr)*$T7< K֎meExӳ*g2v,(yEάs_@'ZN_˅1πA(Zqj ͋d ,oCs-(xTDcЧzh_ kNo+U aJu5ր-HfH$ $uF@:}b޽iK ? t">z7rY.Wfj.wWoDu8`(uN9u}biN'j(51ЌnwXPxU- NU NFM'Tyi"SﶮSIL Ld> m";\K/?Yy+ 0\bv@/u&Jɘ>.9tz3^Q?pAv—3ᒮᴄg棥$K߯,y?ɲc9t آQjs1 l'(8t'1"o=27[Vp'57lAxÃOgͱ"Pچ4[ H]'uVp A-Xĭ rT]7Qy$'$ Q}]5R6gbÕ=nr)mAjρDdHH<XV "" uK u.]Fmк 3ؒ-V:ts0C2Ҵ^m`u ꖳrv^+zhUd&i6lP\=s bЖW 7m J?i T`u*]S*gWMul_z>OVط?}F:X_ |7CH5FYWuYEw젻6mT=xx grBX-kN'o#quuiޒ_qr!U癋ʱЄipbI)SU ݍYN?l6R6S5]yaK3_>50o+To-.4{MmrH0. {6wx'`<$?*ItF+ed̰͂b foIc|6}EW~nyLXA[a2 4t{p쾩D~݂nBYP]\RlИʥz0I 6vژZO}1fб.W+6<旊4rp[-|n%Ψ`JA׾׊ٓ;W6 ,2Ѭ?FiGi3}ѠWʲ vnH}7 >4r;b[wt"X;z94Oٵ:pVU8XKC7%?HZk;9VU2p@8JnOT鴉ӈͫ@J\]d\$1y>{C/Gx^Z$t5_%5%CUbi#3uꫣpoPnlDm Da^FbԂPeCv=xMT~ŏ&bz\]P"x22d~d5TŅLњXg6ІT`|g'zf OΘHclPH KR6e SwǠ*Ygj;d H!x^f>I%G5$/R{'=1xPX}0pl2`3ë4Cy_^VsN|RVG*} wNT~5&Vn=닱](`-㽝)l!*'axm#7wd -7zhj*-yj̵wi[..O&R>V^i:*uu؍u\ثoLwȗ?{U"aQ6fqgo ?~\ ԛ I?3Nx^2t  WP{r`!cd8 tO" T"rhDtىK󠘆y{=.}Lh JPeul=qdK^ĥ6 {BʫIOJ¹tte[Iq3'9xoq1"&mbQvSYpRJ #.Yx- |[YrUIk{1tO/f`t&'; Xώ$x15nR|fP$]P4y)zxRM7HFC21Q*Oy'D61o-K u萪x-U؅{<_]av!s3J/&n 2]0?V,e!5i?֛RS]m;U V)DIz~:6@]]*POnaOY=5 xgkڙJΙ!Q `o ޡzP/n\mc(.9ƻO5c5ś/zQd&Z4X|KuBYV%Pƀ֠ e7lZK\\7@;/ݹ7~u;sȭ_77 Aci` %H~We7q^ӂH1VO[kq F3  Zfe"#. _$y^,f 9ρm!{ bʜݣ$ea}ܦ6tSͳÂ}WsydeeB7?6cCy94 orbyKSxܝ&6!*sA{)V\2uR䞷X=a~~Ow&c'M}s"(jGk]uQYXM >>p61 Ԋ444,60kF#ucOUێBGcǟ󔬆ga @>Nr묀F,!ଚOe/%,0/ 6_|d:;쏶\C ^,e5 +յN#qk0Mpyt;{Xq#I"coOQSn`]k";ػlSI #e>K+_Ub=OIot`np `8 fHAS~bvb]x0>@̍YK{u(jJmϜ'1T Dh[ TWTQ+c1Ro(5j2i]b?2H4`( [6t\f]=X&]WE)BhC7pKIGփpO7PMMOZ([GKFp*kog Y\a2c5LIW'ɍ;@daNȶnl0vs:YRq"`>^ !9=).6΅*J}׺^9?#Vn<uJYZv3Wg|YOW$#of>SmqwdZ~˟݌W&a<5i[3x`+g ^@C|&J sQ Jʊ]cM 8ma(tr|h<ۮ?A(l.?YZS0-q}o#h}ƥ*0^A iZՀB=.ڐ໻0N Ib"FX1-$k#O|:_ "0~G4G!ĢAk~o`++N;̉jUnէ$yfj+Uvt>ƨn-n;T啿͈ѧ'WN!js[wԵ.ZyNQ/7W4Q-üE__Z\7OwiA%6۷ [:ŃXވ?d1vV|F1EiuH-(d2ªk9;PCT:;FjȤYSC{-uU㨍:anEzmV-۩ xZ7S^պr0~De$mC˓. R228.7|y:2,Y#Y^{~z7KAwLѬj4]2bILoCF7 J$N~NRkuaTvk1})D8ܿE_XUj=R-{kra*of.`BГk ? (EJj|bt81bUڗr\29ǛM4Qgx/+wF V{P{4fLI5myo-ނ9Xج=K cxM|]$^{KoLÐ9gSA.lے8 !KԩGM_aZG`;Ubeq+MOxWp,@O>BH]G89ؾN,}c1]G;{44hĞe;̺K'S5L2S˰LtJ17¡KZf8 )"#5@pg%@M7a}3I gnE!fgӆ`)?z;wB]$'&2'em9 *Ύ>:Gsި:~mIO etˆpW{9p#{RMB`s;ώ+(>/ZfʹȲL{כGFC(c"/,:;ᲗVLS3p!.+Mp\|-H[g>å Ij;Uìp?A8 pͲF032![d=rTq5@d"BqlXbCT1b%R &?4,!]`!8q5 znPT H}*ONU UPw"}(q6%&{;M~q)pyc(' m?ae(T#s^YZUpq5+͝GVth@uskuپS3D~H\IRq^Z"#N=؅)w Ck$.ksZZRTh^-LV^#GIbҲRAx}1%5wӈ83.});g4"^/vg|p4kK[fGmLPQW&uIBWSQS kquDI@?zԔmK m}o0]N.Ms*[Yb>a 1w|ZT{01BN P)F'f_/I 31ikMt$ j054F~PK>,`dh34 %/|{Β_+Q@q&/BxCeVuq^B=b7·8ik@{|E/<9V7n魤G玨hʉGVbn9ԻԸDWd V#BU"e!Zs&Bk&~ivWL 6 rSp "^0l\xBeК)}a>mqB` ;C YT[3ߣ&?l+SL'BQJ)vhwu؇06y  Ǎ=l'.G+HH>/,k3#%F¾]w iz%؃X~wUޠS>A+\ >Ir b*B1$0$7[bf:r $ w+"X&,۳;1$SgV :Sz1xrBNk%*kB0_"ҹ6K*;d.~WG@I`-\w쪂|#@|eϤd!:uc2bG7ysU:-ŭ,>+T P3; E_0u])MUEС 7>d[4dCF-.]A[}-b^O"~FBq[ e8МUo2We&\K+ nE&EQLJktUB68<+׽ ݪ0iU ?ъlt}T3,ڀFkEtU03ZMl&.3w|nBO%UGVT]k2vh{ż[Ν"$WC^ׁW" g푎(iƷQ>IoM3?Z_CDJ rέ}"[LHx ꖭ7|s}mg8VP7TRMW_;t:|޻sH}uM,l^/s8l#D)-zy]8]Jɘ^d] j[KI/|K`OV@ 75ȴPUbg \h:2u(٨sU0b [X *FZ:!7ц霰=5y0byb. b[Hsu,|ĵhXT{jJO~Cu\DWaZNGϭB/fĥQk$4%"zfnjm L @d3mzEqɯj-ohKUǴb^0qòGJu-h3Hא,Fi~E0 '-4|Œ/a"!v H#l/E[^z:}lFu*#p*Dh獼.j #X?`[p\WkQ,D--*Ӣ0b|hzg\`}j i[.sƐ׼ Q?x> [clK/;9 Tll1+T.P'rbX[HxqmMrW:fҦBATRLO]w{l^b}3tiL}o̘ 6)drw3(?8QE!mb#n`m,@@V'"Ԟ喽pp#n٥"o^l\S̎9Q=!0ŧDcߗm|-ɜ>Ộ~OӶC#I#l8Zo-f@H+vr Cbu̥ FI.·* x;%"cnP&:[Y^4DGAƞMT1Z LYk]o @: S.SMr厾'؋7B!`jvVK FYȐPV25O&+|gR~oQA|%5d&1q_9JFOD76#nEް'oilO#mpUkB6'3QU[3'jN-j~:6,E`\sYtI{kjfX_戳K\K>Ͽǖ~ڂJ ]R~q컀}$c` 6fDE3o {$ `z(e -I4W\(]FݗI%@8vk7`FH).d1T4IyGÃvQup-?xx6@XTֶm%ڷӡ8RWa!CQ}bdgy)ҍ("7qA'bE?pilt``Z9 x]h!p#;8?o-8(1\<ɰv&Ndqj߾%A>vf /m9ff+*'Kak1*"Dj<-܃ 3q݆#\8:0M-R>ew]v߾=W"Z% =yE ѱ4?! iY+ ] OwG`!(0]E㬼DRel/L1 3?b< 1 TM'њ@CypUr+4w ;cOoxi%4F$(xɬ"(aD]e&py"f]P40ά(aP q&H0xr&q T㑅"u oF8Rģl?~gyG{uآ]>HJ'axZ$tqd!}/(4F9󫉸t^nš[> A5mdJhT- 6كǖȯj_*/6BO\ąlk|}2!|l[!3wwoH5 Jhuq(u bb}'c2Í)Mי?ЖT.ٍ),t`Xߛ)fȰ!@>$ nrR+{|h;.]ֆLS!! !\h9@}_: T:?k-sİ.V@V"жqnJ0υJ튊ɺG%쿀ZO!m\!P2W=vf2zg#ưŮ^nW\sQABFuj<4|KVpo^Ȍ+}:?,LHD힕AA$+(o2 DR9y^2֋ {*6zd/S8t@0xTz9(wOLܞ-"v:k ;b.8W_ͭr$VmT04@& LBh$c'-9j╽tU-(b2䰺dN-ߔZ j[ bnK[xx..(z=ٌq! qu}gJ q(LT]ذ,tO||rc]-#acc]#thNQA ]Ǟ@eAg7:c&/zkXГ3ú$S`h+QY"( E^CUn|l`X8ZW"(^6J^]g2{n ;58 )i]y'{W<@:J35PWDlhWX0\ 0@诰"Z^?}A=a< ]!Bjٚҹ;FE2,qڪOnҴ$LwZjh꺥 \:ߜxl^C 5%4HMMF_bzjS%j9s&3I7~"^TA"k\v?dH6g]\wCCؘ ňrvӵuDFWh2`"n-T@=_fK@ zRpXSQejM]1'[tľCEbcfw2wLr9 ia]k}ïo+ҋ'Vs@K-Se~ݼ6PrkzvE6[]B6y7}@f:@ <yqP*Ω/G hL rݚ6߼++]$ E>֙A|r93x(cdU[lcP0r*@*W 6uIv&Qۮv]|]l9N+h{}ѭ'?tG(-0D?|5OӃ@boԘO3P|͖[N ^VPYSFD''J5byǤl. ²O+VL-?Yqߐ,qFRz}5pHB g4-O?7ۓ k .L5gu pCA >vY:#ݚn@G^jLut~mҩY*\N@4zC}ٶ<"nu(=A#r_uz"+AG&S{ ~9 ;"CA?^޸v64YL/|XۀE곤0ז.[.hu&,&LeֻΣmfv^|X{s[s(YzRZ`qj م(EXlO::;ZeyzKzk? gp9T<o(abך\ı|]=$еͤ#>O"ncba'mć޸zW' ~+#T7CLrȆ"K,z+t\n9г u`B)S-?POJh[f#|U:ؓ`XK\r-{JOM6bA[g@_/A ~mؑl Vu ʦ<`898gcΛ@_(bچ(;7릺E>>UwM0/}A7:od/r93z3Oo߮*FL7sǑOʑKc+,qN(V)XZp"du ? .JLJ)K_#-+LtZՁYG4~mК q|DSKfjE쉪8G?#غ`h/)nX휪 #)+z] { ܔ[tmeb9 b c+>ծk:_d95fJF)&-6<`]~CJFMӟ)4Aҋ:ǹim$,c.۳w2Hon2`/X)ټVlIh0[۾l[{)l/9Y,Ǧ%Oyn>6}-`o*e]2l&tP_P$tM4!sy_/8Vz]  SXl,/IB 8 ݘ\/bqei%:umA=u4%{]Fhk>@8£d٣qN;/|үW8XT𗀫|Yn]imDN12Je0}8M ل/M7 [Kct)T*X][Ȟ8x^i*CUj4fKNMyd20 ? %!wAhrɕ̇ӓLH$0'Qk㳳C&7E4 .fUm=6%¨ gbMccdq ":I0s4%~(k>z%:8pz:Ohőy5ˠ¡bZV8^X){5E7nN͋rqz>M#k*M$iLu,"lu3#w̶{jAB־zv/[NSmq%Awz-{!A5L{t\ubm;Dxy4w.!fZ֥swG l$9 "j(3]^I!pP5MG7K\\% OAQ!?rmU'U|PJ|c/˧ZFG fܥ#9ֳd&I߯,C6Nur)55sٵ:jc{l;pfV׮)E)hŪi9ňvKVνnCͦ'o}LRm8@BX[]U!؟_ZOw)]{N%u |f +>{p[Bwa/I{TVMk[F@* a]`˨*~0:+ sizXu />MjnUTQz?{U'ת,vhG똈`@@IE7'=a_ܹ  Lt[QR1r6^!?I~l/d*N%JP j|!n%$HHe<=ņGiEwz[UK{ \,MR~p&OѾʇ(]xU>#2?$J.~IAO03:-4-fEײh Ʃ LwvzCV4+ *k4zTUQnKxftSȀ2"#*V>X-ff0-0:]Sv*D«pxS{,T*!oUe$$<ύHVA#jyK~sXvi|IyK6 "KkMRd^ȣe@`L@|Pݢy >E~sfgW7M >=\zى~Y&Vq] OH5St= C ҂7ͨHwjGo8vOb}c$Kt<^ZO{'Us ˰\~TMnC||Q| jwИGIe,y>wc|YaGZKyG_oXru8.30F$:>q}my*NzlT@ő.)SƊ舺u]~Y) twgY4Ki}e|kvhU N\ʉ ӹ24嘛Y~if4Rβ,M"T-tu& <ܙ@E#Ё(muބF# ҝ$09s9#R軵YBjI%z ~ߒnī6Hu8]0Q!U 4K%Ԏa4a4^6‰.K}%޽k22E33Yy&s{+:.m(Em0! f] UM^ 8&dM5 K{Y''Hs5t[Pҭ(P)p0"Sxia.g0BR,SWϺ朏MHYHQ;!7Y!/2\c`>i7QMra pșrC E=S7BP C j6Cۊi(dDf.TʸQT\KuYf?}FkCp%0>⃊K70nBZ7>cTiSy㉙ΝzH hDVSjH˵I{mPSMehvBY6 N-oIH6}r=~hDL~.6𵖿ߙ2/XG0_Tc8P\H p/C"GeC b-V*1 E5{PX{ny{;ef\:Ku_\V)ۍ2J<@/|]$Vf<w=: LhXAϡ-FQ1ƯmVwI7)\Xp>ea&d&z%:iq\;eM>FΑ ,k땙߬ye  )%{Nڷ#PB\ca=DU+}֊x}G3(3yF÷žb9^aAQ~rOԣ3R9Ő(nmϱ?TeֽDDɖV]wY@.eA,?Zh-Vah)$ᠢk켲 Ș768VFlDYN{`#lus0u~'= lyb_DkK*~8]cN 0P S F=_&4e `K 0H8]:.GYET>ZZE0odžİz ]}R-Ða@.2ِI+Ne*2'Wߛ lGq]K>юRζ NmTSEI'uڜKhm1䆤95ڸ_Zr[7uJbOB-+ e{Ʈ'4\,OiG%sbKFRJ7iAF^=T\D X^Et݇V3X}bw\ SnU"!ΎYۚTLA¬H2>1n$<QUJ/X%웵B̰Rp5#_Tއˁ3?!."|_|oToNMmLxh.y{sMX%{-lAy f^ \: IJӇwb$6>0ncmE̤dZ E$rʁ XB>~ 9kKӡ~f;;%ĨWX /;`M%GZJ,!8XH)k\ORpHD+H:wcD! aجѣ_>ϊ"lz}7Y x6Puq\ 퍟q=(Ó_"*z2Ч~ RU|̀/feʔj{VՙՅa[&pE8g7?@IF~m Qf-[ qRENT:<-:<.&A OQv|85%z +>n5n ԙ/gliϮnKn^tPT-^K/?J0EZM?õqz/NУO'EcKfdkp_idBw[wW;ir< ?=@51Qɘ`za70z!MAg2杬^RxȨR!e:#tBF,V{+_hsPߧ >O}  '2X.% n%r1NZcn'%HI"Gv0k+F8 KV4ngCAf+"r#p ۛZ99{4HA΢J>oÄG~؟",WzA,KtՌA uۜlq2NU k[ pbu0D 3$׺"_ɆIgݕ'RȖ—?WM/ptw,BZxCphdNIOAA$ZK:zz vA Y:(( )Gmdb?RI` ̃(| {,[?&3"f5UTk֘y9yp5Ӥ؈Y)V3flzVMxIi|rƿ.PTO01쀠#Ie3cNYKcYA ^Uw|e ^pib5yj"14ˑP[gdS~]{kFUJP$d4a'jS?a1~w?%WgoyXw> '4`WH&džxZAPl&?Դs. n@[(||1$[ۮ+aiۨaԡoH+I&,=BC"UKkbCJ7d7pc3$ZIfdm9;p9B~;$2+;Մ%7:s * n0cJ#HO4^<. ا50sDcv4遇M)E 0;:yڰ'l*6'GyT-U߼y+<߬pL-wOuǩ@u.DžMejकu2PxSB}NDw5eG,͉޳ qs,j(L_ß|px 6֡1^MOC">QV3 -5P\Rcۼ*Gt)a4U0 M Ϫ/hv=0Gc's-Zݭ2 .OJϵ "~?9 |Bk$)nYT5zV8pw|e9}Qefu,*Ȝ `n)\aG R^Yʕ;AE4UnLVDHPbPNv"mCȽ 7?Ba^%=^S0k5$Pl'D &;Lc/F )7\vzsM:֮le]q:2QNy1 RRwx["rh< >kYS 7_8Sjb<')-zL~-r'XWXIx"E94H6iπoz}GG %EwԾFK}\CƋ8P19#55*U'%^۴qɨ2"{DgE!P>kL h[Ŗ Xߛϗ!pfHbO]a@~xg.G/ygq8#j}≀Dͫ-7.kzK4/h۰Oa5P\`t r/QȘq;9Hm-: ӽGKeHj򟞲KF`_Dv/eS(3{#׬&ϐ'u?1aLL淡鯮D>ȹvDi U{d?:o q}1MH{uAيFgY/@&wK&,s&Tj3 ia36W[h®pϱqV#zW. cC 6 U:/pjJq a="YJ-hY56J8e-.?;nTZᯟ85yjvOюtu&o).jk9Ie<zӝ_P NX{|s1~ ke hSeԜv0ACcv@ڇCW/|#Y="QvWzZBGq\#Pr.SaMK?ŀ؄hC@#&aYrF鎌 I<: b8O\KGAfnDqi- ODXj=> ]^zg7CgY$peIh69.ʷ{rXǜAUYMTv15( )Ș}Hpnq~)&$i"RB3;)ґccl~@*ggh!z*WhȬNa-:]U;qTzSl0EsXDMف-﨧z+k*M{ܱR؄Yjsq+Kߠ^ON4*e5 &SM{DZY&|ɐ5 1Ahd<%ZW`V~?q_,MtxMW\)(׫ pK5@-+o rn`^6 &Qw&Slwܠ@T.ϰ츾9&uGi^o٩BY)HAqKLl),Ȇi}GXr@+ Pdxd'ҠI~6?J'j?t̎~|*ꭨ2tHP%~qZ45?p?"P;!XQzs)1*RKaBI5M_cR~#] vk򱒾_5uT0%ٰM D@J4QЃfT=Ç09?kt:oA\sWee =TR~U(V\e)C-c_cbI7݊]vIl} [S<GC?JZeU1dl0ໂ[ٱJeygxEqF2e4G4i&+|'*aJH^^"6R°ܼgvp;dktqpKyjMSS{MѹeY\,oΏΚьn!]]cIWCIHTvcY.ah!?}Ai$?"x[o"EK W]qwm6 ֟ޑ.@jȹ?S:V>$r= #5&?t١cnet~g^6: (jlVs~mԋDyBIgvGzx<(kdQբŇ,k>f͙gubquLb(C2L]D-*6YǠ&a)@蓐Jw7 0İ8*-펠-y,O®Z{fǼpIq]M2z+}OV4$/_=F*a}!$)$51@㌟K_Z`h p7-IE%-(sZ 79^Y4ifwĉfJ=pn%~ 4-z}AIpZrFx=eo¦_RywDupgOc 2-cцQ.g ބEHiW´늖id{eԂoɦ|5qpZP2> {)4?(r25m3<SZ,NÇG0?z瘄KcƆsn"ŝSLIZBV 4ǀE-jy-+bXe/X%=Q(ݰM|QRLKdJlf| p.HO5Ȏu*ཱqOY @OT+G߄5H` 0 S Qn' s!taI,L9~Ҭ!/q b\^/hN:Gn-*_ 76e+I2ף,.Gsqazz¹ZI&tn(" IQ5Of̪,%6_![W:A!kO8e~L3E;xZ?%RyRtrMtq(:HH߱2V[X[lOT 9зAKY% +.&a_7ٟtA[_Cd2U%՗$ %]r,μB̋zG:,y̤O9Ș$trϽ׃ÆG#Uґz-TЇy}R-:i#*d'9MAz4{Nxrs3鶃ŝ+Eo-~r[PvJʫ 4~-:n1d˜3ֲ9L1.Ȁ (œ|8IffıiB]@\X5r gr >ɲ&;7& ⵝɰrcԵ5`t-yoBk՛dʞQ:#<.0F.U*ИeײߜmAƣGhYR 2֢>,Enx>~~[v֐j0#xӄ;+b$%᨝LRЈ8Sћ_{H_Qh؂~ZMxivVC]J$(vEIEs\NS‘ GT롌b癐qؙ7y?H1L#@CXuЅh[8iLhe9Ԝ_[iU۔HE ئ \#9)v? 43JzB,69k7Ѕ8uY pQmZC#{hVf# ^Zi/݄K辿]{YRCPb<*F^{9TbBFIX Y^ʾ'TCEAPIhŇ*iPfz L9.RnMXxcYQzVˢ*Nɢ|*\H,ΦRHf%Q'}kz*1Z[B8WN|)%jEI>O0}ᘹyu"GBڱ\(3z)jevq $n+*$'ɒH-|dOhS ~ -<ټNVb4(z5U|L.h`B⸒[c!Dke1ebhL2 PDMn}xaec<0ikHyCј\&=O^";",4c)|Ն..4b+wڌ }% f-ozi^cQQúg5R?|?\*Τ _gJXKUqz/H x &b-KD|gd}ē oj}Hpg}K#ϗi4UR]gc.8;NY-Yx{cUi:#jq_YFXK$pIJY|I|gW͑͒c 'v}@6nA}Po19+I氓!6;H?c@<2Lat@i٢>^Wk5t[5i]NGT*~p .ԂiyqX2MQ!}Zzlټ~xu㣝`As=3h AR:-$8W{&;>|VyWo i{gg8(0!]_tDӤK'‘7exEHNՍhJ|Aĝ0BI,Yh r.{~9xuYnw oddQeg5]?k_;WR1?ҕv7*}!w⛾6@d$n8'#N6 \3|ƍrڛY{RCdyG@j.x%8\){hc75v?K~=! m.N>YJ͔=-n0a ERx9`--VV!(Q܃fKWXd>uZMtSXYLR'd!| &O$^:6.({atFbʰ<^?;oόfmcFޣ @@SD]]qRve/# O4(1{fi$#EՔȀ({AK~K(Sի=a< Qvk !m,PxxVfx-$&Kׄ~Bf*DwZ ϳr+ԌK2@4nT5P4OU'Wa?`_Znyc9Jq)r^h\ʞwnz ɭLci9 9jrc4q̪[r,!uŰO5~oRu) $ vh©?&Q>=L-q JŲ +paY CNsr$t]ݮkFPWQ̑ yAskbibȵ s-LI3AwZ<וyN+i~~)˖ʲZ_uw2v#(W5m}X ۤrF_ 7;}5|i2; Eќ)iyiZ+ZЁ:M-o$fܙA{Zg5MoqM Vp-Aera2D(|J[\2n*3q;t[p٘dyKԳzOJsqf)/r@~=Z5R1Β&: rm4va5]f҉tlH5;֤?c"UG#R%vMcIyEft 0bv|;̇z7󁫦u!P6= ,| [ie=m}TS3Z&^Pup۞Gh>ڞCtHh#9Lpə }VTI?)_a%Ye W7Ne|\sD'rZ$1g**˲/]쮗`/D81ԮɮpDV^]$Юj@sl 񻞐h4ɉfe33IvwoԙMtGIQf>;{4[A'ބXfC`*9!Fqd]4XKLlp9t55|rZ hE/WBT,F a߲Ff k.Po(k20_ gzΐ#H!OCejn&3R,Y< pܔjS c@.l. Sw&,uLM0{[/+y8e}?eI ˽:`͗cc |4{joZގ%)70ONi 8p` {,%ps370N NЍ K:!1v܅x+<@Y̋nj.rͼ?Lu:mM'}E!%j(:*8o6%Y:˗YQ$Sh:Թ"eWevȌ%F T6˲6'2kмeLLi˶rDq'!Bn˘tTծ࿵ɤ*QPCOTkD-8m&$E D$ iLHݜ1DRn/pC~8h>_d/ۤ|5YBLw`#'^Mv Jե30Rˢ9$Cy6uHw:jJp2z,4ꑂ\ y3$ :0r^x7\g7TP@5YWAr!һ@zN# "(4B&G׾+*5rvA/qZ5JZCmv]!%q (&Pz?e..gkbQu,~ar;$<߻ˏjʫ?}=h鲀_@<@Ig=L)1u+y+1̶҃S>ܺN$CvgD1~D>8p9E Z (yy "uxaI;P57C[wV\~odS{Oq#qG0uh8nATAj!@$ 6zD'-dCj־LM,TnpźCd13J_8Ozl7j.!Q`R/l> if&߄th1׷23$sCRu`qtK?w1~Js ^AvUQU,+}w0sG R_3q*"F)<5UsOܘ+>Vp /5i,(?eXx/n>aNK< P$(7{]/]br )5lő+=HC9hV%tBҀUp[[kߖH{6/v:2<ףL.H\n<;鳞"QM@1ζ`8?t,Zm`gtIaZ'lLTDPU;#qL.hp8.XpĉwTe9"7.SGsb5<ՊO8d d%V Z2!C x({O>s!l.[U󠪶avh4(sdl 񶶗<ہ|gtil7]'r;j-UPuxwN-@ (z5D 4F/RL\KL.ؔu,G5So<#"v=≤𸺒U!Xoob>Iȿκ~|T_1)3k/r A/ML2 S'FAXJKT£ m"*BL/w6z0hXj}\Avnv3Tpl65#X_o /H`IKᇠ!0%hV,zUsDP0yV~ pH|*b4< +be̫kKG`VRrs|G0ŠN@1]h1NvvTDO; Sk%L)!}gk?2 K/W\H7Uԏa_\P g )+`jmUeW^)&KUĄ?hhX5*>fMHW`ZpWM"8nD>s@Y.X(E=1RkOi?M"L^MWu?t 2 YXuU8*eO}'U{G %)* P"}_ -je6FlϪrteL!wcsLC@o|[ `bPW4WC7YBkbId dlC ^HlՉxm#?R1}c1ZU+dD]w]'[a_k\fCͼ^0k-j WSJՈpst(-oTB ?6-텹`Rchq=AsУZJ'6&EI$K(әܟQQ=sAĴA\cRO$;_zp1nr S4ų qF 'qɿ&{I>ӎ:ZxbK,B09GbZAFigK85M E6z+LOO/Emf-@8evF2dZKO"f=n/"BQH-)}h}mAC?qYNxB)XH-!=U/{êe٥takwe!Bcݧ8ua}ASͼO9A-Լ/I(l ^ J zQErհBH(N9 zMΓZxo7VkZj[؝zt)](yj5G>jv%*}~y'QZQSRxQy#1B|Fo8 g4`e\r8j S#bA[*@]sxW6(8&<.8~f/!f;\P]JZ[9ĉl&%0!燽$B12Ԙ>aBZ;}#ZE7lYo.UY|ReD#J[]zT,pQ.[L|T9Isa^\u 4sSH)*wsr+Nz?0.,M;v/~=Otg0K^~ۋ(U O0z]<ji/x̼g/qrmd c|Ԍ|T [b kpny<_bz HIK) ׻P`v?,-"6~=]./ٳy{G+#qkD%xҵ* jWqQC/kR6\E :&_ ).U NJzjOM_ OC5w5φO}\u92 VB}PGXhɡW^ձdl֊OKiHѬ8JpDqGߛ^@"HXF{j\WfYmq`>%T  QUh~,گ\XHodl#qS3}N,(^C'H@ӿ)]t +DDk!C nw1z."ߣ!L9].X GB;N1yNx1{&;Yrޖm׹k>ߑؙV7OPvӐ1̺(dc s)9(i?җ{RqʰHLՎ)2}IiyCeeh-bpZu5CSoq${3D JLjpM} x V 6;gܼ3fz k1z;O'AgqP,2OI/ܭ@H=6 Gg[%Q z,ZFD&.F\W.^ ( h<% ]u?6auI2E*nB ͍Ph,Ob&린)`M䣴ju/M>jF 7+2$HaDO印2|[E]WemnlP=['|޸X"&td"dnK5CVS .r2c[Uw#E*6!~ƠFJc6ɰ(z+g.=[im:|[(qrf[@F|VГUyϨRMR8ys7IY^ZdƉ:d0zli fsM2(} 8TMoDk[Cq]Hk ]6YmaSy]O] GT[n`YTKblR7?9_t ll}ǥnt!035B>ǿr62_U-Sԋ[rZc{^8!Lrаa1EO2Ab<0<"y_?5 Wh(*w[,gEtTyXٟ1e[f7We W\vai :(Z78~o?!5t(Ùc2DC i{|wGkVX`)sxL3'%0T}+$+JgIS",?i,_ORC/Ovd(BHΑڙ;p*p|r^cHλĢ9kϝ2ABNHx>%tE͡g.(C/{C$X3#Id"_%ߓ%UXC'vܹP!>.P̄wdPIXc6%sd'%(InW+t1]=٣iPH0;.yr.?m-8y,vPY㑁Qb 4'/eL`{B@֭HH[GݒRf_&䲷Ú BKe')K=QFJEKi7;R&<2[rmk~ -h Q? [O4s2J޶nd3f?Dh2z~5<ya'?bM;s0F5FHm"(}ԏ=\4b?3n큈 JwrK?9Ooh3PJPe[D}:̊g63 ʥdvNRz^g6qe}fU2gƤoj!ϐH|YK c#(zAn0%<,{%HV͟&Hr {4ծMC: ^b(q.v xoBWBoW.3<eˡEfـy-Ax`y~ } ;_p : IнkpxAw3 |!:j6{096shS <@%f'S]tYT v  C<d* J!IC/6yC.S:"8&_>a0i̾ͦ CYX-C]|W % Эa64 \,1[UUY h*k;@W@y+V~+ԅ\l}7f[ƺ }K߉{E$f#&lMPmwWWcL^?N- ,ew "]l,AeXg`fct/ 2gm2UY.biu¹"% fgĦ2pA龍QQ_:ߪQLȎNu9I)ݜVN+͏5N^l#fcxbr!+JQV%c !⁧Uu.BkA,xRVQ9ң2 I*QqsI ъ'`[i_[sYUw t@sP5QZ^0i@Vf!VPYА D)y#Va:j\*ԩ&ބlE0PeۜQC:ZkWx&[KY@e|T7aHwvn>&7A2[mq$nB8]yA$ޏt.dk<1aEߓuVhL&X(wx'qc*^KL0r;TB9tFSmi1uLw"&aG%X-!lb:V< #NYw(u[f4eWRM{uP^)h}A4huc,)"'q,&7JPr[TnG X5^W%ηLvBy0TFF300L6B l s`\ Jz7ʀH$1d#*m|VSJn& CC$Hjn&v &JԬ.mGgo#RŻ盨,,, =i"LB?)l\..\.Dh]{?aTջ| ޚu* kOd}M<;ڂe=N!Z1x-z/bjADRPfr5:aT\IW,zv&M+4/bdzӿpeSJh8Ll#ѭÍ=%~rU뽚z?IV違K']i qe ziFݚ;6Ă{ë5) h ($Igt@ sP_i˗9h lB'8zSɲ 7?"}48fvW9KڑXA9T K_|P!hoeT=+Ql aD(C8)6k=;OIra MjpyF \3 rV3iƍ=\$v}{9nNqOl>=oHQ|3{Ts~&T}}R7y<3Ph4lf=h)|"HȚ$&7sM!!ϋ02*NP*x{" `?Tb^h{ee&ڃHg'E\'wV@(!MLvd-c _t!:K;*!b$"}TrU78k|q ZdUH__> vam}'ڎcS7o"(1E}OdJ[:+ h,&kZ>dHoK1ʊ/,.HMP;iPTq2f/uk8MŽv#\*)}h*oDP zfh\B']TB2 zd|!ܟE ͕ݍ$:gH.iY(,XkI )-{B4ƨG B_mKض%#%1kh뵾\8[7bꦪmdK+y2D _(sӻY9 ͩ& Ѽ^ +N3j%M\R[_S8țS9kt1h9 P+",|>IE&mFJ$rg^Ĵnjvv)r2=\7gE_*;,3Fe- C2,oجZB"\(TOZ9"KkF' g$&rRNO:ʰAn,%_۪,}ȱν)V2zPJ?p6x1~ɐϓUgPjJ1B#-~xȟ&y$dyD E!9+Qp-^HqL. hxB#eAͶFu{`4O7\as=H#t1A^8Jː(jmՄ݅BM8OSܐ͆Kx6Ym9a k;oIh]9jfuMӽf/ۧLqfW+/+@ꅁJNY@(~P eA#.`/Jx_e99"Y5 oZØǰBnj{i`ۇQYuogcND);Ld]hCɣB@4_Eye5{Yn>s["}cȿ0ڻw7o,@.zۓ3J32m+<6  "N—9BwYd*:D20;.1?G Z)f[IgWdЈ, 6RUz hd'_ҙuoP_bE\{O /#7_*&5EIHUeJ/]Ĩ|\>R>T;b Uy$4ɃGmj^ 3%aKaILcrv8 Bp.tbrʓjMdqNFWx` [bvf}'CAu`߹m}vXAgA#R= E2b~4>f5tUPBp젙T VDaM`зjꄒVT2Js7񒿉ش1 U_LxA)l&Aᛚ-m0Wض "\5x(n8NsB\Su!R<'S:a&m 4a-|j;:`VB2@$\ U5(Nl;=mz/}l(A s{;+@K<=B.;N\EK)5)eWg(I_VG0=ʹ́! Ngk_u#I3[LYռsk+vNDJQ{xX?J%.v1B8TxUZ'bvUnZ>li9)Ə*% HN /!O<2l+r, Xॱ5,}I$˓ɯ<:τSm퓟.?L߼_9=@pEE"! _ 48ΝY9Gv+\A>[RW0R@$+=YU!eȯX-\P R,](X1L~qy9SViJ7TW?DI"1Կʽ_$ͰQ 8i|ؑ5k0Qa)QȣҼiU ;op0asmE\UXc8S#\UeM:ͭ>A Mf `x҈y`.`ClWSbw7^1]S)1~HuN2[TՉg߇f3Sp%!O}[֠vzx@ڎ}OÛ1x iVk˟TK]FS/e"›y?qu]}G)#+ͫ-;j@wmTX볤oF~z.{l)ZtVa c+PvU [srйZU'<$uh;AS93Gpt 4[]d\iM Ef3,9RiuE Å2ߠM?ym #ΆNyӄoѣ: Tjgz>C+2\Aer.\Io߲Q1#e&[:af[)o(j(CȺ? n_un]&rٯ:-C"0YB],r|=)k"@Kmdo]#>,,ύ"׌ f͜v IH+5KK#x.wP*N[9qBeά43po4=8EN9Ҋ{* /LwZ5$!9eZokWD` ӰJS,C**1ye.۰:VK;[oz=#~ixOX~mirB,&ǁJl'u!sk|}tKh^ i8=]U;AߺAywͽ3}޴WU=`)'AhNh_<ͤKU}1R-%&Zv286rM/MNja`|G:Iڢ̥q8X :^643qE~t%yҬ$"ʃc4OzĮSwX(Lym"1_FԴDyLݠ0G4? x O{DK\~~)?[|RJm*rC ;DL7-#@tʱ)y+fg ̃XŠ%u Rs!5?gt־i`/Z瓍"Q ;;{3W&[O y5{{i2ܟ5a\ (t㞼Sɶ$Q Y'fuнɛyQZSԟ+kn qM}:U)'+ G;rT-E1(TJ8P0W w.jOCK8Ӻy* 9^4-%f^ a3P^ ΏmN{6E%QΈw[*;x6 ˿T/ᝰf9 D>a= )!'ȱ&Q)IORqgm [mkqQ`-)4~GphpI/-Iw&R] @'K+4^ˠjE.29JN3%?;fL{.잰BG|,ȿȔ5]vN#5i4,1f4ij>ӵ) S.gݨ@Ld_y[W عļA/E 2paOcm:W N~)P~fߩ M?H'304l2Ѫk+= C0Ub\?PJKt-5u)`W1!f dpiq%pio,7I2YFDXŒX_}6+9xkZ%I{P]gń 3Hrcȵ:ѩ?*6ݱ`}u︭5!ȡ@VE%W()}R)pCk"gy$_n'.rϠ׳q'[R9%•r^~\`8zD;a,!ϸ.dJW +C@בSOAQgPR2;=;w3B" ?ѱWP x(YR0Y(M pnm֐e=򵦳r p~v$bwd:~J#tYc]lbF&x"2nzn~CV`LѼh6 H}@W7R0GuRN5}gQl9Xuf2rX> r!5D+X2gb`b~]_#TׂsL_ǝ32ۙt5>^`?OGKU}=cpNzt1Na6fC/z i;60 ;i2[ 1O+J݃qVQ;遱DmCrڦ-_],qJ r`:#FD w=QkhުfiW=!jFԳVN:Zc('ԕvGxQ@suYдke}9hzne4Jo zzoT{C/Ξ~aF1bQ#\fXb!m/‰giؓO gev7Y.3f6"?dҩRQ7+OEǸ2Y'Y/BǒWr)3ˡU. y5@.b;˕z\{G^:5P2[u /&Z7dN:ңɵh LLdi$ BZ:uNilMZXhV$v5t 6ڇ~ & N~8NAL7ɣf%A!E:_ʇ1Yx -|C{D 8TH 'O[zzyɟ+P'wȔI Mq5i75V' L'0|$_r_WhDΑW lE@20]8ZP!B}K2y鋊gCVҏy*T|='v Nehl~Mfg7)a+VH|8yu׏>?v`aT;I5VeelFP@k!@ٷ $:e`tʴx7cQf YZ