samba-winbind-4.15.13+git.710.7032820fcd-150400.3.34.2 >  A eup9| mƚЫ:wh,a١`cA( (+BzsΩ%nf/ܯk\2f/Kmcu+COAX|ٸPg,>4tH˗Q$!.UH|޳T]o#~, rAE$[Z ZCMTb!U34ezQ5"5;.n|2Tbt>Z(KY{.0Wh6e6338d6fdb2c2b2666a80c67d1f73de821a8cd7a6a2cc20b371a600868a5e3dfaacf909feecbcb369492e9b8e530396aadd1269~eup9|&z'd.OU32GN@Y^S<[ScNP ۓ0:a "=EG9t zQ!w1;wx{[#n2BJ;]o%3Y ("7N֪+byI qL|`.PQ-*}1kΦ< `ޣ,Qc`Ed:Pܬa 3¡90dLPe&YQw>pLv?vd+ 9 Q .4:,/\ ~    T8|D8(9899>(:P3=i>i?i@iBiFiGiHj$IjhXj|YjZk[k \k(]kl^l^bmcn5dnenfnlnunvo wrHxryrzvv(v,vYvxvvvCsamba-winbind4.15.13+git.710.7032820fcd150400.3.34.2Winbind Daemon and ToolThis is the winbind-daemon and the wbinfo-tool.es390zl34|SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxs390x# we need this group for squid (ntlmauth) # read access to /var/lib/samba/winbindd_privileged getent group winbind >/dev/null || groupadd -r winbind if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : for service in winbind.service ; do sysv_service=${service%.*} if [ ! -e /usr/lib/systemd/system/$service ] && [ ! -e /etc/init.d/$sysv_service ]; then mkdir -p /run/systemd/rpm/needs-preset touch /run/systemd/rpm/needs-preset/$service elif [ -e /etc/init.d/$sysv_service ] && [ ! -e /var/lib/systemd/migrated/$sysv_service ]; then /usr/sbin/systemd-sysv-convert --save $sysv_service || : mkdir -p /run/systemd/rpm/needs-sysv-convert touch /run/systemd/rpm/needs-sysv-convert/$service fi done fi/sbin/ldconfig if test ${1:-0} -eq 1; then ln -fs /etc/sysconfig/network/scripts/samba-winbindd /etc/sysconfig/network/if-down.d/55-samba-winbindd ln -fs /etc/sysconfig/network/scripts/samba-winbindd /etc/sysconfig/network/if-up.d/55-samba-winbindd else for if_case in if-down.d if-up.d; do test -h /etc/sysconfig/network/${if_case}/samba-winbindd || \ continue rm -f /etc/sysconfig/network/${if_case}/samba-winbindd ln -fs /etc/sysconfig/network/scripts/samba-winbindd /etc/sysconfig/network/${if_case}/55-samba-winbindd done fi if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : if [ "$YAST_IS_RUNNING" != "instsys" ]; then /usr/bin/systemctl daemon-reload || : fi for service in winbind.service ; do sysv_service=${service%.*} if [ -e /run/systemd/rpm/needs-preset/$service ]; then /usr/bin/systemctl preset $service || : rm "/run/systemd/rpm/needs-preset/$service" || : elif [ -e /run/systemd/rpm/needs-sysv-convert/$service ]; then /usr/sbin/systemd-sysv-convert --apply $sysv_service || : rm "/run/systemd/rpm/needs-sysv-convert/$service" || : touch /var/lib/systemd/migrated/$sysv_service || : fi done fi [ -z "${TRANSACTIONAL_UPDATE}" -a -x /usr/bin/systemd-tmpfiles ] && /usr/bin/systemd-tmpfiles --create samba.conf || : PNAME=samba SUBPNAME=-winbind SYSC_TEMPLATE=/usr/share/fillup-templates/sysconfig.$PNAME$SUBPNAME # If template not in new /usr/share/fillup-templates, fallback to old TEMPLATE_DIR if [ ! -f $SYSC_TEMPLATE ] ; then TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME fi SD_NAME="" if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME ..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ "$FIRST_ARG" -eq 0 -a -x /usr/bin/systemctl ]; then # Package removal, not upgrade /usr/bin/systemctl --no-reload disable winbind.service || : ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_STOP_ON_REMOVAL" && . /etc/sysconfig/services test "$DISABLE_STOP_ON_REMOVAL" = yes -o \ "$DISABLE_STOP_ON_REMOVAL" = 1 && exit 0 /usr/bin/systemctl stop winbind.service ) || : fi/sbin/ldconfig if [ $1 -eq 0 ]; then /usr/sbin/pam-config --delete --winbind if [ -x /usr/sbin/nscd ]; then /usr/sbin/nscd -i passwd /usr/sbin/nscd -i group fi fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ $1 -eq 0 ]; then # Package removal for service in winbind.service ; do sysv_service="${service%.*}" rm -f "/var/lib/systemd/migrated/$sysv_service" || : done fi if [ -x /usr/bin/systemctl ]; then /usr/bin/systemctl daemon-reload || : fi if [ "$FIRST_ARG" -ge 1 ]; then # Package upgrade, not uninstall if [ -x /usr/bin/systemctl ]; then ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_RESTART_ON_UPDATE" && . /etc/sysconfig/services test "$DISABLE_RESTART_ON_UPDATE" = yes -o \ "$DISABLE_RESTART_ON_UPDATE" = 1 && exit 0 /usr/bin/systemctl try-restart winbind.service ) || : fi fi<rHX%"0F^큤큤AAe9e9e9e9e9eTeTee8e`e8eeee8eAeAdbd95eb7e0d1e8c973d39fb53be9be46276b21bcacd8b0ae1adeeb63651f6fbea676af835bac5e037fd6f6d9950ea49ff3f39bc693d479069190927c1c53083993a1caa0988f1da58a965d7a954f36d791af7b63f8f4d458a49b7b48dedc7909b3d847fc09fae65501eb021551b5ad406cdd42687b4e2f2be2b8ffdff83f598871bdb786cc63c09ba44d2fd4352d07173ccd3c52e60676d10b1471c454a46b9448c787a47c3127f9c5fdde2848eeac71a06e22cbf997c132d74ada549c086e0df97cc497099ab8fbbaf480b1fe02bedf9f0d49137c4498a58b9a9a533996d5629a16eb3e6b8e2bf0b1ee56f8a98e8ed307633badc5f3c02d8a82a4293ea4743985dae7fb57fe9a00e79b9f73ac89a7fd631474538195bd1b3c75b68cdfa1dc6f343b183db88b9e41ef39ecb19fd7b3660b805e4eb6d21b10b25fb0ea5bb2396c6d061d76762ed991887fcd167d3bcbad738c7ee86380baf25f953d5ff7bfdc5fc6b4b0325dd3211474ac785379683cc4e7f17e211327fb9d536c1ff9138de03eservice@@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootwinbindsamba-4.15.13+git.710.7032820fcd-150400.3.34.2.src.rpmconfig(samba-winbind)samba-client:/usr/sbin/winbinddsamba-winbindsamba-winbind(s390-64)@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/bash/bin/sh/bin/sh/bin/sh/bin/sh/sbin/ldconfig/sbin/ldconfig/usr/sbin/groupaddconfig(samba-winbind)coreutilslibMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.1)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libidmap-samba4.so()(64bit)libidmap-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libnss-info-samba4.so()(64bit)libnss-info-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.14)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.21)(64bit)libtevent.so.0(TEVENT_0.9.36)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libwinbind-client-samba4.so()(64bit)libwinbind-client-samba4.so(SAMBA_4.15.13_GIT.710.7032820FCD150400.3.34.2_SUSE_OS15.0_S390X)(64bit)pam-configrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-clientsamba-winbind-libs4.15.13+git.710.7032820fcd-150400.3.34.23.0.4-14.6.0-14.0-15.2-14.15.13+git.710.7032820fcd4.15.13+git.710.7032820fcd4.14.3e[J@e@d.@d-@d@dJc@cS@ccR@cctc5cM@b@b@b@ba@bascabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Add "net offlinejoin composeodj" command; (bsc#1214076);- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171).- CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). - CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). - CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485).- Prevent use after free of messaging_ctdb_fde_ev structs; (bso#15293); (bsc#1207416).- CVE-2022-38023 Additional patches for the PDC role's netlogon server; (bso#15240); (bsc#1206504);- CVE-2021-20251: samba: Bad password count not incremented atomically; (bso#14611); (bsc#1206546).- Update to 4.15.13 * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); (bsc#1205385); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); (bsc#1205386); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); (bsc#1206504); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/bin/sh/bin/sh/bin/shsamba-gplv3-winbinds390zl34 1703083733 4.15.13+git.710.7032820fcd-150400.3.34.24.15.13+git.710.7032820fcd-150400.3.34.24.15.13+git.710.7032820fcd-150400.3.34.24.15.13+git.710.7032820fcd samba-winbindpam_winbind.conf55-samba-winbindd55-samba-winbinddsamba-winbinddntlm_authwbinfowinbind.servicercwinbindwinbinddsysconfig.samba-winbindntlm_auth.1.gzwbinfo.1.gzwinbindd.8.gzwinbind.xmlkrb5rcachewinbindd_privileged/etc/logrotate.d//etc/security//etc/sysconfig/network/if-down.d//etc/sysconfig/network/if-up.d//etc/sysconfig/network/scripts//usr/bin//usr/lib/systemd/system//usr/sbin//usr/share/fillup-templates//usr/share/man/man1//usr/share/man/man8//usr/share/omc/svcinfo.d//var/cache//var/lib/samba/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:31907/SUSE_SLE-15-SP4_Update/625f171e9af34d04e78337ab8ddad37d-samba.SUSE_SLE-15-SP4_Updatecpioxz5s390x-suse-linux ASCII textemptyBourne-Again shell script, ASCII text executableELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, BuildID[sha1]=5b11e3b805d59e1ac9a3dee6220eb4db50aa89b4, for GNU/Linux 3.2.0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, BuildID[sha1]=f4066dd08dc13d64ff6884d29e46fa51c8223b5d, for GNU/Linux 3.2.0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, BuildID[sha1]=0e1dd131528c0eff52211536156c81b5bfa688ec, for GNU/Linux 3.2.0, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)XML 1.0 document, ASCII textdirectory4O3RRsRR2R6R[RWRR_RRRiRRoRRuRaRcR9R]R!R4R}RRRRRmRrR R3R8RZRnRhR`RtRRlRR\RbRR^RR1RR|R5RRVRRR2R!R[RWRYR_RmRR}RRRRRRR RlRRRZR1R^R|RVRXRRRqRURyRIRWRR$RCR_RYR{RER RR[RR&R]R7R6RGRRRcRRSRR4R.R2R!RAR?RaReRiRRRRRRRR}R*RKR;R(RwR,R=RoR9RRRRRRRsRkRQRPROR0RuRMR RgRmRRNR RR#R'RRfRTRZRhRHR RrR R>R`RxRFR+R-RR:R)RlRbRRRJRBR@RzRjRRR^R%RdR/R\RtRLRRDRR8R3R1RnRRpRvR|R_ m4>\ssGIp(,RMذtVʛ2,d.y^5Q1_bL_ؾe6x#F_GYpoWEv@h- l*gZ;T2&Eŧ#5 #(!EM2nxNvsp ^԰b+G6o';#_r7b/v9(a.s)gD8Cde2THc=v6TZ׉וH].wh ~EFb&. 4n:ąAmm`* !N; 5lXFO 8NQmI?X!/HOySz^NPHR b ZMUp,„"o`[N =_ /{әJ#~)IQMo52]ДЃa X̓ٯc3\NA-e}∎z]5]%||$ 2U -R;C6;m;8Q ?2e0x+hAKzCPFɂrP}Bh`W!d:)ah/`9t 7#K8jZ*6I@ t+hGg#[6`_.7W<۾7G*:ȋcɒReߕ)bMϩܪ_v:S1Dۦ[REfHQF9JVIPU?:kZ\; t>ʶ+;}w(F1tHv.#?gu7.5jp8B$;CC(cs')h^},a<DD2*XxaP.r4K"&\&@memih>VicND& ޾R>8LM%xHo`)~jGX Vijh*-|EB~NvDBtvH@&wk]}7&ɘJĘgg`Yϗi=Mʟ&VtrЁD{ҵX}u8 c^ml X\xDlK>]`(@mͤYe,;5˼6#Q*s[)S/OsbA_-«\g u (PUÎ>xZkFEn0J/^z@)j85d10|: ]жLG[+N[Ij1S?Wjk+ fi܈_4RooGx:842#2%բm*)+Gh(3 VқhrhbTcp%Ş c#̍r䘝iA^ѿ،x9vr=QN3bd;IzS;^Dl<4E<'<&¶{t?U̞SyeBR0vvsY*h'Sl! lD!KK)q{MO`K6B%WoDm"D^pԮ[cAw *JTYh`|l鲞G38 a1kM8} Do-j^eP! ,C_ q 8սCuQ~н({v-E>Mܫ} (V녑C1<7f+Ffʽo]Pʦ̓^:C 9B:>Nz3CP2l) όm*.EfXƜB+Tg %׉tL+Jr[Ć+J_ ޲Z{y&)|[iU $ `8;sbhk^Ӆic]| & %&#+SRJd{.D-f|kL\1 } 4KyL-<(G]M,saޯG(e]-wHk4#RCm%WE;-!a R]Mr b>8vccP\x/-VwҜWl >:ة)=fHfXsG4d$8+9) gJ5'f)o >q&9d2#j`|ہj,RjU ;I1 " (16;LEvK]{1U Z yOU#Wmj\)N ^Իh5Bӛxg#NOs{|:sڿ^zϤ~v5Bے"eۍN-L]:j7:?5+La6(E!) Er nЅdV[Ӵ#!tWYnE`wv-9K;r&zhK<%udR24l6+΋b3xClݚܙ6uM/y./5@3|ק@%xP6(@AxP 5o$V_`[J݃6Kkpy8DCf|)%@L388/!w5Y|vR-n/Ƹ ϝd~̰ {)Cpu:񏬈@DP;C_qn92Îef\4Kհ )VvBo P$AjeYnk} **?$Z/Q=02x_qF+~64*[LTHD>aԖ$ů\ ,{|lc`āuCP g a{ )3Y|݇Q4u?7Eݹz,l׏$N AR23TC=8y}i SL T*Z0hK}?Bk(m{Ia7WR57azEiOƪ4u{{=fu"=^t#IG/Ш!J0}A :;9!hKԱ>D3Fx+< 80I E3-/)`%Fp93-U"h#h /N)5!_dϏAw|蜊K3y"ݜov=9ъ8 Zne6*)g3 HVkV,0!wx~b:i/@Pf CCK1ǹ g=)wׯ=J@kĔwYBpGĦQhB}p`}Yj046A6 g (Ef]3YW)@ʹxADؕ΋S0TWa„awl:mv+] L}^vQNzs`ڠDȩMo+Ϸ-O ;Cy,hNanNHEzJa/^ 9J>EZG1m]1$}P8/݌gp7*Όk*1aL,NS-ο;@[Clkx nVV~Jep|ѴP5w)@j0d3\lwCi\3GkrI9iM }.sFu&D_[YQJK'8ԍT'oBZń l跍ُR8.=I$L?%FHuZPԆE[p՗ ANd&|Z@fDW4 btf?4+M\Si0 -J﬚kt5 ;El#eBb6 ^*4|=^4z1L mge"" g?,?4#xO4@عcWSF)4kH8Mo2#î<?G05_x| NV+OJr~Um?4@T2.zݮ) /%PDǛyn_jТT/ 7OQ\~P`omZ;M'P~\V̡3:(JH:[`V7!cFInՔK~>qjlqU?`*A’rySpb4`BZZ(>NһOb{u*Pw9s͒5hY}":j5bl)4RKS\!s@er d/^Tw&EEG!!!a,&VqJ.]F_E:c]Ҏl. 4(7|ah8l§쐘RB:-h5@>4ht\ebM xҡ1;+-tޢ"<5a;;C%/Uv[e[h均q4= mb=NgI{ڸeD= 9KdILнClg`;l2ީj$[}Ui_=sehJ=uŚ Ը vȘZzŘ}큁ho;<3Bĉo*mm$u>8NG$kދ{B7ؐ2 $2k*p 5Lt]?sBMzrJ5z6DB/%^/]Nx 4~BfbN'LrI@&icXT ͥ){ȯ XN|_5_blS6Q=z QGNE]@۽ @+Y ks :v]큙&X,,DP).7sXrbXex#?dN>Τ$EG -ܴ\6ӁnN. |y?ح΋7OZ+H@56T _w}DDΠ{5nZ !W+,S@2 9k]]=[e0UK. f [[Vy))dZٽ!*z`|M^%͊zS9}V>5nHcl]G+I қ :-k_KZo%Do& Xk%Zo}85fH\p`jaL7U8Si) o~)$BrhCQiQؤJpUÐkį>gW鹊>^eRz̗9?KƦ]wW7Fz6`ayNRjV1JI^\;+ N/-Ao:6=^SPn=u )H});[ l*j#w7混l R: pt٥&tCT0Oma`3[4N jI r }/U/ae٩)9'~3IeG]CJ7+Hcܪy hLXUEu 2 d ngG'Nh4mQfGG. V7nϺ()8"[^Nw}~hG›P~ׇ|Vyw{z37ToяwHJ_\]@@Z|?Y,p$\k:~u J RoJxdf||&D1ݡ+ԅ54˦ngªno'O\"}8-P90`cb9H)R/v{5Ui˔t Qز86mOJx2x5|&n@ICpɂwө\}AA`ޠY/3`Q#7ljȺB4 2d, 7Q?TsBn C[>zuwCq)>m(* +N Pȍ).+h/ao/Y]nA_֎U@<:֭߮4q]_e+N |6USh%[W+b.H<`8$P%R>* 0RR ÎQ@07C{"̝֙@mۖ:,^Uik)v \Pѣ셺cbV 2%i=_@ukdWaej& A BYf 3qu%&ɨS|ƍu•ִ?Po+wQQ-%Cmm)B mD mULKq=%43.Zq`!|vnϣ*iTgO2&☙vВCW4˻PˋdT}sٝyԺ!6[U%=@_B3j "o&B,KƔ!27%b"RjJ:Xǀ*vS>wms>@"kg tQiܤu8A`7{4ؾg?@kRԫ`7yt4Ys{m  0 K`ra5-п Q lcڜZk< V`m73il`{%IUXw|isU$!o4vX;fD'I px壓?:# N@J7v!{SQa'81-&C˗ZC; WTSTy,srb-DTnY2tFMy3iaUM`%㮘n"ŌIEeBzh M@1.^l7kkI!hZ  Op"B,!,>=ܫ#>H{ZpoS?`T =R5@S|&q\|?MUre:IeKxoKDin!6 \y}g|֫ˎa ́*龖 yȁyUz7k]*ݣ$,2Yo )MV'$޸Ee_b$*3x\L_M.8U~;f*'Q62.ύ^ dm\_`oɆ.y`M}VAzli*H^Tvjį3S7[O")YAGdASMW@iz™+Q2BX6ed uRc^Uw%rF -ȶS0ņ[Vz=u-g? vS0>]?qF¦4Hb: %.,M\(<ǻ &jn 'Ht70y8LEg3'~] 37)QWAAB#hm=f2@>o$|9P1V"J3<22_̊Auggb碝<8PCca.Lˌb HMJJ% M@lLō`mf -͛099+TM=-h/=b7nPEx+?A׆Q惴s] +e:8Ͻ˾JQǂQz_̴PIϢw ϼyBHKˁNg\*}ߩm $]ε`..Dnx ^o9yY@W͐j|Jk8J (N]:D {Ix0šk>x4Y0(18D[6XImmIA2m#bc`R`d}AR>Oy3?^ݸ/9- /QNB&(mKyu 9bb<;mQLRpQf]זּJSe񽨴,9Roubs;Šy3>`xRLW;.`,^9<݇gpۮOBeUQx|jU7I}9B'v6JFij6eoGIډEԍgbZIQ^l>)ӪJ&' (ilFj,R=-6:D)5qwSK`5@򗈡ikdD)8X~{ո1X^- ami,81zcy}Ab \(Eaw]ݵbE[ l!d1n&6Ԝ/h|_A1Pi>8>g ;)T:h룴 QWh7_% ؼ 'Y =˖\JEYOBf Ie>-kJ}_uYB&5YoQ#Ui}?)7 }-ACrSZW&2?Crzaj=$ɢJ(eo!)U&.1*)F9} N~:|L>O%HYhɜ/q[[#l7G?؝X'u0}&"[}],;.ůp60QFi"C!ag4|[O{,1eT>nv\+7gyKccԒe+aYE"KܼL:G+qR a'6E~vRֱD4SuL96+W'5sg.XPy8ygh*~k2mw]zBYĭpFo-ݕЍ!?+O#eo2"hqF~sgY/##<;ȝ= y+jv2SnK^,j>yQ ehmi[dfdW/a|,}nԢJ5&qn\h .$_z6T?nY=\k`LɡʚXGIJ "R)ͅ6Ͳc;wA Wb}?\FVdt;}Grk d<8"L1_LEzj0Nrߡ>Qb $ q?4^ٛ@Ы2'IZOBB8svV IA9ݡ01ph!j$ϥ [A?N$f!a"[XӸD<+;B>Fej#`>}~fhhBtA=f2YlV' J@C]({`+]](£PLHq ]N`|AouK7D?3LL_x#h8zZgN`>%%@YgfRH#֘6WӅ1m,Fh܊- p D,@ 4d6[͐5 p3,FP[{V?gx:{4N4c%3e%"QR ^:2!M^V7؏]{bqx&3PVw&I7UǗka^0C sr8/i/, ͇[vz:W*b.Y'Kw},2j̻i<8k]9zV¼d5ovnp@M>M2-o}ҳx[>_sŧA_:"mge.alyᗢ}"ivÇ5L[l8{f^g660=g\fo4#TCSuZ_Mr76D^#뇯ݑj2k1"OI<˪L5[u"GJ rFn Hpx'MTZ{#>W${"w5oqыY8t3~3+d„R?Wʥ_ݐK!(Tf*Q AI#@'hw,iں;V6V>63;"m;Nϥ n.-2^C"dՀh "nTWZ+:.TQ?KPVwq =m_@-!6A՛uB9:`mBTہ}Hur0T ,M7q~N d|p~¾!!*WFtaJ09w? eK1'kӗM8o6bYԸ/"EI]ہnfnJ/V{2:]C>N&/p_TƁɄ2ȫ..Q6rܼlaD/;Ia'`<_Yf2/$)jE1 ?:ZK`%0?;i縯lYZ"ͅ ]0"9J֥m䊣zlytoH;i:,*07yaAmiLtna FO2"1bj~xrSi rT *`76Vʔ>&VTj1Ȍʽ@4F:|7N}'(l ].D>\璈_}SF@H,]w{"z۶5,)Pk|)-7ӟaݺLz7G2V.V[? bfvDpMj#եv^~\maLuVqѶYyQ[;)=9(Kg~F= ETk+&(!ԃ |W۔ut]nXڹ RLlpM'`y,B@<7 Qxa`Xn;5/,+7ɶrHV鮾3qY&˧AsC9a!J&|Oqu a \חlĽ~qW)?6EIhǁéKW@M*;(8 cƗOYXtN[_\knOԩGШ13WNv2>vꈫ(3TWu>ֻιd֝T^]@~,8 UU :oYQY|eۜ܁'1p46ބ"o6Ί󂴫X04 cy%j ȹ h@EKLpÏO-Ɵ ْpsJ 4G$Fj)*O#p.X@Ta{V^=BR0U9qi1+%VB?EEڴQBXs 3r݃~U s9&6!qgDzE(ljSKatVŵͿ{;qլ(4wĸɕ٘zeeVQ1pp0"kѧ}4 kŽJ{) Q%R4I  iva@%.؄X9QÑhJ5e5-$Z֔EY#If| ¹JYӦKկ%H} 4/}"z4 O*ž1*[g{2=yv\d'p#,OeA \BP++Ohُ ܥΜo!P?'w5#> HQ][F)U빎`Y>B!u&{"64{\U&kn X%D0go- Z>nޫPj7¯8Ss`|S18O,1 1j<7?bYLdNm bjD͌MCؿf)W +Gol˩g-9DR>ɗvd{M~g=.S2z,b`rDz"*uGw]b^mz]ė^F+k#*ӤAV=< Ez|N1aS\w9<Α38AĪJp#cƨ z<zUĿxy1lj6쩙Dꉲd3Z쿥A6P1ZǤF5+{b\ WGlDEڸq޵@K;u=  Ӛh*Ŵ;å?DFnP[Ewt#!C2_ +nktAQRX]ݭ ZqVC>6U5L_md p'5Y3Xii.wj;iiq$hex%O[O eBM.h̼CY!Zؖ. 5ΉlF g*m5+<>ӇR7 YZP ~ep6*aFXnxaB'y@u N'?Pਓ?ӑ`]zR` I<%N?feKT( &omO 3}kU9[=\SY/>ۧ瓄a V:ʥPz,|NMpſ1`GDSb$aZ@n~ /dZ1mƚA0a*EnN*12zК}k6AiՅC PP^۴b!dgZϦѝD, gG)r#p80P&ga)Qb6{[ &{;AwxVVj+þMfh^t`G-Ҩ4eͪi(PWκ鞶 87,u.R3eJ~tfŔG"7s+@λ`E` tjs׀ǛvgV<nyQa\o1Wͻ/g|j#6ւ0:ݰdeu][8cdWv>itz,&_Ͻ;,yq zwظmǧ`w62J6 ̝\Aʼn4s%ݙZt[EQCMaPa=t7c3D|_wqo@R ӑx⒇sR7jap!Z'Se\%3YGkD ͵mPЕ2>-Qo**{`wmtYp>`0\_i|?bհ\n F_"w5'W0iֈFL)ۛ Mf&LAR)uDPpiote0<ףڐ>IS/"CT:pʒmqmI$ UdOk wpco 1@[g] d]WU'^R')Wm`EÉC^2YW+phd'gpM ~m@qd/]UݫHJ)9|r/+,hw-Q BL" *@ `B$ "n#e]BW++O~@0~7MO!dPbfkpeBnSww3R/FB2Oe.tP(@#yCj_i8O $qt"zBqG /*ʃyuW*8~!Mvo*S)h]noQ($y|!dA-G ah=;[ݭ%ôxIJ|5u=3-('*p?)PūjLF ,飒"?p*֎+ْ~3.:}U*:ʄAiZ5Md'8Zɶv[MQQbh4i ZljBiig b{ʠ<^75ꢥ*AȀ"YÕY`*$ogb"S!HIлRfMND\.DVfyȁMulhοF_53;;0l9+LȿbH¥!J)OBI ?X2* jhf;rY7gphWQđC= |?mʮq_l9 $]ni2 渰[^G,򟷰VJQTݣeKޏB X)F 9ih$',,-_ii;;ڷ&Z{/[qbDg=I:EesG2*Ēk><"67;U"Dpdpv3M)Q5:V|(SHP m7Ze8ZcnUF2e5eYJ B$=8[@&Sua0. h3{в!dw͇tt*/\ ץz9-"O)5aɣ=FNPS[<Z^U~PrT'.8ӝAO.֟9r ,V?):Y_Þa~V: w}B29|Q(&x8j,&_骺j@|*#/EQ@oօgKhfY:>@+cz^st;BK남ʝ>D rMk{,i VPw 3-4tA1 @c1U11m$Y-9MoG MsFJIkGۭ雙MW^9_f˹B&9XMw+ LP`UaR/DS}^t4߷Gp:U$U O{k:UQ٣I58!BB *߷HRzUàriO2:~nw 6~ T%].6z@܆x6*.':'%<%xr7NG|dCMʁ:oW]OZGGYA+|=.sr M<#ޖƴ|H8p_Uh{X{?i^J&_t9x>?DPAȚEv$j$%e +PlW tIuݼ K.^+ձ]I-l6 R]]w6NؑĴ.bRz5^aS48׾a|pg/spPU|.P5W-i"bA@T}y ->~ߙr ί-Iƈ^?ܿ<䴂C?GIZEX%*+? 9vI܅4P{BP*ȞU,ĔCVmCyar@kCţ5}w-)*"7 iwVMPe¢cXM *:&6mWf‹8qGذ)Mꁩlq Pca雄M`ܶ|$/T(V /N4z.T0|4F.vX In#K7`Z AS /r'g8缭Ac+!6׈ Ξ?倕oo2|;=SG8&c\J)iIoҋ-(':M7iV($iP`g$ElLc> e#liOJMNKKboLs;` I9· 2@Kqj~Y^d|`rѱtJr홫+_dE`ݬq=]~{=39XDbWlqqeigs{] SYNd|DaFF9ܗXԤ/B&:xF GFL1JpJR(^iI c\nl[$LQðܛE2D V=ij(ۢCyW9!,YC y`( )8+䋈Mꇂ:F=a%->08mD`}Ba#NXmqZ`9*݈v7ⲉa@vl؄FⳛsvD]{ɇϯDZoU4ban|oY#;Ur')׋- !tMq. ti zt+0T}Bp yd&Wצ\WCwuAJW/eLC& ՜9,$H{jo[^$=Ϧ'">mDh H:SaNV0 Q3)9x7q8-"_,NF$H 4 ro9MkΧDŽ+۠1ݾ9w3R/N*P0 *6іdt!bkjGew]UoK_OJ>vCAQ&pų8Pkҹm*!p~O0Zr^r2&rvQ?6ݙQ6jHqZ;ŸLWvw;Z):";kmO!N/^[f]R/O3؃x m?MҎLs'8ڜD:tEF*"RB$/&rNcJ!}Ge_g"M}]mw(=xZ_?myLWnI#ґdK+-B q$>ȒǰݹKHQ(KNhFpf:dlS12UG~ȿل3/zPg dRT5SD-GjS٣)BŒ $E7s3|)|RQZ O J8ƀd|${bw^;Bk'hTLIAN4G7S,0ˎ/p; xb{2 ԯD?lT:Qv2-xGrqˇ~229@Y#I.5Gx%=f.ŸI=ڦ&v aBfXZ%%;AȔxQ-?6i-it.&wED:SJ;}Q-f %ρ]Teڊm#P"b1-[?HϩA0., Pv^X& F{R7wiSzmJ/bzK KظH]uۤ k' n[DAFZNY~^e3GqhSe)̿lxS!DEyj!Fk@(W.>&mw * ^FM#ҭ;!8~_G(1GZLsۡ^ïBu/7l=̰K1'cgdTdT\{$ϫLE^Rk@^%-/Yy Ta/B3Ta@Yo6!nPd<5 V*O;yM)u3>=]B( ~r*&,8?p: ܇Qi7hZ2-^r\!>6fXΝj&jP퓦ЛsQ>Ewx ʡ JY8Y TGk>ONm{P,ADMF/1;Xi @}Gz-}/eC`:cMQPp~eg(nGMtwI 2gҘka ͸"0`a= gvA Ъð);fSBfEbuP͘Xjz%ZmXH ̥enw7DZIGB?V,*Tb/3On̚2+9:IPJ'_ס!g2rwXb ^"cmV+s3,} zp,GӴ=iEf0 dk:?<<$1"lGir̉m n ~Xsv=3DH5U'_g%rxU&- ^ L<_sʝ(n:cs k%vyz5o[$bAӹ\K°_nyኆu;7~ ~ [3w܏ σٜ6d6H`wT pB|f\\T%+~}s]!b28Ͳ|84~4! 5Yj+bDTg`ms84~|.&MBY~ QVw:[;گo/S.UUh1}z WiY,w4.uF/A-% 4{𛼋X ׯzq@K$ 3C_GȗXT#1̎797T7:\ }dU"sLtumf88(O9&2ta\!\dֺ(>8q}q;Lj 3*NQk`$b BSEKH g' C%Z!|x_Fmb Un"n{tih>j G3 (|}#Y1yEڊeg `UOk-n na P$xw l1+Z$.+t -,8B<EFpM= xDu\~6(+\2[D%=LJ"+ݔ*d8D/6rej2:<*n5=7iS #m2TX`fFJzj.BC P"Eaen Z\7*NB _5}r"? b7# >aI"PR+"C{|gt]5VGe]0ᣕ&ȯ09\u3nW"g%\>67ގ -V7öh (-\rRU Gtq RϢ}X` rSИYOh,]Ɯb>f۷w{8 ˿1!V M]RCC \V8F("´go407̘*ϱ&kǪCI۶Bc ԓ|}'3=`8 ]з&gg[(+JT?!UD'zǹd YåkfnRJEΓL-X #C }#(jc|hPȝL&vDS/lXN$WwI$PJ PvE[H9EIΣ3fH}3LO%DմqiJͨL-gq;G[)%7E P#M~@'dȔ ݁<Ȯv mvV _[+e=#Fs_Pc3꛵l9$oYn2赉_ mM\JΩA l?bp3WY1ρ{Bxsɔ /woAGr[,&dhPQcܑ3V癜m#ӐWi؁p)##tٯH#|A3ՕΚȿgy15 -IZ7~h|dA9q(4?ԩ XeS^v҅m40ٰ wzp`:IBpaD0%lT1t垟`F>Hqq_'538P9QGKP8p/1Gը7Dg*d"o.ز:3Fv)pIs|5ȫ;-tll۟>JXLleySV} #R6^?W.,T^K~QMO>U_Ww\ usx8iQ2OYa׮,OUk_2@>B{w<\[BjkTss<5hθíSpKCi~/PD\@} 4fO*6YB!os>(oz:7Jz25?7z+3KR N/n7ST J y1\)m*-kul)DVuڨP8r5>Ln'6y^S;UC7Uq^k7 a]{Cɷ. {|?@J ȃ/6Yv7RUqH 2Es =æ PTa?-44{&`D$Ψs)/J~+Y_Ѐ#%ts|Xp)Hv*6QdV&Cl9ȥ<Իp^23M)KD,@:EEwbA*&s+y9dΜP&[a۫ >\8Ȳ"_Y-d jͤ/@ʛ]dڶfkjI=x$bvOZ?фc9Cia1AD4 aCiε>uإct|ÞnSgɝJ( bqhZ:`ض齱/&/Ahcb+d.yKTYZEliʇiG7f(gyCEk c+١>%όƍ<7ڙA(CG[?jZf?WV e:ӈ⠝F=BQٿQ?V("$p$Pu.^x9Hl#N&Sk!x0 Fkzp$a4i}y3@;հ@h;VB`V9 Zf(FUŕVbGnj&l*CdIy["yW2OM}CQH՘Bgyկ<6ޜ-\{ 0T5س=OwC댁| _IWV"WJ19OТ&p[$p|X݈V!-os/p2B;EVevlcd@DW^%+9"Q|ih&`6 &6# &%50!o`>wi6^>åHZjMJ$ۖuG.-csqЯjx#MUY\ 9 ^eesAܢAJ0vn7Z9(}]\T`i/JN{FX7d<\z|+„N(Zv uR e'^Bb[;;ŌD$lU@kWB=. OK3eJwPfU9a+)+RZsKO2Fp0JYRis>cPvۦ4[,c4TACQ $׿֊37cG7[WٻH&ϘH޿j^Mu w1c1HSWȌf%Ϗ SQ-dY z+zWK76pA؂5&PKDUM<*{>Ve{nB(T?B]4% )5)M ]@$OޗS9뭬ٜ +WȚnՍH&ԕ6{y q+H§F1x@&[!Gt;F:k6c.ޭ:9s3,6'+83)4:B94Igz7 *xh|EIufݦگ$ĔW[<=]ǝ5ޣ5:H<{tB[t181bRulDŽ/={F< M"bXς=]SxRx'mPb-Ljs.%>[=#`9|nB7Xq0o1 [BjB/Uoq]z*I{mGwS+BrԉBX/,M}ϵѮl1D˿YYE4KF.aՆIj^!X᧋6t[q_;9!pQ=7Da%#,]=~V V!]/=-}Cs43pG|M7,ƺqdkUkݗ$n-?";RD2W+0@C-&kO?2BQi)\o=i܌,jjÙ &^k:xv^*?z  Be[_ʎ |B6:oÀSM&uGϛi;KJ̕L@ a*ŏy&7r.ә9Z+oJX/8NݜI~j?rI8萬Ad­@gc #aď!B얱]Qqdz:J^mЁY2-EW+C߈DYg:rw&(Pm^+~РaV X. P(<= #b.5UHq8Ʃa>D$K~ bF*!n 9ϣw}9CLS8q\Bi#wfD-SvR/5٫XJx]EȺCb{npOB5Ͱ[\(0u:FQ8&ʷ,Bo DH'IR`-n>B‚]L-0??G-ʎ (bdg'ZxNDIk `jS#pM/6KnX/"źݸIRkK!$# ;:|`-F<8جn8=~:G6BU6][4Gr,{GMY  QxfwcHS܋ί灪{b5]G=;?~"W¯uDz;? }*]`@N)f[sd_A wEn?8oMbx7%u E>Q%SqUJ& ;~?mm z9cY7OsUj@4%oOAFIrȺPʫ$c6ҹ6VXD4h409C@'NFں9HqAY>%܆bRNn$3&}sbEuMtxzh?>b +^q'iW$ɥ6"ҌE#Ju: ƴTk/{`2dc?xJGMk4D5?i2d1 7]6/3WVc\|dd25QA|SsmWD!܍v4єq}=lw VB)XۂpDiM 㿁1j72CaY}v+@rկRfԯE= zJaϦ/wGG.Nx}َ{Es4oMV0&̅\[ ﮃh({LJPWlk vBgNEaJFnꙚČx WѬ:OlYfg9ת"D1caJ(q 1FpAK{f-FD35G/ZWIGG i{ZGHM๿#[ Yg07@rmER=}u|DeM&Lu _; b11J t`);*$ql^_tz7HJak^O%ImcvFߏ1 {!q[UAUOKKId0˒sRu !-Ѝr+̽X" z{rFG+dBX4eVm8Mu k]Hefr Lz9;L}r7aҎJ@C|>VuƵsKE[~(uW49}dضp? w6q^%FPKE~= bW˜׾KW%T5}5J;FcU#:L6><@ eo+hr~ONKL3f`di(=&'|ï$2u6Ճ\f0]ַ#Uqw_JflJ~RS? +…~u DJ#73k Y jdPT191dAE)/ FGݜT&Bb`.gɒĵNZ'-J%l2:H\Y'wnXoJ"IudjOT`diS$`IJ^}cBT {8 !H` -xC;lAŮ:`qxH:h`!4ob,6*"Sx0w a[Co<[v[Δzd[EǤw0O n'f>g1ҩpm&zL/@/4H;9F!vYX3 %( )CĴ0<Ŧw&{)nun׀aQt` n[?1G4#o+c[\S߰EheA6!B૜ndBی"5Y 5P6r3%$:\ 0+!g` bӛ/m *_!dثV6d)sEՏأ|sG5%N~L|DX[@^$/~yF36 \W\s4ӓh%}X.\6Θ ;U[P]dw2 hYccI84icYGcr$kj5)L[Q:͙u87yo2AUt!G3\Hڭ5Ox@=٫3ȍ0-0i10q vU-)QȤ÷$Wȵ$YAS~pRei2tX1]>fux$sL.6桲Fd()Z" <)p EDz/fXuN 6v"HX]gLxrJ^od$%fo `1$#+Ԍ=p=|- -ܷ(.DxJ쥠u.XOB>n"g5v9tVi6"7 |:p #eڜaM.}b`_]W rU$B7QDv(e: AffD__c9czeT¯]>Fq㮗s6bθ9xd2"䈭e୰,Y}vr= HB tҙ6QQ~k r[~*Pf>65i$oL1(wUGZv/K5t4C٘S$A4$qצ%'S%d6ܵQ7Uĸ =f5Ƨ3N<@T1E*g}=oz5\\ BH:C>KX˘_?~F]ڧKՆNoIx7usvO8x%q)gO~5ʚa-D4e9cxs]|?f+pMbVgeg61t$-~ 7//1V ̛ìqqȖUwO~p D֤7b~c4u_[׷'1 +Āb/7rżs qEp*MS>})%<Ω:VV;6RĨ'NPuGXɭL7=Hb L⏞D8[ `N&^&UHz2k sGsc/(u1Jra=&Qś{Z~ycmQCݶ~);sPȍ'dOZEqEҲO֯\rGq^}'9`ޜcG p3}L|FՈp% ?PP]Ng`&,nCapK?5ypCYq6I 8v*;|&s".`'ހX2l>Đa@X3$Pn!\=?hrUÅ;vL7mt̖c+_m/  [ جRQ.*{B3*؍Sr&iAGsOb_p6 ~jmL_2nuԿ,v0=?%? "*{~gCH2_pO"6RG'61)i+]teCsOjI>Q@lQ}1=PhM mS&A",h~SxOP }fa}S8$b \\')1g&i2;bnrQF {HWF2W(!*- Z \TX/Rod9uY!@ i+^|[3ʿ`ʏóU$&ط5鵓q):dfM8i I hiX*VŏL/0{,x/&WdM~=r2VaFP41rgk5@ޅaF!*1RvIdcT?w(\,X+^KC̜ q~ E ,V.R5Э J Jev<h*vHH6ݎy6T}בxMspπʒZNjF E넒HҊ_sBژ^z֨ :7lh0 o4>{rAaքt▊sw@zV.0zLSЊۙLuwW)6`]KNNa೓w6D4uj{cSr(5?!&m`R"1p*wݑ.2bX6ӅX"g耧jMvW5ݼpW`ch9}u]6 xX+J˜mr @C..SER.[k)J? hz,{3T/O֥s YFGc|M,); \1QU;_vt}f^l-jnbrw=ldRxF@Bkgqƈ}|P7N,a2JWHd~k\FfoBPq~ njB7ntEaD3dy?亝΢~y)8k6O _T86w,]W4DI7u"K=}̊ɝHNI=3hDmt61!ͲOKi-(X: ~}D Gπ^AxlhpA6a|A FA$I4839jtʼnӻh6wH=,1-R|)HwZ2.N>Gr#7.x\%qHD,o$Rt$Mrl7`خZEU`U_"`s^_StE&[d'%ɠ#EH5AEb$m6n{!uycUQ?{ W$I+UptT4 l>/C-Xg1 jx.>Ӆ.zV'іC3&Wg'Nn)*굪yJfCZ&K@bHEuE-`}2z6׭:r0ڂ"fu_S<*)pc|q* ҏcCqLwpV6z^qM5.k[2K .O0Qq|A'yC*Я-p3=}eNjdd:+o]ZkdT:R2eDhy׵[b\'Nx{fQS⦋\#bO?v;JAˎGŖH%|`}~GC}o{v2i7v?g[6iV^,ArJDB1e҅aI|o%޽\Y6>$/?H]?VI>zs(ӄ\`ϙG+(!;BX 4>NL?F{Yv;y J)QqSVO\]R[;pEXiO VT`:8HVUyW `05A J4c'ryV{0@4+b3@ʌ`G)T0nزbAJoJ<93]ꪁf%PUz&{J" sX3NR)|lihT\cjo_#1j-w1.(يseҌޮR!"l;F saRGf/oT7ʶЙ3q.^/5l3(YCLpFv.ŕo;p-f2aߖ0]Nꎟ8l:1S7ypS|TC~mZt^GL$ A:lo!|RAWQضL:$xB3> j;k|ٜaG~hLP:p[C(Ks яXTGvAr0ћ =->x&c̨!OOb^)RRLE teu~ޮ'sDT*]KK,F?ݕJG]ߤI)^K]| ~ɾ3ݥ̆o4u6bL،<LFoNO%cY?wzvuQϮ(QXwJxiw] RS $)2R:/v;Џ6jRZNk)P:m BҰt IH+T 8u fjl]K['[ vg2;d? Ic.{|# "5cfA5jI ɉxV!F$'$4<٥!"i.q|/91ࡎ( [I:,2,RSd솛!Y{RM*U~ wZaEk6k'mscˀE,| .Ŷor??țpPYɂ¤ݍ_aP\ l}MgĆO 3VN#_ gVBϖa)v-2)LojchMQkϸ<7 7^gzE(ƓDOcoU`S^=NfIA^)8ؐOژJf@حy]P댟Zj h܌WGnSaab֐^48; 57Hl.0{cүhZM.Gw8!Fຂ r*<{?MQ4BNV/{4UXvڟ)z_<BJsn;;-jݕߺB:tL\SQ=BkDE3aL;6|*hnRoŊo37 64Ҵbn~!M V빡_ُxK`ēaUQ6F"NWO7( Hӣ!:S5p3Qݯm56aG;PGކR3яpزi?tt\IRobQbWN`ߒ*OL?zs -:o)* zƮ1H=YdOlHb <KD6)SծW,5&u_a#geYdsGxjn R#͠~$M.y; ̗%I*,*HS؉3q*Ϋ8w |"+qEPy_[~U )8v2ۗݍ|6r@ ~Hm{w-L@J<%U7ps|OȒ~?5j2$bV:& +Ut|kuag?E'pȿAk`^]};Hp:yκ2nS#55zJ9^˱~/LNgYF3uLthNب\> utG#em wK$^;I\Flȓ'?W5)1)/x?{ @ײ+h}x j$( YIhRޥ<,iUeaSJ3VlT($6K/t\ Vgd j.#+mnPרǞ_XN:-Tr`X HgՎ؆=u|(?_:LykY XztXv|fbN9@uqI\r@*(ST7.69l r/^IO;  WEa4#s{#b/EjҬ g^$2}d~>zn~.w7!Pe1䒶=i_^|lʧCtu PIžu8X $2PK#w~zd5g`4VY;xo-&哐 #ܢ}5<x~*^ʹq'h usWO/[f$Ig)ll j霴In:,GoXΌnq1o`Ŗ;>6'3$#fA6¼xeq*?qk]L uTo2>$jdՎLV6I[#5KB,L Ll3LGh*)ch>!V9.XdÉRt;,yܷ99mޕ"}U5}p<%yxAyA7SN,a.&So$%=>DԋG>RWm՟|EDDɘF`0g)-aֲ>s=zUISն:{т*opOdAZHB]?  ,%E47|ߨ̯|^q$9#~h0Ke"a)agk }W 'bc^6-%srhyFZP)˔pJHa%>c[F7|-\u<;j*!&.nv$1+ =,AB }=αq OB(3N1'E8B!fq_l.u})N#!=HrJue+ | /}{z5gRN(Tkmw{aƞ>|1$kD g C52!fʹ&MɩtݩǬɍZ~^ m̍pPE^!)bx.PBMF\2,6 Rƨe ؽ3dUJ )e["ؖyWa_5{uzb ܫG_Lш-`"xfZҩ385ivD 2T&rȇ`5ĹIH~]IZV#QGeJ WNޥR\zMn.#g7]7er|ONjIylqL>sYGL v~lKɉ;ifׂGL$6();[碔B߮rP MJ^IeTIsK~CH 9¡?sB4XJ_ vTZ!g(N~T창QY=`n7 ;7!sN[X%@xVӕy>_U]hHyպ򘚈Z/5JZPn^2[ξۥ=B]&y?j9Fc燦gEZ"; VJ}D US7`qɝ$nj !:K]G`-nwvyTTJߕdG5@ 9R=j3I+^E=l юQiZD@\Q"v?{E4ۼ-3. ]{]%+M,*˞tsP"&_S+RVPNR˿<O  v@cT[m1 u\rH{jqnD:MbuB7&a`T>keeg}w"Ӡ/ fu[`!ш}ꬎ9R?uyD4O~Jyv^7RM@ /:9ALdpy[d|.~Tk7'hK]K;O$/md,uwxY4lWxP󾒶aٽ 0O]?Daԑo 1XsҶn>67o2KeU7}V1էf_ʹ%кiaw1:}N(vQDOMzXm\9 xݯ.[傺r CS1:s{yS,:!nMqq9Yl7Iv?$m|To‣NDn-'pph~{yD%"pZ9ȗJ<آ>XX1mHdbX#Kl$Rw(!²7*];z3r|а>B."@?z7RM)tV=&Ҟ`S"rJ a fTn&v@kOš-8'^ ,< 9JA88XBX훣uqƸiG*_K:|&d<0I/49rXoEѪU5R?zҤkPt7lt cj~V/9zc2b:4ݛ-!tu]u4'9ʐY< ׌g!f)r3{loI 29(:oP!nMiV2g`I!A;e =n9oCr KۼDEh2&ݭ *jG mB29w4:&2UHk6M|6.uu㱹7b".W,eZRe%]s6 gnW : QB,= "!r8 KRȝ4WX?O!)/RL+F/N K'n)OgD hryX#nc*tĐԖt dA-pć A C2f{=]~WML)ZY'z@brhLj2Hap6I%jWhDٽH}]@h#Ҏ>a6$;^`we*O1`-:fӤeV_MDZ`py0 91,]üBc,F\c ]KE@ʂL镆yvtvW(Z}H.vh ]?vw!7`~YֱbDj|BIߟ(d ~j`y]&^Ѣ#:G{fd-Eմ5`>H/L0M%)Ů?PzA9 Աrx|o\ !r F*9ZOĵlYńCttzcǁt LñtZLdnexdL-@Ͱ]F-A,Љ<(ݠAdakY.ᄴR TȃuIJ>j ׸-JobmK9A??y4e#q-H$K)LiX:.g|s_~NNl #gmPbPJ`GT8h\ˉ^qTG@hS78h0vK6oYcl ed) YVf|7D_4:x{kjwz82M)Lr"Gs\ Lv+Poa/ nf^zJ!JR⒌K-—x;r?Yrz g󵒄35N{ viI*II~6^NDq9=e^ gOM8y`h"7/07"B;ᨩ* `൮<^bu5\"^6TʲtHGX^glUAӴ=mghOSPӾN:O+Xɱg:)8OH[&46cuJd/y:zq̜^bE4PkXeFZpsqWfp߹;2)??"ySo5O%^__"ݥ*!wAw(j=Zgj t#CWx:=V 5a[aaƉX_p?Γܲ;DI IZ{/ר:ǃ>W_v>tYc *WXƈjj (6iq>9 H/ے5'^AzY]YỰ̸Nݐ]VAQ49s;#Tݯ5k7vVP)w9kw/ }=~5x3zL(ܭs"ɁB]}kAJnMLx v_挟G8ȠGe"p$v{rx%˗ם3󗫑l2CfWyX8IUWN_:a Vav|7'‘Pgxp.d!Vv b?#Bu+Pb@(I4DZ)/HBdT{:R)#Z:9,0VR>](.,NEvڔauw,Gھ^ϣ012 v0b 1VQ ΦzgYEMgO#znfPICTLw9n:o GP)t'a%2yYEj89ꕷ',m8 _,jBk :mC\|y lIt= NK 4֎a 4^V,w2lu)d"Lƽxvnh"?[s| P(-Qm<uuB $@|̟4pW[ +"+H7!f3w^]%H!CEgzQDOwM+Zu2(NPxIWZ~o:SAƊH,&KH:ae{Qm|+e_0+Ï%,2,}P M?zC^&͝V80jj/WזaІ2aæiˉL(%9Jd0M@=(FwF}8Pv 4kء)Ru0Z} OyRڴ$@ ܳϒF) ,'i0?èly. 7? 8m:I8][\  )oeodÈyǚ$w!{>%`LlCy4~D$ $+Ɔé`ŰٵvXA҇ҖTmq!8Z2 꺞.(5Rs/c"TsSMu` vI{Bui0v$un D{>#g{Z;&>Ҳ/K,F8E0l[I MsbqJR1h9s8-͝s~+k&unK8SqjqQ83ނ5-- Z\[s;^QiINV <#TlA~j3_^G`WcȎ}hp䀞8r,Q:]cMEda|_eN= N]VfMMX5 qGlěDg _;\EI4ZA4 |o =B݇Q D'PO=.WXM)Dhr":IVۊ7P.%05AH\FD}]#Je rS& S'R-E ? 6II8h|oY*4rS%`6iA ڇNiW`/ݮ Srևz(C D_aV!nB:W3:Tcϛxh2/{.B"Уl9&tOocoX=B6,Qae+F^]$k, 1H j1 v6g<\aOep&/2{G$uR@}`/FXn9L't:e>&Q5f`Ph4WF;.Z@ a" Vb2\qAL!!CpNRt^+9QK̷҆*Rdd׽o@.9>n"${sh)%̂Bn&ShvRp(wΕ=b;t+(0U@s]Kke[A KzVNBb=/%w?ՐJk4N[2>[Bf\xrLDef+P7V>b`EjM$3,]kDݫ͏w Gr;%^=0mB/3Wxp&]kG=Z:@YXsAZ;i'ݍ,3olWa3+D}o'zO#BÃp˧Hkqiaa{P -njHX de:`·N]9$˱r bN)>jjAMQu0wE=Nx@*vl}=e"4ۋa: v c@bV}^Q2_1o4Ik alGhkf*5vmq B58Y5-HPT#v$< S Vp ;ʡhOd|"EU,bdxZHRm^v'FU%c(@n?b黜,,!7$|$s I"L׳$ŇPlnuRi ɹG^C1}J(-RB~U ú̅K Mev7QdžM.ش28`* S u@v~_(r X;OC3ɢ#Dm wIlsjSYQeZ#yR=X=3 jٸN@ Y]$:AZ&GnwAW]Qil=j4f&HVMܱAApPD$FTM4ii5(llM m;nFm (8vXLW"_Bե;or[ QKBmaGb ^|}hqoasLiP<%n60'@"oClg=G@`i1S$x V;IڱRU{81%"|jab)8JF'XZ.5$ȏ}oV:O5KtC\МcTkD+ɤu1_]{)}}ҵ{@OÓmcRfoU^{e+lnWnkɲ(6ЮTJ~{abTM2L|W}v[ VrvzhA:;( +*ɯ9MMLb3 gBpg;E$icoaM-e+tlաSEۖ;<ߤ `o8]Jz' FvDI0 Ň.0(``>E<Qu4p/hzn4ͅ/^oڊkeCrkh"~ر,|pIHrO|1$d᭨7wei\o1bkq9ƍ4] q"]g&(`~$%lmB}mCx8;VſjO~ʟN@w[@t~_ ֻNKL192ZDYo-CW|mI(:g:Uw'Wm9LG*dV {?.Uѣys[M`gT‰DzQ_F$tu2lTW=%dcSFNlXR' &ԞHQ\(yj־{oZ64j|!G""o ") UEM)v"T= ڢ#Qt 洙 H.4. MFc1xEP]@pOHU.Ov"2}-RcM벦 cj?̬n4šQYR7lN(ĮoHƂkp@j!'1KWm7փwai6 G3dD2!2 `1S?iCe?ȓ,rmXEsC^.H)DUj\,v8k<)~r, ;|=d3"=e!J5#:y *PSc#%BcPb!E8 !tҺzA(jyN`W4@1@Y{˷8+,4LK5R‹0:gb?o+ 7z\N֮qbيSq,S>K^:ifT=!,@Vzeab6Rܾ: dD4#0KGΓ{ޯ'N|6WQ pk3/EY@A*-N5N}!FV7hoj;w,avg+܂ǣ{ bk,ܰރ,r!QF|9/ԣn]`@[/KC.$!Ƒ׼>$*A<;Kb& ^Uu gi =X/Kn8k"j(H8 j%)Co YTtK!>/- MĬ*æ UCJ2s'm$& ltnI;3qj@7|j#%m kۚPjr{g29;nb^W2&&`ʑe+`#)PG€h,ui-43 ISAsaLw3a早X 0\dXeYt*eu8K1u-AS]=$ҙ(|e }=ـo9yR~%?.5?OeZ^m) Q_8 gS^Ix012]^s&6n'YgZ<v7M_(f+bZCX1dъYS7wҸ%;#bhN5210 Bn.Niy]s }de%@Cj͌zDUeݝ':ݲЄf] `d nt]MT@4U2wDȪ| LbgbKhAB-ִO8w/B,>3 8=wMj<>L,,t~kָ7l87Em`ҸR]qrEgb DyqQ`^`)IaPg]$ ^q)x<"f&0R줿K`P ~$%Yd""E-_{bXu^Rd^< 9,֍.ׯtt5&?Gjk~Mkt8(F*pѱ3Ċ_1~ ո헥ŮTʎOAi#[0Eʮw\~;&Hɀ·3I+ӕRv e3v qDrBy>^' rǯ=j? ֕71 J i&:D~}[wA0 0;GN~"޾|m->)Ch$"'ŗ\:5YД$r"z8?rNí=]/iI1vbo8ɺ8 ЏHXڋԎ93kOuZNȭꓜhs[eF?#&KBDiծ{/vcpG j*{'Lµ]ZM|˅yCpHNNa=C~J˂[d+xZt,*4p'O1szB ͒SAh)z!oG<*[>n#İֵATD 1GozZ v2Q=dQl"_ ' -NVͧ hbKlut[=Gv+L/%g>8FKo̰lXt!bAW@91\˼Hn(: 5pU 8ۦ;}Y%gfP3\X W)X?oAұ-vIpV~蕱&}c5Y ćxsz&݂w+Nzrj>/e0 {K[_ Am{k8m;s pi6yJ16)q3g[EIwM^7 <ԀyAu# f;Nx;e {:8￳#$㸽b@)ۣ]+O^c}^@[lތb?u9x*ˈЛ)f QI ._yE  cyU  ςG^:d\D#DJiZs}a=\gqI8ju +糂 ;2ֺ:wll.)"NOP:-t9 US11*r^H(ąL.\xi@ zQR!6ҪmWe,Ȥ%B숷Yf({4m\xʼn.A&D+3nmSG#9ewj<#/íڌNxSn)k `[T)&͒MqJڳy3}1(w%buItMY6YTnZ6Xc\krY7]3#hT{jYɦzMuXȧw6c+()R#9i}h׏S,s($د;E->u \ޢP i~ \rV<̓[{},n=7ٷGwO>WǔH0n{u7T!+_h+i|YPgq+cԧ_)QU3Ep5Y6վ++n\f`SLSݦ*3p1 MOхD?J>F$J׵lWt-kTAr~58ٷ;Rit!(3=Qu\C'e+Q'}NܒBW+_;#9P@ ;U\cMz Ш&ߍ!Aǰ9@ke(m2cR%iNGڢ ޛGB#)!7,MLTE?yR'37@fudQ%#Q⺥c*J:6De5)pQ-X|7L\Lf+%%U2 6d!Glo{"*Npu5_Z>іIZzOХ(e~T/v_>3 R?ggGޔ\VOSp#LoYҹ- G݁7*A,{Z͜F͚0Kf l#P'zu[<{}DA-\oP{X)|F8YyO1|oU;=f-^ς gQ{qy ]%ZMo"aTwK^ ~jf^s$ WߡVƸxHؔ}WΤAZDt<z4~zQd|d b:=Ԡ,m$U+Ū|kɻԐT-m΀\F1SdGlPt6Cf-#t1dgq CUhy `7:+A#[vAPk\w3Ӭ߽vcMGV.Di>2\Y<4?hW(Wp069ǁ;aM9F$4[ȮkyKZ~cm ʋlo%S_ jՀ޾3p?uOX1/LB4-;$ڤTZ1+2Pb*#pi{{W minnh: F. I2zmknby~}ꇤl-]LDQ,~#qۢ )^P2XtbST_,ԟ(U/CjMOM-:{ -଄ ?MIB(8!mU1IȾ{r[Tof&9Ѕ8 .[׆jfF'Ht ?Lс+7%؍KOnߪv&H}ܢbY횔N+d(/"W9RD Y&bxVsE,4ko UU.R2!k'?WZŏvAZ4VA FIt#>9f' }O/f`nǘvncE5u΢3lX2O/~0[@_# j4*)a0&\]=bJPX2V8?I%>-|IL :C{̣s8Kr%W$JТUSe֐ z6R^(nwFmyJS74EI36)0rTr2.- &ϠAYx߁5 /NfD76R VhM8>0g,:vSf k:٢|7J(6&Mku&1]"} F/>q 0-TKӁt-%!PgflGR"?g ?n{%pɺaѯy p3juqS{f04P&[G4r2! J,*U|>B<jU52 C5u+:-m+7^i#fE%Ä@BkMYur0.e~>Z3s|LU5 \Qcw/)?CZ[K{=iW?>HPKKƇR5pO6ΠS WGmsI|Eytz,G,rU$m.rV|F"j]m_EJk"= L N9wa ׶K =`L3? f.f" 2 b!b8E: Aco]hcHGkzdȏ3sw..4v!,Դ9]TtҬ`$X zvQX #=˥`Xj-gc4;4Ch2xb A]|5NMUTvY%:vm(l9-t@go-Qem(OPsthk[ާp#U z/\LyEMw}˓m;t48 QALx|B&9ruh˜0H Cs\_Պ[儠@m@3nh[DF4[rt20S(M=y<>t^~3vgAI-HxLIjyw0^OFN5eQfScˬJޒ OL0SPYجT0>*Qxavm`fDˍ-2׼'ڲ*^'eɔrRZIbWIC P XWڦu uhs0ѵT>>)tN3_xt#Zmx|Ek̂n ::iml͊CM5QBLgnUU9pe/}e?SAQ{9FEnA<t9u/03'Ԕr#AX\\T*e#%ZZjTey7z"r")pл&+4Δ8ȟ%ҿ{X4HoI89v4_9^僼އȱۉ ѽSo81{<t%x?g*i NQy]ۢ_>zW,C8u~W[XȯsD!-!R[ngpbYf#uUrAG5ӈ> 956.D3 M]ELԡ]_qKnaEk:tS#K&=Rc1v1df/4Dl/ woȔWo^!5o+,МdYHH TxmRʩ)B<2)Yew~PIʅA3[}c3=%5/a F0uDt.SMu lGB^fxꀢSh>|o}lJCOLKt6;{F}'6H2S.%,:LMuQ "SOъa'ゑ{#"-M൏`kˍDL8 kz#FJ/pʽT(q^F4L Tf xaþQQeNk)rsګg|&ܛX oϠP f%BK1#wK/Ir}3$_K<( GXʕJ~!M '{zlvEn&k7vѴ>[JClH\:[^Hj:(6s$p#NiZUl\;L/T ē_(0Wpw3ka&~r$xob鋸f乻V76NnoIۜ g~۠Vp =gfE岖knmi.i `Sޭc}zͪPY~_ν:IV"5%R9ոPOOޕE؀c$BrxZt{ .Zl2L T"囈lQqNՋ+C40{Dܜ"%#n6Ô'Ϝ1t)W$+ՍnR9S PVQ7˾$AT@NxƢPh\ŵzgg"“:iC~BLU82dzʓ #7=7}l\VnDJp^wC쏡.B9'qwRascCpdrMل,N.Eg ,7Gڮ/u:ő$X 7(| q|ny kXJV/+3xQ}@4٣8 K߂0lQwBEm,f]7\ J$G+NmwTӰUK"s9nC{: K2aZ`V TW]~gz M/C'2xh _q/\4߆tnySƶrKR' f#ʈ6qwŧ`h`8p nc` ])]bM,;܉z6ټ0t\u&pO97Sm{8bh&lS'@𥫹 6C;g#8WY)'U~tT!.%̪Wd LG'zQt_i(T,bD֟f,BUL/CW fy 4K pӺN!]e'hbp9 A*xFPoꠘ>ys%)H]툇]=pG}MKfsw{ @'~<CzNSPBޢՖf/[33Fp~e!*<¨ D鐴_xT['ֶ[NK2mIP%%wĶF0  *Z"6pF%͈%|+R `˼"w&x/d_iE;\b=kF\éΈsJ,A9;~e)%ڿq8=:>J=ivoO,9Dg Ӯ=d)0ԩuh;[/R“// RPߧ!ѿõcX>)3l"%ݢtauqYVog(o'a Ca8w*ccfy5FɎud=50pXBϢC\4}JoG[VSsC8ؠ 5 o(n@O^^,Ad7T 4E+0?, ^D#l)˔^%R]증 !yA).&e.l Ɨ*%LԐb8a}T0 S :fчmK(M,PZY#\*,>zHd[vV X;DŽ+fGnmE*GDgx\]v|`9j%:w?-8 =C&򡿒Cޏ]i輁j;|05sE($$=XSE.^Kf! x³>NS]a0p&rYM%'mRڎVyEC$e&ω.! LL\*: ydjֵU嗖KKK{XavybrT7;_GueHErf5jx-1M*]*@>S Mz}bjNRX2SiḞhDalhMN/pݪ)  1=__m;5 VAa}ґ e+Wb%Qkg5A17%H4[ zw~hbbb\ 0p_gip &㉮+B&dd&?[Ly"O;N:<Ee@~9ڤgj|GNuOP[+}++68[ C]OgXL9!BDT=N\#k뇀0lqQ II\eqo6V~I7\qEį.* T@SSO9&p3?/<59׵ID.QQȥB댈|1F0(Ѩ[ej :7$k;;:Zo%vdA#FgJs\PT},@~}UO Ѿ$yO " ~ՊN&DOo tKލ}~vY[?{_mx^]/m/@"t2xEg,~kDzISe<&hWͩl*9x%^I m=u-ed'*S^;Լ{rX:8#IAmQK΄3jx?D5ݨea}mUyJ'_f&lLU曣*yoCCV#wDHW~sCw흺lT$ATC)C6(5S:koDhY> )ࢹ|e 1Z'L/۫5 ë8^xӴpj)!>:6J 7I4wmO`hY^Y:d9?y,|$15<$c,/]&Qq}UNJD- U^&6 TB b47f nuIqoByd2u; CVz*A;:EY¯ӊ/â8%E|XAJ65[J#o,Jo{n'pbْ0nR 択k۱La8i p0os@cwuF`b; Ĩ)-b9p!-v7dة`*Y9{# B`1=eseGM!ʨHCFSqwҙqZEVZ2TT+!tjt(Bݕ:DϛoOqpbqșlRk[0' ~$rT6tZqDʔ-}ñcpVWS1ښ @D=|D2mx q yu[*b}~C i]l ʬ?,5{{ CBa7 ߚ4y)usNߞ'~*z  αcޅS [Y|a}M|hI7ú lUeɅCM$hgP N MO5ljb)/q\GXgB9ӹ2Baʠvݡ5uJBeT9[2:s`}1 , }VIg !AHy`Z(W"~`KE[I3լnpkWóB~R=.ogvi9Tybuyh5IqC2̍pSĎ)dG\c$"?ĖfAᵇ! )0"@4oy黔x-RZ$ !@TiR>Kʌan5#X@ڂt۪Xϓn޽B>d|,ո"/s7)?w2@rX=uwI589b^8O}s*I+|"9*S'24B[]U'%=oXu 2+4AvR@㺁`'P= `lb"vhZ Qo'QY Kdɖ`[4ߢ&LBfmrV]T "!Tcq{Cmf8b 3Z˶Ŕ3X^ 6zu{ YAZlLB6E.='I})$HP˯I=O=1$,.57ٰ{E LoQ@Օvvc3hc@ң=p8-bO?ho~x}F_ 2d5U@{J-'L2|\=J%{܆J/o$UӼ՗m"Tgp]iԕrZU%˩K~s|;1sD|'wblVby8V1W 8LMC֤ܧ#~A*_NCO 0z+v)N,nN4X4, uەnKي>1^ #9*جՋ4kg߼3Yyj1~q%N3 k"/{4z;Jlop{ &`&̹& 2X΢>a >1J(wYdW8R>%pyPj 8.G4| z [Ax2M$}눛x8שs&Hp˗,fެTǞX*0ҪAF&YIX80(V5ݽV`Q%G^~JI =Ʒ=ԱC5JFwr@9gNPlDNPoݳ,<^=<"(a:5Y|먳`̟H8-PzP:~"h/#aBt&J|fVtsvVޝ4-7q&dD\CTt!d0uOUX7nVu`Hv;OG2єfC@O ]L4Ϸؚ L0N\R2oK}b%T|>>riôF8c2 8zx9VRŁaWFNu5. u[wRgz)MelӞ('Am T xVt\7̼QtGRH|aؾ^F-8}VGvJ 6]NDXX;bhq`|\Wl^- IѲ,AHpAq`uҙ Ou<v-dh4 J?x:TK ;Djԥb0hs(0NP' %Dٲe}h^JT;e<0k?ё gÁɎGHϰL/IH:NxZd~/Ϲw @=ߩv~+m{yi./4ŻHTi8۰8ʩafK`5=%Q`h ϓÛO$)h͒ኋcܓ$an-fe@Gk%Rm3+ nՋwdtا=ҟ:BlG2Wv'A~2KF/OZnp3DF$r鿄9䙂MM~_Tܝuu| j[x3vJp Zѭ9!L|Pŀ$Bgc:HN($Anv4)6Mm q`*dڶmUJͷf{F+ISXu*/I,<:oc ^Yx3҃fc!7 !q5b3-Z}"CGb d>v0KD "YUimvO6هGeSMݞ;A=l#^ |7t\_`W2 7wS ?Q8 7n̊98!bL}b+rD%Amk3u83O$,ssIgud/Dݸw 3h!bC Q8"=i.j"f!tc,R&,uX'&H,sԇnbORU0]02Ώ^0 bjC23zZ]1[n c`^<5~̘Xy'W7h/*(r2\令֧8XTzܱ@ 7/9D)ߡOş!6TdW"JUC2 _ e7!5O}ya,dpXd|q %O] ᗉFս=bnݒ)؂A$s$P13+kP"CnUJ0._VA)q?XMjZڄD{_8/0w[M?@xQ 7y9ҁ)݉m9% n¼TZӧt~lOgs)lZJ%+7E.QpeK;qx"'#ߘ|=fB3(lztP1$8d!|,Gu1 5uTr_,.oC|d|MBR[{UqW[gč(\5"24n k?Z I8kEI3b;- fh$|g`cT+g;]Ë``\'^`W#m<Ŧ9:8nN0!&5测v)rٞBF8Pӹۼ;Vzΰ-*WԢJukl[ [/Qyٙ"#8 DԽâ[t)ҧcyb@aHvߘK^"F}11HDatMAUͽ~E1y 9` ϛPzYaw '8_f̋(TH[˫ 3%~Av6`'|{(+Ԏre{G )cJ6X$~^"}완R/Cb%McmH=P FWubm?2f?*cnʒǸ>&ÈR/xW9ί >iƄԷ0$tR"FyXdTś4rWk9>aݟR*z. o7s,HR<ܷuyp-K 붿ҹvrz>GN1dͮ{ ި UӨoO5HLie9n&٦o@-ZtI*%óۧ.!Ehy4HGi6d+vtJjfZ.ZNbGٯaݵǃK):zӻCѕӪk?xa ?JUL|c$)V(Jݦup6|)M>޾])-\q@Ak2 {ڋ1x$ɦem\ĥG&bfHDMy}x˻1iZ T@T $GKC]8#݌8pAC zW@j0$B #4 ۮ~greyQ2}.)F?qz\!osQo}V sQ>/,-1}bofJj[3̢ZlI|8TylCõg %tƣKџ KPILgDhdS>{l󠫊H@i%K-_X9<21\2_by315㯛,aFgg.tD9*A<@~n eT?5`GΎ}vv8cYH o_:_BXj*oPB(IpB| 7@域rF>Z颚?8xMip Mp5}mz}(s!@`9)ptn䩬 >*+0S!}s_{:V@g>t@FS :D{'W w%&Un-tF48Ps/C*!4"|v?p>6T߽ӡek@`Td#YϗzH&kKՌfWC,>a{5@O-z,BUɔ01ێ͸x/.\ ƒ"?gGxӇ*e vCrQV' W̋l;mu.:JL-m5!z+ڍA gyK kk$ĵ/B/ݏ<9Yc2I 18#{AU+Ɏ>v2#n?SIM/&s}Kt zJGx̶=9x_H(ulM TxDSUM[$:e>"Q"rʔò@h8*Mĩٌ׼*n ey0z6Xͤ$L8 ~Ph |cDZe 5~=v_v⎡;%: !pKn[9Le| ^ߩ`y~Y+ ?-[=V˳Abg W>l߈=rV8upH.4{ߨX +^bpu E{*Ie&G*1d1 ׇ 1Ef<;C$ a_385gow%Eʸ Y9kqoCZ&*Cj';ꛯ ]M~B3EnOdR̗ؖ7z!8Y P䕚w5m C*yhQ&7kOq_7\ʮ܍-K9Ögc[y7BLC؂xʿnull":}{,R! bECՖffFlpU%; qi!r_]yҞ";DL֎ |!GjFh3yP7"P`ZI-Z3G5MżdUj }A3H^+/fּ@gLj嚂꺋9\֨@ؚ ٚf$%9+Dd&`37ynC3u+ڧ8xa^㑺=3YYJ 傴**XrI2ϑPo- j@/\׺?RTu[ @|]ʦP/w3zgG@;mkbͨcV4㒸&|qv[ -&ed \F2|m O XߟF6aS4U1l=vDGuOD|i LK8x:U=+(GbN ۍ|k! )h(O\ڧ[- v=^$H NN"Lga9 %E4Z҄2IW;#|V .ѝ5T lV;SS!sذOy:ߡ'E p$~%T>%,KH`"v뜎8vğ)=I&/PH~HŦ3ԡm]X?7) IϸQ1ns<@ZU4|bKp1f ,]z6VbcM!iVHOmJҡ= D(>\R+^&_祐5Y8e6 D2hKH%/g3e1VKrc09Lj5-I"hn&sёT or~kw:6rY2>R]p CR@s9pkMbrc$5!鄥JWBDS \Y l]#ßGt OQ 4yP]bPN7c1[(YV]6q̂ 3hw5GESLh^dU֘LLu5u_/e"V?8Kȉ2Oq3P)b KEIVcՐ!x(+m_%"ՓDI)^S؈;=UX5:isEQ_:!H<5w+y(hD$ihCi‚jw?yC;S0$xA,{=D?zC/sFa ;͸b9 +$:#`I!C,KSqܨa Fr Eɟf&;ЩeT xwMBzIև jaoY/Iv<+d(8ua[";@ Y;We -u|ӄdljhjγئC7Re&6Z~[db5 S(u0HQݙS,i+qz<[.{0M0g ByMk #K5"עWԭ]v/V̓s=ASVq8d^3c?-9~XLe ֪-v#yFiUq|) #4=y/9*gϘFs D PiyՂen *s^:CB|_ƿ~eIa6X?ξS١0>_Xej.{\.ehBNklEHGx6܂qK6b.w/@+s FY#emlh5]4\rTBgs,ˀ4cW!y_H|5iCG0Em^ouoYb>Is(oqLQ#Hڎך~\m9Dc푬y^uxFJxyh56E\}?&2KG 1bX^;jizuë6x@ARv^[ hySߞ_tl/Gbhd[ bО *AmƋ(L M$flKX߂&nث:j#ŕ4ڻv%@d|[ 8y҇m;vcnF'=sDY0>h^zq^DI,@q1oG䵚P:ǧXTnNvxlMsKɎ_Z#]al`aQAii()gF%!Vvq}۫$<>~{ׂ;^)ӨY&?#EBg(CLτrwPwO[kWûI"'6lw/ȿMx䄞rCBqOʫ]6vX՗s{ZΑBjtnn(\5fā53%K9%k9햷_Q$g` 콳!AByOm:Rpt {4U"|Ie#Eze6 +mM|$P~/O1K#RHf۫e=-]@ 6@NJϳH yM!HHh R,46kQ8BhFx K R(Ƹqf-t3M3N'sU:r[f09'E*RSٲgGCob#;a[rkxEm^vATq^feH~-w"@t2*!K\M}6JevIK;,-q 3hnx򁍫`4'BkaY)iܛQ Ȟ  u\#QJ0jR#EZQ$ t,@n0οӲEvq یO֛6 21{#uAp{4]+~Î B!@q: 4:$gi܄ɵR,w%XyL%ݲ*3څO˷7.,U^I'lW򣅴Yiͳ9t:M> /U|h48־II x@53@r>5hr9tDyX'kD%# @b* V]Tk 7Δ C5l1 $ '^_߹vcK R {|yhp=|M{,c"-ҲDd "#BZ5ǝFqb1(KcIpDY5QFFR)͐_,P7{L|ȋjw窹(`a۹V r'櫘^W3yR%dFL]޲~~D > KIDŽ,D,aIl̎pTʢZ>Wn4-9O; ;AȻ-K(ޒK_ȁ06qSm1<1^ԝQG%sxp4 l^%ɐ3 N]5Tlt2U2_Ά1x!fA'QL#$.-ZAeEW3y\ (Ko$O .Sf+SbpUggW#BFj3ۦ ;a~1Rօi]X#6/P)4B_K3eA^|550 М5grFZ@m3}n}H ~lqV޶J_Ÿ_1 l/Ѥ|b{9A7J,1g0>bE4 ׄ@Ur,:4>1]@KR7Z6ŀktjZqt"k/'/]T;C!d ψ_Nnj Ncު^b^#$ Ą!0;g} ؕ&nHf5!>*`QAxIayI{cKU,e%TS7%,u] TRE$I@y~=U5kTM#::$31كz6"{»D8S93tC@2<lōtAxHdSUD /A(h)MVHsxr_uə,"4>u;6@~XX IŜ + {;:_UdwY/fͽ$FhwgoVlcG`mB=<#8CAr +xOci@] Hr'#GN TEAzZicK$E6*=VZ(OqԹY< Y=:}%ѶŐ`qFEV^@m}IWYbLt3W*6YmKP0kcN8SɩGe*FBǕs~DgG+1m),n˷1m+]{ %y%0:]:nwq$CB{/֯bv喩 h}1}Ak ItFS4!ʌuv^uQ zEŘNԢ sb(Gq&pv 3Wu{nVE (_C5t2VOg\,*ݘ:16)Zk_z@Z:ѳ^c);h#ymVEgQ#GR+|؛Kr5䐤~ɦa2 %TN;8x֊ѡRT4jA v>~Ry=n$FU>m B kLlXm5F{BEm_OJD3-~BFPr9!A5?Xj|tcjj]'ʽc3~m3 ݙ#2(?rv\.'g5!z5SK7$'ȶ}84={%Bdӻu ^-5qkl N5p3IC#\Eƞ 3r*DzYa N H_\%̺RFLx]޳ [P&m4@_Yh_ 䴑o\ ût&.ٮ^9 $'NAEeǖ,bcG0FƟm5~uf)?[DY?0D2eX̤ Ɔ]`,ӽ]*-G>kfF0rDG*nepl+j!rA<˱)Kʖ{nwԲri-9sV!%o#UcTpOͯdM}h vܣeXBv>w 8;ku(di@F-/4(J캼RxFH~g !D| z9Fktqs!OV+q8̥bdњ=iXꌒ:Y@>2:>u~!FLCM{U=c[[l=5;+~`J|8H)忊Lh 7MW3OʓQ| 7֗0.m܄skLoF$BQ:C8dT"egȆMS*,*N0џg)W"hUgݖynJ:Kx66 ĂE3u u*O4o.]6@ ?]-x9U~in-MTHƃ (_ff:5AM,i6 HwrԸҁ]V{hCzh+88v"?@EҡVdQ`AR;i\~EW Xu<8 Xb5{/_g 3[5dO2O5<P%m- KUe,d!U˔> CQl Ofm~[Ta0_t6Jhthњ~ʇ6ћ3HWE~G#f;YrV+YlCq }&UeFoUI{vQԱG!w1=yzvf8WTݍS71 wqb\Պ_wE1N\sȮyE58)&HNz[ʖd4_5FecUڢ2qsP6BS|.}F5R^6*jlB+uvC&ph|CZ? )qm-[ќeQдjoV@4❢Fkq9R"',ӽ at2ZZ\(/;"ΚÄ=y:w|5 MN: wc]kWJ~@#޽:;>G6nkuY5gA?Z;VMrch-\>Uj hRfn /6'ot-FX&QCnj{8`-BFú=r7{appz?z4lGt|7Ϡ@'*Mgy-M:{.uosl8u̇Am1jsύjӔ*<>$=v_@>0ʹݽ"`ʾ6Zf#(h0OT#6..fN+[@zVBZ &&[?Ls"6Z/M5 *2:E#,P/k{6s8%ƚE}.)o1>)^$r,)dˉ|չIpyݜN<)5 d' yai9{@&pQjƈU[Noﱼ"iɍn.FuC6,4儘%CI?52-a!@(҂y;`EX Q9:.{0Uʙ2nq$q A+T ӬIc,utОڸVпX6l[{G5,ۡI- V^ N-6"繜.F窆dg 8h ˽?sÛi<гeVʥ zoqL\n31euTo'OIE˿O]'b  W&ؘP jw[n$f™5E&3{ {a^̲&=*/-S+ wƊą%+"=;Mc<.Pߓ; I>h10=sa0 (nDkJf:w8)OT8 JP~|PىtM2z3@fn'N?;<ñ8Hwc,4 ixָ}vYKE<~Y%?ģJA+\"Ԇ %χZRUn/C6jNv gp O:aa_aWZQeK'Ш9PlQt5U}n>>|\/~P [ib7K`8;枨#價~E:N)`xA/"6j0'z-9FiYP.E4olRr֌'oPJw@hvkIq&;$^7|bℱMJ kmHȿ_[znPHIM^$Z(q\SG ?JRET(ÁrG*q\-/Dd"If{\q>`y1p"tVNmo,LUotNqGۊNci3PRj9ORT0-r)Z ፬B}=#ǥc g\t]@ʔknCE(BVT$seLKu&vˬ@TU_# }D *YH.QR ̕gΒ9OVy WF i0$fdA3_/P#SKzUQFxcTDp׃3{0rb!# ؁RƛM>GwUAhi]D6B1dȀ8+{%I k"kJ$ wK.{&Y/evC#m@<s|RsKz},s CT<ۏhZLږ dcA\V#guY|Uz6{: A? rd?njzbf:LW 啅A͢}{DbgB?<Md+߄o^kgL?PjG^0짉A:cȣQ|nTƒ)zvi.wy>~CP2bjS--B "Qp&Z+ݼ_{U*VzH?(y#rd, [k#* L *PmOp%iH˫\LkבGVVrŲGM(<5 ""c}˽~ 6^mϊ1Ǝ~GҬCro?ʚD0a(WМPH5j閵^BhMcK\hfk¥J]*|(Ag%jv\O@6"]UTxz -_~ ;҅Gk:VW*99/ȋܥT'Ѽhf_qjTl W iۼxW ڦ𗍯=sڣ-аԸw qq=<#uڥ=CPQآ޶|(6V}H?E!"`!K4TBRӈ)<͝4K`u6R1*nBZ1q~ul@_Mkw=?Nӂ_ B)ޖهrPk Fr#f#G H& A8UV'g+\鋰Jw\ܕS;|dCx̛ GfB9ڎ9:T;B} [{=!Oz^'(Ț)Iu+fL@9 7:J[EU ˰q?I;C?Z돏lOBi!2n6J[5zqID:4 ʷs/ҩ3uZx#f>.02rS{Pi 5^u8}٠SKb**g8W:O>Q !)6)^㉄W>q= .J_f[U4ސXbpfmrBe?>F]ҍI"ϼNؐzH1$@iA%H_aOu.'b|.pwYNrI <Yg+4mFAg; p&~[\ڠDw7%_ 3̚kO*t Oj tMQ==GJ0ihmLln>Ƴ eÚp`| q+nvMPx7OKhTTA vG|5rO*^MuT_FX G2끁jpC8TFfyo1aTbX+/ѕ?sbD-+sx:Qcv(«d'ҩ6pDkjEX(xQ^ZJ ޑ%i^exq*htVq ŤtIT q[z6W`e= i5'-9+Y,_k% GXӡA}`*3FtHLk$*"j~С! \2}>Qq *{^7 kzg־λg3gxFNzSek1Q7)PBdzBbS/{k8Z:}U;nb&9fJ+ŔrW^}?)bS@KE1,Y`\ I7 RKNrԂѡ&"j =Q]A: TA(" #.FYZyŘNHOd y]~?qg|YhrBZ^Ǒ1JI\:hq'eJ @K 4uTWt3K97j-wH3lW e@8>2@˭r+tR6# `9#=yתHYUihmu޶x*b~O S^J@=]l,ښe8H.Kwjd13@A2Nn9P jIHaaYwOAuA6h<͊/skmT (CK`PqQvCkHi[$46:z rˈЬ{E8 g-EMM=_:J(n>uB@hHm 9NM&mHT% ƅmoEˍc'1wMj"=Yj(-OB;:ћ櫖 1]g3M_7 uJ Pt}-hmf97 >Pg&c-fN"-ۚԪUY`, bi N4ЛmԌ$@f5L\EhN7a6gP sW _[5J.gx PC̑hEc@g$97h܌f]\GWh'qg >;i =T#Kx=tC Wka Æ]|ӄ f.,q&訹O"֔y^ G^0J4'vCº#7qH0@ +vF3nӹ98n]L :v-”ϐHt̒PRU 9vu0JZ;mty?!9 psMo}iW{5;+!|K}s%pf԰m Go#ocH2i锈Oj_>va шI `P#JV~Mnu-~s1HA"!lk-SF ^ccLW|NÆqF FKxϯʞBf Y *)w4-' `l_ *`i < {gv;xLE<+~CZS^I=T+bLp?6ə_-"ϝU)zn T=JΏhKٹY.I]0'WlwyfAt.K~KTz\Uڭ pcxP]oNM_2VIv+n.whN-vFou:;u繃>ITi&Z%%[c4:YW##zΐzD iN%/Br_NkLXqMs_kVeT@E,Ւ2<9d"]ERk+l@.ͭB1qW'TW[嘊qD:vxH|ɩ@ްŀƜٶ O-A#!lp>6J7*~_¼YZY'bJ}zvCq;A^xBT(|EBvd=2NN˷bƷf@qٚ[&wcXp Cɔl w<,$筴kAŹ*ۆvM>.Ah@@4G[aŻbLn_g0lup} In2X$0fc?Wͳs{ozHŁ첞!ܰx K f%bn2;zFkyߥí,s1֘ew5%a;.jNغ*oW1t,2Qf ,[^]%V876 g>g,/LT!+b+4wǜ_sdV^8?c˭xCQAbs |ߓhPv͢D(;hRWe9^ $ "НS%. *R^V36;+bUw&f%P bӽS5-ƣI $b)A%Ro*$@vѱ x@QM (ӫ]\s6& +Pnv,p0i%l|4-ȗpc+,(4sȢ]voSf =X_o7j:ډJ<]9{%+q-i0iHT&`MY"cKd q=rT_Z}T>֙QglAB[&;q55@S.(t԰&k_%8茡秳nJ#(!1Um)ߥrC zǻTfۘܥkRB&:{!1h/S|.xFҹSPW$HIr'eL:E@ht@n`o) %p?J-M~=aBu$u} '85M_P sN OpY /Zh"9]@: 1^A+S2K@hW/. ߔ1xGe'P= /&ć :m^r0TUsTm>xYf0Q ڿ'25q=c'3(=#@%8kl XU~[ BHpVʞȷIOb1g8Erj7cGYofmh{l>ْPYr#FFe; TSƘE'ׄ!h|4ܿ"$az|*Ao= ETjK=96'jo)oJd:Z%fy8`]\قwVt|;eqq\j:%MlRk᱄Z(j0ޞ]}v= ?YjL[?#p ǞTX1]!_< T~6y.UZN`6y.=J=9vkש&9 eV-꥞s xKKc!xl*ҖE+Y M;Z7 RKOQꛪ.,0[:SЬ$!blCD8JBl/dMŞ)aHġJg[$"ya̝b'Xe'S;J!8jF%BGswIO['A!4%l1&mڏAb1ER&ڋq.j&>8n2~0ΫS8>~Cޡi27 0h$&Uąkװn3ȟ(KKL k5fι/]y ⃩>q{$1)kʾ:D| (\hơu ="=A AŰ)?9ʼn֏ݓʄ+'{u><+uo^`cmIO&9tt RvW l.mA> 6u!r O3SfcdH=q@GŐe#Ъ}Щ5υ;TeIY3a?^܋dPAcy%8%e~)hmv&R(M!oZ K6 ) BkTMϧc)TKt7^I=8uG||>ޏܖ.Ҏvm_(**HzM ']RgJ/L倽;!t:|sKDy{xZ]UÀ=y'_⚐:zQk !|n*`{_b\GM_LOŠ 1K~mV~04z! ׍S [2+U*д1 o ɌA7Z efl$df>8&9=/g R҇^QWA9#s%zA+NuÃUsB Aacե^!)!o,1>KNq Pܐ0M ׃Y}3Im 8;c憼=Ԅgy&K=V8Y2*j^Ku}Zڗ ^(`3U~rnJt\֤7{8oAa{Q>UQ͛ٹq6́Z>?7f:Cn ۩jKf sv&ԗ,0})@4."T\ Ao#Z\f >8Q:% qaZxuuפYSFI̮!KP?zѼ!鑌= m TTjBF6* Iol]Ζa /&Ƒmejtd -PGU3ڮL]v,LcHYjQXKϼ] _ǒ*% y:~ª-ae" )@h:|& R9o a)>`H=WO7+/+(Q Ŝ13 S#t TOX ptDՉv w:lcr" 1Y[Hvk<"Y§+DI\SPfzf5Wo.y F|zej iҘϝ&T$s{;˹c=ޠb(!Noy1L!D[lՓg]/`bWݒ`uluuD~n&SYlc 3 \a`>I29XJ03ʐ.;Пq٢jea=+UEtL.3˜MG)שè]1vZAaϖ6ʱn"łbr@(Gvbke7CtLF=Et)lEӺ1n>cPJ#Ƃi)KJ-8nB(uHHx5gjcZ ƳۿyX_f>N yws-:Li=CDKc -z6~}x2ZRe>sP8qsֲ q5s[Wl]f[ Z}"j" $xNkU l%clJ:nj%Xg/hY v]UTHm8AuTqzC]  > fC~aFE b`ڱySoatr}z$۔229;GM#~&ʚTj&xe"- UPq"dc,m۝qqeF(Xxo묊L!7{id莆< !"ni`oZ|"Aϼr[t1t>Y?kxNJ-Z 34-ɦB 2V"ōXce M1#ͧT/#^[ 1ѣcHD.Ech3e=6o֨ 2;iGlؓX~iۇWvz 8 Ż>4>[޼EaCsNU[ԥ*6$lJ̏%qn% 9yGobG0jqۙeiVH"ֺkaJ"NرOzXJs`w șf +e_鈶~&P9SGټ{6U2dǤT^>tg!z]CL ̎߫LtWܒ 3·@цqxoi#b*N6z֊,+P#4"=Q :r3w`!V zl3(-kܓb7::[u?szSk"U/oZG {zU6*k#Չ ,RqYZj>izt'p$YgqkqmH=sJ!bA ltCy{(] tTl;1{M+қ@N_R E o\ ?kS3T!&2#՛|\: Nx:cM'Z[Q_liʲ'$odp{kk|$yֺ38Xe\mykuDk=YZZV><ӆ\{#KNwx7-E\xbw,#d6jj- DzYO3?v5)gvNop,~<ٛ|Nl0o!ugg1BBSx.q6ÀʅqxEt[7)1Yx#9!,0H"tZumO2afwgR mrn~ Vxmq竑ilE8$ V4uq T50'2_g/og<Гi +}> ~ܹw뼭 ql$FS&\|Tjl.n*E^@+*< br_n9Xo'\՞ |+E t3/D*:-NT6pLӾJsNRsj(cLQ3nr ia!HDt,{R7Sw^XP$Uㄦ.4rp%&qEh0ø[gmқ!Aߋ~˵tijr痭Bc/'T򇉳&:&@MQ Qt=:D'i pD kZ[/FƓNg4Xbvn]if9ܟsNOe qto#avh# }=|0{Q/_r4R(/BB-kZ~xڧmxW d"Mz$cLCWӭۄ{rS{:5 {$0U2Xp5*"\ss(:=xZnA?y.(8ǚ? Q׬z.d29ȇeCV7:ڭU&j3F(1r$Z {Ŧq99Vfݲ9Kо|t&eUeg2/ m4,amE! C ʈs)Yn34Qg%dAlä\9: CehEVGͫSZT'fOUŴ2/!oHA긽1T^/$ dF:rMEdnGH ryR KΕ ŬEpPs |9.pn=s¬GNi2. o(j Z#(rO+Z@)?-0H@g*Hn]L^;b8wyyI=J{5X9X#HT2Z%`YwIeqB o 0~ d5R<Ed+P)^6=PFd&&N㭯,_{&&yaH%HA+˩Xul=IͿ+#}V<+z.iF.?='`BH4Lvy#栛yAބGOQv'q,XiH̞󘩤ZL?CTc.S7ղFUǾT99`8# 46a <Yq*{7QŦ~Z,&Kbxd.Lxg@5qNE}iV],2!ia`!Ja&cE_)eOҖ\-\ OҦl}{淥`|d=o9ԜƽւɡG]_VE-1FKXAo\(wNM-Pc~>E 1ڡ)[,mؖћMj]?C6ݴPw,s~mV9BACgToۨ16m~ Xe<^$<׀ Sz餔6P'_V,*7M>Hfpl0<xΖPeL`e䆲NJ:p&Մ/7P@S8Z#5ٓ$EfkTyஊ7.|lwD^"MtFҩ%,֕uҏ"}ZHGgR''\!LyHm,WӪ9>7%َgF3uQ}0h) r$?`W(Ȝ*z' ^gN>o!i 5os\/mW}`6I^+7Q/+s3+hC v-#gp5[~=#@ZmiI W_ WTݩ~.9pc 8H$&WȣI h)Wm*W LKA(U0}܁G'3Ű%Rr )dxJ_>\ſqs;:[<{ynJ\a:M 5-1n1৉.^:I٠UnqA;;b ״YVD>^J.. F&{9lVϑtk\/4'uϐp? FOȯ[hWӄ y 戕xA)EUލL 1j%iSj43Nk⭣^J'lst{]  ڙ}B YZ$ʐ^eqׂI{ܷ`BTP; qBANHcraIbDZ]*Eѧtbm[]h~ L^Bozr]Ri\HH)A4rwVv &Giy3,i*\CAqBʝsqX0w{_1Gqzdpe85("=CݽQ iB :GG)<t?Nr@Ɉa٭4R 9l͒.ea sF%^qyvvđ"{2 xK)g\/%a bpMFz.E:MNcT3ͼQ3^yk_,*0m7~4q?xڋ3kN8.NJnEתiBN<ٍ>k̃w R*;UGIvT}?h OwH2x5y:HK:?f6 ScvNdyOKDXsrIR^ف.IHwTzVT8#p3d撷ziнTŎ1@rZY mA>CcLX7ئ4/@5HXO-CM՚4Q=>RYe}M~<;4@r\(7lujԞJtcp 01|J>AE6h"oz~o;H=x7Fhw,k[ɃlG&`9PX̟~*Q+CQX=t2ǩ]{̛%"7}<ਵ6j|0gd ,ӗerQrUKi}|KAV!|aah[)1a>:Ӵ%qdݘ 1{$}9w*BDĄ~?Љ:{,䀛+[1ҵr:(54:Gee8(rf<ǞcczOk6{[>Wi'gRO2-"a +*-f dTJPՊ|yĶT)u2g+׈rF4 D}UeK.6)EG^۱-ut48ߍq<ޟ?OJF%O&v +`yOqT|GP[zśb9p^ '#N{1Yš2҆Lߴ)g AU?owaVwU^ 7 Khutim+w~׼ EfXXƎcM\?"#EԐJv*)S\;ǿ")2Nqڐ`*5=V7z:Ou~!(L5;jjw)KiWUOk@ i=dr/_/9q.`ާ܍blWRw'#Fs"}Iޒgn4+^wuzt"(Ht0=| 3)ٝBBŠu DQd4n,y;`Uxk.wA8 f5CXuiBbX,l;+YsI=:3nb<cDgL)ś++L,LVӜs^=Q=% ]nP4Ԥv;?Q1eV%k1k'-FMQ^od: ,=q*=I &vٶmOˋKAe- 潃%9qo Ui"mM>EIsz+uP}5֖F:' ԀC}'!53LI3l&ӂy?x4T _apov ;r,=Yu3)ɲ[2d,a,zzGD2xUPݼ`\ȎFohB3ef 疃 *3?&H;wxK @Omu =ґq?UTωc'[PJ K8f <#|srYH)@o_2y=܄%i k* K`:5L Ҩ<[e)xؕ qPS?(!+pT76zr$a,:Vl0m/l8ѡ, Es)zǷNŌ5=L?>Q ۶QXW4X1ErHCqL%tyK>b>é|[,_PB7_Q@kӋSz\Z&z{$zvtt4p@v}N:7*3eJL>\ϩ`? +buWIͮo2?%ș͔\`g>VB{͙@ʘƗM91`&DWM6 ϲ"L_ bK:[l#`BaeıcPdo>Txe1Icטo~Pz3=W " UjX9.Ԫwb{[N7^Am S;P!]Y/TtW%,h~jJG7XuDg,ODۦD;YteUz+n|9Čpn\gGWpcYC"; 8Tj=Ge"Ա tRz3Ȅ'ZDJ @ahUf]F6i=vm"ctPdO-o~`VS"lEJdBBzJJtla&FOIڕ;Bj6܆' ݤR ׉ jaf7!cPmx:)l#SfЫҧ99G!n }Sw@֣(#W|>~q/5ħWI6KDP'Y14S;˸x~_a-d 03o흣P et<<&F7Kko櫐yq\+'ՖIHիu8ӟxF=qˡg9@}h˝J]j- M#'-_vYt6STE]ޓD2 4LIkeJê`M, NCS _ nBߊnx#$5mj;>XXAGp0FQ〬YGl_/{rsr=dsL"ٮPɐM7w[44rtYD}Dx{>>(B<;5q U>\xQZp$qUR~]HXè3tFáϙgε~pytOX)+`A3bÝR>>-r: 0r0i;t&[|ߍqg2$TЀ2K1ZaD +vsŒ lKxYI8w z^U h:XT`fjҲlp8;1*c)qֹO[Vo~ӎCwVCpH njnJ U&t.f"#bNoH].&F.y9]ġB^x淲E:I^IJ:PF1sFT@Y[iRzWL&J}ރ#tH=QaożwdwK(::F fMۓb3K[Yq_^͑ǧ7P YƌDF-wm厯ă3aV3DLRyU#Zts,tT+("J)X %(=N˫%H!RhykcK-h=0DC| ~/cBrpՌ `Xp"'KK:`yեԍl,}DAo+ $o].NYEx~cI\rv;D(3K% ÅWOL|;ƾgr4V99B6B` Ġ~M^q9,cx%)OՖ}ka QG$$i/Ds'gٴaf4#ޫ.iEQi_O 623GkZ &g5dX1^ 3H7Q +#]up l"24Db;쾓,!PN#u2喫mY23¤$0xn7 f07Khl;{Q(drY/* hweБTE/@vD%8Dm TQc;B2Lѓm3߲]ǖ*ll{oTduWMEQ^AmE<fy#a*6wQaVm޶P;#z='s߬`J%ώz;r= ҹz=[`Të.4]" C40@. X/o 8@RԀRx*ccDj_[+B]zQkV#kocF!2o|T5@EmJR3jW p_2DR5Sjm^& i~N|o_F!6A:o(d ⷖM@n*`Y`͊>ix{g}'|cWn Ϊ%.%a ڋSŢQy8f)· >^R16<*Uɨm p9n;^2,6_HCz8J0(Ј8ďC©*D?tik\hˁҟw!W _(ό,Ɗ)̭<;Sjnm6.$(Ԩ-wS]ʈ|paZH\8iJmfIWl\a 6'U$KgyA z7ۘ'Ui@yOƙhɛh</PKILA4 W6!l(PU;7FC‘ѷR.=8D ihLCU'F5ѓj >ՠ9|9VfTJNt\95!m4cQXoWՐNLM~S< ~<@lKEL,LiNK d#Čv! +iGwB 8NaxOEI+JsZK^{H&#Csg>}3 i`+z~Qui0v%òwȁ7 V}-" DeK&j=yKuͨ|55G7YV' o XowT^(4@vZ˃-2p5c!)h+PzMɁ')Gm pϩX|I=4)IV~ zDᴜwwOvX##S`c{bۑƆ3&+(Vl$IU;8eU1tqx' Ә 鱪.Re#qqkr3 ]` 8ko_M35`=$ $+ rvRwC%{:/˘割c\!_9xT} 8IOU}edo!reWx'6HG-w-Sje)^B6 +)um .V)*\YLSpV4Vx1ms͋LYϤwvw P6U"ڈks (qv ct7 hk&B&CŀK٭nņRTlqyYUkLQ luYW sF6ð %FEr v~UF|N|KyL͟.n# nv&g~slAakh9 BF hUgEv x9N¿!T Ӿ6Ei]LGSc6v dҰS&a:3褛ĕ٭N^:cW٣!sԼjU3eJfȾfMcpCT%)$xeXnГ'~Ju+3G?p&)mPv秮d}(Uٌd k/l~=ۜLF,^``oP9a[R %%x Vg m $I`0@ޜK`l{_\1!Ky DPyY!aIɶm)%Ns$Q)&"0\GvDWPWl`yQh#}L͊.HTҖ |CəOw}^ eI۳ώ,CCl2f`oAO{#c6jUS99[bey*YG>T8m>o^|:nJjG $>f]~UiX*=C(A9D?؜9mȮk@v O;z+%T/m&#bRS -~)1k4ƾl1KˆB8&Y Ck6/lZP<^Fb3u}$=rg@aMOmg(1RWdqSUg!֢Z]P@) ^q 9KEEb oI $^V/=@ɔ03{D=UL2:`N\-6vy $*tѧ-]&uE1BKMɝpҐL$2¥%%gj@04`po!DyIRYCJݙr,/܂R 9lp$)M(By캪<ƌDtIvgCd@ؗǢ \M6"zU= joؘ'SU|05$w? mS=(;AgnാUlaf!sfU֞{q2nbԂQ|Gn`|C<ӃyC+W/ +;j!q3Ɣ.d.6YCij0T^-s|hii[g1:{:8-.3|gntYwY0CQ> ɥ]tqJnz3s;gTPzz^ƥtB'N;f,0G Tx % ͗WA;H_Q-L픪y:X*ўXa:EYu/(+hlV~{;_lVIt}H_#+PT+l 9"7n:h0 2y2poLCV01ָ S>E(MV?!3B~Q{ V=PF@R"<8Q) ܰ~.@T׉AZO8eYk]Y`;ue`z#Txi] "N{O1$I#mGUeb}b4Av )޼Eh|H4 Nw`,bgz"IOBzxwlS7:?h7H S$nM~d=^!1,y Sw|Bzq/jpUIٌE ׹G]HB`Ʋm+4x'Qءz|Gf3W< _`9[ ZWEKP2uL5i ϤB.O-'B :K(v+M$h;AŶr8]Ɍfir_:&%E>CȬc!|p -$zUL=Hz6<ōy.:zaIm'BPHw4,{ tuSn_Q wŠ}JAp2/ W95c.?ʟ¥W8rba(GFP=P81^9O%12O'=.IްVqxi~/޴Y ly$ӗ3*-RCm*ȵ󮻦j2l{G2Aue26z":Y;𹳖pD6Pct#;`qTߊ~8t=غ)x{,(*|=/B;V޺?W,W\V)'O9D%ûRѿhlU'xȧn`ͳ사)8>@vLtJ9}} f2\jGs;kvڕoc);P9+΋Ok]?Ӟ7c;xD,ǿu$I^]dfT8L*A/= ylh-e0isilYn͛]vQK9MK֚A%}[Ӗ!R#wXź9R.eVPy/]<@_MM6\[wQp=k5L m:ۋ >~ %^>ditXC7 Bm.=ȧ;2 W݊pgf $#Aa1ꩀ{N6P7:iÁ_Yb*dwkrzW;NMcL(| mȖ6N]S\p/f9آo-wXzS~|5Oa{p=Ǧpva>dWv)3ArFO&q݇ }>bP,Nok9<,?k réyJҎ;A RP\ndDϑHMT/p.͕9q7m;%bV$,fB~H_5:*LI4SD(+×f^; n ! H/)LKhoތ6'lb,ORPe0q|.3cwXvpM5 ba8uW7R*Q}kp`B>/1y޵cuXb/p7/~I]ˌM>Wnr 'IO&*xgl*)ez fTT¶CwB: 0na6LeFu&TP {Y+jd;02 F~v?Ws8NK{5jN/p\WXu{Vը(®&Ӏ»ܣ@M&)} heˣ!ay%!wjAdI=-nVv 7Ba^Jnpdrq| 4A 5v2B)ka5g,"VWpXOSn[iv芝8)|B53Υ+"EXo=a(ͅCnEDku$_}Q,1gl[^ u&6?̼bGi'v'Rz:"02@Xa?]/ yaA3,ʷ(^"Z$<i#^U3aNB՟z ܈uVDZ,ii+"oJ5IǓevj?fVnn7n` 6*hZ:ǡv]$_wug P 9HW z03n˴c*h.Rѵ(~[]SG:୶Rd{ҾkKC7~*ܕL3OUB d"/麐uJUb=QuѠ:Q4x5#;WAEa,D:ؖZFM (дd}I1~2FEipD\* ;̓GǪƢR,XԨ$UlhȘ1.WTkkNKiJ)3"q̑'܏,pAbTw d՚=_zApz8j|e\t 33U2ҁ>d <{pCT0@oP aUrLV@[1 x[jG{0{P[/\> Ңv nZē֪YXsl,8BS[ǜ)1yɥà+A쳾y\4`Uwjڔ:_#ӑ?nӀUI_|Uj98Uq"Z)K'vj %< aCu9*VKဵ5$T(24NɒT|;D OgőfvC J7R(~7JeU~yi$Z 7MMhRLe EDN/wV#W_c=:6*yw#]Ô zOXѝK%bfdQ~fvuWAu 9r= $>KPr"唼ae}2{D  U|2: V{4 3$!S;:5 Yc}OM&u0ם|n44Ǭ _ok2tvU jCF ns;Y そs1]e0aJsߪGX.Km%g+b)D enm΂Ze%O^痪*;[oakR anN;%GnqLm|~8+ݛg\>t]e$W^@=n(#?!CQ40+>c"YӧA&{v=P6h4A!%-[޷$"Gpg!i19GĎ :sGQbu" 8?^j[H& )5Q#˩,C:o STQiYqPD- A=5)Sʩz~Q/VuJǝʠoF޾m}]7ZGhQ6F%_]Fr&_^%ͅ[I%Εpz[!$ EC"}ͬ;xƚbldžH[܋pNMBųQY3hF1Z BNĊ4⩷pF[arr3ӏ?iVd7I=KX@2y aoU<T :}lx0Oop HD*gĀH]PlEckV]u>]{:P荰9 \a8T0dhԇ MʜB75gfbk3,67 B*c7A-pM"p޳ |!Ǯn>:NPAHve%\9fAg=:w7F},j)_8˿>xah6 +Ur;W3p|UD(̙ǿ !i4Ȁ%osJ)r y%Bx&"Q>1;X~Q[t`2^pM~c&NiJ֤uחB7Q)(i/*"!Z,dI9{Ӛ1 &.vo {W#J.@?:3j 'pSĪ ҸVʲ@KD9_sۆsR~;E:堼~9 wTɌXmTQWUN )y& X)5>P,NTc垫> 9OFH(7!=v<Ҟ %bVmHGYCR-.% 얣f 0Z䩐Hu&D\Hw }-XRťb"mwfY)š4$]̈D'cNN :,N?xYXd#.kz?e lpD&HU vzt6,~C:pw_xMJcliv Y2>Mp,yG$XLn9~cALt 9ө)'ä ;oW>F)KqYoW1:d. !eKqqA\=B9ꨣ.#kٝ`QZ:yfa.FA4un$!؝T5wI*72ya "èE!S/5E+aLsfN4BؼD2'@3tl#53g{҅Upq?1{,ۑ5ڏʡuIH:0WNkp/M C{7}yt͔0ם\SH8RੀvLI>xŮK-Eo|^Twl$!ve2Iջ--Y6-Gn>oq}o*4Zcy ;RN-Pܶxm GkI~ Fy>ghm9 ZyKUBxp2dG0~siy4qT;2ӻ̱qDƏ? *H+&D< CPu6f:y~Pi̎lv YWZIaB-5ɟw/IKt"o?yxB|u}5uf /`4SWD:L~N27Ij6};,f^dg&]$+ ֍f1ӫAq<)U@$Q= "qHa3)ř=vf."@Ȭjĕ7eԙo'푮ؘLadY ζytWONuE'?|ǽ4mVeN[4ad@d^~YN>< #vmV-< ak4.1/q]&ҹϕ F#&~:\46ag^?C q-e2FL8f@"]o:4T:>&OjZ}$+@7N! $,N g;B+b/H$]7?xYVC %c./7~'<୆–[{68T,PhytUwjJj#eGǟP~8#qKR^czh.iPl8#;J {!] gf B7(٥C t_)`ѽB`Ëи{;LR)fr :;z8DuX!JvEݴ*b" .0>Xݸ(+&02E~Z=[#^ƏF kIEbخ0+%h<|$yIs2Lآ&y Mr += ư}Z &6v 6%Lؑ7X]wjݤYF9h?еJby%1DvNLϓ71(l b4hU& H/|F[| MH`=QZͨX ,+K4T- pN<յӼVSI-Vh0M+B%4T|J4aq݋"4H~&j=T8 6&MQu7>, D< "?G9d]%J劬cOֈJ d0T^)sw&;Fp9q8^S8pX짶$k'@.g[ 9$kz(@F(hc;X]tǕW=)GoGJ&nzӓeĠ#A<;܊p0ֲ?=/؂%n(zW$nfowpNt>v U)0AX]гڥ͇g&gfܻQ62輮ǥ]H1v\K_AeyEz21, l6,f;.>m{7F GTr}mB@\tz9>)KShtнE|)9hHAسDUƒ+Β;> K*>o/'>i#á6̨E;m=F~.v|hbevAȷ<,kR@ֹzKbje%,'{d7jhm;`F5 sok PM8)ԜN%J"fHQ6,:A$6qwn[QM\eԘ/\i*f*BhMO"{{x*&ii= Gc4z@&\-!;yG8-z[t;O13uqP*TlnN(upjwGفV%]NQ,,X>ܡ-•X-ۏQDu`XzL)e6zhc>"A~%L5bna_YaqX'ͷU'W8+2%SW3N1+Q {HQ][oCAEX~@+gM,Tک|*N`vj,inI:+&>o75Ǟ&6̣K5a|MCx%@.xk#z`\fP,ү qtmBX~q 'Fkgaa ;۶ (%ϝ9lfD.)0F[JuL0TTRa~H]Y Cxysz99[=-hۥ\$FEP#2SEfmΚr[H3dPw6J7ŘYT% (;7X8bCC^ 5$g,tR1c/y戭fYv#t"m P xAbv,#Z( KYxOu=~x?O y-6LirRd;tѼ9F$HXٰ)r,=ZFU 0hKX2ui *9AnU-HR/ԫyqgU顳~0R-C,lMB::${1b][N{qAFHRgSx!'($LcogZx]4<" Af;!uI;CFšN+% Llr#\ +&|1~ WR:x${Kuroww\n'{,a.ZF~,ߐK8Q [ܙDg9}Y(l|/bru-5G?$R. qXRGCbr('g{yO9 1{ٹ0P@MHemo **-ňOK&n{/J}ɵA&:sa\oڡs1Z@EAKW:`ܡem_vO>;Z9ʷ'0k pͶ!"xn<O}ⰅyQ\Ґ4!|K E]}Bk1T<\ &SV4M-^1r6à 2EG}[Ӻt̋j'pn&,=̶k{ [\F?%~qϟTC7Eq%E#u46Tf0F{4tޭ9-_ww'k%)_4k $8:i>fӣR_tE :oBbmفJh:Jaz\.]vD]5cêZH^ |ʟ0{t4qiBQu?$ @2rtmU /nLofyJo%FrMr2vMQokʜT~7#`'y,Xfoԗ}\pV)#[ ^췭L9b#\mO #W1T'[1I v{oX/H\D!dxLí ॖ'1,~/Vs%lL- Wܼ~ L| n{OC*(opb` E-LO1Q2Ux݌l]:^V O F?} rz0mOK]caIF[鞢2@su5|^kV!޸QTErNZ{Şۡ -)OڅI* 6\QWRza1x.N9{$fm,$G{ v''g::PaG\_HǜO彦֩G0tU7Z:Lm ۆ$Ikn(,yň<֤.~Ԑ`hݙu= 3ReZuL%{ٸ h" bX7a 53[0젊 ek?+S([2^;Þ_%*YSv^<-Y,c~c9EsF0D;#yKCmT7뾺. u[%N0\ Oԫ ?M}DAB` E$9Φ)g BvOug.HY{`jo =~]Ʋ*\%X9腏vCS}+ӼO8z15ȊLB4ǰk@C +yYLZɯ6bӗ'N_c"{^a7Dh;8 yd.{F]~MOۆIj>n& WG"rDNI*)SSٓVϕ9>fvCT/W5g|.ގc&TQ+Ӥ7^5c ) 6fmI)-r%G_௥. Ѹ*Ia_'KQN^ UJgsoѣOJȘ܎Sᓏm'KZ+V6RÂf-X˜EnREgOklOvK*3PQZ4bQ_ZL=健kF9= M gg`(E,JM^0fP?٢+Y1U<h R%Þ_jšng"jc)Z i `u$F.ԫ1™2^XZJ}o]i)h>q$9c=22_!O U/hKwvK!),^8q-ϴH&<t=P5͸"OP ;u9O1daOz8?cocB0K=KuBu9* 8դ1yy)A tUQ%y7Apl<)#A{%Qgt7|QEI )TCs#6X&383TgY:a%-u䐗">GG2SW6M `Ёj-^7z(B%c3{X]J><]a~ g Wсӓ^Lv(1w,'`ZPuwϯcMP>Ķ2y=Udc & .&6BY9iJ!qu7)C=f] MX-6TU<~bxMu]:S}gn8f1Rnbq"!nXLrCv|&<,ٝ=^FU?5tbi1nnm.'hXx6-wE8G &rƣx̣icBBZ~_B2kol5+1qT q)i :g{j)e[,ݘqM)iVN7UTq_aHd`yijFN+\۱Ih?\zlelnnx^Qy!YXq-bsvw?2|&V_SLCLŰ"x}?/ys٬d86+0Kn2<)KN$uS<~n|)1ZFuځ`% s 1;8ʭ]! )yv@"H3;Lۙh3'yQr jI]ra w $vȚ?B `Ti)iR$Jhfh#Q6y,s78E9jH -ob`ξjp:>y mߏҹ{!XPɈ$E2 9yJ-{ĴM:nӯ B*|9N6ղu</U0Ljz8qKg-.e@f씷'YPukTA?ErR;>&c>Ne3BiuGm1>-7ZĪe8z^ {tKRGhn_e*Mp"FѷZL%y+} 90ZU'gTCH盍7 &δUҵE:Rw%X%*Q|1PARP^n0>KĖz,nS"Q;_>J:ee7`Av@)['0Q(Fڮx,\iUF;VyfGC98ZQZt%q}fi(In?_(_FAdJ~'`EHw3JZ!`xlo*Zv$P{8g3:HSWOLU+o u*r~_X;p+Q>g:'ԽCdZ#(d20>Bah 2kz3'{`(CS?~d-aR< Dx$9J,E' Hi!xg_.fm/0s6:e"D*"F#F{IdY:eU-TK_ P {_٭`+xTYgw{c>VK eD]ߑ=nִWWYV2zstRȋe-'Bh)2{P"`HfWpQP;G*I*\y[¯R괅L^Wfz&ڍX9No=p j|H c Wj-;+̷88"ͺC}LEh!v ιu?/8h=OCC\ ­,k :yS%X@SP % P, mj5e_uPpLXBR S̫] &71FjcNϽŲJ 8~K'q~}m(逤neDq-ARyOܜz(2Ÿ9ŪH _&MV4T]bʼZ?cS6tѯ3 5gwE`,ܟf/"襾yrX:']^7ة}b4_m \;Fb}&3v|^qu(H%{S"L7FHo?=>}rrpf)Ba+f8Ix[P-oV0M~m8nFxI 13bB3*g%"^ 0M+' u]b}Aeݾ,S9ϒ9-ET*#3'kpJD&`/gmá4;"7-AW7o0m$V?"E(ͩ؏]:e4[0H~9#B^;t:xA×FWNOÊ2HN-T޹Q4$\ ʼn|xBHά?`7 0ȴ[~h{E[/|ffȻ*T,m[4z+x?sסϡXt;zOԾ $2Jbf<Av+(MCĘ;Df:z|OW3=M)y-nv#\vN? m AheR +qэR?z$kwǡ}=ơwAGy6^ U K B-I[ĺ7b jewo̶aVZ&*87G2k(q9]ϗ 8>+OI"b(t0gà|i9)?ܒu^h&" :p_23o^.ݺtվOtpJew4,k ?݁Ƌ>['7YU샺vp8Fю*aST7Ş.0>(hatÅ*ڮź'^Z\QL^!`{&Zw{ЧsN3!6QX Ix{MD_]~Z hzhU1!*7 6+ڒv4^D xt"#&"XI! 9zɑ@ʹ!Ȝ$p_-oXʮ_ 'rjJg(&lZK]j$ ?Z* ID^E* $8hr̡Oj}Z}F+s,9Hd| a/+!D܂kO^ā5?y(&(Y |ΪhQ\rT&]OD]ܾ-{HET tx,g$H{k׌= KI &|! =}6rڭmig2oluH!?_!3Q6l6VHŏam>ė}3Ks]!;dԦ9UnlW _k;"pZ T9 Tp 8~/oe%} ІqJ{V+Q&= ^ĘZXL)+HGyilog+]ɚ<ڒV]=Lzi=烌hF +F]}N%v2uUwk¡ k!W]b^gG *asW@Jw Ik0ql /hcIF<{;zfO'kPmoo^tl+- s}Ҥ5c\b!~-Bn:PŖڣEcYX=v-ЛUџvɠ繛>G e.BRz@s)6ʜ"Ib3Pځ Z ai ;LBA;\jU4OLNb3Z,>=e$aM6YJ }Lt4O!'WsDXoES=kpC[اw 'Ֆ:~"F{ZpF@;!=6'3b74~.Wy,\X:@O̥G,/'9yU7 o嗉k!nj)p2R`]UHڤveT,֬ؔ1Y-]/%`Xeht~( ,wg8gJ#ѿ[E2=rb|a>@bsBs;lCW"*u]|Ub&椴.c[|WB3®DP7ܺ.OX{U0q( gfՆ>IqSצBYE5hyH$=}m\~=5rHUGOeEH[Ix̾XFD {MvA#{0(O_q*2DZkZ'Oyc .WΈ0e:T/T6v ygy2*y񈵘vA+&šFՀ䙞+&&>I5k5L?#XuG2Zb .׷rĝCkp[BsRC+D[>+_3 `6|z4j8"@yɖ9*m9!A yQaBQJ%_oldx>(l#N5>! DcX)pff4w?bIͼdmV`H#GVjrI얤~&PK+qB}>d;QXt¿b)s5b}@c"6UVPi$^_|kLm~!tSI`L,Twp 7m|Rs@J#743<țzh[t q">۸' odaLr6b@Q:lϲ"Ve'Tv"!k aGeD1X0:hn'2NStE0֟\蝘sjp37* 5H_WjsBϬ5Vʝ.S,Ol,./'gM;GΝ̥p]hܹhzGgEkJ江+Jk%_w|U>BIXԌAXwg /""FT6hЋi)\U;ቾ$f[d<1 4ق`, pV+<{1 h[r;C!A 2lߐdf^ b2ೄ8>?xVvpCcZIB#D`UePy 3.N&Hl5=*4k^<=!WvluSypdcQ,L X@I90/{<Zo&+̱%T@ҧD腆K|)_ݠ||۔>C\oϺݖ۵|Eő|Te/ 凫,`ʗQ-]9L8 <{ \H貋.k"w$cvWmFY/Z9YW_>Iye?f6:!&)tx8FjuKɀf0Ix Z.WrxaF"GďŎM+?]i k\dK8֠Pǣy!zIҶQkq4P!(DOud6>R0/KІh_E$xҤdZ-L'=eJX)oݰREN+D!!fw x1ŒonJ޻LA쒠ttޏ=ܙ'KuБ5n3F]WXP-kO͞kX4`S_AL4X?9Q3\Y4__FJ۶F25X*R1*Y +娎&Ь`HfdF;."*EȄsK Ue5r1lWl)DVR9Jׅ>N{&ZNٖ@+2{l.UJ Cs=pUzEYS|K A.TAN-)-/ӭ&u:p!BiQ}Gd4"Qo4D5@C&8k Gl Ciqqb[Q394{@`{GIm} xHw:,])V ep6[fӳ_)E½0G@ɽ{`&xzsV@ڇ;odgxda_n u5U^ ߈u 2d ` eS佽#(ϻ\I!8%)~֢&(cGsh9)(G9zLAx 0z"B11ٸ_gEfq=l/`m{:x{ e>B9,q4Y\de^EL6r.:_7%92/7nJXilx) ٿFN,p#L 7Z~ʹ 0{񰬇~"ۧ Vl6ΐ֙t9;Uxi*nW ̅m1עxD4"uYsJa2" "O]PFOlagɜ+,hd ~9U(0ҹB0RmǨ2RzɻgƱ {-Xa}f^$y"G/(bcyLh8rp:kH(ɣ`+:' F)`)+}q\Ԉ+ n#xze$c-g)%J-t͙7iAczdlc4mѬN_[/ BԻѰ'.Y6KNMBC?ji;fw3F@Jc6ZM옖%2PE|+̕go7vwS?"+>\g6c+] .0 1ZT ?HV+!h]F4`St"n)$7dfc# YSS=Bȏ/EgG9E :YWgՀ5c+/+Jr{rT]+Kٶu],U#|E]R`b-_.¢> ˨vh1$P\&8*$N]ޡOk(,ݛ p=+WxZUZ@yUkw`;OQwgRh?a)l0@, JQkyYHOLd>jvUJhD##@2b04ӅzoR H *SK-go(4RBjW}%[յ!֚CL&(VX B|6QGTXt5 FTu&A;-h` m.ɺ7.b;Cd}L_~ S!JC9w\p2v'rz 4,SgT &T*7כ?2^~f7ҼܼjQ 76 P\{3Iu}`WjW/"gҍݢ 6; ԖhJlW0dB_>^D1O+Ngz<"xew7mtmnXx}d>+@ h#~8gϝtB3StVkYAMÚ 3Ђu1,5ց&M-2t[\PR "1!f N;Ka'_E&2:&:SɠR&A8f0~\.5Sـ(X 9lWES0HL6'Wu⁹#enw3.Rg!5z+5dEtH±^fyeLd] UqRA+wY"bwhW*`m;5d=Pb m4^h ӱzmA-)ij]~wMl(v`yj"$gw`:$Y.R7FO/-m܊&V85$* p0\;i"H&p*MHZ;5&'S,$yܘ F@\^k18c^ۑ7T6\%ţf.Gݹ;˖nyhM6reޯ@o)T򍔖Ž $jdw 8J:ցvb=4ns,n, //b\}`AbeIdN:WZ@>̊HU*I&maqoR@$Lag̷s1;.0\ՏsK؜VҒ_ WUw/<Nּ[jYF/{l:|^6EXgMwK`"6įa5!8 @@%Gwb:xJ<fiMӃ'"03bv@I6̍av u7dXYB3mS,=D/Q'5I !}5v OYôign:@=U/6kk5<`%@߭sپXqg+:.j0sJsfM# c`]k+Χ)u]v +$B ('*iPK_JDfY+%~9HʥX`~~g)g{^09?_1&шǫF"ueuXK9&r۞,|?v؞r~ L{\Z1'&%-4ry.YgJ2RhwtQ-^+‚gjn:ӁޅP 9YqZDp8 ߱=FCؒ*{+ Qf\`|T5y*9>xF3ɪ~#ӄ L((@Nчl>JL.4 CO4^a'eLev4to鯥Tϐ2HgaA1ԂE4t5e : ^u! BT~Mt%7 9J6%"xAR+! Lcx,{{ģ$OX 2?0 3i`}CDO()R2 027T. L_] PؒS4?=1X>H/Ih7Vb5 ?LKeL3jsqN7 JO5Sv֮8Q<#.W;9)r/TyJFH 蒘+.'soQYW =АoBe;4^{ v~ "L5U6sUVX:^6M`u{Smo Y{UZ:Hu7y9xb! BVkϬia]b,VC/<6u(CwP5h0(#L!*v(<=s-)@rm-*Wv[N4of#M GN>Ei<]c 9P#ӕJZ!Ԣf~6 ,eZT31U!՟[B<muDځw/ X D>Gv] |#zGs .܂˞ASV7ic8ZL:hx*<.!E8ڶи/z2u5Gv642Uu~bŅY(y)}9RKH^.BZ7Z9f7fDJ2QSOHz2u^4ed'Hɨ05&m eyԵՀYBtcw,8H(ܲ*s\61$Z+ԺӠ<$~t?;\Ϋ߰xN%c#\Rtiq {|vTƃv'2c_귰ABESZ4$5 DWłFp T&_.2)|gOKX:dʋХKPp9=)垯mkNm2hY(pldfafώ ]6N$!6xE)Eդ%zف,A?9T'Wp Q/|W1KﮯQe =)&*ƱAU5+T9O0J`o=l=R e̿~JPQ Ai'/ \<ĈP25n۾&2@OsD5/ LaC6{ϥFa}TildEuu?\ :Ǣ?V,'DWiMhٛg[P).Р0CvO[A0aרrࣴ0(3Gq*Pٮb^[E\mI!5 `?E1޵@ܓ3׉E4-`;y6==\}q춇B9h`~ W=Gcӳ9HP */ &jj.IOY3@2 Pt2*668m28MIQo_$-fM2vӆlMה=y!lk`,<z{ c=!1^'G1 (nuY|Ko4װg5۷g˥H(QmpMd$Xq˖1ft*ay;a#NumQ<-4l*HO'.W,v1xފbo%$B_5P`AwpOyՎss~@UC~4'xn`Q"\CqOrH.$E7kI|)FQfͮXg1o64uL\ s|xFJp089k YܦxQ|Ϧqk'7MQJ[g!f@LXǻnjEks6弑7.6=2vweEU.Y)[QP#_X7Y// I>U_-+Ux~4 ʊ.fz1ܣ0|d"$|e6P6)j[uuMM(&/h+J|%^庂^|m9O%VbF,G~L: ! ^AOyNݲ %D" m(oU ? Q ׄFOr$".: `ߝSxU^W0Rd_$ Yvs֜r ꕇ-%A3i4B;&hMu\-Sf2,j;/)GΛkC("DMIJ`YOEGmfqfSnPT@ :F(uM+s"5uުZB B LKB-:>p^b;_vn%UA7H-':ʆDvN#;Q19׈?\R™~_tZyvu)3kU*[$)hHʯ W!FhqIF c&y0 }QK妽Z,ZK-DC* >Dvc-\T`2[Td)|݇?ЃcZݤ•Kڋ_[D2,JKkZ {PRMS@]l) w?c96: |Bm"TGG*0o0d/5*q45nBcxXcB=+onc ?R(Sъt#X<y<Y⨂Db$"/CbV y+W @2?_ l|Oӗ;Ak? PZ%|8hc4,0gN3㴡,_ygOzC l[ 3y8䤎Ln[6{)7 9EJ9b9 C|% 8ܨ"5ݯU]%E@e&lKL7F |mo6GtÜ9 yG o%BʯCcVy^ kY( bKsXm `9XHR ~dBHr`v UQ|m-NPB8׾skTHj;4 O>fX&5r~sdWeV^,Ni0WzQ 4 k΄ GDsoQDkH?_o{hۥNSy({wumj#hWrM #I$#>'2"{* z&Y2iCh"=G{_;U*BUG":orx2)N#jĺ=-) 'r4 xy-l`\ -"c@Mjl7h%1§.r|}IG 4-3>uüw˦ nRvEk"A8#{@_yU͞ʪ ![Oe_ 6%4(A A6z>b+msVuQzI7Wm Ö͒/SjZ *r=Nb2Zվm84Cu1>zmPXpRLߒw"WUsw eT}wf4+>%ߜke?!>[(hd; v ?ػکdz&ܚ?E75-K\b"зz^A]z`NmSFs)%a$/ZfPnGɜgy<])whCʋCc$:8f3p[-Rnmo19Geg/ํA3 Z><'3A2ڤQԭT9^9zxx%GE卯t9π 򗰫7oCM֕$e7E󀺒?*fvV`rsBE-4m3:5:|鿓d!5hͳQQQA~Ip\9c܍Ъ'j^6Q# cQ_ /2#Ӽyjim(ǝ@c,d)㹔ǹޱ?i#=>E% R4W*ojǒ7<6^T7Flu Yp#݃B; M`$b0Uc+p±g` +I lW嵐ҕc⯎a}9[Ya?Ȯ]րe\( s T/:3͵/`5f+?p`]:?B<>|ϟ6N\v.<~ A a (Z 37s=cTg#~DsقjC 9b'6]~ϩZVKl,%{,:v|/j7TLβ )S:=Ra35.pM_F5HA6lЌpX]35WUnGl5Q\9B.$˙XNzdI_yI _V2x_kTkĘ-yږi"' N/w-` <(_y'\@1۹%q%'_ġOccso&in[|T PE$;_Ro ] 8!cd0WEsE52ɽzz@dF J0@9ncy$F za2moؾ 4j< q.`6уpk!G[^|u6FP6zTevNHo NfЮeXփ(^mWAH5Jҁ{=_04!E"c#xe&^gw~*cЭԗ(۠an7wQP~.w>)(pEHYzA-bI,9N&#u8z2Ӂg >CSR 5VeZ͗##Ӛ֏NCixw%V5Ƴ۬Mk1J{jzco >~!ss⿏VΨh|5j=IBs IY%4rHcuW! M&f'{9Ja"5JU_*{w ER>O\%kt {A ֓Chz8/їh9)j<`#n˫JӃ"@(eկXhoU68U!26*5NN$@gI '! $+27O(Y1b禢 lx䭄onS_wʐ =_Mwe[~+S c߾bĺ9g/jgv6[0ǧ-\!URxwj&ys,4uM?\]9˽+\;;2!ޝ&䃽 sxKѬ̎ˎZW5g:E\7EE1B=1Ӑ yV{+$佈^x.tBJ3>Wv?JF+ mg ŭR6.,pilcZcP䣞Ϋc^ym O'U]_S-~- 5hPAL -R-YXhݙdnr $ưWrke#v&R:j+Z>fgj"̇@=ߎ*Gn ;c0Znܙ c *L3_j6݄ n憖cF&{q1fNdFʝI @M56)# d(nW2 va ͉$,ָڞ\QsB#Gh)3qگB]{R-ق`zv\i:ZJЙ\/l ީV`:l<:ԄpKf0K^¥Yc˿ .E0/cTǴ6heɰ l>cG:袍E~Op564$6Nz[Yt$[7ʾӕvJ2.. l(N _Έ!G}jW ,\Я šzn+k1V<]˱&tG   ˬ3G!p˶LV_i,E_n(5%YEN7{2DH~Ux肢!o䜨+zTuv|Z6 N K1XA(P$>tuQ5!{Ձ1wȜ(x;oIW5L!k"xyPك<ڎ3/VlS\x%`zK2=B< ;ҳg2N玂"a)Z5juY2:EXj:O>g"!⢃-i8y;0;@a.'YqqնEe3(.NihQ/B`NX߱6xw! $AAX2]~\}C9KkˬVԉ} (ΌRܗa*_ee?8Jvvu<&٤q]MwUρQ"K/rtIŔ׬x#itCZ,J:IH1(.R.?+] tBa/ԯUxuFU°<^)xա=@ -61ȴ iV(qqjSd=2ջMVz„k5bˁvE`|hgg쳄җf*Ĭw6[`Ѱbq)0bLBhj#,.]@*L7=k-mCPK9dކJyE^*% <ԇ ~h2BڱOR>(LSյ/ J)|((iZȅd8fQ&~.l5[cӔd,]F@!OM7sQ<9rbU/rUR(s҆|?a" o7PGtⶰհGkxc.%uҾ"(ib$-@T@YNC P{|]V:ytȄӦ*ޗ`)<>@mzSy`1NJyri-G (lB,-.OX8HNu @=_(^ϝvpQf;60)?K^1 iI;!g+{C+dMk@jPVY_AFe,`YCu0QWBBZS>+AΓ~gC5T<[ymNV^ɾ%ޡ=c?h"Fӱl;K9dD{h+["SG^k k;6IZhm8K*ʯb5*xJr[ m!"emm"nIya*rҾn$Z4_P얂"T 0WZf )[bzʘ7rM-aOJۭS'^DJTv)/{3eP մjAe#3 $&#y*YIb3e}5ynp [ΖLS`Zl]nT,bm3oӝZEgM uz  3GB{rw&-Ti-{U5d f B*pes\hS Ӧtiyq/D 1Y٤1T`w*j&H*Ԫa <_j!Rp]>sZQdNEx\_Zßg@`@ء 7>W ^ Nt]494zCv(߂ݪ&2$4|vp:}N©JE=cPaHX~[HKnփNY$|t&3P? cmЯrB;SNR#&r gX"KPޛc$ 3(/ۘ`H_a v@,~H5m\7PprqjFB)b1/GSouc}l􄹳RoLS}TjEaR|~~+zV=z*]"TOs 3E| ji1u0BoA,'q/,J @,TId뀦4ha,tc{5Sca}2݈ηL[T.FuHC7;\T>t04nuvq,R>H$lDxee^T[֜LH%zC.>/AsӮi:_ؘٝDtl+>N#?o-QckdetxS KoVTk 8t"ŀ\^dc?K-@6,̽tCWXw5xk|g؝^seD$˿ٌ!iy5f*ZkOLN>uܠo9ZqJ wҊ|M.-lKiTbI̖蜱sZ}v\<%:N`㛉@q 3ydk=0,+#$r]IDq, hhv DV/ N(sڞ{*U%*J.!lYhft.p0qn`>%;1w떚&ܲM1@4ցUyj.<=S]| 8+,y.c>b#r:)"5s.?ibow#}\h]1.Q?61pT)^zd:Cdu%XF)ctL&.k͕a˚DW,8࿴ʼq5lJy|wύDX|moq%m8gʺ%[u;i%fMeR2- iیK"ٝp/{u2Q(UL RD{y|M؊z;ӻKe(Fd1%#>|ir{J?_<8sļ9ݏ2%#f͈嵔*.ĝ,vm]1YB*-J7Ǒª}'Xgu\3VYY[~Pu{5ǡf*ҞN?,£c|/drh/DN=5_Y8+ᣙ^  @/hk[833MbeAsҤ#ry)pE7g_a/@5?zŎs Nxm{,5M9{fgu}BFW"`.hJۢЍ9#ORKV cRc xa'sEf,e:o&)۩D9s}A.kq6]7!$&~+{JRa+yX+)ҷנuVCJG%CKBb>-& D29ɏan&# hgZk3FRsM ^p5~z D*f{ m6:W/B28IxOU bMy{`]5&E)f6宣/LZhr]%ƛ%L/OC Ly8IE$r> ow>G4N1]'^n[f CٚBs6g4La$~U4gʘ~|{(l9$A 3!7wIVH_2fA QssrS.&~~"=P<'vψ?^'lrDA~w>3 s/V)͌GQ0S̎th=;Vr*Enλh/_2lRq@Mc}=j@\8d=ߜ&f3j9lp. )7bWa pZz¦ d|(Ѡ&x#uY[ҜrGS[Bc=oag,=X+q BD!C| Rkb_PQ?CbJ'`YXOnHAy nǢEӫθ_Nrء8%D67r .ނ A*Wf Vb)5ӂ-Xq(n.r3edHWtU%n1nՊ$!JE$G1OD^ޙt5$#w% E'ȿPbZINJ(sVyl>s)Zci]7od,*'VaHT𧢏ڶ rgE*6ΟGIjF?&>bE;_2:ZqD`40A{3CΉ-uKkm6N.Lm1Vp܎;*/.4@{ A|Y0`F=EUMW#+T^:{ va ˏJκ`]~MuTΥgDȃ7GeDw.wiSdH /Gw24&K4NlwЍ e Z{Ig->' ͡%bBBˑGZnJ'6V{;u\$74LF 0)pN<΄M) ?a Fvڗ}JBn s43/qS#␸&USv .vZΛЮk-$12%酚gcm= .N{ӄ2ȇn/ϭ{ ry]U$QUXy=#i7A7S3-Z-;S՝%hM)-!P9Sǟk7G ]lсlESQMzx#CN~?+Lxc&;fӽyusweoA{]hBV>FN OWH)>Gkw~%.C`u_F5P Roqv[iv0j5/:5R%՘U0QQr3U$N.okָ<* ۋQs:j(LqgKb6L\uLHAqe2()VijErΙ5؎!ħY[,21/Z*u[>Am{(g!ӯ`Bv3`T t0L!NFŻE3;\Y]!ǬbfmNS,DXLX3(_:z=55=-¨(?tT+ʢ ZY5AMpٜdQnI7i7mA==},v; 3o/غLoi8FPyvt%Tn1\ 04;Ŋ:ÍO9ntQs-P r~,FDŽ.|?!rUMlu L܊9ai䓶-7OLy-2W%.FH;U*䠰b7qt:jM4:RE~K|J2U燄P;X(7>% ȿP4x|~N%ٶy\bP lr{%u?QNmnJ=bsDX\C}! D|c8  VĹeH8`zJue{hss߫o"f=` ` KXU5o!#4Yd#||9ς$eN8_۲EϜ i60Ku5_q(,/e;pZG֖xBgrLuXF'M}@{& ԛI\1a}ZezR''T$5xHWOGvyDI4|H1ۤ0kŁ7UyDbMlv:zibAqZrk1jE+0/*L+r6E*z1?+랂ۘ05EǬyD>U,Tl>쇊&"f_dua 2+x_ G?T9鰮Tβ.B3l-R R$br[]6؜4N<݁.Cf^.%or Z./').sycyX&{ՀjINm2`Ծ4Ў+i>+w|DT4 @ 8ז\lɵFgTH7i ;VBIz!.OcM3]i~ʠ0=y^A "N\~fqt4YREFT߆0©& ) 7jN;AZG7~?[V B+ьxt~02-;f3;ҏSĪ !VnّAY#Zׂ<lKVHjΣ2?*b>ehUX#::{UORC1.i~|S?z2D+' tƵc%攠@iOZJ7Eu q0w41CK3Xp㯢#WrLbk勵2- 94;!Ng7?F`oT1- 8׮E3ybT,,fC9)]nu桊Y6ؒkM0@J@pQ@@}Obr2`Jc-"W!_9_O%7 5ccg+S)!f|tLw;3ӢĉyDcGYZl,N)mO-q&8>KEqNU @Qb_v(. :Q1EbB&1T0Y͗&ANYp4 JyM*,Qy+d/^hhf"/[❣٣YmnUAi5\<t4te+1\`)! O߭ehij$6jK8@~Է%AUr3 -S힐|'tڝ ؇Ў$=lz7-wmL.H)lIC8HB:{yܴA%p#ud ||Z7Q ֽho !.\WVf gJŪRgؿ?p n)w+i.)gKp77;NdYQU5,,@MɄݿ/ᓢ=ʇu}J+S]Hg ^Pޕ_!J$w?,|g=#I;ufke$88-XWW/FtULQOH6 5c5ADѼJ -z[WpI`V٭?I&@j{?_FOOW_p!\/`2QϝШ}<\xUX orD[7qWDW=k 5I#Dԟv)/V[n= 7̔Pdb8yL(5OXN&̚y_: tOs8VsS Fj^Ql'ܗmM`F_Y2-Íp>|{6C@ڻچnX=jZ! uΈsg"\cb0ˁ)wBȻ2|4ܒnlӥ>YKM^vH+=l^ #PYh"!]Iu%r> xtFz&>OW+sjM;*^DB$qcxiIhcJl% LKYިφu"&L%i1)ui͑ԵRt2,GtE&fyL" &_NFf_$2'&,P<;2ayn`{JueSa;8*`w/M5me(+]u>h'Z{ʹDfd ^y4 'H 9JX86\7<3 ?$z⍸B(YLyl| t0)Pjfb'5OM3gN^l/:=QZD^@pbr-tka xc͊LS;?~?ŋ6<8`}$0?1UyX-]]ޞW/J+\a\㑵S'q1w5- D y|rmxE"IK;3j!$2kTK{'0)`^&VGɵH2:ƘJYT@U5`&޺v/܇UEO[W8K:qO撈ϡ*b Q歵YcFEBhP2kmAZf7w԰/פ|fvSZ'˩ԫW$Lb2:fmLSZM4HV \ضq=5<_?DvFT߽`"KcJXs;Jgd$AV T o&LẆ"eKolLe ƦyMro3ECwKX{cK94۽vq'qq%7bT1/MTbK3c܂VhtupmGndk&[R^,.*:}^B?*V)|F6ϛh?e%X6MȔ+g9e~d0E0&b@ ˜t9ڣN,/wia&m<1:u7VѰ#b}݌Ifbxcz'KU|A^YNcŸH>afMK7 p%\J}[5P7S*A:\ "o +f{ Fx~G}_y|Οo΀o"ΜEۤ W8=h 6dc4 GeqV#^y4j1QuCIS-~ü 7bܻ| ˳"yi4GvN?9ѹWxk?EԐJ7E2[v4W kHqp"3֢+ p̘O.& ThC,gN>=G$U=Vg~CVTJZ9QF|0U#U6i@zY=C'(6 2Gx " j@q7f2)T[oLn n̨Y41;xei1V!Mo788t{ wDANΑ63a8Іb};K@ L+Z8ϝ{=WOӡ-7^%H;}r"7>{ݼs9NJ!\sGF'sonqUAM~64?-Qfs G\%~H%۶%Njܑ5WBPeY23 T|#mh'B]q*) cà #NbkV3wT|'_2-.gف_;f['G)YT\N?h`@u ?d9Aʮwɋf"ڲ{r>O;MS\/XjZ d{[Novuh$v_ry:Z LPzSq˘ h۬uo'^+`Y5.)9(e{YL~cw&CF8DuW[okN_MMڃ+S.s _?8qY((an'=mmd C' Á, 5T?\ ;~*`u|Z@.4gy^*6Aك,"GY^Uou7uLm2NJNC[t]['˥,eCSŽRn|-o67iIFSC0z帙8[$S)$^6ʊopZjRzNpӷ㴌 E \1*|rq}Y{HWA/oزGtqtiǪ .;Hk$I.eJ+)R,),7`scQ ,bC䋞f_3N\Rq:}t(YNʹK š p͋:|w 1*YI1LM߈cGY:G|M%un@YZ +xtӚݩ^N 9gyI:{g#:lKў 8ornZNY%c[OܹW%W#?4iz=ҭ ]㲈$9,eݡ8"Jx_ezC I}"@D6AN[7@Eg *UR4;y' TM Ӭ@-r` R"v1lw6P@fX_IS5`.%haALc%ّAi:т+u?1y9T˔ͤ@s@i?NOp(/Y<=/.;vFBڧm8:Er9⥉&zCk gtd~UĜ,raDDĭue/щ19kST] ul6#R ݌Jglw@BQ^e'ҟ<,;ދzo`k}rϟnTpb>]4K@eta/bv!„9 = `Y#?[3vD&M,~%=MG=&L z?|]i!d;DݑOYowa*(4OGo_>GqToA4A1F'f93G\/ ͑upꦤwMoF75# Y2IEѺNp-)`ݞP`R:(U!O[oteI99eA? Rql[ N%ŷbOkWǐ'X7>osz⌁]SUrL'V(51R"*k ib jv+|*fSdhPw k 5c߼KxBĔ$:BqϾޖgo&?U3RGzG+^B9|CA$dl!2'?8R~ƥ y-y]H<}LG XI{_ T3f-)r?M5"qhf6nV7c]>z0C6ֹ01c}!o$@ӭ_!PNO[;'ӮʘxwDi9gi 3tIcA{gg JBcW5+]=A.unGW )YzU8w5Z.ˇQ ?C,Tq,Fu?aʔ $P4QQ-(HQۣ:?8D~Zqb=QGa4ў[c=>Ӡ6 Ip(W)b~lTIDxv&J^?jQ583AEZ"i;@\pv?(g;Wl%*,Hoƕ +|Sg\ Ms`zCNVU^NV O q2#[e޶.Ba=8$mG2""_={6-6vC@2 Pladq-;5~Pc׽#}G$nx!W$0 j@2rm\Q."D @=MӰ^=iӖiSO P8F,YƇ.R#*l[E=Ȩ,p|VzWOcވ@r)k;;69RgTyR ȭ ͛DwY@0?(U(EGlЀ'`X$cXUNϡ|NDC@`@X0BEoX݉vpsR?S kv%Q)gESqJ=<IVq)⻄ 07'M`Q7gXQJwT/ itL#( 1vV ?7idxtRg'=F䛎ǹ*ƒ^VVC:oH7ŮbL,IaGN<Dz&}V?3 r2 $-\8]k< ߆:O;4;|ᇭSq412۟N^Ce eՠa+*v@blUilr`JN 1:Τ vYL"$ptG)_eOG"ǣ-Z4PX82c;BX+>Ρvw9]f.P'&`;,C ||wqZM7J%w9+^HTM H5@9<:7 cʕP_* Sbq i}$ecy SŖu@AIHk C ;1 ܆t:ЪT#Gbu͈'̈́;J%.NɹAUp̆Q~O@ɣM*~f@TP6M?Ca^xjS!-'˃^87KeX3D^i<JG#$ ˊ7bZd­.iƛQt ?_3&8H6^N*'~k;$̮pQ@Lـ2CyI)z/7ҧ*XQBMph~SLA[d Dxn3N6=@N]f\۔j"0 V z+?Eޯi"-/Tz"jK숿R%cqSye<ʘx(N0E64d3"SW<ߖsKBI'i玥K5Ge6.GI.yϷp})Xid)H%Ns="iіsW5917b(Q*L+8GPi}buwlפ b8& Ca2?Mj-UɃbҙfľ>#4_:.zLξanu.2L67 %K b|WP ΄jKoDſ' k{F/$^HwnZD10Ab:WYV1@:5ZƎeT~c(lno?<\7 Knd_(B0oL z|}vM;$@a/{tJP^ڗy_9R`3d:QYbl^te4MԡT3"ȅfI6aS~me~J $o H$H~%m.m60&Ĝ^p᜛l9 +\fљN CGj-Tk"]zߘiGDzܱpZG=RM W6d∟[e$W(\}w lE0/f# L7TDw@Z(GR\'?ʍH<d?V~#k3^vn5Ho`9(}k)B I>qr\hX/2`XAՃe!}n?ӱ %&bwk-5 i9ҫQҵžʸHθ2&]Ǻ֏vqC{C5{Up> QㆅG_:zx Z=)n89Ѱ}l%:Pbх#~+ 3aw#YŜQ<+˞L"F4њ_yn,`K#qᲉA$1[?yTrk >2Aeţ[VA;xԍW2/!ku%x_TZ?}svZɝ9a2z+?7]+\&-4dY5VhBv60zr+p4㤑3gE,&Ze}gIuzQh&U7V%k1s`?U_ 3#glPgS(GۥSoh[MskuN%/欫Q':7Њ21VwQ? NC c6~ipR"<ƿiWժC]1Z  z׭)hwr:'S =HD0a* ^mVQyؼ~(}f|d&YyxBsO¨`ZܠJY.eC:25i""2E:zA@ŵ4g}/Ԉ#Va\j֗[_do>o<)翳1wkJqy&8Q((gXߘ0'Qb( nv3uTg-0 ي ߬ b\|iBgЙz*MQQXML?F wC({H6U :Ta`Տ˫׋@x&qO@W?Xesɋ R9 w5P25~˃0ws'ճ_8y {޵0eL&%V je ?C]>fP! ,"whl:I-*WBukVg8 5c,~|B܁ֲ8t|U먏= >tKRCj6?52iy\]ɊaÜU[K窨ܯK{nBw}}$+_ z$ >#Bo0%@?@.ZG?k=zU;PFD71 LQR•/!>s {z|&{! Ľ|??\xtBgnܞ<#Y0zS#,>Wf%}4J+'ߥJnssANoC^%öȂ>jӄNZb"oNN9ߊQe. \pŇr $7 l u9:V~rFLԀ`O<Bx*A<+zAK43O_vu-&r͎ lE{)&I3u[ ?pȉrBD@q3ҹB@eF#4*M.… i\䖋kXJlpa"3Ŵ~ÿ6$0#4D⛝;Uh..@Uݺp*dr* J6ߎ:f.`|<<O*YLȃvNFt[k9=[bq>CZLrdZ}ȚxocDDLDDB-LB)9t% }+%u%7Ybg0b:YшvjEH* KvU(Y楴^ p}ca/Vk[jgIJI._UʎYEVr,Kޭx(M}fV,H`?7@r7MLCMqF]Ķ?&-oZpT{C{W[DG03Dj Ÿ 9z)f 'mi=f649XoИh=ק4ASÑDC6 b={恼%ƃEEV'j :\ _ | 17.n<֐eArit Ci5 9%Az8=qẗd7{p 'KMX;nSm Z;投\+3t!xr] 99hZ"f%*SoIk/}7Fij Iξwmxߏտ]G>0nmX%i$'0S< f&h[Qk~!MmU3/>5Qb2΋LB^RWuT5hc^o6BG%~a 3ho\u~g". %u't9bS$ǖS}E 5 ޠ׎!-4[b{$딭#D)DB$,#RRqs'tl@5j. Ճ]fQȏ[lbQF)ؠ7Gw~,6۽!2'#D PpbuL&2`/OK:؊ |yjrz|2DTJV&[g^W 3i:j=$`|x\M?7.ͤ[FoĞӠZ lwKsJ:IrU<|)H‰ꆒAJ&@ eFOҸ\ji]Ϣä0쵶RXvtċPi;|OD)g-kmqEZ4l8?@b1*>d}Ҙ>]#I%_,F̃cf-.HU֪I:\D !%-\"Y6_N դ P{p?j-Z+= )I5 %K%HFXuqL+ɧA?WӭU>JNhߵs_ȌR?XPfo &If捖p 2ׯeh\r`!xh)wb PVWH`1ftgj Y_vDHD9[TDe2ޏu y=Hf^'۔WkA/\t_@"ߠR3QjΓ83[cdF%tXɿC`uod.x-n1*X!tƒ%.q~xo!c9U_X@dؠzS֋bC\)X@s7|=r0("sZ@/4ip#BD󮬃@ *F%^ M< $ěO#1ηčVY"")ÖT_RpetW'qH !-rB BjV!jl"ۀ[E5X y/O3}=lfK}+tnPM:=(V [,hm;-@*CO("⇗蛃Ej])޴:!Vgher۱KH9FמwS;( 2 ؂59nᥰ >(mI1QHTyUz|s)1d'?(JIFmDx'GSM2%ciѠ':3@ /བ9X&FͩsnhTȳ1ɥxtLX*ǹ ^0V`52g?K8;=nSî/ HF4_.g'0HyNR0kU7txx!" »&E76'Q<ɞ4ؼ|FzɵklΓڰz*\6J 55أk030`O߁PF }q*V[qϴBR)0f>X+hR5NTQ ,ڡ~Z3r:6Zt~$?Nƀe)v+vh%Mhg)\ƱU)!3qLo36nL}8 y$oホ1.M5?ф0=ǏXmƦ(ݙ%+@2?/8}%6qPT2)%&F6?ߡhe_g2iG(BOܕuun"ٚ{XZ- k$J6`6>BN?ޖS. }]<sAH-L=LWC#1DߖiJ >it+:%|VKd @i;ẨăĪI(^ZGUq O_4E['-EV,nQu?]; hY׉hvtS[( W~!,1 GVݗC@ , ' #$ȆM٢ ƨl1)ۚ>L|Mf \ϼ^uRӐx=j&+wޔdml ^mv? +Hyѫ%yd<%53 Ǯy> ^ V,y\03fW2 ]jSB m2k5aqC '98KrVQ/gjR j8UTMUNrh@h`0`@ }2B.*]4ZsךbgC[&I: qr[#5 HuUPLTg^7‰1ߘ`\H`˖k -8 1]F 9V0*W90#m=r+%3+}~و 6mNtNg"X W)[a =( }0,$cs:G2g*yZܕ5:2M)KP/)HT>IQ[ePP$'k9U>H(}5xK1O}5e]Ɲ$/Cqʅ>lP}3,~b$w‡A~ႌ b "l@OLU iE1 %Ն"\Y(\bQCJJjTb:pyA !L䮀2&r9p!b9Rd["A|CO(?PăB3~ 5_W :#7:ddS١\/3r3/fU؝Bz$z<}dԟ"b{fҍJ;3*f:bݭ: fB+87IwLC8p6Gr`-[]HPKqhU(aP|bSQ4~~Sҟ/n:o 8]3ʅڃ;ّ^0e;,C=P& Ԑ.EH-'^M2,Gkqg:lIO|1;H@5\0}y(j`xt9ZEf5`"SАW*|͕=n=aOEƟ |$-EXG,1<;+nLtEyC3Ȳi&l~dI^28fB^Og n qA%lT/@\ )$Tb~ %,*f=+6)ثVg&YzNJ =~$hm q}_tNnEq.Mr8tê2(@.a,[9xEQ̚Z4hGǩ2*,)gT"|B#ѱ&4_o,w=Wi㺪41lbYqGd542[lJ/l=^!7Ʉ1{tax b!%y&qdH8IL[t9/UʧtGLq#k:dsJ\d(ndw|+6O|xV.e b,,6ņ#Ke/FԬ%$'g|,VdEૐgl *;,Um:rW.x?3Mi0'8Cz1[F+@Q?rlkno?ڍi"#QR v |5G|]gۚQyx(g S*oCMtmW:CҶH}S&Q$Xދ׬OFTyxS 7݈u "zYURkuϽȆ_pDw &)8S@,.&vY+#Q1JL* C+AK <~O7j.qefYDȱ NRFV }U1Ù1tlgu<]YsZ ?Xrą:n\=W^;5abH߉fsvgĂ>qL꬐<.F-x!Gt<83YEPM>' CUyY$}3 %uڲ ̩`>v38BTQl)ja"~#;h?,!@ t!V{,ycs7E"f66>/d1$I]FP?>9-i'hA1%pV5M}T jȸh6K+Ie5?8L{oPj#0,;7X$n  gX] cf*YCYS c\/BnG(hG}hE#03?t}7K(;PGAp⾏ 3Q,hCcK*[hލN|L`0 S.`º@)+7v"x]ٲELtdl 7GWan]v/.@8x`FG@D"p̈xA5 A!;dmC HgоdxTfd@SӷBp mez-D ?m&wk9Dk|Cʿ[O]2ATa$_3F #߂[ƚ[u;a(>Ẽncuiu+eT^R9k[KH&֡U$VX9\KDpC&As_sUi=!Xŕ?C؞Fמ ?T{aDƔVGv e`~U5دexT i̳ M, nBxR%WQ`NN~NG΀Awwp6'U.T6] qkL3C?b?LF:|)-oeHؑ"6sAXv髏[ޭ!dT5ϖpjgȍpOSմ36zNscMƍdA ykfc\ɡb d(g0V|3 F1(&Ғ Ʉ<'FQras|b-KqpP tH d>I=|2ivwLBl:鞥BYE$E }I/oئUIΓK$sR)>pXf˔GM ; N,_⧻W`-#jSnҙlaxLU>Kr"CHZcs}FRX(Yסv9%gr}Gk#%?۳VW2!^ 3tnnC-JҬ,g4xU;K8*AղN734&`|rح#H0u1.$eZLg^2utLOąrM"uq!G+Z#+U`?:)ںÒG)l]rN :ίZ=ZA=Ҁ9Wk@'yjW䐯̢Hja һ1,Aixn^_qeNTⱧKhBSѻ%$ }aT9[+/_6XnX,,+W=v4~vŅu֟-bͭEO(,ȈL,'-K׊RHqolVߛG>Gdjfʶ$~^n@r+^wRCʑ B)q/&d7<;%p|nOΘػ6IF>9WXwsl{F탘ȵȧ۶dm{ L&Y˫b0ϧzŽ;XG+Y\mcn=-пj5\[@Sz(E`X9@XLb@5\}͑%&A%& m^X*bskjۦJ1xa~ b[Z lσ=?Yw>C9꒧ߺde5fhzD⤛`y jڨuI0Gisҩ\R$g$g)yM~QaPoL>\3qR{DG>)G)&9$(2DnO+T4,k~d94FGIE?,kmHƦ _g^Y_Ұcqc=vZP;nD4{G [M*p`M7ſCN$SSDVǻ@9\)ӕԧujԵ"x<1"vKih݊r&EŇ![fٳg\{ 2L+1*\!z&G9Jݔ-rӪ,2|Ġe7p33yfn&_ 91?5(ܬ.Omm7o%f9I"eWﭢ9na~U.k FXt%jԂxA8{.l?q5Sf/űTHT#^ذw+%N[1Y(%3Mqof$,n9ތfXE|V@?,ь4))3۪T&@w@\QVrj QʆrB9gd@2JsUgnVTM'jP ܂M4 Z.74xxʀ%iFR|Χri7)1f =Fg|&tbzF;8ȚBܡw[JT  [`p+tN&euRvRwBipZamqhqH]jy=d" ^ONAp+"/, A>CIolS )bvk_GoI*r) b=&25jQx[%.b]Zt߅,OXBM{yJ.S;xBر4[ [J4(hQ1ƣB >_Ր"<\5}=Us,AlcDz ]Ù| %oLx،9SIЃpE{s-Z-k%yw(Ú(x :: rjNy|}Eh0؝8˶T\ GBm Q[9^`u˅;'srVY4{ْtUڗl\c)-rdD?;Ξd-DŽj;/R2xKĀ?j`zH#C0HD:>D o3^?F]Th9C/ܾ 8֫o+ɬ/L-6,SG2[] Yoz\–F&䢙o㒖i9`֬m17,(q(> z01uSLoK2rcP/rwܷءaWVz2/,ͷQM!_{s{mRvM_#ŵfVdSuq 6#}56` qtLGsz.̢=azn"'P(MT*ˬ/{+q`ȩ~:o/ba4h,YD40ב>H5 ȃk\|H0LZ>ýĠ]cXP^}lX\;(2v "rk)][}zL_kV!k4Nna@%.xX)bۊydk:@RMq\'xeC\ZQE!c`II Z\Հ(#y&׋Uj BmqaI8=D-=H1Hꋇ>շ- ))GX@WTwv%҈wYgOS:]gkBٳV62.}r,߽ CUa~#ͅfe4U/W Ii=Y#4y1e:&Fk\F-]pB{םEi-v('1-nfTC$F %1#~7uK|#MXhzWgGd7;okR@(@c_.GU,g˔e`OuH=ɖ2wie\=ApզJ@9C tfe `2mݿ*#N< @q *h (Ft@11zv(6TjCXIMӕ;n3Ab!;-Nj %d9%I7ޛy/]7ݲ (ANyF#7uHHoL,'N74њb'?xd.ϲ2İ5j{l%Γ S09DCXNQF[8㣉"fcLo#prix߳q.~ ٵq=*:e;1LqcYW~FF]BNL q;M5z2*ؾKs{M(n<,Ϫ8iYTULsB+Y+"Gh3\ ѱ;/$\n#(E=Ka`@MɆw y~mnW7(6rv ߇Lۺw@mKUeSFf/Q2]<{ uohD{ߣ8wƴ)>O>/tJCQGvc5 "cm֕Z|&sـk<};1n l;99Q0ž$.~Vje+KyshВxSo] ł'~dd߅( BnjWu j'vգZp}Hx ޏs{1Fy55ׯl)NmD! -zhw>fb@JAS:' 5]@ z ,ZA K!͘H}9kO2F _GxQS4vMYKi`K8.&Z?b}(U gWfi2LU^ VPO$NG ::P+JH`T8xábg9h#ztlTfT; Wmh/T>^Q"amu:l'Sȵl"ID;6۬zQѐD˚Xm'_\*1m$.G>߈1V ca  *TMjh5#Q>xEĤ:y@&"h19>?J91&QaH`_n+NJg6!R\7EY?dKs#1EѨU~rVYyEʓ:Cĭ0~|p:]U<8RĹBݭqv=CҚotI >^lĀ.YNҁElI/t|AGx1~~)o&pټxA4`'WBE-6$W4ۣqȾ!HQ$H:lD8[דe0f29dI&ҡ]J8Vcfæ:?+jPMèeXa ' XQ F~ݹ{)huxlMZ^Jښc3inYNP5Np[MqW[?U}GF02~F.4f|ӏ5Հ sο!pږUӃZ3!քFno"6Tyk3_;OE˾Mr-e`P^0%غ#v3D 8GrxX#oZ8XQ4p M6,ح 1~]M ҂L^= ͸[衞sBW;; ب7.b,_-r?'JUB?_Sk:y fV+\PH#GW e[]eQ,Ҭ@)VN^V. a":>@qAj)gFח4?ߟyI MZ Qa^,H"RV:=*_S؏)\p*U+%@P :3Ah3vpMj\^Ԟet>7S<>P&በ&­~tfW1IB'5>u U +^GvN߹|ʌ0XFij.Eԡǂq7c9MMwor[l GogImd .禄' %I! N~O:N oqQx`5U^Dq }')8YڬRN|ڻ\<ƊlCi0$ct*ϋ- #d憑-kþʷEO`3DQGƆ:RR|۵5<6{+*[J)ꓓkAWXF+I}be=ƥ" iU iP[)ss+w*뜜'HH̊ȩ@瞡_Oyvn]ѐt͍&T.@ê0?}8Ot-rVJ qYUp};Gmלc3'1چ 3 ?zW⻇FyN jrԌusㅗTVvʔ>^q4]Ox~҃n%̵|m sB9YRFw(rZ7ID/m( :["O%6kΟs (\1[훓IE:y֔*T?U y^astNNvvokf{I15p҆Qf >3>uUkD+?@M}EK Ā ,WL>h~-٥Z6%ңb8hRjf+B/~є^$hѮ#6Na;T,LIʞ4ӿM. `hUj2-qvq$ D֏T&l O1?dKتo9x)hd=W4Qwd5VEiq7Js IaDMvꜶVH=pw#2dygYnݏoσ^w}S*R^}*Ji2L;PQܒD7?c#$C;sP2 .P)eH0G8}n%,] $`BS1@8!TP8kԑ E6Fre'VK Pk d(E405}f:_ XW_ylfPQCIro\ !X,Ay\J8Dn6*"= 6+&v]ygB3՞_GDYE"-?fJ(Z} z^AtPsIxGJIժ18>lD4K1u6ls?rӬ!F;~fK| mHnm!n ?:=EO -u⍭f 'W̲}}H{,8ŌdlɺR2Z0EF֮C={%M+ &/iqkES_[6MZv,¢ySrK@fǔM5'N'?$= cR &IQ9cL Ee'ZԻM~bx[5V6lכ޹Špr9>"mP&nKocm滝)r>bR+Ft[%kݲ: A;-#TB}&".lRHA1vQ`IUuh~θٹaMjЇWPR? $x;J}d\/x{wofc!GxF{ ՜W +C=Kǯ{+A~ :"- Ks>'r5IX|NH[řaojy!0$&A3@ی$l;xH1:Йix(^,Vˮ\*s@b?] Ldá5yIWe&Яl QN.H|i\̉؝cJޝQ@*9c#}0Ÿ%6q . !w!v hr&:~/;kV$^:Vybǭ : f`$H JIoC/ĩs>wE1`S0)<ҍtLdt ;7lLIIHW\R[繃?Xdx)ug/#VEK"ITIF Hzek8s[by3Tk9y&Bc1UPe6 1Tυ >fԔw*ukcRF6 Qo&T-K g=eAYR~ⲯ 8I\_6 L4u*iM]N@$9yĻW$GҸjP@(O4(sZj%TmOTZB%IB>h!k4nw?'0CW"q|>&: +^4T̿ddNv^I&GCM$o YQJ=ṓ L@B LHYM<,vBtF\WCaV|߽s0b\SISLu9PT.&, ̚軎n΅+HwG=|lK)*\V yuʍqk5Ki1Ʀ2uF޸ 6XCn1PKAWB/cM@9e1}nʍB:fM=^ ]ж.Y6gӬ:ju`i>26Vrû<šcX]Jxs Up}\ŧ Lѯvn2E`3"E)sEI4no7DA[~'XWQC51O{(YHM?9HT캬VXpI.⛣ið1m#QUy%.كt(Q(QTmrEu1r2/~%oQr|t3IQrL-xYLH8@Yi^Y\7i1ĪϵFMd,~w6"NS%Q{|GSfA*a@MS{~D3/Ѳ8 ՐaF(@5 (m |=G,@HJ8C^2t(>U~׎dyU2! rDWլ$r"𡹨uׇ)Ip:ƙ81QgF;\b_)MѱzyRCVa} c \15*(XZ 4qj|g i%f-X}|#i=`&5Ri3|_wޙ2c+'EW;Nԍv"? cO3ʊmJ*T2=ܾNE&c"-Yڂ&" oiJC?A|J1ee5^\O,I2([bHlw=kdݿJp,[&`Ur$ QlJAa֯hf2[><deǯ!ʦXl`YOX NHFrUz Bx&R (%œSDc&\w٩eUȜod61ǧw#wXnΑa"OyH(߃K,mM Dp0̢#ts ZU/ņeȍʎoǾNDHA6J!i|AW0YWOq>t$h|ۑn~eA4;Sv5wt RLARg7;E(6`d2!m)LDmLtUxbI\^6QljoE\7UH%J4|A~!ܴQ]>^tU]1R]2h*? i_)ԗWOKHF). g䧨+ec;yMfn'~FYY偼@?-A[UIXlZE-s|:[eO-GW؆5jN񼶝 tjGZ!#S/blf&9SN Rͨ=B׈a! (QbeAsG0Qoؔ2;UYL'#4r3X},X])L[4~1K%4u oIE@ij1@K$;| r+*S8Hڳn:{VS~D0)>gܚA]ӎ#[Ъ],vI0U?(TIp]\ay ۦĹ)` љD@.Av]V@3H]Q2Y1<TSz+ߣ6-]K'I6%x>O1 [ ;{BW],^Ke%pq>Q'nZ)(m[ީ87L}R]5#DsȂjY|<>j#lxOYOvU_iɸH^tvHFMXY3b>@t!jorU'W#uߒ~l+9m&J?h&~ԍl5S=؜8.DT|Ja|qqB/!&!f9l4SI0(y6/WΙ8,=OxÊ_^E++HѴ-JJEc/H6(wk.-2H+*JP{OJ/p)%Pu"0>|1W٢ORD3{N+ bA#hyQ#5xˡ!@t8{z/H'[VX? }aV0A@ax^k>Ͻe}r[#"z2yȠ]@!(\4*~l:B ? X"(`1P\Y5!7cB[z>VL,Q4bX5!R/巈X eƳVWV|2eQ4s`5t"$xVЌ@?o @Vnpvy8A5*#l9@IW \5c?Zy| {Q 2zy]Bdl2ߘX g 6X p^ۈ/]+u~z.hf"Lbu֬Y`Ne8$d[&SHۆBy*DIJHVC@wVULh鶂iU*fߙfoޮ Z9bbqךx Hyf ޯ>.oC14}#1D4 ]ܶ:?د+LJ wmtI :B!K2pexWxH7И2!f-͒c™ۮ2xߪLe &_s_u:(Ob1 KW+lWij35yU. Daqsh@=VP¦N /=h/,~T5:L<&rj2|5#J;C7’FwrK7 `բRAhX؍ǹShej_T^4B5h`,F/Wǃ䏐 2\l_(5@X= -p`~kVj%_Lٓ6R~'vhMTT9z쁡ڗ0QtSTk5UD^@J7+b+O qD%Jl̟<с]1y>- 46SG'Rjyҁq痰,4ZXj ug= w|9  LiM}UH(sUR D촾Q܄+&5}"Lh4:X 4bd*ac2chf̖&$YݚkO'lU: A֎MYXTb/lV9ѕw,Us`oxG#LH =G]5aZ=К7~)J%H09fw{~oͲؖbE #W!zoA3LDMņ[WG%= R%SZ8_Eg?UYEVԔys>-4[@fe쳞P{+), ?Ø mR zJGIϒC2 *9n qT\GD~bCg$ oi^i/;Uȋ0~Feٺ_ N'@M;>9U:NC$=[:MF (o#;S| 4eZ谕g7Oǂ4 vԯVBpri'$TĖgEm|g(zl')L8P-6dSzIgEkDe]]H7#'UG,J#?FrNrTf葯_={F%w9~1kg$u;rO$h-/X-[I!b|-fjUC9u40EQk( qy_O9>!C53XaXǛB ̓Ώu{lؚk"jA؋i۸S)CNt+ݍ`&d{TlT f-efdE"6Z7;0\VQ#&3zSv);zMlu^ѷL"ϝ*ܜF)S>K~':KB1c5mT4;+fm%0&[ 7 9IG;XI}村:If2Axҗ^:XP}u;*Y;젴e'IAjbM?TY/3z Ys/x:܁ ?__.‘${-= 5]ʴ=Q.ƙ>ԩegcJB\a6r['>pxtױu"048ۺ5`3X!%pzI>^HO3ƮGIm^J69iG;HٟX (!%\#AGBp?_3FkpCW'VmY5u#taNFCc]i^C-‰z8HާzԌ%iFV]'n`\:^j7Yu[{t@zة/֭ZQ;~WP==N-?fK˪,#3Is.oM9)ߛM~7Ԟ~[t-]LN4W#wOaPPfJ 2& Ǹ.$4g;ÇRȂp_*'D7C ;N @ MK ?sdi4r@ مbHb>)~hsێ_vK}#+.4iѓ]o[}Q<l31{^u:CvPCXb޾ΚCVzXЯ9T,s $gO]P%D ӬUu]#Z&Bz"t;`oCi@lK^&g&(y"%YX3qo-E` 3 cۜK(~{ ч/ 'OrNlܗ`UI$q_ 5o*+݁RVZ PG BSZIqiiJqO6bgja0BMhRA(8e9sə@7/l5i`i@05ɀӦ$m<RO؄[NzYe C}#!e\D[xoY1o Zrx3RFwg$ f33yx׍JM^I ba-t|U`|:2lE^[>d%nch.')Idӆ]nK_Lu0^>v7#}h SQba> sB-?*`JgS`.'pS I1id/]6'feo@lMt8]sfeb, _ „6t6|kvPԵ({16 P"=*>bR5DrĶ4*K0 5*Tu$PdZSY|`-u); d>4TH`3fAM#ri?sN<_ېk !y(o/MrK8%ze[5ڛ1/~jFF4ܩ)½]زV%$ͤƆ|ѯav\>.SQ_,aۍa+%uศbиFN8/zęd{|XJ}مmW `NOދȾO϶ʬSw61`VtW(2`|.YRUs4j_JEdKQ5NCU\Z&rGk!Vi"˲@FէcA;[ JĔ.+Ovx~0`g/|I\Hy =@MFu]rEuxNLxHAAnʱXxx>)6'7  ZA i9}'rHTBѣ5 ??Ɇ{_=c f p!P?y Pֿ?N]aUN,Đ [d%؈jw"ͮaͽg;#Ӗ 2OSQmbffx`hT0i.IH%CAhWX'QLE?h)ѫ筿uD76m/0ީUs0NA0n_{W=fcfI e+8Zp@/ [4[ނ/Exz-v 튂UF{dMzY1< Yo-UJyIQP3Gõlw6͢po|Hsސ326Xʑc rfɱKXOocOcJuH/orf`R}#-i\ %ݍMNFdPyi0g v`I)zOUe {8x?(crp@l8%xRR`XN'ѸRN,})N]'v: \RKWTn?͝ PDcga|$0ƶqwa6PR U-XS,1h:xT|/wcoYnsFmX~lRK6-3'P|{gw[ps<{A`-Q oZKy1RT P176myvl3: 6!(aBcU!vZë͊AfxJP/k0x[ c֙[SɣYY| Hox! k~4>@LJX~Y;p^%4p{끔Cg^9.C7XhuogwRhQ 2}g[bfOByFbwӷ0 !UHΨlYӓN׳pH7!Ť}[0[RS6Ym;zHItb?ov!zBJ~0ί^"-Bs@N!^ik{Bq`6OTb wM?G)-1x^6u͝d+JgMK`)Pu]U$؆wyTL)7R[<'d[^C ܪg;4%/D,ūBc΢N/0)*sCM3MH k:/gʔvXњKA'6DCWZ)UxgD>רZ;6gLB;?q?^\A] RĜ hd09n` .#Ꮃv / 7uT*D×|SƴlƝH( J\#d|غŵ*mѿ$:TB0EaJq4μOn$OBŸx:o_"=VV]ʃg-;oРo.aƯ֗wѐ"*o_wsZFu$}18氲[/-fk0>^DIAu2?}W=@p9cUA8('*a8uR0{",8Ztkc`zAH%edntubSAK(j '6S O7'4tKN a yyk-*-RJ͍$=)FU냴^*rB('6@P MmLc&<ƬWzw&3vgTs7WX 'j9-PQ|Ua7oYLe0ù-V&n䃭,y#)3&od%;{IW5IJ5⼽yh [{/ck M8㮥 EF?TŞR%݄bpEܔV}N 6*8P-2ȳT p1HצerLCTkNƩҀc hѕ{/96}BG I\\I{S hD׹܊`&/;%]" j&31A$|}k̄ƶ n]=hFb;=RXR' ڮ 2<Ƙ߀eJqN: z6kd]J}4("T`1GO]0J,kR"Y~dlS!nB;ڙ"8ʣʿqn䟯W]dajܯ:IB處Σ>Ce*`[{Gcv9VB׳ tGc@'.OVPU, YG(!=}16-FK"pq4UW"߆]"Py@?iójdX+U!yXRzWc>`cIFt]A< +X{ҫBwS) "-#92bX\"$M)͞H[dx?dn0{`9jPi| .;Vhѯ5!:q͟sn_o_G;I.FNH(U;][x@N9$ >%ptw^3+uChZLC[07VYKi^0~l:~2:n$"vԿ%,<4Ps^Mg7H~Ta7*v `P78gY!g֌~s llzGMqsQiQ8aAd{ 1ڵL{I7ӄOb"HpR@Rb8$C$f/5MClbw}S_Ys2$FO-xE[V: NeU\.$~/|xZo9ݻ@zJypz98ESyX8GF-ߤ tx#̫9Ѩ'-Y{dS0HZCn9 u|TgU]nJS}XkQ'D7}Z@ҏ_Xϛ3 #g`m*B~ju0iۖ9="sXbۨDqxZFtʛ6il>B,\ծ)5-ǂObva?K-4dy|\Gj ꃬ:(N`BJqsO4eo'°1b7LUԽ=j6<%зvWHшjq"LS fE0M qIf|(ۯ]R s(EGTV+YTteY:cS (pmm[qS@dٰK&hg$ 0?z5>a7Rz +28> Q0t%KjH4sTT%5*d^:"ErIlNI&k]I_ví"d>кQRMtJa?Sb-(]&HN<]cT* |yk֐ǏXyt%}j ]N`F454zt "R]lUf#D_k6dF]b/UIt7&ʄPCuU(TK<d> ,FY1?G/C)4lbi;?O4? mezK${ORҥ5zIUǺly/g׭TY(Z N"VV=$v<2Xsp"F z*r!.'vdIT$a0adTcՓ$c Ŭ_︿n5jY~|&o`oENW3ljuO=v %C7ʤ6(>?DXN #{6J+Ӈh_tq2'Vȹ`ϸ1 zv vETW~˧/<+ŹXo8X0"h~b26r*zi9R)l.9x>|-꒻IA!uq[T@ZO%B}FE/(+%+@R1me h"=ϾBSKfՆX{~F@, Dعށnm ¥7? ,ڄ a7:cp y#le._^8DgAB# f<&Ј8Mӄ_τ1gd\n!8iR./L% ^e>l?F\}18{:B´ ?g:?1°ѡDE3tdh}ﳯߟUYu0o^U}k//,֎eʰa&jH 1Ju)@mo^^j0G?cܨy%>:Y9EEO\-?%ǜ8'Q`ҬXFGe!m~R, :&LbBUV/Qx &clݬ*/Q`JWakDA[?-64Q\{&?2oU{Gӱ_Q\χYPٖqhr(x.Hcc>ge'ڽἢM䒗xrhGGh6{R4ouᗭ h1aL򾭲q-Q$FK%u^Έ cJOә-=vmZ54Lkpn7 (.#6E=V|y6#Id`ր]N̜j;462B6?|^=8qu\M{QX"9qvSɋ?ݔvyF)"˂N l*+ o(r-=Mtct!vļm I3VkӺZV4{,2dD 02 h."zJ? C@l[Oۚv =0fPK6G @p@[~;jF9.h"' ujvɻwɏ\{ϑ?i-!1&/ꜣ's_HXom $yUX9 $NRdϾ><4@4\kø1flD9\=5x޺$k*dw,cъE P[Ew#&.7[n#j4tuŠ_Z d `H= "1A btKG{4G(P&og@_,;vYS`f Mx&EtDQpX;_6Ip0dL!bJ5_*cdy1`YLQoi3KfUNo.vmG?rN;Paw92#0/*x5\Gּ/aŖ;AQe qjԷ)U('_ڌ%qz`rTpq׏4_JWtÀTۣzٺJOJj= B:6\/xUwAހ8ϴ%KGyҾ; )$ZqW}MƂKsjlQXτ2uߟd;ңkh7h 7HRKPZJ]ۯ_œREe+ƚyWG6 p1P?t٭G%;xTda,/eC(s KvB}a2e#J@Su؛{)M$g47A{f@|ݔC w0J;a 1`q2suUuIPGF",6g̍ul)y+O}-kyBk sq | a;%i^v>8u[^q*0+pa"}4""G !S$N[ƘOfs C gKPBBM8{xHS%_@o1/3Lb.c\@TNj7 ΥsE2Z2^w.<(HҏǸoM% ^CpR&P 4l{buKZZ~6hx@5H9kk Eyv),*$7#3yn}Vs}6:Q^cg8:%wԘn3$%?;GrSg[+KC匽 :/y* ?5qX-78̲SgI't,k[춙"U\>d4.дB9ybGoiV<9 I&U,-SD.wĻptCD &hΧ__HhNv=3"4+#|V3=&^Ze}U\9Vބ&@"t8*kc5u [%ix 9py*N;HfɋXZ]ܾM׿U0[𛷷PU*=7I |e*ec!k䤈캡Pz"7ff(wGR7Nrf_lpSVp#􏕾,ȊBg{|6rO7Dghtc1%9o{Þ?PZQyLvdY[,n|^VT,IC.LBg.ӈli1i*F^\,[ u6-|Dvru ăJ2o<;6{w0 pUP1M,$h#قAZ37|Gn_A}hd($T')$VuQ D"nC'ՒW D>u.0U4Efy|PgD=.`NGI:Of4~r a"Ձ8Q}W|nƨ_O jДȑW<2w{ߗZ?&Er>1\nV[͑}bkvČ5뫮-_8z1=A F~QS6 QV! ~ Liͭ&  ڲuGvB}æq i 5ȵ.fR0 y߻ }Րm6on"]72#55ڗqǂ,&@m{H# 5d58$wաh>~ ި=i}ϲ?+Ys{z)Ǹ-%$P%4Rq4 hJh^H}//dHR5G1*1xP@6X/X@VבnQ۟Zjw<}&@ lB'jۜoON:bj~ey [6lSPM1GQH2   16r*--O?n"vWfQ:.=ĭ:J3UzPK|;tVW1͈6$˿'G϶TZbj npv R\0Rjݴs$Mו9];ȡĺ=J"R^Wma˰Sǒ?/`\5 !2:ʜUHpؕÀ嘝=+bڕf~nd2ǀz.^y͌)`OC.zUf+zWye8 4Y#[$l)/!gZ rF4;ΟK D N'u莞b:'7u:^GdGV}x mrg+UblPIJKt;ɍX'=4W4ӟ7*Q?dPF}xHYL BZdBт?]بL'kg1p!Cjr0ͯۚ(JVw~>@RBF mfHҏ|ƖP(c&8C FF;T D13Д2g-KȟYiSWG_| dM}Kk'}$I^ѫ3edY K?/lIDc7S+:3ƚ.Z;?D T^"l{)reQQ` 7$tYh +Yi(9xb ?ǰ#U<Lpf- 3EI"0}ׄ<┋kt{Gj`]N}[ngeLI@"PBXn+-.Y4cq[SOWnMk|gFyT-Vo#6ޑEӁIڪZ/vZ*fWۅ[p%'4y42QyIYʊMxIK7#8ˉ z =HUXi#?JѧV}Ĺ S9# R4 k$e)N:L:}Ӭ#ɞKBj%Z>,ݽ[.8vkJ  Bx &M#BKLUFOTpeNMa?muKu:ğ]feWe\mzJhnՊ/–ZnIn2zT}s;w76~U۱dz6&ާ; a)Q<(QW\9@-XGhKxM sc0)NUxTD ovsL免,pNhqjNdW_2z2bX_@h3Wҗftm@:v}kp߀ՒZ4N$4cI)]vi=@y>-/d4'5LB>&`od}ڐ `. ݧp/cCCdr"t&ܳ?]jZd呮'}BAۜs/T˱tY4FQu[WrXDuo2m)+ϻש=anAhZL D?+==t33%?ڐ>otwhC9^|RNfR#wMݶф0Mrra5UƯxwpjF|MySѯ4 yw6B5bůYSٖT7LO ZDC7j4p>d,GcNxZ F%`ݵ tvFG`C~ /=,p"ƽ֔B"SX Q4'WY['V &8Tc?h1oT[e* U@q;2Hz"wHJJxmQA\Va稈tNdaYTts*$;221Wūt(!*nI2gXV{N;}B7=fvN^S Q̃n*gvZ=L~C^N7ۣ*DVW8ꘙG:[HN-fcZf(̏1ZL':VXDU(1dro﬒:><' aV7X-B\iP9P'Cdl>GYD`91xoG㯣0 ꕄ!P?:b>3/Zh/[dYfg ͿVV}yu CѨ<IJnG'1ϘclqCDMlpv)N CAFz)fT>bjJE<Ӹ]%Ҹ5aU R. V'Zi  = GO*Ջ: +cǃk.H:9 GI[LLOC[kP3^=GtHp2ksݷ'^@|r*}_"3#lRAUĺ0[*yovIN.[nPW3ep=A5٨Ӷ,_3( "'MW,[)L!۸!6cy%{ƫ7:eÉN&4/[W1A2Zyq@Y҆yY" Vˊ#DKŕ>%+0=OKHRyɤ5l8Fe:S;Vǟ~RdMl/9$믂ca+K?Ve 4a:$xzꗅKC}wS+pvv>ͰC7nlMm\C_1检iϰ-Q>\(Âg%h҆ޡFԛN\O\^;eڸntR37ZID{:LDysݕDl* Kt5dW-bOq_ bvk~ ӚZT貉B9MFdž$㽞+u1C3p2* zsQa v@]U4- F\M͇ЇߥQt ??]_K[{N˔q7-L+\=;か;4SE-#[N J* ,?iS(q. ޗad}.sewl, L^tQ9)/l[oByvMCRjg(o?<[(82ZK74v9e+*G"`hrrB1vLFrֺL9*)+zm!p.P}d 65OiӍ)e@p:3jAE;AGohmpUb 8~B,E*`䱋HFv˓Og)?@N&[o|UlD4 9!mQIɟepc7Իh׾2Qg@hR7Ӻy>`cNw0HwYslDOX HIeVz9N :n߆)Na}s0 Pyo?G3u?-V)tQZ:(bS۸z4 ww&4H9GsT;XА#TS0¾{-GFNόְΊQTN({Du,i"yD^ >4S3jq]daRh:$#Z@؉krF= 4/R97Ť1,?j)Q)Y34'̺QmT QBx`nْF {&6Mƽ:{ +.gQ0^3QL?4#ڀGB]T#%M̟c rBp)tZҍ[li/qx=ңNt_#^uBV74L20 6Z%;4*m'׈0\haku4 =4 b]-w KFt{pު,ņ/uĦ_H@B2[K'2kKjgN 6!/{,DiO Tۦrl-A˱ 7k0)Fx ҩ VocgSvz"J=f%,LE^*.fARFH Z+ƉFF&̔B)U \jc8ɨ4?˸1@MoAXʭ?#xO$#QK+¶Is^ժh[̱AC6ϗ>u:o^x1ڍ+PQ^)kPI . ]!z]({|ؔB_ #BOT79VW\Mٶf˟"?Ӎ c*ݡ3WM.WiIɸe/(3c!bRO7$C4_)@v!:,K+X8`)zpw_q1X/ԀDŽEoVRDy|~^x J0 NJΑ)PW ;+:wL eAIպw R$5C'ԣZ4=BOmas[>'CϳwV~tnEa_v=t.Q'<*hJZ7)ߙd%̮OY k%hVYpXz;Rl1hbUc|-`bCQRS}g*Jp3ƼJKru ޹YkQ';Y1@ŸQL_?="M!j:kH^5`E'y 4!䘍 6[u[S ͳm]%pz@ (qdf3[ܞ$VI`^HK$\<.9 (2xnfEԷhPZ`!&R`Id^ֿhS/BJT1\;[|w;6Ts((wM;O4 0͙Hur!uŶjQ%pD:H]lP:%T^ Zgt皀2p ^Q 7fgޔ>VkSQ4f@7 hGe`A11*kZe#Pv&&`BS3٘sIJfJ}O7u qt!7!ۖA4Rn}Q#aEo9?o;)"v%nآuLKtkeD*V2 .Z.$|| uҿ .#{ -bwe+5 "^e7B:JSJ#.h-az4Hd#b-8HV 4Wq4dj^rY(@q? , '8T7F/8ci#;*CIȎXַdx܏͓,_Sд>S E;M>Z2\aXVOjRd\.DֆեKUZLv . qZ{" #grA&?J"?4PϪ=3ߡ7VFt:0=hJtUR8z7"> }o18S"/#%7߉k"G q  FsXN)~Qpt/9"jP f]|75Ĕr' Ora%oՁg SZKNV]be[SF С-XxdU7)hHk: bۀZ>;|XJ?A+, _Z $&*DIָKLNlTH|={C}fQDk eͣؓ+Q8d@N(e>ZSA@̰~8X69z[,3T>n_|:ww's8R8j`5 gAY51bESL7`A)듳O7y6\WKx'|FzmOԯ; x)ti]Dq}Kxoc4G>ĄV}`Lcg5|Z1XqAg 1Ϡymsu:DhʥAO~$*`J Gǭ!A5NC=KTcL 3nE15|m=Eo=zU+p-u:1KY[^Ǩdj7H3ٓAuPGȠ  Eɏڣ6knS,vr;fT(zj,|d[D"e;*սbȃua iimh!u\2Ȍ q$dg1$p+4aaI÷M5<N-ŖLcuq` r [y@SnHO)'!+ffUj-[+hoDk% xsils.2>S@T",|'hfuZ"*~!^5;r%u@ܢ4/j M45Zd3.\Y)ȓqXkGMAuNO^~Wgq弟}&GK7X7I\1K|x[g/ REA_Yi0YޕVҿ7W~Ti-8Pd|GSޣ\jI"Mk>wrnTu 2<̆"{5x*~2<ͿȸRGC}?ɀXo mpvǘY(XEx,69 v;U3 GXʃWY $> d*UЙ)~PH9_xzן?sq)\XbYV2l|82,7Afu<ǒB΃n(8{k/ָk^.$ g.Z$=1` 2`($ľpbYFV + &cm_"p|4\GצI(zR]H-)_QLW+|&mh9"R)Me&B->B;T(XG,Υ;G\ح[MLKJ!1#C|1gVlʾye㈺oGDVˮUR%2;x5CW¦(S (BGAT&Χx0 XN]D~ydFDѧT0щIh@h 3z_wHqM֫yv;lb L5r1Ko ]vxQѲ>H:*5E(Zt%dʊ+Z f25g[Hbɍف =~ ߻Zg4$gK#)UKvyQR%>guF y!#x| 6LB:sz;>%]VR}F@y)b˴C9J8x^N6x_;4=hGDXnb[cg*|FAI(I\rm#|BB)?TЬSs\ SQ!v޻dp7F܎y æi GVZIˊÞIf|BŏԌRIo&Ыr0ZdhhC !Vnx<'vc[Sr 5.tSdFy"mB(7qG$'͢4ƿkd}ANTc%2bTOjK$8hٜ#Nuxi$Xǚ>r9X*%G%HvDg:"׈l2FuOh}l Ad::Y\Bྶyמ{K~ˌ|hcSN* l4u@2Ed`7vqprtVU[<;ң2{s:!7lo8 D,Il&hľP`ߊ|x IOR"4 v4Q\ [YL3C u[K,i KNB؉FV1#^.w[ِQ`T@C#Jq wU']Gj#pJs$ n Ee@**JBY`, f $:qt}O '&Q>]ʗ@ɈBP7@=꧉S öNT|#MjChJ)V=f!qp͚В@Om覶>4#zgh?dn8$EOo\[{O8+[ ]RTʕz/| H>b e%KR1?iD1_c/oyNu`0>P\YAx:⑅}.nQխK(mu6dOݰH T\lWq.UMJLew'd۱D?nOL%$Xdpc|S~A8C0Ԉ 1g-  N*iywO0)vi!q_d&(+:=&@[N't?d=\6')jɈn8Tf>x_Κ*$ZEh%%{W̴wVΘ~Fԧptf <Xb X$(̎w/Ј ꔗ(()h.FD^%CT%qNOO9iETXUL:&7 !yC4C+DnWtcwz[ pXwL@1ɐ@fMH`V x֏>5"ӛ&XD7?ӗdjί;xs6?riu,ՙr@4'ѻ4^ /6ŭfV5a6[ܖݧ B/j2%Tkg8]ݯ'j3`mM3H2_љ]U ƱqSn;cE[6P> ؕ1xdtWeд6S@x\H&0=O1Oc+ƐM7_D5-w(-7BFl9F_8-Ҫ Kn_B7y#cpTUJ]v3Krwo˱W0ف4:tg.(Zt\)o&5D[M &Q^u?d~[dwRykrT/پ(W3IJ4qzϹR~y f[p<3ێ/Ė!T ވ^9tV,iqbf vM3Wįxo{K|}>U'|E>0:Q5\GQe9N_MX2Wp3LhW0:/QaLہ;z(@qMcV$]&J2_آʧ@,vm!Xv[8]ڵT!mAi&aC \hQF@Y-`jȂPjf_L9ZYbNNN#feLRUyfˈg7MBȻnX1\!M 6녙/5j63 c1G2VcTi'=|‹vJèih~iȡ #jr6| Quh)I*mfҡg9yi2ڿPќ%ӌ"iBƝϢOD|d%ղIvoh/CAi9)D1.6Mak(zjeָ!aޱMP k[K\Ҝ An{X>8ICzO\RdŌ`%/~{g 95K|1kDƳNhJ Aui֘(#+JlWADz nNn0oj:- $'[.ƏJ7:ns^rM)c_LZC^z ~\{% \AAťeD=x'.aO$(j)inX[b?I|yrUԧÞ(9W(r_ Q‚x"2ws'u vئ[e2 p4We׈i˔V8]kQզknN+\ bnt(]\/|S&z%3_3 :"B[Oİn@̳;>qp#uȊEvPۮ]~r\(D؏m\@\`ҹ)@-zY$M9WpE9O cXpECrHH} J2E%Q#[C!̠a:l:tYXM( 2Tеo\S D_bH~o<'omOV96 ja*^sgH7֑ J:~2eUFgĀQ[DžD8JPX+cv_\w˞v΀j|ߜ[e/o:bTng %oM07pLGL0Y6 Ԝpy߸`I~p)сѳ|(.=b]2 2yiVAu|89mg`95f[kAAB@deh4  nJC VI*6-&ۮ^<?:}At'YhK 9N#y WAcV0ERk.6z rF;R~9Q5?/x rN.~@uRM~K˲a8JQ,iQ\ @hFAK`Kĉ&NBSL«B_%ړ1J͒9:!*Rm{q tG6$`yAYL:F\(EMu,-3v?I$BK aDO(h%zczޟJ^c5cbədͨ[V ?f"FI!z\g4~/v#NcJ!a,Q}3-_+0r BԻz\_B]H"s)x?e;{إ00en AJ; !phx<gje9%H̱j5틝ϔ?G1%,\:̉6's 6޸4,jX#EX"&Ɔñ" K5o+E F5?>øG(['{9Z>w/a,pQ1)AF!$_"\hK|)VcG|ut[<"dfډE.|X uz;+t[Zэ2W{Z R]:>LuTy]]j߾? 2'"#: B )B&%tO2"_ E\ K~TDg6^~qBÂpj(+nC&WmQ(oֽ|0_Kgii}Sz01q+HFL)Oc3Մ8CSV 3^)(@#p$pfPo56sLS7ikl'3:S  dՍ@[:LX@$2Jb3CCК٤LYq$a@@xES+0M\XH_WJ)(w8mOI|\T:d+o]x?Da*++b@IhVu+]hhQ*b":3TS̼ K443; ‘6{bɭ`ofRw›"QfrèʓwY+~5,Cfmѩ ֝J-*7rvUa)Ol 3}O3NM&a҆tm "_tu,G63H3ϨFR ŇLgIqgɡeR+ ]sSܝi?Y\Z:ߕR0D˧6!+#|Qp`kYh/c;#)#o3$nb۪ZiM.l5ض~ED$x[ZD>HD Չs;=QZϻ8lV#Բ[<f?DE60 ڱED]P"\a`/֍&ce5ۮSW2BU< X$c6oLdajd@k"ݏv'E%1 N'إ(oy60^7F7<r8D!<ž5@b:yit |j :eA<ʮ*߷-T/zyVys dr ? :M^}wž {{ACl^3p]KZ@`|jc64sVusaX\$nyk֋Šbe:Eֲ00XTEA]Δީ `iRc+Brwp,S η`#aZ1gB-ȼ]D|&z6Ej4^]N$բQDe# ?\S̶ Vo=$MĩDať ۳b왟r} ,},S>`UᱠpgJ'1J?2- [$@'Xe n8Sx~_A>G9){6ic0woV^3pA A­Uh_jG9;z̛*I i~5c3YM?KFJ0ed6nV„Q;6K9@rNe_(-Qf{ T. +U~bA4uY)X%gx^-3/Z}N$ ϓ,nYEL&U6/8I&^3ӦϯYdby/9a]EkrD = A.utIJCuAT֜&wi| (OV1׿@{K;KP7?4LC%V =(Tb/ ]ٓϴDFfO<3 GCaBVJ`c$߿ W̜4cUMV L~1K˼R6r )~Զ@:LQg 8e؎ٙp u끱MmG.%eY%-0|6agԄq zpʚ6Vhdfmw, O*,[nG¹B>zαd[cKv)(^ߤ8΄3tס@\Js-ʾAEܾEgrY7A *ĊOۿ؏X8LV.CeDRZ5F'P lʡ1NCGѺf]LՅ"#d5Hs2V*"s*~ pݭ!R˄1xJy,p?4KO68{F%pb=Y ?k"IijXd]Ɵ8PεK~O6ѬZ4-͈C4$aɋ@m[CptC)&Ժ%F)iz4z0phxMrD,ZNdXrXO!Q/MB`Dd“TY^?S .D"[B%6W4dkh-rnkrzvyĴ)XToU7ѦOED0VLQ^5U?݌sQE3VKo*/2}.d5`0ru:mcvzτ66{ 5 m))fQRe $]A ޠՎ6Npi]HU?Q1{Aj jB6dTW҄Nx2%ڰp@>ssfesBzYbxͅ9+ӥxX+Mg`]Tb'TRsͶy]O}TOZP,4 >-*!vԊv g3[is޺MZ_bŪ&/hO Sm@FÞ &w9 }\=8ۆA[X*}F(QzcpRSg6}36W _> VE ߺ,[;˭ w ƣ=Y .=ঔ2I/"hH1|шg۹xB> rOOucRFajkflNC@G /",k( 0ktc9= ]V'`:9ه.ڧ%l˪Ϳͪ$}zGVOjT q#{kS#mSSqPcjbzO]2xT@] E.XORZph[ceL~[5nL}%A : +LpKKj(Z(7s3 JKMKqW^"BO0p~WOFU_N']BuIx´9"@Y1Dc-N'_-e)Feyv<(—=k̓n9Hs|؜l=.wyq?\-RpzN_LAU4hZf!a{1ZL:ԵS^ YܽPhmߐ /Bu ݁jPq)لqOܩ-V± Tk>T|.ç<>2.bBJL׋5(UXB 8[A5XڙÞ4&2aKX۔ Ӝɬ :%drt*FH#zJ9FÉ 1ҲcT/E3;ڛWLr^#uSbj_s7^|UJYSNyr._BfXCۨa\G}5jc*zR̪;S "#:*\]!9epl*L3OYf>9| ~p_t!N"Xܛ`hi" &:lP+iuPmny3+jz.AXY 7bm8 v0*jGv-wE-C Af+SW:J>B]{$ԢިqAc8ʍDŽEH~6p>ևQFMY?1(=Y|i+$y:h;$*(0Ȑ+7z\ꣃ,dosHם|I1&[Ӳ'A:ChK_0#P3->d(r7S 3Z Yf=:#Y{?;.O>X~z匳bJ{͵>6^ۏ?-˒(ZV1FGx\,=؞!L+m)A{)LQ[+u!7̒ť^k'=#D]} &RZހ23n&uBV b. 򪖘ͩhRMchuF98h#76mq؇r(LNS=?SFvsJunf-I  W2TMs; nሲ$0 Ҵfax̹mR9&`xLBn1_yI᧣|˥({ؕ%P 1a-V߫/ h:ےԉU\;GUOG[I]̟ L(jBVU;mӃd+%zRh*dǬ =戶-\+R"4(tEe?p̀2p3Tu> lMXЀe>*4Q{SD1~;6Ԁh4|L=ڈ[{m#03k6MN:sV;Egt\\3@nOCQ +!kPa4Ieel\?KzJRj?jJhFAs P9ΏĎ z-pir|{5F(6׵ ”7+](vE Vy2HE)"< yHGԔyd6LŻEi|>HâUkD>]@{NsJߒF q?-T` a/fޢ5IFK`Fl{\CNc 0BOtQ xGϗr#[BxͲu.UD%xAA\-w7mϢaxMiH,}mә+ OMnڛzC: ;T۷^!E<{zjPg Be+/ҕSMMCퟸMm\6c-m7QZxR6Ny%Ӷ˻2m_UԨUG~վ !@-* bnC)|uVS>2/j=&:#UkNgF~H@Nay-@mT QC*GÆV&hj5y\^2ӥ6s&xפߺۺdž6rAk}=.I"2ƈ؂!- 'ȊB uG>mB}\&$=N|ubNŕgJl,Ge1ٲd:ge45$lul-~38OބN֔a1f<0gz Hydӻzz;an2WFpy`hnsh8}' :13Fq?SbƽBF]$+<cjM%*=d"]"̋D^M+O, ~@z&( @"׻P[߭pE#|"#}6n}jt- DTciY&Kgoqåjt}b{cm.ݸJ?,8KGpWzCT/ ōkX4)᧩5.P+N,@O_jIMRB=$D k>D6 ^_Sxkj`1ʖFNE TY{ӥkۥ}4ĽA+׎̸8n#fCʆHbzA a· W#z0䬷q vn ycf0|@X7#@PCIv̨)07^SF=ЗI:9&$M‰63͊>.[t u-qw:RiUt瞴h0Q@\#d&$E7fXy_G~5)R9n5! r$Z0p<27EWq!st-^a-y>iJ?lͅfg yʤ< "iU~gi?6fl:l[D5٦tGBsShkPܬQ>DƑ/?f-ڤf%a'lkI]㕄32jxP Z ZW#9"/ó:;P$=2[$%mwzXfCvjBx]av+Yªd #xE *c@'bFaLh33,kD3NǷfy+`i],)©X:=lA1FKT l0^}F|[$US]Q-lͶ@sAWƮ2gd-O%0)r 2bY eOyM2&F}ߍhO }Ia^[ni ]7O!pFyk_,Y^P͔DYA5o3Oiܙt5kdCO:ڀ)̸l}<&W iYX>Z`yO%WeމB}aLX w[^=bvg`Fq Q4 e ݑ6.Y˲y<TRYy|O9r&+Ehs'[\K2(f?VL#UQ8]@m?ջL %\~|NW;4sݓuPmuYQ6RA[+P' =#A <:%C>ċr'}y>TFdhL՛ggG aTe=vM+9c-6FF2O !XB=C] L;u *l쀡3 bˋ[kkJ;͗"Pa35py=+8CL=%N4V>W/QZ:dSOyהBOdV K 3I6oY-K@D$#7%M7@0DRih%"}՛d]2± 6d H5-@gb;ybTmz(2`];EIscF׊ B};Y[!*[ex^OpLn7lO}Xٜ[{ʡ q pLba\YkI}5NSc&A MaV(RI#^$]"G |T`kε3W.'*Ex,mij/q K_6u]RFj{Ũ@DhJh0A=6JtTЩOv Z{pUf ~RT`ˌh`C F22ՉTBtR=2޴8?v%~g=ĈcCDOĆ+ ){mvpF0I#Y.@Uܖk>Y rg \e(CA?NB&@a',p>[f: O"&wztyf2^Գ)N#D3Җ h=F'?M) uԤDjKX}ElYr'oud 24$;*?J ƒ68Fv2Tw2=^GJn(5> !fr| |$ 9s{ @T`w -ㄞy~.";{W߬O\+~b UA5ƥxJݱ ل9ͯS|"q3V%YY?{p&V HomBC~Gυd+"I@Odؾ-6m.i{jk\'4>v(=bUBI!=S747q탭>7dY-0I⥊m 3eDARK!H@nPK~TW(#.a/mBs0f㗙H_X"@f!vt%Mhßy~^ӾE lLi~f:D48} AkOgzX tsHYĂգSWY Iɾ%n]wDsqz&NDwM 'ݻY7*Bg&'Ѐ; {Ԃ_=).Vs V9ԆU{f6^+' mRXFeft@:])^kZzNW{ИK\w;ڑS!MYޑ13Gђu,NND2vf#PvqPCWӌ1ˎJ:;KFw42v$F[NE^a(aaѬOGjŊnUx <3w)ume௘Sbj1"8hHS.cڝ%[O, [w0 |u,5AbryȦt{GD#nba7_PA!bÝL,Fik x\['s s\ h:lƝ[x j~+&@PT$*J!ZΕBPP'H~g' a=:l"+-Nn١@ۚ*}<3GXR{=f@f:ZqlF oZlwjF 3nW;R^Xl6 VuRC9 OK:0skLSin5mEErna{AjGAS9$H#<;f5x \` q.i̛1!hFB_q8hX\[fbypi^M#YLg'Yo:u!U@mufj3?ֻ""T/t|mN .böO> `-N3ƂOTd 6:aYͮI98V yy(}`OqY7R/]O BV6*U}oy*7M3J ]ulzsWNhùM%j4H9Ĺ}3,?9 dcxDv ߊ=C4O |9\+1X֒`"6x%vW;̔v;@\=Θ&jm/ ( g IyoYh{<@L%LQ&rG hrv om>HPETwtR/Y!=M5*-dc]PΦ2VPfoy_ฎsQLP 7M"Չ#BVcy'#f;e)W.;L #@׹ $%G^až:[N-"%aQ\RVrݫ}B&K|=?[Ű![1Q0,plOweBgp&k`'~*n$AKK[6 a=):C{ui㒖F)8廅JaPHZ+ѭ||"̚`L1*;@v\F$|&; iP/Y ~΃㯿`@9U}(FCʭ>5qDDozkIYe,vB%h1=^j3 a%\k`0[_3y-%pEEW5Ѣ fÑaŸ;AhMlxTNE$g*Wr.hѓX8B}U!^',@pIT)@V=67wJDI&(﷙Z,P-#V\Y)@8^Ҍ}`ַ9{P6Gb̞V8 q[^ZhKt:?4ݍ 42"#B݀v>J_ $C }XG2*{x nsJE{X2(3})Khn zsQ1 a5/p _Gj\>-N_7l8WDA[CĮ] ڂ'nn};{/{_[M&3~@5S91KLܳ]Jق6(Uk}i&EkNYmysk"a~wQΉ\b+Pv=h<mQNb$kZ^} t{골<' 9S!;,I>*n ?@%{Tn:\iжc  Acݙk8Ϋ(A*B017$X&"';#9\03ʂEC_s ɿEChw24Sr p.E ^M Ks =6q@mf_&cRs vy-$ZW΄D;69 g/flLm\HQ1.Ijr~ў> [+" ;]1\å~^li 6:wxY $u=^ \[CjGJ]DRdqޅu?-QktvWĄX^ZM%ٔlEOT~Fu Opm#b&T )Ua!|7OzG0c֌%ux1O0 X3$D@ݣ{ϠgQa8쒈 *y<n&+"ΡzbKpL`7Wki+)l&WU ?p\e$b>K csCxJED\14/]҂ab[9t/`~Y9AG% ' x2YEHQu=E龌L:OApxOߖu @,|h=^(UB0WFW][?ـ0l@V==8[ez0R (2f~ک4;?QFAG[Vf6:UqAcF4'p9U]Tb4'QᎽ;!4QzRPU?`UáC r[ trhM4szӪQF{bb}FLF_$os /8)H+iQ'GIC=g2Fa4.Vƒix R]2B[*hNO]r΢4 lRjx^yP$ڽK_2wO5',M@&Z7?n SoEbwu] ͆ōpS[`]xMrm`!殛])f.'`Zg% TI&[/0J oWsq=*ߛM?Die3c>} !uy޳hJ`qPiM@kIGgaopۜ[;Ʀce V܆0 7*cP "{G`Zz"us֦xQإeT^t61D.P*}d3 Savh߾R]hCVkF& >QM _w|U_=(@wh 7(jPW~iZd{*`ײJ6cGPWJ Ljc'cΣpvb,t9Uda"EAO9RAڌcBy-+Zn;[MX9B&R:CFYneg Hp~B̃oBtzdȈ]8|oh]V\)Oh#o67+>Yd~:g@1$C.zBdqv$ BNIJit;ϛ :nO,60E*HLɳ0ºb=P=ؐQB#B `C-yڎ^1.6-Cs+jcK 5 ž/9aj\TڌYP&ݺFJ3IȒ-g*kӴ \[F߯oX>3GLᴗTE H_XXl-OtLp@ŐdBr}xsE@vϬ")FTgF|(z*,׆9fb3]#Ҧw+q2/!Aуl9 ]IȒcMsr8Xf#Pؗ9TԅiZ aJSLF<|΃dy7Kì%>H7Q:vGJ$fcOɂ>>F'8&*Covum1k2xQ(eYD;9iM<[qy e$m'vEQc;S$ˉi+n\7wû~ o_жV^2o5V{`iFv1FIrA:CUkbl40V ;( 6| yM&-h%\5R1wxǓX2`.L^wWI?ۺvLsOck,=冰[95=0g:^=C~/3N6kK;Ur$➤ TyBR#$9`cH*865T(.hI63gF DJPVf2Gw=4`كv?NzZ`be|) ˸c Wx*w>U&atPY{.oTH^L ~]ՋOUWw=a׌ ojΜgy6(ˆ6ćϯ=3!)Qš H/)h="J B P2Ǹmci摍oM֛5H{ˡlǣT*md|zs&FC0w;]#2:9X[ KDs' Xt+%]^I7<#ě9X20}iQo!*dѯ nh 礀ɫmIYsZ 3 AXf,h$|<}i*tϰ]z7 p8?H ݿa>aTɡJ*bM#[ -ÐW"BLN׋\ Xx;?gl:&~t 0@X|þi>-ީ{2*͑h]FsWqo8ri*9E(vEYoro5.ˑJ$p}}IJĽkY#HeԊix+!N%4= dr<>-V} Bc KFk&jKz؋*x?hq#b mDޖN?AH"(Rb$~,Fh˭B]dhX\@mGqv|%q <6y@ G-Nt;d;8:X}JTӟtcZ왹H^$>!DDRt xo1;T-8*)ݑoWeeUݐ"I{)#\: m mݶJXNH& lLsa]w $b`gj:X9{4 &5BK( ,,3+5Gء:|kב;%*X';k&{7x;?Emɕ&Q]O:62H|81!XHʍ[2 tsͬ߆y(pXX/:Z)ZBe/Ɗ3k>‡ힷjsZTjHH+@ӔG.B 5pY4y[X|Xav)D iעæح̣Wp?s\.VV:; , XIk `q^վpG ˕ ,.Y4^: ~31AW7y\#PίL!_ Gň%  fix>gE;HRZ1j8>ST4&ȚX@WSx_f6UrY.I,iA6F?{v $H pwÔ~S Z.<^=) h?Sqw*M%M[VcwשTEHV.gͼ_1osi.UYIdz{IbOv5 k[.jT[+*Γ&!g|p|᭹0 Qd.8d#2p}d6;B"YvмeU u7eB>QUjo(iy V o#u5${ _ϙ#>\a8yQ~G h=wHI8q_VL0 u~Phyzi@$1x$x}|PjтQqjaNKz4=/[UPp_ˋi;6A㯓W2TL+?JGa-*kǘO*n렏gH 0~uĖ5me]?Ph̶΀bb}{WwPPURv ۘZgNFE(:(Fד(V.Ot$|mЇO;iY1fq=OمgU"d7e \-|JfO[Y$so̅7H!LBY^yIw5c rUB tYJ?GOq'a?Fϖ?DE/ϳI ٻD"c!9?ݽ{ȝꙖPҏuLg[^`w!r ,DI epdrӒpb }_(zTN9P?>p?iJjP25}B2d]WDV8gק2BMf ! re]1ԂuRfIZj. @][O#ǟQ|| ĵ*Eh{t H=_f|,L:<)E Vaf-NJ32߳~(Y/XSQM=tiGbW!"X,ϥ駸)&s4+ 5S @B.'\E7QZ,x}(4ZYKN3;[qY[w v9L\RIR2?*Ӥ/te|\yUޯ)$l{w>en xlY=11ֹ^owu6)Hҝ mƲw>[wiRG{wh3`!}DÛ Bv\+_w@尨޴!xL/H$5 xrWL_L;(,`/h`XE9鄿\7?zhu$ke`+r"*9Qn7ͫj?}G`XD+I$Lay߾#0+%EgZsfXefTF-u >~ {$ ETެ YA_2_I @؋lrQ n|gp|g 5u-eSlX &$n kNEo%tmXD2rsId 1"}g伵YGxhzx8}ɶhO-^BQBp&kn%H{_l)G ^/ >~Xi_+B*Kcn@xަWltQ#Nsg~N=Pı1FJ)RB;W4tX[^s(]΀0 ̧wr(](Ray!<";v?Z3IԤLPgB[&)EHX+j#ժhE)_Kw[I% FӋ>|W6Bk%H-Bާ_gklJ'Y-.< *H5 Uhon,,lzJ_# q֊ UqL%k`l ZtSn̿oN`r2'BI_Ya}iiqDiEkc"+W|C_]zs~3K OT)_seS[( TL3#A2dɎF.ZDӲ?_ 3Ow0o1#bLD-SV2X;'€-NZ3V\s{Rسc}l}DUUb !crO0 ~U_xHUg=\ӜX pEIZbZZէDugVIsⳆkb(L=XyZd" eY@#~ڂ;c,k!gRkclOPڮގh?+FKEY2spdzSg WqN A]z7`W1\;gقtjɷ:3/ pP4$w{0#k чVPxg64EdR3wքnYOAU Egۨv~lOίP?,")&5P-$#`%7 b{t(m7l^#!xdGiXT$) Yb>vQI IPlԛ푭SZ8p$i5q-Ѡk zH#WyZtlj }˿>噖oit: A3nɲ`o$B =oP!D1!#7 Wo]ēF Ӈ򊷜#oد$Qv1D!)m~WI0gV} SEY%7=2,\k4o(ax0+rCbIY5Ŧրo0f;zo5=5d=;nЋDS<|ZEV)CZ82Ab(:3aO y)8פʻJ2PUoWd8GPPzT\_ afD0!ei|]{:pQ%u.҈ n[*aH2?gKQư̘D k8УӠ]qR=;{c/;+T倹kw_ś' K^R:mc#\n$݈'LfA9)WzX*7A11쏢 ՓdQj;j\,ԥZu7d]˭ۯIK!<^'8$zܪ6˜cTb3f~.470G :ʹǻAS)jvԉ»*Q`80r՝Du;rQN;*:̡yW1"|T+[?KQIF_CnJ+B9q's4@nv> ɿ¿8.6"ҽ|`W m[ y^2)?L&JJ=+tT"0(cyOO(yR,ej ZUk̞%.m584$ۏXqi,n +ԙ nTeTLQ]Uͭ)QrC;QX̜?!U`WBc¬耖0 c2qUGʁL}!@[ /gp2D>;U"ޖH~Tc5$c5c}O݁ ##2ވdAy0G^L4$fp> namd5TM%[0X 8O @AłG Ar;L̊iN a=o$[-#"(~Ɛr&]eFu'PcqZ?_]hy^Nw=6$ - F9)mJab8ݩE"ajh:սt櫕]lȆ)HZ7(/2"۞w%xov}Tw~kj`b-pƑaR5\DZ DBr$"R&K-}pUz7'*6찲E.*lU[?E^yN_u'2oA Аlny¶C.x.{䅜>"BpM]1c tFTlOU㑺fqӗJ SGzTH觅LgHZG}inIpE,l6!]1~i>,F.`܀3Q=؉G:Up8dP+ߋt^9 3e✧+.0"}LB̏}fnzgpkdDyv^dsd4/,&mD$=Zt-gz(^j|:ͺR}o bg9̥#tPmBL,u \ Ir[*9%4ߜ<=UրuԕЁ*^K{{72J2 uǏ?ϩW6qSw+0لhP'5Eu,js$1 d 5ERvsX[Qn8'8ZʨGeZihnrq)O }aL}L jE` Ǎ"FT.h9I,^PTsƊ#I]߁J>*x pXD=tC,@ږ)6Hb56?ʕ)j;ys`^}\I~|yezKb@d\KM)Һ Z]x2UWTM}e8o sK .וʿ'6T}j4_W"g LRi_$>Z2_CHWX˿jLMy}# `sJ5\,p6XGV!gMƧhuLDr1MlwU r\aIc8̑Pt4@qe CZDl4h=җGΉKjE<$O\rO"NFr,ARtd4o^" }NY./z[FNzE@ψ@s׎͡r@{mxoZ4{3<&AQ2lRJ㟝 J@wIި":)QTX2ҕ^eYړhůk!5Q0`d bi)aBJa1q ɱfj2ц6l'Ρ?cGT%_H @Eԑ6˘iq#s(+7(YS)ap5t˕w↬;ڝi*1zɊpLZ\D\!RݦQ* i~ w.^Ddu ^۲&_ܑcjM/˼*5wݫ&IMVKQit\8/#KaXT@Ű)ڗ"eqve\ö:6h%M> T,YpI}fق0CCc ȅR\黸ڙVu£Lq5Ǘ15^-s9{VКɧjsdq:ٍK|Ϯ?3ñ4RJy܂46N鵭FnmA>U"8[˧_nbiQ>> D<ͩY} 丨:)E2T^U0Fm Ѐ־@͘Bf~pu~45ϙyePXL\k M Y(vbֹE5I/,j"Yiy9. .sS d߭l%V.py?|/ՓYf'ċ;i9ϔkWW"J#AZv5Z)Qjݙ'2E |hUpH(8dC[i ʰ{Bz>@ 3m F ]鑟a*ǥչhp}֟'-KI ǣ(<+Pm$j!}8N K˯̌+?TutD"l_X| A5_< i7"-dY8LB eqwyԵ* ؗ>7qף3ݐAX c 6(ѳTom,Ӛ9@ y$I(e{f-4L9/46s% T!C0sm|Frއf6'Bq/X8y݁Sxӯt8M"(~f9W웂4z!H Oˈ m">a؋!wmߜ,+ԼX''QOCOam3s>%rE*ݪDX;  /;Em6fCĤp촆G"FC@&dxxjOaJ[Nt-Y5n!YRQ̚ X|[ory1t[ޱy|1cP[<XaH{1bq@%h#_jO ^F~,Lm IRY9-B~dVjj@]ZNz9-d Tws _Ҥ $1YY QKnx=eG,<ꊮyT/Y*jcO-ҫ~~ =cYؑWo~|:g!N2WB'kzYʲ5{M4JEz#$/w<ʊ߲Ő]%-TsynM4|ݿoIȨ|>Sj'uͩ]4uz+hBl_+}R[8<kQ%l߹R@g Z 3 ӫR˂r?:tla$ ztqnG2Pg,DƦ;M?Ybq#|Djԍ4=ƲR7V4̈́=KH_ڛ'! R RSo~)Ƴ?feW~}=nK'aF5[ wnbx}+XdtJ#ܘġ+HnG[}?X(@m"#,EQg.p}G켡Xqy?.Z}UE,gD!PE_NgoH?(a} -~rdaŽ F\ +u:} S{BJ9͖ld,'\iޠloᏼk2 $ʳU677E`au HHDB+ +swE8O*ƽo|8cN8ZSD-(NJiR(.}x/mp XXz#H^c cdQ,؛A}fE6yG7KJ4Cⱥg688>cBlUޒa[(r$fisR;V4H2g9^9?P Rg4 gJ܍`icK;Nj~FcLݾH}ټŇ.'_8T ޝ6N64lz|X[11аTHO:G#aNjVO=AIo #P4s{\:q2@ @m򙎑Pwdtք;`j{"8n4:2tQy B8>3nSVL5w1; o '|C9*W̴>?4r{/|r+*ݱv2Ƅ%e BY*%S2"6Yi1#]7+d%cmK@6 ese}O֮bТŘ`tbNIxБ+3qH G ָ#umۉXP<]ߜ/&8~5[.FNy96=+sN6es?}*í=B0)Y]^;.~f*+Js67V?5>XLCвh6bsG|y}C2 sTЗz3Z"J|,[^9njg8Z/bw)=6Q.xW4y\("wI^9DVmnEKӁj!f8 1Oc0@Ʒ K5M;% R>,ZѴϠݎkҭئ%>l qh;W,ptP_<PJZT#GZ4qiC$V}).~&bsk%V\(քըyGw@8(oLm+ /,Fm\L;B(윪i"@kyǎJ5ؿ:'$2jJU!I\ξ5EǾ¿$N*VyNK:;XӶ뀈R3l٨ںY|lZ$%pIXSֵ>t^P;57*C3kϼ2%M*|kl+,h9v6s*,WrJ yY+,Rzu?!e$~0 f¡fjhۚ2v|DX8ݮJOMeX8E 7n3H^##^7 *k`5Q%K5FElGFw3gBҕ}eU~5Y~݇"ehs)S%hyao-&a#ruLFChePRbB(eqLKPXuϨK }in5QRܘ8X6_.wϦ9:RT`܊R%DT}Tx0 7Axɨ{tgìF@,uE˯bUvF}i 1ⓒ)BCWkgd^mi^19dY<NI|\X"ⶉ8pe*op׮7 =V4%,lMtnQP*]P_4=`c/vr}Z~.[Tviti*Gmʠ(^ Nn9լlr Af]ٍuAzQR֍q3dFA˩;enCR$hbS?v8K)a[aEN?Or.RCG|WL2o¯O>ͿႦJ1g pمKi9)+UL~-#dY)y8fiЛP ekV^Iz#mAؘYl$<J.ޫw3Vw%]CBnVQx=A֜}gFԯX\/NYYߋ)^gNo]C"69OK.\y(݁/ Kso;{ʏD"|h13(Ǽ¯/9fSe ya|4{ dRT ` Μ4ꔭ}]s| m _jZ'lZka/-p5F'+g*] Ex!d}ta2͐~C(-]ga6h1{GN9}VH¦/ȴc رGAo{hR' r3Kꭄ($'5+CHH`Gt-[BI< L"zjKfjgpS0 L9oyZNc~N(J=غlL+)k' E2GZuFnL%*YdV~?c+>qG4-N@ˌZ8z n3w#O= l䐉y]=tqBEy׹-pUn͓#5D c)IќӅ5_+'b 6T5_ "--](!2H~bmB%1phCL SMC߷<˴׮6]BL3H)H&0>v|3_XIk[2}PC3Ξ{" %dq F5,&"aUCVÜ3" :'b J0{ pxpϞ溏`.P5h.JeЌDquU^HPgfpitvIh4;~?t=!P)n޵@΃6kL;]?e$g λZV\ï 򝟲. 3GeA[ߎ bɠȌx@S8צºK-B}1]ashE(ԑJuB`/!. * -elBEDgWtH('L"5>UPJq4% $bdVU(6$ђ| wZz( KuoD'rtYSb_۴?lmyx0P'`A㰺V>?[h0JbZӾVwToN'lH]" rN sߌ@c;C׼[Z+t%RARjR{ReڦU ~Mfw~濦Mu}}9d`?>@;]IˡSw CJ5 åb~-7['!L6^nY[0~Fˌq IJܻBVvݮ8v]a:Ac!dOah@vGP҇ ϝ{e'vlZM.dzߝTWL53H&gH7h݉_.=ؑOG>^+݉ z1o0G}0xQk `踖#'y\rYֻd6 $lZcͦSQn?vSNz $c3>YgFX0IsB\a>hTO[|3 o!Hb\?]CsveĚsX":'H bdHGϽ5t?f+M/zRIf`ač<ؙҟ@gv8kem)"ϗwDɐoo˾Juɦh*uZE'cFo[fJr:Θ$vї8.6Ҝu6{BOW&G$CT/m-R7a< 2 uF5'6,\dfN_L@K׋ >M/9񡕌 ,4V[k'u|(%@zn-QݒS←qhV<ή.zd6HEu`P FD׶4,]4v8It ܘp`.5Լ8=$fYDE!,T)B+<u j8w32E܏cѕ_7*#L&bLo^gU>1}_\MHZ-T4ru||+"\+>OxJO{8VUW`|~gS3X 6ۆ&X8PHlQ0RDM8>84haV%baH mȨsTa75dh Mݩv*L/nվ&iN[D-Ex֤s# g J__y=Zecz\U%bZ_kO^rlV$8KF~Ҥ7CLs>.P-$ŷqV֙Pis]bdbXӤgm.M3U/\'Xn~̠[:mo sun ef۟ڟ1g(j)pLEaD9WaF[>A;wx9r Lj׋Z3+s~I&康1U*~"t Fz%OA6B0)aFl&"݄Z,}LuOdZ ]zZ~jn9dk%oRG:0Rκ,&of4LU,PPQ ZCՕg_\.sRzҞI!N6Xz;A dRoF,: <ӽlsJ7Z{[r&g ]Ԇ{9n},@9zyuISeLOz:@"uҊ=1yE/U֔:ɱEpļWvT{#E 8qH# ^eGN!3ZEfFڿ/vk- `B[ Kf&L^RTQBH*<Ǫ _xY @0&\/VMvԃBlF 3C}=Rd0,]0z+F#ͣ4m׽kAٍݰEFj=@ZϠ=2HڍVIX@ԙ?p,M%cvuc@T^~N& Q0NvlPR "rm7{90)_9O(W#g$+[t->-a A{aѣs/L<*b%FJpW4'-mAe~?V͵@H{ ,{ߘ,~2M_  ١;rp :kJHƯvgRy%k}kC 7H,+dQ~kQi ]⧃iɜO1Tوk#Soz=wϵk@4<[gkl|E zk(å:_s={3Am s@ 8,O\Mef)&+.d~=M2D3w,hן1@opeqԐfCSϣ k'+2B+&eRǒaLSݥ}Uþ he\Y0zQEk\9ˤ  xnU7/8*hT!˖L]^ 1xpzO :?MJ&_V9ͱQ{?n.Ln(vTԦ]YMi(Mk9yѭ}i ` fجv%r)+K|'Ob(Yt_f*" X }?UI=5wW;'YA{6ˆHW-Q_:0YbU:8$OG l蹲#}#i $|/ȷk)4n* N봀Y ڇm8fF> HT&c U&ei'ـ9R^8s&;FU.I1- 21%x|lrwѤefN~qƭÁ9=e??,h G0˾Zmjы{҄\hWKԄ`Yyv-D2͜7b>nX;i"@`EZޘY=,ާjcYjn|zḹjbHP^]S\8sљqxssLB!$>9~Cc8oѡ9DFϥ4R`&g.4E)wBڱKd$;k`V ,4ڶ.e:I$ې UrsK~d+.wIVf*CUlI/[3l?ct;] çEӢ H[YXdE0Qo+N(ƙgBsZsޙ&CIt O4ZB[uP6G E&썭[&yↄX܎1K-)"htCY.bZ DR B0hm+ __3OT`Qb"A$(9f嬿E(XA@-N{XWhFhUXUPp` \#K@ _~{B5&@D 43coBm ւ+)PCUqXFGcy!8>0<^goP^MEJk.] fy}FDYw3%i ckm5x aW-Wp]LO̮>䳼zF!@j imhf&2" ϪׅT b{?0xZTIdfoxz  idM e]P!_ Q+bJXƔ)խ TϬ]/#X/` +nbR]~#礭Kd2{F=4jHNn:EUWҕٲ}ï) AeUc.\Ƃn)Cךτ?ٝ3=4~ZZ(ڄzXv:ӡ|jiq)U!j9Svfb/*hlTY'$>BG>PE\@x pQdA%zPpX uO;l9QoxE]H}v#![VKjg7LV̮n\W9O&Fvvd`r{#GM0TG-;Qb _=/=T QBۃ@m,7:]]<.eiz{`WSS%~HFoMJOW,:NÝiw46EL5_p>SyvąqxɌEfjsZh>@JL"C+/^g9.Du-UоWk g!U<]Ckt 6Hpx7ԉ $8<` hF5ѫJ6b&=Z`j|^s7hAX[d.&Tpj詣"3u &p8A"AlȜ#Pu R֐)BRC,uId.lKẇ'$%@4I8tRT4b˾*YS~yWRq5[Vb6 kSeAWZVbԠ6];G: O_/\cձ AhÜ:?Z:Zy Hf|; .;2#Q՛GDeK?(Gӧ.*tԇw_]/61ŢF|Te ;/>[n%3 f a=8AOΡY"^%9ǏFp3t:B| * p/?v7xW/ d@~ڂe:3Sj jFA:́*3d0HVt!qVw!X!@`BʞmiIwD\cT4)`ezs',QAD&랚MVB^jb+P;Di&b"j\Fٴަkw$Y6/:`^$ʮ%&V :`jԚa~d*&m_9N$0fmi.s+eTmitiD YCT4:rvzFIyqx6',x/7UԞ+֗S~%+ I g QJfIw%҇}Iu&\i#!>=@|,ȣ@MڦAy@l ܴHMzBWP7#XFGJZPGt97{:Dv+ TAol~_aTHaI]wO Jdj^v"IT%gjv`WzUۀXK`0!Rzv \Jjp1E%kEQrԤ6$([B(F܍y赀౒n1`<1}҆n՗A2t{ [GS `XmGZ1;eI9%@YՄ) \I!bVh=d =Zdӑlt[W]T_tL& g|l9K^u5ɟ? y{=9^[.c~DjmCJUo+#V lJ]+;BCT kJ\]Ilc`bߐ-[GaL/9cox@n)y 2`u: テˏ3P 6f`K*ۄ; sd_fU^?z?ƾ Ώ9< ͧ-dy  I<Y' Mo<4-x縓17V!$VShM"X#S>6#d1c7:b +1g/CLJIpn+l_`ʹA14>c}י!Ut* DyzDPW4M %ʛ5ţcS~֠N4?~S_<\x)k'_7pt MX] W҃r|D]ijy˴NXjdJ x| f7ĚWbR::W5BvI5vtȺ 1~7?aBB5NNe>4 SC}$x\*e&}ÅTsIs"?D"-ȻlD Bu> A%nNH{+µQ%q2}ogxvcԗ2SB bՎ|h&Xw?/QAQT0}6d1)z=ɜ!/:t{8Ou6-c@ػ- 7D/ `T^j%m?30ۙEsH&mQ t.JB]5=orgiZ'zOnշ ɟ07 s}Mw5,6?n}bj~ I!WaWG",|AR9OhNdc*$D>OP]`-S[g%A뱍RpUo|`¤%⽕_&_4b U:rnjgr]nT##gt5[5{ױlo$ED8ɚFԫ@kL[GoY X{ ~T%#/pѵBCYShGq.#EeO|]ѳИeܖ]a6}fT2|2Isvaq7>IZ'c7-.ĕ]MuHߝMg|D50Yǫ#DN |ySN97֖nG.DtJ&&ߵDl^r:/!&Yܬ{C!TLlgbe;ZIhN&'4kpbNUY?㎷.rE(̣Ȍ",CRs&; M$7B$4*%pM>b-`E ed9{2UNQݱlLO[,˨~n'OQ!w=Um l4wΊ |f̄g&3Vs:uZ5S7+,g P@l+m]J'D\N|X- $Pj䃈JĄ϶'zM,I%Q}N=2~46X}g3c~ARIu1ZLk~q OF+!ڂf* :"$!i;nXSS)6EOwy -xHW?}vˇ9o=R%iw$C}&t "q`pIs38 Vl6#9@QdJ :}ZG,:ct!jYH#>r_593KOKg0{ + w/Q >NQGJ+rU^ie .h]cXxuX<@}F}/K\fޮK,Vٰ5]ƗQԜg!84Q[3[8ye %ȫթV\'xex)Qzpd%驁H~W%aV l;ffWy5c@XT~P1 ?_"T@MG8u~fnI~XcmX}h#> D,Sҟa{bj=qfU, q=[=5HLoLCVF}+\Qk{7[L"cqD,gwEWhK= p}qVxG}ÿgrormvp.gJCFxu,<b_m,N!`De`t$~B~;@NO']gَ\Ղzu/bj'=/O?kzޮO*6xjã9HI^$`D0uNX{7ɢ"pq.G 7";[ZE7Tۜ=9Z#RT·/W>Y;4B)DM-gG B>_ W![ΜF5]lxg jʢ{>![c?T9'8sf F2|Ӽ`4.ڗ%C<M \5rZ%E6,^^u`kX8@Ob$5m7+v?1(2u,&2?V[ˍP%^r[D:/_/7(WQ -KEa+ĠL`ZT?Uf,O׃RAaz噸p;zTI[j[?BtkA5C*EOŁfZc]#?wZZl0׉[teY#.kC[v,B# c 饻/S/FܤBk)@ZUY+8=-k:үaЌ(oH1Ėo`lQjTKr{v6s}5w08ouMKT&hv'iqs@@YwAӐP6>B.2ZC3g7i*R giŊM4ZmK.;;x3ј/Bo]s`)aCMn 'ٱ_l! 㗽|N_djX*0gSLcx<4m͏(-1j$OOp0{GeW -wpq}xS>P&qCh2F|o30~B=dq:6`Okϐ/6g6R6'F2cs+9s~rm5<6k䠱QT {Zq #&fFI1d 9(kԘ*3(}Ӈ'x=xܠ\V}*S=3T{ev/M#&M ctW^CS&(K\앻ՁqȅH8"3Zܙ#!:P^JlY/ČqD+[0h]9YWG⦤.v&~ 815PPd=zdgߒ 6D@B>VFܜkC%?H@xu󾑬MʼuW,&):ަ{X $CZ2*].v@G^lW'j*pwmRZ5;'񁎿 H%/m'GܻHW3</.&h,z\. .Dc_J{;f[B>]0I>mr+<[EMU91=־Kɯ6LYȕ9o#5w N(XU_K%(Ѣ<@)bwt(~~[wdb 13'^Bal: " 9B_9#';8C ?E&o9(ThՌ/"||Ŭ䞗ORi.POmYel0oyX* E^f?dO`:&&&k4NW^$gCYIBîɃ?PHDhm=D2oZUrdȞtsu!n #ɋZ5Yj(:<1̧ ]5qA/QY k\VvW6{NJC8!*z?x1e^PՄ*9#bDs-9ӯcF8ߵY=璸`j0-ջX:'KW(mJG5; iW&!LyD^Z`+rG*XaQxֶtmGXl $0RW-u}6m9Tux `_K RD%c֦_\C|ԥяnWmYmF ZzNo U'}[h(0At( YFL;2W];^4Oja gK"9DK ԕQ%(Vt꼺)oQ'q. \s߶֎#وSM]#`Ӱh| GV}#ZLw/SLZOUFX~8v=2Zk0H؎PG[rP໤^m_V+zx{aZ=hOFMT6#Mk{ۆ9c/CDM.3H6?63M)AְPN'Z_,96 M֧@KVȎčsVzN5bU+Бd|l7?1Xcd'G:|v 7${f2!B/V'a$$հvfZ{2DnDp磵.4 _@~?fdy퍑s?z #1 -C i;G:A㳤 W[R& R؈[TGWF_[eE6T)M65|@s7s<%8Oe zW\ȑpHyJJAR#OӚ΀kYH~ wV6MLΐ­=x8KpQd\@|*KO׀n̑E1.-B*GTOiy\4+t`Cߞ@ƝcQ݁cx ?>pshW> S^u|b '^{%Y[ AT{xIO@ߏz*.FJ5"7/te%>c1YYꌮpj pŴI]i8KG7C{=ѵ~˚xZP0 <bmDZWx3/D4>'U'ߑ~r^'4*jF7Boɩb#!4G1z-T:ά֙ Fc2AʧiF] -C>Fkf6qJʨ5y=ײ iGr:ro" 3ΖXFagեEqLÜ%vChb/9 PKeR~dZuMN(G"^?Z@gȶ;n'Ա&2c[j ӻFtm62KEWܝbƮ5"NzJӑ3g"ű\1k]|2T; N-.-u!j5 u/|!QV>enXR<(V&+];Jdrt) gےſߐ)t*0]{C<<\xQzDqBZ$̫\P coclեa3Fg? @ftwP(Yyg?F{A%1$*sq#Q).AvP6Klx-;e^S'n2s0ӊ(Mh>}"O|j|hcS&J:Cwۖ1KѫNd~ TXi&4NCCc!u㕽F+u^ k::RԳ~um uNa뺡~`pBb_~HԗU?/ 7Q@z!'#E(0iPfӿgPjh Wݞ(Ȕ _#!c}y0Fd͉rĸ̿itT18|m6 !PI£bX>~ fr2mvaHO;++ffs%tXO {2SP IB0U5ꥯR0:Ӭb]pF65ͼ E-ڧW@.@j<2(B-dGz.+u(<9r7'V%gS#F´= r6 5@ܱo+X-zejܪ8ŖtqmQL9dyv0["cCA< q.3##.O}Hc]cz|lAĭV誹 8`D8"Irhğs4`Zcc=/oI9,+D#3=JB\K$kT^d𽢸Pi筍qj%tz%mWG}GW )͘{dGh!c9:a]H_kjwA(2 tgвqxx/Eȋ-?Zyڥ:x+f}׾S^H} gQ3m>=a)UcC |} 1Mo|^ ~-=;]wCD it=xo_ٸ`5@2\k.z%v^͌,q5zXi9{ 4~nذ%Aʀwx[OlDQnHْ|z.o,î4d v )tܞ不>U0gWM3reǧ)#?/Ri543@m0+#n.Nt?Z6[㘛Oϴ JԱ,sȤp*+@:D;ntwH=fSO ◘C + &W)W`sƣ_Ln_~vD8VAP[o^b ?/3\OG{O#'G*J`W^)l I3#+YG.χ\4ʛԆ"8"] \Cۢ`4/Br2 'kHI QZU'.eR5xSԾ~T{#fny唑P&S[z~^3w>oҨSkk1lq>:ye/1^vDؘV7f;=dg(b(+$JvS1.NRf5L^)Srt/}gGV&~կX[1On/Ͼ=y/8fwǸϟd.7CJܹwǒFRMGtcӱOQmA}Q4,n=AZ/Buyoc͎_g WPȿ/Wj܃tpY֢q@h9dI5#qctpv$LeX=޺3APȻ6XD wIϔi>TcT)kU\ҙc3&Y9 svpy0Awo.`&I(SLP/(ս .]r?IrXi$)WM%0!ɿ Wgaa?gw=2boBhDHϻӑ:7r'dD)R-1$Ȯu$,i ]s-gхO!5Gs.w:IYVwiBwE)ՁXhVH\ܺ9ATxi;Hׅ$8c5]:`u O薕PHe +Ld6W"^F۸ݶ+XMRH0|y Y'7Ł],'|,="!=᱗ؗU)hG ]gj-dHoҒI3LdAxn?[P? j#ѣAq_ܪƭhzK,AE0s 25':~@ːr2sKVɵ.6\wԋ0g3oJ9 =ODI0n$TLe0FPuAI.W [P x0ymLOzk:ѿ|, z7lɿտ_k],E2iI~v=qyЇ.tAr6I9*H@Z+ 3'ٮ ʐaٽ- liVq#tXWN9ЋiBogrbD1+l7CVXS MЊ403)i\{XPn$UE[ J]`İhu)y+;mJf[lͷ"Kf!Z&0{t'j{sOj}WٚCkf 2 Nl XRհ?|}|#\ Iiڙ"wW gq"W!΃:#T<Fg(aכ T@~S):MKf8`l 4  )kE HP[0œQm$nw,IZ.RCd=$JONu gAPz@4=6ƒC C<0XٗQDYygkW5j⨴t2gwȋUiV]/)|Z DiN§4k,7HFФ\Dz ~)ψ߰O6E# !VʗئNĢ 厞M+KQuoV~Ea{ffw Sᧄ@e֞ZE~AνIuըp0Ö=^)gz<97>>h~F/ Yzu!F}T jZP$c*mh2U披Y"cq$(gcwЫի`ьKu#0g0[$Hހe+_0Znn*(\rfdXo|8fq+y}]w[[v|K:ow~xvsLIZ]a=--}KJwS@9Git]Rx^ݍB9+YD6;AT֕klcv 7孹>lu~ɬaVWVUxDlLFZ4VwiLr՝Cߩ`X^I 2JYm[VEUY $8\Au`mBHEw1"ցh.OWp!>_<שø.00lL~7#J=,'$[@Ubڻ[9gTk7z2XL~ Q v fpێ'~Q=g}*)R,m\o@l-F7= .HTx|?-4.)+2`?L QwREY+oѡzjLfѶs;)iFe;ʱ57b}c|~ܔ`R["/ AZtG.a@Pd,ʆt2H8)ۅuzķuy8m0(S (m?IZ%'r"r0XȎ"˺Lt -.e9Gb6 ِMe!c.FAn-_NQOO #Q% @bkh~ (zN[q-p1 ڭ6yD'j$# U Inz8p7pcǸ:' % S( u?]F< ja͉~mC^rC@O|ٔRg(J'lz'| yTShsb[ļO1W0b" g4[oX=8 f;Ț&.gTE$^s " 69Aև25aDz\*ErdYo}7O%o*[6L$  RyT`;D@?Aʇ?R2pKDs\C/#2O L_"+*fK$[qMCm-<ŚP>g8m a3'0Wi㛍ހL'bʿdϐBͦy=>޵Sh(ޠH3ﴝTB&wFm]"JD ogb( *UU&6JjgJ0@k#P L[!P{'rBDM4Cz&,RuY':O󛆿 3*RZ # 1Ht7KWa6[ϡ/X)'4w<ʜ9CTP<&OxGx˛oxrhK  d'$أgqdTDq+gDE/A2Lt<"w`CUgvVJ&tEmQtcqѣ8\%I+]芒oT B#.K%zPY9:̽y@dzcI~%#l$ga.v'I XZ 3GxC72rtvAQD~k%UʯA*ÿ^d5M#Qvn&+EW]eEWġ\XLd_hK0J.[<mT ʷ'Xͩ.GF꾟&ϥEC\ Y%{]ܩ[u;^)VTg$Usmq;Oij9.Qs|r\q|a>-{<TM)p6H36Ed&sNIn0: 5$_R݁QS7[NFVIO*j8)Ų3uR<+" × ;2Lf$z0eq,`FVdL`6ugcʢ0 'mGP~:2J=BގhvnhuXS-'"ݦCUȔMZGZ wH10Pn*4-R8gʻdw^V ):`YL`#@ zvܧ7mgۣvcJ4w-E uC#Xx7L]SەRnR-XienCSob#킜񻥝 8LS'bN JO ]PNeI0E]gC:l]]"1RQlSYz0Plk rM#NjK7U4%2lo!o(.N+8az#Xk[?rKV~i^4Eǵ?^CmEwk?␦RrFIe̪J/˓|H O tA͋<:j;sxf%?^o/5˘ynέ]˞>|sjqX`6ıMIwF*wujE p}Fa4$dNq##)q*S+,Fj9nRk3 |k 0Z:dEB^[ݶZ2ШhbV,Idg)C߳8JA'WCkl ȢꮼO8OA0Ka~-Li*} Ү;5j.&[%t>`\<\/w ᩝD[n*^_V 0 5NfWxe 5atT"Vcޜf @e`QuAk>.  eѭv6eM^^12v O̰8U:^)(L;.$fivUSV,Di̘¯(@jh+ Ʀ|Jxm0-q_WB;zk7(uejy-kQ $ɵqU qy*i3^. h9;-4{Z|lW{p``}I>Lv_&ܑV~1P%9}g8 [px*Asq[ԅҏD@$s= ƴi,@H g-9`^0Uu+PS(1td2OpsDtaW'.ֳwՉT=f1Ş*Q~I]IjE&-rVgcT$ iCԥH-(8y'^ME(8G^mFueC'OF6!RLOEROO}Xc:J6[+Z└[C7d=:hVy؁wjĉenPPI$=HuFi g H=VZzUңK46@o'9d|dG R4WsO1~Q(JЅ-(R਒4T9$sa:GK؋[<^ٟ_pDX5?M|vDIE}Q/X]7)'Hkh@7,EQq?^De=?]]%i3^@Eʮل*~ڍ͆[@7e5鍟T|OK[SAyu|Adzͮmۺ X%޷~|Ant< > +UCD. QuU#і N8jz(CMFj-/5zDT@%Nj!b^j#rOA[6x*T6csr<85bB9=-ˁj400B{gM&~V4nC:ǭFTwI%B ;ŀg[lN `ᲧXxބw-<8ww,zq@BKS|^Nbu=1R9bx)fip/uí a"-|@P8%5L׎q-sb`~|;I]l.כH u]8`^~4w6!~M][`(^f))G`*g1fD[`܋^> i[uV aWYҸLgtxG՗u~1)Svk/'B:ttΛ^adWU?*V_o±/b47BӤakfݵ5oN+JV[+OIίW.t5A#kH_sd-#vC[D3Z8%™,qf_b dGc򜤃?-,abEM1o&t$, [?PѷbfX9}mL12*f[$eF KX:O{y9}O .wJc/HZw:55Wzo- d0EhoCAStqʋaqXYc,lͅf G=PX%8Vt,p 9k?Me벒s7 3eeOj@SfU-#{J %/ߔ愜Y!Qc6uT. @h ow#Dn%Zd nX{` Rѻ 8U6[~?7Mt4*%ǿS#~pLM nɎ;@T>I˵Tb%hL GxjO6raHRi㪆,]lR{~YR NN}//+: b-(s2(=\%$P \r @z]֮I-~\zlQ 56LRNЦ1 ;o %ޚ)qxrtfźpop١ݩVKjh*lof񫅎E=ziv%oOKW'W)09!M)k-liHmWmlidaˤF>rnfݯp\^Ph}CG`rP6x~  Y^q`XI2pa|p0W`32a]}E>Ȉxx"'* TADM87*ʤyԾQ݄qscv L\NPRmVgFO^݀.бAm QTETH -يnt'?6f 7uy\cLG{}6^!hYtn5)2TF[€i1-2|V `f@7 F' Ŝx~b%p$Κf2Tԑ9l?: .\Cs"u:Pma)u xghN6aT'dajPw0;sq{{q}K֔tI )Z1I2WpD$UTxwFNϽ*Uo%"|^mRn#=tv / 4H*Z5Gy 94aqy-7G),G=-{3-įw>wni`?m]U,j̱_sczdd+ 9$O7⛕ȟ"6EW(K .#Xc%|VMև9v37+ثuXpp΢JZAdMTDnK 47>Wf`L;8(T8[މÜhL=\Ef3żBNkL#oM.!ѶME=FϝY4D{xeZ})Ky| Zޏ_A^"}Ϧ<!Drɚ=}:| h ߽}c>&OB!xZe92D@!qPŶ3 uH:?Zev6|ĺU`k3ka-l_-1=,ipci SF>. %J%bf9>jX:lCXpշGL Q>u!cv~b)[U6 -ZyBͪѠ5+$F6°\ 8v҄!8Py^Nvr7,^/blZHW[EufNd7h@m7B ; ~tkWtcڿ@ƫBxߔf ;Hl*-'mXŹSE eZeO Ɂ $[/`gLR׎b0!>h$*q5:KN:ܓ++Z|{^S:(_8bLr3G<>.K1$n)̂к '@U} hE] r<~A"ALx ixT߽+@Xjm?[@Rش_@w|e1KG]mC')kW$hBkSVbRнPI n]:^aIUkE̛voұnp=q)Λ:;.FɨxO56ŜTϖ# i_u=*_Μ2\#n${0+}qi$$픮9rI?=T ujޝdb4=!nFoqQT'ՀX? RCGIG2Ptr4}X ƿ-m >d&]k%L`<Z?ݸ` zU增11kPg]0d\~'lq)@cϜ&&x?մd!l|GT3fmX)顧IMbIqkNKMP[?67\ҺCeŘTƾ?`E<~ٲxrA?$2b$<QV(Hx2<;{MB):T&A~O6 U5a DW.:4ECi(Xua2|GmLBоKus8㭐FKٯ(e, tf5P6.}` `םNCaliƈ`fv Ge^+oLwm?~pUN`[P,;O&a* U*fEh%d_>Mܻe?G 1d Xl i@x0eu0hݓK6P~* kmG.Wtb`#5UvMϊ(A=L(h᧣ݥBG&]E{1R3T #~;N;T >7,Vo"ZA}=* n?Ky-WN<wXIGGK{@lb{r) Kq.M:C;# 25b_ܕbT<;L"/g*/.2|}D3Ӓ]gٸkC6ϤPE`f4I0}R͙HήV?n?|8͌ϧZ\m=QC(عV6\96w% ]_MI^P4UaP`uD{:`%dsst~j,&d ߧ 1eWe? { VLJQ?m c '6gqN&ޞc٠-K4RcZ㍷ԭ: .1NzbH?Y>ÁHOMGhu|6wT%^Vs40)"m@Sͥ A :NVq>.kA#B \.¶ahpQ ( r&n%FAIr+/1w*׉Hf-_wtږ/nKA aV$63L Y~ј>h[p-Ng@ڠn`!4ΊM{\ƘxFdebPs w=P0}O\)4οw+8 .);Aq y{WuULcqD3 Q1X"P 2R}&",yl݈3yRÓ@ckfE >X"Wo.qpV*C^][{Rq:qy?dN}*JZ#iEēQS-Te ,{˖Ж-à-ܩ?Rﴭ)ahRL0A w!.㠋=k"[ߗQ[7ѱ )mY^2a,M`dMR::A&:Jk#!azMNw.R`RbZĤ@*#I cG(zE& ,dnlÅJ.`ԏ^Y,)n, ' 8*>9YuO [㤗P1VERlOΘ[k%[HKۨty%v |HLz#h*4 G/8]ko.S#zT)x#2٨# ;o5E'l~=v  +uwu/5ϋ]\6!{43HF+F?qeNm'`p $2);g)G9.h$?'x+L-z)_arJJ,O]mFoA? p؉߈r5{+ФX: HŌ_ Xըcea3=\ =XBdwrT3m0'[wMLa}[ˠ3xC(e?6dc)e+*OB9TD"!͋9M$2^yHu.g% }CcG(d1NZ]ԂT!q^0ј_S4S9&{ǡ3krIXֿch`LDWS?@ۀ[sl˚z8d)G,zTQFT+k{']ni o/H9zIUp#3(+ys(]AH $`I 'f#%5r7P6ŋELB#Uߪ``؅ DˌZ*~ iH7(^04.r98Y}oq+C\q`Z#ee29DvdSqIJ \8Ec>6$Ǎ{ZAf ߴ= D A<@9J:ƙTr;3z; L>6 D`bNFz^L0c|zu\}[@r%_8i *;Eu=ݽNl3ʘGb[NLW(ٱ7f\PA9a&xl84&څVvo񆶉Ldm~h 9&6[mCPBNlޏ 0M3/miŵ .mLJ/\U[e/ΥI 7kQ2IXUpUXy|M\b>vcus0ckڎrRmJT?a^|UŪ^2 n%B5.kPы=a3EAH`M4aצE8_ga-ڠ~ ZԆeZ;/M[GIG|mнUۿ~n;閭oyͤ(A&H(o ÊIf` ?v3,ܞ&%jD Gcyd:GSצb=7cE+tNDfӓZՄ%1/0۬bKؘfqfϑ9 v[Ydln~f`vt!1Bv7^2dJɄf޿,I^|_d:U!v,$2V|.B={nd*ލGOWzP ӳYl[QYR*3VV >FU0|{vw F1w?AfjC[#.+n7AY z-Վwg}a[>Łv  R31ϗjl ҥ Wc:vW>qvJZo./rG}Z}*VN585p(roq0j ! O𡊴 oi!^Z):q]5I#hL,?h ~@Uqd&{|x+g&1{q,BWFl_lϳKZ\TeGVلp4`_i].x ,6XοMZ7}h(s{hnWq< Gѷ^ \b3@*]t8Hb I]sפA$;i㒴&{1lR-~U|+]! Fu$8% /hh]{v[tx ;}v LI<7y+%Ml` VZNbA9Zo1 NGݏwWı`\}K$͛Di[^Gw^W͢lOJ9hZ$B MHm7=OЛ2Q]d[Gfd \7 NL31xuՉc+TAԹ^qDbոcPH U7 m(*!J;bjR!&1dЧdWcPTh\- /D?F B"֘Z!(5ȫrZ:DGB'nM2ܘ|Jhkj9y"0vȠޒGsEO0n6v%J@^&<꣤INcqu/Ю]]{^B0*lq2vÌsasnqk\%4cN97ZBP ʇ!oԡ?nMHD'A%{LѽsUeK6OuYڧΣY 7 ]!\t'f"螩hG.)uQ&:T`w^z0^ZЧcr~U *Ϋ:t 7NZeit2{TIXlˣTե۰xvʺQBð뜯aļ od6"_=%>}L@O"H$l`Ot賻k=WЈYAّ?+m:#/ 0n3XbU摕Cʹgv̂PIa b%&e3}E3iȮi!}.)R5ꌯS4Tc;mkX0 b6!wT0YG SgW@ȋPm\f֡E"G8p_vq}w,Yb|gy!Ze{ }t>fGX}脥׶J\K藅BlT4Z6+i D݂v:~z'-~":M uJc2<%HcF^]%ҩwF{gGxʾ5&giW4f?W~$C-j(*pN:I 蔥)HtXpɌ*QĹnjTzmR`[v0J~ujOj+oݯC r%OӶz"<3քSW!+WzɈ]q0Ht=;a]_TuDZ ϯ[V 3םA)NNlgnɾ'TqZq37OS55yuȆ4K?a6mkk.GjcrZM" >A^FP~9W4pR]Qے7h k_]s%j\ z/[5O^ 'SF=0.m4fSELHפmC~&!i$QHE-&}tx'JNSM+zdng)v;@ s\剀j|zڒ N|G7JGĬx0Q}5 D-P9?TP]JHTnDl75Qb#/}u\[n8Н=ռExo&y@`!b\[K[[Gn$Q@f4d=f ݛj|/uaӂ -g?6 &37IBeko_Un:a'[ zZbe9^heęB*e}cY<7w˿Q5~3J, &}&=);֏_١R6@Sf~"-~9$7 >1Fw5lM!r݀iR]'AwYQS9pB<(iV]ȍlFKjB"$2s7&SaI,`?DfyZ@CcṆ%ߎL xSG%ͲRpR"R[y |Gc*b&JoN>AIpc0>д5/Cԁ.]~tkkd`O]`O~":L&un(r,Vѱu { MW!eٟip9WnWc֑KC|TNvBl<{`.UW_'.Ф!LDӤ_+ :!&#讳Z͌>J\LE&R|Ԅ۸P ߅&]gLHsvvB|5[ww'MdU3L8q)2)ߟZStXljͪb Ɍk ?ɫԨ6+H!L澪Nf-W4@x|+nzrL,҄ȑp"Wzk]\BS' 799/G25\ Ji8u]0|P_;Ȇ3ajV\B~GkxɠЗlJm3Rl*)hHg*i-yxbP-6'], WP 3zPr*7oVAn *}bQ3ك2؟I,w7}mX{I蘕+GJ[ #d_̜ǩaI_0v Mj.#oK2D7p9^d3tiTTrL÷Ջe-WF@mԦKW_&ImFXZ'VL4n7Zn36: i56xAyVΟk=s Is~1cq JiZĀ09U+rJZ83}/X(,_'dxԎ\61 L4Y$1U.k%,0¬)a۫_"*.>O>J]wSl8G \@+L^Qswv\Y3A=P;;,=3*YP%-)\+٩ϥ&Yşc_ˁkxl'k!c9}VKI6me亨Qῄ'ZnkV$Zx<gsn> M)I_W}U)KMɱaBqB 2t̉lάs@_J}"OS?yVvlH\ŵFH~d0h*aM F0x䰞D>9%cMU'mC ض8Bq,rE .co[A|kUT][0aȖ_5D8j&IK ,ovվJĉay/`mwo7b|KrA|j'DB*!Ue\C|* #aܑ~'b%RĜ@D3/^~R4ח_3I^Sn3šc10Ei>{nߨv" |=cEC=#]v1g0qV ńXAc$jq/'.$/"g vhz=_<aĔ/_v#0HVNؘ^a~Uiau'mYxjzO}yxhpL@|̝hv7R?n?Bae2Nfa9Q~O9aiw%#ćN,: tc,BYxP0u iɿvt1`U16Arx.S02]c>rFzrrP|Sf1k3O^ };\]NI58k#qq8 Im ~ xd-1BHgej b-C&Fbhgo^dPb||#2/C0rnshy)CQɅ ߌ5@LJKJ& '0<{[ݰwIb|'\=لHBnUiaBPa>(vsUШϟ YE+:._v@&$cӅҺ!b}[":`YD+뽄=N)r=Uh{gJeͬ\r T<&7"qM!eճF*Ќ&mxv1>i6vjVˉbD6kxj^V HB8n%M6>HAX6MSL8gNR|KtG2K p %şF*odĮt -Bnf[OZZAEfx֞C$[1RQ&+ R% cz3'X:>}M i2'qck}2WΠ( #th QRd ?<<ٝme#`$$Q³}7e^ҲB?/Y+L#y@:U1vn\~@@#>,RW>t)kI'l DaTRTM8#Yn@gkvpyEj.uL)- d6`7XqGa}ٸĖM 3"zu|JRJ5$i;oXR[͸3]\خX˗.pԷEq/R鎍⑼6r܃`5d0jtb@$KYUt%c_EJ]ey j{Ry͡H Ws|v\~,6ST0 "✪$h3 d1[{QG@@;?)eBĽ٣ef"YÇ+p\^dXQʅ_SlstJܑ&Nm8#aG?J53`Gm3_nDGu d<> 9@yaVu@Rs IA50NCxam<>&V Żǟ0: Iq֐yjJ7 ;&i͙Bn[p9St|)7o|,k>kLG$gj^?xS`' {䔹>z+؇]W>Ұb1B)l*+vY=KuDt1=mC?.g9BL"Jwҧ%en4+Py ۵lTy?{ 3B @UGN ƭ|soV[rrǞn]'K[\a_nnJ $-nw1FÎ| 40[ <+E~܆::wM 6 zR{[ rPOP5aS`fAx}|El3cIOA] dC"Ȉ348)=.ytG4L<Ɋ@ӔIw[.~?mǫjO̧~OuʹGywH ]Đ3kdÉ!8TD_g(̾Y3Cdeh0m3? n.;7koӰLrt c̪_?x,(q*yS^[X_ʎlL3ս&U;Lp8aTY1Jd-ԗHdtތn5vy34aYq7 I wwd`(6Ɣ6alV[Sj/yyANŠV[p  ;0(BC\7a@J`y!#cD>\(J D"Zyp-j7*\@I2 ]>YbEx]K-4@L9I)=3- a2/? Jn6mh>e W$`3 @x[|pAMU~)#D*gT&[g<&WƌPP`eԃCO!,qʀJDSzqP}k!5~Fi3ԥ!|Fe$g0wj#~ra  fyY) =vMOhV{@@%M/B0۱V2b$:d'1ږ3wL$f;9xy|y a`9zYZ'~) 4ad*FZkH t3A^;ay I[9&fIFJ 'r]w,>qSɛVU%#L•0$t*G'\삿o79"U'S7{;~)9(O7qg8?m)&V_pEfi9w*,zd3?"ؼBhb^wf>z2<#Ȳ>)WEO6uGxxbPgE/Zo'[ fSKyǯ &Ģk Z7N~Q͐w:/w 7I*:JqtP+o4)s ߀!|)5Vu'N6]fl -0+!ذ-A܌St%d6ɿMe#z$3_66L֩e Jպ8~I&ⲉ?ǵ :b~J`kL.KJieqECF{!#}&EķAN/Mҫ0Tl4qT$WDcs1$PB-GآYfT()9h;`!2s*or }4-Cwd{n N,M+zb{o*rc8F&,6rM phmyDuGMk2t35PDx z 34[z kɪNXy q0sCw>Nd( A<ƔzR4hѿZ3+9lG>=*qn PAښfu™e B=?K EbQTtHwTy#a/-nO]UY`uڃ\tv{]9S=yHSy`ynDJ:iqkLPdV҆'7%_Al-f. jEطP(9~nbu. \,{a}NXJE%t1_>8[g؟z7<+ʾ޹cV-`:(4)\> ?o1(.K C'>X4""BgHha&}:-ċjgǖD{#Փ|^CccG 0 qv}$璖v߽Q!j|cYY` n.bP<)/W%!k&ILI0@K{ Z Dj1G'"wFjRqraJz1L!(FvG؞\N3gBY\ʢ7қ"=VkJ5^ة\ *ABcX!>&ܦ+X<#<:X@DauVIJۍ]M)H V^؉{8>s^s.1bVc$LնρݡYq<89!E`3<]Vz?ldy+Fq|RI,)oO#+r`Am*N_?Jb|;wCrӁ,,F EN-].lOK"]X;xeо`_/LECqD Ig𺽣 V y2-e\]E?֭ UCYI,"{be{;yE归s&cܔ`J+ Ksx$RUj[W6:=ׁ/yn~pB0Z)$m@l.ygn)!a Ϙ3kGa*O{#y920PaVJ3Hwqv!Nd JFjq*o6* ɬ{t+'L{8$Tp%r|=q+=mʼn>iQb akR.7i tLuq+Y?gRB+/ǮE US&6:ڃۇdu"'#w _}(>V<|(i^p9x5o^.0֛00;+}'٧Mf!¹r۴Z:?W p7J`r" 5MT}.q?{g6"[v8^r Y=`MǫB_t ~NZD>o&>re`}# Mg f/gk$b%<{=DjlN*DXVQ04|fUi1`ưQѼrDM9ܭKsS?L߶gݵmއȺ4jr7vRh#+Ftq9T̩MJxڅ7^W]Ы/[+I>$\g ^Rߛis)Nn~Ơ`$ԑ17tT/3v_RoFg]rdG+*?o~WNq|/+%~4^u@d-nARL6&8NU[gzÃ4'{f{`h ryS1`pxEHnRne⅙ Pzx?d6ADYLu ;Zv]Z-"W"?\" ιbkQllB6H6$_=5\uO K"7dMW3kӮ%u~N㈗,r/ Z$J.c?=! 9Ig+%Lub.WWNFLn';ìkM2õTP, |ZκmakmwE'aKHKib{">"הdj&f4DX`3(&НW(gl߷#M]BlgFq;BsΪGWf2ΰa[eF̙/KihÏ;o]A9KtFZ|#!ƈ#\p?;BbB4,- 0dPOiw3DyP~ wW @A>F8&E+C6ՆhxoZR:Ċsx"XЯq`::jI}]uD1M(5hkwE[ pۧ R@.E[$aHw~LE5a /ҥF2f_0yVnFT=2V~BخP!,gF\ɬHӄ-X9Nlk;|JH>5: '@C/K R4oo]VER5T?Ӫx֠Y`ަHLC%E*(ia[X"sx/% 0Hnozk5J6 ]uQ_藞9$`3bys,Ld?Ѓmh&ZBqqn5[-["6vm; XE?Q% Cݻ^"o܂U< ~5v]v;"]n0T;O⏰W ڨM돆2Y(J\ou"J]T1:&рNՁʆ X 2Uz=$!]iRU`{{,^PԳtL8ƈ@8/y? 3|avG2&K+SrF I,vGQZ*Doэ=S>͞ j{`CO29 toV]ĀIzN Gʨ.="( P}OL1^c{ި"LVq/(AX==Ⱥֲ-tuU%U">]L\$'=iś0kk(A%.89C@NՕd/5hw֕ZZSDЈgG>^8qU&lH5esfXsgYPJW΀iQx^<2ؒ1E+1vґ-$m׆ , 9Kaze05K:NL޸LFM%^{r=r734* Jn8/up^Tъ\[ZOj}(BWbVV}r1v=`M* HwU.%y>FL] b!a⯉g\jiÈƸQ4i3T-'Dm6\霬UX:' $㟶9[Lj9TPu`O~PwwH-$z(V$:%G \i0ks.gU-??fs4;tt󰥫C'VY4E#{s*w |j0pJ8|Ok#SwѺxt}fķ s30X1Z2=O)8(4aȚD 1 [{9ދ﹖CI GLGG Ŀ++6T+?ni. ORc <4 @Q{ hU^J .S+osH| 8N!$Q`QeRس=g9{ Kc %ڻzenby*sjGD c~[Ke-Ka"Li;.UKjБ _nI<ô9܅vf5ޑP_)[ я‡ A*U?]"S^؛Oג*k_wΫ,CSa(YK/p \4pBok ~!g-WC!x۾Hhpj*3Fr? '΅wt*suu]8|:lQ-+{whS,mz(d4 gqjv4_7 -{1WSRնgS U = їL'u?BGґ } HkM6d^j ;"gU,6q09@w޽-fQzLU j(!=xN:s*m} xqeݠ!wh#qjd߶[#`vrj``5odG8G< 1Q1kbݵtn-ɘb2Fބ~P7:wύ.5ab=h˟RjF,+D[:X.ah0Qsfe0^M߲FBn_N+V%f/ f䟔{GlK0lKu ͚Ϋla9F F8@ ./j`->>)/M+fp̭U56cA41[hϏcVr|f W{a[i(GΡ_ӡ` ͎lp|P">m,PiguL. pye&:[^Y?3]Xe3(N0lt==pUTϪKQ<]?6lե^qw}ΑBW_-_7]{Ĉ~ ~Y fqO.ݙDֵ#f Xr4+Q+V]j[ϐp*\݄ lrWP!1)7ׇN"p]E{ºs{YgQ$kWoL f50;հyDY9"R:#2 EvO*Ld\d(!ȡ%eYEcx/Y)>4ۢ&U- |Az7~Zz/ .x^Qg#U#ށO8Oތ |dNe[kWPF (y3g ; 4<4pIXX:S$K !O-Ѧbz!GmLy?(uS/fꏆ u8;me0ߎuq|:7f0D]JÓQx+VT8n)vNR\ ̍}ָSW?w3gO2XVPTJ\e>S8]Gi>ohz!Z'Q`Z^z`d(#͎8b1`ZW 2q;Y|`ȏIq,\<I3g"_THkWP*.S@w^!RFVd,~ݸ! 'X@'ǡ8݈=ܦ,sm<~MXUf_>tK'U=/lZ@cX=6P@SFM)~81Z'[v~[eK-F qM>oʐ"{F}Ad"^.e"r'W5Ѳ֔y3Ap*.JBxR.mЉ۰֏丏 fTdCX0 zP^ʔ7#yh}MKg >dyykgʌMJn5Ԏ$*l]^=y2]F+}n!-^:cSuqֱak)*n y >߂N/;:6Gan{J)PtL0hv(0Zi)|I>jjպ, "zѐ]wx7L&c8ɟ. 攒o:-;G;ج8Dc?/2|0!`a}1%!L8dlv*n˜Ί_Q'^XuAnV= e2FʳT+}˦MS;;l:w;=ا# ho8ӥ"D};w.Sh,LnW? dp1!W g#4fz]Mfp] )5}8Bp?%fo%О e>ƜBVfDd'ɖ[n&ѾмF&RϏ]lp2-X)/ugbW^dt܌q>!Fzj` ¨D~xH4]Fw{Rٲ*qI&7S: d $"d"jœ0Shb:mg-Lkt1awSuU5л~8Jb?lƒ^ 9]{?yu:,|?&5Vݤ s9~w̰B~6\qo bbeT5e毭)MCCS{ Ӯ_Ky$[,B.7SgڔN&q ߿tloZ+1go]B#$|EoҰ%ȇZAAȓ3#6qK`y/B.Ђ +NX5!5;_ x @cU븑^,,A1aS9_Uާ/|~#uL [rRf)ׄxɩDh 1/:awWM;27nmA~cOjk*mEUrVP8KQ}]\U3{#բ..;kG=hEji9/\@uԌ|\C2Ae?JY?+Ei،xLjy2]0_LwJ|r5BCrʗ7+lR}Y~SeJHpefm"~ގx[{*ZOt$ 4x_xEn ~\7.vjq~rsfQqg0Vp'l3 +\M4yԽd&ʄ|AtC29ztNƺ0t+覊 g; OH1X pH(u[o`Ѫ}q tS|ߴ}2H]BlqD- b^G Knխ~Q@AIی+t,"쌄@qM 3b&ˍ 0p%"| 9uf$^AѢ8vasHby"j7'(]D ~_A!)/Hf}KhGWrY1<A1,بL O4HxYb"9\j&d蘂 yG*>0alV&-y@cgOm7%vϡz;1dX{6]ԊJ 6(+E8ɾ8ha)dy 4qX/=>8`0УDWT0# rCbspF0>|`RIpoi!ߙ'o5+jdԫ.eo` fݭ;G)GJ7UԐ>\8I 77ʬϵkVBl\\[ul=}: dV7id ˲-2"n/al1 \>Ęh#,sm[_RDi,|0!"IqUcoL2aP uuc[OhkC*]YS7P+xYniR}m7D IJ^7U丏g [}*e#&7-n-|̎$YcC`=ܮZ=Y``kK` f|k8jڻ‘ѭD|Qw"џrL(^n&Êu;~"M}q}Gфש V5eV)/=~QaTav׶*2.dvY K3s9 _{]Glڷ A saa$!dQ cfN[U&/_̈́ @4ֈ9:lm*3J+Ynƫ` 5I TSU Gӷ8Ю3< xy YZG\GJR] Hro' Xm3_WJ%.odb>7u5b_D9qlsýXE(wlmw?MDΖTB X[¶5cśTk?lsIWw8b]T"h(iϬ3``5rJ>雴q,`*_7v:ͱ);붑 ,ghiTc̼MU\°{% 3_Uue vs6'4J27 5N–c&1`,-!|rgO.XK禂OyX>GNHq_A"=%V"9[YG㌔KY:Oes|/0> ԓDDI_a.;J1,|aMDt݉LBhUbSyo~EIsލ>5֣ǧ.P8|ʮ];aq#/"d`9 7-ޑfX*X>pxclbdچ+ iByJJf!i+E̐ny J}+(ϋ꿛vm('`֮eT |V{K%n#ѷ JdDQk5h Ip*iDq켺x{/LD m2zyyO [mk~&U[aݍכk4ū:a٩d͘]0Jw@\]B[0w?`nS&tb M$^ ȇnĨhnE׷iMvP$rݳ_zD\@,C')eb~SN }Ҩ n%W{ij@q8|fp1xG^(weۣ+bxG,@{Fl(Ukz݀ 'akuL+8^t9C^al+SN3L_$@B'~Bٯaz[}2dEjkǃ4dSJQA ヘ qHƼZ*E`~~Ethh9ÚX}ݴ_0TEn{FoϞhܗt]hԩ '~%WLpfފ$:qFk/t?FbE@.ʣUٝ: '7BkqUR,?`aQY5,"& ax:G}9L9^DKŁ7naEcs̩K?RaωvZn%H! SDuO)<-bCԢ<6!00eU+$_ Wmmu V ;$FȪ'Rw'hyQߩSCs|=^)z8 \.Qgʗ]&Gi{ mA1(lBM/#sDPY bB¯U+*՝C<߹xee{YEǑ6pZ yɥ^ ھ3X9f>b# [c؉_s@fUQ>:xIޛưAPG歸E uQIfEd"ԂcNpS3'm'G]ݦㆲ>^Sէ%Dk#w  0VדٿvVfk0 #~#Tk2_^gګw@g-+dԳyd § aN$'4wuXu#NXWSkG5Io&։NWtdEu^R>2sR5Y)"u7NyEG]hģ"}r2 Kh(r˰anM4SU3H{#N՜֔yxu09wϻt, >g(u7,wL7ހɾ 6re\|W=9'6kjpWlG-ۤR, Li=?p zŻUfhW$@[6~߯NP WRjLR@SR3B}GP >?++ĉo %aN8>w01%22Og}9ba Xq鷮CܒJ pvo'T}q2C2Qa 7S(ɏ[7 ݇T$26bڂ䌜j M!lE`u0po6Tz%sꗳUbHR464+q؊ |CH7ԕ:U)^v6n|+mh(-R`\j̏ 3s/փg;aJGӋ_ا -^?V*k|Kh J&6}fIy&ƫ:1WyHsuuw'EbX /BWC4bPvzKIؤ^u>PmXQ`nm|'5_=O9I67RPX IP]r7DajY,BlgsZ)h.Run?p`⤏yݜ~U/ s'gsE8s;A8vش2qs/o)6,j19σ,H.d!?d$INoS^?H6zn;۵f f Iv-|ؖm9u|,Sut$35VށwViTp6AVL/ٚ8%`%ĚIOJ'36L`]ϒClnmA 8cS?i{$l+khޛk섆3_ | RjD9`kΟ6\PHI+^jHZ9$)L|nj%ytϮ@ I\woZSZX86 x %XJ 2 Tݼ\sn1m)H e~9c9D,)yS"koΆ &dPX"xP` b[i[˼;jSi,D%^틽_ :ێ.ߏTLP `'oO"cuY%"xϔYrmv:R!bp&29q! 1|@ާ(%|GH?tp)Y#^ع$Uigv,N[:}HQ3nub@*1!>8a()wQwװxg7/՗H ռn<&m;?Ph,%1X^w8Y>#Z"bH{Ҫ$BxN3uȼ o`ܱ-wS [%SD>uk(wL\dö5&h: "h#\Q7Q^p,{_\+0$7ǕsdbݫB1ּϬ j%|R&d9"sPaY?5\<c?b7j+_Vs}q:>^iY ){.qUΡ^W{E 6N˜Ia>iӦZO:qM4.sTAWX hI6ć2@yvo۠] 7 Ag1Y%8)۵eS=ɯK 53S g?S-Lq;UE,( <ږ[s|NS*+W"zZ.zk[K-ϲ} w,X\L=;=Sw:8(A-aJDʧ"Z2gy5uƈ`iG =:$$n2(ʎ1q1l„3<۵q_Y=qC)i+{0swg#ۼ5`y  ME,rb܏C3Ų15ؠ]7|OytOeh؊kl):1k:Uf)vl?]V%ܷ%r&ew2L`7:Sf'/ ]4+^G#( vvߗ{ [׃:ε{Sh)?>rf*pEBSC]jst>^Vi6Dm8Cabɋȏ4S[t#:4,N_iܴ$H jid.c^\1_;75fQF8 mXW꥘I }e78*cm \UoNs,[_= !e)6:WW[:hA0(T&qf1f#R 9{)JK=)uFEh> ,ۜp# 2"3M؆֞?UY\8űT?ရ+5S۝guU2gH+00ZRx+u^梄5MWS=S˘M1a7_~ϴB6+B ,1Y&N׃j.ܘHG~Ns@Tŧ@T3 bj.áG u/# 53)dᎺJɦ_LkbSb;!W:ĶжjT7s.k) ?ORMq#1uk)O1:(PPU6'Eznf= h feg>,˦= OJAz|38 P!2HRL$2^1LTSR"`S L?4E&wk7v;v`HqSfQiz$sTMb1:prɅ%?P 2ȞOVF Яt,lЙ_?8/3;B W2xQn4F! mrPhZ S"*<: kຸ'mXR E rfI(.,lY ܳqW>Tgf5b1͝ tDkB!N&?]gPO#'1Dp+rfG`VK*TcY$A #c%WRG>ʧ|)`6AP2Xi$͒o鎓s5LhUup X\[+F