samba-dsdb-modules-4.15.8+git.527.8d0c05d313e-150400.3.14.1 >  A cp9|S:A* c>+~ 엒έ(5s ਅt\3ruB1&%Ug0y֪.Ɲj[4(J,@%CJ"ؘ ;@2c~X5Ѩ@YSnjTuVch" >/W .W}c\[I  u1Y!$z_(0_uo ӆ]*# J12a/PcS')w DlVd3f625d00772709a7849a06ac121e24b9a522df8f5e27b15f34684b7ec9e9d54b0954cebb0b76553f2e37e75390d5c3215fc3fe4|cp9|(swֺ.=} awfz? "XKӎf) {lc~Gh"}{c!qOhhy4㒙,1:39D@y [ь~M/2Z- ig1~_h>9_u4Zn;3+@R7 6<gwm!\YNjXъLQk : c>7  ޚy-!P[{|`!O%==7!$YGidZ>pAv|?vld0 > P 7NT[-x- - ,- - M- |-0--,-xx)x(*58*<9.D:?r>Ev@E~FEGE-HFT-IG-XG8YG@\G-]HH-^K bKcKdLHeLMfLPlLRuLd-vM-we-xf-ygLzv vv v&vhCsamba-dsdb-modules4.15.8+git.527.8d0c05d313e150400.3.14.1Samba LDB modulesThis package contains plugins which add Active Directory features to the LDB library.csheep21?@SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Productivity/Networking/Sambahttps://www.samba.org/linuxx86_64rm -f /usr/lib64/ldb/samba ln -sf /usr/lib64/samba/ldb /usr/lib64/ldb2/modules/ldb/samba /sbin/ldconfigX7Hxx(h H HX(x(((xH@((H88(8I(WHYH(((8(HG(ccccccccccccccccccccccccccccccccccccccccccccc29a60c218a9078eb4f9d4026b6c20fbd6a242b1d2a5c208bf108797e1f96bbf895335267caa26cedff3c17c81045ac7ac572de78719518ad520b503965059a2dd05c21b71fb1af09d7851279b19746a88e83ae64b9c31b64508edc677bd9f21678db6eb40f8a5113ad37382292b6f9fb840901d6dd6e3b5709addfdeebc71d67b7e47a80878122e3516444a386557de39c226c20d85dda16b693a79070a3a9298cc7c2b7027907b0498155e0a71e3c2c7a73f4a899efc1a37ed6b49aa52fc8dfb4cd688f4910e659dfbab8f2a112f9d9eb01046089f8023d356bbe8b461b2cd9d181501f6960c04519c3679379772fc42fd3c1f61ae826cbd27f7ad7bb9aad32a2b06615a85123ceffd86f55ad39bdab7cf44523ebdd8144f6ce888b20cb7b995173875dcd0269af0e61acda014289b76ef205632c6d9cf5ae5e548109149a0b33957e0de78ef65826f7ee523f63e3704a97eea940144864e017a2a954c96afce19aac22f734a6ea6b2616af191eebd58cc7c676cf7642fdaf206fe57cd727f225afe7f374afc58b1e7ced6595101c0ba3753171149f964846cc7759cea8b10856ad6aa9eddcae298c25434d2d84736062516b7cfd5a20e9ad7a69c9c8ee72ffc47d4a747d769a280cf3a0dfd65918e2e7315b078c8515b4d62134d46a031addb203707aac57f4ef04792a559867ed8e5166d41d31b81e2ec9316e97ca0adf0e0596a41d3d7beef57c332370894b926b53c7c87d4df155259a93b54b0e94e7c68aea3d0d24e17f18e07992447fd7dbc570bd00c15f73da81a8d88be21add0f0f56c2debd6a1a685f06e28ba3b952fe716de54e775cc031f1256f773d55c0b474819c3045de5e1cb4f1fade815fa0ec75d4b5360a634be550e037fb667c8b83a7a874487b07e6cb2f8ffbfa208eff5d1ce6f432274ddab1dae62886bf60c9a3f5494db6b924e22cd0ee4876d31e50310de983abd75cec6b04967111f5e100887a36b8ec0af11ff733b9f40876c0183d2d88ef9dafb946031a0ed7b8b4dcc0de4865340897ed74859887d7f3c7c234bb45ce6a0f5d293be14970840802c9ecce066d7e0a1916d0ea42fc9ee6a6791eeb6c13b042383e3c17123b7caaf9a65eb91c9cec753aaaf3d7706662ffd596c59abb1ee57b4d3ba4072f3ec8a804790e8ef7b7e346f1d5be987065459bdaa4f873fbe1e8ada50978e3d715c8ea4c3a955eb761df57e1eb1a31e85999c1ca0b3c6b1235d1d333392776d000b6c77904c3365f1f73f9d61000dbc15fed4e66f63cecd3c913a9ced51621d82f3fec3948ec069beee02c1135dd2f91134cb72b2bdc7e4fbfa0ecb9491a674fc052b04bdb8d31cc602caa2e7c8c648cd51b3459a865f41e856662c03c08fe20a13c81091b2b7c341fd87140aaecca6cb848b3a273722eeb970fc5999e7fdefa811aac64a00e10d6fba7b61bc6170c3392c82c03e05689e823bdd388a4e4b75f090edaf3dcff1f42f518dfc1172afb838e8fc4f58772ccee838925315bce99d28c74591c21872d4f6fc688132a23f5e51749603a606c06dada93bede549b2c6c0335ed8286887e9d109adb83ecad60f8ae6730e3ae6a073f0a154ac037fc02aad4c00c1d1f49077ecd3ba2baf6487d34c10ff48a73dc13058d252e452af6d44747def3f02e8080cd722eda840cd827cb0d79a6882d03b03b0e68a0a6360beb66f3292e59efe099b226a8848fa5a0ebecd52ab0226f0917bf2a2ba12c13bbfd986d2319c7608eea8b223474e8ba8ac031dac509df90c3ee883febd0147d156cfa2f37202032854da705009f40e7952bfba7c315c84fd4efaed4926cdf3238b0e2b214decb31560d30cba4634893ad0b72bdaa72105733c97b50c3cdb9ce29909fe3b76a4b23e1a1e60da8ac50590fb2b288aa9bb0711b4383ae01461ada21b1321bc58b86f65aadf99f15d799c0363d90f7bf7940dbe57f0cb5a45329c1e745ec9323ea8b8e7b56d1f3b1b55d2344bee8b2236e3dc97d793028be15cc93b339ffa649bcd185d1648drootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.15.8+git.527.8d0c05d313e-150400.3.14.1.src.rpmsamba-dsdb-modulessamba-dsdb-modules(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfiglibMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgpgme.so.11()(64bit)libgpgme.so.11(GPGME_1.0)(64bit)libgpgme.so.11(GPGME_1.1)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.12)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.19)(64bit)libldb.so.2(LDB_0.9.22)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_0.9.24)(64bit)libldb.so.2(LDB_1.1.0)(64bit)libldb.so.2(LDB_1.1.2)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.1.6)(64bit)libldb.so.2(LDB_1.2.0)(64bit)libldb.so.2(LDB_1.2.2)(64bit)libldb.so.2(LDB_2.0.5)(64bit)libldb.so.2(LDB_2.4.4)(64bit)libldb2libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.4)(64bit)libndr.so.2(NDR_0.0.8)(64bit)libndr.so.2(NDR_0.2.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.3.14)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.15.8_GIT.527.8D0C05D313E150400.3.14.1_SUSE_OS15.0_X86_64)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba-ldb-ldap2.4.33.0.4-14.6.0-14.0-15.2-14.15.8+git.527.8d0c05d313e4.14.3cM@b@b@b@ba@bascabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh/sbin/ldconfigsheep21 1662104806  !"#$%&'()*+,-4.15.8+git.527.8d0c05d313e-150400.3.14.14.15.8+git.527.8d0c05d313e-150400.3.14.1acl.soaclread.soanr.soaudit_log.socount_attrs.sodescriptor.sodirsync.sodns_notify.sodsdb_notification.soencrypted_secrets.soextended_dn_in.soextended_dn_out.soextended_dn_store.sogroup_audit_log.soinstancetype.solazy_commit.solinked_attributes.sonew_partition.soobjectclass.soobjectclass_attrs.soobjectguid.sooperational.sopaged_results.sopartition.sopassword_hash.soranged_results.sorepl_meta_data.soresolve_oids.sorootdse.sosamba3sam.sosamba3sid.sosamba_dsdb.sosamba_secrets.sosamldb.soschema_data.soschema_load.sosecrets_tdb_sync.soshow_deleted.sosubtree_delete.sosubtree_rename.sotombstone_reanimate.sounique_object_sids.soupdate_keytab.sovlv.sowins_ldb.so/usr/lib64/samba/ldb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:25691/SUSE_SLE-15-SP4_Update/b518cfb68f7ddfb5e239b417674eefa1-samba.SUSE_SLE-15-SP4_Updatecpioxz5x86_64-suse-linux  !"#$%&'()*+,ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0749b5530ba841fd52c83778a39136a25a20e49f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=86edbe366e33d2f22b7888cc50f98c4bab9b4f77, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b004eab258990dbeb1d836a4b23ade3ed00dfa2a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=33f86a589a7f0a90285ea4e318d18830585caf98, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cc8fa5a76fc7180adf809218fb97c768985f6703, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2652657a7bdc0c7e6ca0ef6bcd345a5e43f550b2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cbcaef90bd7c28859c86ca53ce4cd85db42f766a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=66220c038c87a519c29141f75f167457c9d67c2e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=27f0f897f91683107579e1e14cbdbf325a9ea3b8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=62ca92deadd266e599839f98d46345594f051fb6, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=eeda1a745c4e4e6f62594be4dfca0ab187dba82f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9cf99eec9079aa604fa8587d0ed9df80aa4cc2ec, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ebe74a13b5e6e4bccd0b771f33c95a3b698650ec, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=03ef2651b661fe671bbc469994946c53d5fed658, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=434fc1cd22783ff18ee8d52dc9994d734ad220b4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c484cb6af639e8f3e7adf6b8a60dfcfd90909f16, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b25ab9f95f158f63914104e4ce3d414245a85836, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2bc5ff7413291c9cb2943e2ea44c98d62ee2904c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=12d9575c4413a7981df625cd50c59a67f64fbba8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5863395b1f0dbade3a23243366d633f1b0487cc4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4fea0d66c83d13578a2d65586d1a0e0f63a307ee, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c25f76b9403a34248e8c3399ceab9afe624f78d8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4fd513cf8f850793b78cec386d181cff7c62b055, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9d9c0bd723b30a6b0ff20c7deebc0507a274a6f0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=18509108203ea75a9c58e3584ea33b89fb1b09ab, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7cda5905fec8653743aefc92593ace8adb100ef5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3779c49a66b53ca0239e139930934c2677c052dc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9f22a6b8331ffacd6b4496f69c260503e09bdaa0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e01974648847fa91fbfedc0a117256e7a075563f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=144e9b98d83cc89a2a81d40ea0331250aa3f41d0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d02b908785fcc01180af029a30a353d7b7938acb, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0b24453a4c58be444c9b32efbfdcd37a9b581a0b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=aeb20885acb1e72a0141c1688ab6b6dfa2e3d5a1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d65765450fe901b26eb05efca1016e36e07eddd2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=abc72f875058d8a8a57a566e69142e1aec3a580c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a582a6c99cb39c5611b651fc4122a7819efca7f7, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=47f05385116bcffee4d874fc7e0fbddcebb84a1f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7121948e4df83609ee098e5daa796a1a0d54db3e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=61b6237fecdf094c37622a497c50ad34891bcfdc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=482c99a60ade303e39ec46e2dd1f63f2c9271ce1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=aa520df49e3f38277cc7eba1798cd746d4457359, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8d1e5a0803e34e1bf12768b5f5a4c3f20af8b476, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=516fbffb54812f9ae0a85576e578b325618113de, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5031949136f79b3529bc15209b8deff6fd334277, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e1d9051d88655426537967d4a178e0e5a90e63f0, stripped9Gev+FQZs2=fs+<IT_r   8 ) . #  R_RRYRBRR.RgR R R RHRaR,R2R0RURR^R-RGR`RTRRARXR+RfR/RR[RBRHRYR_RRgR R R RaRUR3R8R9R2R0RRZRGR`RARXR^RTRfR/RRBRgR_R9R0R2R R R R^RARfR/RRR_RYR]RHRIRWRgR R R RRR[R2R0RURR\RTR^RGRZRRVRXRRfR/RRiRYRgRkRUR2R0R R R RXRTRhRjRfR/RRBR_RgRRIRHRUR R R R1R7R?R2R0RaR[RGRRZR^R`RARTRfR/RRBR_R%RRgR R R RHRaRDR8R2R0RURRGR`RARCR^RTR$RfR/RRYRKRBRnRFRpRWRRgR R R RR2R0RRURRRERGRRmRXRVRARTRoRfR/RR_RaRgR R R RR2R0RR`R^RfR/RRORHRR'RgR R R RDR_RQR2R0RR^RPRGRCRNRfR/R&RRBR R R RRgR9R6R2R3R0RaRR`RARfR/RR_RHRBRaRgRR R R R9R2R0RGRR^R`RARfR/RR_RBRgR[R R R RR6R2R3R0RaRR^RZR`RARfR/RR_RYRR]R[RgR R R RRaRR2R0RURR\RTR`R^RZRRXRRfR/RR R R RRaR2R0RR`R/RR R R RR2R0RR/RR%R_RHRBRgRRUR R R R=R5R2R0RaRRGR`RAR^RTR$RfR/RR R RgRUR2R0RaR`RTRfR/RRBRgR_R R R RR2R3R0RaRR^R`RARfR/RRgR_RBR R R R RR2R3R0RR^RARfR/RRHRgR R R RRaR?R0R2RGRR`RfR/RRBRHRDRWRR R R RaRgR_R[R2R0RURR`R^RGRZRCRTRARVRfR/RRIRHR R R RgR2R5R0RGRfR/RRBRORYRRiRgR R R R RlRkR_R>R5R4R4ҊZlVUO 02jsɆY%(3b(f $Ih`|P^FEi,C |_b #XqZUw8 %l(c}8sC w1;04:3)s+߱=jſ25 Ͷt9oRXF֞a߱L`F ĸ+";n~M%cFNnR'CVf2w<} PV,2a%`àjVG ^e?bӘQˁ".ua%'gzeHlXgH%琂]zꌛOI1L9uf00^2F<޽؈fFVeW<Ȥ;_"²3ђ"6{;@KO r$R;ta3D]a;{CZPWL̋5,dאrp*5L>Kk )ܒMSVK!jEg_ߞnSG.}Ҡl 7 ;(C.@'4^;\ǂw aN":fyE,Ox=]a/Ѳ*r/"?m4f"dg/6τiƟy"jҾ#Y?D5i~x!aoOf]INB7vbKÙ)v@M q4Ufj2sDž7ҿ9oOV@(BSYމiPESmxwXjiaa JV>wJ ~mHɱsXHjETos^cLL'f MGJc0]PZHf1 D?oq}UwIp1\ݣ^Tj=F4}y90R]18dߠl ,Eqo,Lln1㠂b/DN[[΋e?"z5'isК'4?hlbh<9Dhl*CakwrļPZ%sq1!e0ܲo'lAwӛNCar_mXIiUTc-KBc dʧ$6p]Ч͟p;?A?H{s1CEnNqjIvڗo~%GB? .&-Gb&+{ZsՎ/j`n8 6űp&c0|wʫdTukn2(ʠ6)S,س}y;6dixA#NxB}.^24PQV@Sik$%Ŝ(wS"`WIF6," ].Uao>kXBU4'ǥk7G@$*M牥In+'֮Y}}>`}žb0嶿v3vnԹ+ ;iWr톛z[#8`]Pi) ]<ٷQT$Iv TD^׬!UB'!.RA01ZxA~܇&o|B6|A /@μi.|ULX1 @l~Fc^}-8Z̊ s$[ʺ;wG.Q$q |JA/ҏe߉IHȰ*yƍm H!s߭](yo"uhV+/i>TTj>_s󞪁N%C^+]N":y,ggā@L.xhih~('jC QǔK 3HN|<-]&iSǬL82G*+o?Wo>2ثjzGaFw9\g&C 2IM-$5~ߘ{LɌf'x,ci [a;X/p}9اUwZk AbҢ0)Nϼk1W(5h#FQ95=ZmgK@wW'rYIHK'j*srNWyr\Jë԰C<˼M/=>mB>cغr|)&' mBYfqUkEղ;dF U2M@1RZӓ}V6PCp~ W>#ٕfzE7HRS9l^mu9S%]qZcBN0F]yDᎅ.q(p!]Knʿ l–&9l'ђ5g!a~@AN{l0S2l}”Q6nTE"Ew "yn"0[! |B3٧i@=C <֋BĒIAXd5*ss.pBQgYLvI-;D y`VBxUa$tE/7 ,Z:Xe%vJ΃?@g6naHI>ى^#j%I9+s4V9Es8`U<~p:ԇL֬AE~[:rbMbs•=]ކD[0gb:,(Lƃ_a1 ah+&nʧ!?x>*&`S*ɮ6介L-ORWa̓$"d: R#dgQjMWK~UW/Ѳ9_OT,S<0I3C-aّZ[C:Fd4EWg9(?f(zVI |G5jqhH\"O~ pUAD `PD636 YgKg>tE]Zso 5=SL|#0$BY[2֧^+WP_IfLR7.=0C`߃Jpu}YEǍ9嶻x EOs!Z-9Q}TXRQ(rh/V=t /6F&#yΛ_Kr .Z [?ZgLPNBk Iܜf5n.:MOI;ACBS8?}g%OHYqUN1ǁoZWt '$n[im"@7K杘ڑ+=xA,JqcVf$O7nB7.a݋4<悫vh^sW~$X\,ⴏB<+eDxA_G/9o{`:&8Rˮ6#]+}bKBtL% OUƨV!a8,f6zϳL KNhW$/N|w!κఙ֓r}Cfbs<)pcK [u(^TZd;wL ׈r+%2q*qcsp`Hż3sJ[t4F Tv,/ *aYֹ[v8.xU$G+yk &xWwtPI2Of!MShy>qFqeVC#؝rH[ x (ɼ!w.2W\^`u8ƘؑMNV/o8;S# 0s8ݳqDRӯ^tsmKKj[԰rZu,}15u=3"J7~8qK2;1rٲQkekaҠȾV~ }P[E=+ |0-B7FVX+yJf '< ΩEҫZ=i!\@v|.|l5qThZ:)Ζ86$KͰmcG+scYokպx7e`*܄[ bU$_{(kyKG8Pd5"@fgA=0tx3}9wg=ʺٶ(<@(6H)kRaI[=aL݅%סp@,t0Y* o̐PFZu5i=˅DG20r"tcX&(h>13RoЕ1~# au,e' 9+hhd0(BBdb$u/} ߉y[c cRc!2,$M)4 Nʞam+FN,ֶYcV3[cF~z;4]~/݉V߅l̉5\"-0(8U z:9f' J&QEgOJZ}ˑ!FC*\!?|!9t * M6YA*vuI@!|SDZ )-2O2͖FS*\δa +T@yvD6 # S8THG഍0 !ɦua2&|D4oVTQjRM)H*$ -Kc)?~Zx}^0&Z~|nF±^%// `MT5kxa+f\)x`yF FO/Ü|(F>Rn_@V>4՘zc5p }OHLXE V{S?BPYV+A S:Lʖ{y)8mP, @Tw{'ǀ&^V$;2Y|bT`^,+dAUɒ{>>;q}S`YCmK"qh%t]0ثnq\.TMǗX(QInsE]uVdH3\wЉ]s0簹$8#@VRP{ ʔ=(w X([IH N^8gvR[;md%h8Za1(Y)8fM 6} b2["s$-!JqS:j)gejo0YaX-՟T9iaZ%di8;*7BMChzo}wz@!v6d7tr-&m*Op*^h}5&}ϴ:nr ;F~_n?4co"/S?^^ Xng?&'͎H= 2E#>&^nkI87K]o$uvj26a=dU*NN)%vUܦ"It3p/s%p#4TFu'9h/ʼM3z;eRX:k/q+>cXG$'7)آ"Z) @29|v }| |;ђYa!W#6l"^1cއy¶dB߳`2?ܿP^;rrوr~Hw_T#u;_shpS9+繥3Z7^d7^wt$>-Hd8X(2Le !a>q%-<"p=6#o0ԞUd> QÈ^9ӄ%Ɗy_A=* )<]/`_7i:Nx ^gY2ܽdAEG'068j?=|f…fl'A _H.!,u(Rxc7W]{"=I*eBU)Oƹ:zCFIN+&R^7BE"`'\BIJjS`0`RT+鸞;gy̺Zfsŏ(煠`MFQjm~D,de @7=_.Ǻwp?hv[Nw?J7tUD$C*T'C|xe9bq0 Pr eS[(}"`(!'3PcWJAG'fXrwS,i jN+Ǚ ُC@ Iw- -XiN^mlruakVvZ_q0O(Z)"LЪP҃w&be9/{Խl5: ~xr,C2 B' zθȌybB;cgt*fy! -ira^1>l@јذdILOޘ 'Wndm{wCSW)~JgEN'h:=Fdӓɓ>Gv4z?u2\& 1[]&a9\}9ȇGMwcGԧ4|!-kܾ)UR5<Q{;CJ桶e*n>,{*a8vL" gũ97/U{XF? b t 7BY'P^en5$pᔔA~\WN,>DhT*>FsMwڲ\j!}]$B)I $2!҅'2NMk32@Y>PW~`;}60| z΃X[dt?OfĔ&E:rեP%1Fm_vJO,4 91ta|S 2+w׺>5%mi0΄מv9ӭx]<-UK~8\J4:tcj=pɈ^c 3=\ Q :P+Ͷ8#C;+4ٌVQYKzە6&bdpب,֜SenzOWŦ=21b6wc("]Ш(7Ϙg` /^KMfD-Rxcnj7ˇU#n< m3ωZ֬Ї;P&ՕLeWU˰A/ cY:_b>6|`n1ݺb{ƒ ZJ6dOZi~ofjBS~Lc% rk2DwO7ZMԮTQIRǼ”}ň쟠_<ƃ?I^YI -C݌+gdA-ٛbuv̆@**}xʖl{³m'ɬVd܌ɀFi&N1Bi3~j1J$f..m<^?u1`xEl9ܐkH6sVpd 1Uv#"=.G4[]b|i؀V-`jɏÁĨM L@U(#͂%Qvn;`zF=Inm?1>(=Rdp1+IkŐ=/B4uդ-UáPfx{K“ 8IX78REt< &m>ñ7wls UmLU@?%T^)cen"XYjP*1 ~^i}ȅU! 9XrA$DS>c}W&~ uK)O5`\h:k S_y#LS Ub rM 33պbh4ޓ˴A=$0ةB$j]ˋVFו)^]JYyї0[~\FGb>ԁr?4o/8,.?w{S!'S4 :5"ΨD@Ƀ $;ObJdSp-c2ttݷ}rj([je39v*pg@-eF 8M1a-#G{߂ųHPk{gfܒM ,v+iȾ7][K_2o L PdLt?0mA*fçу>6AIjB0OR JU+1̧Z!闈}(bY[QNvkO93zgy.XR ! ѝ65K" }"z gr؅n1G9ڀ;E׽WIhw . MH開ji$O)8͗?`Սc<3[Eirk.ZȂ,U]iJ<E ѝ~~^[ /XRY1*!k@S:ӽ#[zw˕Tj2q!a B1:5P ?dȰ=Ucs̰`$4Oʂ,i8ïl}1Y.5*4m nD}SD[Ӧb5fbBen ?y>u 'O뇅ȐQ"WUڬlj\ 80:syy?@D%HI& [9 ,~*.3ՠ_427Q뙗Ԇ !jĻ׭!nMN,F!M/+ڎryUvU!:-eg؆' ϹvfJ@JgbUz}?(~ 'A -v}o}ۙL&iS~e4):.fiwIJM`Nȣɑ cVmesc_l_{OBOQ5;{ Dٕ&ez^H< L) ܘv2{^4R8pe{tn:a即U&ȰkP)*7G-K+bl\FC4xLbf[~:8@mIؤ^/9LSǎ8"F(*lH"8cU0\e x,t.IhoO`X $fNvUp. IA+R;?TtrW]Fir|ؕ.D^R F廆b|p!mKAk ĩ: 4w4Q9UK۪NxxTD j߭ ֘'-4J)'`p:l(TV:xf˼B|n A<$9.b%n!&@LLVM\m$Jeh\(_ 5 04oRt)O hUm2d&8~eSZhoЗU7N-vƉ[NBVC*YEPɨ 7fa<ߔ I٢L@۾u>Bf6jk> "<\h.q sUReqf DW޲,XmM=˄^ p}lƀwp> :z)(oYeĘ"XZtJҜ"DGk*!gR'|i|7Ȏ'LKwlvݳL+.eH§ʍbݽ 9s4옂@Hy|DZ|Cȝ+Ğ$7ZavN%%Z2F҂U EmeGcF!arRlk*rnO1™ a,^Q6zLlwCelc/{lŐ9]۪ ?xHi~3 MH9bEPp[3 56@Y o)VNBx.5^xZjgvx$hdç@q]qu27 .z\* .]u<WA\g \A7#msdOԟ$nz XEQf,%Sy<ʺDGVÏiJƅ7Gڥ'. b[EFК#H3ꮛp $䔹5>>.+la!v%Q;-<˙qX F $:܆͒ AnsO3'05@[.\"N12~1Wk# aG=4<7 ~Y@ PyD.@v]іo_y)p%M:"ZR/FNuqB W-.U?։z%t Tz*RZ5s6D|Fys,ϗ5m&UrB-l|ƣu3yāAA*AL!4*17!$hV+*q^meYêZW@:yf$2|cA@Som8&\(Fx`*"ޓOV^sTl5heeo]|FdT Of9d|@@QͲS.!a98ӄG>gޞ _Aj2-v&љGآ #焅@YWrD$lwD{Z܇ b߁YI¸uQ\`gؠPPϹmёð'ď18sގ|NR#m|Y>tҋhc& 'F]Dtf0"p^O$1($.Ր'ŲBzsT!܃zvaҶ4D/Oo{6^7JK 앶:$[Pit0 D$9bGpCS$1Q&HƲkFRE|PGGPJB((PPsw&9GBJSxh_W1+ĕ:D kv{BaKrرvQZ4-b `6ܱs^P$MVȈsl aqq v& >^S>A .ݗn4< -x>8/)Hg %gsˉ>_UIW[<2sTQm%bA?%0PqMY(;Wہ;=1&Z۠&ع ~Q=dO Z~y>CEJC &{,9ʮC,x͸Md}ԧq*[L?7X뒂2iP]|`8;wiΪ[յڄы-HWzjm X׷HWcMϧqAWXCl4]JcY:/dg֕Ixu5v<H-<P$dٟ~8MMΝ1vԳwוǸaž!TV@:)m«!~OUY$b4 '7c_ }g U^GF3 ҷDpl"-|>xj=Xjs fqg=Kd8~#j!ndETQNkkQI~qT0}&{鱬9G?¡жr \l5<&xZexFxF#6~\X%=_[a)5([ "#a"Oɠ: F ,N ܫv'xR>ųp[yW@5 _5H' q-=vF,ՇOd1' S[axh"jH2K OH- uyEz`p+/9QᓤͤҒcP=1yB.Vf5xT,4afljY@#6Y DAʻi*%/UWeq>F.cRaɣlȶ@N>v󗹓*$͝?y6Jک-{EHMN܆k0/=&>l JTN< dzZѯjn8qu(0u907 g@rp%@T%!v/l`G ybJZ}´)}WCȰ1U"4@.w T_IQ%C 1)9ۉ{(a M7iPzs}?bf\mqUHqJʱEd )m߸27GΣ;nV@PjљE_=vlvl C*a%XN%ggahnE*{{!gRIb:`v3PY6qtetb%Ucf!9bEx`aSbmBOr%8,mܑk@4,>,(X g`da(3Ā.z7- 63Sm0}R+x0~;P@# v{̺Kv0"Ot 9;%GO[o,-n'Aj(m47Wc/atpK&T!>eTQ*9~L!|pňO"Rh<: 87~g,[߀Q`hu!c_ 9T`IgmAIʶ 1;jhƌGէRp{?$ﲶQ ?]8ai=ƱVb3""E\>09<>HEtWmn˖ld4a( K%QFrx1~T6M (ϡa܈A:|cp0rw#5xW|m݀~]fxH| jd#U'I{*ǿ)T9 > {@_p%xz!kdwack.8d.V2,| w]``uyVjر"`PW  r'U:Tl펃k}ZMiRm5=Rj\t> ahRBgi?-axѤǢ3dl0P b!ҥNE>gC,w(˄(M=^goglsҖt|pJFPPָLB<<T9Xn }٫10='{҂A\s&2TׇE͍\f hL vqF7r8>m ǯ 70tEť3b(4[,Z+☊Ji6#oiM/m2;_n2ƍ#Mo}[$Gr\ knyX.jh"ɹՊ+sCzU*J%ʓ1ٸ t"1m gA<ݍfPو H_$5ZOJi)ފK:-I-&>B& O =onSOEC%,kae gB,E(1qIsf6#vT~fqT7̤E'7V{#"lL;P>4q9;a'R-QU{SĠ nZkiHN3ϋ|6ؔ~_*(_.=rmu4y+(9IWj6Az 7c$z؉ƉyᄚZo$hO)F졿.(]בQׂMp#Ց`1̐ 7Na7Eun#qnl9.ж35=](ݱ^ =_'in@Y :Y|vX 2+^o^@̮FҜϩ (T6;ыHLS1~gN?^pB>% Da$>s, f38㽫bZ&BTa$`n0:okuIb*AJmqN兩@- lیPddУj2Q_qgZ+O:ϰ$9ġ^fM#91j%ZR@otO6.A N*JUlˠu;%@[SB! z4x܊I e\]O"XK^ BJ*SSJ@r?;.7*'jИ_o,DlZ_ 4n(i2sG"uėL.^SBhkP%vJ~'HS U򲘴]# {élwZ/goGg!OSԲUA:nrM>Z2 ߯ @%7zn͸@܃yr !ܫ I6у]rLv =gYYկ^#.gz cK`Of)9*]{2ȟZxwtwSnqN8?gaI䡲S!sR 7ayut;jY3꓂ܸE-Zl%!oc&6_Y;\|=;cƋ$΅q*DF'lZdԉi4+gf9L#4MjJQth7/p3tk\rSKdQ_rĮ+=H:*F^Xz[jq0X/BZN.$v%yjPDOQ ,\\Ɉ'VL2>s+d M"}0YPefaϿ$y._1[ }!eY b("5WLP"TK7<ؗO 21{*4@^ouf?uķXhXy 6"ˆiSo$V@(:Iփ&zs^ɹ]@XҊ٬8X{tl}[ $!7* ګuFJ'$/[&hQf ݜ[GHOX@fVFoέo[ )U' ,]şj ׍d NS$fV4E'I.A&v~%8*(u7'\sj a P:6"[3$"kBd3H/*i*(&FQLj7"3n8x"6O%2?,I`h}PE)9ЃkI]k(UPB(Z#gT/E~#^+f w% ZTaBwt7[1>%o1ڨ`3Yk9~t^w*Q9pdJ^9\7 6VN?\Jqmn`Y"jѧ;-!(WPrpX=iؽcrH`Q6T!0o~{Aj1J,Zd"G.d 5Szǹg#=5G A`6]LH=g3sWHe:E'p&ϷCO Jv=|ϧؐ1|E'lw/ leHQu:aQ%Q]5 \(ot[y+Q+Z5uCw^ݛvbh2p] aʾC'P1ѳ.'Ӡ;13UyoK o$KS+0b}>S>bmڋ6SzUÇ:.$D_j~ , 744X-"Ĩ;FJ6otrLԆGdjJ d|i̝s5E8s=ŒT5ӣuװWyؼ3_{-ϭA)f5ERUPnyUagDmYIiعʄLtt͐3B꟫h80Ļl{nqFЗ;mfl%+hR6,d@_Pvb|LMah7փ.]Z8H }alTJ&Ni|qDR j10s\b),H-ʕ^,B(3Ĥ 7%Ā,H0M}B,TS t멈%nL9ed80^Yz'#^%@o0Pv;7(Ib(!8Z摳6\n},ۭKuEO=@Y^&m\r_Ű^^q (Kzl,Hg9L}I۔7Y.E &AoΌ?JԸ}t#J'3Wpw6nxN4`znBLE,4<UqRrB߰\&Dv-s We;k/Wrǒ5fmE7Ʒ;7E͕mc S:Nky8xZǑd`j)cSr,"cT#J/oQ*%1I !R3WwD6^xl TCWK;fJϟ6V,fab2- b#Y ~|IXh8E LjP=mKine6LOƂ>k6 G6t x :3lmP3׶1M<Vc3r檦IRft@1+jhbމL#oB4 |%= %!a }@Q>/BI/̢Y}M0E%~yķs%? R,@y1!PY 1& T!Sc\V`G!̀0djem&vʪ=~:f'>^Kߜ+1SyK t1ي!vլ/*Y?&D3:+ T&pEׁO1i׻gjHxTS͋\pf],:1./Rp mC8F/ Ų`As!Ǟ])뛤[ x$~qit8ّ'}+Yx/۪5Bƭx^WT?]AdqPb5a?%{}aʠj97sTv5)~X|l\5.Ǻ{)+SYP< .?%ΌS7Sph>S8X=Z|B~igE"^_% zR}Rj0Ze\`yl\E sTP)^%#3 `fax#{^=dftSkIUq8QwјSf^q Dh@׶sSrdP8*lyqVҮTFrȢ `tQy]4Z!'M.z,NdRWd=.}K@ҋp45$4Ykq%M^-R+=U681P( thSzTeĕyn(<ܬZdGKUƙh{[ft%Է?,sD2L|O'F7LM&9O~wwvjَRJ}>W7}T xy ogz&&c`Ba6B44hؖ(nKT4=UvDIz) :O_nPyF"#owKg 3c%YF; [|FL#–Q%fZ@ϓLN 87GRU qkkhbJ]OT6\6f/A άj(`o'io܆4ּ{4^?!4BuH{=bjܤ)~ "1&Fj.8}k/u {7o9Ll.0സM3.sV6A7رiy9 ;*P&y-a/WBH4q3];h;fN"I.(^xQU 9e| (+%18GcG};C-K44t҂E](:}Z Ժs1P7 &:NY3,;Ώ}xQ0p%tulzP)bzMdF)i7pSq4;t"+ .h;mOk@ө|=K~mHUʂyD\$ 3>eQEʣ>8\ fӝbK.V] /O>f縶DKp('XŌKל1*&p+|742} v7e׏I&\FqJZOZ2:0a4?,mI[ɩ?9@[%Wc5γscTQ 0F؛A3o5G~ՌO\V@!LJ|D@+m|~UI76Fs'rVY1RM#* wn_^tٍtĐ-,If8%\vrڈqQ|ˮ Oc]rLRG3ޤ(՗ _ 'HJPםYhxuz%Lx| [tO:?X,8zTFXߚ_j Z9ds82J[i~-f's3Fm'aGqg]bJitI?|ы3lJI&f̌(h1s#5<\:q͈N@<nBL!/<*1Jg̭ ;k|8Mjr?3Ȟhn`f"n7Wc1#|oULO7]mWo+)J2HdwO5H|vbJ(ͥޙ8Μiers(|yBCM] \MAZ= olznDs+Pk}`6P=n%o?37LDmLf "=Pv/DDvMV9gYeM E>N@FDmE 6~n/ٕ7Ex,(1"U: &\0gy ?a%=Qjrڒ-vK#A?z$'ֺER.dVb,\X |(+j q28Yyk4"4%#{ ֲhX )N $40z̀7(: Eۄ_5#pMQ|qܮ ՜+:#w鸒K⤠2.a+! 䧂eR}d!JNUUJ*Q6sc*I;|}FQR@|VxoE 0uQn 뾖&Q h=,f/lېҁ5m[=F[2 0ŷBeCaϘp\CM+&(P3_9y- C6]R/QPP$j[&5ӽ}M]z]G$;\/"d$,eIPQ8߼]RgX?;e,]!R'Z` L{sqPN.W4 8#+5w{@;Q)۪8 % ;-%JBZ[4׉Ykm^4AMuHM-32a{ߝg/\Klu=˰De6LДd{L!̨\r0֒$Cg1ʆ".H`zGt-7@( 2VJId e&܋rx5궃J˿[w$?q4lQhF9jd!Cz6$5D{X8gŮTN%*,,vVW)w8ŃJJg,"w<׸b"1QJ$,EM!JZ=j3JCG6±uU C_^,d![߇Q g yYV3ԣk'$;v P.п$8]-2Z.q n$qL0p~a<\>VLɟtvጾPө4T9ܫi8}20Zr\0ɀ"6,dAX?;믮 } H?ذefkQa i0Rzx]U)g3@#)JCi'ު[mCj! F7q@qP*Pw%5+U{p8VOV0ȋ`sV49" [D\+YP37<]Y~im^bs\#+7czQK w'NM~| S@>8 jF2D;_ЩdRĢgVW 8ՙoTJbp3顈L @ ;!Dv=EooϛƪzEʵ8v(,JQ%TiXmLߩ!# BK U?Z4 h ip!`"JLKN~CZ'6^exLF bKu;7G~[6?uauDagpMbh{9r6TSj;Niʺ o?BQ$EG!~_|{խ$9GTl\l"ޓŹZ{|=Ew*kS0@ڊU?⽅ԫ(50@)nm,Dd0FJ23IIr!p%xl!T{nBړ5m14릆Vnەgx ˅BuY L-ILa"Gk9d]r ev#%`;,>Z MlhEE-`uЋ9 lef.جWb0L}J/W?Y:NCE<>izyw7|;}K/WXhDS3^/X(J-# Dh{byfaT/NrXf"v63Bv0&z|u{/#+CI|m8f)byr4"ꥭ[-}Sm>ͽNv݇:RbT NK{{J{g}nb`L02"UJ |Ljwm[e ҙFSr6 {o VK |R@a+<9#$Uld隗,]6>͎x*}вwo i :A%ɪH`ٻ-̧v}ANT[鰮4b6K)-ЦA9IsF <  \3`O0heL>dU%K`ɞPl7|AÏZ$NA <'|WJ2Jl(1+iNfIHb 4\JG[Ɓwؓzy8Tv x*}Â`>kEVoUΎZ`ٛ\s.&G1~R;jm'}V#Y 8M[pPpTdl Uh#ㄸ h CvUǥN}ۄWs]H,~Zlf̞"R2%q#?7O00w aiT%3D,|u93[XWVE|]he%,nvo7`Bb]2`5{p]m]o\Z@ z`e:Ե…]uta-q#L8fRUâ)pgh(.[) j.kBot.e-+L9(>{[u. x4㗼9c:&7(xUν[WCH5t7FU01G#nuibi)lpbY/חv(* eMXeHt5ɝ )h6{qv  U`5:V6`?4$6<@a(Ƥla8b&̂S𘬉2yھf<9a`fΫ'Ip΁Cip h#U"_laA^|3h~l'_zPNDo1oZ^xBl_exv?nv,c(2Y߾1Lul"Rc}Hh`Cd#*6C1uO܃GJ&M7@( NZՅVǂ֖Э-1ZR*A>X*EI"ԢC $brZwъ|pXBƒk2Q(¶&zw,]{ȷ%#p-1h?~pC`[qո"(6z{R"{qniV;"?ԑMdXշuHLlY9 wc)P% ;TS7?mĵs 2ݒwG~0XiȑHgkHVf'U#;qäʢ!cN"׃Le-sYKɖؐUHP h붍{T{- 5֌x+|rHs|ަu.sxA!Uz7W!z.^> NT!bo{4݇8a7v5+MN11axZ,ccsg` nYʳg|X&K%2wֆ*%cߋv6|ʻp+VgT6֣=Kikrٵ3.~H 3jElXML> HaZ X=[I&xteezHl<ܫ-  ZH5׍^ܑ D @;TʫEzɼzrNim9Q)H3X!;D(RM&,2g0%q慭OFs@81zݺ6Azg|Ϙ-G?6>#mm6)epҚ^vx@j@!|Qᶔ sw ro&eS:hob]9KO՞MR{s\0Wm:<9O*3^bK+/ff"rkyU POL^D5h9єՅ8$sݫ*Bgsp`(.>} CIviia1 ͈UO=Y2n6*$!Ol<L1~CP/B l(gB";WZH@|nKеԶRicJ(`Y=tsvFIp%`:aeZ;*HL S#`ղswc#T*^ "L=!"`%C!RPJ'YLO DF7&>@ R!%A?n\ghyFT>1`ڷ-qګ>NW H_ǵ}?ʐflYV}V=EE4uz +k7+ RM1a voL|vk iP7?ZRj1%o~`?BI\ ];a^ɟ!݊[SBP$I3:]g=-ȶ.`^ 1}s\i>Mrd_Էb׍!@d,"^/vjiq#HM<^9nlnihg[}kSrr fʿ]iY (;2cߜNZ\֧FZ!<:]N됁YvW!4F>vdߣA} lp#!Dn‡arEwyp ك ="cIiQ*蹙th8ĥXߓa ?o_Wԏl^L> -ESǍ|)-p3ĭcAU-I}rBo$i 6EzS^N8Ҏ@k~|P]WS+bN&8p{Und篲T3dQsKJU_J۔ >:-|;o&E Z@E x@C1+`˶ "Ǒ%~/L\ML9:'tmj4xEKd.9:|{E3*$F+~EжZ Xl] -{4_Dę?y7"sWZs3=l$5J 6 KR aּ0w3&W;JL@sK9p製ORD),䫨}%Ji56i2JM&8M/vő+tgk-jEg&BR𘆕 /2~o2L;5{``q-}yj{{Cf(jUFDd6=1>C>|K* wPX i_x/}e`NF}:?brKi])J (H'6\h4|P, I`ή[>Nc} e55cIP̀/K 2jWNWCŅa6/S51* л6CH9~{]xn[[y*o"21Y}AdttR%\mѭA-sn V.}:N4T3 \(+^1 GKi^{% 5!|E,PrSWATskS GQv;~ X*] {DZ`kO&qqÑJE034"P>c}=-R֍gN[{ !Mu{&tzsϊ9V֓O"FvzVWjݓ ԒhvA=}NG\ܠ@n:9\6ؤcP'&@ɡM=Gz}6+zJq͠Tz)rA%;R6k`#fC-{30嬕"s(*W1ܰuQPR,~k EC3Xo(+sdQ|,4օH3{K š5HK d1uyvlu&J0';B&a6||O4Il@J#y.`!ѩV_ҍ8rM|ł+#qA`ooݢ fPOBG%.NY{r iQ Llw0*T%m]xdݜ|-M[kJŠPaD+({W8W$x g(ZretNݛ]'âM屭.? *x)SYwDwf{iHmP.11&鵆$-UHW+4nag]ݹ䳋C iì¦xE_=7AzIX?]&e)q#\xe:5raE,27^g㪪c*Ǣ\#MiDB)z+GD(rG]TD\(N f/iD;)!fTdݟmzKZfs\Wچ 1/uwBNQ$B$,#,9.5z9m_(9`M;j7[h|b4>"}P-8)Z`z:\iKz7+axz[,a8I{k43lcwrm [3D{ gOvȡ^@t*f֊+$}Df?7{l]yRtY37QwD Te fRp–Bb5HxՏl6̙( gE-}>X51f'7qZ_`S9C fQd'O.`zXsg^*<}=.B ]e^ 3_~mu{F?9J:CVc/@g/9Ȭ0 @ʬ` 9M~-y'ORUVՓ=q2{S &?2tcLJ)7ŋzHx,Oүjw6Ϯ2  M'kiRP[b8q"4fbE!W50q$N7 qzgGdkp9gMkp-3<% }<IqMP 4ݞYc*(;,~KǢS?Yp-1-`$?vGJ!r9w )ev,oGUrpN.^PYNްޔ$rN)ȓbBeA~H_ ӛoSIDz=-+V+=[mk.={$-<ֵc%=^Mx r4糀eNL|)# cp-[z4Dq,$0"`5nʫaOq.BH[Lczb۹?ɟIavNgVEr$`k~`Z\\8p^ 0kk<ojE_f:*xXjc|A+.|kT9=CjQtoFzS4p݁y<ꑀ1@,xpN1zM{Y?7\k4<PpUVjXiBI \8Nbйҫ5’Zbrepjw|.Lv% I` 4ϑOs6hq>yJB2[zYѕv#_jk"g(xM\ G߱sCm{ r ӂYJ6|5?s_PAVo­7tvU΃"4fu1bq@֤ 3k~PW B,g1Ga{Έ;O"o嬍#զX[KP*pwb@b{ү%\/rM@OeT*afAP{>ċdm2D{5G:+6}N5L\곒w#\ y3-!8]e9~ӲD 2mĘrxJ?A.,tt y7%3yCN&HcH$>]-"o}Uz(ٯvvm2ãy 'p*RSIdG 65Th_ e| ٓ5X8e00Sސt &j.:Ktu;84ކ̉cI/>1[y}!&HWyrH00+ Jdi: Йh| syͩ]c:^XКi޹ C[n[(/;4:0M["Mk*-+p&?ZIq6ZS+Ǒe ,=of5}9C g S ''`Xi} Wqa- 7p3baySv-&x@bxEVWi/iD+F;{`a~2e0fqCnJq] sǫ(0b);TO&_$o1WR 5X60N)(Vy0r\ى H혼S'ҤD_t> f3́l^v{/_[ C#vT$ŮS+Oku> ǯ"tomWcsFJ!(05hF?NopE'㣲Y^xۢ*{QlumA_YĸK a%Lj#5Jr|rT[?>l6D) K.hUeEo8So[mVxTT>ybr^Yoc䂹~,j@KJ|FVrXfxO3`Rj<ʭsV֖.vp\'?^-4[2Bt=-ɥ1aӻTn %ͱʅmaAj嬕W (YK߭TI}I[jS\ bUUӂ3kp땾"g'@ЭHHUZ}M"F'^&K+A xFw[Y1>tpZؒc d !@R5J'o [KZ =۴tU~]&opr{!ke ל"J(硅MY=O(8%eg)FLSBf$;yp;U3-p XӲ$z]C.K kU-SY7<'F;LFӿqMoCk.2oq)8:&q*UtF[ݵ9i<46Ȩyeq}FuP:(j)b󑾜_ع*e8$'͗M{Fq/9\Q؅M녋2 y y>^mϴhߗߗ%,mimXH[WNE'&%~5J-Ðݕ}]Z~3 |Rdz Or tA B5T_ U#1 {[XEBA3nzP'4;;(wڕͼ&o_YcsW ˩%./f*ځy0idYbYĂjO1씢xq@KD~"[FmjdLc 0̻r!L{, DGX|LV9x4ABX7WIW&\JKr?,Y/ٴab8rg<|;JM̑,L1_\l]M./XA82mLW,~."J@ϝ\qz4]+->ٚ[<֥SZĥwJ!et!efՠq#5B\0ўibك2mYU'7l`є/)TI\Bt31>$V:_<6YeD9,|_DžfDX*Bl@g'Bҍ_g.~h΀dV)t*g٨oLp0\Ld  mJ=d@<cA~s1\iM{-%W/l  n[۪) z,vmιISԊZ^OҊoZ{+ IU+fwIĴH"56\H[nЖ?S=EK"׫F稁؃\nA ZB4YYvk%`笌faW9 !| ͚.{]GNӊ}atstO/V¼\C v"-]?4J| s̩o㈰ȂPqCKRёlcÃg/mW1ac!m~d+֪&ܽ=jdu\9\/(i8I Q 2֜;uD4ǗOh\B&uߠJYҠ*kMxA`DYJ guۙiIy+S!.*WNd{ ;2s'fdynȵ?DPGuJG{f6cRJYCӅ-H*be)G7@K+%D-g}M9#f B އثP3!DdfP99~XRʍgsU.eVJwj:=hIb*9饗ڃ"xg @6ДIO%; AVNS/ La,~@wm+o:A^ 䦃+עٱZ3Ȥ 9ޕ?{˴!Tna V*rzaμd hOmyRF#(כ)5BQL} 2R*eKYCԘeSl m2(S:üpw|*#m<Kd𐡸\0b APU]78WO qjPu5"%TʩOMn.Rn|sIW`z /^Qy|Aj nlqPlKQ-8QsK̡)z31i&3SiaɯΔn\啘V;ŭ2= OyN2(ˋDb4~xsn)PߤU*rXǟ-EyOye E,ٵK4fX9yDt,LcyݜjV_Xtٶ<6ϲ$jYΔ pz NDa,Cťd)2- D\Qqng@?]Cȃylp[إ&w\91zV]hk?ipFqAIHvD%${\,gפ& hw O[&7+䔆nɜ34w[\8Mg-~E'k,D@!fx ȋ*MX9l/݊0vY~T3w+*a>K_.sxZKoK^ypw}Ӯh:T-\ִ5X͋]~y1$_?ΦcOG aszTg;.>nM Q>뗉Klj۲I>#=it/S|)4šfwcEP{d?%WAk|x"d}&#FNSbls'B Z6 ##~Oj IzEk(SSysQbEn o#^i%nȁw +Rkxi!N9tM$?a 7'_LHr{FxRXErۧ`m`2aea0i=&~*d5WΣ~Umи֍:Rv8 # f j3N ^/ ?10$H⶚>ZyNV^|Ky0pӋm{lQbz@^o i/-NA9m8F:Q<>H\sbf*3^]=%IO@ k@x`vD*ǐB |r*HAMjis^ˣ}7~-s1**V+D}",-\JXjpz]kE*x]vVnSGsv (U`3OCln*XBuŷ73r"٤In12sV1ق@Aojg0tsEv J΀漢p"^0tgڞ8wäA۟mouAnä~N,'6f*W?+|kP&znr+\4EV\6:DhMJkI@4nBCV0o ,Hh,|w | ::&"1޿E :{n ^5рNÅe;Me gr>[>)F܇.WZj ZfΩױY[7hp.7:Ճ&EYӝ}M[-W=-'v~kֹ%5Ho9R (7lK$Gy*6By:b$n4"obUk^?^]/>ܥ`BYcQ*kԽq9qSx(t6dȯh39mp]hY@b ;\H ےOT-@Yf2NE:Y+ŕzBt8@09T|0nYlhaVFeJE>DYJ+ 6@4W+r{V;d6 $g›̖"U3*@PL; b4#tZ!{TIZ&gPOyIٳteE2T  9we`M])wH2[IjXvJ4:zoD8i \GDbFxpej/}fz-<ن`daaU"fFZW_rQ-$Wxy$F]'[/s%+!N,R|UQZA^}Rf#; Mq}^DZ>x1ag蠏+{&5` u A&`8K_]`R!e|E{|~Wgҽ|t*ٲ沕$ zXݸPd5b>Ij^rl F,疆 眿XXU^~%*-M,<O:?i(q(njUb6"1b O[&7DUm{X.=Zߨx?nls >鷯NBDNhkF8TKvuI=pwK3$@͇h=jt 6߷D:,PKgO p =>h:bƿ|OȊyiۜ񭾔ο{ 3R煦V\'sLuQp˫$&3G4K-lآ̓]Ơf%>Fq,]7Q&'@ofG;uRۮ"uab8USY@-1l q6;(0$00,W|FR|Pv:2K8;e-Ӿ<g qNp{y3⦙jOZփ򻐿N&Sž 6NfyY:[][|"FUF%z$~IF2HL58'ܪ*ծ ]0wOyLpF MQJnS->< k 7x.hO2XsTq|\V0%kQrسta(VǢ8"s)cK& f +ދָfDP׬M^ڛA~W&."n9 W m}'wu}$'&3Yi\Y# YNH^d9u'+N~btgl-nMVZd.2b7 :'Ĵ{OgjddM@2.;׶t`'rkp,qL}AyǦX56N\~o3>Mg=~i1_yYAM<9ϙtUb4 F W8MB;Sdž A[]`khyF/9p{>1Y/m2ŇD8i`ԝ xدpkVy;%9Zqx $pՎh1o 1Uve~ Ev{~5M)bpt޺~{ &ؑaVoU [,}??lj=%'fWfkۡ%]ƿ?nUVU7+V23"2p:d?+{<>lks$;uɭ9'*.| 35}sks>6{Nބ"yfU|z XL ;d;I- V%'.y( ܳΩB$u;qmSHgh#h.*{bjǩDC%"ݚ˟lvZ ~=r8Uyѕ3u|1J;w>?JkUBg F atɅo~?3ǀČ!rQmPkIFNWʼ )2sٞ^|."GA퇰/˷}p΁JP7ښ!k#XꦑEҋ 2.2.Ry)M1jjT[-oMMD`-W):m d-04c}>ڐzb,Y7ƛM4=;[CJcr |f]eUOqGcP? uT]k9&<q֦z%MRJ7cHԜcDJɡ@j2g/;+#ŪZ8p2[A_\%w o!H0}Zj} E3[BW`ekh -7W[uĮty7^)<<յQzɃ{qN_Z5K208DY%;i#g硟 /SG>Wd]%۾L=CYBGB ϹM7'wCx)zLG0 ƢԘxr_!%`!4B4XߏKVq Z0DE`gLԍ3:Fㄅ_X eL75ؔ% I}ެ!y"54>@ sӽF:1>t{&И ~Cl]7}U`In a0QNYǫ({hh_C=Qz+qRdR<:SI/ҡz5[ѣ4:H׾rtBa O +*N1 ӆ [/DW&Y4*mz7ͦ{xN*qYVqDA@ajh 1 v(^yWcMP N( ~Ah*>)#蕃|TdwǔS?-9eUË8r8+jdTSX*Vs? A:{g$|߫M?x_a&]0X+T;'}^@lwsw$D]AyX.T+3}8XLO0‹z{zS0_T48 !dqa<*a?/"xIlAFjpBQ*$Q@$rELWi}fju3M-(ðex`@iIo%e(qWV$LLʽ`!]l22}t3jes>BfϩR f_CR 2RDĩM؛P{5F;Λ_uGnGDx Gϥr:eXNWeō\xiK /{)gw6QPtա%h+$ؠ/:2Ć3;V2b.WSmB"_?Q(@䅍ۣ];wT+.?lhbc6Xl=Da"T5[5uKfGgǴ^llA/ ,}|B4ϗ}0kr[y># 9V&*{(~?9?&/qݑˇLA&=Ȏs=<|XƑ1FXuM2+ x#9"Ȟ.U/|[;0,"Yc_HpH \ܤ6w2ܕP*LvQ,ҲWLo̵tWfH@lW.,ט.B" SI6pD7lo,W`N7Ev=ҨPӅUrvvz96rrv<7wgHGO,2V7O꼗>M%ͻNisaEbw$cāq~G8ٛ2Dj{>*z'򉙟q_1nX[rL]YgY=uH@tW,E,=({@ڝeAViB\ -&aR$gӺ_>Y䕐B'e2[XD̗) 3y>+  ;xf0P| |< MRF~h2yoUvsQ X0f1Du}2<ߠV:QM-a@T2&I:; 'DAK3{](q ^&S}bDAz~UmR&*Á$gzm雽`MBF4:w|ԥY;sW "0}:IS' q$EH砼r$r)TĤ qiRꇴjY8RjTTF tcѴ3Ա@G,okt#Gz|.bcⵟN:֠`ȿz#ӅvYv $ zSʴc yI76xK:ۣGetx#|M9aG}(jdp86 np8l2}0A P,_୥YiLngd 1 ks ?:;z^d8O7`$-IOʍ|/gH_@y8cM]9 r/%PN[^@a/F|X4bE4:5>Piq=UyUz ~dBj4fzyJKpYnc<<1 !PdѾ'5T|kɃ;T&/JC %[u8k\ {k2%^73Lnz@v2kRzxR1ӮP]rKPE>?1NM[]>tho[fR3LCuX#FCIX*<Q{Og@é70ؠMw=fO& 99X 1M&=ʡB;P,ʠ`4#WN ]D2!Ý }7)7S @kвgo5wQ7ON `fwKTXZr_ ,[!X\Ag{ Zkm!48:;3AMneA=.1ƥ5Y#BGȗ$~=}^??Fmf|HSܤDyj,P~.(.ۢ_$mp<եʫwГsQGmE3-- N2"+-l2(>:M -s&t]s.w{2A:`T~ЛZd&_@9&٘T>&-],dyBZU&KVUҰJɫ;K{neAnYRx,9Ä: R54T/*d |VY0]Q:G. "ByzJ4>osjDc=x'.aJK0CI2A"ZbCp-7O. qʐ@} 2D@Q):a#=L(8xhr9D_B($&e)z8`=yj|U<Wcӱ6M5̞h6> 'Kg3T֟F2.R"Ϊ YSoDFDXdBf?c(L.(cݩh5Pq +t)W0$_E&U`&,R T8GZp8hЭA gP8wŁQ<fİ~fUٟ]5bf"æg|wNnm]  @ep cX) Q -\FG{Y3lNؑVH}tj=F23J̹êb❅I[[OȠE"4PlHz%=%sD0tʊP^vwH5avPZz  8ZK.5];YڵEib]#U!4! Ij0_ja/ aL" Q +g켮'0|p~x]t@xΌDjP!K&@ga_n_}͒3QA+ U3gMi1 K҉etJO:^ǜ/*_f.n-KNaw,b\:x;Zl3΋Rg !9GJCbҰ9u܆hE]N\Jn ݶ@Ĥ'~)ܸvp{-q[^*=ֆF ;nF:~C,!yu] )H8j Łw: /NB->q.) J^>LQYKǮ+(4۵\*o(ڛ0Fi릂KF1HB/p ?MYGc:ki Jz><$]BKbF8D?MFSƈ#҉"+c;gN!= kON- /2k̭ywҗ?W IG7jzP}J$ Pt󢯄0/mIs*m_Ob19"h'7zڨހ IrF>N.2c{ucT_6I+|F馜 [;k)t Bw$+z-]4hO"/;,$RNQy%&E [d6W*7xHIs ݡDwt"|@|a1?2RP Bg9fMB4^:~> ,@PEO "=e]<>F,LO4\y)eH fI&YwC=lĩ?poۭzd]v}-&^kc[hPQez =+Tx|#*rlY{ƣ[ :f5~mB`#+o>+6ʹ4Ƃb( ӖPK?1.Dy@wTFnGѶ^|m@69+/cs?׋1|=t7Mz-G܍t)Σ*#NR*as~7}s/+ e0*@OW#]s` Y ^1t֊vp0dta{ t"v3Yon ThQُ1&՗Ym.bS~9;aE-|j1, R+d2uh@CS,^u7Օ1$ϕ1,ɽՓuVŃP6X +ޯ=0zR!8eΎQq(Д0EkF >F(%Kӭg}AG>VnM:UyσZMm֪[K`tj{>iwcRHJCS=I]}@^ $3}/&^ŗ MbN9FkygO2zX0Ƕ32qn rLFjUtCQv `\prw <ʔm+}LZgCDvAqPfOc4qUqn"tmӴ<֩/VH$}@12DotHˣb$"d1 OJHE:c!s_abDM3c(LC'.RY.y2P PY `p1qoV)[C&{I>ojjFd8֧Vhd?)lJ0FӭA^Wg/"3f(?k4C0B[G۝{9 h@wj ܖ()9wŎoL3av+`!X:f>91mKF4Rޖ5y3N6/iV3@A t1Z?WqJn@WСwOKN)`?]& t, c_*\$ܽH\ƥH\%dN cpVk+ Ho>$507ͮT܍urԚ[Sr<0+yK^zW&r>ޓqF[gʟ5 =u-x>o$-[e1Qf 5KY8K&\lǐL+H[(1.l$Fhq~jlGpWy?5' Xd =t%)῝W cޮ:=bi"(H~Qw.I5; Z-,-~㚎]2U΅ (\B}cYeu(9hP}I'q$m #ԣl w lrM@ѽ^ $I8`Q[4z7řG+ žW!z,=c[#BpB4-lE חcTu{Eb&*< 6nJGdDbmo-jOM]uIJ42eGk:sd^0>>@ 'Ecx;+u+ G,ܒ6g_Aj TpY]K^U0k.nXNc[*MkSn.| 7}$ &/tc+c|Dl#t`ƓҺ Rab S)ȟ۶YYL0NYI* ]kqX:ᙶ[?j$j6 -!9AO)O ?ۜ@E9: LNlҡ̌Zw@}hdxbKCav"x,J65{TF}%R e΋!_eRA oՂY'lS1RsP9s/1I{5Gl9T (J86ތ&7 95 L68C_,|V)WQ4]e%j62=O V+Q̮+S[F_R%e\#$֍5FoLGy7󘥆&9@Qe= S'N}awfFB:tHwyk$=%\׮4(F\M|ydH{cK6f4jzd2 &:y2®dPC?gѻ,1d:)O5+*P.VChO`jU5l3HAK.%I)ȋR15R߀jK→ܻ}}ip@i/ ݹmchB9d3cGCG"$|DtM O,$35 ޑM_ռSs@Xyž2J '3Jۡ'/XȻ(-dY_PI9g-SR# #'l~s菍̙͒F v/Ώ/RGE@iC_;ˤPD'QLBzi6 >7Sc_9\șl =[647ڼJيn/T#A%˛svϒ? *c xʭeOIG ~7_ `ȠQA >I\e!,H0Ob_qkv%\0j*ZɢZ-뷚?--f$*'R\/0.hK81f9PVc%B*3 >MlJV(~˄@ٗiPD-qVS&'rpcJLx'7 բ]_ۧJkiL3i׾슉DbJۺ懣YmnjCi~/u-%!M2o5Cھ \uhg;?>BO z6s-s(H5^̖tIwIL}Ba ͒bv^mOӨۚW31ubjWMa7Y--M +DPGD6>{6Sѻ}ZkNhwogKYY;Yrm,(R=I}nG؁Ȱ7Fe-t41 ]e:/%6dXX5uR)8s"^U3{ v~?'{TϴG5W[xv>Go 0M蕩c[8h  lef3ZG :3uBG3J}ruܾ_ʹdTS!Fi(b۰lkĻfb0j6^?Ù81-L| =i<>^GKdH>sb5OO"@;eN8, E{<:ǚZ2&zzٙd寉,gDƁ {X:t ttDOXO\w8FvfVqR>z-~rgBös6D8 Eφ4҃4J.hU5 b;(cنv3Ȱy{jio9L_8{4)گ3r OMg(M.S-iPym#WE+$ յbr5MoǞYA5($!KT7HY٪_wI?Gx\ݘ%lo=K:vm_09qͥ;Dgdƌ;~cZ9ZH; Y9FGHON07`2VeߐlDAe,(d( [&ږȰ/')aɒEIU/\A d+tp$= `{U\7f<%j#_P,8PA8D_uofS;# Q+f~EI֢mTSR:-QTڟ_Rťy#,9{/]NlUv*JL7Q#>]3W\sU}j㜬Zٱ*WW4 Dդé"կ)n1}gA' 4o9SDb 1p #<%|`],lK՘(mg鳈"j ?mc0<أg A& $/X} Md\S~I#u>_@…4,'XO$tu91ҫ-ׯCG~vA+h _d+iu ޽"t u'K5mMJ,+L1WfD+b8BzyI?>ߏf]I]E:Mb7WLw8Ī(x`+qĎV2k:"H sȜ:X/ S"CJ>Eqx}F쐁] ܡȴoĔC76H;7ʽuonboKb]gPp'Mw:K02{BD b !BNzRc-=I4`V2 ذMPe2JG62, Ay%T1~ʲnݙ tjU$-ӥ1A\9< a'E N?zJŨ}l d?,P?B"%KSfg~f_!tN> ;1H(Nc uy'@& H~*r( [pHqOE%Zs@7d9ˇ+P匜 w_捫+pUo A k ϒiaY ^ qiʝm\,(źN[sKK!I x-!P^G5n;\`EHf)(ˬ0V?yVXx0 I}zv}6&>Pw s8xkҲ+G37nn vzR;i Tŀ(?-Z8MxڡlL/8R͵:c+S)89rz&؞ɫ Woe)>A97E2[dGD{ԲinX_! xLdAs]о_ Uz~,wI5OХjj8ߖ!ITM5aKNa@~jsd TgnS&)+BTH#0˒$"'Mx|7UA,o<6W0e1t̵|NsB-UHc#aN; l&'߽gɞ:s&@T~\dguoſXwb!u_uQC͕%g󃼽,yrN!؃VO@]BhT̓UBq÷S2X Yo&oMf N" K.d&Fހ`z꺓QLlv>0*.4:dѤHb%A80%㘆bsNov45zB=n'~`mH hZ[&^RSO`d 8u?!&0ϟ,p>蜤V!ȱu(d|0[6ZmX6Wk{Q[Mex0!@rym+dlIJpbw:XW%3)1Ehg&zPSEF6jCm[=%4K)"X䭋<|ib?VL-A}u@NdvghowU2跬) _ CY=614,Q8`m畆^9]p?h5RXzT;:6U8.رE Cɘ WpYLq-#Ժ6怹KЀ5ſf^HQg5|Ь$W@ߋTSsl7ʎMUw>i'J;`[abxP sx!ѧt|+bzc Yml`꠽lLXa٢L<{oKfYK yC\{XR^[:KݙJٰҳo_.J⠤e/V|qr nzlW}c4sFϪl4 ?#4yfn@Fc 7}[!Fj߹44F{KτI&䗬")Uw*57 h#ܼe i澶j=jfYl80xTIN~R.ĜYr R)JFEcݠo<ly &!$H**WpFXpyo(.vO/1 bSßO,ǎdw?&:KSyo}r7b[R[݁tLyIik_ja""肀#erCgZ62@u˄ۜx_МAhGCgYf'S^/61Z /UIQSVߩHr˯ ^>zL~062 9OQO9,̝ ]r]o[%ʼPZuHhn arfveWk/QA]F6dD$<:Uvy|E `<@MWbs]Idrlء6'|$)xel.p-$a _l,i@\K Is0/$ wNbijzrYɁﴣM>+ hEyms)&c\yKQ% KFgo|md~}Jߒ|_ -[`.!d>2}e*bl;[ w*{9 2fU9+V"vwVUf"Yy!ZP\QyIx;$!X1Bb$#~uʯu0Iז\TԜ(*qeM{ؖ2Aj4m }TZ8x͚am맶6V6dqɐ5 j fGw ߣX$>D V>k^4xX ErVbk-v%7h!/IO:\c'Tf8VWdEK[-^b:7=N'ٴZ^k`d6tA#GXZCqnp]lﲽ rgX=T@c2Ăvi?;y~]`eY(\rN3ᶅ=םĆ}Kyh&ϖUapi䖕 @ hlP\b%ҧ42eQϛjœYNj;mo1Aֱ]8[}# i34$Bd5C%S.,^6*8 =W"D̍Cy^("m?j2ztUW|*s47՗<Ҭf[zt7;Bn?94S^QX55x1nZ{ʢ c`'\YKpрsixS8Mg@c!@i#Va[ ]c[eʠL3aVwI۪_f՟#_: $B^&8YCyUg4,Kʕ NGr%1  $ ĮnTdtU)Lv!NZov\Y+:-(8(0 }qkEΈs-L攷Vv |>)1 梔nOu2 0§nheF U:?fqs=]{{,? pΚ\̡o\@6uY\?%ڞk=Oh\4M[d}!_&<0AqGЁ<]"d0%nV zGQ Eg\?̆&tADs3 #gzpt}rD0djs>蹞˼ϖ_ -S{N/|R6 *GYI&(심[p=fI&cyGOttia 8Dz--TW:?c ̈́_>fExi@l  o> ])[04z씩yoPGŋ‰_mP_QiBlWPzĜc9 :S +I|E 5q)-|l ϫP)>ۨ@(Ngj9i7 za!oX.u"L0m(T$s=Qe;cTu؞A)YКoz]nI9wr~(2M|(_<1Ҩt$p'JYWy3fG/#.n)bJA;Sj*G|u&v"WaRwۣDrZܻMW8mp0iKjZ+^šDX^U$&Ɋ<~E;z7amJxܧ#WAj,WtZf),SՑ*oכ`07s1%/e #O RSg|t!<[^vV)Rɐ$1N?;BJ~4emv9ߊ).rxJL p4HImF򋳔)bchofqo/8!ۓ$;SHW_.ׅc~z?2̛/@Ԣ%ǟ"ZpPU= X])sSE? WįAt}ʦL u bzLh#Bz/4s@Q#FABHamiW|?]襙<4"B,s/XUlߤcvngHcwΒUoPd0K5_]WoޱILk9_!l&Rm9f2A#4ՂhID1b&S@[ѦwDr=4˥;DK }eL.M:2pTlE\g^$c`%ں#O=[&P`u<1u`@Nf4gm ,޽t 6:!8'\4~n3oMd`EKyU.uKRs-_ " h| VйL^ٕRFW+C}[I.1Q";^!$jtPD"u DrH p:t |$ 9 ,obٮ(T (G =7M-+zrm3:5EMW8=K_$&MȀǵmJW2{zlT%]->lN}zݣ'C+cnѧX +px7F83 bl w$ôDR-?7)WfK԰'||"n@_ldVO"RDf ҨZ]2:a Q=V$vowUA]= sa(W 陾T?ꐰx$W'OmSY9A+N[Pʯt@=V*0#SѺVߢwo|[~j> vu;Wyp{;OѾjڢ9ɦ ]ι apq#vHm1F}=c`vTvHtkB|Yz 3\G(FtYGI:fC41T5ODf:6+7팘KTFl lqn̤L^5B.l*[!lc7wyn-o0,M OJ#~-N?Oko ;b3{(w(>^']\e ;v /Xwvf~ҶG)3mFĺU^?ͱ6+Pvƹ4lyX@ S[\S>(`P"J n0rƣ< o?JCoP"eUtFHWdIn49/e(9 ]| ic0-B>,9^OY}Qǘ#ݿذJ&~MvKqܔ:9n!oGgpD,+Q7car;CXp'|_.˾pF\.V܉k/*`wm ZqM;v85e""I{6盟IP|{z!Pcu? Ų+ 7Ōࠃr$ gO1fѽv- MfJk?bQV&:hhݺ8ʎg \Ota]+U⇲:)m, 6ckL2eCMZ:מ1G*o9g): v# ̃s{Jף* O($,G\=xUh{BAH@_Պ#W Os &ZXhhh\ 65%lşqgJ&ץ[&. <'}U[gѳGSQkzp%6BA4pt2&"(f)$0/bMOy:hg}sj :57OeVyH $Z ;9^+2/)zFZ  a m)buJr 1v(!ѪLcNzLAo^UafjDs7V݇{];j.us <ˊE<DvoGV3)9߲q䥽g;wVc+qLMr|gaiN3RjeŋXىުhBx|swf,gRzem`T̺3 /oL&0ljUo>^k~!>6vߣ8E`pS&Ӣׅ~xݱ%o Ol!8E$oH׹:y&T uvXj?YiP+!l#;=jV"hU<_ICԧ1lN9`q?QAmZ.68"UJ$ֆ7,TtƝaNgl L G!_cJwMG,`/z>O.qIٯ&Z/DH%_$ #E .#&?~x >.ˉ`?k?U&/@KW+}qv[WƘ8M ]0/^ū;\=2@)HN4stn-)Oձ"VEX0иTR"wh4A9}g鋌L8U#~/3 //,rK[jm3uS; Op"C|bƹߡ:\KqBd{S ^?ǿ7s73+vcż'SFj- ӄ\%A_R^ϙ@DqNىa448 :.v#)_yjt:C$*)˼@%Cԇ/=s՟ ~Q]aů01_bde פu4>j,Č:ю"8טgG\Jn]pH3ݶ['g3OpJ\-8O5mt$5F4!tD0k"ƿQc8QQ ➓O$ 2}ѕxVVڍCMqܣ *C7u0 *לbpdsoWqP1*~mƙ\M+ $"+֨sUQuN᥁T^coݺtuw-b,5fb B j 񛰕Pfȷp;&LUaݭyhY:t7['0IAV_'ZS1V@*~~7D-c%ؕCX}m"s q@muVu`S2%^/f3\Ĵ~-Ŗ_b9SXk&Y.e{caK (FSEB jFh ۙ,{mb!Cj0On}UH6*Z IrAo/O`)@917 {)ֆgWQ9%p%Nni <*[*L%w'uo l eئJ cy"NZKJϲ: ?z) eGEdhX?`Aehw SBUQG~'(δ{n1*'Hq,Eyޜ|mB%K*$d %鳁lM:HIRZʌ.N BeyƸbכ_ gjLvj[zQgN@}Z SU4YT7sPasz+i+ VGlD\.YGAK%bc+WZm>]/ %]=:t^ќPCkv^6G};x0p6&JwG鞭S(EƱw=Bf. ϩ?#((2A/3-hҜu! zϒ3!ռPbtVy4I`oʒ4l006 jXGx#?;Ϥ:*jbGf[o,m$n0iU%[C/4[8=ћgVr ;}Iөڧ?>`uIiq3yCP-9PGy'FkFC6N+m?@SXTz _N 8-akvޱ]/ɭz#qRǽ ۀbn?ZQq.Oq=`Ψ+*?™}Q FO[>3Y ǧ' 6HV q[QYK] P:c{+{F &/ Yn+(1>G!r7e>[%{UM܈@UD]1t3nͩ? /JAHmϹ.IGee6EuъZ^vנmD7>8"'of噋Y9j#nUj?l ~G]RNU )~163ga5y&~K-՝H"5],y Br.TИ*""Wtϛ@u-s`nbTZ# '[@!;h)wI[z>y"(Bw$2 >\ԿdYyюݺ*Tʬ# iwEp N. 4wgKE] pRr Wљ߭nX( yRK#q}uSSBq(5i8}9QeC+!+Q HF357Wv`1fYFh̔n5ѼpLbG3d @r廧͠W?78Nk*jSb6ԭ]ni['D0_;4aWtI{;{==| 7"ѥFWEEnڹ@KCRNk$s>u]U 0rEXS`)m06:Pً3NnNb. /ƧXg=_nlW~aJEduf16sCK,6(-w3cw)zܡZM 6[.6ͤ[έvЄm?4;)lAevExPyXT4纄:zJP&9[;67^ ]JL MN=Ƈ=[vJFc<w!EOl, g{$>jb9;{ΟIUC@{ZN#]pBimE>yӶrsFBi\3jU48._u=i8H5d`%KU=,%j3H?rN$+8kfl [7U@:t0p.#Z|;gufOK T_>%9[7|>cCrM)ﱡ+h dExNPR(!J -dHPԷOr&yRKu Lp)ɴ՝(QG!\?}ˮ)Q&F`#]x>dxeןLqa~O67A]KJY\ Ph[,cEjWp]քJ, I@1,$cůlWCk h*Z` )8pNt^s8#kn3KD1R+;BPâUu TrZyHՒIyWhM IV?Ky>RI'K YW:ʢ-aj3~fȀW'Ε%{fWtK U0Hcr|5A(p=l~z 4$wLKƒ\Y(:R@,+P4dL2[0 Aӎe*bf=mRP-hQ 'cEHJηxCGU0Io3{g~R A\͌~şoS[JNoظZ|ٓ)t"/or,iX0> XtcH֕a im'IZA̶EQx{N ;%\ޛu?ZDFH^>G&r&.`ڋUuM#2 `np:q `y线 iZgNR;0fO3-%9Ʋcn) oNŪ wЌ\nˣ:.|SԽ WZ{w"Liඦb(B~8?qZRd( Ξcc\!AFp:sRZ)^A ;&[Ib_X_EYhACCl {0 !,'p&ٜ;>6ZsUɍ\2mCUݮu3.|t*e"gD9y9ht9{pa|Nx:"%BV9 38LFA(0//pܓ}g8K[Lcywb(L.ie/lq,t|iF!tR~>vDl<Ҷ~h?57\MUp +v+DFl8QC3a b$Eu)p&;~,Ԓf[|a39pꋝ+9׍y7.&E5Y٧ڽ%ږ|*g(T|ǜumr?)E쩴4\MTYK3J|5alÔܔ`CƬv ^8 jE%Dv<4˽yWԅ ²᫲ڨUct[P0!D:~bktgG_3'žm%8߂-Qk[O57x[ReoxF|YBicF2m }y;cTDi4`$ʭϓ-] 6Kðt88$@1̶Q&*d<`` !Yˆb`OY$]F<+`H gΨ#^|Nt Q-@X5[/gTYk{uXZrZy#|,spfaD'NU)cpQLq3x!56nE)MO(v=89'%'n+VOl"]q\-#nqL(R[s^i^[*B<(etZԳMS*qx?BK-H+JIG'|ǧ魎gc3Oo\B &-S;BW'x dN.ZuP!P q9wh68x|" G袄 XBxuH,TH YpCqSb?ӆ_uEʣyXqk2B J_SӤB}<э3  i^gD"i,Պ/j<ܫdƪZ т$R(DQ_wi'eX!WZ \o"${ 27h/L?N:暕A?Fa-NL=##)38Jxևg#ط^)6(4mhL0T:H8#*:;' x, Eحe!Hі",\SLwH3HdRյŝDŞsΏ%KDi.Eh ih}Dp[scɝ`=fJykNw8~HOg!"**?OòTǨP݆<$5và8*SpLdW!4A6jIs DH&tX32p:D?WE{-(,9eR)طZ"?_1V^WڰmEdeͧ\uLz7o'qVg(D$ޔGycx07K%R=;r7[7 I"-_6Hҫˠ)&sǧ=6{^jAd v]0zf 4dKgeΟǡ,ivVRgFczdNC $VmW=[ooOxht+ ms";d窔+ mn/I 5qyH򞄳D,R.JXi|n,N [mDqd>C.nb hъidIZg~kF⌟grU@$uP /Ld rpɮF ~UE_cA^ ·d y3 p )yE/Ph'>N|̿DeNQe//o箒y +~"uk0dFtSm̭g2ډVGׯxtb6[Ψ󈕺7caYRªc}ʍk%M1y?WGYܫ;tJaqr@e$:pPȍp7I_h 5SED~O͘q'ܢPcs>=|LB\dLg\$ݾDXj1=hdWf`n>іw6Pĭm#$wBa^>c([WPCzw88Όc oڼ}Ĕ>Kkv-zJTfv>c\}8H*/LbyuJl%~?dc r Mbj3b(`e,.,͕(O.o(J'.=ddF֛2_O͟<8h!bA':ȊksJб96Ɓo[oxFW4OTH7N?QUVl6ΣKwJ,)7 qP?E[xSq~WD$$w=K}-ZA q 1XۘOT\/aq*_E gu}RFYu /"n"ՖZu7Qh$3KC d P$\f7z<= وdLj ):EZRTEY&^{>5ɵGI67!5>حkW⌗4+1|Ik2"Q~ 0lw@e;Eћ[^䞈8B @ɦ_.P-%P`K )ŝ?<+(Pˏq+=c_LߝwMj8ʘYqKr{ߡ5L>hqa..8;M' y윝P;%!b^ =2aˉql"6] AhtC\R zCA=5d-?DK 5-dW)'S#1ϢUn8IϸF{Y_4Y(x:3xq)K+1*]Pc&E^VqKy}|wx'BCծl) zK  `G h6x"3ṿ'g/DWokAYx, s0%>Ǒmf4ޒNj\L&8!35l%c _x:[˩ - :˟^7MUD6 4W23Lᵟfzë&"<-|?1V8/KTm \8qSb}o PKe30QL ڔWj|Yf_b"W×̍ưЮHJS 1 F {2A (?2Dc ڡID7HNp(std$RRCݪPM"m2;ŭ.d Dp_%WVDx-F(d  Ymߑ7>1-2 g=[ڮ-<`3k|  ySR~ (g1Z x;w R&(q-(r~ic-~ޔNEr$;0^jJ=uJ5܌.O"VSAǫl_;ϺVZ3+vݤB5qLTa/";X \گrְnx -! #5Af?|a{Xש@3XiP _Jq,MIp' |I;BHwbs )JGd=$J6)ue~VMJp X)a,}dgT@K] .dfAAR"d:8QwWEWZNݱx=S.3FxuKh{gѿ.ta 0t ' 9ΧX"WM :TT;?}e5"r[Rl ُ!$l@"~T5X䪀TG 1W0=DWouaԢǹ-Kp7qډf]vqKCnSx9ŵ5b?U^2 фIib }'VIo*< " ,S% =Xjk yZAIg!)_, S:mα@gX ZZFa xVdǢMgT=tJ\SѧWNS[ zm=4\L&ė9֋Wք*ub::^ä z^3ڄJ> 23x0ҤBj|r烌Ԕ P?$ahAQCԱ:€6ꖻ8+-( Q[f;6#5$] aY? .y7ÙëH{p 94L؄ )(p UϨtEN̽ Bʕl3%3 fnMW`Ư8;ˌj47yDG F#x*ǭԅHﭺ5nq=њ8odoxTXvpO{هL-cRjgt!GBlLL䌤Y׹C]~љd0n-==$G.{=$`0 Np'-L{v4qfݨ$ٓmXP)u7",Eh_w^I9 xm@Z##vi ]-I:Xu 8#'@:c; P-j\3nL ąYyDo=m#tS!"̃˛u3g~+,4IqD.&(bt^ͮ|e7hN2ZZ4w-!VdE!/-0?lkL<%M5<'cӄyU0:)IƏ +qfZQ%4[6 \i/+nW ,O*Wc]z]}tw9-BӒO@}dg:ɦNщ6EZRՆLCp5S[!wؓIJ62Wb('IAC*k؏%;t0zr["(`b[d3 @KWERH?y(iAB?S»V!]gwx..i E;c:pL 9O|e"t/q3-?Uhcrcj%ϹoA^*Qao,@ա'ͼ`;A KZ]9u-QuPmc]_XbsG6#jn\jgP_nt/Cޙ1:NmM2].jT蟖.(~\WJbbt^UHC~]L!m6Q~ ^80{^!#^ɢ4L\hA.{mu ]yn:1wH)uoP@WIJM|?^suj _>bTW`MEIDU[E[:6I‹D7r(T:]eS2ۗ| -; `ALgkx|\& uՂ"Ɏ5—>4[u٥X|y 88+-vw(lCikjek຿ !6Rp| xA>3AVqIӍj@ .8+`hځ(9-9}It,ß0`'T|W%Qt\vGXRHh#rCleV˳NqSx#m\9T$T vVEfW$B X?d4pYD[<{du1@Ny u-"U<\ޢ;]Lڗqt W)NH۩/l+!="fߋ,|>hzQZPx4qD-/8U%qn[o7c.gn% 6N) $%yy? ZE"Y*?Xyʨ5GސHRVNԥ>Jn#h 1lyH^i6=S(Bx5NΑ'Xj38pwڔ }68&ڙ,֘.;&|Ap ^[mBRf=֯-qn=3^ ~N;3&Q)b9Ϧ!\Pca~慠 $<N8vJ3Mx `Lb(S7‹v~}t2Iz[%0IF.᭹%˔L_ŃS!lA{' OݖF/LdllmRYz-O{Ց]2I  "-$2)#T&yGg؉ޢ)\C[֑.s_$puYԦ^ !~O)a +yꢴ\i4b[ܙk=nvǠOxI^{n)IEn0JF &*x,+;|br͌:~t-43HyhǝW&daYKc0҉ {\,X N[Lu;}D6a"O|oDwb{I!$l7 YFcr=tS=)<+1ĥK hn2}REvI hѷ87wXƂݵee!,V N;0"K#7ajw_-qBW an T\&!6i>N([ʤ!t(l ]?ۀ=H V^"&p'L_xLPsVQm\׮:MGG/$A2Γ rxɥ` Y? 5y|Q}!D^xVhJ}+8"QfC; F,ߑ ޏ˷j2^# -!r+פ׹-pB$֣ؓ 9bL#9D;$\ئ\%eX*WnI"b dmo!\u-0skM̗p&f dVHUN>#*UBZ)Vt47'l? 6M ?u\`S8"u+aШ; ~z~f匞brw('~;9Djdí0VZ(,P A(V # AfjHjSj"/>ll[*5dͱ-k;†>xaЦućTa{&R 6'>#VȰqҐĺNtawO }x%^nw/rBg!UhP>*S3"Ey dsig/ב؆uQ}n|/{ƗbS; .DXK]c/KY}Nlx N8Fy>IMfi.hj,[!3w͘.1Oxt%e>NY #95S;I%Ԧ {:-QվfiN6GJV}%|ąj[r|ڕx$󲱡ccC'N^؊el"}9(}e<ݓ0NύҡFmY12Tm<U;Knm-ЙD>8ߙ0;?%a>opT:BN.L&Jk˧J0*ҌUߑڸX 3ez7 Tڤ?!ya'q\C$H\QԆq#j3!MB祌CAx.Nsf"b3pҸ쫟20 B8tv0Dz]WmIGV^]P3μ~9/)y,$U ,)l͔E2@ 2d3x:RZoww~!W"Wl} b_)S>`Ǎ C 1M]BjVUKjl_j#hJ薫UԜB&6 YKh)^_c7hw9>$[ѵ 4+"~h`65՘zK uv[&(7TI%&|JP'jwWs+XdG&%}+!I44G H2B *SKg.!|ʧȋd@()NXUg-ist FUP,g+g_y\P }0Cѽma36.>c@MA 04wMou80&*㌝rV< dnwdGR 愳O@̭U&.® -_{yG34\:5GʹxkU8ueg`\ G\,w["R$eRNh ҂#Ӻ$/Nh)`G@^G^s po=OIhӎ@z1[us rRF6r4uװFn7kl2z6<\ }5R@zvue)m0/n>mT\fDS!X3r e7VJ8we7Dzul,exUKB v>u4#9GAE%MpƤ'Tz`>f3[W(ƈ{gmic J0b/zAr3Ow{ZgĭWeZ0lZNdI(8_ylp%$;ѽ _@O <ǫj-J7g3ZG~BI^dF`[r (AP3(\x:: h'GtnǶ8>^N"z-Jw/|~}%$xN)B gXjN]N7 BS ȆvɘU:c4UhS(G?@a gY'Ȱ ~6@d}j4kŒI7>{{]z1:Y8ݠZȩk^'7W1n8`2ԴV"tyܱq4|9^㴫 BڡpA'g3裰 LGx <@a0vJ}?yk:#7B_H/IN /"Kw]K=2WƚN2U13Y9v/ـkd|`9"/d ZFZ$ 0|:R%o` -]g(LYRdQ*QEN1&1 -6Opgd6xw|(ui*)#|8`Bun؂K`ꯇG&`%6 ,NڟA h>?& " _$EHJ87< õ-^[z*0JRls%U= AD 6!#̳P ^`{HNGpBWL rWH[_b%> xBq]$h͠gGO-uƫ Bjf 304F0(sL, m:}+LZK +'_4/ |w-SDKJf1g|u9<ӎ["5!e {8bG\"v$> sqXWj{@='ͦ Po7V}P嚮e-_[ȵ;f/J-hg {+`3Nev4o˕)%%KXD>C%/!_<ۮX_gK(peQ .H%ܬ?7R 7~dklH.d,UAQN3\~hs{1?Ye{iC>=br?Ȫ8hL4ra]3$K#jzR6U`͝kjd:؅\s=X9-L0b`uq, } SZDalA&E%ƤF<O?%|Y 2TրyҞ`]$O5 o;IzAӳ|vLP='va,E~힛7rhJwy0K2EսEzRRl#U@?Ex*A3n\ IZcp%$!ځX@VX~䥽/&0(O `o1H(,ӟ֊!>?= pJ/> χl3j,?6LTy󀞿2LfOذ'(n~J {5O RU9pv;[tdfrhGihkLđ9 i鰴T<ŷA{bږK2@@#+_A{hBĄ_!J;TB ٦Pi#}ݟp 7i5bzC1HADqVuK qz.)| 36IP2P/hwA_!iεZ[G?4gTrDu ˳TJ6<сs sƀT,5ЀD "%_@}cn?S7s"wIhZdߧnxqwȡ+> N}O&HGS7x/+Ӱ\T&1%ӿ'8e.82-a~SCɎRt*Up'eBC {AQܲJ d|UUcEAk,Q1]0S,V(tϪ0qB'!0؈ыCUe j-JkF塓ﰺ{u*>SFU x+e-^E$=$d"RDp߾Vu1dUUU#X[w($C9#CY{%ckp1pMnP yMæ ~,I @ 2FUr6[`ZΩb0 %mxB6q%>h0Ć~ :ÆlĻs-&f mw1盐] p] <'7,6=b+ܱ.``I !1RTy^Qb50xy!tn<_v<HmeO8S(|#"G5ӈ:v`fgl7(ʟBZsu*_'hN74bWpaQ"Nh\I]ky7b;r<ӯ*`J~6zIH[f(>K\VIžRXۧ ذJtLtaY`^n/tV2<μ:*XVr " BSfx 6_S̝@aֺ>ټ̽kUH'SԜ Tf2pF:[´_0C c Iv/ޅOD=qM:=HjeV:WQլz)bqB.zsjQiZ56CwcfK)08n=d4r#5[Jx=1ǵ:DvX!t).Gƈʝ6!Pܟ0wO1\^6E O5FAe"->AjN)Ԣ-O15B= F  <:1Ṛ({HDҟF9yq鷳ziQ& x(ݮ!ƒ+fªEƥ g9)7%CVFP8K|c,rRabjVaj1L>g3Jˋwj1S|{"AUz ?6Xfv14tFa)QX*v]rc߈5h+󙍮4@sp=,E-)pM`WR6Pbd )"dW/Ci\"9KfKGPlZ} o̅fi;.z"f[sb\/+|o3㚍pCR9ՆCwI\OUV jӌR__Y$v։bs84k'}js.e%>.(?8Z@QgV Zɡ ұe#fwI2ؽvdEZ3401x8G35@(wa@(_鳧nkv3CMZq\c׸Σ?yrk\Cu*Bc[>AC]/EK f5`Pf  mܰzƯ?,h@;!3=" ϱ!X檣U񤑉&)ЎZ?o'YLt gN3F/ 9[{#tWv0$_zD슀5W׺㩠\]t־'g[=N+uÔSE5CL'ƥjsaIuJ^{g9#j>?k&cqǷ%6v _lxoi/@/E䀒֭ьl򄼰̬Y-+WeEiLl-eJJHZ& ZE,VӚ , VV]2V112Ծ}ٽbfxA%=6?jcX@(ɾjS.FQ4mǦŹ0-goTU|o+@룂XY/` BĀ`+?L},榃$un8Qv8&~~t(+oW¿~ާ tta;9 ?:AP=d{, jL D.[!a ۶٧rx{ZV@41 V6a쇫SMzQ_rǕ{'qzf>%I#hSAoEQz\RxNA$bH g*( sq1B8.IhKb*D2}`y '[}q [ ֺIH7Ϣ>5Va3_K  p.RG9=ԃ1xxЃk}1-oFaU n{;2 35Bl?KfI.R%!o n߳yݴn?l1T2/aC˂L&c3 _0o0HIMSz²X"pk3 i3I^x~G euc}MPtL5044I1уGVD N< x!L!:!K_SUC90,Qθ~<^A<MsErZǑQy ZE!Q]T64:=Da=gɵ+tݗæorDkE:t)S%ҚG:9@Ѕ1+bXiFI ${s#^BSU=\dC>;2d=󦗊r/Ihn!\7Kpme\c{J8۪͖W[~!dx{6YH͙,ע.5? W\Qw7^KߐF=x93un.BSK"8Ԕ%"BN6("waeopٞvsN!`By7x-!'BǴ+3=7{ 8"~ n:ۦDBrBT*dYGצF Q؟m?!LqH7 B5"K=̱r)4>{TM~6{a hW= ;m4:ŗe5CZq gcEd1Z8|FBh"c o:%ԸrzѼ,4,#O)׈-Ufb#9HXeiKX)v>d9;Gj$@M-yD HFPJZI h(փ<(d)T]g*8߹IGL{?p&oVpZ뻵/4pu\u]_،cuk`5og<Ι(z\ y(fpBL8s 鲱eT:dE*!q0)wrB~~!$$>$1[ I*_Q|/@B.e~+Ji@y\Vy$LüNe9,}eY1d?)/uCɵwQ@_LݓX3"1bj ~=AC#_/T/\j:j>\>zd 2y~E%y{?uWs:{L!Kl?sDd .˥{ŵPCkt $UoL0: ,bF<3s JJS6 wꦏ, 4 aэ9 XդfwF*}>y;-E0͊4>ӱ#5d"tKtv.FX `br+A;4eShy;-?udjtzcDRO8Q|M ru"#f >ԈA d,wc$u5vtt2lw)bLXYJ7~Pj$N6$j.£8v1QI΅2oD߷9~Iu`M'z اAW տCkSx|:5 qo`zJe!%֚ U@99F&4 =NRW]FŃpx<ٛlTt3ka5cٗ`:e3 [ɴwll}ma2@F?e뫧iq .fnkCzsFb糞QkOF$&{SVvh_^Q$&UN#p#lw0#?X?y5Ԃ s>e b񯈍[Q!!Iy7e4522ΏH9zyCS#@۝PWuQQn^9sOpeMBo P-IN>ym;ƌhf|K^-kӨy8Ei%&Q0 pԒ ?Mt[Y[ ҕ8vi-8"M!0 6Er3e) ђbGO znF폅q<_6b&c9\=j-†= 'Xӑcq@6Ҕf ?$b F\PP* "xhS h̾cyeJmb ̽ $%P‹S|QUaֿe)Vߨ.#  rYEA m7~f4-\ E 'NƳQp"D9Q /_R&Gb !c7%S#ӕWy썕h Q7>:S>2N1|i9,GשR߹?qB~歔sI\Ibz*szPO|b;ʰ`M_w.mʮo zm}M&r ,v %2QcfQ+WpWz᷒`fHȩ*Wv>:@Hév.۩pc$o>C,-orIl8ڊ޻_d5Ml*c1$V64wzoMq̃f:yfi2RE>]չ|o/fG @!õ(Vv"jr>BdK((D_be`M/y9]ix])Mv% hvl,ƣA0Wmpoi&SŸtNƵgɱBiS&k}]c @8u1 h Eo!KL<V/? ܄y^MYi o@ nuuaM[2p=Ё՚8IVcdPs/^oC Rl^kA AxO:9J 8ߛ |@E UoT#ĸՍ4%LH[Pxߺj# ۞cМ嶳)/da+]V-\c<zãS)Ƕ)zsaAMBEd)ާqгnm,1\qXKm-ۘTϻ\З+F7m~cQV踨d#;r+,!z|[z4-1`]V 2f'aА[#:MN l~/>UkdnTR w!$0UV>;v3.~"J偤e[f, EMB_M ])R~ op?QVCh(HO9g#s*\LBbj J[v8zȳ.R(<#e5г33HsY OBUBbF^+f-Lem-d=g+  vCgIk:;y `"q28wn L|l_܍pg>Ą(:ҊT?\ (BIXin`UL+YNY%N+4zZCWfk1V=~pG =_dopbU,\JnTnR@U6`Bl(BmE'\JCN8]NS_̼ *="_ɇyE:ڈZ+XO Qvv"W6n>.l&0?1 .Xv2y-=Y\Dxs|Bć󈘃!mhRΐ Ǭniy*$_>8&гӋ{p;,76R|~s!W,)Hhd! i=]|_DHHG(v57ԚDL+-J-uA,7`xwqڃƄ͚v2ؤפ;Jun $? \sO-|gkUq(/7WOb~ц tPSE&7۵njcE^DZd\SKWX\& ?ͶԳZCoR[ab] ϗ̌5rGk!O9s6r WBjbVP8S}j6/R%" 2[}mn+GƠuJx 1Q|8/(3L2OIqJ( %7VEbZuX㫽㌃zh1/nzb}1Ai.NiaM" 80h EB1VuTi=[}UR\]}3s*0Ң%ri]ems'PpD$.b{BEoʰڞbW߶{ʞ[0 ˜"?}(Q4RMW ţUxڝZOUiJK37ƒaࠓN^G!$s#G }Cwvqnw]I` dKMtI,p>dJI!`$x0"ڳImq J>NQ`X wv_EߗZX*ZplM0/!eyQ!S=yGHbq!{rN^g`㻟e]+. פAm]яj:{{!5}|oA,|g {$eI$c i'xM} 1/OOdčjS*OIJ?UOMt6tW.$y+52RV"$v20D`U̗LWx]!H>Van ~f2inш23mr+ ;Nc %stḚ(-:ܾ 2eɳ- Xwk-2eA6~>IHu9 ͱO쐬U\N/:b{:lQ֊L ;n9(y\ߣF&++IcE",ɸ*P& `9ǀa{ >?S{km M;]rA| ͪ1"+FE3\e#3e]=jQikU&t/c<[msж~|t}]*xQ\Z6zf4FbcBoX.-)SdSIK\%ƾ&잿אzs;x6gϫSU۸? pc{o',EᑭX<=Mn8xdPVRh{ rg%(#{Pidɦ>'K|Fpp3 }.0̸3Y]<]FdVQG?XP?z:S]zɹKe$=fdq21l&c +n^N@2r\̺S\|n0^6)H?o@6f7zt 8X7ǥ2cw Knmhm^-m{LjmypPl`8 ψ\g]~>c_+-k - 8Z"E{s^ǡq؀ +JOa 9ir~ CEϏ- %'lĘT*LsIm͑>Hсd)P?<-Zf}ȣ{93u 2*:6 F _<ҋXeZNv: $ߖvZ$*\PMN^ 'զGEWrQ5&~ߺv;h( l>hS Rw/ y]ѰH6^1M+#uȅLd@CR:y>B冁`karjUdIʢGID 9wHCؼtV-z"@##dn{KS7 wsq.{>duETy(%/rC~c*kpid&Y^Tʴ63ǎYxsD lQՈ ѴfSg B/u:߿IzD,V R PU-4_ƀ9U;g>}*b}0pT+J(BJ+,i,` t~o`Ƙ^ 0;xnn"xi3T}!/vu7زC<~ϰD B՚Ѳv]D8ĭf+%I}lQ\z+O( xҮo cQ6fiTTn08Q kF $CfSy.Œ Z NZh g)= Ns:daY dk4-T_-w ߑꋣD^m#]wv6!hv :hq.d-&pTjس6wDl Rsvu1 tvK_؅HNt|=xI@"Y^" bR)g4l$ٞ$ă`8wI']}),G>>Z)e- ' V\ij<@QP .)Q5;W:tH{CbHэBگI= j?P RjVtnuNqm̏n&>˸R6k)&VTv=<J_#N ^Z}R]DUJU0[ &߃~BIyE>wهSw!\id}Ǫ0Z@FnE8O`Rk:r 8/Wĵ_{ !ܵi܈'X<0E]. -iVSkvdF5{F$ee6OMF<= '(}QcZNi՟9\ ~WԄ p5Aկ=%Ebmӣoțb6π!\X^-: Qe#Jm31o.Sz{2E hKPp+XdxvFx{aIYlp Jq'ԻHL d=WxP rڊ~5-TSé, =X=E6i!DKeR<<k1|n<'%᳀ٔ1$_Nma%;a[dC{$:.!8z3M-Ȃr>XwKwd\Oav]J(-2Yۈ=hCT\-+9h@#88 r%~dJݣ6p\yJyB-*S` W8-UT'6jOF4pQ#x |LPX~1oro7*q3Q-P|JU\Qm<ӻ14H9smds[V)KR+MvPaF pBSP=Ej5pHNj?Xml$PQPYd$=LQ)g1]8)m[]lݟ* wRjt.^mcc!jE4*P{2i>l[OLFQ [!-]JHCp'o3O *6VF trx}ֵx4<>(~߶XIե?;&'ۚH c?viYr#QmEz3Њ_9J__) 7)UCr.0ӠJzo&Ȳ<#$әjE-.Kڀ)R@0End&(^sg;́<\䫬,Of:.v?O?8S{A%6N|SEJWlDE]>3#:A7:p} IVļ܂F~Л h>7wpyª;Nj5:$Tte'r;"WJM:-Xa>J2 -{%C>g'ɴNS Y $i%H:[lߎg7<5>l!{!Bd m.n\NV R Wݭ&45˝E*O:n/؃9B4 E.줌b"/[utYYj 9,Ǘjt4qy#I>4T$8n*`\}xpV辭KÔ lRiVT5NP*i}#i$$qeMd[c">CV#3dȕ +?%LHu՟_S7EI`x)14>Cuy[|r]~XTz샘Awgʣ_*9,B+*oDEHvdt^}A R /iT8 obAi[^CacҒ9d0DX TX@$]wev\ 0!Z!*3T_ <3Fxpm !`Zsу `$zLRv Os8T<6b ڝM@G{ Di.&2H@PS3@lJ" 'd[r`aIOb>yD% ~ה3-Ay V 3_T20AEG!.X2,ChRbX4 |ZwsЗ䶡zrx;o.$XFC8wFTڙXEco1plRwEDU@0kRs"Pz'8Y/DycNʙG 1VtKU^"RXf7` iEg@g;96>#ҿTdK.5aVƘ[:'BA^9Lǔ|mC|+p'VrX=VJf: ?#5r͇H/#r?vl"^.u|Id)HJ}hH,M*$]vk5y+U80aU' %XߟwkGSth]y00΋WI(p9JRlp@*o%??oϵEF[Bh]=!D>{FYq;F )znoO?LP̭M]J/ژ8d+Qif}E+Zey9(#`8#`L >(+\J*1wyץxDP}0Xito;A:#NgL-.^" Ao0ZIN}O9`cz{4=ZWȷNSGR1zʯ-9>x]:'׺)SE8&颳̰.(XB8*e}XPGIB'RwUx+kPN)4{ T+ [Phۀg9M$%}$busIʰZvZ"7TwssdbO6/'~hm\E[LޫX} 6$ȞSx)FxbOʓ*J⾬ s2>js,(6!J#Yƶ:9wl|}u`;Ѱ>Lq0iehP5)PDHJii0DKx_v %m+ SA,pQߚFx?ϑ8'{&+Pyls`*аNF @_àDs'cOƼna<.CSk7iJp5+pϘz6G479_<|4H>MC Dzeβ_Xpe_;i9Mw_0naAxU2  MuM&x*W%hU>q(H~4BHgc?Y%=>K7W?DĭyĝI}bV c7ug Z*ĸEH38W\M,TUO&;jPyL4y ο/Bݳ ~1C SM 7YC 7tT˖'"~"%_2uy,$zNBE[k7OƧpV;I;Lj|9ԧ8D?ey"Pڼr| 64H\cCipi!R8a3_ ߏv(bѨP6Yf1D-'Mur1Q&o34!U1'u\b-1\;0 K%\>yΡk<A,fBeo| H>17кl<g߆P<0r-mV*CW`(Z_H@M&#uN[%E PaKcTɳlt9JVΈm*a9/k{>/ӷW CV[ j5N}TuB\ԍ-/K\< dKh 7ZΈBc̱' 1C"b@PZt\ x<+=+y<֖^/}2)d"g%KŸ?Q ;Jdm{`ii_/ ߞL-m,>a)PxV=Oc8Ϯ:;)`/JBipj :}v.3ŦVy- x-pQ$hFapk o(Z\_e 3ѮGZZH!y1\G3/E|}Bu5WWh,iE9gVRLt FDZGk k];WpD<&eG 2'U5U6!ğ+ ϪW"AI٠R⌈=Hb~dէ]}76j_scyzw` >HzAlg~$xD26 3YaU3TD1%5eS6}WP>&5y3ꖋs%Ǥ']1U^"Q(ߔZH'U#Dv]h%,)#\ r/C+yG8NJr?hBGbh@H1JXF-`kAmVNj 9$\pt5H Mk'7I` >vE^yk_AlacBw\*}7;**ʓ=jgD|)oإv /:U_gR!҄ _SDgl ӳvʆF֟Cb n߉SN__\h~)PUxyߐһ-\xMfIc:TGI#Z[. W 4^,\^r \֕Yô(w8 R#m 6FWT6s7{õp_Rw!aq{4%.PY6 21Z }XpJd H 2U>?˽.-Ae~Ep z~V!gi-S:zsy+V+e9 Ϊc,H臁̶ )=PB ءF[)WF/jmHSXgach.M{NHk^ZP1@ED"AGiq 2K 6iڵBza=MYߺ&nx_{|Ҳ! PSHк+!fAc()TX0i k猝O֜0St taQQXm{MV)@hQ1Ug 6Uۡ|Cn+LkRNioXDG :ι˔q$pQHmꜭpm*g9G{%ySHFɃAQ5,"N~*.yqdXfD;R8;$.M .x0q7~vmoST3>"ZRY]<0}!0"i, wЭA3V?rlVu-KMQhW# S!Q!nK:Z,uEUMSZb#NXo*#SѲ;JTH 4g+Tд ]ǁECEtY:||I-:e>6iyOo6Czm@t^R\.&A<0RcCڵ詘)(Ŧy^LU4^[;E+Bw8znӬ$?1xLh'H$Lʛl{یR段#CO/;f?Kۙer";3g>*fCI(f!1f3H3cbtAM I˰)dNB M^8*N >#&$$MfBRwRG<-l\yc༤~EFWU+n<fݟ{J'뚴VNdZX ]Ua 8dhݶ7Qrd1IG%Jэv2#,TW=5 E4W_EkDRNj|(o]PiGl=O}_V2rmtҀ +as;V&Nf|R }C@VlW qrn$ vp_'{`CyW0žjFߚPHpq|dĎ{7 I˹bAouz|5MVSgy┗M=xq ZSjtFWRmj1 aL SxŻtwtr͟[e<O؍GKnTp~ǕL]-E<Ÿ́EVQoPþop+=_0J]z9@)J93,CiR3lX_Zi+*JȴZhB \S<%ND` yX;v"$u=b{/Zf, C&tźq^2@`Echc,>x/cC1Ώz[A\s@GK6%VX_r" ÖW ;0V[ox@+"1F)q)i c|p,'8ikl#::ѐ09&w&BW2Ŵ6bM<լ6"9ꓮ;0$*VEȅ$2v%WK| WuY7t5AhpXcS׸0Jw(E@Ϲg:8 38_r}HL#' -kӆBg>gs`ߴC7ĴuHZ.^19y ԙo*(Ǖ&Ky)SK05wk-3c4S_l- nϞ*1Y_:yk2r!XqV(Ttbf4̩Cqp'17:V2+Thp;3?b4? =gۻH͇j\kÌGXHE0Mla~E:Ch- >RMeripR? }[ ѭ_ ߔE̒HBϺIi};GgL$A5W5ZMY\Ƽ\㥛*w~R_l8NqQ V)TWnt7ɛhdu{Y"E`P7j~foGMu_e\|:cw3lpHEԼdF0z;d KTMښ̤TCڪ *wx H`!S]%'-m=epY^i7c%'[J6r X ~q;'ѼS'CB.$^:`3j4lyܚEΚ>yIYOCa3Jqhs* naGIa L}ˈ[\-]D@AKRށCK2ר܏?Χ$Kf_ڊ'M6^KVuͽitm4{`=}dW,sUh 9ֆKM'eTXk'K\Ŕd9 *%G]pjh D{13TaOD ဴdK\)9@qWH]O\4y+FN7qg ~|9VnWpNZ\ґNAFM>Tx؊Jc̭D :d 6 \)v >o1Q{7&rp@GkH L̈|hxk|LSfiӎd٨QZ*3x7^*ӓ[p_>5)z_x,6Y#W ;,&dۆP3Y}ŕ|Dp̫FʖR$ @1U\&X~qtl_VIVK3_нyfOt1'2 .eVmUFEj'qkXb-0Emxu&)kep8|KNsy+k a5َJ$bZd#2z`hMd,'Fv/|YU@ 0K>oa#Ion[_dD0q6}g8t 76"qPJ; qjJ'5@,XڡJ.XnT?h x-pYA<=i} 6T?#n4. 15E/m/˛c5 co~W H}̞C@>SE$(Th\5=lb=tjZ(̵R8 Cl3}84 ̮<޴vF'tfyc ٗqL"{1Kfg`^dQ#_ OދX@Eci&\emvAgVg*TEy;/*9ow{T&rF>2q(?)| #`ZdP_=묹Dp\GzW2*GK"Ki`d(Oʋ?M$M7LK%bT5L?4MsydI},j| RqZ!_ɾagolk?^ÚO3bLR~G X}ۥ5@Mv'Ϡ}6U-ثHM ,& QXB6FۓwǾFԆئ}f?rj1ٰ-z SnpԚ uWްJm" SξOaI>x ol}Fp[J~^Ÿ ofɑC@% 9pr=LS>!xa-mi7[7Fdg>G9w`T-I dtMQ9 XN1 B}&k1GԳW8:4KO'o.1t*~%n)4NM@J jZXl=GrՕNs_%wZP *n;*d= [~N{+v~1V][ y\RV][:O|3r@3;-57D ui:3Xz\Y&E3# @uiN5-U1XC)W[YiQZ4o5tj_rqdV(Bp Bht4'/ᗦG%=hJ*'dK 9k$N5c>Hm?:kT|&UG=( <;hNr CMCvDh$/GM%WtZ."x-G%#Vu'T `8 :RJOvaU/A]=Uf5z6m!Ϝt"%gr'9̥>.uOweKX, !~3նսSK&7?BV' 8Q*Vɶi~motG:8xDvzq/XawgPFg9pOD9Tȡȴ}s$;=7-ATݧRqk kK@%)DO:0ddpkMjTR ~c`7:zBt)\Y%gNɣ+$BD-2ڢTHWSX+9gSF#:5AN7ath]T @Lh`s/;?4yВ!_KyW^I=j5*;+?hQ1U}t"YߘZ/[BT !mPԪS[ZJMr in7pdPW&|^euAހ9M=/rC{"N1q0MrùCD:} W̴Ǥ0vh*%+@Eíམ!Ҫ}E}+$ Prbi8.xhQ8\,%q_n*YяEapΚ\Y!L¾nA:T*;W@O}΄V2<4s <C*˘dnn-r`̈́Xj2$hPq1ky.y%=\niMc1-D''h:-`]\N}?YDKWLvVX ʽ rtF}1xxCۺij}O|4PVRJ[;*Iw!,EGy1;&QNKٴ!ĕb(CV-19os_&cm YHAՃ7fOxzTuAPEȝ|1|4p{u)$&xi e_=$(֥U*Λ5E:`ȺLzI 6 3Eԙfkj Ph26FFLP]g!p_3I%}ߩ] h/9nTI N6vvaSJ)%٬D}VӮ J9_D4ƲDk xU>?7nm9 &SDuC'\st)tarw1ESlO#R}"}CۆMeBqbV\NqYк Oo}-aԍ"tf-DG}z߄Kc˔R>R< W*Ogl.{+_ &5/x0n෹ SmeVLhՠ=bVi+S*/xéߓ ˻`_| m`ELv)MZWBF> !Ec*5VH1ƾ)T)& ZRP*:.~y&]j^)`@GWp)Ӡ5Mqy;ا)4DUw+y1^\|2C 2-f=>Ğ&٭B#pyQ0dRI~' {6`H 0\8 OnXCBA.(o24 Oỗo\wN.G,NHf2R>g9sP?\3LHZTSpͯ yK9oWPjZ&/j5g;.Dv ]mбBE_IF$!5b>";aJe`0%k#°]e'5n׍aLq cF1p1+. L {$AwHo oÆ$ G- |lP~ـJusHa[-O<7O;RvѸ1jM}Z-\v]BWΆ<'2&*U$ĩUWN1FjҿdtiWe: #PhyAIB QvЊ- ),Z!4|,cei?eI>G9Y*>za=ylbmp DƱpP1e. '3>=$ݱ- .80KEz,afT2Xnw(J)&8Ae:f ~Z?[0rK =ճڎ9<brRuϦ/`KJڡˍFjS lȒҕe:w2JY B$R<}q[:c׌jFƋq޺-Q%;V%g4xn'2>q"%иΎpשAv'i"HZPe2y-A@Kd[yn:5Ǵ|w>ܖeLY(Գx z螛@aL<PHQ?]R!Z[n`m۰T#p7+yVvks:pĬnN~JvY6*Sq~55U3Nz@;32Ȳ B{}_RHSpl`!rt=j=H[ 1yh*kf]"! BXsH$[֓ 醩v-,yDsRll0 Brd X #8c/Rm=+_q6rWF<+C~uw:3A Q_b)b]&ujb͵fkȸg O_eSJu=VTGy3X^9_!s(=v!II$a $ﯪ; 'ȴ\nާ.8:/.0f%ޅ@WD0X#_xƺGܿwnGd^#"vJ}~(/'OzH.֤QA퀨Dih3: R^ᮚ!'``\re'6KE+%nC rȝjj#&lHP?Ӭ#`>C ntb|ǡ5+W(SVt^)FMB"D07Q6P=e[AEXHxPk4n>(@E,bԅb| |ϋM[S'Q;I8w\kJ Jomt{0x/|s@6+Wp}k{Ă ȵltĺ ['wcwɺxI|P~/%LIXi_@*La\5A.6U*|f:ۅ1\]ԆT񤝕F;*Td9ٖ \9+MbWtZyBthЕ86 s~n<:<ܽ(3}gU¶hM,&N˜0; œ߅9q2+ zNB}(FnEI+uS`rt T}i/.CS{i`eh>#6m+p[$/p$iHy_wrHӪn穠cǯem4"C5R<«II<)44-J0~eW}oPx1@?Ҳ5.Gr^Мbȋ:VU><н푪)ѝqhy7_=yIb|f{F߀gAـЗ>JJVn)UGXCOZs=󬪰ٚR  .J r,;5up; zٌsb%w|, XӸ=Rm%nEOdxgռ*&bjDta{j-֒Wַǜ_}i)3 D6 lKOCx(@%wȖ}.p!7--6@ ENOg_1CqC|W'9iRkUWaj:Sf,[6%!rRVt mkt^^"OWR?ėF>nuA[(T's`ƹ,?Ԇ%Ύ2@*pi8(<m 69<:F_d>! }6r7?5SyXJhOo [{#e`דq `s "GE%0=mÊ.OʃEU¦֏kOWjb3zTޒcw^)g(w_AkvI""\Qr{F;喽-?\64ᯪu-ļ> ,wN_L'gL3U勯L3^e^q-}POqX23%w^-GLh^ZmϠP| |@6AR$K6k1Ë@޷6_ /^pCk[DTL|Y>X`- c Ǥ?Y\Z;jGH{\HH^ )~Œ 7u!DOaAFVp (5HzDQim(se7T=GhLG{y iޟ4FŞA)5Tο3awPMO(ĕOo_ˀVT???7WlJڐKcQҾ>{ m=i-T UE`*,5UZ6>n#v,Š  ~r20"Z'" ;jg?K@g]Z;2 w#fq wux#q  􄯗lx <Z4A~Ugn+%FyM@/"ƒ/eAcL[1`RpT=]hrGf%D "q=)t#@:5¡j~*AԆOâezɕxMUoN~M5!c6|iT86@4W/j6V4Bpl1*@$D\$e V$<#J<@6⩝ю&ЕwMd;@c@rT rnX$iL<ڏNa| 'B3֦8z]~s7+˜E0h~O*? 8޳ Xny^,꿭~jyRGiٷFÞ=El0-4ĝ-i/ȉ  H:-<,tK8J%=4.g|cL2iE$&+CYWbt"_[;*aIqCqe M,#XVhs >?f%ƸjMO 1) a{ؠE܏< FSԃKf%p72.[M M>c=a"2cKKe4OȰ*3pLgb+5X ]]״#{Mή.l|,:Ѥ0'cy4NHϬ #Un:cpK/) > F sݍb$Ivo] ?o$ꁛ :n=L4tоs?=IX1סܳ]w>;?p+O7UvۖU׎Gna"(j%sI0kBA[J^{+B酒BoӍ6YUNBz7+6Ь8|t⤄؈b&*`ܢ~iyXZ`Jt(=58 OLx]`1ZsepjeϪQR(Tw+2t+ToYm#+ e}xH=zCAonI0fkw;bibX \d9 | x6_Yݦ !q:ƃ8kC]e4iÁ`-G$#39rZxgD%yPzVl&)ƖzyLl*vq}$^uGT/o0DY3\R.]WyK;='ȭ,ϒ4^*Tlwpj.TqT`LbG -q7),`It FϺ昋&P %떹ma8nAI1n[x ZZa096^#!X#z̙yb á@rsGحZ 'A t@DɎܕ?$koK[.~A:痭N4tEt>@ZM!TP.Js<]I~@pKnxrplb NKuѿ:?"DvtA箻t`\Lڛvm׿[+.8N0- DV<܄>j7 # ԚvG?3. Wtkh9{;UJ#% SU/{z|QlgB8f!gZ.cegyz~#_BM@9T}HW3J3se'y<BSqBoe1==?[QOxxQFCJm2tW^œ+<ؕOl>"Ig.,-Z@ч!ܝnT%ENwnRVe_Z v1$-J@@[Tv.Gd-otK28͔˟X3gEhc7/˼hAM£+Lձet^TVR (~.ÌB:/00fR4G nr-~^A.I\7.IJ79[n:ۈR*peV·8|s \sϲۋ`1v`["=jwD ŋ&32 )0!^>tш{˂ȍ=.Qpgt8a' z\Yl QW9f ur-]_5TS8-s`2EZb}F4I\v6:X0`[[9;37ʐGŞb"*s;jϴm},DW(PkIb 9;'l_b8H|~f'Ԙ, i[1O莍-?MF:P/ gEl9B_0PIb I}vѾ^r66{oITqdwGژ⎉:,3潹dP`ʏXKKn-r|2҂I2^x2xzԾN@ (+phJoYzv]x ;miUeR.%E>ov`sލZ\&v<γʱgoP0S&=of|Qɍ(0\txf,-/ ~Yw7d҈x'Geĥ̄95$ẅNogZ*YC*%|SUifbnD %_6Y BxT:c9R4n&^' $Hڈ'[K 'w>_PZuמ|vOiJ+M8H!#\R%ZUGItv&H}X,Obʜ6.9oUtmK1SKODuVFIX @A?4'CNDžmcX5|'y;1@?)f0dzM 5|O9 %-R 6 6clȅ)0A\lEL!%!qOM !s1K\8v{IN0ʭ8N86z#hi:=J( J7PfHx{">(>O#%8xEkn@! aH9c%UNĿ\.zIss-fQj Rc.\ ǝ?@q{\~E>0g(8F$m\#C$d qLZ׻qL$ 3ڷZߩ4 nP7\V'i%/X4‘~K\[O'd~xHQrUVÑ>o\k`W B~o}|)m!ȔXŃswŴ(jrs&3@cWZM亪]I ^ =bgs_W)Sl*ur}X{Xu3zsqܞ6}flQ c| Q@1cbc5 F!>PmfH)`/Nqԛ4/(|:d:V{Az5WLe{Bi_ AƜ*EjNu#pq ^Faw;N-ˆp a]@LO%:۲d9%@e,دt\aamo}k-rDǔ5HlD8 b)g7$h&ݬ`s174;i\eWH6'`Ѹ@lǠO(u7(\dđ,(u lg~_6 Π_; 㯡`uOpX B.ehSi[417`%ssd$<S4 5_(hũrs>+R?>+Vo_Wա}wZ7p=A6ʟA=ԡN21UғV>Iԓ޴Zħcq P)=k-D jf~TID3:yTqJNth8"k]71'QҨtcH^bx7*ٶQwN0d1TLa[)CUUAx`w; t<'q4eeeo'os#([AZT)9"Gbߥ_0qjmd`D9[#W6Ljz'@IOeXnY>cnz*Gn )(?J;X;+Rՙnُ~7e6EsGTr'}]X1y,.MYױ9Jp|U&/SiH_[`{YfzE-z`jޙD"u/J\k 9NdqU2&P%P,+7dq"["3z+\fEV/^ƌ\X"wl tUL1bl{bV'}/A^]T% a[ _iE08d#oabZ~ț;/jRʚfz9l|B H)E:7xASY.<6+!0Bb1EVqz@Theu5W mԭ>zqgͤ|1 $7m=?/eVՌOX&0|a";u9Q){20>C }80mhrIx%-A;V\Xh-8 {q[7̶{6QnPM7 K锱"TPWCu,) !5bԯܦ9k/(Ѫ y%7l/]JR]= H+/< }pIݝDкO$HJ| LPhK7Q[ 4R8IJ7 ݶt^)6RtbIJYj4 S$L]uf_gXfb80RTU< E( fRS$latdЉR[vY*q \nx V bۖ'|6U0D?t3M`m}0!zဉ"ߒU&rO8Y2±K;,hJ ,5{[ȢxᩖoU"GUjm~8(GFC ۉbtYd P֏^I譕QaKP)LMfܹř}/קzP'*y]IߐX Lj9`s=S(j-|\n3X e)k,VSML(>.A-yY}tJq)FX]ߔk:'baEI0aP{.v?h`D/Ϊg 2o|}L;):};yg#<DY& ɭ:M /&h~\"a+:_¸@FDfjeuixz(:qHO=.v2 ?Ch7 @./M{-e}xnAmPB#"=1Ř)5_ș` m=B" 2RΨRGz-@骣769W!;rx=/P? =Ev(dU%gO%A6uC5ȉ_9AT2ݨܩw! Sw?m8q:,eVT__NAEG-k* jIo+l2@i ;WֿτrRaӴ$WӹCi;M%,]aAS~KHu1ciiɕGSIqXnY +f[F-;ne[eK?tLs\DA;Z\ǿ*_^C*k88s3ꭃ&w(OU"a {y-bȖ`ĥg"#}6Xn5jE~ѓI-aŠ $/b15$Ɲu!Hdo<+Tm0նL0W6A88Jl_8g!`0-wxZé("ɍLm[3TU9S!扛ڒcw5q1&2̹c]b/0O0b##`lzkno)]N,e5Qx-hNM&jb mN g1|_Eԃ6R].7fvOd?_ڤ@YW | A^_bs)T×idBpCVx_1MTu ͌-w)uknd˿\eyn]ܴ:':.>OXQJ JKGV(YH':x$ CU{npVYDģݛ[a244^CI(bSc!|Q3yF~j%8")*JLÊgXdV81#}MޒyBrg 85ߚѴm_cn"YXA&xGtUǝLF#2͍~//. rʈ dqN"8 Sh09X,Ӕ匉IIM#BٖrB<Γ|N`Ea (PHW hoܱi UQ3/ %X"B_eS^݋B:v>4aiG6~\u<bYd7akցmy#NB|KD#ɉr zW!5Ѿeh @j nr FM]l0QKF*a{Ղ:E@129JI#]˜#(%sK3  mn)Bф9T6e'3j_Ab:A0T1NQ©k(i/oSZ?RnLyճP!zH΅A{uzP`c8c]^,cș 3~&Pa3r3e5i8wנIy J,t2˱AiL H)QO*~ELYT`w3N4G0d){_d=Fbo,"hN6g+T8EM 'UIV*]0c1`<,=*l 2ۍd~ ޏnwn- ﭺԟ"d$pTF0EЎu |+b&9hs`_Axb@Iy2ؽ4ay`#kY{/m`+GJ0eRFdA,3VL +>w#opdoh7E8׏LC,UnάŜXyR:ՌY*Њ5ڙ樿/eoawk'I6o$p]{wtqdoknYF[PhPN6˙6ZO.S;lZ%0 H0)} n'')+K8g9-_n^=3Rn`Wژ͞5NqpUR w"*$ZA֧$"| 7-U6<$,k9>CSTT&3KȝHnn?*u7dE0#1dg!zb4M2!Udvs#^)cW&ܩT. Xt#"i؄@ݨ7\RM4('Xv F#Id^u<=@cUg8Hl*ve'%MRin,qL\'09c)!,6셺eq 3Ԫ/o7at*"e!>>X,ے'y(bU]w6zIL`%QpiݪЈ*\H;M?Iv}8CȖg?xCͺI9oEv3sOy}вu~6r27k6-t]T;,h4Ϻ\${̵z!3q8_V a!Vsӭ妯B3 #C|kGAFpOKPߖb8Vkpz'$0 zW}%Z^2ߟU29r.#ọ́wYߋ(K1"zb's>S|S |ș6{fί%ƪzT+Hk""{TMZ7:+c±=r X-aƁ ,+1yrb&n|"<,O06G3x]۴6d$U=e-15ϴk7t{-L= lu">0j46Y/PrΏ5T5~ E[m]BI6HT K 2 BdN$Yvtl˅s͸{5]8t\ޤ!P@H M5=0d}אyrimqa)h,l<αes.|9UشD^uyz?C VjBbO*%RaJ]>ӖYR2ۘ;B8Z`#Iwfǜ`Q[/Xgx Tp|Y'S97yh܍C9z-}Ut%dY Ɓ}LyMVU"a{ IN}ɲ;`f{c EpWSJ;=Rܶ*SJWe:@awˍ_F|%uaF'\fSZ;$oHQ<\1+Gx hHxh%N(Y>RCgѻ(gb3.MwvyK):_Y}UE4OWC )hȀK P{B[(>T MͭR$0 j[7WU沢{ϽMA@G>!MW {qRb'?ĹҌPc Hd/KA1P Y-ApC-sTTfɜU 7R R꼎1>8qE{F+SCyۥ3O,L]z#5^cK kL*ЬkqH ۵02/u5=1j fK{g=p$_ |*)׾U}ˤ*wfW-;?DžG5 <2JQeg +)CV?!:'n 6Pe!q~t]s:|W,,ra/Eۃ.M>Bw@!۔ )yZdȼ>GEѧy4g_rbw=ӳ%%-ogy=`M+C;!PP!`rKq^^pצG>qpq325Cz}P]F2$wɑ4E8kI,Z_΢9jr[W6Mk8b𓱣(=I_-SpqF1"C6ExnLZt;?_k:ۉRX3ctvpR0N9<.J9XM>dʈufI;$%o# ȱv]1N;C?FZz8a=zM*!Ra5KĸvΌIʹO'KKת vffz7I^Thg}AcH<Dk6S(,0ukYڲpFrߢ+5R MY{/.i3bOQS#{TEbOBI^Ϛ' sqL0ǖgD?OI',K>`] jPQvk#.3CcE0#hWPJ{JfDxT׾8 xA DuH m&&{.4^*\N9AG055:"VDK,iA˷i 2R{Nx>8ҝ{kRX,fz.]1+\2M+'W&Lb~2j=5mS!z@-lMa{>OFoBu_lS1tDkҏBVERF }H`աѬK6.A ރiScbl0c^x/d=Rsiv8/Nk P x=S(gZ{t%oNhۅϳ.&u_-PPU`L^K8e!z4'.%9xf%+ه}w}uW$Cܰ2}*RٓCo?}lT9?vLVeG8؏Be?ϪށQ޷#Z0Fzة>;|NۚNnXc #y鰵Ɨoz; "?-i 7Rc,n~#7gL ޖ˿YwN1HI*W}+Vu1p f¯k?8!YY3~t @zV;hm̈3Yo>eM~t;eyRN&{/`p+( -#u@hz { Ht冔Qlv$FyЫ8:~=8rAQٝcֹ%nV=Eral!xY'rN) ~Բ+Y[ q;/)3#72Xk_n[&S&"qM#XṏoM[_Vc0SK>yC<7(ޛmuw7UL@"FhV51HO=,?Yj<)Ԓl/Ϻ!yw.CTHyqXbEԪaH= ;.6.V̙[k)!:~+&1W^88w^X,C__tE_S>řytu2wKdv׿K#sZ$m"?ѮsP#tRCu~5j!"C@RrݾZ5TFB8BymHw皂{iYW)o|*Yp[%\@Uȍl)ݭSvtl^W?W_lZ6㮻bxxʒ'?& Dt^}ؐ%!|MVCpTǕYf>AB%w?G, ʒQń3ev7| M+?4yoDC-f=cJLvP ֊%fԭI2?Ǥ:9M>qe2,RE-[W*LA Jo]25xmp@;L0 _V^Ƨ]~#E!88.zoh֕j/jUo=.Hy'֛U:5 Ԛe;(cô)Y|gLv7W3է9܏Nӝ[PᾕL1Kz(b}&<X78MC=EV9M'ck4U?\=~ɐ2 Me@bܐ<{˒6T:WKJ.C?Ȑ%'XQ(n f6V8cPA=XsܛX0+0a*@)}wӢJk"mz{P#"HSe6LK}:AhCW*2 &zcTIM)tL XEE^`nS]) QE!#K9DVXCrSTNCQ&ݱ` L:RMeuz^[l!Sߠa EbzJeyr<J||r)F4TX:}=6ߝWbܶ9P $Z~_)^`nBKT~<~x[btQ*,=/<#Rj~_Ry{@zAghry-pЬ0I C?nWN&{XYxd@PZlu< x/ьvFDOsKaGSPAţ."r _. ϐJaDlhCAqڞTu=1.5tKS\cz%NK#'Drfc|\ed1ކmRf9}hOUň@p5CNlW 'l-+P:F)-(Y(Χ%ġ랼оz'Dnbsj#%`K]Aljg nnu|?пuk%@D^}-8,"SɕqG.OYf%DRX#ʁ2x19{ XAIѕEqlB֙ 6>~_f{A=%j {2G_QK̚s\|+rɠrN)+b怫@JS%VĆH+tsFtu@.\ MKng''mMfonÔqI<ó?'-j*k5 %RD>j)iȾk)͉Ŏ6p+D݃D'ePgj LK\#نe06{[t ;> HiCj-3GNռftLfߊI{TmdQtItszwfROaMCW:į\Ts9eyIzζ+H/D'CBֳ}%X}R_LMeP) ts^tu(e!@d^.LrN?d^KUH7Uu<0v 81 N!g_*e<1lVnBT(8_I%Θ?u% -mӾ d*4V?Ucbo, DsjUWqY$-)'2 OtAUie :R̿U8C$i8K܍{;?YŨ,#ڠjxa'[W߈ ZGs92Z9<Ǯ ڀL9wi?٩mrX©<ׂ7]7wYCL5V68y,+W'x@uqΩ>IpZi/O"F5"bQfSNP$`S 1hv1 M޹#nWpBYL]DŽZg=YJPr$̴@nQv*%>Xq aM c(O:IOxPM'3_e. Y ȷoFƹ*˰v>W:>0VnfaVڦ5dag*u;,2Q^pϫoc\]S[4]^Hrkt(&BD5 ^mfp𞖜[mHOu*qy[7m\986QKI-;hYG"JSP&:QYk@p$$1 L1<26Qz ?;3ʴ섀ᮧ2=FU(׵*MK˩uBddob?6`J2"?=>g֊hD{t00'92A#Jj'l}Ca][x;ߔgIb̑ r40j[0CA]IʯP'yHA"I}sWN֢_x͂i=ٌU2J;ο7N T-U] |TݹwbDD:[uab=oTŸ&d+xI0qIUWw<9-Wd IqH~ ,׭$|6:sh8*T6k6'q6 &X!Vބ  z*؟X4"_Ga4 wLuK3y!w4MR9H150f ڡ׋1}Ī<)PIE{;bL, M!Y Grr}ͫO$D<I@ELL黙$8\oZe94=*'_,2gAOC'O47:NASw)͆QRxachoF#F`Vj); IaFγHR] C_d[O`bedt>&jGBr/#&&yŹ\02}T{ 7EU?/ QC5#gG v t}[\-+K8A+ + fx-\ad uAN9ǫO;2iX !l",' n-YZMnT$֋u#Lo|?"q{-!p 1ʎ|hY#.^A q7~7[MI6|(^Odzƭo9-i`4شϰ,};{V*c 51dkYZ@Qs 8r@ICnT\("_pʊg\΢w!\hWQ7rw~[ lqџ9/(}QʡxAt*@}o ;&@JY^OJ)'-odvXٚ/6I c3+%r4+O;8ЯU;Rp 蟰ܥ`DP[1Q q5Qt7EfF:bj|̖޶/JBN`C9Ēw =y!4n>D]yUJ!sOtjmъtcSr%XZ;ϋy" e̾}^:PE#EWJSeD\MDyK*5sSe0 -, ĻQ;kA 6-"B A͏qDhao|Zld밬y\s~:ʾ߷r]1۾_M9};1F:ZMr+!9xBK=<Y\{cNW~]¨ap>믱h(YܐU:-n5ς˶<qͳ3%Ӝۅo#Q&ly%"~+sBmy0#0ԒLkU7o.AB>+$E!|fA3FIxk] =eK}fQ-ZtYoUyf(۪<[3ISHUDžn)4Y헡GFݮƋ蘌Ą~'tܤaQx|S.U1cYX3_qo90#= c l di,͈m3^"㩃[ꐈ06/Ў=*]Bl y7 Xl`4 &i0e mݭ%e;?a׭y+&``Jޢhtķ|RY7xnǙCړxa8 ]TEgO!7E.Wf]A\Yи]yY~Nj +us3rIIDcwu<䖌(E%7NkdWtYe/ wįp*+V/}b"' R=AWտC(&QQH܌&u-,hAl

 :e\K^Z"}r- wmKZIvh|^/P_DɴU[JpMQ?Ly=_\=BJ ~PIc<^|8`ka^(Ҁny~9䵟jkZXbZ&#eS!4 T./w|c>1 `9<X 6/C9\Q~>zfHX%4oFHʰH.A+ܕ3U)mg#j8zMZSkS1z />y v;@S#w!/4nq?\3>ap|Xæ&M<4tAB,™JJ|+Mܻ}v ([Dd@V;V^GS<9Og i R2V<.Ln; Bc-žPv>//1GkV3*DiÀ>ɇ Udfxc:l䭘:0ZTe*53*Q,&~sڒm )' E+۰޻X\-JxD)鯱|hv04oyZj.#iZUHPCj?=ͰGq7(I5-m31B(׏!+}T V?~7ex3 E4]ALN-+2ήNF"~"s<>yM!ʉT ѽBJ䰻TBkSQ) sewڍ5 Y4_&cQMB"UD[@4= PӔM&"13t)%+ߩSU+9O¨1IcÍw8eu%5}.ZֆH~*<3 K17hqa  l;7Z\I~j.HWo TN(m}uF7k{H7ŏ_ -lG7fA6>J]|LOB6P>\*+H4;yzЗ"exպL|rT`˕$BݰpR6@C=toGNqp{1z5f[2d5aVk6`Ʋdwy!}(DZ·X賑ʹmKʹ?|Oއw9:e{><p@%8L 3ߐ4ƴo]ޘ*0~[b$ohI Ozrtr =3]6>a JZlEC B_Eo&L)$2i"+-q&3ʆ.V\yfO ֠s~t7_ ?OBvCxKZzcUY:F2t1AF=Xk} ~"S!6A?'X`oe4L``vU#E"1 >*ÿǛ>Z _Q$~:s䩜{~Yyb%*cJ֡7r3ځ{s˧mQ߷S7r,r4 $|560rCSZ-h4|s@+?^%ux0^A-J̛c|&5б'm!4 +AhV1vJr'{H8Ijۭ Y&8?@CPFu$ MaӠ{-F;a\!mAj޺s=Ғ;{gkBr؋RK)8"ĵS׏Sӟ YfgvY$;84R,:s)Zb]nqAo.lzj Pt  ٓuz;\KY8-1;HC[-f"#\5` 㴞 Z" $v7lrUdiExsK FѺ,F}1"4jENptPEB{kqsH"/?TvTť~lŕ7AWı-U0[^x)9ǕA7aO%=$$cx}w12Zo1k#)tbap*l5b*{{c +LE3V$XHwN;r9/ _`M|e"b 1nq6h?<4#g#B)j`=Sy#u1'Er$ZJ}M fON^b/5FGh'@'"+A{sW񇗛7']χPe(U p&doVrJjT%LlizɿǏͳs0^t};wh8kn4'#6'x*2R8oҼK|-AN(Eܘ2㚞Q!C?d({t&6ٶ1벏*r@ 1:bQ\YEK 7bD؁ uiKxa:h9`S5e$0 !EhQց2# B n851cx)ۅ[IK$>Cd 8c]O nXRcxD !~JŬLce &_4R 51KCg2:bB#RIw#<]#~uf \BW˅RtV8zs|0Dk].T0ò @!{iqhmZ sslCi% 8W"85ᑾX|:GN|cp;L'oHCB]OGr0IHG\78 DQhlx NĮP>"W 1cXP'`ڡ_抇&X|\ h'1gVp뗹Q]T1m m(J2aE0;DӕmW)2Xo SDW1|\^(%- "d{Ptt@(>ßTvFM5}K>48ܤyju4g(%C5`w7iV j wۻ"f˛TUۡkG~M;-E=죘Sr\"NxA uC_lrz}F2 VJ4Զi7pwԢ$ḾҟAϝ[X{-& #4q\e$=6ǁEH#D RxK ZOMdl+2gv + E@)-q4CsOGەwSR;(" K˖ ΍U'h6Jopl"ퟣ# HxΤY<1V7DXdC"\)w`9)>f$]h2K"pIk|[r0jby$rmz$ȵӜF㊓DTiEn8e cn6[h92kdj|CHSl=_:/ٻLG΁d]?Ӂ$WS .~Gmťq?O StcU9=JT*metuQмjrMv (6@ JQN8N9p ,eѦ^KK=F8fx2}Q'zTx;ɂ4o7ai㳿 n7A~ qc;>n3XYI$i%}Ld֕;d=^NEnr5sb\R5@,Y (0"6e #JZzx߲k9!PʸMEE7/46v.w= |"V:{@OTy?1+I(^ = nBsaRtҡAs GXL'%j%tS57m9Jh6JuʱAkL qSjJԋZ*ޚY-1m@^w#1/ Y<ŹNŷ`^[.zt&cEs鵮_qD7|{rUoxB\ {-rp w{oc`VWFrB]ѡȂdS`@ 저EnF# 9 W ZCjvx"uFO5r_>rX& 'v_W VC{"L[8^Z7Mibr7P\kt CɴCP7.R;#M/BBx~/B t9NK< O;>*[;ѩ|њ*;f"܃G6ztΓv; *Q]C,Qa.RIN:6r NkӺj$'ُZz,6cj=u&.UnYyx_QDh76B<,ۧ%>kh::r{P_e|SJa"^#dL;9 ɥ_ok>$u8.hT ;-NP:BC\ = m &n@$>njB}6Ul /3ZوskDMt*nW 4 @c¾ pߴ )J,R&[LWil5wT,>nK׳Ы*Z tI8*08;AE;E;} ScÞXpWo{-J𕲢RIaqc4 +[?H.&sO RY`p4n֝?G!7"[Eܾ3/7b6ڀi󸢒JDi5+ͥ5^֢} E <Ӌ}@܉Mh9 $8x eKo莵ZۦzƛΒ'@(T!Q=JR_722=mNInG!yla?Ok9=Ɗ7GlKđNǝ#]뙼@zzK iP r,&G~aE.5;YkGUmDx\GZsUFAO/D>Y,\fQD#: 1Y = +g-n>+"^Vƍ5uAiF9-UXJ3 *wԝ -oǨd1Zo sРhMP/ 5<[ZoQI|k1H\N# $˙4j^V᥼gJ'g>' - g(:H;io\IuMQc%kӦ봠9bkE,łUx7gX .0F-gx-op4S v$ņ&F|3LwON9 `B{tоo\B`1Hm M1R&W.vbAap *n=g-/=yU>iI(6pdq b\K7Hҭ&&cYf# :526k2j߷-1pDKmpɁty:2P$SRx^%,tL/ͥ/=]-[f~}?YazGNZiV"6Zѥ&9 QFiWrrخp-:cm)&^'SnyDCsiFrEFAM+ h15u C!I\Q<0U$ 7М [RUj,6҅WLR#sǫtAGssp1Z'Q@>-̜q,&1~-k w_C= Xqʔ8U:[x q ʜS ߞ iLd7 flM/I84A"mYc̄>1"=AuOGEs-$e果[t`w 䨧7Y*c m~sI6p2?K"d'Ճڰ=V׵3't;3b?%Dʠl$pa 4ʲ)5Qͥ&I!#}ޮ}iF጑f4@0JӚꤶ̪+#ڽ]9Nc8Xq-p_k(e"a4?C_pW"VKϺ|;*Nw,(dh$/EY l> Y|37 Q?%R^ u(;Y<%L<|- ɛzs#b sfÆ`'{Vɭ@ۯf1eBX/eimn)Tˇ#^ff/˚c j'Lz䒤k@_7;pmblPɱnс3z/4"ȹn| ORhCTFy9G1ksj@mUia7tAfm?}@ߋ"Ɨ]xlR3h/ (EϽޕS5:ҥMTqk j~ OO &>}ݖ\24DXC 6v'XPN.'c_Ec 2F蘄\O^߹.ol1L auqI`e&*ք|12!ݽ~16EDRL,~]I0>! &`#Rj>8GfbsHUc&twF0^w_ +4m{dLWʝK~U"@8&%"]XC<46läs E(W`eAY;W{v\V*QDKg!.Q#}"U9 UBlYoD"a6z;!y15+l:*e^r+GǮȑRqͺo|RUl_ذ (]=b;Ȭ7(ma͍z[mC@cѕ?0*:hjbGD d 'x~eCl͋DUmӘ\q-*ڋzYA;S!&&  ]32Y}ǁiz#gJRV;d孽Zjk}}̜bD.|#50.w+t2+#侢La'Yy1(YF 8lB\gh唊 g!Ͼ*X"ҪZezIZR Tx`rF4w#I]3lx}t(߅EͬZze9cJ{cMę cK 2 'ӬYoaZ ߀j}jh=-JGLDSRG ΌWEZ>1r=H}ьJDZ5>V * m+twhц㟆 _jG/> qzPzunі: u*i˞02Xt_I#0Z _aƤHK UՌID/ {͊"_f tڀ,1:AuE^,}FQ-y]lKΙQ׿Lp< K&Dt?Υ6DP~ w,/"gYCo+xك]KӃ Ɣe269N[v,jL0A/ b##f(a-PzfEDcx&HEKFEtd_%PCR{1'z?ܺWW͵ј lAZ{PL*;Z--_9atflj/m6ziɘ%$ON)PgJ r223BxK#|#-h?(ߦ/:1h cuITJb鎌"MZ@h\-n,"=ݯpȖƁ}lԧ'gڪ*c"|6rS|fP{;$X'lCB]wxi 4aӉ$K#/cj~UʅPVrMw 1R¼r 5O"^ } k%'3p< tQEuTwX)I&˅I ] AJC!o+=RndP<׼4$o}i}k6q=ID}l!f`݊- cgKQZ4X3|Kz.u]W ]kc$NAQ'+1OzC"Q8l]tG2|ǚh :]ahsOH1<[Lci#)=nPR B Ol|ۃ+*ɰW7"%jOGFJR!$aqg6?h~̶ #qQ1c~hZ=GR2Ea:z09JwL{AHt]/H?U1cP,N J/ŶJ/ NJdYEc"erb4#κ3IHW9<ɳp*1QYrIϳGi%&Q]";cN3c_?2GVM"tnYM"x oqE$`U]ƒlI tn7Dw!G+-(yl=',ӨJ&'wYYsVHY'O%ssG%,<Է'r]<{ߢ92,y5Dm'@(,i5c5ޟ(B|-OEKG:҇EJ=-8R(NZ4D*m@.7(yg(4KX 8/Kh$*RkPgInM6f%-݂>ZSHn^RU z 7Y )0x* nH1MubUO$#*Bڋ7,Owʕ5%[t&PL4C 'K|kzk.]`LznEHwg-Cd{ڻfwHUM.;8-dtVF"+BM氳Nwo—9{>0~zBǓ4P~na X ~02 7џA3NãyΣ248oDffǞ]UH*ө42eHw2Y6^gnaef9y^>]Jk!/ {['eht#BFo ɜPnT+_~RUIPq:xnA&>VqhxU+QNײ@YlTzMY 8xNcvP70DZG`>+JOޓ$bڈM4(кmh>ۏQԲ&tJ˜cbMh:2i.)"hʊz-3TӍ7Bfx_)™YS8M t4>&b \D}Op}1 'ixgfXi_ngiE]Б86~Y=r  I?~%Da; *0A' >p>|ik7Q|F6"뾅Y\]$7)/F D}O ]q#D?꛿ wpu m_DdT֫bV,ٍgXs+Jnڽqߔ-(03[וMvd@hVQKz~96;Igd`B.{ OXv@9&J LqA<*[0R'˚[#HK3M x71;;:DtC4Nj[)H"dcIm?^K{M& YMD~v`uE~XHjL,98a[[sa斨Lr:g^f_ ;fIӘlΦ_^٢:|eyP&2CF$qsY30[k=W^0(";(R5ܜ﷜fR<\BK.R&v=eC?7~2HcxDѨ&v{m-㘶e;\O~y"r0%I뀧i廒*\/fomdWT?(9Ƣ8cT-vC,_f8{V,w>eJ"vOoTS)&'KL e6 I9FW ߐ3\hB./#J~P@a9)`eQe\仙h@e 9;K0rXwp!CZޟߋcZcם1FjqCUW2%&^z"+j jlufbǢ:N)BTB܆$am;r?岟3L큧Y-t qDØgt"q]( $έ34x”8 `-ʿ/fTإ͟7$`}m$^^։:pPM){i1>'i6I3 q+XWK̇S4AUx_ȵwˁ >'(kP#pL oyk8}}{K7 66ȑDdgl8<:)M2KB֗^VO+IG(x,(ކy8ЛW,:\ ZwKfR;I S`۽! B+/;gY>"zE$͠ av4h2Z-1M^+XlMZx_Y~Ch c!F '4Dϫ:MQDsg"}9 ;~ D,c(4;bȵ:zɇڸޑN\0M0-UwC[N^ @?&0ٍXJ/rL0FƉpI+LJ%I@6kL-<f~ !'C &|ء{feQeGw+nA|%+VE%Mc#ftI->l3Fwbyҳ_yͱK'ztV#L$BZKAF$O1ek +jJh`]B1<<ѷ 3Bu[x}R MYϦܪ`X ;1={`1xvK/ xkzx9짐[)eɔM(8qYq u_5s-L#9|foB 7q.Ua mFȌozJ8 ǜ"Po<_j em$cd\tv>It4?o,]}TFe="kB5}w5^Nw]\G^9N)JG>l1B3W\kB pz;>i dNvTٕZNEMC;1 |9~.H &[ ۸Z*%ޑKK"WF+]Q F.'] {rڕiQ"<_3ElʯS7Ž5#_[~N D ͆DXgN{g՚αJSq%]#Nh4ܚeL ,25|_zDB}VB,-E l-]!L=Cr TGPӺB> /VrPEcP:t.46Zv"h9S:2>F]!' _4Z(E{{e*>_\,GMc$&~!}Q-Ү`]!wba\?zǹkG!@3S߄:q.~Sܤ56SqHg\LTMQ}׃L?Sz{h$U so ޕRcbU:v-Z6X{jnIU`Kxtpx@Ɏs.y{t'dYAۈo4O,ݷ3;|l'5J\;CToϽ"c9|$'&<RPǎ3# drkbQC“WO0J8لfuo}ϴ"se?TTfJ__1FhE^ uW1E&2o>?{@ i5XH|S]҂حpJKv!Pھy=6հ |j-MtE>H<纈<>o;]G_h"@x4l/ܓO C/K%NWi[\k0x=ٜrXoa k}]D1-?7#AkxE)#XCwGH:$Ss@M~KͿ2`~xbsK:XsUoJj~r(At$քGq$z(CӾdRhB+iLwp[,N*_dqG]@U 5,#0gt.#t#/X|W@1A6QƞabDnT%':Odk?1Ӭ^miXb5L:9`k X %8ޗ.`)m\K2+'2?$w!O{g .FDn}ov]rO-G ok_W.ر^pߢ+U+[+7P$߶mdܧCl۶X_dЉ)ZA=xt{p\oH6Uo9 {z$I,Jqiq-,m7xKJ9 ^AI/.5}Aۛ?g) o9deý1娵MO)$/Do;:0z9aSeL"W*_ L𑞣 ABJw aW.S Q;IûR8[^ÊY`2cM6=K !1Y/Ź3<\ 3=7SYh<.G6$gPUY':$ΗPGj\|4=Nd*k!q_f0D[omYk+y2Af |ǟ1' CJxj$P,+JOv:@wxgY>&/m{!=fH%xyKFIK4%U k,i<9B/!c6g(+xeI; z]_z u@\+ ӓ\l. ‰E\BoSU) u2@'Q@ugp1G0JPnJ6[zE]VOaϯeG)aY [ [Dz?A~; Se}z$C){lWTYA:S]cy8Oշt}.4hQG/8 rj!Jeջ=E(tua}s0va>jjNi(e]TP)޻~:C׸^VYVE6۔"Ed}߯.r6\JmB!cI1kc,f(߅}dJP\o05C}NeZ3' ! )@;ގ4%Dl/5;ZδW3u`dxxg6cY +nn`PnMw$|\aO['{Ivo$y|h~4L ܐ\_"0;/ L;h6>9? ь[EAccx^\@ua6$E %c*"nEL22 Xp8&}$9MV c، Xcn}?2](KBTֿ_?-$=]Ky(,̾!4\gA>'>p8qdNDe)rPʉW44:{p0%nwJcxg!"džBZHt;G#Z 34.Dtovx'YL=7P=&8ڴa,ol=sjq]Z)ldH=:A7 I噌?%T[QeZJRz˻6crkXo7O;YѢ0[c6xžq@wJbR~l(Lcfo`, 'MQjtܗٱsA2-n0'W ˏԀIאy8Ngvn1\ v_>_IARowCA\Ml0͓-:[6F5@aTy9_lxޮdu`b}A}$i$3 #'x!^RW=ڧ{VʟEJ옇Yς+ҎfWS]b^jY(2`\J&OHTe_=űji(`S얅6KdK+nW1Ř0ٌahMv=I:2CU{ݥ'wZtr>dW+25l-;Lw G}nŪU0Je ,"f^M!bt`>`!^h+^cӉV8}^ c1Uݘ]A!fϴD[9qV^#M8Dl|x2886(ɶK'q_ #K[]Ӟa`Srg)|R0%&+U|>84q5LJ8 D,"iTIuQ`[3}7t,]V\!?O3<(6t@Y"JWsQS>'.Ǔ+CqCTʉ$gLdv$Ol[mx̹8〓*(OMHuvoh%>K_[pZO$hwEH = źσt&:21k땷GVcU ?-É'aCc[<jSWJAtMj晿v`R-@caK冼 r9zazB8hj e 6eا.OFtGpqX{zu N|vԅ6FRh{{^Zon،="&c 34W+A7,D1Yy<G-4EW1.Lkig7wS%уw*#{yԯbV*8 lO a+}@YؕNd5^;rkxl5%*m|xAO[u"Ǐ@(eA8 %K5+_SȄiOĪ4bZBǂvJr*3sbZM.|amji`ݒR  *o\QhC4/`%$md2&>4KXھN8LC8$xk5C2>T Q۴,m8#' ӗ?EvWٱݲҔ= Nh)c bW8#1QʿxK!q,fe԰3<ײu݈]how_=\Ż@QVvrB8}3@? /\SI*keb;VҭI*p&rnёs̎VkcZbF]_sM/!n>).R3 +gJi?(-ЉLԤ؅}ۙfDˠ|E0@Pn$mxҏv֕f8O=0 ֽʾkحV8&taO#^=B+v)m>-%\s #%֫Q벩OV>MA}ep1K"るD,+ӄ֦t^^Cw3@ey --ih,k\ɻo2HqaZ xȏP!J*Эm=dyw 0Sy `DmmLhd, 6iւ-XA\Fd'x4,M\*+K S(CBki!NQxu{lغ b؃uuQwBaƶ%i٩lw&![7K[lV-#mX2#،D Wv} 았Bƿ!gn*TW%Y G>ufaO7k;j3l 5L~ >!L@ ފr:10[+EoxܣI b<}fs}t}Ӏ=G~dӡGF![@1ږ A.-#i*Q)TMKzMMJ4m5XY]ģ{ʚ%#JJJg +@u:hm^U5 ܟfK_t/tֽf ^Dݳ*Y' %U:k;ޑJ,-CN;÷%A ˝;IJXG&)`%oTEW;?:џR'*0gE&g;w;. ʋsbVUZl^1u٣-!G\]qKdpZHdMK`ZQTcJ"?38q97ws{f }0-W 8'O{sdVWDRORəlbΪ ѠOa1ĿeɡBt!S,ɫ&o#ʜu'K[DdC{Qgk(~V} bXJ54ζi.5)xB*YŎ-<TǀImohM>=|l @Wʈ8,<|[4$<7 |q%XW2Cpi*gk99X asKJVC!5e-0a t*rR~r^1 f mSC||~ҙbҁJa!#,yxz&H޳Z槪Hֱa=Mm%q}9ygS06g齣bW g#dsv8YкhJ!Gx_v$(PayBɬLm?$_1 ލn &}]9CpCsOkNf#(q4? c=Vï{iJ4y+ײ,PIr+p|pɤUo0~ja>JP"uB W(I=!7!j\>!I- {Sd*DH"+}QF_c%Eq =Բ*/*RcdM8vlnc|8<~^@G]+|ZD|;U6 $3^ρ-Uz%w"Oy 45k<;pޯ9R XzōnL Et.1xДզV5u=4*`/ĞkK4%7r M:n"P]70TlЊ@%A]R[}u\{#Cjgt"(OP/?F9F&@z2,''aZ [C=pW 3V6D<>ɿq#^$\gA~syWoǵ :} hdy>oRّ.-H 0p`YC&e2.[0Eu+e# ܅@8MɝAN?CNvGpJ%@}o.TYfs@UJ_$?s~Q]x fQ$9wNi`0aٺ,Jgf.!GFʲ1`.7]Y|M^w|֢Cv<h,$ .yO<GwhZWKR$2i3P`=vHCT#K&N,[@ni'S]4]D `*b8Yo2THWF}U)tHau+`+$`S$-ƥ?ť ˏBA"4l QԠvŃPH }9-J-auxqUl?UN a =AV;(`bV.G8Eǻt:VߎVߢBiEsAP߶P f rۧVh}x EUoLњA %sFq<߉yE=cBFՀӪ(l#,[Sw[|_>jQhd3^=suMI{ş9ud4`5RG.G(8 @<7]NsMPyC3d.0j~zmC m (Pf^Nzv#xOh3|auky.#*2q|K5ZJ\(&*s ෂ=`e>od ?[mэI.> я>!@7'dk; ֱ׏t R'L_le^<.܆Lhg&]ڹĚCemvmDҽ2ָ~ < N K}cu 1qҸ0_l5 ZXcv0&fPp],S1GBԲ:4OK*E>v0K =02댡I)f]d" Tzi1UhmT/:-vw |z9Rh/s%@ʺZ#)@r`pME:OjV("I)|NoR6, ټn]L=M/Pfqvagq>?vwĸN0˭[5_ǃ^~3$tg ^&Zi`}U ǮX@!`ɧ#UER_ fUls2ʭgr]Wzpv }96}doM&z+y釨2<;|w;5u|XB13 oS+Mr h7)`@Y&m"^. %;VQmT?՝^aT6\-,̥l'4##J+ғI) p5Qne'/-EdXԕ|Ay/g@tv PhY.p?6ME2o1,Lto*̹ӣ̱T07<gOq2x(Wz|=t;ZBk߽ғzRZK4 @\nuça>l-6SYA< u@aY42G42Dwh7,B(C2q7l_d4*UT5TNbi {p4p,5_M[@Ly2t6^o73̥;x/yx!P(ozG"+,K9(ܣ /ަҹ$5}a`Ljc^zۂ+p$#Q~D`s |ϐ^6:4W#`sN] NZ1_(ck,hW4UY>ou}H=!py,ͳ}2Mi2H\ZfbUjP0׌Qg? w,ę.pʬ!45 {`Zȵ6/ Dvly9cަ9Ũg~.@|,_=8Qc:F/^ 3@J?SS֬5 Y6a[}#nY%hR`I5| dkҗ[šU}mh d{5+9R-0Pa2Uy(ռZ.Cqgǧk),R0#]Də*K'En,Ak:I&px*PpjǙiG_lTe 9(V?,Od 67 E"$?dWMY]9`3'LQ+e-G",sQo5 >&"- E@'Ť⒐Q{T#mx@?KPSsoT@C7-߁ EaoT̲KD -x1QfuB`t{d\,,&DLխ5pɓkQ-QY "T!=xgD\|Tl#Y*=ć*居HtkTmXtyOc$iDĨqiwC)~E?S &VIQLڝBҹ/3;e]WN1<DX6: ?ӻ -1%N6vl[R ԩI!5~zM&t2 8m_&`{<<($~#h?sxXXotآ=7BjaA-:aSpٌ4Rcׇ3 hCwId opd?Y?Th !õD>3>&R ҘS*~ze#.b-~e\qxK ̹Fp̍m3>){c|PJh`ӏiĪS{yHh{,`"s8Ӵx8ab^ݐ{e3tZ\@q2+N‡(sM J߁2Pe: *ܰcm֧yvhvvϘ@x 5륑47tc2 z|@w-2\!;rX6!\)`7 NlDf * $aSDϯ,8Jq!5TD%Ʋv>j|B҆~ߘ^H^B!KXqm> +;iSGaS8/H9&5(B~tW0Yx Anbn=n>ĈQf$+ϖc69x b2z$/VkƍJ,DmGo+IH&XI$Z gAh:9]uݳh3/ oJ$ZdDdDe!ugFNo|M&óAjߤHaIMرQ8Ase $gM?euxK]U(U1?ᠴ=vh΂NJ(xnĤ+TRJJO=Lg`aRŁĺﺪi=)&$Lem`.!3' W kUCwoAX죔yu^@qV&zoCA]ju9uT,|u?BvlT@&@U^'nB>AUc+"=%1U { B4#;AVBu)%fp 'xr0<=9ߔt Y]{հMđ|nvR$ߑBnz4F铔fNp?j5QdOS$ZO2TpY[=`ƜPas*'{IqRCҠ0.Fko" W͔>0Zws\F=)p@M`h*.?;.R`yEQ z 4D(1svd 8y}0S9 y g_|ȪU&&{2')CRr 8=n^ԑG=-j=';!]oc|zjNƩCط^>wÊ.v2te~(;17gq9j`G3@6v =]Lt7eNh(~]K[KJ:~<-bC|6b>`X=gH[uQ&-qg3t5{¯2!뙅 t&xl*5bMMit\ "`*eIϺJ˘#LEoH*L$^2nђIYy53ŁmZ tbtS$?(8Ͽ v_H߹-mR4;^fXWa 9؝F8B!룜kLrz%Yq , T'Ÿ|3?kKU1G8ҫoK,3Xaj29r].9"Qߎ1eQx oÙwf7$?, P,PΨ @5]CYUf7$pHK :3{&3>Ts=+~Bȵeo" woX=l^/+85Q$ E "R q?3]0myц% y-peYesll{|O =&Pd(Voe#15|yxd YFvMY ܣ(XU&lɃ/o<̽Fp[sx3`asЗ>zSāWwtk߆Kխ"Y >Ҝ ^ tvRVjJڵ=2M fGGD4Jv]>D%X &XOiYeΩX);Εfot1ʈFEԙ]\KH[Bmr(jQDa &_[A{' <2qu㻌5 S3pM$. ]CvP] jV/!.~#tĔ\b>D+'5*1}+TIhɲGx fsB~ryc=7M2{n e^9Te7 lSꇪ"O0 C@cKjHC>Re!>aB<{*$X066Ҵ-6E;nEVKXyG*B)}/y!넏D}.f@Ӵ rUf>YVdz5^u e3q/suZ1Q%Y#CgTKG%~=>!u23z&yx'G^TA䵅ߠ:SWV1ךέ+67}G Sm>Ʉ& Npx({hW7["]U25[bk&BpS|^v=vu1yle&zJg4W?}pIv>E[<o˩ޞ =f8>܀9UhKh3w%ruDLaYTO0PIfU$SBUp͠_2=y[5ɪ6^L WșonJP" ɱ٩D1t:J)) ɎƸ:Z-LD(ԌIx{ט%ۉpq?'^wV>w(}7\̈́@zi/lz~LbĞ\b߸Z`ZBArnlVQkJ1B q"Щ4- 5?>ZА| A(1ڽn) 0]#CL0wEKV8ߝu/HN~'*sѯqٝוּ}(sט%⨋Fc>Q6t15丼Z~ץ..8a){cuûWo3F/ npY(?2oY+ۚ/ʕhm~樓rF0DQ*՟[T*X% XJݻatͭF~Y c5;Kglj8 傳3=8s*@ v,wJ9Rf3ȳI? hl>E%jf_2jqy-\ersR++X><8A:3Jѹ2S#V'^~5)J!imwZi"pYV8^?S*G"{]̒k:.+.#:wu_3ݯH!8[n('{ ӛKk24PmyJ(I6!,wva%eӺqںc"Fbۊa#EG\r9^˃,O_ɴwE ϋQIد3 ($t DH/'lp"hoɍO\hj I֓P3swƈM R$<APFщݖvo8zAyo2p\Mh'p-&Qu_Ͷ!"qA!q*9]*\;1yYAbIN.=?Θ>PsW`aa%IZ?}4s?T}n?Ȫ%V6m;|俚 a4q=Mј^oNՔoJqzh]o1rJC܃锗Xf6vGz4Qaq5,!ݮchG$Q)0?\Mҋ|eoW,4$A*82X~p5&Q® ^j7=+9&5Z6@? x~ոzˌ-qA%tsh(0:=֥*?oN֓Ar:r|ȰMg[' ՁG5TYa3$E'#GC{ To?dO [5Z)/ݴ6uJ၆xa}U&`oLjtfȜ+#/!B~-˅"wu)L,g$zi%2z37\jLU㓙 gz(`wEN1a^՝36kWOmQ70Fΰ`-߯p\fbɔyU^hW]O;$]ׂij)kT# Ƭ=5_5`Sikq;QG.ls4Uoc̒Gm2Q~hxlR[\p>]9q觷- 27!oK7K3-p|P `)ol3d (D잡K]`w ~!96湉`'l^$2nsm&g076?҇xq ݶQ[T^-5W %GNO_w?X3cO4b՘A)2c6.[Ku%^ؒD1 ~4f,lSYW [+N ϻF=eLDs3ۦlaկnM)pDG)l=IJ(kkG  ƾd x88N~6OvO *lA 8dgMB3f\A44?RSI&*`.~C\,I}Ƙz7!*4Fb9S lٰ`vղ W&Vk6Km=+\$%u>3f_遌a꾓mj '6}Q\AYZFZzVDb՚ l|zf`?J5az$582JVs!ʡfʿ/wJ3/wEÚ ,\'z$M< A ֊ഠk(@*hȏ[k7L%EvUxuh쀹aLZ1ԣD>v?7T4}ۑjZ suװAl jʦ&EG&&r&.-nmLCćGJ X&6K~Wkz@ ϒYw]d]cLfU>9TMJJk^ֈ.QyGl;N %Am`ƪ><I|eO ]PoN \%d@@,Ta*{gʓ3ۋ<3vp:O%,k#y-넬h!J']`H²#`0+Q:n+y?]8'<[ x^6^4 y$T5A#um8(H~YEG7f^4ؚezS4ZapF[?y1)nG)WyuIMOmG^;cwwWDCeTB͝`$_2n._?wBF%/~Y`7ttI b,7p]U{ Ll?>+&cZYܬ "y kh9H(<5["DQkvjae8wƗsFf1 f h!u",F>(``2;a7CH_UyyVbjf,.ϭIjtς|Q E`2pǎPn p7T4RRua޻- %6̠جnUvw68PX]/@T I<^9OZZTsp6ĂndW}{UyM]båbby{AW|Nrq=FXR%r6aTތ,{V`ry|h*=OUXI'ۍ0TDr{lu Brk$خ<.nAuJ$ՉR!ӲP-|C`14LX1P\KwNoTo SGbzx.c6|&N!#3ơ¹ȋ Ik`-5-{,Kbۮ(=Iǀ6tL<bϿ1PY6B|gBskN ao1"Haֽ.6Mc$!QyU"xH3C0 ! 7u:&˲1 #-\'0q1_*_}O ž`|-TjMn*~B0XKNmo%_&#Á|}oa飼ZӟN_씠Klk""Z-y%Zv m~BSqs<\a@LU8404󳯑;ƙò&6tX%!n<Y]/B oH&:93cGYU4oFKȭyџV9h$YX5)"r89lĊ9j@w w wۏφJV*)UJ."novo:9#2!Α]|epSʠmO!Uo_2 '@siXa;n-i+}|;~Y8މarTF@| aQov`gBOZ_ $z^tP#C2>AH\&z]U3;* 6ԁ-Y/m_ȭKN^E8ֻ: J|9Eí63p\s81;!BSt1M9zXPabk5|$g'NP]EXCf+ dB-q+ ;(.gِ䴷d;)tї? 2W{~ 4wx'o~%`-5D,6@b ^*X aFB%bi#Lu k8.<CBV>-3Q8w6c>c>Tb?scP>x~"~ !nQPŷ\{YhHCʛH=Eqf36v#c UY hr,&}$1Bh%Gr@* #hpXZH-lDݱi`ǵ}Zۘ=ؠSfd0:Xezb}m.73kCCd=#/rv{jzVߧS {6A<'P{#;8{ehW|!w* !C;ۆ/Q٤K`s c{'yǝc*`C:E'G&&]ۙe;] = \cJOqdvۺWd%"YWruȾɖUl͵SכJ0Kк*!2`}ao,X{ NhQPH#﵈%ԙ ;=qiRpREJw߅N.[S 3޺d)؞k[KA<#խ~4qO[dap2kW5FŶnmِr0KAspq^WuCK8^%d} ӛkA֝m^U`m Tjm7l_=N3Tq`c˫˃dMz_HKQ=hIA uaLֻN}73xȎ=kCh5rtgVn<)h@;2f, x׭7 a5A KjaOm&a0MZPrFxsSΦQiD9i#ͣ)8m܈Dm|[Ϧ0NB)ܾDztrF}&,D } Ŏk̍rB/W1 FzTjT KC1qsH(e3 m [j z4}F"zENd;ظIAmU{#8SQ⟸D3ǃ TP#O&nO^SFUЌjͩ'$Ifs[kj /&)9ԣh}9/[u71WT>1C'ON9Kff[o8Us~RBw=Ϫ@W⊻$%+yjlsL WA]ApmWLF0ھνSb*"biaz6(RRi( a Z]#n Y]]MWY輎|'YxE4ӡ+h"EQFӈ>.VJnu$.MTOVÇ3!5',@(lo_9' (nSSJ<|X`қЩg;m(gdKuV흡( } ẹɟd/2BĶ/1 ʝ/ovݺ8)sluN}5(I+fTz_ پe^ $"RI7c+n:b=Ѯ%RO 1"HR,K^MFdqqy:Bՠ);;L{_zT-ͯex8:B=0+Ec7eDfk (&IVN9^5Wk91bf/{6jβWəo4kn3 'ٵAߋ<Ms`O[$v=:q9GYXJbHxv}R-|$D@>[C $/TTSw l3 Ǫ"l5z`Nd>z,a;wmnR|ȗn8}7V[ޝX/誢S?uf^b5,ŗ^!TtIС7r8ʝ^ Ez jS;x7]@AJIR{ ` @H UpA"t\p0"\un Y6t#'ٵ(Y{vW&Ŭd(kP/ڲ^o?TS*81Q(e6AAY5Gw([7֒D_F-f7i+ʬ]W D$VfϦz֖>& Uj;d$ah gy%T ^p{}(U=~JJ)vFPgXu{EXȰoRu%uǢt!l?˝#$9[49SFOR.r0]{d-P\wZQ}oXdۅ= X\}sO°VZ8KqGWu<15DS밞H6"^-ԡ'GNn@|K L>9M`Fb;6ETzy&p4vX7>-^y\HCDbY :yxu{ߥjX cI.ƍm?XIܼfN >?r3rpv#q2HoJ>9GBZ;_Ô/ 1] ,mUyط]z2DXPA{JX A~ą j,Ė0mo0c4 ߥQG/X_Pgx6#yL΢^Vccn(^=q맖a &2&t.5n;K?hH x >(OWyÿ! Km C>Wc=b@DvSMtO:?DPY3Uѹ%9# M48ѼL%x@Ӛ+( N9ijT"pи3]a! 0*KdGxߊG~齋uc~0bfܫ8@q;ULh>M= Nx;U@ޅ%!z/XRo$bs*Lk3Fru"VaԝM^TXZP>u+&"ʰ> |oNLUP'(ξ#g‰11ϱ^T" h{Rc̸ٺGN] Sg]?xgaG5+2OaEڠIM>ևtK[4G{eL F鑔*sY/Q]/l\Q(S[zF8Z-&˓::BeL^ QC" x6d )cJ ٣}|`eU<%VcZTf:6pĈv3#DŽuf)DNzDFWqw? ϝRZMϱWh!Qxgn_ËPpqx"GDs+nßN/Y,pjFvNvÚ(2egŽsK wJvu?ɑ{~k}vߜr}v$!, 4в'=%a)M'=PoPu|@ 䓟 5IКm=C|ZZwk?™ Y_pJ!e&SҲD`;w/bڲ\M31ќZ(E>[eM@/;ja-5sx35y=@-',>P|m#D!swRc_Nz6[hHXu€RFK :w9ups?Z>Mbc A #ۛ!F_nGJ ISC^zŋƨDonAzjhX=-PE˥V9Wε.  !%8wi[_3ϋDK\q3@Q^R^Hj,T Nz'Hu-2!IZ K=Yˤ}T |g!h1QS +Ms]JVӓAk3I:@q|:pS#ŒNYu$ka/ǙEtී{b>X)+O;Q MˠC9<%{^s'_魭JUjpO|] :0OQ$heRW7k3."W)Ro2 Nアp4.>//(#tY%ii 8b^Jx4JG,טXXW0wtXS$.qE-Gx#T@2q2o@y4bZɭ@lLY!h'G_*oY#2۔S?]VeIDhQ]Xwm3C`]CbH1=.á9iYaWX*q ujӝA:bȚO=̀IoU](j]D۴?d\ok*[D8&ǫ?oBκ,lw{jep^73V./&e5Wx8a}1vQʛXHy{'`p>ev0kz,!mHM [4,w>vg9.흓7@~S|l(R|,5?;4. @ea"kʼ^s2'7X럿] )3^\9mb80fLE9%}e?B3J/t0EwZ:Ȝ.IwVG<3HF K*e*ipkNۭcdiؘKv T {߱%k}+ 9"R ۅcn%:C5 }ߟ-PB"*]>$<~(+yٜ+"Z! z(Ud,$6*52j?lN:dM)ߝHOAp5?OXzlT>.gsVywdp "GBH} L܅j˧x>q38[%aK}y7d!',(s 4+!_Z;`IdN^D]'g1 XIHS}WϏhxƈh–r/ȇӾ-($@(D2P Z[v75۲n=eگ!7Sc~hS3` 5杼"˹KwN:?HWoncVd][tBgWAؒ6>*yޒxAc~k{Jog$Ճ_!!Q]ȥJwCJtIo.dFjR*Ȇ-dbh,5y#|E,"3igO1oՕ/J{sc_(hLYj۩L9yk~)ǭLdwP̓ߢw &%:NHUbYfPUm[ad1YfřQlR*QZF{PuZnJʁ)P 2=~l$U&;lFw9G HK_4Sy%r}ͦx!оc$VYqOф FT58D[B%l6nS򝾹yyAs@"w2^a^jC mR^pDqmX"ҜjbdDm,SAc+"x[%_5]P&tsy`|Ҍ*Dk?H;_W09}gՐ;WAzL?/j&j^Nj38Z^pNZ2,@fcum2 h$Cu޹AFuxN]?A*_x21vb Ӡ)0p;|-Iz ,s>.ܓR9:qr3/Q!CF)̒{BŠɄ_TksWCa^姼A!0foHeYc*06nIg【Buj*)_ߥc8n"]$$%ڎ\7b&AsM]2LQZj{Uw;aoQS¨:eճmO,Zahdw.)<Q9 793Yj?$VxH$s!shs6<}iW7ݡyic׈mzT5uoYp*&Yn&hGlb7Hrz׎o\}Gs"@476M.͏[%7N,Di lRlJO.֡Tfz%;.V=͋[=itʻ`np{s󋶌hDJȅ ip32# uRqa *QlcH8i-HHHt1&E_z O<A0}kzYrmoq}acgHZ3K 3A%NWӫVXOWdDe.-8K(ˊ $'7Ԑ,W1+ǀm.Br ?/yϗ&s%aJuOͳn. b5a` W!ǁ a,-\I,d/'K4JhNQw50fW a$L4$j&TSjFu1Q&=^|l^,Lق&/ފmn=|gEŸGUbna*:+$ 0ldaio@OM.=N{pv>Gr8:1-MgDQ qtt-Sz#o!C@BHO mf9-DJ.ǪȍC8T)8Gv@VW/3M vZ;E墋iBc9؇(7C^i{f" @I* ~8dحy?iK#6sm:6ĤO" ԧy?H]v ktx=5;4ƾΪ.d+=b]"xlb_ݩ _jvއ'CpkhH?}/ohKeWA|GoEb$ '%Y}V3>Q׻5D*70i 4|I 3.s_ޚD¯ OaKbeô_ ZCx⍫x]v*+#^fбZbTh_'I}1Rɺ;d&4kqTpRm5Ra0a,v Z"CX 2yqN%u<`}Dσo6g>RBR_aczPB^C|P?ZfYn1mt3(gMP <3{;fF `f-pz>N9 Hçةfj~rԯLNˮpanγV`bMoC2~&j8tíPbJSφV?%+Y^˭6/8C ud*;Z1{3JSOŚt %rZJ&r :)foJ5"gi*'QU|F\%@ܫ"4^i M-(/kA/ssy#:!CFolځY+@aҤBxw#a{%A a P} ="*B.hPqy!d}S"H}!u׎^9kMjYTʵ+MoDٶ-P u" Qϗ+DZZvtc;2\w@'W]M~$礙 !O͝="&zu .)H x(^@w} kPBZF.Z(RS3Ȝ͋Jfkqvn#g`lBMe%f݃6.(4 86,h=&n}_*򖨿)<}%)+aW&jﴋti~ |+H[x}~,8kG.ة6@UR\ wwKvn?4 wIKbtT^z|WK5O!|{14Sisx5 Y@:-ΗF O-˜oprҐO8ҵS#}_S>~1Myԣ=W4&óOer'rZр̷ϡ\껾~"ϓܲ5a}2)g3ߎsa8c*i%l&S<&CA d]™^rJ1Jn#3́LlpH[=C3d:eЃ\hktϏÎ,LC65);ɽFe[f\[bK)^ݯ&2۞<CBx7t[}mYܶjHsv#xp\mʇ?v`qu vVƇpE^ .t孿YO-,ns%\6#L8TZ6mYa7nL)Yo1CQHs _- OQƹd@ODOmρv9#=nC5ձrXi]1i gKFSŴEuk~s527?O{i6L l'ȡm-$Uj,RobBs$K3 dENOʲbv6]j«uE4̫ اS8s;xyV*iq˯b6]؍Y5M):$, v~ ky!ΎjP"Qй7jBey׆q&_v!qaGdwņIdiUc<o5]TE)ڻkqMPըARO o8 {{xč-o3cb4OǛ8A\ܵ{ɵD[*y߬W+bA5a`e7lyel<:͉~WTp^Ԥ_(S32gd#aJԹs!qTNcK۬~Mm+ĢG!P_YAnj .-q_!^%h"ҴxpEGZnc:˛QLrSsgWUPw̃ f(_[Zhř}nte%7(qsq$->"j%#+߹ ]I ; νt ;7U2'Opވ:AS$:>д"1k9tA5||ֹi޲2-Uh1.JBG ?YP-1ݮc-sZ"*ЈZ#\|+K^}cO-{͙@3SR@$("I>^{k/+_F 3/M҃qL"fҞ>5=%IKQ*.*+1}>i|o>i%a-!+=\`X%;0B(l5|Yå@QZM叾._r{r|Zty }RE57ъ$fnj9r8.8'7KJ\')]XP*rEv $N^6v F$ؘ#6l p"!/{̓jaZ͉/+ vBrנʔ<(^zeA/]nNRGp"96Fg >);y#beҞX>$G %rі@Au+Ɛ[5GQwzOiFK7]@AQ3N9 Ss !F e_vS~s,a{-=H6Yߺ~[',Y'8R2`z >&4nnb6uybQ%. `Y%<$AL-$AO}l'jJX#lNP'\SH"P)Yv~ }x(CMz+W Qq׋Ohҽ A?4 (Ԇ8ѵQov[Li> DžzDx='\pӌ5⤜#~94#1Br0ٞ0^S#dlku7.sȔLǬƖ„]BKVb̫؝E ,Cz1~6C]=L4i5 k۵Jz h*&Dcsm dgv3r9>!tl4BK`gJK9>;!F1=8>㕱dNdmXPŦ]^h;s36 ZqK'=dOuA ׇcjGqC8ndKmⵖ; #W( γ^m'?\):Xp]n4l-$=CY*NbX&UBޱ 4,S\ n~ިD/GQt9r|9(MSH ~PͨL;b<4r F&P_ Rq-8 gTT!kD='y0r8?L<~ pٞ6S;hT,48x6kQt@n&]W#=oZZhh5UBP5(;oH%5 a>K$&xu6#!λ)bzdAX[%/(tm;÷ FW:*7) . Dz=*+`{f`1vq u0;O/;JkښBʮYd$S ̆`m#P󆳬ݤߺH;,/FlNr^]tYCE 7DYonL%t/ 6>+YQH/B ={¦53 9N]#X]yA$Y?}/uyx,jN7;=TNc{]qk70~@g<5%̔ W(N`\V1#Z 2O܊ 9"A'!]NKܼV@;Â5Lb\{dqL7[dˣ &0~[m;6\/Zɮ\ xGHo&zO;O]@u7taa7_̤\jo@RxؖrGS~+e5A_֚p2? 9bq[KDHmIklW{7yl,+wCb d@A4Lb8!GY%1"#UMz Vswԭ# P /C=)2#&aG\B2Cokgf&}S_Bqҽ8?U XNmC7ѪEO+悞@aa(p_ eV03*ѓk:5G0cRP͐%BF [o=0-QL 1X{N5AA7i(kV{ubgOԦA * 03tЌlmh^B l "xR}0/WZԌL%iQ8gj':N)WP)L JrIWc}喿5,J^V}ES*OW/0mn8u*}4O חpX% ^:\Z:Q:VbGڵA}c*w%qsU\דZ RTak;3ni巚H:\מ9ڀ{H+Vo-g5ozW=>ޤ(ͺYwwu[sK@=v6 3F4{ ')}?;Y& rԉS 숬wR+GIL|񲰟ÇL4Hߖى̫l*+^%=[ S%$Կ 3pe:KmbbD,IIvrI6 >7(Rug") Qt5U-WF`56 -dL֜f>>Q?[Fz} bvZ_7Q[* cf&\ d>y-1]!l^ɱlx I TChx: ]\!Y|jqs@&aġ'֋5Za2_E,^'UUfp/&MNQG(bPcz=h+/C?}c+8}%M1fc Lbo*S9c#  -'u 4Vz0ӜqUs_vTȘ'LČ)S:^>C)Xvq s>JL?-&/ʝw_$0;3F`eHfyLSXHbswƽK>B^<*/PLWNosh@j;lWDN™39GyxN:ŏ>5M=::,:/϶5E~bͫ_d6*29鄮P.:pJZ"yKq8X.R# XIj Jz-}p^s /~9#CJQUֈ/'!w|u]X}}8S`TRIvyx U `5kcF&s %Ke(\8p>/yl(VkaUp_d=o]~sX-xu^=X</|Ssw"Q[d K8KC q-oS \&Ҏfygس 6D^=;, E9l2&_6R"KBKv@3d?\.ҀK*bgy&gs. 0%v53ۚ-ϾY믄4eΕ*b©8Lx_1" cPEf{@%v+ILT(`@BgQk!;QJP`4uPhwq v+#&1`TtoTfy7+ r(rje(yF}oY%yjmIJP4']P65(Z 'H%K~N-ֹўH ?[}"ד/2yQ T,7$엖0Nmo95qQ"VI:VkOn>K`TuFHM~4nYaqM@\AOޣf[iC[ʨS:,'ػe`DqךnJ1C/DP] " n1B߿}C#hgfk$V9G(a;eZ%`HgLhښ+~uP$Kh4P51/zDkFT}XͶvuL)t_(/{8}*+:Q#R,mpI?QE =Z<Μy$V2so2R}]uv#cUnݢn0Y) ktfچOV{+DXkMXƆ]|1`B3)2 ~uw-1rfx//z܏xy%.0`7Ktz b>&J9}QbBD)`8$[* ΋W11Ͽ4 ,qCe12my-0W'4QZ)%Gwc]$7 !%֦-sv6w\W^[=xYX#Z'ySDt< #rTM`>u%틆,ePVbe]DRiX%B ^KgݿRΣ/;1HW+һ=liȫt!&$KLp{\;aq%)-ua_6 Jdϴzl(؁{G2+-nZ*@|o[5n=ps5?[Xsv7KT N P}:7%Y^LzaLĀTw)[Du#$Wm&pPN^|~M 2mj}w wq%5Y}SD#46T2!L,]?#{{|4Rϴp'*jd5"=qyHf4va$փ֫qIjn\1a{4Nq 2dxJ#`1{ nHgOuU EA_蹝'y] @!Xַg]2es.l i )iE@ˬ4beKiu2 G($&VAwMVWLrV3͑S"lB6E"yu W0N*$RŘ<&5 8&6(Mn ߓ l-0VʪySC)F 7/fi`z" U9r.04e&ҎU&-@p9ag*_3}ZMfs9c=mFgp}ȗpz\9v4*?QfDW8'e֒Yw'W]d;}2{#vsWzeK22~SM,tX(BzSUg-`BI6Уwp ;ڎDŽ#6fSFp !{@xDt]]y= w]G"@ LGއoضlk?|On:m$:V+;BΔ8"yulĞ]ȿ#kJA,N<2ܝ.fr$-G^k9&1=N<BzŃ<\}^iǂ(K~Tӝm $Lc{;:>E??qBd%njsGIJ0NSg,d|8UЧܾ DD2+Ua\ 15_y~ X-RPu*Mn;`MK''{<^i+h]zQqþjS'j'3WxCsc=aYծ1Oq XjNWoYi'Zwhv?@45i nk ʂ, NPTׯ|ING-+D7WfJ^-gmǪͦ<2$E c~^q򢠐ЖhW=&t,>. n5wY2EN0]۵h6|&=#[w:+ 1BF T *O*Ju6XEw̺L T=<$TTDOS:t0#|ekK}ү/X!jテ;?Y)`DSV˱`|WO":+άi͓w+()H^Mtx?!jI3^b4@Ԣ(Q0}Ję!"jyW툥/?kF6s<2{R;иz]mf.&4AHrDA3K[%A*%Bڇ:C'8%(d_(ao|ɤ*l+|Ib!KW@R`bB"9^LˁIǡХڨLU89 :1#enO3bwGJ@*x|/wmt#bwye=ڈ,dxrdxY4{;5znk Ǜ4 ÈYycB;};s ,s'9 c7(%4W{};FA 6h/y4ʖF;,6W_Cd4BiQ-.I/ 8''f)Em &Pi(cFҐ?(ϋzB >lŮ, +?uA݅V0CMYzO]w$a>-L3p bUo$lzd%i;nCQK"EpzΈmSġL~˝l[~a}+lvګY.3G|xʉ6o8Gc!Ƨ&Pf F}O:-kw! pJ`7=&Fij-Oxtjq?^btbu+O0Huj9Pvr[IE6ɥ]TDLYܡTVAS}w2/ЎHM|tr9gD7'plSWvUO]G-&p02?kt/+)BI5*Nۛ:]zrQOrj֟iݢWenWJRL LJD& Kݙ+a]tˁ@}nY-v9RaĢWߊ֟!fPn-2RӔMXKA>bGcCo{|Kg2z}bv7vk۞"2{4i6."9bKt6ۦIt3]Rhy#YG1@)-FUll|ϏfYh|y2,DLJ }8U.o޹X_j*U [Iwiih_= %8۶F G.l7,|~)䑁"h9; D=?1X0hnݎ*ݻB{;=}Jhܡ0AqWˉp :sd-Ϻ5X+ &/BCq )\K̛&E%y1R_g ('U$pjJ1lj@uu AF׿8 {sndQ׵=C2%pTA;,M^o21?wR2Fw`Z [d.E=!P͒ )}AcQQ . B&5e?oy@f,fҌ;h ݾiRnzg?D0rkI8ixFTݩhJf+T?ҧ13<:iqs=4X*vDJ15T|ib;矷 nZF. r V#k!oYAGVʛpJEoe _ 4wof$^L3΁DЛl OC@Ca O 3B5,_9돂g \%GoxE&k6&<٫cK_Q_! k"w<),t:cpHqݐJ@`gm.U4Y5I7 C+*gƄl0Se"S?ꦞȫȚUb-otr'ʼU5'{ˏezV.IJ EĊZgz 1iL]dEݣ& c"KSe2jU=sX?uP T;̂۸xS( 3pvmܱ'S7Vɭ7Q l%j>Gf=bGJ呲> C L %)ON6POjc4g)j'$IH]O1_wބ8PrAh|( c.8JC82ZV_K˭7Ν΅OkX؟((1? ٳ O c4pi3:* .Bd޹ @JYوx.pzNjCz3dvyH'YKiMLUҹ}= ^EL mg {ܭ>cx)e `VUl!vnF>n7)b "|ytѤob}S.d3M"__(C _^CB#)@Isl"3TLg4jB1J]jZ7~|u8~XbR{,Y~$*h<#~q?jm*Ej@Cʟ7 rVY]t,(r ͼ~%ّn J\gyP`ɮ$q#bH(bƫ. 6ѭF|8` bQ aɤ~ӦJ 7^CA,Ђ]>qX$55-< ql$T Ԥ90.|'J{?]A<^Ƹ BX|(3\R<ެ!GQMCݣ^ucNOuji= 1k|єG Y+f?)fw7<~C: v[ydVgG砕k߱'iԕ{Z'M @c-=UiDи\w.&x}`g- wCxΑ=mQ%hMwԸI!̦Gm2Pbb!Fߞ۩km /!`U| Zm%r\s'8 >ͻXYLhMcB{&MCKn8?vk ii%HXB-R)q4|L&6[C*;WZ" sz}n9neٜg3T;}c Yg ;>2նsp3m۽J#Yix7[ O#f;ζy``wNiܬ=ؤX:y-(J &4/%*w{kzrTD= g<\SDH)6ba+;*aa |i,Tk/L/z}:`L=M7DUj%PKRfhuċOl"'rts>"pO*uEIXpS!R WDPZ#̘H`ʲ%5O=󍾸ʽaJ gtӦ_ ? aE(DXmNzhל܋,Zam@؂NQJsR½|q[A%.>(}@:GcGQf7Tt¤H:z*hMQu#Xbҹ*Ae)ȟnh~=6]h8#}@"J)Sow,zcP̣"TOٵPڤ^&^<\.pXUWHF !w;9ܛuSQq6w5Vp4SXH/w ;f&S+/\gy?z:'R1ͯ(7154 &i~Ze+2"@'߈iO4ZUlN9N\i-a3^ uްmA `f MG?%iv|##~|ѐ~Wv$YҾ_X4D|Wh;-=_xZ׫nÞeeq9YaLC_sWp~8}/dC1Ĺ{VZc~p D%Lr's$!M`#zpTTMTr2\ D ?cr3gk9hNYrO$E\1XSE(dOd+( i/E)|fbOV#][v外t0k ~T!@3¶ (T$Ah,*NJ8F*r`iN_r2qEb'En) OhүLY brb2oN!EШto7cof}^UYic/C\ w EkAϴ|{e&RE `RkkV~0{"JgbwhWtXnڞ/wصJ q0rЖH9b>>E+ 坰͑%r:(_hZ2qS .м8?{8o$&dWbO–~'Xf}wp' I]hE[ACm鼴76a -^ry(uCt1,K1)N`۾7L Vbs99?\ZeA]hg}ap%8Mzt s j&^7F1]u;5llTe8 lx&׎bUͺչć"C>v(? G^4"+MDn)Mܺq^?ie%8## w 6+*Yk m0)?˝'ެ~t1Zç9a/ʲ_1$$~UIoR8~0ĦxՅ9#t!7\;#)3i =yElx7}ת;/~U4x7cu=MgϜ8irs%~;׻(kir& {s/֘P}ʳqA+cL={CFk:lyF7큩Nݼa?K%\V=ȫyFgY•@w$_JDzCA:. 9d:vxLkgn"A>K$uc[@)W/[(i@ 6 "Juޗ(wnT*{!ESVJ9@rL%)^EN`.'K$2`0ҍ|9g;!ש3 1(M:˄FTHr̤"w?ْ]2O_wx:3XV=7\bo 6'ӹV&;%IVϟ`O,yBዖ ?oy]B!gy!3o&)h;5#&n9ޫ4֑n,HIG^TTS#Viy՞0aݥ#qyX=Ol+]a %JM^Sb| "'\;qUDyA  -K*؝0OLC~6)Zm.g1!ni[gV_@n\ݭ򞼶 , pM|،?:9,yr 5{75tP9a r9̫44[dy$^Z"[46+گJ9٩gpxG>W#A89ۼDր겧Qb.`D(1UlU#|J'a',"8O| ٩Rr x3gdM(t7a,0A1:v:\,dOsWv 0~FyO|c{M{(;sa5 _o[Mn^'rw~o6 RYe%.Ys]oă䖮>Ĩ ܭF,㢨(O>I-`r9c8CY$a-~<b1S_jֈ,HI3RY,9X]htgl,)ҒB+zJ2>?V4(/܁XZ6 U y*C򯳩 *)3T6Cn54ңNˍ:r\i4yhh1q=\/ȁأ}|͂߯ !8#cV8Z# t#5޽֩W]5j23ѯbˡtAH4 bģ>ZFj/QLޓdEr@هt;mP}XW6NbσSg$Sm[k XrbA∋^Zh{>7#LАٻ◉WHw(x&1+m/*,LcBGCf"Y|{I ^@Zҩeo.)+vy^>&[F48-sN C .=iݗ'/bmaE0?k+:qD~hƬ iWSiI]z'z3©u`$ :ZLPiq it@igrz-G{{#)iB$1f$| 'NT)0;sB&/Q5dMc!ϻJl?}z*ns'+(0PU8@ʈCCyY[ }SIA,uvR'dm|a$DĠ=G8[t5B=Glӿ0+*PW.beg":ӫ1X$$i{[;% !%@WrC|Upɦ^bPr/O7%̝/9HiT r-la۔T,f1K}(31[Na#6K5#R SfF&j/!ٿ'HÔf$A~/^b-Fm…% t;G1F 8- /â1Bw /e o0](/hWnFLj(yFoh4dO~F0#ҳeI/9VpW1<J ݫAQD:Ǹ>q{_4¢XWҡ @a1*L13|+_8iswZHU mwn<Mm4BQԷ%~MMZ\y m&; u Hͳi_NU4غKQۿ%+XAk! G;(c(뗡*]n4%p=݅-|ye>3re"Z㱓Kֿwmߗ{j0>ŬDeAl"yie[_[(JPĺV-1-\K;V3y(|֓M}rQQ]E8E/ EMqΕ6qX nz4[Q,-I6q!cIOLl2xU#׬0vA]HzlԟaeMg&g55/oEk ro_Dtfuw@/)zN_n  @H]. xzR/.zvfGL,pWΊVuC†o9FºD}EdknQY |c2 ldS'WDPc:o;hbSRUgAʇ tXR [nh \"7aĖKGSb v!}(羺!V8'蟘0lr;ڍBfڈ-v8sx3_s_+=AvHiَ g:H(ՊJh\,*QϭZRQp9*52pIa9lBp9௸'t$gO8'eWnt4z$C<u G< VdFVԑ:ؠ1 %7%{K"r׮`Bzs}PD0)zE=ܚBV;ȋPkwR |țXRȴt:-QQ@ϜHf*Yqrji` "ZK5:*=LQH${0ҫN}!qё$Jx( 8H^ԻU-5}%'C +U?811"nROQYCwomSq ARCk}XG PV߫?݊P#% ՘ J25q`ح:a< 5hJܱ_v?,M}⨪KəSA{!( ( !Hv&6K)mca{ xl ٭ZW8tK͐RMwMBn7c>\R-|FH?%zi]SwŴTJņ-֨;*^R)odrzjPiAb8o[ԛa>cP\Ƌ6u%0ɤZ^Apd-zac,A̮~. C$8V7hxonJ.jD0b_Z7$42DXNn1䥤U))b].ƙ'ptAB \Ո8I1NQHJ{>='ȰvO i n"`O()/HixLV|2ivqA& ꍤF1C'Щآg޵)YS/Ѻq Q~H956⪯Pӯ 7³q$ qryj=Tryr8v񈺵+0sݞ'2x7+I&qG֓~HCX&\C=,D{tmP{:a5?hQ53p6k,]5TN-$'Sn^z l]Rp9JqWr*z IdE>X<yR;5'GK,Fu!.t쭸%lը$oO>4f}WI2,'QHҮ^aWj<6,QqPu/XSG{`g=Y|9"MeK3#|o ljtq@;m|^bl tυxǣԴX~hsB%䁑b$DXZ=_kyO`y2u$wG{{J'6/Qqm3eIlH>(?Fvتe׵}BX$ڬ7-܉J!vYҩ$|%M'cvߒC{r 1gcXuGv hdmLeQr8#$VݿtQ$%W*\H@~k8oC?]M.P)~yF$38ydN5s=1dجXCt"\K#%o#ߢ0%'-9 {= i{3E'Qs:3D0L/\|1 /T1,6.26V{gR5x|x_$E!`T0.Tr4vqsSL [98rшmKLKDkS1os@ '1Z?)ܶ{l~bG ֭P^tqNRwO#_ص֏|w㸔&8A.nBHpR1q;TnK6) G/bWOQ' .iB4ܤQ}]CHYD9Nq>wNY"VZ7PlBA-6 =j$7dvaoN]Eu!sIb{ۡ*99VK 2mt4֞:>Y+0g̛yPyTW.V^pfM.Ê.ϝߚXԬX:j&yxnSo)ZXVo驰es1W\L@ I|GNCm 6~5g> .!Ûp&kkP[+4Ö/" ?=pZ:URdi#b}jX${&{F6vDmXVK`c簀 KUfDl7ے5 /x{"x t~9HXmOW-qCWM(aUcqLE+|s>@Z]tتA'>AtԿVsΌ&kPҘ )V2P jp4rgɥRY^붠 4fs'*_>Ge^yDvgzT3ιEIiSf! x/v >\2l}t 樭JhaKz+P#|;`be7dx*ƃLm@{^Ɣbt$ԅ[׾ EtRk:-t 9fҘޟ[ct(~:COZiv?"{y:;(+ _"a4%CP`DUEyG/;I +N@0O m$A2D/,BޑYㇾqe P#' <5jo] @P71V#`˩䷅(q9¶3jCu ;H}2Ĥ,SQǽv:/B0@X)X-ˢ0,XTVmVL.ƈQ/kUvo &^vFtot_*>9bn3Ur#^TD۸GU݅C@!hV=] N-_ (9i(2w M,Xɠ&u߮K 3舡G|W_DnbF(&L8``: v>#֖@?ȇGxzi䁃k&0җMr3FD0J<|~yE-|, !je.=+̔vQ_yx1i$KHy'og/MnV>ʉ@tʴ2 4uQ&N@7%XzN@ZÎ̶_ jm%0N`,Ċga__dr ^}C KBNMa&H")̂'-0O ߡu[4zǖ.uDG*garM| d҃qBJs@YE 7CL~&#>.n!"be#1ORYQW {L L[lvqQ r 1__9L6ϘHuӃ,Nzzӥo7Kh)l+>:Hi2Rܾ5}aym`W"VPpd.ZToc:2vq[';Rm !BEsS(?-U:u] ~IJ%3~RbUsVM >Uup6ek`}E<ڦbjCc_WۘGa)C$y*?h m'R}Xi]&OH'f-m mB1{]2Aۤ"?G}X8X;WN_ئbY8 ,*ٕûԘ9f+MrT$c>kNɜN ƴpOCԓ%[3XQeWz%?dͦiC$wJ=h)Ĭ<Z0:t:#W'](;k MaP/) !}V fWr?=5OyP.y7 /E܌ "=׳D@JR:' CЎtpX%iN8ZEX[}@wd#; o~T0<ߣjb 7WەL*@i\ǖ@Q=?i7OI!:vyv ##z:G>2Z/*Y6o\|uT?NJo2V{"xQm͔;D4=N} qXqtMK)04^jfm5Z:4{1@aŗY[L`v(/r8v;C|_ 44ɉ߁ʻ: PkKDx%%Uq"1=-D?Tn+<.P@+]j>dh:2`Ct\0E05zm5aȹJA#k}oh")ʭȜ^tNM2րV]Wuƺt~/=3l@04QbuWA@h$9/N|o{TS{E*U A"_"s2˿@Y *m."SO`Z J=0DR[= t'c+R#\Y]kJ;;M]e!D sۭ^[vJhvsFr rXڭ K8Vbdj< B,ex,o[o^/%+J @_(Pz([Fl- 3C ɒaWZ$ݸtdz?<{i=Pr7u<Ysk;E4`^L ^YԶ6^D}g挝l?zɆ}`\&",CRqfμmU2*Nj3o(١ ~<̂ARo/LZ 甽Cq34kB|)UE`p}e/.Rf*zΧ4cRgnJlwl #UJI*35~ˀO|U(咆}:'ܓ0tmuiRW !u`s.>27䥻)Gw(F :U_ ۧ- 6q7GRbՙfuBӿ{yYfg7+)(FMւ11֘ v6(BشqH ,p΄e 5:kz<6]H$_@|zcN (膾TnXXkI)ɿaEx\aUį(7=s߁/qAsV-+m4>~F(_}ZG\qUzDq1h>(0(RMo+%ܚ;Sܑcn{E`:8}fg $ʈ4lp!PNE;yW#* n!ٱ_ԣ0gRTzW.֥HL1I[&0 A1^| Ɣ*͙7D$ժHWdYJI,pU*4ա9]UYO 5hIvZsM5!|$Abznf+퍌1*,qg'ݬIt~c-qVXs5s8x={V־{s)zqߘh]:CrPz5h Kc4$g64PII*@s ZR3˸&:}Dv`qΖ 5S&_٠un<9 ?OqB;wD&{7B}p7󐋾7ObN޹4@aFKeq#kv 7Qb='{}o.0Qw&0AÉzw Ӈ kH/ßbޓ\Jbpp]E݋J\,UrA7gh>S{Tyz W^a?/,rց YsVr/dZ/%64u.x84Ul;>}x\\.X,9ƫlVJ`N|-׀LٰngJE0^Θf2..ud@`O{D<Ilɩ*J൚/#`;3U*9q͉tByް?4g@Gꪃ"aYY;BAtlnrP|jA]@bZ;zSR~TYgN@ daũw-*@bk_pTGJg&ԇb Q>wFB;5/1C6onI%FnV|ppvjH?F) ]b .M f$L2ͻEgQEWpeToEr);o[4}g/Zۘߩo^|E2Fm,s@?J1vZSi؉̻8}B})"D ՙC}pګ;0x8&b;.Y(Jz{kRNk /xzXh,Qg}&]O ޮ|:p8o;녣%xc2ӫߦ\Tu`3 7 ~NV+2{ׁ]ߐi(V +huz8.ٿNZv~X:)w+s;M++l1c=*pe%E}8&?BQ%(9qͿU/ZC;SHíi a`Nc,/ϡ. C#pus!I]ؖi&J&'MtmMMd忉 ,@M(V ,FA&u|Fi3sX1CEehԔjw#+^'zvշ.s$Yf(!x3tf);r^NX3:xTQ wHǵs=&;} m ]Bbq\Fު\OtV?-i\'is]CZ/J&Vi,&*\ :zO\Sd yq2(I&Y㵬A"{8xOq2wn$yŀo΁2+tINܞ9hNkS93wW]XFntJGG_u&p9.&b$dj%C+M߫ޝ-ڤU.TgKnؽߧ+$O`~u:ͺPz-]A -<ǚn5+ -.X(E}1% *LBOEߓ~]z[V~'՗۩uu֥y`H >/Tf6%-{9#hI1fjpflG;Ʊ8:Jt|Zoȣ+ojT{N}yadi#llrH}\z`Ld.w98 j/g̓,jX v ;:^,/)d$^mF((gd;B\M!PƉkps-SĄP)¼5DdAW"O7[EΚ u7ZR-v fڳPn[*ֵY}NҚB.Rg20d2i6S@jނ֑1k﷒ш ctO"Hlj=T0=0 {6!&kFs}]EHT߳ptiF}Ca@sٌg=[P>(IN_Zb -f}FwQ N g I<1u<],|lL~`VcB%D3T 7ǒ\Ճ4=!gkKE]OK [R~i f _(\ծeF¼b`o d8J>>IL{A ^F̔UtҐ uЈt]%'O~W~KtRݕ&fYqTʢ2 /57`ź0\VFHhXCO Wyb(!8^CⷙaM(J>+k$`4e5DzviYŸu{[ KdN$(rA d\ZO<v 7^45WnɄvߎ.;YyD*51ס?Cqډpm:& {U!ùjhr̽u~^me˴6va<6u(lYgL/y/cѕW@Mv|l}YF81Od~NF"ORo׬ﵱ~hֹYk`H Xjkt?{prWJ4vdE/JL,B_闯$CE` %KOk_2DF r"SUY75~D07<["7C\|*yfCL8y$eT1X^ҹow 0D.wFQKŤ4.I*s,ZW&cFD(9=oYr !~dtOTnmH1q0RK>݊ёpZ+t5$UXn* hGKo}UFÃGOm@ %ΘSe Gᆹ= !TBu%Dg7F LƼCa!ԃ&BMV'a~.ô8[3"Qjt% gIw?37a*|^6o٣{nXql1hJ.NW+- (RyhIW"np.-3W2ȲXЎh ZiYv gC߂ S)i0C p&AP~H3T+8cܙ\)nUFݑn88]ԉTAlc Vqt]bm0\:ھQ#`c4yߘ'')5E! ¼4Iv3`d dVfٵ8ڣa֚hz2fn\}0OyxD|"Kbc\sU3럞1?~ӱUN|S 2E$[R@7^l"w^,lǯNh6U>7tY BvyChe1 UEs ¤G&ZK֬vA?sg]la.)t;Re g;@DX^,wG`>x@$B^(gi? wX?=׫|FDL. wTo\lI*FZE|L[J~Gn34`$9aIj3@t"MlS+̫F^Cc &df%H^ֺ tax<+=R;cs1]Ud Q%:ى5*MѢ`ИkwYO@UjépKNo}h!s,wJ…tx}NKi[ ߟ4cO%JȔc\ƏfsD/OEQ%-pI1bbSc5F7Yy8Ň~}4_gęE:v6;^\skZ?!5-1~CNo=9hi$ ݲy!J-bcP 8(M8K9+ UzK ` = Ọ4toSjJ`^7EkhI{ y39kuHzQ,d )qZ>k-m?@Uk鿩{MTv@r0SbƟ,bB,7U9V=jI+}'ӶލO~}~rSO[}:Ȟ w8'8ZaVgWf hCNF2k@> eLW$w V|C~eYIO?J/E _0m'L֕+㽖_g%"~ zejɋw'mrlib݋T DRr1zóǁ93>pjܫ0 „YQ,so;~NskH67̎`JÓ/_̹l |g$Rp|(En8MSf`wT(_t mw&1;}y˚d/fS)5#;K/3!Js!M^q.DGh$n43/"Z>&F!{Md}ﭖnή3~RK[hl}z$bw7?^N/fOd::[bK7Fw} \Ƒ .LjZdf93,){9,3tjG9fmBKĚZ ^s8 K @)g<Ȉ <$/n[Kn&df_)\ddO76Y*+%ԢGٌ ZNh9>׀Bbsk[|.fSfTSC$uI-|H$Dꂴ֦h/Y]y n+zGE T) {av.&X8Ek3 ּYsZg9Åe S0W>o녯>ڑ@>Lqpϣ:2,aO 3'\fV8%dื\.H)!H8Ŕys1t&` \Ee$o0~Q\C*B E,P-E)gn`KLѤҦA9n@M`xo_AǺX$LH`ol 5 [ E6pSIP$\im[63eYtR<$iYd#3ъ/[UsDd'kN+H~ B EJrHmծ =y 轉 gSZ?/!/ZRVn:I$PH" @%nͫ8l3I[TpCqy]1N1@ '2V liGOv\T5Đl YQn9Ud,{s3R\:x7Jz",_lYl+]RߡMp')oϐ=j)s7=JWveS 6A6[WS0:Ť cDY8brQU]$5t5_uZ`3f:ev` 9|.K}7,<,Hzv3bo]0$Sb;)ΨS'ڋ^oX*a|4*9m=w)2gmޜzS1ݻoO6/| O>xb)f Nu;2>]jR!HܦCC& R`>@VȏC\eh"B"gHU5)Mi^ Wa6,ٞwFDK;{C`ލ(^JϑFzU>z2@#bG]h)xqs7z /UZ("xUUp_Ev;0ze(''qyR3%]d)mjQkv?nzDL .\)귿`A{+>[tߥ&*hyOzd\pq:Ii#Rkdj|dw־x%rX?#眳ˋ\OU Yp-)R<TgU~.,]C7WSe)M9€v ;:*w*y2H rh>HWqQB$Zt f11zY1tt z>"̋j뗶=򞅿}w^p$d@t%௨]ͱAQ&' s DT΅dfgL asWuʇ fk0G!s^\&=6rͨT^fŨa>5hFeu ŋyc1 ɽh$ ~66fE0l\.zøyi ˵<߄U@&([/~$ !#}3}I]z6\;Ƶ2O{^ HhJ79v!_ 6Yb5)2hK@M{ԆT"C]9uK#OI}~S|6&:LsG?HIGvEO+Pe@{/bړ/z9yhk"<P/k5w"E:*i&T?mUo-F>4h`-7E"U-I>XZ Z~_tS kR`4nnD*1K;R>HqAy(o)R וrԱ+1C,#7ΰ62-T|rv_qkۦw,}Q|Qф7l*yZEK4gzΑTsBe"G>-^> n0L-$¾E/; @ C@R )/ur2A16aZ(vo)D&\ 3_ۈ%r{  BnL$ڀc &ty#9z$נ&zRy|4NydQ]q[XqؼʍaF֋pe#&+2X˟t/=-"wFp>鰠T4:73?km,;ɷ@tRo;jyIOW$4ElOUBy*%}t&ڮs4qЂZ&hG f=QiUTJ|pС R:-:5@;}wuU\n씭oz D'Sĝۜ %g 㖍DZ xS8 b (cJK,IX?S@VoL! #s8GpO"ѝsh),Hbk8Xxu>U(-M0~R,;6 4Z/\'ySkpw|т>sC+’xVۨ=xblio@e{8@9{uI* (< aٴ%{?ROjڧ-r԰E}:9/[*|BX;MNgey =M?`9}*+I]5I̗s h\&Rj^ G3ىUDh2X˦Wǔk| Fg(s /\k_3󙄤hQ[EpW;=hǛu7CQ 8oVⲉFocQrX/1^U-6 MFTˏ (GDž3RO*Zliuv'S_EYY5 y0Dn\sd2UȌhNVж7WAF"ݯڔ#\ LB4yNfZH%jGnTᶣ2+Ӽ@ }$ŷiEl6# k*kNXj@(:[KXKr.'<~H/N@1b-n<Ԡl 62wԚ8.n^^.8_2-&H;[軡" ۳[!Z@YpTIzwv[A Oc?*i0!Bx5zLBޜ!dGU qlպCMrEIr T}]3͙> FyccЍ4%-U"fXۢA J\Ku ?cf*x$K(3 j|F(PWBX*ZNùS͉S󅑊R=7QgjW~9KO= R{V-:_;LNԋ&2$v j3Kݏ~?LW>!`Dll1B YkM3hA D1þ| |CwrY{"(K<{4Fa#O__l {o^-k E.ys-;'qJJ;aHPƧ #F5IKiyZWe%A61x0v'-&$#޼zn9أ^{d?ұז^əl: Cb78ݸxg(ځ D[(Zݹ"H-OG9+e&C'Հ/+F4عpMm\z[@ћp.LLhT.iyۉкM̨TsHoBlܡ⑽EE`uHzDjZrRÊ/mY\ʺҾW,y:D}LʼnE‰v\0/IN/ YFÖ~1(c2(`{V;nU/jn5a*/f+`/4+} ds+Z^4VW_ogcЄɶtFmJ3qH1}&{,gbl @TGix$oѾVCb:7V"ņ6sRN&,꺞L' QU% ="R|^ƶThx9m^TkUBcErG_6]6Y 42*l>[#Y h 4#伆8?L+h{olV%y ۦ(&ŗ-;H@p c,\"vڊĠ6LSo%_ ר N;ųx=!oUɷJaT9JZ<7b9cocB ]Bj@_Jp9/V v\S7j$o\ mWؙ`9% :BOiҨ*>Kb`/⊗XҌezaVl @Xf Nzi{(ڢo#>03]ᮁ}$kʪ - ̈́,6 m xdn8?k,__Gtm}pwu&Z;g !N-#g]+S[} MaJQ6&/Qݝpu$ e>Dj€2MO?yP (L"WP2F? yjW4PtVV K8k P1``9mT4~?aJh?/l;јMrG ,L#=ֶlD6QE TZ&w)s= 2x\E;k-ff%b\,~GƩ)5]!v:f^{J@/g*D\]M{K#vZxq@EGyA|R5f#ؚ48.T.X^>!x@"_`$_b93 AO#T(P*U{PqUGTꕼnThz'i<Ȩe~D88`G"q')Q chl[:JH=Am7]D ` C hiuԘeQ>Wwnha@/Sy9)I҉HdnH5R=yGX󵪰o) tnf p r$k?@3pr_8E$ jx3|AF!J*_Aփ_Z,2; fT0F_ܸL$.-A$g$ypҰEAAG8Y ͂Qg]P;+&z0X-\Cw*7NYkL+_] Lx>TCGEYky=%F5D~,c/4܂W&! t6d_'255j:y ;œ)3J[="pKX Z;1e"ACkdDBtx>j*?EЙCENNø@/Zl9ۛ76KDOwOnh0ф<F^qD|q:"A6\wDE1DӪ[X_68;EA_#j'hzn1nReBI}(2;lhwc7Br)G~s$1Z@pYEzDچw":Nh,7DҹGoSL}`;f*2J"xdY*$$Ւ꽺wъ q.u@jTgBHU<8hQ~H "zsٗ>^N1TɰK6@8ax+] &*ŤqY$ \C.ℱ"ysAh .픭3v*mTgH͝Z؇0I}@XAx7h;/Ϙ %" ªW}|Hj-%SGn%T]lq| Aj% 툾Y6NIPdK~z1iMH, $]YOX=_?o;FqjC86Pe[HznďW13iO`ah}=%Qf9!e_wyF ʟaRiJR'TJcE%٥:Êöe->NGjJ+ZlVAFL}2WK&eKٯaGqԠrXޤ/\1z|x+h5:1څBGBФ{p,=|f1 Tn54˯ ^Hky2y16f䉓NT V+fH ?oZ"*QIʮH@eWԈQ/rDX,.mmNDbD .@aZagC_ ZTm$LHF'|ՆÆwznvZl Wx`\~S1@\H1L[!rbRh-GBD6E󢵃Dč/O( Ȏ@6c*h'{,Nj ::괜yyeD{ihcﰿ1&$~{'uc#W lJB h~,:py48$Q]BOIwkswnxS+ۿlU-]fИ;"NU4 E4qlzn=^ * bC.G7ԡѵ.QLYګl4`CSg(ҘFkk3ab97QDXa$údP;\&i%(6]Az&cm,w(2cj1ǚګS: Zi)^j:̍(%ةꞖ3!+Xx;()}=s6]9^eub``}֫KA9}Q͡ҝ n(ۃ?6d^IU`|kergN%M2WjtNtD=:m=[PO|_w$;Sp=TSmųU1M1==|ΣRvrΓt|4t$gjozmW¬#rh H. 8}G^?LO=^~&O'N 8B#@(Ri2{E6O6%4@ŦĨl"ڮA(rik8Uàߡ0ʸX2| mّ ?lgz>"Ƀ6]IpmG1ue_VXC}K`OYN֍5#mV9%`r+$X&NsD@u!,bH#!E^"_J^1S:&M2)i|wo[o'VП 7JYGqqqݎ5YJ-[Bb=A;+ Ht3Yt k,i/ jqh숂_p\xȎWҗ鏦婀"`SDC F,H*h{I [1J}uG+ 9c搂r Uj 8hQcA L?Xco-@bKS*wtP,Y3`o՞4h1d7MnMWYoF+zy^^ˇRY`U5cGTZb?b Àrtz}\ *p6{ 7ڈJЧ1 k$Dܙ8ɔdE-S𳦥N:c-z:N`O򵷩|"><7̀%L,v̨w gLR]71=UY8-$Jד&Kd֍BeUj-J vk"b6&;< p.*f̋d@ۙji ʟխoƳK(bPcƯR3-$svcPVT(k83MԷk>l- u` qzӃ &dŭ Cws] тLSY8CzglYuػ@=INʷo-)@ٽw1+AIm̖dg2!I ]B6Y_6CaT gKF %eḏ.v|r-18չ}0X:m!o|!.~W|K 4Ǐ#fpUI9~˱:L.~S WN2!RMiH͸eb۔#xn,1=k_PSEd)SIS髄 >Aa%h-xI[u:d կ 49f sZi9 = wIʦ}eX~ 3>ЍthbIs5 bX\;͒`%yn~4֍ O0ـ Wك= ; <Hƚ .?Y4|jԈe>?l/L?@Aߛ ' O_$ )u[[s1 ,̢{th7ӂd\\ iɄ_(g]Z~/]CKa&jI}<0\ٳ`?e7Һ6D.nx< 9&_UAxc-N/Ixd 3h{"'\2׿W Zk8闘\zJ8_{cuF$sLнhjsi>p9_IC7lbG􋤋0>S !jF ϰr= ڌ\\bnVyǜ&)_^?Z>ؗB|ql,@3 =# ;HKMewz1aGM4!MU[ FJEp^U@^)5oyW0FjE᤭;q}l$+֦mUõK&ʣy+Vѣ&fHjsvrR0!.`Fu3m h?"Q`+F>DML$jdHFrLx 6.GwbQ9 hMi+5k@ H^(RϡLi3 2H꠵=V8\&vLJ,^I+%rUVt FW\#Zdf9TO* L1j7{A w_͠#gF:gӸfT*}|!DdU\ܝk}JVVƐx}_Mu2Dx_px,zߦ-VCZWϸ:b' /"Ȑ}0zL "{^Gu ֌ܷO }vcP u@"H퍼A|QG"Z^wEPVO{66Bc,NEVd >} ;*Nԃ(7/-wCPj/#BlՇCCKf&ܩ4 !\n n.XA5/lTAE Yq\" pS '_\)hOs{v›])'6 m^st/{y9;:{ybQv~DJ%bP~{ <0(83~"m ҂k_ ׷.}& G}B ϶THgͬwUQRaʮe2qf'/=4}q )wx#Z j YmkV([B\=C$><_Ylhf,:Ks_/179AFR|ކyJ73Le?J q[̸죽 t|Tu>Rıhh d}wlz<5ks* 8 k'h/@18Myԧ|m(KyJFcH6O#f RN/O(JOCA39S `"zbp5_'OU(l+[Qu%=Rه\d:vb{hʠ#4/U3 7[|)[<Z}>YG :1( B9Y5tw8a,?ٿpd Wugl3 Sgp%R^ \&r$qH Њh0ZbR-϶[L+!! PA ^n %whXt~ j0p^̓߯ ػ,'ŌLϸuTE#"{DدH%7@y)NFr{Ι{^dAxhQLTXvűܘ +A۹d`lZR UxH1UNGnMŪA tgAX_);H+_ fTʙ&CmsCcW$LAnʊ(O,xƚ<Ȯ A22 *%=);h"4΍jv"H$<;q95T&wAm㺤6.L 8F=ddLƒέknT^B]w8UN1/U2y>mQw{ D&nSG?HcٶB!IujjaNv.r2AQ6:q0?E "(th]bAլΘG7A[g a}q=>ϔ;} Uk| 6浅G뛙4#iÀ1cVzkT;gh`[~#)svSU*r7śA'Z8dQrZV)mRn;[j{2;N1G|O&Q OnPW)tGfza_&]:!WF8#Y tst`?Y0fTt!Tgё#Òѕ:Y:S)T3d邞9#Dk< rId]1z[fF#2 7!4{1]QSM 4lb[)I OʕGC WZa [_4.iWAڙKV9it\"Wz%>,k+1% 4NOr FH[^BcՕ>nBqA1ag9(2]%+ϴdqf0g΅+'xpSIqn{IT_ e~*bVSq$t4MxOp#X 뛫E*zǏ $d`Hlfr%~Su c]*;V_J?.=Ĵː7x$Jw-ʵ<_S()RI<czH)T[ŧdzN2M1mJA#9rCBܹ#2|$OH-'HKWk/OuJ[~oN R>3"d1HB\hs/~If'At.o"O7.eB8x9B!I ,," d#ծ@V+??ϓВ&F ?wk>z{k3 ڏ(>҄+WmL9_nBr7yEN)FsmFo:)z.E3I%q3@ ;s)ݵnaT&JV߅o<<-2x nQ,֩dz|Ӑx,H&)(LfD^3^0If;60Q"lk9!Y2ڥ$|2-PHg"{_כ^^"P̑4\YmĄWEd #*Ց`Q]WdEئ3Kqdrȁſ-cƶ3 ^hRU~[e۳A֕;f_\!T!#xM8hJ(ɯ}3*(2Ud8J8t}b7wO[aR2CLsHB,gMd#aIRI.2>–pV9,/KۜtVeLJh(جIw< #ZSS(V2VͫpN3f(LKulr|(2T Ret,ߡFrٔG +7ȸ<.xAv&6X+" ?i *Uls˹pLQd~\ K^G@}6t zҋ~.+o#T*A0%}wT]zv;Pbrg7dK!+ܘto_%#o )93Kv.ӊtb9圥,a MBuy^6I;TG&_{'4rmxa4`hKgoNUM#Q*4lhV73wPE|nKv 0N ;NO:X[,@8Ơ>mVabf;=,QɈ\1;*iɸ]v"5S4?CC >!*]$1֙/rC{f c1K.r !;Y ð5:ܐ଼;ڱe!jCHcy\]w r:TTp 3֋2>`z+]jZ4'?e<7_N;!˒s! q0*}hJ^6phD%?1@3兾iP =8deP/t/XŒE^;*Wᒧn3DtPͽzU]5?eCٔє5Kկ[Vv "RCᵲOѺ}bTia;R*!xyܨ\@OK/`\$3\>wwV*@t{AiK`VφeᅻGOlWJ@7HbA6kyg'K7(;E9 Fs8H W9hյE(%o [Z$8 zc?`W_$׀pj4?TLprY}7#A g{ewZm>M\w_^ЭyA< Jy'ƆOe9j#G;cG gSk-EȧސX+eK=B\? ]c4VDv#+=zVJ:`ydCe0l=gI|^O%A+.TBٔQذ5t$=a}(F FH^fx۪ov>de0ū9B?-DPFh@-L 7 'gC @"6J.7 0"C'tGIM>ivb!UsSG^}q 9}e֏-&&GAp/+I 7Y0\jkɪN4`V?r{7ԿVto 6.c)Tu<%JLԧ'wr&JzVxq8q8Pr1FOĹdMNME_%*D⻟ã3"܇B|GN͈~M@!̙3] F)AUS$~ Ih6ҋh&$`>|JY̟DC,!dEPbQcj\ZPZ<*1 (OӢr*YՔ ;)-K+Ja8ȮWfa_y)u\o&;nT(ďD=o%fDY]O_AjC !\fEջ 3:MwגCB]z-z]fF|5rjն/OGp͵zÙp BVЦ3ΟN>4s7"O!vZTD.ハ [ =1۾ƨGuVB8~~ ]5)Ũ')TƘ݈i2c2į.|S'%qLa[{CG"ɂ80>#[ʹ=ԳSJmxGb5V/(]<"PV:*%L`(rN!IIJ9?8 ,@*q˅p|) ,ޫHWMʞBRꊊ%e0/8U9 [H\tZo$?_~Sor۪!@Y!i+e!"MmmH8]P^&T7t]֥^ds0RH b,Wq@I?IKa ..F&dșAzpp5dLŮF*'"25 S[ /8 S^Vq=PG2 N=ßXN[{8 D0b 5ĩ1Ldl6QyOiԊhQYHM||ފG?mVtjfju65%*Y}D@qTV [K!KKNGP͒[QY @@{FoU 3H_i_({`f[ l.aؚ09,9)q1h ߁g Vh| a<ܩIL`CڸLeKx0 L}ͪG*W z6Ǝ%;ל $fSԵpzo9FmL÷c"R$@$UwKe'̗"Maķ(CR.iڢlZefAe LK?ƣm[ pC n$qlK ;/Q+%W| ߮멩J vtd "Χ!<t_=xu-:kCtI>BAy2{eLg#Vo 1d:-uK S2EJXt1AV^F&`Z)V77|i@,IE>D)eJLet#⧵e)`T.w6F5{?C\t~Dx|%~r0!OM3'V\<:vIBҳ {HY~ЗnMB _J{%= @Ms/&)SQ"O׻٘io6Tώ{{Ĩ`:"D#~E v =ʵ,˟i?4<(<5u7~uI ]fnחi9>*~;-~5{bcP 6,ԗt??;}9}(~>a{WwC{i+\qS 7oQ-C'ӗ!RLn77I)blNGz|5Dc:fMܞg-a:֔m*#;:mopI h503aDw8}.ldYWZ' =%1^l8 ,)ɢySv?,fme ~NFu]!lGF'顶s3Kh=r%S]^&MLmOO44؜HY-7%ƐVEJ,?#A%E=SqXigMH Cc"DTFLқ)uh!,ÛɷANf|Wݶ /XyZ&|y`(i";#M_JT" 8u!DSt9%^ocƺz1)bSo{H޹^"BmDvv}zb<>xl*lMۑ5yHOqDmËŰ!Iilh7kͺ'B-H/'ȤLOheA==.FF:k8t?'G47duBs<~9篠kx J$>SKqệ.5.8y(:Ư{BV3J.tZWDUFzf{Qcd9R=",rsu>ҎR|9MDk> (KECL]=hLf2<\؂SFo!,_hߦL"f|Tzn W5pb3{!;XDSH03ïudUTLn7Q7ۗo)8kf?t)@@g;y|2zk {1\"EiY4-h6?֛|ܦ &4'e9Yّ :) `/ZiBVj# )O{[fwIN'},dInr41=! &Aʼ6fxKt |O`}$=3d{hDFDtXOhyd-n~5O[2 .Ĕ`1쥍aALYCM1Jy7FO\*akj(Ȅ"A΅T~KDǰ=te6aqqpզތKT"TFЮ{2?mmlsѡ:VnEgaHU=:VXj.~ЭŸAan㧰24Kv/dP1m[-d#H&I½F"u5*=qa 3tpi F $ω)e>k~|U$=܁P.[U;> %1%$!E}Bsg¯w+YOۼ10{t#h`ej$협\ZVyܛɓ4ށQW֗ȌZ7ovSwC!ȀjʱEzڬGWUص{隌Ҷ0wĦ\Wŗ(=d/40**5 Dvӎn E']ʰ;Q3\orWWStyjfH킫OR3/\k<%2 zM :ҩFZG412:no/9׹UMsA3 ~fq9illU+v cljv5rW9۶vICk0W{\$X0VC#zuP^`;`I()(9Xba;GO/1^R?q=}Сv\ -e*qVIݣRn4GD#T[o|>/s B*^ָ[ yƎ5m]wD$c] c_=3c.b9Jz+슸 g>.174Sϋ&΋:o3iȆA͚ gE[9/{XY9m|)⫄u+ʾ>6xRP[0zzV Z.q(qu˂qzNA̪v ?ڵw[FOGO%G& 톐u>= 8E b2׉q6|wYk8jwInԶmJKk`xi!y>oΰ9lHluzh')>`p5bkp_L[3mzTT/xeSBk^^yr96ءHhx!)9t= Y!=Ch42~h6Fl X_KI4;FZyd10{6`ۈc1OC"+PXv]`B>|P \GTPڢCM739+!xe}KWPCa}/ܲ*+Ap1 -zLDpXD쎽vֺb&&;y 3^X8<50eX4$afw/76 oJ-jRB}^޸˭u6N#Gxt#YgyssŰCj ~v m3"bszoSn ]s9q* cY1w9 \ .^grWe|ߩ?rP%ZX?}V ыJNrוlk+J<#$Ʊ5meB5L' t,t2EAW+Z), K3cTPf: *7J0EQQ3@0PE0FL WNnjSܱz7^.:4C9bzPm}8 %jsIg7Cp\b/hkO7dp3ߦWCwa Jfl;3WdK p\;gYE2n$F=Lvjev pkqvX3JkyaQ65 Ai<֫X[O C|=0`~$`3 Xpm=RA}BCa8. O[ۈ_;u#D,p%>}/m&d1Y.<_[G) fXTQ)\sg`ʦn ȖKy֨+)fh1$ӅVB63ZY3r(Ub6vLvc(Ը ,TD7\Ӯ'vU]"4M L?`8*Wa"f~AwL{4:`a7^iggө3ɤ9*`ӥV4>sӻt=6 9%УA y>ٞkVm@$*QMؕR) !Zč@HxM~يh@p#,9|jS$5337Uj [oWXP ?3f@.qhM8b;2o#ˁAԑR4Kx J^v;+H&(*Tn'n(j=OJo@?սJ\72qoK.+~Dm@+f=K)"b.GV4AwP/' <қKKQ6H&#~G:֠)V|.?+E:Bԋ_ !CRJ٦˪-"#ݫ4N}޵ jh"_HX%@f!鰘T{2g[d}a5lDꓙW鲚,$Y-B LBɅ"|G@n7~Ѳn%&{VdKB1~tW9a"4\hm mz'M ӶpS{,y.[adWcW뺢 #7!Ca >zE>,}DB{CUL&'Q K HWV=IJz)|5un)(d4Ǐ_0Yc>n,l^Ӛh\T4KG{7\=gƔB9D!ꃚmE {(\z{yjQs"B5w9cw᪟#eN1^38Xػְ: &ڀ4 i:|jm۳&#b5yEҤ;HAU%cŠ/ORXs/6}6kj].'g5&[ *tk *fЦvMG`{YF c^\rWD@:r \3|:JY*wXDF 3W(ic"8R946w hhwoqSDv+Li' 5 Y+*1T VJ(m=tBā( +şZ8ad!5컳Neh5ugy(p%l!Xi* 'a;9"׻] KI`:yA&Wru A 9^ ;Wa7}*kYn!#I=@w fZ]R>MT,$1=l@>(8o5u sB|(Q"zDhfk3I%ov뉫S(`Vh־mVi֥J:^s5ƹ t^RD JN_u_TV k!M̏w;BS+4hCmrm`P,}m4 Ykk@ֽHY´-+e}X-:MR*…!Q zkn0,w+D$ z(?lI= L`҃Fq^lZ7b݀4!WH|`A_ySwrj&"}a|h$mrl 7d۩P..z,9zHXf!2^K@s&)4}p0qտ{=tp窂ECqsILSVgN#fv X|a{ FBې|lw_}W_}#"D g[!y" X֠BX>6.;=2X]aCG[ Wqc{%[1jĩ{@Y +E5S7d>҈גDq. B/{Zy샃%!4+׽R显c:WIhtσ]K=4IQW;a#8ܬU%, 4`VдU9bspaŞY|!?AҍSE 3  2|>|?й0|mO äfl~11=3NmN 5g/iqy̴՝!6"3Z]GYHھQJu H៼rnV`ɓzpӱ ґ@Zi:Yp= ux" hWAIѷ[ӳXbV''Yʏ!})i3.5:&%ҚWIŜ$!:Ck G]mMѦ\I1qV vKe0Xɸu;ȊҿaNf+օn߿(%EJuWE _D!,by{:N2ZG|qaˤu\]|'?@sȵ}>a|ϟz"?@ J.y&G4ZK SY?ȾNP>j"j›=65s @2bK'd5(O&#_z4Qlg4#EH\FiPhEGW#lXI@)ˁrq@-(JR6ZS]3S%yʵfe`!`\~ZHՎqj+_';ˏc1{z|FvrM<D ҭr22 %~_+cXa{uxdqDp f> }/]^$Bck"g4.MRL+m]8co(rX{Tj`W-oDfeV? {,b˽<\COCl=բ fTS%jVڱxzLo.D{DJ@$)qg avVhNr/ u Ϧ6A0YUu8ugvـvпya8/s1F* eΌ#:^ZTy+Cs!\1K wdPTC|o,]8P`~GH{%P `s xHHHf7+VhU_CI՗MscS@OHC*P(XfUǝuKYƒx%ZZ([_^G$8y37ogOK9Κ|87AR T<@`7Pb?OTԖKQ665,9jMR`iOjэxW֟05+[..]A7bk8h?R k ̙5x~ b٬ǐOHLBYju|"';S1T[w1dhݖ?7bU=̓Yx5L l.Ujv-8{s9L‰Jąvɣ4O%#Ʋ/]*Ȓ\+^AE U] `X- ?|ܓX5|LoJ6[ulf 0:G10ΪS5?氱^p< )˴'ho}ػŊaf^Oa+* Y f^b=qN*[a;7ы,6vm >\7 9aMXɰ$<.\p7hbΗ(m={?a{lJeQȹJ 2mF /ƃeJ-S,hr}q\S6'uꭘI zUN>C«QH ;i2[+_ a-K߀Đ"aq0 P i0M^X;M~؉c^ig+&::{#mZB8rsgʭA57=-IweC9%2Ysf F& F]G&)[Z}q4"S?jNg86p5i=jeL ;2UAVgFCF^M^IY(S6ܖ#=uSjI4ÀA7 ù P8d=.zVس<3WaXSHeq{^~vUa,X+q@%o/3EG(=ճaS`[5ǓH]Df)>LD~*Gg?-Ugn밸}z2v:d ڟ w-_<> ":_!jT,mҊI&`rGNݐR')B/03Wa[rA8gyZrQ1סxc`E;L&%MBخCQ%ufl,CJ *I cכUI|S5{sGIvUHMhk% m71nk(1 G1-zg҇ *j"7^0⪄U60q]5hU@[^;FjGYpD5‰Ä!$\n^E9l,ꋺ 4V{@0)mhNs=bRyFrtl|3 J:ÛA,Vu,tޫ޷`?` J5^cbWfwC7W- (iqr*ZQ$aX}ڊ:^eIXrh7%`PynHUmENp|n׶a,p@iqT&ϷwD,QiC` *+UĽFÿ|K *|W6˨'mz~]pҒD-VHѶ/Çf;fon0&p|+Y} E 1Eswneϴh5@)%I9Ww,0+ aO$q/$#7 ƾ[§gW]oraz7MV-< tH>(Vc{ih<M : YZ