samba-client-libs-4.19.8+git.435.78ced6cf30d-150600.3.21.1<>,h.p9|^_6*mgОl;iWemB[`: bx_ʞis_*4Nޡ;a~>y[ukA)ƸVhtGM\ w"z' ~"b1!v{rSx q:6??5WxI+~ ` icѵH \2sntlX·A]ƪՕl} (.т03<|3'#>Cl?\d/ = T 9PV\v4v  v  v v v !v#v&v(h(v*x`dLK(u8|(9(:(>N@N+BN:FOsGOvHQ`vIS8vXSYWZZ[[<\]v]_hv^ibicjdkek fklkuk$vvldw(vxvy z XCsamba-client-libs4.19.8+git.435.78ced6cf30d150600.3.21.1Samba client librariesThe samba-libs package contains the libraries needed by samba client programs.h.s390zp35GSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxs390xH(8XXIې G(H7'gx0X wW''H7WG'GHKpx7)GW'!`GG0'W7X`y77(W`]X'7''g('7HAhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhd016606e3f46a310dcdceb136d71d64f7377f41969a7ab96352ebb61c4eff31637d85691407a9a40d4bb2d4dd35d02ea648a3747c6456d9f047fcbe0afcd2985a7240f867989b3a36476b3adcef710c75ea1d17cae60ba069603ff265928d56b22461ecb4fc5d25305df59fd2511fa0ca6bf1766fd582e1145a789329f64afc168ced71abd46248d807b1d8b35568c7f3c47e5ba2d70b572109dc202bffe7a82ee51d067e6b0338281bc61910fc70306c5b13b073e96b34e39027c0ad9fb0e781515bb02bf178329d9456db64e27e7553e3250a30dbe751874387576e20fddc82ff48c307c6fb324b4e08ac1bb038a44e17d14d4dbc5ac4061a7d3fc4524bfe1b255578470fcbd9700de85c8866aa10f750a0a157ad3361e77fc500614d7f8a1d0f7723963f2464100fd7fa131433dac6299ea2bf94c66e63208735a15da99264959d4e8a72dd8827d54e5a4e374c3761e3aaadde46ffc3545562e08fc68071f0466823bf02d674e1847ed442cd678797ffdc1986c725dadff7015736134580a83ef650865f5d8f6172e2b9695a430f66d8e778433c589aa42a6a296626e63f7c9c2d04b4d88eeb9b682c6379c810e5bab5f35b1cc049c0d61d75a6b87ac9496e11985e331e80e90869795d628252184daf907947481ac2a6d5e0f95c9f193edaee3e6b668462007a914444116e972c47169a157de6a95de01d3ccd5b6a4486b96cec588006c5d967189ea140588cb2287dc01754547036c9cb41c0125c6172c88e995a104a5e920146eb9874f117ce4a17dd8e4fa7e0b5ac4419b6793dbca9d26ec3fb844a0b3f11120f1e651789a76c63df94052444c4d2a05418143d0c2068b5465cfff93d6cf5184f8568a958b84de10d85e997e2514e4dba9e1a728ff522895a0ba38cb5b75f0b59e7bd99d43296bd0221615d9a9e0c0dc0d1d57261f6b0fd1bdb994bb0094a3aa87f7777fd35cb6e3ae95940c1f84088a0163c243c016b3bc907676f106840139acac08be86a7bf79da09a38e6b4b531c57feb6b9772ee4dd97b15f9acbbb881b30a6e89e2a909c4ccba5467a1517312cda7e722ea47a870733e335a7765038e6731045f437f9b031c054873911bd26763faf27b240d015dd45620485da328234f15818e6aff0e428e5c5d9c4a26d7f1d008047db1bf5b9e510d1f3deafa7d674d9e9db565c9c373c29ff6419f7c5afcc8282264540810b057fb1ddc4de395e9805d6acada3df025457d5b42603085365d778d9aeda8a519b73104fa0413bf533774666e0d65d7b07d3bd587fe1ee59a1461ae2af2b03b2bdb45c9678ad8894359ac2434b47f426cd25f66086c25c06ab387d314bf347b7a9cc62fca2d73ef3c044a4dbb8b4de9597209256edf820763c318b352bce8cb792cad9160aa6eb2c4d4783a28a1f65954281075610fff766b28e8f028c086a9a5cd365f5a9caadfa7219fefa0f094d045e749b0f811d5efd5df2ca840857f3a32ef18f2af52a2cb8384ee83c1d9798d512562963e8e260f892e03f16423a9a07f26db392beb9cd6e9e5154c29c461cb5c817ea7de9238b3755dcf1704a607c6619bf5b4d0ddf816bbbe91e03084728b84bfaaf4bccc058727f0d71d09fd34b72ab41c4ffe0a75178aec90d6f3ef3113d73390fe187b0b7a62eaebb1ba46aa65fa1b670fc6d1db9f8bc2901222f88d38139a04e5f69c5b8c8b7df288d98e49a88ed0de0783a595ffb14af20ace681778c257f7196cb749fea2aab11ccd2175b8839fdc0161b536ee0be81dd575628d6e953b9628312af03d45ca77b4aa9099d8d43b166ca978d2225bf3c5b89812c6080d587c532de31454e364f3d7071c948e02656c8947355455751ae3854a6a557a6ac880ba73be0666e2e4f096710ada57f0e8ec18c85817ed1808f40e085765dbec1722652c2147f20715dc945115c7ba56590b0b2cd04057c26d41fd727e8cbc10a09d24560d2beaff10d8e26072177c1b7fdb0d8556409f916cd7099c77bd205bafba5d7d45f3985bd54052a359280ccc45e7eef93a114b5fdaee842d67c522b4ec5f5b87d2254e1bdb78282e7db11f0a7d0165da945122d4f8405aa13a4576b23f45755a70bf89a7945ffdf8f812c919cd9ee47c926e1a1dc74f8bdc84110e74bc70aa6dd897698c618beeddb107130313c3878ffed72302d2c840ce161aef3221d20f45105419d9455d8ebdd7ec9d255a7008cb6ea9428ad7237d3040bb4181cc8f47bff6fe97e74977aa6335aedead22adc9dfe2e25ed48d1de88d0d5ad51a88e0bfb99c612e416433c7acab83214d72098e5043a9afe8ac644efb44d2508410e31ebf06d63ba290bcfa9338cbe6809eb3c1284365da0fd2212c667097167dc22d8474bec856133ddbb23ed4f7f210264c96985d028130ecb55d1edb01dc6c60e2c6a5917b025a3784a1422ff2744b9ade5a9b3b382a92582698afca38bf7d1b89dc3c2e0e72a12855943cc90e80fd0773c63de5ef78ff73d45ceee98dc02de85a09f2235720b009ee4ee12bb7fb5d4fcf5e4a2517d5975c17ff2246a71f07cc170a266944e1896aff550d9357100a00ea03f40babcb18252e582d0dfef593d67f6eabf42d4be1e6dd3062ca2fc8c2e7989dc137a4dffce2a2035a4e78182785a913514a0e10bba8b2cb04b8a47045c8c88a81f47ce061bdcdeb6b8b38f41e6b0e733784dfcccba97939ac3d65213b3fc3a2e4a924cdb9134a463f8eaced7290165de73c465dc38384e37d0dde08baa8d0585ce5b81207c033c563f00c3c474affd4a587194e4331281628723fa2843f637ba98ab2a984644ca7f685cf00c0d959167eb5d91a912412aa022d78f991ae5203e8e03a70f6cb004683811b2533d8db22d1964703f8f6859ecdb3d947565647983d0525b5e16071328ab327c5920bcf3344e4f15ef7cfd827775a0541742ca0ad81804e02447e1270b51d852910385d78f9a2fc64f1b5282e063d3f1f10a1d1a4c9d55ae1baf3c3a8e4d3cd7b7b6d92e2e48d2ed228d69d035d7610e6079f48ad1e3a17ef6b1aa0f987e53eddf07644c9d0c56f2971d005aa7d70fe1029dff0b4a3bfb00ea013fe7d3e3e09ecc8afb2c3de191d51381abdb7361625363b8858a5cbb1aa4fb3576a9fdc34325a8714fedb769e947e86cdcd95b6004a118735015b2d9a8c5468f88795560fac32e2beb9dc6bb5e244e7a9875ca011a3375bbf9dad615a83ae1f178672977ae48244dc5010812241ba3f5ce815c76b5c76d06e42c2fe10f58d2a9275aba740d4896abd8e1e8a3519901a2fbd1cbe13882f0800afefee71b8b9eeeb314e109a1a8c7936232ff604c4a8591711547e8aeb329662eb82f0154b72d2e52eaa2d172bee9a7f77ecf79a9cd0028f0dfc4b36894b5a9451b428f6ef1924737b870234d1f4e2f9ac5a2ea908e434cf877de172a9dec8009550edcf22cbc0caa1b91188de1d6851d3a699d0b52192d0ae8324155be1290cb95db7b9a4e5aadc4d516606f330ac0826673bf37f239fbb3bd106c279c05d0669038bbfa61d58f6076b4a1e0970615b0c0b6fda98ae33d9b124043c9402dd974bcff98cce4555680d1031d646ffc3ec4ca06507c3f30e4512f37b4338ed3a6d3a5154380a541d7ef5c40cee93b5bdeb852db797867fb2ac83cffcf22ee8fe9ba0ec36982a28b7309e928a94e0927f33f3f69cb6044073516a9cf04909984e4bc03a1733f32b181c5a2a2143c0b9f6b44a14c71174e869ad5642ffbc665d527b129ff853bbfce35a316578a8c33b83c66e70a854917c5a3dd10993bcee8f0d43659aecf9ff8ea775fa282952de4921095dd7d746774e3b257efb4c09f76b993d6607af93ae8ddc8134754aac9f05497232c03617fbe4720301d3b6a1c0cb7a48239e5a6fd1fab621af63950b8d490c6c65bc6a2589a5727851382f533658b12e9acaadce1174ed0b958c2a5d5452feb89818ed46f2f915f97fed41e03780485895203bfce945cb77e66205e728e30d1bf2a529d4fd352f93d61561553ba0904cd1ef09da1a6efefb748113abdae690db1699ac9f2762fb9041a7d10c7ad465883e2f01dcbda467a79c713607205c197eb9ba6cb0191655ef925d1837d7f3443c1e58013fb8508a8e867b3199254a640bcca6004c1f29f403c071e63321c45e28d08355edf2f388b661ba8b791fac9bf7cc9c58922776eb307cea3b86218f3f3b79128935d07f7511b662d83acb639dab45c697a1c9bc1153b09a9d9286edb1f3e3c039a4f5f5de34a42a54a80b42121b8c077f47e4b428da122d25196202b144291a9f314f37efdb0f8c059d580190c541d312c92471d55aaf9676ddb56e7f93b51e42cc877992fa487468e46583635b3c767764703bae33c32c663ed21fe890d425a96156cc419e341d83fa85d399090f0246ecc06ec607c1329d0f101libdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0.0.1libdcerpc.so.0.0.1libndr-krb5pac.so.0.0.1libndr-nbt.so.0.0.1libndr-standard.so.0.0.1libndr.so.3.0.1libnetapi.so.1.0.0libsamba-credentials.so.1.0.0libsamba-errors.so.1.0.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0.28.0libsamba-util.so.0.0.1libsamdb.so.0.0.1libsmbclient.so.0.7.0libsmbconf.so.0.0.1libsmbldap.so.2.1.0libtevent-util.so.0.0.1libwbclient.so.0.16rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.435.78ced6cf30d-150600.3.21.1.src.rpmlibCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-binding0libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdcerpc0libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgpo-samba4.so()(64bit)libgpo-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmscat-samba4.so()(64bit)libmscat-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-krb5pac0libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-nbt0libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr-standard0libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.2)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.0)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.0)(64bit)libndr.so.3(NDR_3.0.1)(64bit)libndr2libnet-keytab-samba4.so()(64bit)libnet-keytab-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetapi0libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libprinting-migrate-samba4.so()(64bit)libprinting-migrate-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-credentials1libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-errors0libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-hostconfig0libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.25.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.26.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.28.0)(64bit)libsamba-passdb0libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba-util0libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsamdb0libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.4.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.7.0)(64bit)libsmbclient0libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbconf0libsmbd-base-samba4.so()(64bit)libsmbd-base-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldap.so.2(SMBLDAP_2)(64bit)libsmbldap.so.2(SMBLDAP_2.1.0)(64bit)libsmbldap2libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libstable-sort-samba4.so()(64bit)libstable-sort-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent-util0libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.11)(64bit)libwbclient.so.0(WBCLIENT_0.12)(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.14)(64bit)libwbclient.so.0(WBCLIENT_0.15)(64bit)libwbclient.so.0(WBCLIENT_0.16)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libwbclient0samba-client-libssamba-client-libs(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld64.so.1()(64bit)ld64.so.1(GLIBC_2.3)(64bit)libCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libacl.so.1()(64bit)libacl.so.1(ACL_1.0)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libavahi-client.so.3()(64bit)libavahi-common.so.3()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.3)(64bit)libc.so.6(GLIBC_2.2.4)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.5)(64bit)libc.so.6(GLIBC_2.6)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_10)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_1.1.1)(64bit)libldb.so.2(LDB_1.1.19)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.3.0)(64bit)libldb.so.2(LDB_2.6.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.1)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libnscd.so.1()(64bit)libnscd.so.1(LIBNSCD_1.0)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libstable-sort-samba4.so()(64bit)libstable-sort-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtasn1.so.6()(64bit)libtasn1.so.6(LIBTASN1_0_3)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.2.2)(64bit)libtdb.so.1(TDB_1.2.5)(64bit)libtdb.so.1(TDB_1.3.0)(64bit)libtdb.so.1(TDB_1.3.11)(64bit)libtdb.so.1(TDB_1.3.17)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libz.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3hҋhm@g`@gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%anopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2025-9640: fix vfs_streams_xattr uninitialized memory write; (bsc#1251279);(bso#15885). - CVE-2025-10230: fix command Injection in WINS Server Hook Script; (bsc#1251280);(bso#15903).- Windows security hardening locks out schannel'ed netlogon dc calls like netr_DsRGetDCName; (bsc#1246431); (bso#15876).- Fix Samba printers reporting invalid sid during print jobs; (bsc#1234210); (bso#15792).- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfiglibdcerpc-binding0libdcerpc0libndr-krb5pac0libndr-nbt0libndr-standard0libndr0libndr1libndr2libnetapi0libsamba-credentials0libsamba-credentials1libsamba-errors0libsamba-hostconfig0libsamba-passdb0libsamba-util0libsamdb0libsmbclient0libsmbconf0libsmbldap0libsmbldap2libtevent-util0libwbclient0s390zp35 1760090414  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuv4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d-150600.3.21.14.19.8+git.435.78ced6cf30d-150600.3.21.14.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30dlibdcerpc-binding.so.0libdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0libdcerpc-server-core.so.0.0.1libdcerpc.so.0libdcerpc.so.0.0.1libndr-krb5pac.so.0libndr-krb5pac.so.0.0.1libndr-nbt.so.0libndr-nbt.so.0.0.1libndr-standard.so.0libndr-standard.so.0.0.1libndr.so.3libndr.so.3.0.1libnetapi.so.1libnetapi.so.1.0.0libsamba-credentials.so.1libsamba-credentials.so.1.0.0libsamba-errors.so.1libsamba-errors.so.1.0.0libsamba-hostconfig.so.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0libsamba-passdb.so.0.28.0libsamba-util.so.0libsamba-util.so.0.0.1libsamdb.so.0libsamdb.so.0.0.1libsmbclient.so.0libsmbclient.so.0.7.0libsmbconf.so.0libsmbconf.so.0.0.1libsmbldap.so.2libsmbldap.so.2.1.0libtevent-util.so.0libtevent-util.so.0.0.1libwbclient.so.0libwbclient.so.0.16libCHARSET3-samba4.solibMESSAGING-SEND-samba4.solibMESSAGING-samba4.solibaddns-samba4.solibads-samba4.solibasn1util-samba4.solibauth-samba4.solibauthkrb5-samba4.solibcli-cldap-samba4.solibcli-ldap-common-samba4.solibcli-ldap-samba4.solibcli-nbt-samba4.solibcli-smb-common-samba4.solibcli-spoolss-samba4.solibcliauth-samba4.solibclidns-samba4.solibcluster-samba4.solibcmdline-contexts-samba4.solibcmdline-samba4.solibcommon-auth-samba4.solibdbwrap-samba4.solibdcerpc-pkt-auth-samba4.solibdcerpc-samba-samba4.solibdcerpc-samba4.solibevents-samba4.solibflag-mapping-samba4.solibgenrand-samba4.solibgensec-samba4.solibgpo-samba4.solibgse-samba4.solibhttp-samba4.solibinterfaces-samba4.solibiov-buf-samba4.solibkrb5samba-samba4.solibldbsamba-samba4.soliblibcli-lsa3-samba4.soliblibcli-netlogon3-samba4.soliblibsmb-samba4.solibmessages-dgm-samba4.solibmessages-util-samba4.solibmscat-samba4.solibmsghdr-samba4.solibmsrpc3-samba4.solibndr-samba-samba4.solibndr-samba4.solibnet-keytab-samba4.solibnetif-samba4.solibnpa-tstream-samba4.solibprinting-migrate-samba4.solibregistry-samba4.solibreplace-samba4.solibsamba-cluster-support-samba4.solibsamba-debug-samba4.solibsamba-modules-samba4.solibsamba-security-samba4.solibsamba-sockets-samba4.solibsamba3-util-samba4.solibsamdb-common-samba4.solibsecrets3-samba4.solibserver-id-db-samba4.solibserver-role-samba4.solibsmb-transport-samba4.solibsmbclient-raw-samba4.solibsmbd-base-samba4.solibsmbd-shim-samba4.solibsmbldaphelper-samba4.solibsocket-blocking-samba4.solibstable-sort-samba4.solibsys-rw-samba4.solibtalloc-report-printf-samba4.solibtdb-wrap-samba4.solibtime-basic-samba4.solibtrusts-util-samba4.solibutil-reg-samba4.solibutil-setid-samba4.solibutil-tdb-samba4.sopdbldapsam.sosmbpasswd.sotdbsam.so/usr/lib64//usr/lib64/samba//usr/lib64/samba/pdb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:41070/SUSE_SLE-15-SP6_Update/5add5f7dce01a5b57b4b9abf50b932e5-samba.SUSE_SLE-15-SP6_Updatedrpmxz5s390x-suse-linux  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b8ee51b60204698f6b997b0a2c117d6dc32df493, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b287073ee9b321d93a96d279cd9cca1a2d136b04, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=503d826924c7531b35fd8b611bdfb98e5f758342, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=5fbf85a1238748d07bd242e2411f2ac56a2712e0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=afd074d524351849abb68c40506d7bd2396fe001, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7388fe6930bd4e12d0ef24043d6ce8943734c9b2, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=96f258eefbb81ebe5e34b15be4398a51c5477a71, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=20ea15ae2734614f5270f49f0e3c812c1e4608a7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7551a1652ac6a808c947133ab1c5cb33b638022d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=431b543901b21b24135621433b44903192bd4a7b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=239d97f040dde26ff4749d4fb8eacd2e931f1acd, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f9a7bd93a6a50e8609c674223790281f6c2a507e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b55dd88ab038de5475fc98e95d72f1e69adc6fc9, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f406b01558c6880d506f203cbca436b63df40ce9, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d081049c5e9846be9c80b94b28bd318d9687afa9, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=114b6482d07bbb2d1a86147c011f4640b27bb499, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=27f89af25e1daa7ec1af67412492ecb5c86a96a8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=729f9ffea0f896649788ff71c3e46e74b5fbd6f6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=557dcc824ea38020ddb12fbf73d1108aee44c019, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=871ec541355c3cac4b320a9294aac77146e2da5a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4a71f6481aaeae635583e4c3f4b3f73265c8779d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b0c4177bc8c27e130a7ab42c4a6e8e0820e78f97, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=69e63cc39d80ec6741a0f85c6e143c9a78a15c15, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ce413f835f333cbc1d06506c1c21df11c3a8ed5f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=08ccef6c8151263abcfee41d271975cade356f07, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=73627435d9a8e8efcae5862e2b72068256ed2dbe, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=3186dbefc671fce5289f9c3f9d008940b7fb994b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7b1f7fdd28bd9dee22a18486234f06d5a2bf7f35, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6b189c7a3459a5fa14a6eb78aa2cb113e5bc2544, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ae5df82438dca3af284c30c01554ba858b163926, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=17604b1d0fb23f42baf40c39f47e99dc376a2b70, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=5655ebdbfa1960ccff6b15091c3ffb0434b372f0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f50885817786bb7b91622b545a1276eb7dee65a3, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9229c0ab22fac631bfdf42b61e309fb57264703c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=5ba11888bbcb215ca270de2fe01e8c9901f72ebe, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ec8a2abff648cf3a0a6cf8453d7f0ccc28d31e1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d5f013a9363968c4767e12c7f5ee4181804b743d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6d2a96157d5baf6cc32f84b52584f7ca167bdce6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=151ecf97513f19ef2b6697b1e18b36b72adee579, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=12dcbe0edc1f2ac7880e088c68e3667bdb836711, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=67b133def286f89a6e61161a9219d662a1f01c09, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2cc1d9911606d8e1904fad5fa8b1611b291a6b91, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=286a3e2837940b2a41dfa98f9602739403d27052, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c9829a45690aac9a5a2f12b203cd4e442c360cd6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f7b7c24918260a2c7ba43ff76359fdbf534d85a1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=42460960b4b128950e3f91543547a97bc8e3f529, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8f1d1269c97102aac8a24d09453fd01679eb6b16, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=3234bfd4357314e16ffc5384c76e28c6243f9cb4, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=550234e79fb3a6f7cec28ecafb58ed1a2870e489, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=20bdc9849a580c1f51baff0c9229af000c7ed0d8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b465636b89796fc8b2687db8fecf4ce4b18029c5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=0c2a1b172e25b199dd4f32175b8f0c6a8c4e9336, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1098135b079c9e5a08db925b810795134af30b31, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c7301805f63a8a72e79b91e0dcb7b515b7bc3cfb, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e05cd208f96e5e0d0517dee0e1107edc05671fd7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b85743fb886c295cf02db4475469318374a45ff1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=229a1b65bc7a702dc43a8e25bf4b90b3c7ae0e56, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=0e5199eafd2f46f1fa83d401eb1e12502be1853b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=52847225f98317211df4cd5702c86c849baaf73a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=5adfacc0fb1023efe9fdd23a70f3aa65373287ff, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d74a44be7304e4686578e9537554dc1860a5f06b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6e39c8959e32d4a94eb77a2fa8198014831f5c83, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=abfe2ee836cf2fca93b3e97948b68504f70ff82d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=caea7ae618603e891a90099aabdd4a399840d1e3, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a461b80b9ce73e7907dd0605645997ec89c2dfb0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f0a408f907fc1ce807c2d59c3d06d4ed7e085e37, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6bf59ad420a30375d72c96b0bc55c94d5176ecd0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e354ff81741dbfe7914ef00353fc05b5b2dab84c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=3ad03970b8c56707574263464f9250521b9d033c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=5e463697def5764639ab0ccde54969a704f3751e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=71f93a0c9064fbd2f2e728607403289096887be8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8f6f618cda241c98ec1576b89622b363dca6e1b8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c9eb8a5c095467d9e231323d70e1879997542ae1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a88506387b0e175a17f65d5b5c72ab5f8db3b5c9, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=00a1f00952b3ae8504ff78d991f93a05172cda3f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=0cb24da6457e30dd54293f474fccbe563055cc52, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f6aa0c72025244a5f1b772b5988c3c594df9a7e8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=11d8273ab49d4398ee41a9da1ab1d467bc2e3266, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f720329b814ae23f3e2694abfbe8b7b05ea69ce5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9a73471a22ea2f1dc3ad6d9d81b76c305bfbf6b8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=3a4e2ffdc4698d38dab73a2cde0f54203e52d06b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c598d29b8db8e1fd2703f802dc6d20adbee3f578, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1620e41bca419317db910271809e8d9440308863, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9e35aaead92db7b296e19e25efbf7a925b550f3f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=dce76ffec42721d4d538a63822f0c9f5bfd2d1a1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=64c946f44b34ecd9ebef12dbe71d884963c8e374, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9073c43004364993d45c813e47d8ac1db746b755, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=3a7f1d1af6af57f0562c8f49fe9f328e539990a1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8628213dd25c3ac3bbb1fc39c321de55f6f237fd, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=cf95a025f5a6c1cfc4c2afc104adc0314e6e8616, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=954378f1e2e06e8ece31785f436bc6d69dbc5d29, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=3d87b1cfafba8b3075494646b6c878aad4c5907f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9d32eb6428d529c98669d3cdc925f61b29d7c7fb, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9bc325cc9a3ec494541763f4b787c49251757473, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7646ce095826a40ad6046f72034eb45bb3bdf60a, strippeddirectoryELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9fe0ef9b74231d6a1f1a756feb4130e1f1fda9e9, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=47597ccef6042f53fe3500a64723327f65db5439, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8503358764537041a0f0274a28b8df4cb24bf7db, stripped"JIy:/<Ox/X} +Ogt| W~3Fg%Abz . F d z +   " + O j"(B7C0 G%2Lc )?I)%2+ $  ;'= 0!:!G!"(3*.  $P+P*RRRMRRRRRRRR'R&R*RRRRRRRRRRRRRRRRLRRRP4P3RRRERRMRRRRRRRR%R'RRCRRRORRRRRDRBRRRRNRRRLRRRRRRP6P5RRERRRRRRR0RMRRRR&R*R'RRR,RRRR8RRRRRORR4RRRRZRGRCRRDRBRRRRR3RRRR7RRRRYRNRFRR+RRRRLR/RRRP_P^RRRRRR'RRRRRRRRRRRRRRRRR RPbPaRRRR R'RRRRRRRRRRRPiPhRRR'RRRRRRRRRRRRRRRRRRPlPmPmPnPnPoPoPpPpPqPqPrPrPsPsPtPtPuPuPvPvPwPwPxPxPyPyPzPzP{P{P|P|P}P}P~P~PPkRMRRRR*R'RRRRRRRRLRRPPRKR4RRRRQRSRwRuRRRRMR8RVRRR&R'RRRRRRyRRGRRRRRRRRRRvRRRRRRRRFRRRR7RtRRJRRxRRRURRRLRR3RRPRPPRRQRRRRRARMRR8RsRRRXRhRRRdR R&R'R"RRbRRRrR@RRRRcRRRRR7RRLRaR=RRWRPRgRPPRRR'RRRRPPRRRRMRRR'R&R RRRRQRRRRRRRLRRRPRPPPPPPPPPPPPPPPPPRRRRRRRR RR8RRMRR*R&R'RR R RRARRRRRRRRRR RRRR7RRRR@RRRRRRRRLRRRRRRRPPRRRRRRRRRMRRR$R'R&R R*R!RR%R"R#RRRQRLRRRRRRPRRRRPPRRR7RtRRRRRRRRRRRNRRR RRRURRRLRRRRRRRPPR`RRRRMRRRR'RRR?RdRRRXRRRbRQRR>RRcRRRRRRRLRaR_R=RRRWRPRPPRhRRRRRRRRRRRRRRR'RR.RRRRRRRRRRRR-RRgRRRPPRRR'RRRhRRRRRRRRRRRRRRRgRPPRRhRRRRRRR2RRRRR.R R'R&R%RRORRRRRRRRR RR1RRNRR-RRRRRRRRRRRRgRPPRRRRRRRRRRR&R'RRRRRRRRRRRPPRORRRRRRMRRRRRQR'R"RRRRRRRRR^RRRRRRRNRR]RRRRLRRRRRPRPPRORRRRRRRRGRR'RR&RRRRRNRFRRRRRRRRRRRPPRRRRRMRQRR RR&R'RRRARRRRRRRR@RRRRRRRRLRRRPRPPRRRRRMRRRRR'RRRRRRRRRLRRRP!P RRRARR'RRRR@RRP#P"RRRRRRP%P$RRRMRRRR%R'RRRRRRRRRRRLRRRP'P&RRRRR'RRRRRRRRRRRRRRRRRRP)P(RMRRRRRRRRRR$R'RR RRRRRRRRRRLRRRRRP.P-ROR'RRRCRRRNRBRRRRP0P/RR'RRRRRRRCRRRRBRRRRRRP2P1RRR'RRRRRRCRRRBRRRRP9P8RRRRRRP;P:RRRRP=PRRRdR?RRRR RRMRRXR"R'RRRRRR8RRRRQRRRRRRRRRRRRRRRR RRRR7RR>RcRRRLR=RRRWRPR RPAP@RRVRRRRRRRR$R&R'RRRRRyRRRRRRRRRRRRRRxRRURRRRPCPBRRRRRRR R2RRRRMRRR'R&R*R"RRRXRdRRR,RRRRORRbRRRRRcR RRRRNRR+RRRRRRRRLR1RfRaR=RRRWRPEPDRR:RRRRRRRORRR'R&RRRRNR9RRRRRRRRRRPGPFRRRR&R R'RRRRRPIPHRRRRPKPJRRMRR'R"RRRR`RbRXRRRLRRRWRaR_R=RPMPLRRRMRRRRR*R'R&R RR"RRRRRRRmRlRoRqRiRnRhRRRRRRRRRRRRRLRRRRRRgRPOPNRRRR'RRRRRGRRFRRRRRRPQPPRRR4RRMRRR8R'RRRRRRRRRRRR7RRRRRRRLR3RRPSPRRdRQRRRRRRR8RRMRR&R'RRRORRRRRRVRRRRRRR4RRRRURcRR3RRRNRR7RRRRRRRLRRR=RRRPRPUPTRR^RMRRRRRRRRRRR%R#R&R"R'RR!RRLR~RRRR]RRRRPWPVRRRRPYPXRRR'RR$RRQRRRRRRPRP[PZR^RR]RP]P\R?RR RRRARVRRRRR4RMRRRRRyRR&R'RRRRRRORRRRRRGR8RCRRRRRBRxR@RRRURRRRR7RRRRRNRFRRRR3RRRLRRR>RRRPePdR'R&RR*RRRRRRRRRRRRRRRRRRRRRRPgPfRRRRRR'RRRRRRRRRRRRRRRRRRRRRRRRRPPRR'RRRMRdRRVRRRbRcRRRURRLRRRaR=RPPRRR&R'RRRRR\R[RRRRRRPPRRRRRMR'RRRRRRRRRRRRRRRRRLRRRPPRRRRRRRRGR'R RRR6RRRRR5RRFRRRRRRRRRRRRPPRIRRRRRRMRRRsRGR*R'R&RR RRRhRRRRrRRHRFRRRRRRLRRRRgRRPPR&R'RRPPRRRRRRRR&R'RRRRRRRRRRPPRRRRRR R*R$R%R'R&RRRRRRPPRRRRR'RR%RRRRRPPRMRRRR R&R'RRRRRRRRRRRRRLRRPPR\RMRRRRRRR^RRRR R&R'RRRR[RRRR]RRLRRRPPRMRRRRRR R%R'R&RRRRRRLRRRRPPRRR.RRRMRRRRRRRR&R'R RRjRkRpRiRhRRKRRRRRRRJRRRR-RRRRRRRRRLRRRgRRPPRRRRRMRRRR&R'R*RRRARRbRdRRRR RR@RRRcRRRRRRRRRLRRRaR=RPPRRR RR'RRRRRRRRPPRRRRPPRRRR^RRRR'RRRR]RRRPPRRRRRMRQRORRRR&R'RRRRRRRRR8R4RRRRRRRRRR3RRRNRRR7RRLRRPRRPPRRR?RuRRR8RRdR}RR RRMRR{RORVR6RTRQRR^RRRRRRRRRyRR4RRRRRRRRRRRGRRRRRRR RRRRARRRRRRRRRRR*R"RR)R R'R%R&RRR|R5RxRR@RRRRcRRzRRRRRRRRR]RRRRRRNRFRRUR3R7RRRRLRRRRRRRR>RtRR R=RRRPRRRPPRRPPRRRRR'RR*RRRRRRRRRRRRRRRRfRPPRRPPRRRRPPR^R'RR]RPPRR'RR$RRPPRRRR*R'RRRRRRRPPR'RRPPRRRR'RRRMRRRR RRCRRRRRRRRBRRRRLRRPPRR'RRRRRPPRRPPRR'RRRRRRRRRMRRR&R'R*RRR8RRRRRRRRRRR7RRRRRRRLRRRRfReRRRRRRRMRRRR&R'R R$R"RRRRRRRLRRRRRRRRRRMR&R'R*RRRR RRARRRRRR@RRRRRRRLRRRRR/B{a|FGSbutf-871ad5784ecdabffc3c4a58960033638bf407bb6762c3ea2b8fe6ae3b85d8366d?7zXZ !t/]"k%~2_e#Ȅj((KF;&H$ׅy%Wr)l2 v#['/AV`ލb3u9[kQÎψm\]Z#8a85E/0 8] UʐtU=qR &+ĪVvu4%l)/йf/=;؉tuAG+eO09U6!!]P%#e -\mSi83X4(% Z'Q!S4HGJhb'm^LV^ҘZڲT x!F CNT㺲jQڼS{+"(yB]Z!]{f8- |m8#Nj2~d1U;(]>>VX=mcS#yLNXfGw0['f.]ʼۢqh=9B?];"h+^f4MDg*c-h?xhBv3W?6-N͢E ~+ʼ[*ň@,lEB. `ɾ4>J|wyDw%aOZ=5́|8 9GM׎¿v-?o85K! "FVzr)-:@eY%Y=Hm;}m-G%LrrIMIEAk[Y'®V~kMBZ=ڕs!-Z^}BHO-&yjeX^޳AS ,|-:BG:'EN:sXmR4rE")Z>a v8^k0g+\ 8s}m"IP6祐hЭ$)Mg;0XtDRb%w3bN_gAz$5\bh3ůl?]Jv;{G'2RSJY dRd{]Ti!M˕:t3Č?1 Eu}2'9щZ%ί6wN"д>r:E/>y f:Z9^RW31JbUt3ESU jZO;p 2XchOa\wPim\=3o D';Z2r\h_{W9آ @8XAc\{jFɵ͛xۉU $xՌd, (/l (<<{̹U{P鰟5r;d=eV)e!UFI3Fˬm~gݔТ׉0gKH˧KS!Kߩ86LIh^~?ESӈ\lIfD$qaʌS*9XHB NS } »vc܉TIz׫& ]?׿@No@c $|Sӱ,% (KB'&ȫ/͟Vؗd:61.$Wt`2hn)8#11rs0%v&N7B3KgHKt, ݜ}hA7 4JoĞg=. !ݹTuxnbpUeU7U=ov-Gh 0gÐsל> =~'KQXTV\Q?2HԫVc;2rȽx'Y[y(y$c) ,-p#mT Ҡ(0K'F[.fZƈ('K?ڸ/,Y\`3|Nݮv-CdU41Z D q' n Pf$260 daHvEob=k84reX9EDSsi U _&Nm*zZ8 j  /zAa'O&=|T:)s22m*ZWKYl,!",[g9]7Q,qYa~qx7ˤ`GA9ĮdV]Hڙo;J))PoX=zA4C" Y.#X ¸:x6ux/'lÌfa1wLڟɜ^_9<jih՛#6w=R0PdEs1y!9`{.k o@ܖ !џ4"禛V=XqJ|2x}/aLŕe]4.9!@Ic颁2HȯXtί0O_J]Zg bR@XW5b,Oh>2P0wnɩc(xO] ͅ]_dc )4eBf |7&yNfoM B;#G?ƲՒҎ|J_eN5~gO*vEd9sM,,dU0nc"ٓzݞm{gbjVy/D"Pu + )gzßaޅӹnE_@ъ^!eWj$]Pou3&;F&,s+# bڕۙ\l8`56e^\KARYبA0:$+ P8Pmn=\ޡxq"ym2`7 *vvIM.L ͥo,?. E7էSͧ´[s?ہ^O TT! 7`g#\. 1,-d6:;[qseeP\@"Aib`F '^^ONs؃4kh;TG#W7d×(Η2LѰ{x-,[Itꯦ{8r3lwhW3n`yOۡ|F[= rXl˟!$G{MCo%- 0>#vq^>Pg+/@hŊZ}޳KiekSd)|놮Y2V;o}^?ܟNg݇Đϲ&S|VšRl'G6M~H?~uû0phϤA< 31AbN܊qxw08J|TE49Njc|SÁcq" M}!X A[ YF@r-'vK$KE ҵZ}.hE0/0T_T.Ϻ:\eLd@*‚C#j)X<Ƈi4^ SՌ{29:籇JT|y3lg3 5 z&,hG E:km󪤅z^% !I&4ZaxƢΡs*Dμ~rSL߬K\P 7oҁrk6Q:v4R"Y^(1~^yAM pgA1wKtY9;?7i}h0wn8pIiOgnB[o)k=8 e/ڥ}9~ WSDo\ b l`s'w}ͻ=/ng/M"C^?^j2x%l.[T=ķ@kOJPL/;&&@wmZ8K=0:J<ЅfX !+FȬS UQ Y.l9GFF)xi"ܫWnUWܖ[o;J%CxnH<-:z{´/!rF8yݢz88ޭj/T]an+"Zrƌ@, U8%]#UW~4uVJBy62DحOگ鋥k1!Y[Nti~XTgCBv#%Z)#%TI99 * 8WpMqO `]JV@p ^Ys ]Ӯ[a=! n1M]OUn F+ "5tb Tt=ұj,oN[j  b3r 2 w_s[Q▕D> %T&x, Lp3D0' ?)3^ߣ16X*qʼnһY ֠8 Y?NjXj׭ 7'sY . YOJDJbԚ /o%2ӞJp'S[lbYCk]I=$c&I}l4NXT8A=<ލUfs謘 }~u> 8>ŗa.> lS7[pRM}L  #*E=9BFZ-U)%5`V=pRDj sQѲ%ObLp?swHs(y#gp9{? Lo:Z! 2=r}ZSi㗟Ԭ~ÈG3Ib RuσF#ܔbUhUy d?z40u&r V.@[[zĐ*}*!z?+'u}=z)+s&+=/>;X e# 70#{1XNV -(wݲC q`ִD'n*`yT9B05'Y|JdjUfգ@֮iXC ]q;iҷLƭPʐRb*J'T 4+Ց3J~.H }a| c=Z?%I/ce024Qœr W{U,UDU2j|}(Iy}8Q+ަ"YfN 3B85;et,É4NO7ވd+LW-gi (S:Dj:bc\uAB*%IN [ DU7)e)mGw(O{lVz$)̺2㬲v#NJrTLJ=EJ+q**b؍{"CukӆV>1?ʮ9QZ`_{>!bceFz!K٭1s~N.TAf _=PuU*J?|40T՛~K{黏MR ].5 m\J[&ݾ@3C@ZO)LZ dbMp4f ":nNPaQ(y.\h=ETEq b[܈5&]VQPjJLnR`ߛzV>Y2Z:K%>2e}N9-U4#kDxƃ1(Jѭ\,͆m\^z,yRKaa15nI6Zߖ,<>FY3%6 <)Aj:i-45=- c̍>*x֕;mȲC&܉tʥ Ya_'n['?2P,beDs@^ɀ-*!=ΨR-K q .bR8VcuE{m' qNhmٱ%|[k[D&ij625'K?a`1-txX1qx[.yHI夔!]B{sz?aNM.,q==\f!I“(k¾.3yi ,!UFA zd+Y*ҤެchĶ}LK}y^lב<ُD:e PhRA MԢ*(%140jf=Ǖ3Ζ9rb\jPx" `)~Mt#C~]_؇wd4ŪH[xF_?p^Nq} ER3*iB=dQ7~\(*lQʂc/ #ę/1)&| Lv`5˗Hl>(a)de9Zr2 qÒUŌЙDus-%XUUP혌evӈ5LO˿w.kq8`>%8/.~I\pU#@@KC1r cQ0ɫApC% )J,>Q4K9Eh(cF 6N60sN+`+ $ J6 ƿ;X-RAf6)^3F* 3?HFuCT45FNR@qfLy2dRs\HD]"aϙ~Q/@ +F{b )HeF 1*'Y{SŖWGb8蚾p0-Խغ<`!76v|PHI(ϼh(=&UGZAY:=GАH'Yb7f:;t}9(vث#Ycs,y;:0y p~ p~Yǔ'ɰ}i>\ G[MOF?2E[X}@"shtQE\b̥jIG_:d RTdQ1^F qw߯Hv 楇oC+|&CѲ]XMeNZi )JЅ3ZOُ@Gh0%wVՐ>C}އxO1| ۵`XXMqê4SX_Ao`yOܰ{k:&V?U6AFfAN8RK_kKs14IAh e<`lo>:Rf&7HJ< "|߆H1+פȣXp7o׳Ggˇc E |>6T]$`_{bq1vp4l[$wᢋv[ŗh+w%'E~J;mX3zyWb gZ@PrTϲJXs*7-Z?rde&ю#x(%pg6y>T uVo"OhJ>rpxZL|aWg0v|*dU MXUOQIyO=_6t}s/z llb˨L" f G=qoghi]B;~81;.X^Hy2f~4ݒsʵ5g? ^В7nh;2!đ``̱%T~t~`˜lEw$cJe s7|I×ѷoB ^YfK㋮RolK(ĥr)CNoQ;(539&a-u.*dѻ,hJ=^΄49;ŭ7:e;0gUǔvX֗2iGʼnXQކ % `O.fcDeRsk#*B&7kcGD̯YM!f6Kޯ<+V9?Esmw5dhWvh鳷O+R;=ŴGKWU%}@+$en? ݰ& nE!W4VXKԧ]O&Cxv H PzXQA'QJrRa#ӗBp xTbl_?x96SޮPMj5PI\[?} V2͜6-Л, Bɔh,yQ@x}NN*L^&0>}|슶7Pf@yV8^?)u 髃kK=נL$ D(r {daik%g#,< b!HuqKkp8cw`(/Z^9Hcs5m0&Q#n$ttl}\ DB:^6+wqk絶hDOjP]6!r敎tnnpdp/ݜzNo^s tSaT/f>_jE%F68Ѫbn|`Vy |<_W]`I)&׫o}m}G٢l V%ſirVt V3[vYF0&<VKQnJ?ZV%LǛd1h|jg(Pi7.A:X9-ugTnB3 Vs;>U?ξ'soomF֪n$5کד/@bdwRp% Ǭ"Σ|xT^!pٛ  JU#L2^(Տ I qSA>$?- &G:՘M:VQ(88rfbnؼ֘}}STBY)$Ofi4~>Sj1L:`8SgRm)[!X4ԟbC_9 KT  n4}V2j5hoJp̅Z.nmg^13 8ܽ`o`͔ &F*4H*wfQ=zHdc $'—ppQyL1pJ&7̂I@KunXbJ& UM=y0DmbvMՌ膷 IA7P-3>s  Lj3ǝ |BgJH ͈P@KؙY?ʭa@ECUzW޶L3;ϠfSɧzFlCAg_)&نu Ac4>oUG,+87") pTۭq5M_6eg~γ^X'NA1C8Kf2U䑺}Z&Nڃ{t%I2ˠ[M y><A9vÁ0iGC|<B.ۢD7[~jݖR2J9/ q+Ke eb?%ӣĆg]x& 2r[;f4<BrKx5rZ/t\~=c(4|Yv_'yEZuGEށMdێ](,I$fAtya|PKsnC!CĈ?7L$8ZqnqgGCS<DgqSw )1D:g&uPvfc1}LH+]D!dB6{6vq m]#2xC 6b+3WzJtY10Y Lib&JېtZAcXeA5z3BNsM1F) `Xmk=),Gp?n-i°aHC+x@ePA%mp:93m۞EcUB)Wגdp3#1eY)r 'F7CrK/`uoh7nxf?^^Y2nzFȽWw;8d%EdOmn[{TQЙ{f9_S۶%6 ]!3,=|ƈSJ{Um]U%\04@v`N_pOx%@`QjCCl9-@avp畛i}YOw-tXݼzTs PB)O]taNV+lz: ͠|{qiA3Ѫ]p6z#"~h+9!Dz+l1E7jGG(m_y-JopݓQ) Si`6(LcwQ"i*%Ui,2cX&CUg^J_H.et{UΦ.2"a%+o Y۶vKf;H"[ !9=k CS/D_߁D<=S?"^߭웖ҲD&GWS.D@XYW 3wȞ֕UdϙbGpo \ct9; Q%%x˵ݚYt9s0ʏL1uqG ˰ tE.C}"g:uvZϘ$_av )s낽xUQj5@0G)l>=憎 /):/BkCnK"'@;{A7?Iz 7gO)tB5 e/gRTk,=yܕXNaUz $Z>6%!+1*X+Lcg~ȭey2e5 D [l i;-6CdYC_џp%H%dU<g,g29[AW55xS$ l@}˾e0](a|YM4ZOCq&C@ӛ 3YIުG\3c] Es\k&s0V?W% I޲T-`t+g^CPt(ΉeBt{bԷh!'S򚦽,2=Pj/m0![/ickMH2kmNJGO3%mϮH[jH|l˲ʞJ\mXp5 V*_j)îךJ:IZpJ>Ӥf̋<ߣ6Tvm9RQ0%6#YS1ڇx{N-1՗14!J®x`ϼ) H]x2'ApFDeH/*Eg8X,U,Xbբuf> AIR?{b_t J_z];g-l1TČdmꠡ{f4]jD ʲH~;B#I-1֦lcFC>߀X=썥hͺ w3v_az/o)Rqz,M5>tMa <i]o\HoRk|U4s#e@0-V ?^DVceiU~YJ}T4B@uŠu kBX\c7֯Z[#B/Ko;x$%~(7&wEmz /eBt #vPE}9PW3>j'HNB0Y/`9Ҡw׶GQ\=3v t6(ۇ#tzQTN>m%{XZ\;c7Ž~3`ѐʻX0>D8n_ A a`ou@`eڌTv[WxHeDD{r# oVY )ہt'd_ M̨nL `4*y#YD`U$v *{k+&BaZqw0d ./xxCB M ${=V&E$fݹ`AW2!;̴M1>~+|(E: f/ .5N ޮj n5EIu腥pXw#Qޟ ٗ?L'MKp*$v{:_ uD%=)D>wx/ul >>CV7v%q. 3f~嶸@v*`Tq\_H㶋&@̨WvYF -BrdE'Uc(+Ͱ~yEwzJC0ejaQuC ꅆo08GU~٬8@OP4g/y Uc]ha]Cm0"Jݔji?{=}Bd:ȍ 0MqΉS]!zpXBZIǸ/D1݇G[",2y|msD_[b6R2H /2tE]zzԕ'cA\RR3yQ$,x6D<'&G|d򇄎iR>cY*e) O*RkS.a Y-7rI v@o5E[ s=ʒb z4/VؚiD6MVhei=jY2 9Z9id4 ؾGgs#UꆝYP5x1< zQ Ad-VϿ΍ egY^X$Wq gcz,*r&pl%ƌ#1|}+6> \L)U@sxUc|>&aA?+F5aLt6Cx=v{g |&;֋BХ6rj6BK:b)ZRo]̥/EdyYRf'5dg\^dAix"#yU2y(pPG~EsUi'>3P!v_@X#OFx_+uG YP=j;6L_1]?C,g˖&m1/[n Q_NV뒘BSqT`g3)W*ךpe*f#e"RHSU-{>,eV^%w`w#rzn8yNВiNYk!R7("W"Fy {qU4ͬh7@T&3Z{/0m|&G-:)o)Utw_>ԑ:Z}}#i*K3+q,6oE04!K(̼sDV\AbhqnYMI'SAGz*T1t(ڌ /Ț\0'k˅zW:yl10+]`' vrdֈav/DsЖ)҅/Q<`*}SOe ZHל',Z13ke5o,-V TY=⽒ =YA 8#w*@x֊}Rf d/+M}B@+ 4v^Yq/O@\l27NNRdl8_X#s h&XT"yFДKlJ3mWOƧz퍄3m q N>"(hdOYAqiܬiPq m= &jHYlzٮUVxYF?&AvUUpåG8hT3f$cp$hmqoƌ7ϖOf5\M,t8A@{bW`! ݰ`:ۣiEeC(ڝfQNWjÂO%805+„ 0\!uFC4@A&E S=iVLuI鑛]NjȞElDE*/A(j?7>:ۖ"1eO8ps2 i,bCwب"qo86غLXV֤5 1hQ B}h>;Q3ѩD"O|a|(\&Du0 :’J|a_rד ZS?2%hR2Ay2vE`!Bۛ]SG0x'Y.@]PG hTv㙯*8>"{x;-6iKi%_Zi6?hJzLR㔗j"DGUi؋;h~/VX~z%=+̾w?9k0jd1*(X Z$n6WgZ] 7l{2utDġxv5{l M}ALnNxiG۝<+0G0=N@#웯qXB{U"A1kc1l$oWWM 6vbSֲÌze[~OLO3tjSWٰQ:p\v۞TazZ9 Ԅ:)rA{VИX v~Q2pA5P;("li~GߝkdFD?=?ω TKgiuKquJ|0 RR'%3d:/s><ݎ&j6Tzt|{zAI@+:I*C^m)y_$&\ 3$8JOFIZi1p2D>$ $ @\M+Fk K_DGzķIz+ɏOpPa8E 4~("&b&vq4<.a  t9@YސvfRj)9/̧RqqVV6዇_ju|;$wr )#v.2 axX!0Z1 {NHSUJAC#~<i[~E疊 =|?\l(oq+qR'?Ifp)z;C+i45"l$'蕞èVp'oHvMہĤ1צd)}""$Ђ'hb݄E;S|D}$pEyL>&hC|g#eT^8u F;slI ؇I=xDhIwƇ%tTt{l!5xSFŠxY \&6RNR4gx\G_=,C!,F 5"-?P1p5ժ $ Q}]hoHNO]Er뉣BsE#r9.S*,@_DfvBdA=V-B9Ye?ZrܤD¦Tfs8?c`+:z&'FWUrK`{YDHu_ ?B&9e :Ø-zRg;[Ԟ(4Gy`#eBzD|u0ù ^;'(xo&ƛdX&]l2!JTm>!mKׁ+!A9b \,蘆lf/&2)HP@GCCpM0%:ҕXjyɖ@T. H}k{i{~+ONN8~ɄR¼0FQ2z1UA+R ]rnH3\&9 VmwrT8ӟ0\qp.o[\>dCt@UR~{-2aZ,b`x̓EP ٖ)ӝxT+n3 +_BNX|$R) weKGov,_HX-Q\U`^ n0,7oB:w?S oI1e nĈp|fP>&x4hS 5T?ł>1ȧ/Qlyi`pyؾGjHA쩑  qHU%wgܶT9|baVd>b0hݕ&쵳v'x"aj%֫9;# 0в)!}Oj3RLRէj8FBI .n.)"~?dX,r=,L. OSVJM혩 {T4+rYs 3vcJ2D4 H|{8( ȿ”\98i ^u3r6T<'.CUWҕۣ _%rNQ!5o#9d H y8ݗiV8MJhc$֢en)B$.xi/+ڧcz;@'#I)eA΂lz8>l C(0[Hݟ,-UsJJ;/%ޝLA)D"1yV@:ֆy'}D|h!4S(>+~S:CT?Ic͔}ley͞mc֝%`b%cvx.)?pUX[dy&0Sgo!4JMlU#Zr/etNI$]穫∀l3vԮOlө+>Փx]6R}ɂ1j۔dh;vœ4Uc'j$s7y9IE {]w`Ȳ+ko4^;$לA9f֭vWH;r܅'Ak6AWdot~P91^,Fw#18f $Bڮ˩YUt ^tx6-k^t(fT*7KneFTso"rqܸ;P# >Q;3=?SrZ*M"$YR^6)_FU:O=hoAgC`4^ȧ[: /ӆ;tɫU3PA DE*{g)Wt*˹Zb(9ѤmȆb=Ey5a  Wi`,$ˑrvJ,BuVW>-|wPfZ)?. $fNpN!VdK )kw͏Īk/6Ia6WDf,id{`[4.U7K#8d<Ǐ|@WNpDDwUß8 V+҇s ME+D‚%ɜFK/z;('- Pae){"~un cJ~Obn?嵬ap)\oF]Bŏg"1/GHT 4i:\'RALFp1]MxD;IRi8tT WkDF˨~j^d/UX stTVK ҕ>stGDyzmm'bt>w;׎W0U~TJa|a~pltVt)źW^PʑYi54 6i˾(:/c`AN"i`r3Tj#ɤƾle-5d;m|HT/\{w~k)X}gSY'5]K6H㼓+A$f؉D{ByhLuR̶Ġ2Zc_LMIL4WN;~o)hw(رeR=50_]rV!meH"f u9=⍎v{t4iidŴح*4/U*^9jkT:p-i'1@x71愌 ̳! bͭ-" p[DuFUbmޑK[)KqQc3y8-O)_Lu0\#yST ùreӽɛC_7e L&#`(aMEAԀ~F{7!}Su8m)ͿI1@._8f,0H`P,(ͬObBR̿xr~/RiXJ"o l))RGց&*mϣzJ>O/F=(@=has_P  ;I#fD5Ep8.,ИlNpk/hW^~~P=sޙ}1.W@Cz KM"caw Nk۔L)I%>VXi0gQ3w ٍ~g S`jGÒw%^>fuc)`U9@O*y:>ӎ? +E$̚5%1RHb\SpJ4fNp \AVKPcP '+89n]x?lQH( Mw ,(H_ۘ%]) E6e9r ey[YL{dmSloP2;x;('6jȧ4?Me% Ž_b16TIBNR4[>o,8㹷UkgCZOl+X÷fs/nvcᢼ#e[HB38XNgxNCs:>Xo7I1߆(y}d@4EcLDep. s0hd0dTܖRV+J ݞ+M*bߢ FĸJXT,=h܈'͈W@LJW\ij9Yi}AfXy.&jYbϡ+q|?@6"gb\i8uX[Xoܥ5XCl_^N`{h_RRy P.a8V>̬ao ~ E9+52vײӫr@WsfmD-Dp3 lJ Pn)RouPc2al<1(Cbz$m4kI>7$ [Ebe/*?ʘq[9Q*I@^5OKX8Ţ,ic<# @|;M\EVmdM)f߉OTZ|(^6`[QY~ѯi}n|TZN( IAb n `Dw*0V? U~d#A^\; /ufG mB>ۥf9aaT ?Tkhdvh䨯 ?8Oif;AmmًnE2t6 !q{IRk^.vS[LAoǨ-.ACb_L klBvəpL*2> f|\M=MU p{)dD/)' S}[sۏZX}D?J`ɵr&͜Zɏ5'Sz^EρVBBL2dsOT{Kޫw^Rg z|WC~Iu!aWAb9n+;gR$#owUA% Fc2$_!}.6Pq]v#ІW< l?H& ڰʻT 4[q)Cx ;0je qRI`ޡ·x ,W͓u:n?ɐ&bo_S} 6r=~<ߍd51Pң( D+8Y]8-EE,/>(| u_=QE0femu%ޤp%kئ&^}}ضZump<qe188YkO?4~j^C?R!%X<"b e%H`7Kf,OMj9 6.P M_ ^ +;߁~9\Wtl@萠6~k_ Gir !j/S5|[wSeR/˶Npc6BCjHބu+7 //&#'>D\-⭌w S.Њת4?oX+$PD`  qo@`V yZATċnbAD脆0\d9jAڸ~) ΊD<] wxߒLvA>cSg7e-k |^c!f4(3dUV $& LzAOUqvD <툂݄ >~OPQ/ (j|`}/?TlXTb߭jx9B;ބRA PG1Zu J1<TZHsSyY1@d(uh׵qy<&d",wb$({S]ǡ5˯<ÖDgG/_p7zixk0kHF)`{ ^`k_c%ЮRFS:Zt1 '2cL"hܣW/KD |CCκ(]s i4 EQM'a ` ':O@80 >v E_80 ?//t)l4iYoϳ21m_%޺_$r4kL J$V%}SAEܭ '1X"*.?bWu0>PgmJZ.3@TИ[䂻^4Kv]cQnǂ{k=^CE}sP0&F0(!u?:8;Š}W_gCSs|>w/׶ lq8UXjG#7/~4ٯ`";^\5g!x=7-QT,++f6~0{da Y"'K?#3QPմRsX'l F]4LGWDD:Np_VK%;Y#ؓa~!Se~R~Ɉ iC L0ZjzY,S@UK&t -An< ɚNo8/uVD+|+z/L)0 Խ J B6ƨwlT'dBv'^d>+B;8:- 7J ^8VTZu /6dy%۬?v'q˪YCAHKcl=TX́ XSLɬ+J?d52o--؆)ZxxQ|ҁMRXkw`&AnP"Τ<1?7$3+p]#U ˺%fULDKȮsXr"\KK{xUȆ~e+Ψ6xԆ_V}W7Q.Hg\$jĴ{$_,`ԇVkt]`PLmQ%{LV~)AX}W@9if=oԝ r (08{tӣJPq,(=Zu"X+zZ 8N6xo}_D1+LB y%g*nf"oHX_C 3 n$N~>5DN{OtuK,}(h)0铽n}@mܔ}FB˓B !a裻2U= =\//#Q7: tpsZza- Uƿ֍-UzT(ȁ$%pYӕeur#,Vv|r11f6I[eŚ+glłw(>?$#5--Li( ( FIxx^ 5n|W>!As\epl}h3Gf;{$Xۂ?]n6+Mrl*a&B.pFܿ9'ྫྷ, PТƴ|Ѩb~2@k)L @0_Pz2lT)w]_X?9tG*G>J(C7grܪ$>wAp1S'whH4& ӄ"mKT|K_&\}v}b zԬ>:pERY-ޠm^5G\E jn${vv폛8K-\aʠU@($} XkZƾq؛dpE!MSoQ,jlY?[J#9_z,89 B]' 13kyid;"I7͎ʕ𫝣ST;qL:^F^7@t xG (9 9TaVp|c@s %8oO>Y*!u v8Zu3 HPGߪ[[dds)Qu`9섉%d7k2Ի2Y"}q^iIV2O=>8BjIy]xT'aLzL1t^`z*ELq4SWb"K\+ANG__ΰpE!N z*8nsVFzsA9^.K{bzMQ@ǃ톲iirTA0Nyc6p}Z)A^ީ/%GlҔik"VĖٌ[X&_E_<7*@UY]k>"MTB!H9/ tJlV~C_/p:B>JZ% Kؿ]z;=}GҾK8LQ✊w; d!/Kbb;&ujg/@Ml䜙&3F-i]Wi? x1jQQ'L)g)qJB1rW͞(A@gA:iV5s,J6'9={U)"];Q0|J}7[5K}p8>ڸ$ ' ㉥8ys]36!I3l-=BBTiLWY̪+g #>& / ]%:w&6ޤ;=I#?[u0J:t y8yԗ.|nI_&O&5G|gX +GGI:Fa*B/o}R3{mE2;z *7;z:p\|'¬)<~qe΀ڸWy HE<;fW%:4Hj3g.Hpoe`Q鱲$82]4(/$A=:;AD!cAܙV-~G\d-e? !u`kyI?Wm:L$rM6:ۿ\x%.>a\;f7m4 f%8>|):ZbeZ6 Q}4NUzY]]0+YQϟ+@譪j{.𘬽FDO-wfi 99]5.+~HTZ#O*YjjI؆ؓ4^inF/!faak^ټBp+P`hRSC/Gr9A1omp}Dy,E`J+02RT]5t {)! 69zS$nNo싳sM%zb@{dV i0CD"4 lz3'/K7%_*urW~!HQ1|*h.%tmx$d$# ]6>ku9r ˩݀+zJ՟g8y[gkتiőb=@ZV+{nˀf2mIV7ӗ!ݧgF_-w[^=lߪ)vBp+^,b-d,OTz"DJ+Re/A_{+t"z<$S;w- k/CkW*' ΏfH6D^b3hg68&q,1Rv3ED#N4H<`ge9خ}DL՞0m.re1͎W6[B%&28qLrUU,Rrϰ! J\*brKX3ғlm͞upep`](<n\q>g6lsݵK9wbu5ߦY2v3݂r涆{:W@YXi5{84cr.Og7<+㋝G8~< Uv +L+!N5re 8OL6.rDQ |pWSr?Al3d`;vitaus*k#=n>5Yq@; ]_IV( ĩ8} V*K\sh I@kwftM O.^ iS$K'{I< U0 M[*OM$wqf]Q&}(ՑI/ K`a~V~*GR^?Kd?7堙4`Ӵ0EYK˜≨z]umPug#Bs9,Nf3gbK kfiYCX ; !Ǽ>N%7ݡko8VrTͼb5:qWB"TYbZK~`yyK~VỼ>IEߑUP"Km5L&E1~\A 6{8y_5G *C4[3ލpXO0qIZF͌>:u\^L2k R֩vI+AI}['-RΊ4 H!ڛT%$W3 ߆2+K7S|]K!i!== h;K[MܭSyj Qtm TS0 }o(w?>}RA1J;~&Tqzu7cُ!W].O 5+4oƓӜ:\1ݦ%O$~@~_sΕ߁aBsf :s;5{(Ot(hlp*dR>=}9@%/x)(b6)  ,7 &J=: =!2D_̞W¦XEX/O%eX v2XNCo4bZĸ.B̎! 2vzۡ!3OO.%QbPd\i_Q<iѝoUA%$ Q-#BwITX؃ R?lY, ob)>/V2M97 ٞY5N\7(~xAaiDdSlqJ0_@sa2&J& n߯2acfL}-Щʀ4Uև6+N])5^D_R1ک&~ѾS1GaHvU'ÍP<[cIvNF=hsG$j3`g"8BU);V6q WC!CqPn3i. rmF>Ȗ#ÐAnC %¦cxGw闪6irmU\-ѧ)._/2,'&|lti!XզBP7H0t٣BJl7s?*w|%6yؾA?JpDL.I6ߐ%jQL4"刄 Eq(bW]>WXX0mVc\!dAnn¶IcnjqG~ 1dQSu8`n, RfN/Y`R6/j;7ҠC]|gYzW6|Œb%g̓ǝpC~/ɥ+`}FIR6v+=ŕB ƭhBԳ: b@{pڏSӭ w+Oo3Ub[-.<"ױZGQZ`.CԸg'Kᓮ`[}38>mJ%bg^g&G[//*(JaRGD$Vh¿wDC|!Å ;лlj^}>6f4, f~012a>FotzA僉`%4dmP磶"8z첆 4ߚvk2lPX~`[OnQaЦX#]Ӻ!BGN'|N띓 QH7 4&ȓđgW:1!W:5XP/v vF[!1KWhaH&2Zvo}dBipϙwoꖾ~[N2=EO@ KgcӅ^XDY(8J< HPH- -^=s\Wj MvVFAI2^k tWǙ]CXa]CԋNJ㽸M7O1 Ț^F(rf=rwEjGkѯéQ̂LEGTep`p2AUA/8TpT)A50. cӫ.7$,7P0^e)-Ƽ. x 55^d 7n6kiIdG>j!it~@x_i}.% 'XKIa 4>3}LH\ABRFv'Sh{iA$ʃa6~4~d$sM(џϚzw0|dD)4UTӼ>쳐Ƕ."+c 4hU+Z e\|qb01ЀL}0|V~ P.h6I/tL`W`tsmե㟽w ӛfb"2/ xDmybg9;etu(4/!)~~U5$π(\: Z' wwMW4ϣ4ɖ׾Z v]瓚7A!bY$Mah7-b_ OSOM`Afۃr.lbϲ۳[! .3 D;YO= oJ~'1ystF5?&VX+Ze섷31tQ6IWN˵DeFXxyb>;X뵚1=f<`A>)?*gKC,3I/剉] ~$UzH'ʱ{oTE_ppD nYi+r1>+!;=jõzǠZӣ)w$K=+NSBE^65C;S0 2ڇ@)uܝp VW%%.gVOI.Չ{'cx^)u' jۍV>Sb2> +ΞyT|D 4Tm&P7f*p[2@I5R;@;i߱L5$ =h16Jt\fz*r3Xl}66Ѣœ>$^Wg_+0 e֠Qu-I D{ 8/RcH BRPN@(/{0fشKB"X֨Pg4ڌP<^V4/]!❣pl+]6zCQ=[˭,l4MloZUzӌ?ĥ!`820)>Mk#J #^_"{cÈwBgYG1|x|ŞZ3PB^a!nhtv g-<,Ը=#z6E,_P{u{tR3X>yJ[eoK(gA4h -H=Q(aJT 2S}qR9/+v%cp5˹S 1Ma1[,=Xj`}׹14vMiش {z>lmh0~.+Y}4R74q3e{@{ O), ;jL>u=֣O|{j>ȲWX׍(&܄SW\Q YeG Y8*=j<̲v[x:3QM%+4$㗃M'[P(gE!o+7GKi|JopX~mYwDi16wЏvl&> Di99g*7oڒ@Z,:9ş]q72g6*;Yi|x{k{ 5b7J HM闡<*V4ڍozv>5U"Xx`mN`!±/v$j*3'Ŏf3MecЈ>7}m_&X"35 Ry8w֏У2ZJkuZg2K-<)K 5Һ?7'ӽᓼ$I*C%/5VHB\+Q餯9p`"kKo5x*؜|ءZWDyX*Oa:Gș8՝BzɊcoj>׾-! j ?Ĺn1`HEdUJA [׸t'Ϭ cERTVi; iIY-oQsP@ ™/9}#:GYbґTOg ģWF-*mK,7r1EIo;C;qK9"'BiMӋJ}@3Ym SlNnJC>~*qbб‡M#[GclV+ewWWDq`hqTBvࢣ`FW?ΣO+yQ#ێ̎(WY`M@SJ9Q\ ->p+HOr,7W4E<\ |:r+֡X"cƨT4 / ![BUmTb-j\ziĵ:SO ^2!Ȧbhi*@uHÞ?>gF$,o6zԷ?Ҹkߖjnkao9`Z*ø$[b\j ~cv !gKN1W,qp,XysJhEdC?I69P,MHm Δ-T##0V^iL6 c i?h'mޘ`0A(>b0? J\F* P$+I}*'ooi-K a aeK?޶7`d7] O_3}$}'1%z_ns#J] w7{M;Nk!yExִf<{aVJs4AjLꘖ(Ӯ?D{|a-RN j{jݎ uXkvU?$/6"7=-z(ʜƓ8=|˥=9fL :-ht6_[GIO"̰[nk4Xq ~3>))^ܻ"p$ J@槠Ɋq0iE'U7pۂodM)ޠW1MNAr m nF*A][>eH%1rJЏKt[_(uʀϋtdu0 AV;aߺס,NqUM*HH j:+;G{kY*ݚɔ[,!ܛX/xYgUTžjl }U~d1ۼ:g>4, %9hiQLZ ڧL GYM֤BT)lWZE99G:6;j1O&'ѯ@9сJU<$l:F,M0DJ~ShPDP f!79˔r%> 1UMN}S` Ϳs}ֿ. yaGzŸ)z Ӥ2W_<oE^>l_)o ;+iYNo)I`|S':?t[k+=_ Zdq;@w|D]HU9.{{X"#*!E|fnU'Xbi%[l;_0݌9|TøvR,聒Ȩ|2*?d(8Y@ߜnt@MjqLoґ+d8atBNfZj!~P<{3!^y(1&kN<}@뒜NRdLuCvJ>#SRY Z,3b3(yn^Z rE1c,xO!]%x- d!MC<Ζw7c<:>HAKp0 zhyOQ~CYQڽO00SނP"}vqYduqtnTi * u!*@\WnUdʄ{jM|D؞4Pn{b zVꄧ۬>iՐU4Ǯ0H/B][ 恫KHM-ϟ5K ';|7?Lab6.yfV)f4"z,O㎯&d_4XoFW2l7G5mO07~ˏ_–.CQAń5E}<чTF*kC 3- `q`|~rdܕ>h(˫ȓƕ'M-L>l5’ 5?P'T-, G'ikYe:e,HzٲYPzvCnym]EeBu*cLoSAӄn1jҖKen""c"wd,tZPG\D5aI %#0s(~5B<f]FؼU+'<=q(? #)1nwώ*^ɬvt}7FHrB7*v/#[@phqȖ^F f5V)pF;7x-?L]HevQc0#>f瘝*- Rd+#`S3] \7R;{\GhHyEļ~byN{Z)s"_vI;%-+EEԨT<-V .%Mxw=vv0&p1$;,u݂IiC#h !s s< }2:N;u6Ǩ}%0:U@rLvp/(Z`O bK"%uĮe7(VAsSqSA>`IJӗ^ZI( y2Ak&D"O[?6QrBp"K}^3w̥ZUS CI0#BAs+%W"-+Nc +ed:$L\}™]rҫ6+;|nߏPvAaU 3'RLTp˜CsLwCin)der.gx)LQWONN+w+QF&U-Gxav }[-lɻ$=b@Q[o0Xҥ R^GPďSY GucϬ `͡8 2}Ȝ :;BC'g4ULԷHZ Eӟ8g (rFwC4Va1H-&:~Zzv; a󟹔-@;F/}Ԣkf!+Wk` Ol`+ x3XFGBL=8UH.0yջ\<hg!q MMiRעP/de}) lQ{eVD5 N`",CC,bvk0}zxuʽ{&D&L@1O@8InӲ1 7a$ba <[{FΤpy8,.BmL(gҠN(M@}&RNVv.ĈL>|0 XU"U3uNdj&w]O=4.|ڔQFQ1FSw;@Txzb+,po6|HM p9 YqR(y^ 77"]EŘȠ=6kjCG$E\9PѾyt p~l;"^A`HkZXSN+/"heAUs7)pMbvB,FK,?:grN=t\NFpe:'Jg恄^K8\+v(o -B563XuMIDzQ߿=w!1= h*zBI|i%$ZL'v $7iM6vY#ȰVw<^BuaZIg/m8TņUM;7 FCa Y`1QǑ+ %+ۗڸ`yN.dI j6G\EMl}FXhfNO;^d.C #ŢTOsuonWX*I!wԖYqfTf4qBڟdIwvx { YCVeYZNHE2KJRRD5 ٟ.DU2Gآ x׋GRV8Hq@SV>Nytpm2ö^Xm~W~@gG_1h!’QL:=VY'穣Iqah0O-Ͽ7[I0/tHjf;/- H}6}Z *KѺ==/&15v3puqEo) 'G3Cy#@> `~맳 /Hd7No^VH.'WH9U?k^4e $Zw9z/lBNޗ/de_&Lg Ͽ΀_b+"y~.;mˋ(EZp5FQJȓmjN9*Utk6qPviΒ>_o{c;o@zi_^摼{ "Tjѩ&=i̺L#"Je{doL7HQ^n쀒Gk%-dOᬣ[[E5+*}})Z$'Ş%_[MK*@U>`Cfؿ.g>fut`grftRaA'F5z#  <ONJ|8d;LG O| v V BRLϖ+e3 Xo_b_sFyzhS;.ƯJʇHy%_o``Lu,]wa},FE<[Tw Լh+m.4ڥQd1M(;u]'zo?l8 xevlF>@Q T_L0L36 hq{=o~e5yL.uٴy_U/%Zڠ {3U7QWvHV?œbLpPH~ж0~_7Sbˬ2i^ϝOZzB&,.b~ɭ |Q:]hH/!KBH)C?sd}b5ႊKlXR"GB86v#"7C%!MP[?CHqgC>Ci"{֡X8jFq?łzL cy03pVңR/Oijh"*>Th#_.kAmwc}*!A_3^"-;qP1,dP ȬWEvI.lYER~4P!ьTmiRzxR7^ ǹ>F!퇵zC$)07٩M?/٦+S#k~2Ia$Y1eQ*/~K͔`,V|EZpk8bBgqgY1Q*jA"O'>+r(k4l.fh~$K-BYpNh/z)~ii܌6ƣQ/ ‡;I2?5,Q^z鴈-A[C)nn t$3sAѺ"h; MGA8Q5d"_bU+p@)u%C8ar.AaD>U ~|dl)/^[$I Q+\|yOu?֑<(#9;W"ahaޛX$,M]cXWIm8o3d$]\P ˰yM}_%Rr֚1kWo/䪑vl (U/zBd/ޏ218l)_+Us˼aF/M2sWi`T)*vE8bɯ)6'kH. @mS^RbT|lmHO4a.W"sw~=6z_ZN;i ؁ a]יmV!CFD!PBKɸ8Pg쨏4XWak'v:z&LՕW`:1&+*h[ٸH2 B`M3d>6Ƚ 5٤HgvEfo;D),09Cx/Fgj W{mP:hA{[pWLPu%aZΐ m4) c(SAfaH*;ΚԚEbpcmw _6.q": -=z}<2ky󅞷Dz=Re0axJw]^;3wb)Ґ^@t\0Bge.3d1coχPOOoU/"E`(I ?P6fJK-.BϾ!ӗf/Dՠؾc I9i)o RUu E3˽8Z4G7eg NΠCSE AH:G>6ͷ&G/CE>tyl-֓=kMmM.ǻVK6]EϔoekJǁon5x7 _4Yws֋ZE6N(^71IB,7arlw&r#p=&EcMS9{Ty"ߤ ѵ/יVEK/hW^۔.(x*J `sز7zϻf-`jS/*D2lV AOc Ys琧z7[K2DCr:t2ZGm+w4OFUiwrDt rFIWՑ[Xط-Pi;϶ׇԜP!~Ljٓms゘<`M$).q^%#x󽍀A2̤uQcez[ ةgΌ&%Iڎx}7;?ª-nW~אWiid%-IT~u-9er'-UdC{MEER>@I `Q{~9ÁP܋ "O +ЍX\D~2C<dqIҊ5#KA9žmXƬ䋢 Jf ,))}|wME禲\ت>/[M`H[\HR~ZקDJa=8tYg ː8N2ȿ#^6pdix)|`M"ͭY*mTf.P k?ԯz$2? @KNVI2 {%J6),= e-E]R=t?:H!~PPWgq{tuޗ̙C:逅d`9My!TU 0еr2ÁBN/6V0Meމb數kZMW9T1 Ō鹽v/V!Mw|-L03(d1FA* ІW\*4c@Jc3E;l{ѝ ./^G(An&ib0o0ɽF;4㟐)Y i`gX X~8.9B3◷n,^zB]&{S8 ,P5ms)VBe˦q:ݚKCu%j.DWQ(7CJjB9p8fH;3_:&oD.SW 5;.XKv@]uNj!4}/@\ -iia.z+;3 1jKr#}cH/ր o"aXK(MBТ2pr/`?p[bT\O1s>=7(5TJtK zQn}Z_Y?@Rde3ɵx"1n]K^Jwk<7qcdv#%khHRQ)N5c]KE='L@>_ ]ۏR-G9_sU[D ͎!Z l46j#hBc]=]tjb}`ψ[93Rن߭w ?MR> 7lFڒ,NcQiYK}uL\3k:@j{.be8;bŵ2<,|A<'t+& -%zq%Ώmzq?gUED>e]P vi]3ⷝ#cSg 1Hŭ`U&v2X nAlӸQSÉ\ʉRj,ho'L8 ZPqx zwz̞1oBF7ֹAkE{?Y\VXs| zlKT z9A9J!i.Al-U5y#B+Hh\h$YBŜ$\_l Z䖅;d0ZK @y1ۧSB/8BWF| aB+u ^p /ͤ`ݡ&x30VG\0;.R1qK.M[N2hG~yC(g_U@ k0[yܬ ?XPHqX5 6b!fQ8xWyD/Tkb蟮J1il<+ rsVm{C(W(F"rcq?&72-G=qH%\/CJ>+l995m$m)Њ"cuN?K@XL}ʏ &I{pc!N4{o㶏~QԌ< tC1#,C2FIw@܌qLyTwø ى`|c.vˑa"دFLF`w KA}5lKQ8I=* m3z-ɭPxC;l!X^_iυUuIp8}ϟYA@ EQ0Zo`U@JAzԹQ"9WZQ+ @mܷRb\xa@E*H߃/Rf1pm}#=wC^F_W"!YlpDkv ąo3YAmMVRHV| ߮YFmW}eD|5BZG^O/*mȘU]U`X7MmCs1Dh]S%~b(O ;MSƲQh{r 4E2=hbC^[CY_q v~϶,Wٮ۫,3%f]`^v9V#A^ ú\`0`ܑ^k}mx6U  'a_\\|Ah+rV+EmLw?DǺ &$paD{&Rw<~_uR: o6;(~(lqz?iA!ڥ}grLd19>E"Ը|:ALOa(+J?'+`\4=b'b'|>-OЯb]KJgɭ=gԻA5ʼdl64.އ !YJp3]=bg$SnWvPCV7?/;GalaY:`l W.fMSyeғ}!Xÿb'H3`ny5Xb |y~sr9CR $w>#R6pHaЬ A;.I /Xa#2RuŅU0+LhQΟ9Ya+(jѐX_[Тڟ Ert8T8o(OpO0/90H"TSEH+, ׎ƓJxV3J+oģrq/m/4uɰ o"SwLn2 |IsuK`H/Wq1C[X dE{naZ[NXY?/viEVf/4iGF3f0?#F:|S8_eLZh"j>./s1vefnEq_ճ Қ'(jQ[nj2)Dg1!eQ:-!q6.p_[eY2NdPIhګ8vn@=1W/=6u,ۅq}Eu1A`)F4Y/MZ}6gpUn oD^_L\6=~?`&#'\VsJHd l$l KivD4όdʲUVVU7xED%XbA,gegjRrY)HR1S~v׎܋]Nj#}j>X쎹W=Ժui Y>E9Nwx 1TEykmNW)PЍs I<(H@[O܂B)LˉGqǒt-{uvsu4<^;k|n>o&%:D^Y"HZDWrZMӵDy/(H7?I)oɒha8V\4r;-n&/?Ͱɢ\q9.EcZ|i^UU$usLj6OVPT7;e,YO:ֱIHU%RRAHV " UScYXER 4,@X>c TAE"Ra[[+ ţPQH)DY l ,VPPQ[j,DR[AkPR CU*ȰU01YX|, %̑ODvo3E3s_ Ggo;e@ȲE`R{$h ' Q=ejW15d#o9Ol0y8b](OE>{3Ѐ@ M,W D|x4YYl T̓g;?ÕޔXϋZեqLhyBVT->fyF4E|ِ0-)ϖP 0 f꾤GR80 5cc-y3kP"8m_?2DQ{G/?D"pSg>^/dz[%<Z *nyX0qo.wj}6:b}XG?T˶E CfagrP{` Im y `!Lg=Iie+猆_r} LORet_Soh)ZϺlQ4>i9Y1IT{S~ ׺\?6hhCDdTޫ8G{XMF6*֏b c)4!xe#7VnX;-1_N9x7 [cnWbE˚MS\:,L(m*sR\SnQSP5NoYB=sCxTlYXnF޻mޓZ}^Ҝr7Rm% <~Q3po13?jI}Dg8a=BxױN `&rBFx}??Wl˹98)|2kʜ 5y;#f\b\bYv5<䕂pRvRzHM@JgYi}x _oU^~]{@j1(m@&Iq58g&{!jJ.2Ic BX)'UFF93(Kb#N-zোx& G! Hz~<: 9Ajtm>HNȭdQVP<Մ d#$" IUCW..ubo"/5 ;XB~soH>.Nl۹{א)YʑVȞ4v 15` +"v'J)1Dh.ӵX_a#RO19;FUrTX1XFUXE4,&A97u.O" 4)f<QxR@~]dN<'=? av! V25iԌ1缃М3g\#!0z1#mH=\UO$yBP A"XBG8 @"pf&lZsMwrT`hSmE~e@8qсfT 8z)m@0@Jff Z۽W αji30:wAp&q*`H$Pg Ap_!m}5 W'aVo orbYyqT-V Mw&s<'/ѼYWTZDŭvٝj``K} 2/v^;)$`,CYMqWeBc ^T+ػQ'pB}&Kh,ePWm 4=+eM+PhJƙIaƳ7Lǻd_tJƹk84n`*gMRq:2g\R ")A ,X UzN5nB[gy22G~]CzumZУbioT$/ڽUsFV3hiR!@deCjʑToQ8m)w{G] $+ʳ_8XOe&P qN?>m-[essXMŁ~B NqfkIنN÷tDvĭ+ g=&zy8,ПMav; 0f|= Qˆ>i-H@RgDZy4{zdlL6{JSȜҶtiM^ACo#ȗ Lֶ[I ʴb4}6<}fT&D;)ʆ,0:C.KWcikĀ2ؙHBFCwӂAUrzَ?7M*VrX6Wz].z.^İԓ @BݻgƤ@fzPfQ ClyLy JbNx V#YqA$襺6U 0m(^',$6m*t&p *AιlSj`u[ZhHq~ЄYxUOKƄ]*%V>N\qUDUr;3D.JB&o J*.zÝ+ Sc OH7ύH^NksP;*6LAkH@&}@T {SĔ˦RT)!|fM&^-[2*$g,9}Fڵxn1i@P(Yesb_C8@b+3u$y h1-z*K̖:s~H7(Xsɟ.A%ɴmv {3Z>/n(pGJ 퇡#@jc?G.!+`>Cooĕ4Ґ;K zTn4uvw=8> dsA;oZzm4t X? }dz5C筻>9o6n=2,R85(RЁ9V[vT}t}'} c?NqZT Y~ފR_MoD/lb5B,oQ5:=T˔ y/]m#> ?ϷsW(Q?Ký?F>E'leѸ|?Nh̿ U>Nh=Wq}Ӿ!~Ɗzk'xF^Se[jy6߫vjsj^TUtg|^8;.% P%F]Jh6D0wI"o6}B:S-5Uy$>aZ*©} P$Y7[oRt YEszb@%D" z_aTTx+B$~SWc>PYXΫA*g=vM< *p,#L.Ƙ 㚩?JC@kAWGWijt>;ys3 0bH谴f Bh;<ħ ckN+n\ݫA˹H(;mqH֡fp|]Vչ0 R:qsͩ' ϗK{Hx9?w8P*, "ȱ=I4f JRHitA2D.ī}hn~)a5[99 s,G~ƚJPK[3=j #J ^_ Pf$RӼnSwlx k,Jqoz Y%ˁ>0PHjh7R(@$37^OeQ";R7RrK)b'6vu\&"BB*l' 6'evϋVRsSu7R aɛP:)ת}yE H5xxY Ű] 3Z0xXQK"B+W-(G ~uaWP$?QWpP Y yP]9p$BPF BUF! c,az8P6Wv02xYlR6cXصOr3WiVǞ1=D[A=9ETowCnz<(@ȯzM $ڵPXS;=R-aE(1oEaMK]11kb+Xn1Xu[.£fJ]?mg3; ]F#b-Wp`ѴjBg?GY`~ ၤۼ]  :--VěD1E( _Sɣ;M_Bgpkذk['PHw'0 B@!`옭]̚ (ŐC `G\9eG@ϗC( Y"@67<}Tv GF -YBЎ1iQȿ1nO>d'v@]~^j@ !{Og>GFӪa5Pu,颤Q(TeV3[Z_)``Y}rђg\('(4Z+* ZY #Z@lȳ3KHqc,2M T %)$_ϗsiǽ򾏓W}>}EGa巻c{ _L; =P)=YM׾P:֥꣥2Ҫ 2O}O=ڪˍ }MhR$9Pkz3asoWCE+ R[n0²^LWkU<^$J[3^$K-No?VY%f:[s\slGs[_ -):dƨrg7\F\63%y f9JLaUL"̟8>emH5OMY+*f]{quދ~VenCup $x>iw&o5@M_*zp\>8x0@Z!CLp'7I& ͇tJsJ ^ö?{=?nmF"%ܼh*l9z_n(zD>!!u@Y!6U$s7*jLI)(E@Ikٜk,6d@ ȁJ}Y B+j%#ڲna3ߞ3|x>_3=*;Gq۷/QU#CV`@@?f1*CiXm% X1!HP&! L Kf0ԒJ? G@϶ B9@.Ïە}t_K.eW#"5(}$g2"Hq;q% ~鼧ۅP?PMO*e&~åeQn(Y 4-|X=?HhdSA^?vj|ɞȘTP zsۭ4"PB{eQ%ڵJMduugU!ldD*k -DO]}*V2 SK\,'h۪MT^f.ð$q FR'ߩVP6;kX؋'vzMsk|Oks(~V+m\Oyb8[MhI@nT5iYS!%Nj1rZq[JOVBՉ!.ި `$ː#dh0Gf86 K6 Wԅ-j_^|_P@Md؎CF/FjBt+,J( 4&3 ^ .Dv } t?([(&9w9^X\Hyb5!9JBB4B`67X|UO:):M7~u&i;|2?+nǧ+wKZ8~k>??I <\=^OMXYH&IKRB6Ә0>@;&C+!%\F%gI򬁾lT!D!B'J%EW)Yj$uw !H`d"vL0@+~@!ٲN;'q& E a>T\yx+\18@$ UP!_K`"$@:WSfyԽeܐ Z1Z.yM5 Ś#!|ΦOUfpebn]ߐl~Kafh74BzIET12 l E$A 4_ȲTdF1B,8-Hͨ!#ٱ $2SYDL`#~¦$-;0>?|>{o㯩烉OQV`DcAI`,,2 AJҩu@5M!̗=T -}0$5tHHY'/tnݰ,p,wdUb3 ""JT=fCE e!HS|ʻη L3E"EVF2()VD-sexrm]O0).KۥwXYfz+_oѬ70حv v*R= 3tJj0q\Xs|@\z|_N|Vs]&`-aX Ȍֆ P dd6VDHgѤVHS(Q t"!05*\#WZJCOg7%v[S\=fn8cbeC1%7y_ڧ>'m]ަe#vՈ D FQ(DGMjz%;HA<;ԔF[h&gH$b^[$K< EVͯ`3 X65^WvggS. a R@@_.F._y0%@h*AW!u>0gDT]fH(Jd(`PP"%25@d-zKBv]G'WC\L<{|" ZAkipcm X"b~u* y^#x&Zd%) ,IY $Y%E$ M}N>&! $q*BRH J?"YL̐3-_A!7*Co'>ڿg}RLT\6: S &d^b~M6]CBb(eU/\I6 M3)UZ!ExV"%xƒO; <-p!c?aաkA IJB|d*߃1zuW[nRwd1Z65Hhnۺ.ֳ?s[8V#*3gLG#JqpCžX HKv?R z@dwí?8E@s`1h; !ڳDI hXU'43(@ڒ!M!JU9ϺwٗLS`dWn;Pφ  {5RLa_ͯ$Ĕ9%(qUO־g/ͣtR.3rw[?=g7$Ԓ2IdFՆ$Rw01ڨ5?+Vgڠa~z&x?-~a.-5|X"KRr8-T0C-_,+~GȇZi&y_%!!E6bŀbB Nх )ర}1ޟ֩H%;!.V'(/0YCHOژ˿%!^nt!+,kPobxD| 7!.cfO9"K&4Ԛ0Ep輓$BFFHfgdžD?M|L͜ _I̵P}XG%|?aX$ 'hDw!D3̪MгaP=Bw$Ԙ=|!IR.U~zNyKUڳ~fsҥ>asļ~/{o I A9Xf$ '.=jҲ"r IAջ9go7?Qbj&b#IJW*U%3˧1婙$(8{]VsK﹁ %X1uгDLA1ᤒȇCwU_L;eO\Ū_uz[}g5uP=iwdS:޻Guv#d6usls(!=ig/fx?q{<.}^6`aײ !;??S߽aKTA7$s/h L~5OWPt[%MwȫAmmq7tx<^Fu,Ry֜MF#L b`_PHO0 ?*(T1D0dgΝ$0ii鮻:UT@ʞ$pLJ[(k*ɀS!rx_k B{ogqퟩ6gƃu}{.,g$-$jMB*1?L)BPyv!j)nYD'a1'LC LC|:"E+6^N G{ydjC1}-l³{U$9<p@ I#ZP2 I]?3i" h70,~q4F =BbQ)%0ꈆMGs!! u7Tb9j/0^dЅ2ٕRu@&\)8 981Np'$W^XqSIj=;)բ&N0b*dDrlN>ٰQJzdFjPRZPE-*<8`mQc: .s+ܞ)3Hѝ4_*'*hOEĕ7a-NTw f]&K6!$.΂A$] HLɐjEZMn0e08!%Nq)YeS* X(~7JAwcj$ת- ON?!ŏ0'sD⇻ΨdK/3~}i!|h)&+Yºmfo0_HLB$~ tY:49B e0a=¡g61A c,(BKzr誽XQԏAˇv(KН ƣe"CA;N_I)}p.|vO/ऱbn<'![:ξv, F3l9"~!G [״*(p2_-dMN1΢hw2DZ#*bHf2"?5U?m9U .C>Bxb _5bIpk,@D{?I },m _>d@U"]M6sI-cޙJnh/)#|?!fCt<eԆLBt̐"0۪ FJmT{\Wyw"ޡ.W9];?k(e{CQ-lIu߼ @`,#4 q>Q|(#PpG7{ H~KbT!n?5d/u!oS@A5oR#7 yܷ-VC'#Rڱ)'mݻ!^^2^ vv Ca R,v-}#s|Kp.19|ƹ(u$e;xSM?U(N_~dKW.(/%#q[mdwRȧdҊ~"ɷ eT`@H,髝[_|Ut0}m'?vH:S!K q{fU<^~{ )dM$* [$*p(AZ@2TgU=+&ɒTQ~iFмia8LA<vjP?jR1~{cGfn=}a d̗bCg2 O0c! I!(}3Z[TBm I FI.9V N._K#42!F @0ZXj `77tn>Nceb3EV+ӼnV3S:,W/GGcxvxΒy:aDz)7Z磊JޝrqJJ00R(  1r ˲=SQ'6N_u>zOO*@zIsI #h=\`^s_#O;:75f}a F+zdu?Ξgp/R-PW?%*-萦Yo D|6q#'b &B:Ÿ^_Ƣiz&@f!R5մU]WK6ljhR(&3! `Uj@t#ʄ%BS@c 6NJ`gABȢG^tfun'# 1T@}׼}ړD}@ yt_a>^~WSδ j[|Ȏd9LP:P921(ձo^N ds.C6Eax{e%'J5$ R| Ą cd2]]MZu<~9tw|e`"`j !A{\$%8JaO2d,X!IE,޹]#$_s:D/эVuLQ/Nf+5TsEޚ+[s~ )H;U:|5x$ L&[XQF@Ha4StCB]H ,\&̯ˈC a~9 ~4G4౞=FA!Ijΰ9#89f9w=?WRB K38|-Ր  sj?ŭTvˏ'7JB]%us2N]]ē)/ƛ#vЊؚNSed،=ZHY~9g-f"A=p0h'2w6iqLjRwk w^fvis/]@c{*|>Նyc9{L;e,NXхd"YJ1T`MQ)hGR<|~Ij~-/w{or@Q~Ժ9֊6Q" YFMP葬Ij.!D` s$Ppng3ͮ*~|P|_#bJt#o`jMSR!F$Wd^Hݎ:9r4;mK)J-&}οgچ8ElIVreNi铘 A/2j&'P5%nDl EhÒ٢<;^}GuewGYضR.-D[toIeuвU9Lj̧ɾз̵ ~KP{՚8HH4nz2{1YW4zHNc4$5>FC(C0L9ť-S Rߨ%ßv1,j 2!g3qv.}=, iӳj]2i C72N1E Hz~XO"xkm+⧝_O'a_nho0P e3U^6>IJVE2 $ *V:~[[0ߒ&)EP!!H1g~⋮ @€)E.aH`Ťխ˺@$Y-,@yk3,Lɺ\+U=]v=AdF qTRAٰP g\,Hih;4Rrї}ppG7TVU#L=Jh 0h$uנcmzub.^EΌ|9 [UTDGR"PfG_s^$Կ4a$X?~AH_sG)md"@I-v.U5y MU2+a',8`dVF]ܕZYb{LRy*Ė5uJo-c$*80ʁl8ƃkxIlXVmM|pmg}<3øCXq0'I(KϿ''>82,gHC$ hf]]!(/HB'6f\=\<4)@?4ʔ&*8PP2{10O)<9KҎJ'"M05P{˔$;@2(4Ҙ^ɊL=ّ6aRj8em`ʨeC5B5-_v).#Na)$t4k"Bk^H$FEtOc)@`2C2-3 $F|'>./F-V;;ujV"| YDȞK Yy.|=a'm1 61%ívr׬ANB?rD>uH {ze/+-{STs,{y Uhě9{wt3YN!^YflE5!{ lX<ͻ>*:Eej{^m[<\[vvʀzF Vedw&x6ng#ESI:r+477{/pCDE}+ԧpH#"5O$ӯsqp$NhirdS !_zD D{Vlazu{k8_k{sy֥XX$Yd!y<,9+9 koEq@!,ENLlv`{AKGI(S2y|_yVC}\0PW-`TIX@XJP) YXJ R(ĖRVXVP IPu6m񧱿R0en5e,mp|q&Wf*O(R8kA@H@*/yA<GY\03)GX8SrLqs|O4s5X ws@AHG[g^ L)ost^צ 7yIQVHH"ev>b-x=Hԧs ɻ~_J@‚k}`w> 9tDX_\s"$$ @zWRdP[LQrJJ j;qfwќ'#@bͷ6=r^va|~C vvEZ5 iupeq\qKZME-bIY -nyAMjeHhՃj-bD *S*a+-]f bXƣ䪭e,kb3 +LE(k4*.K!ʆ,əAV hϡ&%og@DJ1쁌W>FEHtah ~5 /9$qVZ DT<7hr=\vFuC^n/'䁆'jy3LѡpV N|EDW,LפnI%ܥQ~~і+Q, nKIP Vt%cK@s_2?ף^Vd_ѩ*\gm#@9s͢[o ؆`*L& ;A:)OLCrO8gLm7fk'ΗY-ۉ̫#,`U xϐ}E zZ{?FHbf__?(/msm9uL8>Ȅ4(_ZP1 mɩMճR+ה*i@Zbz5ڙMp!Tb'z-Kk=pl J7 !"(ú%`C~d ,c7j:b'`8:/pS>1G%\QI`BZIޥ=* TP]:tP#l9 ~7B́4k8Q,H=f/%!_ɨثX+0ܩ#|XWJO *eL%O!$hIݒ&ä_ ,L= &gٜ6'f*LH+Su -(_ 蘃{p>kZը*f6߫,G/ *{'V~ۨ*+ow<"}UQ4Ulvаw8"N)P 2NXbjOiZwZēŁ[N:w͍`^x_duuk:sc徿&]7\F֫\<>ƼSYZxaʻ.'uB(XG/Du0 zw:|,C36DN׹pn ]*jU|aJvVW)%^8L@"HgIdK}uTv@ǰVSRlt;iP&OGqoR.8.rxy_"ckg?unvj]*79|9MQ_$< ^]{ 8}k*>/pn~㑈{,hͫ=Úh:*]jlZ7X3j~'Jc~EYb۰wi۽8z-ۡ`7۶6uEQ3U7$CJ 0HcQj}ꖧ"d!9}x\ZgB /z?bNWx[&,+z?k'B TS`]n6#D}j^iz/cOs}r2۾eo,Ɓt5SuzN%|VJCQu+K[u}tV[v %\UxNf]n؜}sjO"8KjuE.ApKP4@S gx[TTK|rr?s?֍ etbۂ6ϛ/r{ 'ƅ3af2A<.gqOǝO_Lh h.KaTO`<|jmajL!&eIŰ.1<6FUL@q֙#/;fmy)m0*)YM vd\_/Bҽ,,}|{‹1cY2 !VC`ʼ$~yD P%B62ejIHq!k%mCY)G)ѕn)w tx;T8&vGvV7=4Y>Nmؠ%4V?$֎Ig :13*'<}n@ĴJ &š>ktP=Ƞ>#C`i]mY@h?bHi$Y2 BPRXO5?$rt4xJoҌ>- C&.iWw;Bm  D$!I @HI] |+Za.~q/ܮwB9]e5\WG*d uH@d@4! 9,&z(!d$fOYKAIqzk}Nlu&ufILHF$$4ڄ5ueIf`E$k$4*BH 岆HDOBqEed0DfW DŽViS3k{CTjiط04\I8H HM!)>͘m20 $B,: B  >'gB\*Œ 1rH\27  %d>R)HIz! HIHl s懓Th1pִcAy;y2ћez!Ӎz t@6Y!"9l$!I! $`|2Mdݐ:^aSIaP LOA>džfp>/~ѡY  2}??&ʔT[-z2 ; tPaH4u4$*Ol$BEXE$dXC,@@$[, SOZH9g'>|~,X*.< YCctl rY%z?U`_k>>?E+w2}z]x_bt-~y#@9ͫK"ab)^MM5jݽfʱ:F3P8!y>W΋U:2~޼iӲ]?CHXB,;ow8V]3N,)e2{a97t4 mYRK1wA$ک9O B C#K C7OZf]vy_rg \;jtJIդPk3c{<\4ʯlzj^L&PII$$ښy:ΘX6w`M(TP3ijjDI#N2 +o>w7`e.{<~έd@+4:.D!$%ƶ6BbHE#EH?3< 'g9 -D֠^wf#kF9xtjt:M̬Ɛ%@R*N*Kӹ?SyIs!?-uuH.77ŋ &=O;ngW[w6uolm6k06˨I$@D, ,O$!d,Tӹ@I8>]ƨ> ʀAE! E,Ja0'@X+T5-x%='{W JCS5.o , !Ɨ}| 鄇J!62zt?xZk?mmR.*?*ӟ_m,?@I;_Z 2Bt!a$PdDd"B!lr*oTea粜C`Kr9ԩ* I)wZ9򭃨C\Jd_.JR{H.4|3UV -l̵_7c;祫,yI*l@! xL: @%Oȩ)DY:# ͵(@ifBBrY+kz>l5#O02(*xU[ML)N JF  Ǩxe.WU4#"vidM)$Bsxw/!!S'ս!a5Pi9M3埯lo\*zJf`ՅZOHW-9cRXHqO9rB~N]?%+y`d.@A"$mU R< ߚcd^f8F~ 27{`pGx}ʇ "0$]캭.@CB%SKN@0v>?,%[K%"%@$Ek(2ki.箨4座Se/;痯ScE mIEPǣ !ɢ)p"Wv;5{<.e'yP4 ՏsսvV&+>^EZ' P#cE@Hyh55U`0L9f VZulYe#/871n ]U{M}` hJ ObyWynV#B@AЀfE`ԣ@B\3.m"E[@HQA=zo26ځ*x$7de6܅EƯտq0W;wb"}g΂~j_}sJuIͯ^*(YPREX F㇗GSy}cWl ϛtOMgK f迫l$RPZ/CU x YS&@i+*T(LR dA>(%/x+ 0Ifýp֐)f;sS bQ/xuduDĘ'-<wa )U nE"=c3SQ@X+?eĺL@4jܺ31@әnKkcO7$Eܐ, qP4|9Yi%X,Ĩo(;T4%dFSxlMywϿw{@1&$@1 сX'6 Ec8O[; Uj,a<~ܞЎf~JmqS.ꅘEa/T{hz6V+PLE$A춌|%|t8 {N1?Yw`$@_]H0 .K0k8Cd

}B& X(n&&#W 9lclATQdȱb (ȉ,_SO`zk j9B-!(q-\&j;QZoiPUX).YP53,6[`d??m4`PF>:y!}FYق]6ʩ??>=- MLI@吉6ܫw4^ZX»M[(?a>C!0 {sҘR)uHYB ETD#[ $AHVBm˖"4a+*qj,Y &2fϽZ$ȓL:î77,Ǧt֫b75(91WZ8P5"tHX;o(۶qvC`Ts>Fg:zs7)NYh4-\:RQ0[lcy-XIBbH/K&z.P?a[CRcq;M|9dgc 0q3MwEDIV^3eoo@tSD@hJ(tK.T]&$ q6LǍ;鯻KfC'eI@d9@Zx95̪œBt/ $cɠu7թ7ѥ:˫&2{hO5zPqO'/ݵCXZf@sd8üGHIW-۵w[VXbI3Eųs{/;!h4R4ԡr"p HeHJٜHP X1- LYD$OX8m&vS x̌4i ? gٙP*D@Y"2,>ݚ :`t=r, B!!Ȅ* H$!"b,}-%xOByƘ$Ɋ"~}99i@&e=^ɍ/A-ctA]MwgšaA:Svxɧhi2T2ˆ:J49QB}. =sq}f;gTL,vSM| ĕ2trspaǭPgHj0IW9zձ,J@lŕ28X1%mLd21O29aY=Zb X?~_eITPEIHF1 R C=ag.-Ҽ&Z/7Os쳄d`(qt vQ& E38VBtƗɘr(,EcW](TD 6<늻PB7N- NMH=qݧG|X[/|"Lu'͖+B$G*wF&, OrP QpޝM+ bA$ \IC8úȧat"&!"Bި:șCG G^?_[&}"숌eAֵMr e@hb9x(X7\F?]`a^;1^o\ 0<*_GoHmɵ2σ-r"o@@1D`Ϝ'yDV5QF} |5FVѩS GMd"|}R2P'Xp%5mqn`s &w,-i`oH OF&#]zݮ_qx38NHL֐,t:{VVuoۉ8N#{,L"(%3a7(j{]kPFhDI5[Vw7a:|I RF"n"Ѓ9x=Gv1Ncv\1xjeA1U$P%ṠإNfJ刊eWzU^&sX1 E!IHrh[G.~& ^ҺmvIK6ϐXM4z%+4t6S(u1Ȟ$b$` +oy0zBo1g#ƭ- A$0Z6 bL(Z{zb:4SiŠ#x&RRC%Հ ?;AR`rd*07' H)$hr`o |S̀Δ F]zh'\/V:}* T^Ʃf^(%~mGI?$2BY d%JP;2C~Vn_3!C+{YŅC#ګ4 H4Bwt,`jAY[ж99y p{ wpHHhx".+a$JBҕB"$ɂ1gﺌ WW;tudX҈?J~,aD HCwe:Knc.}]{Wղ%XWN&׃cZxs)дf:-a #e"z4/a 57'1q|emZ4qsqj$;pW2)a,xi7?&.^}|ri9²q,7O85JqMw-Tu=@٘"<IF|ۇӶvu;Y\/5zI.}Ml e1Ck/I͐f. J,QE M?|q kry4͛*W H(h29߮.$ 0 An~P+jAu1٩|P-j8C7WqA00JY]5S(n0aX fB[oq׵ERac@;$ "pv's 8}oE<GNq eHn!^7hW6-m%/r܉\%;߲TÍ c%';SGv aD2^q!`{g%}䪀 RVLa)h膤PAD{Rvɩwu K9$|c=٣Ȝ?=ݎJ^Rh#LJ֘MV${g0!`ǦhPsCi71_i!RU "ꣃSH Wфs g^Ɂ9T7oz0 YlH "*O-$ڈE"!]0jgw2sةA)eј/A@bb$h/y׫f'D#EQ2r2f70t>Џ+qyVզu)BE\.SbQu@(A1߶;L0[9PN[4i6*hia${/DydL6k]u_{\hE<.UH]T+QFuv03Ѫ{<)-b<~NGG:N:mk+P3)!@h',Ax< $yZ9gvTTAR# ~fx\7,F[w6dػ#P6G^C -lm A_*׷Piڼ@QBG\T<0_~Y|%JkW;kH$wʞD$K~?  wn,]K|=,{ɼ~,A%dHOoIЇ!!y]ʧ&.]gpHȾlmnWuz=v <%/%k(XY9L2B_ҟj}9C>ڎL~_>2I N5:Ϛqܮ#c NvbZ`oGw/t=~p6&U\=Dތs [_C0x\ Sj`8ڜ6nKH\] ݠѪBIX4WHYCJC0} !InY;1>pr8avyX &D$Fk [&-k*!hoؑ:d+G@DL \{!܅!4cwI¤EjK wG@0.X{|=@ekj! te-@(lR.kcMקig[qJn):9&R`sG/%6;=?Z?\cEξxNokd߸8[fO; ,TQb( E,PUQcD@$X (EPFF$,  ,T AdNƸ?ϻ`ɨ\҉ :ZrB :!@HqV{E3j 'wc1]n(ON:]QI'VVrnޗ/Ylv"(UXEh 4D"Cn%!P#΂:0'D]eWc|bC_بV6c#4(h{mXλ#N-Iw, ~An"A`,dR(aHTB*PX,d, XH) ! dAЛ@d@t&i؜ZCA_ɤE" w6 4[!pfs7CpQ[yc,t4>Eev $AљN*i+7UX_Ho>6tUnQMTܩI;E=a\KyEd9%fX߀Q. LI}>P\+KिEZD<@ IW-vT@[ME~EsB/SE!&>;[ SO ېIŨBTK(!"Br MTqt(dv_GLE{kqņf!#lvI$|Sr D7)BC#5OQ 7fO"â.g_Maltt_j)&IG }V5@)RB > ?XOGMo2-9ZxUDTiVe aG,@Hy} y;yxSz {btK;bS]|6G4 G5[TFvuŷwѝ#H  -AJ_P[ xs(`{(̣>A$+RCƠNX)@ĊL/[Z)/9y O0(6 槊M)`78|V.{KG16B]Q5Tf{p6 ě> ʩ;{PtC/@?+QĴ $EiH"!$;8{:Wh.qI#݊sUKYuKƎ)1:|~PU<ŏbh 9rOs2d5 .nmNKni9q4|އ1%bHO_ޗ uҔ8cvQq8&`6rɋ^'IA}aHH "] gENUaL'K9kH UK: 5 7nn&z:lU Hcq(" gP0٧ >QC8+8G^9HYw*XIõRf( xԂW42/[PX Aɝt-D DCF+1a8&g5ˍ../?jR>h{ ۰8IrM+׷yY`]W=5=48lo=Z-;Snk}#j<м* #X"([ݻ}b1qڐ B ]+aE$:Ckh {UWQa32q셔cux'nM$Cx1pH(o=K  MhXK|SX*r`;e[owĊ.MGac@I#Z0[^b ׿V*S;$tFb kŵEa1aHnN( P\"c( "l@&~,4hyg`ybmF~Yz6gʁ^|* &޷iH"z76Phќc%M&yh Q2sBH ~DBZ9"Bh4KM*b. W]Լ8ӭ鹎 0Nb[ywp^i -LzaWŐA(S lu )-e4=7vB%M@W,EXH,S󣞾cѻ\Gi`3合dMn`lCdJZ{-DHեh2qa9cnL*tn zҸw;ٜw*LLDHJ~-xՕڳNPojxFx(/Z  EB52)eRQ&LcPXu;}w'ѽ/mS _Wgk oKHİs1į RL̖ NGiԝgW!i [u DdV2bJq${ϕzv6Z!$j1sJEm&P"1FpL<$) 7wr"xU;hQ>.@9 _13R.`7eBV&#ç{NdEyD %GU^d(﷛˂^Lz n,hb!BX cYNcq[ZuHz,Y}d,"V&^Y`ҡԵo^p OYr^:URylBm!bl/d:Ԧ9Dٶ4U%kYQcLTEZNb=kӟ8:y:v JCCM`$MbeW6y`iߛ"W\  @p(J ]Vx4/E$?&{"\ai` i2y9ĤUYY5s\%Nv|&RHunck>#:HH![I03V`~hY Q7 1DYYbEdiG.C2]*akeoJro1x0"H@oEjP* Alc = Ѽ ĚR2~-uEE9Q%qB`-dAd$Wj84 ;IHEZUqȰ"%!8%"U*Lh4@B E@!&o3:F*pP)r @*&ۡVq$1$8 @a6f#HG,^gY"H3Wd`kR, o>ȈT̂1)ZJsٱ* 1C0̘=O{tOW PٺogɊ60~DhW =;#cśRPpSt9H TIīYtmթO-7o3<$tq<.A; wȆ/ 44$&֫3)s,q4AqǧcWg  VXIERB,E Ϭ_B() @XY$"*˜r'8&3s̯0oC21DsZJxBEmӻ ㅓ6|W:tȈ1c0Z1ЮNj;߰9GT)U z 6ŭ"60jZ S`! JqeBoGڈIv9]ܷCokvQ*_#,%?[3-D־,׫Zg/O}w5A`ihnie5'dsa請Ix_Qwqg 9d` DTI=t6K4 NN6bkgD۞Ă !8:s0 WcX$yd}ݐs|)y(xFA2#)ʦfJ*g BД&|?Ca^I4qcRd3k1&+D3lj;@hT8PVr^vcyAK Ba #-hV6W32B`]km3Jd@b 4W/e LoU^c1%m`"NcrC|",ÚWMST"s2*L`%蝨 "FH>TS;0PEoH5A)`销bOF-H\ɑ耵ANyYs>x[ƂUHE2r H_%z9PrgbTMjbݥ]gSG2kL%MdB|ĈT;fя Älԛ$6S4^\`7͞vH2هDUoǑH4lxutC1 %LXfyHn0NK"Q/g*3X",Yi<Nȍ1r[c<4<nf k|nm[$PI>}ZTvS:ZKu]]ſj{˦ Uh}jRJ&k87 ze-CiqY*u}ADEo(>Et2Q>)ak!9-t1d 1ʱf.D!T6+@HI$=ya.~#F*wI:5 ɤ%hAdq^aO*ݍ)I#)彧$]1mSr4)3pdjrr=q8<%I :zv۰T!T'k;sH~F_pl0UqO?VgzduyzZ*gԸ).LH?ktCB"RTށN5j>{*JjP GzOl E52\iwuYTwruamxΝIIk ;·< ڥ*rʯ341Sq; 6*c7}j9i{"϶1Lǝ:]̓Ǻ X3a8dK@Gґ$@Ģ`5RX k!X $l(rDoq]ֽ(&q7(ð&E 7;g$a0ltYTNo^ʱr9ﻶg+?Ynز|K(mI#Ar]ԃ-SA C)c-xA#_NDƊQ0RՂzv޺u]!>8l_ciMYXvTNDMP.3ml̬| Ya0"?Pc@ЏZ+/е;$ yxW@R(syO6p x鳅Bi3< mA'P/h`HJ@8Ic!pPB}LBH$5 tCŋ@0)_|̮=r~Fa{Px9c>|whOdN$7(IPj^E&@o9jXXm[^ ¯&ɳ{o4~I&O}_ZP?VfP$+B\*_Z£$,I}$YdIXa `(@) qY$H᷋N7 \7 A?)0f3.yf)w?e퓘$^ h?k~s$ipE7oޘuno<^-H6(&' 7_V"6Ƃ9$w'01@x \@vL@BH6Ec cq%FFzk//q5Mڞ&$a(7 h0&Cf~p&}[RjPz~cҠ 0S~+XF:,=<}Y׼HH,N d ЇHd k071-9!գ!۵^>uí6 tвj$eT-0/y-¡Bx@Z=W=N,O cvml7R0Gsn2, Rsd })P!@$S$Uwa3䪄>'*߫DghQKuq"Y)[zD=MPBΟ)@+v(Px/>2mZ ˒SnQُy?QFI?p>x$уu~~RLU_ٺI+\O}Ј>vTj]'R/H_f6عIɷYϮfoږ\@}/ *%={ݷ!{I9ocM.[gvv5%ԙ*HW}}z[OpW};9X%R u&HHA"AF$a Hd)!Uj 8p|n@ʒ "$bo}zYXEZH4AsqKU ΀`Mf2KbjD@{-\֞Qf~a FK7+s g[ ]zʇ֫?uEy \ ab S@Γ{VaèS{,y8w}q}! ?[QlqEJ9RL 'zqI9]!8M"z` _ɣ^3HӚzlgo\l׫CvIK_C/>4yǒ k~Az6 'q/j_gmQ'{l1zF8BtQ4i%~e7XeB@scJ3-f849ᜱ߯zdm9VuD!ŊEQTU""H(T""$XDXFHE "E"DT_ss:ךꩿ,Đ1g9O hynQH$a aFL$(x*#A~{D?Ħ<z̙DU q#9o."5G\μ=KmqcU (JsX[R4K|tY;mbϰYU`v9u #桦k1 6QQ|zv+I 4[R/i?_|rˤXx"ԃiuVQ' >ZD oQQ(yY$!DV= ҥI. q kʮqq._=<$^vw [k~[uH@{r;]lu4-lA@@(D$JL"̟WsFI 0a"F- jP+AV1PXV~YrvlE'B ,GPOSEK6@ċۉγVrMT M ձA G. vkHg]ϝt#K-AT -IiXq ce\:J:7h>PVXBQwOv}Cnt`xBƏqL$<_K')>'Сq_RCEwҿk!֧fPkM+< xx7%nW#\=BE=.ϏcB1F a.7mS]"ŧI} hD˚"Y0!de6rԞ߈i5Mlm,py*";C`<ܬOWb8H +WN \!_ԯ5#P]홒2 a_!GE0eofTڛBr+͍)I+=| ts$]RAؓk_V/xSfP (3.P32YHԲjdSPK&Ӷ-ڣp痉{6NuOnٴu)I, 6z>oGҐ?G7õrK>Uj $V&(ڂ]zmׅE- h9TrVr|^vѸH,Rn4МFJH"QPTOp,;˩6_+'|c\p1O1N-4f-j$D;+gד IDH,b^E2oo~^q!($FS Qc/vjοG}1R>O^T,`dA3U?g fp&-b$ $ lm`yRKu2oh(!]9wD=amjB`>Y }9)o%&뚯jvI]x!N, *wET'dakU-U)YBKϐ!YU0I$gYuT./՗zQ8f $|v ᰸@U s8urӄȝ!4;a D@FY .,$% <%0~6 K23A`39iX\s۫3}lR&wNC/VtkVxשPxi ]/䅣9E/kzL [X頯mpt+q$BHUR`1Lv eQ -J%͗}!HDذH . }arΆjWyOUTXsŁ@I4fS$NpjDn ֵھ^^Ly$)`9dyY9ګ|5R{Ou\ܧ7/HE 2҆#4`ZagZ.F[{@ѳ=JƱDq@uTmgCPJ#b,#a|T_%j$ 2FŰLI}XM Ȥ&jf;Led3Uml6*ցL*hHIS"d:OӕFFʤr`JA͑jeJ)2(2N "l\l&ʺJjI6S% I0igU\{2ilE&6#l@=,MR6BKM!_F @B5aLXTuX]ocſѴ̯s>Ie 1U|+k<ż.[GWNi=:eXyTnVr4r} !)4^|ğ̄@ԕۚ8%K)V(_˂'Ry+4ڟr=JZ=ܲy1xS+ɏ׹;:08 <%ܐ\O~.s{xEz>FSn QvHˈPXkwOX򡂱>ojWprWEkH݁xNHɉ13hqn бM6=ENC.sҚ-R<$r[_oJB= ȑ\Oé"h´_J@,bZ)R9֨k9cÆCn徘 _GuX3pYЂT'dwWhr޺1'?jTYf$Ȓ@NKjp4loGY=Ot~?5]N1a=f xgڳI$N$!6XzݕBރ+Ԑd"%iTHIDnLW _+ZLB2^6=P8&z];EW>ړC(|jA(a[?t_w=7S>srO;fwFjdrg 7Z}S(O~pRXOq2v*5&_0i6b^c Kӟ,1,*M4,]'Wǜfw$VMRٓR'*H p[#`OD‡B˵%cz2&JH$,eHKr`i&c º-!!o̺*CiAI&~DI(XNԴ粡UŁ29mQ@NV^+tb k{+8 sea#"1+B!r✡&P<蘍wDAzͰ"*>;(@H(Ǣ:'d|j weRdJI'GӐC2  |l){?AC (e} .@v;[ HSCͱF-yX>nji4Z,y Kؘo;.~,j՜G7%l[;vqJR HOPF:j=^IFtt˩JJ2*)i7 ^u (@3<4P0}@!S'/]\ʦʲqhڎB=2J$\7j@$ W{\Z: ! 5![B$ö׿;!v5hyºS)'D_gC~ 'y(@B@!8I$J()'Ǔ١ `deKSK7 q]g~#- oޖ L F5!ZL `@ƒ, @}pIBȶo'vD r$K7m=߁7?> pH|Lհ;6@hIڰޖC1*RxZ^oO"{?e`Ou<<>3hc~ B$ St]I- \3^N:,]-;lq[yZc#gV/+E=v(yi>"Gcm =y8l61`~ƠsU>SwE6[_qz tA=|iݰ~)ed uNAfJvd $l#3#!`I#pwD*q+MCCv}΍w{8q*XKX૷鯑>.o7vrB>BՠVIGΦvh~ƹojc${<~>1vK&3[kdMD3%.Vϴ^VjN~[]i@6ͅ '3Vt515BcMT!5Љmae 7>ue**@JZm-]bM#QP=aFpӟԽʈ%Þ["P(yGO +&j1BA5hw]qv>o/<~vg'C6p iS,® / D _Jߊ`) :OG`gSow;;¼^4ݰC%hY_=_M?V^3 B6y N }KCQbTE`#+y,'%!*">\OPݫEQPUb(`Hoj1nt|l4fq^1F5\%=TLqYA2a"AݶNtkvibwN#փhWxv{wUn&P{Ht &t9R%4 wsS.~ neV_z?vIxd AQ{Nk~9A@*΋I(t:xE:{\*@R$w0ߦfLݏu>&w%=/D5Us"*[t|Ip6n륢){욕:.@B]1µPDA-W~-[CDW9>I[nhGF>Un?>qZObbݰsrV6NS:ƀT]{Ojo(ҍPAa_9wNrY~CY?GXqTlyvuHN`N4S2Bs~Yo.ZgfH ,]ƣp2Ft ] i&? =?!H u3DV 4 "BѦ.?N9$E0] k{꣦_κ񐟢G?.ڒI #D"Te3NL Z©FzIC &{@)~X4DL[*J|JwaxyfTVjI/$ 8IV?(@hr3ZUd_h]mEhgU=pp_`II$&{Naj,H~RZ,s,p شP(sɵ_ ~ijE{oi }`}8BBcIܞcd4,^;$ xy߁tu>e!@G8I>E$=3θԹkB87;ŎIiޡS+ía=4Ur ""Q@zH$  8A x~OO&OeWt~8L'0 訄>_/ZŨO tz^m73bmǗA`G*Ҥ!Eg)!(IIUF'Kt,>OYGam*W?\H dﵮ_WW3oWG\oQes*6mH89P25B4Ytg=#> =l> O' N92~=n&&RU۽l ޲~['C\G $ -~ o.Ҫkrp=6{76>0NHK2[wW!\GF R"ʨEv͵{͛oo3K >ovI$NhH[S,X 3:_]oR~mp/BP3t O`YgoArTA|DdDύzBGD;$I2vX GFwd+ 2wEE{1ܹwNyt=GO{]- 3ősf{Ȃk kuTD "$ $:V@bӝTdžK`TDIk/?odQH$lq,E)\{;Ie U3!t8u[wMݞ*Df|-[aG8DB:I>̫r%MM +PI* ={w0Rk9dԍOkׇ7/Й༤_.YH@2;0\5jF6 *H ȍec$Q?Y(|4] ,Iż=}oo7\P/ fϛQ/*U״US\!X$ )7Q,^dX"8Thbտ#ϳ`+V4²v, `R{9n"@_UT{+)@YїN&4f-+,XO'NL:^WA" ;e- 5=Kf7e!"y܇yfkٟ#ԨHu6e(HqE[QҬ[MD Wjʉ1QW-:F@P@5M"G;z^9FiJVj3y˴ ZBԲ7vƕ@B7Քߜ2vQn?f %R_A=$!VD-C) aŁȒR![<*A!mht8)W`h#M,p=X9 6vA(p: n?:2 Β% 6;, G_5G-se8tdYL&s^Z4łgʻ?O%[ó+=jh˽FV=t ^>ˆ~ΰ)kj ?O3hliC(BFde7&hR%i&&YdU}.gA6o`"xvd:N)FZކ>uK}U8w<%<_cYZD H-Ό7 k>Pbձ `6gJ]M$"A&1B@_i*l*H1%nZ!&e쪬rm]3=-Ni3 5P)RS"7DӠQG#Ib>AC*^m3}n4De- T0Z8S2"2ggK YDRtI f`iؾ ;c;e Nc+-"U4bQ:1>.<˓UA;x$|B~I۶2\ 46TAl ]e k+UM0q\8ONpB, Puj$w1f5@WFA Y=|3#| tݵ Qqû$nX'oCt{sp2:^H3꿿g5{붲9j[V*1C!T !dC$}#$ GM)$+ZHgQpyϰǽ-ߢ:/Mc;$'j+ie߿YBA"CQSbkr=Sd%s*HTUKeW]`@$ޒ8?DIEH +p\g:Ot|2~]Q'7LSɩ& $uGQ ~Ij@(ydB@溗dx5b}ʷL}a ]MJεm&;z P!!|F'}m[%z!}Kn4I?24+qVT ԷK uW҄kB_?g@ JoURymQvS_:gXD`=}mwщ$'f5W9E`4>Yw>i\OƇQvGPKt Ÿ{I6Nv/+]>.ob?<?6_!H^t[̐ږibxG?Uwۿ`D) fZk\a]U"%zܱs(aP!C۾g23 ?Is>1)F&5<Ou[zW+AlSoE="j~h@5.b:*%CȢh\Ӷ{?e3,իF'QY@'?{`l}HD! wت,V1 n^wqj=^-Ri"qw Sɬ<}q\~=6:fk1'7Y<{0(޺Xѥ v A:-`Y8ygP+J:~$+[&7X#Dq̜bAd @C6VA`AZ5LꁖCb@Tl-;u0|⟫qaP`ټ$FN`i]TPAd>P9xb(vCc<А4fhD(YYGϡЏ:Q ТA+"T DHy_b~jDH Io$F/!_:D!X32bn:OH ,V7I'((Ⰵ pZ@Pdņ {tER0QT$DP_6a]nmWg.S~ a0F InQDX‡k[rdLj2ڂ(`x$FEe`o}O{xjɊ4|Zo{/EEAETT{*dy"CH|?#};{ ZYIC~qd_Ӄ䦗#CUU7m;CtqD( RFإmY5g%E ABEP0TX_cRIuZ(W[TOSb[zIH&NwwY~W+ L Y,P(߳.fa;RkjuCQE`*ŀ b2-&  m#uwk4yΩ\ ˡz(g&l0Y $ *4vV*1Q- ؊DZǸ2B22$X C_>@N_Tidv\Q LiZ$`hMS5폑ƈK~ɼ~Fiu4n\5g]6nɻ5E>U$CIQL"2F$*&JB-h4,^k G~C=%& t;j4?/H+%2 @֢_7On`q+,LFk8:Lh$ 9j:G23@qL$'ˢZ\(@KTeAev41r$ƕ(z4Yߧ=TD,’EζK׹Xp6$r`] >DվHF[ s+sv|BIqzh8dwEӅ;s)`1Y 4[U9#igqnp6orݜ,8ipVmd` L)z7CgtIVZ(tgd[yw;oEKU>O4؏!Qa!5IGҪq:$}#78A5B wr cKmqvywzG:C_mHjܙP?n@YvS4ի{Q<%B|L3@$kCb8)z]N#TTՐힱ.2߈UM͖&v I>~JGtw/ٯ.q'ܱbۄ{$\>HߥԟuIJfI1V^XOƛO۞ , [NN寭kryEsG7W::55BI=2'3ѧ {h+b"Z\i~'xlw= %Ie`z ;&H]WgpjZnz~/'i`}> 8,QVSCZn2C8FIT6~]IthCq14u]ӥ3Hʛ}gE=F[ZQ2"FKTQ6d N\@f\ }2BS4^%g)'X_[>VLEEJKЕ:(p2 !t'`zq@MSOipYX^{7>q!z;+V5O}F! B2  *I;S\n]Cl@Ea\) aܚ=z@=!CNڤYw7/4 LPc7ѱf5}c `ꔀ\= +)<\Y?.\.5>koܯÞx~fL?BB@]g2L/)*[٫g.H& Si?]$? "#bS葤W(OC;_,FxMIx8d@,r#ӠLf1ipv4ɤdbIS7oخ_Uy-%u&ֳ$dpPxDA-y*t@'~U0lQ۷{{;MQ篩'Stvٶ;B>ߑ/ doI`-1+Hu6]ttçt1;6'mgXwD `A!8[*k+Z${~dKw sg%ofK` +_ne ذ=TCbhE,tc/}"pZtLY1 "n 'ُ"hu ezz˃,$>xEDd @zs&aDAbsTuYo}濋EoIZ0t |&rou$`& .Ƚ?qޚ+@EQ7SV5C1' ޫ-[- @đr60DV“4 x&rKo f{rxX0Lɟi2j:9YJoK΂(3n.} $qo!O[ϛ!`0i+8*mu&-%bP%7HW纓"U&&Ђl$i]/RAsRFPy!櫸c}01Q$ަޢfy.oLIxFW>GvURY:xY_gX! J8IUXרe|3a`11V(dE\ȝ#m4_h?߻(}2J-! b 4svHԠwY>w".4F8HIS%hvfaYh:,'MC~].fϓ`l"TQE`ټ襫NwWUů%(YMU0洘8@<[̚>6g 3rq*V!vNQ4qعV=P>T%I1韚}F,((n.wDžL{\GI~ ʒۃ\v\)RCY!uH$dY.88N$!NCt|!m`p,u43,&uZ)I&bUFji_z 9 "n[)eRjq-$"^iih\S`( +WwoM>-qj"(  }R!%t/^rjCѐ"x,2y( 1# %tug`FZvSr)MW -{X&f)zbE08xyյB'N۹ٌN *%UPqix*\T˴%|ܯa +n\V𵟚\QIGzu9.WJ?Ig!:+Hc@kf&lA뽪*&aqkr."Qq:s/Y8,`}$'`y?a ٢qvy :XOWC=1꿈 (ZF \TЫ¯ jAZP*^_Ws6 )>c7}: aQX=R :~Xҝ]kX6RzȢWR5BOx9Z;{wqsi4,|c: N7 ʎf곔_w458B}Hz6LɦBO<:=[{2`r&x2B }Arw4^A `lPSV)䜐00īz ܺ)S윩8=B]cM (D@g7c0d4&zSjgTwCUHįHɚMp~hWu8W~n)DW 3,1,Gmr/>ĘO1KL"B;RyL!!}<^A]_/mK͸ڶ3dA;&A9!߹RIj 55Fdylz+IFm3~>fuD0; &J[g7ߡw'el< (ژߔ,Vcs*=֗~ @A"3H&Fj7_w++;$ؒOp#;8̔_Z>Ň*ftONzr%'/k)EP!ztM_0GI Q4TWPBؽֽ,ֵg݄:T'3(dvWP!Z|:T F5ޗڑ kdzRvAyU1q &cUU4ת8 3a%J7JwjZo h$o+ >P}9N>,P-YT 2]PrquBpU ҅V>| K3@a[["+; "8_ hbHx Nzq&1J ܪ>d4;,T ZU]e .3k区yY8%5JDҳ*<^|\0Qnt4ВEPG;䫊([9FGkZw`č^K!ˎ*$ $mEML(bM@OR2s˧a).=!Ks%I晓-ciz5h).G=靬Kmt /6)[U~qY'%PEբ<cU0( [Ykp(gNF8ũ-Nt`D92A$Gݕ$NU3;c FCȈ9Uֿ\_zw«Z>;5Z" /e&oP+å~ñg^fMw<BMCx ˅i0VUefDBhH\RuW?;:p.y:CFPdINCo-v )\Rfϯ]޳VVO/A>|p>"aְ3Cq^nwx2fY#?CK xw]OI`R ;4Q}p?BӞV| Q9@J@ /$wy Xy>TPW>ldpG1e.(MOvw #0CH!{bG@B 3Ϙ">fZDRW#D!0 WHď-2|tL6U $F%e5l>g[̏Teo:|Z@@h A D!B'R~c݌J$ygV@=ЕY3Yp~o[T|(M5_! ;dNS> 2&l~y@ ]~nFYW췩|4t6H/pxOZ@GԙwtBwRbY26Sݟ+_w<5S6~jHzHhgU"!$H(#1"1|8W}1H;YʘtЄfDًġ>SvwGv[|˨SLTTgZbiulpK F\22yíKN$9Ep jlOg[=kv9Jo9C,Pذ"_-/G`H^H‰ZW8V[m<a'di!NX].x'`]c=L3n5$r.k%}W5Aa' pMQ$t~^ ZUzDPH4)<0p LߧMH9{ПXj/O77j D5Diӓ0eoZC,B^"dX,X3ݖw|ͥOt-2q{PQd0&[n@!AgS%5qa U9Df aM[dȪȂUZ:_'-@FgG&E45n.oyhMA~#Q|Bѥ?>9炊8 GH5b3eѿ& .7kU" O6˲p$m5UGMKZ[wLjC%o 7BzЀCg OH" n@w8Sw0BAF)zXgfES."|p_ī^2O ^ u}g4~/=k^ D"(*`//oP6SjjHT>H+Xzsw־}o^vᔘ؏Vɕi8>\/(Bʞ̅s侑!{8`$m4Ou[֋7b=l潍qr<vU|455Ё:=뽣E3"J(vT/AO鸟 QNxQZkv&^9XV˂_B6-@#4"RG Ѝ_1B f iX׫Ƕ杠W .yypc/}{XƾcR ɮ 'ŜHE!Bj!tVZO?>[HrfP=4t1⮮ֻ<@=og3 zhiFb4[0z~ZT^L/OG.KA! B GFD\JNhwql<(3o[5@r=wd=zڸY-Y DB.IdaiEvzk9V1 3Wv9o/א׃JGhH]Q<|&G avWcvRIa&o;վвD4_*@IfW0abMZׯH5FN1ŀb4 "uL)E_bh_ V&/[6O8?lahI) X˶Kj|"BDw dGnwbtSF(Y-ߗ?/ȩV0ْU %D&\hϊ^+ $4MLJA$!9@u!4Ԣ SesqUbwLzY@ a( x$wyW;RkuViPBI{f{PՍyz`(W$.E˥ɓ_^C%Aov¯R4tS& ?;Z1e*U{)\ @hyYB9gGUюہ$Qxר3UU3>yp^9 Eo.EJ0,*dwzP#5`vXtڕ#  4ɡ uض,P%ixQ5R&뱗J_=ܴz<7SS>H&smJ(0)QoMPVjeLfBQLƬuBeS`Oz]vl3ߊ歱;~۟n/L(e#D" Ч뫁t̉z8 [J\j\K- -<2ɋ;WuĶLOxVK4@<>VQ!I,jG ׍ ڂ{Dd{\D/)h*X?1;1%%G>oaJsc- ʁ8<es[PQvEJBrn7]IR;a^Q?펔haQzTC); uL.e{[8C]|G`X̃,T.2|RMw=RFNg3Z deJByAIB;۲* Vqv^X{d.:Ft&{1lr*j1"I; ŸaPh+Hɶ̥X-ӭ[79>;Tgǟ6:M;N71! &6H`4&t$ ORighL䆾/j;6`^V,f^?m] 7]ũE4#Nd $93 )^_6dNydaܚ݊B ;0?P"$"OUbm@i=cqeԛh-Qs"kWpzuQyj J0 /=pݧh費p*77PIA}_JljS9NfqݼKf²3Lne4$2o>21D&"IT$@J-U0md'y"'/9l?i# @~.Reiqh5:H;A$@)L99gL^4yNU(n@QߤKLe22h)I>k5=Wͧw;O ?,f!}"wH+Ku} !fmz*5\0'Cv?}ĸet8_]苡u/T nq:0a@;|-$?oީ+ݗ]CfOvw{]+:lJU)"(}'//Y$"9RlBYs\B`B^of OڞrErJf_"DKvco<= a!|m@*%h}u]4)R('E9 S݆!:8UTH8p4&SFlyvRȰwk<&>ÓR`5WP?}m4m3%+2|}EE1c븸ŭ2- ZhZC?<э{X%ި*|&)6-+BD:j"z`H$c_AEɀ)AI0cS}s*Rhn*VTь8E4TIz1 }>OIAQAL-.̊'_sUj-6gR7˵\vHDO}ݦ7^nhy]1Vr dȗ!-o) DAEQ` ׆Ҍ.Q E,I"Ԑ(p!󿚐 J,ȒCF} ͸tOfwUÌwQ p.5~9-%%$@@Hmf_J;`.yc^"v\6,`=NTm_H.J*U>GAf 5 D*!p:0_:h{MsWU*yvCмm;3 .Æ)1T @َK p,h%&VHl0ὠK &Yr`L'N^WF!DI9$ߎ(p:L/MZ.)3:>=Ʌ2rsN TWN ":Tα#F1KGvpAJ-Qs'^uPaР*B~зԙ'(n||*Yo?Y,F٦J놧^  y&|VVXHaDEh5b}A9o1L711ZX: Lh𪼵k{7$Avt⿦,z/vӈf8vo6da+ZGq*k*BLsኊN3JbslX1-uY2yêZ#4Tk5y#Jr;lT""NA?C@|RѨIe% 3ME]wj7;vg;C[i ndšVg3GڹWB6!~Uy6*\VD9}YˇHmr:ʖ3}6 2'!8g5awɵ|oɇzIOݠpX4VA^Ɉ{ˢFdc''v2 3~49f"NB"A$y3.0Rx9 $URg 11g4P`!>H%!UYbj[T/hL!B1!/bYEgo5]ߟ#׼5*nĞCVQ!!u;D}%9n  2byոޱD35U̱|K2o>lT\KzLyZw}W%b3bp# BEB^`*u;*jHFj+$C-&I{{T.?LJF]5605*Lh[.ĿK Ԩ$"qALDBԨw|\ɎP+VowMе6v{}Od '+} [ԯCBƶo*Zˆww 6/Ǣ\ $S;@4MExq'yct4s:{y]yWژzw8w#|9C OҸ-o,ϴ` Fo8fUnê9޹ϦaZ()HHbU'`+\m-BJ13Xa~hS0ne0$pҥ~QLa+XnOͿՂJ;w9X%LPCԜ|YkMww\A3caBbYv[|z% iw} cWr$8KA!0~2P8~"Xqt 7̂׎ 4: R 8`bgJ#iFH$^\9z>{UrP'M\`BP t20ozzvm]iEMiRKk:W`UU`ADTY)X"GH`9l?FWiSǤ_͌ѺRqB!P @DCOzx42JQ 9pFD2h'$Z.)n(}@zz%QbB&#^m0Blgtzi] }~,RqNUc$2дC3N':ybe(O~cNNk_ [dXXA=b0I=Ʒ0޽[O *Fr]8U»;Տޝ6rZ8/Qftx6H>hmV8؝md Ky=mBӲ%{Ku<BI7HH=  p0ig$T9 '=[ `DH߫R$UQ 'Cޅ%q?}%YOKY&~"TǛv K %o| $>1V:|皈IyFz_'b'RsRf]YcndJ糖;uOS QNΟ<3_%1+=&È7u*TrݰhܴKy[k1dv[<۱9N kH2u=' *`/ 2CDO8Ls/>Nڅ8^lV_&|fIV$dT3=u=eXI G\sd!! GHDV_u`@q۹n( ]..9" $sESF Hq)Q'; pY:"huٗ/~-@-&L5Kot%3:{ >u*wZlh™n{A}b߸U6{褬/ǿNu}|bǧH}G&!!`Wi{/|#kkU@d5P?(%[eB-ȭ3Ba\ڕO{_ˁXf6)&+OydvZ>eCKa[jb"){I=;,Sê~ga? Q4i DfdS|4}rջGjbƥ hjBĩ*mJ:@?qxa>@jLzޒ #qulZW8㌬Va7շiH@Q"|KgC9Q_W`2\lEn:$ph$Yq 9Vmj*ʟ<(W4BiT鎣iIxVypn$&͓c쐙G@ږrs5S*aT(gR*t!_v{(8$G\m~7hܣ|j݆rut(ʍc}` [G H({,=HG{1M\p{FOR4SxC sG'vYSRnGt_KS!O漋W\zj*%1_mɪ<\&Xi#AFQ!)mp)mRҢ0SOd+ b I 7 BW X`;}%H VVE&Mx2gs*TpUi;UeEe~%Mkz(oqv`aDߛG iKE G&#FsOZ,"yɺ[n'NYXLL9T 9l9w_!iLOcZZx]gԃFX>$W8F %>/j]rѷRzٖŠ^]wtlj/S'*j"P]GY33?|FЛөDI 2#$X[A #zsDDH&~#{>28F,EU&*V^N4VTJ;'ʎ^U8ҫ[;)͍Άd离yv_Nqu,j-d:Dm3Btp ra܍sW5h4G$dy;XL 'x#ꔢbӌ+< .+%2"ųyԻ=j"4 k 3%v..IU qMii;$U@a  XE0DI9\OwOrGjH sz;ԧU=:c -sy*J%Z979ZJlLc~XDr \fq"F,VY)=\9-Co+~^`0POvlnVV~WhrLsn.Y%9|RfFU>^C9țY'öx9Y^"YR ׸.Z$}Q<8M]g [7Iqv wљǨ6+WO{6J xmYXS[tޭ.Wm="LVq >M~eeM.E\M8wYUl%O֧ؓ ֝m=q9"d]ghL٫T}/J\36n<m&C:2$Uxո)N& *Hl)vM]hS~x0Ǧq6אb/1 ҅I`6G~ $ @6Mnу^XbQOl < Og,sA'=8YS; "OܥE$% Jٶ_*`Z3h#t@hgU~BJ2"B%0XՕxkkVJԾY-IZj!~-n.ٺP$ +I3Z>6}lO{@$QIJq,Լ_MGqbD$ak|I^Po̪$ )n糔&l_?=HV.r-@Y %]aw$n /gJ9⍤UbR`$:cBcJ\i;/ӶW~wו_jr؍Mo]bvϑh*QVC ,5 gѸ7T >DU]`.<oznt^ $MVխkkۅġu1o|q\+S? Xe}b(@`b9$Wx`|'Z)s>U"Wr>g_YbԙLԔtKK" ,ئ1Ţ2 iSgܛorG/~GWkXRU52Mt%[*^># ń2G+>fPUՑ1t Vip*xM=#sU# ! h$(1+8^n @[$[@p$,e24}&ⱕڹBn/cRa} mXNY-w}/{ֳ޾@3MSIE`!iƣR&mmx_b`mW^^|Th*̝g.d vJVÉc7>UU~Ny[ӢQ\2O+%Dw}$q*jl=z7}U2Kg ~j$h)(4 g!H[-~cf {sq ].{W (|UlIMwWrre9њF\/v\B?WlD*C(5k6 ng[ab2%H,IZ8 13sƏF$ NXl#FD{3U-3ґtHSd~&7,/V_jٲ.wI 1T> 1rE[}C_#Қ%W᩹3B;TFi^IWt0&R+jI+G+!D$ B>eU$z5W|IGxuLUz} $= "A XK$pZD7M5a3!V{,cbA(Dx+U ) YC=\H?!4l%ޮaH'7X3;m`v_m{óyǝ@2$B1B3d|o*~xKV5nGr_U*ƕ9sH4WVr|D' iV\Wz\S"'!kbW}i !/ yY8p"@=FbGJGpw^.w; V|(Ců.PGwrq>'>Lg|`v-Й5[ɱ}m_ͪ^Mb&P+@>3N[,=1qJjmqNbd"[n-c-s>ExkcnSWp"CJs19G\VJq|JWZ)H/q/:D%]?$$fkV+TqckvoAaW]RLbSV$~(s#K.|[2އ^jy8kA3hof"_fjS~9YiN3H˜dDdkUo`'H DV|pmY׳\/@C¤htr(Pեn^@ \S lC&)y%nZ u</⫓V&s}$XDk*=nȈ3g(̸nuvX-Nt@@3Oqr.PYQ y+nIF|}=. e~W0ƷDm*{X6g1/;U@ñZ|rbYZ-]qV_T$Uʤ(ӌ y.iׇ?CU.|,p^zӵ}eCQ}},s]aC)b<'62dfZLnvM2Co-ĢݚGÃp~}p~MßUB2  HWc%YIx)oӫ}'+JImNu]N\3zqce\qp=t{MsosGBr1{'Bg,a)`rA~녘l5xmxDk|iY/G2G,Ho}lZ jmƫebNLiC("E^7C{i d F *"F`EbEdEAAa.(B(DdPQa+h[k /Dng7$Zͦ |۵KBԗOFǑ+!u_+[nrMs8掃bzT% %Gc"Ϥ i˅rCUS)XrSAd՝8HĎx0mTL nYnnJ,k]nhSZB$Fvv?[]g#^j VܬaZwTO,Kwޗy[07Po1Uq{2r'#0xH Nx$bJx(adoQ{tI}A6Wiˈ8R8!dcʓ=#L!%>f+5dף OQ"ĬE J[Lc=fSG[io .:1v.d J:px]oq4O/p*H0I( Dy (֙(bT^Pҕhr5{<).5Ih)p-RrLRwE\֡ +$khK+ p+R/u׳!4 P"Nqd) ̒R#$!,L@D 9 ?/4_a,QfHkr*r)e7)ӆtdcmѡDoBa,frp*Ump]ɉ5-giAo57l=YڠI5spkG#piy9i1.;kfk*Z\{+uզW#Vm~*6FMલxOW&gWrƇwa&V1oWVnLقr;˜lOs-yGǒO f*r",hXD(;:_rV&"VXfr{tP{%y|4 : *0ف~aUIClLTo .[w9wS h6H^&oG +İCP2W.CMowڊs\%`nBI{-,OGQئtq I%6'.ڄǵSJ^ĕ^vLɢR.K/h$)ϗ |2S0c\'U ԺN&crNU ɴ7(\ROm',)#x"B#PI!Z`х9mmq1?oୣN(sF?vG-mqOqwp iJÊ.En( b]ΣhbN&`9݋n՚M$.-4VF]n|_ʫ){cUCRQQg/yȁ34 ;wov6xR@Us2Xrg{:krg7ZqQWRj.&^IH\mV(;v 9>o͉V(o]ܩK.nQ'mrgZY*ch2& Ό-ѨW4i{B+p}YR-IYg}R|;+W AY=K3R_.W--(<oe:0$ Ȉ @KkOɁ6'瘮~K4ZJ˛\F'߄""uS;tYx<,鲫*7-?q%{CՕy[o;7bEn]RHx+ I[ScŨ=g{n̅9-Kaۋ^hygn;sZ.Mݰ̳jw ;]\Z\,e?WRqVnpfsL#8TwTSշNbEIvj;hpo6,;~y2 +Z;3Mպ9oYo۽ZyjqjdhrkMuwOkSQ9 s!gUg3ob,<rqh!^u~yTYHdfHM{-Ext/wET|1MwZݭwqu8r<ߗŋa!x{D:u&K(l*o3})¸N'WwmkXWB  9i Va )}Z?bI$DSH&7 ,< 1|M/2o1dy3 c8Hp_2f;:?sp^cOhdX:Ua#Vф8H jKп=^éJxViT{Rc-ݟD:E4k1I $ݜO#! XշjZ:q~bXrmC~᱄;j6TnO]ncnxrr~c7+Sν&GX+B@+S0~{NU0U@H*ŷyſ6* SdOqOq-$) R^Ɓ k=?nԠzJݫ+Lr,m~lxJLኊ4{'^vg@u{-&#{P>-[JpYWs9}Q@M:R%ͦƜ2 & Žf#$@FVQtR[Ϭ@%R}lvwӦ~_oWH\T&7Gꄵf{S˲wQ8?n)NggyU4wUgyoWLJOC{Ag5*]ʚuo0ѽ ;T <ǶOLv>ʾ#DefF-M{?TҤ4&˪uf1xW0;NO.#~Ȫ$(Y#I=c(> M-JdRw6׈16(~Kzmn(z.޶mE$\ܩ=Ε p*|61WuAzN]o8/彳op^7WKdQCO!7|e6'YOEW,oO T{??P;׽c/j6>oBkV-9'=yuS{I!Ydv4VǜOfBrknXY=-_/ccܟ%Cs:4Y]S6aXDpmZ Vrʾ;p4j͢&giWZtY.)h|oV/=!UX>\i$S,\qþRN ;>]@/8M1['?Y{07ZNnג-ϰVidrkYY%[-@_Jx6`űKU]jcs EY ֠/\)2 WڳGjԮEZ/՛G^aKni0ٵw/)Va)aKFOշMsͻq881Wսv'e(SQ 59ɽpjmͷ'pDHBÇ}NCVsՆbxkclgQO휶 \nZ^?,ݿlY2&C|b\J*JJ{̮oUh[ͰTOK\O͡R*n1jz?>F]˜oio%:jzj t}2%ww[\Z[oЍT_pώTΎ8nCg~| ?zӓmU/صCGNkVNX#Î9$ rrCSr0j GѝrQdaF*<x zl[nd3"+JvV}A H܈vN9ۦĨ|I6:}ct(='<-kY˴O{e#"Us<ܛ;JDd}bs|[F{Ǻ{][d%54-f JMh"2xkx)(vi P3&U;m}#g\Z rq =zhm3gq1B\[gC2vI~mlι;DusMg1~s9r;sׅa?H A17ZREP L0 0~7ݩ,X(zޤ=&fء/nљF:(Yn7,[~m% zgq2hҢ+fDb̨$",C+ 1$Mf mƸ$˩tW`ݳY\!euqLy) FYzUӕ k%/EvwΓd3fIzvCóLSfFUV`rBP[05{k*|mTY{W U51tŴ dٰy=/ Sxw?R#`|Zz^YGT19 DwX"A%< 󮧏ө>!oA(nKo$8&7=807ev -P0<2;dELi"]ըggF܉˗3B.wuizhN҇oޣ˥hЄS,i7zM=J/B[KQ:d @'qI,DlinQBlU0ѩy‘O€xiFדZB+'0B"g0 dPQH u ūt݋95-H9Awfsnh~r@z{8+ke.q2|EH^7m%i.2n<2{a/5"APC Gׯ`k9wdWSr:'_76=]뻍NAD!F&omO5}Y,;n7wTpR`Dܔ,pTs[ôE]p=#OlIEKˀc\neRw>H!ҫ{"՞lf>lmhe&fwq,>3\Zg3v;=W*etrw%;ŅYб9}`*!v鸝a pTꢞ˧Sg?v8N&G!9Ah9jUYMg?Xl_E辮;ڌ.1+wtW!*ɝ+Szb=M¬@PUEkk]m@T$$wV`f9wjoIUz=Ttu}#G,Q;4P 鳛'׺n63Sغڛ%/ʚ_oIwk@S8kj+{Q S^bȕEO쩫k6F#Cv"O3NlW TsLle9p ,= 6uqftp+Kdצd]~ LIU3sy2sg֪w-+#* 8S*~׃/ IZI֐:>gؓwf],\[AȽzcpBUr::wUǏjFOnt)[td85zOŝæssѿ#7yj/m<_o5/cA53h@"`$΁S;|܊3cxOC{ߛu;pDŽ"LG 11ҙ!m(0-Bo̶)!!D&ߩkqm[۬[i}{|oֳu:K{"EPA5 F QQ7X5cw9 o_8R &S1ObTI5eXoZD _ j +YĽ8tA23K|K E97, 7DLjᴿ5wkI@Yi(\w5Ys >ǃVFS %}~떱rz]ȯCXOvZGa^ ʭT?y! +yT\"ކV{ul-&%(č"AH ݂&8 CM1ro'%Qz#G#n}+NB^za `D?8=+Ӱm3xz.1Bö?%@wEh|!F['5x!GdK\=;C$iTqc Dh噌 C? 8: d%1T;<>eN-佪OoKQuT2qsd=UY60ٰn[g[|MT pi!\R;\>% C zZO7d%hh55y#x&#:'=y0˿7K-iwɰitJG7>3ǮuNCKjKkj/>KQ cHM&oYQBm{?Lݳq=]SnFib%"ȡ[]30ƿ^g $ =Ŏ0Vu.O.:H`U_pމ{99Myx|1*b&G{vď4pɂLh9^c4mz/8q[)YFũ@%`rdCYעWݬH "8,@! L/y-х(z߯=3ppANHT$#z ܔX< (_/\BvOscۚ  Zs\p;*>[DWsto⌫굑zʔ):"%p[m{/LB%t(n5 k!W=zhlzu7F#ڑ7u4@@A6MJ*+˵7q]yi >)G0H:Ɓi|7SH㹬zOKfgS\ ]f)5u1.x'^rN71B 29x!+NvxȽU=ф׹*@2Kdci7bzg!8|L䅒5 VOl@ w]+k[Nܺ)j Ir?]^dfd`,W\s>SPuum*u384Z C"y.;۩v/"kLtHar'~ gV|_::_'BqSA΢sÐ*C`{w;u(`3aE$2" $#E%_ZhvTIIJawcԧ~ׁ]Sn ظ7n xK$ NZ1tQ@؉)FuHH&wj rL \!٪>x +WfLk UǠn΁4\Dx5KW'C8N}`a۲`M:%bvzOXod!;ݢ9jDvf~03wJxX$f?L{SY3 RGU \^/%^ˇ uO#H|ALƞu*/N]PhRÔQ_ekUЁؾęĎZÊ$!g`\6$8f2OtIk$@P!!!!{ !$4& $ 22CРOI $~RqF}m:vY]/`;Zvy<=_ewjS:^ף|-l`j)4w1OmT~un*0@+O:12@KWhćH L^b*"(!@He  pX)G$8@x ~x0Ȧ'kԚ N'/euq;=J$!x$>3E"0 =D]JݾzHBrpLP-_>)oΛ6 $:$$ZSS@IeX򝚂FdI/y윓ߩK@ۓE[w=&&]{-K'LBۚ //3[U!@LY`eG/+y&b&uhҪn?}s; -_>O_GE&NIxhH{IY v^xþ7Ž-Rj̓>_5OmaPz-}q\o/3yk?gc$!v|~clyX| S{:R f@O/kIu3=oRrNisL7t7^ΩY9=]˙zp4͹˨$5;Vjo,Pky/q8l{?;XfWvSv`Ke0ѫAlf6Pw#ӵwO/ñW?TO WZeS ٶrBD%ݳU Tq[4ϘCAarC%ɢ5 MF#3gɬ Y$$_cq(zpwr;*(&.Qx]C0DI#CQ@Pr З-\2qCo~:V H$EEy?֧R3KCDd GBOtO\nw,a^^Z djwgnǧޟít3R}YK/?keԌNlhF@ /t*'I2 e1\ m2}?6`A6*֭viv嬟Dž-\Xў*F\܋7hq*b,Idf2'q=%Y*N\fOe8 zӵl+396BfZxFr ~n0 <ܾ3S*æ ȱk-W% jտY<~! 1UYr_X,`bĴAQ$ZAfyPz^U"WԹ>og:ۤ[u5 "B>/c<& hO٥ BfofV},?sx_i]f„;V3pBcPLܴ(?r31-I?y @B z==~ͺ8yW0<8C8>Yc$ {WMGQFo t㛗/?u|_ŧ@LtY4$T#Aa H{:j}>~-)j|CuEQՑj2%AV[$ Y3IJEϷɶYX,r0`Atgq%EWaVR)r~Ujhr>pksVS êTL = "e #XfGʃ$! &"̐!frAm tNĂB @jq_sgtubLcN$M (n(etdSG{(h;:9}7c\jQc Z@R ~jGX!pm~aMϴZU3"܆Sg?^ ݿm fam%8 u~ bQ4p Ƨc-&eXa_#/\YĒIH0AX؍yW`aKRP7BCwzX]ϑM _˦GW^8ʯjq6#c30 ǎۼy +,=z2,?2?_Zu?{Hg2@B D \6$?]L$R;NUw^+=zgLʾN $D/v,嬭TN%PS8G$1I؏#g~W筟g`@SY@S}m.і\s33 1KK%s>@H?}ih2bNJiU q ξ򪙛BߟL-AaZ1E"/c?!ίл?6t~=\kZgO{Ǖ*40c0i՚oؒ0;Y3_=l~Ui^r, 1\,ߪkAkHNUN%BYu!esN=N ْRv Epv^^x;  E kZ;-{7W], eX )%[]%2wVF|鹺H<3U^}:jZwuFOfrpo|Wtp|<XxC9̻~5\\@@M ܻWHŻA\e4I;eĦ?vW 4w/t<'+`6m8T)%] ZgqdDvl ])׀?[yn dXoSTRwFkx5Y[a)tt v=|%ƻMFz+OU>Q\~Xp y]V #T3&Xxd%Cѿ_F ٷeo3Gbͬr0zyw\ D}c,lTݞRրLAűhIsO?jޮ!5`'B؁AO7ha :mҽO aNReN77݃&aZS:#O[[ѫeBT"H SQu /e;P!LPUwNHxBcJTXmkBxyGuXhnLӓ0-W{xMe+[xVÌ\,e8ԫ,EvFd£`[gv4^FW-[=VIj]ܵoQBvz,M^*iӂ {khM.O鷸\*dX;p>CsrEswK@Ŋ֜4*3I ,C\U(3X\8_U?W ۍ-ܯtΚ( i܃3FwjgO3VK\e.d+VreiiG#_h"˄YX^w /,ґ^qW,뿄6ҧ4܀rsƹin)uMQq? ,6sKM3p}(5b4oW\,31)[؊\áQmA? տ)NO"qȶܳb4 !5Z^ȳZdO@ʓw$WK wL\嗕NY5J1«UIlŀd9G>yR!q*F(~^~Fav٢0(ͽFu[pkg+j^rW̲M21Y]uyGVc<\sgvز苃T$a_v}`;??0Aٕj L,N.$*t|e@5I`B9s*!K:^΂sGPe? ]2ÌA~]e&'uIĕ֘Gg *o ] Qd=OL7y][uY=k%*Ai\2<-З9g'><*go,N:thFIc867ɇawԜuE-̗)PnB۶E~eZb%a9."-dx52Uԃ3es^D8m/{z%''G)n/#*9UjR I hwxE\!'{oٟ#Fza3SLn9¯=^ܔeo;2&#y~n{Z գI19:ޟ_+ȞO.mWց+HLbB)Nʅ@-D4`og,9~/VĦSŝʂ:|FtuUb9hp4ԋ mdT (w TȄ [m{u&Kum.e]V %KpUF7{2E  ߨ~.4E.ktڎgMG2s;IKv Z՜- cJx$~ĭ%#7.AVEU'W7:niej 6u.C.W؞Άη2tZYy:435r`󉈽ޅͺ8X=uŚl6OpSqG5()?7ZjMlR!Bk.G[ƍ៥rj.fukB D8?'ykC>_ŊGm-3q-nw +E—sg̲>uoJSc1o""ܤddyT.>kx4IןG= vGB]}jU6 !}SaTeUΥ9Oyh!($$2UT[9@[*@,VU;[6NyQm5[;` vբ`4  4Ӊaܪ;" ` 5ko>aj f\Xf7s”6R 2R.[emw7]_]ɬ)615MQopл hE)Uq5٠SM44MRE':T#A6@U+Ohm}âJ 5Cy;4\=\w`z;}_}ۏb#[1ӽozsݸ;Z3ۯ{]^ IP;;Cpg[fwt<̍^1ܘ׽n3nfƴ ((mxo^hG][CZ[2/fAT{cC.>U@ 겄@|7[U>5ZtNf(Ӷk4=1{nPh [7aNu\#5> :(UU`tJB&ú4, @4@vE)TU*Nqz̛e:ޘ @ 49N:n]jSW^{TQi4 wdzjJl=/U֋Zֶ^@݂ϱ֨G]k裦@*ISO=Uv֛b&PQV|7]҈\r홶6T6P7wv}}iɾA`4@S1(ARץQ8SJxp)iT2($ jTe4fhH!ng_^/Q?s{KG&Ap_Ҙ0$woAc>I:_V?[?A%ٚ1WQqck -۶;ZykW(.۹`o{sס}yIߗ呲hMca95I݋̏äuc=Ӵ2A13anfU.Vئ NzNdBxK/?}' Rגym|^ߝfJmej/ѯN9ܻYSS\4TSEvЌ$!KPT̫?-W+}txmU~rb*=A||)d;g\<-_Nͤ%+S>a:JF܇K!S5|7J}ymqZWD뻪A=<5L.׿Gs0' #/SQMv[>>+T[6v$0: ?Իf-/^-Z"k8o[es=< rxκYmfXndYl!VIe9=LNrC[UqOK{PJV9 e|TV?)y;GGt}Y W2ȍw߹{3`/U=+~BKg`>>yuM).s{7o_=>E36^οsd},e[\&!CmƶQŝM!G )O, ވdm0@@ od9m߬e]sׯhcz5=[zݷ&hy=H %8m5m\:.ÿ&3g#3mV5vOa崌h{j-Vy/3owxXI8[O.MLau(3wzyfk3{{EYi>9>U,8{EE͝vLf wkτbhl HtdyOdaط/ɞGTV3bpd԰{oޣ"7jwk]X0KfL߀J(>~='3}gj30Rl`^$~_F.U`<{qoGWGM\uJ4.&t5Y*](^^;sޗ蝣C#Fj>\x 5=]~}Wo嘸[n@ax>^\W/T+V o3X-gxWGO?kxiN5©Tngo=\~V%!>3?v7!8fbfݥХZoӗ{uaMV;#\x㮑úߚ2 Mvb&9Wb-ۿozNsBÛ|=Ks[)(gun9t_f>/rM]Qll2gg\VRRf= 3;޺3ۭn]"Z }<8OU{Oi1n|/{5Yv>^Bbٯ!x3q7(?Ną;lvʹ84S}nd,ukf利.4\{F!X߁:qg۷,9YĚZ.oOEמ.э`yb?ul"O=.]{5K> Vf3i?]SAS޹l쿮rIlok1eyW5Jʼn>"f2{_;v*á$A3#녎>G$$cP*9(5u}S{-V;/8Z!j򯁺1ehJ#J(D6f\<`:rߴiY۩D:^[qI#xKiM0kOLl׌Aޟ5raT%mҲssGpuK fcEBD-&CQqe[CJbeU^8?m~ksF7t"]Xcf?>[qe= 32?18V!ɰht)e5ڼhr w+n8.?+_vX+}:~i[z4&kK|<1{ ^OAѻe%.~v^uƁb#nNuɿh0UCAMor0)x:&M;aCӭWݼU2.N%'/M1ӏmwYq)l9B_oy饹pɹ^b^]rݗSɋsq}\wMprOk$Ml9lI_8+:)1ުFCeB8EԁY/.>g 3me.|</7<פځ~P>c_=U<#"Ə!xjWk,N1}Otw`s_e>#us9bj<3 {\4_~jWzu)11s)R`ql^N-}d>}O.7vbekw!r_l,:m_YYtcO/ٻa~1N+g*>6Qd4 uz IJϲV}2)ckI\v鵟ry>Rv"D37.M:1B֧,ΰLѓ thojcrgךUw*q? 6mMӑ_cώ? 67`a=ǯ,^S:[=n~.^3Oc/w X\sE5+-W>fN|:i>;i=r>j33z1!IM="{|CggӥkD)*mHŔLOտjz9~Y\[ب,Vpҧ;6fŌaXV(|v3.m7nz}^=Wc)$6;uF$jD8~aW,$ySQrL^t {z<Ŧ{Կ ˣE;i8{9~K;/ab rO..c͎;O@.o,3&^J悋={*E87=V,(k2:oL5nūC{{^Z?sfѲc&b5ڕpsܔ̐ěOA,wsOF2K5#nUbŜ(_:f0[Zm :RIF6G#@&_XSTg3*Jʳ.e1lD%5UbV jAtblƕH(k*"#ٰE1DGP䦧=Cv.m?M[nA3_^J{Oz/ Y^b[<K U6}UZܛEjD|v($BJx[l?3,W;gIjN_wv p=Äa/$ .FOY?ϴ;=_+9[7bQ0Kvp͂Pu`4#@ s:|8)w槛}mlod[Oca9oƣ'$}h@Fk*I Q#(d טn~2ETĤg>N5ZQ !Ƒ`j},G_s<{c#ZԔKSse==~9 7~BG }7.H?2ueS&HI IT؈珤zy$d?%-V^+6CyYr!EC7yx4{슯vWX50 #۸ 5 n+d]2]…c+!4} mh3I׽~1/(1Fs횄l-b- Af|knҽQ}̥v+Lvi!Cg\n6f-b=ۏCp_73c`Zfcvjpju/Oz穣[ |aKB"p3wtgl%An~)0l/Qi_ǝڝSE<Hˍ R"H4 E2X 8b$M_c3,#4Բv03u*le,˱ N;G? . ނBRDCBh40F<Œ`%{ʹ,"BYuu"JP wBO+s*YTZt:h2kP'X0 '#]i*Hdf?>q Gww 0#[LXX-wֶ乁J.(P*-YrD@vDm4n-gjwKs "# TRS5Yĕ_|Q_F$a: t% Kc'4 W}(RIUw82ZM5Uli,4tAMJ7C)IvsB;k&5pɣ4f֪hP/eKIj]@'",2HMxnKɍ&ѳNjU NJXzFE|bM@+](f+ĒIB ̀h$ohO?mVoqO(4A試$Zp$iD@ak;2,xxvusb 'B$J*1;*xn{7-͍ۣ3 ".Ɩ@ri3gn޿f9Kfn?뛞󎕉Hr肆Ԉ fSLŚlD[`HɤMrwmu F69wl1qfQlH@it(Rqo2dŨ2m6)?[.y%ᯋ5+ģ@%pϮ76uv4<(!l!'W\Kt >9!JS@I _d?7y>#:@tJ6WeZ_7Y㹐]+wJ}ͼ1 C7$o4[a-7T/3~4eSx0o!R\TD@fS[01ȥRe7]Ii\vk_m}u QJPG %KZe&*ҡRb+ ?ַe"\ >ʙ*H$vn98W 'y1eSBTij3jBIU!S?S{/BDF )(c}?=]χAz9襽2[3|^ _ 1|bx7;nKe^8h'] B*nWOLqU٨ZnP2ʥU"(J/X(*,d {~6cDr߲H4灡8"6sWbR,?.oV<$>^g_+cWu5tuQhZH>#~iW߬cJt2D#ErȊSEf8}`|ċ-X<AK!Tot,1njB*ʐ[ nHYW#wǏDnU taD€PObGrNJJ5) &()3ҕYVAƺ+@!$,Qz%t@@6$IA78JD a-rJ@&5q06nŠ#©V EEL7f`$dSyMbL8e_ AQ5Tg`t F胃 1?9qsZKcJiƍbݔKz.n{o8(A*@F. KjJ(p3L4%Ҟ( $ѷu8X0v!Z+b[!ĹDnыavEmd`  ~A6g?T=40TǦyҐzQXSe$+VW N+f Ls:Vq=ȠH+0Y{[@h쎭XRn!|W3L2ń(@h*J5R:IXYLbIF҈cg]xCP 5"QAIE!H$Xʲ^d;i. 0VYaA3%Lg:9t2fXYؿz֎FQƵ DAK2;Ņ?J&n>bh2a3ɞERȵ@(YЀ(I֩Lk]Gx ^"pO9b G!._&x}d!Nʓ8LfJL#O{,mX6W|8vTԸy?I}{q|hR_W5ӊ'D4#c?/M#qֳH&i}::4yQ"ޖ}POXIZʜ>G( fchQM =ʝ^ N"ZdHEAOxXXRWuIj-N5]^=H*CL U;>H8BAF_ƣpVNKATR~/P /wgD[$$SЮ>`x&.T,<-sHDk2Fj?$ ,dx"p2hi}ą^i_]$ ,ے2zv DG./VOpv@CѾR~xK͚ ǐOoʸ$"1gЅ3|cf=}]07QDiQI:xӣj(? ǧ6C& ,6dLs6\ce^{PN},pV T[Gj7Պ-b>% -dlFL%\5JE]48íO˲@jҠdn"tyxZWkTn ?c]{G?C?W(Q} Eܢ#]‡pQ#(C,x1i5cN;LJGf);Ņl ݪ+xF>ν|=:ͬiFIjMqx~uU @z6j ) 1kI#D6Z:%%ocu] ci~qrxw79[Q  ZvL( -0;嘫)H%"S KǎBeR޲刱 sNj82 Dǥr^T@F %Y#{9c`~Ǖv=޵8 AK0i(0o:8q `=6>$Y(iϚiPm+066-: sO@Ųq#+}MW%#Ho|xVjFƣ @. 'Q!\N Z₄q֑pVq=Th])׆1i^<:Hn:(B!$˺RԖ_0`\{':!8Er3.QуP!,t :x ϝA8q!Ytk! fLH`V#5.c@UK!%4Tӧ?.*ӳO+AӔ8g;> 0F ]|zH9F4A?!8G!,>/Sl}ƔzMi1Qጚ.l 8‰KW.8NL~+85*mMGdsHofŃx:/~xGvN3 m FB͂b2d vD*tu(x:~nh<+z2ϔ /o]u{ g*i VCI| $0gu; غDR <5-cDB2 Ͷ۞f0B ~# !e)A~x.;g'W.߀ןn' DiBL*;*dM›T@68pN-qP:y؋g~2;S8 6X#NXEeD[(e*PT$@ CAΛ@Ԣ 2,*6o CCĔ-Ң!$XYG$1EB*H*& "1t@ؑX+z&CSUqDJ\ \k=83G:V"ޕA =fs͂iAb@ۍ{3Qx o`i5QBE(iMzz[ Y[XE}Z??:괼AQVJ^6@M(RhXAE%"W7dF $RQ,H3J(-`ͩF.- 6vF 6TAVObn9$;!G%ղEV8Vܸi(*P E$Hq.QBj\D怛%J"HUR=qYK5e %\*0ʛ[0J iAu1$~sD!0v,>ф{PD!#Kc?dq?2EO(cD8CvjppnĻĴÀbVz; Q0Y3$"#Tf2.TꤙE  umc!qXuT ˊdtZQ2a[\cN0awކpE,:h |Z~1S5r;pPX]sۮrΝLuh&D3 F!1-*5RV@$SJ(DiѓedS mNssBfR"")ʼnȲ2 `™ƔlJQmX~'#i')rPN u/і )QdytJ MK65Vw] enjD&n{(Z:.YZ%US$\ R£`:0P 0Q֔,*[CKG$FH2&/ `h29܀HBHD#S$Ijp52ui(v&3Pi $.,*dB6HD j`*<*:2=%-VXY xM0Ѿy:%JK]k9BiTkvN42_enpDKI 0!ʱ VwQc4JKq׊&gJib*ex!8@LNaVT'WPn))(Psv 12%26Ԙi.fCa^JMpkBtPH 틸G-L5[V`oгMH6Frcb!eRP3{F%DVX"0,BaH2A y X(;>J[CznE9εSI#$YaEN$dwnph5ZrPJzq G*v\͑Gơƞ͑{onekl:AuU^:nV 4@aw ,77ⶒ=: n9,"` ($nBW*k58T D!f8B"J0.C!E 0mR)9dЭQMRZ2(Xmc-06¨EQ5.KETC6(PYJҠ aίO"dkmk.{"s׾,6-;u)s[g3z>1KHfsUk˳Z7mx5ʻ/5HW6wY|@z*96K`vSkgYinmP/g )Z9uA5p zϙՕvo"ouҎk:惓nE #B<8`f1Nˉ(M2@J . ޹#nnkmz\! ;އ[uKcK|+kW۽;.#P)_j0Wnزl؍ &1fwCqԉZ'3{Zo@9, ieU\mϣ$Zl2zGijR <o13Άa<ߌ@uD#ZTu.DEJ+ȩ#[hMj× XSdz\(,IC*Żip攭՚ԔUÅYq6S2ZqPADZMRD@-K-csV2i}5Ap$kJtK'3g(l׽6ʿCt5,KURUG7ZV@\jD(,JV&E&BM vPuݻ+% x<"ӆuX hIEU9S@MWLxJ#=uT櫦# ְG;)-8ˎ9 B`tFueV.jZs."Zf N[h@$~A&6F uU˽gS s% po< ӚUFyS=w﫾i\a*Jq*(Xdhm@,즡1&r&*NHBz.u\pOZ_ŤPM\(+MN+4cyke bmJMJ#%D"5 ưbT B*R$Sye.meg~.EytH͐%T}V9uE` (o\^%J忹^I 2҅*H bns7L 0m{JO;xuk|oT\mřUt!St42Qv|Zp9{vnˬ^嬁# γp3! P-߿`ܭt?>:ddq q΀Ys))ɶcРsXQ88i⮩JniaLE ],,B$eI$2,QD)uڍ0Ʃ 0F ɽj/0xjd`Z:?kG#:c)@9Z`sޚ9v(FYM\My6k+LtcYhL Ka.&D)I I-0h)ޓ 2I%UPTu 4F/Ͼ,0g:L#qڀT|ƮH}'{I/|{;VAzԔ:Ϝ)rȔz~ѹgXrb/w#^GчEid$*N kl2~yfn U!9?J`8 蠪QOzrNd[ Lt>4NGnn4Zs6Hfgg7kN5UI,sq؎~.Kso%Ͻv6n{tQ1EP ů,ƺ*YwQk|$IJ]&UKIbD^f9r(L_刀 *< HTx)?#E wxX+[lKn&*>C𱶀H߅=6aIѣi4zE65,\Oh1(v/1_?G%.?biwxYMccN𻑂Q_0F&uHߔttTGns!ʿ`~z5NXfNjvQz~~ x*{U GX]ۇ &RO;`]G!]F7D.0w-NUt>cud=VX4vy6͛wdO4Skaxi7GnAR,dzs2{k⛍=VPg?v9h::=gӥ~I-:{QȷߟzS6.ֿS5c}cZ^=GkMMPXi-֜yYָR&0]e7W+&'h%n̹;ZO=ڊ_}8;of͔@@@$QgFGGK9vWc_YBk3ɓOw;y]:nnjZӏ"=Mv6`YM@phخ_/&4n$~F#İYVpm~|[CC^$4Z\vźmmds};zrcڳޛ~5 k#U>&/p P.wKՈ?c>Mt\OyyͦկۏX;(vuݼoV̺N!{zVevyNO32ݼc=lɸYxh|z|,P\|vgmwghpۻzS'/'׈FA)# 5R_E|K=f5֦76u/&2M:=:U9$q5hȹYx#che`%6ֺ܅Gb]keyx|mQѤ VRy9&}ƗO@V"]$?`u&>^dW'6_?'j<T>qew嚓`;G(4:O%tٿ9~V5ZZo=VN5[؟iWKIMi#>:G?¶_Y=՟Jgxb~gCRZٞn3DzX=~Do,߿*umm¦ósĽܗ^)/u4obg𔆺u6 I}g+Fuڏb_#_Y^/Vc1Є!9rڡӣ4Tdl{5|?i ?zL=vk??%9I2+3Vɫ~.],5n`9mՖ|v )14綺ֲtX͏BSà2 91|',c`e}z-L+e~oji6z}ɳn`H LVZP8N.+70rcν0w8;)7Q_>6>a愈l}s{=:#7uuh=VlR5FFAIMs;-Wڷt>=3m'wߔ]?>1U?^CU *0K&Q;WD{ID*(b(T$!!ҒUZe-UIVZD@ТɇS,[ D a2LbL% mZ3:TDMDs==m2N=.a]ջYwRO1@"B$A]x֞X֛6 ?Hlr $kM޽.ӡp/t\y)n9럚u,^9pz iXW 1-~V=\5l٧uCj/]SZf}p"agxDߍiU3j&72{(JZ6&<ΞG' -iF]`=~odD+>G{})?k{=z.k]Jxg~3>Ygs[&>)QKqiKF૮%!y Qa_[懲-m;4v N'zxcd9KMyMQ+ ~]2r]v>>y).;|/)e87r1L7`3مzWu^xܚ1O>U2xދ8e7{דo^p4si]OC9=bwmۏ/שJ=چe~5^u|H?/f{Ap/i_nuĎ;fÌUid] -~Osz-/|>vEX#=/;v=GquۇQM6zd7NN (4(a~[Ln=~LP};Ut\?&:p4Wr׻Τlaǻ<{Ӯ%{RcwSH|?0@n,ІjcWy}r ize54]yU_lrk9+v#4}eS;o}z&^ǍʾecNjbuD/D,V~/вaj$yUwͯJ>W[wqU ?n_u+"7rYi{~># reiآ7pۄUq2tpd\Mf/)-'cj=[Y%m5 6kzuݣqs '^k$硗`܁&r`|- zU&kEAXpYf{0xE;uk^higL;=tNI|dh|Mݜ&ͭ!sƲr>)92u%7/_S|{ST7:W/<%;#pB7x/  M}ϲ/Qq/#o4V[;6FN}MuMW<ܻ_dhZxP.Zqʨ1WEfsEjΝ&K )~|czOie*^V]Nvǿsfk'<5DM8|1 v:S9ي B>~s`v|k׻|_Vs;CGwg4Ic-Rݛ}93?~O+D?Qnv]gnoq8 oo^۠UW6As5{*VC#xȩa]1{)\\c]|L@[Ӌy^Rɇ ,]R!w yo,#hpO^NAl+'O%@~tW6}N>wA@uzZG(nO}~_kU.k79^] @geVݬ,g ?/=p{L *:ϵcˤ'w;֫~v{Թ3}ظ'<$ӣujd~$zj_u~ Vm,qnCn5-':ՙt1QH SY1r}.eǐr3(3GڡRCpy2o1>zرFi뷺_[MDJW=Q4љF7?ݻ|y\F Moz|Vϙ υӫ9=_{$٥j/-S9_iam}v))eFslyy_*r19A :Q;zYk4#5UKa5u *7j{O9P״6/<#;^A-iSs%;l/k9Wzzo|=\;|?5E-54=\@AwSk˒.R;\@1fi3,):9ON~fY%u|Tڝ?~Lfyx8ыdm'\{ F⅙E"̌'iy.I]F{a:>uekug-?څlzBm.2uMvE~{k6Y} -u?{>_ev~ɦF *ھ[ǎi=?+q.鷺xL.{q_"S#!ݸw輑1 }7u x76 H&F A$ifdI"/_k~g/; WeF VS)fРo⠁'*K 6'ީYӗrww".Y3=3 sB^ZFUx;]A"Ϳ {ew^Q/TMhivpostY#,(D{d}M9}rkg@ؖՖfGoWQ2M]@ Gṗ}Slg蘤}O Oֹș~ ߯YfdcGRuq'^ 4D`G,hJ;7hc[4iW-|?穜h *vubT _KN܇WwI<{~:I<+Z*C\FSIy9,q{_%xX^_3ϝ;-:]o`7䯯H$C>"0'+;fYwbS,fձ,Y?񝯣uٴ{hv\TL"]]  _(_b[L8@[h |79j#ݪhܝL|cx@X0(qFqDRZД{ֽMҺϴ?x4lB8XJc}m?3y_i۰< K1ID)V~Fuk [زjZaeU%7vA ad"aNs+8@D3",4 $44;*HY{j:z6M=p`%,JQDFۿߝE^pqu:U8v9ײ^ΥYϴ;ayZG!,9caIӏ͟Зqz491_\'Ywv F]$T􂞊$&`~Cl8ī8!A~֚" kx2׏Vmt!Dbs>?04 <5XEVf` MP?zp~m =ZWQΉ(8KUR-d,aŚv9>ؘF3! ( Eؔ`Ok<غOooYrMVfCc)ዉ`,M9[ 7W;mPƢOn)W?ЯC,گ-+Pu$ҒNk8H*+aJ Eųb;Xyncr@v[ QDPHDGclK h (dH`ьO˻1.\px^"` #Ғ-^> @gJ 2_p68^υjØ !u*S=CXFLZI'rN oQ3S^ ;uNWu[W#U&0>Wm ey W0˙"KDQM6Е*=7lӾGV}S։yXb~:׍$>|*3OBi㵐Fysl}˜Iga\H~ԓ fM,8{Wg7_#E(I=\؟]נ҄g +WT(uTdٟ|3C6BgyPؐ@$rD7#?V 046Xatu#H7'|}񹷽ʅ|[ӑ^6+VVL< %*[ߎ#W_5)ּ>#24C40t#B$h!B'?%\(%e }w-zˊD@h&H@u5@4n&A<۪Q5J*my?~gVU_wefM:<H=5?k/V$ TnwcGIH$"(e EB,Kvn=O~ǟ&>a^Ǎ Л!&>9K͔cthGK+/OMvYETC =m)ZPGj/9slukVVwq,!^/"Ҁƀ S5k+7$doOOn:_z8"w_,!_?Kv,&G7go,& a,sXHH1 q ,3 o&{^Y7Hq/}زE\{gUʂ2D+';q'uۓcA$`3>*c 9S3y@a (i|~p2|#4bNN&A[J=IBX\9uc5N,mY]z*\|zvex[ͺ$@A팴 ZǷvpMg_}L]i_߸/z ,.lx~yOppIN9W|6̐e :)$$@%0|6t#Ԉ38GCO6l T)fYdvbkh)@&+?0h-gRe qā/E>I0gQ$Rvb}c&_, dsgۡڇ-יWs>gYs6+OzFV֊Gbq$+$~F ~3Űd,hĻ̯+q5,Zh]\f<~g%t'5~m~?^_ں^gο'k~9 Vw8-@A(@,F>(PF+39^zB{KlZDɼ9-%c`2? O>Y'u+T4Hw,dat߯gz/oìy-pYKf:|R_'l/$ޣg$V$a 08YeB/2''Hpb4>EI5Hܑqsr͍&7Wq>~kNW77v+%3?|c`;֤~7WrG09-hko㟩b6ÐK]QN98{݈WwHx"FX[obؼ[9r CJx.aR"Ф,1#9 쐥_;<7hsg~IH7tEʳiq^n׾jOy=-`u-HHgk3adb*?Ntή9r % EdIL @]3]9Nc5zGփ7JC4.]hL(" ̫ WoK25 0'S0JKrhcSst}: B+nBDQ˹;ra<ֻ4Cи*A/v䱋L,̅M.vcAYIrpTFUA)IN;%t/FzwvZq&9>]B$x1}]z |QC퇴|`9ǒ:QXIZi^f ڲ{:>z3/.߼=B&{t+Iw.hvSkEIHׅBD!{G;Ne$ Pi#l7̐uIU?㰦Gr]|87ݷ,ˠ3pټ:=~R-R4rENi6"xaN`\x8twN&:gXTph1( ;;daBѦT>~mkD  N Ht虋\ ^V◝»(0*Ef8{6apObX_ Ar%0lB؈ϫPbrRDq]ZFx /Y8PEؓ@A[)v|o$f`.aH ܈% "/W>8EK= 舰Wi(Ćt}Sn+ 9|x(@ b{ * |'I7q=|rgޔT0VH@Z1Zܡ4 (^}z.j[Dє/Z@mQ[ 313koڛDٍ!wf9w\JMKCT0CpJQM61m)ؤ6tą7H-gć`7S80WۣLtm2xQ,DwE$/DĐ \9 .𞅩|&, Ѓ*N铘X=kb X&frzbDG:Kt=n+a5X&O&`zz,AL":E00O$/m` [D#ibu0#ϟ3 y^ro4 ]ύ5Er6@UaiN8}/̓|GJaC`$SEksC/G45d7(M ZbUxMhunH JEVPDDUDU ECeR˛]U m2 5/Qwo]XI_/{YzHED_;jytE۱,Bmg;tƷh]3QUxp .i̯7+G! QPUaV#rl)\"i TZ%1n[- %%<er]㦵YZCdVIHDXp9\J Ī*kC-뒨%!DH(r7tR B F( AZb}YY rf*^-K i67s,/bL28]ww5 jui(@\ffR)8 m<Ĥұ4+óbV"9@X_8qrlFĦU)R H޴q7p aQÖUae,E)aI)ې fT'dT@UThJaՉ;U I!\RL ,TBQbBd&Zf"cFBmZ Wv*(CT ٤ v(J!aB$lrca v*Xikoh1d@fY) hB" "*V()-* SHRRIF$U֊"]@`TF" /"(Q"`b* rE"`MYiU#.YޕJ:)3ZDSL*h*Y BAg uF((."qMajJ.bì@9 dqyeu{wҰ̿iv0v$lnM7?{'fqs$x[iHѳ8 l8U򧲡&r9]63\;Y+ vƌ-DyWXAƤ(`e4I\1Ku$9ТV5pb-P+Gw%^Ϫj(i7 B (%r-Rq2X , aqfˌbF͹snB@\_*!+0, Q01e/UMź0Ӯr\EQդDBȝ.BhC"} kӔ˥ u"GN/džx@Xhx@ğ`XvQ.[>m[om*8`bw5&ш$Tb!ܥ*Yޱ\ bf~W2dk(HZxeC0n ^ RhfUFژ4aj@T-SsAcR+Qd؏}b5|Ks¬lc*gɁG : \EZn*\:ȸiLpFpn F(.EQmo4ҵzB mxs8ʣqT e@)9vlY/}/޾>8H$ܣ]%+`)'n‚H!`5*[ T2lA1̈́ [!giDiAEe$ qj5\IaUXUJ"uZjzsLV1 $ɕtc"6P C(@mV,ɇ7 VT%"L4d.3TQC,n)-ՙT4EDԢcmfո0BF&I0<0m}6a Ɇie4QR)*TdEEiXUSHkuqhX\b(` U2(i Q *`R-0HR(cq*IV`HaS AUEe QtLب[+ B ф*bESdl1nQk vCî_tB]i|˂\RIFh4ժwr%dxڇ]*OzSd6'MvJTZt Oef{ rM,G38b. S5\zmN]eY^ovm^ 8}2Hh@uW ^VyU ^VMaKP/i· YawNʚ]Q ii븶ARszfDLiRHEi(tF5eBl2(&ͼznj)^R* Pr&Ʋ-JcY !\!@ S5PY$ՔJ w]pLC!%d[n+v bIRJDkUTR,Qe7^e»Td FeB<)4CI LhLhbw4Xo$H؋=37@A-HpQLM$&8n ‰H V [u^&EnIP  "H A wb5k i^[BA#1 BT™-WK N:L]h\ &|&fm&LYk9?z^\C:{`Q L(BKjm7Z&Srl#e+k|#mA:bs';Ɔ`A R{'TMR )8$ڒҸ[ͩşnJYQffZp 큵@iocmD45)(Bda&nU 1bE6CƁne0QU84NZ2J _. i%2m`Ih `YD0Qx@b"#lVQ8V, 쒘M*Zf2ik6B()$%]Eֶg*FRoal&ԛma Ēa-vɢKfѴ4fh4a20i֌URҬm WbwPn(lIi 2BJ7h31u fVKxںս02iކ]fhQnO `RmBnfQmqSz)-&CDaI0 2a. **V,Z цmL8@JuKv;rTۭhpL2l7S( !іBV՛٣aod5d  `jemfme(3q>3M-k9dwLBυEjbMTg{}`%;qe^wзo59tLJj@$PTW,B^FMU$1`@Ċ<}U ~)4Dl7&J2G)(#Z(&mW9/t(t{Q6m=+ Dt@*38b[y|رQ[xh y[ >bNV0 bPK`]ex HAV%=,'8:QH(:Rob% !hMQ3!Fj)[ !uIJHR-)S 'ʔ 5s0(2ѧj2hGP[;:A1(VX!@$(0_6jTT؉(T*&8kP@RVH'%.`(zԍhD-C,TgY Đ8JNyZb'+t J$,g0]; eJJnmF1lk*Vղ*ғl5Edj"l!U&3݆^o51խMir㚾nѱUKUp `=Tgj/該Xb0%#/T/O`0i`0,#kC8\f2?200 @K48a"z إR_1f~wr|&QVQZ[XNE~;]mu݅HRAb>^NPWqAB(:?,Gd)*DS *vES <8/O"{V4ARP1cM0ѭ%wJ%fn 4Hhڠ hbLyE !7Vנ4JE!I @SSJ*jmX1:/YyabQ.٥ltr;*X(hJ0 FLVCӬj bE Q!d3ki!eD]Ef&S1*)=O<u(ȍc%ʢZjrx,@(.Ő Q%].t?vv*_0@霍(FSN8w3Gd$N2hX myHR_ Wcα䦴aP^ecU0?>%3fBZtީGn>E·莎 3J-8?]=>^:P%dU']Y f:!Ä |CcHiWlR+-t h"Y$i5c߻pl'\`jqǹ~T*{Xo[ nv(NI: m`$;B HP6 5`,&g;!I d,j+HL*jjniQE L0%))f 1I)nҥ"RKHjaYbwX$2b2Eȇ؎MX7U C -qY{ k)04$ќil ְ\0BT/)V6\1o+qq yθR s \tpA P gN*S{-rhI8Hմlo<~>*zPE5P'̉$3GRE[EYv qU˨uǐ2.%c *&a-` ;vuP m ;E(<1gX {AҪUJ) EP F9@6qDmodN'}Ph*8df en=H` ZZJLr)FV4H(Q@")bow uKEP9*J Y5fET-5@Ѽ AŤ*s$ej%!A@e "qPaVnL^h,C%dV(E[(b{ JC*s;ƒN5U ARfvؾϩZ]JإaO8?xSg-+łĤ6F J /ͺ/|+zi9aDg^nc%j-lòac\EZ g1 iW6 1!X! (Qt2qjb/fR[N>^q2(\9*ideMVaйI-ځT -n"+*گJI 8 զmVz1v^DvD0ܠ 2˒lb6[j XȱMY,߿en᝺dHАUBD(rwqMb7)˔1c JСi(ƒ#(P)%TX@Q"e+T5IT5ATS VLVքdÃe$}F' ۆ#pt$L)&&F&L$0*CHe뾜󚼻Xgy߄‘:-3 FW1y66/s{0+   j (6t:ފtSfJ(!x VۿJ"UP%3pHlJ'Ͳ(w֟]XJhvPC//ESZg:e\b!T e$Q+ PlŎ0p,Yw OAMRvWBݭ%VZGVVMomlS@NHSir4)W 6v/̀|jՁQ?1(Fq$~JbER`  -/IbJ9m̡n7̜(Z1Wr$5,4Ad jhsɂ"@QzYdr&KBYP@cfFYccY,n %T$2d*XQ&XIQS!A!%(rVQ{[]"K-(Fp,;! a[$}܆UU= N^3'FsD,j"ι TxZ XukMٯ=U`UY gy]]UR[zŭ!}%IU%0-Pپ ""J)AKhQJ!]0P. (xNH\Hkg@ 1SĐG$9, I;MIETbeXiK%)@zdM@92 XJ̐7*:nCT @Q@;h[4D f %(cA&3i2ERQTRݮ?|۞6.D\0var捝_hu|wj-@Ce.)s8L zt 3U- H56ox} Xnn8R&u!̯toB'y>c,C& T'vӭlkmN8ubEj#'=OB}tqͶ}Y ‹V6eJxU|";B9x}}raLbYZD(YU5uSl0ld@P$ n%u\X }Nb>~B /Z S6x Y,\*eB⣭&3e&c$!&VՐqll/uH "`$H0 IWَnlr/>e&)b3lUjY"\vo}"Al%0HTQI ehsI7-BUu1hS83u D CO^+PZ-X`HѢZ̘Z,R1ɌVE'&.mF¶ab&hqhxh2 ۮ9@1DfI΢dVAP#yKueဌ$YF1wRې*ehH tQާu!!zP%qUTY EUA' n:VCC(dXuLݛQ91IjHԡUP %21qE'Q!?wgۡ/OC n<n0d6?s8lDʶ,;^v7|#DԵ~%ǐ@T%C@8S;+6?}7E@>$2ZM"?ȉ2H!r(I#>J%=-o)"Dx>6a]+TpbvuYQ|P,MJ>xSI&׈BU:;W_q+]#7_pYHeܰe \&RCȗY1@) A ?o/gkoq3`.joɬޫ{E5w͢/x!H&0ڥ6~yƚ#%GifO&) `¾'=5P(em8Jql2D &%}I:RˣX!`ȠD iO QxX%`0Qz䡅fegY<|zH!#:HX:*IuX (2hQV%$+@0LɌcjt|^HT$ 53RĔ!W|lUbXk)ͽIzӼI7TPn&-~Ki<6{=}0zlHL[O"|[>>l~)U'cA]G_tކ6"tV}ம:}5D*LsD@pЊRC$#;iD[; AGB=OQ@nQVo Vi>n*>OxXHI{U"@a}疿|_[ \QPa<ӛE2de5eraU"[Ng2@QUm+-`_s"폦Q9ůSeu"n[o[+1Z 5vQӼT-}-a>6>,^ej\u:up IHWޝ,7q+f@C" ,x2D=uwnEf1ťHABIXm4(0`a6S\0L ]Oȵ9K*FE,l$ f5ʹ*P¦rRB$XV0T0[]yۧ5X Zu[pԴ -F!@ $Hk2 :#Fұ6Tfa %WR ʯ yo쩔D5Mo7PD4рX]ɼňYҚz;8j`XUu96y"9]ٺ.g傂* jEAYU֬ e$3tluaɫZp1Dڀl$2-Lmj@/ +"GAQw:MlDۘ,RTB@a=s+w,m?S9_X|2߽?*"T) M)AF`:xbI @ ):^Pq*^!} EN;9j^Lkdc xUO}^طZ)BKU9 KRW<0-ֲV,WFJV[LiC(8usT; /v:fbbՊWNZɛpM,*TBՈb̀9w "I6JH@67" Й)D!PiZ+/F~Ǚq u !.! / "iЪXH!cl^vC ~9sfΊy )la4  1B㈷ Mfs}mKAӄ^`m q^Q oچ u4ISd ]^R8-5u{pnb?oFnU:x݋>0UV#+8rDJe\J-iXBW0M$XS AJ1LUڪa d NH XI6d`C ̤dJYZTZdXbZbFjfjD¬@%$Gujyf‘x633-@pC)4sٳm$kARhr8@{|=jy kS-d PzawjOs*:-#XQZ_xd*7q+U-@ QOxiCUw˖"A#'ZH}S½ZK{kem]lAS4쪓"B6q- Ѭ(N4"ߗ^3A2jR~eLZ⧾/%yD t{_yYMvPSFD B54jAOO1= 31:W2Y ,(F S#ϛ&.׌`wRl )#&;ܾs#z{g" Q#%88I@BQ`(M___P/׈=aZ2jq mC, "SVoOΧXcHD/I eYl1 Ք{A)a©:0vԉ_[q -$ٛ9OOa`#, jHflh$|Gt4\m= J_@F odJ=O_Z:zl:kRO+ZR%W./|'ҥ;ir=N/ܻ#Ϛb8` DT)ЄNϾH}"`˾Tkk@K5tN3Փ](u)SWB 켡)ʈ P:,GqpF~Z3|jta xzR2>]ߟ<*Ww}I"fj/)W[ja2aW:PvQ oiw\:U Hl1 DuCOoqsH|a|_c{ld2'KOhpdG=?Rɇ:ɾGWMΪwPbE!A^Уhqon-tKT,M,KY7.w &fP5ከ%I# (()HR@Y0pm4$d%s3PRZH CԈ1|;obMvt^(AZP"6b eo ![MƗ+f4M7(հ9UTF$N)UݤV]CcPUP<SĻCeگ֕k,1W!JiCA`!n7^i 8^7BPc mEX|Zj^0cb"5OY6'lZ]-IPkB!<(l$+YzC`vք;edsUA z 9er(l[h+d -QǽM|%Qc&\Tg ]ޭd^gK>-}=R?Wjgr]n|5,Xw~^&ܩŒWY:D6Hn~ڰ;@3ONZWz  <=y~3\/ᤁKdFڥ!5B^ U<8DŲ h  Y5\YHl4ֵ,e %QBaE JR@7犯ӌ[om}wv+ IFףF {}E벣_.u^҂Sn-c fq(BAчeFA-yPAB Ruz@DA\DjNO(3;\n#U;aLu֚\E@%tV 쒤DXd,4]PFa7az 45HL0ILC71jLTeT" L1+R4 ++JFQ2t)x l,‘8e<[ddT[Rʇ/Oh7o{.7?t%-b=mՕR08"b;QcwHJZeZDj I!bqUu2-\Ejw 1ATRd N1 EMSfCDr-P.qAŔk[jLhS$Ut5؅ FPB! 3ש+C"-[{.0a1ˋ@ṄиL9X{`0ģ4H! aA+QhͰ͟ബ[q/5#ګ={xo0=+"\☫^f>UT%d`!URBO rn0u{gM'@Rz*uo_7RNSң9ؤ* 6VZKE  "m/"H$.L;3` ;_2!6/(y*K.]gVQᠴ,u+z43 t\0 +LllQU:\1k N @S0]hp9ީw>>/KZO >~{!df㫢+΍3;,QA:_uҿ6| ;RCQg\Y-7l3KiSBA<$>Xßn\َ~h}9?B<[u9*T7+CvCRQu#[DC"C[t!fvJ/y< !JPH$uƦ:V'v:vpK?/zsKJr]i׼X6aT и @irCC ¤l֫AdcF #_԰ :࿵etUG0BJث )u VN˅TʵVFytͳwG"hC$UMN @gK-ڐUI 83D~sqC8S*~y|MrKFx yTFe%Ul "n{1oc0>6}3w~MXbT+E{&68 9_TU*Oe@Q&c&VFjf'*g-,D<3Z U̸bn@6Y kZǯ4+&ABD'j6x-^,.-aD>@u Aٴ 1B !k2ۥY"Ŧ~`)o|#f@R4ʺ&i@@,Q9qiDKըU3# @t mK~FfxCnh/2HF(#m5p' -I6K\؁hM٢f{~g}^TiWw2F?wb꘩|ʮWS`)2jjjy3ݔpeڲj?{#jpSefԑ"7Id7!,iŊ7)=?ӎ|(=śsp<ͥlT ݐBU1 6HK` wfbU_rl0.B4b"NH$#@Db/]?g9UbH2Ae@MT^k~=>,忺.)BY&LoD$KԤ=i(XQGbB{_>sec= b䘁ZA @E Y,!RiEJUfSiߺ7Y0f.B -PLZ)Nafe0B@b ٦C&Sa7( HJPH& |xnc{v^q~,2#˻Z/Q0r{θO-%~Ƶ9o4d{ƾ8w `oُZo=44/ QٜjG˘cԠ+uXO'#Oza-kb`hh+&k}QS*(9!(Cѽ.RhœbpUb0Ef.oFl*̞"=c[7 Ӷ *Ҏf8鑈om ͕3*&(xs1z0()8v q/NIaZIN#v̷)@8P-0ëU.rj.DPvB`IX%_KMr(@ĉ[vl2,{z[GNL;1[㹹 G}Qt5Yۂѽ[m6"\@u!Vhlm,)ZUmb{g|8$rTP"S6@d-eT_nvX>Jzc| -b[&֛oGG1<wKY&e8iaV)@ *RgDB ȐP!Z\ZjcysRfI0&hVi#YprX҃?Mq @"Trسt慢u.!3=U$LђM~\'gV~֫/buc#&Ӳrm!Nr)dHb#NVѠ{Yh HBPۍX 46E4} J *&]kv7z`Fn!pPk5Z QVr0fJqM1E,V8[ō4y\p^8HAQ HBP6\6$6p۰3el;tQ9ֱL\}.עz8q7|u]>\~xn=:qliX5#n4-k\^m.B[l/Uu%QOD3J9QؐT%m#򹩷Z|\J* xSѐs]^fL`9$VD,۷1,8#u#tI?w#Gq>MIuںDW2u#c9,o1o+'sW,ٴlnq*KE e3dH @CFpcX?3X?PҌE!$!4.fcK;Ќy}\k[.{`-=u+Ȱؽjz[MCƜ8-(bF'z2HD힖&؛$tw$T ,kTR )it8xiB`I\2ePxQKbi{Ƈ ,޵S.ૻ‹,̅nHr3.n! C/9V2rf)Ҡ|^5P ^ )uTIC22+m2ќ.a e1Mi&$+ pl=4|uae6҄L]@ůc_yxե6<ǂvsUpX.ak5h?I_#@ R#E@ g6h$IB$ҕ,6ϴ#l2 H)Wu݅W1>aQui$&W61;Ȇt`pEkVMS ኱h-0c$=2\IQ"YupJ񯌞ZlGKZ{扢h+¦z^-IJ}w^cAC^J~ kE A@n! ຂĔwW. w.ej/\QTeb`4P߇O WXΦ;[, 8^Mag2=Qf5Q2ѫ &ꂲIQ⌠@b(TVؽ@&$-٠@G!.ElRH%30-~eQCRӽ.~]7Z>3 D_U%#9?܃_sy?Gqb!J t/{&$C W~hQZ^˧cyFDT"@TJ@ѳJkX&:d؄U(Ebc;OHkC{=rb,prAX-߃*dү,FZ bG]b (Ȏ"D!ͩ 2;e J8l k5RC)f~-~Pb1NGOG_GtL1n=헪m*٭B&R@tbWvhj5Yjp A$Hvhi4Q#N3/| /|AOU4xjԚTN 8ZI  M@xD@ g8da Yi/#W#8w>~m6*Ⱥ!/JʾD@ Jj<ъ,uߪ~4^~C5%5&ħCMD \Н Dm$tT 0(JgEux.֤ՅR'HPXHҁ,ȀV\iaN7ރ`O>Ђ*?gߥb{Sio3s>ˏ{`y!.Qi6W6ɀ$*D,"Xn%*%"`mۗsoaN9h' L Q@|rɵO5s_J;9n mҗravVgRQˆ^9uGew.I1sBe*8LCH*^x_b_3TZf!Sjuk0 "\D *5µ(4U, u5ʽ40 Ͳ2S0}x(bm7k}<7ceL׎3gLTEObڴx|PTaV@İ!h ʿ4=z][cPlF-N+apTKgg`I,mC XZJ@71cu\=Qzs AҪ]Xa^%m8PڢtB3!R! )c+ݟV0ELMI")dR$y"|)cVKNP S!"\@! Pځ[W:+ڍdrװe &)TV%f?W5 $D+q[$!T*w=jDld%7J:LU)1ZQNsh Mwf\ ϳP 1W TіBԲ)URSтqac{Ew\rBUn.vpJLo6iRQMuZArv9J1 $o{'՘#uݱhbR(VˆP~5ƯPOZlGKd1{aWں6KYDv\Cb׼:kYP8jV.rOG kscȓ͐&)`id#u%i"E(gDHѪQqx^_ѮOẏ8S{vݾ{qɍ2B aQC;K" Okxv%x)4i(7-Ud 4je [?^xnC mb=Gujzuu|/~jo B l kfElє\! 941E鱣W HS({<4$f 6as\o楩'8H)[?+VgJ0r+y.5h.t46HaN,@4*?_! t 's I'GBO%B"?H×h@'Z('ZlA2 p&oA#fͭE&4@#R 1՛g>Qݙ 'e@vC GDHY]E-foco7)٪GD][de>)9(c[ Y#,B/*foޙĕmQbQ6:!hҼ՗ mͱQ8RXXjÕ(U0'aF+ \|PʁPSxlZ$ttn5~$F\ҕن0aε@$jfOR!0aKkuf: tZ(`P!b=|yԽ ?i+=.K>w7J] .=:{^9AGǶ'-nc?oɖ$U])fK*g}"@=Vg} ״ j@e -dAeyѶpX4( :57Q4ٞ@Q"$PʄH !{x67ǐ!P,Ϛ< ܬz5v՞߽T=W-HddA]K!_Oc0T\}$(0/uK!pi,; hgSQ8Ex* 粊BQmS^݀< #'7 _i$iU{0oٵ@HE)0G}t]+RR \lGFH]7{qqu,)Y6J(u{{5dwͷ!e.1zΪ$@v):oqUzOOv}kwqn9ʄ ")Fs^ T@ < ˛' pP~`a3XGKҌL2ي".pQHD}DSZH{,A`Q)T>us22$Z{[8;GC3p0s'UbjZab;4X(NTeD ]Cnq1D Ur\'bt0Xw6캞I bC3ػP%hwmAeH)߽F! !$V2Wyy\0*d](>Xb8WOrxQňFOqy*FWNBZ[>F36|E(TQGР+t5~Juuotub㹎wu7PC߳/z`}ab;Jy uɜ♈ɒ jfRCd pGv#k'?`uֻYӴ>cfzs3(Ou8C?q{Y R*#mgAҭ/(P_):\7;dO73>- gϲԆ.ةf:H$ B>\&%H HZvZAK-Ԉ#墵b* C{o)r(Q:EFaPI7UG||)5( ww1RQ: ^SO9:@)'ڕȇv>*Tp7u%{n ÊjH"#:OxA0;Q&C`Ć j4?0$,#5h,$E-4S5سY_ilb^ ̬Z⋋K'a 9>[aQs;d, _}PBg%GPv:Ss x(;'[Gߵn(v"@Ja>,fbHɂONJb,=*Pbuq>E!}Ûs MkըV)llY HinB]Ȝc/(?U>Fma] 7(b$}8}ucߘ.DfjnB <Uuym߲Bdhm΀!,C;[bڌR,VLTZݚTS&F&S}AHJNGeM8/ ֨s ,GCą1UTr }v td85iC,)K[I"Z8fI&ӱUlI:=wDС)62CbIJˎDֈv13b1C].ZnWC"h` e^A 7mǭA'|d2LV(E[Cf7J   ːdQS=~ИLA` ܈DᚻI?[nSw_WrXWֈ*6SvN=( h& AN~T]8  Q@s͈K2"EEU e@pbT;({n vh@;xgJ,"|t5I aL t!"6T"a*v=dK(G2 G""/Ê]ш>"9@> 11. A A.&m(. ƠN( 袅c~*xZ k(*  h"d@HpI7׿kL݋Ga6ִ0 ב`IwP+ }AuS\wѤ}%stĢ:h,@ps]_+Gcg^(m+s.D[PL3jw|m<#F s^?zg?F Kژ!@@@T4ꥳu, J rVK6, -0s';7,h_c3 ǥ coru Š+7/"QɱSQGPNDݹ/@KoU[6u}MQzǭyߛz"A 7MND(37RO}Ar;XF2穂'@'Ov3)@PiEAx;n">;" 7([*DA_/BfC/s'Q7]B&:O/΂"Т" ; T" : ~㠺N݌TPLT@=_ڈ*.?ח*AG@DP}/;8 ( D ݨA8"+ \DT@_Ղ&TP]P:eb%[@ W9( RC@D`ʤuGh ~!ȉvuƍ׈0EEDm PA?@'!Gad`R)_szx?nX$vLoU0uJ >v9QȂEya IGRl!! Q 8@K ts7C~0<<өѸc%)RƢ (*sg9 '[S83Wau(9qr+}oh,|N+)Xz[=Gs S%w 4ڐMC Q/AX@6ȁn xq @lۙeGGb c*?> "9m"A QQC(@>"~" /$D:H! kE |7V*'#~E(&8QU?0^[&(&㋥=;?//OM 1 8&G:x|A]+BE;OVn~tp\@o,O@|(T^[SW|頏߂P7Q4d#")N~?&9=:H Tz Gz@ u[R닀b?\[H8 >NWr9 ^{uw8!wzM*-d]hq)k`b4=?vV+E '2."h$F%?:c2+qQX.ɾi@=W R"I9?O Sn͵vCaITN#zj3<4k2fY ֶ؂.Z\GZ:򇵡]lG_]*δ'RmoOdjlP{緙n2C`~yV*%8a<&'+^GQ>= * M$zFRl&E)tjڪ%iv-xLt֐1T3m)2jvg: DPb5.~,83o/(˭i.W^矊bӻMESť<8I')В:oށG56]NQ%Gm0Fviפ6ntXۯ:Qe 4N1uKeR\9zg=|TwnBk =w65~ RpEU9$knH./ҶP&Q .8N>Y\~fV(fEbKL,M([zmQhSYN_9e7پ[Q zoK2cߍujo4676wz d '5'ICu,GW)ڪ7~긩p' Z֛v&[w;}8M FW֋~| ywjq؏PZzrzf4K:ߛViSϨ;: %ʞYku? %G 8e}3XT*&4p@@CWϥIHjE[K6mYTX~;mkmҲɴ͝fbUvf_8*+*ҜƂBo}~=h7C۫w>O~?Q\Q][.z蛂Ҵ\ ]{G Mʵa?= zuŃin"!!ʕu`&DVduRB"'ݐ+ARtnAT=UVdz&)ٵN,wRҙRr=z+@,۰PT9*F{ -v]qt: 8[SU'㦻.Tx6P/^"}"zoP8/+qX)Akވ(wUm'9P34/=p"i#"ʊ Ҋ?BD&3q~](3*pW1X0Q ( b)@@49QW>"16EzHQB PQuR %8ȀDQ@I( {H (" #"gDT81TЃQ &"qJy'>Hf&SuWl"A "fp{pJi4 ͐$&-uW]7gJ9NC?W2 A/;ZT3y=PnD 5[r#4Rw:UX7W%Y\JT*v1jZwJzs Nc@5+'[e @޻|NV]ft_"*o37d}.f7Vvs88;>^ +#!}C*VmJ5q&4vD6ɵҫ-ԦjoS|qmG*L"͜.;M I,Ҿ!tRηRbuȥf*Ly7]@)vU%TrM>C޶s>!)hɒEX2gdTn}Dw*efԄr 8HUi (Z_ݡBgFi.ǝ.NOcf/+Ֆ<{V+kzj{)'s>_7/J0qM͚iɁQƺ1)HPDbR4ŰѺ+QtQ:lNjh^V^.Ӎ~ۘzTNR&[rZ}!#a ֡փqԙU lG}xYLr̳*QTk_ פŽb&4|*L_|gIŽ.Vl-ӳ ڴ=ZMv׆9.rPĴ aǣEe}ucbCgYfjrwHvr&1&wr7aIK)%Orh;sgEe "6ZˎKK=]cKIˮڢmU>N&n)-M߼;V%b% 4WhZa:Squ\A)|b$'np3DDZ_ū ´`?0 Ȝ Me?xIJ L4Jשz8Ңب1aEϹ_2Oےwid[~o;dޢ:>G`FsDf_ 棛Fna5 `v8]VO(>%wvCQFə_2mRn4*NkqZ$LvO{ ݋g1#}}6kpπMr] ?B+Vڛ\}}LRg}^L* kT݅U':%6 $!BS4C XC$%wr/m|F]xF.bTr`|/ނ4A({&r,W,d} ]>m[1A!SW:-hP:D?ӹ?uѡĿg?x/''ҹvr%aWk%1Kր}T<$[٘_=U,VGa)MoiSMK@ Ejv9$d 9VGK=3 $kT47QVx8@H[ι)Qm1P/~4gu}ˏ?(,]E~FGFd y0(=iH J *_i@z*J265p_JR]D]9pfJ;8b<+j(,Be5 yOj&]:r,u5 cYCZu޳S65o x7rOQ]ueRhEb)ꆧ}-״s8e 5FTU5uE K6 Hvy48 I&]~nzqN$[kiDOT׏Ƀˣm$;rLִV i1J tYt(ywK҄p7~͂TɆ1It=bso7z 6nzdweJB pT)X2< -5]MFs &tUMYf76ZWɭi!Z|)՝ j  4l'[vn yInbT2R?ťn:<6]nz%Z*q߆m}'ʱh \ W|0_-5AuJ@`%"ʦ{Vkє?Zԫ- WD[VUqvefOq)ph~* &jx@TzvB8 "J![GY\Y桔Qvy5'ӊ6C]M*Eݠ=} :2)-V}OUVrq,j{k{3!sScS)brDmY8)Vu&IxY3.TReh2 w2&lquw3%;SRJdrj\s\MwclJ%ZY2)#$Qu&߯^s ac$VxЮ3 gI.$&I I*u^ʝg΅=aڠKe}'R: Y:>i&I=[nә~OU =.~摁D*b'A lX׾- 'J5$45>[RZƵ5G?<<|QM`hm1o\Rk+>~]q"OԢK<ǢV:m) KUD~ҡY@LrtunO+.ŗE^6oӖ`0V͹V=h3TIJhtуMlDc%Xx`ƦR\mBٖKWj\57&Rj#^ 1hs[- 4ZqM D%xTjU'*ޮkkmJƴtCPpgԿ .s-{N7k7QdsRPڋ)٪E-v-ϷNgV{^y]ϐyoOJ;y>&tTMM%ۉ :O׋P>bD(4.HPG}Щp<$q};Ԓzlƴ,:q=ցU:|U7@GJ=Qkm`3LC7L<$H$%j9˩@@#*̤Bc7mަl:QLQ48~*i pfҐb2<>ڕ)8.Hr+ߥճz8`˂q2,& v rzj,)"oG8c?dG,iJ*zO"~')8Q!ːC2Ę$1Dq`lHW6D<̐p ˝T,j ̪ P굥*0MІJ*6>-+W}Ij~K 8fUV܍;k;*oRj55W\y[6ua8WRpl I {/ulhQ!P+/RMAH֍0!+ZD%#q߹.s\cdw}ĕ-{rh9 T D.t;/ b&օoKUfZbN)FQ'Ke) #Xl@7iUfHj/I |aTuٙ'(0|Fgwѯk_&r=^[^z{Q'L%/xO𡥭2ؘv'<*bCSMgRJӼClħ:*Qe:X`Qakw)UkV~ c2jzer]kýz}dϻeղ^9.6)`sX p"7FeCyy.\vjix7!q9aɔKY9ٕGQFy;ʈVXy2f_v3s#55 U0},#KqE&Jh}o-q#1P[:G\R+O9JZiCc2Nq[Vʛ)~9,Xݴ]h} )zWƐG$2POժ\ E7ұJ7xTn]}= bXuN9KGnWpeQӝy\=!E#[TR}61^ǐ(4&~@0tе)D,ؙonsbIn&q<^%^!&tTVhneHj%hũmk'~F p5;[3+#v?wckEջ~8ZvJN]jp&Wm<L=ym!󕜫ݶiQqкLvWKC"n^$Gj@4pX$Et@P_7V1,dfd%O<~bc T)dTMaFPmjd0w~#{L]Qw4m4޿SZ88oG w!6)0b ! 0SM0Z!) VI<+8 uM% ,)n؛@DF,{3M0-nbp( =b<k`O2~V&kmB+mÿk sxq\S 1pn#d\_n!ԿiB&&Q!l*#W>j#B$|yo1m_]28>ⳗ=] :Ĺ=)D؇ ػl?KAn.eƢh|(rʯkJn7d*h>\ۍMIe$}E]UJtٸu =|K6'Z&M cTcG3dhH?Nw~gc"lA`JlA]j,\dQ/`Ȱ2g(TЏ?+΅~WuUmLokʤ3E)ċk2FRl ~_1F~3 tm،RĜziS'| ^?Bs(gu167uY9\lwF ֡MC2CyCh Qi^W8[ Tx{DP"CM`(B( T?AS &%7c91ax?jtźmrHػ`KMxMZ}t!17yo#qt̂$C B@]TG@ID YJ(Y x YG2AS^m~0zB2ԵBj*^ EE#|܎ypst2>^mZuՑ\Yz'SAqhܢWGK})k6`,E .ouC;z`.XqK9v2y}QE4+ڮV׷ 䁜6̈1j0 ƙ_^JƲAP!%RA/|a@7bɳkAbMYHĈ% 69ònJz-c trs{k?(i @Fbf$؎}Fk a/)*vw6s5Ҝ@t8+r/Bwɕyɹ S]*6-5wZ\?|f6Kє*Q#O4tqj*Gp@tnhWUa/]KOEׯCU,Vt*i -&4XM6SQi0Cb9f܂\H(  3|WNeE]kQY 澚De\NʦgPhe4mTJ-ЉRXJq+K@miċ !]9VYvxv48t$Sw>yL&hJi^g&es Al}]?/uj%ohCL mT$ p \!]s@h (Iula zNnm@2.bSzOa- X!:n5~KfE$7 *mt#ٔ 9A׶϶IyI )N֕ug][zk , ϥ,,sL64n(GI o=lrQ7PLL yzg+4SK|Si$obGK@Rr[1EV !Q@rJ;p︳0\`ȇKڛ~o9XMZBĂ`5")LSA `!qrC,rp.ލNrfmVktsP9P5aIYz@mJTB-DI $yx;/,vI,c[C{ KBQj+ HPI* JI n r%PWRuK)2PX#Pn.ı;go(800fJFEz\00GeQ8n<&~EhP8VJ@ԥ"*N޷oEo9wƟGIqF'ʺL pG Q`nE".c0[aKNo~/녲>t:nΝ>q&/q(W"$SDA0IYm%;>+ '2NbМ컪VBi';l,Sz!S-cootn1b+&jƧfkkVq/ݳ*ҏ4GsN5IWc2@>,V2K6g>^YK+6GJTVTvflGtAwUqYHUk>ׯ/]XaOW3Y ZyJvmd(fh M;4~}*Gw8TU %JI=]\Ȁ\BA&~]u0 fHR} _U'Zծ1] l '2Bs:ZvⓙU_*dRVUsʺ&LjӶdV y#"|TE5$h*^ {(AF51  ( <ߟyp^A@ !z;t'z#5n ]3DzN8p1k?ՙ6dExӣP),%AG I=7u&u!cf*H]bUYZDT;{Z}"g{5cDH0dd}SAga$s\,1(}=7kr^ `) GTh"oM5+Y1M<8z\$Ζɥ7@_+LNRm"4u'divb31E(`U?׺-)Y|Ig ט|]QIF-_]TO|;}C@\/35jIIϘuvAbE{!\_-zDH+FcZISR7?~t(I|F:G#% \5klw|jM+ ,g[phB f<ZQg k>O)y>HvRkV&ߧ~SPǢJgD%E〺93 |n&Vc 9יVCh/oEWuXĪ@!}{lm ( ҳ^<J:G7[]h.dKelROt7 t #Эe[H?Yp>gκa&hJ`cUI(n?0Dn(3K*RDx#Oo8 ufWYZMGsw1+J(aKLUκK_A؝%V~Kヌ>xl>w;V -RR޼U дnOW^u)JX(g|2cA2|,9UBBEQ],!HCy됐u>;Z 'IGMs7:]ÓV'tun}(Ja* ΘICY>a/$#UW$dMcw8e2/Qi?ҭIN+❡އehMFs8TFf{C#.]c`;Rwk\.ͷŀJ=z^qT @>F){W|L|z4Ɣnuo>]6~͍ (UyugSE^b+2w.E3 [\3(ګdժVٌ2YKw;mk<&0UL+fg[1\0("VZڤ&3e`1/:d$’7X8ִc.}|xs \3Bx*.TyiidK+M5NxR_.,Y*M(e"`Y0Jͧ5ge 7k=^WR]FK(&U%fe{cj&YQ1JhNV aX{k!Pf۷в:L7 M4|+7,KVmeFI$J%8[n͢,ކ=`9lpTCY\Ykb>sT& ti`;vNz(|=ӻEީGJ-Ol9"I߲&HA"UY {!j3R($P9& imANͣGeM02s3 Ě)Tl` e̴!1,4L06X•.qiuZ=J6:^  Su=srY_ b\D7ND$* oM2l+\oBCL(:?|;;EZ{@`YD V#֘#@PUo9sTV{C EH"'|M lְ4vJ=.XBB0,!%66c-vVJ0 -ң6wՠZ%UD@h@^>_nbc{C`D!h>X1)TzPF}82m( jPR,8(&/-\Zjn T< o &ȠK*+/ ޞ*hbcgQAB '4ֲ݄IvP *JV|$g.f 3X\5-3K+Kv70qyd8Ugwʮ1"س([Z-XƅX[R&&|B|͎n®ᙘ+ӽmȵk#,c7zU96"FzmxfBŪ AFJ|_5a!8ן_t)htq6r]6&낸Z[dLծX7ާ$A͎XyĐNvҌpj&%•Zkd4mٯ -lSmٯ9vݾVKspEGj5Wn(oݬEOw/ 2I(75@Y`r=kỌ|f{{=w**]Zv*nҸ!߉AoprA NS72k,q+ju.תܗL])pv5B?/p׬0vXR fBغ۟h-[Wg٦sz^̲$tWZ+6P4Z^& օY#Uxc_q4D]˵\_ap}4Z3̸KQ԰UVp',c"e6N"p&lT^&o7k7lKCⰂoڵʋ2sff4E ^bj-o|۟32B̒O͊,ʫH 2D3,?smRS㢚2HrK;*{\hAb<Í6 s G5Hw@$]:Mn ((nfV """IAs9ㅻ:-d䖷;ca⥼.aָZ6NV'?M +*C|*"/oj6 Ed73@(HRAShHnT$[&lAW@/`H$BH(#Q76p81 *.!E*= !" /54'v6!4o"_d0p'E@CŅ9',IJ2)`ԧؓcp:l|n]ٺ7d}*&8H"tEX0 7x|z5(ZĒ oeo-~6 CVZxŒ? ]")J(irWh)gbJ~a*U[HT5 y H@[O]ۯ[ wl}c! }rvTHE:A4TyBJS%AG8m$e 82|ޭEXڧb}S]>!.LdA$>B9蘆M4NYCIױ_o"I외G@6B$.H7MŬl{MJ.Һ~)T;h1M(#_B|: t8?J$)J "1* H{@$)A0_)7ܨdz~501MIퟜ/R0-M kr9@a34C<=N>1P@ O΢ "ʄ8ZuO︮sx5:/_z^G;{ens}*SSqr -#HJnxU߶_ʸ4i.;Y#Iä6$x>(v+~Ї7;|>DH*eZ,6i]h]_2b?HF{ ,HPX( ,FEQkjUx'/'~<̎S-ϊDdAIUs!H( ,A@nAK)VuUNcS04k}U>iH(;I:;EQ`k2o~}ɻl)t$}?wP5OE't IaQZ`H/Y {=Ͷ'/ <*(HA`*,YB"$B(P!҆e8;~>=6U},ʲ['WâD]J{Ċ$(䄐"B-]w v8rXcZIZ$(DG%TV%4*,RJ(mP)[[a) aPQQPRX(1:&dBI+&I{ӆ(@$BJl$A"@)~OvF50P,=?Ř!ճnqћU9eYJ?_ÜDXPQb,K[DpMAyŠ *TErlɷr~#]{{wcQȕޛw߳M D-%hՋ Q"(EQYcDQR* *EQ1U~\I",([as}:jPV#XTTAU $A$ !^ @,B"9Ô(ç3sGnDEqžpU`QX0)"xQH@$TmE)m#I@JKnLF`R M0X RHTR U]Yu(ES*$)tR,QABQ-cQ˻2Ԛ$O%Pb1x//1aSQW8`E|_YU#.Ql<)r4CS&9'JrY7%! $ <3DV.QP$"cnRE FT"&+!@`I ’%  KGf"[4Ume3$(ZH0X #[ǝ]Qb"X W8%=04G6{3/'ԝWNW YoO*_[iW}29אOyTMȶt7l lZ+rI^/hТmV6A@PSAa4(7H s!_xia61bo.|jaLI )CJ>;4לyJCO6ΛYL5]C|hS9AƁ(Ah!v'>_j͆;3"֩yӦ ۤ!D3 iTX"B.E\1!L"l #ⅰjMzF)n)KUה 7f6[ldDҺUE1X-X#)0DDEU5Em6ԩl/폱[wA`$H"|Ʋ'ڳruy (( u;4$ft6U tI3wt~n3twW 9K^6s߭0!&#e #ؘڹ^x߳(eȎKi`awbGlQ堊#ݐQ~G[6= U1rr.|c5<ˮ(6+MPS#8dS9>i" 5LwzsNfK sz%,;TY<77c%(Y*RBb 2PSo ~_r~.CI0SH7 I3_+wx\Ƌ^'ۘ2Mɥ]*˝`C\6GtWo̸CIK<H7cx&9MʫkE?ZTm[蒈<`.;d8a8twdTKhVBZH, (EQ`S! H)Dd ()1d--"$ *eP(Qj(@,Y" Uf,8RIB4)`S)AiR# V(%U*1Z(b@ݷ0 !A;l,Zzgچ$uccXmwi,\&ۛd!À;:! ͡Y Fh )*OMAT  (, xƢIwL6 " !"jd3U$SbeIcdb)]qtцb!8'ZZ&BCd?@0%(`;HTKQ~+I15|F'x ((! AS)ReE.L%.nan; dL!Ju髷Kh$fjC*`@yf3ʑQ6 -ϵC lV(z Y9. 6un5=70xΟy3h ٨Hi&!`{M.W?@ ڎVIOY@sI"A&8u%!BY]K9(@0I?7ﻠ" `5^JIUH *#TRM jC*n^t޾xi@q0$?=c~ɳi5WS31~C $!Aa= ߦ\ӯRj+Z[:Pp% 5"'زT..3D0`b WOEb^L#12ókh[KERRљIF FB֮y8PD-Pcs]GђBEAL4dT鄤%D:vYLV"X,RTE%(c1AX2@Be UmV&EX( B!9 bŀ,Qd7$"E$R"aXA@PRAdY #R) )(B<"r4-M_<>vE3^O& کjC\0^+Pe)UCRY5{8éWBXҖ!Oul22/nL ^ϳZ!I)d@1Ԧ3Bbt=ywxЭݱ0d~ۯSǾwŋ2+ǛjCIv 6 (!v!D 'xfm7?׭f.5G)H@M*3$5!#؟ŒQ \Oi0a;C ڭa]◗&F60/U-a H?VpxΧnĆM")j#q]FTSbIGH6gكm"Qv#s$x,ڷ_#WASKc%ƸbVi>AÍEHk/-t]Eh]&IMdӓ奾tמ[ HAQeiz^6 ؅\UMf*b1CTݥQ08إl{=3k}""B 9Cuq5y_}文yC}8&EO{r]TNa4/պge*v{r#\g`Fm^_3»߶f`\t핚qV۟$70HV݈>dgcƶ~SabF7):ME{jϭ<=jA+lLC[>qOL8P[uIΟ>%5wªhg(5j<̩K%UUe $TOI (u4tZD,:t=q6I)M纏woӫ^Rΐ"$'}.d#Ck)4Hq:Z+&)Q'oz~v*EI)J;VY˱q[ԝ;%4Ƃ|&qWvZ'EKGE~=kL|dio(8[*œZiCZdirўHpڞL]ZU!QfVrTqI8T-<>C0r<%UrsH$h"1W94lDLJ]\uJ{0!QRUrY5nؖ&ZS{j;{dCN` !>m4iڨzѫK8= ΖhZRia4=_3[7?.Z ˜.krpҽ9QmiӬ>~.=jQAu=* G._tN^u=}tZEvXf{-lnYЦ2N\c@x||DEtR n(*qPQO&(dD*$ 2*-Y=<(fTZXIܪ"OaY$ HR <0dfFۻ5?/_D!$_Kyg#H IDPBQ NNU`IH  Ss$ < b Ctf[L$ Iz @AGG_$8q4cUO)C6+A1,M;|T_û٠(NDLLĘM@wB;LXVMNM+ɜ}]h?ds;%JQPW_8ZTD** o" * T AME8d 8Q@|>nMg93XmG͇O0ݡ1GGz(EQMr\Q%JNf5`&LI*=}GD|~K3)\ʔ2QBVdOv&{6''jBM=НW򾒥ՏLkb7V(!KuO|4L'($(% >`fGjBߢ,,@Dur4'GпyEmSM *Zxi$_g:Ά>c*9tK;Ka!B;_ {NCIoF 64T'y$5Em5Ro^2n]Ͱ6x'r3yrxkKVJb[x~> 'OQԗlK&uʐ+ fP c=;F|+(O7g7E3{}T,<[ks.H)U߿ V[3[dH@0jΙ ,TuFS3cGo?l"DQ9A3;uɛa,&KxJ йĦI$HzDů-w$LnAq1d$tnilUuuآ NE5@4Vv!0\$G*Jmk s6Y>o@.W ^LqQj)Ȓ ^u#D(9:tę0c_1I0$H!Vj\]ƗZ[cz )pvsݙ=tŇɔzI% l:AJt].`YgQ! G xʊĊ2<2R 2ctֳQگ C%\_}"҇?2`Q!4^QD(M6=Zs⽔M"gȵ3-62:09s lDl(B/aqhx}ǍՒQ4C6w/[tNGj,8|V( ޛ9w:{iߴ迻wߌݙ1h965nndJT~0z1 eD\ߛ&#baGsr+gmŜqtRjZKvvo1~q-ľx'Nb.>}ʀ ׇcZ^! <y`0iۧ:~ ѝ!(#E&'a+g q5k09,*hWҡߤ?+SkvB/}4)6q+ڣ.A$RBA}PA*0Q⎔?UEC_ouquW⫮f7y+ܬ~ڨTO>RCi1)|Nt H2"0FK  li,s+&L. ~8?^WA_><wMRܝB2@2y`[2ËOM8K]sm!|@X JU-!&ufOfD_ 59DDYJ[XѲ ID?뗛℀ZD;m H $ FV19"H @E]}πt;I$mLp/D5!3aZshυ6RyeP;ӁQ3ִt+ܗwnzwRĭadzŊ8!{AA=\T蠏qD{:q}9oAdFcEY=D8YE 6YQI* :Yw#,bW]?l[MTޤr'o>~\o.1yW+}b0$ KVbB&/xyI`Zߡ @|:d" k"S u>mXcKҍDf_у]Oͨ #TR*sm4q}jpLL?z}yV".2l Ą1E臃D=S"5!w]Uq[܌1dV5`0^9޿^]ʻ_Y)tu:h@J Xm2 ;X" PUe!;֘KX$K7/cLM8t 54*bKM<Σvڅl$+B^_`7]ˈ} A  @^ G{Z Yo;c亐>Gc`i5&?z/:y/f=zKbՕHPpCq*gc[*hpX <._n}_۠nn'{+io±/x՟7vx&I@W:z{@cIwy/@dϗ8Zr~_RcdzaJv蘃bQ aܶ$eqmI*wӹ.L|*{ڴqeŦy$xn3rMc(VwJt¸ ]A:EUqrFi)*qp۲<f%Sz'vkAx1= گge텳'Vnf㺪ߒyM5upۉ%CP50G$@Lw0yIBqH9LYbM0BX+s8K>"G}EqY_|65U%UJZicX(UKbА)[yqphq?sTVdaYg’Pѩe=?W!O Zw@v1\~o?Hz̧^@9/j7̱H`tL`Oo}oDI QEgAgj%I/bjEI5Mw̥%B6t4/BYuŶ3HRSS U 2?I"m궛z' rpP7.wAykC3b^ױmZݾNo*%D&bZqIaB*Yc{5qF 8/xU "s.Edjhew3Ԅ6bOW75uLX~aWwB[VZsJq'JJ{F) CGIu@)07seQhJ=!2>G~J[qPμ:p/0!pe aQoSN2 w(k.U-˳?KʁNj@[LDcP6&u!S>S}9ip-8\*-.ʦ:),TN\trb!QIFBH]6U@=W. Hql"]kWam/b:409ⶑEIi=zjJ64R%ׇ:/o:6ئ_ mD %`cP*F%DC55$5PB%[ gYiȢiVKv XDA1PS`tU g_ecZ' SCy첆tЫW{߉=BAY9TKM-#ucmsKig/ 8Jbit$="Yِ}kǟxLw:||KfBа)9nWHjrouqJL-nm!f}OVT>n&D|O2îFiEsAA>Kw)+vߑ\} adz "/q*B}Yz8r@}lx~\5q@ypk$m@=jҎݱGҵh@x$) Vdދ%1ke'ղn'6!1+flu7:U;k-!9N$#HHl-کQbB fQL`7ɌZSi/r_'6XA:akiWsYFaaŕaQM<0d>{+5^*>l|ocfHA+[~(0v\xcn䳵G45j9ͯEKprLTK>C Ƌ[jY(4+cXfl&$Ԃ͵Z»ŋw˔4[ԒYQlE;žΠΎcA/ExAMT-t*R@nZ<ұ7b"D ~Ytr2K]rE3;F 2X~ws$lo}6w(/VitJ9L22ݦ/z]ϝy䔹r駇9"Q G)4 XkjW(iJ ?(9Ϊ|mDaqcKa'VmEcϞ8v.uَna̷j["V[8zNاłK»as`_mіBs}o:D* "*1dTEW}^*=sz+I8nƞjF6 >5HQpZ g ؂S.Ykr­bqQ?ѽ*~:Vd4ef$l6ZD+GTT *NU#]bD),G U>o7XF@ƇU M\Y){hˋ+#+oOgo:ipt?ϐe U{pQBBH'5eRmM ML3쇏3Vy9a( ځGR 2J 40b>M ]NSzPstmb >ÛW8C,ѬӮڙ}'fTY;(Wm<|Ԍ$ nSC~mƈ|[J4a!8ѻvRpK6ܗPU-J abPyᠾiὰ̸Ep]`j)ʗ X/ߺ6xeq쓂i}p㴾b6c O>WaUҤI ͩ˂VJ WeIAdR#g>6ܶynhI:[02Ou u0ƁTCaKWjZnZ F&ueSjL- [xuSR-FvPf<^G((]Ydu֒ &h\)*C&g&wkPj}`E; IwD)}go͵ J+HahbNc}k2n]/S;B{xnEKoT+՗ rZSw h :ŕiޣ-0իVk6aU')K˄^AkbC"fҫi@ K[m" ːOb5Š{v:U⼍ '@QK.~h!$Uy ͶLӅUrvzٿh5gRzauIA2TI ,v;}b`(e))KP)ATKL(aYh"Qb"dLRˋ5ABL%%-*$t- 4)!C64[p(ҪAa"5EB}]Xo_JDcm16!घ>n~:_eRcTE2G1ns{~H@F!Oh1j[)H|J~d#`H2/_nd_}|6hӟ|ܦN|H|Hw $Ӊ JPC$??I:%xC:i`c^Т=!GӗNKi*JC&?ldx1˱s0Wo2ΐӤ-vKD/* j&hZe%)rDMn-) ֟zYc T"GQi%@> 7Xf;'}r|<8/OTc)\N]mb ?_EM= ѱ }>'c]oqM5Tp+CUSYuK6 (JQVZq(7wM){-(ZexS^du=èd-1. x٢&5DNY+d݇BZr=23\ƑXd$43Q1 mh5Ф_ilPOYs> DO9uIޟ LԚij㊛NET߂!OZ`нIö!r4PV䵡d߬Ll^蚓JEɳ'ޫNB\$Y<`̩syl젊>Kۏ&k\JtaJzNh-x#?ڱjsCD:&~5]m}g+:C kȣ U؈e;|t9M7oR# 5ѢX,5PZ/ y]O-!;Fwi"8H{rvK,_h|,JbSl$?maC<4"9U_m-Ծ2;(x8KDL4ԸUt *& !'7h~f%) v jX(ږ?m֛g@p7=؃3ܲzzuoӯ.н+51k wϘ!$#UɗljblMf5w|}R|)&Uer5ˍA!-**gsD͆!Y=Im}e #|qU? 5{[ 4,Pc _{=} צz|x?0M3ޘ @|֦$m6)RtjSY;X+^\)cg$oc ʼnn;𥒸/3XP̐۰M< YI( Y8;{{_7S!P"a2ҶA>}VfP2h-RmהJZ5)abbsk?inx2呍wĢoJ h޹3LZmhӠ} _cokK9/@ EK*YuP7CW ;Y)t0T kL֨L1֊8> iJjto/hvVvӅ+C ŚK]W42*zJ+Y̺Ja<.N#!|LLg$cYFbm"R+ _}Q'aDR}{4Ys)`NOZF{*0I){kzOe1i-Z'Cӳr:Y[؆AiAvF5.%VRVq:dI̒vaW43 /sqT©5΋#6B-l]wspu w*QR&(^ y*=w%v8dE q8j(&QDQ^dTv=+Oٺ//~c)/({tѫm?\è>H}Ӵ+q(<Us|6Mvy[YQXy jN~'o!ף&\"#zF8kx6Ys3_TY=G2aɣKeNlXޱw-`ja«NIÔ\]\G)s&(Cvߦ Z.&'teΩ֩a󓏲U׺ lܴi^s:.ꞡOM}Q_>P! H*Zkj6Z ()H#_ZM8Em`y-@ ߓ6܎Ԥׅ.D[@*'c[HPB!!$1bXe3X;%iE7dVw{Ml??+&Y9`Ȋ2{ z|gco3XD[hC\<⛓]fMJ]UK7z^#˻3/B3]kjX ~DOG*(|xPBDQj#9AI ea"rLΧ[=#&EV_~-om#S6elf|uQU2#"'{5v[]QSqO;] a:YDCMFfK('GY S(ucfιjE0ib2b+U&TV tQ3f|g4$LG"^Sͯѽxԣb,YO渚l]꼻! $ vw&z=Oߤǘgw6G9*JhHl6x:.Fy\Y5ӣrߏqsO?jyZMjA 6< THE9a'q~`F3iWs׫l8-JvaP"?*"*|Xv3V/BI>MÜ}jʇ?vM;39q M&*t݇W-֛&Pq=ftNzu?v[fCe?riRX]7[5k*55]6=ډ_eXhg{ISKܾ[+6ΊPٕL!5)1$ӶI-Zޱj{ZM&Z2A^WsDDAJIA H"EEV*$Ofy49<>O U-Ҟ o< ,mIB4WxqMG>m6cvWwy/d.f`x[3dﰴ=xwNvk'"eB,;t{3FKKHk8UwXiCc4}U7/;4!dE0!+ *ٹ,栩u|O\:[_%)}l ]XSGWv+*gPyYuR &4lг+\OC)q6-zV% 85:+@6PA<^#:$h>ƍ[[˹|BB(DDug|^_D: (A&L݁MMU8 ;hqvިɬ"ۧwV>mlGG6n,6s!}uއ}Zc_;dE)FJ GCnm0VxAA*p?spXзl^(S7JJ Dm4!A]lJ5u}# c֠`BI$!4v p-K%4 SǢ HC`GlOPt4aNwqIvv6xބ)w>9G>ֿ>Lg dUA"_X,Wدj!> BCV͏{Bm,p;5}sf{S AVlx] !Cˆ([/0n1,53tn#͏TWa6. v1d#믠bԂ6'cLגET [ggg}Xb1PHc VEHgxwpxkf޾>y@PzBw<u8ĵAUC!TvXޔH|ey>k{0"B "A1\㯻/_ I)@"x`LEN(yGG޵gkHȫ H4pbW#N^+Z)h Jrs&H:}ÀWy4_c6| _}Ґ5$nTL$#uٗ aڻ{7($S۰Ry.hnȠΎ}ZG}{ |g W keYe;6u&v6iW'H=RsE&*myWǤwa Ͳj&ELHh5o~3=/%Vn4M[y0b *cMӣ+/ιA=yάË`a%>Sp?ĉ[]>Zu.1>d)!0R^nλ7'1qdNRSyGޛmakQJ,1jnR^T鵬7sqwnAvv*bT,6Aęa$Ưvw ˏs't ėҕԐ%dOB;3ɊJwށ4B:pƊ""_s(QKGw1{^mN`?ݹؼaT6Qޔ&h* Õ*b:ˎZIHsu 2g(3$sMFu 寄 dR= .Jl7"PY4_+=p/vڧrV!*A,xpf֖]3kS&ϋH@b[7ק>" *2/7e;McJi6NvnMFB>X9(S)DX}[wI(T#`"0y}?p<}v g4 !$X߮Z;R$}q[^10,DDA,"9`<뱱=܊ӂeVw=KVn8Vv~0Az&RAO;BddHA4:F)/KD~Z|$oSbL5=5I þ**ƜG($B N(nGO8e&P KIJq1t;lGn& px)葎0dwYE#p}LPnmA26p!ʸo4Dh ?TB lk7c\q!j-Lݚs/}з5eTHE a=穽!EL'1iMuSpП9&AR$!0S-U0yQ'O+VXcxF*u+.]0eENvw Qі  /zVhRJ,KԾ a/mqgrmV*pTJXĐ<4ޢ{HSLSRKÖg|ok5xtfG_5N~GTuY@Đ} ǩ=}DNK&=gJpRʂ+j- 46rHH"b,H׽;3U58֘Lh?•wU˫ t<ɤ#0"ɸ"u9LwjbIw*jn$i\DE|UtWFg٣oũvqThbC:^&꘎jc>U& +[jY4}6j8w6e^ݤ\L3O}#, M؏9%*g(Dm&buHCTaZ W ?BF9I\%j ι*D!"$!VlaB^>&g.-htDyVc7->uʋú2*iu7"q6wH]d,/UHفڧfmw.kmA߶rV'+++kM(PՂޮӊ^6aߖJ@3yߠ̮=$bO k$g{/βnHus̼~+U ^lZ.Sj>xH|>zO?ڬ|}\xkOTg&ϝ'{[5m:d݂vLPJ Qbrw'nu鲎| K}|+)o-is.}q$5=>uqdݡ57pdf{?c6"\Y)%{0y'-[Z)XY. 5]|zx[v cmm?+s?Ln>^ dLGf$+_~|_EhYddRQ!>p*?->S_f?ŞbA$D@=Y"K%DD\b@wc\n೎]JePL3תn}osS0ސ HABr_S1Gp>T :~CP_o?inx}/v-qKPpf:TAY@ X$! 8UQ ∇Oߎ@5t9w]dri ~~6U RMR:| ?3DFNMb;>V?w{1|?р1vmMxTg~F Kr9~?]M`LTRv(zkƙ hI$$6rGφ(n.TbXB.'MĤj%J^k {s=xW9S u뷛/Cbԇ Zv q^JEm|UdNj=}&VYRt4}aS>zyZFw (@\Ssʼ?pڽI.%}R7Od{&Vv#)(f"ŸV1Y o;;?]Nl6 P6u H*/ںe.n6Pe" ||RJ t O4$8[R~ɩj}aX2( ;/abE= |8U? Z~ ^fӷF,ͦliZ[cS>f7횚h%$IaIQQHS\!õ l DC!tHq2ptb8ui֬_k\jT$c9>I^!$x> {6ZsZMA`aDw,X[UTwvavJb3= A.;On'YPՆu?*ߞ+%箸"jnG2ĿfY>܃ЗNCd )!υ&G7<š^^y~XW{"uԠQH$(a7Zy!d5b:U j&sNL'*BXi{[h:Cy'h'7=TjAHyxr&rEbPF:fO_cz@GLcR+sfTb#y ֣㪞|w99(!(9SQQ^K0=űZSAbx*%/\UPl 6\c7Mm|` #w`W}A00DEhZz3uΨryw,EoЛJdX=:ŭ=Z0҅T3DI HP "Q$-Ec2,I# 6P!@vEk, N$M4NwD34#=~MA#Lg@"4f=Lb'>'ϥDDxI9Їrt𚸟(p~iۤ'^/ .3H6 ULE23=pF ?DYlU(Ґxzf2Uܳ !eEOD6w:c`JPDԧJ9kFj†*WP'nSEjDꦣZBf+gE~F$hW&))'5āF3Ct`s%妊KƱpz=J AA a$r*V[[Tg$ҭERpƬ@Nn[G0Z|κcxʶsEƞܞK6Ha `'wG۳Dۭ j(.SI<}˧P펤 JCGļN]o'ADfJ!(/nۨYК˒Qk9cKKR 2hz#2xk /|!J@JBUJ$_j(S=;|'0@jc$s1E]Z$?tpd+ddE \Ă$ !&f36RUІԆ^uJ3= +ԙ*P]B &Hm}RbB"pHDX•h!SƩQom4-Ј,ql`X\Ix:dn("k"O=GԆo&Gu%xW| b8I$/xbYp< )!s3j^N'`iR,~*Buxb(dϭ}.,*_?)+v2c˖bDaKΩ7xs]gSAD_Ryߧ}dO-U TZ@Ò%R$Õ~oO+6wjM־?v2dyj:ې@@Yd V&wd;?/}+aɢff̶ֶ|=:ꊈ})wAb#"W}7tT k8Fиuﹼ;]2UݵiI<ã)}xXeegCJu6u9w_e_+/򌛽}|+M:*_B H v"_A+ D26:Sr=JRYE ȁVcHQ>\oOWzFz|C]97COAQV#Q2<S/uzD4G;[o{sm'I侥`~/Ev1$&KCvƱL>[kɂ'JLD6{ T&*9>'OO*{Y߲NTo=n8l&PӕU ACmZHa!'8|_麄-ɿ|9%T.fz$£]oWY Q/aT> D@E +JT "I N||߯iZk֤13nBlvXNқ(z%@~}<!B@tUՀQ.:[odaicv:[:Q: Q5)dv>i-PZ^*[իLelA3.TW5qSHSMOu?=+Geـ-zއ7A2r&M&_Sig*>|~zR$J&+3uu]lxȠ@D:zX A|}(amnյJ{Q=β=F/ҫйKRˆ`'ũm p !"Guk/a=,)P5s iVl=l5w?^._[~{΂\!.ٝL2hO4Gb밀 mNftSD (9E2`N$BC&3kԝT JbȞi#|Xra`pBlx?QDEDUA?SO>&/IbY:⧕[|Ձ"H&_7WVo E8wokvtބ/!7 z @GECR|DY8nRRvtAcJY 7/ܑ(}2@xC#DgjI18c_vTߚ)H[ / :zڒI>ZUSƆ!b:!"(0 gNY)Ap1CPvSTvޯW"Ō~lgb!zR2ߢ2Iw xwrvnzd1@N쭨x7Ndi/IM!fk6o'J?cDJ-:= !p󍵍]8:"@tԌǾ@'&3Z:K[ yfH~ej%:>M;;!w?xaX:k?xSr.\@]{A+_C|ҢS?$-fHqHHAHB1h("I-ڀ48 F)5AJM 7T^+[8׳lN9ȰEϘ|fҞۘI RH4-TLUۄIIY2gmn " ~&"HқP3)-fRKw=+_Mfeٞ>ovs~.&6z֫pcU̽#r5+'OKQ{k"gR`8{AJ+Csm( %hܪ>Ic|JjEaI]u "6'J(D WɔYÇYN2d2;7?8H 4r*w5Wkϯv]0 EYc4C wzX2 m)кQ2 _бb!Ԟ˽9?T&ԛ{m+4=P.̛=M?3}йݥvKQR7I d~e(ΒOʀb:4;("ThiPj1 鏂_OiZ xnݪMs5'I׸gr8hs]yv~/e3bj;ii'ӷK=Q*HvAf !s7Gt.('=hkXTUO9-}1jTc5:vOcJ>=Wf~ nW ;mZ=S $XnO.iMkEt2S֑$.*M7V tq ǀzI)Ve}m)ZGll7U#o;siL*r0CE(V5I /N,9\&5$@nΠۧU Mt?1:GBdh[:UyS1QHq3OO#$4B5*U"JsWN+M^!|<4s!C4Ӌw6!(%3H2 $(i>v louUvwj &"|gR/{͑-*֪5]9{HM8 %^(ül0ne_. myR53=S0@;1=2-8ZZhLר|0 fߞ+Ǜ)H%;e/rj@aw٥ [kWR5)x ]lb ӆa#Kk~󩀁[b PNo{:#* "4II'uTՄ[\f:|Oa~$:e1_oGΕxz`~zGԠG"΂@DЃD!B1sTF)%*}Cly@=qjpt?ߘFqC? $9]R$CsD:=bN1X!$0twS߀tϱ~_&YO|~ UօMإ ~σ5I⦥#f=}0;;i59ٷ?1U~7{F?sp8O}G'kW8AE\&c;̊ juy EE7ѧ`4f}M*$x=.wlZNс)n &^3 bHHmhʗ48ZQw2Z;U>ީbXRD$#jFiֈHn~@6[ڷozow ^MMsm4b׈BGLF b?`-淋l%b"!]\ #~9*!r ^ 7}C$4PC%!ҬCt Y.u$;ڏmah 4Yu ~Ա^[EDp3kP?W @á\òCʗ rQ8Ɓe%G**`0% ~Y,šEB?^Ja!RH),i$HB @'ڧ[m@HY=aNTqV&٩PkruRo+)9q D@A;TKBKwG㬝E/iFOm25ι&_R c,P9P6;, T{':T t+04T;hweϖ&<{-W+8yBv"7uz/~I?ݚ5@E[7[4*IO<ɢCھN6ۓ%kMɄ]-nѡ3ZT5am g<yIVor2l3~YuGw o߬9˱O+Co[8GM-.Ƣ6DZe\k[30(sp+-Ng3A\Oץf11ƕ| QX](0)Ys}iwQyk?m\t | *ؒGokŮa\ |!6BgT"-Ji-P~##%L3@E:]}ROz]oO|bQsS _z<+5)B&<. ?B2Hj,z5n1ג;_һu16IՇ?;\G؇8UOl6WYW$Q0xSq]0rSvRGRVa+#b^EL)JSB'`TD$qkԭl q*qko.}%Rݰw]bRi3vXfP?`d^W>⏸>Ȓ - ~WbGoh{Ӭv]m+/.ú|$ $>\vLK*X]jv(M<=p* t~l1*37yO8,P.IynN{Rxb,^cT7h TP~?4 '_䞾Ԃ_ˡn\u9: ~CcMuICzwS7!9 iH/:O>l-L!$cO7ۜpb" #0пIqoR<6=mܣqRxHᦾ==\/i ւ/J n#0  AP d?Qԙ m'mD .4e[NWk<%BJ[U-sUM.x;I1iA1"H @4LD LHC0 yk+ok`拪chc""1X*Z]OjZrWD¡L)19ˍ9>ZGlAAtxn/v6]_Ap,"tz ۨIU;ȥ*Т> DARq5m$ʜ6xFç$!2\ 1 0Vyp ) Lǰ=xN4f}>'f뢣zg&&0p֛Τ} }mFBG>K:ǹR6:ʇCbBO2k IDZN%uuvG/Q[f- 4 )@y) 'F1- (p&CF(Z{AY Ȓ=mhDzTsf'H.55^{C"ud+OQ'>@U ;Nm/.=@ ԫhiXK@Gp![U&=% a DH@wuN&JOǂ6jV t;ޕ=6*2J&6/_fiZvjUg_ U)T$9*[Eq+ԏoе%]_'vQBr!7`-bR\f `/$PlPy,vuNxD!'O4ةm{Z"ojlN~w.1>R>Kg) ;C-Kui`. !BZ.'sH$1K/? LJ/82ThF&o;M5_$ WzGdJToACjV!&#8|j L$GB wr$΁HJcVDT.?&{ĵ$#BUY, [,olvCXጄ?s0N'H]:xw}v)cm߄\ SUv[TP =Q\P~48ա3Κd"8ˢ^'u;i;2s;{UZ@߉|emzNcu'05U:S_{٥ř&GU3rrϽ}@$d(d ol_`KF T~#JnX+ZRIqʝcl2TIk\;[||_S?zq ٳ;Ԍ#׎.Q5W ٺqDfQ!~!Iq HTk'hg@$>/XVqIFt"9XO^$W ?g{O d2$ d+uN}BɖwP7R? 1&N"zZBHK,,J4Fc=W)UpOeԉH Zk(󾧠X5g 0,HC^zR+4@ls6ÌChqX_v?&5JB jHHAF|tA=Ӹ5>[uUJApOOkR8 چX:m% >ʷmV#^[DFG5a);&'w5)zKCIpVjIn|#M9fb^~o!*!PE [+Nc}|mcPC͇7yh*f%5wHDYF)VjrʽW(}+1%։7|304Cex[FX =ЖljLJ1Lmy_ ox\l,&;d5!b:  Pԡ3WlI&M=B\vAO`ЍVCBjE16udMeMhևzCh5pHp CMX |I{77i!pbdͥ|3¹e0^Ty:yMS(2~f(fM2IBD@:eCEQ0!ڔ-Qk,D1#cƋ?(KH@(f$7}>IM,CI1jq[ svNƻI%N1#*q=G yRw"W&] 3/}~}`$]*0PC1c ԏb>wawVrTc~9F`b%I =4_.tP~JF|b楰L6>}H7ߕ!ۿʺ0l{㳸S~ٹ1"mY>lgM搕SRzyBIlPaH"# YYAL*Z_4[{8ۘW1D8ǭ#F-& GDW)VU?zt34WwwjI _Jy-$kt(D 7R?LbX5HdBҕ7 ,"pn,2я &[%(a{BX(%67c)0uLыlҥU*fJ];ڝy m,3ϳ{,KJMB.mu68WyTx5auy<5bkAq@uǰ,tߍ`0uJyr'C1ky`T$;vDqUBqwW%$kjpT)8{1h=)\mluuN0yФvy>U>kqE;kF^\i1GTq0,eFm&Xx>L_?vAs0hLQPEw`29>>__ekMOHK Q8Ɩ\"# Tct,B9L"eh$Hf#`C/oI0dԩsxf$=C-,&w4>gnL ]Ѡ;Gߡf?. ;pU5,di&WHXpbH@y L0*D d@EBҊ& 9$bH3 YZeTV Akw,D!bJHju?\44hz{?Hd1ZNM@RK ׷ V3hϧ@0+Hw/)ē@ g1Ii/S>zItg˹I8ExY4u|"zw_`Hڍb@B 2wz[ i-m|wa$̃!Ʉ33:d-J5ۑÜ?;FV`t >QܩB`"29_$(gH_ٟݓ|~Q=+)8Ȕ!H-! QҚۇ@0k:)S*jt=w'f8I}rCچ}4}TiH؀A#H@Ziī $$.oz~h#p,Vޜ~jOD yI;hbe龐H{k A) 'V/vj~G;WǘSsRBMCtZUAﰡkj׮+<E9T JAt+'+'s#69Y 8>7T+;Q_@B^Jt4OhM4Ti|\_GےT$LxchR[Iiy,D1}oXg & }ȧR&/U]ZleA)*{uodu#| k6ѻTgT://7'e9$Bf~Cnt8뗬譊d%n_qr?>q|Jeqޟ^Ae Ep ߅Pb qS8je 2g S ²$|t)ZZO4$~Q}cJKy7$"fF@6K^Π;|`Z|88>\r3¾aL-N f$P MKI,~0V'"u喱A1_AVB\ DK0 iM.oi ᤤeQER 7*!dJ'CLcSQ}lhE  s6\ Z%~ۖ_Wzf#"$ZQd^.RtVz^"AO'Fn~BFA7Q ͝uϐNt6^_Аs+\ac)հD®gf'$E o0-m>JYAFS5)v) #ϊj$*E)Qߊ}nySWN׵^by a$ f3 IDNߡdld%gY=R(HѮWB ܵW$yLseŐhyesHn5~%!\]U!E#F$Z8(R/@# 92ILbeu aTpi~yCegr(OeP*  GJj1mw5EP?j:y~8VA Dĕh~=eӶG4ҥ>xD\bG ຜu"C+|уe\BxGi6\*吁s0Ë́Fk< wbf<ھ]U$H=0$bPȰ~ձmPwd&ʍek`7kfHNv>8{wI !"%{?%&V$II3+YVI$X$E,QCdfm1!U5gš%C.Òwّi eT,j/X97aM^$>D^*Pj3| vEvLa2n~pKN#4ck=N])ha4$-C6bv{Uf^/5I?_绕U~ |..ʼnkAh@sKOB]khCf|.dp?{O|+J 3`N5FBťM}2֓$u{UZ`A -'k* HՄc0)2ˀr0 Xh ${ј tn󲒾/o Lē>)W`TQ:_M)pP)dN|peʭ4)∡!--ID;ߛcXxxD Gɰbnz#揠ɏ[=YGrR~+_e(oQ>b{-.'jU4Xt `cI>^g k): -hv y(m$+h4ܯ<>(o}m_esXc#yw&A+垂13|’0~[!z=nLAc0{FU}w7OyA_}'պz^Yb$kz;oT&8xΨ=ۚDLN9 <(rH0H爝j 5*:7C!=fN>4ZUޕPWZe?¼?U(J|-E!S1\ ^WU!@3lB(vC{e\|Ը޵OtJhB<⻹ݿ úN $Ζ(Ba*BE5Eˎ82×fߐҢ*F jRE3N%5*q"暕b}B*%zƝsA !@>f|dcٓVԢ I^dewB8Hw}? hjQ qR yW鴋Dy*‰(cbʱ\ bA^5^G w+鈔*XMvS^.G{)KiE3%pOb!{vEڭ%D GK,m(x b{&n@ LK?>f){>@?aR>@Sz ӱQ,6i,U +1y}N8L(z[4jrQX[Pwhm]aj<v/F@('@JuKķ)8 ^(e&a 9(1)%̓<u_OXRWsvצB6;q.$XT3o?Ԥ(QNPC&i9`3g3$|^5;Qi &Tyffґ_2"q=χ́V1LV"&}U'%j7؋ဩ3sd鹕'o^T9RTS@`ե敖J,(l #4$o `?SN/fez3rRMc)oU !XDm5! Ѱ.-;i~V7 b|ҖpXQ~Nuޡ>M*8ےiM=mw]e0V~痦#C.+ Ptu[UTUk%fSEu-`l8kOH)N >LX($^_@dwgґ?IHGpw%x?Hg!@%7vGnE)lqLJ?&Ԋ DD"Ŋ,@Yoxvt߯Oa>aOۏnW[I0&Y?_dź7MIEIuLn~ny,dT$%JQJCS,( =$i,RLEcN<{~ .oۼA,tAbt[/[~c̰AXQU+<gP<}D{br_XWqHxJyz|zktz `,eƹh~_wWUd{¬)o @"JKwO`kPx?ۯ9<%o#ͥ͟?_^}k/:l^$c,$!jB 7yv- HG")moY:tu6Y\z׉Z3gD8CGȩ4k<oN ͥf Bf:o9"D T3ҁNzM'񔀋1lN&ν%J!FjvY;U&V̙23*z?B~bAK!~.SMo,\FHd!qZ"G041b)]!eh^[NQjP Ku/M h %p5BgOca{>=L?3%IfREMw $?e'1reϠh-y{gUJ4w4| bee^аfrУ%9C⶞_dm 1noKt6GGreQ1ЫRd=iVᅎ6Ȃ|>SnƜM21I",惜zcAF4OTYX91;ڒkn7!KӝpIf]bAY18žjo%}ŗ^lfcF},,#kձrѷ \M~GDo&U I5;tg7cm|e03c\q_YwfЂlﲎ#+<3JW ?}!ڳ˅$Mz7-"qFQKjn&`.@vJJVqe0BZ5ϰM2m|ɥ#)9չ  /1$zDA-MH\Cyu1m*[( '5IۜHcB* ΖǿA)iSXE=8&hջ#1C3RӛA>̴g:X)R|wet71v3,38Qws*L4vJCK-S,nc `ۿk _/UVuNM8`0wO2?e}bƒ^IIG%mQ5af W_OI*qnɓk9`:[+j!Jt+By6$'^5E&:4kn`n(Y@DOnG9ɶI2R\O|їKMȕ(DL9lRdYV aO(D->pq: ѳ]6r}MABGc9ZEEyo=NuӼԺ%JqÇQŋQ44>j$S*a)ΈBŠ%v/"f7cf^{u c3@:R$V©&Pé/{^ǟҦt,짢x_IS+^C(08 K3#>YB?nlz}-;{^u35tw36uS)v+Ib*g,jd A#ķVp.!Lgf6넡;_J$$5@k)A9MxV;KEOMN~.0 rnƧQ%_7㩿}#DT,+N.tTSRMg՗sRZ[ EM"R@?P`OP2hdjI\ڸnb8oi7qCC4fRfY _FxX{],ur,^#$w-qf>?*R2C󞼠#=7ewܶB[!kPJñJPuxmK-j?4p]  HOs/ ~f:yL;T["qM4$</9WM*G"g" bI·}MK;霤b**׳׮|U9\<VGE c $( &EPC"KՙLB7ha65 E#+","# UEE+(,EJEh 2zw? 1zY[.Ku=dHmCUĮ>f뱕H.*XL*SKY'eƈ s1Վי9-:gaTOa7'h#ZBA bCtEmw+TDUSCyՖ^ƅ&ø1VJdNR׃:>>Q|Cw #^,Đe䠨*1QUƼ[+?'5L{Jǡ^V=[f4_%u'K7CT"2] i#@& 1BTKI;Rj SS]h&=rqQzVrF0DH"%[ BKO0Qr_VºrφW1lP|Z\HEXAnF]yl)f7n):BDa%0_[w9U")tϘ6QWo +Z>oM~w ;``)8= ʶiaAQCkun˜.^M"x CpxK=6[rh(#QpwDCp)ۯjד f%?h`yTSOŏOgV+u,cE.Ҫ$b$ [ x Or6 #sR.l2쵩(}i RP.BWRy:4g c5uFaoCL^wD9NX9pH1b:jz^m:T/'S >s:v7t1g#O(DI / $'v4ō5,D.>eACˌV֝EOX^+ߐD|7:ۍ$J!P#-'+80J$"!"?d &(>$0[M !3tqDP} =ޯkvV,kv;MK^s~k:z˞o\Y2% $wtUQWɻ 3\u#Pn}9uB`x|;#S :MeX.6{'{Bg=JfѲ6O~^[Y֬1bb()G3 JN(F4`7;{j vj0,h|25b˶瘵R)0!FaG٦ԋ ?LDnWHRh2}f fc|ƸO"!)MXH`:R D j@?$O{&)cd> 0iw9<:+ hM޽e=keکY%F"Q"g9 H ]۪@ + \2K!IR1v\xm8^m'9}Si_?4v"ߪsyݸ ŽVh m^ǜI#OޫRɸ0޻SE}eRdø)8yW]d1rE㪛EQvr w-6c]-QvdniO.%zWu2rZ%*ԒrO%bW,$}J~KX#`n`nQ$"knf?Ob<>S`蟴IM*SM/_}U\nQFWj[m7[^.A?ky:UZ %bI-KVnٰԋ)$PThPQ[FŚgXq4!j!&wG~8O*=N=I`XkpS@3'"DJul6Ѯ$"]ln3䶞Ɵh&9 yuޫuhT8n<ٔyx_m LP^^; a5х@$t B[$Dܤ6ژ}%}.fg<9$}U LuIФ_y V@Q[$o{oFRF&x$#]|Z^* #أ^[A;[tom} ™j{>eI&\$;n6y{{?/fN}DnH T_[o:SSf93AC#b0>39f2&>D6&!VjJ!x:i (A{x@^ 6Y]mخeOwС>$^٭o~}굸&Āk[4k;P.=فFّ;p CF! " ,`0ˆSd! 6{';ze!󼓁qOu$TUPJMuR? sDA mOg7{{Y'x䒒mO _K\U}NlJ[w1 bREχƽV(c L#6${}!]k^wC NϷ,e /M$Og)RKfTRA%C))+iHe;!+\tr}DȁJ~)8GO*JUbieaS8Oje(  ²dhLNN颾-X_$e-2˺DX]ju8A̰!4zőX<(@JĤ.ƚH/.gYGԼ*S@_^(j7yH"tKkvKLTPD֙\)Ċw"e#M%eSI7$jR 5Q)E'&HЮޚJ I]Ӕ +"EQ?arB37NߥhC#U)m_}'qS` `1['\ ,x8oȻnhRI B@! +v3G=w]^f/\`nŦIFƞCkn*})v0 `H9Fb_ :Nc7I۴Tw>W4T<:OU&k?#o#߃1|:,qusiFE`|9,C4/ |t3=$w~Ӿ.hrC/\KZcxKbe_oJ[* I@(JUՔIm &(ڑp9^K.W IiS P,/~뷯[U~/E+.@!ƒ,-Mae05 YOf)loOg㱓10quH1V?;Jba"&.M:b懓[ ?;'!r|8BiϜGhWef<7]|q3(zgc]yc_\ͻl_,8W\BT,J!w*Mφdk9hآ@2}1aѶA|F҃\sACQ12јW^"s R~ Z C2.f"St1~d>TMClL -v(kw}V7a @QA3>gsݰe0D^@g6 {\d5WmGb#qx ,}2tk Z!)X|V(ks:kiu31ζpvg+MI4-Jܑ!ٍ,({_~A> ^Y$FeDI'V[u-S P<65D܆LH *NG#u Ӛ+ "#& 7cL\9E(LSq6eL7|.],\M\PBSUuEfPH*e;BHf-n~_̻tbW\rxx Y|r.8m׸ap fRBLB`dÅz4'l}#0LR葃li.YYRZ[ $%ǦVbZ bK=X5 o[+X qf+0tqS٠57RRLyLBa F"A+Ξʁqv93]J(lѠI$nXSj,%ˢ'S{fT`XRnؒjbϵ#@Y D$H!vZ$'+(rHD o*J$a+ =Y_WfL4,˄3Z($ d"IN+?xƯTh /iJKEσ(DLm^ ȑZ!I1^*ɪZԨtV~:; Q&FUaM@kO0չ(,7;kd|CÞ!<4p%mb4mt(M&0Ծ>-ca_Ee^BjjЮÉw.sfOz wVkdC $}}m#9p3р1 5sNAhFH!ia!d :+=_:?Nyo[o_ߢܳg꠱X@2x2xІ @^q{-|nw\h2,f-vF _j6)uw3jВ^ :bASl(ai kW-X EQ,Re q1҂eA`WFqPsN&(ES!vz+}I쐭? "֪!a^#yoQ"c#ԀηMD WU~t3OT깜((VTEe+!q2VS|LWlzfɣ%F ],\EoS(l[ďwʭ.zܐ 'i0LR&H{uQtT_^ZZ,B<'ϽQ%n-_ުA 34#qc5LLsS)(ϭ_Xͻq,gZ[|QW5?PMQrv!]<:1<5\h 6FQ-(u%m/~UCϵmA1;bYnlםYj"k˴R-I∊*zʷKj o__ꎽ"=IbzpGK/NwCvXԫDY |qlf1WV LD`à!{l$&r.#Q4-Kdډ|0,a1(d2sB.+];Ukل% S.^u p%*0|M`dAUa0X#  "E"Ýs1z?!`Hco[k}]Q;^K8-ܺBΡHl@;Gx|nrQUT"ddF[߀?]I˴]_ㄾ`, U|%h̖Xse9:Ɔl5p{,]M 8TdRתcuyAx ؅Z1UjU"4}=hp@"[`I-keau ,&fDQLJV:p8,]DrD|J)Tj7Ug x”p2М @ɀΩkՈ!$[')*E} acV ֨wUl*||"9v:{{lQ6R aտʒoI᣽ACF4 DZ4 !] Fc'W=}J$O}44 G V:L-\?{3v|ˏf@eFV4 ZE/r25ހXq>b jI@"[+*P0} lM:-2nVIŻs:mor*P4%g̰HKx؆ @l:+ͺS#"9T|BPoR+0ql*-?:1`yO::PߍS_$uGnb19!.:C/HefAp5O s{w~3e5(>N:=*LQ IťIZo @ ͞]%uDbfe!H"$SZŷL͜Oӄ@)I$KxF !sça( |q]w@zcULJ<ذKrvvmlgrőzӲrTҧU֖Y+, ^|h]Kc|h?qA @NI/.!6j +ἄA})6Ar.d@kJ>_HJ,I߭b?lG߆`F|<\r~$%'8i( D1IkK$= xѡ?:LQz҉6dufʆOW/Y4!M]^}/UO9%F}7p8 {O Nhifcz);%+I%B( \K(:$Fg%iGs@r<)C}vnfKan,9lAv"Wu|~fw?ؐ 7;YQ7 K$H$T폀&O8]_1F,hEFfxSJ8I#I,n:eiBStd·5{rUOaQ)!|R =S,S&M"|߸H> 7էHv9 MDo^Qoz/T$Ck Te1,=M'1[,igZcCSꪰ0eCVn?p&l7RY?nN2!Fȼߛ-FM3:4wCH,5'Qt~~䌤+e( : UʆW,r\91C5Bp?N{DudHRB3^g?smrD5zx6+tI5 ?gS)> RDK] FZ΋4?g쫨c*X(ЪUZfRu[ 60X=-RhVJ FSٔLK@e(ETĒwv[T?QҥۉsG9$xRMPީ͞"KY4j)䙾}A.}_ɢӿ'R%E-58TǞo_\^F@p\$""Ofjw: ԕX?W+ӊo`K I]OV\n5b_Հv+SJRh8ÕvzVEyD+pˠ65F*?U, dB"&4ȥ&1wV,fIE4cmq=)mj:q (7;|c z;HWzld&fD3$!R;?.0 CA \Y:qy"SPHm_߇sRCb)\idP'!yl͆hRWk[ۚ@F"z2݈Љ?d0 LhF kWTR2))H5@&_n=< F[O&u' -}V S 0d6~𝳟  ?)|k9%<݄rZN D@b{e\.%{3wyp˧ vFm]٤Xt6EmLvɳ ͭ#dp{JV#;=%e~1PU@DBmqG M%O#:]vUv\/bTQO!hX?+7Wx- %'{j51ʟKNEZ@0 "@=ÌPT[_@5j1 BI0'ޝ!UC<|K_I[kJUmomSNUGPmG'Ԭ+6ె2=7Ip!Ja^Uj>BJh^>~{Nd M՟D޾R.pX<єWhD %̌9FܤK-"r.r:헕)]jd%tO񘍛UseաMEVG}\=%]SzHjԼҐ1W)2Ikʖ)i4>I$A$#Iݺڲ΍ba&<ao3c<ᵴ DS۶ͷ[-%$Q2dJ ]|BťTXi0q԰~~nܝ։{"ԩYyʘ"aK?JTm~]́ dS]mAHZ)%qolSz<8͢6riRxTXLzd٫-Ș'UKzqwWzdx J$s3;<83P4(sI}%gwo',Vڕ*Qo)S۩j./Ď0HA}JW=5]]֦S=m2W+ \'חqQ[JoqAg9wRs|/|WlpQ) @Bpw S@Ώ<:ȏ A?Mz4;S!bFQ ,<5J4u%<:k/H"Z1oU8`3_^Ez'pn޵Db8v'k…z8 ,AP}jmU+*W_g_]Ps0M syo4ڋ."gbؚTZ}~ŏ¦,ҪAY0<ۃ.}u C waJ#H"/Zc! % ^Oj\P9F>CA/`u!N_MPZku &н ,SE *1^NelEZmϭ}tYre~6* Z-B-ř㱈 G0}[ٴj%( yI@;Oq,[8i5TnGG{td m'[ pM뻸fdNWJmz4w:F_54ߘ{n_lRuX $Hd",+闧 l 귿gɍ  ]\$yhEU12Z6=k|}W`SQ1P1yáv7dB=%rCLƾ=`󦍨@'qJiR6f,J-[f6kt"FNi0qCS̏j:dxӟ_:CQpBfj(X)yumk3@B&>\IПHK6~zj 5b0 +$,<5h~Qn&eoӧ8Ga!AV%S]#¡;:;4{efb#N3SH uҭEM;GCj8 fp.ugc)hܩ\uU]KF;j k#\2 4]gOݸFcEX-6_$L|Ts.F/DɟL"R6ت&H~,OdM-HѮw_~'M>+ ӫy~c6N-c"&:j^WeUW0qpeIkAcv3-o&BI#7.i~5}<ҵ!7/XOq i&N+5K2 !nӗ{)-wHxp%w^5$mlI)ByN 5_mS>rbIE ƞمGk_I`q̭^co`vNtuC;RB;%K*kG3k­݃O|9["]YH͞\-XEoC%'wr Go~3}'߈!y"MڪHBJyyW\TF]=VBH-RhEM LT^wO5վ;K_C+JbvKieZEbMaIU~֙KjMv\M "&h g`y'÷kjl . MEOIN|UqkͱYXO  TWaQhYd%gUN;cZ%9G?4cy9zZH\n *4yZU!"lܩLU7 tx<4KpS=LID%YAo=Ƚns3zPh8Ru^77+`m'NYc#tQzN iHd<$LRp(T_rj;ULB~Y"\ZmʽorӚ>T%<8/ "ߥtD/Dʏ|R /OZ:E6`[Ac73e߷هR^N{ĮqOuvteٕ}s™Q>Haupki$mɯ ˂O. P12lCp0L@aKt!s~֗Ҡɧuz{Eoiiy)ѐ9!@QD=M gv⠀>^{,aKpG5L˯ FzNTNŒwt=^܃ؗ!45)`Mn5,^_e }l  [FZ&NR7ާB#tz֭. s';ubCgb2zȵ\rmG&8uZu< z5F!794] ‹zG-مgyYYf?̶xh*NN_ѽM>(Tpgn7[+K{(Z`Nl*zYSz`Kt\ٓΞ>ԫ)Sۻ5..lZM~Ge,vgn"BDU<҉~ Wn j`J*Ƭwz<C-{Ӌ_$D*$MelG]vG#:-d5;H_0N3.0SCz- 2fF:;;w"+67u-fЭʩj-S:h8xu.nզ芔(?e&~cۦ,~y\JuƻR1MTXm #0`\V 2(['6s76#(͜&jӍvZNYoWve,T GнJWsF(jzP^i` `U<,wg^QPZsX.50%wR/ nZ]3:GJ,[j٬x7jscz,nVaX)䫮 wM~._/(c"i\ǔ]ѱ7ʇˢ-_)ՁM@wKW+BMOB`p ﲻmi #e]ɴg/ӭ  nsJi71'9a624}]Ww/(&꓀߁Jx=C)5=im9-ީjZld&5wl&w\G*#Έ2#QSWΠi>97+UW y|b,EnݯA u @$`kq$MH5%zvV5a]?s'jAz987Ua2NT[75 qnwb ؛ޏjYϧ׭ :LZRNbx허{r5"ާb5-oP&u+h*%5j]Xώ v{h=[}hmY9nYR*ym[f,{׹76W<#`,<>IgߎK~ߡbzMjԬb2sG'\\%٘k%haQ0)7L:S蜛)OJOOWC{{?;ܹ6)c|tq+ GӠ@JN??z.UvcvuD tuamMQXPZoa\z$fZtY_}Wf8FsQ4eR}/J"W|.%,ɳsJ >!H_o.ݲWcϯG}.ǵhXdKM1@Dbņ+f? t?7Bv'Bl );0f2!?}2΃S㚆 0Cn,h~?ϢC1F) I#JaU&$gQ]pvS7[M9yS=^isOmj5NP 7DjRuOR=g ɋݴ~g(A%I#jv <̎o*>Gz?tA@6%J|>r?S2{4{|4?Ivҥ|vH@E.Q!ʎ,e@l9rv"N@,;J *Xij(8{Ǧc>Zz#40VBqhؘ7Q8Q˟n|-Ncw#s|WsFԖfWd@˼s}_+MImPZ{ Xb?݃\g{XY` iHTHDo(~[c^/C[^뒋Ӊ/Y˞堋osP%+V(FQ$$PmeR-'nỏoaL# (N]rb|:c#֎V`Թ-O?~?ڟvAD^Ƿy#Xc6>_R@/$_K@b̶֕k[aO;:)luX O6_I*{w?cWN>dyJȏא+E dyՌ&,/w6G!$?B$"e,>w{ԋJkHfSB_ %)d$;Xe> ]2%)%&eR"H^ё%]G{GZfMUag^|+vG7;-M+Zmьc$J4!"o:H}G4pW]{k&I2T+=}Xͨ@(߆6ԡ;j5!MP|}uOӡW3my}ߕp^ce(]vU}IPA.s:xO `;ip6L$-d|ҩ eE{FyOBܿWqy[M=W$WblpBRFA 9@4$C/}~=Hdn)e0$1@ȪRiMFYB(Hq@)P`@C}yrJ9E ;=kG;G$~D DY,1x/7`4kt̮W>vo=e^Dw +@@$d-6 (-f4>l8 dt,$cBR_KsUm7hQ21Oy$D3Zvj'"v@D9_^h㹧x8HC H čFҷNBC7DduTa wLNב:h[ѻSGUeo{G `&ύ/z!m/7E+~p1*@0 /b|-!ԡXq庄E78O+HOL}O9 ȰXy)LY4(Bvpm٨^pNf c+ä(R]{ǩ&ܗWHʨ[3_$Rޠz orH5bΩcmVg-׵k7Zl6zۨcs/Be=lP`W|ʤ`S&)iH mHr޲yUA.Ω>ps%4(j<1išnM6Nh79t^ p4o3mrZA;Y{^&GED&DDio{'^4 "Haenij]u嬒=P@F{? =; aIM=7 8dS1g6RtiiڴbU $4HV\d5h. ^}m qQЋc/n(JIQ&)Eu3|e?ƏߍT=`sʞ~)5[NK]bUÐgz| >HEB%+J=^56v(DXG9rz9}uB=ST=ĆaE(еEA# SBƇ;lJ4R+U讍w*%`#(i҄u01 Zo`}b@ "$ph!=[+\[7 Ժl+W v+ylrKp+ uW7pZb 5ܴCؙ$wt&J+;9HMnꊋo^Vjl0P /7*5SP0Ը XgQ[u!73rۤ:?E/mըOu%;;9l1z#Ck>ޜwē2OT'eĠ!^'plфn3bsQX,XY XkЩI;5Jr["@"kPϫJph~* ee/y,ɾ).ďi~F XMY AgV TQRkPxhYܯT V\6_1=vKzd%}JW9 @NNje$!NB Ym#fӨ4cY[F,gSɂ`VF8D;KF R&rFjB[jn [$LʁTT$)~0?>sD֔}`UB 7jZ[6@:` @aN܉}ۃ VD3*A㧓>a_#r #WTܰ ;So Ql+8VCG2c@]0c-$2Ter"B7 "{,lzvCtEsn(U[}.l3.̓X%1]luwL,T:hɆ{"t!q3Nc70*UBV/gtpc*NMoDɲR(tv}$Ц =jy HGR~Dt꨿zUY?#zC7ϵ^89-/uEsdH&-b Kz)9L"{0ѝcZ9&!*7Ev/6#C;C"sOʆMJg#,88#䴗jw!{SP.\\޷M6azJ(FFSCa&^i-@U&-D!:aDFiv%yT!hW hZY"'Vt6aGK:S@HY!0Q@iƴ %SEGadV}OE B!T$! HI 3Jaq*Ť vU}ZMׇlaJ,2cs=i -} p.&3$rxf@!Y^Hz]͎ócw UUEà\IM_<׀ [(i%Vi¤"[:71zgeV'z竕qxXN/JU!JMgV;] cm4kMuXoISi i҆Z+Zi2ێ)m9S5ÙYu, 뢃o_%'+sG`jj3Fz鬨8'b夡ZQl'dtT^ f=M*Šlܱ*(ȚewqSۻ9y-N/Xa !1iWw5 oBi*$#_nSuC82@nGuJ(Wׯ5cq \ET?*TI4uTHI,&uuԺ| SrH݋ahC ?%teDm!;?ZaXxjNXUʄBp20wF wR9DqQcuE>7dIMgjj ,&eZM3PC*~:LNX $+4~0eeo*R-{ֲqkgǐM`)O7;*_&H< (3 g+'wWX*۞/--kY Z^.\:؞d3 sXL>d_jCN05$S0 (ɁHkH51I,)7:\>6~nw[VP0%vu|My<_Wo,e ku:Y>S |*t$ 34# +%Ht<wn00a7tPX8Mq#O:QL$cSlҁ*8e[F6&ҔH,JT ^~&6*w2(znd`ȭf]~ax`fR P`$v% @nC͔P9.mff_ 6}BnabHP7Hgzۚt$OFQ;Q.GJ/J6m 7 k\r'U}T.́X"9;7Wg@>fN_3.\q\*6PXQB,X ,H¤)a  7(؟jn{>o?;8[=+gX9Dze. $]qLJ}qMHrn<5VVQ[P889G{WPUŗ|ے@\u=Ga <Ն6s,^Oщİ0&5 .ik;+"jCw§9 2qZ,#߷m3_$5Ѐ']v07rq"oC ;X{{{C`0{3UXB;`~wmtp ;nId/VIhBwkVtjp04`c̼9UmUzъLI/eW1RXR i84#*3A>|3<%S)_gG_^DdŦ0fuRu*_ptx6l6t 'Am,+`$7bCu.Ň!Dbsqp2_ƚ/.ҚEHЭock~n%jDk 4lNcwU (= Yucu@țm2'46DABA0N:gcy5e&Rş Q@Cf] WRNs 4ЊWd됥{i:Q1Pb]YЬ9 jß`K&vك3 H L&nǃq#PrwU vfH~ i &FCy:bܨG✿y$6!A@ ڕR\^JXcӼ;c`Z <nz MoyrVX0fD]wK\ՎJ;??1AzÝ"\tLٹՠmχu|~?be9^NW!bשi"v-A j  úXҔAԄċ˒lqλ3`" S/Q6]6.h2R㥜5eG Ls)eb6vRqK/B^ _E{};HmCxs=AĦwm9R:!+[d$_Ju(_!i-GHJTFWuϺm!ǔa|:nݡ?γ@ȁŝ37vO>d'Wu@so3G5yzXEKGt?!xV = QmTsikγkFM09H<tQG~ק;~<;^ו0 bQۆųp8O:~Đqw .1vhohԷxp 8W!@Sog9rQ%F$1N:DǍ)rvDh2Ph ]\$4R9jB [l Pa Il Rv]UO~!َټ[BnRqMRxwu~&KCo\&vy 5QEq9S׾#vC]N G!6 |S*@$ru+)*5XRbCP .#٤Fy]v=b1jSQqu7nRq}i=ʝcŕC3<2Mg&Ye:I [Iّfڀ%p_GF=Mnyu= ӯX=)lGxwv',#KH9;+qkEmܑW'st{ .195wɣqD@4W9]VZŮg%*:ְ%‘ e%ecռHPwvǛëuy3WBq mxW)pJ]XjŗN(!?NS[C/bohI!e_\vjDݼkiq?lviw`,.Pq1Z&4QE4ўߑ*j; ?'ЧM@W&[pnVeq;0է?%^E9Oab iv p2*Ģ b82f<ʅ͌!U77L_Њ>e*M̜PS'65oԂ|W!&ƆLڡJ+ˋ@䫢)65&8n j0A{vjX:YCiԊ)Z{."~YnkgWoT7q^(+I6NU=.,p9qtG)rEs'Lf.Z]$JY p}gz㷘x̓ls5P4{Gb0#Oau?Es>Ms]PmsR3/ݷn0)k5˦IO`RQ$Y?],=d4 _ 5LH9^ORfiqaX`=wQɧC-Ӳ^]p_u?'KԞf>ECr|Clձis~V<]*RP7sEUTI4,p$[0 IQP k್:vu[u`3n6概)Ԧ$TJ@̖-]3I*3Dfk*/K=o;*ǃ!eR *eM?U[⿰q q)4F/m@HJJ0 u1vrٳiNf wu:(hÝ6ayA M<>ܽnF9UR3hvSUZP67pZ}j 4I>eET^z}ޥڷStJ|YW4[a{5e%^$kMTԦ`^)*C| eM\eZD8Y;ۼF!K/H4$J)f=;}UΞ^Ku R#;Hz'#LJC +}4ʩ,M {#{x87P¿B$ʙ +VNͰ?Az>x+u? "x8j2Yq!Ia !N>sHUY >_zyXpdM^^N5aOw- R~~ftz'y|+g.6e,rQzZo] ۛ.4ZH V[76y۲>!R:5z0K  >Sڿ/%Q?s: 1ixf(ˊLhZQJx}G+?H$PQ[Erxqf$<_[[DUέ27"@g_o_K:}=DP"Q#Qy_븛}׆8'Ԟ?`1ޖ7Ho؂ӮTzWlxƮI˾غr+XLO<@C47\r;uyft?-m]zM {c@RB=FIf=[@nKT_~+M.k| 91-'ڭMĭgZX6{VH8Tn'^덩Kn8h}3q\]rt{6nv.tNꕢGHhpqߊݭ_g_#JLa|\Y8 @lgկ?@eeѫ2<㩖9Q2Q^$ `މE@צffr^VpCЦTǕadZ۝Ϛ=,0NrLЄyw" 콡k3r1uHIIOvT[x|@T4D*qcyE5ch_VնcHye;."1[ֵ<ؗL'}u\\s'_Jq&dvUʢţBZ5״Q3&?{wbA7[Q#&j>}<)IFo^/.^22jKR0o.(]Z@ DGh{xjIc5u3-`K;L7;6{ES!OB>~,.+uNG u.g˂MҒ!Mٴ>&1z<q6wx;8-G y`5ǮحZGYΤ8l`ҫ"$;=(lA (yЁZ pwG%&KM9[sj`RfZEP9x;Ӂc*۷w5%o(9 5ɋ>'Ip-}Xݴ:ܩ:Os7_x@-ClWVw{>97!يBtbФYJsM1`y$)k @J`%gp!!#SLFOP_#w ¼G/>"pL ûB΢pjP0DbYeŊ1Xið`GO0]<}zr D&s:o+q $}70mw3[ݿg; | 7B)w ^*! N엕b, Ց0|ux$1I6~RI>5CdMATijZٳY)|6?Oh!0Y\&I.ٕ=WOK["^b< !H-&4C qZ3'sӁ&$w/@?L}_K;yߞjl j!+GS:_seaR(xԳr|_s ECUjD̊p{ `nHUOm?Zؔ۞XP)}Mv H3@`^(~\4Hٿ$y(賷( 0F0!yYdWg, cF6Ǣ<|}%D%x5 ;Dve5:% H. 2>v9~_8pG/gȊ{-}'tcc?syZ阘H% ysuRR_I!@ooaN3FcC!dR>+Lx!ݝ~Blis @}ZK?uU\M,I H"0_BUI;?vHj$1/<\aA"խxH 5Y+4~DHAZ! A<7}\$4-Y^cF M .}'pe`Re¾]l("BbOV++ôq_xwQ#GdW1?ِTe5""snz۫t=F{lS?(7 \_׼Z1 qdqK2Htϭw+9^9Āe.#ܫeP,0߲7{KB ?dj25>_*<@I172ABAad :Y2wΧ0]1l<FY;8*H"H,y|LCS1N2`ӘԑaqsI|>]QJ34{R*2)6 -K'y}>׭Q{)> ԮJ)V'F |2I#fBw q `̉'Yv忮NO^u d g(:@MoOMDϋΞ9 sif !el+H2A~H;`G,! pW߱Fyi涟V;NN>_y1OOϽהTv58}?ee3Ovæ,غ'8Z[QoTZSȠLA |{aH e@D0D@UmPN"9pPdO𾅝&njGRGѫn/be) }{"JADFUE/{wJ3BCʓsWut]3"(x"!CK.CƉ՛v̎P@H2ŘC5]I !;,E$;GR+>5TʱEq,UD.Ed'u&ʔ(y_1|iH\nt:jSLG(kTFǗ;s|#xza4Tq+T.iݙQ?kSokBT.N?ɞ:NUgܝlU+|>9DihICb+C`uI\0x!D_ <"2xGx~7U@؆4u=rO D FJ/@%v<%j"v8҄\~-#jN&:m|\vGVub4""@7S4;av6QB2!Gԍ`F |y>o7JQ B;Rl0 Oroz_/dI!߁v߳LPMT0;?*-EWԩ[DA  4 *">#"$_0 xgj/xK> gL" tL1A +KrT+ j&QP}^~'mFTī&H&R A~mL26Ck7UHE Wg;Dvcc60A#dp+^Uz~=ÇG|Zİc:S8?Gn'sRaUܤcgOc/hA],r{ Is49$,:"GA%ʖ2yNGHe/AŊRu=/7qijEX(,Q<:nVt_A$BqLt- ,9tWp@n"^`THCg= q^,w1Ej$FK05!L#H,3#H-Z|*c'͐52t0UG 0rxO{ =|tw|C0,J "mn||{8ZoYs %)aKm`tZrVPN'CeHP<"KgƸth16G(;Iך矽>R@)?@T"E$Y'־ Qλ-`{*> >)Ev+>1{łr5 OU 74?2U=%JzYC4W GnLJHtۚ Зf}ޟy  R5Q'Q8ebgbjj@bbAHP5h-]3jyeʳ|X8p£QENOvCDVX^k&%F:hn5CMiO#HZ.Pߠ6H OSWO,zC2 I4Zk b)ٌSDnvW.њ=_e!3/!%us!X"%h 6WwV=c;IR !E5Ӫ Rը"}"rM:f` !$!$h-bAPҐp .f O=oӆ3Z&Pɶ\-){v䀍[~,^n2k9d_Zq6h W}j&;N;FשDfiڥ*@ih%(ꍚ Bdjf!YQ^@XAdMbQ!В*FªV[wri ֎nՊ@IARGRdb;j¬La(:(HTzj#|(je0 %H 8pqj@H"Nw&AYd Zj6Y1Ye|A>{K%'b|-YtWDM *rI Ol覑c3r&4B" Є5(j|9UzڻזV*3q󭸪(̻d=FޥdžhcuF=FZN1JQhl3ka2JTbRtXbI{Va "e3 U|97F#D'LCn{z$̑t LXsHL>W[(]s%D#2 $\Ecee,D}j޵[oƷ1y3r`麭"b%ύg(QL4ׂ≸]fxR=}pQ3;to線ET0܇X-6=snCR;tݠ=l[\+~L-~2|)'RC|c7>fGQWã*7[27-youw_ڡ˂(%Y?!o4@P[N)w0=4Ʋ.X6{?JOOB]yO__1%A/ R ݱsfCpR`y fP%j_eP; 3r~)rRpPF0!k F*jc^0El5N}A[2`Sl)۔@`uEebrxn_"ҞXȁ+Kz x\;KČB}-^]?@Gb~Y$,B LG7q *Bҁlc5DUq_\^˦/DsHNz\/fD'E-3x5[SOlkCTЪ W:kMf&:&u^LEoJjɹGav`"\Gڳs7_#R:Ul7!#uՙZ(q}>YN4?PyGYherQ>Nώ֜쌊0.s]#%ʠlȁI+ۧaÈ6zI7U"4[O6{w=.pOR,ӳ57i:6ϊqˎŤݰҘo\]5{/E#e(d0AL Ȑ,;u bX[ywpL8II">W,ezƢ/֭ȕN^g\ 6ƨ<?&Rώv7qk3L}O:BIMdSCJ:z.4$k.?Xo=ȪG6 Ϝ;MԢ_ ogOU Rʞ|;ĮK4@ O3{qT(fT`JCu9$kdܙ ػYE|g+W Q\F%9JM?Pj{&G?wBxd[Gs[MƷe5;΁rL>VD ԲU no+ _NQـ.NUӸ'a -W m|ʷbb,Qyc.幧cjrv G]ђ.(͝?..ݮ7⊮I:䧋OvFD4#3(x$Wy\N| Iڱ/ۇ ;tvyv[scAsr4e Խأ+":yf@&}مd#WفM:yaMw.=:X?QSnDZk@ʫ^nsԏn] Я(z\sݘcy6$=\>68b^dL%Ub,+ h+SE.Vtw@]4jx6ec3J >uHWv ڤ栦A/R#HI( Ч#(W%4`gnV F1pm7m> ´L߶ƅuUÓuV+x㢡 OڿX|?ȐcF( Vt6U6Caw&.S6=f3;b̥]u)6g9!ǬSrm7<LD"K+y4{hODD5@}ѯa&PV?y@0cTog Ђ ,ьVB9R0glNf:KcO:W˙7=48Auf <56J`pWҗ5[vNF♡]xzv9#Dܩ(SPVvc*(F)607xY EJJ  jJ8-HҺ̩phBg-@TN%Tk9HRQI2`Fttb*9Eg!]-ʹvڢg= E~kTXaUaҧ y\\0X0lYZ}H+R./RqE5't7% ԆR?*Ъܩ=g)#l^I]S\]$w\*/^ <EYpWoMs#BˎtRϊoUP""ٱ%W=57guB]7wQޱyf8jwmm#h]+f`΄ԃEU,D*Qq/dK<ʮFOKhPQ(xdp+RRQB:5sv;:3۰<&A3Y ⳱Iu^dL! Ŝ$v`JU6uZ` -塚 XWqv@x8e.OH[J<Η_ZHI\Ukeh+p|5"Ԯ^`.g~_p_yL-_\wF3v5H fGE"'n903%HXA:H4^O#}f \nHѠYLD9$)|O@E()M* TQݤM̾3VsvlԆSEKD%ܪeHݷbޡIDI qlOV-#jMS-ᮥSgEt cσMwQ1$KT-#NGF*U0c} 2eH_Q-2b52a?7 z炴\ǒeB֍eNA3tĠ%>P6$.6L[]ꇯyƛѷ7ۨX|ѣ@CA5J ܐcPJ'grS1k˪jb;{Κ,iT˞(;yQsd@ߺvlSmtĴ+9 Mہh'λ}_³!Օj{p/;K3B;\8͵%b2xV }JvkWi&]J"WYbYįFn8fJo+斲VגKϴvq=w-V}s?GIcv]dMO:($'bd@J 9aw\?[j= _{MAzFݶq<8c(ڬ*cUEe+s@7 "J]b t`)D@wy22 lb яT+BQ^7 @@ŐJ͉wI/%pՏQٺ &왼syj`&5V5Y٧nI:8LrE!BYyUC^]w[2aZԦN(; 1KլܙOnٯ'RSM` A!sO{d8]e4>P . a,̌MkVvOz*MH` \8gqT4b-|0I 6Sɇy&ew/_S#nVͺ8XUVmMO]ȉ,c{^PiZҸߗv]F:V\tc,RUHMu)4(l& ) H%<oFuT:Ai CjzfwW^?$Q_n]?\R953^QDiآGF _}k"4au X_ i8h$aƑ1# +p-TLV[)VۻlIBHbyhi[ENLV7,twmiJ'.!뛆Hc`ȁ +3 "Y"+xE' (&D`˔4Dŕm?vK1l@:6ȅHjkRYrMѴ9TwSA1!""DB9 -SUaM1qAW̒15J9zz'>cb_~g~y D %@؉hM.wbݨboo.R܍06`)jtAd~莫oxv=TOlqLʡ84y $F*m0!_4H;RgҏuGoZ$ud٭bzZc˥eN!d}6z:TꗵN6 O<>/`,:xqf*o9e@'A.q6#N'l>p^ 7d9&*32 De)lYxTt*Ֆ,q~$H^{V}C$My.ɧݮ^,PIobցo|- CA UTmHduy7U}9up+Hp d Q4A]`<3u=3tQ ?'N#[Ck6&p˓C\y _% 4(QbYiHxցv1Ǧ r6i5p}4RAR'3pA4Pw+~56"sFޝ)3` mzs6\!b}U֛&i̥ۭ~~Mtިa5u 8, z̝z?3P^];7h@Lr4@ hVOÙj:(byz ~۵r`IĐWW!1P7=59| iJ3b^(ҵ>q3>rfԃ<'5 c"DeG̩'eh{ꫝġ Fv+< %9xᾊx߂)?]fS8ZCT26n 4-"c]#J# ԟNe8ru}72 W6YRD ЫEƢMںܻҲ\-I@JA,f{kJ(w (j.WcL@WQ]B:,~(𜠵J>a#әį!ǧ.wVĎD|R}Gg<-d)".%)FIqn(dzV7 W A\*B9p-~ g(:*E߳*9K0H*E=/s^eF\Z+[lu6neKMɲս M.{u>w-qR -YVZ(᡹ƺ(HJl[}/EǪˉF aPd;bJ`U4#9)#֦z⻫ǻesCΪ\-y TGJ. Է\l7'$&V4كM2G@g!~M}7U)z:s&%D$q*Ͻo ͬk>] هqo/0L+R# \C}5sSdb{Nc&2ǰ+`̞Fꆺ :(>Qk,}$z]B@GWGLIBC_2.2VWVGWVRWVWWWW>WWWVVVW4V#t(>_ے˶dkpaJUk YZ