samba-test-4.19.8+git.435.78ced6cf30d-150600.3.21.1<>, Sh.p9|5àq 9cz*=)ӜqkOa܇Frȧ(EM%ɗa\{ʀu{TtDUrޑ\ Po C6(E½yW0M7dMeRIgW\r8-CMClA{xA:~gd} 递7}08_2YIEh=j\c>?:PS˽A(&zʒ] %Kg*>@?d ( 6 b -AX^d      &l 94(:j8:t(9?(:R(>@#F2GHHIXY\$]\^bCcdleqftlvuvwxLyzCsamba-test4.19.8+git.435.78ced6cf30d150600.3.21.1Testing tools for Samba servers and clientssamba-test provides testing tools for both the server and client packages of Samba.h.s390zp35GPL-3.0-or-laterhttps://www.suse.com/Applications/Systemhttps://www.samba.org/linuxs390xs HH hhxAH Tҁ큤hhhhhhhhhhhhhh39f933401e96c6e9bcfe70b4809075f19bb322f785a7d6c5eb3f8b9e3bb9e7f95a6f11a168aab80faebd0e5553c13c17ce745cf183fdc57eb97b9743f668c266f10cd3bef634ba9048c715b45c748026903975b6436a08d50361aee013528ca098401c7e07aa9b074a1802262e90d8c97bac6d2348f5cd9757dbd304ca39c2032759ae60133d535508c9d290ae65d796a5a3f9b6cb29a26601fc01b828dde77ad8390978e864ff1b89e3fd8f7daf0e5d7bf0419fa65cec1dcdf7f75bcb7d67df99edb6394f7f0d1953f7f1ed46a26e7407640affb4fbe5a52c71c77e88cf254fceea340e463849b14ce72b3a4b32b3ae756cf981d490ddd69f8eb17b3414ac8e435405eca06f4a24358cc1b3641c15f9a5bd5268f631bfad264bccc8a05b868800ab76d0fbbd086c0d85b3e1d3ac5d9a024299bff6d3a05d58d26f117dfe92c3d19f9937cd854c08ce90ab4b5c4dcc7df1ce5bbd26596f042e10e78a0782a8d5d4bc12ef27d3a49ab1371242832e20cc50c9f4afa6efd321f05cab57e5feeed93529bcbb524fa7593ebea9379d36edbc714838b5e15ab3cef91aabf979bed34d504e553040758ea9863d941067b64732b01f861484ab4fcaed4217b6ada6ab87rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.435.78ced6cf30d-150600.3.21.1.src.rpmsamba-testsamba-test(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibLIBWBCLIENT-OLD-samba4.so()(64bit)libLIBWBCLIENT-OLD-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libRPC-SERVER-LOOP-samba4.so()(64bit)libRPC-SERVER-LOOP-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libidmap-samba4.so()(64bit)libidmap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_1.1.14)(64bit)libldb.so.2(LDB_2.0.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libnss-info-samba4.so()(64bit)libnss-info-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libprinter-driver-samba4.so()(64bit)libprinter-driver-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libreadline.so.7()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-net.cpython-36m-s390x-linux-gnu-samba4.so()(64bit)libsamba-net.cpython-36m-s390x-linux-gnu-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libshares-samba4.so()(64bit)libshares-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.0.8)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.26)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.36)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtorture-samba4.so()(64bit)libtorture-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sambasamba-winbind3.0.4-14.6.0-14.0-15.2-14.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.14.3hҋhm@g`@gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%anopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2025-9640: fix vfs_streams_xattr uninitialized memory write; (bsc#1251279);(bso#15885). - CVE-2025-10230: fix command Injection in WINS Server Hook Script; (bsc#1251280);(bso#15903).- Windows security hardening locks out schannel'ed netlogon dc calls like netr_DsRGetDCName; (bsc#1246431); (bso#15876).- Fix Samba printers reporting invalid sid during print jobs; (bsc#1234210); (bso#15792).- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigs390zp35 1760090414 4.19.8+git.435.78ced6cf30d-150600.3.21.14.19.8+git.435.78ced6cf30d-150600.3.21.1gentestlocktestmasktestmdsearchndrdumpsmbtorturegentest.1.gzlocktest.1.gzmasktest.1.gzmdsearch.1.gzndrdump.1.gzsmbtorture.1.gztraffic_learner.7.gztraffic_replay.7.gz/usr/bin//usr/share/man/man1//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:41070/SUSE_SLE-15-SP6_Update/5add5f7dce01a5b57b4b9abf50b932e5-samba.SUSE_SLE-15-SP6_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=ff545708aa2a2415ffb884f50516006c842f305e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=54c816aa1ee856dbf5ef0a3a85c09457adf7bf77, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=d1b432dc964da9a33531c3bfc8d0b91740e78055, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=76caef5d8fd621476431a9065b76d505a0946ef0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=d881469622c431e9f4f173a63f4f7c1bbccad36f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=25c8f03041663b73187884429b276497be18a0eb, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)5g523,R$RIRCR*R(RRGRRRtR RRlR0RRRRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRRFR#RRRRR$RIRCR*R(RRRRRtR RRlR0RRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRR$RIRCR*R(RRRRRtR RRlR0RRRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRRyRtRRnRRRRR7RRfRRR0RRR.RhRRRRRRR-RgRR6ReRR/RmRRsRRRRRRRRRRRRRRRRpRtR0RRRRRRRRRsR/RoRRRRRRRRRRR,RRSRRARR3RRCRRRRR RRERR&RdRRGRRRRRRRhRRRbRR|RRR?RR RWR*RR"RR=RRfR RRRjRQRRRRRRRRlRR;RRR$RORRRR^R]R\R[RYRZRUR(RR0RR RRRRRRRRRRRRRRRIRRRRRRLRMRKR5RnRrRzRxRwRuRyRvRtR9R~RRRRRRRRRRRRRpRRR`R7RRsR@RR4RRR/R:RRRRRR_R RRRRR#R}R RRgR{RRHRRRRR6RRRmRVRRRRRRiR)RRBRRkRRRPRRoR8RRRR!ReRaRFR2RRRDRRRNRqRcRRRR+RRXRRTRRR1RRRRJRR/B{a|FGSbutf-8e657d08d51c42db934b73ce417c74b9d501883ab3236ee86664474d7aa8fee38?7zXZ !t/&]"k%42_fR6mH> nBh]3JiBO!i4=ru!-7Xko$'J`k!@;?jaŌEoZZ"RH=wK0] yFlNJ#8 ĻvKGf51xb_cyH)đ-@JrN[Ow/cW(Ђ?>Z[KW1j< m˰w]Yt&Hk+՗tDI|U|t ~: )&:`9`i쪩9n"|߀ K̇ONmgѢsHi]"[PQ'n$uCLe\5^1Ix!U-^uֻf[.6ℰBm3Fo"v7w`'SS°J*V/D$ѠkOuTK%Z௭:zY"<9 ;2s2c꓂tS%i)umd)~-X. :0t*#ICbbE{j/Yf0M!tgFƛz9B nW";f֭ȕ+p eOB\lAHG0VIq[ss+ւD,`J51 ~|;Y-+6}s +d/gEm>7-!)WCQ}` )X~zߴE +~A؀ѻOxED{^ yA;qPX4 c6gmtiWkw JDZv7 P iAQCO~YֺJI>ccM%s fsftE'$>?AIBdH0NEZd'CF/,q1NojdEL@}֒ Q C/x%K9's6Xc_BF2uվ&0P%t][4 nܳ/ȑW4>}G|׫jHɠAVȮ`#o{^+xPde?mǠcBLQގqhFK\u3/ n?\)fwa*Itb Ț#wxܿH HH{0yʊ=sxe+&~|Wu}rŐ6l{w; 4JnU"$Q_MA֒dRtyЏ-L?5<Jj6YpqY(g /}Eܺ@GkGao䓍O)nt+^k.iW[3MwC^Ӈ.CItw$a@q}#u>BP?:]U==X liwRweDQY..y$4s.WM[4;/vĦY̱D6hS!AwnYIKzBH' fugD. 3%UL6{=Yc5H2$T~,lٸ iFmY!ABT&N6`(A7ȹvmGiOT;(ZApZ?GNUy.0PΕRGt %D'@P"mt[{YZaH,n,L l6b<(W?Ar/$tZ@|d%BǣmǷ<*a6P'<ۧUnP#lW?8ROd] gNh͠]y o ;*U٧dvp Mwgj^p F6g(K6 ]DpjZRQA޿ֲ{J\%&F^me;zh;ߓQʾ?m{G ^o h"5t48D>LL%=hqCEDTM>Tcn.VxaH%,ߡBn'659zZ*zi%Ý~1An $I-KGùQdCoǂTSxG@O/Y;gr=sv.k09 :+`P-®PSјj4DЃ&GZH*wu+\Z_눆`iK%|780#'hQMr% ث6Mm`F/C!bHf7}zc첛?#2u^9MDPhp܃ iaEm 5Lp>{J|4A_G䣤2pE':v:&!Q8!ɒIJ(h^USHot297?o5kPdx& X;v&~; [4(8e 0ksRS?ƭ P'Qb:«IOlo?[J^f./Jֳs]$ Uݣs  Š OD' Cm4sIF6#_ _- c--i3azǾHI7%^*:E :zԎ4 _x"WG1؞ t}K+<BOmX B="aRt װ"FlV+큨s-@*]عȝ`p"V[(ToM>;y@mݒ)1^⥐?obPim`TPM|~&2nuky~Y/D"R+bfeU`F$IQP!ӱ< @8;۰q<\NFi}x2+=fEr]moOek .dwI8]MXkEZ(*X.pMwmGB+ pqM4-*ڌ"5ݴɧdsG5~!2s}Y{adyBThc! z,I 9  ,p)b'mq\\"\³< W,}>Vb^ 1T3Ϸ.3a+^&%i\PʽON4|QZY_Sk)"<"5l}1_@ҡhz)MŊ&|gdPI' 6`̭Gw)Mf{@9$:L-~`hL.e(G&@6M>#Ag tja}lpO\j _r[2tc ֩pRK Ndd ctW?B.)X)ב &5?*8K^$m5teEk;{W9Za*s #9-VgK#bW`4Þ&߮oN rũkۡa%oڤHe[dm !=: y`5ͱÆTG"%+djAP!h[\˯2)/os+Py_/0iPzs'ـNPw4(+^W2()J= 5$hY>Ug"];f; }Lvd{C6ݚS]% ([#+"M_*C+0@M#WxHJlqlOgNt WwZaܴ{YQ3O_c˚ICdOdn?bԮR<V9LT3Y,b07/ lVg^)pF&ƹu!8d|^X%ɸ,nG&J[ s 4-ؒ3||P#,l;vYdz)ȟ4sW-pŀD?.cNXd"/XOz`]@bX1G.3xZ '# DD>KdW)93 l-9?8hKP8GS: 9ҩM=T2f D:cN^elP\ )@D6ѱYlfM⼴mD aLUSˆq}]б4/0I] B~`eZowh{8ﶗ#hScӠ+l%,,D/P%EA6?3P|s*1TrG|W-yh<ƋY:֊"0gN_ S8ۛ]^=V'Yvϵā3w6W?B88cl$v >E]k!RJ@CdF-JJG;D_8M},Q\ #$h}JHn@ m!W[\2#siUg{ i~x s )Bc])ť D4e^ 1Tww\Ih z<OW))7bqG8& 3;WExY!'^ARCj qrY( J%_W73:J9`\4!4 ۧA+e |wJWl /* ^ja(2HAm>9 /1 hs؞2 A0[Hꪢh>jg }"ů^4becrۖWMj'Ja¡;i3H1 r$ `a{OU0B HAufN6Gx۫rژ-Ahb|(V-;e!z"eSFW<)TdؼCIjb!>=paAo(O ]@ ǽ'G,u$f_|R}7xG 4o\kGE9MJ[MQNeT/{)HW/E?bsb(t: {- c} ?^mBZKgE3B A§ӄ[{Q٭pj.1QR9#өl>fumo`>|P*PKƵJN3PY]pjݰ'50 2| 52e57yfVgs9D"KAo]"x%1x;%gG?@t7*hqNC?>hI3:=͵JMB|9>٢925v3sadHJb-{Gd H|7BO`k+DŽPmBAun|S\W"\ֆ߁l@IavʨHo_80C0yoʀ H<^9*y cmQ6D]RS(;!Ӗl NO¯JqEgTChw4uMRE觎 4vb٭@ÀݠVȁVB[t">Uέ)d0傗 rc'lmҾp]G^+X<۞h X~ 6X!3 rj[ώt/VD D,mVfS+C,${Nr[NBSP 9gx!OfDa+i~R}WdebuRTz}Oy[xc]]Ff -$v;gœMPjhޓ^X%;3 l&"o\5SM&y9&uvUnNVzl{[b҆Am4]VAIEhuh$8S&" ROC!z-' vn}13D:^>]J`b?_L_JlPmԸyv$(L.i^ +chcP~G`suu <=j縅9ƽCSY#Na-ar 5 ((C~g <@lX#,Bo%K v)0n>u.Ԩ\ie1ҐqǠ@ոCRae30~8D~ =/ ]g-VS^7)L) k:Tܔʯ𢼍a "k |MS[ËH׍<iO׃ٍD5eTP8E,zFFJ|6^O?Bx(J$;B<^H9P'!vl2J"I>=KYEEyeAs QVo&z *&۝c a[ٲjN6Ȟz~]S؅*_l;w~Ft.9u?RN˒/58g c,ðXY?H,92/#Ow|!,iv_cN 2c\[i7k]vz?'bhafJqy{՜^ZeFJT.sTaN5?$.oxbjj|6+3dvtO8[AGOmW-o"z]nloϙyބ-<vt^NpƠ,{TjE[ ,SB͟PsTOXD۳zfo=H '~X,<};%i^@4Ȉ UQ1|[lXqX<&1 ʻx*Z2ZJ \aYh@]RuWNVo{]J7(2 Ҷ$񢴠O<2֨gjb7ZfH| U8ąi=pflVD MXx‚Pȹgt%kPկ]NPc_QQ2_u! *7b| |\+T)W|ۂk׌K^%.sMnPڤT^ 7߼MY OAIHdMXc\.m1kmz+j^ +M"EWobE+9>wiۑ=1{~ + <[:MFQ\֪zzr:Gܙ]7NjمcgXq.<>arVU`Ňf?SCD$\t$I+9  v`}f>ǏȆL:[?+@(Bfcew_)_Nx$XB_bHIDòK s.ͫU5>qr4  H.*8'AG) Wuʕ~*(lR0.YєxMZw]QH_{ʼnE!LtX^HOp+Iibnꗵ0M58yOM`By'f l-vg)T*n{{ ~Lae &} <`%0֓&+>ouFx8sPZt,Gw]':yқ>w m [p1^l&;W0g[oӉТǐ޳vµ& Im莥zÑ(`Il B?->g\&t",zWGw-۸UÆ~\*1~SK( d>OAntCT\ 򹳞Xe` 'oYpG8\}]~ag}=U7OQ (--5̬LCP Z?Y稵uux +JxiIiVP\g7~6h'Vb.ˌ?@[M'szv܇k~nB5Y C>vgnTXDUd-δvtS-6]&)() D}Psiz2:((ze(.'ɖvRy0C8|AmA$$[P-5NSY:-}g9av7mPI.F9+` <;*A AOSMg]K|+i%O|U㌖ ĖxYu6sAߓJBculQD)j?|*%@'k9e$fӮhd$ж}O U⟥g6=s[,NR ϶VA/ޗ {Sҩ4F۟.)_=wAqkAgV O#bЯbxҴ1ogvRVN)>e-÷}b[]f2{}}fs$׫؉6p5Cyc`Y`jkZ^Ҫ=K?`Zm)Dl9pψ:>AU%(,fOS_{~j6dk#@+iŠPv!,C}*NYWfMa2šd5]t߭B M,JxC;8' Vyߺ pěCDB̓i*o^Ke܂>BRmO=N?c6Y.?Q7֋q5)CթyL agair>lL0.2oQ޸9@JnZc;_=Lua"b 1RD[ ]EP*<B/NľeiV{֚;@KN;g@*Bf+m $&yN(@NBJey|x9L ,]uxSeB||UY+# z>Ra47QקTC^ p(]{C:4$ M A򙔥 wSTG"t1O {&so'I.~:x yZ2ɂ^CzE?6eBD2.hj83~C8H-.DZ{d4c>}qyυ`PDzksbLp~fBKyr~I揼 Ć3*C U98v;i#$e1E=~vif6~>r};͆ Zɑل68R?cd*!f^ӧWsxr n@e#Ld0Y:!g5dM@6(3BE)FCb|(wKxLecy5[KрKYt} K ?%"'g=ZmC⼭3c6ĭ>bgv/UMTX܋p(9ɔ$JX+*ӄ"EAZkanhm i 5k^IbS}8\?ѳ 1ȁT L\̶,&{qXjl%ns]A# g,}(t+|CݏZ&:d$1D(=Z'9.$ M ˮ TN|a%u+Y#=y3-vQaf=_tr_i$w &|7 ۥg[(*$k<\6$#06]?nׁ Eu1>%V^},08N\6{%Uۂn@krb:'9 M H.ʂkc5Ǹ'0;i#=K9뢯AX/D+"oLSl9p2q jT0oȷOدX퀆+>In1#uJ> E"-`1=7|DQSG  mh{$.K $@Ξy)HE37SJo_<{z7/wsTqԦe * #uC`Debqڞ NY2r&r+|OukPHi>Q>eh[wEM ]-M:42af2DEP&Q* u cmpDKv -bK#`Bw7q }]!5{6|_vĬS dD02l[1'HSFe0n2njG~9JAVz{~X[d+O]6 +jr1hv n ϦV *y{1njt:;o$B> ZÖRhlRl8eF{ٱˏ|fxYHNG0F$?4[߲g 0.X@ c2djxae? +3C 3ûFJ daK5_2_⽟86`s;τAzB"ZpXxkAk6(sb{-P! 1tj_4\E8 8≚/(sm͗>wO(Yi-`m`!<ء[ 8dbyK1x7 lRV}xniWK ]A1CS l[P+朾vyFW\w~^/k+1siԳZQ/QBJ2p שzi*':T){UDci a>7H74,˚k⫖!KR a៫k &hYKnF7blxH5Xi^_ԞlkvXU[y\{ftQp)g8(YaꚯK`fS U"@r5MūRo~ 3bD$w^2 !fNBKIx :vD[ P~>Ȉ:"E"ߑ&To Vj;"A%yMNn︺=֡`@~p|f6svMRuDVŒZ>0jfLkZDtcrb3֛w#`[AUPo|VFd+;yUVzg~'/X K, I8SUL؟@dB8a`E^>?E&4&= _]x̲ŝ6t3S/Mn8.4?]z$FVSx9I,=fV5bZ܏MB}`fY}:+>nfUZ(a' SCepLsldh xz9cjyƕ9Iꛔlj;0AfɲJJ՛jg=DO8Tn{ ɍqxcAT&-䍝|_"Ю}\x# bb@>}ħpQ-Ty5(v؁O@;6 X5oOoe$1mlZ BCo~tdWLݸ[?h fqSTI{eJmk{]|S~o-؝ǯ!] 2uCrYn ]84/9#YܷT9}]Ńil, k0Ec\m 'T"-[a nsMGڸɉH AwrHyqKěViTpoAQ%֬72# [7l c􈻌؎A87%c.o1$ӬIqŧmXO`ڭb';]?]uGt:hW3kgn9ZieR%|nZ:jBP8a(i62hE+4ٞKE6o"@Uf<ppN4}?ՀJ{X}vږ0 8sP<+aHtw5Oq&Sc\[&кލޥC5JR*TWWd>-bI"H,ud,-,Zӗ/6(Lpim@q#,Zo@1!3P9N t"\hX:xiP$]1' &S iάu82C;sKj{>_E#r9 X4"\y^}D8.ŭpGƏtQVI0 18}=,[gG(ې@l7}gB+u˜4W2{ ->]K9c/k,M{WAIМns>گC޾~GByքm _t_f:}c&M U *aT[Blx*B{pڂQr*20'Ϡͩ2z>eަ\͹}gRڦ-AN?")z5(%_-d!0XwgbI#-oJTaY ߸#QHVNx0Rpxe2XsbVog6șb[}TBv܍8㮭Ĩ#tQ= ksT_z.棬$cگM %GVy/rBB653+aA=Fl'whhQ{H .j mڃWbdtkYߴ(vyU9hgs)jy̽GL{ty@@O3t ")(Nh P٩ 6I=2Џ"rlg78oT-9Q=؇tB1 r ̓LSRkHSMxcs J{SˆP ئgwTeV~P8O5١Y)G@:9@Aކ|.X616$\{.h x ᭾\hr.Ao^RYPhG,)iuci27g!ӏ6A*}NAa fPGMG;iKalshe J[ .>93Qw/L}-OU)< 2K^i7w똗rࠫ-{1 D,NHƷN󐱺a:ՂA0 @bVɎ?t5@:Z~797`8퉲^ɇq$$c4 >E mt_* cQnbFStSuPmwe6D9oEA?jnwХ2P"Sޢ$j6}-ј)YG~)0ȈArELzy16X.?>1(u X04Wzu| eK#p sjuLIbs%KG[c(] WbKeD򧙸Kw.𨌧0FlmhAfO_ˀm9C\MiYdv`em.'VVt)( r:z)thW#_L|VZj:>.8s|1ⲁuʖT igB4Qе'B6\:_PYaT;v2o'T$10<2BuƟy3 HVy8rTJ9ulf#. q#c)j3!dos0FEL<7: 3Bځ~6CBH6 ^(8I+М%w藋r)nN+!۠\u?+Յrb:*5ܦ3C4ydmPg,E{|:t07LLVJ;bϯ]bq;$R.6ŧA֔s`qLZ k1,Y'̓n=\(cщDa[|%.FP<@u:1CK=( c I!s'$goZ#TG:)S]K"o.X94A w sU<Fݨ NՎw݀ؤ[;B&h]qvJu1ޮEDl'n ̤bzvE`QQ }V1k `% ୿ͫD63Mѓ:p_t8HktaxaN1õ;"=F>]G*Cx6VjMGq#$f ΍|~~g4O_zMn3}~<1B׳π_ rF #s(5wGKjI*M+mo^5,Ң&haLW3$ ,ٛ q!CݷD6#DH_9ȧs:7E">PͼwY%N^-*ւ2(^^S}Z$uШaw6?+mK5/oޚ?P͵DH+-(ۺ>z ͒Ȃ?-JWUnCqW,-˟˯[Kvy4K !a֗Y9G 5ova+'//5Su#EcD+.A? ݟ~z\\A}booi)\lA[.!5Z2pSeIz*Qʊ 8'}n3]2#)dΡ$Fa%|&f -H! >և{BKVgCsW­/M JC)]TV!hTj'l%0< ,t]а.')1 2 À0aU]B|budE 23hp*ȋX鮧4O_SfXx嶋.A~ҮBT"kzt?W!LZ[ φ4-d [0 Yݗ^02aek[ a=.E'BF9qy%6*UUI'3$4,0*O|xRdYS?z6"29U'gV"SUrpH &c9lN"ǿׂ蜖Ev6 g}zʺoNA KLQՂ$#'w^ S9C׹S2l(C%LmAB\2?يnV<(4r̯!&["o#\gWm*̫C|8Y0BÍ jF7=.1"hvl,0D0fJ2ւ:g8 yj( (RWoUSiEژQ ޕ^e&bmN-7-gܤ=׏jI&/Ö"0%~~{LV̓y_*o(eÅ֫c>)}TOYj J54䝊hDLIkz]1)hH)eSOVHC B'27m A&ZsW-lHqgQǀFW>JVot*8=TZ8TF#]@أ5:~#ylq~+!Jݴ ŋSb"&((4uS#OȂΘ%"!GAikTeSOMA o\*ݦ$>`ѫNW[)BvΆnov$9HA vcW@{fE+NU<,p||TAi+?q9|߅M30{}Sh%ղwqPf: 4dK.̫(g봞,9gV>[$vNQÊtHĺMyJ[B'Ifo&9LI⊇4_ o^6 씧\ _>DfYP&ㆡCOb0LvWސ vuUz[^y߅U=*Ƭ]h<`\1+nxִG>mg8sa];7ژf MKeE'NE;j=.BᡶC(T)$hXIŠ'u|1" ||ˇ? _[v4)]ɰl '{LM"ٹ|W◭tEԂT_GQJI?#s;؁Kު+?a#ɪ4BsG"P DgpӲAbTMȃ 5EQŋ1N^L͠(ʻq!v̒-(&HE/~VU?qOc)~YF4JhIg3a7iǹ^&ƀlāFZ{x<7A(+mQGL/v8sz1r_o} rs~̯iY$uq|A_fL&U)4IklB*3.il pZ7XF'm7gwA2E'%Q⡟,)iwe05U Z,D=P[f71;; Opg$;gm?̮+կ˔Ҙr} Hmr5^Po j+*؞*2B[)SGqo @m xB7쀡}ɞ{kGk"IEYl7`~ pG,;[;R#)7cD*eS xӤ Em!Xڽt*z@`Z}uG惊-tUv6^6 VZF\a' T@x"Pej ix'ECIZ8rApؼdYQd9FTP5f=ЎT HQ{Liw8fҼڊG$- 3}R$_(o/U1 ^nBQn ץ.!+r"Qbbeö"S-Wܻ ] qdl,eлKe\LLm0dewk`٨s+}ߝ*ȗ/rxO񡫰#Qd|Aw>>j6}p}T ZF["Z9eֱ"yC!lRfzA0ZUU$7^. fEI:>},@{!F_'a/q7F?[ni6 L) 33n(hH^1URFc6xnϕ3!svCvytnS%甁f?Cq:S[d-w}ۅ7 Kk,޲_a*X{lޠfKY޼P3Cٵp*`C HK<Ҫ"ϧQB>C5x9*;G,ݘLv^>ƆsuTNv_Cܽd#1k &ծ$@Pg<*x%@|һԺ.HIiPLV^̛N$1kEH-Nǭ>#Ό00Rshv< }peD&8ԣш`qQWPZCӃ;xVQXpە)4Tu/}eJH#W$&?2ϟwSqEݤ6%Ƚl[VQCsO6Jdƈ幰qo>y>P[%0L,v9VN+\x7x^uUd _QE b|&]qA'Am{ q8)62wcOG'!ZE9)q20jC9 eU]֡g wnsQ/> TQ8P{Z/׷wG.ۄuL-?^̊:l6%L^е}.#s}212!wY/#8̒{QJxWsTJ~w:y χ%+ZkMUdE<>+33ׇvx:zU\obw]~Izh7JJ~}gRV-kωp>5A}b`3NS mN?FRw Ya܃2!s{q&EWt^_nd-_Q wZ|Ռ#skȐskI^KX'ezjW IA,sƾHGG}Pm#CMYwJ{'@[:JNSɁU n ?EZ҂7'SgH.4Y-,>;g:T']N&-J#T?k})l܏l0̲5Φ=8G>3\y]Q5?EHP I{>,mIsF䕿0VsӛE.P4REMFwB9P5}64ֽ91 e*WnÿJ 5g'D7fZyQ|H7/k h"`9mN яXygޘEĉ Dh @joTV1uXY\=mh}DmGzdX騧..=+akO4|d< -#!Ku~"g<ݲ'ݙHB!-)7mO1ܭhY>v9BxߒR ƃ8H'uS!-ZRl?U Z`(o6"ʹ,~;-u['pr\L sgxiC83z&lu*)9'"8Ymy~,錧7\M3W,j"+yX_! +8/ϿrZfR^Nk25& mqE8\=* $!7랜J@3^)TbB~&}Hը)4=35E/guKn}`w!AsNGft{]yaDx|fJ0.#&cte\~HrVh _ZUO5Q esb溸9`pP)T ""@D2'֡P.2Q33fܣBaF!yLEu^nHe7t+T05{ͯ:vr ?~,텇zdt#±f7}^S \YQH|a43hH3jZGJFJDצezc-Dw? [!2 !B˗e~c(лLJ? M:i~6Ru:ۯ%1w}]$4%{:9$ _NՏ}֓h1CNm}(J5[d']uʼu vGn-1 jPE(co9*SdƗbt:兔NؐLCP}eSLZjVJn&pս& ߩWѲ;Z"xԧށ|O*o$NCTUA䯓NRm_RPMayi$<E$Y-NUo}\2mD33Obcl/Z,b=sȅy82h;U򄗅}|=-?{/ JzXd =kj o x}oADo>0[]<)&EzS 6ʨtxY>q|L+`bh rC7*)Y2-h54c!ٙ_$e'$J7px=/H._\k9Tlg7QEHX²nūmP{L2^`r+gˣlѥn`VȽ1&"(//aӣ9r[e3Ez'veu։Ce9X ߴuCvYṓEiJd.&UU\hu$W4&H#)<1;:Z8ph8Ojx&{{*d?qw"*Vإ9ֱr>fE#F۲>_v>8M. zU0S #bIndlQ9%V=ln2j~@ '۞tS"QY +Hzd Yk|*[8L9e^OH Nro{CGlnɯj\ %F#ԮZXDظhtueU h.   zdQpGgv"3L%`wUɀqZOE~](|A{tO\z˩sH6 ǛK}/ 7us _&Jh+eVCBU΄ ҽg$V-gZz S+ !A`\S2諳}D.Bc{K403: F=S .T0umSuT=3$RetUDHH;L#r" }%t>"sB66ķ14c(TQo9OeasP%G\T$[rhf%L! ^Vdz6HӚSv+1:fIĺYC['X<( ZQC틮d9f Y/q(0LlIWVi71uOh݂,TՔF"fE&eh3E6Yh JOk=!KPR%q2um*rؼ669Q.쁇,*mSM)urhA*d%%AxJ NJ&աASq8"iR?$Txy1v k1"|Yah+_/g̯u~ڈEw(txsF|g\$~ <=hl e"HcRYE{ܕØUCO*6_9$mz?OQ>jtJ *ӄb NaW+Oi48_XW9?Ē=-j7(ڳ ,LWtSb:z @0\(:1$"l/z?Y_P` H}'ʿe'"=hFa3.eςTUⓔ)9M kNkf_)x9#fMXT ta 르Ęs!&ST|ccRքo.,0Թԯaf=}܎zۛ+PK*?Ih)qZ7aznFf|3 8X NcR wCā>w6K;kQ"RhJ03~xN}po] tW:!Çjf;`hd͗窋^ +Q^X >iE4WU (5>!&3Xq?|&'SA&^PV'D=P))cd nuL.pX͟aIxzT} B3^#D/)EǮ0jMA܆` _O2 HxSGSs3pcl#&Q5Ϭ,!TiuKpt)Eu)c"F18Ǒlz)&ױ{CC`3P58M:'{(!1$@&8Q0.b5n4죀 ]O$իw[goSа} 6SZaJi@VΏ[`F4vSH̒6Hmo( "h<$esHDP`)S#(":7ha]V_Q5ivswY@>%)_GP$A^l۹}Sbp|%$?TU\;9򂳉meܧs쟰f:QŠɺ9Ge <|S\~{84D_oW.6ue ;˸aNsӽZypbhēfPSnCetVRl.&5n,Xv$ |32Ҡmir`KA`Hp 痏եi6'z7i,癳k' A' ,afB^/w贈#d>ƴ@ԛt/ 7`X`1x +f1`I*(rN~%DB+W7pBNtD%]@4kWh:ۮi{$xn %jmz]t0OmfBSS*r&4 5|CEՒ兟b.'eyэtOwN"tB,n4@ˁ$Gs_ݶx,08-ڡOۢ&Ƞ.F:Ӯ*ɜfhxUh5[֎N/rۨ9J/9Z&'[>C0 20 hZ|{ ]/ޙH=mt/)Wcf^ fcII]̍NWBL)˪I1.h=bbޥ|:x_ !,'+@p\ }ףܪW dSL)GLs~$Yrbnm!PMz @]{k"1qO] ʕd:[Zcկf jŵQRB]zv9ȈVޝc7)CW#׋7'TuIzj,*å !:`@7oſ]r?_Q6dB&}k,ߟle.DyItk5{d1ٿ\JöD}^ı2 ~Ⱦo,TLb| F~iTp7LHIRQ9 7[]i :ZkchM.3I)q9MWaYՖ8݌[߭lO4HXt9jm[*U0l}j/ ^?.q1A\s|W=%fk+SL[̥[ڄ 0+B/#n['VVʳ 6,C#? (VG Ы CnQPaQn, -\eɥY2Q Eplv]|]g[o }6LXW.6ѢS$BpN`a1Ҋع:jƶ?Fko`~xnB2?2ppgKq}FE\db!Y>#̐!V>$p5CXsy!IRؙ3nmׇ{v A~Nsn=C۔&Df<ۿYXͅ{Q u<=-ӼV^U;p>%.MlzNkFnI.1sVBa!&+)[IHMwY1wBvֆ!A)Ӂ3.2VQ&T _i0Jd_O^t!wq{.3% i@Ey&v`۪7'E|=`<*ǜ/]T'L HR4JQ$k*R)%5ʵ׺5섫-j53+Pv0 Q ¤ɮ ,.:m0Nd8Pr'$Qږf _E*Iש‰LWM1D])1j ")%uX  jsE׏n8GQF9S=.˚p4.l{:p}7

,+Wm#uQ9q5(Qֈ<-&F봝1MJ[x7SFNmj.,d| l5z$@݄u,..<_#ԫ~q pFfW&'wtss2& Ji"a&k|ֿ"E7evyWPE<waYK%y;o b\OBBPEtюdž9^ΉF3>n\LN|\u}#ٯcyU(C,u׷0X癞HL;txc(Zt+ظ[tڕ.dgG}ĵ"qqA@$ [R֫lz)F0^Cj+N|=.ox,IyP +b@=XoԦoaUZ>7FSMai2O:,^ 2yreփ$J>КMF(!Ix*x8 ׮hleŧ_Ch!jBآo 7גVE3 C5i#fJ B1=2h '[ cؿ%*L2y5y=sDt6B螑i*1u/FNQ̗1 S ֬ 9a];5s&vd#E7s@JktV]H[͖})$'=,- l0֌F ݢ{FwSyDLUcy]T@e2.xkWtAk;,ˋW"Dc fzx|#@ҟr4gna>Ӂ8o(nK) ._[>F}Tv` 1G?88nE[P1 A!ه n^eJQ¸){d{5j8_wCCF QaVP\wFŊRPte Ν)v'Wv8eTk2yR_إ))]|kWÉ`b=(r%8)؍vP$l.NWnWNvBܿ0n4&6@{G|WMHv;w0LTf_T\/7ˁJYr~i=񴝋cd b/|tlϷs7PFjĔSx#n!Sg xnk{YIwtߌ5Ƹ8N5V1Wh'   \q*7ȸ"畸lLڕ4$~E1ٙqڣ߬A4`;FwByXf..5Z6oZPK<!e/ɠq6a2u k="M?;V|*F` M(#F[ 'V;1A1l&=^&hӃ49A,qG#5 C[tEj:~tNA+fzJxF ސ9OԦec 㥩rۉ˞}޲3l?Dzi˄%s= ;0 \ Lfsa?tSɁl֪)/6kcY`g&1f xX Cb|_B!jSA3esqGT`O5si-̈́E)4 xg>|ԃkFw} ay=ĪXT @ oQeeZyqd2HHCecKv}>Z΀a!B5cVvExg)I$J ɍ:j` l5,'(y%> `=MpycՋ7x d+BIT]z)k4G)2ݨVf-&@~i izUz$ZWEn;p?t> Nu/K@(:w*P)oR :ʡc6juRps,kMߡiV.QzLƆ$7K4ELG. ('\.>m†ʓ 4/-(Mt8ϗ!<OƘ' k6"])$&wItRnlS uurc_>q3[*.u~Q6NWd"qeH ,|cqRI#-=H1)@HLD3u!e{_axn|rnBTϗ ;E߅Ovx{g2ӎL4ъD(mu MƘz ħB`=wo$qp$vjNAl ?&Ő +PAiqēN͝FWeM]G1|^o˵i0ڱD]%DO`Ƶ(JiUq[h'FG$i1b% MzypsSu[OK-¡g)>-~fGQثٷ0w|҉&/d=u.bw^H!9MT5 NryKR+U2bŋΦ\RG͎lwuDGXy"a.K0-KO~fx4tLhY{ Ɵ<}F]*1pdCuFV}G"ADuޮ>P}pU M^U f. RLKYi-7 -N;گ6WnA{=3,Y֝u{(wѭo| ס+|AAxEK/* SM?I( j#lc=Z0{kizzp@yQ= MR#bc/v[J-DbA~z? ̨zsGE " HŬgֻi4.!Y,uy1>ySyI"SO]4n s|5t4 VG/7+Wm\EϝeKc]^>ý5(kDdJ6{ .,^2SLf-o*7pgT>?OUeҤuxI x'qlwq/: <nQy8؅u,4z/KdouV]rwEHTq j55*CkEZG~}@? Bi37 lRN\sY=%ZPХBVޔ@X6X\c20 2tN|o(23/)l] `= YQr(!_2n֣_d GkT3)H%-LH5V]b?CVg}oYe5[,FRmɂ[rtM1&-Rt&,Y9;ڣi[)Cvؙ&r kVo2"5fqtsk׵$NW΂IɸN5TH&ٳޢlwprB8Ue _\vg. G^7͞q uѺ:M}r#V2[RN ]X<$*D9G1f4? b sm!lpa?!u+&1XꑛI `[< ,oYA[xNMy $!57c{4To!'k`{wlw֊QPnlcf3_atE|Mns7O׬JSΡ$O0~s. zǍ\lxphehrͼpa-RT:qb#ޭd~JgK`]a_HTوy8{>lOQ @= +/&zqdgKzU@3Z%_iuy>8(@7,c$8WD]Z hF0BU s)v5{{([6ܤS-~-ݟu0s Vexkc{$5E2L8W˴91@TՍBm Zt2v a5OUCΓ12+u[+wjV꺶bd)Uȟ }F&c*0Ff9X`j.Lq S/^Չ7a.qbwKZA>!`7bEÑx((o =cFUM5Khi.vJۑbzmyn !jHzN%!e ng*3"t85u#CGH2Qr]*= Ȃy¼Ѳ46mWO&Ka0KvU$~)YlkB`9\Mj+v<2P|y4TlOD^h)^K'&Jn܊%]&e񈼕D@' +tiaRB6-;~C_UiTͷx:[:aAwT'VQ!r=B|;A-]q:0shJMANdGŊ"l3cP[Kws,T3K'KߙpƑC%| &"#8+P g&b\H5N[f)BheB:3L+gL] QEE:Bfx1W%J>~:\{f]|ؑ}L$313{3ܥ8zF<ҹe}( )x66U< ˓'gE?t%p3 К]ܘ(jfKwKQ;DyL*jIRŝ=}C-*/NWG/c)0dȟU`gF5@BMs1I뀠[9RoONU"~r޸ArhAA$R}u s+53谺 g=τx_n13hq ?hO~+_zaJב#(3}BO9aCuB1GFG Jk0P?h/{WO7?k;yA`&l'S[Ϻ6 5BdӢt6O<BܐF܅dd߇0m9&F7B{2<O ʛXVZU! D6<ÖXo1óӮnȀFCId%_N˗fi(5)6LK1w#G($kpb|qwA$ '6a ץ:,_T}˜WhV>tC3iB޷/;`ql"WlOY &3r "YLGV(Ts ` A@N/]G Z*X\D@zq/GP \{25\$ Pܪ뚔Ͳdil?TR|> CRk$ڣt(p&mJOFw»#&X"K}A&w=k 3)j1Q-ެNM |OBw$À 5f4gtK/^6*ع7P`(@_fJ$2OPlF`[n8h0b:cr >*JPwQ^ EK&{W68׈+UCcjlfsZg,NWe1XZlw`Iq9ώNXN\SҼ-7Y/MIۖWGخs`R!f B>'3۞?n_xvs&PRpxMծT˝ȫwc؉c̵9gSS^".Ù|qmSHdX0>zKLJ}kc|6 |mpqADDoyk}V-[O|#m"d9D0gz4| EfP&@ۓO7 e[; &䪦oh~ ~=m WJ&_}/4bs~V_SD$ob+{ӵ(zcV"YB נ0 N23ĦBRceFq5.ŀiSΏUem%]_239=t"efԶb%eAKSbJo#Ȅ{uf W4m6KvrZY/HtvPiq{zrb䱔^ٟ][#bz0ZXy 7xu %_K|n$ :->$.okkhkm [$ M9=.8D-(O9ӆD0H=0T 댦rrRCb`8cc:y K>>SD薔ڲm>_JߘUl}v`l? g6w}Sȷ׷y "^LOβ}3BJI /X&Tkc00_a65!(Ei B[o@ڗK1a)J$WAQSߌ: b8c,FXS,wu*e1Kd=0b*c-@-r]8xFRRlc6B0bj?c Z'qt 5~~RsB#V\x6H8ͪ8Gh'_|[ڗDmQ]U_/1~'&DyX$Жy(S2gm2õ/<C%-/͆$})S >.Xnx~@%7uYa2(<90K,|J lK6l $ML{Ԥd'wbŽ[]'gN^ )<ߣ֡sFLre AQ)W{%2gY')?.pɎwśsgxTa{B|5鄮6~t:EUsw9(w.&eǂm|}$Q!nc97M!5dkKdUgY \iFv4J+t:~ ]`s3 #bYl^dş`:1F̕15SDtv-*RnrqN+ginL0"N os#@}kBG*&Gcֺt I4!-L\zbV(帪Z2R 9kL*JTu{>P|= YmLjxJNŌv٦{XvYhG 2V_OaUePb Q2/TNw놴!s n[ o?*H{-.12E"Fzyfuc t[WyMj [ bgO&2mllJIIjc35tL_E| H5PFέLf ~]΄ئ1~h$,Vq˱:%.z`cͤӐe<Å;b?~ 6k lF=@e= 7@՞)hIX$vzhC M60 XE4"gL2,N4d. +=p-E(XC>VMFzўU RA#/R7o2ZSns̶ ]L4n{یimikеH"ٿם;b9C&cWy(ۏק(aQaʅc(1Tܩє^R0bJNݲ ݆x<0Ǐ.x9c742FROۜTJ=G{ˠ J 4]!KH7;MP[uhA2UdhQ/qti~IaSJrWT!<K zT8ܯJ$n7<ďUHN?by^r=MI+77lpO (> r9u=JRQR; O?`RJHngpE?P] _.ef49AIٔ}Hu! >3E~ 3uC,ݰlƉ "ҧ͎,oSR+gLpFքV~QLyr|G +z2N\5a(qXjG]Y>Nm]G9L8*ّ:mcôr3Nɑk`;,pR\y~3u|)VI{7_F- *5 )&u%~?ޙW"W@)|&p){{!eu2e9.4UudMEsvx҅Xw]K; Ǧi;*J3)X '/Sj'BTo4juhПuC욶;\KU<:ŬOOe]Ueꅻ>/~^2ЮPVF˟r\Cmn [/ۉR'dhݮDͲB%v;a;Q3Z;<M<Đ85yoT<֭'Fd,UށOV7DNP3ץ(ݴC0v4 󵃫 ]@wAC]D:E"`tu<aKfFo"rHJʺ(p]wn9_)U8 u({ "6oP?.ΖEGp#ۛ쉝t$"*vs"7"ʤ[bHPki2@P1r>˧#|u_0S2R  Ȩf'&k'[yޯhY2&yKeJgI;'k<4Xm6Ϡͤ|˯kp^kenwɾ7×>COp*9'h>i.??NEu -Jy7*n"a>DaKQ9ѴLCR w/eF#vY<3c'ƹv,]IWO*~ꉎAFc uU}u+uf0=?z}Hi؝fJJu)yjɬV|UD̲ݭ|BëCknhY q4訓5#{^?AfrpjخWj)fe~@~C#N)gQ(DUVȨ2hXv`gro䧸#3jl4%垉yPY3 &q?D gQˬ-cQCbR̯ӡ͙cYkYȼ| iԨ׺CsR)|Ͷ2:XV!H |,ϩ)ӵ6 5XT,uRQLC!!y_zƳT'ZNm.M m,*PdpS .1ǪFFZ;z[ )iX&Z˫<1nxIGOaeQlTvZ V(%}C/c&P 0P5"ccc%2WoŘ7y;r70NX rǧٸ)AYHVW%Ynǡ׉m xX'HrIA@@]>q[y1渗@ZYB}:awږVp;YuX oQ)7Z8t\!JcTɶ'@.ohymi(ϰCa4] T0ܔu><>J¶Y| " ہG:l" &9WD{y.7&JW6 U4r a˯sgHZSGP4s2FAKTı욗;cډ*R|E'@I錭,Uo _JFfw/||{O?f0F9S,|TDjdm -Vh[*Ã1ݯG W?SK!~ÀBYjCckDk}p Nրqru#Z TONSƿḰt$W}nٰS(B@9Uiᛶt[oW6C<Ÿ 8:=Bt@&{w]/[^j37P5lI7Tz_"nfBGT6Y%*>b_}~(]_UUDLBST%:BWo{':ZvS[hGebˊx$S&t F:`L7C5jYYJlH;K_ ;(wӎ@2Y6dV`K;iX) C5TOLQRRmJS?@NKD܉:q̊wp̕:v!Pl{ÞxSx^c5.G=h| pU/;Dp7C`5ȭ4f3F0BWK)ĤMOgjyj ϓг3[uJP6|Dx]+܊%OeWP2>gzr.*T!PNe~IP-KHFIvN ,;V^c$|%LO\T7rrG;p)CΗvYPV66WQ,N5 4$`n`% t=VK-+ YBƮ{%tP@E'E ú:ؔza` =}##*'.^]B,|ĿڎOo ~^jz5 w+;'Z"7y9珨Tf1ސhq0l1ɋ/IL2K[Rsk*tr2UP[,%DLϩԤIi)V5=EPAJUPJϽP 5䑶\}{]F4u#8x1MR~WʼnVyhh_ܐ5}8vzQk$—F">pVR bE>*v4alߚ Y{g ww&O,6+Q\A&hzyu(4&;RF ZExf|&\/'%f0JT|s53AWc4Ɯ* z/&)u]d [5DS{ 'u+#Ocvĩ`eSCGӤv@np.:Aj ~1zGPޓ{)@%" 8ܝ}'o6N0G̷B2^*Y Cy*`}1t>xO Z:fyX$D]gG@AXn)tdQ g07KJ_6|/;C0N i wb`!IƍpQwP7{WkɔmxIzLu7Rh4x/GletvM_W0џ޷@㋺|)]g G@0uC@a I+)\ٖȡL n1s_K;aH<lIRe|c~Y 2j\op$J>jtݖ]Wx0.]#=MJx:Ĉ]Dtm<@I\:Nc[;T$4 㣵)8DVo@Rd+^QVxV=Z ?oqqogIAK Zõ)|$6Oo Lӫ Ұl:r =\[0NLb~RRkԟHHA * h±x,6dVvo吷?}d';$l:荓%<'RyNչs^^DBhˈN 6Ȟ{w5#j4kdc>nd%pG=4# z~}kz[lwn# w.|K5W_@vTI8viOP폭HO?YFҋS#ÕrrGG>>Vx&1 ~IVdy4FxTB_8vc UAxqtiSRG,Sy\q9 1=ح>Oݡ Y[tS@s`b4]?Q.իN(IhbzA^>Vn#>3JpSJVy sXel\/&W,y/' E -T)bXS ͌`k\tȼ:VK渨ǘSΗ+`A p̃HɻvSh`.'P~f"0*]'a(nPNj 008&kkɌ:W?fNB -n<11Y\{ Z=.?"G?͠!WV x>q̶ v W L=#4p}3G]:QCWrIXň((?9S*~rz͵GC6YTwl.GJ [yIPD@yOa {=||d"tq_SjG:rx5|%3k[fC$]B>8#qAqQU*Ms=*%58AWCgH0ݴMwXs•#FIM nIixg ʗ *$yÇ|/ŗI6dL ;j~ WsXKYQW(*A?|JOwK9Ø<6mxŢ*yWk|a~;;t` l:^zoFOΒG _:hߌ^M'D1{v iwKcFl&vՕ]n8DnPy'|; `:(ۡ>E͞G+~bƷLYe9k-kFP tH4?3ÕLBd44WZkI{P_z g8lHI1ߝ'IiX[j~hC< U$p_X^t%!JF->0)Ĥ^>QFTF+cfN0*ܟYoB]r-Bq[ hWlEvN*vz(X`j tOMH7 O']:5Y솪}m*˵)?@᯷zv?'w,h>%ڰJqV|eq㓐Z 9w~apYS? ͵$YL8}+rt]uL*I9igܡp!pM]`-fF p :mN_<緤KtidzKyq$\s[ˑXhCOxk)jC ;MP;c˞Wt,bm%4e+>/k֤O-C!uAx !pq6k9"z}T,ԩ?'G ;n&YR"Zꒃ/|S{hN"}qF!)Sdd$mx**al!ާRX10R燛D֫m_9@U8D}>5]BuF<.٣WNr6Im,Hfn puRM5tt"lSHZ@5O"ۆuB$ y_XѸ[h@!Hp _atW2| Ƹ JuzSB8n"(mŇXLU;TXw@(jĔ%}+v8 ?\'&tA0w!q>.Q4׵iesZGPcjɠwo6s3y1r/hN@TYiS22Pr~@ p&Y]c9S6qCY@H2~!р_׺,ݔ|^`BIgǢi xMrJ|(y*,wOQ>l)%ccA7Z }pm3ʞ^:[ wҎP_n)@R-nn7mɝ%KvaK,"1w"H'q< {4V}ogbZN 7@Z̫mJ2MiF{F1ی}Ə}DI vk%y+A<]S!爏2}c8P{fRqU 0oMتԱ(SQ\寡PܵW̥A5EsݾBO7}<m"g嘖d>| O X^-:M^/q$`f2mԵqShJUџ*0 VM9pm^ߢ$m]s@V"Nv˂C41Cw¦,sDbSVzWH0:^Hlec?|Ms86aHgQxxqr}8/^TmАҾCH.65'e/$!d~fA#h_V7eHM9ϲp7J*WBuzieml~][Ռ#l ܤ{@tP5*[Y$:zAs,Y[>ʭ).7?nP"a}2Qx)sUuّ VZA7$լwB; WP L'Hܿ|I -~Dˋ^լ.ylDxkZrNW;;r_;cbAx9H~o .MnG6#Ϭ=5'@i3'H_nRWzyeIi4|+#8&q>,Ow|540ﭖhLvs,(Q-;Oy^y ͮ}s<&a'9Q0:XwKFtb??cWvf- }IF8`P$(瘀6MAA{rF&N˨y&a]S`Brv+Z4w^酎?9a/lþg oCgMrŦ6M!" ػ *C Z9+gh!r~ bufM-pnLi8䘢*UDL[[ȸO0#17$%dak-$?*IKrҴBw Ro|N=Hs`!Ju1NV9?]ޛW[WQRr}v3rH48)ry  .ÝU4Af'~lo᷾jm9u4uml2/`E9BeKəxJTcX@AMTorsQAc?…U= gFG=} ԣ=We>j{fw $JHkc#~f4ERWQӇalq Uxq[Tù_*DPO,oڢPu[ n  *-MV ^CYܧ%7Y'\qۨȎ宸7_tlƑ ޟXLNꮎP"qv"fʴ3rk/l| IzU 2!CX/ {}ڼ~v8Xo.ڮ9 ؙxώb *}8"G=;1 ؔ!=0ݥ5 U4Mog2$/__vUU$RZ2iW&+L 4Q\y^,k+?BDwq*0aJCڇZ?p@]=jGh(~3]erI*}.G. H~zͤ#̾Yl!tV`/]~eBgA\z9B1ժCӏC%Z5SeWc Eie&;*Ԝ GH~.^:dcO2hv$žˇT^[8.gꚩoz$ĻA KpCӔ}fF҆*-+ A,`.P3["Ȫ]Čz\\a1qC&xO$/_ *%.Nb1lq& [_3mE듼l3US3cwΚcj Hu8"7 l煣x\i(iZyam%jrM6qHq?V(B,c><%-6ѫzB Av?im4VY5Ga#&Q["gJaF? ~HAP&/ /pL\bMx|pؠB[9SzP#&,L1)/vڐ^EJ|o;~(d5y՗f($GQ 0C, m ̀Mu#)Yu9_,/GwxZlrr0~ZKb'ٵ)lq\Vn{>i.b%!1]D^X>nׯ#KyVU .RQ_OqZQ @-vRW6ĩw,ZVWl9JuAf#E%qa*;F RyR@hz;;vɛ`cqn|#vr54G!EGv-(`u؞sW8BYÄ%* A>@ $P|Q"F3$mH*=-n2.8?kצSnꐌ"h<uFɊ)M;u >JNίIVjC]+r`` sZ{`zrH@L͡a~iPI?8GJ slĹڶAA%C\$b"a R#)gd. 79S;S4M7˗tgÂw5\GۜՊJWʎEҙF?j:ߜ󮂋R#M];N'?F"%z @ s٪ K2+ X+ @OFhY].?*cR%{FdG"^e2b</ZmM8Wtۈ8'O!.pR8vsFNߧGO JEžy?Eɪ\&b Na>A+ؕW%#`ͷӲ tEy;r̺[;)%qZa#ZFtWǷ@ү~>-]4Q5"N#𿎪%j.cE(G* ̙螦qo&k j`m:s3܎9&$=h~(?IO|xJMz\H\%_o 5vKef#aa~~r 5An99ú<udà7'bbMGs<  :ζx'ody$VL/< c_:ᵐM[;L$sA ikF4 45i=jjhS#s,DRL_]~9B m1bwzQ NU6c f *"1ڬfK)U~){/~I>[60D*}8u[υ yW1sˮVo:VSsQ1ES6A&g4)omZ ˸+Pt6][ǵ0m]ޤu!Tr(+f߲i$D-}+\),׷m9ND Q>_i <@=Hfqt,P G-F.os2hEQ2h &Q6D j# ʭ\@jA$CO&FMK1A&wlbpȸa[sK9L,0n1t"Z+Mrp^$-* rq/^Y)?19?g1ެ0wGe"Ld%Yq;ж~F-6ǻ9Ȝ5r `]gv%0TǭK^P+ VHnF(s5NKvicԒN?w;PD'KeAX$;OQI=|#u±W}4>8r⃓^ǻӿx1G,@D9/gbM;y'0##l-L-ÉTeR;{e< |[Q^ωߜ3E'ǻׁn>4(JKa]Ok&3e:ӕI{Վq {3 #Ƒ[Ed:`F}$xUUg ٴ}#ikjdw>HDȟ-h{oE01bhf+W'{jC%dŁtxѾ,hVRDlO-5ki*GpcSU#n8%GfDn6W)$_Mc"S0qdD-q+ GBP!0~/71xX}+7$g"5`ΊS1UBKyS#{T ,ވd},\AlRď-sL(tplWajcY YF3UCDZePQ->MeK|eY>/ث1~>% ߗIm߷OI="$%%g̱q'ti b1|I)SNH&.[,6CNG]2Z:"t4kCjv7'%j0?vsT̀c梤QA lUeT6PW?&$ƫG=HID[uBXYWTTzaq J:2-*Z%Xmʊ;7Fsdvzd:!R1 (cYշK<7IXPj-_Ƌe ,=7)a:u~x}_t]AںGӠ Pr(q8u$s_s;AS3W]n`ܭx{Y,Pyڈr1N_53eku@N.DL85:V=ocP"_u\[H;yw^9Ǻg!Co yӇ}T;r`vEços8*Ӯk`G5{yp9h3[tj}6cw*^ GLZt<@NvtA؆7G]IE_MU um5AKk=WqprfS}l6egcTWsyScK@&2g@AxkA$=\s ;җ)@p滯Yx[(N;/1~MS-l@o: MQn g58sCc:gͬŀ0B^P*v B8he"@AxK[q"ɿuu{m61k8yU۷E5')n']wk 9td ۇQXM:`y'` -SPj<~>{}t79ykYMi[kB 3Rv.ǦBOtto:Z o3ƛ[My[JE9˳g5fzL/N.=D6u7OØ7'~ϭty}t:K"!8ԄH#"x~p")fsEv.vI:g_m,ڠ"mP4x71o*1wn5 {͕;}NҔh 'Rjh0bPk608j.i2@2$IY^' ~*Z4h 1 97pʸ .gEͷ=edrO]Ƶ:yX^ Drl@o;rxN.zMțLL{#yj1GfA{BemՄ4Mֻ2ajZ_!С 6` BA*b 5*<wgXIlۖ*:i6I cnTMk(s{ǣ^lH7w;HRׯrwK $sÑ%` i U>m"ĪRKotXM{`U ^tO>ۿt s)gk2mslxTfl&%ȩZ_ 8D>(Bh4t@n`$`b@E^Ugsh"zؠj:o{7<67$_msgv#Su&L " (""#T=.d~F r\Ÿ.Vz5T R4Y:]n]+0=WyybqP0c9;+ҩ҆C\ֹ?R @]vMy-lm{Os٥YKԡU;<]K_yBz[@Da;ǭz[V(O9g$  &3eYgpy.V^n=vT`R2ҟ=ڹ@x8/ }z\^;D@i栠=;>/wkb~Ώ5 4!Punc&εR %B ;?Krγ'ozF֫@*=w5*&.>rye+zgM{RZ[v"p=6Bz\Uܹ @ /UCAWO*d @ dTgt-lju0˩ZfɈ-V1{OBa|@g-=fG'4IQ<Aj'ik{\o}>{qG=L͗/F ǣQơ_a8 /8Ԡ .K t6}-fiE;?.[e캽NM^!J`bD%@)?^adJ8׍8X--IX!B%tY';W5z{ski߅½EK麓e(zBEs`BG9-$ts7ȼ9=@&+{|׶G_ey7`N]mhprk5w@4vnxZ{Ȣ>ëkxPTW.=ݮK10igoxߛ.;od((OzMm櫓 b }E~ o6Byvm^?Oj-&&mKSu{aW(46gWZE_{>'h5 s[>÷AGp"=]*&Oey`.TfEs}/sWx@+pløv6p**xwt>\g:?ElD "]Ob({|.{ j!S3] i?eA~ !,\"=Si檂:H3m+Ppj(&Gy{ }+Ȫ(}H"bkt^EOIk;xk≺7PD;_±U0_.쩕B?RglPZ 0e"Ȉ}* 6>tz i/hU{Xj 箪!ELPKȦTɪb hd1=6MlWeD3Dp<<W#P䈜}@=ǼuSsyV~ƛ*g"Z m} /=T2k!cPon-.?P8XxZL/Ek=qn,~½.wv: _E:g!mfKZp:_&d}=^z7{Nyx 7 Pcb w+0i4=LA{ ۴ 9ĖE5^P{K\p9!vF~Q1F!7Yovhsm/H@dBR 3eB'h= s͛<[erVY{l}eϤpx% ' E;.u us2y ȣ5L5t-4&<Bx}%2%8ӣ)\(j5: @TMCqݴ&4_eЧk}K01<8jUvM\_6ϓGU`tB0Bi zs9!\ 0 cq8wbxD6Wnes8섴uB&=9czkS/q@B!l^+V6k-aᯏRvI@IAt.W}dfw&-{X* /vF5XG\P %JC $}Ƶs] ټc&8ҳP^$Qֆ24@+ ^:%޲z@u+ Dwt moе@ЪbddRۧ(_PDeLj,$vۓYiBt D+ZAOb J/.'/f'b-/!EBBBZTj ^ӊ 'Ul$-;D GWG-?9g rAR^e^?fI)1ʱ'!L+-ؼUW,N  DC  17}>ɴ:)OReΑ,7Lh^[/i]#C$N &fs1;D>f>[إ{+w4y½[ D#Pm$~3 쥛п&XR lO%yu @UW 6L0DY=:zY܋d[|EKTc NЅQ5\,\Sf&-N1>l\ Tecz2ۇ^6q )ˡߣ}tj@R-2 _* cCTdpec:Ԭfڸzrϯ>;Yxr!D_`J#x_Ou o%SS @b=ͮ7{{s\Եx+#4 н s5*YW|4܉^M7L|<2,/?GIC6w>ѣvu ւ~E>FCgkљEV4en*F1՚*r&K󒋌%hcڊ^Srq_KEA@OR7qq]T6f>; ۃ`ɠ2G'JN{hSP x|v~e{U"""(J̅@YnhѠj94j MN_N\YMFj8ϘNO +L㵣޸ޖ<:j5ڍgcnh4֎c+V" S!qQmy)5v@6ۚ%FQJC|5sKcd;E8;_Jڥ/s83tJ>ﹴ $o"IЩ TT9h^=4ܰOhΒm/삸6˜t|k/µ盶&<7+Uld[ 4|@|ݠ =S{ݾ13}SwWe(UAWGTK\1/`YjP94i"?*F(t7 eJԟnqp_u^Ӛ\<.s~{^t)-^%4w}.CeE'Ro`xb1&HTJ 3DAg )N1JwlCZ3J}8lHӇDd*\+n#6F׉U򀿦1T/$P̈_/,@i,bܠ%Lrw"Ms|#Xȡ=< ;*#4s» /h4?/$ Wٰ|^0`L$:&4좋Z]Kn%'54g] թFDt7ngpMk]_V}XFzN9(_Gg_gpY(yj`0`Dx3XI 3Z 0m|ƪʻ@1MQi0[w Wc,g1$] w؞,5h[K5 Zl*0>!uV~}/H^ȃe]c.S{\Ty_q:u̇ȚUvYݪc/5maAla oO INiLVu B&FY-d{oD9j(gQM'/DbʏC)<:s."mP9 UƩTt0D#o߷͡~mAAS_B^d@ |a4*v5D>& ]>LTYll$l ?ț 45?=A`'虚8E!?3-?ɲtt撟OP*(F'BpB  `180$@No-t'c˹6㟗N4ދvn Uao ,#7esk~}tS|~s?[?!D)@{)j> YTBd=-9XrкoBi_g䶝BɃ<+‹~9F!$S$BRU']ˎԦFw$z+>_s~'~gx@ +DDI*H;J3]-f)(G졁Ԇ2'BE9qH4Aķ2]hẁ9CCO ,"LcT^^ae5;.1~:?x8 #p{72@Tn߃YN c${52xlSfEe`L +yKFqMQd%إĻ۰ᒜglU2Sҷk/, ~ DDTE w d3P/yw;Abur{p8~&U<_AxԻIStÉA9&lh(j RrL֋[bq] ~^6`:q7Fc%Y3YN 0G)HZ\Msvs6 c҄:uaC7z ;ۨdAбDtP Dd|}TmhdAqWeЅ0YK+>"R4hUDKoVN\[_5mɑ)qZ%qhݴk=.iqXHSj|~B-< } el$X -?sv 4{5L!#J;B0DlU $PCq`VS/n)^|1?{ĠSJ_h 6"N! JŧtAqYb6g;ͼ`Y |PG4 JAKцZ65K1EiXִ .]Z15`fFeM9Mf3A殭Ӭͱcmx 3{Ä՚dBU:٨!+]ݵ.3Rn3Zxyv al $nT'{m!rmO RHf9k;{`9d܄Uش} sP@g D( mhҀȍ3X0V U`YRɨ[<{p͗dcareݪ`oVFQS%]7$䥸Ya(UHر2 Q 0-cB ^B"(=bI=T_ PDb (N)ŌN7LqMiH x+-CzRDT*: @)}R?[[-0!Ceڨr:0 4))7.q໙lH) k1( +3^[5M֘܋YPdzLFEUna ,1- A~7:W LG 7!p8TmQX>x#O̧ron1]\$Ck8 b䁬K6i[gV wpol>_t;iS!Xl]]e_73Af dJ%0u)0&@ `ZVͩϡJC, \b>[ĺdظՄ@&o=Y8I*H\%; # Pwyw@ϔ& @3>;E9n5Epi@@1@ۧ~9xcu,Тw΋3CHhlHjmRro#Υt 1qZ /@D 8;X qbmGg8l$xH FW7M˻sv; 3^̰//nonV\0H o^HlaRBb۰=~{ xIJckghֆj!4ͲѺM*q-:ɘa7ۉ5c/,)ɫCInumxjd@ȏ.C ~߳HtHBN4gF\ۻ;mp:Aܫ9Kiijɮh7+; )A6_ey ޠ44D@+es#y'M8W`;;H1`kr5VW{ xh\":sMy섆Q#RHRTbENkBӐ$Is_iY!7+KȈapPQ h5 -fL-ʨ?XoBzhI:.@M~8I Ֆ(6c U:uXAk;{y1d ಖZ,T"QFV9gJvm :zkpɜkșn4"1E@ЁqDAiNt\XMe3M0 ̄&8)F4Z喢zhɺA%!ΉP2mFI 3_W6Ę0A{: Cb8)t X/ʄ3.$ @)ެe np.pn03vk.s:P1ۍ16~[;hd !M`q>V6b0 d .VMLcrrpHv/>& uigJ6ܷk Q.$t%&Kv)V A*`F ZJB yЪL,XpPQgon["}6 e@Km}d)άPqWj\n) rhf)2/PLA Jh(EE"$Nb6]&1N~]z6Qxɴ4o5ށ2U!Ao,Ttd%R]JK_tKw^8_G@onn{k1U$ )&L|'9P`St84I`q2E}[·ק0\1PIjd{X a%E:Y7<]F,Y2Ǜ:DBc  ISgrUqjQXFeigr&nДM&$&e${P Q tp36M$-JP;\CYT^ TiZn]0F4L va8B7\@C1,Ýݎ TwX;vCB$ʥ8JP+Pu?}ɭtQ^`J7Ll)zpԁt,FpA%͆R!g^[(^N[KCհY4l+trTu]4Mئ\P4MjH91_[ƛ+녓TJ$ɘ+E%rG UB(ݚQ76ՠ L*PB@ɉF"oUIHYnUbܪj&"RsI/m L(=!MW!' ?%rfZf.`ЩaONe904]3Qz!y/ Ru('XXQgHNlv^k:S UQ:h@@˚ʍq&Ktw! aȣv0%ua˳mH֦Pñ'}uR kme`Q+L p!R<[4z({M]88ķG!y4 5ћxsNTL:0M^n6 @YE+QYQ#! FAHP sFVR <`j@9p%8^9RDH) aHp,,DR A2/1& $P1UBE!$PXAD Ȕce/Qa p"mnPqn٠mjq.N-8|5^'$q3;3DDgw6cwnH+td!Gu銯-9snL l0ng@\JC,|km4$`[VlhZkem #( ()!(${\ ԧOSZ\GUg=hnNFH`ZBHE-3AfDh*`HI c Emې 'Q|m^;Z0Q"NQAUD'/B+8q<ܿ}t1$)B@ْ=Ëbm_;ʣGy/=4F&Vc%Z*ϯ>g#6Zc~t';O-93y]1 qnWN&m:{30=Tk˺.I̽}ۻrMD1(1ՀW:t>P*=ul=!^:(` ?O- 1@8Ew|0z~C)@?gӃ <.ʣ;(?/eOS DhP tKωW-qJ6"Kh3K;^H@i\V/Y}{۸\͖ /ͥ$ Li3U(JeklR(@ g~0LI*w}-L,H0 P  &P |w L!?\3jmL=:?yQcSn[˺U]ٱw0*̜KON;XLۖ3b͓;sēI,z8]8jkz]MNӋgR2}/^"o[k l04hdA0b6DT\Ն{lcm[C)\ ?j]/]ZQcIV xM@A+e@+mN z" & )!߭lHj% BbsRx}l~=cBM2:hSfF7f8jj|]^;ai -9Tͩro}Afl4 xo)ȰX("9J"k ,-P1 YڅI=}`x͙Ϧ4 0ÏİlL`wY!*,L^6z4aGt%a˙9t[tk_kvhO1lvIH$5GV:.-"z^Y1UQb-EA9Ll&?&|tq}ZTSt/W.8roN_Z< $<(V-rd\|,5dM*O!o&'6a19Mb\,&%5PfȌTnтf"m, ذ$b ^#&0d4) bQVQGȆ$Yѐ"fam̤h8Y*J28&0EM3VL4řjGqmi/^lX~a9}uNG:s45EtbT@Rkզg:h' Hz-@UgSC\pbÒEf&Cvck UՁ`&z6- !I1,RВ+ &]R}RvϝZ\Ȅ&ւjTKAf1N~?{^'w1H",h,JIStv6i[h,&uY'M*oNtE@&8$RdມY&&0LG3$&2ct}[?>mzv$q$˺1ED0"R]ZKT@.ZDز3)ܵkhQv7DAC 2aBAF|;pޯ"BH:_|A_Q~LGٔZe SrgN1m}`PLNrJ_1|.QVpٴ1R85/ ljW +sw %9fi @ 6_0u3{R `"VJ9T2VUfcծf*:A㈎nËNcI my,!ՇV*[SkB_-  d,XUDnbss>kBjc%WiyHax⚗b+û0q2NKyKC Du1uqAPC)!XDNC,U,D-"ŁűaT: 7bՒc80`-ܚVj#BW +sF-cnobSdsC?if3AEX*0wZAayb)5YFVBwa4, 8%!6bɉ %,) ݳkbDW-2*R*ETQbۈD!Uc1&5JX*&-Qb2QQA`fS|bMw"<>NRG#_CSD'5+PyVRP?(U "m4 ]̕Uv4nur〦aԴe17m3efZG4DhYJ -u_-n1&Q$䗆e¯uSO[hUkoߢf޼bLxt;ea?_L 8Ai&_w|Ґd!9H) 夶r T%&B,F5KKs& p NtE5r/YFoF>bz!@M;1[[NaK9 ?uxa2,0+߫gm't$p@ʿ@;e 4mH(@ 1@򠠟 7GO T-mn[FӘl:)UH lt/o٦B'pX3`I%7R sCSt]4%c%A o  @X c@O-6[J!k@RAG!8$06=P *T,;xv'3  ,HUsydd*f-E+]p`Tߔp'0)bg:c%d.5EFQ7]#m\{L]N9 6X^:NԿ/ ŵ];&d0Ɇ#0⅞>|7P:XE2eEPIA;ގ=&-[]A$p#T32vt! Z/3Y fLř2 R*Q@ܘVfrv*$ yMڷ͹vO}]g?4h/^O2;?R rV",P̂^Uz `((A *AAdAE B~JDA߈I"C,H~Gj@ $5nqF#L1-|5ضOp__DJc 1yl!"4ۑb-`Ɂ=H{b3-Xgٙ*F]wgh40j{8 ?jBUxP\I B TD{Yl@1cb 09U$(.u^/4*G[my2?ŹސƥгjCݔ6t,HH 2"p VHEA6PҊZ%۹6wyN<=.Q#HZJApJ@4WPz N? ʠT$DDVI$8 hrM)}Bb1!X $o 8ۚ/Sj8 |"SwUyz/5S* X$sVIt}!l4{OcWҚL@d`N]%o-7{.BBrr70=@/t}ز7RF?XeG(E>f?h}aU@_\{9%Te B\2nE=3Dzti{ 3U/0۲Yc*Nh};yW?%UD$ .WRW4}öx"V0KBѬ{$R e 0ԯoCH@N㙳bMj_*nΠ-juX(4U @C3N/[tv&6@TA!.UMndžpGkL?Yy~+^oQQ(2DUM)HpR"*M -DE7a[qD@p?8Rv3N1VQFQ\|}Gśۭu^\%r\p2*(dTDò`]Cz"bC"qYZeP+,$?&t$/g5HuN~GBiޟ8l~&,wCt MɵX^DdN$`$ EIjrk}G:IS,R,-"1JTY+XV#QiZn+k)x%ܥtDAWqr`LI , BRLJb+%f2bH{~vV͒$HI6vߧl04d5ɘo-_UU>1 |@ PJ@MY!nkqqbe`!Í,ܚ@R+lmw=IƟ=%s`dH .&f1te( wބلr L#:]{ͬJP󲀈 _۝_dl鑧s`_P6s R@d 'ջW@ UQ!Ï 6!^ eBHnme J"&DAb9+ZYj# R90NLY!".Y 03N ^758!!2i0^66<Y gC.m5{^/@C#c!#"H*)=4 e"{EdE"E"e_{Qo<؊TTDU@jBM&1@FCgjpO2X ]G Wr4v;RY%:<>Ymi[/1ZN]C\bQEs ?͎qQ7.55kq!|;|0b3`XCZ02H:>]]z5@5`'V,.YPj-DrJQE]ְL""H4 M@%:"C;[K XaLj->#7m?[`t`4o$ !@{)1eL(zO~Uƌxq} tYɶ} :͛Cdp%q+Fgzْ|K ;^}/ACyZB.G82Ш B,n^ mʠ=`"&Jk65;" AgIpdҝ ߲k-YZf#vy/6>c ,PQcJT;ѷ,.8!a",BܩM!eA"Q1_ų뛁m6TPKȨB -A:rpfzS$&ϝ|7M[Z½C-a}N:X(K/蠐) #U)TIϳ׀8Y< RcDh%F?_~P ! GofD+w,|(H Jzׅ&uJ~^ni48e0A;@Ρ{Vc~/M|))Ģ+h<]Uwb=| +1TEL;vY( OMf9X!,%3YC )!!krIE(ݨw QT( O,p>d$y|~'Kgw8XxD`>=<8H^o ’wy  :bM2(dxR; RfNk?d[;L uPl ڊ;U$2}|YF  }@ruKPD[ vYe楕?ĭXU{ZN*gWU9W+xI[0" H6 +bp?4-&^v0U޻kCpID-~ȴefK c#6o $)H(Q"\1Bo5j;Q7MNN?Be%PP&VBJƄхt9X@p=E>oPL.$jhU?>!$T^VG/ec֯1}Z r[JƼ ԇ*!/ p24~I k~~fНHo髧 ۊBO_P~}UYi>em~w;Dh֤l]Zi h!54$o ) .{0XUCG"$zɁꈨ`$Ux7OThoK1 ;oq}׶8_{/~Y >e:{T~x֊o hE0"@b(AO})dqY ߉߹gO~&X?<g=ω_M߼  ;[us?b'}V^|s-u:[4~]<_x6d E=?u>'蹡8rI8 :")FxVg9l.>"z"jb ε]_]Qu9QBDzӓ=M"P,< ?0 #n3W ,kVtpՎ# Pys>B`'f?es:{os:F# o۶AK;PV>D@ D_?4?HhB;Y Y"~K 劉 /4Hi [ !L `!dNЉz*"IHUA Eq"w@0b d n NUx$DRA*"a`A苳JPM:LT~AA/‡ "MJRFE?V[g[htK!|P. QPmQTևN <ȎEn_EtD tD[Df"g71Qvh$2+!")(ERED`)$UXEDdR,`D,"ȤQIa (QdF AaIdVE,AT"" Ed XE * HdAEFB@6}?O9k-j|:kIv$ H EXH)TXUEd"$X E@ B($R ,d ",)E!@X dEXP"B"+ |G-V /̺6XbȠ bń"XXA"!Y  IHF$ CQPPdHO+Y>I1,H( O "VńP{c"2) "||@B@BEbH"$ ;Y ) ( (A%(@Qh }6Sg@PdVɺv]?(l ~j 1XaD@)b̓7[0ASXXt˱}I먴Ҫ3W(ʩ7&Gfs3o>';Pya(}]k꼓7H'k/N|ͧ , *Hn$P$ERH)$(c~񄆑@cxUU0Ha3XΗƬib&i`$͓rp ")H9lWJF0'vB եu*=6HH,`uf+!aȟx@;|;j8; o_d¨ߪn|K)۫Fm\BIWԔ-/:.s-Ikmz#/^xT1'ׇaGe3C5fs.$$ =Ƌ˄I wu}>ۢj75!Xu5*!Y*: {ԏ8bPP.8-H L&,/@$}[)-ܢ%AU\p4h ?wwW3H ~$!^Y{Z`A GPe\ujSA$@_YJT,niN&fFf]6;fʶZA`"40orSѵi5ݲ^u'R*x1Gs'# z `IMG h[qSd$2ːl'+9]8GaK^S +%&d'R#(Lj]d[=KEɕ;`T}LVI$&q[kOab y]j6[+L|I!VUY+Y(f<ӒƸ7N6@ԮLn9o{_KBRGBNּ^{qJyx+郔u5%\}@X>0t 9CQ {8>Q=\y b"~eZ DՕ&̣v~6:sZ*ZOa|͆HcD_Y:L:2E@OU "jq4$Ier>}<.c/GW#wYܰBN*Fn[<{Zx$|A!TܺuyW()tJ$g \:Az2 ߴŵP/Le"G {QXJ'H"\ FA{x104C&!IB3V5-@}K Q 4W j6mH hc Tr b*c yW^1&D ^^jsY߸l @| .U2浶K2 P˳@"!B{N182 .YiS.zio/+aOeIoXDD<yj9oCaN\3{>̆kͥ5͚P7#o8I $^hCyU_$P(Ine"I/(J ?V:W/F[ָg?qI@u|G.p UXPR~.ˣւ>+"L{XߖH'𣱜?OlJ-~֜DA34űl JNC;] +oؘYдV$V!vrW:>,_g(Y@ J У؜ݵLAgRM0TN13\^_4{m/($9'յzm%,NHUFB 'I1,X8ýp0#l9ꡝv`C ,D`,Z1,AT* l;@C$>XQY9C/?`n[򖘦ȶqc4 eFg7HLe cA덐 @DD(XeH(@Vm*lL`,RI33U>͵x8ޗc"4AB+T-g7ifq!PX9c7_.|/oI8d$# Uޞc͙}Ո9;ܒ0&2K_]iۇ/]D!lk膵'C1aѶ/-MErHX!fwd8rHTlTdiv " E6֐?yOq8S$6`lpjqMXժ 8mf߻tgg$/ |u|`M3M C=}-K(HwbaJ)?/<")Fu>G"]U1QUKKKdި*UەU`}#m3EΟNgyT z:~_|7[::JC1rxrR}ƛb}h 1$a q 𞍸't3(0VPv>ڰtx+.ɤ(b{J#yB{M@0<0 vL` r}:" _ɵs&z5߃)kDxI?ԑ9Y(R+q)HC.[1sܢ^𪏷X([mڟMb'uc^8t*R&ԫ7Lgj_ۦ4e1 2= #DPC _(ϥumkPvpb!RFxOθF )JgrβaS$T,茍8Z*OGTPcx9zfw-ڴ8 XOC&ޝ/87Y,ND /C<7o#!嫗! Nm}{.<ڭɥ !Q26 |n4]3LgPyy6 ]r6و7 N&p@&.IY1;8[ CֻSMp5HBF8%6,kEe[UOA JOj $c'|.,GQAC3_S֛=yiN]t<<(} F3"kv(8(E6]ϲ(ɕRw ZdM 5pTȡ; iMIPEpIПcX[֣&դ?x@0*4Ե&oEK3+o G#(*tj\(_8`/ֿ8{XN᭪_]-*X"fsU=nYҩ޺boZ !$۪`ɥghı"EѼL! ӵ>" r<}TQ],9|Yߢ -rh{ެdխhW~ q] $","rn&v"zt5 n%tsSSz5K9n}1,=w;v|,ٵJӶ{f12H F1&Vd4v]}0lnedx5IZo((xri~کZ@Dr rht˭>~% 68v#GCJ!܀\w{:[4_<zT\v5/mrLB @t~SЪcty{X-~S~{VtisrQ%:0( vN!Nb NPůӻV#4(0BbLޑl[b00&׭^KOtsnXMMK1ӱ<|vpiqpsx}t8F2sV1\ЁMyX(q᫉`];h q~Akzߣ>{^/A,Fcz ѩ۠ͲcSE_ZРqRDѽO~}D'º?G.uY? @W`ܘcoRɏ0\d.4v%- KT<NMFڔ5zw}7`FA SK8Bl|x q8  nJ\?*&[gc " v`B%(o=_۳?Q>y!SO}'Qn|O*ts *A~IAE*fr&ٟ1V.bꓛEfdd,mAfoOҵx8{cag{]4!\kLk?*^ԁ3!ߜinƵf=o-JwOcȠ|( L'bC{S'Ǯ1@$n9i-!Z$KTo1KjV.R쁤&Z0% ^͐#4G(4ɱ|& "`BrR*G}y_#!=zwy.|ଆ`YEz(MbQ%ڜ5Y*lWutCM3N7N!8.lCNE6ի<Ώ̢\=M*c, 'wtJE~>>U~UŴMq׻ߟTžk)?{H4V&B ?_AhmRSS*0օ=ry".n`\!Id~M3M^AUmaGS\c4ƅ: : $XUVo_ggퟎZzzʔ ǠHxP#ߕX;' D/{:l9 m?z_iG 8m(,rX|ڞ~_j.LJ"IaOk>ga}CQ]p$,C 1I!`O` P f1Qi%e`o'ߡ5\.f Lυ6Rd)'#3vSvȼxV!A&aN7Qrk۳?Thi>;qh7xKq`硴]m)f@0˜ֵ,~;,uBXR#eKHJy1/v2MjQzkx2yb$ P f v5J@~W?!n=By9HDA((F `,Du7HB P%A0Te. >#NްN~8_TL>jNz(P3Lw@a QOWCo pxQIkɅ%-^2K!}/){m{ظYf.K6:1QwpQ9I՚m bI]R0H<P&K B"Ǎ%ը(:Sw3ѮHq)Hr9J0`N-lH1VAHN*'Vf5}[@ʬ$hfP E w4ۍ1.g3 % @XU"P(1RAV oK-1$ %A`Ċ ~o"id/QoC_lLEbSb*y|*EQdHY y_fD"C}XĊz6f&C`( ԳYZ1YniRk40e),B6iiE4pxcz]iZiǬm$"mXrYha+2E R!+"yGS8G{&`nș7@ŀ,TY"DDHGm!Ҏ4 3c'sjtl dAfi""dK8j$}8tTb@*T*HUH )$"`DAV(+2)edUYԄ A`*ȣ$L`(MnT"ɀ**0(feV0RER HТ06˧N[w]2Sj= ˬMӇEqMqi!4ĬYTR*5*)mv&(rf̍Hbte*HN̅d)Qos5zA#yՊN0Ny\i=z_ ͯɻ;OaJ} @3 E?jy?By^Nѽxhoq_>'+DAfll0f{TQ4!HLTkw8B_[O0ĥ[ty SG;9pX(XE"0 +`((E Y5~7b>uW ll GzΔNRr -XSs`-NWuE@>~f10$z;?hv`} @T3n׿*~0xCǖB,k*8^q^=3/CRUR!y `p + -Vy)$h1ȏ"޴f>'ֿnI= M! *<\g T;&'SH3U_{^{?]N\-Q2w64"#XJC|ddDY?=U2sfd5r^'kj3Yxse(B@^Ϧ9J16>>a-wI;p˩IM@zXh>ߕ Xdn]|LzͼSBah!#ѡABEY"`",ATY F$ _E}eL?}c|/}, rR@p>}VYvld.b0`䳈M qb"@Ah*pJ Rͭ{i@$HGnz:inl--J ;M#wFm[I$ِ`)$dU,QEi8\aBhT{BadYҸR,@1H˘;vouٟX(cCySaUGg@)r֠NetӚ>Bm9:-LW2crN(`(|I,H #{ dQ]iAR $a%qeud)ͅN)É'Be!÷mftjm`D~_:N~Mw_؂>V90ֻ_yA/].MRsbVrYI\),4i/i& 8f@t窱@ s>aBXSH㕋f bQCœ_ JDψM+:XM`IdQDFb b DNB 3bLN6Ŏ~AҳEu~{" }G3E ՉT@*a{"dPk_20Q(7Wfu͊ Y"X:zi7=nO.&8'#Ax)gUI0E1,PP[2Ⱦ}hE b t'!)Q)K"1b(mhK(1dmXд3?E6&'W02C,z.Pϥ ѳ/H>XEEo2,&0bȷu_la.8C4NR ';?CG' -̱iSvXOn j*"ETQQtgwqiMŏ+WXv* bZM Rpp"b =-" i`$H F*DP(fbsQH ׇ׾@x|P/չojD.WvM^Xm4n˰# 5mna I"D¹ƛէ N61(^ݘD&d1[%34lu33 llPɷjM(ˣ3$X fnm`noT8lXeAbq 0[(|Dԥo&D23 [ b (E"Ȳ4"EXAAU`YM #P %"QL|"j Δ!Ѽ8 P"fm ,B9(9kR$Ac0&nN8dtܳCJ 2l7[};r8.lWj,PtA`20RTX`A4@嘐D ,\,nq0ĎĀR"tx0<<9 sR6HBg8φIZl !9! :aT'#[)*+02S i:NVThڨڏ( 5s G.5ڈ*5 0ᱰox̴4gՋ(֏+.Ts$I"?lA9q(/5D:!"aEUXҳ<_l몰p펠pdz/xvP=6yu\/￙0icJ J]ȖƂ>sFw-Gkӕe>e^T14oCLږxJuv^ ʕ*I_ABd"2,whbjjۿ/>JrA=F`y&9uNz%]l>l!f3/rv1MPP躣.5]![E6hq56*#+fUƴӗaOH?g:{MuX/f>w4 QHDMuW; 6إJД4A'IXٝ߹{xN@BK& Jf9mEእ8: t!ܷmed(# RZ=ރ. S>}4 Ij bQQp5}O-Y:P_ÚS}Wn׮zCKǁBP( `KKV~d+ M[iZf FCva%$KFRNtxUj{ilOGbvnZ6W:X8}9eZ̰0S)Ԛ$2 2St"!AB<Wé!n2 0ЎnENݩXģjFZ4vr L)>/͒pP:ߗSn f)=׃&*"+8^r;MHmNjdzYQ֪ wy];۽4M06bzRGiܧu,enb`ßã2zo^Sz.e oH;3+4Cӷ`r:u2a]fqi T 46/^Q29;][\!B!% _t.6 ;MϋME|9/y;Y1^LKVEWA\ :h) ,Czhczm؂s03 Åe~ِa1a}tkIT:*0.(:mSH31wL@*:'K8b.}VN"xao;uO ڰzeJ;q`V <8!'vLKCmeW$R$6n'̲2]S-'ª1=:%P[Hȡƨ6 /K1 5Ĭ\Z~[/g6}U2C#G0ad$G*/w4B ~8<͜ s?m,ByG&5>׿jA_m=S͏ c&DRpEp2TBP&aՉhfb*5%%Ptu/*o)VV vh+:dJ7O|5ouϽwii p]?[kAJ-SXǎ۪ĺ?/Ars*Tp1ɖRu^R@G8پ".s4[7c{<Q"VDR|Q>H#6JUV> f]b.3`։W#tA6$<@85|ԝH0lֽ[<};-E\C7 QB m5d)^Vb)ANk$ў,(2mDawPA+m[ԋP<6'g9{]ͧîx~ǶX$PX |7&\Q]:&IVqM^z^cQu ` ^10*\YmV1`cP̈M0Țϒ h%#xY%~T5=>X2!:Zo9o ξSw@Z54#!4fzZֶsjƶ՞"jRqt/$a -mkIT*;2T6\>¡iy2(k9ݎ dyˍҋ=VY'6H SŝU(FrH[Վ` U#q}9HcfYe/X wЬ'l TVBpIPXU@R:59!HyS&ژ65"Ke D&duQiأoaF\|{k3G9% "w+1-,&T 48l\Kf4TLZEw _Sqc)(QbO |ZL4A9;C: z=k׹scTQu],LV ' mLJb4Ǎ5jp`)Cv4DhbE2Ҫ2fs.[dŴXfV]_[Y8$0Z;^78t-&(ÊQ16,#&ʂźlcwwBlÛPUC{wbetnA1e:)%EmwZ=I3ec|/:2J"^fJ HAҰqUbEqJ*$U3DPJYl0F`=$/yDOKdgH(Hd'l4(@NH-qd#x"au"WR}t9?Iˆ"zHY+xX_T+"Nv`,E&H i PX_[”2qF3@3)-1KsA!94EqΰqN!-b,Q&Fer. 2kD4JJ+bAgQ}ԁ .\ 6 5 UZ{8_sŷxhZZx X/0T\RM5V ihdV]\cBoK ۫]afci:9-]`b)E,҅CEThl*BVMÖ@WFBTH kDCrjE gj*,sI T\ LѨ &~u)NbybXSn"H'*xkT{:J&Td10<Ј0۾xyns5-\)]iDu[Ffйhލ!0 uLUh0QA$P!~ ט[7.4NqfqL[Qg8lR#0@Ŋ vXi;"tU$2b "Qn^_o2D0@m&6-Vjsa6o]64@z'i%Mq-!"EDcȯZ K?׾sz:;u;sOa}[,ή{ͮ!ɜA^ ϣcǞ:2͇S,YD磩: X`óp谂2zR>hpLBb !PFBT((37w&ٹgaSmhѫWml> m\N{_xoj\[_w<޹npd'qT֊ D92ۗd CH$xXUy(ŞrN#QJhNM*M©j.b?Y22?zNV3DkfߚBof@M!XdNC[K+~M,P֊\Lr_c\91! h*:g^ fadfꦄ1IKC_'#P@]nIֹLC}{_+uw-d;՝ WIBȜ INi"B:4 {]B>ՇdRt }(f9H D1(Ȑ aF!R` i%HD%6=imG\Dj%b@94#:B1*eS͊nڬ''o]ה6q.-NwXF*@;,ZMsk|ǟ>ˣu.OE(SbɟwOshtJ, A@ޱ"24qMQ>c2̈\0L 2^015rX K6(ݥ(RHARPqe|a'S (%Jvk;VQP̈́IղKmilK ,!0ˣ@Q9BEسZ4Fu ՟᧻,*Yca(!BxmVtPQS`Fߕ!0VPR @hG^Nj79YoGh ZeL6:#y*:!596lP(o/o?Gu'KBr: >@Hu8Vk)v@!`bM974+ؒ6o+]lC{\K %cn`=w|iHL cuZ0uQ:@ vܿQ^r~v:艛tp Y" HH,) E( ED,CA?~wt,b ( " 1d2gkqvVtSǶ xԈ T>/evwS8M!G h`LGZ 1bPPԲܿ{]Gtž HDPDpPP#FdR AT"*E,hEO>!>8",uXPZًo5qoИy#ͱ:4b2[b#"GiV)h085Bk>\qMV6m"Di\4KXWբtU-sC. .p(Ց+̑ycNC4uP.QNS G+@SB+wdwT[&ņ"dV AI!lL'خ:oln6`( *@ PK),/ΰD:"욞D{^u .ļOX"STyh[|5_ jPUpc^g]je Tw $:*!9e6e0!We5͝~;4 0ўф6F ՙm.ad5;ƌ-ѐ˵BAzAPVH# D] VHZR AjQ6h2*0Qȸ&+JQD1 "(#D=6v -:Z`I :y*u{?֟m7N2*YǞ;QI'Vi[Dsd͢q)rp%o Q~] dBC9I+nFRlTzSᘩW>5mia@.3+Q;8ox2:OݙTAw;,u%,EpyRust=,41o?N% D#%iA ,bbŘdBbD*6#YETQJ[,@d3=szS{1m[;jBBaU?JO?[2"b 8 tf詎!mϵ&d:S2nq9ONJVz '*ƽv5-PvUIkk4Rި+0лȜST,z^4Huui*sǍ AWC&g߹ax߰lS05F|N}3c(C i d<IL/OI铸-!֗>5 W密v ,O9ð2?-fb$QH ,""c"DX*Ȳ2$Zߵ\eLs޵]~Lq .THL<)ܗG>h$)gɔ(,~sә~0N>4q\Ѻ?j6Nޖ@VLףZo!@#_y//gDlS kR\'3кK&܇LC{pD!!&(鵩Gm(9"C0A PTXE MٷU/={6A{H0#o6ځğ{6Gz|Gn(e dAڡ'A3h52NMS|8KA CHVRVvO6uT98G޳Y}wTm^㇋| UT${im-Blugq[ ]ލ5 -[ռVbF]aʩʲTuSh@H6 s}ONAR=N?#l:-hc{/TtDRlE0) jTEX Ua>D?3 2!XSNCn5hyd[(ѡ`ITGK,G߭Dc,iͥi*܋U91lyQ:ņRf…5$>i+Sf q2$~'g bȆ[BDHd]~>ʾĀKw-vAf@h[< ?!DnxBpԷ`-ܮVuR (H&i`W. 1Yk)2k seDa˭j\%Qe`̴m *,1r 䧓spMEbB'-m'WUU:n?Pw_ߗ䬈|ik}x inūyOk-`=p*$I:'^OYռ90:56dX 1U(ADcDR*}K]D:Ac$>Ʃ:X ZN?H%(WoGtsZuZmgqճߴ{hsNR#jjGOCxu1 !ƓcoSж4鸾= 7ojTOpȚ^SIiѹm= خm€;0KbaYEuGng܏R~&6V'?Bu"cmCov0d$C=.PJ}Ӻ,@1õf\27ɘ䣅HN(OIbpMg!QFxlHC@i1f6 OV2 UEg=B=Gμ.qqy馗OPJn Cu{u]TQ{b~[fD*_Vţ=_/w s02:"e(PyJʓ!֑T <Am;@pw65 ) lt,z>k' ,{]`Է͟.mCtd_F=4rvG+ x\ƒ~?r“mŴ8Ч j-MyΦ?ngKٵAJ [}FW}pG_MspL,u{)PM%m9lс;'Gvp<݅#51KUW^kT$$čp)4ڋrP? Dd* !T5Bf8H#AP?b8w9 Xw DɟPbl^n'pu}$?TJ%Dgj`3 @C%x՝xF"d6ԷoBMؕU]&)a6DA/j= RSUKI8XIt7J~^{3ij^sHZ眈/V,>ųWTAG*zT:?]O[|%Gc' 񙺡=Oܗ OKmD.)EWDz2ёP LZ@ ɑ0K7evңJHhgퟘ*4G L zd\4&R9k1,&FK5@Faal-uyEBpm `يHab٫xmLYAUHX 5 ,ЀJW+#! Zxqu Kd:LWy8̍_ Meq7/!kj&GKi|?=p 4˴f|IHN/@{ a)y(ą.)!^u:ۇG=Y߿Z9?;D*V `ۄ&d1|}Rm׵?=$"JӅ?vBm(W{A苳<=ü+:v5B}+' @QC %ǞcUu{< UOasjV-ҁjE\'0:++ ֚L@92]!H1Ç'v6X"\ֽQg;ɹ@@7?Z** EmCGf_'ܛܯng2_/T TLOֲcU I!d2x؞<-y-ywjBJny.ϫ~釔X"Mw?[U"p~,]W@dT// sD6BXݭp]NZ8F֧oL2]|b"e 閄 !7;5 YŽA[;4/U[gzJW19^o_?r6I;1$ܸUTQʳ'f[I1//oK.SaWemNhzK˚(G^(<* ^yJ hÙ gf'(8"[@>V}@ 6^ϰj.%r#vid<C c";]\) na1zeAw=u?$,.Mϧ}6"+ " dQ"U'?+jNX* XQ,E$_oݧ w]cc:")֗A B\TYpCT=֯by5L)8J\'IH $h{='ťx:!AA!&_SrԳUƶǸUj|<?~(z$z3Or,ﱃ9~z@ G{i\/3_~JY)g6PXtL,ԃͮ TŜ6V r"#c=+fs1: Yc"6RyT޸jfÒobh;oJY޲,qi/ilۇUZ_ 9Ж_Ȱ}3,qʡ11zżJ@vQ6SysDRϨBdÍzTwh1ANW2 ۵h`17tmZlfO>tf)GP1j,Zh\S#0v?9׼AiHfFHw&.qsؠ @U( 5XA=,),4Sp# "+`7-$&*>9p?y~;jE {һ~{"TF@d$PHb@Eȵ2+NY_ߓΟCI,YIx^:}7eĠ:dRO@KX RE8_0P a@BpJ~O -ÕGڲkb -(1!~ÿ6boF)֜粛EPX*𙻭D"H 2!# TAEV` 1H$bA#`0`I06@M#v۶6UН 8; ꠑ?o6xlBߺUܫCۺㆼomx8IBZ4cIKg3|b:O觛KDS0R(9 F QTADړlA@#Pb;l$..FTS6-sXi6q%htZ‹{$R5m6>W,: YOfzyUZ1 Uuf(,<oT?oO„$!~gyѧ7KB( $R#d) aAE0`((V$UF()!AF*@VUAE #PF ,s>_9?jݿS~Y2aH!!{@X0PED 0:x1ܲX4uάLcvZuy,-gҎm{FVrI}y[3P_]_td? g2n﷽s>">9*VnGNU7 !X!h`X4 `TM]F4m'7WwHIӛ*Cw@)|_4;Ǔ M2(,[}F$奧 4jm@b1_ϴM$>JRun\LO9<~e[jL˦wve#Crr9I7⿱B5Lݖ@ܷ flHY(b # ϸ~6רG y*2"Y2RtWv칑RZ&Gpm?j4`DXa;ғ# >T\@>O¯2." a]ܸ8G"@dʂE]@8PqǾ=n; HwWT4S3A+i˽"DPߵM}Zהϟx[ҽG "1(ͱcO ZuXNvjMcYߐ8dc 2fjˆ>L?P7W_8'N#|ϡJruQyD୨B!qx_CJy2(7Ⱦ1 jt9Z8+U  IWM.Ax\RTeɋWuڽN<.6yuŹOx곏15x]Zjf1H>ARbKF;KD6/,Di?p=E~H\u)BX /c1# ggw)̏W)HPhxa$/lޏ{ƙu9_C'rd5bC&-t#P2xH "B/`$b#k:MjW(OП=ٳN+)" 8ҩSP3Е(W N[i@AaKVhwyZvS3dg2tF*2*$c  mܬ$XTNOTDbOfc^5;&iGy'mYt '氝y%#RF쬓-f%|66v8f"*w@ #pe@',e;S`JLetRUPJZ |+ H8Y訦  fG@ۮfwCZRG ͨYJ41 83ט!Mr3RL\OZ1mtX6/jI(ttʷeK)D#c%(2JXAge=; G3/\at[\lnC06vF"*D/"U|s(v91NĹD1f1 讓w?7(]Gf$3˱[|}?J;p銱]rϦ8+ojd#EquHpxDWLxǸ~w!K!V+\Ե7Ozۓ _ť GVwja.-]q7p/oƆl۲>+ u@%HsLq3@:I-~f7g;Udn AP (:N4f>yK|~ /z?#&rmƞgX9Kd-Y5lf rɴką$zf|%J7yǎĉ-&AM ѩ?[QX6sK1, 9BJ,)ӄϤ<έD{\~@j/jȍ (oQp$C֤mIR7uhh<ZЦe5Kjg] ѱAdj|a ZFO_QGLQRl0ryF22//f5] M.SlZO2}~ I#c>!ZjJxu]#HHHP 6V>vw^/#]EգCRʒz~磗IM:/h_FM2 8:F7Ńj~ï DrAf*u,(5#S=(CvȝHI#`yᙖ(ܶF'7`عL:(ekPHDUٕRT@Vi5r !S@'TVdL/Ed\b8W4Ybza2nϟԬŶ64 :Bw2{kw f* _ r,Ep'HӢ7I)1kJFC7mï~a[$諻N]w]&3՜O,,2>ym\mmٞeC_ uIM>!3>ȀTsqY.j Y[Z\)5x3stRu<ɽ}xdR67 kAp8\>DO?1!`@X 5b"u%ČN烲wyσd2z8]3h#&vߐ;'>m9;(!U!21pBsY yM&vFWӗJAB*H #ΐFL"DHG&idr)w=cH7c}#>==M?G lAjhŋh bU4)V-Yl3Fa7Ki5RۇM40DPL`eZN BFaYf[} +5KAl0 yFgi /|1jMb 7OP3J"KmM¶@űb0`D"" W iQ8zK|.^9 i?K\tb{31EuCjFHR&;c zmC%CwT%gW%'6"t2UC2$h=~ ?}_9OֿLba hmbH#,d񂀧,DUb2 U6ըFUb,T`4(>\o |F:Â0H0F+Nq*"PUDe(\XVl*A Eb*"![љUUX,`CXbTUX j DE#PQeV6E1UD"c::ZE  ҔoOINJ "@۫b$RF%Ћ illf YցF*V&(RҖ&yve@dHڸ\҆pa^oIƺ8,,,ܪq}]5^+ ط@eF+QQ(EQpuMX#"R$DYJ6Cƺќ.bb(H͝cW9tŇbpx:* +Y DQT'OHH!("(*"0ddbTTDEF*E F(DQYmw@FXzbm: yk`Ne}6vHE %`08d9 x9pCݢw9djQ,,Tڱiy:!D^Fqߏ635i6Sg\a6Q$A4lHX{O->hܔںaf㮚NvLh `Jڔ81 QDFةdT`)G %$ PN[XcA!z g\Ii=8(NBu!^)åV+lK owq[lPyکc0aY" i+%CL/M)%UV QV#xZWg[80A0g>gD_t;?T۫;wu` &rHm`QdYyȻ(rnRiã4p688C -vʈ{4\8p/&Bt76Ck9w|=ZȏUܔwsXvEz:hc8 8=xu>,C9W9ں^=YEy1pWѹM] ,é4l#DDH($TU"TP()PQQ͡gme5aEbQ]%UR;=/oU5K909TmPػk0gW bӆlBjMF+ DPa!ixkXB4w3cU~T6wp`y#BJ~:rtRܼ`#z0t{fB(WXf{u,%谓 qÒRG3yCh.IJe5m7 Nf ((qmX 4@ `@APK g{j]N՟'#iw6l(,x=Y*EUlu{$6 y$׆|bAмڄ6@_/ekŮ} C F0 8[>- $% œF֦f HO.\tX}Xk<iZ韒e|AF!TQ6Ė(HHk3w;m@û'g6[w?C:Gz( Q 3?= ed&r.3ғ:۷PcV1IdHPIE!GPH]}'#K'p^+*ē9 $s`Hr5ɝ=5s꾇ނ nGuS{y-4MKH'݈1)Q\|t^ uÿ|EdP15|{-`K}wz5=~7u>瓔HFHI!$$QTX#d}xr{\:7j$5{f!\$ ?mמ-558k"-JBAZވ81nL\K}'W? o) k#$ Ʀҕ8:R,O53<7^~DxޔN Nq[ T JdD%Rgzw b@VCdnu2lXUWL6'b B1me"$bKfaM*ogKX>g')XeIhUBA:/규0$@@>]J$i!%s  _~j˦k\a:L᪨gZcCcs^\}V r sN;ߡ^=EX,PP@Pd  FH#DX(+X$"P#H, X )D*"EUD"`R EDF(RD `AA)R bQVER "TEOttlF*10UF0TAbEQEA`Db bX*H*+(0FA*DY *H )V**HTQDXR)Id*)"$R,B,ETcUV$XDB( ,P R,HEF$,UE1AAb,`qgn#5wv9x7DԜU59jS&nFj{$6+]o]mj:j0>S ָc `^s+qkN FPl6r0ވ @1 jf0Ubv`c",I`+1+*DAQbb$P`"TPTHETAEb(PV#!X V+UQEPY0X*")"*EAA"QU*bȌF 1 ŌDUbDA`bDV$HQX )EEQ`# ""F0QQUU$A`QT" Db0X" T THU,b*+V# V*E20H)UX)UUQHQ" +Uc?GuX",U,EEA QDTX("* XbEXł(b+Ec*"XDQU`HQV(Eb"TU`o"X&TDER (ߗF,EQX1EF*Gocv*PDR 0PPX* Db*X1UV"D+" 1TU(#VDV"V0F,UE0F UQ 1bUcF0PEb DV H*1DbX(("*FQF*(X vʤ?H%EUHb`U E`,``+#B $R*! B,dUp`"UE  堊b(1U7~V&v? ("jEcgQUQEb"H,$YF"*$1V(b`*Tb "$QTEXb* 0XDbAd",b "(Q EPTbàBÿو(0Q >nc (0UFEDX"1"QEDEXQX( #(ĄI @Y! "DDVT^&*DUA"N,Ws`XʰUQTAHcGY_g  EFEP ň`>?/y)tUtfQAD#̂F2 `,Q" ( QR"EQEUUEX0DEb" yDR,b0U\EETTDb)1PX,AF1F"XFxTE"b(1TUV"( Q1EX AP~"+ĔXTYUPR0bAb((( X,b(`4TR dH`EDAUXkiQ2)toC1+*)(S`EUPET"Eb,FD"-Hdm0*mRj`hTto$dQ1#"AAbDA AAT"EA Y(,ADB( M6P 3\)rT?9HU􉬾 }DC 9dfJ8|냸WpXO@ A"$S-!iy͏GK귻=nyS@UN''ydp<~j+t4,fmIkwAM-;>` gF?GWq @MLBAKzZVvVsڟ`ֽCrqb?/?{ $!$ fwoh&HGa~* {&$Aƽ%vo4,zo,m6.:C(x0oBBWa*d%֭wN֤09k|$0~1Ag<̕o@ tD8 ݇"Խ~/cֈ(@ɿQwpmCX+psȟ 㔩iAME""ek_Tw6gmB A I):e jv|w\QmaD}КYC8^r&p/~ 'Ƽ-xu6$6__M>Ik_z[h[nLu#iGCm%F1>?QSRאGcz޲SyY8hHaᙙa}7]q D#7,%noR=m*T+riMJ5Z) ߓͧ)1 dubEk~Y)tbL10(2{g) * 7}dϷ5"RXC?}W*I P;Ƈ7'u: #PZBrfo{8_Dx /*XU$5d?Q7(QaN ,a1Vl%iZ|͟7^z57">VnWt2^)V!3Urwv266 ;Pm_wQ+̳p1*0U#$F2dXETTA"U""#QF TH"*Ebj.sC!qA6{`& 8`"Ooψr.fﲴPdd#!B +C>Eb# (*X0Eb"("1A"+Ă")F+@QX,F""UE ,E"DU w1ETF,Tߪ5DbTc*"b("*,V(AV*ȱTTEDEb"QY "TᄚV* V#XEh,b*UDF(,`DTUPbQXDXUTb}u*E1B$cFIO_g{~k` ,TV FDV,PVvP *H;:+Dh^y/?~ig>'mǟ>JEQ(S%`uʷZ^9}^J'6D c&F fڲ㕙z>`ey?1|(#Pi{2EЪ7 ; QL4 Vd.H=ٝA(*e?v/eۉ5 ptSa옳F}:^'9b E36~IYS vhJ&dP IDiF"1 MyM JLh:M٫ѡr@_tmy97Q $@G + r3Ys!/hKT%$% ] !e0eȾ睵@I`{lNܑ0u7?>G Zu.k]3?HzIv|r#3EU >p1l8øv zPwB'$(?Gκ҉ M )"$TX"}މ%OJK6 ~mzCUyېwoSqn6V͎a|hQ6N۳~)&:/w=m|JKv;{xF |]2V@[9zʻi'PQ.׮}-^Kؓ ԙ ѐ 3W5;O;$ 682`/W|1O(Ʃvr/+N*ɥ8yj_XZ ?wᄃMa4\廍l L  )1"XD1 &`$]f hW\E֤,GZak>Mo7QbnzHH'Ytlurl0j pQzRAFml zLK--A ^s"a0,Gͫb' ]v`"Dg_70NNGuY! rA~sj.~ǣ||bixa+e(6jNzZutRR $b9DQvEk+mx$:Y K l"(lnMD0ABܝzlE#b"@V$@*"*XDX1/W]iX)"(dPb$ڝ9\QX10]RT([Rps(r?<[>4aJG/y A ([yLhxxA(OH~YdO20zv ͺ\\ X4~n0#g _T!bo䔧clx;n13"K r 5E ASk1.&J-yВx&$:mԔB;E0WBJ-%qbFL ?_=n+"4HH 1cI!$d$iHarWsmϐLo>smWn(dc_fc`Agzb~і~0QV0EAF+b(*+V1b+(ȋDD~sxgђŐr<چٯf*IRA;(`p/m~,xuKKBM֏>` 9ӭws ܃Aڴu@>gGgW[)F0!*+V"×?ywٽq~H-2 对3ʿhZ#08I>~`,OdD+# 7D+7WuRc}zixWX_=!/㮴hl3B?5?7Hk>p`1:.>5vׅvՂCvSUh !пqg-CC#R||/p bC1~>W)i~qgD6U6OsѿJ]1o3ѵ,N {X/ddNgjwߺO-ɖy~@"ˉyJG0oncſos/}wwMlb=V^|WקRËA{/yk:4 JɷlKK'm$WOד ~>`#{I=>afژe1E  $@2ڄF<6_rїO"RMm#`cBl=%]aݨ V޴r;,ɪ'er,9,{~eN##܂d6&n:)RhZ{}nU|fut?Y蕬C7T ၗr'`QhcdQ?|M:( >7a JI@! !_<7ŠJ8%9XhփBdxs'm\,ᔾ0C_j|C]c{<܆(bŊ )@{?̮$B6v"J6">G|__ˊ^_4n V"'ӽ=>ӯcE񒞪(Bf!LV +s_}'dt{)dP[բ_XG,241>4KHw!!x7R<%!M˵J67ޖ(!?v'x}82,cBs[K5֝ubGj4Z>6No]suÔC~isG Ȅ \ytnq;<)4vlc9ccZ\ws{/lSzIfV/e`dK"@())7瞟K43qʞC:M鿛 /GA"{O76OcscۛY$̀E9}?68Fb%Y%nYZSD! ;wbo;{7f|Շe ]bIH?5Qj} Eϖ4 |}/]+mx~1Bձ['!$xɝ-NwF dHc<ZMF„q Wt>D5DiQqȇEQE"* `X"1F"(XEUEEUTXF"#Tc*+Hʘc``1X *(F*  C5J Sp<EpA0Eb #b$V"1"!I ?[g~}7y? @痽Lt8p}LjV;b雲zml׼w9;_=LLRx_=pmz3^NOc H%35<$|j6w}?;r^f)N&)I$ $N=m=/}+mzυ}S81I!{ <3/n9.=+i÷sױy1mb<-\/-R`J &obE xC)%2ZWLm bA/w+4Ӛ5mjs>UUt]f;]4*~?w8<|EiӱX*V*7c"eOiyUY~=O܍fz[BUp\=0iDXrti?yt OJ4@H7;J13c"T#eA14ݭGzݱ<DMDկaTHH AX*yXX1 A?1 H jA}yRxJ f20?)ŢB2ImL#`(?'H}H5D- sf<]/!n 28@`kz?ՎB3Mކй|Q:?u+cX+#"*DM ӿvG)?^i=adWba?i({Ђ?(ڢA#ʶ2&Z=sLt9m?R oY}{;oxk}L {F"ĂF  XF1E 0_0xpoo嗬˧!8:Qǟ4f'<#`B M0pH'>~+S=:4cֶ %=dH@`:FLT$/w>RrxT?,Q`h"fmcCRS;m1;VāW⸶Ï77x, UAw} $H <D˲v2+<+P gQ`!kB@(JqDc,Tx]Yrg4r@${}Uob PPLi?Ho$zdkRb+Ċ #Kxa, ,c( kPVbr1=V()-P,;:{]`<=Arۧm`=ϓiK *tݨdL.(X 4t0IYǀ EEbEȣcra[-]Ntwz>ʰЌ4+zL dpy?يy{[Qi[U2:>!o7#J3zwα9FpP ȗ %y6"2=.νl@ hwۅP,$VA7=f+ƭN>|Lp"\][Yt_?oMp8mY]>q:_O{JV5#gY?l>Yy|" _{f.wݥQzTE`dc ,#\ay_G`1T  `#F`#fC PAE *i<͛ #L a!Z+ơصߗ=9]|vmɥ/|C>G%ǿe7Ilow7w㝘-b*;扑=}_L:Ν&fIX~ʫ2yowõm=/@א:1'QMtpN:9kyYo9 N\>/7erLY=tX:IvzNk$f=M[ H/n4x~!YY˳mJh,i["%`q q}7}T?o} }pC59m%ƺya/W[mQ>Lƨ(wH%-yWdzR>IVc0h `HC[痀MV^7s0z`60 \Xx¶ܒC@EA7J czCB])lP^g#C1wSh*?1 J_/V !-U$!yA|{}1ABi7zrנf A2/'s٧4#,.䓩i3C Ǝ>^)!z@0<¿0/<JL;3q1gB.sC5BdݶS^-۫㚎㞴vGid)leRFp,H9L^n6l<0Ik?$Hu Ӡ0Qqd ` o$w I&л\agͅ5o>N戫M,LZCP@e ,…>M2*J}%A?ĵg PBcpJn/@=1 QAj(2S˕sSH4 v}ӗj/k0yin ǕH/`t v#anϰNx#2Y>v'fblt'`t3u0NG2O^JDgYֽGE/ 6 T҆#koe54L `hF#ʈ4@HX6SfVo|K hC'p- uy pa]G@!D{GVПSڐtmͯ>kui1gh۟b`y{.q!Dua'4$h/PsS`~ao>aA@zXN8 ϡAD?1}/}_}mN ٫p /%cavs&Y̷s.zi@.R& 2PnJ0(X @BW:owF Ox>CeҮa?#'ɴ;e*YmD2H稕t1@y[J4@CS0n[z\{PGo[OGCa/rDHp.^k,Orln  c7Iب x3O.$ve(f'4{@qSL[ƨ}^~zzy;ƶzT11YRE2 ) (2H?;.\;u$=o_ƱdQ(ȠEDB Cp,'g P꽎>h@[4ƒPXh58wOߌ# A$P+@h}lD3 f\Jz^GWf$#T`Pd DR+ AQ TTX  "Q"1:m UEEbM{(R,R1c0F T"DT,"a pFa9BKh8gQ EU }ѓap0N }{K큈TY TV"@TQDJ+$"Ab!?˭d\B( fu\mv$`2 }pU" 0E Q=7Qbt)KflkFF4BP fn_T,ƭ4q ?=qai^č{waCad o٨:O 8+K4}$zV7޹m擶qXܵrwdY~ \sj !" 4Axv2AwցI,0l shNX4KSq~(ң$#mpj%Q:?Oگ#]݂zfHǘo6OS<P wPI!. ͘$c- }m_={~3bU`r4݅vKQb5l/ځ*ml]rsl $M%!M9`]i 01(,6F)KE`5(FO V ɧl+fAb""ajԪ1,QJMj@ْd,T.)8t.^M|O a륱枋ᙻ>`EC8KZoloeh+qc>zU]_f| B7)FaCALW^3o~V 6/D1,zQ{.!\saAҨtɱA-#/p@(t"$d@=` xZ!t$kۄ;l"Ai䶻<)9~Q鷘hf:[׼?-,GҴ*c3ڷJ8?VR/+)s-;w?!1kl NZ.7MS8D 5M` 4lcb2I#7X,D= DZlG9|<2 y-G?"@7\_{C6V͎aL8*21o !?!:o;`o31BD;;zt7:~wc8z_{fϺt{6Ε1+1S |-* Z#0mLR|rqfz[NCbȳU8P[% $  BqKYubwWD!Rs4ȞK)Yfz &%&¶S1-7xB!H#B ` F"D 1b Y#H(Vg$ EB0A*D" @Eo"¦A/0}kʼnޏ _oSm'd[Jxcʞ$|yʰ9rG iYD,$}PE^W^3!=V,ܑob7n .(t<:3|X:e=KІt o&K{.i.g9/5A&`,o+`@KG:NʡYct]V:tӞ1kJwm8R$QE6"$/#aۑއޟtpr xȔo֘}u}}QG?ey-pfoa{Z)DZRZ{dX&})bM •f K(bUe]oxyccP4Axst9,-ٜ+#ck^+7i;AV˦J}M!S"qd= %Nll*, *"9/ЪI3 9E>'@U߁B?FkH?|6p3 9:{L:xNޖ;2{l<ėpUEY)链CVKx"JKI͛fQ|a4 , h0 a<t2,t>W#/@$-+ݸVBÒ߆GKj`0h ?HeJGQOo ܲ.My#.^^/'/YxT醰+-ݔ6*Hܸ*=JʜA `.)4iГeFh#wkl"0]mn\vS½mTK[UkBͥ$_u{ọ0$%_ *%IȹhJ{QnyEdo3%{zU9#t;|?m!4 H6˙P]W%Sv H~Xg#(0sQ Nk#dy〈:teg, W K}҂ICG?Al0W4sh+Z͖c53Zؤ3(Y30myLO7;Ƶi/x~~ߞ#Ssza3 t+Z{y_99bz>/@GH{2ٛ#~ӼqZra ºeCx{Xv,v bo)@'L!w@c 8̘2HH3J {rE]geHCku<*<HmC{_|ܠcj`*DݨDEy ReT q^7R<< 5r}=Y=s = rPk/i>)C>Q3 (*bxcZd7-~sTlE.f7e_X%W-&ka(4dRLaf6hk $o>zȂT¦'}ܥ}:pmρ2&s*G:s%?|$+J Ffb8(" $t/d0@p ԞÇ+M#qs\jfly!E!w6tYp$ıܶTbug/M?.lH Pj;D҂&R-?}߅Xq4P|Y sCdfJNQ) 5Qm5Y[/ RHbpi8vdd:4XCspX~Op!vzc)s^ G _𨡩mٱ$ F ! )E#X$E$H20dV @ ]bz5;0jHG$&Y$9kAE1B, ')! 4sI8pbc8yC iLCp9trH]Q D@F*IPl-hf+ "n_?#IQAcz@DUF F(($E 2'mED 'NΝmtc^BL^䪊*ں~I?{=<_CW[#* RʡUt4hd+ 0hݑ}|M4T`*b$,RDTTT@aD?Lg)E"7ze% *[jy%/ފ;ڳQ|+.ʀ d 79<H$I(UFR KZX1(J0LѷA.53k̹Tv`1`1 %-V+$mtֆ]MŸH cp׿Bb ( =H2Fқ3,ֻ-]{\ 30erd!k3ikY 2ODA~Y5x6Т2e" Q˙}}=Rl,scmO26AxXKX*Gef<߮O_B&uf=}0D@1I+7-4XYw }C$ujT:I4ώME_rgFgߏ`ܙh)W4h#}E&`=絙F[yAk5boΆAEϺpx^eד j˚i c 3aa$XcǸ_vP{tEԥ'6PvFMpRAP @! u(@?*EcX7; #oy=Y6C#!BC0zP0 xZ~2E:pg ;*9ږvHM*txZGG A;~밃 nuT_oa(Ï 9eoJ+.˨ RG؟A8omMg)[MR#V^Tl=޴nHy)Р),OFpxt}ϴwqwiDF, uK~. xIG^{S$?+G!>f|"fl٨QJ;Zl^6pu4ŐP #9+%\-^.aG#J.{l@aa N;S0wI1.#:L Oٜ6Ŷ kI/>zG3DBKtG! ߗ5>aСaOc{ ?=f+Em+;v4h}<]Q|U# d68`hÒ`>xxp>aP~$0yq }v;K Ds'_ÔYYok5%iEgP1ymW.؝Z$RˀmM!Em7˶22bvM r4ƍ (KCmbuFǼci%3N1/g A"rƈaD`X}2燄#9/+{*O%Q?VT>(]z VDHad^\@x*j-2t{hq4)Y5TeT,hC)6ntPeT8~(5K~xj.^c4$Ӯ$0 fsoyZ& !{jbH/_{_އC$'8z," Px$FsY 0&)EdcU|n Eqv]7J;.BM9&׳>/uiPOetx];i=STӏK?esrcΜP7ȇ证 c)Lb>vD&a 8u~eS恬8f,9ݔH42sQ `360Cp~W[޲uwпo U{eXal cc2A[70d,c38a,}闑S뻜> ]+Ż,~ ϵ 3\ɩ?)> 1c}?xFD`faR$bH´Ye.Z-dYs?.?K] QPp(@R" YQdY*._SmYh]U{ ۏ:\|MSx@4xDB*8I|d*GZ֩;!I؊1S((ҜVK&RX<gfm҂" ١FhG`X0?*Vm",F 'b[9ps8s` χJe|Q>??j-HW<gU2! a){Zg悭њh:7E1*\|'w20-2 '&SKhu[(3d8pĖ]u ;#)5OUQʔ4hdo06Ds/nC.HoْaNc!m<*B' ݐ #0*Å齖.מnVYbX!w5n}|OQ/_4B:jBdil"5#dZZz˘3.ZO09|8&J>pDDAc$aZ?L?3jKi<͎TADhX'5bj Y $&QYv6Z?|ރx=v:7V$7h]1G DφX5ul |p臼=h}ï/ du]%?=CD'~ 9FIFA@ &PP(|=I0XRlD)_B1LGW9=r]M~$a 3P4B=E>OW.\S1M;~ -JB<]Pk}Y0!7i dqzm%0-?V_qh%ӌ$ *%X6 )=ilCL!$P,\?76kz # 0!$ Chy𽶷 }Ad "HF+"UI_?R+EE`#QTȊ UD;<0Eo_7Wo&פ acc ct ; /h0 FPdK}D=B 1`,R"0@,Q)$" bD", TAXF dňA#{lE4A_@-Ba D">IRH0Fu!udS? EQl 1y2Aoߐt S6AZްqdB߲da֖U8=swZVo%E 畐68a ^Z硯_ n[snoYr1ovϵ?V5M.bc&C b=68밍g Ua< ʫ5Q-!Du;l?Nx8~,Q(T((,X(D" Ү~͏G0.I)=ud>71-5+?zY #ǿ!8=X =?_:?].pQ`e0NJ2 Y-tw0Gf_K6`~K&}Yymq1p2}1|biF/f,x(0OhȦ ܁1+6\ꣀԄJhrіNl6^ 0HAQ٪dBA氎3 F/$na ZHֲdžܡ3}lI"PK,85Drd_l:\ڱ ϰ6 U`(ET X "ED@)R(A+A"&X40 !X]T@nD˟J"89E0"" 52*E$ $A@FDb2A$NIF^ R|:+/$B?GgKL>-%,!x$IH("!VD`,XFB"EA0E1D0Ą #>/s5 6#$ PPDB*bŀ 1F1b(1HR0$D$`1 ,`R,H ň0,AĀE" F 1>AbX)X A*iw}-oov%f?S>t $@HD`*,d@DƿCOu`!$""1"$X( +b{J>`f21 9>Y}ku\@Фd@ E O~$ķW$W{]"] <tQE=&d /AN|%P!F`٤oG e0myɛi&o< ̺^0 -Adb&DIeA'd2C8v#G1Gse''= (w JҌPؚpIl2OͮaFxM`SꔖqVQ~u$܄SfM騑Hh E2D`'XQ1Wb}%_FpLh-!9 @#FRrxHPc7;2$5A eпK1O.ߗƘ#TsGPwH Cin.8~ &bg"Hˈ"I1459a\L ƠlRDA(޲Lo^aЛ^Ipn$Tu]4G4dZ,}sx<,^kKǻ{1(rO6#l( Sy"@'`ȾTA7Խ/i÷lG^f.s240 ksGjykaDY꾷5כue ͷe HTViObH{Bߵd$o>k- %<^ D1s@/s]|/>|7"s( `l@ޒF lb݌A `ρZEN\ַgw!!́3H F%Š]atenrv I\@~;4y}q8)?2&Uˆ;.0NKgt"w{K-|.z߲nܽ!$;q0s" 03G)Yd $d0P>Ou *}弈Հ%(#9$BɸT]$'Cdt=i> g`y u #\ u7u#O:?qq$yΘ/{Z-j+LD0,{jq[/0pGOТѩH}r)%F7rY3;ps@,] A3T:ks>~ N>!Wҿ\(~1!SL`Pl6+ .Uc0 qϱng/,6c3c>7Gq%P3J˻N_CgYlBeBpfD>Nvlkbݟ?j%r%0uC45zn}oM^**0G0M|IB'jnsAo;eq}k9,4K_# ٘İXHN΍J"pàriaF-/,A !!( ;"4 ,X[Kr{MQI=gR#t;yr/foĊ$dQPE( *,AHQ"+X1bHEof~f'y1<tVdƎTD+1E*XHJAoͲ  F㛿zP0QU"Q-X F"<݊@P< $ Bp+&srd N*CΞJx eye&X*/rѲEds2VlŊLw߇;b.ԱLjޱQ]L,Ǒ,X׏ StqӒ \ޛ&:څ4]f:Ӛ[)]n95kFZ j°XH8YQBL4mvɘS6}@&V*[ǔx0 f^ۭl qO&*E1Q{vѣ?Z"E|) DidcθWD ~bJ?ӴNZ>w"ne}/G4JQU)΄L0;MP37v4PQĖDž˝Ph៝Fh }Vk ^ٗY8M&ySV. 8F 9Lr'JC>:qIȓWS9}jFЕD.y~>:LFѢVxqCE2}"i4[__S޴]O:#điz,C )q}}|jSGx{>B|/p> yvZ;MGިV̚21cݍ.?~R47WZQVثqӸP'N0n܉q}!`PϏ8b Cg?ߎ c$3)\H|ZsS)!^\)!LzH⾿*g3&4ՠf4xF%aρ$L0[:>/g[Rdת'8Y8si}~mP{u9I1Ǐ,:Hߕ[z6 IyQ h(>%j`_b yy:yܶ#eMuWnbن,> ,@MG#<8ŬUAÎ`HN%8 9<|ELH3m-$wc`t5|o[ŷuUG\50j)1W8'W8cU ?=['/%JdhY $zA2 ;ྌ[( T^4:(Υ~[1|B8}o޲HӻkM-2F:< Mm\MnĊFB 2MCY0zf{zt<+ww, ;ŬJybKyӘc/Hx}OZ?4  H%Ok`ylzjsXiqfAߚ߳*[xR' a9Lw;Ȟ_uGkD%q&k  Ol80v0D"9C}xmJЗEh{(dv G p0(U1نbjH]m+lD0|v[5bj9;MɈ@<4mS$%c)-@WVjE7wMg86Ǻ^sDFȿ؈yBW?6R!1fJR kWNƍB׆}ɺuMd@(7GG,}/ͰMԏ],b(?^߳6nߴ3S[,cAfPFS|Q9Q5+eۼ_Ţ2i&yӪ y6*!HIFA$E",F*R(O,۵Vvz{ G0\72=T04JxO  YW4 p HB` P]^^g/%Q ˩|vkaiq¤gpA !FٷJRBL6oylj[VHjİ{^v6;+2_߾ %CI[t8ըR~> 6<N'*'O!Xk.iA>hS$apŭjwDzcI|[ +T '|qOϒoHBn^Y$ #߷%Nd|GL$SL 1K [2A# |qԍHœ}Nf` 4a}3 6x(4|}}> n=-D{ X`H;Tqqln6뛞3!Df>^G^~L:!7F+هpS˜VnLVm>_v]%ZhFgF ؠaA^RY3q2mP<, ϙ_T+gЅTWW%λV ԸQ6y ܣƪE]wRx3(?˽e' ek A`Sl6<N8tĩ׃yJk;:{"Oks7+h@XҺ럦pNܠk=>քt|ZjCbm~V 0$#%겑zB"҆>Q:t4b>JZ0S^~]_7CQ!:?ꎙ#1,SK[E苗iznC1L}5v|d|nFoi>>$̼#PPݸM_UCjeN/Y⚕Ay}O'!/&Q϶oX(̯haPDM 3/zݽB($"3^ &;N։hi4xy#aPe^g&x^]]z;9a5~)Sf5b K8m @w$s@Ioo*2gowbT<--SHO=\m;j"e}`){&4ۜjPLXgvL-  AS@#cyWC= #>gwwta(r&ASܴyo)VOOw\Yw`v>.9wn-PSu YY1:$f ED)νjINm|J4ؑdg\llhNNi+io)Gp>1=׾f?&iSett=+)m/kΧ-~<,ɯpzUF3! j"mRdhٹޯO7UһQ"XX.ǎ;޺!#2 ~ѐu)elW,}B8is#hX"'GHiUQB5Qǐ:sw? :.c=<3|vXI'jq}hd1)fn=޿ID-cebٷ|xߋgO[hUI=Bs7.:v[[0fn"y0a *8>ߨ;L18&U5=:΀1C/=(b"SW S=lҕfDm4!{c & }r_~o| e|W&ˑWО{fSɑLm3w6\ѧ^c:7ºܮuה> Ns2HlC N5֡xP;RC1L--gEWigZ=5xR %L`Shz^_ ϻ?ђؘ>j﹠d`7^^q*e !4ToUUo9}?VKZG|iDo5QGHH %]~.0OsŅ @)!#!g;;ݥF, ɛpYҏP6i;mrZ#Ɓ#ֿH7 " "PUE[?CO}<)W+W*j|D=hha- Vd^WoefN-o2z- H% 4"*bc%Aʤ#a.9[(wWҳm,R^w|~6p'}X]wO3hSD*Ӱ 1a68[j \3Bz =i5bnP{#nP9nHўW\ZNիfKHKUdb<΀ \٭!5QA8E] [0br2 '7~W>__aWflj.l7!,[H a{v ZV#d/蔻 Yxb"xNCMQkImU"6 sy9"v niqϠ\XBN7/cx" H2*+՛ܸlto"Ɗd A9gV!f_|OR \[O/2N{ẜCB?VBAć/{QV=;z7q৘ϑq0L#b5W2l=;IiM ^2wU/`HF;b论<8)83'o /Wߊ>V*Q&N2 tkX$ɓ>qd@zϭg6}k]<&\YKFc}>l &Z_k_fM_!nCF`/1 $L˞ѹŽK`g'ؑc%Em"7?#}V {ݟH%Kv#7q'7Gp(7vx5ǎ:P@b Ŭ?rrطm[loAI5rs7-wS2*OӭBؠQW1E}eK??ߊ jZaL"e=>Wd9NC@W{Դ M'VrU)?H)j%FͳU%5Y2z\˲pkY-4dQ2"~H$I'}ձL> RDZζ>O^/#/a?W0ovܷV8 x441wNAEdtD&CbwV"N)nst 1 )i*D+{&v%S£>t=o;RX"$ t Dc'"7ysiCU3M&8Dc^hf[[1Sl%JgS~H"2vz>:7q"&;-I=C \$ ׇA!H 4DTנxs.C@l@ PT)1,KכX1KaoO U` ~4vAF}  BG 9_dQs$X{t5PJ+DX8+oF|jOHIC:%,mO};Ϭ+ vsL}'ʉnB j<+i8~ѽdt. y_[&n1>ٺz٠ƬJTחc`ssMƆ DQ֓&ե I!,򲴳N_?cwxGm2OLQJ t[ŸlJL}^U: 8Qub}+vőfxYw8Ϯi· 5'd=|S&JC3lt#l;_vkRyn ,$>]\\I#9DdE J !:~r Z(q%`oPFu G"B:ʢM<^dװěK RƮJbE~|r ټLÛ}uu^jZT8~X5.Zdw*.9̕/P3q IkodS5qȁ%~k`pIV|>SO}Xo>Pita\A(4Ho@1?w_e_h LhXq?ȤQ4jDr n &K-"Vmq# 6w&;\l6S nU+vowPX(Hta+:Z_QUeEpի BPE0eǟjg2qb/FQT`3/R{ q)UCtBFDduv"louo/֛rXpYX w/QtkD$WBmU]@E_U[]c\ ]_/$4175QB $e*3,7?TS}-+9#pFsL[ *cqѴH~2K Kô/7k!E~rw /eɢAՃ3Rd{-b:(s#äW<QB8.^#(48ԭX6VӧF!0h@X%]}!&y T&lc&n{ޢa)!pMN]٘(̆ƫ50 q3B律i('8 .R̋^ TSlԙf<ۄOflmJYY x rٳ-Vv~Ƌr(!~^ԥ8٫X 5(G[jOFQumGQ؟z8.[qP"9,[0UTDZlN|5Y"T9$RnX0 m)0#b00!pȔ!2{;h3f .$&0Aߨ<cF'9%:s"dV0 O?;Q$RBDB@(QB)]="_W~pӸK˛\-bM@I$DYS]~VQcخ+.45p:cx%tmF\@SJو7h_-(_q8jpuIK]k':(Rpmt:J9 "6 ;#'B}Ȝ0,&aCaJd o!o 1MXf#Wg=Nimp)F)V@%KE?-k]B)>ElҍB;nO3G񽟲wWpy^ m!6XVDA֡Z.yKcUa Gu}itŒ0(ؾZtgD xLk*@fSm PkE*bRye,QN~iӊ󭕠;:NIM@k@c"Lyḙ"$9^Cz|߁z?рP.QL홄 ??H/.l`9VYSAnJK}ۑ8f0>c񄄔+ب?Fadl9ͷ,[ n:!ʑ?̜nC!2G]϶G9cleunz*`H,$X(@)to2~eN/ڍEB~!Jp8 ڇPWK_?zoyoNa=<d46OkJ<ˆH~m|'%3{PS,jꡜQS!vXk#S~cE3ͼrUfrA&X"G1VijļpMs[*a}Ix'L)C*Q%!:h#*P D?~?yUs^]h 1^5zZG򰶯f~ŒJ5"Qcna,^^k00ndهӒ[r7[-LרQEHx5@TFY?J^Qkc|[h+(`e%oǢ4!~/Pth6</x݋:^01hx]`;ZEoo2m)BzPp6t';w}9Ӎ|$-m4RYeIAHsdkTHpeE4n] 9YZnU.Y,1z3(f7I|QlsG6 Y®Ak{UaR;壣 V'sg# h59J>,w/RBk2SRQE@Aw9V`G 7Hgo㾟fA.p˖׍]ZJ2T[*Ͻ\3k h*^a u*GO"6yUw&pqb`)h+3,mF\oL_H`߀UubzY2SO"8\h(_$ ntuK>xD_0t_u``"9@$ zv~w~gZ^4u3qBRS8ۄ bZ-;u%Zw.PoV-ψP居pP׿'d30{r4Cf?٢<ckv3XES*[Pk݇`2]3oeL YM_C#Y)5z|V4:&3lb/Cժd]?zŷ?~._bX~VʼnYU^_~ <.$z) Z?ͤR*nקR6}~ܕ$* Bə SշK ,$2ra//(l-Tz!ӏP>"We-k;Y ^RCtKufJ@/s\wg%B=*:Ǖհ h0 c' CD 1Oy^>ʝ,;vLꡪiJE$1/r$F+?#ap&>u>OaIPSބد?)t[j<}8v xK*ч~9`؈ (HgH$PRI( ,HEC7?Co Qf $ƉAYd@CDLMI5kM=QPSSAu[cSDJyz>{l̹g 9;<7RUfl;t!JU[uQ$4=Ą=L$u୩`4 yA HQX9+`q^!foMA;'2@~o"B虵Igf(AAMY)U "*%Ol_QmDx uV1b53#tbC t[E?mxk| yQ ?%x~6x,{( %ғG I?C@Wy 6b",=Wl  فqc?Ƽd}bK!,ФB  @gx۔r}NyDOl@\or]u>* t\̌6*!q>Pt;VQX܀M[(< W*lTW( ʐࠔ5"_TSbh3F:`Ġf-1")HMF&P !W̔b >J!Ώunr@rBdǵO;yJ͔<)nqǐ]k :2%2ÆΫvӇ㲹7XV%ݵ,Ȼ:M|p6IZ4vhY`;xQV2ǢI]k&YSq mC5aݴ1򯏱:̤o3Yxbw̿jH9` " v4Z.׵Pod{%jQ%a +rE޽DN`1XsRD_}'{nl+%M hZ{ C0 c6b@ӌ:-7g1݅ë)AB*Tͦ ։F[frmËȤ,B.V,*c Mqszu=*[K%7dGihB cၔ)~4"PJ/Ʀ#Țb2(H qelUl]c̼TCBQAF%DE.5* JUG䃧Z&ӎ+pe7*BRni*ZcӢҢ:r@.j}eBCa l;>{<)DuX:x@J l.óBU r.lu!diwhravo1#V\8K&i$ C-'Օtq'GO4.go=T Aav%I٭9O6IV0ᾦirϰHk谮$}&ܝU  hl HDZwГ1 "z s42@@ jXuhi _ԣUy"(?s\)vȡzJM8E6p {nA9Jy6Dr(Bu`%Rׅdƌ,W,u! *p95QXMGƂCN/ C 0(i F1!P& m!P5MKoMbXo<*)DdTdCcD,N|)&\BWڻ+ ]clGQ778l6Y 0IM]kА,j[{rΜ*>f`WURLT2֠ #S:J,k+ z܍LTz3`*Jo H,!#D!SDMǝ.|NPX F0A`ad:[&  HHw; u]w9p۩8pwA H@nFգ&" S54TRhn3%i4;z 0svBkэ! %a25.3æhZdAP 4]r1 #q7bx3'`CC0VK_uhE#ݝIY),]Xʔ,&X&_Eb"w5JDA7RUAs:!vUe?W5c;rN;[J%ѩj"I#"uFct5YsY_A n)ݧ}樬hm0iX mx8 jHXĚEqJꖅ:l S_HTDG`k}<ގ{( UJV۷ʞ^=mB%B ۗ v@dj~y{;};V?5ot^Cs| .GzW{+Ov`CYo|rl}:  CI GWV:~86QԿd\/\?Eو*| AKhg]/#?F$Boq?>!(_\iwWlJ\$@A\ s=k` aux(ʅ)X,iW۳;1$Ԅ68NQ!P]IC8:nځX/ٟ=?v6&hB7 E @8E &{Qn+\{_K_4h1өw`ԥ}]{w0L^! 7O5/,-8'^J,SN&fG4x`7$;;ψ(Q(5Ƕ qc[\ zZEG+cx[mJbz"׉*-룤H@*4WrX륆sL =jjھݝJ?3߽zɤc&qΡ#q}OH:36$ cn ?l|8 ]z6`4! œc;hjfd@>T NVTd0YD"@*T'U|0MzeNL/W 5uYߎXc<<ˀZcb:grՔ+II q_.$(E{:nm;B#a;wxk4חËT/w&h߸]z4b*Sb*p齚Z=׫e#SCJbLAɬ:αLuH`F*>VHAl۬"qkL~̓mTۈfvldb*(,-/2vTcOϺ0Wˎ@ ) F 80!Fhc3pa$tF{37RBX̤heb8m>MȯPlӕan@Pa>uւnޡ"+ w Zr&Q DX5@LˍVVDPv58`FL=&\ SlaW_o|Ԛ虁g .Q"-HQQ)MB؝Z*- sPviQ6L7۴Shh0HJ'XJL%nd HQ74m3"=| o0ңc PPOժk5<=) )ږ0-ɹWYW ^K 0dݚ7aBRA*|]/{cbju* ׃V((r1:k5mbPM̓LlVyt)7mvO3=g!IOAyQ-t8<BcPc21CUS>5i5E_@VSMoبRY;&~E vJM0՝\魸h4TIrYJU&a+Z `R2y.@Ѩ7d&H!3~\Lse55& V!lxm/o.M҂5 >fd;`Hڎs;1670EDrVyOCzSI x T+͠lWs"S:n%#t}Fն?jlM[mV4\< Sb4RG<3l:"=(L@1%Qr9Ul'q0H }N*;Vs]JK@$+*k,D02Okڈ X-B"cnK)A@́PuT*Me"W@cjwSvlg!=\PT 7M nѧ ua@>Csf̺8+Idoo.AzS'E>N_:)#!\Ѡe : X7VȬb7T!E|gsxƥS؊ `B% $]rD @&Tb5N2@87 :v Qx,'KC |~ZsDէ_fo觽: slDbarߪ":հ~ԱAPSqŜLdjcWSյR;ޤA:ٲf58v-E{k;ɫyr_f M攅~ ~o`oBx`sZ{NP}3<d&R,5 o(u?M&EgvuuVVۣŭԠwTuWarҥ}ޒFRک!RR򕞲Y8_#q0Ȟ} TTIQٙe.| $' mQe-:Nltc7PoLa|{AVh%Mۻ/3yC,u;iWY$J 4Za~!4#8)Z/bl8SA!(Lh@jC&1׻d 0 ɱ dS o<n\W|Xi; C^ r5¢BI$lVĚPhyK`N`Sr|@)Gb' r4. I9 { yRzZsv4O/m071džӷo?AȄ:yStU4RCʜ3YtafDXfckK[ǔ Pe kN m 2Tǚ)n隚Ghd՛ T6P_Ezv*UȰPI0aFxO'v mOxpT(F:._كu?A^[D) }O}^JIO <ޯI->E/\:)੷4Jrgrr9MM`2^WYFs/W͗꬝#"SD #C(Ku$NtFCX8cF}cke  = u {Mz=n=%/BՍQ'akm(0vAgejU Q!%,pݹSijꮟgH*@LQzx7|{+c1Q ƕZZj)nM:ːցZRƖ(D.0+ c.2Y'RHde+dXtr nJ jJ0%(`2ƀehbȫ,Q`$\eT2*IUXn"R Y LHiI}>)n̜jXWmFAQUV@XhF"4ȈitJ1ҢAmD1eY6sѴUl2 bNܸ֍ePR,9qV`dr`RS Be#[IӚBB1TUaYiAtX,++(b)X#(T@$)hE*ids@Pϐ݃A49J#dh4O5iճorwa/p=mXb TaIq äcXA _F_-n@rMտxT"ևc~|˭m`zlœwkfD7feObk:;;m[v̫tԦel#vNh0w$#Y3L &Yiomx/Է>v }„ nې$1 T`B #Ak.y J@Ғ˚8%4[Q&wg`bc XA3U6VA䑠Xn*u=ծ;lP$ e 7\?EG=_Qώ0Vn hiw[tIYRr4ffu @.%G|ɥUYW8'e:/ wҧd| ‡qdTU=Eܘ[qnT(xU(BS#@;93B9gy͠8>*d DPAE^8U"^;䫻lk6ۣDfnۨ$ (صo-MWbܡle' 2L92;'A WIrDd2YLoEBY[']hhĥ%I-YR,ZȲ !a[҈'b$!$er!K (owwʌ2E^k3 =O_{8?aj[Faj0nuIv I$kA4OKLh}͢8ZuTľrW@ȹOTL BG"2:!Z17cMW\y-$. RuUt'[rջS³1 (-mlk.~B4~Y PL-Kц CUFS1h?e*UfjEUFfkqx 3go{hMnJFG1JC{j"0b-1YS! ca*8Doy]BM͔754T)p)αWTxR>vQ 8聪n,T6*XQl,,|:`h(C>"%4P2x=,R q|k~`E"j2 NQx  1M$!t7<|)=!fe؃m,- ^/v=9 ?E 3_F'IxqÌѳ@U dGIqYQN089@rw܎A J ><1gm-Q0k6s!!t.lT:92,< qbmz/C BL c(y0cy[R`ùId_wc_l$7, wwtt:J  HBhb#GQy1{\7 R9abol[r 6qxc)~bOM^C9l[Asro4 qk+I R6yu[Zn(xq|v1(j,(2}|׮R ZvW}&Pc-[hjED${ߤVnj KW,3m h!o H,tJ8~>!7 2h/"_:݋ӲKvO΅PY(2*D 6&a^^$oe*UԵ-t(6$*dL ʇvݽpC3J͎]Қ օI! V@;CA(+$k/XbOQ㯭cu> oa6o26v}ڭ什BjYcl{xr˽՘ݽ]owL{{{65O > 8-ϧmZ9{z}>ܻ_k}$}c^cΞ:Eu]g\︎[x˳p}4z}1tMcLگl^|Cdr{þ׺-}]}]=_|t3Ѧ뼀:=o=UHt}:U]Ϸ}Q=kOv v8m}}wYPC!v]`vtގEmIR1Jm(6eH>(J5Z K@P R((P,o.v}[ܷA`}4G :Ͻۋvt>}qϳd^\k}\X) =ۂzC7`9{xn( |4Yu_-C}JH{۾}Ksw@w|ssVvn쯛IVyvYz%;km/;z`([owj(PGA&wf5ao 3tM})4zimomqV-y|-]8'vTg6z {mklͬ{ovŶ>;_}mw[O<vg7 G}׼{`}9{{`}GӪ^Ϟos8/\5t_l>CG:4R Az }0Elaݝ:O}9;y>}wzPr^>|xv*t+L@G4η"EZXGI˻9OvM9YO{}ґb9;np|ڔu}iuf{b]B޽}T0mg{;Q|};5b7}ݽ^׶}|xրj}/`rUfuM׻{jnn9^gfvŻ;msu}Bw1٪P EUQw;`*8wy由NPݟy(}w@k#():c}5/l sw7k۸Ox:B]m4=\IT ۄ{Oyx[iL{@@&@#!`0#&L&)hѓM<4M2)#zid4ɦI ЁMMd M&l0T<&'2Sҟm6*$ԙlS&M=4mDoe6)i" z4L =#i4=M44M2i̓hih=G1=F M)" '"izzSjAi|Ydvڜ+:uI}He4ja̐. d nXhJBkjmJ‹EBBBFEdO^Y~[@5DQF!_Zf>F4AoY֩p* 4oB"8L50by_x!=fA*$TWT) zk6H%d ~c#ŰOSP+P)Z\YB CVP#Ʉ`NLiZZL!Kmıkt E6?}dP-ˣ8 " ЂAhVrMo1핖WXt7k_Pm+q@^LJv2E#nA@ly:?VϤhg{>$I@dZo~la's+ (wY8]lcdF);!e'U"ac1\qۛ'ַk!prsݯwx]~;[eoI"Add*BɴcEfTͦڍh cXʹ6f՛ Yѱdda6J3 *C-*-F"1fihm2 hJɴ%)bEڙQD04HXFRiTQ$ؠ-6l,*VX*=)$H5V"HBIQ y_gSW䟄[T–īa*Ud ov'qۖ:_^D?3\Ct{'GGu6DbȰ$v-a*"L }0'38nV$BD,ܞ<~Qi4mX#(((zOK<|)/G*惄MLcsǢ:7+hh0: e JOu}+}Wn7Aj _)h|{18AU-Y>It$F!q!uZ#Dr*IK%&5}%9o'5@1LC b*UId~/ϘA=K^Ղ{+E!PPD޺C$G(6TR&fAIFue0lmi eu.ԲG,?O>?u2Ufk H9.eΌ1H+ۋ=dζ@ҫTݴz7]tND!Cëd׎a{t@u稰4:$- Z6SNNe=1:d^Нu^$P7BI%'e b>d:ʟ1tc$阠.],hPYKCB2ԞFlO )8^lfC0\" !!@9g sdQ@KcR vJ'([$S_ 70YlTT)4+#}”JRhAB"< hs3DfWcu] @Ugs#I8jܾ2 Y&}&}oC}h"SklS-ֳfؽ\\ךDbUܹ;nnnar^%jDG: 5y݂dF;ui.[sQIVJ&5kɎآRE !Z,!֯)P [emēNruzSE*hҲ{O=k&k SMu{&CaZ#Ig,%J TT͂5e #BbJj9v" ,4L-T?$d钒'5  =-뗚7j+bqJT3$aRsVCQXOYra8f 8E 6>_4X-s G-CPI,KZSm8tG>A j[|Nz|5:J Hy>yI͉'Plju uGy9ξSstCh|]v L5 =%6q bvn`S5D'[5z͝,4B&8HJVF(ۄڹjxt8p$100CC$G٥09ⷦ,2@0andd[ <&w1N{ ؆`U!;‚P,b}nw5҄vw:4Ćh`,4esB`z}ZYIQ Zn78mM^s8wEN~W 6$W$CtiIu6@ IW$[P:D CM.L{Npr3Bq@2N 4ˀ1zi s-Z ٰ GZ7=T) mp/3j(˄榭˄z?k#hg6g|H'.+8>:$ |K hfDiQ٤)&u6)wFDdj[."`"&'V H&/ % zSx*#$PG2)Ńtx҅x}g]88@^͵~,C)*29ќqӎxUvi :Zo &FI 05a8tE`H)$@4 HN#gj׫ח%g.C&(, .|tx zv{96=NK(&:߉+#'GiiTQntwOx ,,y\lX,UAok53#0:`)9~"B72(*r@YIH':/BA>ysuv1eȨ`Nxtܜ-o [^Nk+3d"!قz?>[9[󒳋 [4 2 dc0bl'ݐg9u}uWscYxGuh8f꽏cJ 濎ߪm|V?{/J{nك5@4`SRBR$XHIhL?AJQ5:?nb?o2wWd2P?Qr oأR-]G٣{# F!7kaɐ>x<5U` FCg$sOi0hAoMusv( P>2 `Siwd7=0s-(;1~`Ȭ0Ԁjlpț+CRB>o6>4 6$et#݇4;%w믶ٷqM3v`?zzGLG :9t?O?'AX]pIJ|EK!R*0!m takt;L0,Cgbg¾err)Fy&h$2 .xx!Ήj?0_GD$U>S@(H3,}KLIR+&4dRk4g8\!By9Eq=,d~k3QFщ )p G5e߅bO@ V }Ϋj7MŸD4$"|/ZζF!YQc>4H!c@xh0xٗ9(?zVNT^TcR1%-Fsh$}ĵ$Goq^}L?hO+pP\"qȈQM)^'㻝zTHȂ KOD''\L0'{g%v S,V9qb)}n]ibH(#}g>w O:A* !*YckC?-Kޕ@UQVrXuٲ6AG蒌Ua M*o32cQTSW Ci%ﴰJZxWZ$8s'6lE8lKAiD̸o7̝XzcG`C- 7rh1`Z 6n!Z{:hmLUvfk fnfbg,D2Zfe9l8_pv\kG'K4 =>!v:=]ЦfOx߷J)#; ,>Qߧ<2<>5##!L #/PRUΎ*Si6AtY1"W ' ݧ<6lMay>O$EH7i(bD/y h <~3cR|1ScP3<0PόFFDJ m,IPjխA;f(n{_>oͱXs1/RI I|ퟅA!/uz?>[/AzyOT@k2\|wǾ&-2@Ɇ_Qhƙy*>S_{/qC甧TR!ޔff iZ' ́T܌v;6(=%sk9l*Ԇh>zvD+&=}'4fL]t7ϲ|c9smvTdUW"j硯X  1xA7wGߑzY ,]r였u[Y{ 91b6 tol|-oQI;RxU+&i ⋄++:+M{f ]M}s y_z;goC6A-jy}ߙ BgDtrt'?m+1uiz3(B h:DWKjmhJ6~Ѻ)-{, .1Iv[loSa ɶj1n^4~((oA“4IDh.D3?}sᜳ{\ nIjj..7s_Џk|նfCi1=:N=nvI^3xŇcyhd4Tfr#bB`Q]B7h$)den͇hx/$-9RMDdžG~L*O$Z4&kfa]Zh  u}~n}Oo:u7o!1PSIft@=0!-uS=$IlRKK`e*y?WgWQ; dW:!Јg}KB b:RD0k6)_yϏ:,:;էZxa 阳:bQTݕq"".FWr;{H S$:w" w3퓶ݜ&UU$HIcM]S0k+-6VMx$0K) J%*/I{u̐VQ $LjHmblFRy4Jkf[nF-1f5F̲$\jZq+dVc\9KT]&a4U RXk+n !?+ʕ$aZ؅b _ZYl$5K%Mi6-ԥPi4$ȴf))E6.żnH "Ld޽euֻdH,O$Q|]Һ1Vjڞ TVc[Mfnm*irS43SFҍ) (\˩;QL^+%/:-]onvPpܫKqwy R"Bnpɶ-% x(FBQơvQt^w*eC3}kB .S41g0N?u%m,Z lz0=>'TUDžv<>>'gwK[S f-hz O}i9HĨ2U P]mgS_1~G~&RP[rE`[lQH+QS\z>y@H$ᎍ]*hVŸ.) >(X*09`I<0𓣤z4 R#T(ULlmwJKOlE/PWa1b bSU2ߌ"Bg 1>V_}'!2,q:_<=vtv/S؂=|jh}6u[K*.E=\‘ 2ē!Ub58i>񭸾8I`qWewTU[)zAiez5kFF;b?#q~<-nEN6|x1.2V^3ţ~eaZ:#A=?! ԃO<Cvt{ |QtS"k?W>_~~v+ϪT))\ F2!*>ܠbm֝bL&Ԅ<[Ǟy֟L9͒ODfQ(U5\y?f+dk/)hi1~9jV~ƷP=60Xb(#޺~_oC0Zv1}rht>h*O  uNP!cƾDK|0_%C"5<U}Z%D.vc3Fn9gj&<=fޘ2iܤ 8aÏ\/WARXYLF>6Je0XmdMF_ޙ_".[j/ڒ| Y_w)` m? NwKwe؆6 9&/MNqQjxsKL46a{6[;fIR TS:\"k}c]篛 |ōBŢ Y[&lە#T5 sz(b~꿿m܎`??#ϼ؎CbL?krk0xc #r3QvhBE2 p>G x̮mynH}^tF"^tg1H#m¹]K[;=߇ z6״-^I;#86i <$idHc*xQDN{%=NiG\*:B Dp"[{olzH?SZAH=Ʒ!{cHϙ|7;^?CɅĒG˻ng_:8GwE@8'wHR`$e 'T%GiVD@vgz75tL/q*PY,>_?zNUX=&fAI33=5"P"HQR՗gH0Ʉ9` 'ErQWn+QJN]2M"]U5$l qPb65́, 1> e*,@vkt5Jlm[["ErPOEa7ͱjjMی~zB/Uq$q*n[DE5|B^~ӎ.3p =ϊoLPx<(h~W_?7rn+$vw(PȠ(Ȳ,ޅ`!?p05|?]AT.dٶZ P$aҪ} 9@Ӄ9{zǨ#Sw1;'Gl^wh'5s'}A Ȋ9`0r Z̩6{w&Jօlb06h’֎R@xixy6e+U˖ȁ;$ |\h \aC+n@HaMzSܭjQ$K2Mwr6kS#ʚEglu1tv{wb#y37\n x|I=-Y=mHOVx#O6j걣3l6@UB固:?vzӿGf^Nx,& ",D%Id2 `wڿ#y~g]D#Y>֙;Y'`&Tپ?!J(AIADQQzZl"$in}I}X~ADBM@ :iz_MpC7 L R2jCIQLg٬P!_'3)vZEШ( ZJPB1㔽CۥWɏw=SE_?wn9>cMߤE/C{3p=$-ot?KGKm30b%Y1 )6QVKJ ZcrhQLG?]HD+f=SŦ Dd^Ri =;wc+Qڇ Hsx=y&'8vyl[푊f+/ A}UdB0H9Ӆ,İ[g&,Dƈ ^_Mr\c v{0rE(gkaÏ f$!z_Y]a:V ְג )wުh4BCU9ђ@UBR,G I~᪾9EI[c QBYTry1+<~{IÉ"r *kX7JuX}6B(Ccl=:q)-I4LVRTfHjKvqpXh THRL}vm<ٮSvlgƭIĈ&l* %eDdZZƳR>" Xs&J,̛[V R.Uf P:g~Ϗ M9$CߠgE14S X >޵>m{q:hH#UJaZ<^vnnulv7B ၮ$9yY)!RQd Gu=qrg#fI{ Y Up HC!/vOQ*mczٚq |<-7O >#~'s.3wkl5U+X[U[sFr99Ft$ץtWGfS]0I Kڠ ֛2XUa'@mkT|4pB N6mrx )M$Cs D!_ ˨|_]-~n@@RF[>o]K7>_"PF?M$o7ĔxΖ{J~b_d{6!/;]{U5iH4Q51i Ul $bdpRfCۑuTçwm8PK0Dxy()%F ]6w2mzOC?oGeBG)è*63Sr`1RG A|r'Mg!y>FP(r+y>j`r2ydK` 'lB} G™u`_>T]v(p@`PIIO$WO a@o1'>xAH-Jz*yY"%sNUHT񵝾g71rvr66MD5 (AVApS\H/Ӌk̦ )sUG7+3tuԕ;|jp+8X= :z8B@"R#MoIBT3w_%ZDD 0D#BK"|mw}XHB*Otڥ(BdDC|S-= RОtUHB3$M8u0Յ}R/ S0<q@ Q<̫(ͬ2EE'Ӗ1Mrc"Ze<ZjbT&ZM?b`U 췇Te2FEsŠ_zTǛ]0SSp ({Lr`4d,5q<(eMc 1Aɞlw/QIH yذd{o +|x%&xvJJK-vTN`kH0v9U 1orr+&$-|sYkʂDc07:=؂OP3L=bdeݙ:q ǧq UwU6[0 0.L/<^=`w&ק,jǗA mqN\]EUM#ԚxZ)>'p7^_]8LO I @cZs\!$5:ΜKx92cf1'ɫ'8=d HHxTDa Y C:9suPRNWs~0Uẖ,KPY%R0CкTa$ jZgxT8B!0 UtV5|-2o7',E}AkOjZEL"ݸov@$kV<'6ûEE3! ήղesĒOxaY,75a ]Dtf}=:N\ВPQ HN֎꺽 >?'ohs05b'MDbA<`& ?8c@&bcwxac!kQ%psQl ܲО`Dkur iҝ]DQlzA Ʌr?vi˰3at-V*U&ݭĤa71nnbج]r,'c4P2/V7Bagg'ۺ:Xs67ρ*ޟl :am05$(5@*1*T+arݩpr ȃhD  G rq_Kq&Q\Q@Q'6./1fY,Ÿw Slʇ6U.+Z;߿*S: ]\b _{d灌9ǃW]?;=žaUx7!XKkxTqH-H+I .RAV1 @@!ry ަ{̇GQ$3ʲfbԞBRTk9!\Uސ&LD㝦!*Pn` POq` e=-_dH Kg c5R&mhQ3?n&V}GLj]1ծ#<&2mLhyldAwAp?vi"^Hm+ϢI㽁P ^]0't{/I='h-]sL dy8T[o֦GPk&fc=9]/ˏ#*ۡ-+(EE5BB oaQFb&&(~rx+Yg}Z""6ԲSky}6eLiɿi]V߻o@ ɼ>rgWGIDfTC(#g{=" GqBGbU|؃ x  A(۔+@DGnKG3ܤr* l(8PuGe_yEoϬߵ "ʮpWʤv6r>9䬝f_8h/{Rw`yd7YO~1bM-r6չ[Aymģ Cc ⠷Qh?d'(HB}OI^0*rQG9m Bz} L0_N1e,qgyoc!a !7ʴ_o48;ɐȚ:7?DF5&ڙZ$mDQU'/T5}ߡi 0"T ֘LĉdBxϦuѐ5Y|B,yJ@4@,sïx] 7IuyuEQh5JҴz_zOGug$cֵϬ+e5z88jܪ;o\R+(.^.UiY!Lifk\ܴ izM`a2?9ӾGT6Lf 57RO7>=Aǖ#=ǥ|;[{rrüp'kb$C`{r{nլ4jU02Qf7Gl0׫4P0KK 77Зݤ00r61S<# BF^25/g3fP# Q` چ7fzCddt"fO|U!oLõ&9 68HQrU&ΠN}̌ d-3>ce;om.)zx͞(O/uLiʖ`'"Ex&VEUA~ĘZWCGRcS9 'M\6l5۲Qv9mK U giA#Zt-mx_$w; %UQ@6kM>~g-)syn-Mm>M] m*+mp )Q?]&]g䕳pwM rc!3k:r;xg?n;lA׭d *k{5zkh#a<?T@FlK%NbނT wP L Jύ!!{Z~g.~d&;o}opU||1]X"(uės_a"u34c{{\w`jV7{1O&(NTܟi:;wɧӎtΩ+< {^|QI2v#"i,[uS 7V[Ų%9!|7*iacpIBsM 0]qJLC۞O 9{0lVz8vqa wD6-X-K{5.汖 WOD/+ًu9&٧\GuE5W{\i1E*iMztPǮ;4se4ё%(io:o-wf4mx{J(s}*xN]fL v6*(H0\ҖZ.T55!\λKK#cEkC ˑ<ٳ+3\,*DH"-44,6˲*K*<8W~][;f7q!pBED<ޖo_NϙO1()bVզ@u؉##}P^?/ylBOHZ;SuE}fp! 0`[@?1b쪼v}~ߗ~؛O/`$VPDSr}%@DQ\  C1' ^??>G&MrRU&piOOtt6i{& F\[1L8g3x}6?de6sW=zo#@M_B 'Pj"&<'U VF2W"9cv2n.ѣm8V8E( 1"&9i*=e<~5@0 = 2swy@F$.?ͲQ>UOHUs*La*+e* G#ϱ$(de i1bőb"gSߔ/?[+Ym + ,UXUZtÃyw?RX&Dk<@ޘةL!Bx痷ng_س%= {_;l8ߞ=@B81cK8 Q$B ЈaIylLɍf߯ler[5bζ>$$#vbE3YgɘAjߘijmƃpfg])~9l hͺȪU5KMAWVNfHsk2LR ] hCEW MSY-=$oPWYdžGqha$t:ҍ*qaG'f+ hN"I#z0޼; U*x2F-(O#/"I^tA ;0fj.4O`t-Wo:^(ƥv;3e@r?ȃBOGEm^s Hocʷrp{2YHK̔ ]k8͠\ I##LTݓ|>~gn㨎CKJƿθ߁@RUU4@pK\F8`Xs~{Cʘdڌ* MdX CT=(i4eu(pc]k70c\=~avjIcA^ Sp8|};a'dpzmD&~_0RxM- ,1S̢rP0J:3é{=Nv1qC1eBJzDfU9eO.*эGmZmGlXʭntUKVB 1/&|Fyn-S:Mšѷ c nɎI7S ,f/44RtCԻ"UXNVVq:CCt[(9)5+g|XCU3ۭ[ӦGۻgk׺߮ؒҊR®mgi26`0_Jˣ^ʾVerZE<(a+ܰZķפoG uaY9fӗ8W>2g^?ma!+'D>ߠ)n2څ]C7[(ĀAY{EK֯MmpH)|J)D&D>(96N+b: 6x|ۇog)!z6M}ؠ$EPQ"F6&B%&H"^JZe!.+މ-RQieL+2Q/\|{tRDd Eb3`ЬI!L3UN揤:nfLCCGvXbf-ϟg/g=:|F0 <xq=nMT4:LbԷ%|96ذKnfϰLN<[{ٌ!҇ww+8L^ᮃ^!PG{񟟴wԧN4ML'ѓTLHbhޙIQ>n`ymYHQOP8L^55v#g7/ݶF!mxb#mx\vʷ2t{/S#I?.U5c@ js=?"#U,~GˊR8)SB1)ޘLV+$Ucb&>;TKWIkvy`.=XkvWFq 5[Ēr>i@ht`d Ӏ y:q/uL"h1K6 J%9=VQ)mze/4#-!PHtU̜G*M(^DJ`Wrjru~ܚT٣)zTƐ֢ <3 ǼI$nҒXty^k|Ka(ok%<,i`) nYFk*K1q7`-o[ÿHv{9 inI.-鳩ʓ!dXmDd2L5ZmI}!::mMS]VoCI:A*>Gba`C٥5}f˵a$vq1Vz՝n G]e;Ll.>2}suz ^7<-iR3O&Cf&n 8/Ad^&h+9B9ѼG/vkK&"ZiW]ի@QZЖbs#r~m/RNe/t sR҇ʎn&$&$>e}|d`lhS_0;#K|~j B>X5H|w` =vZ̨ܩ HaeM/e8;ԉCXZzjvB$eU' ҇2WC׷ݭ| *g;Bzn}ϧPMæ{WSG[jo_XI_?45;2N's28]q.c>= %ڙwhRKDZ8rʀKڃPm`n9$  vP>"$~8Q>.1n~&xS愇q;މ!Նd}'>2/k#'6O+ERCa{wq;4턾A3`DDѐ"rI:T gx֓tTאOkt{3 >My3<ٽG,/ɠ{C%7Ӓp점%E@W]ugqw܇%1z1[>!sn*@ݏf <^ B:ʲdPB*G{7]{|dsGs&7RArg3vgz4ˣ T0q/9:xE@~G^;7Ui2LՄZcc5԰nkלF;D #H$@_nϷ>bL ͋6\TGy? ys7C+D}!WpƂ?j(?x[)4O.Dǜ ,z`1Lع!-cT6#;;"lW|& 5JpNG$򭨪J|Hq5Ƹ(#taԘANQfzǺ 廦]/&0~!|7C_K=3o1sǎFq'[++,4ﵵG'~}yȁ |iv!ergz}1;DF;6Lg)Pɒ(5!Iȱy={!r9kbeK4ZۥSA1DCfbzmrVt;3]pLpA]bn1za2\t`)@+Ѯk[Yy\Fcrr2tZiiEvY= ij<7u yBT%!>14y=ݿ9RN*'EH/xUaNv;0ۚO ^n gz@ѱ t:> O>"8Wd6{!jz/ )4{nqm3EÃ|.CyL7%Xm^QK7}""";HB%$\~dEl(bԜ(\ b݌3֥ڊ6Ĕ&|Z{Z]OV>m73[P kDf%Eσk Pj&mNpaE"#GP DCAyg݉s /ZH)VA(ňYm\h-]YLw⮆ /L:̆L} $cPC~N1[J|ى~,iTa3cj_t*Oml~z.[~`ܑt_k޲-Cqsӳge7YmiAwbza*"0 cĜۃe٤HY2p$~PNߏ*v@'HB&n8qwP Aa,)Wzai^co}l\=Vd@VHWh%"fQͫno([Qߴ =i# qiu$kn1\[Y@TD AHtѦ1c`k}GGtHRV@R8wx-k-*m[3nה9mҕ*QʎFf٤6-s VMؔ96nzsU*v`Eb luUvb_oo? =~I)_ms[aQA* Pdk4=|T'ٰeh9GLJ%9pom.ovU=$ 1U`]DldbG@[׉f-~!]$0"]skA(swi߶P-Vaʥ.K!m<%h~,Kgy%x]p|y^ntz=XfنfNs+)D`|NmJ嶪.TY*B@IKJ,N I/H^Uļ5ѵ:^gx}5WdT-6UTMkٺ6d6sEګ;+T7[ 7sq(כeyTz[ 0s:-BxE4L,qDN ]چY4c:f?3`?u W*-_r4KNTw@G$|?SÜ/՘1}m5 KrD$ZbPJ ]F=R0<8?kː؎ gMGDUP|uޖ58+': zՆڱg=<^(C@;qvF[rDmAWxӧwgLOZcu eX`ɐd9OZ^!TvnKiߍmfمX%i]C?'{Ћ3w[8J[)$"T@qwa%LPm 8 NДVbGŽEn%LmPe~YK0XڪHC]ll=rȪA& LGpn4!!ٟ@ڕO} 5ԣ+_۝(D$TԆ;mN͔' y~LN_YS'%-%hOET -+P!޻f;(bGOG(xao-R~m`ċ2ll\D;蝦Wsou^ p]ao.A/&$Wf!{}?Q kt`G6yb'9GK|I&v2JJqkkO [^k1n pE]Ym^,3".o:Dݖ@@YyT2Ds tW`Y 6; .c;iS+"p9RfQgw/sxV0aI2SKSemEt ca!.Ő%4J%].U6l|v"=aAݯ;bL[VH2 TҳLB`h6mC]ِD@+Da0O@az}f-DŽ蛷E6Wn\ ٤+ƕ(V ^3.] ]!Cm;ޏK7b!g7d x?8t \c$Da+i s0xERUSF-fц!̯kL֊ޜ#DwggU TXh_1`Etg`UK[`8tR n땖S0bپ:5f@Kk!띝3HQ=I!ո21xC|;ȡeΌAT0,Mu7jZ-# _`ˣ /Y)v?5h͒杮30; &:@2" .X 9dB9l*sŤ90f.zu&T1Nm4&A(}+gP<ۊ(RU/IDڻ܀iK41op ,Tv ݮ_zb12e6GɒI)=GRP>wBRJ>P%C\L׊DMifټ7TۇULu6)zz}Xio/duRHd=K&u-R<Z|aD~>Mn!كe%bo1<-F^F/<ٜDAef 0a!/`XЩ^JGɥ"A3_u{V $ ͹ן_/qTFPRƿU1\AU03qs"X"F> HݵϨpAZv)n80pTU==:A}~fh-!Ӛ#ijţy_99[~rqe& Lm{d~s93!qHߡG[e/*wv7Xʉ҉h!;MsoXבYkW PPgxxH>Eaw}P+rFv:c]JrV; JNc[؇u9u*èjNV:=wj&I`Uf2'xC/%UCci6Rk ^q&";{"jLd_`8̂P ŬmZzs~]~ʻ`؁!vҜWj!޹Ehl>oRyL;Y!F_/!QM(G}ֱE4u2?~Z9 kPA)@i!]-ؽu^ #Gֺ(6>TLokf^:/'B4̽\Ӎl;i:<6~i4+$sT!*67uũy*cIc: l+a-emOď:QMMkЊhؿ7.:^"y/ %ηJPhԁ ^laEЌ`p!\U^\Ku*| r8]eɯjb!0+y"?48og!v;c-98#W"vqŌسy&7ŲdB(D -kN.3,%D ,.! ByRxi 4] 'lή{N:XuG'Wp7xskFnK{x}\pN6l)l%6 v,͌n{% ( ?ĽlS5#H5EBҺ$yĪkd1J%oubR}l[ٺ4f A| B OZ&a8a)\֨`4 (}^[*Fcߎ\:wvŽ6 `Df%ϩ2~[dQ܉FÍPo{O/ȠJ:IյNf*CsH$(uoAs~\#hON!J! . u+UF=[I^$opA_B¡fV` ̠!~ 8Dm  lUAF{6%aMUϗ,/݉/O-}m[';9ovjŦ6-W"DC"?Ċ#nJ@{[8vͺv/Pq vCƽNdz$cbB ͵h&֣1Di3˻nPJӡPsDN,Hlj`ZPjc,Nl#'J%*Q@rm_@g`4>zhMb-qcstfA#)P+ұQ.^*VĆXG?O{t_ԥ+_"R% b#SgF>&JwR &d|O.Kgwot$A|ZԡX 0,e7`Agb nK|qt)b#hJKPF[,Mܭ.ڛebgwl 퐃i{5"+1-)DEdɭQtG"h1%_o~4Y*ol.$N׃ωE@`ho՞!GXT @ѱZVo<eŒث>I۔@5{d/cy,`X0WbzG9rCY,{zd];Tb"(@ԮLBQ>>crAI {^В uOnw7l854~eó{>>L}GlhedV3oN,'ho<&!:@8DACd3f0' 0p5E΍c璡;`qUQdvWᶁΓ H,L*p=2{&.`=H"-8 *z4Gsw0Q˖ˌF@n*&lJE֛uNT>vay Љ0Ht431*#f"78g~КElgvf [ʘ+F(jQ@>;cm[RCA@A@P19~De)wRaR{lٵf53džxc=ҟS&k^hs55esC:[RzeL]a}+pGLdFĖ8Y-cX0K(.n#T*<dJLTEK,Z֞ +>v^ogF z [<~q{n]ł`IJ [ڶm2BBW^k\A2v.9p 9adȝĻfAG^xkxNJMh qw(SkP4cvx~`riNJDQInass{_(T|Ħ |%ul(Nf˜䏋Ѷr瞽B9oB99֐> ϸV' sʅe`cޥkC.OKɢAHPu+*,Ny XGGlh`g~"阱gW}s pͻ9|h <؀'5 kK2H)p6xum<{9蝒|"#)GɤD1ڀono7t[cy8<>)^+l" 8:wuǷ$ؘup Sζoqyy>KWd@ 6R04B|b"3/N vLʹn$}#I::</U`A9|LCѳDCsH&msIJ\"&m徶:x .m'Kq=#<ƒGI$._3 @Sp0lhۿzmmvX EX'X0HIpCmՕ\ݕuE/IZg ܧ1m+gS˾V€^ۻ2raԌ b,4$7tvY9!#:of7.y`o(}ʐc +$/%4[T閔 ("t p-o^o$`S!׮U`wfͺ >i2қɤO? )#gDġpA\$~]16c,f@^׏,]p9}y+mYs&~2Z5N'f:*'&$dx{^#f(f p#ӈbPsy:0 :6uT]HHU@U#ePxjV 6-y&l5,Ң%")PWEέa"Lb96Wbl9_(.T# JlqͮHl3f;%}]Aɑh.:<b6իțc^<tM нN15onJyJ-o; R[|ߴ*մ'}U!Ĩ(Hc|/Jn<$ m=}Z)1 ~;qot `erN*3 W<Y=0NӁF(8#r41[q۶>D-T!DP}]V -/"d}i Ss֑<u 3]KiAI 9Ul?7[3DuL8QV `+\,Z\uǩ^ˇW.D@hftA$h"loɛ&´0HʯƉfzxN$\UIxlՎC} (aW.{b*AFPa֛D]@t j>JqEhsgs~VϦ)IC0gZOW=}sedUI֪KDRݔ7wC|)n=1f p|N|l6iR F ٺp}90@ )#=\дnk7Ҩt{ Bg==|xG2&oOY>˖zlkj2fGl;h^cNmZ$Q#bn<$ s')D4C,ǟڌ] ϰ{,\]ȵmmkF?'li:Jfعx:\CPMc\ݚ]{ZD?\pYL7xs_ 0^WqWApou d%[ISEo`h]eǷd++:B6icnKZ_ZFA+Ά53+ŻX@GqәhǖּplOyR;RUvYxJMڸc8P0;@w:#Te@cgriӜΩ6< {vvj6{ mguU^ˢ/N"xm'sr\VA ҒwlcXlƅeډـ:B7{[yHK&̜@}}( nqfRŸtQTo{ыW7cJ=OM:|A ;ϊ7w4u\TF+ [V!sЋN .$-HnLDMV28E:25GHkki(݃+߆Q[ry؁ \iQ֦ZZn12JZux6jcaTMf3sD 6m;6];/V]V.٪l%rP'h0#s5'CgWYUpiEIcu@j{Aԕvrqw9 2db6. 8a2mȸO1/ߋfX2Bӆ:%=I[j0Zm\,ӻW~,IzN@P mG[ŭu2o NZc{ڛ]lT$Z$J%nt z:7ߙ㵞P$v3S'nfqZLbja.nyb=a0\롧ƦP>uuʛW_p/8cɜ6kۦ1Q=l" K@ /[l3݀ʢ+{k\xm.QܗF3rG2zj2FIHJot ^4)tӍ{zD]yڛ w([<m 7 y5xtԗ!׷+~eQ/ߏ{y: qڵL٣̀9T61qc-v!0Q"؝Z>J87dtÏ+fe뱘lbk0t6L܋ŗ1^6K2erۻHcn^_fAʖ]oG lQaetT-b^f֎0Fv<⭪~qd)e{/p0It[0#nxZWpK5yȻ+QO|B-Ŧ]0f-Nn$XWΧ{ޫp cf*Td!"7<;8)b͓^Ph͋f 7役H6Uz7/ZYR݀fmΒd7'8-b;m7`j[.3H,l ĥ.fm1_(T:66tC.*(=b-Ⱦ{Ǡ}l;rtHzgifwH.rsDtޕriڙu Gw.|X]/:u";Vz{.sʘ TV:tqw5i(Gwf{$/ɢ.lum,sV2g6key9b b*,^Cp8Y-q{<+_v[8(2*aݩ૮ݫvԞ)U88ټ.r C`ewQ'^`t tMܯr ri۲Ixݬ5^{R^w)&N:2hB 7ȣ=}$gb,['lzӡH ͎׼/p GEw>o [Æhldߏ6n5Ӿfẗ3=ƭςYd[|WJJ˻z{d3nm*Ho(a m pk5(71diL$I ߋPB ̪؀jz;ȉH9)5DRWo+ؙ7.+&ܖ# ^}ݵĈ$R,i]!^Vlՙm[ `3,H7dkYSwK5Z鎕s'$:\m͍Ŗ`&_/cU|&z3['MJ :+E$ڌtWgP ۧr|\1rȘ| YȪ1:Fʺ3G02<]of描sSCp{Aq:*=EVnimɸmh]Wof&K0PGBUScn^)?ex*ݛ8c(u]C!B"E`EC&~9[LD`7r #=unx4_.[04EzXgVƤIDFI}m=۶lHrوp ˍ ex ZP呭0܊Bneh SjȔv:8fTRֹ8<>oC$TMe3Zޱjb#Q !ڒ`qn҅d%E,T9i:gNx"g^ 2`df;9h<4Tx"CKfI0& J]w;NrxX C\ q-ckwd5\H@:z^ofbȿ̈KORG!W~x'k$+%c}җOwa7jDݎ67CJ7L A[Y,[F=jɤ(<s,byv8@ڊun^0tu4wxz;tM!z|"i4>HkϠ3Ro劖0 Hm;Үum@Cֱ6y3/@kd3$2C oA|N.oFs5Ocժ|BHIߢb(.u@ @^"9 ֻ YCNa]o+WC$uTAET0x yQAR*a?F*yQ$@W1ي(Ǔ} E.!uؚn(ob$!"HDW6tCށ.Ld/hY.D^]ձjKX!<}'2-ug۔h3C}}*u}V F$@\,\GW~?/ǏL^f,WcңW¢l@|h(JAOـ _.( PDހ=(E= _;D OHy%{n2/7]Q?b5}7g/??{Ŀ_Ba,l`!.?k~L≐?'$E_KFMuwPtN-{Rw&hT{e>!~fi؎ #K]y3(te۩R(|,֗:k:fι#q!HvXܧ!9,ŗut0 !؛2FF"00RzXkmB7ޛ{5+nٜͦK " QbbSxЧCȶ9l#Tΐ f [>gVU a\w"(uQY"> j#7>roY9:5zN=╳䔀{\Ta)f|^D0L,0Bagēer(,cI@ lCfdEp6j>W݀1}*w;h],WFo<(3}=ѯdg:ɱKQQU+h_[0=޹>?7nG2! 3.Ng{0gcRmõG%m]m^ЈP:P:/q|n=)ETiëbWOE6% I&ܲQHՀI$R@P=[;GT29qyglQV{fDXRͿro2bm: tt`=r2@ I-P9/FǙ?6=<e聳ՒRrW"l^0bv%;&͞U>P-bvB’4a:|A ȯ8 U[;AHÑVayt*RZÊg1z9xHt6q`L7Ϯ!Ry$l}/h!!Ŵ:@;:** t1`Le)Ҍ=cU<;3|P1Z}*6iٔ֔=F{~t 2,yh#GZl#UH4 ki5vm ɏnrZc˞tDÃnJE,?[Qc7O<\Q*,+Y6y[%x`9)(J,ol(x ̔`4GͦeyUTݹZD|o!67wj/7ܳvX-/tEQdR#My?[|o/ TDiD!,M]M_nǟԱI|or[.~8&fonL$%lTcm4|2>q  u$1n}(h"DhD|%'6.1 r#qt"5w}$p0p4eAN- ! tq)5r])7YWb⻵<[T+Vkgjf(A?]?ma HD9nwBNc9;NY5Mg֜@U΄ ãWؚbTPi{y(2}3`4&)}W Fڴ@ /Oz&ait]tv1%?Iކg`\ZPAYi2lLO]jPmKznϹO?WG-k&'A.IE?N?6ZimE hqԝJ:#TjHE%.T螤+Ĕa[7^~[\ "" xkKGu٣-p){0/6VB* Ҫ)_Y˖vJ9}_09FfmAECgd_Ǜ1t]tl ZtzW̑Ӝ1 F效! >1{ 80J˧51u_5Fۣbf}2D iE!b/wv62&j+"1`(1֥A=`@P()]TU"!ʶ婮dRU=6Ma|[kE6+Jf0}=L3`.%ݧ f !#ګ¦㡶oh[\7;YrYUvTGL7tl5U&~'SgLl,YLX"`! 3n ]"#:dBh^j}[33qA[|(ÄY2`;ϖ[ϔcB #I'q/TV@-ckm\]!{ʞ!_n.&eŵC Ҽ\)=1F?[`w̿etXO3%@y߶o֬5MXDyH@A$"%tIsPmҵuxwCQopqĥ} bp.K- ʶQ4FX+zcͱk4ŚkJML=#ɹx RZV['^8@CbkԈ"j&/!/z||?PZfAeh-$V󪰤XTnl}o?4pJPA"3U ..7):V[Nw$2 Nyk8w*;k롃,8n#DJ X0T:y61)TyR6:cbpK#v2idATæ d6|]v7"rũ9~}N*,2 6ȭ<<4T5EhPv !TD?eQҪ:*led4Eg`.: C*Q!<$ǽqSR( E@Q (b@RREw-UOgxYnQu)WUt(=vUVT] !NEy4Cb(t 26L<ꃦ_Y.ET_>??V@$M(?0IJ&,Dk>uI"C-.2aD8"f52"~ ր cD*ɪ Xe#q%O>*tf>*35\&עvYԓN ")CSt^fқWܗ* ޹ x],IM@-ւ Gb:a %ao@ ųCFR^(ݫM Oa޼'L>;搡 |oΊarO6;:j&j SMqFRFëm%`f4L$UքC ڊ\K{Ta4 ͙1٩&2&6q9T4Lw0x6_a6m}\f ZWNj84!0:aٔx`s7=IcGFoM\!ÙwC+& ;k疗6 Ԉ uы-bqΜS%o2oN VG?Sjٿ QF] 4pbrLuRgX~5Qm¦%>ҔHOSdCl֌;kCiXGԮ>>Zg  =u$U9/x]U0T%ѨOOL1Ire:sߎfF2v&e d9}+b@h4ԍ u TOH**@A1Ȫu7gʣ7almx$*H a{=R<ҁO%ϳ(WDS eYw 9YW@Sކa";30Įڷ7VhnϵuE&Mԏ͗Oٟ % qIEk0.6QEk.ݨ ga ,(rհחod//GϚx=(6S}9ϝQu%s ,R rr#픒}w8/$*>q1RVTöF 8I;x-gpٙy=Hg_M."Zb[ ΞKd/EU)/pm͢Gߪ 3oĶUkqe!) K1C*lTUy]Xs~QlhmHȒ !eDL};qu{y56wmW7m_z"żߺapoPAԂqo38vJ65jѪ4Z"Wjlmj5%QMkM\njb(v,tB@ AU4{Z:!phOThf7)֜0UKa-nC6% '[+4po1v6Wj\ ͿXVqTkdBXZe0# (iQ`mDQc*lREWV9!}iǐ;4\d^LQt\1mCȭY&@l>9/Ѵ r^kVY܊!4f05.Sua1YrqgI*lQN .Hw 6~ҝnc(.@C +W|B6@vU@PµSϜF,.ڃ w][:Neb`5Pe?>OP{M_WAvyPMMS,Rq+EVE~ Cl5p-UvWG"N!B "26_UZ#hEEbKQFMmTZR[d4FX6Fj15EEFTFQ&آѭFE mFŨ[XDm65FclF4j661c[Zhڣb1ɂ*+m%cEh-bXFѱF-bJܤFZ,X lQFZEEFQY-EZŴmZ[HckXlVfTbƴ[ETV+FjXV&lbѠIQT޷}UXkcX(dmKcjmZ֊QZصTiMcQjVR 66=^TX֣[MUS#cl"h4TVV5FDCcZMB,הKr-bmX61bƶ+j5i۫^66ˉ+fv(ÌTDV5jEEhbٕEDC9MHhHc "#QcV+AkElTUbƍjFFUE޽[je-MDɈn@05RJ$ֽyרTlZ6Mb҉~mȊPp &PQdRhQUpDWiGՂI \U iKU% w-I?gG3Gq.Gg++>b͗>܁C_sʚZRvqИ6.|Z2xL܄&CPksÞ7s1dooۨ(FKne~+WMq{aףb~yw{w/JnW7ڒtj gLR[k%M֡gz1,lh|dtG/CwMLiRಜB.ɔiW,ov){3R,ϓK<$oSrxP_"Q72TO-_~."l.?aDQSv7yK+,9|ۆy*U9X U ߀4aOašԖ5!txzm?T8LTW#Iiuxj鳊jMbGwD}L?D>i~wrm% ۉj>E6r`˅(/'r$9> bNf~اFo<*lPe,hڠLq1-X}-6uoO\MkJ梠[(V FHHRkJOš*۝":}&֏@CLP4d^|/ӭ#-hv&r:}#j͆k:HEEb;aEP8(JDRl{d_Z}ќ`O#qݚ& *Rg˥hPTs\6Ԛ~O4V >i;G,l~j׾Om\;P8$2讨*|IH߄Q#Kț "3aM&ل|/- E@'(}o,W\6P"xjɱ Gdګst47&@3b vL(Qg|T֎AqpJܐп>To j O# 4ɏH@ؠ>Au[RL_1DX"|N ]?bh\: /m Xj,)9CwOvx=FL?ע"k[m6-l/1=W<2`mn6ɍS0fFN*f(M 4 Zku9 WL]̩ٗ=9Ei1 k(78\B[o韓( ҄EܧcwZےxժU44(У({SX`0[~#g ˋp*$.QĂJB sX } tzvSY4+DSo4bH컢kծ%'w2x()(#rBnTf$~B[0$F#;\i2ц$[3if${Ymp>Zm|݊9ы^WvٶP-ˏwn7GFIO lBZ _"=j%Fh3}B!$$Z)v?Ӟ>P /{ $dsrtݑγ,IWhr :7C@nSw J(d6G?pd&*SD"替ebIwu-H"&3R}MگuDR(R\i<,E`&u־3[n)pbNr.vo^OȀ@m]3^2f`=݆t>o7ѲK;ۘk3(3˛普[\d9DR6JVc5 %:zOVS''EWFCCTl`3T-,:1b[y7nvV\pgi3m ~.(eY=2(A%cB4IBmtmۆYXkQsW(]Bcv ؔmY|<@G!P1_hLgiX7a$ӂ (AA5F=);wdo#][mnqf30~_y56邢ƴlj5mu@  Pu]rgq=StCk9A}tvـHWwZ,9ɍ_mI~I?@Uwa0 ٖ[b߷m-щ,5M3Ҡ3wؿwi=}2ʃAPdSo%ݎ__t7 ˃yzo3Pe QAojͳmͣT)(-ߛ"7bS1o;'1@Oַ/`7?Y0OߏTpQdcER+H ;ZhO3dbE``#u!Ŷu1/w!CMR8BEd S G^!H66Q*"XEޓsɴx_>& dQ|U`Bt[(:w)U?2P}@%OW,*R$uYmsf:5]b)Ü&wEfj&f 4D%֞rHRQCHY  ES̊zk﮿cz[ѵ$rKm}͌ E8otYHy~}%|K~?xy¥qPE$z/7CIP愉}悷GHr(S"|&f77G?ش~NTqvc!YƕI"A*WZ; йݗ?'BL\L HBMi)۵ϯd=ls~ʔmM`)5E2\31՚ WҺ΄\ow@XGy<NF.m"' (Z*tkyF(Z?Xھ~7} &TEzf탷\1&}I!8+80 (ii g2fSTDhL(j6׃w'=1$DM*.K0o;<$|\c p 2QOӧج%= H SP)`Ӗd/`y}H|}Ur~&˸ZlS&8KJZLGh૛fs%p}KK'ѧvHTgiGs#ˢWřeq/=ŶʬV,iO ŒĬ `ĕ rh-8ފ 0B j~ՌRmZ++&Q6drM\wZimbeUJjjljMۭ,BbEͨ0MnT5Y-GMnJw];00Xmm-\RjmIe-ms]+.yEjMu J dPpǒMoVLUWJڹ#`b̿"̼~oEf3mȊDvJ:)!Խ)Ɇlm dp䷖}+$9*y'&l))WP|Blq'U L5G[3ulbLϜaFa h~g(D)PnIIΙߖ%$V'LЄ$Q0V }bBm $c~:5pVQ!cwN-,{kjo)H:uU"Umxtcv %1A؝Ƀ6_?;CRql3 ʅH #Z> ="{U] O; "c{WGB>-cYz(PsRM*TDa dFPVr͋2~KNQiV$rz(X恴#w@^lꝊ˨Җ] fn:]X b+M6YqGu^ǹo`mq8[zTػ:тBDs^Brܛgf :OC?} Τ !4ʖEXcԆ#l8ALU.~kC.vn2ps<6RbhD}/FɼbPLeFD(090 -ALaz 8ƚLC'*2~ArkPŋVK6\N̬s^APaߦK^/<:ᚱCHXYlTyB-J>gKFO/;Ί[FL.:InmܒNg!^m,ccosd{H6]VC`镀)"Ľf;غ 1z|%v$gLY:RT@nS&&o lC.0&ڝ{xC+.lMR :/7{- %p RCT-,[&#~l2$A*JJ")@H$Q^]eWÕ`k⑖C9k͔؞e";Z:&'pDEdPQT9YלEnPykf^Z-ԟ;u׌0~tɈ$$浮V!|J#U2LŕhL16Eh|8 1LI:+U& 5$Ib=ҳɋgw{')̓X٤rEjy{fu3r!hZsQSQͻowDGf><"P$~]; YlsLyXdxv|&\<ӃT3Y IrL}qſ>lNdGX—2 =RV^fi~6\}~lGq͝Y@a1iLn#B0ԫr)&XL"\CȈqXםޞHeP\DY3YUIH @tlpz| sU:f5<=Ly{|PP (,(,.=3w2b kgCjw"f#Y<)Bܫ3cך|$AL|>uyEkٰreA2ݬPe"{?BlX\:(W'AﻣIjD&Iv V)"΂>U?t)wI]ď>$\p(Aŷfl;E-Ykʎ#8PQݺ2N$2`=[cbfs6,pzCpھ}I!j8RJoUmZ-&ncށ3PsʨsT0eVz]_ܥܰL(d43pʇ,V2鉱F7ÔgC7^OuÎT>bf52dQ6&HaIAIy˗vx[۝d1QYS ,2\V)[ `ܒ*j3{n%y{N;6cat۹3w⥍b[P{ù@|czڙL_Wvlh ~[neW"zk%u=:-ӽJ {.C5;jZ]ӛbg>|^J -LڔE'IEHk$vt{αF?E*E!S9u>{c0PۚEz̷4yɆc z끽%q61ˆ R#-)/-آ,Em[3znc_CV#1_p˗?;aS3 ԎV; (7 jo'λ6s>C9oX[_ 0꿣&5.(h) EI% ]H(¤Pf`Q<섊- .)hˈR[bh0g7l~bA58dzdb8H&MR'HtwV;"crw;Plfd;zvnft/``Ơ (9_%t&v9ˉg}N;ݞ=,C'aG׹'錗$ V@=}~=^U7}.@O=ز&YE>yZJdlCgm2+*4{G`uu͎]xeljTDakdû'Pr֡Rܭ,bGn0 gWЙʵ536Q-|YY6b* 54P)DH2̖K(,p@oǰbjDDٿz=NĎގW[Fgxx.xw2M6QOJڍF{TiI~ :^}-cHN>9oۧ?W.K!mAH~[7;"yOsaB"9v3l\TZLB(e,W7wn[ÏBJNr1\˔QJNaN\z?bBtfoJI!ѫ%2&h ľ~,ǐv;'Ңo6Wr)ږH(Z5)ڐ `܂"w~"jAdXI+(P "/[52p6{jP7˫'s\/y}*YѭH,yqW&i/qaO(5ϟWVXJzLYuyi.Ug-ѥl,#6N2&KztP6؈mm)l\`D׷yսIY-lGҎs`8 r=_I˽&(^&CzpL;f'9.S[0ruBRܗFΒv,ղ5l0m.Q*Slu~';ݘHTY3Y޹homq꣚ |10CeCKU-283l OYA~.mtgcHؾ=Rzt$<#H<=7raNV|H=0fL `.ejMMԇLpbinک[mwFht3Cjcl|/_]קIe)}LeIftMxK!3яQIg<k L۲i/Bɕ]:S ih7]j#ׄ 1dsjCYN@DtyFSn&-vl>+,\zUFauƖ-0ڷr ]/vggXsTԨozHT~NئqcO\prysV7{Zq_/ͦAy9#KnU IaDoR2z9 9ބX,3U/Ŕ//xov6OKbDݣ;5)U6W abS:%&j"yCt˙uI`L}}~ rd@Vz4R(>76|>r3AIfI! AG.z!9^.]9W|y6P@ٕYZK]Ӛt%ayԦV +ȧ䳊N}zj<,!an1a*/&eVGNVS{@gV0ͷOԔ֚ڄU(gVkll<-]4Ш-*}u$v9FeTC9tRȯ.>N ˈ$o9 =8k3p; :t5|7=Dd8:VK:\mŽ$r( M7,n ct͓Ây2M?;Zh }MX ;w,gkpӏkL0Bxˣ%}3u.=ǣ*[CPʆ웠zȺ--+**ZֱLzY? * (.KMIcrD陔%Ae,\,VdݹΝ]bc얌DES}CYe-e#8 cE$,դ(Ad+&LdݛUͬ0:k"cm(OhFł')[*(R%_9(|yse366T[$˔f^)рTgk|OL7; :> =!s7I<>/^cq7yz\ڟv*D,Qjtj]g!'zT+U?Kzl-3X9Z!^Z>)]ZerKhVYas20Xɘ/Y$@ D/•z?YxfZcq7KHq,O2ߎϓrw]tk< es੷;ɚj* @+¤y_FΎ; V;vWhT,aRZAPB'})wgjcιbŶi"6 9IԯϞ[*G[la+uӶ̝Z%ZxXQD>gamMM9__}l9 Cvg)qV_H@((61utPW ;Z*2,Sli֥Q8ٔ$7mi-bTK fB CvLĎkz8mTAC'N1K5g?S| ~Rh$%i4ԙDcQIHiIԩ!Kc$hK2QE!0"{\k1u]h{XܖXTv!iP*ȱ U8 !]%I)-jlʵŹkV $G̜BmYI FQK!KhR)zˇɀZvЇcGm/a %g"*%fI"%oE}TKn'7E8E\z(/*Vs5߬@ojT捦`&"0UҜ'e2Fŀ)nm.WSr꣕ 墊"SAJJcj*ǧh.ܭobUgh&{хGgfo?tq+n-skg[EmҊc*kOKY^օz!I%*AJ@?5Ya5'b8.]4tc,4h88*CI d--,Rbd2V?xlT}_ 6.AUW(u fNQX5A'%K-ZVX[@~ɽ  7ޠLҺr͈`csj|VW{ˇ:J쩖(g'."(>GBK:#ѳB挸gsIW:I VFwso&)CssuۓtR>O8Y,v`iWpS{Y{`mg>aXt I!Kɲ3dJoVխh:ꦷ7Rc1#=6嶶Ї>Ge7L94s+:H^"w(_s+04Ϟq΍(*VV1&8qm.9wqˆ&A , PLłfD+sb9BE~s 4!39q 򽑭o(jNHfeiՂ_GW~_Rc=~+p}ͭdSB$YoWq. Y,)ţ_p]JJa⫡p~{ȑ\L9Uqɀ7ՀllX7Gb1L0^YHs3)tX9M^'. F@zG;#L0Tp%q|_` (IQ.F1 :Y7g]WCXW[v+:U>%X]^"" k `mŎ(H(8.~cnUkKv鿤% x"1LrsRj n2 䛆Չ|cB͂.F=sQh4}%4GciGD<%АN]?:1ZΠqF< >IIZ;v8miiغՌTNXR,*oWuЅ b2句k0WA>w}(SץBd11Ċ"aw=|5rѮZ#)+jҋOW)LҘ!B 4Ȋl\_s P!kOAכRyoBYR ^x>+{F3 >ڎoG v8Mt.>XslƬ80\ =>,} kxURP*췔+RZM?2]>R˱δLܲ9:D륍"p[6#^Ro3+Ni}LH!T%E^(Wm(Z=˭;F%PH^t"A_1U5O3Vϸv݉ҵFBa18x<~&Q~̕=-> Suuqj# 4eڿ^GB{)5q☤-_6ā(Mj61'cUcfC*oM\LN8w&әHTjki\2iKθ+>W%5;fU:K{rbiH*u9b]i J)/ LcRJ~gO7V2O$SzN괾`߼4p^/E~/!`3HB>KYZ>\OZWJ]G=12Lͱ4)G7Z7u+^3a1Kq.ЌCЁ '3_&_l&cT1*fl dJIe>'GxƆ91!BI@ c>a36PAM3; FJ#1DC, _ C#2.2s[ܩT#KY_8&lӤ8ZSAwpw;4ܩ9N8=w::@&wf'>ayp炋 ߫$ OƇ*  H( f @ 3lN=ܲb,7bq}u"XAr,zrc a ,`vӺkr%Zm  u/ǎWWk8qָg?4$$!qw2DǕmWX!h 8H*@݉\knknm=_=.q ŴBuBJ3Y72fqwOSt\ v8u>&ʈ 2BSQ=\eŘ.rli H)NN>2d )VZpu3h"v$*r5h;Yri#棼ϻd5(8<f4Fȹ܃4{G|:޳NAa@I!$!ԅv5)KDB U%V:UÐ90EdXƓyMُ/srC6G qZUgɘu٢x YXR[_o{QdLE7ca;0 S$ d`y Nql+q6T$7@2u,{4e @q*E+ cϮ;F+2wMhDisa4m1a<&0o%ɟ(%ɪ*ޏpeuMuh2<A dh,{d=Yb* UXZ6nJ} 0Meb 4&F!`7qviڣ#ӯnT=04SKkO͖rJ.ϡM7cȴߏ\}M`쭡s׆L pc 9M0#>M!8 Lylϰe(cˊ]YT+;>{7"RH" 4iYkcU[eͺdZ% 0.b)lץh+݆<~j| k))8t@npɹc974PmlhdY:*!DIB鼺{g8xb2)H3@BC\q庒S6(D~AУ0ZU&s+) u9$+=m*剖Q6I'ezPVPSVTjmҬuRbj B]xQϾp6;!?MnQba_F}דd[^`6y/ olxf,4hl xaQK8gCAq~.ϩw8l*{PP0N,1esx1E.R0vadnx6a~^_?:IʪDWDZG/M]$&T2:]$1l!w3ǷpZ\D!j-6[4I>}[t|߲a{xKH1$@!Q∑9+HO\W^De.iz% c8M7\"arIٮES*2$[4̬=B,f7ٷ<{SM#!$@2% "}-&tղo(Gtqݥ&~2DkFhņ!۪D;f-:%Hv+QL7{;p5PUn"9&r"3v6 ZoE7|)J$H%HP ^]7~ԒMj/H@H'QWMv}:A,UF*%{zokKQiM{n/;L'qJf|Ng"|W2[zx)*"j@hZ! ^ØV~G&9v6 ZLw5B0EFQw)s q\JeV!&F@F$c ^5S~O6@#R'ɸb BF^=/m4zvK$R%!7=$3 :z7|лjR#(Wf{RT[x0swil"LMM'7Ǫ@}wA{YюD9zww$0;l)}:S)2(A6j4^h % 셆6al,Wd9y{!iùRypتPF R'#ea yn,D^xp м?m$ ƮJnLM%ʘޮH}]iQzQFPK>&=6AIw/4EE1\?gr1'5C,wK IED 03f+FZ)qꓺػD6٠o3֨h_qAH>SF$LBKnw)Nd.9w2ٱcص23HAٍ9Qogy> ,s;yPgAł0+}wn( '3S9mm4RQȂTF햘@ :6<1_'0*n0AQ/42*G#R0a:ĄfjQ;>Gu7V 8NCnapӧ 3;ib! J#s|mU\S&@(|GnD+*H~D{W*,%m.xhfUP58ޓMV]$Mc&j0X;'\biy~O&ϸqOIg)6m@R%\n剠Y LJ"Q,nnV QO~7r0rÁ [ҷ{"ދW[R5K1hI w@|U_!$|~7Su'b1X<o rR?zmo-"s O ߉*/6(XTE8GfX>oU7Ճ4Jhh䉱QPCx"Iź(ԏlpxgN}j_>mʣkWmiLtSu]c|XW@)<>lO$ 8 ۟t>MslEe)oV̢[g-ܥտ~G]q3,%0ՠRH=_kw:eU!;,D$R64RRDi0%h"""j-m%AFdQhMmfQ1EQm1PYI*6- Qj-cѭ%bj-X@j4V5!FPkEmm#lhы*EDF(أcbPVKcEF5bFlQ3c4XMdb$UM&" 6 Th54KI"*,bbcF40IlIQQQQX1ţhXԖ-chQH"(F1J!0"RLd0j`d l`KH6I)6RIiEh6`X@Y1 c&BmEY dXb(5Z2cliT0Fm12Tj+( 24+ņ))*5F) E!&Қa5D!dlE`M(5 EI&6+3A1hElhQh$&"bBɱE#a$FTT24F"TlA%XhJb,Q)RʓQF$ڈck3A 61E&ѣRV65MY ,e -Y(TJ+Lf(b6bŋb6L h$h"i0MƠTiH&fł"Y36(0S) b1ѵDi+dE4b*hmFEXI1X2رhEE(BQh(4bMAdHE6 DTYEQ&H6efj6I mA*h` ة64F12DIm$³ FI$TPc5`)с,A`T2F$$CAF* ETXfi" Ta5"cm4ѱ"(!lT4!lhōJ̢Q&fh,QIdƣ1HT3`Bشk&TQ4k!cd !`#lX1ch&6ƤB$$#I`TEQPXa,4d(hfFb#lXQLE2bU6#D)4E%ƨFhQh1#Cf[1DJ*1Ȋ1b,lBH AR lbJ)1h[b65Lfh"H1)1#"F4U&HbJI! ,Rj$BjE-b6-5Je0" Ql$Xeũ$QIV-Z4l1&1bla*4Q(XMQ2Ti$*#hKRTmM"DQ,H%&lb64D)S0jɱm(#dɃFBALJ2E60PS*1E[kc+3S`,U#VHƱF`lTEXXFJP[Iѵ lXII!M6*-$PFDFF5FMe`d1Jlh6kEdDhcbM!5DHR* *65SI2Y(-L1F4QEADQ@Mj$baE$TkEj5ij$0dBh#ThI$f[RRF0Fج4`ł % ,QcjCb(ZFє DS,2651 c3P#m$BbF5F Q"bM6"صEP6fɴFIj2Zb6!j*,j&E J1T4ъkJ*1VJDHI$DMHEК"Ѣ hɍEcAQ([%0Ѷ$,I E%Ih1dll3ii ,Z5IRiLQRTI*"DDZ5DIdѢcM$EBň1 4Qc%QCh!&&QDcL4Dc&d6bd4Z)Qh1YF4DYBDkFQIF`1 eblKcDDZ(EBmbI(6 *-AhTFD5 YJ"e4cFE%hԖ&QbcR"0l6ڊƈe60AC11QXZ(bDh6MFTfh-%hƢ-Ѣ&b11ch"$ɦI6TV&Lcb DQIPm&3$,X1ThhETj!4Pl( 4Q*"ԣɈԔ(5Ť؍bQQ((64j*E!hٖLTRJI64&0LM!%1h1DZ &M%hłb (*iԚ) 6db3)jJ(آň+E(TQFXlPcFD 2bbA" fdуY bR,F4CcYf*+Ƃha513.ց naLR!PES+CKKTkνмu5yn6]Rgq]\[S6ZMP9.P^FҹX39Wy`"[$QR _>^ey>HV,,H10w,Ut`V D+fwc)W>Ox"B!5` ZI2C;1)5EƍkiLOQ0U#OK?;вmuhaTa5pu(N#qZfĐPbf\`+`=} ܴjY0a)QL5ͯڠqSq>L(j,sN$`~If͹K%4h@v3`&Ic"D{3ø`=~ނZDГPF ``JZ6J5lT[(TjEF$DkIhE3F"6(5DF+, dѩ1#F61QcFR2PhLj+TP@@bI2Rd,KQ5%DfkEL"IkXH$"61 AHTEFhL1h1AHk&)6*5,b)Œ4PdQjK3QI m&"b_QjLm%5 6%lb 4lQhDU0R@b"AQQm(k!h4 0TE$A%LFѲhciFHi ƣFQ4E؈Q5hITlhBDV ML&ĔAlD4Z#YR$Qlh1#& `QEAL4hEEc$I4,Dm`F6eEbl`$S4I(m%mI&6 hŨ j3dВ6 ؍I(MTL3abhQY( TLl"A EJ2"EhѓhDT3)6(MbTkF4I1I M%FRF$a"[M ThDEiEI,lK-Y XB3E*6cE@ģM $Ũl(##cl&b$dEBţbQR( AX0QEFQ"d#  5%CAhэQ524XAdنTcPD&QIFѭbdb6+hM@,bL"J-I0MXF4m%AFFJ-4RTcDAmIbJe c)4h"$21QbMd,lTTll3j ,l@ 1Pb2$TH(`MQIb$ 4,EEB@T"3dhbiYMJb5H&`QmII*djLTZAcdbI h` ŋF2bJ,dJI%$ڃFH6 ba6I,XfIh1EIQAI0&(A!#FREɂŤ+b,j(-m%*0d4TjH4cXm3Z F"bPFl4Q)dB,r!ف];WgÕX׾{c_ Nw.c'k]A40:q(<]+ா^"SEBbvZ76һ"A(4` 3u9sA.b'ʜDd{% brIVLlƇ9#`4sWSa>𣩟7E_}CEF_H3ݚ=٥ׅY$WtWHt4~ YO}WfD`(%x?a'>f"=a]fk Ĥ-q8|ڼサz18lwdƄԹ!"J /{Uˆ"XQ[OhgM`UM%ծ#!k.# \i/#bG,{ctMX^I5rC,e"(I`;wѦ?`s .6%"Vg]iߌnġiK@M5)N209l1EQHA`k65 a> ሾm0&;j}volDӏj=vJW^ŜmȠ(RɅF3m`0 /h^s R*֟p 1íͦUt=9y(,wɺB$Y$HEX$0!)5# 2E`ѩ2mLTA4FRشbfҕhѤ! &,Db*,XM%%$1i IcDh#6 ‹badA]WKI" fQ3&6LS6!QIad  Q HTh I؋EmeFITh~^$&Q&Jh IV ,QFѐd51&C$Q`I14ɓ%&4ww:F"e,Y-H,0B% (̨1d5(JjB#!ch,&FLQX$ PTXXذ*R2E(""%$Q6lDIRdk)ThIfll<hb@B7O)N.^b.ܲ<5G3[03D(a 0}_u&TöLf~"RZ)P}}f]uȃ3$lB kxEEA/vHv`6Hٶ&hc(mA) >WxF (LP`&lmIg<"EVmH5p $F2FLokyeڧ ª9Rcg7uTvC"`bL `P${aY`(f$(Cg(2v`sFho,jt(y\)]Z]y}-ʩ@5 Ȣ-JOeAB)&NkuY[vzzLL4Vws2)%h`YU[ @dC2@=t74($HR-UrxEGnE{:燖y>8c,d1/ʤeq7l|YC6洢NH`o͊H_{}nbsdz)'kr0s13 —odbHG׻o?r'U?_!_!uW/ϟOB(+V !3_>{Oè~>:Nt!|LLgK!܉ ;mNw"s5?(`U(-ǣ;.P7;G'It{D.[X 0&QeԠezqS9Y%HJ|iR1R!~lYq}['Ed3Qtln.; "Yn#`%[xotdf|vW&jVδzY^UB!ݝ=*;;'u.zAGY+oS*a*[\ީYL*KJ`4ΦEgIouP!* z_~߁L`NNf0~c61Fh4^TwTIA1Ļ"O_}y*W^1 wxccZqT(j C[|wmX<=\bmfO`Leٝlk"(҉vW,NJVbO_F+͆,-? >&?}z2нLɠ7"w$3V [ss(XKqs_[ܷmEBBjt[8mXP+C Ote~&[?OVs&8++;\cdGKKxMyA.kG2?w=wEġ4"}QF,R^.[{ ‰a ?f1nO%́L(`ۡFA'~(lL˪"A&'Irۜ%~uK&kre3 _@y *TNܯm`[ZEUlgO,/O5hnσOR>2e#d+nHblx-c=zP;X@@7W_tNo 㫪*|+ Jǹڻ{rVN|4^."۰) ʐEY5 >H<&#Ml%Om_Nf  !$I@ 0ARKLe; Р?R( #S˅_.צgw#T"?'Xi_լpz.?Lca?bˋ?n)֞Q6_XJLEkך|?㪘'1{Zy'Oܩ'i;3K7hּa$ (”gkAG) V:990@@57!M5 TS[#eQ1a& Xh%CB$ DF4ƔͶȓ 1JYbJX PFĄbҒ#bFC,XMdXШdfF*6``I$ldb"D"d2Lf BdCffLD41$BJI4$٩FHh@hLBA dD(X1X $CQTQK |Ogs?zvS% CNM)O(ɕcYe &zx^nTCBzt8X%OA9"%0R0@cLQyQ!l_rocZ|;b> n|YW$H$&kjbn)M $݇L$8V`9]Q 2s؆mѷҰPGQ l.jyQ>]ƃC[LC?4[X3dD!]܃X(U0 3FY!*37QGM}9#D$aкq * AV# ؒUbZ@i*rEQ0"@̣(<[J3-r,5VQ Hhd8P_^q++~W|y[n]Pa yέnbb0t0b "W0*Yssθf8W/37[tާH ">NL拻`(( iTGg3`(=`,q8uN',8eULLJԩib!"mSPEۂ Q_~㬘9+Slj뭍EUw8[{Hۚ3'+:D> :J'gsgPSGyxo|0^vs1þuQ5s1Qס]BZ<8L$ PANrh^n/"cp ?[w;WB$rT2ODR]يԬLP]P9ED+V #jtYub5v4|LMtwT:N72S2Q- O3̥b^#EHri~.v<,7%}]}?^G;=Pdj5V@.^ذ|R\b W~i3ŋ2S"'uKx&t\͙i1t` h#*پDj6hM1300M,fDI)!L4*D,ĔdIS"a!$Y+I$mERF,̦ ,H6BJJ SQd`$"EEb/:OM|>ޕݓxJlb?@O,S:p$aS7"}į=w|k1c /mMVc4)[Q׎MCJ?^ww8׷i;N:&G4p _'>cu'~OF~.r}HxSjl)ۋ9Mسk>xɱOqy͇Ƞ>Zwn O1\x2߽eztPB}u>M|_Gzqm8mXUyb;}%Rd9[~~MGm^"yԑRUzÉQvOp|I $- 6VQ fRHaG6a^:I#3a& 'ed WݘTZʕ&lZVH{?5DM`EeB-BjUeoIcI5 E1 2ɆuhQ,FG[zmFڍXHlY[!6,j~w(Wu2IzwfwɵS(H(,R#ec%MI3&XɲMpڛD;e㯓ׇ4 CdYMJ!I(ԐS 3%&"+4[Z-jFشTmQj,h6Ƌ[b+Q[EţQUPk%jbFڊզEh-%dQmMj#[zU^{mUbƭONU-ZBŤbFjb-mlV*6VkFF5XFV55AXbhXljѻ*4mQmV5Ehnm|ȫԷES|URY(E"m%dۦoO73n<9_)L{S;ͥ8 `+fbIJHa@-z[^5Uޚ5QcEX^{yϚnLc:+?`Ut1/W^^YLbkV`"?OifXD&E52y67~/AxF=L3{6-Ͽ{=2Ү? BCШ!~I:0EIFOc8p5UmÑc(l4t&ͺY4NLnʼnIywv$|moj:*OZ2"̪# 8}ܿ_CBBRܽls YS̩B$0EwEp@w7y*")oþ7{߯>{3=u[RgB?~^en"e,>qn%*E\z9r [Sղ/4#$gpg~ᡪ$cCX{"?fqfnXz]Ѽ_]f"zr{!c^Pyvdm-Qc+NaC29(fPأiĨ,yjfHJ(sd xA5Ζ%[~W,1ڢ*t߸\MZDPYk8XhߵG9KlHD`-LѲTϚoonM7oY Z0lYcMe#ffwc5$cJD"fUF% %JI(&󭺓F#M -c %]tw_sތP{␕^?d<{WեV]_tnˍ%c _$3,c9ٷ@>Px|>6WWHBf`꾧G>[k͜9bSI:F@Ra#BEPH'oգo<,7pi,XM to>&I-L|ͿgUqjWX?~goA S2Rb/3#=kY"^IëKWX:sߒ-=$9EUt mWחPIH$JO 0(tqt޸RY p1FdC_=]ן~{_'|6_fd #&?,Dd&4eoFdPDX" 8h k6AlsM,{4p6 ddYX{~nqM/r-Y$I\~[sk!!DEETQFhu/.y,C{ L8"+L#L#gۿ!kQ[sEw0l#u-CWYmc 98~t[ã Bg/_>~'9P{ШʁSZBf6%(Mgϳr(&K&B!!|">y$ȍ N (}Bkt>9REKGWDU+e9H"ӥdE Pb2% ~1JX+l;\KeZyG36^ϖљ'3\qXeYPW_YhoJTeyQ礸,Moջxr^?u$X?? ?+1VD#|$f*MTjb4Q(dH _k|qVElM۞0=7gƕxO}3|ѥ%!)/(=<8`uM8"ŮKV,묙($H0 ~סFh[ogd.E"=_66ԼUi OD}caB=55*FDFDS;J;[ΉƣՒ!$/<:o9%  ۊH?b0{(DDW7|n*Z:*<̈Dkeơv)U\́b\f!g  w3EXߧ7珅?A[1Htypay7Ws"9HN2EloZ+yb+ [޸X z ED W߭5Ff誅~ՆU_@&ͱK6Tx&_/3[C:`?kȲgcL=k%t ,.81`^>YD^cK{Qas=.]:mL/Щ}RPEsd,ga2n.c"|j>V=?xʛ\2Ս! )N E"~*6VgI5o+?rE382D0OJ*OyEt|=[lb`Wuc8, SpI,W/M.jNA }Qe- &ۖj"̷wkff Q]̭owz1UDUDPF4Myyz??f8[<mϖ+dD$ɻ?Upŭ`%gZ佬zƝPiZbt[EaVv%" @ԭ.j> +T+ֹE(D+y5|/xd (:j$}#jS6U‰ ;5vlB ?A!>M!>rY>Nz!-E^|)owgs1W>naŞ~] ?ťhm)4B '&;Y0F;{fH$\UF{>F"gX>{./<˃ ~ݚjS]>c!"SFAYD ݱ`aob;BET:̕ _ew~ʍ}ǯz7hqH& Icw^@1D?qO5[;KoIXR, "2-hQ *F x rIϖBJ&LѠ%P3$ͦIiH,[戇UWKgӪBkS&ٽ!/y? ɋ-+lY tG]?g^'gvwթjQFvVcfޜq+MaK eIs h*STʹ]UqF6r!X QeK";꙯iT[Þze{pPdd@xrf: |2M"RM ,M.fc;̡̖+*Ks;!;Q$Gv$[51heb_fg|<48EΒNPhKKq& Նlleen៑h^xAz]3T<f#uw2QOgFSŜu1Nr=nä\0{[3T5f&Q+胔W; :6JJR[m U6m۪l@!O)7s$~]XxcXTZY/GF:i_G_@Lƍ&w%{0,fX'OWx dHBV)AgNѿdM#lsW,*'NFwvEUu%A޲%{V*0݋˂tD-F_z𫓞^d#Āvq?ЛgmX9eLtàߩfӜe )Ʃ59|wr<4IPv5Sla֤?풭6ƢTk,mtHDtzya>*Vtx{TvmI_dPEWS)fjim"r_mGޠrd}dv**t6`u63Gr>ֺA-|S Wj0[$ $ȡ(FP0ON-D}D;/:.B1D 6˳k:a}~i_dzB>Ιj+VHőq^P4_ҕ^m%NG:@ղ|nύu[Q:ot-N|(ҽeoMb8,cFl^hTHa "'*=(^V&c ߉o?w3YuEIKd6_JU]mQz&K2ikds-&ߏxե{k ٛ%F;͔|mn7QAӕѤ<'+&"ر7zk>ddW}G墽z@xs$yȔx) q\Cc@ָbϊA,O,R~wC" q5h%,Fey4"eg`U/ EcL24dӑXX8p6 ]!e(gfs>gxY8P|&(ze DN]S3e~lmkH+}ժ1#̇lW= 9wnAUH<"ūY)|z $ h@4&b4dMH _2B1b')bIt XbB$Mm}N܇N9oF Qn۵1.ޘ2x6%ՔΘp+:I*9G S78UL\ݮz뮸R1H:!x5jZ # Bl|~o7IzTX (o׾΃7Xib ʠF+p4E2)6#ebRR0xc"dnx|bQW\U(,^g59u{^A h )1ғ>i$$,c3 )IE$DcFɓ e1,)D͓0HdHh&1վ=tūAQF,TUXƣQQ4jj+o >H q2AQEsh\TQE!doؾvsF J%ec2Q^ bG)U0QTQQ6^%/R~41%/_~(Iy:˫jk\=9,WbEU?7du L}KǸ_21/_wo_휤ׄ;$|:K !i-KVrc'"(* C4iDQ13E+`:QHR]wIIW禙"TvK-|IB/wvAgF2/S ).,2ce"*DTiq.dsܮpL'?ogҐQFşa;˖czШ E[{6>>yo w>W\7 l8=bGeǿubD%˟? ,JbЦzY4jUi&{Mwʽ#ƾ*LOt}Y}mXݨg+>7P Anׂa>+bRm` }cSV MoG,E,QQWZ(ApC;}-ٛ˒"/ц*'kޢLh.!qDf8(ԧ(4I\{כv"hɨF!).Nv5"SwiBB ^^]M&mʭ"#Ǯ /OyP(4F.F!/EVDM+ËɎk}":UhТvSL]EUcׯwc>d(-1NnSud ŽZ6B19 DV#7E\J(wn5bPb+VlҬDW._W5ٿVk V?4<0ݷФ)dZkg7a:\b{Y}=7j_?ޓxQcPDgǣ-a=bڢ+*=>RT[)PUQ/89/M>Gڥ!*(kJW糮ESw UF ߮tu 읋EiE}2쁡 %\DU?4"|mAl#斷w~I}IjeaNqjK(rrUr޿ 7/cݝ]O]~I rty9%3h)^`L30~C^{+o"a2` C1A"]J]p;W6E~< ֏hOƷCdVHfՆkq:Wآ+F6FF$Fe kJb5b1ԟ&,J*yj"{+eWҡ7H*DiD"3%|pH/hSd)%#ߡPŐQdxo:|Z4א9b"2Mt{m4U^/o+E[`P)]_Ph0IVIPenU:LN4fG!:@cݼ6ST^z@MBԩf <"^pftps[lss^z ftPɧ\vt3yiY}Tˆ<-V(tLj 9 cwM',剌oEwI'hF +G@,QcG|'~II &%F =zP}IQOd$Œn{{b(N(\d zC6nZ=@FZmvC0e| _~y8o:֖nJHS [jZwJL`p[>Yγ&Rc1Jb?bZ\\NԲOczheQm=ݶ_;Qd^' 1~O?_p6[X|S(?G"?`zUT4(a }O-x1O8xvZw|e+H e}97 +GkQ40@7,/ueH*!+MҜ|M$AMi7lKuKq Ndh|7^p1b;m6j_> Jӟ7ُ,p@0TMp,b0cﵙ֩&aV&YdKέof\9{(LJ) <>쿻v Oqe|QNk>_ʠ$VΞΡT*iRgAs ?aٺDm!f8DAWG#,rqR9PEb~)U%)ȈX 273::=Z=1E=_ᯩGX+=ȣ竫b!j-3h.0цfK 1=f>(Cc׿3!RJXk5KUd.;g)*@kyߦ$V?2jnVUч$$?[!P |ƜdFL Us%(A}7F iᲖyȮ{nt mqN??O?8=,4L6̋OMu$?߃Vb_s#‹MͬccjT {3U50/2ŵQtI)B^=lQ f:qɣM&:w}ysDB#Y@ak@d·0]dk7$I#Wkco ׆MVIgN)^I_meҁ$I2U+mb- +پfbC %¬g3XLiNM=}ѭ.2}cZN-#;%VAH%I2ֳ&etmwWJ"ߴN 8}J_aB>ď'Fw^i~Ra}oA5BDq B[[:4z$NV 5Kcw^/ϖ^ZJMYmG F"*.-(gk.wʚJkz&jX 4ska/Q I n%+̸ % ! 2aKOE;ȥU'=cܾOGcn9'Hҋg B`ˇF~ʽOBd=?z?GiRIZLTBIt" Lcd[ QLH#hIhhvb6%0 I1ŠL).A3#`pzyS;>~tdob*3#&&8M#DN |osД(Y* DTq /}1i7t~~+^F( /_?ݐF&hM>Qys2P54$JD?yᢌvܹ vllFM"[;kJP2dAEb?5^-቟DRFZ;ma :yV@D9y.r7F^"wpvO9X<RsƝW/?;>~˷6a_}r/04o[ ߶e|;`Б;;A."S۽6wCy[ Xc$ ζ?~J%HDTmb(ɋ0ư͍^UJ26߉,63jKchF Y;bb( A]דEy濊Ԡȃ,JkE*}U/~CqH?~̬iG2ө؝y;D"UU`I/@/t }}ԷyУrl &EX"Ѣ~Ưj* VmFQ(qt4afM k:4il&WeZC#ŋ ,;kT WS;i\z߃P,Ia1 ѬLt+6puotɑ`1 B (*M fVk M&M Ad"lؓPRTĕQ@@CjRdնJi1%n_±I:=<NkjK\#PGjqrw];FA%o( EQs6޶vB /W^^(  0EQD%&#z?OT#dQΡj+_z@ӡ!RcEQ@?@OwvĢ ֟a&^HJ7{t0D[BEwmxH d f(6Hͫ&+yU2V^2KզdZB-6//RM3P9! ċ$F&׬4ugLz="޼)4 sfcSpO*m+j "*& M߻N' GGPrEC$d]嘌Pɟ-zdрTm/ͯAS,Ll"1"m>f8©lg͐TUUq鵑5o )T=hჸp9gC<.}ש>^ ݳ;tgA݅31Z̯ߥV>|dbFb\is!D1桶eUMr%v=;w~.m~Xw\-c# H#d#% |OecuB1MJ^_XF! Pzq~c( H0.}c̖znz7®Eϸˆ5BC@D!^a {lN?$G5soSI Rư#V0-?{;{lB*8v*|W"8[Cty,ٱRon1(z|tU0IC `HzgrLgMsEb `,Y5*CEVyFxZ8fuwIj0GB[_tQb9r|zX"/y!KBe`5_T lr#/?:idܛ5 hђ&@9-ږZMLYy9q3/*Ӆ|ɬ{^wXgw7ڽ#c&{4m¨8ʢe%6~#I u5yF *pеZjeƎCpT35Oѩyt[oC}|hm׃*Q{+i?z ?c}C;ET4bTMi~_G}m;Se΢Y脂oj0:dYG [~B?ʰPAu`7аUiR&6A`$!NZҊdT곡رvi>Uf`ʎB>Co0kTĹ/GիG(gVQL^ȏEE%J#K}w^ˎ{93=۾ҵPe,?rw;uae. :$|4_vK1bd'v:P29n"_bsCqӋ[WSQKyZ?m p(3y|#HHWT{G\MK|?;ñg~$~$}5W<}9`1#|$URRg}} O:)F*,R|jEc"UZ,Hd#b6#FCE,0QŲm >]YgWz~~_X 稆OdsΌ$o|VZHV71EvzY,pO)pీ+ڢBZo}mds?T,!S^Ϻ}56YGf3~}|(HEU "ƍŭ* ) XCHW]F*#F5KAhA(cIUi) 1A3FŴcb4h( ,D`ݤ|]8o~Oo; n柠qC 􌹜̈́Xb##CNR'sj(1p+H_ϥ},W) $`"G)Z>I5t~YhQġ !cyKجrSn:~ځې  Q~XFJ9{YN _Nyao \JDH!ݟIsf«LbUjҁЅ17:M?nMmH/6=!1凴vrF,36nS=f>af8 ()8̻kZ=ws S8)zG XJI̻ⲡ3fSP?̴) Ɂʫ,WksDhu6 P!)\!R,<| OTcvo@1\U)별rw"VZ{ԍ%<"vwpp.QJ;TB/F&E@v饹LW6Sgti<\Đ؀2ўp}UX)-l1(aa!F(<‐ʣ&kETD,+ (jozSHl~_,Uϩ7)*r't7WM'ZZۻy nQ7 Gn;=us6yERj9|Ҡ}u8E4mkW@H %$qeinM60SIXI(w~/~%eMv2w{\ab"F8B&$.>"Qi0.a}A7f ~vaU*V0ˑA鱒G;r,-GIjk7@Q̉F%=$'3leA[Ġ(Fȵ]]]$UyK,ʿfg]濚Qʎ [-,\⮃?NhB}s1B U ROM<əƒf鄁P((6̭%m{CG|qNIsW)V$@15y羿yHf|ߌ:6$Ggy(Rnb sha'Dhsu£ÿt,Ao_J=ޟ_޿j٭:Cumv"vߋж޲3xh{~xzZ M^,Z6di1F57V1mThQEtߏ6ZAfG?=5Odead qr7.ƃO?[EbʿS)ӕ /4;td}MwcQmY*V"ńz9#>yLR޹#cƅ]&Ɇ[Ng a WEjPca&1B@eI6c2&86d ;T 'hz3xvN6)X-T+df>413d H5k`rR % F)vUAۮjnΠ27 h#o:9٠H W}NNkr*uRtJ#e>NmԆ 㿁xEe_4ΡAI) mR{4 ܳ6k_^rMs&ÌD n ^wFܽYڙ&8 s2g)oۉ3̦hv q0ȳfI9_g͐V\/ةvu_VUA5_Ҷ*VoO(ވ4vo b\:6kX[RPh/^:2l!5=F#Ym3sehIU> Y#Lk}'sѨHyK3 @8!LcPBQ "H=A'[K&YO:o~~/px^҉c`"Ij5W+fWIU"<9Z>fvddQADh!M5ճDIBmBd7-;<2,;޻zo" C:UOm{5%>d;(zF 77?L@̑ua37ZOd+sqwe Hj]Pu4Ӵ5zmLh\h7|ׁiיԖ*Il̏w 0^ {?nOzBoqnf8-LՠRr8*VYU.qgS ?r0;%mHIuQHx6Yyt%E/:r/}&5@x`/Iljj^ScjÝY闏,»T@Okv?؂,F4}[umL"~Hۊ$ ?on>zUb_eGr?%Dr?ۉ"ȿw "2ҿ.tS~wwq0 Ɗ*M\,Y>T r2a-"ʌ9+=_LP H1APu]W8e\:WʇU2!$ЫlQr (P9o?uti{`lh@rf5Q//E%+- ` P"m>VHDJiC4PBDfPx=2q`){ދED(%ݦJ71IcH(QNTE<ٰSo+yyX)=Y* ހ,ce;}OI g89 PܡC+jX' !J$1cwwmRLk[Ne]5*Iܦe 8!! #[)S~_0)^7;E$8pqվމd,sfLNR~!/ O20b~U<γnqҞ yE}$$YH<_@]کFJrhQJhB>J&jUɍL3C&= әl, {7,Z^WX-(-X+(ZI@$\ʓ'sm|߁I:e7!WͱNH7zTt={Ui$G?Ii~V[؋mQqBXܶ?/g"93("ƣ^9+svWKԙӔ3#pKR efY%$$D`H2Z1c kGXWX[`m(c.PY+.U$Y<IFZ) 0ww9+lX ̘cEp ^R;hȧ=Z?B9Es@[ekw1i!Z҅d±E9(ŮU䱼^D؛2 ,172c2Z QLI (5aIeҁP%$, hBjC`!d0`,iZrHh*$1 + $hT%@Y d2e`*BXb0SF *a&FE!R ,BXJ(TUA3aԱi] kB@LbqʆcijE KXfC S0TlKaC2Ž1BE;Cxs pyޛ/arb ­+Hwډ"e*j14QȰ1oM#frkD+,1r뮐09e11ԕ #°1Tқ^ dۻmƆ~GD__"~s,. Ow^?Бˎ ^MoOwoڋQ" qYcCAE+ !{gN w?ѸHߓ\5acU$:~W^R5h֍kkYr~FecdE5y#]slVJ[G&<3w8R丙:lX]ꚳr"kkVmgDE"3${ws6be_y$ڐ鳧&vfwSo0m۵y~Sek U9MF[-6`"Qyvܦoe'~J e0OO[iM>pԴEmccTUp@ηbX=_Nq/_ϙ&9y)#a!j݊'7PU )6죁ԞIg(|:<63S}+FQ;)CSDqbYSˋE|O[|qs;'/~QJtMw~i%EGVbt&WCUz`?!>-Ճŭ42qXzb'o(xS\foTN `R_)zԨ&JV#׽.)G)&"/EyZhY:=P9F.czzAo4%G &Vt4LX %$,5ſ*'Ü\9ߵ52ވ u+ǒX&WnmݜnRWvTEǑ,޴I=%-!S-5hjoitk2 8FaS&"j@8O-QÞOs OqF`3Y*X;.O}:]J"Gşɶk}_9.řT#<}AN[]vhu ۝܇j{fJ MalBouwbzmaĥeQL WF`ri^Zwknk8+ zTs؋eDQa,&X$>72uK+g 5WYAm2^^#㞑S#>buސLbq`a蹓3JZL&v )x!łDU`HTEDH^lJ= =52f)QU͒=.Mj !=&N>φ/M+cesd5p賝;1`3#b+8&dp4DS󏭷wxLקCeZ$On"ߘBcMF% S:|)n#zӖd>> S.&ebIR_s15_&تS/RJ$ 9lbϮpn-6#)sþf2E63JaMgu"ȾH߾K G4 m (XRE JPkC1TX"ahD)[̶e#9%Uv3j<\RJj7EFAbcӮ^g/Xѐv{Jxb HcTZnEnIn-hkbcjb^JZܥL\NцdţFƵn*Ԋ,R(]LeE,3>7slae2]C̳cJ{o i9,ĉIIfgRxo-5$y'W>S4b0`Bub& -)):_Ht"(EdԊ)DI6x^׫ء&{nQe(ܦ(B"n(q@ter8ZrnQb{!*q]),Ռ"!duϳ ˥jVp;ڱ1%@yVL;yK3t}oE,%"Wl<0U=K2N1؝a1RB]sOfm SյKHSmoU`??+\^s4܁mL[]jvw\crjVdx&:E'l:̡}vˬ%Tֳ<1yb)$mznrrK2&k5({D>we,e ~":sT*{|WBƢ,K>uH# #;/4Ck]ok*MbFĝJ׳P+U= /%rٽW}ywgѦTnqoj^f8NT`c#HO&:XU^QR(qc2"ȨP{&;deחG#“"Ep+0Y-/AI8KYS[sMclzU{ꗽ馎>X ѱy] ixïQM\ezRXK?R 8og7Iaų[Ze'*)+8mb9)2Lmꘑ_g= wt11DsV l΀&E}۸i_wjJda5Rסgքdz$ŕ5hIMk%r()Ҥ㞖Tw9g.Z 4d)wBngҦYZނ{F10"1ouw ${eOVljeAaI@ADih >TKC6yp oSY=b(M1`Ia݅lR3")K\5xiNR״tŒY.hڐ9)5%( `Ia䁛U9`[-ݝm5ت#ѯk*g3= Z{ {{2 }o^j-,j&j#&F쳁ɇ ͝;ln8:Fk |/8q_b! ES`Y-3YǪa\і>퐾ätxYv-mNM&5H%TM]tx~?yHB[,o)AN:bGqz.c8[W%%"">I )DQWYs=Ov*3zJ.01*v`kQUS>FE*6\ 1v(c 衄u|$#IBl1"-=x|̤;;icb)7cJ ]F7 j?hx3o?G9ulYJZ3h~ɿOn֧+42wXBV"rBoz^㸐Ysl5˝ 䅏 ꧂DO6^cxnNλlsn:on;P.ӄљ'3EUS0X䵵^5?O#R4Q{͚{؍s.GkoJЋ~[> Hx!ܱ6FMσ$ZYcI_^X>fw}:Ze\֮HxD! /gu0lqTTmm Ut)꺛s~Z-޽<=4*zg!ә91й2ӹAL0Sm-8[4^JGR9rvgU6-ul LR]C:(b E .7|J*K9H`ǰ:ꊈV-bQ3 ) 8 &1C,7dcɤgv޶- +k1zB~TWěfLsYY$8@fH-/;Ua.:{ sM1-|-%&LxQ溺ZsFfSjMxje|Yb_t1rʖXߜ*Za*_wOD"}J|#*bvr [R1K=,p @ˋI _. LHm(wf wRϧ)dȵ [LV)X۝f]> ͐[}7W ]u2bAJU@@lzt^6?E)I+C2pVNJ67x޻qe XR6"E lb$W:s0_vVx=#tMj;%He|13e{˯N̷NbeY?rO?RbZU;mtktɿ"$qػmkF##6t7\ !_Qh!D"uR:wmE˛\!ko[*jT A`S  wKD"$~CR~#QwhZs{g)q? yqÊSo6:Ah(.(p=};l*%a"I!4eilM]Ca9>Y~nO?EӖ(d<򳌒Z'6eGf+']Ye^x8o7bvxJC0U,RY0oي@-N}Q2s37Ff—G"q^n:8\T:ݷ E ": cZ%&ra ,l1en+5Cۉ!M uGza:*Ri^y4W0.ܱ+ <3q|d 돩\EG!ڵ$&|D5uRX nT$rf+\lKKCN[ N<ؾ3(E.D%Gx5 Mi~ڼ;uB8e/5حY-鳀aWSS8nnDAJ#M[5 1ZM=]Go~/bTb$hVv@m26v/MCeļIJG,qt>X,$4D<|铃w%C&P7~ 0xK"X"z 鱆RP6I1 ^wɊ{.7-RS5Ud"G5Ja:Q"& 703u7.Vn}Nmz1Aim iqZZW;߸{꿓vs|/1!(;Fj^ʻqX6Y^]^n*k OIZn$oĝ2E6`c$ȌF[ 0"*%QCoW.>^= 7TLٴ>~͋x|Mq\YctUJiV( (E=0T~~伨=0B{9:UYacz7(S$~~sxK pu2<(#se]_b0k%R PoGYcFg䌆jf0rG|ˆߎ'$V, J1CV^Cbw##cM;?c2f70IqEfyn7^+h L|rWaFr(ሂDOCD$ h=p+A5bPԵb1?p)x)),AdoVk8Y/<-5J1ZކڀQqOb#jjP5Z-V$HFD "1vf 67z\>>"ʁ 1= xozubLݯ*įop'Ey4M;.S +0Ym\EW]rLChVE뙚3Hk4EޘEkPmC \ցV֖| DѼTEV[*WYp c̥pRڌd&lԗ-NGlF{椼K{iՓsS07أ]a]nKe3G]ex6h)Qh[FL6’GWQ+x*jS'Xf t dNryEIӰ9ʳ6fL@̤Mɏ1Ge12y,Î B"H1 TwEZ!׼L6wTZv$ǎR69 N>tRæVuoBK:gfC-u=Ph'l 2mĊ,\UND gj׷2 oG$g^O0H䲵sy [ ФE,QOlJZsD%/}T˜=tG:Q0Jz2-ȇ)LeCrLm q4m8M3L.J"˔Aeiӓ n`&*G~鹇Eq=)XI0γV*JW"TMWPZ,F)h,d幷1 Ch9k⩓]J9Nm]R6)Q,iyysZ$M]lv1 4Vf8#-pcKc{o(Yp+a5&uM v¶9"'Syt6e@lv1# ,D+"9D,CfNZG)PUbQpoMJLJ⟑e18ṬmN j)NE]qਾx31؉Jguua%aQJwz҃ q^a ijT9zHc2J ,P ynR N]nw(aM,-ۃ"r9e{C+;x#kD&gw((?6'=kgkr澧(+Ҫ,R 9F2K9;Q9G)Ďs& mЌi,‚ q4֬ts8rg5=O_l=nrZQ۪dHHιAN}aD1w^˻]n6> A/DrgG{RBs('q;jbRJ&֨ݴ.&D?'KM,SԶ9 QPYͺa2V#[[*ni1"RVN XH~? :xb ]}1 :L *bT@!.Z(6UἻ\o%%0 B)TU@R7dd imv,[DG*mFN&`6&kL}Mv2MRLEMO^),ĚtKXE-pv.2`ewmqF2<7AE?AP(dA3 @~91x;& 3luOvS RA\j=Z )۱WrDĎF2~0:k.AJA% _uGt秿@žڨ|ji R,?Rdqx$7zKxJhC(wzv~U1^6lϒ\וyF}@u6uo `@b6MkZ*ljŶ-V+Tmm+%5RAR5 E[j-bţ[ڍXUss[EuS6mmxռQ2M5b1E0$`DWKesdJ 뵖V$tRvayC˟{7TxbϰѱhAoi<<ItEWP |-f9l]oXP"\'Ij^<%z֚mkb +?yaC\!H†j*ؗEUkd&|K-ux ̣o`?b(AV8OAscN3C)RHvy?]sa֕9a]r}C!ɯ,g]D~_:>(?c>pl?'l":߉'ˊG}T)==M&}܋~.p,}_c:z 1D_ALq:.kɋ|Y۩:at4avo!fs+.U_KqN7|& j'KVLE$$FE ]MK+|Mj}}Ȯ~3;{0˟m!BQ;،) bpG+H' /E9gwZF[v(m $WuI<ڙ5^.8rkl4gc`8 <8V9RQZ"0 wS]cY .r/ݱܝ1RWٿޒB6\\#Yw=cD/:m2x {׼Ո殰à;ѭq<6?В \YtA M|k:m 2߻:ԝ=:J#| ;Q!uf rܒmd$RHL:v f,:>-̇ᫍA;FrniJsC}x>O[:r6=%յ ,IrB\l:N8 8V;pkWqK$,rƲc)~b3DX]q_,cnM#fr>:l~gm]k:pFE 0,@Rk-2މm\rI[ђmdBI-٘ $6)#Ŵò3w}Fn(lEM+ӖfkyעȢ20 Y/0ɋۻs* ÂXѭU]8h"HWuAC퀏Z&wT.>J?FH\oK}?0۽_Q}~-X`m1=飻Lɉ@&fBSU\f+k4; zzui4!X)HE=ȀmBMԳF$v[T"B"vߍˉ;- xֲhj0(_E%/yHV=Êkea Y'+mT]SA{Bh.JGraw-)@Xd3H>D@c5-]!J6;+%R?-4DUH wK=CYpGގpe= :MNoFcurhrPSk)b"g9&,՟:vAsE^kAhs7tGD'vCN53aΎRf]HpWw= 5$5AdXHݽq]wDa  *sC u&<~rz@bE%5Dyt2/>QUӤW#īRsFY:fxvUWG&f %zplY!!zT̝*xY ".AiݍO{5"R!C^.ZSЈd٬ZRCr B(Ev;B 4P" D xuéj|;u\vhaeNHJ7]%HUV,XoAftOW$qlsO5n:P ĎM-q-UMڭӿ>ZÞ(I@GB\,m6ͣ mކμ61mlc2\zpҘ_<3TorF.Otͪ9+7c7$)n%`6T^ *cXHI<:::}5 EU]C D`,!EQOҟ/!yίUլ7]Y[dPyof_w2~eŏif፬_0yHXK r(D|4XމR]>p{?}nDTpNP2I$keC&[3řBQ嚊RT(BPM&zW([B<=|+ ݐ}@@q݌ QH:3|^&z'  ƨ! ,EhgmPvw cjye0! (  }ڵ| ?Z~,JF OV*-+:8_5 ߋ2Z=U})"Q&Y,@lsn =is Pgf u}fm ܯV[cܻ8;KQf~eTb5e\vn\u2"ik|LNf;/+ k0rD)Rѻ6̟b'SC;6JX(/?QV._=pƞ]z|p S߇ɽ)װ7fvtN馨ZF̥Z##md7ObP,7r f[r:0[{skIDفU^]_R_mG~%}Ku,\*r:'Xw{_llu,/WP >oTP4@%Ȫ.%q|K?w|iw_ >y9{*]b'gH~M!4Y?iG-w鑣JCJ$Sֈ (=%(L_ VOק6.ֆ!r!UX)"0?/N Qa@X b5?=xާ+#R(EF R8Nxa AtG wLPZ#X"O-Ԓ /[~])d6X?Ty$%]}?-uEmRy&iU:DX:HC<3-'7F e µx}zOkfzQ[dͼq۳!،[nZ D0@۾YUFuouɱC:yvm}*\#:l0C~F-Eneʳo 6$X"Jj@PE'' % :ucslE!8z yNMbugOn2xR0,N &p斕NP%6ck@ )訛GQ1W7co(r,3ߧGL3>7cUTYƁJbqu9xTS$& "vx}c]uJkZ}}(FNJ6VŸM__]g&\{8w}xHop wA}((YK}g}7b| {n }{̀ }|w]>7h/{}{_|}^7{6kqϾsmk<&87]wj|[ݷpڼmow,]6A|n\sS)x H4 i4@Й4LLM1 'i14a0К`2=CMSؚm`)4hS~zSL$٪~m$xTiQ䞧A4 4{T4mCPF4$$E=&Hi$M5Li34LMddi2=L тAh 4h4hIE&~b26H3$mL56$m54ƚ&@̣ I104&ajihi"H h 444bz4Ѡ3M'&MlFTM<L)MM=D?Ҟ lڦ6z4Md'=zI6OjPI@@C@&4Bb`2d`)O AmOT&hMCvy?n};fL<cDSyy'atMJ᧖3'g}c/mztŐ7>)]Vև؈KȰhC N2\Y߇p6[kjoI{6e oÕs.IDm2#Dԛ>.8$?^W$g2,ՔX5[d%geG|%ij!N%a)'PҒ)Jє,Eғ9H3p8Eh(Iw2 ɑ+2ɅSp"Wϰدky`alɞ$"fzx$& Y9&@٤L4GIPaXi;zu "<J%'7&I$"iMX+I{Pk@cr:x~80O{~́\8R,8|Jטs:TJd(Ճ>.|,5&(0aF{MF5Cg),vyhrZfAf둅Uy5׷Ӂ.wW8Mi@Op8x$ o@%8/ <|,8[5 q}dmd ^o7;(%/!2׷WoPUkpGL#IA1bУcY,BR* aF֌ChqrB UAdYmlE9͋fcS701(I( ڥD2cqPqd}|bu-[!!((5P$$WC AAQVœehdffKp=p4hw wHcj9kBĉH5 33Q/[8Njp 2Y)`i'M4m-PiBP6ӓ3y47Z,i< b=X ?%,i1a AbMs!'2'.?~/ݜ *q)P %>>oyMhhs8Σa88Ɓ.4PQ[lLg5W'fY/<t^%9I7XYs@MbdȬ(ͳu Q2'Gx ">U6P S |ǡgƁR'lDeBqf'>ˉLDbܟvs]h;V%` F;E}}t0y_}!$6ژ$\W<̱ 9/EcBpF'jt8ԭ@لLLzߣ_VdЯтjė *e7*bLfpɅM%m_u^U6zlO"Bd&II>]6!I'י-:'du7!(Z2jd11>4^Q&jejĚ}؇R 4{S9nvI HiIm|U`6X_#kWMNd~MIթ˃u1.O@uz<S,ڵ82qdU(A*(x!4znn2ߌ&#w Ƭ1֝^I4og}ITmEL=JoW Lڍ`U,m[8k|`3=eжUqj-|HeD%,.*24?٘ ˯YL:R+ZSsVBs%lvU̇HdG^37$cP0XϾ\7 c9ųUhآenC.*X#npp3rNYwe7򝂱MR_+N6'BlFK c(sg~Z`"K~L?=N6>EBέ}W&rWYNzP:8色@- :V&=\C)ϓ#ըʸwsu4gزt] [؎&䋃Ok7|}T\ؽ=./ 5YD~d= t| 8 ?ʴF2f]~,\1 r} \;ٛ + | Lkɂlyٸc;.ŮۉpPuX+,1)J#rR}/s UP/wgVt%1OQ'ru)DA8} 7#GƊ!y` ﶛ <auf_ 9PcW CFv:wBRˎ?,DӪ x ÃOX"|.3R f(tv *F[ԾiDgRzՎ,I*ϼ1߰cqnZ=09uWoJkmW`W\:,vk2({- }A|i10{ D *<P ^ ا H]W[^%\EW?c sB1@GY~eb;AV9VhM-vnIb?&;ţXt oqZ!3?Cn'^qp1dQ(I\{?]+a*N_y}"s!07Wba6Z`=ܖNΕfyYMGYoߜ)Q'2.Y*7A'UT,kQ!4 [y$Q[@LQLQ@nh?:Mq n>}'ӳٓ՝cvZΪjb 8~:sorc+B?Bc"@堤0G!:2dʴ\qpTXe=iVzB3F aTiC[#١o7!3D&?gk{п^F\Α9$3ZpMe) }@|=F"qt1;Z zRN;&$|M.UyCbo U nq$j%y2CboQ9m9szzIduT6o35@z8]3ަyB[~ (wg6?bTu],q##_,,ѓdIfGrxWVjo-]vYMb>v"U3ԢĸibzҹŌU0yyCC&,B/:v"y WB̕⊶G)ޏ~pDU,OQC:ma>-#-̮ķqBGjrݑS."PʜcS6er88ə& [N[gjߐki)WFJ<:zj5( g^$9To0#>۟oU÷.3ǣj ّta&G)Z'|g{kZ L=5Cvo^p&^.3E ]$f ɺ0oz Aq.oJ%|>OxFqTUVʿ^p%:XEtވy$U+cb74sRAR|m+rg@K(CO=;ItJ#N0se#EwdN>@5lb򴱚GoV"zbR &9d[ԡ}#kp &)܋FT},=Қ܆pWVAVNMͩ J}ǩ(P4TZNgh5A6Cy~!;?(ɿ_xyszf=K^u۬EӺDC},d5Xw*"n:l %c}nxIgF#6IJWNv|6MI`@3,,o#o]s=#DON,X+/P-Fg]&Gu>i' ,dT䄹0"+lX#|4I `afn7Jd _r\M1L:uQ\B]pU-,N NBZj'l߽Xl28ekT^HO!o&' %$P҆Mzڑ =_k04%9 7mVY:`G`[4k!{ ` DufH(Kі`{Z} ]e[ewT63~K;\#LNUӘ6K>H~[?>z`eۓ?8 5*ⵙg"-Bd,CQrkdtE()D帵9-p nVgv?TRi%lcVD8:vtpay`d 蜑~$MԽiOJ R8gW1LeU%wN=kX퇮TIUհ}ة1h,P3H fM_/ߠ k{(>$\9$U HmS!m~qH@g3e![*: [sT!SΌQ%V׀$(iGpJ2E'mسVނ \(a%dLXs8NH1 wJ4g!$YpCh&ZNT٤jBfa'gҫ(R (XAΊJc n;f>KI:t#qRi7 Ci-w0>$PWI,4n5|jC=Zc#Wocn#!)6Z)/sSt^m;zUzU8 QbpĴmZ +Ηʪ+؛9)kE.aj8lXr5v-TE-[<%Mdbz8JP[1$R>cDf G#4sc뇚g1;.X +ƚ[nUO}!0{%C-^gL.rr (*f"=^:qȝ+w>} $VcH}Ⱦ}9?E~?1 0>/*o8e~i $@P/L ,]#םqR;۫zi>DU8uE=l jW'k!>P *Tt, ۇ?9u[u`UH>ܘߥE&y|'KeIqG^I8lW8ϚGtJ1@H "Vy Wma|=R= MbR|`w^)ghb'kw\c{ux3dCsg)~ΗMߎz%6MDP,*Xsp(TȄyypeĞlG[+l)c!'lkYe"އ6?J۰W8x fxrٌ2;$a U PbTu;{U_"o-'\ğg@dQ S[pmf*K%yQ񍘓*OX5##h=p٪ eR Ya"?k`~*;wcO \2 Xl g5mk<ZyrMb]@jrAβ \P6[9e\ZWQK+*u?ٹ/(5B!y>4gkh@Մ0 A]Uu Vo$6IXaft /GW KJyٛKbԱk nQEB~?3$zv(2#jj螲DsxV|2-UyYaи!#Velt2}rko}\"ǽ^}QPuI{;zaK\:.*M 0A f;o$YV5:=7a;2?}" AR+8)|a7# `*G^4}-f=Ku'g !r PV_dih{hWTjMV2>g% ^X2f}L0̴+7p 2ɘ(GjN ;8{F$6^z{`S㇨\<_rg$jPAf/)3kR?᷁cgpLe 1It]d1T ^z7*Y-?r @t2f'aiŃ.P6F˔BH[Q| $xXol-%9JOx,Rzo77):uST1 k)L~@ ]'Yߋ8J6)&aw]cPWp~zHBWRPČW.%2eF_VGOGzr> t{5cmtTt %~v1'F2%u2=On?w48I܎P~x-;'@Ubʓc_]Tap).Gg\+E0ըq|&*;yLrR9&b 21M˻[O7*r^Q w|`+8%W*2Zi>Υu1G1Z{-E dG7GkĘHȚc8$"fp<" u[c>k.: ӆ@Ȃɗe"7zzi$DE[*qBCW5f|\Bm/Ga_tƙ Ic L*%NQ^J mbhWAZNMI7W&H;yQ-Lփ"~\ F )ܽuS ^d4,ԦJ=>tgjH;_Ԓǖ]5Sl!;'jQ~"A?s?oN ?V=re\ Dž&s(Fnpʕ1]Yl&, "?i@r2鎥v2Z@:'>ՑS{"vakhG٫ KməINg'w1zq Uk(4ƼDcu5=1[ZbiU5gH .~zeۮPL,KcIgL<g7X+nx䨠Yd^e?1*z.aM;fbXir~*_fs.,n·ZOjKe$\rS5@ja'QRZn(.2{ShЬ 5L[!x!Hno|,]qF]zo(nNN' ݀W230b1R%u&Ru<K8/4@dlӱ@ӷĊfi>5o{iЇ߿͞.M>Q7%5 WϖpgOT -y_|ҦC[kwUqjm(.ËD$[OY(X2畆!5hZwHCN9 "g?PrRxLe7H@ b㭶0p݋,_ @г.*ӓ^{Gscb9pgik؏ٖCOA&治t6 ގ!u;;)=R/ sm(W!|BTf?7Rxg #jh3o䚨J3{{”ud@z,!uJi*5: t3)rjxPwF;!9͙v:[¯V.g%>0 vg"?(\ssr ocx*z(xv60iEYŐ+ .<}0z<=@LgE")"I=&X-YFBr/+Pٍ w4Ѐ"@=#vn bn|LEu5U:TAjG&>2< 猔PmGĄtt"1F9 eHo5:o"ѠWTL11ӑf$-W, xs [ uˤAluh88P؎AtFJ(VzյgҞ]MHLs.>=.⪌iwm5Ģ5T\5B'םxf"4 CfڈE+ȱzDu?t'Y@o(~~("枍MQ%AqJKp1 1

_j#H_ks+ޮ14QM2p#\Ǿ{uc"|2_zG]lOƛ<"+ۅQwd K~_X^8X=SjAcx#PeEhmUނ"=Uݙcw(#찲w=g\ ev7OrͮF Ly2\l gw("s=*wc<>n AJu^4"DԘEi=( +4,3j N APڬK0dMԕzyg]ct6؁#ZݰƯ2ScM4Zpr WRBbEb ʯTS&kUƜF2&ԡ92Wczm_%ڃ0 NZZ/,bF7Ne\U=K.=Uc}^f7h۞㶴e{p>I 8q *]jr/To8^z8T hC/E(uqO7BǶ+Nr{W=,hs18+2O9l } Ww 줍;>RB't%I!sHSQNAu`WeqYU?cy>15jX?يAa͐eut X4MU^y"d3r5Mbcs'Yov^}*Sx}R,\GkolI.6i#k`PtUyTpn i {,m Jd<(azOgwjmd{jkџ{. 8wG\Ib%0tt-߷%i#C*{I\&XB+ߪG;^ SʻUSIpUg8$9j[Kr*ZAʸ}1e$饦Gw~Wd58+Rva 1v8v56gL-xTmapn;d" y;b6x*vh28aZV'p0gc;pBoAeP̥xA>wő8 ]~_#MP?>f+jc\VΛc5 ȗ`F vO.'r9ryr;q sإ?tE4! ezB^9|'~IƨGd.ߓЁ{acF/BHM]\E-@2FvT*?dn;>-A"$$-9|W+5oj$ͣёEr t-_#߂Au-!y%2F-謒-k>\,,qVU[C`/袱Bdvsp37@uF޸#>Loݔl \qx1mܶN5SU01wbul'NφzPJՔ~9߸#Ɛ.g|]&H· 3*"@ IsKIB?<R8o= Jx ՠ ercƝqŴO%#kl/A,!frsza8 Cٙ5/?Yg{S2|^Qp(Y |A AtL&HdfE $AB}V'h7̓Op,H%.E5}oL}zmD7x^ ]<Ӎ>zm {CYu ő}껼iY"}hƨK[VVnnU  QN vNw4.Ֆ? 9VwVSuKE1DBCZ mȀrtP<>uBj͙NNQ[ E1 TOR,jOI0pِ|}ؠ i}м5',%ݙ #!X?sWx Ii\cY+ ޵razuoڡO8v,6=J]=5PtINi`3ak+Hl SnbR.B;VNğYLUr {jK#;Jlб(mYeSw!Q-KE9ne5w-Q-]ܓ޺|`v'%4o/ 3ge- y +xqiA_W `$;N&l@P$xhH X5?[FߖLz: $s}!m⡋|浐2,q2ג=Clϣ~TZL9\6.Uw=WjJ;@1!Ah4d=Bع0+J TTNZ0f芍"!b+ٚn$%ǝXe^+ QN8nr?O( Ⱌ%˄ ?92?hԏ&p{l?+9 ˭xvuɀך5J25e}s~Zuy3ZXѲH O۱DdPo+\V WTyۯsWaX#p^ͲusX`Ͻ D%s0r7zmp vulj!%W gE/ L::sJJw< M,IS@8J _XA&+T(¦pShS%A@ɟd[WFfF p\gzsW=*܏ۼCmԢD|0{otJ@ kťH;)UN*Ytv: `Xs6 u{IGX׭;uqzRLT;. ź\wѮ[0XLfg™7!.`A()fGJ靬3]D@)Lg:ž-=)eC5P]?эwYl! '@qB(㡁*7+U`oq)iE%UE/pk&Ӟ@+՞ {Ǟjdx^$/jO._Iasحٵ2}S2ldUVrrڻD; gF˺/APX}/Qt?v9;/%d@bv*ү2BUdתH'SzRX1=fF`w(f $a^jh%l qa !gxoAvPsG2F\ZK%$A^\GG_.lBp:rC*)|(Z|T`Fhqur%VuN9wb\֒l+FiQQ.r.лe h C"v(1J *\TPNT֯z7H(ןMwin/akӣ=0g7EIאD4I%^wϒW)Ȫg%n2)o`ƷsuޅJxRFk5cuI' Քn"zJe>j~`.TwP0#?Y_`=ab=ќON>TFF Ä$:2Q-^᥌hd#m_:գt:4mM9>rĻ64karz<o"20fz9$8S_(54$ZHr :ќeE a71pzLQ9Vϝf9*^N˰Q.1q/_ 'h\ $Ya{YpfLI|3Ch\KE GF̓ͅJt>1)*t<'NՈZ/\}is>’A&"ܧ9bJX}HGx3L=Jـ8 uƧ*؎l- o#\>3fŦkL!껫-Yw8r]&-HBd`)B$?=h UW>'v»C /Zj+SdJ802achp\-O7|,|>`׷~Aq0z&BH"sxvRJbb6@ҤΩBK:M}O&klk2EuZwyT9I5Ke$W'O\s~ Dἆ /S!;gBLN7BC{ݲ?nt9T‚×ݾ:.N*_JK b(r \3 vbuW7/ͥEqQ^&/ pVC"Ћ0w[A"r:RkQcQxgx+p Z_=WFu9o>Y26 fY?mEQl@W߱s6܏W,MQ  rH"p~ZqF-mxTzC!۟GlRCRd}e:\1JC]K/JYq[@ڢrN@kϗeabx AN18 7r56p&hoyWS8O6(;q>Sp"TX2 ׇ넅J-VPGTXXߴx?/)%D:MO0kVs5GrAclʸs=3STJ.Zme-Űg}=3ͱvMKvslt79>b,⳷3tմ)mB' aO$y~](wڱqa`<0%G~5OQex£ua|/&6KNDߋѣ8u@CSهA0{cPV]Ch ;(gW%%uDEqWHd)cf4­0}L %1J 4[N|1(*OKdIfe Si-z9X9eFYOVce d?* Dmhpstv( ~CHxYǙ)βcpCXmt熍-Jxl҄Kn+(ɶ׻*m-.L]o1gPFKe wTUڃXmZľ8,aZCv%n'I?uHT(G>~=>NԐ~A7畲l <ۋYʵx([p@1gM BL 0/c4"t(C7I= >c ؔukLn"Wt?J[J-w4qP o/s*8sG\lk߼P${QFʱ Ї1IrhF } 7$=z;ď%bIڎ%瀦I9!٤؂ Zm-sc&M>k;e^֝ \pbbyq}#eLSjGo1& 7Nj+:Ct,)bȻt^IQ"XpZ!<%wPe]6/!4<5!{iIS*Z]/tSWnڗ|f8adb XuW"k4"јZ%%,_(]X;M!a%׶ha߂F{˾Z*wEZ`PpRPH43e'\==qal{Cm+\$i`ϒmK6>,X5_{YDȲLl8Mh|SmA$! I )i4=_ק3 u2tb<)P~VctQrUZ1X<~|#KgejGp=>c8a Pu55rokt)v jZ1wSP.ax L.m%B++M5GRc!t0,0B{h|}febԩzvi, .Sw֧AU{H82%V]N :+XP f`@K&_o)p4Ǥ]W k7Cِ!8*/U1=|OwdA^%q0| y"~1_vQ(3MuIO+챲h&C lwUFmw#~';/LM1B-c .2)*8#i-@i,ٵmwT^ Q.x])$lZ N [6q;23Q s H*T d""xdz%ؕ<))nt3iwFCWA`x*6p[{#"sTw[!|\,_!s/{J`"3+'ցJ##ZzZE)o%x4@?4]N34%&yUk95^:0j+<^5gdC3pc4EwYe >x?憝S!nmXaI,5G`k8ʎqس "d(] Yu[lɈ&s9#慜.b_t/U (iLϋG_6bbdTjn"q/Ysv>вzM׹۽&rP4Bo^z4wusGss7WwjV]`:LO-HR2Sa+!5 0 5_BS-]ݗMcV)\{6&aQYEhKx]2?-ank447k& ͏AVGZUVN\lrnB{ŭ"#cHߺ@'(P%M.}Go@;RB5-A4assM!Px?fq\4Χ6oځCx-&n$`ZxIqۤɉ.>V"i8I$[|[[+J 0xCli )"Z},*H%x} yweNu(EٟO{4pZHy [z1 N Uhy0:JM}-h2G!G4;/-+KLWBHbHܢ'~#n.oS:d!L:/U)$Xl'KHe S,LA9,ᢃ]2Kr~1t^ӬW| !=x3PșBZlwy `*se(Z_H>TARѵB"v"+?&|>,- 9~r1 w)42&श{",c`9XS%!fRۖsd[]KK6VM"2W2.OrWZ:.dPs>$ޡ+ܥW Y׿g*^(c2Ĩ dGj1Ӥkζ#֧C5o]Qq𘡭Iy]M5N;#o ?Y̳g41Gd<,l]26X!Ec"+O[ 2TFڝح࿥S}x(Bg1XoM.Fjøz 1Q=8yE+QNTNlB] v(,=0*J`i[]SҖ_ҥRe ՟CpaQ X-k<;Q0^yѤ?*Z9l wrJMu>u EfpⱮPr$Gbg Wxn{HS -&da?sds<8%92h{ΟD10,Y4\ue} 3v{BOV*: / cҦG#.\t{UC -?S\,aog€kAU6D¾F؂[%k:YЈzL ߶eUZ6\L`fl/VSb.WћqK,8B]l޳ 8 g*Ma.smC̻+P+Sg0AllSńҨ>7>"raF#:uͩUYHgzBgcey;#J}ˀ{[u o掰ZY<X܂<,Qe87n*={Z|wV)4nv\x6I(ڇ7G;]&8/?Or6N:n=n펪FMx(0xHX%Uӊh2`(2$#Hm @łHE`CTL4UЄ58eP~^Sfy  uy~EE5d4F(wToɛC[vFKϺGmH{|dA)} #u@p/'Orlo-tENu=ϞC"y+ښĉ~qOa P%,ش֩ΖxRD-^NVG~+V7nd5 0m.U~6\5wG \2~ShUё8šfN8I/jD{^Iݐ2$l+73EB{j7MV۾wYqV=p SKHA9"&h ~h%-^_+ MIR>ooUU= .qk*k潧NQ{l+cI>mU]_lEzJmTtZ?9H3S=Њc'\Hag>[}4y^"CMqn4PUqJlu[Y:=zd 'l 8#ष[BtkPA.Ȍ둣ZA#Nf瞧"㠿Xfp:Pag5+;*j5rjӇ215V2uس qM0R DXd9Pʣ_nHh (݆6 n؈@ae{Jo60 N3:"p \} ;v lc#\%;FzQe_uǡ|s :ԵWbHd C\9l5f s?n-~0 Ahh})H8%A8vYqBO859ђAz{ȟ[|ђ`䙏T;|'2 !F`';Og<Q=}]p7{YܰJXZ3|,:A'!*/jO ^GaЌ/ayv[@. 9{MwUNm&>&XbzFtLs)eQ+LӔg-*E!l^[$!.J8q'l:~4DzaDy5(7eے8䳷8G ,DU7Гǁٹ:tII[Z_'[a;Mwkq$kFZ=UO@e|(+Ҏ`Db|܍;ey{FYD"D_Ka2^Þڪ 'r^SUqY^dA?b o['Y-vm3QiαA_o% "|k4~!1gARN VV#]qD7o,xWuZgquXgADrOS$Y/:90 i :&Q7(}pvFN NX?SOyismGDu^{4'7aʷJۈ\ .jAHHl );}\FR흯Ul Cy^'qlJ2qyk3Zj7H&f~%f)ӡ3A)qHU[ѹԮFiIW/jAκц܀hnP?1,mt4bdؙAjo;@bӔ D!ϵ~2T`_^[F.`vU-"'Z4Ҙd οdҔ)&T-eVcO _1'~۰Xp< ɺ?j٠4˂wE=-wsv=dBhZ.с*Рw_ElmoI^㮡q@z>23i(l§%>\jɸJm6Kbe2!%_"ZwѯՐ3H\CMѯ+qKhL6|p"OWycv~ooRNHG3)]£'; U'0>Q=˖d-BZT)Ԛ1;kf6_&a~95h-q6 *͂c5ʰAtj!WRNB3:ᑮhUA7#w/i㬪 lM:_l-!x[c'TF0tJ[v&D8ablik:Xx W7)ϳd[j\lثmEdʫBMd'>)t2aF-QYFα$ЅVqf\ O fޣV\/y}urf<˼Ny\B17n(&P[{,+aS0s;[}n뀨j)꣭ 6jڎs~C-]p𻸧w`)?6;%Pyz)!̰J؈=7J>(٦ijŌQ1i aef=еw(sU< X1%~vXG6ՑP2y9,ʅ:Ξǒ9y X&b+iS3цyCTA(%oZ>'ӕhW[YBNCA1M ˜ȣx=g *P3'e%&6L;b^zr۱3l ~;I(}j19< Jǵ.rP&{Nc+yWb<'hwV.qZs96Lm_\_GI9m[O-1"fB* ztS|_tyTZ#MPH@$ -f!u fx3n$VmR(nКe3_4+C%/i "?'òSy |k_'-f5cmC1n{7ޕkhHTuָ"nML{aF'hP*lW.N L 8o%VH^γ۷>c 3C$Fb GPPC#x@-YTOF| ,< BbheV縯YVQeO 񱻁ET5ASUΞqzps\߼2F7u*Q9׀Ư>V{oFvÆ~^;4i58%ա'Sߙ<:F1*3R^!SPɋEmDQgM5N Vͨq"XhbŞkVnfUdb2ʷ.آ{v+5l '-q?JRFxߛMC K3R? U0рN!dC2$qƘekWd+|5p\sav?9ܢ\&4j!hI߯ko_F0=S۱^V˲s^WHMR Aԟ8ظfe YY)pXlfM ԮC1qM&'b&E1x3Yv*Zl=SF^tڗ *Dسr8)j_tU9Uym bL߾ߡG9Ʌ4: /3o ;;X\+ȊR&^F*Z6U&@- VeR$ |j G[Vb:3(Sk|!!%78{!pT׍ #O⣒I pL05 PFu2 9CMt$/Bݟlx 1Bv0]bgdž;F* *z@<ΰW,[o%CECz8X$QidkBp~a`~"!+ܝzzL''\q[frI7 0=Ij'3$ʧhWnBǭG3(p r1Ѳ MY%'4OϾu.)$*rT2wS[E0d9?ˎM.JG_]txs`:d7l J'듒T˯`#ӑ)y}م SFWM[]<qDmZ`Hx m}+*J_ˋ dihIIAJv~FI-GR>ulNEkSA&~Pm( oˑ!DDyQ>}l&45_͵oh]wpnu{ys^\JQG։|` >R !~j4;="G3jk y8Qpn'k7fkنZڬ$Ž>5YۮL`U>_^6Yb|Ç!9eG1sd%Ix7yǂN!qꪯg{}u'iy4 ׺'Ү & ?Ћ`[~[|D1KQ-U0V2`Vy5w 6.1jA>اhN {tr_kOc9e$PU }crw, 4q'qg !A)jj'Ǔ>,Țv<@e.grrÌuA͸}憐wxK Ugv..fIj>k i%}% z2CBЗʴ9qa4h0WtM"lyB cYu)^ѪS4~ξA &+2}W ,ϋ\<ݏ8C;pqU[u \A'6>&z0EnZ\G@vJ jxuT`9(pdI>iŅY0e'TQZ=rH/p ˠ8Nj 4`rO2ļSmNvc"blʟ|湫~]+ubƏ8ٹ1s :NR>C]5SgZp; L߃%w7B<?FD$exn B'Țc/L~ D1ʅMm"W Њw0*25T+~M$ov+3lFLuGٕ4|jLJS HVYP$-g1gUh+/p3NJE MCNyHȵ$,q ýD,P5yyQG.Gˎmvߍz._uk9PO(@ϑ8-K Q7!eL ˀXKPbK8#p͚ܺ'IHuDm$pbJdrr`Zu/Qd,ͣmE(>kUF+ڝ`قA;֨` x'IB$4sxԫ nB hM<6^d%bH)r5Z| R w?H f¶mrqXV]y1'uꅧCɥ7wﱘ>У)w"; h%t2 . enM=HyzDOkF:_3[ &4&/n6v8G-z>q)+ a(G"@ߘZU.CpWuˊdG| 6zaHsk}ѺZՖxs˝ZxG4d4M tȱA 2O\"6xCUG ?Am^YBɏQte%)sƒ=miOa{ՋJSi[i\ BN?Mt l;aNۛAl,QǗ>lWT\ʣ^c(qC}aH| f}#(C@`3RֳSlu^-᥍F,ɍ/Fv:͇uw5D3 %θ Yo`KCT,$u[ aMy.Or)Ш \lzI #*i^`=EF0m7'0%C캊,%ٕ x66}q0֏'%\y>FFm()'L+<1`X %JJimF[6J̘SI<=җvDy/Ѻү8֑;|6>O}?S'Q,z02>rAPu3TX<t8xy=yS'r>'#zrBo^sG]im?ZRZeN!Z3.><,` Y:H5KnNVݤjY 1)O"kN矕ڳg2ld3eȅAxU4oo:N!ׇ;4n=F~,„Ti29?:5 u]SÅE?ܬ=}x=Ϛ)սml5F+Kq9 XQ R~ av Gh+΅f}[%twXpmhu{G4+Rh+dhtgD9x{ew^49NN?g1U:a lgvLft<\QH?UR~S@hV`ǵO!|Fӕ;X=E\1e/ z$5U=~']92BF0~Qﱭ%vI~QlH(#E-W pYDMhDOI%ɳ6jm)>o2dܙyjX[WhW Ę֌6O(C~P^ppGE)+Ie Q`xpWPy`}~N&@vDD!;#5stiqY0G#uܥYb;POxS z@azY=!|Kȥ;cu,ZHr~*efa)_A NR~C7:AL8z@ulRu\\(9KXhtsO>(G*!Ws裔#G9zhўVB.pOlpm+k&ȧNwo@^DH0tV32Y= M\<5حb&ch%bpϭ;oC-ߒxB3ϧ ] 1lpcۗLnS43d`,ndӛ${UƞMh*DDUմNXoshcH_RcK̃(jОރf۠>)O8o!@f'ɍ% ,< ֮\90Ng  Bf<>./nɁI^ӪIVҋ>$yд݅on?KKe-cVF{ y<5ןJE!}dx5 u鐋xGuɾ/YF=)k|u2+. 2%i,ИPL!K  .YcCcTio#b);ؼlf_zz">AzKHxo-@w&LU{xڨ$y(GvDlX&Ldލom_yڈx5Egn?by,̟Lg<.*,;2Z}&䛏_eא} 5[6E1=OOAL;{و:gGGBZ7· x٬'35Oa,~ιw:+$J$5uξ\Ńha!#=}GZ !ڸP^jofꉌ}iD)e7=Q$&k40:;Sxn5{Ye%0~_mR].nYWiba)lo;!T0q ^O>eI"]%[ !ĒI75*MJa~̭uޯxY=wx+3>IfyR@),+7DZ˽~H` c_)~p~6ɬ儳 C*B6QWcAt}ȨLK5:o>bZϹEjQ9mW]CBcRS 'axsZsNK! srلhtg ts>@90J7d_@f5߅.QSվAoWE*'rw~8jj!iCJ G^:d?P/^Ȗ P*dv&IqaMnÉXc w#_h lLSnZ_|ܲG7OMP̈́ae=W|hw(o[KȞ3% # u9ʥKׁә`շKJZpZZE P&5G]-l;eF^i{5-wS%(CDpz,gs`,a0ӰzUP!ZnL\W+FwF ?%bain&ܯXc~%k XW1s>uj,@ =|t'5j <"`nQFjyYdA!wy{-j0PގWđ`/.u"q+X"{TS(Z6Z3p)K,\Ȗb'Vf1Kv;#koIBeO+_;=Zl59 i[ԁ kCg!@YJ$-psCS 'JYTK~Unq1 cC TB ~؁ӟ˝|-^8'_eRBo]v Y2(ӭV˺^痪hCKGa~ w﷎v$_(XWyK2cd^B9-jm(9g 3- aDE@) Ҽtf<۸xmP%qڵ%aL/iicȣ//f0$2.7S?]c7WhE0E9s$hIJA[q^jDfh62%UI % w:- <9.kiM[?\C,-/@1*,KJoXԷfYɹ38׭kv6ԎfaP:}I*%~5+L׏Tul3 ׅj8Iද5]JG&פp}ͬ5Ɯ-j3:wb㵱#)O~tS%{Rf9ٝߞ}D|cCºm)A 5Yc_ x Qi\oRДvebc+X%}uıLbO EEs; ]B sMsRBC|!x݌v\Bwf%T 3Pr(:6nYmn" ipd[8I8,ڜzל]̞H`2C*m=@ >3o M k%ŋcЫȡyu) ThryZ'ٛ9U:l`oہI/ּnVtt7hC?w2vj$5e}"V6C/+č+u\?2?3[ [w`%ē#H?M\Yb|mNfnJt}}EWHO|"`mªuT1^][B:E4s2 iM`H4e/$2~"z&B2;33Д*oق*9 ”~'9FP(,?sJT8كGN)*C~{ovc1syd!8UŪWƥ6~Q I$۹W7 |4ح ,-mZc[Ug[U݋8$'IƮ1gߝ+f]\⧥{HmV9]"T PA P~ʁB_ ?DT)!N _>^|E> '!90 ,/] <ȓ5Tf= ]OmiPAz!  @wu0A/shsGE{7X;y:Hq3I$Lre諶SP%ptmkhI;P`%'˶v!S-^ _*<IYWHwVo9|$LCq PUN0ɫ. `ubZsǀ7')u<4îx8&UTO\C9UҤ-ohHo'!^io;,7?liAj\b%#o2:Bd|&ϟPhBmAv{܄:3nz m |w:8W>hFùHH|`8 rߴv9cm˧]Tŋ ] :4"WQ:6GSkm/U LvZ'*_%d`nzE3Cm[L ۈE4'TaHL4+HK:k>K6 ^fe/&F#:ķX12i]YҨ:2ff [Êb]EfRF\+xJrn2pQ`ORZx>'AB&O98FDH0DP1j4򔑦P0ߋ*NZZ@A!oMalrc,ߑl8'#)ن)Ę{ɇI3>8}aR(Y{7HI}6&dmlCL=JJ̓gR"/)+ebHH"AS|*zGY)|<-gVy%}E"s_Clvblk"!⠮{؁״_+޹%5~:Wa0@qϒP,< .W xܚVYp ёI0#5I"!6_UYشr^ m,o.*q UPvĦyz/& ',b;RbǎiR$ďiI+k/~=u6 W>DĿMIh af/Hy^Cp8ٸ_6ZN+FA?O~5Ჭ֛3_s3ݎl#J'Oj?:PiFy. mxg~⸕ӱ,%'Yl} .z9w±L%DA +qW@U[zXL@#\6dTenj_W|̢=?PD/#r2Z*B%C|eTtG I5R_v8%mq)zds?gHoK)6qŁ~$>y(˧hJd[er*h1=%FJ(zFHЕ.*d¸jev#+5t2+عݕ*woZ{sF>lZ?HZyǿO~%"QR?2{A".2}Pa X4nXOD\0xWZsG|i&)L0n:.5y򘄢%xܿۀ6&r ZpQTP6B_Ш@-t`VTPbyP+X[oIdH&uJ3l!Pڲ/!4qd"3ؿv$GhFןͱql2k␄Uu~_t9I?iAh5ڷ !qV')dڳTDs:=CFSǢ4ȋЭax0N0kv腧;[7sڛB5S̘&+*,i,8y)8sr#C_ވcAaclb8L C'J w^i?`q <[$z?|6ģ J$s[B`<W~{/e?QFO7;4Db}&gzĊ0K>B6ѓbxl]7˸fp$Å,reNR=J_#`0Iu ~0L.G(8R46,KQuWԃbۨ֓ioGSұY+x YxFoٓ9l6=cϕn/G&kEd߼m 瓗ɦfAM!h':K?kBUN~l3Mԍ6>cc[/Q+-DJM{aAB]CE` ~xwX so,r7giUmcWoYiyi"82 K  uJ(/? ], &0mYGuE1 K-ЯmlFERe_'/ы~kzWK$+n~&/>2y<[[qyZ>1@eLɊl H3>ZϷ) \߽H㈹'Be)O׸=,y_PՎ3|gCрV3?{+OW5_aʲ)H`%ItoưPҊ{?-riYY1;=̓BU="/uVqR]yjrIv)TQƓ;@f`M0/zFxܑ~| I}*NXLwiSr?8@̓<7np3=5Yԑ4X 5GqVA#S4+N0nKqzԪM_)/#KtōTvpƻ蓝0uX}hx@.ʛg d@&8D!^PB %Km0RNAטI>ql듭Q:|~ ɤh,#U__\SXˋDZA!'ʔSC(c ̳ץGKq\5ސJ'i^K~0IPnۈ)[ i0|X?erb&nD'K!)YPdhzβʱM_ȳIWR%.*Ygq0p|WChz2jWx ͚FSxZ0iJ`] "K'j &4^сy|/M@WTC;QzmNL\hY"-q'qGGH*'tLmoQhCP7Y?[(\ycjr-ĉeq#8RHHdrB+.N3΢jTn5zh3><7ul$b9NEA]>F?$Ey]Oa\+>j>"Sm;ٯfC9 (;GW5A!fܧ:]bdVEYvⷀٽ͓o=$h2,L0Jq=5яӱ^&FKkeZ%I5  ϱ[-2c$}UrDUI }>5N `MH?j`Ϻ|HR(ؠtpW$M^LBv~X׵c^^U-C2%3uS;_cf 1Cͬ]1洕1 r G^BNYlˣ }*Soԟ!RNdD y'Zimyd}߭bWV|A3GAZ?I/"7KeM}Iχ@vbQ͐T(ZBJ: >يp߭0@Y?zheV"9x\Vڰr'/2X~"`ރq M8*VGXθ:y ]H>=cyJx[ͷmzZ 2?Y&+lWV5Fg0zm1窒3Kv J:HUWe]n3οVlQ[IH8cm 0`k5sou]"-'5~1pwE$ya22i*+8 PjbGtAQ 2eOؘbLnU[.Hx¬vJdW},L UNʤ҆v5tNRX/DVaԂwo]@Ld5U6"Ll-䍅"go7hsn0+ ejo̦x:[ie9r汰Q YF0[ $7ɾuo$ XWʹPbI1,-Hjn &Iwi7E='(8x`J&F!7G 0k/vK L ʜfͯ9(b-CʓwWAYȟwhsTȗL0,ֺ&WSFA *TETsw+@B c"b"J ٌX^@cǍgة5x3+ ]˸]=#? 2#v|k5_,^*p/@>\ѸrǍwD}v2p?F UAymDZŎȂp&(V#sl:نBa'G ܖ #g͸Bm]8/a=~_:8U ºc?s,T'>ˬpQbs(s~Z\Љ}rױ^Ke-rJDUx'9=֓@ 2\c&@`H{CEPb[>#7til ٌ2Ɯ} +xn=8=Z1$x]#52°|[X"؞?UCnGœ[1}Jm18\?Q iG@iG%g#‘q2.hxa]u0]+ Va,`g|zJTgSLsXTl l*87/_dte߀G#bUix#.fd\b *mᨷe!eOM湐tDE] )9_PiϪ,EcUH"vXIaouBO啢HQ@=\ip'iڥ?:l>Ӛz-obFNO?BXς'VVfMN&+]C{A>,aN$IGbO`7]s`2֐'x ߊ&appimx!!r17Y-i(42 ]{SvYur A$ig8'T4be1}4@yq(%;cތ$"򩒂œ02=Fך6΢?ԉ08VV0 FqLuNιM&@Z$ .=MqvZ7x8l%K gGsqnGTy+HP͸$m &6뾷$|/] Y -a /wv2\ LrY%5D7aor?Mi91w;leAV2&YPg dͷ {R:^#ݔpF鰅зOYYL )Eև4V8١C?hw9# ΀/pEMZ2ʇ)Cdi#oْe68Os3 .zߧW@SX2ᣇo3b_80P= 9eɝXHjԘr,'d "y<9|qX;yZ7^na5cy!F:s8ئsBm[qOc$7稆>f4B=&*6O^LS "Lް5ռ`oAjx2x=XѨv…ʄS M@1;w!xHm(i{s*mX ;ZW]vDXWE n[΀B94ıl,Bv+x#n.ɝBb,]Z^UzI WN }Pl5=@&ķOs]TfX$DUᝮ3\XBf&AfթlcYc7"Pbsj%Z{=e#Џ jm]ķ n1{%ϊBs:$mBS-xZt9t,;ЕeiU]].BӉѠ{ۡ2SEyǿG`Q@|P.nxxέNiB%nG|"T xpqpXQAsѦR)!M &] ml`݈{ |箖2^O>]Ŧ>g7[=e[5 -hb)Ph~nCA%B:fwweP d\:O/cyrag{U3b{ܒ/kA1Lp-=) 5@= 5ˬ/4E %m9+ک(9W-VOMRt"ta#Scu:A۽$;j%h\V`7m PZv:#b7P==٘glh>>n:!_e}WT6c_9:HAƻ "ЩOأY`%P6$M 8=~i%(zGz"rP'NTd%.@`hsR9{w!<8ψ% KhP꽲ָW}> w^4J҄ۆj?};P5qZGBI/oQ%jc3WztpٖI )ÆKh}5UٝoJ5NLµOy].siͯlred\mnkf_G4U|+@7n9;T%`G@FjUJd8lVV^h5uBܡ?~W6֨\c7Y\14<ng["wX@{N^{7 =R|]mH_DD_z+(=$m< R)CsDzQqB`X,Lչw*#7 qнr6WϺO6`7/Zf}5gұGRU±;9(Ե=_aQ݆?z<Γ`c-HY8 7Qi҂Qg&*VBބ d&hq(qRf\ʢ,ZԮ(z{ΙҜr_c^F07Ol$Gʁ3y _o&} S,R42< oeY|0?JH౱+C6=ہHql` #IL@ܞ›Q;*kGS3=bY.K6MҹلQl>zu{p>N G->T$tcazO!5}ېtnK|$fK]wp\` 5KӀ;֔#S=. xk߰_KpAH$6*-4,Q2rkU- K8ma UPn1mӚP8߆Nms"s" 2kA/9N&4fWgI.="dtʷ>+"OFX:S_d9"g1'B1v%K+Z _~V/m`,7녜@ %x?5=L޾qf6H@+Z%.=g|#B#ܝ,ӵ}P"? _ Z:j^ݹ.f3TMMq1scYO_'\*d5@(F{{f^,y7pძ_'kWG߉䬫jY&)blSO|n0xL.c*Py0ezDFvH&* ^܊pr+K<58C`PЁlCE )Ԅ#cW uWU#wۆ" <8.\r!?W&W@~>?DQK-GYgܜω <}Ye>!ɺ7/bq>ڡVwSi]). ~1q;Sᇠ,:̗l@`^S./^nK e꿨좱U}E;r4޷^ҸV&Zf~VZ%,/ސv-i NjsHL`2zuܻ\<."QDVW-ÅRWHc\_922P : ,z[Yz$4 e9 _@՟ 2m\l3b H/ @yzI$%8%nJC7@s"1V}4ݾךs-#ZCC#{/X{P WY>xygkW!ڼyC #i!v]QZHVXJL`xgR*s1+HJzB_aceLㄑx\1|p*3w欜-4넻O[蟠Xjpu6!2Ԣ'8Y\gviXv69edZؿkCN\zO-)Y6ƸZޢmRB%?Du9siSAQE{)%SvLYN@g+cwf;BV(5j]noC#̒ۍ+&CR&Z qf+~<ӘyU:-z;ԝ곽M9Kk6ZM!5UE%'^:~-iHR )]`1W?Dȯ } =J! =]2FMU3dDĭ`2}RMU_̭)ʃl؟/2ɯepz E,mNM;݈YKX% )wxF7jovKU@`3ih [׌.`[i3zFih0lumz/`(: ,eW[G skt`B4$]%o,7 ^r.X5-5cX[?Xٔ'gqyW,/5d9:.FҼە'ɥ=dFs;~c%#Jw "Lʅ YR=-7^OsuLIgdma< B1WӕFuף^>pDdZ\˞]cBVj\=ǹN{@ܒ/ VemPVI&ZD(|:ۥ4x~V,p*@bzEsG!Vu\Z 8bTƼ_D:v)٫/P뇐WiP`<\ԦNV (}Vc BH!;D4~*=CI2ܳTpo[&Rk. t"s7ӵ+5RE .Ɇǭ6tCe|+'7:ŠV[UrcJyn0 3٩ZlywqtMb5܎ Ҍ{=]kg,g̳:~Q6?n@+(L¥5 Pfbw $MUd!Fa>῟һ2Pm sMGU>fАwrWIښlVZ܉DVEHiOsԮ@YAÝl|=k'1!iwzt3J9as4E}ZJCr^_1 sv#i9~R-EbáUMJ;XTvM֋y!XD8u1+k'16YhJSNF~VELzDN-"5#e_-.[\X{A# `Y_M0`U2i]R"= ]і%}RFN>Ȍ4;LU"=tLlJ gIMw'*J? Fm}H%`qwN[R%xk?BS-.nV a755V0!1u:JN=rS2%h:1'5>Aw'@yD4qptܨGިBȇyYуƏ&OZTE-~A= ,;IĽ<9cOƨ)"gƒQS[7n\n![M@`AጛWcQ_}i %iargp'(iKЅe쯙@_ o I7yq0f"#awu- 0`1 |Vʞ\w#1~E|XO5evKT6\v+іP ' 0ZV+cj,`K$\FO!s^PL@gk"b$9NO2X}TѢmSefPuWфj>KGAY׈Vx@Y)xd;tY LbMyV+bLk0w |7Œ^<~ (cT"]Fx=\y_P~9i|-u8٭@mq0:Fœk:4N&!zKHJLhE<XI1Z Ies+cGv/(՚8"+#k=A#<:f껄Ф^-d`$4r9b~[z䣜%ve_Lj7_0wMDcIs7vtC~1 ^[Yo~]T";WAol ZK*뀋 ڨ7z[T1wjxs5+ʥ+kt LT 9x3]M0l6dWHˇ,'Hgf74GD2Zk@kN6.Xm s0jrk .e0M 8 W,.7Px+- /_`+{ȘW`٫mW@[ JMק[F@k~ɜ]M'Gbo~D7,Mv }#ڋL I %O٥ >D\ÎxQ 6Ĕ;'\dpU= mŸ+غ=&6zV> vdkͰh%}_Lupbedz/,~=n&!j>䚒%ox7HT(R 3''bAdG2%LR!B,Fۧ |o 4ߤuVP/q`řbc (3bԽQL Gtȇ.zFJ5(If廉ࡀ$@y|)br^6(]r/4~- 'pxfؠV%P4t饍AhaF-Fuچ؝NERxq 8H xk 2UN1A5¬-S.SMźC/U^?T#p}Z]!19ha %/}wJ p|j{㞔a%dxYk7r4iSԼ)~u]^3} @&"7QIW'-<`Ӊ[!>7y,_|+%+$kx=W(*,}bJq *Ɨ\QϸV* Ifv3-fȭ{|'w`*CNbJif"jT|DA3QpTw"Lʉ,g? E.^°6bCp @AS$uR=3Qw x3qءU80)R" 49/l%@k-Bz}*Yc/\2SR?pUCv'<!YhA$q_EnZ;Ɖխ !+h/dbI D!ϋO7f..៩1|"i$(J`a ]Ix#0=L\@lg }-^kf<}5Cʑ/sE2/<[*!оd#kem#8Pԋ} 2\9!UD&7MY446o{_~Lk6F/&wwfE1MHϮfB[w#z&ަ `٤8vݏN9C$y]ɸtevT˥$mYɌHrq,US))R _UԙۇdcaRrgc Hub jTdbAњ`UgO0>ЧdbPgcjl's+i(K7 U\|\p,< Y9Q\FP4p#fL9S]&%&R QP98u)k}pÎ5EM8/cJJZ(U!"ۡ0PLWq.>5D7@,8X[/)!+Ѷڇ},oyxs镞K:)^d3FC[%~a hx"5dzN$PvIJ;Y& pX5qR2/75܉]1zHlfu6hrV|A^EODTuYzgR-gF}s_d]X\p tW]1Q}n`~knrEc6ET t4Lt]Q:}㍫}(scGOn|H# ' L,XDs cFQ}lٍn݈PQݵ'j~ڏ\%|r r :XUl/U &'JR\L0X= !AtC)˘=IŪCf;% bxjeGd "񽊲!8bcSɕ,,=j=ڼ5ARy.} NXDfrG8]jb.#JdIV @:[Vk @5{ڹ^ꩴ|% ؎,m}'>6z.]/nMn"(|\Y(B\돎/S_Rcazo2kO5 >(3FLbG-egzjp4M?e'bok/DbV5hG ۬*y)}w䔫oOuA 5DŐwIT~6o+i&Ln\eIyb҅%Tw{emAȧlĩ:bbn.JZpZƌ۠APx+Bj *qxxX1:NtC$! ԇʮ;NkqpMVÑHEK:`  Pš0R|9dC|p'aP_CUxS:_*K<\f C7ӻ4Hr_/[ 5?M,Doh瀠vGgL:LDdQMfPOƗ ZC=͈/o3;|Vb&ό0]ꐝ3~.x4]9 eIhٗ 1XHB_;|)W{~7AT_9'Y=FڬĀB7~1dp*SU)ŮFI@cCzgUI"d'` ,"IkF=v78dC )}^bl_BǗ9K?X?-ĵH3m HE~Ǽ0tDޤTkL_ڀb/[f +%u/6o+p'ELvc>#Ը3|bP^` °DEK'z)qWV7~\ivPpIU9f(9+ʇg pt"гFiŗc.it+ Z˝[70Nywp3*) N{Ү}۝2c(CEp6A{Y2`-o12. ˢMr>wv̨IVS2E4eK ur?! dK50h(ĵk5,I'?c8ߏ?΍aː zCά4F3kxX[;Lo@&Bjk2|4}2Y߁=j*{pp4HnsL.ݤ=;<EְYE\<̫O̶=\'B צ};ɕg`f4x&Ysxf<  U>5bCI6:I*bt`F}Fg5_Zo).-+"#*?xҕ~V+a(/>o@nᐪݎk)TGAб^qFp2xzm:gPRy`crY_JC A,?%`x9$fa",nHQZsk.-Mt,|?s|d!e&hl*=舘cTگ|W+Cob0eqc;[U|+^Zq&W_Q?0͝mj!BqДJ[ &{TP('Er)qm- 2v俱cuƩA ێ OCyDD!K/:Zk #|:'2"Lk0aw{H4ou7g +W Ŏ+*˘fñvSP(M {e"bV{%yU똬+ Aŝ[z\} y F@ &pn MЧU{&>/(Q"kx2qJ0dm._GtER sl#E$ t s!hFڵ430*Ju! dO Qi^&"ñZMݒ9_U tiOns^sa݃&>1'F_U1a츲km6cy_?y&ߐ] n7d SviUklgQHv[HpG:fڣ+vL uz&z$X+Ϲu8zzv*N!t3.\)8'T^ uR ==|ZG91c̚ߐv!>NCa7v~KTUaa#n*]}ql2h!&B#>Z*tM}M=Uj7՗*i*:ie<BCk^+(*/4hVvTO7A[M(yn]h"8 v,wBҭ'u<3ss6Lws(`|1q _X(,B9m D.іo6:N3M31SZޮ=b63ON5@x6Dּ˯&B_durnK/kR(9 Lş6O6W ,DN#e(NNGZ R}2}Hj`2J>ĕi'cS{!O%bͅz>>w UŎC=wD^a4]>O|ˆ0(>k#iӓz$t(CPiĸMvdb8z_uTl+=ղ3%WY^s5D.3Σ[Eǟ׹7!>mjab[nmy:ɶƘ}abn[9 nbLL)eP q+ZOfSta)[*Al. _g`*tLXVli\uR\&:[k}3ԛL;q}'їODY,mZ  _GlXȿ 3d0XDD~Tg<$YNnEHav ڭjp(yׅI8#%yv$UZ|GEhz(cq>̡KR#k _Ya U:=IT K$o*X3HT$"o` {O4uGnU`6-?i_<&FS7IDFm &s2KiꁍEۯԌTGo*½y"ͣ>b_JSaWvP~|)kB>y'!nHd rbT#8ρ( Whz N15w l-;~w]\<51Ir"3`t7ǖHjPDmL5LO)dMՋ2|]N ve~4N`b(OQGQz5Fv%> ?dw8N}&|BHv,m郈 Zz3 DIy]|j>/:v0ӬW&np lWh8(Dhb/=O!_ Io');@V*]c_gw*w hH }~A{_!t^ GzĜۛewM4Oi!AD?eYXHH|W}4͞L}o~4R•W-\9Qzҕ6ʭf:Ē6߶cAZx)恽-!TE.ckg$a:GᣞT`hཀྵe ^ 9%sa,1qgȴ^<~ʴMRw #Z,k[+ruv# ߣSP2D\AOzS]H,q& cvdؼ`?Egrm=O8|&)0A)Fn \k᱗If+ql٥:Sn%W2(jt{Pk(f9M%N!p/Py`򋔱)fcbhz֮xi5>0a,6Ϣj:9 E z+QkF/KSC;dLC n#Yw#Z^>e &l%58a_ ߰k|Z~6mt}ey$ԩrrc2ܕ8SXl+QSJ fAאG|$&}TG JEo咎u3C ЉeҜ*r})Yӿ\0ۈ !oA #RiG=(qqǔjhlӍx.Ep;sXS,|q/;xX_b4sx2kmͨ)ŤPj*\\Msc[ <˙l `Uŀ!"Q^E}B ,# dۡ2t"M.bPC 3'5YD䇬#'^}A}*M"u?Y-=>:_Qesh688~#g o,%cPt o= 9Hfm8)הzRxg3̒`s SF֔Q"/cL &=߁:mI)6C0Y#ݡm-&@&)X.om"x'9skىn'De\DaEQaa5=GnCy28޸x ]O^=Wfs $E}a33] c,Z&\ao)T]QR?;$0.hf5-I.rt!s|qʑC6 I۽_=Ev7ѐ>U >/T$x|4Xi>ᕚ6&wR%2 N0jy[@.<rz{oE[2^1NazlO`6`ޝ6+u{$6`g@UIڍի0[Ef, (8u{N/4H{Viky^L߫B2 'nc0 W=2L±ʢ-̥2ҕ̘tN{LIlG'pW9/>k 7yč|R@yE~7zmįi& qY\t/ J/yC P0W Y]oEzϟ'RE E@̴Iv(~cF}H~mUl IRw/%M+zW-;*=̇R|Pfo5Vmn ,°_ٗ¶'"^p+!- [=ˀI snY_(QK7բ(3#^ F]U,rɜWe7+Ѹ5nxvTx΀͢C>oe{lkIw\#K}:\]},\` '/)֌F_pH?3T,V'k#@-z[x%vFCB҇jeg})O>t$]n 6=QT׏hwp 8BCxl,e`fPRO[]lסXOŸ_A^S֛hY)8d׵Js@' C^M M'eq+L+ThMc9hy7pꮘErY(Zh\kp6;ļĔaS^& >T#fa6]}aEʺ/xc}g+t]4_@iXaaˬWs\m4>#&4d~c{2-GAtSQN+ۉE7y͂mIEs' 惁8=dNb>߂S"},⭥ # VM[#pƖ(o tTH0ߵ<=T+3?\b]8b`" O}CW#n]'kiNPIOq{+$~hv+ Y8C'ꚇr*µK!3y E?}xqDBrոU4s = ?W&tuX9aoq?`s~ha#¼ ǡ\_T$5t7og Ojk网e wlFg%X'x]l(ɡ54*@S`I:0ۛ''Ni5V'5/UWMR]k*vrYNxmuv*D5l5i]zD=,dz*c@I`z%XSO7XrɄs`Ͱ6@0f&иBLHxݫE})RH b~;$+,ue6?<<y=ʝsQ—r ǾǸГ{|1RgXOCTF%T߀do3XB#\%O?ğ3Xyuށ0[b}AxO2hʁU a<]<;)MsXtEva>^E3&yUliX8__Ywcg ;h)$ly j`>j'O^pV =%HL 2u :B`Q:.;JhtYZR٫}|VxX-I6 >fn6ڎ!xJA5'Fnx_{ 3tcctW290/xHisKAZ`7Zu;]>+]8"y0&oHPPzX~K2({H8 @­vsw-SЂQ_PoXT`LCA0Ť>4׿tKj=[.ۙPbbbr~Ѷl@Ff b{bcZ~Ԗ(M!/m6Ytg2aJZm.>MV \x"*·s\(*Rcy8}Ǹb~qΚˠg?CdW7)Tibh9> 7QӍj=?y1Q2R\U &NZ ) ]C`(͌eJI: HZtI ֠&z.p[M"u儏5^DR&ro^t]L)zg=l"S6 -{mEO&6dm0,8+\Tid9hO%!q7X5䗯cym6dfo}㼹k+ жa1莌B4~Ƶ&EGG?ҽI(]'o}Ȳ:kcc#VgG?VJ8c - eWD-3?Ҟ;ǩ!!@ᝂ.Y7k%)E>;t! a. Zlc<(4C F$zD 1+t]=b[^}o (+_j(Iݛg>%-k#޲tM=v.r %OϧLti !\Ai^N\ ; ԠL*)nA@+E=V&ð@l/"M~ynȺܹDAU9rח C;g\`j:$]\49,xYU*~TYMHBgP:0ow7鑬RSOy4*TkGp&|EZ88Wa p~JY'*|"kel_w"nSІ?lD YDpOP5\4)& }-APN,*ԭY*mh >`IW.ʣ4Zv VD سtP :\78 6lRH5jԉgI_!9OqDEۃРR\k/4Pz!wxO?*ņKE%S>j ڮ4R$@/r&6?<9L AM2'n6K1YP8} ggZ Z/2exήe"/` '5 `aϙ54͋F 3 pxp}o_#-2i/ %O`:iv-}T{Ό3Aia4 e >OYd/QƲLsE1-#cmV)p;`97h?:|D Rer'Wmgt6YEψ.B7"x,p>u;*tP#_I[t̜=ؤ?` dEڰ>/%ѓ}oޓit&/rpu}G~~D"Ѧ"hH/|cNqWDFBˍ&ƥ IyȴJɛFt\]' /wiw5*sVtN7S'ǎdT6o@)\0c}mJ%obny@?`Pjl;{s5)8߉ND#Q!:MU݅K؅3j4u3xh\ImhfD٨gdGFZQ>%zzai`(Gftn3`q_Ac5Cʜ:OO2?U4o6Evpru)zD+"=2Q ~c3+&9~ζG @93zQn%O E;V)1#$S,w90SElzѝh=ȭabf -ű@v) ]燚 jeXV߫6$$Rϓ'hHc^81ó:ȸ핃 Gzm?M{ FZ 4bqvGsCʋ!'f\%ee+F˂jO0Z_w%NǦlԿO3*'p<n 1 @*׹<x_ku#xr;c= &=jG=rec;pFϧ?47Nƫp|+㓯yHYyKlp.imÎUzB؅+$zw"iHMPSI'[6qjy _醙u]PB75 zC0ӟ50@Կ% f^(Ćx$C&RU=VZc- ,aUL@&OYlW @ͅMqd8:ջ<4(ՋB豮}%~}m?{AZ+oկ֤p1=x?S"GB+Z[b0@<,q"/{u59oK#ڎ ~%0ң%VQ[DҙP9K]jYހ X-x|bw2. $<-{E+Ƥ1G[C5[*w,pT@s.C.a[\v>9$ BG({<jR|=D^]\"RطV5QL9 V7iQK[EG.LLXП Vv9cX5(+|h@R4-*cR2ښkoCa]M0SNSO=J`&Ԋ΂NÕ'u0L?*&ҺLJ|% +zx"2Y  wF~PL$"8crqu$CJcV(g* b{]$!0M46[Rnv1+ă[zzUы4_-N)j4a!Rv|GMN4gy)&B_ދi!qyKtZ~ ՄKA 'ktisRQ)袡d㍉YC#-nҌ~ۏIJYe)c:\>~f'\E˾9F:<ͱ noÊ"Tϸ95`nޙf>^ޯ|1qSՍ Jp>)w<2\x@CL>W1>af9w֮,D~C%U$~h,D`Hvۉ!U$GZ]l&: $q/-NCO@ZEWz 6? \ ʼn3̜'<;'rgj &CH Y \h:? r$`o%?WRv~`ZcMOp`*& LblW~ܚIRMhwwYO~|atz"EPm_#|sꎧ\9!um .W{iW VՉžqrBѰJPmsA&FriU{ sEP.s {c+ DfWUڣd0:d?\w;l+?KJS^|fmC\o~e8u!3=LW Dz #";Џt+Bqoyq^ {V'm|1lq.?+', ȿD'iWez rAC7Kާ'͈.jDT]yu7/{ҖW>gՖKogڲqrdL}/ 4NQ(hNSdcaEE\ݬڞ] s`~ud7"o}H XJK+7'rgGԁ) U1JRYH<:<]D;AХܖRtJF\Ǖf<>k=mgƼwq6ƝPÊ{-"40n KAHBFdؿev^*Q:E+%".(t(F*cgzX~"Rư y "h[֖~#g=H==$Og!z(RyjrÒJ]Pҟu(Z~r&2hkH4۵yCcE `8M(iJՐ*T2\j 3HÆa}3/ZC$/}s-Z݊i܋,J9mDDнP~ᓬ' EEp|B˖OJ{zU(31ʶTZ}ЭA%0)n&#Gf6kbEB{h:l R\3ݩ,y~:ӝZ,:(zW DdKë|W1NN{}e WDyj 7CA?j{ 5ܘDYƜfI r5) т5e2HK3a':]F?tcT2lYϙ__N+1.{0'd#D iXHc[H- o7f{9sZ |it×Ss ѵB|Pp}+$hu ٫^^fbCz3w0_41 &;B7KJ&cH<(~ALҌH-UI@j9~D4;$oTU`0"sFӅa`v׏yIU6@ԙta+=zzq)^یS G!HQn&kF0_qtt, &NJ+*,*yXEpzkBo4D(iJBrci` `I!S8$*i헲Odnk ~Z9dž]"vM#Pr5%+H0I$]^-/t933E1qruhe*c0%*jɌ- >5 qvwC=zp/xC"7kgޢثF[ bӛ##%x5O[8([[LօE&1,)C;f *!ը$cϞ7)$n[T` 侀FqqhݧG wY ]ꖘw$6'O2`$݄ f*H5Z+fɢH kfxȼ>dbsaML8r*]'F-HA lt*ШFHF|@j㛾,#`Q#V˴E}K2-]85C0|ɯLM(^S3.цe# 5J%HJoO𓖏5W;xjOlNW qAx4dB,ĭ;9u38dI?heY'򲔀KU;!4~V %bzf?5HaR~)硹/ SlwY(o.rݨb4F:ے S(3%Dm J'^~ g.@j gIS^=av~kluj+E=AkDlKFOok-{k۳M ᰖ;&pK1H_`?s&|u (u֫FXenQcmPΠT7G3kh^uh$oA.!=~I!b 5(eWio/Is8Imf 㘜姜s2'Ԗd;|eߙLA?<!%\P!Y9]%ȳ^T5V#)L! ŲbGC9 f, #ķ"ݝƫi#]K}acS۵ Iw) x~7{1pg[7C";So7ς"<1BO Ž{NkI^Mi  "FUI(v-*qy?+'/fqZ'ΝxdLMܴOhG?3 Ènu-r5Y~ڑz4_Ac*&k(5n}ܢD5EQ]x\"&>. ŇLPwR|㪛 x;&48-0 A"ObP'޷)V =J`k[tDŽҁ@!uL ߿N4z> Í:Q` 8onکd#IԆizQ^VSztn`5(5QZTo`C^ s)%djM1KW Sg[4E_ܯ|*f00=JSHa8 k2(wmƠRKջ QRqlk(vbMBpE ۛ4A2wD3U {+9glmd6KH3@ a`Ye/ '[jnYԓ@C+O&7 !%=O sUtH-ZS3)as Pn-f3aȞA﫬5)s +2op2ll؈:k](.$mu9@@h0-;yu~-Wn7롢ZgHT~-X&܅dofӊ VL2r7\mDJ eZ޹?lf*:n r }^o^Ʋh;>D1j8Đ_.4Zur4Cf%v% s KzVz=Gj>zd9=.M]7k$: ?V,mo%k$'* ŘK`ZEٍɠ,[mt$eka] S UQ$[,0tn~æ55KZg/ĩ^ lLӁʯW\GW1?ץɓIhwi\&ׂr.״U-İp8@rYwt+@FTQ:@++/`5]>y:mQ'Db#)րɻz.Ϣ4ub17cNFG*iUa6S;rtN!&m F*jZAɦoǾT~}|TR,]g $>x+\IE.^Q$i-@%n7<1˳Ś8/JhAR5Z']jx6<箅>M l_yG>d'Pt\8vYRՀl/н[E(*29K|qu~Nrٔ)Ɩ90ol:龜<4W*Zgk)|bs8?^F&UŎh}~ Z^A\s !O^ $o';pNI]88>Ā[ٕN O\!LWߧAz7:`fk)1^){59d<<73KCR/RySuҚ 펌1QXu>hZJ*=|Tиh/J  {i'A ~MQX$ H \(悂BlπH\)B=|}E6at4ӗ/voaO5Sp Lp`plz'S8*t?\p+mOؗ[σXeW3xQ=/69=wiY?o\;}$7tQ_%L;nr Xr3e D j-\^ӊE.=]s ٠}x"YLz5oIKE:i Dݮ)(2~?O f95VQ: ~D]&X*21nޞ_ cg^,TuKrG1ȸHˤzQx5~ Q{wL؅XPUa>+%%X"X8ZN/{!2*A@ '[Jy|_p"ˠ]B)*Q;;Iswi%Wwj[1+D~׌*ۮJ9 yCo$zOVp8` a6"-3Ǝ@/#}Yxt#W |_`!]/FUwrf^6vI9O q'R?6Ua܂#+) }h_T3(8{!,MiL77;j az sT fCzJH_nֵ5&E9x:ȏq(>d+L_9bΉ\G4ʁw3X&=֡,YhA{M`m;cȗ萶Д21 W!nACv+v\ԂLGs'/n,N)ʽ@H_ K m#5S҅a5G1%ƌW8Nx*|ٗcrFnZ,b =+9^zC-8^YF&CgF㖩pR@tL)1r]eVNBiVejR̆eA$cDRS7W_I"_]BґðRYus mVN㉤[]INAsUbxJ%Yd-%AEu0!"ώ;ד|UBg]<}N&N<8 &sYj2!(GSGSK5xأW~jμB W FkqvTMZ#Q}Mqq+oRnd?9fL9=LD Kl`䵚pNCdҀ 9FX&/8i`TA`otn䤈ާerVR1!ϖט);8ye my_[ƪ,˜Kԙ$`V=czLuL7'q-EgRyY )7 _+2q">YP#Ońpws#Y\j1GraaQ͡8F~{=v7^e Ky!mp#6R=WBmZF[l\wv$P,5z WD60bbsҬdj6Y^ZE sڽU)0˩j١a#훔,܊y?웖CNL@o0'P.Pk4pt $`pw4eA%ef1D$tHl{naVjiɈLGz^!61.'p[԰w.`7$*|dcsw}τv%4ж]!eh1 ̐C}aqQP)DŽD`r(V<C_q"_)o?u˺Movڰ3̤*VmƅB(0)4ubI!'f=kWyuV#v#& g Q nQDŽȿsEM*ͧ҇%QCp#ϱ1{*qVYLqu72l1MC&oU/lG`Z54!zHd+$~c p2l!L7k̓Ȭ;glTDZMqki Oj'vyFLt!ʨ?=֍tfcsX"8pU D?ᰄ-צmON#;ooyF;чd@mZؽxhc̏ Z32/-R|~Pݹ"hr}=,\{g\,ߔ7מkQBڰ(vb{(Ѯ)ޱ=I+٘Y2_SyçSoa;Zi{ rL\ $~n-zM.hQ,}s+f0llF,|MɭRL4f?a|Saq W@H>O~qP>h fg? `.+1 4ʛ 6̦})I,ūT~0-"nj8QHrUP3κ)3U寭,>Fk&VX !9m`%[o~嗋`kej_{qX?Uk#eZ dobHy·3%Xa>d$yoV]e@^*:z̕@V83LA{<+B F菻K>Ͼ&1"^lsb2/#ˎVY7F(_NMb(S=8Wβrt7%nh`Y;bn[ehdsuEue9gn޷<{&gx(5HO5Z6woӎ(rkI·3x6% r35m4SʥgM5'pV("#M,m}—|Чkysk5 JbIV;žah i6n)0:Zh28$lƂN|ޛ./u!:qKR^dbbe,) I@(Cle?z>KU+d} @,[Vr*z>Du") NS\ aqazV cUe-l= $X |#V ("9bpǝ"@/wk5>u/,q mnLE?8",D1Qo3۵&jZ]`>Lh@ Ē-Cwc\༬] 'z -ٔ :c ,Q`*Áѹ8G23QN#9Mv@*~4*_ЌBP!^;T.AD-1T۞&`^X^H'0n QX#P!>=!đk6Y~M:4T}4g)ua3ω>f1k/sy Yneb.MCǨ$$ +*T֤8÷Enp|s_iF=&z_[< qF,;IckOyzyX4Nqʀлw+xT'y_lSkwK p|o Cpd٠ÌwQf!H77Tj̦ZheVS)iC$gkoN^M}eO;EB>8|k 'eT3T{m]4cv#񣦆57@o MJd'ax?KS)6a`^/CTx9V[;ݑ۸nBRbJ^3D=uSg}XOכ]VŞauV-ї`[-ڇA\!leEv0tnmx,$JWF6PcRכpvMR| Ug@M At:3 ෗2ZV5[Xl l--fӍh0رS6 d5ͭ:l]T/;?[X,~)(`>|P0OP͏RS"sJ?YqH=tc#az U BQ,u#ICK0!2r]$)1t?.ӏ. Gx: X,g.n+CKjFf;ZЪZY Ȱ*,z [ ٚP!} (Q*? elJ7.rq'aa5[m9%Q:*D/FT˙AY_W>*]7ޏ9}*>ԡ$(VUː;a? k 1μ|‚vފ̺*j,]^ ezs{V&ހߚ$mēbʠ6xi#7{l-K#Lfa P ikr|bf,塲d XUangpx{wvX E24EdK~=ϋ]!ȦJѫo QoWOiՊ"v =kR1b\T$ :3U_"Ni\i7,3#եxin<ZE'pzC,3 KyB. wE,؜Ř WOGXKP[uʇ0^^AyNTv/_!sMӒuYg3TRz{H=`HE$z6+ IШT.ryնkTGg:DsE75A->ruI{xB4g2m4@3&?ڨ SCFrDVsQY4^;ӠUD8֢7c,CcsSkxS|~ҌmXv̓L :a:aMP;ٟ0oZBm6SM_hb^GmfRY H2JqεqZ:IX*v#&Qؕ3)/n[[?̚`!>{"R_=ߎoWd/q`i\suf nT$-sbk5@<.'fМ-B7F#2o{ϵCظ]T[wSg~2iqNrKfO\Bm<jZ`cN`W<6k &6\% 1'nIzR,<d 5+_{iMaRGָ;:c%ces@ѥtڕDKl,ݍ_xg'dy@lZ4vyxs-㎇p{vT4);jǘ kżGRC|Μjb:dc=I]&7kUqL4h c( {'9hW"4 x0N 3x!jQ1h9%W Z&-*mw^UvO&U737` 7y* &GAQ+k\[4{"Ƌ;a߰uy#G&lhcƬIZTʁDm,~O;3 6 ~'W+ e$U3 W1"ayELN ( ,P84[Nf5w#)2LgO}v(r\r4nʘe4Rt:ҕE, OK!lVq1aDo}_X`wU҇هk^r nGTq؅,ᯠFLNI{jk'Dz_&aڃ8 \ܴ1²bUP)gʭN3r0=S3_.pd<ݱhW=j%V9R/ ^D0J{,?YpGxuD0l dW^|ͷYKA /U.j`>pc_1&wwK0!ih8 g6z2w؇pihmitUqimrbܐȻJ]#Wd ku4QVs%\`vB.-}hc9ZǽQեO=QUr*{w9&2f E,bAbEs _2F?cGh/j0&|18) 0Q74YַdO>}[Wn+"N0[$v+$=`$Ywȡ̢ٯr|Zc{ŎPr&WiVIYQ#*rHMZtQKNo^hKT(G$2N7=}8&ʎ(E 3گ?,Í X0\|ɳ ۍx!Z <1bتk?u75젞"Sƻkhv% !kǩ^ Zn b\qjs:5Eyc1(q|%"<Հ#@3_1΀4=ų z*^ 7kL2!9;aRgfURڕY`@Bf9?b7RAU mgFͷSw+#,0IùbjrSm=CkGLO%z<9n,vZZ&|DNZET _ o1z Fv-7palϘ B"cN$ҫp1cHϾΤ Qa(5AG;Id=>e.ڸ8WxAg0% EhFCF,Q!*҄R٘mјl#{<zDMT"nw]] Y̧2zD_Nn~fA$5xgh{#rbŀcJ+DD\Y)y!J>YHi9'z hGZ޾E/C" Qq@aJMY"W0//!װV A7Vd^ ZA1o$E5|%K~!/dk!$1 kz#8n9>s)/̠ʹ2,[?Kae=>ՁhHWϝsk>ƭTTAm@}'r0V{lf0"#iq5;UJ+K ŜMS$ 2RPpi7,ΛUTYxeU/|7V&33P(Џ2 t6NYfū3~GKlWirOf-i Z\.d7')g;{kRywBAFCΛzəXwyR.`Tƀ\“bz K _Vٚo& ̮4:d| L^Jesdfl0U [J]>5cj EQI 5;#Bj^l8[D?3q[ =ycKYR2Ro[jW}l  S`וJf4z㷩 #h5ץE1 `V`zdV"T% NjCLYL)Blt:\,m7_獗ia>7Pb4@';> cyGI@0myY&0  qgսFrCԣ*ҮgsMr{|4 VQ%kx5 yJSZD>&"gα6u-۹B6Rk Pm<ǕV{/x` ɡڅ=;zl;*r-u]3Eԅ# KE$$$ETPha pTɁsJ(o3|]AȭJ`io?A2Y_e)G'nLA`"1QI'- zoe4;?]58.,tu]> ݀9앴3pE <  >-"*Zֈic4|-m# p<HB:k@wk>aJ[!O~zlh{vS,[%^jڼ:fb+if]1L9l~~(spFf.yewE.Кna,cOO?zlej~co^1ڞDn\Qw$_L?-B.}g9 %٘0c9[zD2u.`z r-͝4ˈ|:d) ܗ dqڣb9+q(_ Xs;z?0< 8@Yb/ d;)|'>I2ጦl~,|Nbz";yET6-_i  ̑1Nx]f'mmDRLmQI{Z=?sJu&Šz ЃWჼX=Mܺ']ٶ-xfp ^CL޸ s!ًȻ#yfbxDdt2cTxыcY/1:mMzgV' P0bR+.CeZ6OЊ,DH*@D6;6{ٽ)*FZ}n1fQ-8rr:?<07WDiȻ؃א #] insɅĤ@CZjH"SK?Ggnm_2V2Rv挫aϷJ&E0r tSBњT7` nG(0XU~F! 5ij\+oG%ϔlf6C0jLS[NN"m!+4>̼sC|:wQZ):_ <@T%ݜ~v+> d9c1Hf03Z{mlfdRz6{y`! HKp͉[%i$|xosߘRC5>2dsjA(c 43X6g9w+!h"TC&XJ@~zf*}SsRU#_]5 R}?"I!k2Z0P lV=~hȽvMs eH֎'?]V%BgkOhQqJ؛@Yl(LvwWxg I4 d^@σ/:ɬ>j&*'[X62S VM9#="E,2MMeVrOB#yu0~F5$M}&ߙ@$K#?U1ܡ Qd̫;lg嬣Sk2|2k7(8\Y܇o"  e\tUH?V {7 j, Qf.ږAt~W+MQd YlSh8q14.Rx- JoSxZ+ p)t}Vc8#Oh+)7)E?8_̏Wf]%;lB^ν}Ѡ|jc.#-h=n?rʑ)>x|S"}24͖_ducIͱ5M0S v_ts()ƥCt4.z`>,Bq2v_+buxJ\* >4\K-a=kX{G[ԛKA\;[4Lgä |:;%H5Ơ2zj8Ѡ@!Z0@мȭ^loWC:ׄUF(M HiN7x ='NJ}!W鸯 xY(/цsFtR]zu~3O+,α!B PC蕐cK**]^.b` ~2i:@DF[a^K`=\KaXX54;3Gm=)JEr&(qs5&"Ű̘dv\)[QC;fPa5Zs@n/׺6sL.\lm>0-F@\!Ny>/Ynb8gf PMias]bK0{c`+Q}/%Qk1 rʀ#c9*vS;-$u]Bsٸ,J̪*@?roUo/+g+R"z^ jVr2T-.)@(F,u+"( *nVn[F|/_?][yh͞_<6I &~hfk^~*z9LN+dV%e Q5[j?N_ӕET]A^˅v ¹K)%&>b.tE[! ^֨h$EHdcG^$)db((# ΎJ;[DŽ,>ff|ion` ޭ3wT#@r[t1_2K"(u!B ܍2ɨVѐ905ȏ67DޖNbn@S1oEf8t5gmky:#Y莒9 5-InoD7+IhJ? Tjvu-Jy=;>m;a2mBZdj-B #= K^^p5*5R:t <_ 7y DZq>!&3|,_%ϼ g>.B0/H1MxTIz9KmZ2~>KH'D~.!y2ê>UȞB0ݣиRͫG5KXWQ[ ހV\7ٝdB졁bDr’ Tt}γJyX1!  `][ol|gHG+ו*{w/*5-)Y%z`@Y)1FӔRkTWh,_7m$,وhuNBPrbDюHX)si$CFĭ/Y( FkfB(-(‚Ba4n|HP53[zN8dCf1B@#nf[FdJpU*FDcœB+*{]xB^T]l;@2LA]g"OR7\ k@}ZH]qM4C6 'VʾYS|HhʤpA97-uʄ1$ K'8O&7kDI#QS`qT$yw5*dzj~p1.eʛ1sdib!otOq#!B`uIwu79)8^wV둚#\F_^x8}$Rfpw+[@XCuf<*T?llT6<#'ÒfC6I9Չ:yYOӽn#DxU&%Ҫ۵m .zxl~̹ 9p#2c6AC}rOY$Vm|!]J.-GViBP+}.ǧ,QcfJ[Y7zmT׫ko2$eBx\wGQRإ;XěD &eدB[2Wcg [&&xb_ٞ$ ZR`hJ'!LEnR 87j;>OR[!앉r 7^@>1#s??Xm38gu&j7M՗22Uc$&bCtשBc)E} 1 +0(e2~SkoZ)d­7Nd:+I*W7 cv>+jZyr8^?l-˴`M)q9ibL-tG+h"KY Y?]މ/3yLP96 tXQ5*ΑZB~BCk= NԼ[M{1:rZ3䗤F(ds+H&4xW`^gȤq}FvS *N֤Dg#ɕ!^-}WMlvC >S ^iK(M7Ӝf IG )ǭ$xo4/;0'FAIRkO@d=G [.6up7îʠ҉*nFxiY:tBzWѺMeNWڹjiH1[3%nj5hP=鴄qp2gg!Ekeلq:rEzE}ľn I5y3wlڍh>ک3Вf,r OW09k{n([ s_VZ9@˞aWI`8 E︵KQJ[1@~͵FE{.zy|P{М{p Wq`&`-q45C%vׂƬtEI^,JtZ6<L*,p֔&JF9uC^B}e%h?}HBL Ҷawtu\ěk8}Y_Eu'&5C6tj`M& ^:'R7JmZu=cDy KO8OXڷ: f!^GX 7=$]@أW~ Y܆"cCP5r90=A|R^@ XCrȎ0-#V"_cAKfglTy=,&8fvp,EA? 7J̏ϰlL! HU'Zj_ gskYsf>W _ 48M6͔si'Wc"+tIQƏZ g)3VFoЙP]Ka) T;l 8宫#QyNRFJ`%s84z_d' U mRAe0?t>enuܢ3e݋Ϯ Ej}%_30&GYz3=3y`M =|iNY:v<;Д}ROsb*+]h $BVrK1UΣM4ל8 Y",qԧf(ѱ8aF+M'"r[(oK> E}ͱJxC8{Rx'FZpp_˚sPQ_55u:` ˘IYj⦆%'Ը23qd E Psz|^xV3H kS\t}>&p?Q5µmOKuθV& ^>g;j+;(MxEtz,y7GG h=T%# f&73N/e4꒩ v,g9N^L~E 4A!2ie[V6!=2%U}&rݸR5!xntw٭CdBa pP/,ӡ_ΥuԤ:>GW=A3As]O!n%7%/̳b.1Tj^^,P3Ws+9]W$g M<|APd% ͋^` 5 qo }*6wתQ@ D= z%!UF|҉}MnK}~$~`H xnfˈ׉ -Õ 1woY8h*JBl>ܚ܏-Koϒ9l{F·ߥJmV7Ym]ᓭOt#{+WQ4OU$JVlo%dP#g0 a[,2Oq2((oT ~nBQnV3TBY$8_pxD{_OY|:^Aw5]%9lV;x+ F95=_iI]@.2?̸K̠ݮ[a?KV(Q*RKp^ZuGkrG[4 ;fHY@u̇ewc@$'{TԖx\ߪ moq{6 $ӈsݵu!jC=Sm,lxet(kx20?'BEXMD_J[cp,Vn_t[8.k,,/ޚ{5lE{+eEqT}!, ~Rok~恢9pUȡτ0S!;15X^Q:z2 a[a&%':~*߽C1S%@}6*z{8ұ67#G" ]T-p]{|jB-$piH=͏}zS}? Dz8T}'#'``cA決 Vj &FlD /njKѥ9  \f (%hHPeX{ o}vJF*ܙXF~y&^gUve~ áݹ驢Q>{2R5;H@0s$fa\8" a6]G|nm{, "o 7xWRiVӃЅkh&iqWSpc1Dk4PzMEc*#H/{:qmXRϰ4UAq(?L:3ag,!(Cj`;,(  @>1Y[49N-%%8[J'`04%7pr( $kO9%6y6KvE)*"Q\fPގ憧1Xw!FԒW'QMIdI`a)t.SˣQ}5;3/b]R/2H0HfМi*di.o"N$moF(}PI%?σUS 4X1'Gϐt&ӓAg"8a]}YLGL%N/ԶCZ^R]83T+q>:EM+ єg!Ve#%r:f4:$B+۬T 0,a`mH(P4ᕕȘT~L{( $> p !}2 %3meu蓝j5]tڮao(FjlZ0N2(5v,SZIY~)wxWt$gTC W$oO8_UA4}ٸ$\3,wn8#|~1Dr^TJk,Չ $(c"j$^_N(-G}q]KBPЉ]%ך[,@(cnաɉk3t/cMiTӨ-aKSv*\ygGg {p6Z(ΤCX8-\ {Ae#F錨B|4 >%L}A'&tN#"~}X"}w8K :\43݄(BR)yRLwf ]!{ 1]L^^:_Zk3) w=C|cq9,9$hʟ}ndWvKq&>@MޭŅvg۱N0vƦ-=KM6.lU+$#_q/7WYF_G\0ޥ4/g?E02֕X)eψ?OCR!Y1tȳ[)>;׳+t:00TehcS nk\\aXl#q}ܘ~yK^O%*:I|?fJ]Wl C3Tї7ihL.r%iQ` \ƙ\SH!AGѥ_yԕU :D p܏,5v)a@T)Is&wo|Y!)גq]we FÁ8-m"p EznxV/; ._9+W"r2̤:%G<NO4%<t%aHy\Ѿв1Px}d= B϶bS\JTP=T4 HZDfVz Vb䖨腦?Zh 'LǯJJ Qɦ)J-Δ6rOz,`!0=B#`_x:RdN2Y}P?idx#Wn4&|:~<|8@NVy'r() qؖ]se82\3 u66SyEGi 7!~[l0̆_`­킅#p/MmW[)ew?E߂Sq%WP}<3A8Z)x$l\Kś\Au6QJ:.PJYqִއI 1z*l -2p߃;9 ?%o\!fEA4yTu/;H{7pJtC:v?0'r4QH')T_[V qfO^rO]WY/Ž& tӭEY9 sDd~|\NZ.O7y.WTj皷 [*ū0pvt\p#OQ-v~phlTuxsaKGʤN{o>oM[f]<|t~m=9i70r4 ,cXc]U 8Nx?+Ot?6`7ܪ>:T29V20!'YIds2LBΎ;>]@;7k<}Vt43j T/ѤTw"j@%WH*ErxeY) ="~c}* /zTU I`¨6wlC-NH{)H,U'j F!xO8,M$f,í ۴y7(ƹYNes3 ۿv}#3WB 3sT5oswxL$DRu9IQi ŊP/b-'܀?YsD&tq'[Fs1aoR6D-a*7hKkC.Y$xZBE\C@BsX9(e;tejRLz'\4 $M7etP%YEyzf?!*_Ty@o!ZDXjVЫmyĮq>Ғ 5i,"9"f=7?:.ҲZr$a' #A{ YrgT7E\z{2ĮUs *r~ac~6 ~lr4#ʍEޥw0`$P֚wܑ7~XZхzŵh=n}~wW>;?뭁,D4`(^^Ϩ7ʲʐfVE|-pRG/-%1O-dʇTaܒ_/b{lui\RǙ|y^+*<ǪH6x|8탗gXX󇉒O zP{QKGck ;QXcj\&(V)_*5v_p UԹ~%&X*Og+VHX0Ǡ.#Up&pˣaniKS! DBOD\cX5HS|P %RjB Jw}|IC/%<ϽpLo@ CYI^9. }H}Z*%fiiϊOӝP3C@W:P^'3ȣbhJ6W󕺯 h֬G%o<@1KӸ xI+JWd]3, dx4m m#'4w/941C7[#.%$͎j]^eޮؚq9͇`8ܽΓXGjoݎ*(.3HƱ"1L