samba-test-4.19.8+git.435.78ced6cf30d-150600.3.21.1<>,$h.p9|_@+>ʆ‰ڋPw7"[7 PX)¼-0hGy\rBFU* 9KzȭCك~*BF'h+N)'6UH&YhظBdp4u$jbM[N](  9,Z_{|'r*CF=H:KJ5nU֗$gaѱb+K( \lH>@?d ( 6 b -AX^d      &l 94(:j8:t(9?(:R(>@#F2GHHIXY\$]\^bCcdleqftlvuvwxLyzCsamba-test4.19.8+git.435.78ced6cf30d150600.3.21.1Testing tools for Samba servers and clientssamba-test provides testing tools for both the server and client packages of Samba.h.s390zp35GPL-3.0-or-laterhttps://www.suse.com/Applications/Systemhttps://www.samba.org/linuxs390xs HH hhxAH Tҁ큤hhhhhhhhhhhhhh39f933401e96c6e9bcfe70b4809075f19bb322f785a7d6c5eb3f8b9e3bb9e7f95a6f11a168aab80faebd0e5553c13c17ce745cf183fdc57eb97b9743f668c266f10cd3bef634ba9048c715b45c748026903975b6436a08d50361aee013528ca098401c7e07aa9b074a1802262e90d8c97bac6d2348f5cd9757dbd304ca39c2032759ae60133d535508c9d290ae65d796a5a3f9b6cb29a26601fc01b828dde77ad8390978e864ff1b89e3fd8f7daf0e5d7bf0419fa65cec1dcdf7f75bcb7d67df99edb6394f7f0d1953f7f1ed46a26e7407640affb4fbe5a52c71c77e88cf254fceea340e463849b14ce72b3a4b32b3ae756cf981d490ddd69f8eb17b3414ac8e435405eca06f4a24358cc1b3641c15f9a5bd5268f631bfad264bccc8a05b868800ab76d0fbbd086c0d85b3e1d3ac5d9a024299bff6d3a05d58d26f117dfe92c3d19f9937cd854c08ce90ab4b5c4dcc7df1ce5bbd26596f042e10e78a0782a8d5d4bc12ef27d3a49ab1371242832e20cc50c9f4afa6efd321f05cab57e5feeed93529bcbb524fa7593ebea9379d36edbc714838b5e15ab3cef91aabf979bed34d504e553040758ea9863d941067b64732b01f861484ab4fcaed4217b6ada6ab87rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.435.78ced6cf30d-150600.3.21.1.src.rpmsamba-testsamba-test(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibLIBWBCLIENT-OLD-samba4.so()(64bit)libLIBWBCLIENT-OLD-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libRPC-SERVER-LOOP-samba4.so()(64bit)libRPC-SERVER-LOOP-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libidmap-samba4.so()(64bit)libidmap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_1.1.14)(64bit)libldb.so.2(LDB_2.0.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libnss-info-samba4.so()(64bit)libnss-info-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libprinter-driver-samba4.so()(64bit)libprinter-driver-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libreadline.so.7()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-net.cpython-36m-s390x-linux-gnu-samba4.so()(64bit)libsamba-net.cpython-36m-s390x-linux-gnu-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libshares-samba4.so()(64bit)libshares-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.0.8)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.26)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.36)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtorture-samba4.so()(64bit)libtorture-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_S390X_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sambasamba-winbind3.0.4-14.6.0-14.0-15.2-14.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.14.3hҋhm@g`@gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%anopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2025-9640: fix vfs_streams_xattr uninitialized memory write; (bsc#1251279);(bso#15885). - CVE-2025-10230: fix command Injection in WINS Server Hook Script; (bsc#1251280);(bso#15903).- Windows security hardening locks out schannel'ed netlogon dc calls like netr_DsRGetDCName; (bsc#1246431); (bso#15876).- Fix Samba printers reporting invalid sid during print jobs; (bsc#1234210); (bso#15792).- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigs390zp35 1760090414 4.19.8+git.435.78ced6cf30d-150600.3.21.14.19.8+git.435.78ced6cf30d-150600.3.21.1gentestlocktestmasktestmdsearchndrdumpsmbtorturegentest.1.gzlocktest.1.gzmasktest.1.gzmdsearch.1.gzndrdump.1.gzsmbtorture.1.gztraffic_learner.7.gztraffic_replay.7.gz/usr/bin//usr/share/man/man1//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:41070/SUSE_SLE-15-SP6_Update/5add5f7dce01a5b57b4b9abf50b932e5-samba.SUSE_SLE-15-SP6_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=ff545708aa2a2415ffb884f50516006c842f305e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=54c816aa1ee856dbf5ef0a3a85c09457adf7bf77, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=d1b432dc964da9a33531c3bfc8d0b91740e78055, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=76caef5d8fd621476431a9065b76d505a0946ef0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=d881469622c431e9f4f173a63f4f7c1bbccad36f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 4.3.0, BuildID[sha1]=25c8f03041663b73187884429b276497be18a0eb, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)5g523,R$RIRCR*R(RRGRRRtR RRlR0RRRRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRRFR#RRRRR$RIRCR*R(RRRRRtR RRlR0RRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRR$RIRCR*R(RRRRRtR RRlR0RRRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRRyRtRRnRRRRR7RRfRRR0RRR.RhRRRRRRR-RgRR6ReRR/RmRRsRRRRRRRRRRRRRRRRpRtR0RRRRRRRRRsR/RoRRRRRRRRRRR,RRSRRARR3RRCRRRRR RRERR&RdRRGRRRRRRRhRRRbRR|RRR?RR RWR*RR"RR=RRfR RRRjRQRRRRRRRRlRR;RRR$RORRRR^R]R\R[RYRZRUR(RR0RR RRRRRRRRRRRRRRRIRRRRRRLRMRKR5RnRrRzRxRwRuRyRvRtR9R~RRRRRRRRRRRRRpRRR`R7RRsR@RR4RRR/R:RRRRRR_R RRRRR#R}R RRgR{RRHRRRRR6RRRmRVRRRRRRiR)RRBRRkRRRPRRoR8RRRR!ReRaRFR2RRRDRRRNRqRcRRRR+RRXRRTRRR1RRRRJRR/B{a|FGSbutf-8e657d08d51c42db934b73ce417c74b9d501883ab3236ee86664474d7aa8fee38?7zXZ !t/d]"k%2_fR6mH> >H { Xo݁FXņA$Op'ñC#2 \5CV4fhٟur=jg֨k+;){#Soc¸;|9-䖪$LTƔڞ_ZaWoX;.yTEI r~U%̊Xń(Wp{,# b*T 0薁#FkjW] wI}.4lSxbؕ =Z.T:!T Mi# AK)wY35vs@o@`xnٱwoxďf$>{)zkpbLmyI pM9-0?(Ł,I7Op I3RoJBp[^߅@&}d%ӜF-OSwp%Cp` ' výUY@uX Jdnc :4D_L:,|ilm/ p2~v$\A ;N#:]=kG9RGN):}q g,rCRǟK6|=cr~kگı_)5 Q||VM?buEDwT(qy87r)Ũ ,ʎ%9$R6z[.9.Psqxd/p ۦ2A &"'I쑷퉇&.`ly5(җrA ~L9 >i,qp#[ 0gqSUݏx fܚMpgߪ5q8Q_iy*fӪ.-PMdގ?v{[Si΃3!K| pT''1\N;J}7>s1D2u POKy;&5 M%0X6^21lVOuOw=nx$t}HZ ٜ/%2=uF~M|Ե@q&beYth˿L f oWG˒5/ʈNr[U-4&dLaw?WeN\A[8n v"e c$J.ׄ`+qFaZ6 4w'"Kݩ2y=$eԳB2 C}([gCshI:sr;rޫD C50!3ɚ׻۱Mg*0fQZ2dsR嶆ɅLgE3XD Kzσ)ރLMqyWM߄T;{ b. Z7SiBqgvqƜ7苻zyvKgHI90Gֿ/Vܖ|(LF,7o(͛ &z&!y^)I˾,@Y Ճ01}Qp.cۿр]@HG=`-EaZϜO|έP}N7\5#Հ\xN"&/ď'hڨdfgxGpR+G0#DTY[WE!Ȝ(ghkb\O[K9YO!Q]jJ1@{':7^eFC̃_CcI(@Tg bP{ܡ-~t` !2y(<ҘݴR݋[eQ5x|l9tYh'IJxx->FwC3Ģza gQ~b ’ѽ㚕ZKN"^•t'[]]io8>tN~%nU(C|ǂR>~OHnuzHx-mj Բ1f_0W@5@ֻlZ`۾[BLg&qB@o^,qQQ{׊`ί43`;Udr{e!@v9jօӤ_zuv˂߹2`M(vN'>ɍ.Qٱ]^C l_8y=C|ͮ÷YdX;(JĤ;/|/}g4vVꩩI#LjVA Ϣo}3A 3H>K08RZ.vzt7x^hX*HG–t a ݸR_{Bq'!QlzjDpؽD)u}h!/{͂&$v[?1Ϝ.8Ɠ= pj .ZY`*L$-[?} r|bhΩ{\W^S5ZR}ه4hH7L^j-1 Cղ3^xY)A<'ݖ<9AС2}˃4aPfQMxj[:lP: h ۄ܍~Ǜ5/!t;gT\9C,:ƕ3cj93? mFɞP`uMc$qk%be_SLk> ÓW&JDھ @}-: ef?&zj ʔ1ƾʳѝzq /ȇz |RP{矃s6^g]Zx}9OTCx]IJИ;##ی1@03&G5mynxP4E;qrޘoCf#RKlsv9 )W%sjPң lph1q^!F7a}A'2Gѡ$O~,[ \:j&Rp\}B$)*­ +J@? cQz b|e i|}h 6b nm0X$ׁσy@M+,fήuhLm8' qG.E'I ? ׈ ? }Dυ5WpVH%_.ooYPu5jq3y;+bl`$=|߽s,5* yKrx a9\rjڰoDhB:wLim1/GZG;b%aH:U..bd'%̟ɼQthgmۼ]=LLd>h͛۟H@d~ AE1#mHTB;.4"?0 ˅_9hYˎ.tg2>"P9KiZSG/+ʬėzt` [7F{p1=^QH?4AkBA^~mYf$dUL`PmPQ6\7?=Lr;F&Ϡw'^VwShÓN4ݝQX3 ž'-7fus|C"FO{/e-hI<͕L;+%V+=ۀ'q<tyq_o+>ucdC32SŹ9(t2$Jn/&9.|n){JK}&ѠPE'U0^ ౄaS8ɩ0]%U}z5.9sTT Srͭ֘DqPQFfk>49PS:;]]hbKQۈs2е0i)ǻUyP# x mg,;LjaU:ŵ gۊxb ,Uy?zDjU= A ehxZ&C{X<)]ac)G|rѼWe!{C(rdeODarN:ݍ6D!={&t-x'#C #(mwR2 aB// :/>@2=j6<ēĵ8pop'V2̦:\~ظ59g"ռRh (ڽ "Lg[7!-Jwt!甇Ih Gڞ4U uEӍ,Wz%,bUZa avׁU*AQGג#%5gJ+l }obAlEarKhͲۚ5zChlU5|T `rM?4kHLh2J7a6̂X1iCr4mCWe' 2 /abfճ[qߎD=[0t dI)]r" ?C܃~;Ik"9SAM!Zp`[󖜖r=m-PDt#3Q)(ɘɱ̞Ȁ.'8twY/&8ir/]]-#?Z}P`g_EK$,n ź#fX 5J 5)^q9[_V?8}Ai>ݍa=%s` I7Q=կй6':C'Ua !`NW"P4igp ڙ/$QVZ`EE:M*8 ZշjH{8Q$<>/ 4+8g/ˢSwu:M6JgkB '#z+Ffy|2pҸl__lTp0_j1p9z)wEk`pxn0]&thl.i^:ƶz<JlROR,8{MET'ܞ15m_gR$wp*13hFXO.l+`܃+rp 35]; t7h jcM(1cIϓwJj^x.7sMMJElowr5xtf# -S/\c5$m:xw< 6SS|؃oq4Ag &dW|]˳ӅR2j9&Sݑ%~TB-=21za* xXmRR/Iʨkr{s3> ʓXHgJT&锩">e+WEݍ4iz~syKO!)SJܐčD&eZe[+{懶4we(P7*`ihnMj^sbS,Ƌ9 x f_C} pk jq.҃?HM4+閺p;pcx -//աJʼn" cW…e~>{0uȀSJr/"] f"t힭;9K8$^0$3.RшFBܳ,ɂs 8ZNniA=s[nWSUZ Mi)%-()S\fF|ӮŸ>S~M=B﯌${mRri/|&ZW~"cARA$ '<" %] ZJeCbA`5EiZm|yp5]Ϩ 0ofx(! Z݄&T\BB>Eʙ(s/<e+):+v {{^≝\%,]ߪ>1;:tCPI<4bw_re q}f@$2=Fo1c<]b;f#:Hi6'Ls@^`;G^k3hYqļSIXm3 >MԱRy'% X0 q]]H6O'H! I2Egm+hO`.ja;N"ڎJNS)zjrdTL!\mQn{}e~ы8frhA۫ ӗc>ثMS9kJCt`=iJʥ|c|{gRvWT"ڊbH`NJ $q9fE#b3*|6|\-XbOӗGn3-FKW"aMHuBL4bsM$W܎۵,<\\ +JછQW!WVc(=|{ '_/i|䫸A<> Se_#d;-p{vȾ$Eg!ƽN#cǪ6"Q@^ e 8_[Z1K'#vjS^j&b._(x|YTJUj8ǘm,:UkvL 0Yh %C?NF7{54%$r5 e.F6Oz5D.'MuZĬ/30ڛ`dV_ D`|;P;~'6vtu|B h|՞&=rd]2` rg==L7)2>fS`a(LMM!>Ƽ)&%8꒩fFD/u%o x*bձ ,քv .4FeѠXP L˳mX66cGBZ9R6=rrI*@,VXC\&e7T7 wG!O< ZE*Þm%ȧ úEP6 B3%SI(,vD`\~ ԯ_3W,|:䦷vd80]鷕[DϜ@`}$Uب?}CwA`:%梗- O[JKY,^z%QF xvhHo񫁷Vp;Q>4#`%lh%[5Ft[& fZ-'K,[0G]rghI zp,|0*O"Wk.<~@J>qJA%&EsgWCxWsBi18\F0#p8}H yZ]jBaBA$E]%V'h+.=l.slx=F3,d>nJ`C^RG*rd.Q`Ҕ76i0W.ć5+W<#mXY}83`H/)gB9 R V~;&%,oߧ\lVatW»$9"828egP_*mS~Qwׂ ;Fg^+Q&{kBoOzCʜ[&噇{30\xd%K1V+Ϸ=ʿ2#K@g{< vDcBµrbliǍg*D2pC72[iFGo˝!,gj[wl˪CB[ΤUg~H|C2Z}:7,H9{;56(3\m3\#4;BQaSư5ڷ>5=uQEzä\o|JԌk<ץʑU>1~|/*%Z#L!}qx(|L]֗ NR'T] fYP_%%Gs)ZX9gXRL.bt܇|IZ$9"kէj6kﱜ–5C7kpobL1W}-j򔓅2NPNRvN3{Jyϑ5cLBG!DƠ\,/va MV+ ʉf1BIJcyrFa|۶cZ]˞Tϥ_.Aps' v>bH$mb&ÍI gS e_͙Ģ 蹨X;uizVpcղPfi(7p/e(XxDK?,K!0jyn 9!!Ԙg#&+Q-׋6 n1O||6:Ⱥ|~@/z(38 b82SnD^ og3XY"A=ZZRb,Q S7>N3EX7B];S&I`nt.ǯҒklI<_Ӥ|O, pWNC|H#)U Kɡͤ8Fq$ocCR8522V_-/0bXu{y|~xLoYg Cs6xM0o˕#62}[u.'v+E"^J3 ~c( amhՅC͂ԁ;P "[-<1xO}\5)g <Mډ-ҙJ2#e0QwLwƂ}V KϟU2DܚJ&t-2vZyk+F^7>dط_^MugVPmyo^f5y(i=Ab5q~m+]tߦ%β+! [ ;}b 9/Xer}?Ӱ|FgSI}* >?mB c`LG KOWHF@)x |^13 rƳY9hq x-s⤐  ^񈁑aen/1a3DžUKZ9mT% #krGb._6*`5\GH! _E9kcdjU&8п_@ujwH?f?.m G &$H6 jVT(f>\8ԭdf|8d#s-`d_}/>LnQ0jmg-}H'/\JHw=V& )ao!~G//=kBc' BT|\ .LQBx1D-yF}6֪n:JϟILNrZAeq0|?O'n-:,H$ |`aOmAe$%q"#F(&GGrr8eDtKGXd׹jm};G@[aEW!Р\3i18Q{/HaUFe3"*@aM"!5CסIG(LBцgvse䋆\;tѐ3&Dٳ"vВ RrQU<=uV[ʭ 1 t#C}Ŭ(ILTÇrP=wls01kRܒ)'+ s]frB[?8N&D_4yA4Ueď! p#~qjO} gMGFpz -Z陏Β >,J-yfw{ u(GXE0 !'[2,#(<Ǵiږ~}'Wf_)erm^$jA:gufZ~L"ڑ] 8Qx7m8ѩ#4@8JA1aú"\Kp&8=3w*l{L3~ONwΥ};XWԶ%oRi!/*5IY$:z3LZm"=pA`pz8~Zqd!z,ARu CK.1Ƃ&$;zy;[ =GBJc,.!Q3i-VN 8܋#J4nr}ZDv}D/3hKcAEĉxHĭ}uZFtv5+n7S#P h70[e^|p gMܸ)T谥O]WkoMzλQuۿl?*0|97:eXy^iAteMUbFe2hWB3S6#Q/٠ Rehx @ͪ6Ç)3Z;r׳,yaN?W{fʯ/-qU(-Ym#ܽ}\ֲ湟:2?)2PAuݚU}˔ ̖.Pt^ Mcw.wRIEBJQA u@d$0dv*6OM;&6~CSjAy P4-)e@3TY>$PeKxiblKԕI$5*A)l!oISNlaB+qI6h]âQ. An=JN8vPGY%QI,j7e pdmG¦_39k[S0E,Hu4 U^ggN<Ɔl,R`d_ `w:Gp:Dm_j)a|ul~Ij34rhߞeFnl$9g 8l[\+{<.=A/Jk$)?:aeD䯐ENDtAT3Piu.p2${m#*>W"IX+Pc䤎{?+jR؟a=n?H{m3JlX5 wu]@ hB5d ȝ)-өD__Ee%pr),JA^syhu'$BswF(m: @] 5sn@ÜraMbX>y)xVkd'׶ߓp|hvjC\乜;7J)qvތ#U=[> ®HqWazxp`_I=CZkqm|!C:h3;N@|h>!lz-Xgл 5bDy4Ɩ*GxU֝vcK.Dqu22-VL.</͎MW x$@{Y| ᚐL:[fcbz~0 !SZg_6ݏ 0 }NS+0'jngEIc3 h9b"zd1QqT|e<0q"ַO78Hmlۇ>DEvΡ$7 3owo! sF  1sM̍Fǯf لo Ep&9AU(qMZR@ߺOܙ*Y3eӿN4ߌ<!0Jܠ D{ЖJ0fRX ЂN9ͫGKlT"{exdś6ӗ[Os`XOBȐF_#Gf29t[gE%`X,'֣VZk;YwܪlGX+KL3C q74|{'-F #TX9;^"*"!;5&]-oKumȩo H1BIe09!]ZaI {@tpԝ꧛B ej@񢤵J(Ib+Qˏp %adқK>_:=ɦΪF -p'n1/i+U=߲"p W3HJFT|Y'JWȼ#PD|R҄錟dܰ8%Hʬ^6oLpO6>"@n;O:7T80h0zr&(p>▿/JƑv*1]9"&Ӧn=# 3 Og1}D.tp7lbôN/bȮaG<өD$"L/zlx5X _/7 }۪Y}0PC@ì>?I-m {w.NU>BS _NDN*V@< j%HGDx Կ[$#eMѿ]ALd!(mc;.D(#Ap7ioਏSx" #KZ`BJoyE'%ԏ/y}^+O\ .O&wm076ٮn bΗw0tyVpt_1ICmJ<lAspx_c#!!~7o8xS]34B`>bۯYz" y.b 8YGi~^,fzPZ|x3n=<ݤhfc1}p=zF2S[j'jn?ǒ/X98s*ub>@;mhW#&݌D`۲tuvd(Sr"|Ew銗ljz\lk:s-ȜU|5 4w(܏b -jgWmi+Ԥ=~. h?\yaZ}6W9mT͵`é.9d >\W ̈́.&EZ'x/#%Kk&U~ YsWk3f=Ҵ=l6 bU|,S&آXAgOLGcv 8:K3zt)(-wi;ծ1㝞W*z*NY1>YݎnNoGʛ[6Miefz]ɉ-)%2֯syZC4~e°s`|3)6KA1a=M-Ah>M m#nYtdOdq4gyjpldBB e^`H a RZWs6=KJ.Q‡ M)e`+`>.2u]m7܋Wl7K2x8Y?exW$[=iy]n͈0RI8$W7gnV!cE{ڑû _ΖWjҨΏ,] nx-OnѼ2P1 zyԺ9w n Œl[QعV7ɏ.Tk9z^F _|;kbt|D{Nͅ哰ZL$yMRHp1UHmxacX))vu,k~N4u63ҧC !%g CoO(;_َT.)**P/L͙o)G&!SJ?FkRb͸s0Ӳ% ?ʠx V(&)ggsGM*(F8OS:9v)n38oӹՄް;0c;$q* &x*Z0OMR lQXcuJ(;'r7$|( Hb{ݍk ,Ҧr\c1=u5Xeq[ ApʘBw G_Z@M,΄Pg{|kPa_KDEҊ{7Fqj4~Usp'q'd럷 D"Z肼O. @Rx̞WnKkP&Md1'gJ6DP_- خW#/Zbckȡj@[r\|^9* NMu"(UtAq-nuNV륨x#u# "&dF>|/EK-eR]6]{Zp\n0Caylp=CU(tW1)YfV|zÊ/"|(ӑߞ~҃S?s[x+_C# B>5aa6m筁/уl-T#f|bx:D)Î5mgq5@ӦZdOh$_u>&hܴV#'/xlS;M(ղ.pL$c5jyLu=ieu5^YVT6lU\m峫/P/`ʙd&15\pՔK_UsIh[`> %vɒ̇8v3`_.Nn,qfͭ8?O p"6 u `w>i[ŦzĹX}c@| d^yx%:]Tnyگu{ċKqP\!ZZ rx1(؝wś*@*b `pɚcĘ^RXuxk1t#rgTȴc ZrN|')Pfїٔɲ7UFJ6Ts}C,pV`9tNy.͕.ll-ώK#I;)K}h^Ǡm پ:%&~m/W2keX )5ٰB 5Zr hA ^E=i fUJ3A_˾|>3Jtʴ&_V ÞC1 -b)#Os?_kJ{e{ @+/ʨdxDWo~qTMx.:5Zgit\jvEOp,XbŶڽa `z/CI5)HIa`4"fv2z.?JSʈyꟑ[Xf^V+,2ҧK¶\5fx~;ܖ_x+9fR)UiũL:ļ ,hAzƤgC:#9߽Cy+EBZWkKǧmٍo`#U/zK$)g(ƯJ8_QHN CG ]2Fdԭ63#y5lJiIE@5˭PLb;DeYnㆺ٪`qB>ŀJ\Ջ/mހ}ڷ I)VD~{/Ί9Bc ',۪W6h WwF7Oܕ䣿/YIkJZo)9*rѦ?I{y'BR$#oYk,W.)-a9mj jSUvp6-'"dN91[-CID&SerDC3? {3mO==PS8\~jwY5Te\[{P '6چ ^vuL]l!Na#@U]:8]xkkFtI8ޭ6ߵTB]6F`,Vz'?aybH*`?;:xUf\09wbx˺FγI[qջKL'+n€]BQ{P.u{[MM:y>.j 9 lΫ3}+|E3N`5'v\z Y" _n^ @vCIIGԒi߄T';'넰G]NMW%:bx$.+L9yYx#Iuv\֒_0TM޵]MM+ffzMHo=װa(V;&vys=}_p]RvCE)A{,DXƁL*OJMsu%g8|EqFďYm9 0h~\;Д,?=np=,B /KfQ``ݒi[; |9fM9krRpjWw "dz0bƿ RNj$Q'ӆd*7pw-r= hGu+QBH}h*35TN$6ؘdޘo=݀89ٮ 9e\I{EY!Έ̜B~ q^X*к>7^"m(aC:+jn^q07ՙDXG孟O9-9#{o6Ri %M1(`ǽQ{81rGY0ZҗV̸u1728_}3IeJ)ȝZqm}BikFt3ݘ3Kuf/;u'kXo?"Brg JoCu w|axNfV*.)3S}ŵu+c V#=]O!ޠ!CHnXjyK Tqgtprυ0'{wxNMƈwnp÷]UPt Z]#vrBkQ'xz*TyjO}L|Ch5}Tb2d;'S [u gcC3ތbeؔyf"&}hj"_{tLFȋ+ϙnd0](wϕ4>G{Gl@3[6%kW牿߿hΕ ÐwIm @Bi|:b$3dZ-l,ˌXT,;N(m2g1SYӡ MiXswz#pNe^A}oC%<ʧC0:ހey_21Mr:TʇDk:,%q7F9|5 kؘ-lDB|cy3R[iG4IUQ ?j`4R`kԉV]l1OY0ەyUFsn͡w ešB!z8аpI? ItY ?ӥ$mOe#y)N¸_:z7/1l@GhN1σ{AC@}z@rԶKt0~ή0?F{lk/Nv[al̞Q,@*+o˩9eeiN%4/ª1ފ)xwMxh0= O`.,r#ܼf CBgz}UÊNC8 (q{+kF~ЊZ[ʭ"7΀Zl-4\$n8+aj0mm)K:Uq{E2`2reAͻ{)٦ l }O۷@BLUңK~ 14fL>$`hZ_郊p__m{VS1A|JTZ]h\ /gL8xԇR JЏu ;,hGc0fڤ\:Hn2R]aBԁzS#o P3n;8tMO]ZR i# ̩],7ZwJjՅ'%#ƍ҈4PJ,p"i !fij9-kn3)L AGǧi23Vq,ewdԺD^T $zSw܏LExzPZ9"um%}ުCZuqފWֲ#,E;Ű<0W-F1˯I1'!q+0KZџgI\xyF37RfX[|&33E2zF8$ҌGTdrwZϰH!82@ F"Fr[XZ_w&*`T(0yw}M:4'cxOv2xAY]j6^$=v^!fXs7zsj!0Ў֡ sCwΐ{ ]Nc% S !:PNJCRB\Pmi܅DsΌy^?j2o;Ty"y m) fޤK$$˩cģpYN뽷|U*SGsɓwD/K斋8Rف掚a*<9l _~C`SP:}'IDDc] E`rW8aYͫG$%s23dg!2\ r#͖ `~srnv]gȋVv5LA>dq\bczWNk-@-KFCZ N=()ii~4bl (=Q|m.O̥9a!=s6`_05wA)3E>FIc'~ssuc+6]Lj "jIUCpniLo*o"KXpLfӠ^АuZlaNnJ zڲ7fa WIsTЩ{/KPYc'Jg Qo v?b_T.&6ϸFFs.'5m"sȪ'?GCgU/~PB0la%aIt(fnbEw5n(tq+˃%Iݾ S'P$ђ~MQ0Kn{Hni IᵽMZ+4"[ #շjp4tBpq 4)}qwO۶jOBD)nʙ%fݰHNF4߯wg#| \ߒL=Uȭ fWǮݼˬ!8"Sjy@4- ~{6Z7\T)L^ӮC^-΀GNک+]4y)`?o(0,_w9~hY\1Ol尐cf,xZJ&ebj?Od9)d-2%/oJd^V؂ Znȇ&-焍Y9S)͑=p޵NGwna$0] 1,1$Qs+\bS-7*9!;9|xfLXpw*zNz=;GQ @:DbҴ#߸zbc'} :Q7{=ykZ;IxpK _*O\8n26hEg1D.&8as8{J2oH`b}OiMju?|L>׆ s?f l>n^IvY*3 tA"=l㣤F%z;EdSN8*azZ6'PϏJ8cTAq[Oh9qYBܣ-(T܆5ٕYM͔נ.nU]Jƺ_ȥ;yvPHdcdKwt7IM}xwֱIݝ:lc;!_[SVerG#6.ڊ_TwR*._t:=,hV>tJx+*"U@pQUv 4w r3^+u 2gVTθGwfa~w9Ety^!-(Te Hg,'ry23t]A_;ԂXAȴ)wJw.0B:MC$GV=RGUOӉA+2Ǣ5B CZΧ8 łL>\_bҢ~/2Q";F8Ӫ:?fi#}`lJ%|PMg덠e ^3\ܔTw!OO<$4E4bH/m}B9RBc3X%٪Ao ?Z4>uX{.eS-(BQ6H6AJң8:G9ǫFD! tTm:WL{/zҿJs!}2C:*zRȲʅ |V6]x:# 4`8ax0zhvg97#ܦKf7,0|e@WN{<2!֓KQjrו !U!wxjN:>V?}Ș&-g p. 7I/PUO3QuMHog9rWEʇ8pe r @+}^3ބ] CѼ1m[ ɴ)Mgdo#pE)kxP< >>jvK\v-`7IJ`O+{9cl&M#!5*9CZ9yK;7t3} UF1=$r~fBغF(XCX%%DymT-ɋ l?Q$@&ȅ\b49AZHƙ'.ӿ[5;l;x|81d틈Te㸰o ILcS`Dd6p(Nߖg~Ի̑Bĸtn5pvս Fue\ e%5POxDM϶NN%W+ZьAz!G?oqw!G>Ƿ2;X1V5|SJܫ/K(CIDe*_@Ǜ sҰ}7C?HM"t#n/4MAV@U hBlf&P>"%5\W?5fxBR5a~o! B[ӋG@; eM-i+{5 rY&Bd&uoAjZ'|EA fd\GtĨ5W`N c<'+@%F%S<+6Rc ߻̓}aoyN4 ZXCTX8]1סa:yʤ:9y,l'Xa;uazqm! &C4Du"]8 il)QP $P}u?fow !W2$)N"(1퍽C> !}8A-֡+jpk )xY:=FU& Jn hm)߁Yj'dBĚϥV{MV}WCD06eϴFa){Vw@%9ִ̾ 8#ݹ)Lr)xL>y]BM($L%F1)36_-Xw roWE/돌оx QY֟]s<̍3z\&O_T{8&T~v2/i^c8&},&` K\ $ϡȠ`sC{nUyǠaI >nji+ Swj]a̖rE9"aP4+n'KrWv[*:K;SyKRv٧Rox} $D+l4O2!)jeEJ` J%\M6S%ݒG[ } ipG" i^Y\E3 n hˆFh;Qio,:= - ߺZ)9j]ZtmB̳P5O8@䟲Aܿ!ώ.}w&7 _ y0HO,0#z\n'yT\Tu%Z; f|:Z57\nBqFFt= */QaXL8{xDJ6XHyvQQv=. JU2P֣D-n W-VǙ-ϒ*oHzXZGxet]J.Z}ok_oAV7S#5G /bEaMժ)[ y dJ˖rb0Yv=_WrZ^Xñc'uFhD]RQ6/気 ,)>f]VL Yxa-I;t}8wb܆im3Z׉ݍWv+10CJx BLi#k݃8dViOƁNb #dW9w~;q3~_˼hOO7W3VAm%*CzC1tv8wmUQsB;08`M;F7?_1q:e6T\.*h9CdLgxtmy\7^p'w-{t\OdV2[VI[}&dKXcP7>D"T;/\7PzS4cv#HTʚPD櫗{ݘ[ġv2kZ7F?kԋÿvۢڍ,n4ʵ8) |U9TIA.('f^?=\!8ISQfee.0J+z"6g7'0)ȅ|!C/q*Lt5G*6!Lwh5HP~o'Gh[ghLI9x<ꂽ Ke7{3@4yqu4K'ӟWժUI1&c@7w>NÖd"84RTӗ/B5sh,U#رs@|Wy}!@QggTwExxJ)؛';+†L0#e/Pe)(cQ.<{Bh&+C?iJJqo9Y@Zdi^'p#v[%R8hDB"`vg7 _T+} >8Vp8~D{Z.v&e=0Bni"a: 5q8fk 5 ^u4RS*hlx2гS=kJQEu5[DqPM=!Di.(eQS~:S 9֫N2S 889J>굅EgLH?QNc~pښ9`KZDrfj<ٔh;f4JO1UZ%<}4,ᄁXx5j#*r:JN\ɃHLI:hx[q#BܞQ v  B)X8RDәZ1S=|<4^ɥ< O$RC@pp~; qoocV^Dd߻Ng(WV FĦԌBRSu<7tDsm^Ѝc,遹]pcv ߿\iMڙsל>dZ}[';{g:հQ21K?&ȁ L?.>#l 5[[lM1DY+TP↵@>ôkUtN6plLx*\} ) 4Ol^ GV Sy?:I|N2( U-{~Gv.8 窅~&hE~T}oB!v`(X2IfĠ ֽGq_Qk%U7>ؙ`?0ק.=9_t/VN[Ѧ[ս~'e}"Ȉ弋h;N$և͝o,;9q2c9J6!B>עz ^1`_ro'z97?Y\]{ZLVYD&=T1$F@ q#]tyڠC.ZGȁFS=[*6׾r~€J;—v[S˲A%WHJA>gMŧ"aN:nlu5^J_SʾAo:PA;ȿ ZrZLȦ=<1W 7L2T(AB-HDiCH~<>7FCTa\F3MU}.uJ`X\C[K .excJn E;Y斏:7qӳsJYRąI k" iL iuL[oȓ(؆6(2{^"kbmR7og<۝[0'f'yB m16B{F5_+a[N# aI]MgPn7$!Zyc &Pч2X cO |R8 `NHMD{UriyP P!i}jrp rZ&敷5H9^WrC |LIPT:&$~:7SG qN5Rʏ4t0Ǐ oW-z_-e ?-,NkY]3F=@{1aLxB6H6ϺsyFM\G^ }[4!Y&D}'FݹWϦjl6"ynx3]}!_&FGcl {SdwsgSL2i&@=3kuÂ25o#:kP:WZQ\2aD@)sbw4.,KIeC]n7؞z =obtC$O͑/lΚḶP窷,Cߊ@:Je=|gM(>tΚ;[, idq3u*gLL,+l{aXLߕ!/2 \*d~d:NJ?O61 mK#\/,'sJ%G^DȤ9?*8%']O$nho  ҍ'Ү*}cvA؊E M&?I *RG|pAз̥fyQd2oqZج7KVJ1>nW'B4jԼt.왊Z?ullqU~S飰mAc'gZ KDUpUP'̎$0}hWĪC&7Atg2ctSoAs[N7RȁJF*ŋE迢^>nq"u4vg(G/ l (abͯM ѢB Ұ4_I4Ȝ a:FNcQ'Kyj#6S5 aE1Y./)u6 Gow@=#緶dpm=CH4E%wn;wq7 *)H|hQ^5.;u/h:Z]H0byw+ р3κEّcƋ]ڻ&b/Pv x:7UUm_ng gpf҄G%cbo9 N lڧ0Sc$oyqthlL*2S[$1lxdO}Oђ ɡ>9;2vPGldkXc%޼be午wܵ/+ z~G3[Smg?̐r^޴A ϛ[%lQHLoV],tWLc6!mMڽZ@'6 N/YܤFg:}>vB>':]9wʉH:r5zn2B"7hcDF~f0qg}bD\Uc2X8?-*~$g旀ne CKWje `ZmEp˹ƀfN-31LQTLL*-aJ@DgϚ]z)'v7:躐iBKZe7~cIC,(Sb8'utIm6qy vlwKw x(`T%XǕȎ 76Nz[^6Z]VC !uǓh2nPC7!B¶)_ȇc pUCH`t_5`Y}Ӷ@/$4lQlI`DOċ-_r莩'''` RY0wb=:t:|7]Mb1TXr~`[PJXnOz-#:Η3CWѣ3ǏDYr`$JŚ(66[]q_xλWa'R>:! F˳0Iy¶xpt-N>]љk꓈|w ڱ)S>Gt! ÆiqO;O~uYPk |_`G;W"1v)+uKğr7Bg˓mNZ6՜ȝ/)ųL9hWʊ@,F@:̷|s#CE1D!`*!ZrP#$;s4Ҕ`#F ??` G:W2~b`:'q%H,G3~LeS洁k!+s2~ӝ۫<.YhymW4o~µ9Zߢu@b_D5-DKz qfiP1 (QAi KTf6H _DU W ,oDt 4coGwWP=`_y"d,pLj["= Axh႖T-'qu0`6=gr޸I@sejvQKpN~%y?PQ/=K" ;oh"O=1:_1K鴘W2%Rux"Wpź"ItX 0VMTp3RLzC:yj1尻7|& p|Т@^4ͽ6my>"({Εw:(gQj-Ύ EE;э8,H S"UM Rd}.r^i|QXq Leӊ I)/NsQF9|%fO` ~[l7B'e3NA~r.F3mQ-N]%6 .vڤEh#a_]$6 >^'LSdH5Jy_;HdzNz٣ǰ}ymHjMؼq ch> >%XiBLlclEZ>Iޱk/UdF(ƕ5Ru , T`mcVhP=,s ^eX!7 # a"Uʼnܯ$* FU[Q_-͗q\ehHY'<8\e3}F V@ri۔h*5]@x>z詢i m8稥z A+oϰ\ Uy$TQP(λAsH'ҕ(]/DBE\=ΨWI"]Y) 8Y˻#ͳc){FsXb]t>uYP^*+ ϶U/(Hm@MQ>dS\ϭ[ҳZ,p48mˋU;U-K<`L,qm(is;~A 5~7{LUv@%/1H&`cXH"e4,y"Lݲ)\B4=d 2Yӿݍ)rxH>0kxpf ,>dӷOFYQ`=  gyUn6X/p/)yPddǘJ^%c !:r|K.Gŝ*6I#Nni]2P'>Ѧ L3_ ' d ydY{P!+b\E>xyqL7$hA`T2|!"89W&T*ޙ 鎠ZNz?qRxrM 3a-@PokX)@>o6q k#TRa!߬;ɂ5/a;^NvxhĘ ~֖ݼdsE2hN i%fa1*`FHc_nx|7'ds?qwsgtqA~VOz{L)K2{u$=iЯY` 4kQ99wGgkv~.OlƬ<0Ktf2Bُeh>nhi[i0yo "ouhƍܛ:-p_ָ`{7:=oNW'OZ4+!C[V@.İR %[9ȣ9'lTV@C?ٹ:aaķu8'E:#.G} "YF=G@Ơލn 1LC 0~ 9g[)tߜzejYk&>+wS 8#v{S~/rM-p`dj}BKFW$߽,՟w@y3#.(_z?; h/5E!GYYA]dD}(0?,ӫC4H\dᬻh40K[-W W8IE6%yw5"( psq H@+ dɝՆD_9%lj:δrV1fYڦFN!!qq./[,YpڪCpkmoqPӎ Ѕ#)=n f9>12{.KđZF2$"D#) rșQ!mVE)7WRL~8X$'C̽΃kvp*IߢE1T X8t]*}O6~aGU \6#ݹ3XN% ^MNX'e|wjep5">sk (hb'e#Byɟf<ç?(z7ZG2Jf6eHy<__-Ԝȹd*C3BwS6ņЏ:췭ugğٔ}T |ED(NZ։} gތ )V_KcKu 8̴Azt'ˊwlI!z>&ەtInz< f!t9 jr7<1mq+o@VGD\52t*x:}xn'15a_5g^u,>v zY`4DUX?T)eVeN)V]a4RCo%G|)}))'-5>J D,=pnyƦQk鷆VS~ +V2 : 6ʏ1??G*9#j@/-23A9alҀaZ_/xcVCuLA.&59 }RlXMٍcP[9!dۆjvF4+HJ?u0 S=rlҧm5t3kh,h/k._]&} :g0odK<{ x>rHpѫBBTpz&!b\ 4C -F^pOAd<w>'ѩe"[(wνh:e beޓ,^1\s G(vt(7h~8$5f `r7Y-~i$A-H6awXw<3քQDu~|ĝJ+&>@jJorވP BCJT聗oLkH(ڄY@uU`Q{:ΓOlէdd-U\yNwo$ɬ!:|f np/0_S@Vg#C3窲Q]AӑW'@ݭϷjpwU|v- }72Rf 1H)<ڹ. ߟL43oڑbSj2G{@O( ߜus(%Վb2EYOhPyQ8mc NRL*%b.P4 npt=xuՇ'tW R9ɞN(j0gg![˖vMHf:6pO A:$BsOO=?FU'ڨ-M gR[>2/;sa#@mj=v! Z΍Q:$.LqHJ,1F^m~#36wO@>phc1߇z.BR9J1hJ_pE nfJ JjE޵tgi֕f&K]`eo 㜤90:9;ec,=3rouC-+`K y6V1yKNm:eЏC<poc*PdÄC0FzYH׽^#I:j6tMP]%ZJ * ߵ${X!*aw*ך<J*_bڶ쳖j۩N=ٯؑ@w{9wwG"Qn4UQAwWKݢp$КT ŹVSp5ʖ#ϯSQqܭJ*b?+vklU%_3P:#p&ctHE}U@\n7(ܖ7&Ti6Ϳvc<䗉qH46xsoixp hTz w-&Չ]iNy 0~l6*`/+US*/ˌv(k uT~w: z'y5J-)EjefȍCʶ1߃B7i oKDzbg ϔ*&?솲 ]zfqv % L/LKKξsΎd0Y+(&}f*h7j C⊞3nwKhǃJu+H3G79B$,VxHV9.'0"uOτPTG2Q+סԁA.I'tlsm>">N}6&Qշj9`e NaxqR"0woP!nJ@s[K5:pi< Mý ! { X6NsE3Pw2?)Ųlͯ9.ɸOO&{B$Y9K.|1k{Õ\jO7'jY6ZrgP~McP, Yr_#߶7v FrZnUzYr'K>h]C оA\hH)O~2`1UPݱw*=5Vq 'xP,d"-(Dew)`]>\}D&qUx7w-5ۣrqU@"]uqT-9B !$3Fv/h7~wUK p߫J;Uն[n}ʮ_mJ] unYB/GQwH+;g[7BoӅpeYVv&10ITṿ*m}oaֵ:=liX(" Q4/@z+5:@ߕP!aF((}gk8 f93Uֵ8:9h).K5:ثF\;t05aˆפ6#fdV1z%Ah"ܧJWQHq G7Mmb:E"&D{ó )&+"TrH"ժX?'9rt,6,n*pֱ| Z{b9-,6 ECoQ}/-wwuZqN˖^E_x)qi8yܸOs^%0'(|m 5f )_) rۖǝH4nȋ,M'/5Ԛ*3 :{)/r)I!hݯQ'Y"/: zOmL]yH$o뜘nw'В2QbDoWRT`= aApDƖѐ(ukWl9HLƫiΥHw1 =ϔ@Uz}Q#Zg"7+.ܘ!哬:^(]Pb[s$WmȎwGe6悯T$ XgD{k҆3KYmJ&ŸO6x=V~(R"Djnw+ݴ|ǘwLhZ>t=Tj7#;WaNUVQ|cI_Þ wF(G8/Yu7IeI}"d\hoЧ hwC^5ыE{h6y;+R,]kEb&N'%Z;ɖ/bV^bWx u3>RYk b]݉)t%XFՃ̋WS[VY#nji7bsEBT@To}-$ycپ0g z?zv.dKo Tt ^uf$)ؘ!LR)4){$d˞Mlo=\7 8 #Κ Wf{^J<:Q-Z jOÑ#`dU3ؽ&N2x7c4ګb4 ӻߤ_p ܂/ "ZPKN+엵ՐeZGg((:Q3 $뙩Z;L%Nqg?Ftu^o I\ QS0)VBI|ɳ[  Eqs$G1GƍMJ^T5e-)F65' }&̮C|äCju6ݼ^"$} l)+52Z}P|0&[G•)7ٚVW^тiZzt^9*0),5ɛw@,Lb;s' dd)L/)JKb]1'XK-C$eFLd"g(Xzn7XzYq.br|[5speto6=ɕ!8BNHN.!]P7h( ؏kOP #ymO1j)d_Z +>k $\N%"3 H]MC3r?^#v6&c7v;Ҩ((La`E4q>-j`̜\ʽkV u+6ǃI vTj蓑\=x8se59p9ʅh fm\i .@oGdܢF*{7R!  4iT+tlN1||'L_W#P{UXtHex7YgmairҔ}ooSnIxj<'yRЅLWtU*Vi6iJp.X\a9-x! s[dRlG%cKg:v4h^U%cVhn Sv@lOϊl9@f3Z8tj9{M 3PA]vn[a+;ioR1? ݵ:e?Ъ507%ߐdӂ UVsj`xQAqѮQ'5K@ؕHg*g-0giÙ鳪Dy=܏~}̖ՂϘ.եisc+4>fdӨ bt}nJ>if"Q(]}\huǦ:6فy"5 -jE"ɿ}q^abx04: ˣqSOBO8;j%ȿ'}_H*3[7 A~'֏F*l‹?8iĿÀIwݿ GJAd^HJ&%j$;)aC[¸m хxثeYpv7(}4US-~snQ"SgJY$Qz" h˯>:Ⱥɼ[þϘ&,I solΓIzNeA0w;̘ =)9M]n N%/‹ZgJ%6}=駬;AZ 7G/t/qAҋe?3ŀH V\Gf rQ#WʹB=Y 1gF LeȬ5ɫK!Q6Ox73uf:%BnqGR1|]Ԥ\ lpaò@ngߚDM\w  tdIXO{seTCNkWq{Lazâ!buDHw,b7!4DZQTI?Flc#|'Hs^&,wDl@L7 /Z0U5=cťDCS͂ 6ij.;DQ R?* v.Zi/Gz nYy2cOʺt+%Ĵzք;ˋ[6F ~@|:ynl&e|eЦIQ֋<=/vR@ʬ*{MWUcTHn Uz]JwgZKn?n:p&3h.mgS5dP\_AGu)YT¨k-$_u+r %LWl+^,Gm2cS>vt1wibcYZftZ" Υ2tHlyGP8'}vgiQ)FސZQS}'~k 1MˆN\yg ̢yZMS9,'qHZ"w*/Mr G a;ـջZ吀 +P4=B"; *|[s֐Tr[S߉F t9ߚHZ Oµ-&m[i:{̊:5e+a]k98e0_]`W/JlD`|.jip&/,;chOXRڠ` 5l3IK⒌}?:"ߤxysjOME f`B&` {d418pOLq(i7΍nՋoaSB_8U!(DXߋu,w%.}b4p'mX}9Ft4RX~ 3і{^R hC:So\Ӭ&ߢP%Gof'NUOc<ʳۜY2xA1:D)b SO%Uw`#9ݚ"=)Fpv- )]]U]HOXШҩ7-G.\I|@BZR^fi>51q+|O{| Be`{= %-NE2 f Y9uH0M}ƛ珿Rco#ǖ1LZwlPNn}+LmmD cijS/.Tw7VR0 $TSBAfS9 k#Q#ZZ_5}O>*zBzAD}M@3:O堣`dAkOэ“Lԥ4'Xd/u-7k (}PC'!EQ?DUdhM&9(+~if1k!psV YG# Gj݂.":/G4%~u]?"ǫ^zٻylNķSfK?z;x+i-uB_y+e)20sxgv_)nMs͝pb*L|fIށ;+EQ;ШPgȺjm _BO-Tl968Ir/Żfx-SPXm­o6JJ0'U]E  0 _q:MB/C$ydUVC/})}pXg|GIM1v17qI.&fY.k!*+"clg)u-(av*k101&f(9}HxO8"h0q:XW}甽dr6lkD]6a7.=n5rR.z0]P#A;,t\iq\j |r[2ymUڧtόLu1Ag.=-3GZEmYDD.&S~@\ΓKk?k2pC0{~]j^ȣE+亓S@,x(@M["F\+PT\i*Ivsd ;&oMLNZ`+[83(n89i xM?na8,rG_15aMXk ѽ $<|,iSsXEq5/ń4R>Q!Qv,/&х< 2᝔9"բS~KyK-Tl Y=Q(j6? +V>Ǜa~NF!NJ'thPKOsw0Z?|1JUӽ2-8>Xx<'9VA%=i2-TjP(w $9!.۩`DRZUZ5Nr?vhz}.:5[cS }Dz Y/QFK m5?xpSr.Ne2D'EH hzz12+]h.\U1rcgsJ3IcrK#F w5?d}-= 11hD&z,!`DK[͠s}ϰ.qZUQgӛQOd5 o yý!f?M^38Vi2W쟳o?Is${ujn8DmY2qse 'aUԆIqO1iXw )RNz뾷M^$.#`Uf(mSl=h6 {UjB BĄgd]* 0-hQ#>pQ`j҂NQg\Y=W'[ ksr;Ϛ'X&,E0!dmC@6{L^H8[B9[.(?&tC=D%ތ$-Tv 6-|h~rMS8daV%V -dtBk-]8itl4V qsY_bU8D!w>2X% Z``*ާqPwҌ mN'c6;ĶAo _F=ZA]>%$m *skFZuLc)`tw/DW|l3+ƾ QۂruIFDxC9 H \F* pKڀXlF@nt9yq`5◼4kG|nL7=ΠDq)2R sa/|chU+mI6; yx$8}cwqW?)KsG5(K:IySoKNp(8$>+ Ɗ|wڰhOݫ'N-z=zJ\fB VdBKz_=(yD74om 9kϏU+A]{[1prĿ/^0Ow sƪؤhF>VReV,uRQ*zE\$µFײIo3pkmޞZ9~}U\`QƝQ|)}IN-c3z5K'A.9Eٌ]ف&? 6big7uW ڑ(:KG|6>lEǚ7,ft2|qޞˆtb-p么hĶDGtg-rD\lnjj87ƈ}E@&Z`ǚ-5L}qX=<.~:]KÊPb$-SD|7X؋1ًΓY$_Xi-^'`kH5raP<`[duMt`)rW` hvfI[ңQM3bs^#?n $3vNm]{(:>3}_],Kl˗YkضԆ è G>MtRt`z{rl Y\ϧ CKZ}vI>aYX L5V90D):%vXX;XېEP_r6ǃ[s9l9\ ۲MNj8R 4n/\s8#2/`wvs6Suf/.'5W`!ꔺso-&7[Q0"r{y,0]UtW6-E'iUG lcuD,IecTK@|O>qa<$שm>K\uqP <᪜ߘ9prki@VDnz^>nv F+fer8(¦&pjH rf_{g朆m}j❱T'5lstRp!CS,sҤȅ3㫔yeKjFJ'R"+&Q:n 74 |&7c䅱έN$,9:n>ZO&:#_H?ū8؍'R0ElLVyi]t'#)|zbw܎VgYSѪu56erG`hl{G=>}k(3Vu3g-ip?PmgCǥB;lvqœ qDViKH޴oy++'0Ep l_ZY|m=;SW?JI/HF-$ܒZԼ6mB@NFI?+vHj$wưsRSlOko;tS cpyUX24eaݶ̓ 47ʀj:6vqigOXromd4hH>Gij{p֮jcyFK:ʵ̡w_D wKcƸ~5ߘ֏m}\>u˞u@"5Ot0BG`Yՠ;e'd {ks]0"@@WK͒0Yt !dx'~-vgO?}iKA\*<2)x/,jL'L>2w@txBFbXNэ =53RhˁcGpf(p'n5 e玱ZdpIyLis(fS|xw!6@񭪺;Iif4r b?cXW&✒{O5i3+"`b-=HE6ZQΌ9\XZ~ڶdQCxaYb/AY+݆IHh*t}ux}\`i1Uぱ &H hRX{ۦ9k \rÇ;}qA)WڏaGǙ'O$]Ei1&OSy(djC͔|Jy`s^ znƦnhF M&s7RU֎dzSW` ]ΓH' 1۰{ xO+ξ&펚JaUOwzեZ_YJ%cin!&-1: Jy2nO֑]kX8 9Mt.`TP @;{}Ⰳx!$V&9$ɋ N?U7Ȩe*U؞}ꏾgs>*H#(IJC i/;)b_﷽'O^YShKC)5b;Sx4:f7).ZֆJLxnobNǤ+R4C.݂@YQ9kMUuCQIaX`;X~|RUB+yɗۛ^.!%1T;L*&nCd987!SeB.>y,v#->Rop=6Bzs!$,BtYf֡s;M$ [&-s2ͦ@O#|fajTQi n<*0ʭ@P+z<ŢÜ%RKk f5P_aq`#(O+66 TsG0>GmbnAN|U耋Nv mEUdQZ5l/"uU."Z"Gy2`vl"u!`R60~K޶)!=sEUv7ϐm\2\]v{ńLUB7b/+)6 ĩ2Sf0>#sB~Z%`GfkNy30mJʟx7 p0haI3AqA LſF-2jRX:KA߲hօYm+QSsk_jv]`&ebV,Ϊ!*%gF/j ;07,3ʎS8UEN(`{v-µoa vYw*XQpCi5$o3INg^"L2D,yb&7* Y. Y8l&SiGZ9Εp/be>ן %q*!.w}v9?烋Qà #Uic_eq?|#DA@ J'rܯVr?aj+^m*U(8Tmˌ4jV#D6 A90fT7,]?.~x?H`BY ,"R< P+ډڔ4hm/i$86ޜ 5.6Ȇ]KB[J:kjc}(yoB & 1T! V+ilԭێ?46?v$@ǔHN.`ZT- 2֞zS $K" ej0@Dm@ӊ*lULw?Wyו 5`#VAְ-N C8I#]<< b@1+T vu9I"( 7)H/C)J~ʆlIu4) )!q*hz!'2]a\3EӗgP9Po+̘~ߡVd>MӦ11fTh'R2*_4#/=,34l^kHa4ܵ#ܴ6ʠoe1 S?aP?e{V<^L3&Ɏ[E EyfU B&@l6z/ ^<ނ۵&FYȿFz0P *% n%@;_H Ӈf8HPwL &itV_40,hhT{=^|=T b#M%O'$$1'ʐT!B $=HlHfِ HA` Iڎ(YC,LPP 2"@'Ou'h]OG ~7ȉ St r*C*;M湿o--u$^@$zBP. r?Y/,)hRs匊sC("4XB" nZD;|#xLiUAN.ͥ.IIge[eI h(  %+k !gzS0;Iû{2ςpLT$"+)2qo@{"e(ԨZ?.E|gpJI5hXmV )ve/64H! %8I$qъ }wI H;Dc-0frDQJ"'M tk :*4b$DLe-!  T` +c+ЉAYDV IB 6U -TTf`۵Wbl!pN+JY-Rc@)Fe-A"TV0h*^):BX=#L-E=WiUdI5*^ixNZҘo۞]P2 J%9SEYzi3Z4iL]lBDI#"f҉BMZQBʆ+Lh7vq`Gp4UgHJ Ta'J-Y `vSB1!d게Z+ 0BQi,P1 ^fqg*!dkh*9\fnK3z޸< 2viԯTi1'v9KzfX 0ݒ8`:-d|C?Xl[v~ҌdvE1Y.ބ۶ܣgI=iꧯ#ĝ=X~'3G?XG13SUXײDW|I> KYLQ,&csqgk-Ah }KVִKq-^_͎+WԖ<hc '$,$VNW OjOM2urB0*=ӱ+zuaF\ =5?{ecՈI!OЗ5* UGkW[nPNj&@'mn-&ёf]v}aAA9כM&nl1\Eٳ dQ9qUn" Ȩ 22,%TT$ gMI#4vWU3ksa/!@B/^A : DTDifl8tMYI%U4 HUٲ _=## }lCzSk,1JQGZSxBlM v$a@&($HVز쀡 K`,6 hlFKjJ)Z%`ڴYU{!$y2" AR11R/Ts[ aPU3@V5CԥxY)sLBˌp$D݉tk֑FA\Ep km7%qZE1`P(m,S ݓAkq-aĔ6)5.EW2iuZ ԺB[doY"ʀmc72 Z֑q5hQնBM""cT6@КL`hvmt[&]E[hqcKm0N:;bf\50LEba20Dc3CbWܢڦ8kYKUf`qS,dJ.Sku˰1U̦n(;as%kDLk dQhBN]oLسՑEPɫz|VS[=D 9kYzi9sD!'hyQ_`En e/ZÝ]QNZ2K#s xm̆.P;Gx|ÄVfaS@0mѾV5o7՞1w104 O :F, 8'E4{=(mr6$audL#F+dƱ%#5ݼϣjL5"DI&U5}!zr7J*@%L<8hөAx0.R+kN$܍I ۘh>iZثew}ۿw>~V"tgj`Ƕ(NMN>{ũ5jdct;\(l~ Yĕ͗ϴ01nlc3K5hX*e9Yk,ZJ0FuLa`.hr,=N k(:-nsC: n"|!Aw{# "ݭya7@B0K-, |z/_P^un큏d>VsSxn2TlY_^DUFڍJ$o׃zx=]ifLM*@k J(!q~~Bt Fo-6DǼɐd-j8׍a[xW@ek6Jۯoq^O4xQшB"H*Ƞ'pX0&o1V;h4T<]4 UXOkIn3p=E3Lƌow[[9y>k ArSBaŠ0@7# TE DvYcʫ0ؚp;.,= JΪW[Ǫ ;P!<ܦy{QDkFY13Qb2$smn 6봶Y[lQQ Njh\mL;IAK`KQubuTq< 1xa9ƒU<})O?d,d[K5g`I#"˭z-ˁ0I8ЦA` ie[a]RĻ ST (yX^?z)d ZFpc'CԨ"(/Ed0UJwD3)1n[c5ܩ۟r9Z {Eh-m^&wDjrj b@łފH <ַt6##eOVkXhEXI láC~OKK?F"g4-7zla$+*]PDC k]&ЇNP 0_R hwl:w'Xm 2 "*0,!RAa@m5;9{t6߅˾6$4uPF8pGmZw4 D*Tj} >w/nTͱ=0u;$rΞȨu38 -݌9x W^yki Z=+Hx8C&AL * eem/yjufFM'vO檖[\;= il[Б{  wDNVw36oVyڞ&# j-%‘_vl"H %)Ֆ"cA-5D4_la iq-^.(IB IBHRUA^|3{%ȿfcD& #Ď `&|"YSoNl:j\lXh5b318 tS #Ň8+i\D-0B)JRPfM z<Ɨ'~gՖO}p74{i;Tۿ^\&f*faүr)v*&( `aaDL0o%w̔6ERE3Ժq +\stF*0bNX 7%R)QѶqs0+m112-ʖS+m.W3y56i[[c%i-γ7ѿFcy YY)$LӈV1^sޔHAi6ƞcHj.7y ܇v"jD ASc&PzJ+g^CEth=xL{%&ƫiƳB n>N^cabv9"#qmHe+Q.s1+)<DMSc $%"6&ݘ z {<M_n* ySQ^2dy2\DD>jvTLJVSP5ts 6epI6FEQݔFع2oáOB8WK"*;߲jI]Q5L%ǩMÌ-$" o 0ga6k -F<+ ;'? U`}s9 "hC]7[kʣ~l$=- >(W 3 ω>D%35jn1ǦgTJ-o;{%ŠI봘 0(]cx@{Jf ݣdCVX~?O~}/6,3&vO w)F$Dj.y@ #B^]@D sv\RӂS H9BR)"RRTd (PﳮlJWohiLŢ2dMiJڇŷ `1YgezMnJ&f[/7-DE'6< zP&q`3j^p𨆽|⠊Ge,#Zc\-,]ྦIEKy{wEnZE[._}3ʉXPfAKKkWkR#!XL(Z[hL(lh2!*Ex-He=2"}_yn8JRn\:Hפ%zvX<`ϝ} n>/iu/XpNn:tݼ=D J+T@M,K@IA:ɼp:Xk[U:`ekЭD+C-d 'D)@0ۣ`q8ϳ:;:8u]>TI nJg[I0$!8kVxYD|KLR9[&5v^ߏN9=)ϔޅ%K*fu|p 3:Tn=Uި?+)~ 8JUykG'3Q~oPG0B0g} ]!wQB/g'׍̇Gǝ/PFM%_i {(T3;8:2?)hK:VWeA={יK^W,pPb釕Omd7C*%#s;HET]NPNect˗Yd[KusK,|^uPs<*f %1a9FrT z]&vuQ-cBnzsݮq1 8$Ct";/gܻ9rX!ɝ(>4Hmu_kwq-T44ePºU"\.:1W=Fz>.]@Go Oۮ-%M +T4Vn֤9f}FߑM pv9kL>weeVb1 ڟH NcvKqPU>#Y;4ATRz)BfZSX@r9$鼙IeyTVX] )UcHT_]sz{;˓>}wmҭ}Ee+ʘ!LPQ5䣬S,"lbT Q-Ӭ5T2 (# ƫZGt&6QmzvwւZN 6wyȳ_.ZClZp]HL# P\],:}1X a%HYG(b]#w=LnCP}-O@d"iA̢̘nݒE۳jXgc],<^-rX5V)fhQ=*Q6Vg"{%4N>AH(eԡI]ݜ3w S/#Rig9dAMSŦU;xrHmywqK[wU: S֧LCʏ G?uq; ^%@dl E-0rm3}KbvBAUO\}{s,X mXi5d F 1ukO9r+ݞX\2;TYD6(.֛̭Px3#Ch(Q%BD[⏞ʁ$'kr4楄eX-a wnJEbixlVHl$*Nw"0hkLU{] OmVnڷNSdi`mv`reE0k(-UZsRn3XnTRJ,^jNoGnW @̰RMmc,4%]@d! ?orWP[<:@S2b0= RO7@_-}v}Viwvڟ&}VPT Cm47d˹͡ @y8}dOՀIs:YF\/%w.98.` vmUDE*l߶mBdNBט ąF [UnyG&,D!non&T,8EP(D\V -ŢasGFWUTL.hM*@3ՃNaԆVgZ plY+oyw>o8\>%Lh&ese@u#}"i * GG[ !`nhڰSEUnnL:ӛ.‰ FXYH^<dm,ÇZhL DfE<;9g WdR2#`pI lA%*>88 R_I9ᝋh+(wVj9|)·3ongcw7}u0a'zW8KNw7>O9CDeTj  FïG8HZ  ŽXQ"BSFj%l1b"*eXM:{7Yj=t8XǪ_ٮo#=s/`bCUT}c7˱G_Nra6SQd TcĶH- '+12_? RUJ(qV^%KYK,jjFM< T8;/xiee)elvz˰b Do( R *,2+* *~oIxl:_[C!(#>Džj_NTU:d~s mJ<.'+hP9cd8׶ }w@(':kJVUBm?ôAՎU;I[ R v^HU%B }r(P‘f>2ۀ`PAYb4Ovrbx%N/e1AF/Uм#1Lo9dwuί-oݽoaӕ-3['gNξnKT(n]33⷟/o_*F 5AFh;G:\|_ڶ56J\78i5/bO(D"W>I3=x7/B_:O{]/Փ ߭dI jLD]ňc ڰGRko}r)i[mFC(񫟘FTqP#Tu2֕WQV :]0ڰ@DB<`A7ʈ uSԘ֖wyvOCiT8dEQA'D!!PדN6B5C>i] %lݺjq9Ekd Ci)7R5X)oMA+%(l[E{%H#˗vNV/ُU<Ƃ$LOmgk7MPzB3/^+H3p ÙK8=}-rcSZh9cˎXH⠙gk@"|.WMK,g^]מc az? 91jd GUQ>Dϭj(Cϧ[Flf 0'8W }qud\\/zXAi# :Kxh-mmeD)+0Dת+DG-fuZȧ3SnrA[ u$SY9DRB=QL[܋UABא 7P:)6 11D,qB{0@$'1mot/;1JJ%p P ^1Y✁&1TEf}zzSFw7ZH (AY@w6qHYЩ ϖ䙼$AS*=KRvϊFOX2[4j&0tk +ua 6qC&c2)UasE:꫞,Xl,7rew[J.eZUzoM+d֊n$mT̬.j5`H,tUWocnJ#yÑ5mgm4+̠iD+7Q6\-P3dɕq$!D) -5Zz B2f,Q^֮(& Omc> Xc5M:j ok &$4qsvCd.v]3q&ܮ*$ C23Lg4c'7Kl3͊I ),ӺAK&5Cq<[_l!*5!ȍOJL=痼w~N]U-VҰQHY]lo{]lCɲ76]uPʇ)L3:'b).Qpu۩הSaXEE- Y#mfOOajaSi x( >.rx0:N-}N_Kա{8Ld'CQl[R4æ^׾ϺiqSpVA2 FKu.ixa9(hC<}d{Jq#ereiR,9ZQV,1#%Lb!@Xkaua+p]*O&ɻfan]dr!GvpmGR`ԗʕGOy˿!y!PσgzֵM6m׿CvFs߸O;Z1߭Ppdk*-UH*3Zf`477[Fd@($$KuMkeIHCxx}Qbdq8I!&IU3 ^F{TTF[H: z@NO8~! /'4埸oeGk3bt1d#ʯBt6];s`8Zn'#tevv U`l6c}q)Pq`.hW5,*AV$ %Մ|!SH{zNԎ;~=&aT,5U@%HBpe(#2X_f`g>S[*AHu5: 5<۩G˻:&NIwUҭYwl+n Q~ 8:ۯW+n\ HC\ȧΫm_aSvĵ+)\a,}=>]z;C,8ge9tə(f,Ǭ^^%z9i~oxh|zJ(d&k9 ;hylʣyu .6lW /;.Y6tMgu:,m:$Xy~`Ӧ 5ғ,nLȗ`H:;*)+lwX}M7@Yٌ_;}}-h$ע4şl֠ +J憄PZődysЃHjevQ[DGPTEL[y^J ׆ EY7+\a }|,V:c1hROOd:x$Suݐ=f)eƾ\M VWD4w2*a$[J닌Eu dR cP&MAMXyسw$ 9+w3ZVD[x{]SI. \G3!Ȳ5/8D %zF zA0 ݗ옚95fn1ard+ Zb#QVI9łT|9Nf<(`SÛO+4 iF ZQj{ lcY6#Y!بà `JPkLܸ2)ګ z6VRfT5{#lD]idv+!V=z-0Yv1fQ[D]b\Gwyݰi*TTw􉃱6k H>.FBdV(z-oMߘ̈;\c8냽 |aAX1) 4WAm늉$6)ͷ͛xYRsO<n+#&xSvt+ﵣ Ѩh}gq>nwEEHXb-~* 3`} h$+Ĕ.4AY} Z ` Z dt ujq@".j22׭5tby  ' +AEE2IJuge_l݅i1߀K:oB<}ה`@U Xq KT"jGK :jLYTrs/\"^QT bZUu3sq]Ql=7}cĆYtf81.e0n+((@A:-|Cm0wqmiA|j岀0`(7WTSu H+ek@%!e;"y"I!)Y$Ҿ]!='H{*Wi-{%y!q~0(&8gJ@"!@ZDF}e *HkOręTyz= mgYM T2fh1J)ܚ,\eHjt` s΢^87Ch~ !@i B&mTaLUC+9AcTXT1}!c󕓁.Tp)G:--M62YZp %*0v69[' RL=JࠑP*SW_g)YŖ HX(w]wbpx~q1=;9*v~}bwk|-)>lq:PP%nI9D-nҕ-Q9 +[e=fwVmڐkFFO]}ʱ0Y^Ŏ6_}U%Q)_bm:թ#auj6'g0$⫯qT%X"Z5PQE\jŁt4LEZ1U/gНǗ]E4;#Z` Nn Ϙî+'fM<m_.촠|lUCWӪzR3R(R!Ҡ([# ZA[]IKS:2UQR cUfbw>wc_=.V D"'>@sJ+Ȉ*Yw. O5, H0ϔ$cFdl#& C$]rsD4t M2]I!.p9rlt(+3 J$J:\$N\4DLa 3F c 70fJ\srD@`th"b)@!$A\pP379qh(q9sC!qI,2C3!Qsuˊ1'P幈e0ᄔ\!"b"e]HojA7ZC7jGV0%G(^GnۥFz}q!U rV᦯xa 9(P7ui Xm;ʮ߹J,:YYñCHvcw魻h^{~Φ;jGY݄;T*68U|&7!<:PSɬV`m2_ĐP1͐V FXzsR,3Įp-EÕM]A B8j<@^%9('aN^Y IXZ=9#c H$|*P`G⎵0 .Uny1i7DДB`DAOZKHiKFf7E*HC0 L'nYz6b  x0])JM K V/:oVQ5)aT#2,'!j'Th3XebvXakUJc_UzQ%賟0ۇXGmWƶ¸CN1\gc@B@rW=,|˰g('?a/L MPϻA G@k9x=f/dnDUeBZ~U誟:l1"( :t`qٹ26w&"9r@_0H:jik_87ib Awag0+YKan#.S*ϧc D;ȉƴ yKξD6WtѝBo}i v8"u@EeNtWzUj8bNZ4kl$ M[UBkmJB=I 5j<;YKJJaw(f LvTe*xko=M6)o}W}kgCȻޟes@rQngmY$ϓ<ǁ~/ZQmV5h֍V-E5Q"#",={u}kZ w5 qHXتصDUbֱ" BH(U@<ʿ{鷞kFlBʯG'٥|nI%]o_nMIBz/YjVXxpg#7af*8߇{ٜl,_uw~h-:Mu&fffV[%AeA9*l(%=ŽҞW-e붙?{.󃴴zsεFq^w/{ ]DZHGbȅB He|`$^ƷYbn~{[jesbt. otoη-69j>?LOܮV5öiE)]ծ#c; ^y;NK5g3\ +=fn;CfGl+6{:͖ʲJ6TȂH2 "HUmo >gĔLWO#ҝN .9W(^٘Rm W F|B'EM8>hE/1J IJ(A3?5dɟf&.߶pu#4sD;׾"HZnXxUBACu, u(*" ]~'2k*p”< )* 1'U^0S 7p!_euP !(-l3J_EM/ uJ$Θ{GW͛ ]=F/A/B <E42; tA;c8_<3i.T<%)nμ$`WweCFЀ"klY9jmvj`ҊWc5DY63+7YU_Hsmj:my7@YVxCfvt$ss+!eYoO>/+sہ6\jդĮ-6B)"4!*x+,6V'C2G?6;;D>Bˀbͥ5".`uX |8Ȯ9=خ@b*lGLH鄦bnGWgM1T@)AYgPD@P1o)5El[QV,TXlFڣmV5llj-Z+V(j-i6ڢmmE%656ƣmFѪZڱEڋbkbբţVVU(kQZ5vXըѪ-*[FmFڈ-ckkF5Uhbj5lj"lj6-&h5TQjcXڍV5V1VƱj5T[TcmFlkTV+mj+cAֲm6FFZlY,Vi1QXZT_oѭ䶠5}W~E(,VŬkb"+hEhZ5mFưlm[QmѶحkQV5RmE*EmZ,Z[F5bV*#jŬjجb-k+UbڍTXKj-EmƬlV[h5`ڍմkX-6Fk1m5QmEllhXb+cV6֣Z6ԕZ-66ѴT[m5V+cXi5klb%UjMhlhֱmRVՒQQl}޿qxkhѶTEh[X+`؍lVXضk56mQjضأmk[mƫETEj*hZѨU+h mF5ElZ5k5ڱQUXEkljUQ-%[PmTmڋU0jѴmcQl[Xj+F(Ũ6lmhE@XňZ5ŢX֢QmmŶ$ƴZ#UVZ+TTm1h+lVzPmٵFXm0ZFQX66(Vj--Qi4[hjMk[&E[%kd6hU?]Q[bmj-cEDQFkVZfAI>w3^f'C* Fj5FFѭ6[c[lU[QUlh-*ZEQضmcQZƭ[hڃjjحTS-FjŨƱmTVԶbPm6-j5lmMrlmm&54j׼m_U]JBmvۃWq!  $-FEZ657ɸAtCDZre}}LX>MywSmZ=:\u9[oD\Dr}ҟ[]lsiwsTvp,++T)DAZr[8@ )*X NYM@͒VY񞤱@EeF(KnSvqPiW.˷#f8h# azN`e@Hmk̟)п Ap1vL8mAxJk2$0ї i1c*TOAHy^m);@E)ZRz#å)k;HG>إ!4 CK?CslϞ;'+p>'@A D@2W@h b#lDdEDP驝ڀEyiuTLW FӸe^PYKa]X~1I)KYr4r|S:^)4Co2UK!C*ōg?܌k&ƌrnT@RũOu4~ YBQ9hs:Kڤ'lqZ2qbhZnl'سq)pH,25/mW\@cܨ@!>YKI* f< wO:_D)@>d1R0J]FEa?? DaDFggbs1o)=4O&BʟG):KE[Rrbh8(;Z,a F]P#5 '%Z̾( ^!sKK63]e,ޏ{[lX*U8i"2/P Mj6حlkTWw3cbX֢րkFAU%XڢXTb65b+!_{]*ƼWѭQlQEIQQZ.sbZj2hcTh8Z@vzV;M| hDdPBD['^y$h 2i+54y}3`,q6izR=sTQ (HI$FHi)Y$jL2$0CȏрE óQaq72d(J 0 IIDb'N1G\VBst0m|`"nP4~ e'#Uڔzw~]Ul˨Qkk6E@r.1dAU(/o1W-lTPMHڂ%2x+İ ZADrKV *lvgӷƾD8Wm׾;Ӄ]EDS-ni8lv36˫A ZmDwZSMR@A+?٦_ ̤̆<3Ɍ8J~+g("UW^=@!Wc-5JP#V8B;"i@fLMVAKlӀI Sy[mɚ#HuD!!lVoj|ѣl'wZ[01X HH"$-M.nH+ mA㨇 vs1 F Y@ 1R+J Q(gBu@Yc1Sz?x:H L|u]~9i:_4r'}:cw 8^Ym{+?-=ـ܌䎭B+yK88*T*HE"dAﶡ@gΈg!RTLm(߇??u/`[,-/N% E44.tcrgorӶ/GǼ\c҂L1kmۃV17r Cet3ܜF cz9Lܽ 31!!lX Xlx]  wZy@p*aaBPX蛬 &b r 4~Z>3/}ؑ|L6)^=2CP][h%>Nޅ&UW!pqZ6v-rb.^v>+ $Н9p [2w=iP (*~rެڇj(ƮDA {OAxתE  24q32Vn|n*JnJOHgiFDp~C*3u"=kũ[3&3q3$#,15Ok!%ԫ]ڼ@׬(ܴ!Q|&(qw1owrr.y6&|Υb;΃Ny0Zg J2!1}"5ةoޚaI7Ȗ(]E{@"Ǝi\Q ЋŇv`p n3⹬!>6 0X(ktr,06YB^!3,:ElDacG]#=@FxoꖝnOd ')+$:)ü#1;f`~=~^t]>oK;4d@ ཱི|[,Kmn%C$_9:'FtyDo(?D bffkAOxE%?)G{#dNw?m@dĠFc4{UF_3z3-$'*P:*-"M,o|fs4-$JՏw:f=ѭL%SE@y<cQA3yST@D@_xto I.}f?5>&GnE){ #GeGZP$zR`@B %H4:JDRdxS=@y () $h T ,E]J*.VOp}8-JzRNn g{9$l,E ֦H˜yu)=C0ۦr]7kӅvtT?'-N$P 16e޽ِWhYT- eeSF-"̳= R 0٩F“@3E @K _X 5 R /Pf]TUn`UqDMN<\B^FyʓyT9xM+\7кi p?F:s"] o/4 yqԅ@gǹ%ֱ6MO9VL+.ugL s8^(iݮY֙ [ncq#а$ 0P{4Rؙ٨tX%w,Ab8bsvyN_HqwSذJP(m{pҒJj]me F $ a +d:Wax~I=w==ml.}dv0d@Q!<3 ,(B:79!覈~7FC"PߘB>C1Y*T/ 0'ů8 <.C: FmޑuI2?`-$ (҈n8UOqJ{I\hiKm kbzh[{}W)iw} fd{ǽ€B|Ր1䯅y Y*BϝsYBMnӫPNi5U DaTBVχj~U=pBF:0>KPPI@ hh+]F3ix#FMQ tis&ҝ; #7 L .5L5S Өq|}+TVmy2X,=_sd?~ϲg/:B#X"D;Z9dx0zsHr~*#Wڕ<ưǖɁEހ(gޭThdB"pQ+K=GwPmM Wh$kLy^sxG77#io=\:v)k 2 MDwݫ Z}N@A"L]hOHFy4䏈S*UX(AgI۳`U0ӐHt땥OyD Gió!Ak5hB[LмrP uef_8^B)pY& CV<`ԵWϬyA9lm;UϿFHy'`5.3e1Ѯf2]=)]Iӕc5SzO_i#-(F0{je}]^gQN7QsXIFK –pzbnvyP:X7.qkMh4YwQl65;*]emv^YaDfRT:-~11A# 70oMR]ǃ[p¯wj3{/'|GPmh?gVUIt!zSQ:$$$pDxfIQf2xv `5*{_F*{?Zڸ2Ґ9yA,0LW!*tI#N,)dBi^Ga:/NB"R~6j.Ф$w&B,V*FiۖⳜ8h+4EFjN5bkk%A* Q%c[b k@R Ax ,~/}-x>?9 nf^$DE\\Z"#Pp=3rKJBov\7 u *'rnobsքK+_vvխgOUۨ=]Vs`>3D_'6Η WZzv B ӳ-O =[,:R"1FK"Z)c]vg,/^@KGݭos7(%Px[X]S;;saU<(C <pA>L#" %`5Hƥթ+;F?]Sod8]?WM^o+Jx`Έ/o} =Y>E R ^%y۴6G#'9 lxn%/c(bC!Dx&r?K{_ZEfp*\of/47/6/㪶,-_(`(šqI*ဈ%׷qhɎh0WvugG!VP7ݒrB5z|kmM#j';koS\>'E쳗_Nzߐ,'(suou[\yK LWZȪGOGGU_tϑ 0bYaP2*;OR&qxgA$V"PD?z?Yg(Sy`&j?.#bb $ 8Z6? 7;0gѴ7{{C}iNf}6l#8yaK%3DcP~8e^X$~y16Z10TMY0OVZ5"= ן``(쬍oMfM5sLA6fo]Wzߧm5u-|NYxH40,!e(3Zoj*KQƍr_=>rLKïYR HB-EN]>ͻ$z7|tOjn_6gwӔQHRa)d9#­fo/g8lCBN5m&ϑoCR2jJ&D|W`M-ē{!X%‹}Iݤ`qr&[շ&06RYK}+Z!-ZE(|ZQ1X5q /@3Y@?_WT6Ѻa=u}}6ÖE"3{ZJ>)+>>G2}AG+ Y7l@+F}K>rlRZE>6ⷝqV޻p@nc"`b f\l Ts}3qę ߺv]cq/ʰNZȲs0кgzaL\nEN^J\Q1I_ȪIJӵ϶q=RQ#f:%K?js9 EoIl5g#S]l;%?9oW`vP0kHԘf^c g^,* ܻ}cԊc|%Boee}z>moSh⦥n9|ZW{˹;TirWZvuY4Lo=嶴5Wu:YNZkaaa)El2m===?O&;(k;+p?c4lo ,hBT;suWwk7qUT ܢ:ѻg&]Kn[ine|2j&󜚺Y9FFX:p"'NHjC 0w8kp}uH][#VWɭmnu5z_«y߼\i3M:#0=\2ʢIW 8@4Z Op6BXk#~){+GN(.ӂ7ǂ|ü(l{ag6 ;/M(VpHD9`uwțR^e]@`e5z`Z{~*>wd{e8}/[%ѷ֞ED/%oWvIh @GILH)L~M.0|RǏs{ۆwmVSamhbfdŰFۣm+Am|mi5U?PR A]\?Vh_sUԈ>¯!.7Qh?^ȵ,v@EJ./o7'C@/侮*#{^rkGUXl2 o''I@ oaH) rxn50I9TCW7;Ohve_3DrqC2$UEK~ί-vXwb(C}Rsg=U73X̌ aeCQpN ,>W->}E}}ێӫm6INu(GŷtHE"¦2Ⱥy}_<Пt'v([8/:57Rq7֮>ʀfcU|:JbE~H1$@!> B'-ic8$O.*[wus=eu5u9@Ş^_ L@QBEcQ#e.]NQ2_=> V\S:֖|G "kdo?kEHnM9^o;fރa_|(qW$)e/+:zu~B:Z[US|$#|ʫ]pMffDV([Bh7VS^|ko;JR2;WU^Y<_beo;CCaʦ eo7b}Q3@ DmK}9ЦZw;HHLsFkj?'ZIyH-ƬrJ$"(U ‘BEl(R)FI6W/FV>1rAX8[{i7Ӕ6err/.ϠZȨ!T\O.+O'y|rVam}Y) wOslX~߾w>Z='JJJJ?;NUQǶU!E0h弪*]L%n5J:'n\.*ƫluޝW}uw8u;ʯW Ўsee~|tN8`XDTͭx۬5i|(|oi ')~m#ssyzIy*?-mD] 'x'uTz{ b{Mijw:l/Il+k,l6Lr--/G>}mck`;Uz؉~̚H1 78ǮfyT$c&%@!$ w8fuwl/ұCaGJU dߛ*[mfM9ՔNh-[dcs! Q#8~ݿ^"QW u}ߣY]/qˡ_BPcv3TO<*VZbBc >w)ŲȚ}Ȁ>3%znjh (x |Epǒ1)~<hoVqM7 ԫNu{,ٳ*Vqpx'p/!C{(;K|#@O#,f1@UP:}jQN/BkNʣ;2sr ̽әӁ p` U_6R*lkEm+UN0);zr^u2Y,?2pJ!ook5oDg`T/QF|</j/d:ُ ~ A>Ѐe5X5O.ۊlnF"ק5؟&B" {뎪~,~W'OXi;^몏W67ʈ&~Qs@ a(] ~ɚ޽' s|z~ow>/=a]Ic;@(DTh201&ⷋ\rjݽERiO# LD~_yDDo/V볲w[u~e8df.Ϸw+za5 ԐY~H#sQuZv7G.C{KgbPVǨ@?Ժ콖'+fk̼z+ u$YʯQ57e {TڬYݾK÷ۡ%cݴdH(Jvl)!s9Pg/~t*/u6l7}-xvuD%ꞁۇ`lg13靍ܚ*ZNfB&u(uI";.>5cgz R2}! %NƩ(<)4|)~Q8(yﻷJ[KuU9%P<[ b' >L>}vu޳Bw{Q?^`?r2/#ݚ;bBes HMΔuZ\0VqB>k7E&gwp6k m[nG5O[o`BU ʠ "'lYS3B}~Acϱ'm8@x" "2äCp(|91"~wξdvuXDT:H@<1qr b`Dx"7=w |ww 0x g_2W±X ?>ſx$?>0.,Pl͝oҊj3x ~ryv~@d pzf6,Fт1olkR`Fm&,&ɤA53LTjBK T[F*_]~_5h,_$d@!̀adVw-Ym"TWm01\p5| aho إ$cJnV >{߅}_|i(e"" 2jƓgY$fL%1@r4eگ<Jϙ_?VJdb/YGm ߹'v.a41Af"E!ܦvHl 4Ssν_+yx4Z)#Kh  b,X9?3r\mU%3Mg޿cn4ck\ⵙ&6zZ2e;+RJD(Xhc61t⳱"0doַcL״*#"CfS'c1=9음7#"j;3#‡򿼾w-|I_5Ϸ{ך~>W>zm=vQ~:Nk$+9GRSSSTD$6D €7>~W*kguOWw*zff%ap J/֮ɗpk@Cz  i"+U F:\g]V^BoqrVj3YV0[; 9D.B}S.Yp'HAћ\Q N_)45k]Q=R" A6JU]4c:~.prePNK&s(>j|%r 3 y ?B4KZG˫̎n_o4% ,S@uf 9ş$E;פxՈV(OTiRlu0MY4EKStW<o<{ɛ,R*;=(wg@y1UJјAvfƫ'{6u]UݷgF@ $"!Dgq׹8ڜܐ/آ6brJPWA6!ٻCCWcZ4*7xq[x+.Ң築ʏT$M Ӻܪ+~ϝ Fԛt:j;ocVm=zvb`-h1lQh+.+R!?7_'OB^_zn(@ B'#bM\DLsjO6HLI6N\ɯ<Ŗ$"J^k7䒙U\b~f.fmHIϵiu"CG\a({~F&=VG.)9o F#E@xxy?ٻԽaڵS.B ]^F|0ova~úwNa)O1@1KKQI\](7Ai ۍ!F\m"WҼ{ck.Xpf,^4@ Uτm@-qoJ  p44\<^Kk`hLwisak^./B6A{͹M~M| =ϒ{+wW~gKKO­+ߣW!VwvwrVYFm&0kq־.1WVqsq5Fa]NdUq~AT+XDnuzFO!WEK/M٫O- )b+nY@B-TuiDִ޶l60;CZ:㫝Mvj# :ZGQ\n!iapǃ =R^tKşz/׮~z i3QCnɴ;k+֪C/xn(K2̀ꈌS`ŗX.m@Ra8XL`%6eozuLBBu\ƙA]2Wv17ds1Z?~V}7!trz}6V|t ,v<ّˍ6`S"w(;^/u}tw~n /]rz_nw˦vvzL=ҾegVbNNNNNC159je6AYL,K/GGX4qzA?|Z~oCW5x8W_{ip5pD7FHI|$>Rpb};0<}et˳ArN|ׅew=mm9m+jy}(+˭K+|zN&U{Xo[X][/n:ޯS4Z]{IYfz9v)[[WW[[kk| F$z@N Y<%o>zꊺ gy =qjbiUls=@ 0c|Am W2PwG-hzL" E-)Xp;.uErjV`#k7ޭSAb8%1]#""710|| §X 70 EHsCPƈ7k0Yչc.̗4pgmd$|QoW&QOA I'ı6EjVglz; ZJ:[5o>g_/4?ehE]@1 TsփQ~i'ރ F*tPX,!{[D鵞NHp^A~6Z@'NPa;O/>|ޒq\86wE($aVt^[[)Ā`Y!b6P{uaoyQY"o,8/UZP.4 G݀*V 5>$ZG5ط@ߟ{ Dv Mփȩs)q]X<0ζ H3K$"QOEG3\eNd$(v 1׺}S%ݙpzRNf#|v?UK:e-ѫrAn҄] RϸkqJG Ꮎ/bKNV~IuE:7['[%2&h`h 8*t6CCZ(EV[Zp|ivVpհ6Z" @XE"a>n6{tfKmtBkܴ8=%` ?* $ξݺ; l20͜yTa(A:CJѣXG5CFB]C?p1& %#&Qwa]"= `A;,26 e(^U,&\PFM}1V{,㋱W}) ߹r:dŁ/[HuAcjlB lcKF>F%}[;nBqٔ@C80uT0B; n},Ym7Ca<*#$ŏ8,ۙ?q~ M`Z-UbZd.V{Dl70?@8BCc-BDF%D;¦rV'[ʕᩫp.@P8D&NnXcFJ Q)t ,8UM窤S(ۅ2;a`1Ik6ZI ㋍6&\ AϿùH,ob &Ģ)NɳwjWu\N?;KW;mB݆U:3_k1wݞvyLlTbr~Fdc0fxd?ai۬Ə]sggj5= z|+:[sީ{{|{}āVB@43i?u߾˽q!n}v{6 yY9is{>؞{Ɨkuumzv.ي%`'{>vEٖV[ s*=gm-3:m'O[{=LōKTTk/wga"P66ec#}/!ۖݗWw-mr@-}DfP5jTr nƝ3 |ɺ|&W"A"]Ж6#+\>_ Cx`AfUd!fcg.k6NFWăn`o،SK Q:jߧqt_Scn|H]s:rҩãɥJk@*A=-~cY9:uY(_"mGΓ~3tɃaU B 'i^\~' zyE." IJ(ޕ9"-)&xeUjgky$p5%[A=Wea7l5~^}]赭W\ޏOUy7 ^糴xs` 9}-i܋1҆-s@.rBuώa85ǃ1nڬ}6hlgO3Avr$ǼUvd| >^*21 UnGYڨ[]PCޢ57FA4_ܟی/30` #b`c$ܺ "}UD%%?JOVzx]鷣FM4Hcu) tMdht[]?Eǻ_m={Hݷ gم`ɟ>:w]"bԈ=:[ĢKtt@J FQ2`9c\b_0|}]֜^,A:>p.nj?22N, 8{UDT}fW]P1c{^b݄yAV"V-a?tM2=`˧G1k1:n1܆q)Xf&a֓.ys?1x`=X0W"_ckڍv?qm}W]z1q3_Fs7o2^42zV"/?{EoPQRt2] ~uio;CҤoh:mj6izg ea_bČ5l{´aNzoppٌDscnw9q\tqn8`_]R~sp89Z*><~O1O;28|/Gxmt܍;H>@ki:VUj?acIegvz-VtյՕH45 `t7 aIK% wNIS8xH~l 6Cb:*w5~U! eh11:&rdGOqWQ0LPϳƤ6yG[|fua55Hu'bG{=s|+kHi%YIaeGTU, aS颋VEKuT;?!̪+h7[ЪEuYnh_g+xU`xAx sл魞?XuqR :!N(` @u;!kMͰ1uiRXJkx^?{{o]-5x]=xtPo7ʪ hfPӀ` Y9z2C b3^$/E7&CB"qJ:W8):}AKmm*UP^n :M䤸Ș@M i 戣fQ@g;/" T<~w9ж>o:@>쵊ˈcYwMp7Ut|i,0]ud!O7[;MUAk۠`chx4 Ox&3S$ۙ !!X$a`&(sT3֝&UX/djqumiaA٨cUH/7RBFچ? *+ihuC)wX{V1]":^1΁p/U1v[afO_jO=?%Q'I+N[LՅ I kMsLy>~woEiyTǻe˳^5_ɝ//8NBF 'w$<{oS~7B%cg@^Q[6k @nH^9WnutoDlS÷ #M!jHTɉ* 0 zSoڵwG3g*aJ!eg2p}>bD љ ~X94v몮l-H4J+_O[ɅAD"M5>EddWt} = lFBOޣѶMk5&ӒJSr 1#a+5]wYLI VT?q 4UP24A+usT"͠jkjp$Hr+P;l>h Dh0* :@,YH.HI >v- > ꝷ7Gp9 >_t:&s= ?Qpc\̭#5Gvkmu}7w^ÈHDs9n]Y~L| oqqif&&!&+'KK>gv2D̬檚ڮ SMFjUp<^NW묹\gG^ީ}~oa!x >i*o|spY2QQs/~/յYl,/r47]OCpz|ڬuooGCGJV һUhs; ˍչ=~b{סWWVOO䧵ZZZ]fYKKJX/UDv]߼Y?.nyn[gR:i۴M勻w"Kd[8s@q_Ʌ؅8o;0qn*|cUQ4z78d@`b%, j翭O`mfg_:Z J?̇6*b1²wY6UjPk>Ӌ|%l_fsqlMX7 }C8ٹ\qhQ'QG }=0Rˆpڢ<~.R[ EU~_?}wgn{0XySwږ2/񓪢Et-[? 8n2 S2m<S)D@2fatsѢUUJA)^SqKX`'&C ,DD-xf}}GڀƝTðq7Gh@ T[[6MG|X&b&A zWP- (@!UFhn@8 7LFtgǾ\'=K^WQ_ie0i[lAݜ+<46S@iLog^!#noy*42a2b3BP!f%`g8~w?:t#DDH,Te5[i+Jh6DTUCkfK,m6l⸓[iL,6Ami)4כ,ieH{,bf, )EXeQ#\` h4k_OWz,4=n FDwk|z垓wڭڐ(Y#ar:9w9_ڧj{ɵ6Cr۸4V1 #4Y93qS}G|vIg?Qys7@9]y~no`2?n]߲`bLxi(~7gs@,m1Z{~V_z0/{S!59PHHHsi--ϢCAi?пB:+-36[=]kAr*マgwNåu-=}lG:*/.7#%~pD8q7 }Csh™f]csoUƈϵ'1-9^{̆v[ބFc=1po߽.[D_^wְ+=ΧOizMC+k+,k)3vʹZ,;3UUU(*( cc:Dbm^ 'Ulln?̀9$IgygV"-&IxH&HrB,_9-f]6)"yQ>s;W׵v0/ث,.dgFBǚ{7ƞ-'(Q "\aU'pUC6h&u"ٸo9-簁D@ߴ<߽~Ck@fk+=2f.q%]hNk "q??`ƍ cc =,nGhyNRo _*ȧEl_FfY" ~B PX.hS]ر9- @nŧ3 ;;95'o츸=e3 !=c=g>hAyyiyUPa?/.zp&0809kfNշů2{2*k:)fFtsP'ķơǓ3NW=||>"E1:.mp(Iգ[Cvu3dtL4ŵ !`?!+̱̇Q dJ׮ƚt1{:ڭ0J+<::d晔KbC4|x6 aJć\;ZՒ*Lh`3(%0f@?O}8e#kw4ujMz%_K}uWJ mNZ[56+ U2IywWJ$a~yyix3󟦼?ey/zy)(YIMy~~[}>@[ٿW^hHBAZP%%-6IRh+PZ5,|-?1#~]A. ?v=.zOk !` 90_RDF "fJB9?,<Ns_Wå+ 2D:=q+u(H #|oO T A)iTGzJmgoo滽VE r|ϡ=909 h7{K˱AEADE=>xy [ o3p{votV(y}',AERe F̲,xKt3wcL-*ѱ$@DU;'ɗCU\5t' 9įYzucK* $B|N=E }7t3svuke1k=;m,wA uo8*:ΝWkV؆.wu7"#eD sXo)Q~[ 2 $}R_G9o!'[;~UXT ˖(F<ϕ6{T-5&ÈBI&ʣ]C^U CiU{smm1T_YHk{DQŠngG=w NF+_[>獿U$6c 4պ(T4[ץ6G-@)LnFF"MT%B*QuuLJeT4HC(H\|[~C|7;)ZܩDTX;fT%v<8ޯ0Õ<;;[/k} K@T$D(0:Pt,ODU}'I\-/Ӫgu+}Zt.݋l2RNN c82 ȒHnĬ=h֝q_q|f8^o+u >Q]ϼEYlo[mxW_Cs{l3Xϫ~9_ݬ}~|X+UىJrЕ S}9v]EJ/w.59%^OYW̮:ͶarwR̈́CV[v_N?ql8zH iZt)5wgҖʵ}b3^ķͼt>?Sp Ԋt=ƴ)d5[]Cg6ueχ-JJKv=e9*zjz!!iּՑ^L#wшY\2&@Cp¡E~ ~MGaʥ;~CCNnNJ*Qr2,u.~2P<<40CC+(4mI`@X@ la9H {0hldI.<q\\K`z^c$5+eD*@`]\|húQ~a~?%"x|w*9_2]0zWCW2 %]=M^0pT  JMͶ w0QC:3H|PGoP@/3P[L=!B=!b@$2 4@0 9&J侜FN%A>[Ƨ>2[ɥ6+<*xd}5|bT?8"17mBB4,lG3dpZٙ bȓr c)+z"3 .(+hȾ O 9 A `1 c!PELFY\c7d6t?736pC`RY;JȡA;O|&n9h83|S?[߅t~~0z@i+[_g"D@)mS4}n][ilpB0P-J%3U84}:%mznyXu`qYv]uUbii7_Ы>nI@H9㐡АnO):_6A6]s //3jm& 5װ= J](g,$Gix 5`!Y$qdY{4' z3?|B/Z}@K'_/_>}~zWʁeQ, ĔP@ģh7T }U^CS۞L>샂60pN" ܑd&E}u9g9NG_^6c槼jc&STV[/.(i4Ρ_CRSTn +TUZfi[N=V|_=U6+(h~w6"'THHBƦQG6aaov.|U*ڋwqn.L[?[r[:|'~|)!w*.E^Һj3pkn.AU6V{KLo3PYLdceWWWUUUWWUUWV ʪPKb#QUPuN'ÄF$P>{yn> Ce}{CePpaEInz;[ (=k.oW͹v/rz 0B QD G~=Ij+ٱ>Gω@. J)[7s)\F3(ed;c*,9vu8=C8|䳨T \?k=7xl}VbӭNwJBĶ 2u/9}#~Pu8Mj']0,@/y."VLhd;!5ypsQ(m.0 ,sgXեK>G hZɒz'et4xBv|'_JƲDɬSO9w370Y3n{dֿL(3qQ, P2|[kMzAyuhm)!lJDU- k~-C}|75 58?a V_vz-Tw~{='zD#ǒ=~{T+(C@Eosu 'F3D`Pv~kQ <[S<4ZuJ\oT:l"z?R'_Jo{6\MQ˶]Y9}>*#hOzZ\琉P9!@@X<O׃1DzhA"GS0Wߐ!2=ZL.gFZH͎JOYɲ_]"U",Z|]Q\p(&HK,""(rb'A+U\rIV*YAUA ߖ켮A|^]~$ʑlٸ1@ڟz.2z.[T0ֲuLjϫq: kvDHȗJuS`}l 8)Dã5CKi=o%OC<^;4:(BID'Tf=;,7{B ?؀_8ޏܝyOb!ř&zs!PS "i[zI">W"[u_zWWDz \&f}Hv\oEo;H2 WRKc*Z.-9rD[G?grGdE  yR5叇А^Xtd1,$#bJ` ђdϓ|S͈_ѫ[J >spt>N>.?a2NF_]ྗm"ccfIϗqco^>=s;I(9Qt'&N~j?b/C)J|_IfuU6TH$D,$F`RFv(y8>22Z(FHbc9Ok\bs;K}}oirQX$J,d3}. J6s4ˢeYaNDEE?s @ZȮwo0 z~o{گ>!wULADK_i:1kD tBN֣_sJ:ZO3AKug:^̕=)&)^]{1i ` ! ȅU=v"!M }&DE0XFQjV%(Vi%Yl0 $7t٫XL>V>~~ &AD % >3rf6`Ib#b}⨔(juNPHqi($nasw=_"-pQ~(h%ȘQ@Rx]InE9 h嶕1T?*IΉdͩ@m7De7}DpL6$8R@}>n1Dm AJcd4 wŭZby\zm|8/80HTzY^U #߃]Qe_8Od\71eb0nuv.8B T2z;C=/cv:|'"ڪn0 r?)'9җϪɹ҃okvיMM)gFL6i'٦Uۆ^WqUo8vIjON_Q泮@D@$r@lc`1CsYx܈:)!ݛ˩9onʿvD!=Wn3~vcU%Zݦ56iGugO.ya3UzoãxZKJNse"feqξҞR֭(^=,y1~#~m--Nekio|Nvv=+-1+#&߹{ M ʍ=7붖%mGBE'Bt7;h,$'Blz\~qiislu=gu׸TSZ4߷&?OU;ܮY9ZECXM>m-w;g73UVWXfyζz^/leWWWUUUWVV^ dX4\q48sYcTDRlK|*QŸՉrH̐P8.9Of/S\ 7)R2аCo9yZƀd9 r z`$[E/W}6 N)Nޡpխ2-ԕAE(AcB`Y%TQTR$I+" dk6JDb6lғ9\r0hţcu($EF(e6jLAtºstѧ+UmV _u>|?]#:3&5F#䄂 $]pjw9P0juSif[W|競:ot[ڛQUTRvXV|wBC(:c^9y^d!"V2UP%YבI6٠S-QسTvJjKd;˦&퓜 ֳQc SVVhM0 R):i0j"RqԴ̨Y\`F K0V#*fJPb)"OHcue68جJ tZR%$ e&3S\H"YPBdLe7nSLК9 1"V-0Dj. @!ic3 )" 2;W29JIZXb,b@Q%D"kHհPnf$ ȡRP[LeKV b%-- iJ ( @m&Tf}f19ai5>oe]*59U#'zon^M@RPPt2|&RU?0wv=}qQ7o3>p]D_o_v& BZA@jS&!+W.ɚCWh8 Q[ f dMkVbX \֤+-1E*DTEF =t9\cLJEbW]VWLw +Z4? /Iʕ*8]:F.&ޮj6s4-FM8Bt2#Due 궕YnpŹ}ď y}= )T58X̴ZIQ-"±l@k r#jj H,Jf%BLAG.e&1Q "cHM) dv@[Ed/Л[&xfb(H]5U292]3YIuŖCHi( JZUA+Bˬ1jεq̆b`21A owS}al hٮmӓXPbM'n)MffgtkE\XZ#Ye*c)2DdrFDH0f\H i-e DYQUpR-ѭLTh X2bit8%ܸŐFLA-,&L?nU©#8ȈDtmIQ.TAV+&-(-)WMQ+M]3F1b:tE\Kk0LLʮR,"("7EU J5J*꒥-ѫ51B-"06F)Q\ncO^o,9JɵŚO@e-=kΩ6&2j7WXvuB-vaEN^ %^R^4T,|;կqg#8,GIO>j[b[4OO ٝ{Rsi;6-nλBg"t:3=1_-_DFYNϿwǫ.+s_&5_Z؁!9 ɤE4`51F%a4d=ΤFr5#DOסSƚf'EĿ? aCgW[:4qQiJ-JcH)KK$֦شZPHH?C/KozcSaYHmN{~4;bABDb??ݳa[>7*N{N s#7ˠ$Y=ד2lQzO`_u@loo+GN?xu#`t=|.'qXQX'Q+Tv1+(4`he=b$HrW``, v#$6uiyv>׷ct`n6eoF(1Xbޞ= xo7#ˉ9E͹tڲƶX(]ow0o<1s:+|}^wOޞd%YC|5]M] ~r$*$i&,Nɼ8M=/~l?ͼS7y܎Պةzܯp9Wz 텍'7YW}c!e(e<%F]MMuʊJc!UpVZonFl4rmz|tyNPP& Q<|uP^`7Ĭ6ko-#"@1.Um>jve6zOD~.<"_ 5YX P;ɂ'@7v@,$qrw،}nY`^No "Fa_ww G^]CHp1J"И XJs 1V/i~C1̍1a1>r6 0mPpVO|S\Wxhl|^OOoZUUDҙ WXyc50@QJMPe dHVS |BG/&Ǒ1:<[sgCWe}!vD'[&AqRHH=]F6k^'U spUMKo~&뼰+57ڌNY~q5b깽ed[rˊJه-Wo6$'\$ f&¬ % 1֙FOD_)1i  FvoܛDoϿ'&=o]1Ûx2顳p[|Gcx\) &ME8nխQ>Pϱdl=UEUm3oSR.u֚_co5K-ڴ8>ň~.$80Rr\JgFΧ"\bs8LL/ows0}62F_ k=6_OɍzudMUmdobrfy#1^CA\Wbݟ.#]5Z޳U4 9g*,l[-G__cyM]]]^gWWWr!gBصՠHq'.R0S@@+²ݔwE0_ϳ]}#?笐5!mL K &ʨ  z@,h=jd!HEnƕ1 ֭Mdۊ TK.+xoP貰+vgƻcbq`IT C#@| Eťp:X5BahY#e|u.Sh!1ǎuY}M]__Όze}Vly|-MxC?VP:SL4F 9 7H[-3o=kUҊsn4_z{:K{~yc|,~*AP#!:J_% ח 8y9HHb=ٸ'`zHq!D?Jx+ٜ8[W~  cNgw^2ùƈ"{~|v}Br}Eꚽ ,4ƀٲ Ƃrl 4'RUJ0qlA/`j;0 Q8÷)ϵ892%UO?'sz9e4keS%O7s$*:33y wMuW$1cm<'XGJY($B%"IEFC؜iο1sWu}_9$&C_]us LO_e)) c0hp"$AE7?DE_:ƾ~X#輨*o?,=j8gR\{jnov$0!ȁNl& 5f= :"Hpܑ]Jp"8f5lS2U B}x#@(kwPw=Ax" 1"W 6mr{|n**PR.|L(;M#gǕ<F(uרC,{RP9FM0i̶ƃUw3e7iڰ!fFLƝ'ڲ`)th08UH @ =5tPx+!i]l5׏}kM#"n[ `LBl+ OEuyu]kŒ-?9eR4%ׇ)x\19@lwDKDOeo Ks:5>½wa=>J9E=n/bMt0_5ij\A% E,55w ]53oEENT#o\O?ۺ(~dѴ8EOK3>Dsy}!^|!T@! Ӵ%d1BѥƿR1`a$P!_~ i~ó<Pa+RW ]4 &Pʱ$"C9D!`.9D8b[Bs TN6%0<:9`;pWxMzbS 7X])Xf`d+y zsŗt]I> 8f>@h(ײҐ/Wp'6.??+eOƓ2";|! ) "ԌɇbŘ!FB Q|.9__޳Hمglboutg{A\9}kunX2^η.#“]}73>' < ą<>o@-4;LmR4|Ujn\~OCM-֔wzG6w}h|gSޯuKg}yap/=bY?7z#--1:y wԽ*8\+> %[Msikh(7]b۽d͙,lll(rPYj*jjj%|>*?ym>/7k o%F){ڣԫה{}%3`*D˔`krP$8eky&O<2E|YS'2ea8p׳ZV!鍣#'16m[3kCk[ %,B㳉$$̩Α2rᶒxeb>Мc-:n{FGf՘ `WY!be mC4@!4!SrEt A!Oȅ!#1b E;"?Ni6NCttܵ 8X@0h QԥC~[SOD>k|-m}Woo}>'xX evP ?ͷiYFQjY" (@ou_=)X$jٚ* heWBjos߫UCh (QÎu_a@İ=K?Eцոxˮ֬#(!6uoKk?gLiUXQ_X[UP9ss`I$F,4-Q@_Pb 0(l{x؊Y>@Tu" }HvWVéMA 8}+<Eu1]p[TR.B[g5M+ ~D:AFq#X#Z>*2߮U{|&j=@E/sGR׺uk02mom}]\W?CŒ8|¿t~s";_:r# 8A-+~u;itbV_?ŭ֜U!8q9I_WiZy/ޣA~ N?u(EvH gߖ6#(jX5-l $)ʫ}#u/nہ՝ëw+^I{rWƃNoI+KQ} ֬ 3)< !xʤgV;$g?w1u9ץj<$MaEi[~;O'[87N˓}vZd$۲݈=.݁Sd{n7ĭfs~bC[S޵rNNLg,em5<)rbs" zr_F\%5>U.9--U4 Zq+-k;|+]Sy-m \'~p2R~T쥄Msʗ;sRWsru{y:|QI>.{9Iy8~oՒJ~9<k}o<7ovyO'/ԅx_W+9E|\흧~3}OOKe5z7UXY-3\i4Z*꺺꺺%]  M d1LWЌ*Ϝ's66$Hm h@#"hA,I 3!3Cۭ:$;:,Yұ~xlZY3li@~@"j1,?<G?O8'p9HR*'I)Uy,?틏ʡch[;qaľ2hjQj(Ef5{Nb\MmDu<>L^r|p{vZwF7إ3je?t* C6r1h:?/B !FP<1AD@F,1"#}7*+Q6>׷e?D|q[ [U?"V()]C$3Eٵ- jIB8e"]"Bq;Tb)WT jݟ^ f09<$0+s #sY ?h@.{  kEA{nZ+֫*^T7762GhC|tE6vդd3ɂ,J77 l3ʛ$ jwy3.A% NOq7DD'ʦάE{_Wyy ti Rln0Yc|(+?7߭Mm֒Ts2F6=C"T P:_Sŭ6;݄2j[mް(PKc~/5A(׏ݨIE!iP "92x?#i/SЈG5W'uʾ7gYp5$ȣ3p.LiEkE $R9]StJ_3ۊ2+$gn}ml^3kg_9Q)o$] DMUͅ,1s1˹8ߋ^hHGQ&9Q)A4ML"AR$ĐR C&$dbiZ7ݸf,)heѥ-13A$aCmSD4kJ&&ԠVd֡cBX(jR1a=q}GYSǟrgPʽm !fX#뭢˲0 f `esnbu9Fuh$cY^i~>-]H\@ !QA٧ZTGVS`ıX$( |nf+cn(Ajfl`F #GOkO{ mG6KIa(4W2a0E8l=&(HVl4bd(D"2X{=o|;~e5`ҀdbP,4ykX‰3GzpÆ+ǣFm=s^[*L f&5W+4UUT˞8nQNH'wq780 $Umw -ʢ( m𢳁9VѬRWksI6DEɵf@0)B@D\Zg7HvJ PXlT\$GD5ceK|B X%v~v@NO8[i>--HG7?[!n$Qt$cd½9E!(Fb;Kxpx'X{'{tc"F0OPM$pT)KlYb Ǩi9OL!VHX6I(i^ |4JaʛAPI .']s_m3@TPY)Rh-FJؐ*-FX1mX6,1QDАH2Pm?sCjRzv 6Ä*(̦e`S̜ e" *o."( cy 3 Z"ŮU-c,M/BM a;UcnID'5VՐ+q pK W!:*:*+Dwv*JwRHC3F4.Jmi^NaWREn})dE(S<LhzcpƲ O WT Fb'~ xv{Qxu@ >Ro9<\;/38y3[Fj.fg-r?]2<ƾm:זxatuZ}7~?Q_s)"TJM&ْXfRGeH4 srM[}OkK4uc~lvny7'ӉG}ZuWVg%8CZq=q_RsfW湘:n/_̺r=]\/oh{h)0hhow?{~؆e;DSS붚6r=k'v.?oom <ōFZ)MQQQ)**QlL1o̱_/t,;8WKfڌk:hB7:2}‡)M䴏&ʌ6>~ĒY~Qڲ6rǵ,NȲ[#>OmWwſODZ=xgx=R]#BZАh $ I[LC1>b*;2x.FWGN=96;`:-~,N z4h dl|~l$N-JsG_y'w65>3lWÙtJk̥ly|b{uӫu0TGz(CHB(eJ Ѐ  la%MY+ys`+4w=U\TNQ (0@XiE ɶyy$R6IÄ.sA{Gņ HG7 }X͢#4$Voo:쫣Wc]>'HȤ)K+kL&$PDu$9iI Dh-EUZԅ Dźm4li5fZJIF볭 cu7%1qf (%Oab{}}ɐDC0hfE͓46Gܹ#$ܺ!4$Q($5I$˝3tW(TBiMD2D3,fb(Kd$(ЉInys]O]`12T`D IQ%ۮ!ss-I"l\B&f5$AHn\_widT0H׏U1 X 14lIHB$#G(2$IjRw?+}ЯKxOB|p4LRhjQt$qΛM߭h\QUҶ""?s6UU+͐ܶET3տoN*$^ap\ѓ.y&g~|znO;_^ dwcE14mJVfM6a*B7nグ کy-O~'jSN<ٷqګN*@my6[q>K{ѓ`iNjmxSl>ͲiuI1jk7o ˥:_M^ЇHV !W[,% x e=A8׶Oz&#T qO!DQmI$V#̒U` 7ħ#L?M{X6MV&H f)Ý" & 1cFO+|m1MĨ,}›#[΁wʄݾ,?e._ENΫZ~gtW5y,k4 8S3{NCM+^<]fU[#h|T"cQOc 1`|L PHDb*a:6zM:ƹ \8 ʱ*DP6;^& p%0[oGW*-HpX ?ᮉGx2GuxIH͖RJD*B !NW-~~uVxiUJ4C?]&QY81<ڌl7o sv|N -Wn+N5qYxY&ȇ׵)Dʪ*s)ЕĂ3J7Cӧ2NOλt6~ީ}RU&'é z+|z>_ӧŹtT.o~22222.C3JsE&aAk=['YZR6NujrVޮ?gal-0=|彋CD})bbcߤ#8}}arju{;GCNko"q>x}T}n ]EQQt=޿?je#2ns:>+ܡ}?~Km{XzB%%}kB\G!G]cETx@~Bۺ={ǖQiy׏$pk#Yuh>r +rYew'@#-KHܐww^ㆨz<+Nɰ+Bа5ƏkcELBw05'*\٪#Y!Dtd,L)+NBW@Dxd.Y T/P<'7Tup״` HL`bPxSL,!((^>Ea]#teL (~SÖN{7(Yo~F$Ï۳jp-@ ᫦3 l7zu_1Czy̌jVͭ)F/Cl3=5w)j1akB)-_?寮Wfۭ¨1q︫ܕCS7o4 Th$d`!E4 d%"iA) fDI(l`2!ILL)1bC)*0$h")lV,`[MjbhLJ v$A¬QZS0X.F*6NKn2\䨨ֈh(srmc[A0TW MS!X*KF-IY&ڊM!`HILc,Q 2L#i(ҘX,bMPZ4XɌhKIi1"jQ*!QQvxY|xY5E AiAKd&YKM HEfn '?I8✴)P YfD*#AVbbmE)M&#A-soWHfQI9eA-.pS%QXwog)vњ3=q!JS]sn5A}.$ȬhZӧKocr鴒!o<|7]X4 1$!X҉FI!Ż5sfH$LiKMJbZlY4 %(,EEDIƓ%hX$ ) I1I2!u5/oxU2d(d1F2ň߮<\5`E4PF#6i$xf{̮fr&&EVAV~E(RbFp温a(fM^]n60!ܹ/s?4S1qu=w4G˿/#h_ ynY,>u؊ DF-(jdhK$|z{[q%|0.7 c 41uB:Wde$8P Hp27kwyLg?:Rb@#: j>v򧩆Zs?3k6ʱUz6/?o6G<)88׈~1y$[J(b.?CwM#[Z6˸ ׍wQT^wet$30&( D9ZEP 9\ 0cypoC!?N3Ţs\Y^Wkhuv(R&O}?y/=T"`KÏ.gNU( JM]}X %Eu-WUQ  P*UV!6r_HT7BffdFAfFƳf̶fW[vK6' nc"I phL10D$Xz VxU`{إ3 h׬ChYIWA6.&48 \Ð``T5͵2N x:6%9I=yQE_\.JO0Z[rxw;@Bq} fMLLOL-p{+̣gbNJf2Y:Z4hAG\D_HaDrD>1 / ;ljlXשދ;֧W%L (HG_>ҿS}:2 olψ9ʲ}ןe=YM|ִ[_8x0~¾YWVq|/o]QxA$$$i&@c T"1p\N}*?%@Gn>ނ~׻mdzzuOcP_rsݱ7CO͆YDBl)yk`*>[&$,)rw(ޝ'cgxNg ?4k5_z/:!&7:~?q=ޗE;ՖWhy[k_a;=^g-^ٗZYYYX!Tu_v:~cTXSRF5D)f0L{bCxhvashk}poq^흉+  FDJȴ%⑾O6uF!ejRɕćb֎ا,pi;2eQLVi'@_LU`PH7r;GO~?:]|?aj)Ok-17$;@*Hْ,QOe2JK(ڢ,ŮW5tᆳ9IMj[IbV;pi'A]9 ~r@F GSEv .bTFss絲P! $IO:Tz}(J(K=d=mק:鷛)/*60OW>mFǧ|e4NX)BQ` ,)K.\Q{wDĠ DY {\=z{vy'ߋos ƽ{8+2׋o"i~ GE{%iwM3NZ5@j)]>(  ]R3)B#\ʂ'ߛ~wWY`{.v[MuJ:FP嵋oo/=9{оQ4TB>)SDy< ЧS H@&I[!i$me8[AօU0 aTz~sU>jx\z+DC+9zgve@kj&{x%6m.r4S;סZtu8)E9G$cIcULwޛ(wu{Y{aܪZ/-վ b[p뿶u|V_:WO{OU+++++Vg2q+4Sw vsTY'k io1smqu׿+?ޯt܍?RUwͩ{HBHvac-MX[[|]NG;da3/>sDGv?6Kw08ښOcu#->^o}7qiR+D]15~\ѫt.yh sgWY[]_umyOgOPNtTxMܳ3pZySz;U;+'T(E]u]Oc~X#V_W{]I6O&~ŗǚ^<MB~ $:pIZ j*1e~%d+ *g˿EdO((䲞muysN y"!f Ci?o_L}|C\R.2W]V.^ɵ؅(dfwTX;?srp,f! y lNǬ;*.LQ+{\ kNk}](ºV>>_gyjȳY.+I%FHf=W"H"lIqh(YX2"Z[d%1jJ\$aIb+qI:m$#rfjZYثv'\T  T-KJ Y,JXLSYݹ[ ^vd4j(2ݗ6ٶ2qs 3H)aRmMN Ӓ:j[[Ad"Λ~‹}d8},})o<ˈ%3.lef2\MHO4S3- 8liWZ^+EQ%Oj;(ZTUnjjSjUdqC!YJH1l4+X(%? =S']|/R; Qr[W=LЁRTȷ:dn1qe59q QZd0/M34Aƚ=#<)Vu9k!*%qi=_f~I@qwn] $tO_9TxDF_,TBD(@n9.+$ZYJđVT.'>8lqϭchHI$zI@{+(~Ǿ}7at_t_8֬OwXUZ {_ &آ5d~?ﰌ?nJE\(n7_9H+"5h"8330T:0b`~ a&IcFm5(Qʥ\`C.V @bUE?/OPH |3Xo?my}d(s\ui#\cS*4muf1`mqr iq[$2h4@(IJQ#e$!`!CH3LX4Ɗ0J53`ؖfj &R JfY-%Pj, R*`1cߒmŋXDRkWWYIdM DsEB+ cs[[*iPP+5i$M?G_/>@UpR8S?i=;MFO:~7؊a4# mj j^.U&P4$bXb&b%YTYXښT?U|OLѲ0š()!\m&uͫ3(ןuzx *J5{uR66 7n^O^["3&hBF(rVw?{;9w84w'YD|漽z7 9*$E߲.;"EE- U@ڬԄ}wϿecbt快FuZOML؍{6ךEu){bm`-?Yߑ?ȝ:M+ȴFְUSilc_FXX |KK4ehLD-bh1`F}YPݪ1`w _Oq: DPYU-rXJ=(nBSJ1Hl2Ԓ"f flvCqP=}dn)s81^[,+șHdH v{7 h"9c&ѥf:\r-y;R括a9ǖl;ϕ3QfrO?z .-)aB4tgU 3$AXـY `}[w7!E-)jl%Jի unC,zy^# %|]%MtCoB*{i^4=A {oz^-wm"xssI{G&vFFFN'g_)GOjAG?ϧ'3~,ηy޾AgcW^c]WcnmY!,{((6@q&˟vBV'HFڞ̯cn!W5Ϭz&)eTk^2yA%*rDS\ҽ+ <{2֋sU_cd ?tCz7Zx(pE'_DfC,;f+qgj<@.E@ΧeSjs@̥xп:5wM4.E*9-w9]wIۯ=4wT@ 1yV%Xy^}X7wՕw<"]UdPa.H)H+F6O+<ǭ0͘T4Љq5i7o?C6ڸ r7έOqSmlp$}ȁ%0DG6~<7 xrzj;=&U,\Q[ uΥ= 1K?j}l_,K]{3qi4(bߴAg\ (~av:imzw,-|kvb YUMl>PczåhřNp4T7Rn Z=W|; Q JvqLc^o`W_Ċgj*7J/RCy(3u!`vN¾[a<{6K^ w*p5*_rjaϮ'&ou %!gE-(!;|HB0]8ҐJt÷31,c~]1Kŀ̐a, <%TN 'LmKs0m`?>@V[* E&3^p9wd rB3e!%0QkbXJ2]RzݙP]p3?%nUV,]^;k3Le4adB&*1HD#[h4oVMSgaޓecICO. Q9pQ;R@2 XBq|o4g79,M`sIYr=CwZ+O_;Ph+l1YTPHR ki:#>~D X.Ji_cn5aqnTu4䦘0cg{1o:Ie 3+Z.RYGɲ#>1/s!׌iτ,O!yE (V Mr|đX4@ ,Xf`2yZ q!jWDEwl6Wzcs/!)vK_?=m7>Nu)RG ͆S WpHK;./tE~T 0h] u9u0M }qE_ZM>NAbJp1<FJԬΖED#ׇVQLQV^ge[pAq%;ɩ倫'/^~Ho[၌dG[=q'ۑXabVN<.KJV&K*-w'Xa]?̄r#+jq43>6x92eX֏^j 06!_H6O28xDWB'#9z$0O^k2mr1W9U 5<l,"}r7e9(BiuJMQQMl@1׌N)=/fZl54V'ح%E3c ƀMuCxE_}ɀWK*4-cY6C=tMe *i2@Ԗw] 91ܾ>lWQ8CH+ZO45 ZD  ߪRM2IB8l[>ָ#op佲-*1z"] }?~>{oPlt-7dhZ`:ۢ9P[z<߾ϵW|>o̾#3y-tR0|hu{;3CoUn'<;<ܦ_cyYzJL?{V}{x3M A#RVly}?MhPݵݚ5^*g% >[u"Eg+go}dG6N3؂?Kƍtge98t0BeD6ՇCn: 4 }afũ"Ւ wrq/:I?b[QF0(JMZ*uVkey$4G WfxÍ ߈iO=F>,^V=o9Y{\Yb/+%"1KAW6{?863nYQDN0 k:U vE2NAEYNIM"Sa_Qܐ= >*5zN Y<[XA&2 qN+"[Ά_1m+G?8B@ cc w#0̵E*nRf ɫ;lhS[VM@z lcQTmmmƍaSqWMJ]e:3O[+u$vh:Sg75ы/CH^;UDP';Hor$jF~=ҐB/ŏ$.Rr X4Ef$*!B 9Pa``mn4ap#f0<0v5{0HrZ*M?8Em!gߙζnG,L 95P>DKx@R&SpVk>\t 2۞tP(EՃًM taQ^bys3O&AB門$v$ݙ_N.?*C{wgM"uRarYH'O/2O< m.{o@;gL1 ؇LT)Y2f~ %hn0lQ?qv7VScL 2^+P):;G|K׹y* 6KIAWeq۸4CnIٮ}+@r!bX( C;z vL 1cAyqFx*瓆-&Z5d*5)K%5]nLӊWƊ,`* i>ڕgrdU*s7ؖt}w?/oxTsX` "@3IJq%HB$2 9'uyUY.ξU'gz5]OC/>7[Ml[*k5?qoj.ۨ0V$ [,+wZ2{lV)sqO ]F$E9YL#&'ΐﯗ<ޫ#%F?y͸ԢA|%A.&ߐ?߅Kh=xT7SD#o AbTyOS482rXjE!HOgy~x: gokƢI誔&e[YIR,:?s%G>XpYX#=}{7*|#Sti[U*y$sQ>;:vw)7gs`!"\kWN]L23`J]i@ 4 35%{AQ(|<=$uyb@y!B zADuQC_ʐHr[P(E$`P+"T ΚI$R[(ʌKe}@ L;Ydgfq߷;snvRZH*$A)L)G Pa<==;ڛ7Vv]L۳R|y_.8ELo;QR*HH!qYlA NLTW:l +%I7}9SNQ6trrjh(K663mh>rW\a_'3dSb\fH,DY@ YB΀1t/.C*QYPus Ӄý^@S+ZJ7WB jۄYHa:e P ,I.ҵMҷ[8Ci ϥA:m;֖Gf7=CPsܔ77zWes=S.WN5^r_r:fwM*9Rrrrll_1=@쫝j4~v1f>s+5|3/kMvΎ˩zvHϯ-$,%\4H{Yd,4z.ʙ ./ݶ?[?WVh' MLZ'&_z?N.2 e ~Jf+[s1|ܞ7Yuff|--.WKKKKRB zj%MXAC\a^2|W߯t͸'} ^8q-KsHQJ<3-k$2 dP>]*H(ns.y %P(i5'0i@g )j\٨s \Qc;\ũ2H>$fMa*0/PC7ptSY0VT$z':0 L$-%lޛ̉B:2t7N֫SJNDP 3 W2hJob٬+L^Ǯ[c9.t<"m&|AF[^p gTX{:q|,fLYbٲø_fK/~Vj-) Z(aO>&'xHJ#fݵ:SյGiT 9~+g:_i܏FH3=>#!)$_3@m˼tނDѾ3^DTyڜBN"p3RԔlcbԟJ28fj4?%I1I `15kid:$A"e"/۷vI<A%Y,٣;oр@ ~t w g`q͹s%:Of.8$#l&;ffE0)+@ϑi=#A#Ә'{$H;ѓdĈq_R)ҜP/N>dGê}éd`1Pef$үE}3z~AJa)BF=^]jzTQއʙԓAKudjȌܕe4Qd %QL"*d}ӗ%2v>}gJGf#9s:# Dae![lzN8cĶAe՟ zL;A P0\c`0PP>qDn4s;㝜:rnS7ޞ8a7O-=ZrgƋZ&]2_͆(Ѫv%Tzʫ#%wC㲭eȳWTU[bYb[]GTJumMb\ܞ7j&=ՎC9|ύ'811~sW꼰1{߸F1oyc-mawD7|xo.~kIZ75xy;J%%%d,~[#-rrpYMpѻ IPgU]F[c]I3t5ymg]9YoNen8qQuԌ&RNSy UöEaagn[]6(H s!,4;;Q`>) |nyns̖Jbs[#ᬶ(_/'g~ٿnu/V#{Ϭ5[Ki3u6V{KM7_gbkkkkkkjh^@ p& sMaO$R=K},pD@t#+ IgqT }7o>鯆H 1(L>P*F4BLOm (&,1ԩ2ˋ(!=V?0ծpM:K#TG(*ooF^vof)Esv(ȾC/Ҳj1d`jI$#‰$^{2IFȄh)o&V߷_r o5zi=TEH-$^EqK*G&_t1bi/,zweHߕ#S[mf@Jl e^7_37?%-i3?IU?ZR4L AJ!,y&~BC%@W!C(LAI~3؆&H{UΘa)1<)#(43ٺnzq l~ߊy`Ӻ#1!mMj<}mxb G䲜sy>a},fqFV749znN| Uߢ'yDf O}7ЗbŚK@#0JEi!r&?ǡ*By}׻',hA!@fbgR]h,sێݐd4)s&OR9:މW=ϸbmBu%N5#!b~j:m{̢#o~KLd3%@d*sy>ZCq?{ۘo>J+6F .K(-/YO+dj6E 90hF D%Ym漅:2X{*\QfN|gSST=;gmO?6Qp~KWjxV+iH.T4Z A?D7`:R.]AvԯT@JbT''FZ4&ܬ&$VI1μgi@Xc㋃| BۣGqjqTOI|94InӤ1[6<}_ b-5u_/zr|]C 6uJZs,$rzM@c͝&ptGZQ12>j!c6ϛmE"Yn)"9V=Ljzcԛ J RZwIȡ bvl4:VczEyΝnǟCMA)ѻb$Fav}cb@L{UP@wR튮28'\]`00L(&`#$ a >}RVC̢CL((ʃ ҵ?sߎ1ϴTgU (Mswp*< #- _ `8Wd@b<5u^`oAMEvnz8JT 1!IU PH .KK[?4`LxߣoHoBy_<8QXZrxL ! 9E)sGW`h@-+K'%lw /\nuzw4dsJ#5YF[o+jjEtVYֱZ͌Fɰfu_gq-dF+l9=^FPT *Bhyx4UGFwp'8j7qb-jNwK&O.ŢꐺLN봙>5뤸xվ-;ozUoxxP,S#py߈+2_o}.*x}|Ŧwk|l|>iq2t<^?7dvCm4غo%o;zOSl_ps`eeXXXWWfavbGZ]+љrH3-tt9Y$ 5F5?ugLg+JWu.qHT⵨FUFcMO'DgqS*U3C^JAK͐_!Tޚ*1FEyH Ba&@Ә*D(nHdr 9;vqy=!! EN1HK&@Zr\馥F!ᛓ3DR6}G>c43,YO+03bW)Ez__R_8ypɛ/q` WbbclG؟s_j$db6~[8eutEHSDU:=x GԎ8Rā\)i"v$Re$MB,.$vԠd@zr1411 EMKW:ٶuyL#$_jHuI0OV2;Cv_DW fp+ۏ({Q9X ?iH8slR#\N£$ m:_@`QГ>S2Bvn wϮ^TTJiG& ]ibFT]ݎ~JF5h;L :,JA$5z6Bv #F*APcY7fޒ`y59JkȯYO~ 3.`2_|~/&dYӚ~18uCJLޘs8CT6Ly#$cYh q"S3"ΊlzƇbɒZ)2zc *MB6]+a%mFBψ\PbRYͶichagrnI89)SILAoJDliq9d/C^vZlIc~oy'*[%S!&:pKr,X(څq̵uУsM8ln'XP̼ݖ{DdbҗYYX$%㌺Z0 q#*yT! Of=߯E{yvdH煳>tgωdxK(M}#l"'c%W2ξo 4S/ Sp%/ϕyb5lMLm͍]}ѰߑߧN:FCIѶ\}=o': M' [}T"74rUyE{RuIO)AqCde~n'趫L.'o5s=>z=^xH^"#G|$92R7ppB UI ۢA/[^v 9x?&?E} {#$q..{~;uwmnK%Uyzޯ?N[˳O_R㰽۴'D&n>y֟sOkiwz?gll3[KM{mlZYRg3ƶƺP@ Jj`*g_hi 6u Pc)U);f{db(ZO/Y&GM Ob,ʃ':?9kX30Lg8` a5bH'G<(J_8 b&F˅:&kpg1dq+,7ݓʏPL \9|OgKv6vp@EvX+~Oo&Оr"̴Tj  8PbHrmA׈a][jby y#ZP*/|ΎįQ}%1#?<!,VNc8;.bud9h L!C}>QS_2bdTtPjGHρb¦ HǕc3{7x{_y iP>1w?RjzY,ApV,S3t2ÏVzN–I.HuDtK)d?*hLˑLrxOfl0!qȲTR%fDDʛZ_ W;}bڊ m3Jch*Ŋ*6E`*6lTբc4kcZMZF6+Ec[EhmQZ+QhmձmZ*ɫ%bڊXZ*ƶшQѴ4kF6Xŭ*1Z5b4[6cbэEhjHэi1lVFcl-"Iv62iSR0dD>jK")}B x%enN[=N],4,2RHB-ر2!ݮ3+h:sKˀQ@|uŷaAxݷMyS ..\ W\r_t.}7q,.cn<UChz+<\eϮ8X^T:h-c&(~>g/_6+x63#FW@Q  TV$3FoN`Q:6'usK $:?)Ip`11IS,&-<dbJ?dWP>N1\>E*vH #$ds2e=`>8Oyݜ~QO-/qWmR'ٻquм]_)MI%)e(s#L3|^lR+y<$((H<̓t:yU&bZF3HeFF"5@tQ )Iw)v$,f-iujrc}[Ldy_7 : Y%ˢoals~ԷjoU8ta3a򳳲O~noRݷ'꾾<*daqx Y,-}Yv_|kd[$H3FhʡΘ0P'HkDef,І3:XJ}L9G17 ) Od{IQj ?+|]L^L4͒>[|П[7hʰ$Ft/qhkOOxQŖC  r:͚c.ޟJpbz\oā1g;Y#0珳d2"&ZXA$BAD@It?fHY@AIU"$tF3@(2I'.|!iztgkDgQtRu<:n:w͎:* Nyun!64] _ˆ3y|˓kRlx=_^dD}>1/*bJTCX.4`j,g}@C~G| m]$?."HBXmmFn$jѨ1j#شVkGzyfU45DydS އ3( w6zXـhX)6[ӧ4=I᜹8gĔ'hJŇ-~,7aPSi?o^^g ^I-[k玲x:9aaX,ED PYoSMYE$فbtkr* h 뺥d(Src|?4%ai'5?W(!HB5Cܖ{B)qsmmF}"88;@^&wn sak _).ҠwQ!I ,q_?;se~۴%#BoGs:+>k|Ƿdqe0dӜD Bsڐ`jA"ost` qjʋJ9+*c41_=YRe hU˼?Q ;Ra(L+S0c|ԍb6(r:1"1-)& 4Œ/3;%HaҏEk]nlF%h$rzf=r{-}!t胈P SӡфeU ~])@mG`*ߧVD|}? {s4[Uwϲ|H}fmLKWU S, *ך8sE2f„+#5ضf(r>]sw@a9kw\uJ@*1ό1B-=DyĦLz6(,zPꢰ %_b =|SjO7uYX|(BQƝWٗQ2AC:\( P?K5ns=v9֗&Yi;>Lo͗ux1q_u,5Ӻ:`ɍ#!W=gߝ~u>'+Xˣn(+J=.?G\*(e`kCӬ xS_5a s6ꎯ\6" #B)-3!xJ}KsU'3</>+\9{Ka4c7B$8!RM0Rӂi]So0p2 K-od",;W5Gm6ghcfa^}Ǵ㶝WwY`Sx~k 0dس|M󆼨^L" |$ '<{K2Sĝ lL_En8t54$9)ruuVƐ2V4fFavHL! R@  1T ?+T֞ERCDBy<9OB7&eVXN'cwamhvUiUюwR0Olx[x52WgIܗdtJGN"|7F&WeoPq-_vt8לmZ'پ(!wn5r:?4T1oض4=m-Рğm " @&Aq[Lщ֮*C.4C% j9*7Vov 5pm g,Dʞύ ?:`4xIZ(\Qπ2B )"tT?}V/I"M_t(c^5ƯTЁCnzҳwSjL/=OWo~y|O텍_檺*yz v8,uݹ3P{W{V]KVSi4=.EgvU[:u}{5}I;UUUUU՞2 :͑ p``j{&>4(\*_?xMʦ;88Y2瑮zR.<P}kDL.[Cޮ~_v{;^p,,':0L E #HVG;06|ʛtG<:.Iu>ld([W.A +ް&E40l;¯w^ۚQ̿7z$Bd,۸b `T KӌΟp,Х48~q{|&[.Ul`FkGURa0#ᅍXWD#ypA6{Z\xt:LNEZlCw/{9qzQHer;so68ogNTP j}J7Vp! /nVjA`tr;˟S6;Mf*UP`WhoO$QF!TVwbȘ*A>w~1MnWr="$ >'r CpAVʼn*gd@lWU e0Y>,e D{'E j@'I$A+.ȃ1t6—zA`Jaf5;% STfT=jeN1Ņc7E$QITHupHUV@s"I$s`p3"Pb/U >!ڠF7 @ ?0"U#!jha,=J}ꈘ̌n]ӯ#܃p0ANwør ӖY~qP+/(U&T(t^(AO*0tI'.7U+Ev?/t7),Kaai&ۍMmRʒ *"t8=-8[b#1Iw Lۂ )́D+nہy fP(e hTJ2  y\Yp>b]2n#PH2[_|O7/{SoYJYh*QYX)_Ο(TmozMH$sø. P~|A^^ɼJ4tFߒ1iFLb?z\㸣O%y%^[~ 15 > ]6V Y4(>k I/H @f ?h\?P7;~̓;SD*t?wAsI7o}7\НSO [e ۠aew9QoC{~hd&e4&DGv.zB=G4"X^[Xb^ɽT7wW-W) U(LDkS6kg O'"{{052PjuyP 3 q. A|kGM xx[Ih\gDS3귪mLA*!3A;oBש-u`T@ZU*UM~h?9T%58jwվaCߚ6zDn*9Ƙ* |=%U [a#rWh.VI~jnC X'5 Ɍb,L[ o;;|:N_UOӗ;DA|AYͫ/x R0ՏZN&P:ӻ`[l T`q斐B<Dv !M\:.e6ڰv^@Tx͓p^Y6VYWLHTWT)v6L8R}ҵR$KT3tl s-uQ21(80EV byMbW +m+U<\yhSIPwK+%Jzf!g n(t9Ay* $%{_gޕ Sh֯20NzpNl֨Q|0T|<uK홨kJ<-/;G!EU)8x@ wS CKt_dH}AktLhIE@c7aaJfr`(!܃) FmhV~.yɺ|(: @ɯSߪ)h^͌TAw8Wz,o.Ι`}OoT ^Fѳ=QA)Co.(2w ~uD=%?PFmm?rw[Yh:=A)?P`y g+;CKo 2Qp H4  R&y~lCESڼ UQŽ`fTT#qGbOQl;wİ [J6B7'2ædEި7w8=I H[єRdfK!iNŗ?nyQ:qEٮ~:}hQS6c<͈&NHym d fDqOa0@6˅Rl@1h{_BvoPPRkyyWrHl3H.Rq~`ª 9 ,RMZ^ ]˹2SKtW{lX Ɩ޷!rgl-{;=$wgBsq0BT4_KmC/ ѵ"( tp G, Uj@0ՂILZ@P*)8.5;n\x+0R`_:`ћ#\o99]Epq Conyn',3)KVK(]!,ȴÞPXa{xw.Hh(HƵ{mUƴm+  JDK ( ,X XD klc" E00++뽔2A7)X"l - E7VyE?!ܧo\Aq=~ZS q*Jeu{>Prv%T@1L$$Y 1(n waB*9$0+ꋮ,Z7-"7E7|W~.((/byzI\4gT l?+]A儎w.ޝT;Vp㒭K>71u~'Bbf}Tֻk{lڼ\4B`.~;jQf[0[]5S.3mn"e: a\@_}"!T)S<Xu,Q#;<zY$o^voH+\ h ,<5CTǒ1P{B,S;)-IlSGƺe{IE[9FΌdt8P ENal\xNcZR7g=f|y9e³Vs׋8P~WL.yLqWVZ#/}+g`]vU澮4>c9r5u(o&v96YWXu2PKkyuzys\tr l2oJN_i|OX|(yLY$ O ylM.D!s&M=1#+eAd CSG7vDz݆#-?{ㆵlkϐBβLLPigq ed#z @a& 'a!"$9{|a[aÅM` 5+cMdQc ZUV63JP+fPg`7486 d(O{Xo]EUTHn+ ;$Rw3}-aq@ϿlN8VZP!d Q$Qf-B abKl 7ĂzN6Z#`ߜmw^C?M~)⦊, W.w6J3<uP`< , ;Qa>Tuݔtn&bC[9ʂ!8Fc<5@s{=awlYe>W,U]掟cmۅ\C)asկ\+A@A1CKGGq[,f&UR9QELyhcyȋ<QM@@QDD@x7phԲuSDmf(6RTI {Jm=#$m;BJ!wO&-`)#JIt X몹PP bsϏ D7~m>f=f$ǚee< ",>8rF r})xoOT$g&PEya(8RH:nXo 7֝4 좗J5DnY;dI Ţ@Ԛ%7N1tf74P'ƪwU䯤+ܔAb9Ge){܂yWz^Աb$fJk 1j6l6T3. }_z8t7I'[a#! i#.߰+`Ł`1_51L]ܐaa8Pw>"C%-9U)L2EWaڔj- azsI;`|Djm]rҴZEѲpQ"" .Bq1/TQ+̤9^˛"#b YJgfQL򇗛kfYē, JtLRb4LG}tCB$p,|"rxW[xvkIt=mǖ3i+8A~\q_L:x=BG ؇/,hy1F#ŘF IAXqdY'G<#,e aR( !n^unJ%&[T W£_M`єq:Ptb0J`D[:RS>7a>ށځgZ`Gbǜwh䬵h3԰e &'i0VՈDai<5K:uˊwy[uf~ooGK {}_ "d]zllm,Y˼hIHR86>Ml iB?UK]-%qgjǦӖ DJDLSꍾO/fd2F)]\ hP!,a< DFyʺ˭ 䢅Yd1u>*ޛH(!OVQȍX*+"_۞ S;ID- D\J?<2XLan?q"3cy,HNkĖ8Z4(WIRaܝءJEJύq@xt@/l A@:A"O} &7F)33͗2;xXADgxYGaۢQ[3/*nGV}TY[tۛ<`1m,Ν?] !%f )uewvj_KN[lOa|'5Ky6j,ىDKDM'Qι=^?Id f А9f(pNRU ]!$TzLlVy!W\{؎YwITP(6>S2Ea 3#f@GU3δ- Qw G5Y&`4S#.n+7cZ˻OUl`UUXiy2AIJf9K]5`w꤃"B 1:t Cy{yZ:UFMSS^t]̴-X\q}HF!h( x[= kZMublDFEa?M{7*v Hk__<7>]1oG:7tph`rYz EU(Н>a"C8* UXs|]%B@_N&Ej4ѬR C#ᶳ=Y$tr@JC#\wU0oH/MBf;ЎM] H_,ntߴDZ5k[PrP=)R7 2ewFv~[ R/=&؂"2vi$v Xn,;~ MJ]3fCe>6<^lop5,.Fڍ<!0s8]f= 8`h"<#BB,B'gn2p=p;Scg*x9ʥ:&Ib 47Z+^}A(FJiv<[2Vk1TT@ 8E~{!"27LJJ!0)j?;+XEDimCCd`努3:Z۔!n[+P]TP('<0fK`5g)EI{3QO{,+快 ~&psee{2sԒ^C9kOo)W凾{vUG,$A;81`N Lber)B"u`E'Y6êd{{_ 9{w= fʕ#SF 2/ 7U*Gu̢h"6VJJ:Y}iC6zH,<5JY_{ ¨@0m;!'AHbJ NZ[agz7BT+ڻZ聖&U^qÀoUvx[V]9"Th4I]k*׀rh$G[ hХ'WSJ% }tef:ȣdsᯝ.I*E!m'Pa3ІH,4yY 7txګ7N?/q[ Lwl-:kcpNUoj岐L?*,TR<@](|.WtOS [oxCu-sUvKP4@ܟ{*ElT $$<{2^O<-ު43ۈq/)_3BB<@FU4 zmЂIUVuR^@+j N#u+V Ue^ \XdUEVp93=Nmw\9\:*\I^ &.:),L*,D?g|2{stby*YBS#δkBI-E(U0g ۍ}1W. xJ qŕn.P4J>;S:QZ axYcV.2]k @aeF*s*a,؎PY+1b5V}C A; m"˪TN0S%T>BM_> P7uUR>"4/-2IX;^7vbЯCʧC jJvSJmy0qzǗ]sdlk;_; V:* 1~VE Ygi˽a30pǀ|$`OT)'_&!zV~wn|: c^i"E*) bsR 2גׄfsQ+Y[YIH*a7fw;co';w S;JB!r@%GVB>~̿\+}A+ B*`t}au>.{:/[x{:>GǗt6 b $M-;}V:?aM 6V0iB Эa^(>ӗAZC`!\n"lL|ZTƸ%zڕ=}Wsb {{ʞ]]ݶ';[-[Z{ٞ嗓OC|Be볔eMp0_MuȮwu91^l`;=CiSs\gz {!9Ҕᕊչ@^$)EY@c d 7r璮J7>̍ey|,*l~J_+W5q ~QޏةY*{h`ε2+6_bEJ3:-#RG|8+_e HyA`G!6!:i 23X|2$> Sؾ5d3w+Os9w1[r:P09$"*7.6E\mqE((*Hz<-vu.'~M}'\'m;.5עvfm.̟rnzޟ9Eٺ:S*NCR1ݦ03MSąv.Ik l2HTR$ (C;2cggoAj&ȁ%!Ҵn y3M:i߶~Np/AK'. @\ʹAO6RB+?2ʟjt(`w;*T$8W"+IqY x_$:1ޟ|7u+3n4)Iȱئrk3w?++U?Q:͎Z5:=E$)H=*&T]҈_OSi?{ϻp\9˝LB;suJTTcB9 {Ƀf!P kJL"r*}j.ӯxO'J)."<ɩxs6ٖqw;Etm \^1]F : Ȭ!w'7r3g ,7JqiO|[/DZP3]puz'@aV7ۥUoˏ)o8E;S6+[vb=^@Qmg(6UC! 齞}VH7|D @>W2&k1  βp"JN1^F+O*bBJ/mO&06 &S.m gepWmݞ'{Ǖqot p !7#(N,~s !LB01!Hȩ{ fTgt+u)[ .֩ꗘxt0y0Z.7_NGqP9H;ֲtY0ٲe5[f LxAb3y|82Ջz8Cj 1g46{[QߌTU& Dc,\a2lJSǵH6Z,S-Mg $xADa)&m2 } +Vzк5bagXk5wBA6rhZ1[,~,Tg|,Fnsn,jɬh믏=\oy|9ǂR7n9`]͇?G멦g1:,=)/U`YH%,|Bta^^/OXw}==D|i-tΎrt>Շ*aQ|^4Up:]T|uiq}QUՆ.ݰ8}|e?GN&iO L芆,!` @.VQN,:NbVՂ?f`:X!Fѵ뵮{P~"Wd?k`W(Cp/rg&gkAL;S޷ |;z xt=F9S4"mѻ>f+tUWv hg?_͛Cg_%_.ӟ8ag >~1^7!Otʾ岋cy >9)~a㔷$_ ` vmW~]sG? ?|ܡ_$>ެLϝ\n9<{fz0.~oy oO5Z{֔$ܳ**d[l^س9[zIɾv{VL'm{t)(lj >IRiE$(R TR²|uN@߲0$*RCi2 pP֏nszX`uy&;[)WbTvyA#Zoe(lOE12]XlZ eWv`:Wߐ2 aS}~knFM2O?/ tkQ%EE+&JjqB W2=dz{JZ6>,o AܨCԛ.Vp *(nseHΪʆ~aqDZd.r=/oa4xC9S BϹu>ӖEF|%d 2SF?qeHShoUظg6T-{¹%~,9kcL Vm4{)V}lN/wS{w-΂{`gPs'^g}{`t.nzXQ3;⠻g%;ۮOjMخYRWJw{!sD-m=wӝ׺x+`o98cyljl[s裻NV,Ѡɝvܢ%{OA70ٗwKuC̀ 9tU=qY Ownh u ^Z}}l=ؠv(B4tQmtv n v{z{{#U`gz̹>Bcvn}ϩo}g}|LwvۡB}I >%JY:sVn}hCwm}e,ȫۍծ[{wxU7zݏ>n0ޚS7wW mh">ڋ̰]df|PP*PTHEQ@ ( ( JҵJ潽Mo>">77;"5u'/W g\8yD>&+ lv}Yiû[[vj]㯾RB;bhl@|{h gnXGf5'{|TYInBnF}rzu:z:]<c>| /U.̝@,/wR Vۮٽ;w5oٶڳl|{n3X!Yl{VzV{d}*w}zپJ$(.L׹#N+}:voRB v:z{/@w7ﶗw{_[`> Q@ -HGl @ Ѧa20h#!!`!M2Lj1Qz y=OS2 @ 4dM&)(4czF4hhѐѠ @hIH@I `!mO$'&L@FH6QP4m@24i@  G j2hh6 h $IIO§=4SzOSa@#@h=A 4 @d 1 hhFM2&CdS̩6ҞJ~=GSSz$OS6mOI6 =@ ASPm!dMDA&L M M2MT'zz$~OS=$FzjS@hɈ@ii(hK>R|qr!4$*??>θn@\Vqu9_E@%n l0cDR=$;$5=+,zz 4h@怃 ZWBy f{u.\ߐ'AO~>$FH;?ڛ6 n0V5@ ֵtƉJjBdVx%%JKhb65QQƭ,m[Rݷ*Er!FfsͲb-ʌ )rrFFi7SydDC`Wvw*ϥÆ  &4X;ntLB!{%2+db5E3liMa5kΨ(LDRAj\hシDn6Hgքs) @!8ILMKiKTX Ҧc(T$CHR; $ vEeP  4#Wl'/ф~l bDžh2̽7.& FZkjri D3%6M2-KhhE\娶mhh,X5cm)yx05|Fɥ V닺' >L¥~ -h&`VU1Wa/4 !4Ck}BdC`"^ 4xd.Tq뷋%8sӡ$6Ys)HK iEŎ 9a C 2BUIlkTUVkE4PkI­$C3ZAB)R ^}S! !`yyO` !.ߓ&2IVA` nX#[?վ ^Ύm\Rca Lj6ܝO-1৙BW42"ǎH!48썜:cj[ C$r. @hJR[jlm_mXűEIcU5*! Y儑d#v֤̏ @vE"ɳqCfF;QAhLok+q{Tl!ab0b3;RIb>ͭYNzī 2d1윎ϐ-h cwȧ}>9 xp[:e+ނfB|XcpI:|^EBIIKܕI Kq8@ C~gm>1v @ IzKӎM4(c & ^o 燣9UXw2^}K<8dK5!bDZKmdelaƒ)-:)saJOې$& fo+hj'eBǫ`g_gIβ#znfbHa󄝋E;xL`3ƱCҔ9;i! sդ˚ɰk%đ2ךkE*f25~fזWlX #QkrѦi6*5ͨs^J5{\ح Ɖ#&yц$HMX 1svj-h,c[Uy(úb3&dK:R"^s_N_;v$KF,lmF&e5$% 6ZřQY+k FSQl 3e5a`*4TM2FTjdcIcd*M" MYdh i5ͤV@QRaE2jU5+kA}X5Em6dm*-[m,m4oKHM+@4B).Cn|0d[Da~z+I0<*/DA ssk$r_y YjgBuݝ'Mdd"wY> 3XM*&gfCk @Z)YIRv@,:bS=} }s Lj `T^51`uC Y,F1zaΝgC-위F0ÙX0/EXu:.^ autz"!Naw1j3 :] &wYVkUlLN+U ?d&fA|`@1ϋY <}`e'I\DGovbē!$Ñv63ePToW/ywݜɷ׀^׍pL; s;ònvb.(`t1(ba`_VRL s"\*PrH 0[ɺ|uof28߉n"#Iyn$32rP@ 5zX07IDQEE_;A*Uo0qn㼥YISC&L`<^0d⯺QM1nF9۬bXӎ̵6h aFPw A`,Y$ v_mvbAթ RQ[EZ_ޕB @*@>F\!f2X@BzLґ"2rf$*`:GrLw$^pe0<{CDX`Lxk ',A=^{B H@ /y]vm# Np>A2CBU$ CAE7kWS˶Ϟ^2<5 yTU)d?[yuB>hd"?/|YMS6b-ݜ-`!;J D( R@"PР @K2Sn3dS)g;']֚SRSܘݜ~f$菭@̸ߤs HA_ %yA; Qvƙ9`aIh BR(TJdr-gxf676w):R{Xm Rȣ`Gw(PEUc5)J?n3ɘrac ώPߌِ"84MX""a{ALvLȱoϮ a;|r\ˊs2Rχ'4x,l)Ě #R{ ιѹR,\*aLjomG.M`Dʊ "S͖iU=nq6/q6y֯FSˌ-}ey>}zv4航 DAD0LwI }3K>bg7oT#ڠT` ȅ*&" [@Ȓ k1. 2t @qD9OgS_~c3N\jVM L %'Ҡtb0HS c'$ ôr+tB PsI5ӽt^d(2q) E:Ҫ&CGCi*@ā-O_%|xwcBӃe=vh)-ji~S/ :.l%0SIC 5x9<\/=;*E$ʐQ%!)DpjuXj n{\9oNUz4 T2Ls_h{SplUEUI5F i2j*2f\">'ԐN3pd"R':)?R8d8EE'k0G,)`iSb~gY-鴅C\Պ,|zh5׳&!BQA:+ 0hR^rsa' -B(|1l[Q/e, $&HKy.Kp.ԥ(> "ms/dS%Bt'N킑C dD"&Q„ FxGϧq;N@^5DJl {;ʍH*1(u 4^ǡfBjr\Xֶ~9+M 9Gzt@RodtaΎJƕl[C <ة)TUPښU8ʁPY΅]H.Xzgi۫~Yسq~2y=܌,@qM đ5OE8,1"b]X8R aRٍT$(0;+9o<ϕ1DQE)o*ba2??ͭ0gń0aUPv`b/%,&3Hyv)l?:RZ"5lEzr5 byŢ&Kݚ5X{1saPH ِ aR߉Qsݟ|<0橻 kyD ߭9бlGH>]t@H[=q Ãپ/B7s=s[Mu+֙$Z^.H͸zV%$&I.*t ogs=/I4H͝pݢ Dm_)F8J{ I ;3iGvd) H xa]v)H5[W="h4+y#MHd#4H/2· }i>75|nrHc$[PEA~Y!5d)H8@ЛBHFCÎ;|qM8 LJq B#dƣzuF9iRo-U4d :!2 KdE9 28 9 {.-.ɡ`rA-!ӳ$(oCơ趠{{&Gs&`Hcm&6(wPK° ߙAF&‡E%P2RڰЛˋi7B2L2tWQ(2FHfAumό7VLPH&Q% N[_JK]fd L-bCsU+@Q~YFԄ^QHSxܨё՘oTm.Xu^HcIy²v!kv{6`@5+ ˄՚t0vq~^sj/}93 z4?1W@aPakԱ3Y$!;U :or,3xQ]B IB0c!Dkkw($C-)<<hXy Di@{h%߲vMk%+BL@Yk+rΙr+T;'g<0[ bo\2̅m6ti`ܳ$lXqғ>013Q6-!qߍᙒa 3鍁 %- jͳH`-40]0Z<P3'4od^̘'k@ &Ӓ` ɭQ5մbZ+ -)J4P J HJV#%kcZmhlkQVbح@hjV6KI6EQlҡH!H #A@f&{TDzeabɘAy4՛Gnݮb鍘f`]l+"OKsXg]ڮo_'!Q2'J˸hEЛ6JÍ } L`VMabLC$u"dHy8gI|VR o|P$8ÒQb)B׭%Ptuӎ.9aFFZ]@ yHImJXAl'OdvBVҨtI;၃ *k Ωm%dj:Hyutl9"!P5ݬaiLI٘"[sbjZqbE As ax¢q0l0sj90&5^MCfZL;.k~ *q9@d!iK|W!"KpR"Nv5?;~w;wLBCeaϦ䁤N!.Iu&@h@LQ77lj/c^nb(Q˂##,A&"Q(J0uh):RTMDIڄl&UCx<|<Ta }`!HB)]L43F[N&AtJI&!Mo I$P萚45t9Y {moSm$H)@DZ~fN6gP(DH2;$ZO"Ji% <9dź3^ T^y4bo&:~ԌY릿MǮY%7|TWҀ>C]]biu$<9Ly'l fhg~ q ~zL1tی松ݣ0T*Z̧rr`.T-]wə~hLSJ bkaj0jxɜnub,D" (H%iUq6wljQ,ԙql5Z:i82;=kլ>#3!4YwP{;#ڹbp侱b43l*VNj#8LМ"ž n[Cvت瞺$%o ZM"aص?H;F<SV!XutvG ovv7,SڇV$ёtơ օ膙ٽ#3=!ⷝc koD.!4WG{Cc<񱡸LoLhmh)J@+#cdwiٗ0o  VJYia2foy@|J 6ۏ3nq2- LDQ ʢ6kVVRWtej3O|0x#Кeh"#ߞ.oM^okd( 0Jt>>fѓs3õ'LRh=q h'ݚ^(DJ8>-ojA Sc=vXؼb$?w!Za]3Ur!4:W!hE"vG!`ד8{'W'A^1{嘣; 5;KQdA d *Qyurb2p='<>tJVv1XQsU Mxav@X3N0T1ZEp faP;Jcy$Zf 8}̭5V.bE&%m:9b^tںz,]s-F,&l;BDy Uäa g6LcoEC v'V gٜ3N!1l\-I61 %75@J] 溰4z(d1!'rʡIchd0Z ّ&kgnX.nPeԁw萵UUq8~g} k ,IgC%A僪aB%yY4VWY >1( Ӳƾ|Mb@.!:BBY ) q1+9` ;hHjG _ ;qSH=f/5B h'K)v~/9[ {Ҧӹ]u;V.7+efvf8!<]iTL_:K^{~ a\\O2EZֆ|-ey[\?8ZF/-Q1] 2(F)C ;QHd$;حXjZ2es޺SRĵS1J˾t>UZ5͚L͔hL HQd7{dUuH4qQq&<#Ys)יՁ?Ya ff; CEsnv"ڍ4Yt<":|vhQhۦUMƧV8/{{/dd~ ''!6hK4okLz Eٗv9[h/CrK˙!|XuКY0x2߬ ΝD ;2a9A'mnGS;2vX[ rYXE:.GÏ؊lZzSfy{ᯔ61W_Lijx)_j#4--d3^ncve,ާ9+~UlJal}ݡPM d:E^B{s7*(Vp ܾ6WQo_ $هȇ^h!?Q즿x1gakש?˟:]eKdڦ58_RC gնVlIWsmAw[:Lh-C`hq:s,8gbH>J.AuLE5H[kifskU4 Boˮ:æe:IRP!:!{0 Bnm/-&-V*+bHۅU^]!M.)W ksbW+ȭܭF*CQ@116bO36jBMLZ7Vw&1`{^  !`宖ڜu&˻`K DPH"Jcr֍٫+U梮ۥЊHD!EQ" mQhVWQ6F&mZ5ZX-UҫRlNs]XtRKFm']*KQWuI0VK[,=ظ iFB ׂ|39dFG(y~bxe1 2>[&QT;;6C]I!Ya坙_{N'c(yyFyƱG,2Mt2^P[njì29ڳKO[H9Ǻ; I hVQf ͏ӷʹLʬk-EKd ]fzћ9(($Jb/gTn+^Z&u!,94ƢPHIQ/rm0X WHwtT#ű< [bϽ{RZ]Cf(LMGe߾ѩ0ermβW*ٜcՁnC:˟T1axIHn)3B57S3hvN8tc=pDdl (R _Gf共BN|̦R9 @,Z8Lj9裳y(vq2gL,cӆ߆uMs~xMoYL`_űܳn)~a̻35fgWpCj?2|XjAd$ hfV]/|G2h=},a&[Ѧ·b L!_rBR:$}{7bPڐdϽf;,$LO7\T%;̌N8ŗwORPB%3m\jSH@)gvvs;czujx4 EYJ, #x1)&mQ.*՛SC)1wPxxxGX}ԍLFyٳe>!fkk 5Jc !p]S PfVW \g^8\&BS<PYUȎϣmtvEartu Hv)bV%C9S$7{#ZRXDDuڭ Pen 6&.yWqqHohȍ ~1qkvfMΦR8~ &h- 1V#nɘqw5X 0` ECsw}>$^ɚ6y2%S(IlaKb{ΰ*/y&G$;jWOd&վ^ksd$mDәLᅵF;n: 0`M o2=+E}%<23 c<+eu[TmI_|ebD)egIu]-<=k$ȁ+߉`cUL3C ;Z99mՂK 2 |Tak\-!wrmPGu8XSL1)n QE,4-R{!~}pEh rBm9Ww/LY$E"U1ǤUmRca vAq:1]b{.۰D'TP !~G!،<es1ot.;ۘ >#n`˘[_!1۲UsҮ(p8r3waoL8_TPmԎ?_rXns;7LY9=[͟jQ&b 8nt\ ÖsBӨc  *dεZِ0EԨWkM.||Zbb4" rq/i*# Bw~rU˳+UnzS5RESDJ~qMo3[ة}:4x/W&*lmvޭMeQ9GGgè">n(Cmu6v]~7zxɇ,NZ]:f;~/Wa2ɝhv՜U#(a5vR8_pf.H~xqG.=׈ T wcfrMΗX B&z1mgBō'pЯhE (`u1mٻm9cN&"k~a\;wedYv[1RQߵ;Ҵ쟞؉]<؁3 w;).߫Mm;GQ }Qc8|M5{Ҽ>>J&;;FEicД~Gt|5os>KLDަÜ!B02+JsY'[N2&rҒ dqT[>.A?u/@'PͫN=5q {; dєqo{@MBӅrs˧l-#8|H:aVo !![{׽eՂm$ (fehR1KX q[ki&$w9<MZdHU)6{k$'v~cJHѼ8ׂZۮ/ˢVϦS*Q]:2J߄:۲"aձފW+;\d- :6 6T@ˠVxg6٨p/m_ՒvE<)=oD>c~o1YDc͒QaӼ(7;x3,[:ǵ['N7. 57 *td*sr)m^`EJ J` [hU띿빝s EȬmUhl÷]CVk&vBdaƢ<0mmsZv&:.tt%lfY Д H|钃mKRzNQ/WaLlҭx6z8ffh-lP暑Պ:m/\LӲ8P>bab8`[|%~ܑIfBHg@ŮI׋aO\Y0FƩjóU'N\DaH4Rf@ j ,p;E%gEXVɲ6A9 TQ'ʎ=`9as߬+tٙ$<^x<^HmkjYKqxYFNWc}/b,2x8q2L)^($؅,PrlNBO2JWn6dN<|owQRqාɟ]Z=+o_km;pKl-Md0 ) t!&׀,%Y0rٱȱ-]du-(REnWȼ$ohcےW/yTs cg ٤bYQd8J92N 7@9$h}e[4{^2g[vܯg'p7P7/iEk-Lԋ=S1]z("\.bZEwW[x*ӦIGQ'he6A"gc1SߙUN9ۛL$%JcgE%ՙw֚Yp6mjw|t^{wFnϲ8\Vt#牅@ NZuΪ?l8~[aǬ[:j&>݈SMMybYcP ]qU1f#x%mq[?Hz+?UEiwsʢUC~Pmݶ WާA0 &GBjtC5q¦ĚC6P;_k>w_{#h(C[@s!HPQ=Cd}o؟6 <[5J.' Zb[h]CaSwD'CwIPhVtX@9ճ0bL] 1QKxSZő5 ճD'N1 :0aȲGio88LIG /1Uaw5}z~fgh ׋[qޯ'{69Eγ,1Ѫo<|[Xp!~aI<$|ܮ-rI=ʗb;GY|$oip -+r6h|E縎#|XlrH9 XL _y͛9h}ܾ-RѦmZDZtJ;{# ƻ&pv7⧼-'x4E23%˕YxKa[i&魻Rڂ1&,g53 H&O\Wim:hmԳŮq,_Y=YUTu>mkLsdo9=<8-"rr~qh` UKlIug^3v1kX`Bf ۳-FYz3Jbwc[>?'$}9rp2G3F×%ق5䅲Mb݁lck3~& /B#:|TRE-c47kqpHK0Z|oŠ 3d2Cj+,vvHY EBEN@eEl<"흻ɩxsQ`<,kAV5+oW L*iJHWIĕX=^#3(vsjU&JR~Ǥ5fνmyy)*r^ +jJ#LR[Fgfs~y4kC+a ]i=1wse_oU&SXg⋳psxUGlZsBIe4GE͏ -N+m2_yW,;9cN_=SF,F1Cf[:u, qCEfyʞżlgcS;kߝ6p|;٨%-'Tc `;봄xr0f=|VE9,;z߃=K|hOhmt5#B4jj5ЏZ<)jܳ0[3olaF RGon˭]Z/ԨfϞų- .Ɍr/d v.NbHU=\7P 龶6 I=aZ! _610> 1{;Mլ>R7^9_)@eYl֏D.j8E)!av>0*/>ǃ͌6ۋTIEy쮚Ú'I$#r;kd;.X`mb[djl4 L^"bYkJǽ.vo1rΙnQ7#w(rm5xF>^oӛ nrjk9&Bcv\9&f(m um&Wi`u~l)ȁĄtLv;2 g= x m&7ߊ{`zErRn6.:K=CY^{E'۾g ,7n_./c2t+:m!|uXi|_ݾ6WsgIw0+jxDⅮ{ǘlyNr^ZKV;`.-U3/8VwͽmAsecJDyܝMijs/CuؒcO.[wFgw7uM=!<$3&z\֔ȹݲoa>םai,BIR,0϶0Ae21fY3u݊~T=LA^z=冕Pט_xO Gq7Ǐ_R\u9QSRYxN<@B2>̄$eZ1ti}ŧyPaܣZh0:zzk}QKD^O^;MV_Wkv5rAaDjK+hLEjPվqm{UꊄۛT('W7xQv[x+u]fűOJ[z&rV{1eK".6ya?z/󖱽+P +ozicLm]4~<|ϷY'q]˲[g^"mQ 7WrjC4L bBWW^LP'o<dzwr7gggsԭ&Sө/j :DndooE{0/|F/Z{mg/:wI{_͉D}oKkm4vw`L]VjZ:Syj+|ϳi=k%u>kmRC ޖ*AڍeVp۶PJ)ϽQlL5+ʔdN@-t *Qņ/_IYa }le^|YUq󥓗͑,͔_Dլu6na ޝ&oξ1mRM3EikU,/Ϭj59@[L5g{o4&FEqW=ϊH#E,|%RL}C<3_5:Xl19Jh߉>Y/lV~szǦYՁ^M¼ɼ4O3>[y$;LS]؃<ilKcZvyZƞCflu0^?36ˮvzfvwԽ"&g{%$M4.]F=5< _vE93޽`8yAc͵(!E/yGKdwvtxA,l)oJzz\slfT/rҶ]=6ic4/سYU{CL?U0>ykqjvVZ7o{N؏қ6Y%+p7xGoiuzxx 3sxRkY5!Iny%QMON ]mxܴw^PM5S6+5k&VnG OX4-{hڣ~}_;~{-lhtI,?+:mp~~ٷ/7eSdvf¦O:\#n;q-oZM1{a;Z3gilٜ7}yeÏ$uM7.}糹Ij*lwxǪ:3<Ŋ[nuq^?,ү1-hCVAf?'{A{/K*⠌06ͳ#6?oE]uk׬q^- 7x겶\Ƭrg.tz{Ml͟ >Wd[";hm;d}n9dцf8f~m׶7 $A8]_ZvNȆ]4Әwf_v 7X\ޡ\|;{z1,rm'8ozZ ci,箨T?yw`fzE{j߄#ye;ǗS0Q. ē+T( &#!>wߪNil~>$d_iv_tbFN0]E)*?{]ά<C|C͡y?^8?;r?՚~ލQ|.3 [8epj דZlv${HnUqRE3s~?wi Bl#~/ Mxw0ٖL%A8ǧРPiYv !r gB;>\g3Ur uqC&,̈*z: o[+ OlV0ΐ)JFϥ)kYaTRyD(^m`9\62uJv@v_!@Rgl 1< 2(|^d0;N 2SBR,]'y58D:|Ҷ#Xa3ڪNO%DחyOqV$/Q nBBK\`Wd ʒ Gv@9s;b.b_:K h~eP^>%іaq@"p7"C|G5<P Fw7:ep:o<ˢqn MXÈ 9Xz;ôh1BB9@%7=+^O: kjCBVvU?*0>+l=IMp9kCɽ"0I+ ި"̏?cr}lYf,o;wN<{| D%"zYI}8z˿0UP'\) v;vQ䧮qp8$QcC&ן1\cג+Mȑ79L$~]9QG-.Ri <~Vx'kI Qy1GHC[;v%aS>w_¦UY&Xp(R(v.&8XR I٘@ KPoKM,-H9@&/IB߿ M):YIcXu8ƋS}+QE@&`qw^>i\AomO%F/(ҽ>Pעub?bZmp5M8J@ȍB/G0$Tyu6Ɇ^q;Tdn(^7_bZf jߴDWfnwHͭz›OB.(P?)Zڎh Dd?WDŽ?*) 'F,ILr=rN |'0m"KJqH?"^{&u| \.\,RPtSDߐ1*n W}.kUhNptD L%DDg+B͎f/xyqޚݬjn· R"!/կ h!BYtޯ&iQHOUQeYҢ.'Ǫj+vUf` WI'ݽzuw!a k_=%%4̏\mĩkjJLL`6ߙڢ:Bc:L^;ems BvP] ٴj y#s ʇ,uפ0eiq~nh#x8鐪m6Ce70 hk(|0حεUavB:HppqMս~A}Q]ш`v_ AICa}^/rl/!O12@*Jhebl>(da+*6io񨔬U͹Y]BrR)L"d5vf9Uۮ5dՇo̡-ӳje#9X[r[:AϥB^#PO"hu b m9Bt51y-}\м_c-ҨTN9x.xpɲ22zܘ-&ѱ'Κ=m|Jfn?.ܼwڧ~|$/Cd!Pk=;BPJxvpŻ[oO H?uS$uWFtRn APyCF^܅&@SQţs qQogɥ(cjL (#b"0zqr}Bb欇×.9T n Ka)!+ X[nZF֨#8at=Âu³@1QxnkD8\ft4^ân) D%0C țrłH[V( CsbauOŁB˙)g$r Rb |xyYA!{_{%&^X@ i{`rd$hJEt޶o1cJFwgon&2j5? ʀMiP̜R)%)S7_dfϧTISDeل6t́b nX}_-.-y:j)Jʊ,ԩ Y3o%|^"S]@XcV-$華6S2D C f0xJȕP+īd/>l?=|,:IhCh>Z <T23J [71UYƧbIK ؟px(BAEB6ٰhCxmN=e'>X,[uт1y;L]TQ%k+EsH[EԶzL^|&Z%$q L1ՠPwr>[rE&LbMHyƲod)DSNïܩ`N +pmSmvʩz šܥXd憡OV 2jtܣfџ~wmcG]4}NXr;:bTTTG:jxh`3 8y꾍@ad +i7V1S:SK;]RI˘ӥ㵇ƳʆҨ;YZs{15`mdw^C" S̒*m:xo)JwH=YC8{<ƒ҄^.vxϳe-=u^OVZ >vM~ yx!NӞ:=ycIb< NO~gn%(]H>8B$6s.NLt"=u$ѽŐƯϛDfiEM{=.kmv(X #5t|;kAڋwBOW:$WT~%@2S:<%i߭taSFgFuY=7tWc>px ڲ.+ږ%ֽWKٍtL>&@2WZ I{'LD o4J͉d;W)ͽ!*b1 #NOz(d&&O'?|=4@˥Z{3J( vGɀ2!ߵztm7܈@ok2gf !YD8&Kr8'M" ?1B:9/H! dBfmsoEmȵm% (PP[se&Ŕnuի LT%LQ-FfY0ތ7YWAmMv)ϳ $L3A딊w1 &1lz3PCӟ Df5F m\Eݜb +(umawQz)Ն\gOYg P;z XBAMDLZR-˘0U шf)vadRƤ @$ym<<<@QVmv%/W+] ٸ/dOgm¡MȆɩ{BL{"EJ̬Abd*Db<;\꒟F0FuVRy+C,̡吸*~Fv2] b|hQY[T-H Aa*{MC wrL)ߕ¢E].URc,\{Mj6Ԫg? 0Ao @|'ǏǮ62ioe%Z0뇶UPmrr|Y+ͪN?l1`j VjLNQ6)8U=p'\Ħ_otb+ȧ-U|\*(i(6T(&Z wf>hC) MTRg$)`Ta @MBTtneHxx j@UAgg(m%VEV("3gY4@*46:glHc~_BbvW>N[a99љJG]NhvVAWΎV=y;ޛ|  Bş*_dRx|5AXwhߪu"D`  *_BUa:dN |Rs(d`~N빊#vd<vPQe/3ޖ( Ctވf*C[N~P}Β\X$6Ml4?;->P>ۮgϲyaxޫX|]A?r/u^ұ!s|ggnS_ڟ'O~O'E2} 7g0~a|}gřw$O{FG[c5ڿbn*GUG># *l5tF&ZV/ c'zuqjwBe@!ݗL 8RO*@$ynn5M+R6s'VXP ՟2 pJJ @X>ԘȠ4%Ό)h 7C~}~)㈙(Tgf 4 2Du˕Cy,Д0XPǗ*Cn$Elbv;{PpnJao,^ M3HCC z#3R\?FO:?ErB!hD=_ǀ|r`n IE^䱙C2‹Ih6zqVG{|17" .wh5~f巕~oW}3tp݌JDq?}ƧM_V>RAUbw"F7|)ckrڨUGfKGnM{H2@d/q2 ef&<&A_R> #+)Խ|\uP(SRVE`6NM1p9e$ |=oJQlX D:^r@zG@iSYo4T}_oS<ϷkjDbRp}"l=bW6v1ĢS.[8Hw`kzQW S ՁxaEfF#BםŋjLׇsTOsD \%~j+I敜=Y<禺&<#oa˕ (k9 8(&(Bصɍ!2+׋-<BQ5S%`Z(0X.1185*0lY?:א|?/[#\s-ѳa4ٕ&5J;s9n`&ρCOSI!L{ѻLNFEdnҡfdTN@jvS*+yDG@H" ݑ BV'^94*:`}+¼j-N* ЈdŨHUhgLVrR 'jg!e7.P&~j\k(ZLb@ (N&bY1 wIevÝB߲jXQHyF-5R0LG54bczȾbD'MX'wµqAqdBpx>_*`\|¹ a-|of/2R9IH$ D@nyNFpu#(Ӓ8xk܌!9A uod!g~}<6A!dc)Xe䌿N*zuE{^0sy9Ǒ=WMV\tj3d|rvmr}=.f˫ՂIvV b"Y4fd0,)eSF c[ÿɥH]6le2IA\6=ې{o$\ f @Lz|06`pEMMOеHr`QL! D|v:"(Xwϳ̨:d>6gutF _;=!% P` jҗ]6͉(nE f.ꌠBUY w ̢|̄PTXPQNZ1ݞqBVȜfCǝz΂aUMJ$@[k5gYApz)Ow j1< Cy[PsJ7[J?Ŀ yO&'|W2ph޿>JDK!o`Zmɂ .{A 0dpZ쬧ϐƾ2( z.VSѶ:);_;+~h*ne"sD üm}7]v9i=̚`Y+T~kbOvGJZhJ~( ]knZ @]3Hڞc\k3^F!] 着2ib7mQLdP]2TYV-gNl?y;7yT8&BQ(d=zzA"UWsV)UkTm`KL"4(Ӝ."®L8puc01rޭvd) _!BcZ.q1icINfx|i{RxD4 ~u?5?Űf׬DglVudj;F rt~T84(83uhj#v]2M]3{ޙ (]}Q!~- (9f "3˦*62M%h嵃 5<9 }HuGׂ;5ecʫg5e!+kmoCҥru}:Z?9 "sx뇧nj+õGR!v̦uD95r™޶-VD#ĭis"M&Ome-]uN`YwTZ{j1M@U?ةb ?|X'TY(G[kzÜd@D@P!?@0_+g^Ke|Zzy /4ˈu:B ٍ_v꒲̰fP{-..&5c5߿ g XQd bt/^w3o7(Oщ߶OBO"=) YҒ)몋lɇX1m4$T6t Cz`#n@.{9ޘu5ϖͅ$)i)U0I<ܺd 5ZlVW|aABƈV*Ϧzxl+`"hpQRovst,HIi|s\Gߔ1~)wE 寿Q/8I.7o&=&{ss:`=XyKȗK<%Aea%刧uzuq{ǏÄhD!Η/88ybOX,"EX|rυǙO0=ι$@!IV lT%y 8@i$WTUp|r}5OJ&ۻ3Ƚr텱TY܍(, )|d JQ!H<{z00xor5#x2nzh=xF)hրF~ZdЊ$|Mj@1}%*xbZe ~9p ,Tzj-_ק,zlT k(`iGT*EWo{mw/*͚3 O7VN"͂JV>3@.V[2ם4Qq(F%\ CXA=#s r"Sf=dɉc-]׶eٖf}ۚdݾo]$ғ{/ImΒTr0br!2EwNZLyGF$Gm%eׇu=l玲aL J'lQE-B)2˩>m发 =,Ռـfz.GJrX*?K/NW (sݓvK0SdsM1כ; Xz]aRj+kڢ& xL.6Cd6g!1t:j&m9flٛ鼶>xVF g7'mgv X?T&=!BafAuKiCٌgՠz 5X|iͬD6U[,Ѣ\N~ ;҂[˯Lz<(G@S?1-vY0f;wA %L(!dt8A8sj45l*|(p /)C(F|P>(,w^7q/p~ٞnbr"- );=XwNǶϛ!:qǍ\>gG#^Y)p횿As#xw^SCMd!-_fz`ppZɰ',J\ݫ?_o\~JC4l0 ^Ur4uفr|'mHzD7(8cZ=H`HjiP>FhA x^SAbP+PSzN ,14mQ,$4 L?F?C6dqdv:a7m<+7|Z_ ~Ӿ\ٿjN 7"'l5QXVS|!=ϩ @{)kwx5$h2$Kk=o>m׳ُ`=ŏ&(l)2)glZ&$Y%N\$ 2!k@~^J!̇ON[?Cy۞c@ O(U@'P>e83;rIfCxSd$fQЈ2e&8g<6Dh{ZJ6.J* A+V& KvM]b9˧zaƨ͹2MGoQ38YNr0y: L) isnLhz7~n+7?jˁzh:VxXĮ@.ph#>Z OxnyO?0=/M2/ۚH 5$"00HDg0@ʓ\4{vqـߎg_ IiD"6x)!1}cݲuO"df"m\>a?v`Zb5 6֒p c{ ~gG%ײzsV-8Gum@^8doix@%}?&:QL(69逤r3\ok/-e[{Rfy"tjiu ]1P=y/_~W|aRŹnˣ7`qE6d)5>B|O =w7z{r|ɇ.⫧YlQF(ab;$`茏>&To>k:USo CN7kWq|u*b f-o:i@] ϶q:܅%$R`ѐ~WL:|"x7~'4Fn ʥSFo5S2 sk, Y]fC P@^Eݬpr;LBQBYfq)V85J~F P>v%J* *AH\xi{-j M,QY$2l `w)ԥj( OUrPI@PvÕc[^W]|rwkv,IXqsy r22uV%TKFb̶bDe9ry+GF`Z66UƬjQj"ů]U] Z*$Ldm(QQim`CvB\ц)KJf_{~.(ەg;=tro7798ra@'CfJ!2^nP#GSz∄Myv|IIڙbF#+ƄtAvp 43VPs}ZdcĜS;tB|S# ĸo#]U4J/V;i{̹-`[\1N"E&R9>.҉;g*YTu4{nڒȴ we Cv&ua۱Q\|gK8+J*9tHdSU:WҮVUƢh[_ PdP^J$8!8 !!0Qkp@hY90MkM.x*g](,v5XYA( d4M%J ! LA*O*H,Xp`1͡1w@ F LBvY@JXSGa|ܔSof/ȑIpn&48i]Hg4Wo<{G+(Nu5ңtqlƣ5.mֽEŝ|cD:xKeQȨH$)3im~*8'!3ipa?hR4P zSz{({{v }2 pe J | nc R03Owd8t?( 8dZR:yw+h-|͈-̕;W{iӜu++NCwxj]17r /er7 :9o,j'2yiYbuhpnn:E?'`{N}.l b.+F0UuZgLmMꚩbK94ޣu/ڐ/JKgQ=̤y?)nE OZ_kԒ䎄6⣒ڸ+YŐ>rS(2I3bu&2\86I@Jk;Y;_=~/eّ8m},ܐ89/z3V@Ɂ͘Uef`f.Z\ܠ.zVtA1⇌;:tbyz8 p̮AjZfd)W[9>NLAB.: y;zeL/ërhM4ãsOK`q. iH2H hhs6@Zk:N-~zͳrsɅ8;,j-y M '<sOlvzxN<A3l$r9p&̖6šԭ\|~D Hwf{5 PCIMPNBuZPE  rb@SZ/+uhs^Eu%! C8=Nʥ4ᲠRRE"wed ]ͯ3HS MSsJAG%8|B_'?+Ґ2>Yge߇ƍ8Rjlyb4ܕ=Ux=n1T]ޖdKJND 7w~1Z[t1tS$($ Ab}رd{wg](-KVUPa4*fT** z}1E ^}(|`$8 Rt#t;CRvȠR 4 D5>HRS׮J&BrH=o0gDJA=ز=iS^lE(CyPy?:{ ;,ET 2$@{ 9Cώ"B@2 1iZ,TCZ̢Uz t:x> 8 J.MNP]?Pwr2a!&rC}{gÓWVe%P[Wm\ԭrCmj,u6{;# ±&R(l c_:kNpʋU 's}:zN7r)7vA=Bywv]hQ⫤ȣDtKB颌2hA#̼W%zzϦ;"ChҴVoAPYQwpAAee{Y`R$PU5Bb䢵ec6 {>H4'V~z9ǨoTB쀑Z|3{P|Է#C[((Kuz 籑"mKvk6Ze!#0U(JJYzw웇܇A {XS~29dq46{F|Uxrv*itC1⿟@\v?)D r(u(l䖃ژx2" wzQ^P/.XIF0 k >0),3äXz|7i:߄sZ[DFmP^AY898xs PHsPa[J <[=`yP? pk#ab=ّuNQ5 +X;U(I] Rw0cwy ~T5mh|36¥9"iA5R및<Ʒ ZvkjeE6҉!|k f1SlJ4hq! wD QΔM-Z qVt)tkF%EHN @sANм`O"4#mHR0$E(: n;MSi6OO3 (436I!͈hYv~q(Y.n . (~7~IujLڞBx*æ}DDxݮ<.پ3M^ Яʷ_ˀ% >^&q\|Ǚ_/UfUުa+][﻽4{}6jz>W6mSO0d?ӓ4嗢̛Þef\ZFoO<ޯIuU*޿)^OgȪJ./8z|+1[QX4&եۙ"T~n`/xh)g:)|peZp%BųL\T!~>_o׈s+8C-sQ1aޭ<7koNޞ{--mk~bW|yeԴ9g7-[>wZ JEmzTr.sN M9+ TM)q9Er}uVФm +LA!DsrMi v wtM~ϰ/=Ģ(!mwki"d"NWS((Rɕ) wxA;?n~ Q;hk+2@ K" %;x_8ՁZػO}z [`ghv`ޝ ttU3-5l w>.|uuW(v.#{se~MρZ4ݛ Ńe{~ '1BݽPiكU\ǔ| W",/ҥC7q{ԫb_Nz72`^ h^}eaP F@V4ؽМs;,4vjRP[u_sE..˯lc$5ᜎYxa4]4SZP/Zw3Gzy|Uu>eό;{hlm\xJD}ShkxtYxBC'蟄NQڦodx̢\3I'wnx$}+ѹ_?T$ H"?2\ JʋD؄9oIBCR^3-QJ Cgz7d[ޛ1krx 5)ʯoUNp!@ݘѺ8;畝9Qid ~rS6hڀX\mE{tk5\1+l(Vu+*6X9)XE<{gtc^)8MBEilBxyېq 1Lw~wfyER>_/ ~;lÊnIGSGq]lJX xD%|Rj*|hǗ8/p:2cN}ge&VZsC۱YqcX|jkXD 킞㠨 6_V-3a.]h-S\zpOEH_PtSc-|8L^Z/{v{ypC.vSQ DTW2̋lFtrgS{}c޲-6.16 _St^ NOg`xMԸ_@^ EHy|^k6أyk}SIɒg_ޡ}ۺX{L^/^k~g {;fWı]6%Wel{Bjp<SjB8PTǡKi!'8ziҹrcUluP-10Fojs֐/wƘ-Gr~$=7nynR&ʾ6O~TOWoin-_x%"{8DQ0ž rZ [}jUdENj? s݅jI4{%dnt݇RIAL pMוE݉FB BK3 r>|- hT[yX2ez<Mp0Q/GSK"AJ8˜aQ7LD&\s!N9b.X`]:-A[uw()aI?)onэz5xzOaبʓ|Ѝ)}x(0XgAJ[<;Hb:Ľf;~q&nXn91Q{(VlET[k9xrJ)N_B7Pz@ 8VAç#Kܓi~'<7}}f7SaEh[j"71>cpjʂᠧJUKj/ (Nf(:Ҕ/)08#Y{Yާ6<<1ǻTd dT*6+UhRJqkiu(#ڣ(g?t&f):s(b)֎[Jq[h=QX(:X~$ U#ݾ'ICo$6>d,/J,:H%qw֙zkؑ]@׿1Dҭs%nD̏gQÏ2{p{C/)DĞ6TGGwW\OX}2J|Й*@ziT%33  =dyW9pu:&oT;g-9~K{;rX;֏KDZLf{Vɸ^~5Bx XU(3HuLX.?/,O?_怐"LE DDF]ˆOmT77ɑk>{-7pݝHtڪLi/ƃB{vۏp ~Z\4Y5a6wm[&n:QLScSws+=!/mg/Hy͸)g6-%R0wC<万G{:t!rU[[1xDT+ʗt3Ұ\6jA*S I z*UEeE*%D)iXѱUETQTFUm1J J-+J% HҴ(P@H(5JJ PдСHQXմmT[hƶ-KcZ5mbEh65klTZjV52J( B!Kj6hXhV`Ec[-XhѱFUVѵbmj+cd"6Mb#mmFZƶbFjƍXj"5QmFƵlkRTmhضQRmF[FŬUQkYXFƣZQ6Tb-bڍmbѬjm PZ)A6[FVŨmƨXki#jHQZ5chգ[F5l[j*EZRT A ֢4V6hʑ KBҡ@-*ЃH4%"&kbPmZDiVZTDhQmlV-lVjѭhmb*6ZhlU5m(ڌkEj[lThZQ)Q DhE hڶ UUjjJiV )QZ,Umر-Tm61[Fh+Z)))ZU ZJEmIZm֊ѭUأXڵi#TmEQŭhQlV֍QcV֨F)6Zj%iJA %Z@iUJQ()P(ZQ[AmbVhحFѭE*RM"PP HF-FصUjƢ*6Ph)PhZEiSkcմZVm+lZѣdJJ!H1"*ѢUFb،J*B-*FhmŠj5hmj+X"kEYTUk-j5[FQhEZPmh-V+U6-cj4F4UZ[E[k6hF֍hVhmQmFգ&E֍j-jجVmج[XU[%FU4V6mj*ڍX,jmcQFUm65b؍Z+X")H4B4RR)-ѢcVѣE2PP )JmEUFb֋Z5FƵEEXѶ(*-(ZU)Z(ZTjPh("QQb5m&ZTXت6ljm*h"P([j5Z6RhѶlUZVbՍF+j*ZFţV5*F֡hJZZViTZ6Z-j-bأ[EQF5[cZ-QZP)DQT)bb6Ԕ[QAVZQhJ JPJtkTV*4j[ƴUd*6Ej-[Aձ- AJҍ-AZj*m0[6mlmDmhѵ5jEhmcX6ՍEEkAh֋Xh6ԕն6EX֤66[6VV*,ZUXFZV5XEM+J(PD" *Pmhڢ6FUUEV-V-hZk[-mEj*jѣmآ5F+EFmEEkڋQbhcXV-XŶ5hQmlkcZh֊ѨV(iQPRclhXZ5ضkQF[5KX)+EZ4kemb*h֨VZ kQhV-ڋ[F6+ZE,mjƒHR*D*QTmUTbQ-FصT[F-XTZXUQQQ[QEiiFRPeb$U#dX[ `+EZcjkZ -HlڭlmQZE-ѬkM1V6Mmm$R R*43( JccckZ-k ҔJХ m-TlZQ[ŢlmFƍ+Fm*ѭ`*mhE-XEFڋZ*hj-XEV6,[Qk%ڍQhb#FmlmdJҴ*4 DkEhQEhբTkE[E[Fţj+mkQF5Ej6ƊѴTkcj6֡()DREHmcZj4TFj-ض5mFImjb֊Z5[XՋhlkchImF@BH%+J!B"TV5lkkZ-bZƢb֋P*PTB*иTVm-,Qh&mPhcclm5h*FV5+lU-b -b6c[FA[&% RJUBj0FjQJ("P+-ZmEF+RZZ[*-[cmEQmlkXՍV0R *U #@ҪRbֈIZ65h6kh6QTVơJFJE)h+bkFkQ֢ړZ(X[EQ[bXQlFmi+mQQlkTj(ح"֢PBЅ()J*F5Q6-F*m[5*TmՍQcՍQkDV+ElRj*U(@SG?W('Ou=NEc *?A{ ._K'i3` ∤ BG<Ȑ:tEDrk"_WױEDb|X/T"'v߻go=*JUhF(F"h)DB^DC_JG`$>B|45/W=eX>{=ڿM44;hx6 4Ke]B,[ٝ5ғJϳ?xʔO庳_vf45,L{f(0<$3:J=!q`VjOL59b¯?TOp) sOwRn+ ٝg+jύ2C;8M;p5@FQɦbffC%2>OV@"C-MٗTӦ҈2z=l7 `лrө iIV~hrznTP-1T vop1Zgip?z?ߍFCfJ r|MowPpPE JŜFdtJbU־?T$R+F34kş788ʝxvYe%$T#6x׺N 8Xdj?rjvOD@9fRex CN&I&UMnPSS٤>LHw~dcepMݬ- >q$8!]|dT8b$,4b*;Sq0XC% `(m"O=T\'D! iP l5C,M95&v;> .j|P + ÅC,~01'*i$4lQ]M4Ӹq*`U;gUGO)\}=cMv{ՠzf+GWY&.|~:YʀŗO|FT0e,o21(T"f)jH^ˎ!FN.O}BaDߊPUO =F"Wmx?x_^ПPg0y  @Z>}#3'Z!4TjԔ!gؗW@(}.@ɠ xDwD?[s{FʇPq; ok|x^QYt Ɓ/ވ,Qa@v_yg=dO8*'YnCE}_Qu~%W I@v´~3EGI?hW#W..=4tt+_g\2DnbVYqݥ,(?[yrO{7'n؁'oU{D}dz߇^찂i@/?{CH>A U8U;;]]:$l=Y¢h s&-GfGظCeKZfPS1~ki ([dX&J9[r(4U}PL CD5zfCό;"t)uXa Sq:Ouccċ*2AeB,̟BoP'D=KPx$(0@+$Y))*=X5:\׿"nkM pǞq M3qCO:,d|w<'E{QNɱ ٝҥQfl&&$C_g.^w?brW'Dd? M@[8nv3\ݷC5 * HwСS_.͸.9`tٿ1[a Hh,Nvjcm-yy sD.0PRbR*ɑӅrn+H@ * 5 (DAFvm%d%CMUA,)(JVi6vEΜCLqP+\wG,S?})uɡmjjj[Ǘlo37][#]d獮Ku IdKhcO 9?Ʋ\іwp<.}u`R }&ӿK|֫Hԍha<0nY5" ha>DO^;qpRdnyʲZ||cc Sݚ'ȳP%RA &y`$3ڽ5lTiD~ro/+[2LQIZguwvVddd)5e# TF {TET+"C=b SLسV#Ag]mKxYRe@BH_T-̰0t6J4IAYoq 0dPN-b꺓)WDV ymURQuAh) ^=*k~S6怾[*\{N'g^}"|#~KM9=b 0a9&i3GΖNiHd[sVD@()¿(vv˒ b8DOx*\tUz6MTA~Ua`A2Cp?zģr^`$φi8MR3b(DF竣/7A>. ADeSeaFI P ʘnYZƢ5Ι"h:H5nD2b^UNFc!r%m-dVpۖCpHLL0ɽp.ڌZ[pB+QPGOEoA:QQQÛäXMRP c6)(!!|!E( PUX}ow脀L @ȜIVlv+$X@+ξ: 3@@_7D$*P)F}1_=s]Q$0D@ d@B0Et';$:EOm5p@%`fA@?Oj$-R"Xm! cFbSX$X%R("MQTbD[-$"5,&4bV%0Id#R#1M%Q*#Fm%"d5S$Z-cTCj5%BdfIT4`C[64ZeVTM5HhJR$j EM4ck)EEclV*[E4(FъZ2QFL4j-XF"Ɋ5Z-Q(! F & F,ţh6ٓR64X6M# @(,i4U$ABQRDdAjeV6т#3m%d"DQFFƲk2)&ĖLQ2ƈB4& F$LQ2#Dj(mjlDh-)FƤbFdđL"cT&ƊM%Ȋ)6I Qj(2lTIi)LՓQlB4dTXJ4b26MIcFMQd,,Ij#hBIQQcTZ(Tf(Ula6 ͈j4hTlEEQEh& mQX+)QQ`1IneoY#V0XJP! |)b/CR%;#aZH-0 (# MlQED$I&Ilc-"ڌs)n# DSBDcIF(ƒ $MCm Q# dl*6ԙ4FJL"+6*-DS0()lX؁2kXeBbDhZjѱcTV[Ej66ƴUFhحjJU&Ѵ[Vj5Lj6 hbmhح-bTcZ[FV UTUEb-ZƢlUѪlZbQTXZ[XEV-Z)ƮEld%lXQصJXѱ%H-[IQQ5QQM,!Qi6,QcQY-3$@Z+dMhjdƊ5-dXe61 ŤƊl) _l} Mhŵ[X*-5kZ ~qV#cbe"ҚAP+/VE'WM!1QQ!M A3Iٗ3ej!$1SoK)J}g:k7M0xĪ{ U+-P ) <~cDh`%E1AL;hNF~  ӎ ž1)]ž_*(TeC6 +-aV([ء=I@b_kbJUqpQDTq]\(%qePw@n\6TKܧkowW?F 4PZOeE%% :L*pHn $ ڻ9nn1 28@?0F v5/; $<'/ u\Fb_ֵV׹{v3ԂDU} >D>, zv r{?ܥԛDp)AA<`=|qzpWm>A@S]O^/I >oEI9ɢtJ|$֙ė|n~@<rOfPTQȺdާ09?kp XX MI5rv`[A0(Fp\r><Ř2T ¢) o ˕ERW!M-z}ӂwܓjd W\GO%3T?0])ϥY\ۦb`TK@V /WylQf9LYDAX~",QpUy*8ߕ 7s:U1%<'DDOC|i>PI>;b}66,\꿎'Ow݋~_'zOg.m[9sC=p$7]E},>YB11RHPM}޾U]Mwo"C$PX2fEb0~~9=Wݸ?eCޙ!EE{k#jf$Wس$臄PXquIB >|z3~gj$s gD6TԘAxs>BKp瀞\&M'p"~?OA !7Oz-3Vǿ~٘o|&XԚ4lM(ɐHJbKMnoM4ҹh]6۹~ǻ?q2V I( _7[Zb61A(̊(^ɺoc0)-jx>ebZ(^4S EA%I~uԽۢ:nhDf[W ,&oK33Q\0VyL&V?"3kmE.#-c)%d'NW1,' 3CDžSKsmDm3OK腕}x&2(>Lj8iNBe8U~%vluz}-w5Znq+?soQ_+_6 9gn&N5èSqmDSԱ5+ˈSsXWF~?*K- O*tPeLiH첈ѳ;+UĆDRK[At(>%F3Y,]kۈ)ڒH '**"kչ9oY'UX_b[{vQI2*鉧ۮ>uߡ!XD|*JU~nꪢ 60 yc_m~%c[43֜ )0x~P<C߭Kep||:vpS}wW5(?Oԣ_?G0Yd$pi^~6 C(A݋_gvEq(.Fm$O믳zzKm(̥A'|%dS~*mրG%"e2&)m3kiɗ&|ˆy3hv>_OeN6:ay(XvFy%QKQ{|X^CTJ=l~z)u@zzAʤ,8^-'´QO=١\ɗfaE2 |m,}Y*_WkC2Wυ__8m]'+QNRi8za?smvm8g"O6ØSg5Ӣ ؍dȟ-m3e}FF\NIxY7CVBQX=VhP93W^f1s|e3 $ 9|ŋ `<mWw}cai*t^KP86J$BkED~WJDDInX넓L$aJhc ߓ&4H5V)8 "xϊMkqŸСj" z3̥QH:ŽKMh032ʛ*rLJyWݠ[\7%mb Uv  Y;T1P#ZIɏ ɳ6ʣz\95Z(31(c&LR:ev̹Z N]k(t/L%.d0""j+%"Oٔq(R UiaX4 FizFCFjR[K1 [<:(F(n=Y鼪Qv.2NaMӖi[c(XhqMN\Q9J4Kq0LN͵ Qq&KηLFjL2+وPJvk &Z3"wn8̮TlPZ6 %ED Kz,F;HLVG[rA;ـ,Su_kw;I!i Bʢ)Uef2(mR="KQB;eA!cwnֶ ղ9i ˊhؙk]wI)؏dG9mƍ-TZgevVQUE[S:@"XRl22w1ee1̱Ɓ_ץ3cL˅K&{`!X6زWs{Ƃa`29Q )R0訢C :,b0\h4Kg@-`N$,)LYZhlcYK=rE5os3p 0P%t gN$ Udrq wypjH)&/T/"LSRIKaRqt 6,uS1dk&6u*[  u`cC9ilka2^YC2(PSb#ns&e T1r'PCO-! R!j:^ܠpjHaPUԂbf ila(m:L3-2aQ2VK"ĨƦ+u˩AJ V؜t^#iM̕uY]gmQ5b6VE&*Ш0IE, rJ2\:MH%#&AFc e dhdu˸C* 0 \P[]ٹ5!2BQP+THmLd Mn0YmYc ʙJSLac H5q 1>LLrL6ֺ1.ehUWmH8^eeй+Y*W2_fᬘBw) 搱!D{d8‘һ.u27ԹUjeEMqDR‰[iT^FUb1嬓2K(Q–ͶZY7-r %iy`d* l NXθVE0X@>56ɍssQhM#J!vA1BxS,Ve "ֹIҌ sY։6c+!C77W-Jef90 0dY-h.1U6%2n1EH,68;u jMr1.0*,l2kek1 R0*,e-EF&j)Tc-q"$F.AYeSv魗hc& DaZI&FJ̹vmkyMu,ta sF )#:!fEhKH,1OYL"0OM®{i=*">YZ I Y,$H cݨe&$ܥLH.-8qaVζJ ց%1xqY0pAÐ㦜Ɍ(`$m]45"(* DDY_Vlr.6PݳYZL + js( 8PcY_ dI5WY ޹h9`ڛ!am!XXɇEwwwMQ`bR`%dJJ5Gb7 CcqDXF+vwyyW4[ 2df4N)V0EPdPf0W.".(Dc*ha,]m[KJYTs01, 0ؔԷ. b1&`o/5{RkĘJ m++*,ZRp̎* 2PʬMq2Ndf*r(s1zxZ^xkiG21Q!Ue`. * VAazT"88 #T 0<>7ZhÏeI+4J w^MLc0243 u:re ұ~>[!MLiLI(1iԐ1Yʼn)f IlahC 5MELb@JZk "6 &DREb $I>^|lfHт$""s ErHІ$@A 1M#Hjw;gwپ1Tsp6@L%,('o- Q)Z(iTJ`ҥ 3 "`!E|SsOT+_ؔn/۾{єcXKf!1 1ES׭1ED4QgR9;Ы .H>?ါl(o^AyToLiOYĻʔ(Lg T Qd_˒ї&߱M}#WcJO;w'qvѺ4;dG?;ů N"GtL^]zPOn1 +>ד>1Ek{)MphS]KtS5Tht2ԣo3b)l&g<*F"(n[f@22hvQJ逗=;_78E/Ʃҧm1XK~+L~O-=l|H /alc!/O&a!F#U6#>>7t<rTi&Hz+ڇ?=Y:`{<١Ri y:*=,N4*EHS$gb'OԹ塪e#LVkr+~.8Y3-HUjg* (6gn_=3'O=uCuB|lO-"WMa(Ug7HySwX~Z6G ?R%q|ϓ͚ID# H _{׾<Гp30DγN0-bE#|}6lMTFJ`bII*MJ2 h j=r{{.KbhEATg,*ᙉNꠒs2fsr\o~] ă|+;SQŴ]`˗[áUK- o{fE:/sAK12?_C)((a:WN5Ȣ;S.!`mFܸR ~CݭMbZ_']̖pa;8J_zbQcz>wx)5J[k9q~L7JѴ->⋙ĊF }z}`e##y5@(0ɚ)Zt]zU;&wI LeD-KEk71%WT'գ:y)|nOc?&Ae%7n- B]C !ժ:[_W~̫TsR~6z{V7~>sNWDWXej5 IlzYqQ7n&>>sx vo/1'k\6A)΂`VpJTOϪuW݃Co()Pi!(Bi&}s}_}qQ .(s DAXĻWԿQ<L!m1{r"jR]iq<ȱ $?jo:uJ"?]V< p(GTɓ Jj>)7 ܫ\@m"[;|<>5Nt5s2[Ç_~U"%nr/PhR B}x->:u2a}~`KJ_ Ç"2(e wC=nzݜ JR|i|C\Lx|~,*/vUϡDo!O's_-qe#v ]I>ߍ΂u9ڧ쎑֊;,0Uoɨʠ O=(Q^E=g*BWQ˞ѓ^I\9 ^aHf,oLk  hwO_R`ܢS::`ބWWdlκ5II='ZiyqL4P&\_cnf`Q~2Yι PQSH3Or" IaOƔZ(_*Oym/ q=RX$I$4H_UwhU;:l< >S\iiR/b"+Ao_Tu͂3VTD݆\ bَ/WȴVbe-NLYޝk!"Sj ͘SqL1=QUDPC:O{3L/_I~>+8>J=өAhj!H:̸\Ldo 2&|j[F&p~z2nf@x;3W>3ͩ^j %hة x氩ˠ-jŊ*1z-|_~z;wx oJbB( VU9l=?>vfX /'>h3:E-U+{w⽷쨼z. kG;[]=U1/{Upi;UVa什RS!B QBd~>4׭T`(:‹|kŢn49k}N^ʲ.ag!&kS[8vJ;%CGVxn-1/MyYA:K@J켰Wyq\3 dwը';Gvx9D!s*'WքS4jpd'-RBG+iPBhI*(}u3uzߵ7Gi6Jk}XD#,RڲMIÎ|/Ik;W^&e 3>ܖ{r c?D N&R=q؈hQ:{[ys'}ᄃ5v,Bٻ碕I|9O%r[3њPuvL}YHeA8<_ + ,q<' x9 Y6G-Qeo~`=D17l˻8/5GjÖcνN0un <9M)_Y'ZgT0gooR>nHRUTцAfbSDPERw)4xRP;2d9 Gư%G9M1g_u o*+U^֞÷f+ -,)!ٽ$DuEIJ9}wEۛ@ ~/-la G6JF8H}AY@.z^n&SYb\-fWLH̪262Ny4"?m`8*H?z}y8!y=  K ]ѷ0I/B X4/DI.D4̶͢v+dRr2s1xWj5&cġzM gT~:If9q_|{,8'sǰOhɟemأ,{51`P?*LCr Xx~ot(HBP?EN"QH=P I c"0%oӲЉLP2k%4ѓ*5X4͋LQj I!FɓX l&IF-#),&Uv7Aȗ̂A]-Q!&y*?LH}^~c(3._a%oXwRM'ljG^sq zLqqB^Pem% WρRAdaSE˻˳9=N/^`՞_ *%<w_[,b,? ӋUL"3=5Y->6rYm|JvEjHc/{$] ƛ6 N/(x n @w6325P{I Iʊ9s?xt%wq\ڙckXS5oa~E5:>[yhO~TC+܄y:חbVw\46(ך7[gq$FQ`6EFhlF^JT*,3+ qn4ms2n\ˆ*n b3~81! -VF1XFfsw2lb<]w\[vf6*2X dfZɵޛW-nL;*+פb(hE|9;ыEIz={ct3˿j6u؋s눞mQ{ pLA `(k#h9JB:RXcnnS; \.vW9ܲmDl\FwWH#bs5"cS4W8^o6Z5޺5rۖ$i^މf[L6zMh6 Ez]hۯwYM^1B5ξWd1y,FS"؈ѻVcjjhZW9[F%sT[EFXT(lY(*( ʀZQI]ۊԨѱň5K0XVc!|?'ϘI}"/skK&${1W'.Nr!!hԑ$h˘.UސI&" J/}P7׼|SuT,)&ɒ}zlj|{݉Qh6(b &J TchS&b4az(EF^gu{ݨU% b $L%0IRgu#,FŠo$M1Ddɠ3FPdŢ(iD1) D S!%XH5$Œ |]<)PBQE; f2lQ$4bXE@r7w7$(c&جh 0M ĢJd(Fj1Q̶IT*Uvaə6+"[)(m7mczݘ3,XD`-b)-PVL1˘8u4bPF$}>[Wͯ3ׅnJX37˷Jv}>Rң,[=6ĕElT̈́"H(o:J*tf=UCEs}W$dSeV*"ȤD7j"QQb'{%mY "ߧt1 =<(Wk7E£^ &NKsw{MIQBF~#IS2"כL7a$&MQA!!H"_iJj6f-1MnZJ2FXM#S1RdK1,mlr(є4>u{+eF($C`24ȓ)"#X؍|\"_![͓[ (LR}Xl" a Qjmo 5إ"lY"իfnй.ٮw75yGڋMTEQTExEMQiSRED1!m~ǖ=a^Qw3B"e $}fM@YBf5%5tW*wnhibŹ\2Qkև0,]QDX0(dN%jCxd@PA3ac&s?.$.~ZoÞڲr )կyU3c/ná?B?q?gE=9{,'QA2Q?;X)ZU@v?u'#SP2mJhbH0ƴg7H dY 6FS,BKA$Q`6 Qj6DZ-,`DQZb)JKEbQEMأZ}4RLOzoJ7ԮTc ]'7M7.H%\ɯ ;nE/ٮDQP~qEQR| 'VjRՑg%rj-J}%1X}-|hݴX/|נ櫆Xh Q57@ JA+h)em`5~v/|zu~>E~F~lҿ9I~+ӺR[{$dŠHѲQ%?u&YޢW,;Ȍ" +%xUP}NqQ: Qɦ3˙IɍF~F%W෸]p+>-E(#&*Ri3C&К h-1VDFc1> Z]p%A.4'ڢ8R niD`@SLI7eeHH"`LUJ8OJE'?AgIÏ :>w1 cF,ggv6 gݥAL0Qxϻs9eDܗ̴Gu)Bw_l&U\bZNa:t1^R4JU?sIMߡS.6x0 B=tCQ149{Mvf T@JUCPP+9+|y#?]~4 *,:m 2 ) gWaj&s=0'Ox!l- ExaCqAXk٤sX8-#Ivwc\ӡM6QQy[@Sƌ9̪0NIQIۙ|~FH5]T@p#Swɭ,Ձ^y>㋲P8'%W7'Mʃ" 'أ,;T}D8_jC'73蕘k]C0Qʺèe5fe9աbTlM фЮАRSYǒ7Jԝ$0Dԉ:I%o|6IXR2B29nhna?}`T{XeL\y%!ٞ.g-F}1w>RSB@J3|!Yޯ RJ"=!ZS3uM?Oh q'α=I29h m=)gzlS B/c|r(=l<%O Pz y9>gк& 3q8|c%!}09)70 OS .ˉ |ArTU@Nd#e y5}ם ( ѣ/yisW%CP6][r>1\Bd$2Q2 tE8 nI+#$ 3դ[&ÖZm`Ԯ&~_6|r'g׏KC&VֆGn&W+xݙlc.VON-,vUps3][W,t̚=lt:pOJDɹW˹GMlm^r>d/*!}juZ)t_}_;ړz8jס8ޞf xo|W(Ao@[ŕW;>Z9'ΌpAdΣhT< }흰FBtk_)oT3w30=2OkN0_Ć"lm>PCO67Znc1suNޝEѽ^,-fxwzxO3{&Ee<]P05.n;uT; l$Fr%O[oYCц\e8G|2P*1J J=/.\Kê&# 2(߆}4{Msnp^n}s0y-w9^662Βu(l:5-0;|/&ETS Mw)g2SRVK-0MJŞP~K+P2֮ V\Ĩ娰hp߳~+|r̲C1[&aiO}]Z/1]({&!}DPߑ)?TD7ʗWKtTyY֯;i>Nx2v+ [3*Z|}m|Go1bRv/e&P2*ZgN.uLZ6Pf bAWr{a)Br0RGi&)JOe$(Jdu XWf˱HZvkpqiV6w&^l T}(h(Mal`AQ1hqTĻ}֛eqmq(yMB튄?WL}|9S ]iph҈Wz6 S|i6͖ۼ9[ָÂWqU7 ˆ1y>,ݥNxw.sy̖aiyk-QY۟~q1`rS% s'XB&dKEceRѱX Zbԕ׽_ZsVTutN&#L?i)'s>mLJC@%(EcmҰ)CEHC /v~_Cя }?؍wk@9DE>-"E齸̭=Y`pX-"Ň RJ(=OoK8QP{~ތ~[AB?K6?-aEXQjfDl~^LpT/\)1WG3BO 1*؃(?Q[+K 1)o}'uίޥO=trS__G(U@C bLyJ?M}"w*1!WߵI(8#0TD>Ƕ 8Kݭ.$֖`SZ\G^{|@Ahmgz)R Z,XAk\Q9ڗ":~eI x#}osz\ H@P%!Gn7QJv_7jM+TbB-$W4m|z-NJwd#md[W}~hۥx%~~;Ș_Pg#9P##3O^e x\ڴ9!t?&,D0B^^Y^D{C UUH,\!vl<ۏU/)9 Z%b," !?Ad+uDA%Y.zN3N"'^()ޫR] 'YakݕC1‚$ rƨU]a4IJܡrs}^Vrʭsez=nҀ]IP1r`yfa-ELESBǝbM˓PleIGeR hUEɕQ`_]Ԑm2lT?8;Oι\:iD Y* .4͢ 5Xv?׀py~1,řHW5浭JZ ZiQb;}_ܵ?!yOqD@^ ]_~>P`ABeqfR$Om?@.kLˤ({pUW2f7_8|ADU+"G=f|*|^qkҏK9K@Pd/c-^l}5iN@~ôzfړؒ[ fb*ُt9ww6:D-ϋ4+U]E{%ewضPD/js4sfÒ/ MMJϢ9B~v =ChiZpOco(5JFYӓJXF7^~ꈆ:\H ]c`y}SxtUzg==ϧ2}VJƴUmhڊlmAkE["FڊAlQAQ5F[ )"6*TZcP-F=}^uA9&ܔŵsgdFiF"Lv)kuk4WR|[}luOyd!_j_G1 %y\|=nn}V㿒9p F7DߣDo3n7C ˟K[y˯eߪ\YqN=GWgoӅ.kXCm6_}"eվpGS~~j/M:>޺IǓ-5Ŝp%rmo`R꒑yAPh^@)y٣¡Ph謼}7%erqXiֳV7FRrM?|9lQ:h$@CdSdaBit6u0U%BPf1>^K,ɇ/D3yV2mѾנw>n[nTfzp v6gM萿<̆GvYumݿiGG,&؄C EY8M7Selq(/'mYZj6P;j!Nf!t&gLm )%R(IGaoC [ć3̞9~v 91c`F IDuWRa\Z*2#ofV#CʱT`o|Oa?~>0h GkgWvצ/;;ױnN'/uˇ<=춧pPϗxVZ=u:- ~-o^j(EH%S+V̊M??Ǜq>wGS7 ׇ&T F'%9OI j"Y wqNRLN{W۶ۇnCc3:nITġȘE Ϛ5,%Nx#"e;7[TQ @o }/ !c]ȻF\P1qtmܫ][GWCFJ-bB֮ԍtz13_ؤU6'bٰU Pap~t߹Bl %:]}73ξ;no|9 u~a gH7p?odkLqgM<:ޒH];zەAK($fs>Kc( #M[_xoxS{F#)2R| "xH@J"woٟ?}Ӷx.5wQqQ''U,ZX  fJ}=wO4/eyPojν!/SEE G2`UzMQYI\Ctaͮ2m/ZNY䪴s9!q9b||q:sbgsۄ1I~hªMk/q7Ol}Lztvm65?WRAf.(@{"C k(fbYV3>(-^VӞzF)Vv*ZJ#ka7^ \x6fբY%vV2D_YxRS D_*W~-yt͖~2+ [M kT3禮oPWMM !PTTt*[@l_ zb_׃GBSx&~§w*!cߎx8z&fk'@`VXiWa"udQ`0AGiWVQ2|#|^o FHo]#>L4EI_%UV>D 'wΟIOGf`~C=h d=ntၗ} |-ͯR@@_YaTNhF"0Hy3k;KHM25SN$LhQ,J#ϖH))+>|h; r7LGc J-RϢY>ޛ%S(FQK0e("zdDc"T";QkN)ɰ5! )_Ժ!VR;7>wߟw9ֺkz/*di*eBQ>K=u0>>:isxExPKU9+rOTEZ_b23N8]*E7&$=Qqˎ'ҁZO࿾Ju~IV|reeƔcn9Ctq~uCoۮu6뭈?/LjQsKmzŕ۞WQ6SL-bzq6~\p"80,X/s>W~_8%Y"SUfn>ha`*T=8ݣ{(,jrĎm$!\ٳGձAV).wњto|LΛ КR5991 0B=_-ƹNUaDaDr!Y!Tt/{a>[?P{,AIUC fŋ_GE ==ґT0AY,Adl2($k微#lVZjQa欅XjD% BP%ʌ.C5(_%R2y4Cb&k-SX( "@afݛ]Jm"FXaR~ٹ=&1dX*j9]+sm7+[dVj$5ܭ6[QX*X汶-W4RVd٣mFMZuljfQIͮhʣVۦōkyz 4Qj+w]5clZ6j#mb6 lzZQD5Fۖƨrƍwjh"KYvj(^n[E!1dLVreBEXѤ)-Thش*2kFɓc  ;K+ نiEIVHP5VVE* X#j6)"+}7-rMǦ({y7)E?e׻kɍB 5Jeb*"1cA}{67(k&$w((^p9T&n*)( aCquJ=֌Pj0 ADBA ^"TKF>#?~<}#oV\ qX'/!6;jMvOWFi)SeFU8ʒA5Or>y,4>b5 );FɄ?Li^S/:|MR} >PQMUm^iӂg{#FOl7qyl)7J7+ &)쐦'6Bl.f/j:(Cp-ax93|huE rnHiP@JQխ/z0^#1!{0`T{f1UOAb[1R9VT~tW\ڞ)Q;3GẂɚ|iܖ~{Úy_2af*V 8; ?2"@BPV;#G%'~,pzfDn_tX1mTonЛ_rCMF*{ CΧ Kf BSoW!S?=?3Z9"H)T Y5v0 -׆]+ݲKam;UDԩ4E`Q0t{l(7;Yl§fYl¶QKH hgsfYI _i ̴R;#@[i`չ0xԣ-z$M)E @685ex3Zv *\J5.Kn!uT 5]Tq2mrwJ8 DQHwIiULD3_QBRiUATBl¢Qq)!4"fkGPn~ꚡ/o0JPV)1uK 8yf}ܯ͕=휴}쨟/ؕ؜VGD' u.6 pӆMJ\:Š픵%TLC-,Z{\>h]곍5g2ӍDH* r1r:pR>Eاo/EHAyx۪a9ȕF0U(V##P$t*gmZE*LtZ`Uh]ޟqM 3쪞≲8E BbQWy#"Yq^_g m4y~nyY4l`Ϯ4, *\ho'$5} dT$[*wK%=111k ".^!QPCցv =s v~E eUQ ,39J*_&ijyX[^y UUP-_,*k#5QL%Eݠ7%!gw(!p;Kre}.HÅQ Z)4~wwĿRJE ڛ4O!L=o.|`Hŕ-$ZDA50=QD^6 y‡[a a8o\L3uZz穈}c0qb:c% ƒSP 3=P4cʗ ; IjbV|kǍNIn[;8ˀæ>|Ag _XcZt:W+~:m!=]a=}U{=H` Οx7džKN)<#Un$zyQ.>'&-xgnVZ),W( =mե0Uy#1wg שR],4gT^aO EYiPC)8ɟFo[Kf0yRT5Mfp: c_MXTT\B *R@*4=Nwi%UygJ]7>ɓ;0zX ^F$A=@%.=EY7vwcT_9e%ZQ~ œ&rQ:kx3}}AӨ*ыԏJ uO#29f`{ig'_nWO^x`«iv~*3ۭuC!!rٹpJs{lּ4v=L #>ʽyšo*"f\I#JU`XaqL+: GTBRp ???/s<(TI$@J)'X7 }`{G pk=p5?!wڡVeՐPeOHH2hŃr0~G9sΟZtǯIj* wLyĚ_Lofm(&Ibj1ܝb_L7-vUφXgps! p{&ީޢ`u2b #a&$ s[MȻWPd|}lK<Ԣ|4AS/pBqCY 3xՎ]'2Pk# \4*ⰟdԁEBwquxΔZJ)IW7Z,Xp360;Y4d\܆gSELJ$'L߅SUC+*gsdIE#Rqa*%!Bo[xo.[.Uxl 4./a~o =*8憌&xtH[v&8QX|^LvF \M¿ET ΕI* 1*f= 83,u8U-z[g4٦U&Z_d^0h 0B,V9oMWrm<P| 06Ϲ~D 5AGmpCiCr*m|KWLpXWn]n  Q\'@q zJ=[2WBT҈ T Dφߐl + /z!.+\b|[=kj&aimeSg!l^ 97qcDo0hqZ|!idDvԢJnDAQ9LOX (H/G 7p g (0z)wLx \hS{40thpr!*Fd{B繃B7WiKK/F[ӛj=~ \d>}aA/YD=,g8TBw/7c66GhkOө\+9OU= }_`]~xMbSc#$:KldF+ M@~sF's޴#Mݝ=;n]<.y^f (P͌ހ [nmM&va$ϷѿWF~3RYHRK|Vcbss0nu'+RBQ]iWt6[|m*I}^FS+Ƹ1G Hi-nk3kE56M*ڍFhTh-\ Q( QZƴkF~P1D4[[>_fw/ ܥ >+NAR#U*W~xoZ;N4ޯOɆsR[dvs;9+3is(0VNR&)GT!ָE @e[=ň.G{u9FS'+%qH+VO`ӫ~ycʽrlH(CE)4T.EUQQ) LBsGC3 r(KT 3*ְ2-EE'WgvLNx?>>?eA˔T$}rN 0t~Z<*vyŽޘ;wut=ϻ҇`}H^/H|O"uXSAbR=JN&mD-8aLʇ.Xw$ѳkylu,u:EBң=vSBXs-n%}'- <1s3M:S76%נOE"ӸRm"2uerFxQX ffUƎNjϒ Ozʯ&xWR3Ј6+<\P#Hۙ KFI_̭1nqQ/2!%*XАMT;w<>)d`ɟ"< 2 ciQK / Oͺ0OOh/UXV1z3o<VA7Xl#Sw?K ^͗3HzS-Cv޵t`ʥ~îe\e}ODȠ!#1GHnt8J$8 zct-Slf L[PQ>#}4M CXP[IIIʨLQNM~+ Yo0##9UD̤)o=5.)$n1㦰&s:ikh.&ܙ/GXU}\oV1,DP 17MGK/qѧXd{C<,M=:`Ptdï/?[1٧ϴ>ݒR z<-<_J9ӋO-?_,|]$k3F@B#vS׿vmdj)P-dpȰ2ʀ^M,슝W,2d/[@¿.@sc~:o01hDV>aWcvAEUʒ ]Fc^K7)DOm.f͏idU)J4d"4`f{k~T'>`<Jr ׽&@'}doM!pQZ\9G!ȳqz۫o=~DPy2x*N^喿ko=n޸71\ޟL(a|iGGw>۫Exwh>C^Z?rxö}`@=>XyK7%=g;sp*TصP.>>} ]nx`$jKɟS.G#T:s~G/6}MP0Hn!ͷ63J8V>afX нb(1TMs~Nћm/HGGIO/w|3bGٻ}1ZuQ/`^(24]뺇~_TQo8@cO-rWfiq̜Ys5ڡ(GT0^R3ye۩'W=iNOy8ߛUXaKT4EHw9>?ygtwlfWx 4F\,F=/rmM0ߓM3ӟv_ۤsV;imizz=ƃ0iF0Hj0CQ}oa2L&@4"KAU{r| PƲuG=AJX1p] ]C%yg3_05n~wã ^qF|kd [}s.I(3Ye9gXκTlJ  @P(Q>m'sm-8SS%T` ^1lժ>Zwp3 Y0 # Ed>M8ޜ}]8x;̻=픭Lo_PR55 C25BTS)D*-'_Az7wʫ#0Ǣ툅SR"!!^JQHeYj LҮRꘓ?gb/p ex6H^HY['XE'ӑ0Bv,M{ʊP(=seHvƃXzy˦++eO!`Р>ݹ:$1BzU$4>j I2h9BB+q^y3шuzh0Ѣ*ުuɚt[yY:(dlU =/}R0:$<ʕDI"c NxG睡 ob &ÞUEPQ3B<%*#J;_GO鏈۱2|5ؐI! 8vy@yx̠Jyx)9Tz2f3R {OQ_6*p뢤f~5`wG`w' vtPpg`_9\( S Fs Yyˆ.+|3 A~/2[@AZ++Т(J`w2JA(L#@nq`Mac ~mn7T{yFoIwgݞ Ί"&\l'ddJ7' ғ2:/wrj;V9qp IM&q&ĊSUd%%7/O3}Cd[Ŏ~wnW B =CFZ:^<]tX}t}{E^4¡lM.p""KwNigN|1t;{eo܃Ş'8]h G_~ 6g~5 OT])]RphэX޼mp 6D&ٞfGZ0k㮪2`LíWv~ *#{<ï,'1NJ7j|d{@}2ۧIX2_*\)ݍ:O'\Z4ǐ%˘xf7ȃ=lV^|h#?36b}PPw5wp^ r\ =Lk)~Xc`ed(>THeiq/ךɌo#㽾QOXJO}1_T;q1qAG/}\?Z(Bd}IqQ?/"?a|A/En2}s<MWνeT %Io} X>4,mW$OeQE7`6C/VHœlFvUr5ĝ2,~hP ?;>H4O&S%S邎̢),%0\0̸cuۮaVBs11R&LbVM ]&ݤ-%^-j66 H0 ]q#7GssykNonlDX+!yiEk++\[IT T.sNA %kJ|FKhZK ienB,5SwxWi,ɍ8F!"T!MVDv£,sj=V`KN"铦@Lil31Yv֐H0@csIZ1,ƙ˙6j$Vm*/.tq#c,5\ UR d;t&^Su3h^ᡲqs!8w k`&UQ9l.Y,*Qas:rm/ΙÂn(0o-5R²l!F 3)c˙+ b"M(dE-a N dPicKFՌ[DHmk©PQE _M/Kn\tn80\Cˢ&7YriQnf&77¡<9 \c#!y4Y}¿S{7J.HnE~Vm߿Fs&a5cc]tb S=l-BY_Xͣ< l i+2E1j_1D`>:4oѷ7KɜAc3z|Ճ^3YU:BzuNzn*RS# tL):6(:19m'L33y۝$ULەL܁~|pZo_pS.> 057jf䳢Cmuwz M6w-+>^;9&:37/:&rvyżz}ɆAP7_&ȯ 7.FHvGY 5JȎ W'ݑ(=Nb2L]] 1ÊM%Sě/jo2pǤ/݇L{^i$e#nbQF%W9p{0 oG`;iCylcz N4۞'.d[(iԸX0GٻWx9a`JYz ~y|Š+oGF&b2rMաE&oA#l+w`tˣaEM#ݳx0GCADĤ\W{>m_n$>^g|UT#ͽW@~MV1T-ouOݛzigXOfy76/4lٛ3u-&p_5=Z1ݞx}wwRs SIN f+B(RпGO__(}TbSTۍO+ g(?no(9c=KX wܣ}ti+鄏V CSo91&k̨|A{z̙ci[JoTv̡ y}q$Ef۩*^-SDchtF>X4<Ͱqu/޽)N;ix/[fKJ+RDIs^H T U}İP;cbg+H1s n=<֞VmƇOˋlԼgWsXÑ5zJB>WlIy_9ݝ Gb{;Ť ֪.d]݋L:`3*́gm'kz0|w3o2'1S Gn:}O尸dPHPj>1QlB062a&8+??t<,}*( +L.CE*3tG1z}` b3%x/,+v(1AY&SY@*hgb閠w{C}Ѿ컾}׭mݻ!7soohv6mweW4̝;¼zЈM wATRy5M4 {Ӟo40Y mNW53]pǧu[s f(WXPE) iS.-c }0^nź-*ǀ]ѭϮnwա>3jNv@&P_9ޚITPyf^{}oqk/o4}<wwIz:{o^Uֶ哱#Zۧw}QTWBZeE#av;F=T}; P@2h h M50d"3U?T# O§{CST)?*n`PfCqR@3-۳SK(?[8)?KkVb RpQ] &U";+qKhsr"s2 e0.] ]a +TEW2"?mcFEssFJ6i@V. AE" U2ڍYkEd/ՆS޻v\JʎOŊƨ֒ڣ[ab{lL$K4q4¯5z$/)I%0&T$?!)Z/[` f1]bEK`s kFX 7\A&7^ޔ)8|:`&F?!Ci o@2TM$XM&@a (ģ-A(1@ ߕKȕlG hM6{a^HhXXBDw.zD!d~?uݗJNj֞~;-F -%,tX5_S4pT}Tz,S i' zJP!ƱW'>X %t,.)@h>n+Hu @D=&C4OK+ bwؙ/_~3o$/AC~A3UYtuD@\[[ܣ} 1_lKs7QUTQ[/*R[Ui(ڣa11Ai:H w %xr G0mq4#IwT-eɞsCj0ǮXtjmޭ VR2KtFڋTjemkQTlUXѵ $ER *˳kuMshP%Z@ 9]t"";ݥ}fms53~.t+-u/ !mq a1x$YQJQ=\' 4RZ!C4F{rڮ@РF雡IBZ1q; uφ3*Xp_S'rRdS嘢6O* !XLp0d@20'}/PVՕp"]cNP ӟ֢#0ewGLSwywp|_uR"s" DO? fHSD +J,BTТR FDD9qZBy]W{#B{MLCmdv2mka_;"MSXT_wcNB = ,w̶Mq)$FH]3lv%2ڍC6VK5U ^J0-TQwX L,@b,EnŦ[3䶅QF:J\6 hcfo*ukSzhmF-zQl hZ Bwm,HAK.od>d$ 0`dDx8LI *Nr]w@[`A5B77r7wv(߭G*s=d3>dPW[:M&!+,:xxjdv5`ޒE/}MfTXv|Lg;"s.083d$u;t>WIWB}k` P?a3+t$7w|]22b;5Hg~[a!k*!fݡIh;1>ح^Tԙ %C$a$Ad)qG"DQu 2N;;Oe] q%{aO9ݲ:;NMݏM{alzOR@u~vj1)EZm66TQEUP9HrވE$<׸um<.1N  3o 4\k7dZ"-Dʗ9c`ك H#HE=\ُ0.N9M,G\d,"ё1l73 duJQTw/ϵYtۜlAM1Gh]Ix8||'G(wzT(nM(J 5A RˁM$ GT;!Hy ӋUF"2"0IzRLߵDhA/}P4utL!+ ]%-h_GV8A(@b% hK_&%)z^-ݸ6o| -T3jrx85G /#.~MɃһÎDAV_@tl$m @&ՐbxeSG1B~ 87rTx{SPmug`׎{=2̇\8mB;M'F$T1B5x1"(e6QDQEf{[8+VSrm@_=`G ؀! E/<@~N(8>~Wh[o8DOgY0âZ.3M&g 80+/&j.0 Hjy4Ekw| c'UJ9YZqk5r3߶9\P m|dm ܥ$@,=k 0*bJEDN"yFexAoW dXyFr#hx{hOB&+s" x‚QR\QMP5.Zo̸xS)Rqa%>.B16$xfZyG_=8yݪ1Qa )8`C5ٰE AKAa1T#O)jLi*gJF 6 J-b+fqGǝCkÀxkwak&:^{y#boxv2(%j)(>xLpb?_߽8j:~W">d=c ErLUvR^+o=]!LTtKy{z E:23/^!vH.m)lVFJ!JPëCqzC["QmIi()BnjL% 11ySrB6JHmU* !g%½aVM͜'#G?o*4Ct>7 )gQ ?p/ ,'HwT= vϕKa(=ր2lt+DJP# &OtȀ@5{@ZXg&,!*b5ek@O7sGB[6fl샠KgbypII)|5O Q~R/z~?}H? 4I e+(֔ bqJ+eFbO68@+yFdA|3ҚAMA$;U %{w:WEIY?ςWE67RQ5%j*%+#l#II,jL8$bGMKKomw5r{ν0U wA(D[XQ߮'~xBm$@fkl/!zy4'Iy1ٵW5 7>nid愘sI_y%$&5kp}"Dz>8E'M?` D;Sv:ޖ@qD.n| 3PG@Y0!(Vvɔ*WN_0uzQ ܧ%\$&ߍNkQyIUyA91E!4Dj!khGB\Qb·+‰G3;!,5̂"*pHT{f\|k8lꨚw7WWU=L$upiv5c3Ȳr 1Pڴs=ZHj@dwQ8A!ORbJ(uB =\o,4iޥO$!d3K.Xš_ߔ3ދd&p|:C+n,W:Ey_/DӍVbI G F.^caۚz-g q E28S[a+4`W8WM(R'7ITrU4P§5pR< mH%w! K?*)򥀈[weEvD1$;*/uG[U&]HU)RP \.oLJi?ӊ$nBavrVʿᘮ4δUL`&ڌap(N9+@"O>O~' 42I&C[J;.6:籟s;(Ek$! hI.>~躺81TFYm[3м-#($l4^)@>u#jwE]D@ ! ~K}_@x/!xdᩨ 0=ӝ \!72X5v)v$۳P˵ry! wn*ʲ~A a FE&~f;ZSPjU~f" @RNf<9*n:_%OvuI!C,sa ty?ݾ1sy[pJ]!&*zl],0JY)H r6)*:w* %PopB""v f,g ]¡ithP2J`x3wF* K JuCR3VM>(t'!lg1r:BP=#MFS᷍Ε6A ,ޙAA v}'ID.(!"H<4 7SNF( [qU;V#eY`YJ"vS';Ch+BCr'%ŴDj׮@2|bg@A3ITD@x&qb,}S2h Mƪw!ɯH>+}C`cmgWnQ@Oj#YvUO}㕃mId'TZ~Yj~Hi:"\[Z@v3t/%\VT۪H됀5-js vK2xTV@<֗84<1:'}_M{vuz~,1/Ι"|^?č_f]vco^;u. ]g[)i) |^(mמzgչ %MX2T!tDRmcR3gHIĬa(C$q  sp"J@|BjDq/:4q$C "xtS99!`Szu7XFvQArc9pu"kZW]tO<"D@OF#uj2tRr\ ۱ϖh~!$۪Ҽ!AYk,>""@PUp<"^HBA$$&HcŨ"ݲkL؃sE@.e!M'*" ,"-x %6 4sJ:yi Ѐ@@d%'|smc&T`U_e񈑒SD(U$,a1Jʬi(5mֿ;*,mUV[hH/nalҋ-vJ<,$ٰ6 W.T]*ҧK:}+gZ=l5dAialCYdLLO9neYaf̗c,[uTlM9e3uJUIg9ϭ]&*M%SM{1Jr\%GLl=qnN(5F߳U /k-:f'If@։5λ.$ZƚoL#>2WFVAZG-pbtBEAT9'x㾍Ts=6 4WRu.zfI潔]$~e|>uMvɆt&3 M=tjɆp&nEB!mlZuDm5O;a†LKttYJO*udQ1g=xUQ 1vڑe#l/IWgv5R$IIu:)t/\1\cx3WMuZ`k*]Qhd)dXd0iWJe;2Iq*֩b5O8,*5a. zK rL[/1.}ueF _Svc0$ĕ&ʁB54z|zlɍ#R08>#("H$maU Z68juvV]vS Iu\s@o\:msYl:pk$;i\rE%4"0D\+Rՠinj_E^Gr5KׯAmkØ$F2OY,bc -V( j\rW><ֱi,RN%6(nekWâﶵ6-}Gw#:V3L$K&TS}7V`y5Q}WZ-N&iX$-YhI%t9ѹӆ7ihkekmNu.)F1{x֊dI0)^k'gt1eź9'>9;YGS> V܌onqqlԟsϖWޜ椬|_ ÔB8]lmz-o;ש1m>)y>tgKq D ""0>Q \4i+$'$4#_ι'G\XDR6_{|P^&hd)hjF=,kyd B]՞uk99'.<d ۗ`Ҳ9s[Q -vF~H/9[<1{۞,3^%o?w{/@"]iEcVȄ)ZL#tqX#r3Yzehñ==ٮHcr`Wѹŵ}{VN5Jp]<ͧ%O+*i32<4n> jM4tW-[Pj{.-V4K2S}OoIM8ƥH4ӄzPҫkCd@1&c o[(W zL4읬s*06NܩU_k2fՎ󇜘02[v;7W:7!ݭ_ZoH%~_.](~M-$牷a)mJb'6{jӥN'Ᏼ~JazlStT㷖5i!Ǩlqx,[*WTv.clڳP$~}ď):W=;2$RԤkD 㖧ԂnD릶(mjARQ=nZ% kA:H\zZd#)Wiyk6~Vml,WcK{z'{I%c4U7amιP F 'IH8row]jbTRh vhiQD! sH;w/=# v];Ou+/?Nf@&*a=LL-eλ ,ӯ ᘠ>*[ 9[ ȩ!$) S׏oeyrWy1Dec`.G7JܐllmەV675 <_0)L$ $ ( #+YOmp8cCPJD&W!K);qz*/0QXn 4m|/sv(%>"Z Q C@b.Sl<肠[BTc*POwNpĖ kWhER 5*bǍo\P2AV۔Rl8UB jO?d6H)i kCa(e捵|[ O@TgT "(gjuz,A1hmcҀNB֗C7'\ϵI'yF/=g3Aܒ(X!H#)V$@Nxpޫ^ V<\(ݔrx~ДX6k5.]`Pt pOG |ˆt@$Dq-ֺ}*o,d;0vkǣL_7s|@HjU[l̴w<9`ɂJ {%'MA jNh^l Z3Xl 6@ѩڣ>zUL1>H 7BDBВU@:lAڢUG@~\ۦ}na HbkjY@U}E68br ,($){1?A&_ yOFD̻;LiSoaop:'!m$y̔)AIaJ(i:VeV6j鼻VVvh78@J@'PB[8Yb%m_Äχd=udjN-Nv=Bˆ(/!(N)"Hl>a!0#ѿo0 6n8 "+Ȥ9,SWJ;!E[f't J*zyTDT@{PT򲈂`$O ^9p> P4(<Ƀ`:Hi!@ cMACxja~gp'KV0/DʳUXj|׾+$Vu^['.Ć[O}Ed!J#sُxʔ5$>qmZƖ;'PaISxMz;>,dZܴw UC,ׁE{(>-PiUMʡ)< eèdmBFp,Da/_Q}[X4b"3"=Vvh }\?}atF(ŐkSj3/r/YQ/ѭ2_鳮4u/c?1Pu PCIc:v9MxD{NT鎓nqI? Ǽ;,qPkP,<}9ͪbJq+#nE꾿s[y†m3<6ՉUn΀p 2 }?壕='.+wZN?YTYنY qpW6B^1JȻ+51D-qN=hC8ill鞒P}{ E) o}>lU1^N4x :zVq1z.VW=A.-:Jw,h`uLF7k }2wz/붵ӃĒupKyb! *E<ڥR,.ߟ!izqԁB5F6!'㎮jev{[bw5Q.b'<{M-xu&{{z^ϗqYM lC"eٍ齌))[Y5AC98AUaBevCʤM#*+Sd\ yXBe~*>ܮ.7νaҊέ?!AB@3߽KmBu\&+Z{EsaD2؈qeeؗR*nVwplMoŰll&"m&,4ILlh>.~\e֒ }Bu(k+>/&.PGPfUʊlj ux+o$m\ځhR19)Z] U؋M w(^"zʐ\t ϱ^^R8gfn=7'tB* ҈7DMy {;}nogr}z^W(Uz1;~u_Gz^_11mk* [qj6yock c鲢S_o!,L>/G͢b&i-K)-,e/; i\Xᯝn!$=.u`B@fa1 Ї!'0o[~be!vA;˚ rE,WkOr3&O)0E]UXS9K{0 M X)}?۰[eaָ:Sq:mT 346l[g?2H>s3v_hTR=u`觕:d@q$ ] ٽ풮^* ;lC}2\c, ^T X_F'Ix/칹MvJꌲȡ@"#Qz5_=O>hm(1\ALb'>&JQ [- HQnN{ٸ,NZ~9b`@eP* DAĮ1ch ھ J-.g% gr|sU&(mEg[S@)>6 oe~R܁ vt͜Pqvyw\ &D<㪳^R=$ ZΎh,R}eDW_x^ߍOLAQ3@mfѪ)Uc f*S<\Q)[eԮ7`ƌi^;ZE+L%#j2]Ubri\["ɘ rbCMYMju-:hmx)X, (VXo`bPC4=g"aV~\qd ANJ,80,:Z{gI5'H CWfyB4nrR^+7oC JH"2JUqi33U$y@ R˶;'_~c9^L#Bو&Ʊ= zK1}];Mҧ8[7 5P)*9D,# Fjd.o<߽5ڢߘ! X<>7{&}W׈r' ̝Qo9`Hz(T Y؁̠#`]g#(Dè\LA{[rפդn?7_e)Pi*frk$66BRR0bη̡0!9GevWwwkmbꑻ;Ka7uk-;ۼm]0tM "" EC3屏&-wXt`W`; ԔNnw#:H=k ߁$k[AanHQЀA|:bɦ00_*[za-2u UHmm_JD{7sPjt]-x4/;],kELޗM#miouB I8ڰ"5ohbĈq-z b9tU,yg1Qh@!&97w'hS[tSӣk8⸈_02CH8ƒTҿoyLBT|}hj@(2Bc]C{Y0qFPruGiȢsҳDz+*m`gMF' Q8>"Rhkܢ4\i:ӕCdrfq >ǖqH@I(j\!- ~j:[Q槖 B 'L'f 8zf^D RR ;s]FiƲ6t5/·=΀($t4"4$ؒGb7L/rJoE"5Avm-2!٭"N튳fv7%`-H&5{uZHRÊ 3Cl$́ s]9qc8+ |!(P7jrm2} 8׮;nP;qz @b%I.֖ѣsu8` ㍳#(jQT5|9:Smkxt#kH~kef@M({yhCnj&* kɓc[&3I.]dvʸ<"brje:)Oj@@R6}"Hx]$xRiBD m L.~q g{] 8=Ӓ)JUW^iy-K±FQ46~:ڙHZ|$y0t ?M)^r=DJ+8baU3+2'o˘k*EA M@~2$טp;y_ @).,{ QGf9s'"D_x4VHD^oN" B! 3\ =d<;WcK ԁ|zzYoPGAӓAR"ی_tv^5<gpsV$B6CX8%p *̂/܃'nnF#2"" 񩉄@dToޝd7ƨxf(̳:PH>utӇqg x4Qϼ JVj2ڂa4bU$e@)ХV~F_GZW mm#Fc6]()+c̓[!ǻ5jM} ٌ"ߣ1(<X(8WI lb+aQuQنVs``2C; s pЫ1b GT}n\YKqToHYܛ * /OsE}x!f^IHOo*4*W^9wd{| 3 "Ne$C?97q\1@'7K jHo׿q[pbnt-=ծ.FԅizՊUƃgVW{ 'J*NCuZ~"XI#n>F 7wJ )9c J$y Xoy̏# ry;CdMCx 2}>޻x"HPv=cR' w:ޫ b0$zbCT ւBp8rx6FH>R*,+/;SBP~"hDb?>O7?>ԇak."<sr~t@nF>/6UUq\f*&#* W@q9tyzRT%kFѨkj*6lmcV5bZF4A3Ūr:а';c* #dWePbz@))BJhlljŵQk65U&kX5mVj(IQ[XQZ6Z-FFUV D(E)F 66+&VXh*Z,kbEjZUkQTYV U(  )-jkm+X-kTmlTkj+hƪ5Rm ii(EhQ-E-QZ*lUmF   DBUرѣFjhEƣj-XՒhF֋V**--Q[cTURhV``D)bѪ*U5ڋhEF6֋j6-hZFJA)DT"i.@ސ;HzTD3$ .a"UȍPXWUS!:a6pr ʉĕ1 xP#Ppm𱤾wR/O9%F( X5[!څ4ߚaŶ tP"HʻZFhV5-bQP[TTmKM"P "G_ QD2!u b$IDݜ+-#7Q8R*>Q1 33b6\B $& \fX d aHw2S !P5B89%1dUի&Z0)11Gp }Am~(%‡I<3"PP`oA{3yINv'i!X꾾GRW?j+MOPϊbր8qQ:-{y_>(N4 blɟ~E4o B.VI}cKfhmə 0qcrSA`(4?^BiOxx*d'ɄP< 'ܭ^B ;:s~eQ^_U|6%naV\e3 :1|6~Îa1 !n{S3o*vhJECSd_cPp3*Bh*-mcbFDkF6m$ڌmlmK61U+o^;֍(Јe!a>Sγd{>z}k=z >){~NaZJ&3- |C-K5kFͭQ,di K*kY15*UZeF-cd&[mnRmdcZfMփcjj"I_)ݓVMlV4m-V^vE^|%,སAxz0*}ZCSwX_|m2l0(ţDj5bJ** Z:o _* v<~_Ǡ<Tm"w+ ~Oyf1~CXR@9=%I~CN˼.{1;?]}"Ұ>Ҫap䮽k|X|xI)Z74Jh \& ױp0|jXILX(QzIܨ^4zLIJd@f:f g 93HG+XV7okD*Fb]~ ];ֆ.<'}3LF1UI 9Z @5DƘ8V-,#|4Z;>cm2,~,niOW;L?QZoʘo!2㦢poOiCER2Y|7woox 4CLjGRh3yTe?846 lm4ĵpշ>{WĻair2 h>A B,h$Uy{4x[(nz/C_#o}f| Yn84J!uԠ;W/ Ro JB`+s 4~-ci4X|@H`A=Oˆ_qz /;{NǺ{~hd-!@"STTV5I-Zh0UjAHD61i6-T,I4U龺~<裮Q̇-#~"vJxx+ִlsk_ L[lKCR5t''_c_yy~G/&o˭sh/;y`,DREDQM)OGQu*#{ʺZF;M}Gh ~Odw}NфMCBR{YC}6;_sp2PA>XڿZ4րѨ"iQQ/8ɪI5kE&)MQo[E2h֍$UIe#llQhe1Ei(Hc&f1Q&,%Ll@TTERXfH)>V>wOgmob,1E*>[zJ E6Bi"(Eխ6E`ZV+FƊZ VXъdRkH}wDꀠV)"(!cU&&ؠ>xE4է\{--!2S-izEX}ޝ+z\"1eb㏿fcz- fl _O4YzNG0h0;|:vaqiؿIVGɧWO&IZVky,dbQ8RqC"w=Pݦ!p( R1T-"wGg?"Epl<Z =_ pO@m< /c@vxMx>W~W?grx#脁F]D36#؍Z$l6 #QԶ3z(=CMOS,kۖ7qv.~ꫣߕ pc\};{-S쯢Pt?ۇ p2r#KAE&("6a1F1A,!IEFE3c,b0Q`26ƌV4c[bm)VC *e@a65"4Za%64F3ؒ 0d* #Hi(Bњd1F,Dm@v>s7_k*q-{(hr)!z=v?Rs>w="J^2@(&nd l)Gn3ɕ gؿHI~#-Ao_/Ϲ~iL.j@oq(E3.ȁzβ1ut}/E?핹]8MΗ2ϩsiR"k58fgoXiғ CdBL}F "f`Dq{Φ|}*20s]ޤU]ִ]O{?qsqRRМV~1M UL?e{5 oT=HIƂf:Xk.stdrB?Km_HFާ[. |kVoU OKkT"(JYik"(;+tq*o*4%1 ULq>SF(R PT[4Hl7.L"W+dp%8Wccj*W/3|,y_7xCWS=3Seڨ>'_9|cPYrMpL:C{6Í›7{=ήXr9f<s33ƎFE"TG; W(v : Tͤ גn:m֛}],ڨ"(*DEi(3CӪ%dgQ \0`તHV'/ũxZu[}a.T(p @H1gyK$U7%eak> B~#~~Q 2D$:|^+ #VQ ҳ@c_˔:UWeSsrtDa3pk(= P& dR*.fӻBAHݩJ9auY̅78/0:Xۘav lP$Cm:ᇜmuw׌{'_t/38:/#78`vVmZrdl=4y52˖/[Mi\lCx!lmڪy==yh|ҽhun8}uw箺h0UTƸmAQN+ivQ唑2JQ* `8T dqF\[(dR1"ۖ&LJdƒvT4LoP4 $`Ɖ`c/Ο%in&q۾^.twxSךSpn7  q ުm#.O'静_1QNov3RniV&ُ6w5 _J*6[wޥ1xCx(QkSFNi#vQY_KW[زH q+װQdHH=/0`jghU7,#ZI#e<_Ch`8iEXrlfPgeFI6gs QIZI ɤ]P0 ֌0v#gly֜dfMR4jjN N8˟D WF]x2"c1r"asOfE3=?237] Peaұaˆ뎲un2#&U"ȯ"]z#`q"7`뫳/90b-EN@.A̦Ӈ(!bUrDq#fwaQW[-OV{N\ZPk!Vj]6dr3‡"!nPj)@vQbڸUlhCWl]2NlMDvN+KK "z@[MEF r3Ӏ`((_YId=XNyI1fˏ,/j lQ%]5sQzܤ GuM6NGa8i+mU*UsdvhX.x N$u5x}dUno"5 pgt4K]My}.m3eC3blAZAz(ݧIfĮ8(1cvlyc~uBvkݼxc4gx]d5FkCu'di:mWRo6Yh1 N{innaqB jvmN c…]! b9 N{y q'tl#]9eqiHv5uR', |6ݭ0h%lM3"7߮41Ztʏi?MCm,h֢.6iwkѝ nwmͤ:b7LƔ)jNi&r$ kǮ.Ɂ,zZ,$I7vUZo}w@јj{vVÝyS/W{jCMHĝGV:#B̼sM瞽5t zqjm% YiTgve el1Fmƚ"CI{xe}6ruLj=0ijbc@k}{uStTb3\gZRG$ a/,"@Na݊ lKXo Q3 @4R^V]5Ԇ2Jn ڡB), V7et1Keք;˭^71$:^yj܈L`sW޹e5}3Y Fh~E$ؙ*,0_VI ,!UKZ'yJR#Zܜ7N)J,F%'i<]za}eWJ(-+(I* hU(jUP[L,GEK HX $H|iHiIbWUm%P.(((H0IvDbV܆URoU _554Ur}e4?R{a!?R #| ׀oxOaXm7sm.jd+﹛'O=94_gIȂڀqFz??ca|\_̓}>>WiOx+ o7K 4"9 b?աm im-f΋'c aC"*§5"!C!64a5_goJ{~/YEOliO!zBZՆop?u[өVUZIp@Җ [QcW[ gVLkXm'oGĴ(66nV$&ȔV@c(t$vFEgƷʞw]{5@nA4OVxZQD#0cCq ĭՏoJ&7uԼS$*lGYMxl_Z\hzQEl`&԰H{:GrǛ8nZTiY" ֫,iKv^/wGẻwNܛ5mYHJPLy#CWaL`J iD%TMX@j!ih&DMJXp05TSQ87 XPm1,-!(dJQ+$e.kchm'3ӺFμۼ71Xq$DƁ.m;%cλZ{YʽQDs zaN.w`D~?Ci.<=8ch40fH0$n&dFP Agz4,shLęr&'iʉdQAl\ik˖*gWY~lZo>f4UkomWN'@_Iҗm{3pڏܾv]>!Q &4Qb,Dld)-,".(̔s o{oxa:tJU*i55=S[]QQfֿ2OtYiٜK1vcLkcCdXJ"3UrP U5f 18g hl. r_ ^ZT TX]'PӥrYˍ=-^վGc%$2 M1HS{=3dw3H1n&OԲ!PMLQ@Ћ{A4|ϩ5UTMX\݌ !Sk_g9\/ѣܷ|7>G\>mP"۹Z6)Pٟ-_?/8罯Q`0cЂχW$'_>ɗJ2ՑmV B40ӳ΃ 'דS*Hd`VU/-1I{} 1IԱH}$`z]L~t~ˮu e'JNjD3\*''H vﱦ0Ֆyq4Jm>֖C2 HxkIpKu?~襚7lj}Gؘmm 3SH^kyN&Y͊ރ.nϵSǁ]x_~#5Bjeѳx'3ĝ?+xX,:=4QwJhG(LQhB f -[E*KPjʰOjƬ^9ד;o/r}ňt(j\6E?_WD(AQ3,f<: b5oJ@ddU;n";-E(%ږQhBTq/.Sݐ~ B2E4nlW'muɘrA !rlokK*^+d*Ãɽe ߺ HK& #}5 n6Lc-naX,QA潶kG5(A nxX S%TEVET&rZ4)Fh4۶{X" J4E?E˾omYبJb_wId A(ђ33%`1!sl͐ȕ2oy>^J0 İw6,1IjA%Т*T,A1uc}dHPX+XaM(RJiRPͲD3Lz/ol4 l"[%&Ȗ(d1TI̲XM VF@IDLH4Ȣ†e"%hQhCIDPJfDJB1eeLb Ml,, QDLYIA1PR_tbdd6)HfB&f-d Fѱ "1TEDjH6J,h4RIE!4FJ)ԄDf D+&dبDdJ̡I!a4f0lGkز!2B[S2`M4ldŢ1E(M*L*L d(sA`"H*2Idl̀eBbhJI(e0Vh6Cd1M$DmE$a1L&@0FfILd"` (ARŨٍ TR3 6 RJ!5! S3)24iZSlPf-#5AL1 d4 "bXfFY& 4TP$6M)E[ bL cU eS# F@IQ#d!)1Ȕ/ꂓd"Q%2m3DjK!"-S &L4 oo`"dLaBb10L&IC a$@)E,Fe^ 6E=u!4 4L҃h$#ρȒc6IBTP%2`"dQFfc$)4PbEz/ybd4`ʾX v*b Soq_Sn*||JmƗ>,ZS)Ls1;,#q#1b`޸haP?/j!v~>>>{3)D_ׯ,A.Rixo#b| +!VD_v 7⏇뽦W}>7Be;0N?B}AQ^C>7NyWo س c_tǡA1+L]4 ? gzz;7ﺈh*g":+lWuIo<y}xc=@rPG}^&HL>P"x$Ĉ' Hh({7B7)J"uUCGL\ǹSР2V\8jIьT Au,%`oN hMIIΎƮ# ˧] Z%@z>$rq#$@vfu%?wcb2Nj4U_]0oָB 9vNa a_Vǫx<]LOə(??kAN J-}l($GGMƕENꊽ{~.B\Ovy_?3l001![x0?kzfS$G}Dhp8&Mz)lC^~&;mj(T 1CAY^Z*F>gAu>dzͨ@-tb4|_8rH(Yl]"˯3k0- ؏e]1EWzT,Y(fȴ\n<xp>$} pot #3݆})6OWϕZSЉ(CyPZyuDf4)Q;Á!sΰ@`v/ќ{`nɆ\*fe;pB1z[$ф;8,xͳ^dPeHJS dЄJ诊=msΧ?K>Pi%p>Cy]ϣsp@?P ؠ5m?*wKIoy )SXΨ9 Nu8aKH jGzOk7YlzSq~Ks^!;9.=Wf%KS%t(kh__|U72檗:.<&9*4HPDS%KB;FϏ}ƦM%C=l@^ćb=~ \K&O6!Z"ּ\~n, ð*5B3gA{v<6wgd[z2ECO,j:ax9/Pom"vfޫýx[\[^s}K'I6d@OĖ=$Aj>o㣺?aL+1iD 3)Q1q{rq7a^ڼUjwHOq:PG_ˤ'׎kQul!§^cxvs;1otk:ǝB2miu5R {L ̕J9. L(t1;Sä1^y8#,@rȺ7X ȭQ_3NгCx$ϕ"-$ ¹c{i;a_ S(q.9PjW)ea ma|ϮV<-VF ^L,!._OE.ۣy;M̊j䌃º-T[MYf=83JPW\Fy-fθwޯjFe66AC(9N;/PNi>aë"]I&y}%0>i:5 (MLVDUU4fP&lG_JR,/^Ezmo3 Q"y:nkS5Cy^K_N~t5ky.z9pͰG3—dpgVDd4['j3mWe[\1:(9+9xEzo,]+/̷~ 4(#ߟ2@+Q]u,&!a,='W-"x[Q=(Y88XVZKk}~*{t!]+=גLKMsT/)7M윽돀eA}jCR[) 5[۱ .8{Fa"7k2ѶRJX[I}8WrbcFMwd9=b᩺O=+`)KCX'%>L~/PI!a ND-ImLr~Qij ꡼ ?^բH<vD|ߜ+FPhXNnU焰vU? ]2\$4,Q}PVW h !*?MAN7& RpAeKtH!oj/x4"b@DqD?7'ۆf|vжJelԣ!)$M=,0Ae?HWZ.zug.֋Y%w/ KUR-cP0ַd15|7QCصss fZjHf:p51rt.U1R%ZV&7y!B7d  QEڠz']VRZ1սӅd|۱ZhGFn<~MoGһt/8c$qx z\NVjΝl<\Kk?%A xGb25rRf!P)m 5-E[^t'"Kݑi$!z#-7=? `!v뚥wR:C,MDh48a?޿_Z3Jx킂Ȍ,T{i*֫qSOa U zioDtv=U&VNh ;^k ?O?Sޏ%qy"/])M:9C+.-% !z,:>nc(}V¾_0X8ɽ ?8;9J1 {7rX#"XRj^Sch4&Nr"uZNoG4H bsVoԑ[AKaLO44Xa!ߧd1X!KX3V;2}ˏ`UIgV+Ja:F~A(#-f@}%}ҹRwz!DP|Zy^ rdn?",@͐v(7_wJ}ɹF3Zt =X4Ey1Jc!UTj&O~iѱ~d2D3yd~mwL 4?4`9}!nZ(95p Xc9C993-z***b&61'Oz&@M+g06ޡx;&oWר:O#H*ܟ18Ņ"^Iq<=EcS&aL{ ^/$0Z/%?q vtX\b`xpw~U,*9Tę:? KjQO\c޺@6d}FNN-"aR w'vn:~ mȁl K.=|[uc,`!57, C![ O?s MWɲ1fJ]׆ƶ)|0Ѥ!3+s<5P-cڢ>"YR ,}a vrJ@SJʗgqQĖdSAp+ CiĊgfpsp ) @lbj@sA ݒt|ZC!.H'np58\Yȸ*>k2bM[iC@LP30k D"HCxȠL?,9cg!Y"5?P[M[{s,h[^3 dJ(EcP9ae OL( V3[wD5c[`eUhIQGwgVTD뗷%9v8E^<8s{,M& &Q͚RnQzIDEP,Ґ`Kh K/Gݣ=K! 9҅yOnvatٿnרS(RК~35pAzn_8$S{nX t5$nԩ\+ * B]Z?B)o <{ 7=p*UZ(>my*"*@ƒk'崸[zG_DWg!C|EAJԔr@{Pg87uýLAr_nSK:.XjK*kCo 2T.;acUQ=y)@, BNf RTJFkoT~&U<%ypNdKm55R('[].DBso f/&ε{},4_iM!iX hq6|Z/ E/m{i#"Pz뇽rlMe}O ƚY5{Zʬ<:'t?»0n+D^RHU٤+G7)d+;ccg}̈́gVY)*i\MٵLaT(@ANö.Љ w1B+0j$M<}D!x9{`=R+R3s6V7,6rPfCӱy -j @mR$OZfN{Fư˝SL=la3P"`T'2y%iATio}ߨ7)#?=->CQ6!e@^#gg>R8,D`۸Q/oᢛg0o&fY .Z" ?ha!z`ixGwj'td)׭>>Ҷ*P&2͗˯&X?\e|St~;_v2~V24$}qΓfWyx/W9,O}\LFuv1D>q6AMwld90Rmj+9.kI\>]R3#AS^!ԩawώ"#oH&Аu.qb~HLJ+#^n廚b1EutX!SUo@lsOϽI`\*0(L ?FG39768 2*o #*:)~T60Î0EHK|{@H!8f6~ GZ[~y%v*x^Gaü8SpFkWC3Wį7L]6Zn JűAnq6}ckL@G靺kP| FS=Pq=7J{ݲJh,@2S< 2GKfҿ$2>afd'Ј%=5vzӑT7'j3VO]r΃|Z|X"yܑ߭Js3fUcWL{!ꧧ7u > 8ѼY8h@4bg$tfCJiJEF56CZ -gCa杴()kȭrfӲ(vcTK,͐%eSbmSSs̪ (! 28t;k t)P( QL)Q*@+R0O cUIP],ww2߿ŀkwc@yv %3&ߝ6w֌jD ;k^V#cOfTxW d$5ziubST=/_0N5d9G%$Fc(+tpIjdmg4^v,uK@A τF6ps6?p>fk4P F(;i# sW{?)3htԵov(9.Cڋ,2ЄNDzdkm(MG6A"R䟥N{j&FJl? :Dl0n{2~]nv9ug pǜ @^ԛ=Z\;o=u`훒A ?fH_+LGzjsk?dN )(JpcaQ)T@lލ(ݙEa.vw R':!FxGvik!!/ԼC3h6}|b:<%(Ʃnٔ[DIhZMt³XKcӳI< Ǎpf2A<́3r{'zPhgj6 #&# @+8zUlw q#p|4t&Bs[ {gi1#ϲG}jh)F<1.XK+q\ X8$uoh_}f`{) P1B@́Lcl'0'X)<W ;lxPYN`z'\MMue^T4i4/vIW uks"ʚT=ٹf鲓#RWI${֖ײЉsoπ|u&rc_z {7KkE/ </ęXh=9p Z}-(0[\ê`k0qкىp* \?NdD ixZf``BAhzyd/ 34u=\ upP\0tKͧ=Xj3FX90O|R= τzP,3]ʹ8\%U1dUYPX5Wc륮_WpFb= ݲ6,[ ҊI,0#z/g{jWs_1CF^ޟv"nF2DZ=UmNiIs%m5 6hBc'4IX9s)dxWOj!gc8tsNXSXPC=LL6 ^CBL~[)S8X x6Q-\&t)7ڸu}(˛B Qyl.Z"(,[wH_@ vw:`gmJoA)z NNu(&wZO1 zh$CqJ ÈsY0nnRiևX! p/Qe5F+ٿ6V4uxKW"d,!&6O=W /<+Kop@P_ͣ}LҮo7{:Yж!>Xwk?5piM)мH'4U(0?F&ly夭٢Il=1/+qߚnbBP@iB]u:jE16lÕޢOƚÂg쏶>B:DqqCL ?Ϗlf$4\Zy2g]/6*xalXm&3 gB#+445Jiw_b^|tF]IGBƚܕqr3e`v-]g؏$nzq4B5Y΂ +<}[fK^n0ldZQh'u~Wi,0Rx`۝Rr:H)%Jvϫ؉'}X8 3M`Z^,i ] +4 }g'T[=36ϗJur5wV;OH|/>{Ļq g/"4Y]buV{phT.eaYJ'q]xMn9+S\A &%1O"y*># .˱T΀3hJ΄;sr? XH䝘sфQH±4 ;4fxFRYVФR;QK,b,Fa/ /:.N<{`c'(Mtfl-.WBՅ=wY}nf]8:"PF/SvEs;4^eH6!Y~EꕘJƂ6  nv ߯oHtuקɃk''5>U)4:"9gm. Ef}V͘^Yu0_UOq0#fd'C[;D}|u=HH2) vKZ${c* $]6P!꧸1vh]FszAyD<=崌2F [e%zBg>zYﯛ <Ѓ"gPoB!m|VE4J 2oz]1÷S r9p9|4QJ+(UTo~<0ԂBItnA Ϫ> ڑ rrbeIP,ds0('؝B3 q$C=9)3( [ b|_^˩ lcC35 Pxɝ%`L0Ixb46~݉FX`,syQy6A 'hOU9Hxf;&ȮŢK4A^ Ju yt<".W_ǔh8pm,N"½s*`ez 8f8JSb1Rdž rӫ:+&v)`b>JmW"v2g$`ł,\G #4\^ڈ&=ZH>r] e~ڏy^|B&r7N,5&2%yoWcl\ (1<7CPdjm{e n/v&*_S57bTd߰nAlU4fKkTy~SG䪅tǺ;,BY,$}<,Ŋ -g2+bđˢը}Q8{`H) oCcdg,6]߬@昁#d M3& uEO7v^B|A0k>)$4 A,uBc-6k2O2i-@ _ĶlWA0'oJ5q0E6{oyL\d,0i՞"õ}ٺz:}@>ڀM6Q9S W~Z;V[ۋAot|46c <%/ϊdq`s5mN Aࠚ`fMBF]sO^  ̣A[ &V* Z0L ):OVB۫-Dmt&O|6& ^5H! ޚl=X ;,ĊIͽžLI$%O  _<ێBQw$ ŰJ7WNiKM||x_QlY1GжTK 2*m5 _e19:s۴paZH9oUnN>nE< H#Fif"fIШPߒ'q޳W:*f9; H1q)}h(q( g:9c}G$6 πW Ȝec09 yDpeKA7&B _aj v 뚝sEJiQI:v X|DTuvվ+ 5qeq^wK te踴ҥsum5+_GoȈqKa:#ݕ22.9|~K_RML}4)=+tf CZԆ-,Vi&^n\IzV-Pn?RY5ruL `y3}/ ?V!7f !:#YAZݻFm꠼fҠt$̅T`UC~&Li_]ǫu ;)} ?=E?ȱy82PX@ڇw_Ngu_@ ֎\HOԑT}W,G;e el[rs7Us?>_PH#5.b\ Zz5 5},s&U?ZJJY47_S3RWu<Xi* :nc@W_>y}e"K'== KA!iE MGg6Q\&g |K>=~Zz*gn=?W.% Bn\S3ArL@rd/^%=±Y2ĕ!ф)36b~:ֈ˟hVpjP蚉0f7`:5؁lfCy9JGV”8G׿w|w8_8xW$? BPԹ{L?үJ91/xdRb>W]ǥuf-`L  b!Q,D>r . NڙѓC'Ts ۃɠ\lO @3d7\kǝ%؉x7F/n8fw( +tCna\ڕ>v +u|+KoT圊6GH%KnFk)XDv3.8&B'ܙsAȴ BTQSi6zaI(f99Lt($Mﶝ C>˗IsM85eJ$h W۶0u}._BA^&T>>7=8U5s*ZRd'%:#|}v#Gɂiv{žrm 4=jgz%+QW~Xt, [W.^7Q{Lun=ݽ !9B׃b ZuAr a墸LUȨgO%"G8pd )xTU:9gyFOL;My'MBQ+ZWXVğu,sΩ"?pΉ[kRSދ^ެGsE :y<\PКN+sb[pnَ,9 S3@Za~]OvxP$1 !k(9 XP'_4djIE;ãxAu5{DVb/-;F8 M{ljtX[}A-B b B1PIf]P=eyHbN_\TK"Œ`%߹T8`o\ =ɞl:7zXbFZȩߑv޷Ĕ~{<݉-`\nw,v^*QYAi-5ྊ'/S=[BJ>E:yb~iUU eWep^aCˉJ9njL-VE{/LT^x2GK](6,1 ߌP>m9`yůŎ{Y2"{]s-ST[ wv},%T *G v/ 4jO]3೛=$=^A䜑!2P]6fd%r15 og)VpXϷa?#cI\Na8zIWP)mL*FWa}Ue*3$F1 Jb*XԱgڄf(o JUꑬ ;\E=.N+ ch uƫ'k1|;QÎgGsrEdHuB;l!#ӷjmC9t:7NdBL)@ny"I~GLGO]8ۮXFȟ!26 tys!LrMC9=L]O?̛G>z ӖT|ˏAQ+xf۠c?48J83)|y#]]ƠLLq{GV.Pef\ݘNDe\lnA/H%5^.:¹;9CׯV: YmRY紆Rҵ拂P{1e.ؑFcG_hס5nHQ%_^(6U"bEiB/EZڕGKYX/QX N\t²NC^\oG:By{3RK dnsx肊Kw9[U6(FMl *aksJޙlfөLol`V<̌*=cy^ 7W l>k1G?䕾G'o#A 0˝ rDضb(egx{߼|{^-qM3xR6n_+y(FV U5yY16Yqu\'gV\2BG=h~yWMukЛ ZSP1@ `^kC"}FuK%㦦1e®ٱ* 3Tuۤ+IWzX>n6fdXHsL'd`],!SDp=^E+g+K?ʪr :k=yUL.[[kn6+~-}rMkUHjD%=\7R\#Wdz}~`#e[؀8(Й>[w7?ɏP&w5ݴ@5v4]O2B.ZuQ}2RY29XhiP*@;|lR"F f]o-y˘H\" \+n#X:`KP,n->H w%gm-۩MU FOiNfM_q݆&V$ JPСه3&\?+aM'l*wB9}]Z5Ge&Ҏ'WNXѸ8#%dJa^sYD0VgnaC}[w痪HkXLWL"$ߋ`}0c],] 'כ0=iL`ISHlm^il!m;~,@0<^=3^ne֕wa7]-7Cw{.1n~e GeO'ܾ(6gLnGiOztW~ %PnEaL"69KXLh?bv4'xKg0~N1S13|Rnj‹nip77nNHRui۟9l2"z; ?ydb>ZWE6Ec>ϻINd^SuRO-a9b3&ɍW?1R? `oSyVق=xzx{MuUc.lV&G0333x2?!D$KQ-2>߄6!f'\Sno=STt'4_ ZLdo[rn9`HaQᡖz<'m5+7Y;D~7&/AtvPڙT}Yf޾ŬzB1GJAR2/R92e-JT'-Ũ3 E#YrC A΁kՖ65Y12~Όv= Ev 04'uŵ,ѝAq`GFq$|< *n!`a a!˧xPX:-ms52Ԯ$wG9 [M!dF&uGy1%?Z)?DoRLD€8š\7L9%a̹[Vv߸a`?6Yp9( q>ؠUhdqغCQ"jgÔn6/dNlؐ>߅sbkM룮xYAQG,ynT- 2W8iIt^Bç>`SL̳3>PaRN3-MPEp1`+ʢKj&Q> Yv|<_e{pohS| LiAxޠ^ |%?⺜SU{g8ځ/!{Y~ YKP sMۛ.#r&J]{^H*RJF n|*g{!R@pf>N f6o%*{Q`}_yd[ wj*R{<!q*yʝɑ3CnJL{0%^R2èZsgptАqWa~vˍS>9++R'Cxn/jkۓGix/vt@ۢrsr?@'@Mai*iqy;!D.+ۤa)1Phd.'B-e/&fqW[k/ҝoaAKQJmwDojɕi?YG?"j >4Hp"dnn: ׮29c*~I bh\픯'ϣU|NyKP+ƽ~\68 ZITT9闅;Ve1uE7=dm>c@fFA&qZ5k4<'1 ˰O_tЙt"<2ح&<@Úɡ}G C$:(qOq" _RHuؚlp/p#7.j*œKt6_' @k|؜<XS aȚ?":K4?Jvn*bUCb^e_O}04G9uД2PDL <[׌5r:?E̯b!5+,nn_IBΑ=SQ<Ì)M''!c;Z[ɩ14qT@d%Qvt[MG&7}ڰYB˓RT7 ٲͺ& Fũ^p28 #McTG;6#my}$_WtƧ İyH`=y dP;c6P-b8smUEl #  sZ3;GY:R GnR}mw>5`[4l!`Uq_Tj j:1is'/JB e8jkDE/ana/զt4F&[6Sڵj @2T4Uv@P 8ް=0;+ydʁ @ІY0hjMO^}#]v?$wa~X]+VTРKHnfsT'e! o<-!%Dn~h;+U`Dp:yvT2]AT3؋bKhО:1%w7mTwjp#c195 ԋz ȊD.t/抈iՁ7d`>)E}YR^ 8bt4pm6"'4b'1kXHl'i60#]Z5vzcWU!Ex3H(`f`io6>Oㄺ6O][^94O(+;uAeF\$ycWelOw_9jJuhx3īO Zv'BEOJ^-<ny6jFءkF{POgYJ~VSѰ= H{۵zw}H~0Ϳ,Η _Kdę#eMg/ָ]8@Bw#'6a{ M2mi[\8^߷- 5$w;GoG#c=g#V1kaF{l*h h?;́cZ].ی;v5b@7,N~}!Eܣ|F],sN@F”xi:rTYmpMH[y[Hlq4IoL&/KjIsP6]~{U+'jm3ll|}f6 ii!޿rE`Rĥ{HY6&Z ! מ)233Li5 6ĵފ,wgg4ϐtnjஈ0Cbn>ΝZ a26 ߥ&w$3^?k1HY}FKU4\ u1vj"C<H?%9_kva̾-pO5Q!Fao\ǕkP@ǛEjóDo|/M{ߦ˃kjy}mg2"A:OZ)UZyC bS!'(#mj̧x"kye5aȍOuQQ ^ eN7^g<؊ȂA44#uvLV" Kw. b4[r]])J5v45BWѣ̩KQ(yV5)샨6х911ޅG-rD-\ZzO2[@9tw#&{^ZL7*'el}h'_qVϋJ$]-(to1YsWz4M(dV+XQfPWjeK ij/W2 $Aco8z2qepKJHtY3s# =/n^sF)됭ᇑlp"P@L*Mg//n,]jC*zgC g9]V)ZA$Y.2 HRp])d@nV=c`toTGr gm3]9u ytk_ZLEJFCz$W"mNFUp0|Rlc琣yޢ &` ;pid܊7e1qB$ -jwX׽2V+*'vg>x^&1:x쭇c5[zC/Z!N%h. VZtp \Fl).uCb^ ex4i2^-ݩi&d] `@wP"!&,M gņT A]I=| yr>FBa+h({,c z.DzE%ck%!R@  3wۨp^S6.) LqNt+"Y.@6In7}(P:a(-Nwoh%cB6_x.ʤ{[3u}zfX%_lUSs`ab,s J4哽Taz1IO]1K4l)"TZ>1F _B"8~lGhbկbM@gT\@ ATqR]vpӖ]"?|zv5)V0 UXrk@I%kDw8ʉV,HdžߎΣ1\ՌtF/B[VBcgc-xeecXrK1q%K 3c2 ]5n]Qqθ>67^O '%znC V(,&nUkrXۮB0!h<7BdriD5DLFf>r(a|WAʵ <,|䯻}RU0ډ]07Ji`gC^g}a;2*b' ۇo]_质u޲f.& 8%ogݏ:^1RkES)p]DnXaP,1O'Ev ZbX*L BQfHtI(qu{خijwjѪxmݽ?IkrD=sNA? 1cߕFVZ ,jD;!]\ǝb0SZ$Ms0Z0;0z㪞d,'I^mKƃܢF )5jY{pa}'_sWv .T(8̷Rɦ"5(I;Lfsc0> K=Go؋kV9ӋKQXd^f)KW6Mʊ-Ց u*:Ie:- '詄e_ ̙O2D!QolH~nqUNY="J,,d[qHT3Fj度V( LSx_5ZG࠘<7lQ~Us{ȍݸ<af~*Q,`WsP˪_z]ciD]YʎboAý9|:V 62Q|>M }T]{?] ,a[;Kp푁 syG n-WV 23/F ?W3ܽA?ыM1Gf{F "PjY,QI*Zgjh]6@!aAO'{"Wf273gq7˚[PnJUshZP>cv'Z# 鲿97"I,U 1{A:2070 oGAhzzH& H|)> 04 6C)kh<D`7_Q}DZSi 1ֹt\v>Sםf^R\G"3(bO 1Xj_{8 fiJ4`zQ2%?g&]12a=7{K95F?F]a:$6KYk-B(AI$1өNzN\8٣y%k'$Jr3nƯ&y՟aVFw|9 ) I;1G!҇6|ʺoA-8ąhj 1_߷@B㿣ot6j܁d)XWt;Qd(˄2Ô6$2dBDS(DҶD>{X=DhxRѫa|7}xvhuYI6LG?3YnNLsQ~9虁m,;`9&sX$42j/Ze{ {d\) >#+Qi&۷xDDŽ&I8W#'MQCI4B9 eOX /z][ ?_8,(=^ 7erUG!vc*71" ~ݴ?]@yGq29QTCTeWxf6YQzp[TARo𥒲dDqGYd1A^3Kl)嚌'YmMY|,CA(gy!nN^45-^% o]=Ȯō7i S7Xph B~@+h$/hfJ„3 8Ro> ~E$A`y 1,U94N'[ E\Fv fS.؉G$ 7]k_t`Xj}{\]YT%@ERx[y\@ik(P'Іlj 6Jk7J4n%|}?-4kS`q (&#!<v,1VpF\iZRĪYi$Jb`l*WЅpۮI!5Y(S-J ix-_%FhMQ±ytFP  Բ`-Du t-`\kL hpCMk>God;]P%F4X>=c=]Cv$ ;ߌɍ<` ^X*\)D^(g #źCu=ޮf[}d\.3qU0C/ g&حہ tM@ъؘ'V*7ќTŪO {視hȚu& @ UzQnA )cYsQ(aꖺgB/t-|UKoɇz#c45 ƞq+@Qz_$kVml~KC6hݐS- Iaȅ?E y2xBM pkh" LKCNfÕY('E E;