samba-test-4.19.8+git.435.78ced6cf30d-150600.3.21.1<>,hhp9|qVuS Rp$VvEhr> zՊz7PrU@B<ښdkJg[RvT5 {*D:hVֈ_؇vb}S/: HR hb!^U+HeꌆG|(`g#_R|.SN<[%v'U@, >@?d ( 6 b -AX^h     *p 9y(:8:(9?X(:S (>X@gFvGHIX Y\h]^Sbc0defluvwxyz(8<BCsamba-test4.19.8+git.435.78ced6cf30d150600.3.21.1Testing tools for Samba servers and clientssamba-test provides testing tools for both the server and client packages of Samba.hh03-ch2a^SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Applications/Systemhttps://www.samba.org/linuxx86_64B(Hh@AH WՁ큤hhhhhhhבhבhבh׍hבhבh׎h׎ce8695d9dd87f4ce8c59d4fb3aff26c84707ed4f4ea6da5b373ad7a54b8bc8c46eb3f26a225ead1b4e98d2f23c8ffc665e1ea6cfd6289803e27d3cb7b8b6821c3d0762ca3dcf2e8e6f8390f70f361d31f4f95ee1935c5e09f83f8e776c543464cb8436e7acc45f79a9d1aa66adbbfb540ea474628f411dad590e8eda986a68b634157efe083fe7d134d77c953512d537332e93dd76cdd9a16dff2373cbec481ca14d9255fea48155b033b9c15cec1463c956d1e0d0acecd37748b994415edcaa99edb6394f7f0d1953f7f1ed46a26e7407640affb4fbe5a52c71c77e88cf254fceea340e463849b14ce72b3a4b32b3ae756cf981d490ddd69f8eb17b3414ac8e435405eca06f4a24358cc1b3641c15f9a5bd5268f631bfad264bccc8a05b86886aac5e99dfe5b2489592e6a01f2ef44084354af3ba1a1a423254b42d9758a25cd19f9937cd854c08ce90ab4b5c4dcc7df1ce5bbd26596f042e10e78a0782a8d5d4bc12ef27d3a49ab1371242832e20cc50c9f4afa6efd321f05cab57e5feeed97fffc1ccdd02aac8458b57b86a15e6b4e5b47c8053e4f1b99516dea8754d04e06d09ae414c733bd6e9ea1c3272c525ee7831e23ae493dd75bd47e5ebfc9588d6rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.435.78ced6cf30d-150600.3.21.1.src.rpmsamba-testsamba-test(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibLIBWBCLIENT-OLD-samba4.so()(64bit)libLIBWBCLIENT-OLD-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libRPC-SERVER-LOOP-samba4.so()(64bit)libRPC-SERVER-LOOP-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libidmap-samba4.so()(64bit)libidmap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_1.1.14)(64bit)libldb.so.2(LDB_2.0.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libnss-info-samba4.so()(64bit)libnss-info-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libprinter-driver-samba4.so()(64bit)libprinter-driver-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libreadline.so.7()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-net.cpython-36m-x86-64-linux-gnu-samba4.so()(64bit)libsamba-net.cpython-36m-x86-64-linux-gnu-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libshares-samba4.so()(64bit)libshares-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.0.8)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.26)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.36)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtorture-samba4.so()(64bit)libtorture-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.435.78CED6CF30D150600.3.21.1SUSE_OS15.0_X86_64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sambasamba-winbind3.0.4-14.6.0-14.0-15.2-14.19.8+git.435.78ced6cf30d4.19.8+git.435.78ced6cf30d4.14.3hҋhm@g`@gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%anopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2025-9640: fix vfs_streams_xattr uninitialized memory write; (bsc#1251279);(bso#15885). - CVE-2025-10230: fix command Injection in WINS Server Hook Script; (bsc#1251280);(bso#15903).- Windows security hardening locks out schannel'ed netlogon dc calls like netr_DsRGetDCName; (bsc#1246431); (bso#15876).- Fix Samba printers reporting invalid sid during print jobs; (bsc#1234210); (bso#15792).- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigh03-ch2a 1760090087 4.19.8+git.435.78ced6cf30d-150600.3.21.14.19.8+git.435.78ced6cf30d-150600.3.21.1gentestlocktestmasktestmdsearchndrdumpsmbtorturegentest.1.gzlocktest.1.gzmasktest.1.gzmdsearch.1.gzndrdump.1.gzsmbtorture.1.gztraffic_learner.7.gztraffic_replay.7.gz/usr/bin//usr/share/man/man1//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:41070/SUSE_SLE-15-SP6_Update/5add5f7dce01a5b57b4b9abf50b932e5-samba.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 4.3.0, BuildID[sha1]=5e53c6ea6d061bd8b410761e5938061ae5856a16, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 4.3.0, BuildID[sha1]=e1757d3baa0909b4180d8783d1f7fac77eb9eba3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 4.3.0, BuildID[sha1]=0da2637aa067c967dacbd48522d607985c68ce3d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 4.3.0, BuildID[sha1]=a96f01e01700a576c4cee28ac9daed09dc7817e3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 4.3.0, BuildID[sha1]=d383296cd0ce3c0f4d1a26a1a6bf6d437dd5e6a7, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 4.3.0, BuildID[sha1]=092caa9ab93a45c79539dc418d8953e697d5f84f, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)6i634.R RCRRR(RIRtRR$RRlR0RRR*RGRRRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRRFR#RRRRR RCRRR(RIRRtRR$RRlR0RR*RRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRR RCRRR(RIRRtRR$RRlR0RRR*RRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRRhRyRtRRnRR.RRRR7RRRR0RfRRRRRRRRRRR-RgRR6ReRR/RmRRsRRRRRRRRRRRRRRRRpRtR0RRRRRRRRRRRsR/RoRRRRRRRRRRRRRRSRRAR,R R3RRERRRRRRRRCR"RRR5RRRbRR0RRGRIR|RQRRR?RRR`R RR&RR RRR=R~RdRWR RRRjRRRRRRRnRRlR*RRR^R]R\R[RYRZRUR(RRhRRRRRRRRRRRRRRRRRRRRRORfRLRMRKRRrRzRxRwRuRyRvRtRRRpR9RRR7R;R$RRRRRRRRRRRRRRRsRR@RR4RRR/R:RRRRRR_R RRRRR#R}R RRgR{RRHRRRR6RRRmRVRRRRRRiR)RRBRRkRRRPRRoR8RRRR!ReRaRFR2RRRDRRRNRqRcRRRR+RRXRRTRRR1RRRRJRR=tՄZ3@Butf-884b84415e1e344d23a6fe3cac2f7877e782a1266c84a1b100618266c84388518?7zXZ !t/]"k%2_fR6mH> >H { Xo݁FXņA$OL!^VMni09_>"@}. T/ǙLd \p; cJl+(qv)ދ;2/T/i7=,m e^"StCI݁zURŸ=ZQ*dqDPWfC?㶡 Wap j(+A͟Zfj&ki6._Q'K5 L%PM  O ˜LJ\JB5&=UVYQ]H)Gs"V%L!K8C)`ܶ;!VWL xøb`qDN"L7"iV\H]Eicŷ,9񶐉x?|uE@'?Z+. jX D;"+< Bqc\*k!J`W} Pfsmj_$T"aG{Je?mu>|1E3VlgΗtFIIxi#i[x8OD37l% CO7) U&XN{c-6>&M3KN2sZT?O@2G"*k2 JI^"2|^C2x*m͛"# Z Q2Xf P ;!R1pf.]ЁV*.Km*I;r>K4VYM%qh^ h^o(#Yk`obu矑9z00tqD'g~6VйñਿQHt+BZano=Y+'hrx3\7dWu2MP8ljt7龝uǷK\%T>IWu畳<{J0亁USayuAȨ$ _ːȝ{S4ӊ- B 'X9!Ћ㙇8Q As p#زm =ski4fr %mu{w [{UxU){+)n0VԳ,H ]7 !0u>x,& 5!~N*^C&wh'oDQ Xj|kkک3pʜ] >u-<*d * -]8QIC+iS\y&xx>gpoA'j委omcsn2C>s6-ѐ.<31z| m2n ArqH }[U__}̄(j {@4T`pP:kTtJ^ li(`-7W 3  SC7in QgizLVPrR8sUEXFǵ#6P* ֭{6@X+}ig~Eɏmߠl4|G(~g4pV$;|3F,80IAjˆT)Y0kޢcw@s^Dg&s0*<mULPƧ1H1;2Uү\ p,{lTȎ"oڶFugb#g 'rkXeh;ozzcENq5˛{<=E~ZqK,G |A 6/WО(y:ozҴgU}ʋbj7rd b 2sU^9j2xҳY7%uzg'ػd`}[ޱ=C~ ;H~=SO< K`lp>}aO %*p#'M/O(;$%t Ali*:N/@'ᘥ8BE,]E&K=] @~SIK-yQ#|uN7 j C79ЇXۨe}7i#rcu2 ǜ>IV5Ud?0aTV,ҷ{-t\NJF>6˘<8{&2k?#-BԔY#%`)b8u|*5-_xކm aOs,Zc{`UB%*% JYҋIH1YY#k)zoyzMakN$ -u*i6utM  t*p nu䚛r umhw]a=i4WOϫ.:T|:ʿUvLAn Ps'Ku?2k^ߍ(P(Fzȿx. 5 T8>β5m ee0apr^'́H~,3 Yyu{ {OLؐ6@wMa8 A_/-^w^of}#YfX %zViTcK > fW0dv}`Ňt}c|FiI#t'mZ.0H 46DRW䭳j=kn XP[]OU0O>/o9;s::z`S]Y@nCL]8H`#A:D+R/hSD c \zjۺ2Xmnk<%a gVxcKݖw(E!MdCbV8^=K0o'xۢa~3K۵>UI=]Fek#AصBT/~HIOJ̠_t:[DJ;z$d#*e8;JȱRoC굍ƪ) ^~_{'Ad{7Z9CJ/+^'MԘTjtIXj ݖ^*2n) p$cxF2>PQ{:SWd0jMvH RߟOFOP:ߓ,w[\E COklě[,wy_{ 6^>K쎵#wы&c5޿˙l>ԗ-B"Qj `n}bc.պ3bIej8nFT֗\61ǡ~H%.bLd!UJ-#YVjVS9~Z[*[ )rtێ(T%rN?x:V`Q\zL*L .a kx8|f)#Y-gMXx;Cs^n zYEz;=aP&j]jo8YM(W&+`FnBz([?BG_Ҵ0Y7\k[zG1a]|FH׃Բg) 6A9hE=&Z#?$bb|0p>5EԏR.u ='iYPV ybb[8KqO^-{Ȅ^u}Q%dfp݄o~<ʚit0E3uϡb793t|X[8WRN1\̗e:7~3mԐh,z}/Y2чx`[VUN>ӛe3C " 򃛍`B37; sLt:=h\3@%NMte<2fCr+Al^2n?bA w\Rz?I8P9b&(ǣ3^(LP,pɯDe\뾸Z Ώ,cгƤc4ݥ~,C^hPi7Fmb;C<=dr]Z3븋DYN+A2hū+^QN1E(w$Hg#.j-sfBV]DB~QG1/vL.2"f OoM98fv:ВoBӒ)/8R7lJ|4ћq C}c"jV̒9?ya';l{E&srniqLoMNX|S^0i!=Ӳv|ܡE^CsN^-ĥh`f=rw(,7Zշ2U[\uG8zmaʛ׳g UEwVɤXzV+lz<p+#(Tf JL#YלUG= ~TV䒊oq8 D'?&^R_$"c Ū8H8tW[g04l`Ew^.97MmdZOe\PḦ̵QNцb\7kRз>6Rd>aJ\uUa7 77~UTAbRc߄p鈦 t ?bcQbzN4VTOs.u}E-Zf r}0xD%&z =7G1Ojo["#`ډr=z~$9iRP7_ |" rp|'Tw2X@M˺If(Wo%BxՖh<zv E΂G*LsIbU! lkԢa)vO#$#fziCCjivv&-9Jcrh;EP`KASPv3ɜ {L ׏]Oq J6B U㳍dM`Sʀo%DOdGy~{(_޼Ok >} wnvbMB,vNDp#(t dҽKɜ e\ώ*p0$]G[$]_>haD 11hF4#ϗzy9.);+gj3-,7+5`:9,aD;7fǐ>4Ǜ~[BwoppAa&Ű&ttQ;9ǁbA-D%yq,{(&}sj <-:W=~_S 3T$ɘh*i |͜$թ-?htV5n`tW7I|T6ƁJfH٥iWKWu WB\oqSYr㐚UqFslFap&uҵ;1PW /Ba7UNkm6#'"W,Q'lG10~g8%a?]c,%OJCʀZaMThUa.l6aXýʧ/B9 ;;kI/c0$t(U|6'Y\CHvJ荊[^]De-_]o=29SͩfejJx|1<Z*2DT Dj8H[G&^`6;- !W,_~L*@~inTd^@y ]%隕p9i IHݽdQM ;GoNVLA`ʐ5t vRjn뜠FRV«h[)w>DufԻJ*$ k uvQO8Ey@l| %4DQ.vK-._ƽɌ)E7ڲ檯ȣX^0HףlZ_%C 5)|'g"X^D>v)&!U dQ.3&(vPn =UŤTv'r8ȉCj VQ|ML졵/?%?þɊ{0x}#ƉJnS:yȕl%Fi|Nz\*\V4FVߋ1ٗ{,2;9W=ZbCٓ,;D ;F'qmM.inb ,ɫ L8jb 2}ۥAy,t+ݑRC u bYX w.vZe?7& L>/|UZ:eG#fĝXP&PЙoh%2u''3BeU1fL;9ڤ>VC7REQ_nEx 0-:I~B@֩g)0oW~+GY8W*NX>AnEVK }&k 4X2G+WqG wh_ S_%VX%eE~aCOk5gz2Q򁆊t~:*[d 1x;|d;P>R2' iQK<]n/Im2S׋gH՝c_|O!D$?G;JE׏M>dmAUcDKb$hȬVrIԣAWNy`H⇻$P2B~zM9ٔ]kp5ŧ/Ωyoޭsxh> uGo|͢^:QMl^uƪDYMQ"-;KGW YNygK^( XBğ1z*W,m$nXFT_cM2b"ݟnl(0d[)N0X+`PKb d{)4SITD!IYPXn o5MW6vSM 0<{lPF\^vaY1^U OfBgeoUxf0ccE:=A&Ah[z }.i((UKܫ?ks]Spͼ(Z̃3~7EP5yf#F%Y,;ѼU LJR'3wG]@ v[.Ng\Z9Y~ig&SRPH!Ja4+n^H ň,\n)B7z0 88C.տQ1`6^FL;- W`RHf;qG\%tjddXmVdoO6ЌoH".\^/~= .{hh M-LaQ5HS Ԃo |;xwO)#OP6ܐA uT7YGb23`<) baDz ,\eBa^NO+(V'nN*j~xBa`rҥɬ}#whXt!qXq> Wyaͪ%(D.Oh*$v.LH3ۅNCPNEn=iGyPNsQS&G.$&mn>t@Tj\9aDڵڦg?RN]eImFu R<&^`|k'FI{%[Ƹ'e@N4>M{ ]^V|stDIj2&yiIʞj6ǭ >uAߪ1bʍ#D1cJi/;Hs̅36Q*Մ-Ll?N0C}U 6j]$J@SGIJ|ƹP%{ԤjxME&qzǔٹ jlW!ea`qŦ IprgGnV8I&g6G'1p\$uܾ$xD+:3)io"* <9ugSJ\۳/[r͉EKrc$s{ P"gwOZ8qOmOiQّ62AlY*֖7W[sr֫@Da3Ǖ_C C+>&?/\IAuP%с[Es[W`89ȅ[= I$@;xqZ0ET77; J^>^wV~?)RE 0+L=l*raʡ)Z`qs:Ls;sdԚN쫞Z1l(TBeN Ai|nzE݅GV)x$VFi/-UCd]f;Ĺ*d9 pxEvbp8ζesJn-,Sb@s$·j'GFG!~er>Hʙ&N7,c0ވ$Me0F a2S) eƯؑu@yb ft7^'>6ę;!YG&"(QԬ7)\Z^&yiQb+sj@p&БE!/+9.^\ A35Eѯm|8eW+J,K35Zޗ9`aJGkaX|ZTj[MUkJBjD!_>g̼<1ɤr-dμhδQ/f7T9ߓ"u8@/؟ۚ2G)%|NBpM[P[Me䞔C=ԞAixBQnIC濇!(OT,?8u'glD*+zʵZGC}_UyZ&i褶cA!t 9duC#qgcsv,άmy[X 3A }!ꔴ}29NOFuiibyl6c]<4;Qr+#@FA*@q["0ݎ~F7hr`+v`Ujc]1؋4gptP * |ʯ׏Dqj1@@52E ,zV0zYMSj: U>vZ8 f;qĂ֖ؖ8:M @CuNBw:ہT^~a~ Uj'l:C5AE߶VA|?V%%y³.f];WTeΧԻ*wT?wQ҅'Sa%5&X"Ouvd -YOVH="Ω=k*|0m:Bf~B7{؈WSp' ~Yց!ܾ A' .| xz`]EGhow e_:(ý0"Ф8΁sUXd;u2_] |M$epʫs72 »&e󰳇1= e)Ҷҝjr/hx 4ګeH5뛭<@5A[ %{N: kɯτ(Rq`[l}ʎf1r=@}V&r튏_]V)+e D**B4ĤKG 6TcW/B52f!hEs4`{q`*, )A0A~$ g -/sD{zKn#Jl h-dqr^bÛoSb|0;oWv"Jdu Lՙϲg[ + J]/L4M!@«mnC)NIФ5EyhwzXFm>R'6[KXgzGBG:J R5@S{gqDYی.i# RL0!, 4U5uDQu7aCIiӕ[ ^6jP\E s@NXGeӃiQW-4+K1o 1:ۀ> FeD*HsF?@ r_7!N k>O %=+}HVlx|Bi>G]bXɠ>)=~pK%)^eMka_4ʚ J%p[T13tM]j%dBWNh~@ͩeJڲeﯙn2-'~%O}?!(A3͵ 1YgQK1s[8\9BlC:; qw$6g# ir@ERQWg C^)358fu^Y#5B*LwSdžI3&ƾUC +4d˕SStm_ѧ,P#n>.~Gk[J oZ5wqjlU]k0oNym_q:[].-.^RC?f!uA+lYF=:Yv0rDcp Gu)8/up<(;э!p3€ (,v!2(;2($gxP`q)Z޸1|.+"Rr[%jo OEꖏshKƐ{g 0T!7'H-eXt a=t!HqR3ME㼰,p:!IZiq)F*Y3hyieҧXPTU{0C+.GyH3}ھ= ψS$dZF:x/1/,Fޘqet 'a ] ^#XDVE";Vgffxe[*Oec [ɛ; :[Ē(%eﻝg ;'Bzp%=T)mrmƈ@6EpS>/jEJU26(,EbrZM!<' qYL>;a EMh & M.R޹UHEJ^+!`<'~GSS˖_\Q 0CBN 2g.!?TZp劢%$ZV+œDįN*7i3OHKcj%@6@gE\|hc9cʦiU)Q X6[CuB7h}~:ߜb6kYV\ fWoh< gM)e>Ŭ2T)ľ]0 1_W0gZ{8Z6qVYoM㡯;C:=B"e -"KR;U9 5س^DLՒ;7 mFc~5}ې Jbg 'u6-* isTnkl-xFϖу^aWь8럞 @FvcX`{K[#eZ3}`OTB`N'JL "e_پ1u1 Kf=&U죎  ڦq$D"l/nC_DJ%k.sa&>$?Uc{nՎ~%D r J{y)$.{alڛ{O|#Go2%6HzA+ 7z<}"/9-MdMugpӟM/~~:5ʶqw잞s ͍PGȪ`3Gx kil⁦y/wЁb/3L!b")2hvV|"Z%~cOc{\E^'kyr5X,%jL(qO, W 7@&a控6KV6udGm!<9PJa2ŷ6Ysǵ6bq~5MGO=L~8 A!/o2[I()29 r&РQĔ4jܺh(3orj+QTRgXcqUHFT)7^H{[(ˋu| MP^eGe]- Ձ[Y&`K1ƿHLxlr%-ly* ~ RaM{T| $H!5^ߗ8%%b#H``F|FEy-.p)sIj(T-2Yy$Y\ԪT6YΤMS?C#}qH,yOiMCET/&pq}' \I@!@-fw"̬2E 9bl1JNÝJ_$f&GO<WcIcR_0+u0h.Pm dڕ5*pj) 3VͶ|V]5?[.tbl ^BYԺ Hǐy|'\*QXv/$CLhM:JV;4'-~%()qѥ#3@<4C7e݁HAw+|cdPW.?#MuVw Xb[Q*HRrE1LXWUϷEt"T18 HikϪ; nRZ˲}֐V1RHdm@}%F5{qLD-ױh-nzbS3}0j:W S⅂#d 㠯reOᦶ?W#1.<Vtjʐx{'d} ibAT'm~IT8O.[E.Tŕq/>8T`_I&rsۃ>2; t,׌ H{n~m\F'F;rbpoUE")J`md*>L8< J6R"W1HCߨ*\ţ$:!vL-ʢaؔ Z~(KK,1XTˀ mZ_ל 3ػ݌[_J5O YPO-V!\j QYIUyYy|&MMok^.*[39߬RB;wۮu5sFPT"Lwt S"5:s 4q \ҭR1=?]1,@%Z:QK^~<-%/A ԑ?'-XqRI-o+ˡbneb@#[A3c_3x&߰K1uZ-)V,%8AFuNBCvk65f q^Epfb>E|X^j ll3KiTH ke{B)v@\a޷HCTB{O`8g63ă)9d),#}+4%@:LUXDC,Wn+]d|`1a<@=dqF]WM{;L':4Un}oIVNDbR9dM-$}l7;@ u_.HeU>eak:-u aϰ$ʼn (yQO.#${^i*Y.bcܻ-:O~Q9Q|baAʊ3]BdB6s5)]W{ vPzL%#?ċPMu˄Ojsh%Хp&Yص{rͬ .0(&6Q*2-pGs2 0Pjg|"xcDI}Jߍb9I=}9~g}*G3T ):Tզ} GcNdG@"Q6@+hbmpN"aV -8[|QsPCN^J&mF ?w&SraH]v=LmID_$ $q6{qۑ2֍TZR[9.NYGR2O*c,J";lnJYH:R(zxRbZ`ϛlHX9}?dh'o|J;~Da XxӆI^1~}~y]Lj^b@N\m[Dښ} ӟx&-y+a4LOb@̆ +7ݫm{\’Y'-5]i@B>p;p3{WY͜t \ѥ+Z<'ː)rZ.> d$Cx;;?yz%Z\7S\~_Ib^ (\ j3mr?w02/y4_k"g~e߀JSZsˢ9_[OS?yɘh`Lh`h^EO1ЊۘN qe_ZL䇴#n,]Hvp²ք0L@gAO5HtGhq/wka4OH^]/t}@%=ܴ'fi#H8`a$3:v8vAZJ 2`*;RRV Gٙ9Ӌ-dMSzTx%4>62vZ@Z@1\圂ĄH6&w.dž*6M2Ύ $9kIɼ^]',ӊ`/lEwDY+9]W-Y̸oX 7LXޕeA@\TYoJ ^d V8b~=Y|.XF3h$ FS>H DQ`WR <&*cdGs-\DraaȂdԩf =רpxB7kefpB9Ztk0 oPn^¯@MniQm I=>4eM]-9E1@3;|=ile@뎚~ǯΫJz޵_q-3D|y.X+v޹)8?oђJq(V 0 )YSޘJHLe{Km+ퟙ3@5i %ǤEv%5<^4/sG"J|4|`$)_8U88slG%r̘bZ=Hlk͘I~}akA (Z3o.PCt~@nY&sohWc[f9tG>r@-{͒rJ"eg6h|vgxq9 #}?d|Éj\,;ǶLYꢍuOhpj[pZ?.l%ȱxImk SaKkW= 11ؾd&9Pt#YkNb{w{'\l{ A-Yv4#ƌ'~4l eXjA.Hx;y:tߤ8(EHvƔc~aGg]8l R'}O/57gSE~.kQ8hy7](3d?Ԯ;G^Q߈8 %Ct`ݼx .NxM0&Rp8n_%V] %h.@W)+-ԝk5Ay2K'lZTz]VHcgSLOr\1; !>D84Epƅ<&/Ĩ92'F^a+Uȭ@̆RqHג4ƃZEgB2ϰsNU0B(4@Jb#ry&Am[ F ^1ML(dX@j'o~C"--[*_T!~N 7aѤ ;aABq=9ll]-[͇Z=bMdDxg׍<%5[+D'01MmG Pgi[Y? ֝0O#mM=MG3 wb˄os }jpNReAÏvevG<zTDD30+DuF (`]eoth+=[9kw z|LO˼KΏ &:@`'JEBW݌gԊ5R rhy^[W^d5'2a˝!ÝOLRR1t*>9vvFsHK\nޒqJH̐ϛu7 է5Zdu 291&:zZ)ǷE V jASӟ:sw'Y4t\P[ SM΍B*^IP*ҥe:omJk`O0dR޸jTYt|ԳEEU |Z _ ;x3KhRΘkzH6S/-LNJ5><|R#A U.\VDq-Sr@3aFu68~[S-un9x"[*Kxݹ؈VqE砏PDk#pr>PN5t9{4HJtJTN23-z*g/alG7 fi֠FRiJ̭ҪbMX>̡:W1VUIS}zYY;TcS@MdJ(PÜ}M2 xniْ6svmqxzغX ?AT@?r /`6#SSrgtPJU8*P^t@RcJ ]C|6xy\~_|pNpAHB[Tb1w7Ǵؑ$]H2_0>~mqX-cFCv6/Ucڎ8А!mx^|UN }Loګk04I{IwfXsrQ=t [ 63%k:(|My׸Si JJa7=pƄ*%2j{L<}ŏ@|v'c]F QJzaajVi9~Su[dϓ6LhՄ;o|LĩY!zaX[9n2ωV:16jWg}$® @ ӂP B;o`zqm :oAaC5wmF|`Qy*[@["Zð#_7fٓaFu{9v@ b YE&x|mILyYȄ}qǹ' ݓܣR3[&ѹm !ĉ~dH=B0Jfnх:­:_M.'?4Lv剦݈tQ n eej3U)4Ǖ(Ӌh|MQuUNgީW񓄟07c}ɺ# Fh8݃nv)@g0!W$G'f_u}q%զ&kIھfʬ=3`(o>ƈLyGZPE"hm.P_Ev@nY!UO :8x'[z,-+ۂaޠ5 ^qa \)Z7ŧtzTNɐJCM|%RKqh\q@{,nt.vUc@_m. i}7VZrMjp,:L[(5e(M^8f&s@uLt@v^x~^KDabC+{C$ FM_YgZDITK }^ǼK<)x)EWӷh\y2+R5xbrwb;}ݑX`E G1ܠS 2Ziqc_a\onzL$qnNzF(} f(y=Z2et|.KK SmvJG؝0vap "zs{cyDzҨғNiE xTa/7{i,xW}v)S5=;e*<&It/X$,m/ʴ豱mH uYߔ QڋlFO1CihoӍI|I_+neIM'=PS`bf]N e~Pa̞}ѾQyݴzm8D:٪!=DL1dB{tUXzŞ #m봦eg>ҙq ?fww(|pFߎ}43o}0"bc3"#"O6.ҋn4pPM~^qAiY₉ua~lś(LZFP]sX^xnM6"+TkJߵ~WDBse'B ≈ ';,Bn7`Fge4Yջ]h"մ%^ƒWeLΰMѻ 17$&Խc"+nK=5-2В8tM(Aȟc6^hM;x ,ҟ Ұh &HrB8uтYAtl'vZJAa▅\q+hhP0>da7śK\q+YF*:>ڊOMb\>˾K{GYһ(1ŠRejggxbeIaσ׆SÈh4ߩ#q<}SF%LTGJgx+oەnzZ$Zs KǺios1x#mb8Gȍ>WU?_azԸWx r>-qiK5BpCq_THe8+t+Ǩ4_FL" )w( 6Z J10h.Kb+̦ɍ7J:בGk|7L3 Ce"ln8M^?E)~*lDpUL~H f} pobgyja$Q}-W肵45yYL1Ʌrm|*\XH "~_2VLRF,Fo^C'u'3 GEC8_àfjbRٺ2~+Eg1FsswL1k }d#ff ;>N:p ]'AA#B XлޱKρ9IJ N߄"@o/DI 7?F;>y?#/ aD9܎-;>60nD55z ;|-ЕUOs!I+=j]ϓ"{ab<&XD}R6Qŕq$)5 l2xhcOjT!x TY0bׇP--QSHGK& OHel@q|ĵAl$+`=rli_fīu*ձ^ ԏv fDc5pf0dv6Ng9~ȿ boVU(kh[)|lx`+_20_g|f3Н4F&Bi'PK3k))"D x9,\k'_~eJsOnR1oݢ̿NXx_} EIaĬTfo8A'}eejv_b|R! C4 n?Rlڥ/e|ב!9Q%`jB &pwZwPjbLkwХKؑ_FZy˼}B VyܑJF JsʸSIJs,yзƪueE9P!d3hb]z}r] (eemoIP dc-wQnݻJ{yY˪rf)F{ C!#?aI^UQ>>enCӼ$]OfG ~*!0Tǯ\1aU9c'vM%wPwsf56(Jhvv2C䢐i*v㊉(!?D ePAQZXEp'6#}vst]LgD ]WU8",gu!8r2CW2p zkcV`°Mq+lR\OȽUoC4~@lՂ~Cw0[dIPP2jw!'.60?PzE\L$UAqʼ`KBT4a"Je_ڛqи{/A_^v^z(Lc[hR %{av~jSEٺ@:#] <j K(.^˪aQ\o%\xE䎰`W4;lg4֞bbEwp֚7@'B[;pT|sa ~Pݻ9GK,LiXkT:DfWPU$g靣~#th|,_QLVQr e4*{nF>Q"}Iڥ`$]/ANǵN.յ)>ܞgC9`B[*_;qo W{ ssAR;L)BPag}YֻB'~}"d%B_ˊL<:H:vbL;,N6.UQI?-t6MU ,HL209GE`Ϙg15DSdJlSn2?mqk(t5M+S"_gp4k:=Sבx9b)ndZgJjW oxA)o.q˷ɤ]0|kedD]U!0o] r shrQ[GճNƃe)"2]r=M6tbʢn]0?60Ք2>̏WM(ILNOgOMWbo%ajGR#O(W~.(ձJT->XI1vQJs$hI,*@z*KyԷ2EhK(ie#gOjnl4֎%q- GG-}+K;`HB\]PC"X" ^":avf,="t #"I9,2Վ4k6v1fV1mSq;a-F6E\pY^ o`9L J /Y᳹l kSOĈxL܈'tyWOdqV)C0wp¸ٲߦ J~yblT:n`V@T&h~~x/*Ln[2,G !{`\3#1U>Hhs+RBZjDN M̦I7A/<ؗdCYv~|\l :ӜprY|qAO5nU!R,]dB^iSp_(1}hۡ93đڷ3V3ڬJzxQ~]iUI WL?8]ޚ cN\1&$@R[MnVig@+0/ '5`ZpKiYJ>Z;-r-;NDƪm m66X6&*A61@=q\}-hY&"ED^/4'n>!ټoBuP'H I 𭩉MEjL3Mcp7!J Zpt* !)n+Z#yV\'AఆxQ;[7G<-{f˖ҷx{#eeˁGQz`ZCjR}Y]o)׼t \Ӱ^W.>&cl,0`q୐ziҋ[y4&{.R\©m-_P5^7eX ho`^J S[H!r@+ i3ʵț=>B)|>~ #GО>1X}PUջInROK @ V 6#:L"Yߓ5_΍W@ 7Pl a֚ {m@LK:vm;HK:ԗtZ=ͨT~5W4=^ $\TH5x@N.ao _)130#4EN:}w ؛\zli7s֖J|  JiJ$i?Ke"VoC|zNoen{da:cQNK)9h([93s L"{b caeˉMӓB'` ql%1p4}8аo M[ӄ5sT[̊7c-HD@Y2$ۃeCn+b!E ǖN_0ύw$Y|UUMK.T=DMP'ZGpR6Ǐy㎻ HhXWD3 Jrޟy#}Ò @R޴tVZΎ0xz7c ӉT.Ja, Ih @&cvܘ)Ks,N >9B!-؜sF>¸T#.y9B$ 5K[澪>|rV6C|҂r,MiƬo9AQhk['R]e@ǾRFsɦN0}pɕMVfmA1gO?5cwI`NJEgL!D!z_EYWVU7ZīA vԚCg$I[4l n$l0QXyuM< ðH]78itc!=Y ⑏lnOT.vߧ͊$"ޯTר z=xc~z-΅FG\z|2ky==뇠+G{*BS 0}>1* 1W0 1Lt&؍A$]HYG Pqw]]81jp.օۯtE'4 ysEg]Rr=~Ԇ .Z{:Cq= /1uoFlSjNo0rZLk`[*ঽ'(PmF-HqUTv)_chͣCfZ)N(M-+]9-޴=ൊFfɶ uK+=[cqbȃ>-Iŋm9"kVde Vmbq-5kZ̷F1C^yX_dY{6 Wp-Tag 2GJ?AV&3ڦ]?4*(nOC-;2<ʍ IO~pvu؍A$S~d*M>ؓN!Ma{ b# F؍(S c%NSRꨍAoGq'2+Y8_Fgz cH7UT@U, qi/S_%)5MJI޻E?+!ʷp7+t !6ʵK5SiydPM'2_~vx<S#ďЪ'zwT%U>+~:ى_CS!15lUu''9w#6g^2}|ڷK=LDO((_^@xD ,j?79JnHl; ٞ jUt%Cp jw. &pbEf:u#||Y1#]S=/b|#}wV!+tNl;'#T_aўe3NB( _S|H 5$Z-9FM*C_FcT}ǧ4c߮8&Z!x-=!pa)Iޫ6ڒ1vzJf`Zv)u6X9.w2sи~P@?m]gn5cdYy싶.a'ÄH>FI q0&tg:򋤦`]nLdK3Vqpt\鬔wo}Xs^pȅP_[ M-Z;ZӦ$6Yg֢oԊAZMA6U%])*Ebfq`L;]p9ݱe@lyš[|[iiLUu{PalKrwC]#PXexeV = F|=~]Hw0hncبzRTmZ¿H-~,-AP T7s_~ (l;>8PIm i%+[ip[EL";l6@RgU c"cMNW-;*dνʎȳ9#,@|(_j([ol/F_BYdw;h)QDqf0˞t dE$@'jGئ's2Km9vޑ Y;}8"Wg *2RlڰKbY[ӏG5[#9=4n_0drL;}¥hSX2/~0ð҅S#@VnN(~ @[ = 1 | eDB}xhmG;~*8GAe8a4yaɴ4* %9 CFmo=XN*"9 }/t98SsAAXDe3@#R#~^͊rc{;~H4aK:6ÐmQc,ETNm;A>.s_9~W羍a;Վ_=?j[vCu:F'.\6\mX@N[]LPo1J*y~]w&p{E=mwjޕgrUyAUNAub|󊍳{}zGɧPW", zrwݤS{PDs0wI% qM^z>UYlyn τwU戴j-ׄ*>}C_G@rrrH="?R5|{CrLމ@0n-^:d/Ё 7F!Z*McG1n0߂nm{׿7~s5c ڇ? F[ivǒNӹ澣¿B}B9Zy%z52e4"5K@'ڃ,9EONwyR-<*!Iн^7B}4T3Z-ooēʎ%+f3u"#R1QENo?փ^mnF d;:oE5|T˴/%zmcځTcj0Wj|S[2a֔8:D'N:UbRcp4w[26?a:Hs`-=inWT/o ?vѣS<,du8Tׄx5h%&zu-6t\3˷:k1xb"+,׀\@K19-ae~+~?Qݒr(Fb4l4DVIز[?!޷s)d"ັ88! y^US>]#fgƒb qfAY9Ņj]B#&UM= ƪ9%kxbU#ӧPRńdH2pR|Fὴ9$@f,чCV9 uzAJAsf*S6n6̆zM)5+Y%YaSb+)r0G_6Dm@!M[SJXuӌg M6x KJ~_0&/"nǯ= { Y&iqwgAs̹pl݄.LOJ WO`;ˈnySt wo%Nނ5o=Ķk8胃ύsdVM]A/$v.h;>-D&ʌDqDq , Cዌ~>`bsNm.SeplG^ AAnk//e:E 05Evx6(}iox_GrP*ƑW6grqj㄀L8K~7/h!^hA[|9TG2զ^/$_&+ey )pA==e&.V寒.#o't}PAνꧧ r2R4N{K0E} /ܖ1~罜Fw-ۍd[ f>RS␧b 10ɔ&. VIX]Dbك4{t 2)Ӆ&`=+cyO)hk*VFcO|sͯN P0q8fUFj q;rʶojx-lU X9`6(YkK POR7Ƥ5O0|dj&}5(:Zt׮XӻNAm PJ"L~Tf >k@fY=Db/V2=sX[ ֛T 'km<"'5quͰx#O>!w ItZSD4* 1*=uQʄ0Gޒ$ 1388 ]Z"8'Udg3Ѧ avY+D}HeW !UOa|{v[%i@BŔ2 oP4:pM(Lrt3nDNΥiD0mAC[7M2I9MẌr&gqg4-MO/JBYH¹Woe>ux )kyڅqpU:噲PO<;0D ςO;NFMB |C :u׹&݊YYiYvɪ#tٮjpQV>2NJ.Z Oz Sl n-ە+P dpf(NoMdu&%kt#39@iwc=l<?UmZʖ(0S*3PpD8@V=(gRIn;C}\29ncnipHro!>mՓr uKr-ko<̕l6}4v1dGER~ "6nޙ-mk +zC`hܙAK{jFغˮU " !yًA.uʡEӭy#ӻpְ"ą% ג.C'.ZpyVL^[oFSRq4'GӏH*PX'}a{T>CPrǷoj+C4Uv eA5.It@1SMX!ҝFf#J t_ G~L*HZ֧%Rjd eOlQR8/)Pd-4~H(J<$  ̆z}yRSGTbg>Yw/N=ވst,R$b$"H]ýjOE\7Kxhwa&|T2OcK+`ʼn*(У߃lyefA} I3s_]vUwK$qKo!2q&Z0S㎯c9j kuM,_jW:?x(^mwhS=,[Q^NC[L`k]lO@"$> Ii:%La($>iYixnᐸhM=BD)%Y!q"fAXGYHi箁VU[Sm:F AUF3rݶ'UjoU3*JG~r4GZkRUD-jR xD _xE_)C4ˌ9 u.IՍ.Z7?:yoi~ๅcpCSa@)#[ yl5H]hdY[A HGނvhdjǛvMy[s*?iQCtHjSa%sJAPus(;6ze>jEbE ;;qRM"RB=%SijhqR_TIDaÒBLz&1#yhC ¢Fs+ce o!&Jn^aYOI7|S4qShPx6rCh1PSjM>`͊huoeIf3T4 ]>878nyo9p"=abf1"2#@-l+ Iz{L!c/@M`W&5d.VUX}%Jc կ6]hRwvH! (ZXc lZw{X{ ViJy%e9Tƪ}#EUPxE`iLljABM6[QKWx]BO;Q\ރOG_t 9$/_R\Qe} ߗB \*SY qgk+阹׉ ?E7 bQn|jRÑiMsV֚eR]4(_}X8$Pw?;~9Bcדm{< X7 Ngyax f=Y)7I3نumZpF "AMlD3./'{pjqw~'{Fftw]QE@:kw$wC$MYwsH)uתW| &€$|r^ vUVIcw]X# M#wW ilA)̹-$~ ~9 AtÛ%} GTugG9TAlR @E;,L?!c|^ Y_R_OR[JXOkqʀr1E je ތb'Ue^ǹUi._866͒fl8[ăAUPe!8o`򴆬7&>Nh9YlQ@Rky{WHr$-\N& T_׶2l+ZE`B0βUMѯҳedfl(5n'}2Eld23/Kc \_ސi,RgF 2CRuZ.۳Nrv'Ge EۗV8Z퐩dcIPo»H͑> W$ ыd6ܚ8p$#rܱnΨ)ćd hc~UVZXwP-/RPGUaDWk7/TtT,EU^˜Z%'1I56yWF3 :I1!VH ^/#Ào >6b'zK15\Y=~s-ޏR*E;{6]$l@Ruѥ/|>}"`p3ͅG)[hĶ9a9E0;'\{ĸwse ;l<8B7(dHl\^Kn~,ʺyG6WIWV7Ɋ|Q(9,w|NUoaľK6PwWz1@D0L?{e@F[ZD "ݫVdX[TY7dIfEx5W@!Z  iĹryl u,W?;Id"6|̤rant}*/fz56ZmJ !ok ',x^|=[wDƚU|7!kڙi-鿖|5r#~ G}J:qS-xcݧY@4Nc#0k.T b!hYg;̊ E>˭J/ua=HMD{ɪFbVqYYT5v1rx#+ٵlxDJB*M!|#M 'ZT!Aг5tλJnEʚPJWVM. !4]GŕCJgpHTZD[zi½[6:7XCZCuVL5w:}_ɜSa@ATRs?Ta; 1WZ}Shz]!;W51۩I샇&-2 \Lъd @^$8bI ~jӘY ^pp$M7>A ( /n߭5sLi9 |R_Wz>wSwi^|yDu pX'x33( %`ޣ2+jkT{f@zrۣ櫤&f{y䚥,ԅ7oG`({ ,/_-GxEC^ѕI#NZ0-ײN5BE+GPth/нvq4As>I!5p%z6`rq"1t8#G1mvp 䡏Y ې%}_[[8⡵9/zuZф7lnY!tvn3^p{/"W|䣱-IVn ;xd^gav q4SJЈ뽙hM*^nBtAxȼŁjqO#ׇa&dskeTK~xO;<ʹWB`e,q&f̵9 ?/<8KھLs~k6t'v=qp8Zi:Qgwg£!2tb[錇2V_kM!_čpK^ lm.4=>f_TR!ޢ\/p%zYtX49K2pWo_7ce.bqZ4pe783eSeY%` W'*]?s>'\357z_ttMojEj'p>b23a-QTKf͇ɡ *LvVi\m7Wp?F"S JI"4) XnJk9$k3=XI7 O} D}6F4.GA wg&rxe"8i!%7IKɒn3{"o}AW$aLb+s\bZӯ>a_hB RoR;1+,=V9%srG/rS辗i~UЂCX h \xL.De 3jހc gp\ZzeS+ $ tЅwPYO!ԵU*QuYYP@Ns/7D͇qN~dLE-O+<F/~syC-L \B2V(pKd5WgsU='X0h}`pEgb"<}3x8ܫ9EvcG>]:>7fo>֧؀ ^6lw0 [k,כjkͰ lIsi8B-AHz |id;b8~$#P9^U^T_x?L knfpf3 c JDD_/5ɺ_Kn~P 4NKhP:2C"8SFT&ze@gw"3ة8 S7 R\J!( GN#* bݽO"~`Y(*Tÿ0ZEB0?k$ y+MWuɇ^)˜pR݀TlbN6è-0ax=,BJq~n60&Rb=ˆ(%H̬]+ 13WC (+,8έ@h3Nuak4X ! y5Da%i\\ O6V~rw56ѧb C4O'&A=ir)UmID8lNni<|c֧xXQ9gDr\X>4wuzx*Ld >sö \XF>ak:ݦKjy;O¹{2: l{ShVCo)wP7[cST;B"|xYkg)5|<$'70]N%8PSv)fͦ# j>Rpk'А|k8FNSj~6}imSU 02p$'O]er6YIMf Z_o.׆rCTx$F$p4wV6@)wM*KF`"@VuktP)H+-iG춳!p?Oy?a ƍA95c_iJ*!DQt8jgj߀*CF$ʾ杵u̗PX`+&6*tw|ИeB֕Kt$Lڨl%olAt}7:XXCd)Prh٦xV)oBWHB>xR ?0,0\7@f|D$HHӴ\inᥗ0Iً] SH€nM [_-`,hiVU\6!T@>|ym66=824[<욽W4׵L􆯵؎Q븆[9X}|`_\DMg}+0P(x}@nbrde`,Rcp%lT{D brC;u֢se{*i 0z}E(dUy șAnS /"ȏdF)}#˸zd+7†, L~v%|Hc]o{𳷴,N4ko[٦1 ]7cdۼv1 H:ǵ(^sϭ]LA aPEM"uSב6&3N"kGMZ5A4;ؗ7zϾclF=*êiuk}0>Z{o>:s>rcGɎw:MD8Z qyLfL8L"cZL N (q_]`8M Җ|vl[[5/|F7ĵe[Β 7#wٖ|MdESIf,ph)#whh k?Y6/ {&JezW^`85s x?qRf>xi/hrTCZM$bHPbׂ*5غ_yꛙw%)hX7gzӱH@S@XCgwL?s@nV@ViNdh->pw+5\\} ɑ?blP&/ rQ L>iw LG:&JulRE@vvp:ec>eVzIU7RQf'KƣCV"gpq]5\{JcS,/8-9#| >g $-Tz9[]/r=3v7DUQ@I"- b4^x{&d~/I轑Wv&Ͱ4$[MI؄ؖG7;ԇfPpzYQX]C3 Gg#ZN/ӓ,p.!PM0S'U3uW|$QtZ>&b|i(=yW-)rASibF_ړVl[S9R]` B:;K!+΁V4("> sS%c'P FaJD,zORhdv)rWЩ @Òkg/,r+dwE:Au2|uT 5) v<վypPƆ#Ɬ)8=;f_E T: z.)ה@p҇#Tci;(\lig5X]pҝ<{+~ೋq(Cbf=X*, L>kqFO$8f³n~2'/EX%_iYq2'8D#~V%z▍}ko%1s":=:Rv2h䩓Mѣu QGYny,-~r ?|vxFs %Tbl]*/9?>S~uXX진 _iș&l]z#g5IJ1n=UO%,"VN/B _{oj *["_8,,5)[T޻v)dYrz8JrbYy0%AR /j+ ŨW$4Dhi&=I4j%E?'!܌BpZ##C"Z\ލkdJsRnt+Rm[{qڲV$<v,:3t=3me~v󓫱K3uQm~,"5b@E["EJ8k#Z1뀙y3C ʥab<)u+C@I[g9~6Ν"kAQ]m[R9 b}v\iQ{ jK3D"d qM8o/W;0mG.zq;JU;U b6%\Bh|"#XeCǻJΗ\Zr>lr5 W/." MP;*2#W# hWKpQܪWj;J"IVӭ{?eB15mNwqeqp1GP/+|)ֱ˙:CTB?39GQmΘw?5B ."9CZ 'o:p)\hU\/-[bC"NVv^D͹h\Z#zgCd[ZZz=[ &xXj@7;Y}} /C7y琏HoH#nIi !/݋E1~1Rcc7 T$} RT/ݠXnLzu3x89i3tǝ֍wZҾ8>ػsxez#'o7?xL?1_zԥhN9HEzBhpJ0a!e6հ"j_|ȢZFԲ! eT} 9U61ɫ_0{z!E:n-μlih'#VbE0:7i'qH4p6C'fSD!aH/%x:?n'zx1c v0[PЩn?#MSg9qEJ9.cJ`n1Z |yDŽ 6ͪ} :;ud/!Vw"ȈN5\a,h=&`. O i/NWH%[E@_*Yl 2eX(oyA&"d¯8޲< "eZu P}eNם=;'H0ǟ %A"M rkq~6SG[d8jGxŰx4=L=K J$5AP+‰q o4Bs bFԆ|~]?d[ J_?7A.nkkD]5#BxЧ#ˉqZ1d&ً }Kxy$5ǒu\3,uS `Mf:W:sz\8D+iSAjC\w:O̻e鑑Y gdq/>Tk1h-5ǣKPX^5#(R`pPws4"7ɯ4)P{n{q 9Jn'ʹ-OLCNnJ{4d[;r|>_+ZQMQPǛa"S\_6Oq1fM4Ilf:$l9r[|۰ C#xDtE|6a%L1Nn@y]zl+W+ϪwUda'DlrQQA7FFᡡ#K c߮/EPi߉N[u+y>oj֞ugʁU3U)FH4CcV#4MrbZӀ&?bP6Jcλ .e;IEԅvvr.)0zszWuCbi `!܁k {,,g UW54 ,J .Ŧ'R1ނTZH[+K d5onnqNâ3H@a#gP5΂IHлgrԠg6ɀeon:rIFX@6KLNxCS]ŊKB rV~l)uY%MqYG| / 驆I^Ox"ԉ"Qnn˔R;+]Mۭ1GLK,5ޣ6a$ȭhYk VJZKKCM.0:Fq;MoòͫQ2ʛ VMo@0 ne'jDR;ɴE$**ɂ{`Pٙ\~<'ޏ5P*[MJaF{-]Y/2"``50` H<3wJǘΈz)fI5+\gOhąhIԲ :~s Y 9NMӇ2(5'ׂ&RZܔߠ xGÙw,R/pb c=B5HF#R "#?X( Zz3~WҾt5Xنm2WMYo{n;e^ߠsex1B 4-K%cjnWo VT홓J~ sO"RljY ~|r(IHvg[IsY쬝!'>_V`Rіw#/OUyc3۳".0Va>;aS2=qښ;^.Cp*NG`Gm)w@ \/GC}ɬ)5rLH˃ߧ7Kns2`FˆԷf6aF:M?I }JɇF3sўĮA JjR\m?e>Djt7f~1J58mޒ03_՟!> t (dGZi/Ӽ<5@i.:s(,&149L:om2~lR=&cq9>y!A gufb LZRJ,׉`dW:ܦXF/OG,lzƂU/Z/ P6#2n70+ cԹHY>l 6DPTiM„( ASUѹÃ7tyq; n`kzchL5]hyЍ$g;6 0%QH)Tr!RSfǻ6@o 7}Ǔ/M&xX~EjxU]_ɔCЋ#4ɞ<}~<R4HeZpN I/㔖Hs;8#D ȍu 9*̑/賓J`$#`x[C}@@gf)LW(]U'"L'maz 2"h^՘|G\BBe1{i"? {Kb}aQc }UǠz DTn}/'\I)qdjEoc셿r#Q52"Y~lS3nM8 lOm oY" 0) 8aȠ*ɖ' Me"0`gnniN>9cֽ8yK0"X:*mV6k } GZ "V{)'H: >3\V{еƈrp x`KD6S$z&f!gj(7"J/O!W<-LFqQD dR82>Hea,byU%us*(?SOݠZnή/Wa @^c&/Ӡb3|?adDYCJ7%4WUGz4%'b(e[/pilFܪ?KH2.j;S?s;Y^:Ö=}lu8yRvb~GGcy'2BV|.d j"AD7ewyyj8CNOP:;>i+<4UH|ec;"ɘdB>8΂>Mw٭)M7䃕!4s^N+&{u "6z w~i+c(;rvP0^Әn#Mk'Ndgs?cF-7S "|+)vC1aC?!g+Ur?v>AgVsK9yz7L)Jś cSA5y ^؍~13uܸM/tOad2Ʃ8bn@mo'brpG426ü3>,`AVʸ`$[WMkW?̣!kΓeѹ\FV\vl'苒r5i26+m>:.gqVDZt2mw'(Hڽsbz Az1%fjk`0$#y\?uO,f^s E.5>֑Xn 켺b[hN+c7Y~ਬ6j"2Y("O',H[zDv#~+-P/%d I~'ы: ki, gתO;K{4.e?ـQQql%*Y>Dȳ @m,X=dͬI5d)'W^nӀ#+2RjV^gM>7y<6$_I?C#9)aGh{*y6{_ dN8Kզe`stS+ {'_UBiKYe_uvª-kCw)RDUx=w;AMozRIhW%-mG54t\QNTz[(+>NG,rEPف|wl~l}/^fv]4Pa L Vvɖ+>(sgkR hb4?\Ui3܁GoVnD ,0ya\wXB# ,zMV79wx4P+"cbQ֞^v*X.0n[֯Fjʲ՗>/q]GsV+_Xu "M,yy=5pr8"/!}%hjLϬ|SS`I ci#J.6F԰ U`~g D 4J0s%BA̯Œ c#o9㣣RM^?- C>\8`˶m\qv#=";sw<Խn'5!9 mtWp3 17M {Y/tU6CA`sνS[Oz !?Xt(}4h"mZ4] 0OyHPJ G{$y1p# âaM ǩS)Yi0 AWAWAXW 1u`R_(/J Sr1[3;e3bx:xm^5~Q4 }T SydJR̸H4 b,dTͭ mVT[bരpr֙7ʨմxHߖǀ}Df0ʞ~ \RSF6lkR~q;)}. Tf?~8vXuv>^^akncFI'ʪZaBחXV)g>IZ,VYF1c`d#%ķ>żȺ0󑌴n!WCK\c5I|M'eXb [Г> u05J}Jzmφ=_7:=3֕v=\=~u9UH-XXbڗƕ˽DD@8 ȋPWuO#t6suvWd8~H K!HdB|ZI/4jLi&jdd5C A]fyyhG؟ʝφZhCZ_UtZ,AK YH%. ǶN+Dx&5'NEe(BlڸDڟ@:tb({MUnO%/8Dg]UDѢ5g`LD#ϹwH({tua"dK+#_lAMiqC\e!>@&6 ʞfr S4'g[0y^nHcg(5{gG(݉ɩ1a7qNF1,(;׽ VU9rg\O% f-i *[:N\p\Y: e !'R׫9X1]WSW|Jpҕ۬[X#Eѩ$!%ԱYpԌe &MX9-bw\UZ/q썉K;_^CKmkr;<y͏3x US^&F{Փ9մ%KuU{DG?br|ʪqVj^&_b1O-1SBJªA+r8F"w& M+BDZnv d5NUq%Y5@- ,j$ɜ卒i0-NN`ЀTb2%*j]jVhx}okQɫgddC5[x'6Ymhu׎W" ^<%7o^ q?p,j>WZ$UW>|]#Ưɳ}4^- 7,viBŃq*i<ͥid5sLRőEME*֦*Axî Rd mnoS𽆮owtQT=-UTRBGVą7ʮKt]& =~>IXMjU4;WFaZ9W>sy j6"9'GԄe(KO4ed1Fu j ,"ŐjVw°X  V)Y[J30IIg?ȿpFl"'8}T6/p$N qoEP>E+Ha @ZL|(O~'d}^{""v0=B ',o\m,ԙ J $ў@23r`( Be f0BuhtjOЄ][iכw=]0+o.paG珫Q'䢯IE@oKe=S}A}ׯy8(k'z?)5x;z*shJrCc:RWi}*}T5._8Clxb!@Hc Js$:[O߹A~JMb/ͶئmZ|׃!S87AH/v/s*w)=9G12dnUj;ݨOG˼}/w__Aٹ& 9?U<ClAY.8ZR6\ÍM1,O$7`=}萃`Ok sǞuv{O1%|GelcJpi6'Oo޲joX9~TGv;..Cαp]H,"}Vdaڥ˟ 3{ OCiԷD&b F DQx^1R0z ،+kvsXgltg6wO *?(2}w=xmVWq *~-bTh 5us/^a0 xE^'q. >̏Ë78ۧJAIpf1[j@k4k<{-ߥM'gsC_n~KܳM1V&Uݗ# Z /7K[DԬREE ("sOcM ICj, YZr_I:k|{o>vr]4(}#Fk.2ExfHT3BwÛ ⦅;Q$c2/#>zb "İA^+RA5C>-uZ6Q>_3WsPJ'AQhi muC>֗_S@%߬sUa0z\4qmSKc#/x_ :t‚b9\U\@hbOYG\/]yύ쥆E/px Ъ0VRPÚx(od{=#ԠF*dBHqs0<"a#"2v 7Ӷ́~Iq )* !t^joJ.2hVFWI伃gBA32due}^CSPڈ8&&7XW?( I j(S:F&nsMtUXvHRq}###k'Nԋ!Fȇ/fG-eiL-ճs5?>.(S5e9`;RyN\_U}OF.؝1t@%ABF88iA%2Hbk[e#󼖍+vs*k ,D 0~m~8n(b7K~8>dT+6([Sj'޼iH iյb푗5plz2&V ͬg CHAFA(-CwrO)%,#$TMP#(iP ,Oエc-͸O0<R5R0|rʟE %Cٚl=}Q8?7΅gTO%`_kI@ $<I5F֎O IFf»鄃pVσq-?3˭x9]Apnv8ߙ[C4%CGo8k*F3*9^U:yy*,@%{|p \E@ Q_unS:J"4N/͸\xS=̐5!º HxKa#*_TA}T [r250%Z|zgβaoM±ʦʴ|: ů3Z`$&@$$PbMW“mebغ( ե`!g'҈.Ly}"OqD~淶*T:)޷2V{MW~Yy+k$|د p'~Z\C㉚ǒT)seKױB,)${̯r&hh=N;ZkeŔH7tsgZ_V;Ax ,ExYsQ$ 50l:4;j+rcj4c!}D"&m:c1Nɤtyc wwʡ.C-Ua!ݓwYw6[hW?_7\^;0=HCniu3S'wvx8-dHK&Aԩ8-$x=F,ho^Cs0%'0kOOײxBGԫ%:;I 6*Y1ό3V˺m3C.FbV':#dFPƫpcF)^T+x} Y)`D^.#BTXQ*JYLs}aV]eEM++&&ĆP 02 -J*E,*Uh*b4jWIPYZevƪS,W,Tr)mqeDS ;l)-()|wƩdQ4z~Ia'8AȀ` d Lz?YkǑ< Ս˖.HNJIx:SE9^;h')V`;rݷ2ݕ~^4Oa+jdi7m>oŻn[(J H{1OIٙ=. QQ6;'e^({1VIi{lMw)>U)њxs7usb#^<~_ؽ$ԞϜ̶s=̓/ $G"|&0A@* oP$P E@$DA@  oPt&bviH:J \uR]F9ϧ3|M7O50'~:r#ti1Gv?}1^DVu K-,%D}f:Qk?}Mpl9|%8 Ff8i "?";Ihx~VI~gƙ+'C=ݡ%_e[i5d4ZYs܆snޮ- ؉Z36ppŦ(y~+1>ާ̀w)t_UhX@E"W3 =κ/y=k.m|f;7yίɫ]1kΔmȷxR+ n{%U}3xl|KV3L 281SIR']ԫM"*Fʱ4I媲dD`X 5$Ȕ9Eodw?/?V6p ?[k7rA.\~\}/L5;M߾v/:Zp[nFTl{tomj*>3i ٕq9?t>~N}{{__IL&A9`AB*{Z 'يQARH *`'A0AnBŊ)h"V%LCG+{o,/?9Cs0!'<4.z*EWu>.7~_{~G31KRV]63oUQW:WOShpmϙd{<~ύ) n9d{ Mꐀ$Ȧ : vgEwep Ms&!uf^ K  u8cSo:pE'BidR9est ;IunB1sz'\,\f2*:q~^2Y;'~NY7fif4#6paC*D9~no}<_jt.ILf"UDQX^=2 ЩuA%6y.{ l/|o?smW۱RD{ ;xw_̫etv wb/fmӤ@~\ԊQHU?tQN dE{h~PU#0Q`ȠWUyx'ETʂ: j(|9m+}Gu> a[*QNi}ny\zPꄊy{qkTUM57?t/z;]ɶ[3D&dEBaoq{\6g=g0Fc  U *I $|Hbps/ƦxGfOwKxJAxuA!\,5!G)0O `㓤@ca9r+fĵ{?a8 [DHVlYydwo d|ؕA@Z!Ns>CwM;-}$xJX)$1pR.H/<.-~{oc)ZZZLO?w?yoϹk"Sme) c0M1+. bэboAk)`Qc1:qX[$42_(A~vu+`k0D@aGbN!7-d|]©6$u EǜD: ,d"݋h lڵ=YG7;S{cvD]F= !R\X3_oK\ h>v^{ڎQ/^z;t1_q)_rr{@;%e:*{̞cͧ|&?G|$",] SF.1[CtɛZ{꺾ezCG3T,|/JG ngcoULz9K Eށ>KkBp(j!]-O_5e<& 6f"w{R]G9d"ct! /j̦پ)$* B Vq@*"IP吅P Y8 HH{"`G& qǣCGX( @0Jؖ%@1DD\ށ`TD-݊~Y؏~?ׯ}FA~jK1S]_*b8zK;= Oxgf.SB=2 ubX}(##,9dʋ"J:(Z WaBԸo̠- V Oop!2@:r? ިCHI ZԊ:v`2$REj ?0$H!R(-KOٸ[чF4fBfRbJkV&xCn9C 36Ӣ F= eI:",ӍPQH @ā)kq5Q^~N\a{}ۮfFs;u,@DE$[QK0N,N'gK2l=N@ 1aTQ "ըLPU-OJM(0L1mk;r 3[0/s~awjZlu۫uagĈ,-DPDz%{>;tojWYu.ӕ 歭a#wf1o4@[/(b PCC""t@]EF(C#t@O[*"ݍ PS#F0ZCCe11Y&Mg_&j;L=N+_[Cƻ5";hdo{ZRu@hwʰ#ZYc䬃9FB*FLHuAcOwj7=6^*I{S[o7:¦-gn7ojV~uZ>LTs>.¦DJD ÀytA?>Z@*/*HTEQq |蠠TAD Z?Uu^(s23b DWT-E=[Snؕ-V _}IZnzZ2{֫HkEcܼ/wۆXl|@J"NH鑏$h3ȢU%h004EOTku,+TսCH'TWe^?SڷRhufS)A~IH%ĂNcyh9|'o]4xlIK[00\N qz|Xl0rsl*Ȏ6bX" *F(,-RRj4RV1`EAQD`Iq  $H+EQPgBh)AI=+{*!UQ'JZnZ;QR@ڙM3erc.P{Q lO@01r6Q  EolS}O}m?T}ŀ_nR{нJ򆹏kkqP*(SG尐4H2A bE<iHJ%t0CF1 bABnT/v)`]X=OPQSe` }EbC*EO"B BUH~?7Nw,w|:VfK[׶"TH#0 _y40Y*EPRg\|?45#c92 I[2/~ z>OY\r>FcwR0 `Li@c\"O83ؕHqy>5]VO"#2&E h *BATT|@{iDȈk!wrg'&C&PshUCc ~HeϕsF}sBMdx.!F*J`~<G.2A#g 򠿺ƤFT/ssn@ $ҵYYF aa-Th-+pc.H>F ĤOծ#qOX(HE@`"@XdAAB)"DA)cbADb DTPE"F$Ȃ@[R@]p4֍XYo"* ?dZ r?F' M'L4!!QA0UZ 户ZA.)$cH&AH@2$7 4t|EDJ.@cfm=ؙrr,̆al!B2" E$EtZ*4]цh kl 62L1 I '` ""aT@IpHQP($ @@(zE,P5RB$]q+0'dϹr8PF{/(+0>BEI{$L{6D`t`3llGr.;xx-BApXcB`g{{ߺ& P4S4CM2ɴ6zw`Lc Qe C!+aɇCN,pp+xMQ{AР^ӣmPkFۀ oab^NlOl 6$ CY0l꜉ƾ{$#3] $UmDVa7~n$4'C엓/yt|WK 9B(!!I!B@;PɸSr.AlW:24$RJ `@0vQ b baI$1PJY$*btBPa,Y:ED(,Xt^$7z?W*! *_$A: P(jH #|F)"Tyhr1 "_ ED$BD@MEl:z3: mmP?_),ZPB{M1,N) 0gμHHC RkeQ+I((D(Y&CYzg6wl(!$"ȇ濯 ÌyRH0X ," )"(,H)PPAE$H,H* *X*R(*`vt /L `2(H2# J'['~M9>  P|.>pN?[>5"]s@o4ߝXCܭ_ \h،JF> /z{\ J6AڜP|2,"_Ё˻ 0 \Ƒj?KOJ=l@n?K;~u<F ȢH 2 Z^٬7`B,bnĨ>e@`FWuvFu 5ՐDH2BBx1Rh8 {gX() 7%'6ju;,$2ۺCU.JPLjhzS^)ѠNPI6dFhzF/|bf.T;г#Kq_RUF2h4y* twP HhƑ90Ӊ߲WB 70QAJ~jwygq 0pU L(ll$mxgg B^ŒRm2@SGPmeܤ(/Pm@. w_ɞ.+z" Y(U CZS!}fvR0$,(!a[S @d՛9Æ2x39 @d@Ytu3IRlM$%$s׆óG߸7L(Y"$oɽ O$O5Ę{;8N'݀_f$#jkU.=;ipN>s E=dž2q3WQ >֍)v2$9`xo/(HA zt&rr IJ\X7"ak!]0S< =L,DU]RydJ.T$nl5e0 4 ϛF ;UrMR2:;g T b= ˱rҁI˄) HBR\^:k!k8N ~3k0MU L-F ۑau(\`2<W+ <+̯coQz|fSsc哿mq+1*d99H3ۚyCٯg>BwsVXaڪxA"Cd rzCw*i˄qƧԵDߕbD?:%3bT"AKipD _EOς"TdgGJ uE!t< ZFoZ=a pA|Ng ?plߝz4OtOs+;5H` P/S.c[K=a+jpS3Bv[ dBǷ JU 5bآ4JCɪsӈb11#PB A*{VAQԊ'c?eeE5eT"(6ŊRCU qx8 -N7._ /7%?}a=z4y-[bR?^&1D?E B/&|X'SYzazyRgP3b T"JZ\J{.(_Xhۯ?./Ũ}Oih|f,f10hk#~ ` a|+O\ME{]I{) xBCcC%s+}k}7,=zKx!p<:Y@\/ oҪDszJ-*(k`)lT*R֡#Ӳ()~e@(n̏ UZܟ`żGmֺu/zrK{ +ו<Ѣd>Y%`e-2&`L ڏLKY1}" rw]@ L);=j+sUɱYFww3`Zʻo_o?]ڿD !1Ts yJ2E=A֘R(LDkf)a!PxW(FRYS/^j>B19TbUD%_|Y_K㭈mg]Xg#B du4[?2(q:w`/q[>$PA Ԑ&$A^ :xR m+'l0>㈼xnKe?15e_? P? hjrh7F cݏ֨S+lD E)v_H $uxx}nf6mwH@ ~ 9<6hȬ"!تDdQ{( 5("TMX6H"0b˔IdA0AI#DQ-MDAX@Ad!ߍo}gps WLF*Q,3(4j`QRAHPXHOۡ 0@ŌA` R,FA] Y$(( 9άJs! e]i | *fSr/u`[=Þ7UV*/e`gaXY>Oۀ@1"DX`A, U[EJTcxaH}j0W1 A3H[N?\ Aȁ~N ݈/JvIb5WUUn!T@NڪHݏZRߖZ7nb8RYħ?<(צoOK(TAE X s1!Ґɶ;෱,JQE#dP>*>V.oaJ7cEl~|{9i$U$\)gHcRrbDZ$X~:܅u9Ҷaz7X8Q3mܽD+hȣο]^#H5=q =Sy&Z%T@,Ef}g-$%i&^фRF*[.|S^#tT>4O Rl#J:26E[7 :am#N ,A@A>X]ki~mKXG{Wrc+3.)-G)iJ._-i_ta0,Ќ}mKs%YYr9W,ܴZ+>P1LM g{8=nj<_g0cX*BPZ-kKM[%-Jslv"_ @RJir>d7?}F~~_v77}z?¯PoPb(6htĮyyM._kWuV6WTbŝOLw*mT^}qDs7"0 BQȓnqt2NPc،]^Bj̇|]yMmPfkdmD,4I_Sѐb}JPG쾇fAEvC4g1A"8?"[K 89u` n%D stz9IBY4Ryt=YHt7+b>cX]8I'밹'痩CŴ@x <)v'= ILpTYl2tysUvG]~~ [6*N!b)H$(@v =R7;6VY_X+ܩq|>_ngaF|̯߽}:F~VN 5KA9Ԏ.L|_>Z ^VO)%%xBF%f1 Es#fiqEWfB[ځMIa 샛ؤ&Lbc(%CoouDSNO) 'o"- tuT+ )oFcaxE*TŨc9ap<\*T0] zl 7YY fwx9u1˃"aY ʁnL%  d$0oQE PAYaC'Zv`H{1H_)3#эH8zff_aHJWv4\Wcf ohm6#zU@(ԞH8/;DdL $B h"<_ <88\d9qSNg' *a6wk K ED7}H*āvlkA"hd%ɌejCub@azS.0`5O(Ch w!/%ᗑ<.uw5k3^ϵƚ7B-RAs) !6'K9;ŚL,JKjg.e( @P#Q_/RFYLkuE+>oq'\ȼg ao!*.X[ʻ4gF(Ş Sʢnc s|[@.;gr8{څUjГ%#k@-?kQvMMʯȴ<nHqCs%&4MzT3hRIXJA\1Kֳ C)Y ~H  )a]nƐNs<<!  n{uR"2uLؼ=u=BJ|>V ,F ^GȔ! cզP@L^nm$ySUm,pN,IP̯;R3WD&404d&& i<:sԃMiа^ YRP(r5[2=n٫pPiWpB .1 At&DK/Z`$N.qݥ ~l2HxmrG,b/p[cHxq^ zlL Ž`a0|kԔ* `&>yO78xا2NAՒ̍}HL|r??`fCxMPPaq-| X1+CoK||[B""'А= *"T!i,*+0b@R ܫx|k>,jbtku:wܞٕm2I moz> U+=e~Z/"* PBC$PAYRKd5 jã'GT#⊉E daQdq`?PF\VlQZtIm D,FwDZ ݟG[?C2d!ߕC O*s%1ia\9m'Պmo]n6/ocgCL噱[B+@N;s?8/rE ( !REX -}o#ϛzLVy*9s0ﱇdrc"O^W2N򆠫 FE+&"z@X/8n_Ī*eN9u r Qa4AWv]+CXC@ʌ~x۴jW_E뼎çi$ ]Ƒk-RVuĄBbBBP ԞQ-Cje|eHsyf| |mtNUsV٪k6 < 7YߵUX0/62 F'6R5MJ! :\K>5}ӏpgۛ՗c]0qvcr*$ 2Jk+-xT,&o_| +Qz%%:,$>c޾1>`#1讑W5aV )|EK$Y dRHHS"XӂD3&H[2l0 }Ȗ 6IlcZ_~v;I1xʄ`z̘dX%CJ=]D6Η_'ղuƽ8vF~=Nm1Nuf~+Y]'W5hj-󇍚IZʢzȰL3ˋŠC|$D?Z A/DV" *"+"D |m7Q>Ƶ4쏩/5/Ȱn EYA UǃL(\JC=K`1ۯNWf;^ۥŵ7e+tO7/ AxٯNqXo:Xpc܊ #h}#ވ^ X*$HJAFE-@ --㹋yD c$aw9.pw4. I4M}S"S]߫WldA|?%Uu5YӕOZh,Kn#Xᜑ߇e7qs ɀnvj>вbm!5HH> H(2km9sd=܍j47$ggYamx72!Xg #EBAP? Φ~QGDC;}/8y1$ x@KgcޙP1B`r w[<;X땟Iҳvf=gKT?7$@Ê*m`{G_w~x*dBL.t3翛wZ~g L ˆc m%@A'[֨URg bVT6O_&g" @c4'\^-r͢y%UG~'B}iscLέb$""H2"a ,$ EC3h*0B2E>+䏉Rfʶ~,9T<|܈8|ctls-z߭q=,3NcӁ X3~/}bD̋A ykGD M_͙@BQD Dl ;|7 A "$HP/#0SÎ*a: HdqʝDB1 7yAT 'i(h>93-{j5Rڳ\@~IJ4w#HqÑlT23̍h-[:GE[ǽi<$멭=9AJpeU w&OLJ\IJ#G#Zvz[xnh}9)EjmN^1f;kKUb3ѷb(H"sj쪮1HۛMa`qK9^eP$5bѯ#cfF`ڤ(H:CN&p@Lr l|{n:zhq.:J0@`6'RlIwb0@*2(( 2 "pzqeˍ T}u.DZDC Hq)Ztŭca`1ӂf43쪯xbYVVNL~,mGsbm^$ @Q8ſ?_eE=ʙ!UlyRV`I?BQA5J/-lDH3L.Y X zoAAfq’bd_6][[ѫ5p.;rRMƣ䞹ܜ_m]z3B̍ (8co2 ٺ|,unU@ZSaTxN; 㖒c(m1<N2' [`xCyc+ nnqG 9;:+\8LWWɋ',qAùIP7~xBtuaΜ4KܱكԭZ}1..Sq%(D DF z[;tZΟWY^ GheM}F F"HHH" ,4QzzceKYuy^vKDx \-Gw0Ept;T!ɍ `'|/uE6f_Hݣg>?S|zJ&}uXe9rϡ r*y+hZV8p#s{BC`)BCd8K܊X1df(*` J2y GN &{8E虠xYx30i B!"0阐`<:(nX^b`A,IgGг#)O"7WE|&8AXI0Inhj" &IdϪm!7p t{"_[Y33}.h\W[טC: F0mP4B!+:alj mDVB@D"HB R@PЈZ8EVpx)3hB5jIZu̯͇jiЛF(H ECDYD$$XIm᝸<~-'GR8-%h0mDE`ry(P&wa}<C\9.ak3 !%PLj1C`éabPF ;a {uݿލLerPA \_eH "HW sH4PT3S^?Q+2XX  <ַ*b2URprLpȅ3rU^-=t/ A9M~ej Yap**kn^=|sOO.{(RB`6A'[_iVw &(ߋ].doaAEcŞ/{DjmxÛR/ >.Y![-z,ާnM%!'*B)lm#&a ZEPPZNni K']QYjsKD(ZYgA` "c~c =8>GnDA^FGMHB{hMk*Y,) vaQD9@ϠFj;l }Y/3~hkd@xLJb%ǹ6ģ!`lgB %I$AGT9%G{o .lg6^kGw9g2*;D#!I@tg$ J$&oC"234p_t5[ԏܤMp݂2 }TD3E2ޅ`XCjYy{a(z ~#c In ֺ A &h7‡v*kE-=HԀ:t&'VNjzFG|y7MG}p(jHQBV`XEBC(YMfǗ1oS8էk"-w\!"^fB#A9x]Ǹ^hX Uj$} J<37C:I"|f4!Ca!_";%8ZK0hv{ h`6HhZQ݄ # 4śJj5e)JȌ5_{$dfh5[+A ʡN~+K Y&}FcnyR]s@ IkEK%(ЎיFH -lޮ./ػ]*hbou蟑^m$l.[* :E-Ϗ;ː@S-@-@H@P =l J$wĢG@5@Po?7r(OFF͆ǽ6<ckV]ٟYև͊sB@[nckZ62Ixw@JvC$wɈ1T@$I$ DUNH>7It.1Wkc~y*ǯ"5@M Nawub O)+Q JuYRIWB-pt.P}"[=LԆ=hKT}a CnA }pj^ë*y]~8p[Pcj77#Q{LH/7dO<;CM ]~YRvmAa:)Wn&b$dnƼu{8.(()^kH),fڻSbDHx3a= PWlƪξюgNHnX쳴3uvtԊ2.&-*>ŀ{ Y~WF(1T tǹpdTCUn,[`5Ct3Zc!P5s궱ϵΐ&JkFy*%@Բ/17gv2U{'`HqMpEAUY6^u~M4)ĦPұ[E=yFɠ]Nڭ;pDH^WN:UXCLPڋqV?Ęꗁq0 ,qsf3`{G/L[9s.[R˶C`؍hUHO{>{>|ߏ,Uy'zDy۴Ӄҫ\pM7gEm*'s&|bun 3y>lo>p3∠-ə5i;~͐&҃P ЉR([K.I 3g &q=v~\ &cx5a1@%a5bY(*Z9؋?%%@DaM8X~|4MrڬgW? %56<32$w)>8vrL/3(ku wKyګq;Sn>jẇ`MH*>(@S"B TPHj#mt (,#Ek[!> 0M-g۲Of\x)f#ʠ.6Ɂ'|Av38e$%R kެQ%Qq/?_'Z׷%Qx"0$ ֤ (mJOR/RBWCPTw^ y[Ocm:ce눸JpqKN|2AagEiWNE} tR_H5[`Y& E &jN cܴC$O>:R|AMyY;Xϊa$8.@MZ)6< c5f\zh?} D }Uqp4=ޞzX}?.X0r{ϧOk3kB=XY6Ůx qX"#-+AQ²χ0PYP1-{$~ N[ٿk:SXv W`QS髴%>, 䬾rhF ZMMJ:%c8lزD4hfTǩPUd:*-d6P, >CgQ߭ig^Eh%9E o#cbX,+_kZԯ%*9)tu1B17MZbV&̟/64t`'u&MrI̵?#T HA$gR( Y*,XPDHQUREU$YwT!s7w("|4q;zu&D @VM(~v]qݿX@$(QPdI?S,!  +gF9qpq۵85W~LG.if+!F3}YH8<}O{UMY^U@*4`D,AwqX(hȲ]gHT9Bx#x~o˹o=Ө;h9DI]u8m^`C&J(!CxTF©9#S$KL/c~,KJp- .=AjOo/˺w !"=x@ bXCȐNS/*qQ<,c1{FڍmO_vC+y/ቇx'_gΞ'PfW{G>ǥ<kE,u D=+AN.n5 U+ح1]yCB]T`v('jA$!J_zߔxohfJp<:glΦߡ͚IQ1XiG/ ƒW߂Ln^!ϙnrSzP/2ٞ hfͦasu#IT y%D cs2<]qVm`+y-֭&b# kEZ~$eo/yH܌(T%FWhMx5=/_7ơaEZ5Y6$U#F} -0J/^$&H+0kv_]Yb@Dq4ڇN&D_WӶ۰Kc9aQG*,5OJ2] udUë)*Uv1(bn5rY>()E¾Qu_Q]q&PmvOX'biiHŖ::& !)os5=-ηudw[,,pÁЮmw=m˗ǥeL.?+' z Pϟs»z/J5S$q}Ywj܃sCgn_͜1-XI#jIgi! t]GB%H`a-OJ^C`hvQIA7bifX,N9s9l8vn>[ۆd6fp_|&''xEp OCLī vµ^WCi%"-:gDDfQ25gꅤTFpeagnz-͗Nr.}kh5j/lZ=SپfʛDW,M"žPFD] #ŶV^",`eb,&(^YOGp;IxMaC1$/}5"$qfԓs@F̺npMöYze 3>O5u^AD%WJqoM}^^Zm$GFЖ,suS^\sK{7: =˗EiC\BIl.Z:$;SYG2?[4'ÄuoxZhoWovtéJIţތ;̬nvxƬF/{Fug۝)ref)!mٻ$1Hu؞F.lM>o[ $1p[o k/ Oƺ(lNY;DԽklxlD;ۡ(:ЛTQ"ʘ+[1rC"l8z;įpm,}4E`[vc!0"ǑyrI÷޳j{0{-MA4̞<fs<DB蛧5u<| ww[ "MimBr~)˕ƕ%4aa1V6J$ӘXh%Es9{Sg ]^b_QjYM<}d,GcOJMWs YoaRŵ/ HF+VP +vdk[ q\|8׍ +t 9mMVELVU+r~?>;qf~G;>pɾ57[fsh&?e4iNP`kؿ})y@ chikK!QhQcryJH_d#24MfGqt佾b3җ97ʕB2̉ 4in zR(= &֭k'C>&ven&pT^r"%1r$?ĽbszsAluAAE4官ж2x3JCW$=Bd" +B"yHs.>yazYZat++R@Vy@:RreY0~[zΈPײkGEvͩlhM1 Kc2_ rsW?X*$-5m{Ea@&%Bix2IO;@&D۞&htJ6Yv-tTdT'vg wa㗣u4& ڎYc3#nQCd', rfq+ƙ[%Mi"l0/ǃPX /5v1À5~+>.i;{` PjD(76s >zkW[pd}?̳v{\_PȅoKKA M _gB~-~$a6o~y߻n^gAs4uEc&+z:9VjT!|%)PQ%P7oOO[r^㟘A~߳n>f3:M9D&@3(mOG, 3kG`mnԕ+U ()Z@#q<<ݗ2t/ՃRm?GX _^Z."ī]0W"M2@O翶a<4%B,*`~VZWUU#Dۓ?q gYƙ b2m|4tA6M |@ J!PS5zkO|V51k$ǖ b] ^Qn,i.~; :#ϐ}ܭvQՊcmeZr+Y\S[ZE29U|F0AD2\p7QoËߚ@NnOU2aֶ}~b8K(0dCM2C%̕9@0:Vr8r{j ^ߎYž^A?kxt*@yx8C xX+ %0V~%$;:l>-bSuUuD^t>s-4U&I6Swr7R?Z!2#&Z6V--s̳X,H$Gj4Q?2hF@XPcPRp3wAr.Z X/. Aq p#PB k.R>x ^WiU;m9q 6[dZbXO*N!c6²(:e? &m1_Slٛ4-Ar ų?BZ M-WWu`s ^HHiE= `Oc$P/9΅U򣷽3{_Ϋ&-&;l܈}8 N(p` P&E!:Q͕Ƿ`kD0]/|XS-d16ʶa4gpO߭ǭ|Fؒ{lTR=Ht)1!j s=cӺ"hI؍~Gڦ@h{|kJ*6Xk2P8Vo>TDt7?^ѓg4s@[xv$_T!A0%[̉vB(2!; ID[@9LCNt oq-/Hj[NXv-^Ikx2Jje^{&1 w Π"^cA,5rU ,))k;|]e TK戶ʱ?]5?2`IF@t#_QffHXV$A"xszbȢ,4"} w9}grHg(T@Gi`b UjۚIe A4:/Nl0kkhg796# cJF.Uc_mM~[!*ޞYŻC93UzvoEIin$W_l,Mdݡnm={^8/~t Ӧ:lcnl2srmo96I)>A_jW%8o_K $ZMyN9+0#+zHE(HUr3qXk)))\eOv䪇Ez^0`( *~%V̖V02G3@4g *k~EokճZC*;?alɌKV0ѮUCyqqvUaj,6,BIi"Ąda&/%fs2LLXgB^uҹ.jv>5?ac':/gݑ ͷ !\q6JYҚy;}\,ZKx^DkR-/UU'n Gݞ3'S|2RTo_>U|# Tu/C RAQh9^"]\T7>W?P}S5=ĶPg++MdWN;yDkh1W[&)̥1=EfG?V,u43)(8eBXvrFG&u k@rҬ5`U4T>* LD\|y+hTYӫ <#1RXkbyO 0oMGaVh>|o7uN}߰:s[c\Jޥ0n:?W_^H 2(lzCߏSߪQd{&q"4IaSjƎײ8ve\=To:+F czlr|I~)ѷ B{s;#dg>=ыw::L:jږyB@{UR)x5(ժkqk=(TȈTz>_)ۥo|I}_1ܣ|X h#/Ȓ'l[/fot8}~4|ϓ?+s)/ʏu>Ûg祖C EFTg .+Ci¡޻;ݐkɄ ea+"q*eg_hv:͆~Z9RoahaQ{{ԘnBbeiIpܜ_1=KzĻ,۾ҥ9khw\zI Q{xM rזg(nZOdaܹN̦l4TtccVG(Vutl|觥{͞6F8$ ;Sz5SgױNzz_Uaa!Qׅ:!JN?'.ЭR3?J&<%I P\A,.2-u^Bn4KSOcy՞rsE$RFNy INXB>m5=^N'yM}Vz<g0{ E:r wW-^@R;klcd[-h@Wb& XItBņKOͽi;uM.R'Yq:ᗶA tn_!Pr=BLG'ڡbɾfXƙB$%ҍZ)|}֪McX1+Eɻ}qX{Pp4zB |1FsR00 H2e_0) 0+'|O,*x~Ԩv}2d2SYI#B~!ِyUK#iE @@jeZ_#gt+AoiPP+>}!"Ì,*"FT*F$ BǸAլ6~b Xi]{ jszj;:3cPifF%@$tQ'1T@,O=Aof;gcemMȀrF1Z65Uj j^R>GNOCA 2‚_eJlcbL`kjZZ9!~_4 23c KN\O&_fW=[8Aݨ죪>ޗ'|tV 0T]9f2 b .d#H SAFrQ&.N2ՠka&O]Cҍ)HyY@ 08L0IX.eQ8O^>`e  Mn?;}*m(("rrD_@L5-̪'\C<- D,7mYs:; N QD eDp Oqa2(U@%X<>[>^'1r!s{j*#mLQcn)5r_gO&015rE=;BG/rV{)2?`чޢxDHKؘUĭJ"+rSSDUy[GBfBޢ7Gf r$DeOt2Ʈ/Ya3#z UCL$$0V\d_mharJC쮶l=T gIǪiZ IvSE͗ %}ǒT߉F MYm\zs6}vT;$ x'E#Rx& X:qC?'Psa4@FFXP6}ݟ:k}Oz]X^B7luӥ3HÚn,HdY|kvok9N"c9o*K V:,f_C\wTUD|YQܛ}EOK^(ڮ'=5b,ճ'V?eg$! ?_{M3#gc*|KQxc޺'G`!x-8+ dnk4E'3x";V`CnWmO>\$5rPcgKAٔ0"\ְFSšsx(;N)WD&RbTS?V(۞FyG7~7Jϒw~W\4?Sz8Xdw6Nܨ9ԿՋo1cںΟa ?k&dtu?-a~j2,x!!hG~v5mgAF0Ye-jM0#$#QwxSepGڳ4g]['YT A)&SIDQ@@M^8%; <{w3m7~M2D) Zť|^>;(6j$fbi 5]N o_!ޜ3ddcAw[ͩ+!noj"s z6DaIRQJZk wŵ=Y^"az:7ijmҵ6}>Hzrj;wccYG1=p[ 3 "R1bdk6>vC2(ȋ/{`'TV]YVWЄ^H]{E^=|Gg֊(IUøS3(cѵ㈄Yz2^bHlĺ9e,nP=.MRXX|^]Ol8\(ѓt(X]Z0[im [nDnb5 ]|?rz<2Uwi^h`iKlW+,$JQKؽT>,xYe7ϓtD^Sم$E]?wLnu:}z%56uia@oVX1_Zh08`=E*aRN^^&sIJ\b} TlggKC?^=,<.l𖝜5r^g#76)N Х9(a4K)ZG$rFfE"e~ 9nXI7vI¼Zgřr D;$ĥPcOsvOu&fa62[ޕ5Y&9mٌNѦP83\6{ۗذ=_x?JGEsCnKqkqe77ԒI"7W]SwFLCg&%``m>9j\nRþbBg?NS~7tSx]ϣvaPQQ $JCoo7%Ck~u"^Ǖ%tnm ?rJّN wL.DHO١E<%[fj%o09g2 B f_iRλ&]弾_Z$}ef{|¡05޵EaVF9#t75%@[q9;3V}-j-ʢִ{u˺wx2t#CD7+qa&. xϹ5{`svx$cc8$5ztYXu#޹ggΧv Ϡ3jh UP GHvGsqL5"o\'U>QV.4vrҺ@~-*UU yy MoIQ}fγlsy~_9Zՙ7ma#16flw(*F@$ mB !ݕ,n>^V~u=Ӌ"˰kY"jF/{ ?{o+BXw.ä1D>MO:fe@D4 `H"M8 j˂+.3+gKz+ǧZU` P98|C}7kFG4ي+ˈae^BX9hw0;ҟMm,|m@ȲZn-s&qG{/l1 MwN1 `Į$-Ɖ3'^"*Y*DZ>0t}+98j ƟF KmTƀ/qhĞyR?Hk pAZQʥ3 V ϻW浣uooc $DGBI(J$$#?`= W+Xen nI z`0vr^㉝3[%F|zmKZv]tb3fm&w;ffE ]I6yHVO 姟ա;`%+,-+5dģ@;N{"aZ"OMC; 3p{6{ ۸vVrf!^li-&  hbWi(TBqi?"b a8+d+]{`Ђn>=xy{},t@T$Љ$yo=J ;봃x"]j\ :یNkf6K0bb59PT H}&ÜgGPm_u6̀ xÊIў,M{FxgY&$A3oI VRAB(@LgI$;1 <, ^yMy}tŀ(͝45ïoR tm7#ۏ3gI@g^q ٺ6nHB帤,!"B%vykrA319Ra rk7酹pɓpM6u8_0xvT˚]DNZPH$}WBgӫWv~410Fϩ -vy%2=w33D`"J Q2!^}@ k7,&R}ǻ׌ZCju ewR_a=砣ڋu iV 7m\Qč|11ĸ3-NH!h=Ɲ6]K ԬXK0qbHRE*`F~>v>YJJZ21$¦YneEcF2ǟK0X]~9)|y0!.fyîmLemgwp[]nr ;veTg`XhNR oo||)߫3jY˅6p;3^c6U&B(\X^92)H'&bTj _WU}YI[<;Wo#6&'&#gI_^*c6lӯkIT#;NüKzg(h `'n en `h{ŏUE&r!$u*ݽ nSXdP^ދ~0N s>WfH($Ta& !!klIN{ne&fwooshpA.K˕e[ G\%_uM]֔#II$tԺ>7>ET&d{PHtLu %2ƇͷҘpvq U&2~Ýԃ'/tPn}23qܬ\:F~hQG9 d*0C/Qᗊ:>MIx7kVz|^;k"Bvl9[ Td":)áճAඌ&8GI[Dt&rUfR,(&FgsAn6ѣZ7 X_W3{#XIO,^r$q[,^HƟTTqUg>ݻեE(#/) Š"B`xU7%  fhѩ/1lK~Jow'۳ PӤ[Z>ݝSBP]1z 'NT'3YaWK]Rjce-,LB8 I%GBT)a\S441ۭbݒ'4Aq2_K<[08 Ro 9D Z$$ADnPZL+.2ZɆd pkrqٺQR}Yu6j29 @[WPb?'Qx!'I{' Ia)ga]GO 8K{Oߏ9GDޮ*;y$ e7**#BJ#äIے2374Z&|p=_f{OI)գr4k TǭNaX~SK cpl/-AMeksz4}!3v|Ptg0n‰ 9p&Q̚ c]s20"129ic<?umo~'u)4x,هp ;42g0&)hDufW;s]׹d鸦l5v.~-P ϒ؟ WۯѻNnrKz^G?-dtKW0xh-J I?*P辮A/%1 ?b& i&"sd2!,a+0}l KVEMn13 9Hqn٫9k4F^AP dÿ{v~ u 'ӕ_p16U%ͷku9/ M#\qF临f87m?Î< rd}:N̸=)yŖnTY<S'7ܖ oUf߷NHD)BX@%YI"b: Hԡ42.]ʼn" W^ed@/^q;]mF\0ƃٓGIAU~p` $əT^ÞX϶YsqN{zn { 3.Hc05 A@jSt0pMXP6pّ9T#35vWT3hE6?PR0`AeIX !~>V)#b]xNJHSYݏֆR*lR' ;m<-bJqf͟Uٻq=g5Vxr@{-f-l b` 5oBJR`$6T1t A֙A 1YAwR?UΗvmv<@Iܜͦ+k2Oá[)zWQ"p5з e)P8HԫBOp',"%yC68/?^sĢ1AAQȽ~n/(x =E+r*չdFV̀Ii;{[ܸ`Gx;۬%A`gS./iDGiH 'CYo?xlF{K-L_e<~)g.*4lS?~GYgd%;i x'\Aea`G.eiQfewgjM'<#GbS UA2T@9bRf7GibJP?-2I֩ޖYo- E{2)*xn0yen犢L54ʦ啊B.&T!ޖcvtL/^2V1˽G^?gGњ-+j:9:^FUmCANSUEJEJD2"ZbY(QLfi#r/9e|$iX`Ky Ib8`q)uxkZTDr(t8-O~Wp!^ZOa=f&{:u}6`т0 Bm=\Z+4+A@m>K\9>} ũȾJY!&Z,D)**=;T^Wui7~a܂<_Ir K8whD+V C6"NQvs oR%,6:j+~< F&LxVfkj{1P4N:ϲ[C=mԲ`Gt($}D:Yƽν%prE7)4HDA1 N;j,<*5סۣ+h~;!ŦVFlm4K @s%BNYe@ /ckE i OS]P*ܧ{Z)akkPM*j`(F-Kg\dpV] *I{-|i"~Ty]'62Ъ, M li)K&zB0@0u\-](vO?7v{Yzuv{*IC{9uǰiC^>("H ~,6ĉ [0ݾLY.]~f6?Z'R΁pCFYh>JcOY %,Gկf}Æ$dʻFVgM&L&x=7$@}Xeln{K61Vxcdjy4w<)6_IW6:́o~ 8(ƾ!Q,[ x+BPI ##H3aJ^.*l % ǯ 3gϯ SR L]Buc0{3Fu+H9dE9G4o%V=CYr=1AyV$;߯L]<IT$!a@JptL{j soRHO6ەD56mzޏ}HĻ^ppV%t 1Qy%^@DA9De*בeEJzgR[m%*g81V,okH߄A]kpfev[~G>3ye[|+m笑>H">mtL };32(%Ӿ9ku*Q.S8>]7`iגt= .-ao!AClKe7_~sڮcIa|(|ܽ[t`T+.k+*G'{e\׌]$3vrTT_GxK?JH-"r O^S͙0T:<*[t',qf@GxƟ\y{{9N WtM^h9 **W0>؇'FP H"Ȃ:ݡdw;VG,$.00=!)[$ZF aP85Un ʼ[mpZUSR""R$!OLUؿԽ Hr%ab@ .0"Ajk RP8Rkk1=F0PK,mN|d#J % >1{~)ۡ0R B,S8(dfn%yJh4Hw͆Ų3 GRK~/x9K  &7EQըD`a_10o9lH`%T(USrFE%} HUrWA0:,>줇t),`|=|eSHArf;\3:b37CR 5_yyC"xO(t >IݵW舡Ӡ]Ρ?B)9=W~.Y}Q%*5k1'[RW#R)ܠgN;2Y|\;!C:Sr gfkx"6_GM6gڤ-:67ۜ˳`A@#`Q%2v줐ώYb{(ffH҅gcmXhjeYBi`ޕņ~sUt:1l:#c76Z&cs]]eAsuB'7XB#E,Zn8@>"Olɦ/F p}x[kຸ4[=^?""=u&ԴUcuӍtJ/5a 3#v`ؕ)(u#)G#2 < ϗS6]C[ZӨtHL|C[}%4H$8lSۓr{rs' ?TU.'ǝf=J¿m]P=q @_[ߓ&*VsQ_]z/dŒ'd\i¨$ MKU hu+{s_[ZQfh!UUZGB`Dq<*\H:2ÄFzT^@樉R?x~zhࣟ{w1cYUG9(vs $sGAw9EK5>J5{TҎG{]:s'j.=o,EbZ" vo&eFEUg!^._鐮b#&ja  (dtO`}ޓNcyN18{F8|5Aݚ̔NDHǷRLA$ I 5[lJUKT S# $a#M 4\ 6 dp?QͫeFS|WWP&WM^Ʋ6l祫v^j4؄LxnnaksG'mD5fЌńX@$pHtڐ.-rkL Xv?a޿ /њAOeE;߃wM ;:P3~z彥.tܟ!b")W^ y~}jk^0 *qWi&::aq<<2A Rŗzt>Fknce{\_XEq6ǶMC2i1y<5PG@AKW['KS\ޭ]G=׀ި(u8c/NxtGf^ܢ(÷`^,}+u.n4T.pFC1QB"9RuJ&bsN4)foxlEߕeZEÿʀ G]v<ML1#0Bs| FfAW#X?z CS0PTM@<Ȫ)城?> UgE奎p0ڶ-osf{zt~y[*P)"U no@~ ՞PGvPLdRlrl|r.?rVvA4K%EhH_w=iRI^~vh+\JJswWu0n&z>Ne+ $@P3>sc*rTōxI d`x}|T?|G=y?ņ&3tpQEd'=B׸qn#j1]Ǭ DvVL E2FM3\ rЖ""HⰬAZ D:14 RFd]h4 ho|pLe+{ X~VaZlGkϲFE ͑fvV̘uԳܒz3~%FIRdhG8MO3»9 |yH0NM1~t fZ ̹dkYCaT>WfNs"b2}3%A 9cy,1׉XNdy,f6u =}3X{>ǵǢPg)X}԰*0:Ub{J.f3liZC|Iu 2 '^[yܢҺlbd\CrB(9H(<΍n1jta׿Z,K)qHu`y =V@е,Kt!}!oE,#]e /v;I-Z:fS6vd^轵!ک$X &}s'TX;SDF 4(RH Yh$?d:*zڌߞ<$nޚa^eLH$%< z 1%q.]qRivź\YWnتDt D'7?$$ǀ$"}]В gIp yYV&SYx'ɇdP%{(1{L:0K5+єOp``k.rv摌Mv=ws_QkԸR^ٽp6+Q[[ :)06yr~\_A{zx9%֬Zk}7_jӱ5mݚ$ٜ^M#"uj:0,)'.z[Gns6g5Xa81j'/ ᦕj -%EGm kE?\hp'oWҢ1mꇼ֍bR  ui qtH׮4^sL.[(Y+j( 4Z$GOR.&I饮30ZCo_iyidֈH BTj^|؄SP.9"TdI()#l lXLrb=zwzgv{|[yR(e mTQ.7z ds\=`EZ> ;®N*}\8p ex9[k߉Tı]c5|e@hPH" m_2͙`wv(μ07xSxF} Hf,Cњiv\g9,! vohy dc9|,40F;vJ: A 4Pe[>ۅYN+Ҿy#{(wX)|-x>aÍhv-UAck*O <:TT>+Qؖrj2xQuq g:m׽FU;I]3;#B噃UpIu`_75FYeUm"yTRF[sŭ8A&-h80i>vSUMYXF< a:6FF{,7+Бx Ӳ?2}!pl-ptTɮZ+9'qW"@eVdG=_>6o#}{2HHNmo}mR!E͕+ׁ$¯jiUw/¼}Oec's [Ni:A ij@p Xa@>( [Ci֤7yͅ#]$~,g+S}~ll۟1vn "(iE{mu9 3G7jp>"={iO!ERjOC^C~>\b?aDxmWt,Qӎ3FCspAjcRK-frD;%Gs~yb bc~[#$Ae l''PJAΙȒ!`H&(SP(eS4HKx6 #obS!l*OzuOVSqT#/kh-U6CBCRe]sHA0%OL S1f'EL|?^Yq5%"C}/=vr#b O"L\RU†O;U#Y_z=öz{ǟ=>t0?k?Ka+&knVpsX$I # ?B3i*wa9ܦ3cj_.n?maGP9Mdn&Jw1d황dhaȾ >ttSDZ%Zr!:K/2TiRQw 顑8\o|fd-54ę$6BFžI%&dRᎫw| }k~h R&w$<-I8E+SKvMo7NR'R@XDžWنkC-GpQ:ץ˝@ 74NruEŨ+[PRжEPEM bI`cr1zp`.y虔٣qB2#YXt΂RO/n&ӗ19N r2ZrNZt:Kލ"-zaC2*;+QE֤r*'uHT4Li e6P$p XmXYwOuVshg ̭\:^;ΊbmUt|1թnPvYqV}X NqB,*҃җDhRM,3 $&CJ}PQxjk&ϔC&5dYywjG2kRCޢp5l/7w^M=0r/R n 8ܜr8s{ ˼]D8#ti9bBz=ӭ=,8xF)˻w,$.ěEĆ@wSx;qIWI1Ű19%ЇIJBX"CZ{ <"2oО"f.,D3,5l-W%ѕi)=%kSBCޓ[aBqq+f̄W"3,/9;b:FzЂW.ґ E&v4>*cth.j`tU%t63~2HD;PB8mcmgҬ%n ÇBhrz85gD’xTDX(m+@ $fgm$ <qfE\4ծlؽƢ؈!v=2{l-#BK7s(ūyaVe8_' Q&xbXdx+ju Y(ݬ דHd,"K\Gw%^ERa ÜSDK}K|sy &l+G<]/v~}L Xf?=fͮoD 59[y ;xgfKXeL9~8D[jNϳ1CeVI UsWK:Qlg&O/>7 J"J A]Zf?1zUu}]Hk=<ͱ̀gg/`yAQq@G0@rT:-@)3Mgq% x1jzt$p18 )JF\Ybpbڭ~BsW˹ξ2- Ym].k$?7Z4񆔆-wZCwG$71Ua]6"=6?eFex0Q^ަJn˂v_Tpk2Jˆfj&}k_9f҃ 3gA(gGyqpTwwtmUg"PW!bn˖ W  0¢/Z`-cR8I19[Wq{N9W, ˜;hg:Z22QdI`U݋u58so؊ aF}o35' ޳^7MnkٮJwPmӆj'evM _z#DILKqaj5"Fe?m29oޒl0 A|bM-m"L9>9| Gh뵝]qe?')Y^(1abvU/ۦ*7%-fy7-mxѻG$@Gff:HvْfGW]([{>絚6^w[ep`{~C4Z}q˯1" D-d R<"PIl_Pdq)qņnn]~Bu% l>w[sOМ-ש̱G_֋r\N;A<읙HcG 3dCZߺӃzcO&%isඹS@ȸoZkyHg1 NnH h= }D,&jdx_@,c"C6C~W|8̷>7jNalfZN+'= xu}0:=J |jE$e֭K=Nmҏe Vl\wm@\k(^xZ:+Wa,AFrVt+"BJF}܋<-z7zV<g9z #"l# )U'*f6< Wv+kN2\nv`i7fj|̌]aOwz51q@k}P?d8WWz )# UM0@H &8[QSa- ޯ3art28tF 9/mq$sF Dƣ39Bb X1{~?P]yTZĸ>ą]y O2~)BndGP CC)@H 'X°E()$0@$_z'1\ȢsOe`tnuMCѶ|CdߒyqHȠIAF >-;m\D0EP>Wݧy?Aڅ xC[=V_Ų3~$Ln-b;T"ɑqw=sQY>vf9dЏ]`. "ôĚ9s9摒uKqqF9~$!w~Zi/XS6ݣǺ8w5[X/}ef62g2~ j&Z6(3g خU#\3_>w.7o/,oJ焤@Ml98FvECe L.ަ dGwTQ^`|V?1Z2>sP5UɍpW>J uOk$"/q_|Z\+b }`sz۽ie06ѓBMqW~Ixeߑ%],u[1>6^o1u_(v;^cY1 &hktjNFmzm猲 -oYo1s&&k ղi;vs[ #\6!$m32K-󾱗 8mZ7Nߓcl03UNB몢_29i@滋?˒v>T'@nIi~uYb4ﭡbR &0By]Ed^Eb+K 6~s여4zۻ́˖7V^:1AQ;z^ʋ] i{ (`d]*$B>/arxo. s7t8qgY>DG4GGu:ikMż; 4D.CsT bo@^c&OɍdcT2IZ8sm 0z8/"Ȁ8܉ԏp*'/ ~Z+Ail+4yK Fއ֦2$ [FJp_SCpFśWh^;GO›ǖ'ޒͅsb7 N Jv=F3LٸfD42攣HIͭF@F2N7ƻ_7Mf vn.qyrL `qoO,\Ahr og_5^?SvY0=B,T@FSkOߗuBC~A2dupP2CxnyՃ垽)y_;#w# Q*[HaM _8rgS(&~%N:Cše>\B>fHwa $ݓ#>}[/H!p@`qQ/@# wC?%|:Ԣ Vf\HAЪ2 7drJQ\ m~:S46h,3N7(9A`F1yK,*\B<'ʩh(G|_o#yoL=y4z@A8YAGHC$@IR D| ֪]w!95bLz4Yܟ=.'%' $#,HZsIHdD |!pWrĈ m <rxreQcT UT&& Fzƌ7}_{771R|sAHs;A$=\6mMi`-=;7iw U+,L *bhwphm2ׇܛ6R]=ɗԿJ`b#cmRPs_䷷wD R GL "Ww~uhw鑦wSΗX8}Dg!Q{^9chU q*7t¯=Oa)Co,z;W 6M8%w "%wY//qAR"ߵw>+{9#a8\ޡb"&p0R9f類l"r"@ _tKϙsyFX0~oqaGr L虯K qi1_å!߭ KYiyYZ#{vg.[mSq|X{vye+((!;BhG'tpI5GG XmFgݠf[l4@~^|S׎bjzOpo44XJ+ܕ55O&49""N2lYQ$R>p0GηQ; ˭dg]ƺ\[ӈ?RW(HusY?ݜ] -Y6L6a <@V ־v=kI0;Tg/I+NïzvxfɹfG?x߱ϱ:m["[SE^ef0$j KkDG~}=!oQ֠?0/jZd_YW'mOx!`x4w6%flT;ͨIp|Nݟ8[ρtq jDغYǚoLz\65h⌨u}`E䴅M#Y9F t%VߘL_;< ׷PJG;] #j[TX2qS%R*)\y iE,.Wt.P,B.DG4͙x Y4/\ ߾ f}t4?C`PN_p5WC\ kݻ)V{Czrt{XUY^mXUX EԈlsضO7CT7d"1,o]05RTDHe  Q- ^m-Z,U,*{Tq!ߋ+cӕSIٔTUD/b[lf~ۓfK7a4hnN鏹n\Yqm_UGydFin S3Nؒ#ZgjxMis5lsC%6UuP^mB; *Lwb+ٷ% {mh5^MGF29XهΖGfxzh5MmIDּ7On}_:[_ZJ)|my,OevZ3_wrek\ټZv2(.ƶ]]Rl貞Coó*'Ԙx$kw7ӝv{2}³X|M#sqٱ8HX椡tDe:Zt_?&aɘoIYϴf;0OJ y07AhpƣC!u**H`K},% :뷎8>~} (vˌR&SfaW?ds C o0~R3emXpIۯ~|>^F$ Ԣb-.V@ƪ01O_:"I dahLYiTʉ?Gq>,{=A(ϛܳB\Uk5=XCQJfA:(0Q)@H v-mr?3 gs3SsûR@ TR6;Kq1lb(!s2HVNV$kfbog=0,`b@(Ӭ$@3}ܺ7d+]f x~hff'-4i{GN[>㸣uyP_.O<㥻`Vb⼨n]݃-JgiI A؀9 &uT:zԗ|OuȍN|/u / "#l+ Dp@w<:h1W*z}B{a5w|d8j, V@D @PH䄎pUG8Z SPaK3Y?a{K7~ݽiG#$B ԂD"RAH?n F3i# Hoj_!KiPV|x/QW^ wa DD#rb|O?ӂFOLů~C#l ?|匉f@x;Eˈ1*$tB K %s-5&d/9yȥB5eU?#./+0v̄S/T5-P>ͫ>?N)tl]m:ղfi4@:l@`E1@}#(͝5\!?#mw1(lVwG½O6>x 9`22*VAmD3>{Eb>6J0AV(S1ej(],k+ZTBՖ)EUE(Y3tEQEEV+(cXX]%uJZ-TZjYZ2EVl(6 ъUSPuBRF"b"1VbDIk墪,8U\hG-kB-UնPTamb`u(cE*`#RLAQbȪ#UR"*PAAb",UPE"b5mKeDEvaF[QDȂdVF,Qmb#½LmFӛtz7]6BDLl8_-&[Fҧ$N2KٖSg}V9f&~Z]֎y:0MdxxFə]o'3YUuX:a## %_1>uLx1/ɺJs{[+8lů O;uY99f Ϩ`sprɜD(T!SD{Ũ37VLDtahqZl{br5aİ~4@|qx)#Tk mZ*JжdP>z.Nj3ZhZ90z1TAt g/;[+-ikK!(e^VP`r F@3rg`u՛&bJr{ZCK[)WFJ'9q=)υ^hr滂hZI".W^]Grd<=׌A=5[S7mEqv~{ g6YUЎ2̂0.P?^W| ̐l5<`[ [,,`u~pid㊆1riٟcd,]o_ͽ9N?4X.V] c!8<7i465M/t^-/ڮ+>~!glK%.5o?`Jm4n(>Yp_wodpZ2ݾKw{, i "c,us҆t$YwhW !2D0B$+r_ `~ɼn}1yH'Aim ! j-NQ.Da`o_Ka2@c#f~95'ֽ;Jn9YaHRo(X*Y EsWjICe:_8Xt@ϗ|f)ԭEL`T>&Nω(ȁ6XFz\H"j k+Zkbr&:h@I5C>I6% ʸv#/fݵy H= WǧWm1g[dtC=GA nYpB6MwM\[krn6IZD8‡T\S65O<.VTq~CK{kٹ?xҏs Hԅ2wSƮ+moVDj 320^񇋏gTX5Ǜ2gW4+u+5K* DT3wtN޿oj"V]v54j2 Ƿ=%0*~!" \aG,׳Xօe^Vʿky+V.PIk4 q?3=1FjҒI AfU} bőE" R) 1`" L5+  pFM0!ZY"cE+eCԕ Bb+F1E1Eb" ءœTVyZ";"'V &1XH=)TH(ݔYXLQ\JR.$P%dR;qΎ9,"ēkp²,BѢ)FB#iTbB#JX`]Ad3_NtHuv!`bT>-V (3X{9ڲ.eUb^4 Bnu@{Ի1UuTZ1G26q2(G{͹Dۃ=HۻOclY}7 8kGxُ_%GdBh]GaGYyn/Vh^8w^{2wV1K6xd̎L U>5T7j&hW1U0WtEH " HSċ$82g/TՈƀAD7S<:&(eAMWsw ҄<ؑbƱ!|mw}nyZO*BO{CIrTPp,0aC'=m"!?O8AyB_%/h`I Ѣ 'r{ I68@!|e,5FUxK2#z[oA)^m[C/-U> E3}ޥXέo)EἥQ)QGu۶mxh9jݢ8 !%7lN8ꄭ:p$I]9bb%K,TAXC/(i{y<㷴~Oeid2f&Ӝen?WGNV~aG\·O rY  S< ]{%BL[{avkXd?ێHb> Ό% )>ymXAQ &ʨbN:MFdי?)~ yȎЌow mΛ.&`#S ~.a$⹓HnZnγ$L*˞ tw 's :iCzW݆9gOPUZ)$z}.b@i:>߿Ē 䬜ԵH+hxH ~F׃4Wl;ZrZǰ8t\C8.~{t37?EWIs|QU `k&@88$Ģ,IVTF)_otM2=1<f=!^+!f]9xv?_8|YG@;~.i^/9QXĭW:_}?4P>$>ϯIcLB0Aƃ'9)A+\Lԫ:]f^4kF8|\\7mlv` 'PD AB$dI #oMRg%6$)F3?<ف$N'h#/#J.۹U @pRxUa8~,yp)f^H%A8F2Ǿ=.^Mӭ_Q .\1n@1? (wD@?9~k>q,|0wdss} fri/l-_)i/x9(Z U~?lcoU˿AɑH s.8 ̃fmSҪ#^s=\{b^η36.)WC';4ݤ*RZai}VzQ6CU,E0 @mNrVC}S>;[7"MDTL0J37L35h0+QL"h8V}5LI++r[ ݆m(8׶JZU 3 fqi5C~{_S\MXj# \NWy eeq"WWbyһ,zx>Ua#SO/78qMoU/3'?we4^&:zXhw>tԻQCJzlNfčw2 }ϩ+4K3>yG[Ow u1P8@}̵|``݀exr^mKbX^al^&!I**4c~R)$3~( jCrȡFzJI J[#>)C&DnamP  Vy/KB4zj9P[Dۉqfc|U"N ָEjGQ"bRH NSz*4ZWxw, |Lԛ fDS@jGĹɆX~R 6:냡cXh5\5ցx 4ySվopHkB,ka.)4uv ̰wZ?{0N.m):=$䎬3NS8n^>FG7FXJKveksˁ1*M{uƐ.ō4F* p1ǿ!7 `h܋Rch1[uZt0n/ng02ߊ$58TGc keq]M,g0ШpAA^lWWaUgccfu;˹zpǂ ߏ7xF2yBfY!z! ^,zH@JC!r8Lk' lT I$ʪ $xz:)!;,7jY6⃫}cy,_rz1c ZH{i+ò[t!݌|%9Eᚋ-8FܰsDz_[DH1DL-3^KF5LB!KZ&F4[*GuEK#%˅0|&=d!LЄ0OS 1OX)I ?Iu_20@9"Ej5%o~^F_ `b zM>RF5rj0y!%" b#沒X{-lq%MdW^biBw{^E|}X"SXqVCʑ eI7RZHD) Ȉ !ÕX9ߩ}o /2[$͕1E+&%! # 0A,$tU7_ﰗxP^#vƀcSӦ:P:vQ˝J&/5Hi, B\I8sv;^ |4N7[߅wxiڝn x܁%"ClFa ϯؒN {~f,^6/g9{^M d29+אj8:w_ZiǦG #'I?U%`&BQ4"K1W+M㤰Qjc}.T1[[7|?;uJOnٴ@{ohaQCJ${D%k^? lgBID~b9.O *O.YI0\ަHJCͱ!h'>&IZ.e"e/xdOqsJx cm`g)ucٺJM÷L?] ~{Ŷ;\<36FP!t#'U'uQsRtRO 76d|eGe y$l4}s* x+`ItOHNTnkKLU V. d)9kl%SbQ WqP QDI+AO ~IVYxGDv[SjH<WٸDX8@9ةdgd)'NƜ,lRybR"!51i$Ȅ*xrUU I5 fq'oG&KM `:4%oB~XQEf&bRCj558@2* fcTDU[=+YЮԁ5R$X:>Ǘ~^!Iф6iCLI,2:"ja EN ؊'@X"2/,\`l>6}6=|0bŎ*9_>O@ڋsegB#/ f)g=/i;NFWS@ȥ5iy ia٦Q}<0j}kqM*~45`힯=3t#=|]BQKߓ>z8dci^ ܽ8ܵК9q'( xA)JR13.O0dCo$r;ţιXUHb%$ċV DQAQ+B?^޾~ivࠆ+x_| (BTRyۑP(DRKA)O|?||kE 垿>ukLUfRI$byƿzNn Β*c/g9g' _FL Evݩ]wIan7۵u > R oT *byG 7rv`$T ZIv!0.Y|y>n{:pJw,~*7z\6^ɊF@%E mb_xv<5o F)ɵGZ ^ {es㺭nh;ك Cz_5{ZiԭzPL\Nx<VQǽsŝr$^E ) ZJk'Z#WjHxc'}~k'_fYbE@ycQmgnq. x(H B^ #{0)Β20c4uDZ:EXQAV14Qy"F`0ϑ|}_yߢ"r`K\eC--(܂3Z+rreyei5Xfa≀P _ix~g({kz;{sƭw ,R7HQІq=az,5(;4XJ@KмllL%ᐎZ5hP`Ͷ(<'gbeJibџgKN&CuQbJ]7Z|qSh^Z-_n@ {(y֋ +=Z DGļ}]/mWNUv@nt"8OsuWɟ2Q:dOR\F60ڑ ڧ_.[ڷ,5v%eBQ?K`Z4H#ēysBfc myݺ&L"H X/xC-dG8"Cd0 ]H2; wWobk"gTDYY(Rc'A:}xfGt09tO.ȣbk?K#&6 ]Ҏ_+J@8cLv}'Y≔X\?3@A[Akr3WV<`ҩaoo{i-6'1/8=fk+X0;@~rPP. DE{C 94T$lzNƺW ~ޤFB}W DzGh cˑ쐟bl!hfW Z`zOԤ8c4=u(0Q}v,\j͹{{+@?h7ȣB"#"PB2ǵ$ȷ. "n3̓sLzE &$^`$SSlM|~5uHawmɢe&ÿ>% |gK1Xҁ! Bk>>-Y kB=)mr uGmcppg]r=/%Uf+ӷ-]B0X;==ouևIɈ] 0Դ(mw?M$ypF&c./[w,޷îίX륋M`*xs@$dshAO3gA8;%P\sjO.H4R^j͸WjW窬8AZߦokL mQ4ܷz\O7ӷ>۸y]j?f=v{4ߧ7(T,|5kf&f2H )P RhjB`5V6/]R̟nnw=D5  4sA1>8n۫gW@7#srĄ>ǽcS\M+MjmOWdRRH8 E"F9 $" j%ʬ-Bg#}ޭ ,Nag3Itkʧ9d)vFݟ-୲ο%~b0;('#Wu&?o0Ԍ.@&>ŀyߘo|T jF*h^i*Z7 t5سazYYC# ~@217vZdzO53Jз $Mq! ̬z?x˯V>K ~&t;w36~&qH,IIb#Z΁q!`)%g,DYm3SiQ*4~:}t-o?]jJ9(awdk#("C|Θ0H"@E?BƿB Ɉ%rzAS%21`Ye@ma`X5 1}xg%Ȼ/^l~4{g_ߗWH\xp f?ѳ'bQ8:DAkwI]~IcpIut*JH%vX9wPv9rJ+fVmwvvwrʹ6kJvEZKPnu$P1?soGV-=9wz[b|5v_Ϥ}joB|#-26,X.ʝ|ڌK&NW/bH樮JΣ p.3*"Fo#:zx FjWWL L4AѨM!mY-|*PaA%`VVu%gQU9mv%{6T$cϺP)s>;U ) T|/+^o+SU89=[K_IüTvtH%NB55ww|j.޵~yple&Mٌ {;xO Ҟț\k{]H註J5u7}~lmnO~m4f8Ls'XP<4zp}ʊEv!d]L/z7Of[[bq BlHLCEI7+aU/vj7E~&zpGpALzp1Y2%}T%&NJ֒ S玼)^{G]zj[C==Ed;%7k-;"`rwG0/ 81G0h$0R\rn̬U}30hu/އ~b>8[eb<:O: ~74((s]4JI!DyV?G08{W2mn!rLXlTq_XϺkC|tLh6o/CSm=1 YǙaP)Bh/DF%ݥ sVI9}!|+nˍ㷼s>!^0%r_JސD̯rWX|o1 J9Y'{\ g4Z:$iԏ p.+d_ )\/eky:.#=F`cYJ?Yg $Db2DV7%4F%v+e/׆n~D\`qxE~$v3./D1ۍ`.)bWW߼dy$a[p,0~G<%u~B߬F'Ae֙: |^MLQxJcBPG(CC"UQEShܜꙝ~v:7&pXv `FT2^.ze&1;'D F1IT1鸭E>8V57=4GBDxstTJ 0<쓪aI NjP )r()vM+y"*8?Uv  gIr}I"XOG x<1J<@+ Qn\Q}D '̰?{$`e*'-n$3?H6]=5t7 ԛۜyC2Jy0\%h38tFbBzch,.ͤcd*xϽp*1H+qST5ec\:=ZK%%jRUv^뻫kqVݩQA*PUHB#vH桮DRn\8! Ifp{I8܍)V,t2Q& k>MORBٞqsBK0-8Ek, 4G"|Y ͗6]Yo] A$4FjY<?ek꺘\v&nqAB Zƃ7B%fTSı; ǛrLbg du˃fLq(FL%{E[ Q*XÖBh0e2ZO?E@L$?>n5#Lud>?l" ?Lo_ϭgcVΑ<-h@!JV{**@K0OW՚頥ڕ4-{.}AwN{Z|>HKŴ4٫`ieQDz:7P}ڹU>IB T! T8jSn!n~9ءh!EFwdLj 9+h*)QAqeْKNu^[RfcV`nc\Iw9t()lJb01n\^g W.@oke].ݬ Phy$VT5{a>4;xlzXM"Egor 2KěɧD A!+OCd*s^mՆ0tOrHIEy _ ͧBOu̐ygK$\3k&|ZʲԼ,/Pu&۔2Yl6[Nм\{MFUol{t-ly4!l[~nam.Gu\IHJwD^48B@pxzܝ57'fcNQtpz˜^k;,;x)eowUĮj]Xk` [l̘4T\ 1Q7Ţ&1N^Q.S="irveڎ,V㻿ruXBql0NvZƠ* !0p6IvͰ[FD5 8 UE+/ a1}Hkd~woq NqQF'~Q|z6** =J?TRbTxLNmZvZ555Lz浻sG NieXq",'u h< v,N Jui93hr*mӖUVA3eF[lƶ'1EeKaA A$3Z,%]֊qfJR TDy$ֹ?!7d,2s~.p}(bR뜍@AB֝H=P]G/BT?qIU-GHϬh1At%=(IW;C# ;b ʨ#P}M*Tiu"I{Xҹ*d0tJ;!H!XwM[jz~[̞κجU]mRx(݂L3Qa*Cʑm 2g8gCD_I(m^5tGr;r>+࣒k*:y4HtFb"fvFkz x 8"B ֞5[y0Ƨ/$]rFNQؼ/p#_V*8}E'*:=~N#S5w'o";a \>_ ev/#ϕ+Zn6+z+2/y=<:tOL=}g=>B2R8!p=Z&pL^3H`.Ytpl&6-J(XF1֡!M|~}F|yfVwY[="x%ϑgIU~u_ 97Pvo;N*/wӳU=yAxTp1Wuvz=N t.,1#mx:Y Bϐs,${`p;(Dse~B,V9At3(OGzh1dEL?=˩Ҭ&/"VGڷnoN!_ AÿcR{^yx(JK,iw?6Bb8"D]m kS+y"Na1m_!i 2EB}_S߁E7@"VPVh T?wS gu$T+V5:[$1xGHw xPL$ݧYq\ZSbONT/;nsl}ׂ~_8)i֏ZPV{^A¼ \@nW$/c;3 n]V;AUɩpdl 6JSh"bq!xhx('>JSfMlհ.~~}Z-,ZXgT>sWd0[/.V9Fk4h#; mhIJw7ȅL$9ʁ*d;`Z %E?նM\r] x"᳊`7X$o'&JlGQ 6[M}v::4g\Kg,ơ*1L%a;:X46[pl䳯eqȱhx_>w!73^r2d1AnqWs=v i-沾ɣO'ճ;7Isقyd-mUϱU 7Y&*h~)łEMeNYxv3u˾Yr`S:0 zb胵(&8D*ha}6hkfVZ"ი%Gɱ*Fl6 ",;l߿ۭOG\raIXu6w|w5Fz2pGĨr&yTۭz_3(٥貹[Gy0#\Ղax=Ǡq_k5,wnGQܿSH[߶+]|Ouc['ݛ a>E{ث^EJl (",#x%~MJUh>WZawRR{h3BgGV` $ b]u/ ,i~o~zR3̐CesR+f,>p޴@;]X '-[)7 :Yt@g.M/hɭyJ"_  p,P~(q/o@$w"SgBF/DJE&APb30s6ٰ\[whg,I~۱F:Tfl@Ԡo~k)NJ~Rg3KvZZ?{>XW(8(}on(Ȇ?NԀ>t/ QWDW rܦ&Lvp AT<&ML/d o~ b"ŧ%XՐϺ޵ &1aWo :}'a0$O} XrFO}%JGl!T Ơ`5<[)wtaפO-$#ȸl8z-&<ݫXǔ$%=E-{WÐ~: sxB)!ǬKVF>:gH:JN}9XT2<=yӱGG9kH=w}хh(|qnZ3Jj!vf5RY!A_y8}'\d~@f?̩{Dq+Q(qbI.M ~Dv̐!rw4"|c+C}wzfIdxf]?b3(J%D(pcn m`Π>xwza,+X c7>cڴȐ`I 5FVAVIMM&;49~P@>_|e](pX DXa9dɚaO"a.ѬGr3,dk[͎ |aR30Qc`|$k& UXl a/z$8@AǷwl8 P`#Y gxCJP|4m&3sgEڀ-XY :i9yA)ٞ:6VA~[:Dp^,¼r΅[["DFgͨӢiҋ8$H(I3Q\̾#%]NZ}5ԬyI6U)S%#/L+K`"o˖ jqȆ`p2Ztf倮8aN0Jv\4,Wӆ fՅG#Z\Tr{-47Gtb^6 5xzиsKɄRa̾I82h_{[g֨iD^vK땮*-Ζ63g/-@#*.:0 +" Oi@O#!'rrtL7׆ZB($ϛU.^@;5Ac6&D,(:MCoj2Yâi}&uIi&^i<=T9ssZvH \N!Ǧ[oNõ6_qO?:vϜ ~l+byq\+C,aőH A#{)DkޯcW=u}^>۫֠YD]0j NDi詸_i hzݦY-,Z|4d絶g/<ׁY?GEwz9O9~B2cZNs aQ7CęX@z}b:O7>-t C^'or_^|%PY, }4L)l0 fCJJkcٻz`ڈ"a\e1kEV ?~svh-hm9;.(@:p 35QfaKiϺ@TX,,S25[,Vs6 DA*PI@,.(p ``L$H٬ٰpz4f"&b`hF m(0/}m (Qhm +Bnk:z=lJ Fd@-thWn1vbXVeW*Թ >e6f i" A؎H" CP̃@ki&S{ .6Nq}P`xoѦ@!jd0mХ;ųw ose܋hpAY4..lTkZӀ4(rZS 2 lڅ7d\"[Dt@V#2,8Fa!M-AJ a{* 1`b Fv׏~6AH,9a;>B̎JUR`P[&E28 L0;00$84ͻU8=/m̛]n(œ[~rXWc0(.aD |_c/{ϛ[_d@f'1;)!乫6tZ،rN W7~\ΥQ$HyKP7W BA8%N"=5NgNJstB~&:@kqPW9 )сsV%ǻY}"5KvRMd8D2lbqQXjMqt;i 4%\ÅX}wy[^<27t_d;W,KO*0C >.UX4#va0{ ghoCs˼e|ڹ>3l5NCSrg4NW8NHtLqŭX 1[Eo8׌U(ml,j0d4#%+W`3 b!ș޵\3 f`X8>ڰHJ~ HQ'T`" 30(ڡ՚kY思 ,8S3( !kf|(Bqq", JYYB+D> ʝeu tن͑CЍŃpZ]Ueo[&u-:izH-yWl )3HLA2ΜrXqXD{:Lq15Jj$gޥB2-Fx9f¸6t7TzޞX`$S8xuk@V4;KCAn'5V MZ$"Q:b ,_|kLs%+Pvvl뵴ssjPb!Ӻj"]U[k2$YMD1{w븵-c(og3!/Eg9!߼diwjcs7blko?q tt֤@8C ϻZ?s_AO K1H4͝RvcuH2Pd 02bLf7GRwG)ƺ>1wmg|ڈ>߼QjfEc.08 'G9ZH/$6gTD"9 kl =rr}Ⱦ_b[R4;nCoV g6{:k=iE% %+^vQbLN]M㕝|l˓,R2Zf.U(^'Ilo- {Onti$"qbxyE-⭚@3#W]JmٻFm,Yی#붳Q5T>^W)'1cc`A <j4〰\mM/LBHr= C|r!()"F!~wgO}VC]ہhBăkMG߇q p0{|'91鑿SHU#Mzv7&נ8h;c֐f@׿=g|qmy~rR"gͿK;x礴rL|U?Vs$r|DvWz㺋 ~fd2vYƲ\9T^Cɺ9T zcXcTX~.~>ϓR?{{ zO=j_d2T *P9iCu`cs{iJW=,g{VuWo8y>{毌>{4L6[Y]L+C̎:UgG{X {|_g[<~{eqnoДk(WG-[aRO>yKl(]+]m+ϼAsNxyM)dr˷uSz2g5?  V ;&! vQzJNyI, unGJdwCYG~SbK5G|n,T7oh͎V_}w^YK7›>F ů_G|<}ܪCX8l W6r-m!q}kwW;bNPVI-69p%QF _#;5lfUlBTޞwC ?϶P_σ зl˯( (X''cO ; YAa:Ȑ"Z^: xwvp7p\}ĵ@48PUK_Ms4T( A@sxi;,Tǿ^!meN`:|c<p"M<ҚiY0q2j^s2o(3nBW_$%NIx_j?5aZ!޼Mxef 瘶r|]oSC4; } 'ngxgVk[܈~ABDrT#Mז\V/^@YHi=dE0fEBJHUX{)df#P}gS~w Zl*,>k™Y \$5e />l#rUE5>w_ zәXEM찌bR#ԨZ?-JnRh8yUa vԧIЀq~Op7?8葪o oU t) Ote@J $oϸ)zǏ?iJlehZ0}'UKM]jP5Rj;#V8 5.ٕ^[4ëFXFz26Τ]u.Czy L2ئ|H\ ϏPXVq>r#'^vd > 1 $ ~ _H*M潢Q- ׯO/Vr\,_\-ÃDɁUilGGA>240 I%znd+x23ZФb PX&͓#/9Rݙ|9eiE ){j̢A~LD/FY9F.{`tM?FD𧕰KؽQBqW`J\_UT-bmka}1@[WoQ5~V_{=q]pez'Awf2rXjkhn=M]4bP9^TSo?匔3I?Va5w@S^˵Ɵ׼_F=:-H#}c¹/D+E?@QA$mG H9Ib\Q}E~Hr> C-,gM7k/Y}7gɠq ظ6Z,SCʻ.<dY?Tn9n<7k!;Y~T~WT7M_y;WbeY@>ڞ_Ac6p!k,zILUKp,+2=Dx$)N^qÆ}Zһ[Y"XlQ%A|HjW#(r9ՀDMDgy*5a$Xa? 2͠g._xRSuD]N=uZɲ`jtA aP BHېv/9w-pg\M$W1y@}[5w׺wu=S=X-a%/jհm=1'!Os8:kNvnK,^;oW:xw4Vǯ{BF(ig^y]Ze6Kݜ׻zn>://{yޔY:dEokN}_{=[w^twG}_ kCBq>8/w}j7c;_Es{jom.7-,0ۻy9M"/TzHTWczk{s :i֣c!m-h(h QHPU6dUUABzOb@zzea }ӻK\C@4-[7y{ףgRG;y(H([, ]@ƴ6` 5@wiAqp;c):ƀл+:=3wom۵}hZu}}u=Z޾j ܛOvֈUwzwx8yY> }`[{ <@{:(Km/fb 004}p6@۸>(sJ2.}X{5j-D-MV)VV֊cRZ*ṼkYi>F>P}w>>5^i7էэRJ=]FM%uPZOsuq@(*tDR[ C;}ǽN6$t1x +HQvvG`P\Ӟ޸@qr݇@}4]xq wywt^mm+Xt-}繷{[םD\ m@ewfzҵ7+I֛ۧii@L@&4LOM4ѩOSѥ7#`BiM !4'L! 1ɑ3&LIS6&Sڦ4щPfdJz$&5 O4SGQF@i1h@@d4h  4 A 14U3OI4M==OAiɍzzCd24i4dښd0Li@B@bOBb&LhOh!#6M1<5=)#S<)6z4Ȟ#SOR6PQ6h 5!&b4i6#BaOBzS5OSSڦ騞j=OSOS?@HASPɡOP4hz@=G0?D= $fi&naPSB% @@ PA D !$ ۳*ieg_y) /.VZk9!5D`M/ dߒL1QbJ"Yh b"Va )&IeY*HBI$"(%h$((&Xh(AV ; mfR &iz8sO̹ddf)9B2DpsFK?i0㿾'rD{Ki L:Y&8%`Cb9Q/E w*k[A(mF%E XL*DV i`ē bI"HK*!\#r,k +"hՀ r@]gyVs^$!F"\ ,l1,M%TR\,6 1BA Qvѱx1&Ш 1tbٝdInEUdʝ$*ִ"]0BBCm*+*F=3&1d h RuE&mKQX* h()U(%(b[aQ`UV"(P[ vdV.vf.%&RbMWG\ZaZŪ+/wemN΄ҍG-`AQaG-%i27jRlj,PXTkG<gt$սһSCDF( SG5iw+ L2|V,b 4beUh" f&&%3*"!]xM Gz=1~[uu͋4 vd ?5N~je׽Y]Ntt/|1kV!zsy⑨Fĸypq\5;R R"4?L9@HR\/?]83q+j*0"b"jhhfCTeIITcD -lVZ*+ AMaM  @DҢQR8R "TQLKJS$ffI%0PUd5ER * HTe-PQq[QALeImU8Z )-* YDHiUTԓKTP# YdXk0,`Q"-1 İUK#1AEre mD`*V7 eQFA [QXY2"*bi"J*%a[QER1%cDiZXRJ5QRe!ALMdA4H]d61EDQ]YDjYT+bbM9&QDD$DDْ+ET3~")r],_د~* ,W6(5]_ɢMHbTL,)EnG x.qx* Ow6S8 tR7X$0ɰWSܹ]aQ`pN`*L/1c_k%J*&=`FH, *Ü*&eb * `VY*TP*IY4Q-9eP kD& AIZ"[(,p(°ęhsp #^"̵ 4Qah6"hX*1x_R{Yyӗ=c_xٟq{҈`qz8ա*.RQQ 44 O *iEmH() qR6a4K bh P6EUPUULU 9!IPTJ .hh "-Ȃ!r6E]=ImɇR@n[d\:beBV6*UPX `mmffY Ȩ!Y(TF2lZ*QmXU!X҈Esя$(i"fJѻcTnS$Aa-B*j'E5`PlV]2ʁDQD4iw'y[`oD6n KIcG').l:Y [)ŲJH%qq!qS`C&7K>$\S{^c&,EU嫑KRXHAPF"*~]&Yb#VWcr-al D" UTQpWa0i&ʕG*0-a P1U ! +1HH"F c20El0r0dU $Ѭ*(YXX(D!Eb Ek)kdS,EVPj1m+TXZ!LJ@A#Q[ FY*̴ehPTLLXfJXřJd [DH5#YDmV8idJU-f2WLm aeX\c[m*ˉidH pJ\DU,1\hK[iXUElQ9c`,aPQ VT)D7Qd()ɋpΦgfِ: ֒F$R.fOٿΤ_K,Hγsa訢lv1bUFb TӟY麳LV tN e,S >DR1lQЉ!DI8IQ5$ƹ"Be}S*֥b&bsa d| -FFD;n8pHr^&6&i mvm ݼQyydݡɨ Ac,(ۦ̐Ŗ0E]v`HTӓv=^5% FmfG5:c^l⸕vqVP#uh8D!0Gt^&$bٷ[qXZDaZ#mX#Zնmok[2̊uJH9Ibe1b BiEWHQ7HCN.6`mlv]J8dJG*L bUv Y )rB ŎMRcD9ۦnMZo(%DJՂR TX$SUTx6s.5LI4kD $,؀@-]v4n"((D-EH\G-bYYm$b*R bUeqMW V5)@RA:ekh1i2I(J6 " ܲC2v*2Y+XR6͒&Pcl" "6%Rv`I2plɎf뛊l\*`#1ʋ&H؍eL̃VD*. ia.K\ k# (#Zn)1錂LB$aElG"bvpO%6NJwoxA9'D޺ٰG3*U̻nZI6 <!b"65pe6AJΤIaܤyDՐt$C&ݎmԉɓrkyD $P,jk#;!Ud.19v)WNTlBHJhBí!1!XCP.7uREni.#ܳow-_elmʆW P4@-EݰeIHm/(akld=d8ԝB\1xj*T#- Om reP1Y"(J0Z Lb#fOze5dxr#2b1UϿg&Lc&#uy^vI(0rweq57-e f7fu 7]Gi i ΐ}ck[%>tuk,%UV6$J(Egk3FhdcYPt/G6ՋغB?e5TS`Ot8[T9kEXW%'m.4[FҒRaq mɮmFc&vR{߲%KbD-mJifUBo ):,Y ¦Ddq\n2o߾V$m'::nv|'G2Sy6۾_?\0|wDQqLE-ETDA-icXaIAEDJ 'Ed&a¬Iz#: v,aYX4Uêm=R &bJ͓LuBӵPrixDL"I87o Q2AA+EmmEEh[PR9lFEX* -8d73t7j*țHj,mqQ56̐55YD1b͆vm6V KhT5l[K2erȑl!fDa\-j0]cۀ~q٨#e&é˛N|@V=*w;z浺Jn{OH `[tXL2P8 *7yӍ (7L۴a;~Chc*تеKKKJRRo92I.IE*puq Qş~÷3}dXc_IE,(ijT*p]%@Q?ptD+jf$# -Q V'tKvYCaP RNB(Pփlf5e:#$)% 4RP)BAS%1* L؄E&eH`c6p@XD`ʋ8s<Ad֪ dM`b-"+UUYP65iU!Ta~V1}Z#P1 jՏ\0W8s(cBwjUK`xlghA\v7P-P6*a Q`8VU\Fy>y9"1 ;ott#I,MtKUթXXZPX ENXD $T$9bH XФX,QST +s"=E%4PTCCZEU-EF (1D+m+-BTЅAdd5 DRBR45EE-!Hd.C@d*&Lt9 &@ĈRBm%yU db(ګ&d Όabկź=yR(]$)rjVyI#|qJ,UUcJ=w!ё\vX(9Ed&HLC&mdf*L4QvNYyΨF V a%'hħ-X(,=Nu5lkkj1$A$ T8K3ǚLt":4=bvoykf5E93σHq)4x3c'gCȄ¡b<<kh2hU o]I-JJRك2Z%"Ƣ'$zG>ŰYDQDxɔrGiUAb+"ʨ) ;𹩣DPJAM(P4TM1DQQ " @R%P$˜((CN4D:QH[r0s+B-R4&vb-u] E5Gڭu2fΧNze6i,z\mLŒJY:J~NǪ$K+R}(&Ho`ng|dîvKhz}plhcik -oF9!,d"$V?Mdӻߢ=\qq=Ngí!Xj/5ły%)=~V_=1LcsΖLLZ}LX lU+bҦJR49E%$eӐ1 LPEDPC"T+hbRdd41HTQBҍAL@DHR@QAKCSq8DESB4)E1!2VNKFJU -)Bd5:ԛAM5KD9KHd4EC!)CBRP%fJU)CHR4%AHE CZN )(JʜPՐ%l.BwyȴW/50I$m^ބVf 77x=mkAZԳSA0tab%Җ}iCT5&鰅 sʘS;uI`04 l)? iG `"*d|;qf*W1L 0w4cy=OC_&„8x;&5*ͮ\^.4 o]Q #KP!2ɤ1L.I_p㣌,zo%vө9|xK f޵E$od5Ƌet=zYxkd"]$T$)GrxU|;< ;i3F)$!AV^F Z\E xچF r.Uŋ؉^Yv"n{(U΋H9 @PC*YG9Պ;g. q .T$A`ua;=|{?x,}͜0 OwGm7Uhg{z:42B.@ᬊՃx~ͯzc^-Ǵ}?o\oDɅ{[6[tX\_0bXg.e^ u;Xo@IX<}-U˾:NHAD`v!;0ʵߧdTa(jP9S@DM KBҕHдҔ %-s\3رf  IQTµ+g{{`WaX>CH hc*oAB:g (h~st&)S]h48Ȩ+Jc""GV)&ڡc2°  .̨+#a#5@cZ%FHiFL"!꺀۔s:N4Ii!i gW§F&\S)% biV] ,5 )F#@m38Z7KPB@$I2Wws8$ņ.dmroѾ{7Ka$''{>rueMNa(J*QIQUFZ-e`Ph"BLs0#"AB``"EL)*6.RV,lTU,EjFƲEq&KeADD4.*HlTkVlȎ1b*6r*jaETDN2I0b&Ja1A PNN3LUAjb̤F(QHDPXB"cDD¬ J")j(, +Y"DZPDPQAc %K VQbPPT?yCreji2.Q^_,~gQ*W^0AU5=wd=7׍^sbu;%h^4n )<:/TaZeiFS&$㥎:n4d!U#cU5Migw2>p7Rdlc I rn?]Jd݊Qr $R@:AAWTYg>~W~65NZ]|0- lYH%HU9tg,yF00$2yiM{K5w/q3q֤sDT:?qV٧6Q9♟;$\G\G:.|7lN_ܝwNv-b;ں3w7w :!{&S2)ECEZ] LF=IE) `" GY8AJҥ54&V (yI9g7C:;u2iojvR܍KvVAUvGpPadmf_dyKA"]P8r{ TLԈ Hn 2T))p>{,:}ËXg #9qi=%:ETPKFT UQB*\1"@!p>kDhJ.@F 9 A3gAo19~_ 4ktwOqGKNTUD')1>4&,Rw φV+i˳z G( J,*q4ЂJ"!0Iԭج~cŨRB*$8U$LPLDQ5DUGGUi׸(()M P4@-%*4NCҤ,1U*-r(JJiBZF$ZPP,HOu5qy`*o"ȤтAdZk 5Xi ƪBt8GO]P̊dA -gi}8ڕI׮;yOS92ΛE?8_?>-p77"}8іnE]րߊ 6T$\3M !B*8Faϳa-Jt} ד֮/ULc!,VNV P Bk܊O}žKaNjsߓ" hŊ, [ܚɀbq;ٴ7SgeǠx/E+pT)Hb] &Ӟ];:F9[?k}\ӿsL=D4>NԽpZ)Gb(Dy:1DbR :hN{O&D2R+yqٵԶѨۇtqB};Y\TN7|LRT/4':A}v{i?یl!! B*P<1)tOb s#*Q$ɚ/x;ey\<ܞ}RYrX|a˦2'FC۳)쨶H6jq&S^vP.|ܛ?ܵhOlљY]^ɶ p@(+q\Y<(QO)Z JޮS=1E>SXV"Ch~WW<?f}XI֛S +~'_cϚĪ"b""hj̡""hJjj(粩b Bbb* E`r}.i`E5UEPQ1CIIU,b٬a  $! :MH(PR Ba2(RL$h6TՐP҅ R!TЭQDTRБ% DMR DЁIJE<ޜk@g)]{ TfQxZ'K`A +WtĸN!!r -Z9WPy&e:1bXl3[u+PhE9T" @r FJ Ġ–D)X-VQ#3Y+|{`J) I,zM ɖh-xN:šwϙFʏNJshw T78LPȮ*4Ē-ٗ,ȫiǷcnJ._dD/&Yrsg{l$59g/{0 AXXQV37ә"EH){LRpho|pu4v0ie'w<(Sg9`O<Koqh&H@JRUHY<0/ZtKh23A@fZljKMMs_{/<ã eJ T2,$4< x\ v 3_Лm@mBD11!H6*V ̤Y#kVEȥc%aB i&3#Ą0-)Bo1P)p=:k(m̝ qVs)[AeބS1PO :$Ye^{R/紣fuZDUe H"aruC|-7!GX[%fgD~Y늊KbTVC_ZT;Oo/<Μ^70b}Z ,+e Md4+1];z֧n8k^CL^f@LNE"?A& h[4L5^ڥg?ӺȠwGN|@[,2Ý^+F"e ' qI *v:*YFg^4+'b`;vg4TJ*wݓ CP*bNΤT# hޭ Xgjvv(ʝ6# (aΚC*bV,Ͳن ƃ{ŌLj\<5/6M[2P?1*Ly`fY ayyLIX~nN*Oɫdľ?$EB@IKf atfT,âq+syShH{kt+7'Q,%*Ҙ o>˘f75Ek\M7hY1omo:ɤ6HRRHՆX=NbP%]ޯcǓP|zz$פy):DW,% "ʼn6,[ ڐ/ FVBP;T_]r,FhlCV6o¦k*q?>n9x?nZorxlCC-[ݤ+-`z= r+!j $*\\BhSgTU"R X?:+TM1k5#z:yismW.,2ʀͪKу_cX1*7}ԒR̡PW$UFlfzx@S* +]׹Kvr(*jmxZ_eG_3)j?3I>O<$$Ƥ'Ė Ĭ9iYJ,G2ܴ AMZ b:U"**+APs\Y&BaQ Z2 2¨ 4T`*&Z t4ENf ߆<É0Cə{fBB)Ē.{N=Vbi bǔ*cq,* jذ4]\Lu;j"/~,&W~;xvto-\*4[si,BF*\U.% B6AUYd^#+sdy52$!2c\ ̣1RrQNdZ6LZ!$^.d*MpHjk[ɗQ,r7*)(c\M{Ψ7)5g% GN&\YiCfZ. 72 H(E2)!PJdRA@FYR.bFWNn-,K1,i# F[3(8+ ym&ǜ7&+r $sesHi`q}2IQ29Y8$퐀9 90D#v;Vl."Lڬ,mHD)kVJY`F'&-Wq4esC I S50+s7)di&*ɀ6Ys[֨dE:o o J-ͻF.9MJd,ۛ@*sg4%s)Ct"e`1ZZh9ac**\EݔGnNNR/..6agshdT%E Z֜Ę&VTOզMKce6iX˪]nL\&e!RIJI*B#.;!))!B l#[ nH0W1qW5P.ل1eEъ8#a]ݲn.jLU2Y[]IM)r X8Xj6K9c#f|ɸٮ\ *rfct4 !-+k_Y7&iP^,B8u2reY ĂRCK PRe8CXq!A ]T[3(H\*D 8k[D)SFԪcrcbE^(+$eV0sir0y3łLQ# sPF3]d\-n-J bk1Nrdwr9f9h;#HKrY8iE㊵F%@dl94y %0s2Ѧ؜I/ͭvJUbABQ+͕]"CGd9e vAjB,wbԘkϭUQlWV6je2"J4p$c566hnpjq q-Q8ǒlv93UMѨP$ lIx l!\%E(各$l%XYIdHI"wvW:x !R<ykDP~}]=q/s||w_w4R.S?K 6zC髋(jT҈OLW}d`%x;L4PV[BJ;L`xW[[{hCe *T|uÂACl @E޴JdRC4P"MUT 7.hhACE L@jJV!Ld\3-/يq=P6fIar ѹ|uE7Ֆ@Pak(pɌƸحEJ-,JP)h(m j89o*e[wuNaF2Pa%)((Z) Z F2 1lM^@C5}:7_*,1)"%ĔbqP HJIDp+USɷ_yU08.16SA,(;-U.Dt`"b_qWVbZtH"+l1+C@XŸAT,(@b*$crorvw񊈈+8ηwO$  P չD$2ʥXq6E(0Sti1{~ϋw>_~%W/pRۂrx%;I e]|w$u%>$auZ m4|̝B "!<4yjN8v;vÕL@O?0/5@֙Jp'Sih(Iz9a5jЭ_Vnr9gķAZeũuu)t7{6VHBB19,(:oUX6]<@ZNV' 0) (%qUAETFBipS鵦k7UTkj5N ? 8/7Ve;/M8Ѓ>wWGbimmkn RHa݇E6rNU>+k9bdCI%rO+iFz];x4-շ؅0Ȧ̤D!˶ՙE4ZࠠTw^gؙOc~`\Ǥ,#ʒ]J;uGFaÁpN٣%Y!E"P ZvvEemeW3ÌS9社 J9) txn$Z၂?MWl<\~骠%REh!aY}>ߟb^y7MOPSjXD~`1TE%IADF k͈ A&#~T uϽiHؤI!1DD|q[?JNF|<&K!X5 E@h)"ۯ6 # ( jr" "J& ]^v7HP%@RIE%#E!JRRQH2h;שR+w< Bڄ@T##_V%yy>' I7V_cy#W k`)JEF;gxc|F=ÑK'+6Oe,MߔoܙGߓeX2TSа+h?ݜLkܽ嶗m[~ %B[v WV#(LBiJ) iQ))K'{~%PohP@TvB%- v*8T~{ ?[HMTvU>C5o>9k N1FxMC,>$HE4sעqbCXM)jY]]5m 5T0R n>o݁$ -Sv@#Ǽ"P)Ol5,Zn_}+ ʡ:j;h;PIb[W@W \;~+T#UU$TZ* $!>}^ǿf dg+ղϐNHUK,XG*#'χy.A@IA#P_ƾoi2''3uFKPT TQ"(" R`1eG8SISTTU۝hoͨc>kt5U(|P\aؚ%"D]Ot;]mTI,>CXʿ",UE}Fkީ*Q|#ltFj|G%z>֜ڍ}joQ6^UP=#fth-H)K&]t6mB\*#т*S;T]B֝ne4q8f6T|r9&lN3]ÑnSUGWQelb\dZz_=9.hP 4 010$GAa+C;[_:bqL`{::c>qcFw~wp7}CI`@csm TEJ-FX"6ǟ&)_/7naPUNȋjO/0@E Y@ ҴBp2ӎ[[ذ%XC}`@sgz])e/w`>5H7n]m{>mDs>b_(9 *Q(H( tL%7zZNR ŹdhFE\ \vgٸxJRlDXVٕY(4j^͔>S3j5F+ w6>2xUs%P*5}Y*4\C-Mx,BLJન@{S|j$hn(PVN0d?2p왲(W& jPfĴC(b}Me52QQqTWjZ.;`FT%eTت~h q n) b,(;&L405 P^(PQ)Kү`=^R,L( [To l ]|YW(v:*JB/ېYb3#3s%s|x1";ҴD'= M1m޷6e5Қ`5{j^=Jgq45ݼ|QW(nH$2cׅ#qMd@.7{* µ=Pڙ} bn1|t/*xڮxJlV_+`jZw9.u%0kO&TYN63'g sS0N5ФH`vEzƔ>n~\!=|> qHJKDɸPC3`LX-QPab LJm*SZ I%A, 3m#XDءFdYd%[I)1*IL +X-KcRY)5ES)I(tV~{ +xV~m*Lɧgw MDMEP@DQSUB-;%EPH&4!FZ 3Ơ!\շtӭS׵FɌwAm)!zTJdo=p>S*<t ("(šb ," ?{,t)n~,G.Hc"ޅ?rZd۬pӇV׎+c> :l)"ꢵ/NNRJKVR d2bgbEOP<%C p,YeA ?](CXU5T9yF뾘4~_ą ,AxC:ǵė&UE%<5qK/7qs劎{A𚁆eʥh\Up&l)UȇsK: RF VUy~1*JJ\}X,fh1ʷ.G[m\~)jQI#\t_-^V]ɆUUd8 CљaV?9} -UT`D07J @GFgm*eEWY`h00FlS.S(]׍ed>kb#iWmM '0Ÿs@:v&uT뛛"B6 ʿsi+M"-41(.Xo禝9/|Jᑭ'l?p4?W-R5T[T Ԑ&pPΣ;gi7fyg_ێ⢈"q2 wt#QxYL~dQ#'m"6zAQa(BkT t ka2^{G2{J!!aיDѩ"%ҡ)"ڱ{4L[9U5 =K }Z*o $?Ǘߢr@Bs)zR"ԯF9ᦑ"L˨S m% ,2/o+EPG)2>zp<Ƞ~| )դEiJFK%:{Nb7R)?}nɥ|uXm29ͦxf]2)墈3ig].oPv`jfG#x/pd?((ūQ]Ph2փVTkBEpZe?t_ffܠ=/Z^6fhiRGFN9Voi f>? Nd$w3StqJK-Q+Kәlѩb*"X%h梆<k`b1Bt8+JG 8p9T`Ɂ.o$]il =?{};9ȃvr jmkq`KsEZT A+!Y ةbUBҸ->-="1*F V7[@cFo=ƫ (*!Q@Gu CX;IJQ8[zwsr}o4!*QnՄ83NifF.%s@E\?Ѳ6c:x! ,DSةʊb8,+s Is,2A OzwR?B˓9)(1!Ly$StH__i~)A$uf99~>ixuED"q6xCT2R|yimnOB]I[,BkB( @emW6ȓun{_]UUuR U݃eC˴ta8b)0ID{ [ͨ͐+uj>9 =N ? 0ƒ3Tm/t[r/gq4c <%c{[+a%1ȅ %Tw}H jS" $,O|ڜ%u-8<:6$FeDzf7@$%RFޘÇjޟ%9" 83HgXmeS\lñ%Əl>*&(y:KH Lߑ sF?LJ)-T@}^DS l?W'{rdפ !" SSKՅ7-4`UV^ 3 AGW30@^~Nq 0µՈ[iWvׯ Y@Pf1>U96T ov/Pn$t3. (,DV#X/ wX'`a$!XcłE J~翵3[W$u-#$sozɶsI&FEU%L*VTD;O਱>*Hō p M+ kʦ !1?ci-;I}qVss[|@|\ Y_Rg1()dR}ֵla)XjNenCʳ8]c"1xukn9ZY>1cܧok9 !^U@u߸)2isfaƴ=A Cas5UWo,QUx 9ÎB+Yٿq3`ʝ鹢s'!V""1OFQm(#-DDPbt.dQD5 MX+hҖ7w3cIP~rB~I.I! Lm\K=/|! -vԳ~écbL@XP c3 U ,Q?ᤍ'obPs/C'K^,1SEVmUEb9:'E<ڏ=.٩-K8Pk_Iip1a+Mjn@jpPp 9՛Ŕй rⰪ{Ԏ?˒> ^>oҷLt^0EW8ntyzྫRӐ{0]تK ި߆8m!t@Dj*C>f35%O$I/T׽ܞ&!f}1sn44q(, ]h>0͆mv~CD䡣u!W5͎<@>$Oǚjh/eg@1Hެon2>Y@d_4oZTbĂ CЁm<G☽j1RƆDYrtWg&@ɻP^Hx>)KNM_X&we_/?ӯg>{/4k:,n 9W Uˎ_Olz綋lH)E'Zf\Nc'yv,㧙䀋t:fp͙ qs;Y,׽4v*G>zC w.*UWh1"З:HeQ{p0UuJwOxX @̞oWd$]BKlzx}FZ.ҔX (UU *~Z.֛ؒ, @[ʌ—)b dLT1jֵ-O֚궩 *?_ST)2P%H)(()h)R L B)*0d%RH%h( )hSP! $) h((b(ii]JR%2VJ,hq@)ZF*"Rh p( Z Qh)j*i(B)hBG!2l b)()(i)J(J()CG!)VRiri @APPHjS&* gO)DKXuIBd (HW.,Wg+k(Er#J?sӑY3FcBj `ayCB֣(Zׁ~zU@׈"x뭌~5H%XkX*UmX4%Gm|w9+*P(A8;s0POeل>߽)E7 wQP.>Z1Mzրa:tn9B1GL-b#zWijRʟPctF0_6/&Z+&CuFSX}8^L—8M@  X_G;:l pb)6ji>F4vo5%֞x.D% aT`[Z(o";32!d3W#վ}L{_W 'ȍ WGې r\fƛPnj>W BP´ Z3($ E FVƒ)D6q,g/"KNZ1GcF?넴A.s/D^P.X!k];%N  J9S~wV[j!C [TM ]wĪ Y#m",DA˜RĊ:V\g~ *6g`QU[W Ҟx|YlGOQuH"=#֐ŭq"qJ*AE@P&oj_–Tn_` SR%pd(UCVPG4Zٱ|/F+MO|ّGWâr; וJOtÓ2ׯ-x:⌿DZmñ1s=VwCokQC7D1AIQ,W{ϦG'|_IMrd@δ0v_bµ`BibgVƘO;?|țR֑󈩶vYrŒuF=ܱET;H!3ߴ͹zCE!Y26^{(k 'ҒW`7-)J0 EkU1csQןǖSFwsP+^(l1GZ! b8JG?WnF_yL_`yNim;B3D[z?Q;b#ߋt %=a;1R9[aXRXAA`,*JAV(dĘc"QVRJd7C]jn|k[Cs3gn?eo9[JFya,Z۷ŀibPp>GLtoنr_z!Z4kУ=89tO[jb/?_lBLn MNo0g'\7s>lWl8Fc0݉~E:X#=ݰ`2T+`SjF%OXON1@TGJi2 aM}d|MP^ ,*UgoMM1 `sEX=Q)pJbxR*ti„ٚ;C,m9V/l{k]r*ߣA +~x ^B*AZIOQlU.$Ye JH.Y}!0R #& +a8TXD6uH-x ; 'N%.Qu\y>LǼv^ת©lg^V.ud`$:޼GN_g'ayul;,\|w61Z3Τrsm9۟+vOXioE<mCʺ 2cfPO*6῾;ku|t*? ymSUbOˣj;>*xC1fr0[ٔѲH?H6\IteT Xe!b{~QM~?]ǻ=,QlY:QbצX>ڵ:.t8]bh=/-Dgs9{ȏq{ 0'}!n:ڣ(Q$YՂ\*B[WVUWk6Fr 7+C \4S{֋ <5@'~n UV6˥ # 9sF^>\7dDtOwsRfܹ_~džZVS|2\67wtj)i7XG2/9z%݋JK#tZq;4ǿcv>YO,c\Th ) idbt" 1X vlUP1o(T[+?BWx'aH$oX4\vgj5IDk+جQؿ&QT w]#3y1eycJE4-:~gz.=ݬŞӔ#3*sEG8 zTB6>k7 8#׆3S=FNm@!#*'TJ5]ilJi RB,e~Ѩ-Ɋc dkϦM%~݋ZUV;sEb߹ER I[Jܷ[))ub0QHfe ?c{E]9SdvB.W?،~2J CCKF!ݞ\~gd<PRpdGw ;vfD{c-5I=^X׳}V="!J]#4'|[x*L`,p]w~<l|w`"vfRR4M/ hLrhfHnFڢ)SwÌO*W]hQ!b(fWeJ ll+ \QYTA /`ABP||:_BB^Ag=jJ[ ZV+6>?=\"I?r': SfTl5Ш$ﺊ, 4j_A@P% Cp,G'; ך *B40xdP R,iv9z]tk {k5#F%AB<|ߘpSvtZFcT}(KQ@m=G L$ 8{^nH%[W7]_La7ZM:JV'26+fۏ:KZ? Y 1;Ɏ{q# Bb,}}5f a< |s&f1af349+_Jћ 9dZ3dr SP a  ~yޅ*% Bfu(TD4C}"$O?G'䝪CkoH+Ądu)!~?-}rPa2gQ2!Dc-W%sR"7aU0~wf|}n2 GIr}6[?A= I""w^ ?յ~ۍaEio} KaN{$t0.)xX%amCUQ޳By[ jߖ# ZBwB@;l9o^lrZh)RJ@mP33L ˶,"ů.&QzC4~b7@nkZpz&cd*-DȣTFC]s ̈{Sϫ?GciǓ8e@xxUf7G:rj9:>t p/1uo;uW:;obe!QQH!U8D&Bma'?ݫ3x;-*VH򮊬s42fF>Uqk R@Ur$|3iRT$hgh+~y%9݋F[#] wpȠB!7fm 8i;*˚f%.YQE4(U>eM.<GL4SM%G\ KQ%w͑e?_2Џ~^s( 7~*ȇn~mb[ SD/~Sz v$!QlMV |a* RJTQד 89mg=& ^KRGŸo9F U ~B_XG_?6Uxq,ñD)4ta}Lb<6ЍvcYwB֚(XʥEM;}9FcJ#bqqt!($v@Nɨ'm5J_ $Sf 5d&"+5* g}f nےO3( ]6f64(f߅ $̂L41aF9n=?7~X4N^jPv\*㥜>?&QA$x Ul,aFV!|^/vOe/ϼL7MW'U*U`..#4ǜ5iguu\ưI%wVEAQ;bp\~NJ f V!q? (|?d0qUE΢^3 3ZJJV4{(#ޫ>^Xm?N~-C3Fa4/xO $ŅWjG&J9l}_)ߏݚip. R}iSO{9s~\?,?3 s륰8^#UTPypM^{֨`1|s6}*BޘWj"5~>ԵBN>߹<n1D׮F|T=Zg+q>UOG6T6;nc {;r–1EMIdXB??;uVEb 帔~ϛNpFeĐU}7lcmK}Ԏ[eo)Y**eOnLR'Nag'FPoK=? -*mw v屷`Jx1V{v[㙐4oB{$h5 P+[j9RAN ")5lLK^xB%T&xT%X)ȦSwU@iNdn]L6٠{e`ΰƳF)ORLR> J{cYH|C`}Q-bWH)X#Th@ њt dF'Ei|=:VP7Jh L"{NϯN3?ZP,KڪB&*`|/oDC>Q(U} wyj)gtpWVhO,QLO)gO!M3S[H( =Xuxe&FMvIx*__/t;Mb WU]zB?u-UZގxa;e*TJwݼ*h Ϊ_HO…A$+Ig2~Ѐ/w ZA" uXcQ?QZ"9Da;L$of!Sڌ^ݰ);ppҠiHw1+wXTZy,ۍG k/?4E>GB.? n,BeT S2LHyN )TyAhdX!:?Vm:-U;gR 85Ɗ,t~%ѕVC)=ִ|A`Ro>\o2+9E!FV$N3'fH4n m/JsP:X\ARBOeJ*_Q(Plݗ7(8Aڋ1)PdZ)۫Ld`۳dTK[IUk.8`#, 'b5s1 <d 1kz@י~p)꨸ڔ0ml٠QA~[\]=ctxGrnU\9aiZ$KtA UTYQJiy&_ޗdQCU_oBIQe6v٥4-c[#,,jJX!A TQXCಿNh&-@kQg|UˤZ fT07u/uP&'ɔ0P1J~_RLidKhB|&'F3ceɌalW&a51}KAWZJ<9>8°M~#zo` Vwn}Eh׹(i0p-/ ÁT/7^/"յ0ٷ~ǴRNĨ^0~IJ_(jOבۿE͝^֖ ,aIS,oP/KSXG@jL6cau̱ _x? )o7k ~Ysux{5)ed U\Nd#wуgZeIU3GzJ^F_Y. ~W}*1:F!, KL?_p 124LEJ".~ۧ0]D?CcwG$ p}(wXlؤ§Rwbʞ͖ x$EJcJ,蚄u .JX~>@aڗ̮-_kmX^JB vG"mlŸY V# @BJ^ql~qnB aPb/ߓִ + }3q+O @^+-4la7ؗ*{ 0f`8fFڰ-X:ޝP"ۙB,=ZӘPyL|;J,m8">>&}6S  ҥ#eW[hffaPޗْ@)D!Uk?~0B޽V. X{q iRW^.&ÁIŨ^^nI z8A2"QTe.%,SXepI$*eiVV- \`+- [J(3&9_P+,HtC_S4G$LOb[=G/-Fe~+"B//#K+ ࠌd/OS_foХn;Q^rDjIU7$U_!ŰBxaT â`)ZJ`|\mkJ@OuqRI B0چ2XG<3/^8Q":jF Ux  UI@דow'K, C$Hi {cCL"N<"ѓntjLoeT h8,do: \&-kL+Ŋsvض5`ߙ@{Sbk b0lY༝@J[Od8TvRf>w_=ܥ)a}(@CQ/չ5}0YbttO7 76^;Nu tN.ffCs&PH 5C`¬2: a^ԠJM+uD+}m4Y*X#¸o5΄K dV) 7GD{9Eq|j\ӎO[ْ(),{_iʣd^p2_V dgh{̜»ZgLZ= k)=I3,܁ p I&~fRS&JI;}G'*PzKv  ̓$?(x ,| Mx՞P~k-yYg+nPڣ(F15 `*y DB5?hLvyYjpRob5eY vr%Z=HP-1 $;Sxo0* *8GۊΉtju3aGGޟsF)T1OwDzo WPnڅIFءTOwYɭ=a۹. "RT\u/*拋6f*EF!_}Gۏ, H>ӭNeӰ# ivVakϿ[c:v f> c@$)ܩ?˗t3fo{RKkIH\b-jwߛ$yŏe4E'2LOa*EE$D&]sj^./cG7i5cAٿ;&?;oJ(2,`ZJ W5@jpmேSI9$˗8%;% 1џ e`qwP,Y~iO\yimrHom`m~aǎyFD0vw\S⇏C5}^Z?0_5N/RQ]\c쌬 `?+Swgh5h߿ܐzʺ|7[%^vɅb}. {?NXf|-菊֛kTCRʿ|k7@p R?߮zży`;; =6 pY@R>F/f4ԥ!̰EFk-Crc. "jY?q>w<_jk['2/Qѓ_a/QPi"4mEt 5[vvw̥[+gU~h'fO!Rly|1:M>\}s<ф|腑t90gL6X߂QOڀ#ye Q+.?]x~a8^絥1@4d\={NCmErXlK>sA},팿~-[2RBB:|FȢs4BFtwfp>-%$(Q |nX5g9G|tج5\dQ# ˏ￟2ArEwǦ:# 5IUPrS/?kΝv}{[wܳ3iʃ6os˗kS|%KnQ%KQйA ϲw6ʷ[đ{ )s}gܴd--ʋlim++,WGYPDFT.v "{-zJ> UkF"+=>mP ǽEwz>j8-n~ϣdS$i4 ̠?_+z Ϙ* %(KyڴԻR;c!`U2/6 vuӺ?08'7*Ohg&ώ}::TZqVa Z%ɬGh XKMc|ok)@}ױx=+xYݻHϱt(쭓ZUҍ-I6|ނ1 p[{P(a,SnxmZG33oL~_'y[M;,/vm.%/z<%p|BEG,im mK77kxcJ7UQ%Ơ<_G#; ˙Ͻ ˁT4~]qLN΅Gs\>ގ5U *ؑh"`vYWUP< ʘ,BM Z`q>aTmQ݀mew FIF5oZo{{RWP+3T2U6 *+ zt6m}AE睤>g_Mݱ~ϗ'JNHPPmX|Ah 4|_j˂١&aodD8- k7+fhwըD]mt lЧa1nѾ]03c $ Sl5Y .WaX.O#y)j<'eቫV S)h)!ʄb[&W}f- )W/Z"t7d83;DZ*]@뿠=zuUlގ@CuK_?V'g '\8xωiUW ߱lŠ}q>[c.&U !DF1-jםډ4׫Q1F 8b7,4)3;oKFᖺWvʇ%HAqgM;>_5˵Řr:%fyG ןdyw :rlr4¨PGP:sY+SOBK"Õm9;+ #bpR? ޓmfo»/SSWCydRxе~_g6{R7y4{~%NTVAC:fݍ iuTX,[B@Yկ8CڥPbY=⾪ט!ϵqB9>fs6 u;Sk> UOtݕ jw I^9e-dO+~_Gs& +(@P^_.ۦ yR_WwN=an,>$el6_rn<%υdT-kf͉><8Ǹqb+ʋ8߾FT[1ܝCC֒RU[K@+ޟcףgn5LZ Om) AMcBO/Uh|O'f`ݱ.?'#>ի:a#3oYU6eκQo4)enżZw~:/sn6$N cΪQ`@@S= V DXhcvqWkџ.λ}V/bUl t,2wT՟ R }4vg@,7.E9كE]5W>5_ӶHm!~s6J& [Ү/}W~ֿfՊnaE@<0Σl1|u\ڪph%Ȫ%^?VQxNz ymj1:.(:! }OGεdSxb8deon+ǐ@AYW?/Ԏ rdL0-GJSx=_}+i]^q>yd{Ѱ $%% #;yzF.ߪ?Zqqڨ~(]~g&ּA6LdaJ1YݛG]=[>*E ORۣcKkC|wcX]z鸢jtu摇*.=~A (y1#NO+0Z>d^4=@_s- [Q5wd+; 5.EeFF!50~|vF:M2ֱ#k?aNq:rZeU|S{qsu~uUPG&={TUU#1K7|xkbfc~<!( ֓=#>F$ (/fFuw M4'OHū:]<ץ2şfћ̖ w;4kw&[ԝ.%XJqc9N]j,1H7Ё`#!jN/i)-<h_6ևrkrt~Sɩ Zh4h5ÐrZQkm`:S?^uelfiP8(5_}KK(o+h<ξ6< gJs°];TCXDf#ۂoC`4a <ƕɌf{& LXjO-d.7콘ɦRe6||_yGۂ@ng\{T59Pn=Q!MҖ\*rA-x9aAn`zm]دQߎ"YL7`aa׵nCرR>q(HSL5JV_G љd;ŝOܼ"/ʼnB TQPQ ɯᬝs5^s=}E}j y 'bIFtJt[_⯺`;+E Z-\C$C P4T򏞳~ɻ}2 g:ۮ_`4h,vڳj}c:q\#9q_+.N}lw$5k-J \Ջ/}~/V Ⱦ 2\O&biKs_FZ1b7^@Ěi~[t޾;Ҷ~K||+W\Ɩ֕8ǘMj̜{S-sڍ[pmm\hEg =? Vk-9cbmB[4w[}n<-뽵ڰwβE4Ke[ٮeD^dRj[Tڢ7W-4j02NnVfŨw5WJ.y3 -.أ=[,1K;  VjSkǓq69vs7o֯aBSͤS-Rqb]ݤ 90LHZ>G',:nqai{2-։aHz_ lL@.r|jC 35U{k,䷿| {Äţ3^Fxl)i<ŸV,bOʃn?}!iq„OĪ8e]x̎e6 wP8X=wOUG`ݳ1G[QQFRV| L|YK|iw(mYW޼Rl=}HeJ\u:.29`>ϭc=zŖ'b6HZ~SZf.ɕ+ԧ"z912M)4lϒ}lac]9;q2^s-~Ϧ%W'j㩠~ ksZD*6M^Z(۫;i -.L˭˔9Y+Yz}-d cߝzGΏɔ1^T3;| f\ȝeݺkml[~^Ԅ$$ IIwaZ-̡+ǣex@KɈ* [IFYT%[Cɡi!"6LRk1(6P+CZ#P;͑["&)(B1P0R"tZДv$ϕ7ȼ2O?Ew2b D$S%lxٿhBP$f6$d(abA@^PZPT6 ) )RJDUiHZZJB"J(B()D("T٤2h(B5  $U :T;bc9(I*a4,ZHdv^MZnhEbՕ%-bh~rqLϯtivGfEc4ʫ[ jER1AݢaQ!^-EvG۱v"3!o}{{7ԢBH!ACrٝNJrP <~*$[JT]6=?e=mЯ6r46A6CJ S`k8p4)S"Yܶr MRy.ִlMZIÝwelyk' +1Xű|N/oHX&W%B<'29C{nC/.drX9bUF`-Ad+*W:P' ?<_C-~&m/ֶ /-+moyko,mTM&vnT~8oNXUcz0\7q:q$?⭼쏠o2HUE$ϣ3a*=\u4*#q_˳[y3v9p37n@:Vbi/SLHuJ;'_uS* 7Xt̰VX^s9v2da%8KΦFEc4|4iy76dW ,Y:DFdei@fWI\CBtKI&\Y.+A!~ w+%g P1Mb[+] ^tڪ^\-biGwV<-.‘7;ngLhtUfUVz'?UL5XQdQXOS'=93rnqsG9+)̴=akc/ z+UvdQW٢+uFN2*4#Wj.̿#QL<"tQ~^ w$Ȯi\|6\0k>gF6Vtj r4fs²~RЮ脄5d]9켤EV-.;5r,lV;?ӥP2a" ^*(j*cJ@مl2Me@5/j]uqW^&3 Yk\h[&iW=wqR?>r3mrv5 "ܛ\9*?YxoR\XuȸaNplAOڧfz2\d cHD4PUBDO<7selSjה[h R.73LvjQl ,WXA@]]2d~|K?) 7˧S@;JEmiQz!==g(v7Vhg%6]zi6YLGd ҉d19r!0%e { Av&=fl7"DK`cpi t\˅%nm,4P(^PǪ *LVG|QJ0w;vtKzyxcEy %!9,Lh9ˠY Yla !3Y[|Bʌ:],]UkmSnP2UDpvoQ[D g[RkQ DN0(U(컊o+9DΣƀon$N;1Ӧؗli$@ŏ`ZLN*[?VN@2%֧ѥeiXMXtUp O%3zp]xxg@'CҢ$4DMG~k\HSz`1G{^:w|]ޘϵRb$T^j\fb+0ܦQ;q Ӷg+8mHC:]B`V lYξr>u1Dl1{b#_b=j8c `"ZM%͗HΟM}Zs=.E`Si5B[O9 D)EXcN$T#0] ɬ(cEbJE)bOT0[`^Ȍh +vgj[d-b{#L&o\CS^yĨ|QtJU)%A\֩2\Ig͚r^3_YG3z9dF@u;t,(?ڮ>H8@sլYHNZ(%)S*bwazNmP? 7P9v=T|0) FgBJwyBW'6xTK~W+e=mնф 6i'bXʗd|_"=}#,~@a(}"Oa*RyjP)?^Hu+~_M9af5`4 @B鸀{*?_Q/8IvG;9&'s?~_¿Qp{D6ǐW[r3G8?~Zq{9pM 9"Q{]15s(6N9# ]̻܌&z7?-/aq8ϛ0ٹCZ-t򛃶QJH(eX_gJ&c~Qz<]K.a<а4sōLD@Q0DL%G_Y:#Q?'iL4/J|&d_RTU$$5H~ڠS2 RSuڿMt(wsRmTӤAˆtm`rNE#F oϤ9Kh_Lؠހ]#^?""OF6$5om|d)%WX^ \Sz?*]z؆,p 5+lWQPbUhxWWd6̠9{:$eXr\ 3bṂZF҇dR YBeR[ym]m9JL$%.)$" jv\h|t %%t$Z'G.LS3%(bϰ 9鎙!xHG^2VԝXX+_t'_+?IO٨9sȌT @jy%'u?~yCS繌9RE5B)jE1 łrXADPR >-^lH{!Qm90S%=' ߤBhІ.0 UҰx\9sP hIqM8m^>ܘ 2{Kŋp$F pB0Qɤsz:ʈĤ?OP܉(UmNRV*aVy1;q -T]>@>9ytx9`!\A`"aBR_NqǸ5fޕJD*a?L(KZȢ̄~ yʔa("]Vlv5pw$)h3 dsbBRb6%n:̌Q5uB"١#W](\gX#'v`P KIP9B ' ᏗDg ttU2QJR>hlUĮ"=&̫y3*.ئ!11nX"bU )c>kkP+o8:Nhbm\ h@|Mk1 1 C%0 !p9t˹'PR)Q4R+-0KAJTd 4JH+ܐLM9B ʪdPHAJ#y8".hϐv`A) LQ~vU@Ef V)QpA%Q&(r7 R R$Pw9"*&*IiA f !ckTٙ!U7@2K @pB*u)L̬B ~(!2(i  & *DP@O" RCA@P,$nTD]QBTL B* 8." $$QtHk3!(i ($72efffj@U$MJEMT $U(" $J R%*91 dBi)i%ZEVV(%P@Rh(@6bBL 6"()eb `)JBuk@Ja+JK!@BRPo($w@* HHDDHp*e4B5)[C(" J}Q  , wy1)|08OH 〣僺Jd2B([m&"U"i(CKC QHe@8@r<$Æ# j)YH35IHTLA @PҦf' JT7ɓd4 @TU) &f5P-n")w@S&F$FHEt˖aX,2T/2HnDIRSE )&!)(.R.`2a-d%Q !-l3I#hW5t 5ǦTC!8Yjrisײla׊>M+"ȃoEX*ÎwIѐr80  uqg,,րZUPRtMm")Hd iU )0R+;)7E TH1^n|<z7 I R*J0Y nSL1rR$C2pX%d @FBRP7`Iʤ ֔3Z'$ᩤt28KXA= 7dsDH"c M^`dc m!:>ݠDBlJItR $BjU$M-PU2uႀw (rJdʜP J)tN`F 4~TӃUP:Z)Ќ"gh}h2IV6pBcJq5I$'QA7Dbz ;nsfs=KW*՗םz$>%]<]W;9|\^gC?6-'KhƏ'G:Ϊfkj9gCF ^vJ; n grW:ާwc(wmڱƲSn^捎V8-ִ.89ubdol ow5I//^.oO,k܊֛{{7cK(~e!'2(Pz.s|TyGl452otu ]8"!KȪ J7}_N)4Jc ],> v(|5{mh1@n9<Ȣ e:xkJeg[a̺\HbtnOi6JǛJ(ݳiZlTzDtM6]3@EaEY.!W4oR쓼c"8~cXU;%#\G.5DV̐A=[~ /@ "޵~T(27"yī<9@Ƕ5 B93u/; ` ,(Rqj*US5kfnàƧ[yy>=H)D.>ك=] \dG޷ד6sáA @ C*V:=߰Y8r9+d<Z*IRl9&yH bJڦjBLQ眦Ÿ˼)q+R=v@+54\),G_1a3~s=ST9'&aN \xp4=\=Ų*$3USZcZ35HMk\@/;ӢKٵU %NJ#Z"6$>`OXyK^nrPD'wށIjSq q[Lj"7V -p'p;J%W zx Ds2D|siggיNv;Uc#VMk36N$l$dL@ @"@7HR8G`g w\A櫁SRG4= oW]`s+{Hha`o@@($TR"e,F'`PQWrNz]dط70|NƜZo!B\&S1л8L^<cp8SK0.ߪ=OO||5G;vc:[(WWy3y=oۃwi::cgxpr7l&և:yIIP{ X+ Et@Jv IffS ;mllT$uRX vȪdRJZrZ23ƫÐZwp[MTvedvwLZ4UbSEA}5 *g鱝THxY?|n`N."xD9R.Qxp С%݀Wj,ϑCAkR$ z loǩ @8sǏg;ZI7k%.NC<]Y#Z!* ]j et|y7hΖaʗTgf;o:lZ֝f&\@ PCȚ했MڳMͶIEHyT[Y]Nn){*wfA)A 0r8Z%ٝ+Ysv*#1٫=ځ3 57J-bvHJx. w=S~a8&LkUMT^')Xǖws`rSE !"a *)eEMNm ncsTmA%q8> "9[Jfah%lŎvǖXs@ç:@*mLfs?pcdw"w,Rݯ(~W0n$g@#~ ۧTuls؟`B@$-&D"*xIih$DO2 *z^<_G`҂O?ǟ%((!?ӑOWw2rN{?i@!!7YANJ>2!!=0e5'|i'gЫL޶KWHM0X﫳|Z|t$Z^(z?zm,Q>\lqƸlkr+CVC.Ӥx7 *4ӛ odojê;Kvޠ_ԛ0Muގٲm8G= 2ZPqsN>>8)9k'fy˰LҮc{fi,;MS=[u6z5ٛȿj74E>*Z_],߳bd|?ɧdM`38z %گBQvk?ʊCL[+8؏.hŷM=[n[F q{)= etzhM”߷Zy%%Ŋݯ55n~IP1ּ7#3ϦKּ b!7_*UXW屌\8^š"kÌ2841Ȧ~#vc,פDpnjpkj57PO\)V`y1B"!3ݒc} Yqm5T5 yUۗ=Z)e,62LSƢ#!'!pR,;C'ŕ1iC+eqmSAngiKb,]R0;:^9^RHqHBeez.@E1 yoC nNɪB<1|VUo#'sMX{XsҝźNQ 0Qpr6eG9FaX$IU3:\P]mSi3_wi.W+( Q|жWK GbQ$k:UQInX($oǜz|]{\jX2Xt]ٓiRM3IK=9Xa):!7]@XCNք:ߋ_ZĿ3A'E-~7kӾU˧ց@34Q褙6t֠,!ڜo=1䆬C4磂M'3iʤ0i@j(}й;91N#nH]=f ,=0 .] W Cv|fkMR2*lGC#wH,KFxZ:*" t#>l QKdPN|b8|M]uW %QGrŗ1H MIux q 7I:R^`y k,IUN%asg*6X4XݦES&0huFYbl]'A>X7ynghjhpΆN2uo,IJiPg#l@ 8?|0ZYo+%ȇ`Oaݭҿ-q2:K_@\=۸-~etֻί% tim-Ƚ[Tش,V|ΛDhyTCbmSaMct:X,]c-gۀZ(UA#&}_fRX4jI>Y,,xRadstH`b#Nej:ў@R6b Kv]Y$DBJQ1(;^W3v^';[ۧ|"Ý)UB @%P=5JsYѷ8fMu^Ft.O b$QI)Ҩ x>utva[=y.ej PZ. VY{9p;o&b!rhsbʡ k$%[q3iu5FdX"Xf:HETӧz/61'or+Nʹɮ~=(綶6AǓA&!Žd%9,h$b"̪V1y YљBr:Նӳݹ3&@8kVcfg>*c(un~KYC0e:5[GJy-[aTá%7Ne3<+1#mdTum{01{D`Œ0قã+j8½pK{bjl4dD׺y1H+ل5CQfР-vt@ l04ᣩoJWl?H4zٗ<͛E^#^ܚVIX ƪ7 4a < 1@XXϱܑ[n-z (H'}+H@a>M 0nTP~&2kf]ev]cf Po?&n)4&p VFp-AؼQDԉ7P! _}N"L,6in]c86X0pfATDP $) 5꿡ۯ'A0QJj-@H#A N2R^.~,*$kPa.l#ٓ[[eHb¨>.116L7Ba))F~^oغ!lY b7T  Na6V~Ih+QF1JFB (v17)wi(O_oÞ?OG`>M~#Si3+l7; 3k>;/1 }S>f )z8GhdB빊 "*v7@E[QOA J;Ue)d "3l&0ع !#DReٚ"v ?| %s˕Lƫ*%B<59+E!u9Gv (v >!DBGGs{x 5dd˜ PdЭ f`w!a_3\Ѕ`I!U, fY$нej`XV(xT'n%* UWʀExCEU8VN\ԅ(EYrf>>,\1PaNu=﫩D> bxvT:,I@T rfOmWyQQ!?o7>r=!T1S{L5vTBg.ͨy"/ eZ:Z>K '[[}O^dK|/B$KnƯ}xX'jN8nd]󨤥 @(]ahsEt0 !'U.5$ܐ5Hm _nc:2xJ {+Ue!.<:gO$r|:ˣĸ/n40=lvs 4*tCFBV5>}3xxokUSYr9_tݴP?hNT7> $\ VN-B2Me wT@B#H>ڼhg[^ c}ytXvxz,0uĀHUsF \:{ .D)K8cs˧s+j]" ԁIow; @$JG̳( F7wcak W\|6rC!)Vih9}%3uuEDK^ɰ;(v^Ac~i'ÕNf/»߂nV.c4qa񃼩 吊F'4(XUrD*QhG"0,VuN\9$4+|딖wМ&v5Us;fo$ko1\6Vr)`J(()"NuL]:2;@Ɋ HBoPQL{qYԥ.p9 4GJZ+A]K8Md4*',&'Y6RM6 wIPRBUJd8d1ۤbdPG/&x=M=GH qdj2@)'}~ӱaz E'A(rK$de^3\ůOy]viFOhɄ Ha4{מդK vBstᓇͳռa2] 3|zbYIk_n?/dV41^+D:D= S}tg+s8]Df6+У2Ih`>/0pIm kgtʨԬKKov -ŝ(=IbKOIRܖL"E $$Z-֍ђvef9Nݞ{̴o]a73^+ 8d{c(m&<2敚-$Cr)\ޅ'h6zcÞ]GGicb@J(zCሎ_s*(+/,s Fh,Dzr3˶|Kt6ۧ\2$HtQ.2ߞ-(}aJ!! d)kcrf %-+UI) B(be $+C7dBQ1H . efd*WF+$Ĺ։EHC J*K2Rk%ȊAύ1ZXiY0`e>.ɬ*EH1æP W$@*d[a2, bԀnp*H,e&dIB p9zL#[ # BJHIZKUY[PYY.>aXT" +["r .q]S7XT38Yxfh@ u[!"+ڕ̭YhCKH EQSH B Z2 [$XmI6E!Xc} Uӌ[#MI72!Ͳذh ֙)e{0(#"B֮n[bB>[u)H[mu i4JYɛ"Y2f,*5!RBq,l1% RM02L JS<,5u|_dkS TIoTLH.Z( I i$q{zL5">ld2VjC& EX?ogyKDhz,wɕelW+CT6 aTz㸳x{qeXke5ؖ-Ul Wd ɾse WURN={ՂL +5K!ðfb1w2HEY!C*1N@R\.DNok_BݽkqQ1 ו󌳫XrH.PȂO|Փ300;)r}׾Ř$і+K b V [iAV,^l"RBJ&92%- 9-pO22U(ԫ@ЎH%@P2)( WP&D\d`n:qxȨLbR&H#*(&Ҵ;EDJnBH6x|fۉd6F+-kW {cuC~xtSa/9F' ($&" ;VJ=YZlQrXXy3}izݵ|X=\McKpdk BzY$vF$07'hϧ;bȐ xe0BB~LV}w {<].~DHweMOeP6GGRltԴS4jTС\Y-+Ngd c'o;$P )@ALlk; dd,K$((&CJ!̲mU{lZ.mՓ){ S=|(n eh..y+>ua!%4Kq]Ѱ6Lϖwn\;z3 W<0bzqylM|?nk@\N1x&du 4f8C8)ai8.R@E-Pˡ_o>wnjŇ- |,Y)4 M UǴ'P1CuVZd,oԉ03ʀH`,S5a)$%hc&7ҾTu9 *z$(׈p \OInĹ$GrIx;Zt!ޣYb؝W DdʊBabK3J@iJܴpwx4Oy8uqd3Afv?zLE%*JOCPe%)=XX ebz1?d̨g Nyg/օ<0.*+Q -ַ~%#쭒<62"%RFҡKNbëbTß,0I, FҊ:,MljQ SkI-ؒT|? ?}nӵ~]CnH3PX!\[lN~olc71Wz >ز[J {f]K*  ,*Vȣ,6D R3qva."3ŶsbJ :рUsE" (GhdgΠXVk&0F_QB 4dŜoƕ1nV ƒg[ZiP '2K޷ ƒHsXb%#lvL}1vGḣF{ uv*lVjsc,;g:JbX3k"%א 9ͮZzQN`ʯ}zZcnne$rakTRdz(A&YE[0b[qgXVԸDj$QDp`˩+(}EvEvcmGWFa@Xt[FEaEV (PUO˙~ly4//Ƽ^ kaeyrKXU6V#6& c4"cb+Eǚ1%q[p嵟D|3ڑH4eչ[XIҴ[sb:HJG;\տ[ǗZXep/5R:"Z5ZNb‚:G4A/daaQiT0dV4A BPE{0?W"Uv HTVH*'CUI% w{?e/欏Oh?Då`G`O"E6`#:|>֛xX+չe& $5 ha}Rwn[v|S7@f7Wq+*tqCn/UC]6ԄIFĕ9r\ϖv&_qG'tO{׭s->.n0kw\>MS5 DmޖáksСF͸\ZtThI^a"~V(4~mIzMӋm/9:l1{"SEEc4GSS#H-+G6u%0bmPB3?s*PFov^沋qG9% utuS^eD]mZU{(Pd(-)7lxxI6Ł',\Dl۹@nLn,yoynjcbru tUv V 5̵ BFP`mϣEUCpϫ{D@9sc=[# T8W!!$^W0|ϙꎿCoB\|C(V6-8ʃ|r, %=K}{wKWzu P\桞Ϋr|v֢8p* :+}g|ra`,<;$.f_&GdL!fCJBo [Y^qmʔkvhC 3Sz\DD5k3K6umMbz]F"tc(@&s8~}^wLlļ)T33D1UM4z'joT&GPa]̆<-rmlӟÂusFDe䜞? ^)&5G{oA^M([ NǏKàP 5œE#ŽkZ)J >*LvFRۓϞAUT Z̲ "Bʓn 7KibWkG Zlj9urY 袖սc6GgLϮFWPM(u)J.BR5*i/G3y_kRT=|fȡ~  UDM%UsujE)Uݷ$-0 :P_ln8%IR3S8#ؖ:M@S](1(gf+9Y+%e t,s\wv.,.Jiѕr3ȦYg2C*PӉMzboYvlo ,Kw>qe iV[=l"OhD-ԨGQcҖĎv}p@H ]zxyٺn?[^m1M;^c6hU,oֹEx'fg'ZkbVDDDsJOIw>VÒ0}p[L: "sPgX2<>1Nݗf*78!wVKdi2X[["`קi ol3槢{4rC=Nӹe\-o  ,5\V- & l=o0ܶAA)|6oq_}N3qӗW٢Y|y4ggso~|;]Ov6;1v<2^FC7Ⱦ[" Axw~wO+;iP"D N >^s,TވIh$g6[9dx~7t#"&10 A}_fylϞ E^S'### FСї\v=oO_y(>7;&z {VZ>Eޓ={>)X/qfЧ{rQK.y?wu?o.8h9M|.vt7剿w$B2*!=/Z >Nsw_?1xz]WN}|X1Lܿs7-xXŻP$}Xnb?-y\scO;.={g'ó~PW/_ОYYN\[FͿ!xfнo ㎌i}Y# 0-f7]r7t}ťuFgOs7 nƷ$'A"}!Te!PDuj<:|/G)̪+$4H("OkO4 쥐/L]AH~MFK0"LV䢋B8BVA$7]p2p(@Д}d0Tgn!8!ÙAIZ0hAW4;\!@3n5N戺^t"" b[l $7>%Rp%n Jl~QVf a^ۈCˉ5{CQ4f~==  >BI 1-\ra@7PHc/`,u;P@ҍIf|+pC:L̀6HaGl{j }q r:C&I;@u/ ߵoh*NBGgn[ǭoja {+i_ f*hg\;0(#a8 KZ[{_'~έ=&])¼_oD;U44=}="C(Tmo9k;4Qk}̚~*(K'F¡Acj\QrD~MDmqd´| }+6#RLbzR})gx4\^QWo;2Ooėkr0odzo/mn3'Sus=}ݹbAkC-B/q@]w_c=|Ib_v O A=Bw{X#k@h>b=8 z]*GzLѯ7:k<1ƭ,0dA~%l1L;[W`N&́ s ᪨e]1[гi Ée1վ_7y\t:(ᢼ: oOsVl8sr3^'dφuD"$,8ZX7; 4eimWCcPh&+חdm%)r&Hg/ht4..81f|LHP-[/ػ~:7w\$Tl{쳍vn_J;λ*"EyOhЈ`Vgk~~V>o G;51@HI&bI [Y:+| PGDw-(d%@AS2M>;m#l /i/#sh rwͭ=t.r1ȉƠ3ܾWM,Zf5r "UEfڻ&]<.K%;S-w ;s `ԧy`WJ3-}.ٵYE*CeLӧR8Qu .q͓ #T\qr*ͩadzKVHodU>9;˱b'[}~Mla G{2߇(pGb7'q]ϒm*4CgNm=bq_-MFu u7Ad<:Nm6Z"$Pk`~-QʦNUԔDnwn;_{xzCgq;&Z7;?'&)Ƌ }?xy;ZItk>G֛?3a4Nt_.AR;bG3sŏ]5_u} Cf Ym[TL=ޭɾOd;:Oj#9u=Dw@w^i*F#'G " y 'ds;\ "9: 3-ab.蓒 L =f_ [7]F !_>+;//[>ϝϴZz!ߏwT s{xo/|5Eb6Je|o"=zjjrz<: #Ý<^s4b|]NkueC'lϿV7@ 5\|w_ r4j㋸`pjTcV=t|hRPtNQ9P]ƭl ͸n6v %+eۖ|x784ײӪQd$uR*?yc]ύ ~Yk "X6 .{ճ7 aAgbz?u3w_6>Iy/ Ъʏ) Ҩ\QCڽqoY9R46I/1,6.9yGlneW`\+Z_OzN*y,3Q0dI=l|p'V3Ր?B9Q W%s_g2RP͑Oalw0._cxRۜYPyں^ҫ ъ@`ݞ9s&^EEޭB{,ۓK_\^H8ho14`̷WPgtNm/w+ZruCՊy"Fh3*YPYU䫞ۅ=9~3:^A6RA"Kjv^`\8.22]۔8| `,ٮf:$ʟUL'<_ֆ48LTM,e (9|S]ZbZJ` &\Pę+L4cox83y-y3l]tX *g(V}AVe:@b2%4sߗ:, |6vf'@\"1λwn䗧a';^g-zsX髙̔X} b>?z{ Gw:oE:E_3g.9`y5`=~srǗX)A5^% ~xy͏X`m:W|r(Tc]H|uqE㔏_:Vze]{ִPԫyՉ*? l ֜q y>$;PFJIFgXHw⼎b7C/g b"^QU0GKe.օ\.V?0wzY|=`Yd1WaUۚ]zVB#'Kڅ7Z3O2y@o`yoӼtGkV~.}fH @!B32⡊w BC7tJaka !Fn5/)= Dnl"F{eTA$~d=Y``:Q5Ra~]f ,bQU?GK]}I*v?1jHT1Z#'du],0p94]p8鱓gW7JfM?'8baj_>灾s6?'>?ƿǍGx>/>Ə,>0_?FI,=ZࡣpG_J͡*N|sQ*I$+^4/N~_\[:悔B]]_ On]?=NXev~V+d0H\ZH}vOD|? #ؖ8_懫/k" s(ϔv4!~on1}ֱܵMhvL'c&.`x{5z~fPk/: v27l1x?kyቨ wYД0C/co{km5`a ޫ:c|>kjהEɪ9 y}=ȿuޏ0U8$3(ahJDzEi^0[!aG̅H#,b{y(`lmY'p)6.-דm*ڱ0 W~WSf%rqr4c#^e1S? FLQ T !,Q}lOqFkzzYD\R[(;tj𢻇Ѓ)Jkc7˓r΢u.e:MW$QHT@B$"Tr Y(2nYnlTI~|B ,weI`^VnKFOlS&ɜPkc`q6os?b@RvF^?B9}y5whw~~QOthI=M<}.Mۘ ?[Jo N 0%{$!iz#&U)D oLz2Ȓ`u` apBCCX]: `\SOr{ݞO]l\⼺wb!C i( \ JJb[aSk"t#x+y?~9 hm?Sl~z;>?wojzס/^ݱ~93PdѪro*C 1|zwE3m׷8-σ-{;XD]eWby#f`l{d~kd56WT `Of"y%k1=Vlٖ:UۿuDEΦQ1ܹmh >\8:rVE=C?;і﨎^& xCB,+YTYcm#n>5Bu4X-1& 8!<ׅ'4v~g|~G9)YUP?I 81Mӷb{pc-Zq@ v gv~xGOV//t$CI^vr 2&m$vuNetdI)ԯ!(r9kri~F[ nωٯgm`\7+/٧^=Na38z!cK)Qlŧݣuh|ׇ#ާs:˭A']ాljm4V{n[}Lʗ?G__6֜ xۿ0\o&v-]||e01kuWaCg+ӍaU*?R054UA媌3I=k:gh`F4VƝ0>@RV Iu: ZT ;+X!5w^G.n?tEhǿtRޗlu85W|ïr&U^1-`R9j_#[YAcOO$IR!%AM>>8NZeQVMb~MooV )DAm@\$AAU;v~7Tj*YJ)fRdKXe+MSOOچ}?Fz4ow?& N/8v} 1UH2+h;Ux6#gu"V~>p ]58| w/L(;?/zQ|p[ztR,~)z>5~;6)!g݅|36Q_fՇmz,|D>4BGے|=lo9Rw;ҧƇ|Ψ1U0K (o|h_4)m+rlgkԵRSQY&1#31RJ!f볨΅`׏c>GcͶx^8FO|7jYz}^LO/|`wl~}Gig>> 3JEcw傀7SMݱo~ZZس d6dn͘7%ӵp-yٓ-uoIula?>7[w# |3YT]Fv95iǫ͌S*$I*CQL.54BoP1͓n1Hnފr?Ō"N}y-$w\4aY—~T*t/oܢĞ6i 1M]Lg?ᗯW{A0S=Nrfk__šW0S=4+ E qѶ;{ZeG0\.4CTi(jpQV}o{bsu{oĪinļ16^חL4OxyTGWawf^eS{+x 0=1_;5>Z?vWnU;'J/+'{;]ذ~3hx*a9CvrK['U趺|.ξIsZNc7w'WgiKKx,?U"V?]=5nm`_Zmy*n^=3e2f~Ow(`jړg~/~]Y~?'[4lZy5$WÔډtvV d#.~vxyjףhx*r3EB8L.Wt4K_Wҗ-O@~H$7? ۭ&y^gK @w=+w|@!d쟙z{T*?w?f|pwLQRn&::tӟ.tz*k0ZnR$bbjjBClݩ4n<`oX`f_⪯_Sh1R/qSj^u qsjBH a`,bW}ud7h$BA j(Ppp/X_x4Vg_u$ρա͜ 5B šNJ˞$u `"6Z ֹlC{M/kv3ƪmyy(Cp[Ed"h|}Ow4,ぱ6كU;hT OH!djSoǒHaE:RSa?tz1 Q2փLrjOn /kǚstT ͯ(h-CZ#;!/Q.4bWrTj0,"F.ރbV4"fD຃{wK1(-h `wFh<~ʺBKk ߑb#v͊T Sl$}/${,\A7-u,X,(Gs MLI`uֆLcB*.T4$ >J`vBm>qWb7[x*+-/ 8 sgGYQ׫t9"h@))UY2YڂlW ]~we`.?Ao. ю&h/onO-$JnCvFO6,տbQ}fe] LR&$uoAn~?3q1ЂVTM3ekg@j$Oo^Ǝ_{;`%+H5?A%"~ )16Kq܀g-9Onۀ;gZuyqTy^/n#KL 힬fWDA]M"YFgq褑Q Cx]QoK" y4$vvKtn䐛[j_Uԫn)h+֋ˮԳ5]5|KWȫ)Ӣ&5piؓ4jf5HzƖ(.dȱ (PP8⭇+ v Hr ( ɬ޿|w^EҠ)ߧ_EdЪ4ܹ5$ g KѫC5H^BO}]hTb\0yEyto[Rjo!N#ZΊtz47%Ilh*YT $0܎z(~L-v> ;8\,87vS/MnGB)+k M1;Qd0-@4F8Z0bOYZ_TQmأcz0#  ?PrԔqd f/gkUYDDcwG2 $PV ğ9@qxhWխ_upYrMѼ<{r:b >v0YWU֠P0-0ǿX7Ӱn|+?÷@3oG"CmU*HʌlN9<SvE~#hw]m-"su5l-17"ƫa"$JdşE#P;ӆNp+ͤޒUܙ +( V*HTRtj]ZkQ^W+W<*tU`S( t4j 3+㑃+۹!Ar"XٻmW Sl#g| ys%6`@PQKC83qdT)N&Z5'AA[]CP2uoG;SL$ ra`9;̔E 1 ,y@b7ir喇Cgz[xre'T*HSiiE9ϙu}n{mAcfo$Y#CkS񮑧x*bn7)cLu%iTOnñҍ$mǎ-w1ԫkt?j!|thUKhUMkgR.熔]T _{.du `pf *hB׷x#i06O}7ə 4~->7ƫYQnLliFlDK}.fL)]OSY G͆bĠ%!SdR,) o".a_5L~ʻlv*n=M*|wg*0u;ӝsb)Z-g2CvZlmկ{W2OXIPQ;bwr2y7T:nIPH8B$sEr>ó0FiFBGA44Ja$>g{j>"zz=|*x;٪X,QU( f440rk.o ,[@b7bnqЫגX<ͭz.-&uƫ,'vYgt W[~:&dD|ԎTwC\O;_W4xX$hv`Ъ܁$ϧ[e㝅]JmL[Ȉ%BDQ\̎TI-k T_Up_|-5UK$f UFlK(ެj!ӄHod #lU݄>[ :_1F`YCF,;qj &Pkz',3twl'Th[v<:A@*!Ѿ̲ϵ{ì+ !jiD*THEQHU\*#vW= T^oxfN@|K(8.w&FI]5Mi٣i'{YFBن$i(嗢˿iwT%4U9X׺X\uIFmh F`BÄ́@Yd8@p!v] |,%1 eL7y=I6b8s3(>ӓdi/EXVRU5k]Y|4%q-)e4Yc$x͌0tamCNj 7bkcɅu/Ww˪Nv,ʁ.)LVrXFv0/6 1%YFR '"!9 = Pl7XŜ;/,VARUuk8R^LazrGBeg9V]_2ZŶT`E7#rp+V"k)ddO~K$S5|On`'d,,u*EuDyfٻ+վZTfRl6N'웜96cdz{M$HwqDH|3Tf>– 26ܫw·nM`<4}8헢2[$pD[<)kgcq|3,g)8mBpQ;T^3sԴǖkM,4\.a!*1{Zԇ~ ejij8$at'OFRl6_ }>^NN̕ivk>4:pEe*՛O7xSÿMyC.R}Һ ޙCNۍN@;Ƚq=3WӪTzMo5 63 λwύCg(Ud8;pTX.x˴3|u6 r6 ,|v$Y]*) /SSüByMEmߍ 7L^]͉M\f+$l廳i2) Fډro50'bM;7teI7Sz(mMZo%[J ~:]g)N.K_$ Eڐq<*Hh ՝CG^6]BYTe ک8`y*N*|5Vq$5-(. X CKL%(Ԍn"-f U*Q0Ӈ"G JT3W-3%Fjz\W@5` V m΂\UR)PI d.}EעoG!%ʣ7`HaPvV,*%b &F0LO ݲX`0nذ%OF[O*Y6Ӕ]g[o<έ0|}v`jhG'6`xgVV@tL7t۰IrdұSg~Mc9*9暆3#}%K9` ^Z=8w2:*q;׃ZSM0+\FpefVr3eMHl[U Ckvi.<YmT ŹWέ/$ȂĶ*"JЁ;sS:ߖ(8bmbG4>|.ȋ/&UkT̤ (X2QF(k) "6)5uZ W2<lwhMgɛiLkl{6ib>Lz?%l^ߓ\nxyr/-cEMn籡G0lf2ݙ"2p|6[6-\Io_twG;{{ : xIgЩ 6}k *o{qPZv7NNA-CW!8lLXkk4-*Kb(-Rݪ;6vs{5TnxCC5OKpI]3QD$}K5g*#qbH0WX*.;|έu#{B1oFDNQX6JA{@ 6]^d(^D @(*ViB )x &P[~<7 Ŋ uB5%TueA.tf95fTc߱wvօCJ,UkO.L$QRF 9E輦~ad[֍ ;n'l]syw= fqBкH;9ٯ,XtESE R$ti3Z_`HdP;9C| OV7˓r`jq|;p*MH\QW+f>ĻkoLM"ӮݑTgTJNDT4uV޺d(+PW%LdjWDSP_l-J-+qMyJ8SS*Cϵ)Y{o@lF=Z{Ǻiuj&2aAd%dh[BV}t5#=@>;_m9BaXS/<+mu{4-gkWpF¿9t\rfKs2;GdJV2ޫ ihɡ |@C~`]uXyx24ק4PأBD:$;EH펡͊3DAns OvU?%lkW?Z+U} غY8+@* 3 C 4%\j:4͠;k ekeLZ)[p7<ޫ:ߑ+#M1])M4*g~ j4,+Q#0>_ ;|w{]nQ%7; r~nYrm<𪊠X|'/e!F1B^t]$Y$Y{GN.ZYQM{i{O\vjk3OPzvCkص\Fv`0m׽X..WYx4mԁ֋9m\~x VCř ͹nÂŜՂԋ·\l~@xz>uSE{C$pC39W,$q\M y\G: F|TsI$5/7rր~8!B1>w 3WnGSZc;pjZXj '#+Ӹd{3r=v:N gU\@U-3E&K-ʥlNDŽöF-30u= LzVT]4խ< 9(`oȁbо^r}u L@G ]RQ\X,x{ ,/ɛTTze&9 //=ݴDk >6#$)kx\El.9n|k(Lubcg6VTNp>T'A$vx*ȕz 멗Ƞ-W"8{U?g'3~FV$&{NWCfD~4(!8kPEn(;+AXHU Q'0rMic©,RQyK9Lbs%(g!GxO%'ڝC$R{+3~)#ӡ|odh#S>.pZFic-D*ksp4|JAfLԷ~0+ "d„Q%}>$4VJҘ8}z~-ˊۂגQ&N7ZU94, m~SwW085RdB86;Il&AӴn_,BZ,:x8W<}-3㯂5pJju^1J]O sx$LΑwCJb1 r7!CY<]4W\!|=DȏO}`gyU*MvF\qh*^՜6x zs,fP:}IyrW=i j" 8qHh]KP:,Ԃ{`dCʌ(A/#%ss NBeM$$ dDIHu?}OTS+nm&PGPK½7 A)xߑ6L6!Yڨsș 0gSMbө? yak;/Wx&ךCD>=d7+NxވcJ YAɁc1@$H846u*ԋF,H*q1_-0pVmr7 Y:":H9qP 5|̿X c6''(Jqa_L֝hHJ%7d _$8[L˛8Äj[n(Z[j\AX\v^!QK4n1sȇ"^[ ZC^iظFt TwZH?OÅaNI췔7`8S 49oTpZ:*xK c\qԛ]YH%,9Lw0\YɃbm3,w]J81d*{ؒ"KSz^|O2.fD+abCWTWaLi0VMB5k8;昕Ε DIlW 9j'\bڸ8&5/_A?ӱ!Mڻ)>s 0!]YvO/菸A֠Jm|֣NNs.XtOsZw-X מ&Q1G+1uM #Q}Tu0("'&49>3 M_ W)P9Md8;eYқOՉBWf+Hj٠l$SFPVP^2 u|hQmdqr9$T t1i yKB\{lW}bK uQ]wK/?=S? prH:J'9RtУS$Ի{겇NA(E!e7-[d( M;/oS1H /m߫beGņ:Oχt[RӛTa |Z&/n2B` x% -y4}\LA;b}#4-!֑x.3E.TJq#ER]@j{.iN`GXcBR*b hYo,Qm7O0!͵YO?#0<, NQl4ut)Ψ'_ܡ;_ KESnmNv wYS^up]qEm PUXzO06 㛧KX@?sS^3'sqDRQUx"?F@uN}EGW)qH&/wT[!MTiNhKuͷio}PkuvP̧|׋vrU,_.=K; RH%IUvu,-^b3c1#Ơ W!A_"7ZⓍY P~q.1|6M=ӟ m[W>|~JbۙЪ/UQOC>  hfDT}_`3;IU=[cQR@B۸L3l\ 80g~cOxE3 7>zם";N䐭 |PH7p,-q"ܿ H,YQXZf&TF*ݔdGR,@Aޔ~" 26R'^~Peeʲ"$e}1wʼnߓ[o?T^U-A\FfFW}r}\3h<ĭ!C<*8tw3fôl16~a"M SIj|8Ѡ%~oty-T'.H-k=VNfNRu9A#;<:;HfCFKf9RZYet2Cc9+._-σ`7UcWb2l^F|.Oitw)1Mv(`0(AXSS?~ [bU/lKFgeRɀGYm*Y<4x;_4` XtJWHHP˒?_}wD\s)WgnG2U?;Dֿ&veH ɎFJ+mTn9ξ< *U+ZnEckbMGz'DWzXZs2_83fNhSe{nN |8kW'R7dE\c0lP+:(>[zVj~-ێI蘭^?0(Zwh hAH@zOųg$NE#hekko#[Ǘ`W@ÑDn)H u4*W: āYњ +ߍ;u*50"ĩ.y]N^_'}ϸ\^zb}_,򥪺<޾Z~i#x++ɶ0 ۞Uz@U)yq 5?ڄGCFw uSODV$4c({.?M7- jbuf6!*H0%RwտɱbT@5SVg\W9ӕ(B!C>(Q+ĉ鍅lh ;Y VA,6}XY;ⅆ a쏭{g-f"1u(@XuR-v/QKևKX?4)e 6`ZEq&Qf!&_aM}1 Ͳ Dzc .C?ˀ`byx— m,|. fܐg?݇{u Q'C[~$]8:a]nRrOp&6Jl5` ޷`U2+%gQ=&/xUXKq5=>X$w5CÖ]drrmMvgE?Y̬('îآEa- q(Fqy&F_CżY(J 9c 6t9v %ޢhSjxH# մIS3VN66 ;/GTXM\C?Z3E~eϰs^Y;N8;1[XiQ;Q QYr hݥR(t\D:wI-.`]ݾ|aCG+\ⱃj#od2K ÿ5ϋVA r.մ]U >$qZw`wbc5m"j50|k(F;fm(4AۊqhV (<"xa >xۢԶQ)]ӓߛD#;- ^ CP,_E\Wl~pBHJfe[6k[b?%<=QM?߽)6]񎫍at?lQz)jzqs0Vs,ľFV7!`Z'eGQն+?2[VQl2.mةl{fԖz2;:s uxWbdB)Xbf,Jv_GQӳJXͶ h5H!uv g_:wu0 ?*wrJl`H3DŽP*z%Y 5 0C&y=baRaMsAc;aWn$g"U^# ;F5( UgK3-4$n)Mr!>Ujʪ![:*8T_M(ks^ Tvo3G8}t ͢1h:Wíg1xN+/צxPuj3yU_sgM8KxM+9sKd%#('4YSr?Lo]ݿF@ $Qz.%|i61 !yr.H%6AK^5cYD%説Sd_Ճ#HPۮ 3 \[9"\ox%L4gՠPU?.D3;ֱu>4czBd:(.a;wi$)Aq=PK 6@hNwL\GR*V&v!c@׽Pcxg~AJ )t'ZiR$C  1>JQ86>Cd<^Y sb"mb o/y]KqBF\iw< \y&Z }ɻB&NV:ko+}ǶB֌KF4 :<'XkB\f C,7AakaHbgrWdSJd0CSZhF"ș}` *:TeñoJ] Ec0k5WZ ]I>#<-RZooSfә{Ӡƽ#>K?`hx[XNk'삧!X+9J6 xa }+?go'_&Gl_:8f ѐ< Cg'~Ei[pӰoῚ_#lBuJd݆X zI\@`Ts MmJQ&!G:jY~Hб٢9\8!,n9< EK'_!ߑ/*2E |=tB".V/>-֐ *訑QqT:aN@.=p++s)h>[ +gsg W!ӛWCD);ƸvKVmW !2h)&<P]֦B^i6jʯz"GވuC41VaK%p*AEtH\\)~1_֫(IOc75)40c*/wa^ %bhUk Ǐ;Uae nHpld,Lr;0 pߩdv~Q[36ctl"ʉN h qCWɟl _+%.D$n{N Ot/߂3@\{' `-?ծVP'%jlC}L%Fφ 6?vY`6; $(iG^@C i2*rƿ9RAM9[o]>#jĬ*Fԉ 5s8F"Wf1ZeOWݶ ;=(W( RI~R 10ϱEeN:0>2ک^lwDeߦ SܕTԟMR4Ye =esL.LC>},X@G%AS}Aq{v wNO< |LS [,Ԝ#0":ꇁ3x~& Mz< Y.z([fe@$I_;k۪n/2gdPQ(>^R#0O0XD`9'q L5g1{-pF՞ PW[M{3w8>]dm9BW2+V?A'FYncԡ/`a};3o*kel .n E5r;Y1?yxˡ+*i +Yp5'P-,8/rҝoE6H iWK_}Qf9<^ެdPùar ɦcI-WW~Y*,do?~X0K{b/4P X~8J+Mt{6B?u:"`\*σي0?"C}/3%mdU5Dm߇.eҜDMʹ% &qj`r 8>[UQk[|-JMc";5O̲{}I1)ߧe7'~ّ9<0tG\waI\y2=Lz<ȱ~7 |C|hVAM=Y~z|PHDPIkhuc93e_ײe~is@1zpxlskUo#r&A~eZG}oB8Zu./#!, шܣ͵S\53Lc}j53Y"Nʡ'9OG~pI%?'ʐ(q$L:j}*_8zZ {լLjеa-9 y@NH["rb-\“9xQ`üߑk!%7Rm4B:!PtfOzVǐk&:7gn&;9Ln uU fpq`8$jCF/:%uhix`寃F2^(tr}K|o-(8V~XRn;y2cHVw~w A^r]ޏnU&5.r>$cNR|O.Dž>MO{, )y@]ZԂxvu'R*FO՟ x`2ŬJ6sg^IvKXhTx6X?fBfn8fΕd sWRqܩnѸ,z ォ_jėB5cC.ز3ڹ-< V 8ayqZ p Dj$f07,ucNU7<>!h v&]-W(a HArW,v_69MwCabp9?F'a8'K_,600\͌nj> JGĕr `oC~` AкaAq;€,f`f,Ztp~˓Zj@i5 ܖ-ltQ[ekO9^U\)rɖ)d%%qD*bӆ_]@P%IU^#!Nik(fe[.>p|c1(x0-aHӟmCM;ˍ&V@? Q-_N D,AUil|;v6~ǻPVYXNAn>6+U 72 $ŘVL׮ʁ7tVԧ&Nev7yR>Ԛ#i |uąuȈQ~}kI+6 Ti1s鍂jh(`=z vԶ)U4@1c k"FܰԝF:z;+=/ikBb1&ٸZa`@yٟQr{)R~u,Rpg9ďcIyqle`CfϭiǝXVO/)@}Ua+AV1Sl<"7W`˔ zUdSd=Fqʺ`FکC,C;V#6aܙ]+yh'!0}&|Oj5FPzj$;&0[]/̾ [ 4JU40HtRK}NS_ٴ4t^n%@-kC{q9y},_`a,ͮ97;kjTCJiMJ!z[!rV|)GNs-FăsJ& Z;Za"L=Re)hQmhhi@1P߯s"Dgz&1qUBuHA&7Wg<2H͘n6K$ kx_,OEPIrK0y;vWc{nT՘=njx"Y(HYPiD-PVбê  *2eE }.`DL1Z0 )0vȉMjX䉴hUʹc;!M6+.~ &㊎$WU0^'"(̘'ZI;鷐Pd>ڀWYAIF|Q֑H4;\gnIN7b6jtr;NP8wL'۵i:gY-B;bQ&`ñ̯2Vfe ,pDWOLZP5 9(u.pBB:s%|ҿD 6jQ_U2My8B  ՗5W`k)ޓ~zrD4y̰4PE CpVO[@!\~EZ#.sm,: bÐ@Dd} 79֬f-Y_ ´j2u YIYUE*T@톡eu@)b7a9e:ow~Πv7+4Bz" [ECAq3kiݧvA{ 87Xro}&yhw n1 b$1*'^TD\+Ţ,v\S^{T6[D>-{Jp!Bv1WCPmEu E .+WqnP)jkx8׊WGK!MM$GpCg \ RXry?F ,yɞ)+Ƒ7`v%u}g!̿ ؆;ZZ,I" Oz|9h|R~ڣ.cڃ®#.c0 v7f$Oxm[0"Vyam̗! M1Ŏ`,}y[S{lGzWuR4nEQF uT O`5g {Uk",1,ZGe>G$8" /@&D/ FUǶ "3EO8e'=JIehMX3t׵T:'C}|A󗧊%[2|x͖LدԭLO% 5י31YћK;$5 <P">$ͳWyx - MH'%қcCy'wY|˕JŢQCk*,g(.J)$"9=qTCr56ӸW7btSʃ\0cs%C@*yiWܓb+=U15z"Vr"7T$Ն/MS笾@0M2]) ~ RT nO\>/(δR!C"*[!koaK8'4ϯI؂ FFіy؋~?VRD<쪎;?zHG*CK;m"b5U6Rr\q5 vV*)碞9YkI*B+YDpq=a'xIH7"tߨߚ,a =~Z JgV {r|қ1Y2= UfG(PPM8M1+gb-Y}+yKU/ݮY#dBw< ^aga^;xZ4E`ڝ !chҜ|`ZniAH ?[ bE.(鉕\OhV suk L,h7p͑3Nf3;FebrZrbV]R F'{؁껭:\%AG1ӈZyL?Nw}&$@c g_EQLӤb'ԺSV} sRk^qO-O*&UHLL>EJλ]-#/i1˜bdu>'Q[*BHT̤z(F8lCqI{1t$PxqPR+ rjPz6J5g_uiI+RZ](?vԎo}}XE3 &ʳZ c7piizV2_ڠ쐾ʆs-#`;. 7W=8w|%H`pӞ4ncBO;yhKY)'oleIIn}9:BG4|\)EW8H/c!ٚ }Baz͹́7FьhBzE['ǫWT/W40hOxxZJ\ V!<3ԶN7][Y[@wyRJs{K5%XQJ t֨hPRtõ`t-1&njkjex,*>Фd"(+?%KoJh-sj̸>|b*r{T: S#٠vZVq.L{xM/w Ş. `E'K(+*1aM7A# "g^z6؟`_P 'ONcqyjBf%-Au5m'џͭ04[$VM"Xz^콋Y0 !npzLK*]+ WMo@v6ZuP˪R'qP_au^}^N(flVg B^s^E$Z>滅YO J_l7dbxDUI C 1` %9]n9MJܹ?7Ej6_F`4@B2"py#cFŧ:Roeޘ'JϦz[S.Hz7U3kQo3 èN>ⰇM/cZ;8c)JJ o&> _A5sB1›s `Wf1~:@􎴖tS+M<]!`8g (gr 9EjH7[SH P'mv<'1Vݰ$COy8VڅۤĐLR6*;㸑[O`煞D8>U_B[fy'nSSbTkVdѝK/^)2 {?H6GX)4:Vc٬cn#gM%y8aָ\,o}_ pjcӬAv>X^2 a>n (NMΤx\H`ı TzX =bJ W͈~@-#Ku^˙VÓw \FS6f 7x@^!O+ a.L2d4ޤRuD]`h璪<chH21ј Mykڍe:'(d{̾.Rk, }EvU]3m"jTߴ )!dn1aMsg7-_홛LP+1EhV ͺQwg$?`:'7bRu\؃l-a.E$Jš*qC7fDw4>A:SocLLG'Cmz8r&è5e _cff^43'bjvcX+?5 d0m 0vaґ~Uw*g]Bwg['UDRy5xئwPXж"%J\(BփIhxj;a$3,&i"@g oO,DIYoV%eZل8onۘḾ_[A{ KN䡁QfJN7bLʤ[J 㦇#G`1><³lЉcp @̽ L dɯ*$CK*{%RFJ:QSh~ԔDx~qٰ}*81ɵW9s]{-bH,F'e "[6|{w p_RU~MtZ@[P%"܋so'A֜( >zIGVbR,Po׭>WҘK!҂¤g!euKO?T$i*s C0)7$Y? -v%bclmeǟLY Vܱ#.9m °^TNNmB}+V[$]5RpZav<Ȗ7V.1x^;TojPX?y#$Фz|].nsĎ#f)Dt3Zx  o=ı GfOY_Ure1:ehܠ\S6/NJ2'Ҏ=S?=:5 [)P,S-<3;Q^kQJ\]NkMgO7~.u8V@+s`ӧ6V~qt0q}P;q(q9oG%S-)UC&вW,xl-!7Ƕ{&$s֠~[~$Cc=!swr5sH+q-/+I .;;;di7}JţJ*; ڇITkR3U׈|iA#ߖDGP.rU혯F "R!!V7u:2d_pkvu+-d?0l~1ʆM~zp~TOSZX.bL>${#5OOHR'< PoE})khhخvw`k @B c!l96!ieKr~c*"Ʀ/O ĉ@+YRp\/  I޿@Jh;ژ,q~gǘ"7ô`m]y0GMF_ <Ao$i]ݿA}*S "S"DR&57Ѳ|Md sC/|4* ~dhOrdMOǪRp*,{hWqKM$҄@`WgʖͶ/p%߰)aSx˲&F zo X%"1]ߜ5jȌӮZ4R0oiAfmJ˻#iqm.@$i& eN^J}Eswl<} 4wFugb M+ =o t"HG;WgtId[U |0Cۨi@ln?yJ.mP,4|od?:]d^y"{ػ[d@"C/4]FŬ*oqe{n{+Tuka1@R.~P1S©)Y)n' zĦ/2(+-mBI]uO8m{q^׷UDWWBaI9loTSa ģRV t!ze cK-(;&x, m ?fFTؿJ]koOL%\{YLl?vc!Q*spmt R+9Aenvx,pz)a;Dow=/P E{L>o-(^wkĕΟ[icӢzBN!aAR 0e[ KVv1ˮ9&6sK|rJ@YWRzun9:[tKeARQlG2QvY^ۢO{9a*uNot9>)ĩLJ?|">a_X@2;D{`C])ZsiՔ:m=8]zlƳC$Gh}dD]`2Pt4GI EGHL?`v0$Yz_2kI}ޜK +R+M?컇-(!/*No[Hʹa,ۄ^M|}؁,wm YhSA,GPZXҚʋ/0-s\ΞT]d>a䣏*K4\UDi3sS;g_[^> Z+˨d:\C =D5y _2"7 >_J"nyy", ? @SAP4"W5]0tR}\5ijꮕS[*zp/F́qp)YVĖuudGXU@*$3* ~~yfWq+Ӹ$2Y!a[,S8=m7jf5kagLu`29ܲ+2&-nu`./"rݾ7 70SC`lO閧;Z/S0fĐ jzRt?߉XFUQE؂R0K{[dc':GOT!p:Z;lngk)#-^'aY}I6Ts1LIGoqE,ECK o;H;oə^z\bG40pG'`2w/]/Di1gik5(x)kaba 9fҖ"vm,˻ 6-E׍Q\ ^WɍkZĖM+ɨIdn}"nam7l#o8gh aAhpDϚo@Slk?mz'Ut9׈$C+VU#,ե_};w|#L;EKnBŏ^hh.)- Qiu&PsG)DBgK[l<,eOsDim 3y`&`JchY&2w$'{CLϜEOXX֜V#Y̹_B'"Eæa6tH 쬋I].!VMb _8J!85bDn`|3եz]1-VCŅ?2WY8JOu9B+;߷ﺀ 'ct]&k\0C/t|J?n-;.{KN^vI}WNG9R(gRXe_*mc(fXnU&*48kW]Uec7m9tucBN! q;P{x /7x0{ %r FpwZ+BP6K;44͈l7]=%[2YݹԜ| 31+D-iE-n 0sy . :=)tSWQ~nٲmfæOp$wo+0Fg^{cT)4-Q.ߌ%xpD_ʫ RVh%pPtJ$,RmKh9~aǂ$)lǍzf'Y\'vE (/si!`w6_Մ^/@?$(@C#/&bIᡧT5ډjӢL*~*5+Ef,s'Pw}.Fgpv%77_GH퍖v=_OYX?xQT2{U0`TG_buuK kH00>b]EX1{*WZ1{AHu\JܑnSyѰѺ n9,h"0umt Y0MtJeI>A?e )/۵.ȆcAdTjyիٳmR!ibB$u'i ]=ƹv_Qv bC 0dg5ډ:^>7oj`{qd )|,Ox7ٟjƎNtUtIm b b . 2U_rdI6/8e JzHqx 9t~,37-2+jA@Aﴅ2"Ѯs 0~ ]hCC+sto&" ێE0o'.A!ۊ{,7LJΣ3E82ns[~޵|ghaJsuθ~:!}Y/8ކY]]=߅.wELխ}ZlYɀUՂMFTA`(Yf֧n:HS+O!;xm`uH!?"./w^Tx%CNPGFOKUjz)ḓ F.=EJP+ *Eʼn^#|?yf ڬA[AVbVyHQd֯'JhJ>0DrTVqMBj/ܳkezW#9)i z3WڱCqٺF5!"~S0uuxOUEPJC @kӋP1xsBK:vrbO܌*=Ԝ8#&jtcr8]7X9U+S$rAJ$v3CҴs͟2A?O\8S Ov#lblާ)k!flC0YG:ŌbjA9{क़wAP (A{T}_.d'iN|x kmci [Y9D`Kx}GFf B9} YxӄM -3abVZJ!^@&*}q{j9qJ2tiB{ e2f˛Ǝ1('=!*QFK*-zBStbmp+X HP}xϴvS .3>: ~LhIyȒyan2Bb%QLݑkk`fle [)7QP^oMsfWGBqQedXB`C1,ت?|D gӥ{n _Ksn",YE+NOiv{̨HjE}nrCA.{&#zzd ոǠ.ĪbT;|+Lɾ/0̸SM=1HƔQvk4I]ij~TU~A~k}тv6=G(aB> 8۽%6K]jt&kr!an_9X:HC!",k&1H P:=VRS2OY4eaDpoFT?ϮEs vU= /yM[-g%K)S¥ƀS_&5ŲcOΘ8EJ!K.F @ַ%}d`鍹”9_jY-րp&| Oh>.\epDK e&(g!i^&&d8Bia ۤҮם:WH^,kgVa}O@hxv.OB%O B(GRw1lE6/|,55S :V8í˱\"Li39+|B퓾7-! ͽs|j\ZJ~`^  %@fNJ0{;BbMdɕ dO0K_ OFǦ6e؏- _)ik@'nZzX0NŇđY&G͔OxANQb.(NB,GK9 MdaMf~n8ܕ~(.ZsNDxB/ÔO17" TF*FN=6.1(_*;@M!U͹X\"+Q4|sgvCta}诋W),`7%%޸W}_y^SXC-j졇QMtŪͧ@[~a YҪM*Za+iY;D9̏y%eͰN~$F ӻ Rrܳb^DIlFAxpQ+O-V!9Gbqi}w)^>3Mknasx=.np-_gj- +@,`?o.cPu3L;{6eE5PeuC*Z, 3{ژ5Db/˻,pJebިCN5/}f ClՆz#g|Ӓ78=ϐRcBE5UJRpiL$/sNR3˔~0vw3Lġ@5,ڽt N%XW3#B,1+σ7Pz+ES╆ʩᴊ{g:iAq6ڍfG"[z]DӀ[ ?&5ےFay6U6JM1BG7oa ^.͐lhy tZV^ןd\O@n9O!^(C^CZ*~-TGdNDM ]S- єHh/ߝR(jW<0zÍ܏hOqn%G cku8 f]V΀w'c' ! "028;yK;_Q=1guAV9(@;g(_X,,5^Դԍ࿲0!EW>YxwdUs#dN%zxH|kA+Q9k jiٓK|>b*H69V̰M3ֹTouI;_|=lsQ=zd64Xa%Lg=)PzOQLH)eB 5|"+c1R}shX] yqdyF9KiHtCyzkO+62Cˠ3K ZQT9?P=X]@&EMYmmak+EH=gs#\<.%@$*zq#4YG0za HËLQԝ&։2L4@lARmMvo<4w(c^DvxE}q1n 0,hIP&Kdٞ})*E橕^ܗjeRaB J{gZA ͻhz:JW Y)FSy;l AZ~44U%s>3Iv[>dxкɑ+R Kz5<*PM@k5+d 3/o>tAnND*ԄtZv!)OW05~[vd3y˱A :kV]^ L|$SYXhl>pI4[p t`ύ,%D?~y!Rr3SQ}F_/t'@= A/bsǫ7p ^L8O+ oM9SV'|*Ǿ9{0+3޾z r8/{%|Q[Is͈0q7jMѽǰ`c ,ofHdT-]̖ȃfz e{װ5 Όۯް|R@Mmz䴨se6\8H0~jڮHRòS8lGtNj'_FΫ & fX;nn* NI!;h?SK/\^-u3#D$]XPJld@5ymS7YPf%l"AFIJBChl$ OafżDͮs&cQl4fٍ)g}q< " ~o g\\GM{A@er/LF*[0d{sK6K֌l '5Oh8~j=5>--m}AZ1!stψo6yFN\YT6̳:Q@nFQqtdnj$ KA_]]fNd%6vċG'K?X'¡wY #?*Hw@k˯Zz4iLԦ3P3h3M WB4B: S\jUfæl<] +2ucʒ|Z-BCߟѽ knwcJ̜>aGns*"1"i+\0`(435 ) 'RkFF[\04qo _4ؼJX,-\$lp!G E|;{frwVXܩ.^5[(P%f9iG^f4ً8Aeb|96>y.SuE.C~t{brSFa_sT*8yes>욶 GnU/ltd-(Da@5?^˶ !CϧE H\dv ̈́1;p&ҺYZݻgFRu%ܐ&(r3uesIZ !|?)L #s:'7MGW@q̙\+2Oqwv-ڎ_.,^j x،AEpR:/Vm#h)?K}0:ŷ͞tPZߧ+)јH%g"? EP[ĂUDț^|FzC=4,ɛGe/b'|OH'2$>Rg`{*GC)୑qN`J >2lc|3jm/|aTpj,\"L@W&QJ,TDK`1FOe'!z!Z-TRXhO_^_dEX,pXmՓ>'T_1P4XQL9 (P[,z_=e pT|b +BM,0ܰB`CYV2O_UG!ߘbt",qkghr`(-2Q55C혎8DV|l24 `&E@A"m~!skULx # _h3JYtE}_K-Zk#>!*[A8GN%wc(ȳfZ='z,~%M 3SG8I}/(#gj: GYhCPF,"1.iܾt$*`BCdPk9,^`^ܠO"[)B/OsloZ> LtCR_8:ǮXN9`wuî@'kw߮p]NF:w8o,t)@! ~Sb) 0R8_(; ^[>J1m2-Ɂ#l?8R5AlrlĘ<+|{ctrab+Y@~;^q[?xrHpb޽Wڑ| JԐy!Oy1j &MjH̱Rw, +Sռ,As沸{z]Id:G-jCF#t[0r䩱钐$Ξ 'vR5m- WOЄMKk"@K-zQ}88w9y•9U2A vѐSe0,i܂er޴' b{ v6J U]XE3]&u#̉{'l^h衷1463Wp#%xHdGo92_x}<܊eI, 9%9_{X*a$%FSφvupuk:w_drZu)j)ḩ)6Fmۙ_kez4FI3 qB1Vye[5r3ukw9ֺӦp+iaZ-8<Hđ̈$̣&H?} ~Lc@[;?J%w5UTZJ07dU6KILy JH]hpɟNk'[ hObxt<]ڪ;Uu`pOB1ܠ<7Eduqҭ2kXvS\Gq^^$?+5ϭGPCTaE=:4g1DW:=ơ]ޜ\PNu J6x\HOy8 wh~j`TYBE"G5OJywu>aGOs?Ir/n&Vq2 įC^ 43cxFNkf - J2. Et+BPnT+vt!Uo:,^(24~M>{/@7A=aCrsOd؁ !k@l&yuU\z&B@tэخ~}A1 ?]-)߆ pl-4{PeuZ W0]VZEcQ)<քcD"љv_f(K34W]͆A< RLmf(`>b'˟8^.?;ܸv# <Y銅/RJիuR2 { tx*4έv ٰQ\o-viE~@\evNNrc\|wR)t 9"ey mA]Jў+~A:(х1K%`$:>#KvOn 6 bm.S5H>B 0 Ij0DhJ(jkZ..w[6:E}F?/hX叚8R5͠Jg_l>UDC-VG#&a(<^лVlTjc!o;?idT o)F"8(mm_+ec;3n㾱Bx[7_p0_ C%xc@{ 1CtXULG=9K ^ҹ.5scx"'וq֡azjFX9JPXzDbi{ %fM3ɡu=?48c-fܥm/^?qEq `gEN15ѓNmgF%i*Ү7x T?}AIq ÷ ;h{ǂ:gbMW7@swQz6EDV׺s|  ?% o:-A6@OYw4n\##.8ĝԇ}i Rxcӂ?P~"yHr-/\ugNe_IҾ_28J"}7:;k]AE`&@ֻƷ8RyY8V0>+ks1"r셀 }{|B@: y%t/CYЌ*ɇwa e9SmiNפ$pq?e *4&1z@s҅+ep+_KVJo]Qe5C2nsm㕮7S^CB#OqU2 %Aac-m&G[*GlU@-dXO^1s PᾁyK_n7Wg CɈ_ŲreJ. Ȝԙ4^0`ӱ=+'eOu*آo=2 *QP-Kmm\ĕ-nd\$7Fr"t3޸qV6OT_Gܼ%"4rށ\fZCԈ([ʭ CQ΢"NWtZ,#etX lĵY⃅cgHRdbf/g-9c0.8gy"l4 Z|daH#WfoQE~6"@0Ƽ!2`#޻$FR.e_ԃK1t1gXIb%aˍ.q)^-V0N=k}$08} ^|֓ߛāor3;FYS6#`o$yxڸWѝU"ͳPNyٖRW~]zÚngbR1iYm [S?~ibP.л6kv(] WP6e+җ;/$,mwSr{j;%Q N[{h4p_% b&HIMb.IV0>,uC)Mw_ܿ5ӶqKp]7Th+k+Uĉvι)_2s1_rԊ Azcm @X>?Y`! q_.9߇!UD2w_0A2:sa>EH45A6#}W'4~W7i +YPD~.SycI>s{mc@կü)!$ăЭ RC7 e##ؕUuAi\zlK M>ڳZ K0BKϷYz/f*/X+'="jF͈3) RSOY7.I-εƦktKpW+ LI! iEؘXcuѲcl+\3^# S1%cAs$A$on@VB`R=p ~e2|}(+ (RdgJU#B{M5s&RV߻;) oJ-@ !jBȔyB߬ഁ1 Uү14N{0`Kt!:?Ϋg_4fpOuLf|Fx'XGq&ɩ$2EDS/QPnTBBPmg!\zNQGfpMecyI<ȲG0SV[xFC6F0lBU)?{:n(qhHƩ=iq+ ?;byI% "5^vy@«} 5 õo@,ܨm zlZ&Ae65IVS:Qui-T1˃ 8?L%&EY>ŰW0vPQ>k^.yEWpI\IoۅTCox`:,/îuJT|/& n7ͨX e;aJC%i#t~YNw45+fd>Tb6)ʧ6XFMn42f y0*|9)eN.:P^v>9~~^0 q Ͽ3%\r!N}2U-j>Hi2wn/X$?JV4Xh|2'j{k9r>șkNGU0 >=Ao ºH#)6 ?L=Dd9G=,pB伙9-gDxvUVDpo&VƩq!8/PbӱSIc>񖅉g^)ӬE!cͶ*}EL>Lfit6J| 8bA.6A5x08nֈ+[$O/8]+&('.~ N.M&mفє~.8g4}'(psMWm_mf~&jQJ}ۈv=%7 ?ӄQwZfO=23yɄFkķ2Kd:,; re?'`g_P֕AFbpUlgɸaB,ېg2&p&PPQ$Vlf=R] Jobi1]2e@HSnJt?q񦮏 5% 5C!D`yhou`oT7޿ v N;UJJ QZoH}- ia[O~9mbwW<3-hnua3}U Y"׷E4Y 6pUWC~v|r|! mm̨!ӬEQtٿ_(#4>mր'WKt7FӢ9~M!۔j۲"CI|ZJ=T 6 '_: s7ZEVߠ3w ?5//#wjT>dO/x%c*f̍ OHcEQJ&ɓ6?A$}S)/9WVsao ]S(|B@6w6Xَ$ DZSN, p:]zV1Gw,( x.S)b#TϦĀ$F|W:(ݛـ!]V'D&tpKcŴq,勭2V&Td+ii׉phXHumQzlX5IyZKfD-(SiLD 4w" &`Yc FK5YrD$BLTb-d|;._37\u{^*paxO0j{oԄFg? @@MvtN~;$+'W GrFBS4F[Qֻ@ tN:]XH*վ:5~j_c-a? EɞfU89sl(|x״E,:Q5B0Bo4UӊӷE2Ign!P7 /K[h"8)^> ?\}G&^76:ţbױiCXK8KУA͑O8n\fO=v⒆66#eQUL{u kcrt!Lrp<4DG*_1Tw&NYXksp06ddm&OZl)X"wE4-b"LDrgi"# -H}"1&ˆQ֢ p:nm:耱GՌ6EؼA0U[džY;S`A&N X%-N]MetCXE+~:}"+aBPi{3*(@qy΃z=*]P!w2('bSQsmCFQ<;DZT)1!JB5;OA]jOk 3Y678~'d c\ᜆz%[LU?^6}k۬-|C_&}?C[?`8/v#L,P$"o^TYjיo:, JHxkȘYaP _%uFA"ŁeD-C# @0r%8;Dɗ0I2IŤ7di7Y*c8ʲY~}:[ }LtN7T @a*ufB:xa}~ڟZhqN|АH]d[;3)i7ǜCLGh3Ds7Z⠊a29Z5ұbsq|GNG~4< {X6&I-rU3?gmY)?{%[$~G'AYvws :cUboaC{ `054PPl㳶U "tRr2%"j!C3HE@7Eȗ}"yRLQ aujG鐦[~dL晈a:%2&4DAFمrcL!h.'қu=N?]0$j߇wM;i>pM + z7~4>(&gR4*hoJy$B\-Mڠېmo-|vzbz$~W 35wQbӞ=h:)W^&a3y$  :Zʹ2GqOC*nypcHص]ml@s-vWSa#@ be#i`EDv*Kb('Xz5PEL[or̙b = cE4zǪC`\j?3au[v"m"97GJq!,b:7%>z:|QviȐv0Ve1tMST/kUEuek]&7~AJIoFL>< 53t6wvZupK^K^pg.V<gҷ1ǜP*V$x!ć=sxؘ}&yS١Կҿz dw?J/ yl~ m}jz\^5DumJK5C%i&ACaчv28"}]7}9}tf0ЪmM楍,Ojzk7wl vIP J{UJsS06bM?OXf H^2*Ux.<%Y[e Wײ˾+bCGH_Mq =;_5JV`y=(X*vPdiK~Q"w 9e;@oN dJXv{{^TkYkw5V:3V+ nFB,rT4učqN nbS}){t%/oʝA73[|((z@K(|3&3^hYTIju|.^Rc0JE^| {&JoBm{ ?9?l9z} u=Y9ɿ:kKR)qE Vw3fjGJ:3C ^[[f-r K((-JZ^ sbXBM҄_t%5-! гǼ,ul&EBS_vǼX,g>G5b|m;w`XS'ɝs޹>{jJ~)7^ܓ&5ӿaXstF>7qW"V |8I:pz 45'и~=47b9@YDb,=Ц.jDe30̄~e}y9M3O\5Dn +WC_fYNN\61k?*Ə o.[H7s#cmE2oM=x%[Ts !pdvhwLkwm%{uL`s-+VM~js*w ť DkeMReZyM2 d_R=tzӈw qv외y)$. WPdQrh܆6+FWFL ֏C+1-pMa9e}MKϪg8%C%xXN윇,Ǵ (s*nRj/x,,sQ}{`4Ci_LŭTwNCEc,b4ۭב+ue>V. ANmaDsĻcz,s9ϴD%])w_}~{,?o)&0ś>c./z]d+ dZ?{g@r E r_돥,SgC«xz|+!PE_6n#1TEx=L`H&7S)S#Z)sIR9(:c+!8fPDh.݂:n3""gR)FbS}JFʻ V?X^fʷeOl,2xـ7I6F>wma1BTqGjk'=Qh $}Ce9}o*~I4;gDbjJhNAu3F(-*ܪ+_$Rr И8{2,69naեV!g\[5WmM`uJ6x.F$ŎPdT2Yf2}`L낥~p@ %{j#b dXf1 ˍ8&cybG5.z A "beUlVၔ*%ЎC" IұK>ˬh;Bc=?-C^`^ya|~9dqR* BH!#m-ל63eT (V3OS"t(E`!Rsǻ6BgՅ2n;r4xrV$K,孖䮥xvsSX ȧՔXigL\|oԧP>3 s %% _vɾ #ؔSܔBvɲkLcI6uqhUnPIZ>[pk*M9UquOjXEӡm7 ٰ@2ڮ5!FT6[;IYykw>#'n 7]>0} Ɂ@]/"4Ki!4@3vs=(VN[)d,!H{tzJh'3ݐ7"Bhj[R(op2>5N/"|no&WA2|;;ygJ)S떬<-uBER8g:xM!&^hP0޼D?=x:qwL"<4xUÛbp$ZNyZkD}1MWE[6XI<+ t[Z|Rȴ`(N&2r d4.bf D;^Q^Y2]BCFVt@(cQܡiPc2?Bbt6.coTηh ;4t񶒔:2loeZRi5Ϭ3û.{v:~xv%HLM.gJO\p:f4D>p_<fjIWc}9_{S%Պp( |MsbY}NR!Z딶{ɩ5[zxB]Xr%\ԕi "7NmmT?4[T7]y cO @調٥ˡ% (/"I!bNb0L. o|-#ȊHa~"&?:GkzڥZ!ͅ4;Ѻꊹpljׅ8X"JV*6)qcxOs[y֒j]~#<8F] {RX1^|jɰ VI t"dcve}} ,w=Ďڐ4 |:we^(Eg 8i,46{tF눻vh]EP $p :;~oVn<a! G9=1(sg Y=aĬM !CLeztR-싰xI=% MT4:alS2&`ٚZ5ޔNJ]XU9kZ1YGLRC3-t= WzXTŽs|Ne[2ܑ`!HW׉~uX:at+BX.DFe(M j-+7䢿ۣk`_cPx2@c?{.DQmñ;6*$+Eȅ a' ڶDhK5a, vZ0>Wx  \{SpGjΦ!e_Y]&tdB0ߵe>,_Ze`5q?zU̗Hszk(@6d4lt " ÔmsQk]f+EJ2JV$ZaSlS ]Nz)^}瘡B=[Nn)yfcW#D\I3rU`NZj ki%V2#/#ǐ_I71gDc VtGt8%F*tOb d?؛yAoNRrFE"ԓw9U:_i BۇQwuODFxꆍl8&1i$| ݲO 1KޱvD+-0bsj][xV W\ד9Mn8wE$Z' 1NpYvvTc8#mQ;<A<[U%G)E׵V&$l È|_&% 7M2))W-~gӍ(D%s.a3 6{Pi 2 b#ZM̆@abp :G{mqoxp%LKS5/c_7Y $^2xy( 'mpb:"י>bmL߳7קW{fvj>WD7/S89To={oST*? AX<,e<:Jlӟk)kS{75?;"Iv\g6&3[hU3zSq WQxXAzy 2WCHmTqaoE}Qe9,pEo|EPӈM(=>O=`~x *% ԝvpB A[˴Lּhk//W05-g,܁“ȸ (ea*W̤snVZϥ{_0uG'6~Xvow/CŁŰ>hnV"SIb1ӽ6Ѯj /hv͋^% @~\Aeװsٗ$‰3z2#-K`DPDynNm 6"P{_TK VL+S%$Οn~MEU cVK>n O~%Sڶmx7F.<=51L#RhA>yz8}'8D$ eX\d]~u\Ԡ^s:K !LdY>YE[pAzHLT6&,`6v6,?Q*`'Qrc ;F3*12 z\嗭0fN`Х`.k/طUhMeG|o t`"eqH}k5>.wI͍xmR(; Wgt޶M!x> + iiy K(R0BFj__6lT,d21w&8oT g:詒qi# _u~7n7RtnYUoD"bhcF'M]at#u^HTOYϔ۠r).1ՀIqk4Ov"VX~lvO>FBbr|'%Ȅ/:Yȹ#&ur^CNN+d[do7 ~[Ă7U@i¹2skqѿV*j3yWgo`D`B>S Q-yp`PnoߝQ;G읭l8 U'.,(.=ksy2F+bWg ovUrjxP9Dohg O [諜DžC " |=Ғ[c'.rψfV[IID 6wgofSEA8HJ7B,M-Ghw͐loސW4V3hW:u[{$0UȈ kZ5Þ#r)g?` .k0Sf0"Y8©L"d|%S'g`AK&?\ g>E~6aob>ֆpA(WV㢙Z[zoaΩ9FgES<] \I7]Ŏjf%${EIgrG>Ӆ dC`T)5{\V{Nn'%~qZ<k.>X7W(E^轎-ѧ_pϧhzuб!q Wz<UOOS_9T%]`zAnj~9ԣkQ۵@|/ѹ=  C}at{UVޕFÁ UxjE4lw>3c Y܀~s]kwcˆFbgisB/dI͇ܸB{&t'ׅG[Cy}V5i@$Y{p" ' i &C| TwӐznZQoYv\E~Zw>eHS'EsS5dt ai xa>B?1\&N"0`+ ߃>'lA^ |=T&4)E)=`5F@Lf}:_wq]'j?]=~贽j,̴_]Ýs+Ո]VF g(MXd"6م5CDoQ4ܶ 6=Eؾ"j0hlE\c_M]' o\$p|jwP% }bGf`Kins6p)XFZ?޸<'@*{Y/4n-?lϘ6mwЬ\ WP k ;?B|c/|̣VLi{tXUc0n?ĥ(`e 6@-V6k̿4Xje2!K ά^&oju@wc8U+00X/1SG'$DfOK{fu|DzeK \=Q,?W*K@PN;[Z7A #A^"  S獆5ڵmP5JV qZCj-y*^U&HS{2/ ~*\CT1OGaz~fN>;zRY"&$^^V6-V7P9*ph ^B> K\r)xJzni8κ`3L+7L=͒;i[ ~_n?c,2(C<άj Fe竜S^:4JV"Φ,~哃eύ0l:Xfgi[C1{~8zed۾M O Y*G%E)`{5MߏY2v$?A jI}B$\-slrL ^|Ab3J3Rh-ZF/EқtyAsy'Y_cZBM68>SYn2:]6m*t"RDʼn;tiޥm(W8Lw냏FӨM:\~{NbI> ߆džAPں˕`i,@Yy3aH@7^0?C#b_+h*bGEq$M5kXU@42ydPN5_Y+C'fYPG V! l })}YWnjlƳNs/wgDTʌ`;7CBɇȻ}|k&MrXT+W"QlSμja0qG $| UoAODټ(_%c( ra]*[\Ր?'8~^K3Wc%P⧃adk˞Πazn#ZrʌE(քdpKv?Iy2Pf6*E;zw)i*4@bη>UHgػj ߙUTV o*FY[~ͱ{=7dow9#{{MB݋<ܲTux6:SbAMӡfu{`N:gxW>_VIp,Tnu0|2q/[q.e?-ȧ n+@`tPb(at5LƆE.dXkY&AV->f'-bSg1'' ~Q оr䟥̅LnL% JQqCLL/^KnZf{ì5 yx"ye MqGj@l8qwTMvZ40Vfݴ,˃n }u xGۼC1&4&[o髐Z$ޫ7V>˸XA@nW $`51>s "YG4mt4\ ?^תHh3%!I~2~L4V1.dQ˒ Y(JE&7k\qWޣB3XVNc oE~YK+Va槏oƤ>uĦ~^(y; 4+w h,k;UČ|xܖ!^]Z (Qkf3>[=:>BU5rW#DO:?e>7<gsgHejۋ\0ܝL + -[<^"L A7cq~Z2~UQ43|Mӡ9TaZSf zlПO@z xD݈/c$;rc V(x_\csS~-S~_4BsZ W ZAćͪ-Po駔:JkWms>lX]Kp 4ً 䡟U2cA`p .{e^< #Fܞ Vb|He: dvOyX.FU|YY_ZÊp&Pґ3wt̆ yB=XZT"]Qa?&u,*]&FP}[Q[R(m&jz`DbSeRz94)\PaO7pvdbE3#a{՚_Q-X_آ/:lqyN$CզPUd5~Ɯ&ߕ0̸O;3XB R C*z4Z|PE]RM4\mDq\Mrn$(Ћeγ>e.Q~KH'KeO!$Tz( OG+3wz!ntL5TvӬ32 g/L+?h\AӹxH@> `y ~Dh1VC\&^N3oS$Y~ICEx7p҅)m|=>)-gp&#d Ck{^Te}eJc&`c륢X 2 a0d*rx8UQL;k9ͺ-,z1$N&U2*WzWLU"g}9YsczᐳH"FFG6&F?i_UOÕS:G͝oTYnlu;z;z Rm D=ke֟ڨwVh?=볘#G";6o;$x5Vh5sE+ɭ(6Kq'3\Ov+vCĒM쇍)'KNWݯMT}~7-9AOV-u#od"~4c(6O?ncA*r:iwt+ybW|U)9VIOs60*!s,'Z LYC?):ãaQV,JPf%7K1Ģ[̢~9U kumc-2\/j4I ڀmӨ bRyoGq+^ =˼SqhƋIƌ`г~=awcBs3 cB / /Ĺ4ҫSk}(E #Foeh?0̆DBjb!b_\Rm|7@;˗K\B8':7Ȇ %QS^gLpx1]4L T֍ Y} t] ",NƃM*VyǓ9\}7%cwM{fd&^ΥK5mưL E(5 fA|&9Gs@g0Qme`2WT%`ns-dQtZ=_'tɖky0pAhQ 7TU%ϊ5,IJ<|v)U]n!dz/>'w.' ?,~Y<,I6tL81B~H՜wǪhR/_#㐅ٚQc|32؛Sv3m'T@C#%<O#d;j\>03A2e5z?\ MTxQ+*ows\f/,_5eGU`!M KTo{hC[m+ /qUja[,sʽ<+LҎ"L!wӸhovʩ/ mZ6d^,TYBxsa4_oҹ+J=ס1i:*qE6%ʔ`e+,IzZC~㘖g ɚs,vw*.UCI1h_"{).21fY~(~m{Yɥ@}ѳYy'h9$8vIĺš>r-%EM :Cvn T<H;'VJR;`M8􄞆(sLHuU9Wڴ0B^\Rߕ1Cw W)Q6@1yE:(?o唂ugpϻ DJrj7`1C\I3SnA8ZUi<$,qbT$LAS@~&7X.f,b3gߜS!$IWwRA%e g#RP 2Q)QO'pp;ډAy|J$T S`sJ>CuTZr-|R|<;~PUO3_]{e I7GDy4{] QwSN+]aNTIAg}@&k~p`h6lz>3Hl{(c!n r"O"_|Z(x|A ؛ݨ" WK6h:,e15@kDv=zOa$BC]rZAOlO.0A^OR:  + ^t%,9 ""qcwQZ E. M1}牆l fEC4"ǫj-r&eּ~QWva \P0^)F,>>{S kweTV-~ݦV"O̊Q;@_wRi-Wy,ne۰%dL%t(%])9Md3:V2|^ u}Sw/-d)K-J= uzҦ?p6l IP xƛHf ai_a& 7]_:C,.[8%!$VK٦Dd6h&X|w)ًb׆cHVx#u vqO4}NU6d~=i"vj=tt[[)B< GtdLM[Lny4u ]ԟf"mbZVd%1gwG)Tאe{TOTӝ-&եo\QOG|0dӥ9Eр,4IauJ6 ˛q\ C[!+Q3EBpM&mq &{jN 3Y#OZmAB+mjEi̼oj%g>BB_JԒp.*ԮH6+kvq,gS2*@mz_M;niP[hYMitCfɯ:k0p<}?+RWDFVC'dKe鋛B Yު J]Qkj5*blB/ &aCTX=Żݞ:@JM8o &3Tuq [kvJBy[PdseuŕPE?hi*NW -`ެ mh#Q^SV@qOjo3bkyp`"x'Z*Kd9tz}AUm|G"niqN߉PK3~5l+=T"{bE[?gWs($+Abiۥ2Yjp7n0? =2(ߖnl^tbI&]jk &1 ಀ%0y:޷BСrZ?NBS0 0c53s27kҘ~wT·\n oV 9}n\0\3giQhs|/iM{m[ 8UQf/KOL1|W%O>0bf($HC--R,򱪶yN'U{{~4,K> Q%2{oYbH>i<-‰B黏]"I} pe: iZScwX[CQ8*bnu( ~w0ھW0ЅIiK#р´x:T 8"GTQ1)MiK{T ;+Bj7W+ 嵿S ^ڶt-HWAlH/r PS5?3b\'6fz ~Br(gs?S6t 5PB8 R6L{GȰ+0uJ%j u -7#zq'3zaޟI 4Ul2{>*W;R&(I&e"ֽpљ? 0/֥"gD3iS_z^%|EC\`:~@ϯ {jhqmӃ|zR1֬]8mFyMtTFvO0/ E3cJO*`:_,ȹ*7*NTJ)p]z{ră%tf2_^r]iB̂8+aD?.q\qŷf ݽrJA~ZD*\9%|7]~\ 'WRoviL+x(mJBߚт^T"/#R jQQj-X=ZyFityOom6G [Tu c`m 4YoʾY2#_vۑ.Y3 6mo]yHzXY]=M(4n(ßy̫8ݾec'YqXv{v_!L@TɅa:(R[pBjU 1^2x\yこjTPg$߂)6,o.#~OyGDx'bfn( IJ mlTDI\LjdV}Ԕb/,?2v-pEM}al[NC' ҩs?_22t:[oSH|=/k+tѧ*0}̣H+ɳ3@9cA=Ol]z8D;D@P,k;.ƪÉ*P5*ɞ^fU7=SO;G%JS{ninC4hz /@RrĽSh@gG8 Yp,Zfڬ M=;73Hak~KL RxgI>1Fs#Gu@M #T>{c#{60&W9~44 ͖]T lN Q0&=uꬥnGS  #ί@nw :7eK' BS;x-|uYn+\}fcy `ӼU cpY--BtP[Քe2.3nC0NZl+4eXɒG񑒴ԦIG4i,$'W1.pИR9wI24#"eoL86}`=]-q뤗.fd1v=8ޑ7f݊\j,-a=߻3Kk`+ (aui(ʎ=.elm-{]Zp֫C0(կxV]mD]u{(Ɂ[ @BNHr]cBOGrAsiC8hoR֢n,b&zi6=}q]^sꕢm9& Z+Q&XRNj4s;1sK`2 -E_œ۴- ˱ХYԳC`^b):  DݶPţrH'pQUu$X/o[4c~L+\,S;Dy$L0;f"ϝ|[2_Oc2$|G>QO:i-e@J(HRXWn3W1XR~RKo6!UykqM<( UQTQmߪ$_>Q$ii9S!F}31RGy~k]G}mNNa'!nE.zEoسe `_H#*d ;fe2(0KcN #+C<뱚)žZ@6;aIee`hMhIZ)oh&Y#xRZRX)ޔmkt|o/X-|rӭRՏoD83guի)h4\8$JρclP3{}DTByaA͖G?H_v .k }_`A̳(o!ye>㰱O`D뺗qO/Y+E.IW9`Ȕv*V}0%,gz܋c L;pxg:bB8opYf L 4VGHI1^Mor_xXdP WuV3ax>Lk #+1޵<7*%^ELb&M ɣd<1OQ&w|=v$تڰ2ds:_)B*oRy9oAw0'dc7Hs*#xf7"mt+wV@i}YLn#![b.BɃ$O]<&4Omϕs[E>"MqCׁvsv1N%Md0~ xlV`dqS݉cPyiBj,5a3+z %0Smb9:ֵKVWbYZɬqrxUI3ζ>?Tr @Иelot︪&cB4_ sSUEMf&:ax* PrAKaK$fL"EƽgթÒ S3e)ď;˩ɼ-QWb0B>ߌ/8SgP(K7 Hhot99)JƲm؈w0g=| ctdT1ZV3C 'E9j%BYc(]37v7x&g]Ὺvd2~_^9TY+z P8bns-^C:,r ܽ)By[&i lo$n?0_2ւ(ԓSٖ"{6l7o( *pWn$=誸n=7[U<{s.VpD;눔:ǰ7\9SNzx0Dg?)I~`%x|`鶖6ıGU$E?HҾ [Qŷj96uo SpO\cBP^ɟ(mSjxBOw#)V=*ӄ5:RCƷ]Ouz->#8yv yl t  f݊0ڞeo|CtlVL".EZaKH{ fƓƺ:ʿ"`FihFö*{B`d-պ]jXH7E/LE >IWһ=>\K/ p.V8udC#QzfNCfnJQ;L^GU<StWp,})i Jƒ1S^cG2'v;,'@ŸK>y-qm˪+p+.nB K<SS^$wl# We~X@Ay4h[,>FBi+z$E|) 4H]6 , .nMU=tS)aK+TqA9\oёh<߲1bgѽפ EٶޑT7Gjhl(wN)z?Вb*_G{'GN9o_+(KypQXmtNӮP DDrrF罻>l-GL&C;%$C5iNYObhJ |\N թH@h Wk  &~uphu!ZFRl?-zѡ8$i)"EtO 619wдTP%)z*pTkf:Yl]HW>esddCDM4ƽE˹+/mKѭrF`k!ʓ@xp ebPA'\Yľ($gj?;d|$!˦=) ]~uܦcMX1o .WNeڧ7feqΊ.T$yRٙ9Ap0ffQ[,Q`/d2^.in7.'r;D{Lw¯^ ޗDIKT0t\ ],V/ݣy A14T\K VBXYCc_9ݔL#l0ti'TZ-{Zߎ#Ӫw3Z zQOD 4=üZ8X V\4jE$vprHM%)RoE{!Lg'++&$u:=d ,Afr:{ԅ +ddBj/C2;O:u1u!\7$~>Vj4ٍ3)2/i4vyRFCt G㶜v# pCG=[Ս6p=r"u*_J=F&"VW\v", g1*4(b:crҡZG-7ޞ6񋭉S(M|O k?]̎z@oո>#KC0YIb!i[_2b7l߾H=(-l&_^AVz]1<3;eV^0uBCփnMLMih9 N0:FW~5=l<<HZari} wf!V}c /y|pʧk5BlǜrjbUۚs:-8Ozd(q|8to;\Y3<# pL|fU/F^<}~ F;rbv"lgM 5jZ3y56bOOgc H*l%g+ ? Aa@Fy-K,I?Yfdk'(\I`&`zs";ȷv_8H BMԘxOa3*Q;@z p܈b2 hg݈8l[q$o fm Oo n+b_F|&bt:bO bg;RM̢r_`rlF6IXo1K$*4W~#or }*UX jyDuۭ,'n2_d7$뻇;W0sֺtĴ3zNN`(9j)ic I-27pɹXPXH[}V?!.}h̋k_['s 4HSOwD8bA~΄dC~I.;ߠL]s($Ṙw;3|bma g+ eN<CضG9#8^S(KgaB-GfuЉf< m9"jOLHt!i_]q5GTTLg~{Q*P,Fd9FU܂7W 6EYޡVO5"%spMFu n~/x̘cϺOωcfச@zô':|YU o:+ o*Hzl :2dK0cbLg_TKsH)YbVʦGr9rNE۔/&ң5J{0T}Cq%Dx=>$S7R''Da>C~{GLɋ,Hܸ Ѷm׻OZ⍫2tv  V%q턫~o/UQQmok*TOWiT@3%bA )fmV`M!}mOɀ R>d~|d3#û#P/,VAX(Akqm */k?[lUsES@=Nu͕"zȌ.&5 $Zw (JM4C NW:!x9ɎVɪV.UW}`U81n7W =F\ TQ'# ~ndC~|w,zμ0qj.R}m[찟)6{ݖikP_pGKsC-И ө7ffK2 nm鈿\D"kUtV[tvo{er14I%M8OTb >d)$&m1[?X%0GW-{MyՕO*[+X(H"jŷc菨!GD7vh@^(@0:KmۀPh1c߸\x*IwA٧qRpCwY0Q8HDmI,deT5Ol5j 'rEB]-D 3rzPE=BfHקh{w  OD ͠LǔR!GWJbKxE8jUrH.8Z@m6b{Uқ:3ܜ#yF׏4Fb/;nUZxFU]D1^UZb`G BoUV8(s[N*nEA9A6\q_PH\j5;CFE~P 38xK)߾Ti?,WHO`,^ṩ9m\OU޼:1/6c9m h"lDe"-Ʒߛ(> o*0S%R|cJ.g]Xl֍u/ԋ&f\ab-E(]@xC|F\<5d*Tt/V?(!ib*uobEUv%:  \pf/[u[xlo"_JfMq34ZĹo) fY~E[\mؿds=x !MB 0=9%<'Pw|#>k&PgRe~(W4mrMKzDD%t`աâe~OT'ܷ05w_o+Ӗ P$d\ oo^f9v9=A=c]>\ 9%cN#EW&{'UF)< d@7r㸺)f$af&ǖ|q732B$"JMϤ7)OJC~oF8x7&[F ;+b5!gOf`p uY-ey;cq}<[N'l5 ifZ|&(=SdSIY!٢>d,hֈ}s_$Aכ ۲91N/slyp+Nڄ\4v_nHP-/PhS cJUםYO D XxsjfiAqF5*w%őOcgXQ`raPˁ6(\[ v9P ݟjCm U˔מ-Bt<@wR*"ݴGHUL bܙjAW,ͱ`%ܕ}]1gn!%UxlU҃P@L^\*L4]|g  u;uQ=,E>>5ey}"1XE1#33 1RU/Ѫ4P_zΆD>H WgujԊ]ad뮤M-< wBTqȲ-l)nmh=/.5@o܄1Y 4(!zPS?t$b76PvWPBIܹ"qq }{<*\+ Ko{-,v!wc,9gϢAF/X36S?颯@~ֻHe]C/${l.M hu%^ BT{lZe4;Wq8 5nu.TsOKKgTCLaGoGbK[3߾bq:^|O>exҔ' p)$?Ծ>"ĉUG'k< n3#ޒhaþ⚼22 n *8ފ7 Z0I\t(ONyQG58IĐh>'ê4NO̲tΞIƩu,=gl9<> Z96xmXVg$+vuSʿ|s`2 %Njs<E5h LڛTXf2j2"Yf*7 YuS8DgdV6۽D/.NRM)lg^kû0'+G3g)x 3ySl[Cc*29R._T!ի88%q[Z (%X)8}U0'kTa=]ԌQMr$#_(>B·L%2g}|( ˨WC ὣ\E E 53cӆySy3wĻE g/ENo#I~t1(uf:o r1YvB۟,E>7*|iӣ$]oV Qm%~S$,N`|`}:Ēt5em='\tB #Ǝ_GD/% vhwT@4S?l=0x@BrfzؼR]>YRFO1s7A3PҶMme?5 vR)~ J㙑[:^fLQyyiGsLH5?G;t*oR9?k3!AC `2r1Y6uYx#o& ~tkg 740]KJ[-po$?nwM^rKI/j^3W/{ iE"+X,]t{AgR ]DS"jޝY6ݩ$nעaEZHg-c6srI#2,XzV^8h6rMgY.dz 82e(iui0W`38z0Zlf?M̼Dzml1x[JkѤoC;ʢcF.[hDIqH~F!d5g:XKب+JE=y;F۸k=E*Su p~*VH*w=Ii+a4 eЯ_cQW~4(?u \2:TA @˳VH0XV u=~SJ{n"X>tJb+ EoB:Fgt#*gi8;܌彄?K}O'}ċ29*}^/p .1[<s CnTݴ@M;PN/?)m6؏:|č C_֨#,(|b(t U&`f= 3䏎m{mD9/`2<a{>3/8;a3[wf HSACKam3@/.Fg|ccH|br$Td[CCe[je^{sADsKtMI+3{ HbT3kmEm[|W5}LL;Q>(Fn:!`tJ0(2&;lZ睝~D| !fj3駓%x`@@k!0n $Χ'.HQX"C"RhGEMކ"[{@HaJsx=q]xT† ۅOI?[1"&(/O!5w[8GHOӴUI  ctC gMa8V B5ꑧ/k/(OHXRбn8H$d 7= yVIqBӐTO//?m#p-/3)e k<J*a,I7w<5dWqp 0ᧄ8=_WldBEX?}J&&k!5ʉ5+֒ Na_ \e8Av!*"ܫa *6@aM1uSjdQ|AB 3q@{ _490/=ݠ6M9z\ppOM66=`0 ".Mxa LZB-o4E9ۢȒЊV䀠`<@+kx7q궻JdjۓM.ژF,ZiF)T$堧N`gb \R<7\ 4լň[md\X mW~G ȝ0N~yv^EUr]i\/n}&䦚^SLX'Y$$tA0Ag-jLFe0;|5r󪧯. f]1"`3?}u`%#kTYCrإvt` ?IG'+y\<}S7YxR#,pI\ 2$5oMGJ>8}b{ 3C'ClRzLJz?8~TrEn_]e!¼Fy~aW c/a`v“Hv)kajar\vԺaI4ylh\ߋ]ngŸrV8cH2&Ƚry D4ٶƜ=zI? 3-(^#\jVVL}T, k:>|#Og_ֽ?)Z.:.ƅ'E|N`)*MSmR_og+ai K:G:`tES1GiԲW6Ym6Շ‏STj rK\߷,}3n{Wz^ƞ9)8^o*l`F (s@4t#>2j׭6|Q(!lcЖloN$ ?λ5$|kd;qSW38ÜC|fǣދD EevAI " z.ߎX4)NH iS_]uqiBKq>i#Ĭ>5F_&@ !Hyc٠X6!FЋqrmdudC'h8J = ݟh 7y bjZWU_ ⬋.]o]Y7SMaz$هqY8w$kkenϱh"HOX(vF>cE?~ GJgfN2cI${dX<0m/U9\ I0x?fF^n,:cS&'xbqIT o MSW`P`h7ǚȮҼGnXHn"v%ZCwlt%/P#l򱓘u܋ 9+~]2peOO)~<*"p]N|qY_dx['XfTPjfC F@C@'T7ZH̐ VswvKu0áOߛrytr+jm |l^&i2Fr{֮+ P![˜jw{ݯ).m0/stRҚ!(Fj1usT*kq7&K ZA&[MC/wv8!V\;Y4l~qFiEjͣ5zn$/t/q0Ȱ=;X;}'R,nx&:m^8Q\`Im y.P:otW%JgYJI/J9 YߺngfNvO[$egIL[|$$h $ U.)uHif3]܋N%!߸U YgVv9wF(HC/h:bҩPAqA{/:Z`>- a 8{:,\thا0H6$+TQoӰju/ڈY9]uE=Ѵ+{ u/a=Ht4H~Ĝhw.gI(x՛hKbɑ@B$"O/`sX4\OU&XM/-}ل.& NԚ,jQVRE=uD&MKgm3~%ُ\Ia.(طST2g 5cvh̵-I)ڂeLZQƌ^ Z>DbDvh8 ltQåNpr~?3<$X|^ϟhA Yx*k9wJ^:miH.F]mK܅ / * Aq6n >I!ςޏ<]meqfPrQ$dZC*'eN#Z: 5Xė( Gn׋< ^鋢f4-Il8~$-r4{:9Sjt$G3G0/3 0I4lBl@mh+ap .6\P^osHy&l (USJl+W~tSv~YGFwhB!h%S#Mfø ;7M.A=VũxfNx .}3#ߍݢxeco$<8q<<“J%1ɉGȶ3|X^9LǬo7r(10~OkXxct>:4SQ #sIyה4kj|;_ѱpP &t+: m+|{6 CQ4շrnCpr|3CMrj9k#6 F#֜[lΣ=i/_.ue#W{HP$=(yr9Lähw/j6-G ! 2qV:Pv)LO[ĎƋhVwYm{T=Yi _nQi&*ù}mf2zqvjZAaث͔/碔rΓ,p`=֡9V:[.`W 7JϺ&kU&S 幑t%PL \?; b8p^ptplwCKC<#H-B"p_ONKI:_*"]ösՋG'$z\L[u'tģ\DSǧMdž#b!켠@?s<}=<'-rzZq rb"bt`l1:|CͺsvndX<;c}~z]z_KL9O/Iu{yaYz Q ,gyh"J]. )( l&-6%bKv.0x{B>v`uO˄IGVy uk/R?Hi;RГ*+1ל{j +ǣ}"s)bwqy* p 2 IDt~z5ΧhGB>r~>zE^[ظxkGh$aMm\? =sut|Xd^l|[ )jxxr$[ÖY#pfXc+Γm_ eO5e:xDFk Q}&E8R+T2Lߤ`lcUUC ÒOv ) _ #jb| zbF2 :PiS.~xAim8H/U}w|t(ca]4,3kYG:F'_܀Ӑ^g.3x-&蹷ܚ  ;Dg3*NJ0ǚ#il}ϣe"C}}i"ߦQҵ0<8v"eR-v[X,b2DžXf1m*X2a0sʯ_}W+5`I*]c YZ