cifs-utils-5.9-3.1.1>t 4 DpQ/=„eJ-ei%:m"  pQ)fC?d   [   LRY*h  (     x  h   8" ""(89:>?@BFGH|IXYZ,[0\4]^ bcd[e`felgu|v wx0y8zpCcifs-utils5.93.1.1Utilities for doing and managing mounts of the Linux CIFS filesysteThe cifs-utils package consist of utilities for doing and managing mounts of the Linux CIFS filesystem.Qbuild09UopenSUSE 12.3openSUSEGPL-3.0+http://bugs.opensuse.orgSystem/Filesystemshttp://www.samba.org/linux-cifs/cifs-utils/linuxx86_64[ -x /sbin/mkinitrd_setup ] && mkinitrd_setup exit 0 test -n "$FIRST_ARG" || FIRST_ARG=$1 if test "$FIRST_ARG" = "0" ; then test -f /etc/sysconfig/services && . /etc/sysconfig/services if test "$YAST_IS_RUNNING" != "instsys" -a "$DISABLE_STOP_ON_REMOVAL" != yes ; then for service in cifs ; do /etc/init.d/$service stop > /dev/null done fi fi exit 0 test -n "$FIRST_ARG" || FIRST_ARG=$1 if test "$FIRST_ARG" -ge 1 ; then test -f /etc/sysconfig/services && . /etc/sysconfig/services if test "$YAST_IS_RUNNING" != "instsys" -a "$DISABLE_RESTART_ON_UPDATE" != yes ; then test -x /bin/systemctl && /bin/systemctl daemon-reload >/dev/null 2>&1 || : for service in cifs ; do /etc/init.d/$service try-restart > /dev/null || : done fi fi /sbin/insserv /etc/init.d [ -x /sbin/mkinitrd_setup ] && mkinitrd_setup exit 0 24vI8H'8 ?s,1hAA큤AAA큤QQQQQQQQQQQQQQQQQQQQQQQQ4c95734a68b45b65a5dc7b108836427bdb5289bad3063aea58e1814380259a28a282bdc147739e1136854d3829b40eb5728e0851c3356a1cb816d3880ad33cf14e44eb786349b0fde270c450ec6c7bff24377868ddd4ff4ac0b9142b9e4398b45360a078a7696f4a93b5b3396423fcc111e1c3c982b8f46799595b808f7ea2dd51146f45f1fe43ad1ca484907039767c35266d902dee59e2dfe3ffd3dbb7dc91740e8f0f5e82105fd50f7332393769fd139243eb96cdee5314a5aa65447c2d0bd4c2c5ae5b98a556bd98284b16e9b273b00a874bc0a7754a09bd767cf2fdf3b7ed78bd0b331a6ffe4885f6ce28077e230407c8b3774d4fe44311a9e3ce96f35ae111c348c722510468896b725c26df86c2d7479cf059afcf88a8f82607bc6fbd/usr/lib64/cifs-utils/idmapwb.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcifs-utils-5.9-3.1.1.src.rpmcifs-mountcifs-utilscifs-utils(x86-64)config(cifs-utils)idmapwb.so()(64bit)@  @@@@@@@@@@@@@@@@@@@    /bin/bash/bin/sh/bin/sh/bin/shconfig(cifs-utils)coreutilsdiffutilsfillupgrepinsservkeyutilslibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcap-ng.so.0()(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libkeyutils.so.1()(64bit)libkeyutils.so.1(KEYUTILS_0.3)(64bit)libkeyutils.so.1(KEYUTILS_1.0)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libwbclient.so.0()(64bit)mkinitrdrpmlib(CompressedFileNames)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsLzma)5.9-3.1.13.0.4-14.0-14.4.6-14.10.2PP@P@P"TO/@O/@OȮOȮOȮO]@O OO@O@O@O@O@O@O@O/O*zO))@N@Nl@NtN@Mv@L!LV@L4l@Kj@K]K @K\K\KKKP@K[KKKK@K@KK~}@KqN@KqN@KqN@KqN@KoKoKn@Kn@Kl@KjK^@KUKLd@KG@KEKEKD{@K=K;@K/c@K*@K'z@K@K@K@K?K?KK@KmK3@JJJ@JJJJ`@J@JH@JJ JjJ0@J@JJJ@JJ JzJzJt.@JmJ_@J\s@JT@JT@JMJL@JI@JCfJB@JB@J@J;}J:,@J8J7@J7@J2C@J2C@J,@J'@J'@J'@J+@JMJp@IIIo@Io@IԨIW@IW@III@IV@Ilmuelle@suse.comlmuelle@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comdlovasko@suse.comlmuelle@suse.delmuelle@suse.decoolo@suse.comcoolo@suse.comjengelh@medozas.desjayaraman@suse.desjayaraman@suse.detoganm@opensuse.orgsjayaraman@suse.desjayaraman@suse.desjayaraman@suse.delmuelle@suse.desjayaraman@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.desjayaraman@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.derhafer@novell.comhhetter@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.deboyang@suse.dejmcdonough@suse.delmuelle@suse.deboyang@suse.deboyang@suse.delmuelle@suse.derhafer@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delars@samba.orgjmcdonough@suse.desjayaraman@suse.dejengelh@medozas.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.deboyang@suse.dechris@computersalat.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.deboyang@suse.deboyang@suse.dehhetter@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.desbrabec@suse.czlmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.deboyang@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.desjayaraman@suse.desjayaraman@suse.desjayaraman@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dero@suse.de- Set parsed_info->got_user when a cred file supplies a username; (bnc#800018).- Update to cifs-utils 5.9. + new plugin architecture for the ID mapping tools + DOMAIN\username@password format for username= arguments is removed + full RELRO (vs. partial) is now enabled on all binaries- Version 5.8 * NFS-style device names are being deprecated in 6.0. * Many bugs in cifs.idmap, getcifsacl and setcifsacl have been fixed.- Update to cifs-utils 5.6. + -Werror has been removed by default from CFLAGS + PIE and RELRO are enabled by default at build time + better integration with systemd by allowing the use of /bin/systemd-ask-password if available + better checks and warnings from cifscreds when used in environments that do not have a session keyring - No longer initialize oldfsgid inside acquire_mountpoint() of mount.cifs.c as - Werror got removed.- mount.cifs: initialize oldfsgid to surpress a warning while building for RHEL 4 or CentOS 5.- mount.cifs: set rc to 0 in libcap toggle_dac_capability- BuildRequire libwbclient-devel for CentOS, Fedora, and RHEL builds too.- Do not call autoreconf while build.- BuildIgnore libtalloc to prevent a package conflict on Fedora systems.- BuildRequire libtalloc-devel unconditionally.- Update to cifs-utils 5.5. + mount.cifs: don't pass credentials= option to the kernel + doc: update mailing list + mount.cifs: don't send a mandatory ver= option to the kernel + mount.cifs: remove smb2 multicall binary code + doc: remove old XML sources for mount.cifs.8 and cifs.upcall.8 + mount.cifs: unused variables- BuildRequire libtalloc2-devel instead of libtalloc-devel for post 12.1 systems.- Don't package get-, setcifsacl, and cifs.idmap for Mandriva pre-201100.- Don't care at all what the real uid is when we call toggle_dac_capability().- Make use of the stored return code in toggle_dac_capability() of mount.cifs.- Declare krb5_auth_con_set_req_cksumtype if the prototype does not exist. - Initialize bkupuid and bkupgid.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- mount.cifs: fix up some -D_FORTIFY_SOURCE=2 warnings- Update to cifs-utils 5.4. + the "rootsbindir" can now be specified at configure time + mount.cifs now supports the -s option by passing "sloppy" to the kernel in the options string + cifs.upcall now properly respects the domain_realm section in krb5.conf + unprivileged users can no longer mount onto dirs into which they can't chdir (fixes CVE-2012-1586)- Added position independent flags to compilation and linking (-fpie/-pie); (bnc#743133).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems. - BuildRequire keyutils-devel for post-10.2 systems. - BuildRequire libcap-ng-devel for post-11.2 systems. - BuildRequire libwbclient-devel for post-10.2 systems. - BuildRequire samba-winbind-devel for CentOS, Fedora, and RHEL systems. - Add getcifsacl, setcifsacl, cifs.idmap, and cifs.upcall binaries and man pages to the filelist.- Update to cifs-utils 5.3. + admins can now tell cifs.upcall to use an alternate krb5.conf file + on remount, mount.cifs no longer adds a duplicate mtab entry + the cifscreds utility has seen a major overhaul to allow for multiuser mounts without krb5 auth - Update to cifs-utils 5.2. + cifs.idmap can now map uid/gid to SID in addition to the other way around + getcifsacl/setcifsacl are now installed by default in /usr/bin instead of /usr/sbin. The manpages are now in section 1. + cifs.upcall has a new scheme for picking the SPN on krb5 mounts. The hostname is now always lowercased. If we fail to get a ticket using an unqualified name, it now attempts to guess the domain name. + A lot of manpage updates, additions and corrections - Update to cifs-utils 5.1. + fix for a minor security issue that can corrupt the mtab + new getcifsacl/setcifsacl tools that allow you to fetch and set raw Windows ACLs via an xattr. + a lot of manpage patches - Update to cifs-utils 5.0. + mount.cifs always uses the original device string to ensure that umounts by unprivileged users are not problematic + there is a new cifs.idmap program for handling idmapping upcalls + a lot of manpage patches- remove call to suse_update_config (very old work around)- add automake as buildrequire to avoid implicit dependency- Remove redundant tags/sections from specfile- modify cifs init script to use /var/run instead of /var/lock/subsys for state file; (bnc#697218).- Update to cifs-utils 4.9. + mount.cifs: don't try to alter mtab if it's a symlink. + mount.cifs: fix possible use of uninitialized variable. + mount.cifs: reacquire CAP_DAC_READ_SEARCH before calling mount(2). + mount.cifs: fix handling of scopeid in resolve_host. - Update to cifs-utils 4.8.1. + fix mis-generated autoconf files. - Update to cifs-utils 4.8. + mount.cifs: manpage: add entry for "actimeo" option. + cifs-utils: rewrite hardcoded paths in manpages. + cifs-utils: fixes for manpage pathname replacement scheme. + cifs.upcall: fix memory and call krb5_auth_con_free(). + cifs.upcall: use krb5_auth_con_set_req_cksumtype() and pass a GSSAPI checksum; (bso#7890). + manpage: change port option description. + cifs.upcall: add 'l' to getopt_long string. + cifs.upcall: fix crash when trying to free uninitialized var. + cifs.upcall: consolidate find_krb5_cc calls. + cifs.upcall: clean up key description decoding routine. + cifs.upcall: add keytab support for unattended mounts. + mount.cifs: add cruid= mount option. - Update to cifs-utils 4.7. + manpage: add mount.cifs manpage entry for "multiuser" option. + mount.cifs: reinstate ip= as an override for address resolution. + mount.cifs: use monotonic time for timeouts. + cifs-utils: infrastructure for stashing passwords in keyring. + cifs-utils: moving resolve_host into separate file.- corrected #bnc 641513 by adding /sbin/mkinitrd_setup in %postun.- Update to cifs-utils 4.6. + adds documentation for the fsc option. + mount.cifs deals with the _netdev, mand, and nomand options correctly now. + changes how mount.cifs handles the MS_MANDLOCK flag. + makes cifs.upcall prefer the creduid= upcall option to uid=- mount.cifs: fix parsing of "cred=" option; (bnc#618877); (bnc#620856); (bnc#621525); (bnc#623763); (bnc#627243).- Update to cifs-utils 4.5. + strip leading delimiter off of prefixpath option in mount.cifs. + remove magic number for max_username in parse_options. + turn into a multicall binary for smb2. + fix uninitialized variable in cred parsing error path. + cleanup mount.cifs option parsing.- BuildRequire libkeyutils-devel on Mandriva systems.- Update to cifs-utils 4.4. + fix a segfault that could occur when parsing the address list. + fix autoconf/automake problem that could cause compilation to fail. + acquire required capabilities before a couple of operations. + ensure passwords are not left in memory. + cleanup of credential file parsing.- automake: don't use @foo@ constructs in Makefile.am.- autoconf: define CAPNG_LDADD even when it's not set.- Update to cifs-utils 4.3. + credential files accept parameter names consistent with mount options. + some problems with linking are fixed. + libcap-ng is used if it's available. + the capability bounding set is zeroed out for greater security. + CAP_DAC_OVERRIDE is only enabled when updating the mtab.- Update to cifs-utils 4.2. + significant overhaul of mount.cifs to make it setuid root safe. + mount.cifs now does privilege separation. + re-enable mount.cifs setuid usage. + make mount.cifs use libcap if available to prune its capability set. + guard mount.cifs against signals by unprivileged users. + mount.cifs is more careful about signal handling during mtab updates. + cifs.upcall fixes to make it work with the heimdal kerberos implementation.- Update to cif-utils 4.1. + fix ver= option passed to the kernel + fix error handling when duplicating options string + make check_mountpoint a noop for non-legacy builds + remove uuid option + remove bogus rsize/wsize options + check for NULL addr pointer before handling scopeid- Add %version dependency to Provides and Obsoletes.- Update to cif-utils 4.0. - Create cifs-utils package which is independent from Samba.- Update to 3.5.1. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7. + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7. + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7. + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build./bin/sh/bin/sh/bin/shcifs-mountbuild09 1359256219 5.95.9-3.1.15.9-3.1.15.9-3.1.15.9 cifs-utilsidmap-pluginrequest-key.dcifs.idmap.confcifs.spnego.confmkinitrdscriptsboot-cifs.shsetup-cifs.shmount.cifscifscredsgetcifsaclsetcifsaclcifs-utilsidmapwb.socifs.idmapcifs.upcallcifscreds.1.gzgetcifsacl.1.gzsetcifsacl.1.gzcifs.idmap.8.gzcifs.upcall.8.gzidmapwb.8.gzmount.cifs.8.gz/etc//etc/cifs-utils//etc/request-key.d//lib//lib/mkinitrd//lib/mkinitrd/scripts//sbin//usr/bin//usr/lib64//usr/lib64/cifs-utils//usr/sbin//usr/share/man/man1//usr/share/man/man8/-fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:12.3/standard/11156b5349edcd43f52a6d3625d1ac97-cifs-utilscpiolzma5x86_64-suse-linux    ASCII textBourne-Again shell script, ASCII text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=0x03c2e0359c2a8b951a9b7c206baaf30b313baf04, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=0x1a269898378a9741a79dea4a97c02ceeb635014a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=0x544430277070e82b037a62569feb31d0adcdfc6a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=0x8ac92c590090e202b86651fbd5214224fa9694e2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=0x8ce77eb55aaf663ff3639cac91c2efe0d553beba, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=0xe54b3c22963075c434e1d84908dd90aff991eb78, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0x2cdf6319e0c357bf8fb95fe4fccfb7fb2d2c2218, strippeddirectorytroff or preprocessor input, ASCII text (gzip compressed data, from Unix, max compression)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression) #,  RRR R R RRRRRRR R RRRRRR RRRRRR RRRRRPR RRRR RRRRRRRRR R RRRRRRRRRR%x]Ke%װ?] crt:bLL'S&ޫ~=2_& 8ch~(#z}dLx<.|HLV ڦi~Y򛅃90T+DElrW f Jj6vOwIYBJ7F)P2i[E7Šq/~VVb,bMg30q\?nSb .\&/ޕ*j$֌a-0ҷ_bkwJ<ׇ3 čVyfj'J(f9yC[-EyrRP6όoڻYRr"M=,\G4u;>LmY"I?WLPMm\a0:zy=UZFs~LR=mNY8mӪ4+\k'"͹BO=ޮf&ȪYC>85lٍvB p qH e-azZl ڄԤ߅CC?%Uă|fˉX!MKnDR*<(v4 5faE[ YE4|mwe(D9{oE 04;\"m?ox/b>ڥm+'9`QBp,yb>>WUޟ$J= 9#F^v&oeѩoոoYZT܋.K #A(Ml_a79\\N."PzLe҆(23,BtN6OM'$7Xơ'*&+%l"YrBS5atd'R|d]& 0 !m˴f5I(Rj2J/F_k̀7\5_ ر Qm qs Ǚm 7Z.l8E)alcr>JOA\xvQWtxC}O-P %&2j?n,p^퉙}_.}f\Ġs{Yy"LId}&hE :#Uǘ0eu<g gFhQPߥ1sovr{ȣ9iGɴWo{+c†ڒES޵#_]|QB/$ɱ40^H-~T4%gIޓbWED:nB)9Y??4m\^rC Pxsn_-D{4!DC&|2Y;}q`M6NӆͰ ~(RVaX=ЗYY}BXM)@I!Pyu*/!b45W52u[8Hps!!g>4\sBA KA ,m1s'IQ &Q5oDHVpKvN-0$0Q*Vb+70[F=n4 xD{mf͡6G ]+OxE՟-p6pwޣשּv0W(o|RsܝV6B36j 94r@r7Sp+c9Pc`:jhQ]gI &#n?UpuL 2-%^Zwctư!,%O*qp䫤~CڕG*nU`&uIE;fPAWw9$0w%᷅E;~b{`vA"Ry(aYr 8rmUkk#_72 5-ű(nJwEchjuqgQ{s64 $w&3±Y}q ,8%'m3\K$En݉n }ݰUB.!"&gkvJ@N>NW$[ȲWS/ie~u+=`ꎺqaϛndYbt4FQڱx\b9uuhCIu0خ$j𬳛Ok qTjfq _c, 8&_%=\r4Dx;xykv_;53뎘y4v !fE_(ڋH^$Gn]Ve_۩X5[zvY r,~Ue7ɋ&,P=f9&a7x d: wNL_lLÝ(w^Z-\f4]M+l{LT-ْs6\Ęk6\ G`r;I(LZ!V0>hJ| A2^NWO PGc:G,F!=蛑ڬq3ݭY Ji/ 2ZC^n>:q/)}DL]I^xB#d%1>_ }kB#Elv/ 8{6Wc{t$0}-xc9nn/дx2 _J їDY3H=Ц$%JwG2vYXB/'YJ\ٟq? 5PRAhx S13doKEz/dMA-ƋÕ'yhuSˡ#Mڻŋۏ;9Cv[b4$p9#j+* hlX{ՃTɒ)[OYo4\_7ګb;on6t0:Q% "I˄M=x mk(\KJ n(#J_]ǞZ0Ԭ5YכyO.crCG{I4,-8%$M]AZIS d wJg2"ޟ6cƄ!m XB9F6!SK :1^'$ W%3Q.D]DNہYEvw٫V0Bmjv_-QhR Qw\>˧:j|HiGd4h)} ~.gRmARF+T[]ު*?dɢy2{2 ц;r3*T,_ܹZnR!$/sMԒ8,)j֋( {C"ڎ72&J.6ў 1 zѮn l7"X% [TeD Ev9~Ek X)&y^HYȣap$8˙!-H2bf3`J<[gsU6V ˄\n>' Sdq!}Ȝ+TmO|+kR,unWG6PDтC>p?kYfk#qDTk;D{2 ")3]Y\Sb^?`5iP~?juPг"6]F +KpfB|t돹uLĽ~k?2!<,Rl ek_.rƫ64JƤB{j)Oǐw{Sat _!/!_G G~>DgGr>e~bO$!" )]בg-Ʒ_˞J=&Mv`pϼ0rx|R |@nUŗTKv cd[6 GMz`Q׬n V1Z=GmJ^(&)w'Fщ,gЮPi+ qbRaڌnߡΧ8/k596 `I-Pc=1_o5go<)ph{ t(z L&r6Tǩ("ܥ$ϬȃoH p; m˩7}cgе?)#h WgGM FM<hw)st&3)o׽2FW2C3d4ԗog#q>Cfʹ2&}DeCRhQ,SF^/p7Ofs,9'RLXREȔu@M蝉ҁϴxNŕ(q]i x}[Clq+WD7_RmFGE>AdzP׉6S"i9qw&n8#1o8O<IPIÉULLz6pbj׆K1M*f(&_%/[r pܛYMZn Ȼ@3 uTNU!U6 FS󖋑=Foc/0:S͘aq1a-^xl9͕:TfuMdKNQ:$74)_5뢝4R]ߒ9a*[DQq*a3R -l -zh$kD=0r.[|wo&'0:H+18?4y7AkK "xG0*@%n-Qk5hx pόڼ=W -/拘A;q$3tum *a=E8ٝ|7"aGH0=qcM}Am5fsc6VeUFVUvg J;e܈ GUT'бux #nLD)7-D|TX[тhrdsU/AG>5̫vՋv Ʒ D]5}q)b l/NMm`V:`"gXd!_@س.)aR.j\/䷚x=Y%duӧ¶gج ȹ{`,qjC-IcB:+>SQ#;̈́F\ʀ~P~ |[3YD,"A[y1U B0sE/-evMe#s~IA;]=S&`MVA=bPhxh@( LjnVem%qCO4d[ WܘJV^[mn@̈>$ =5ेї~d(cM̨*0CǔuMwGPs5Sp7c4cw{j8f]&ڕTDeV;0SX' 7'#<6E_6*GٰRJIOz[(xj@^kN#x&A%B +d,6gE8aXA$ҁڷ"qHCι22h4<Ԋݸ2ngw_32ҊKB6HfߥZ4Cm|"c0pq|0hYFIw-DS$m.sUkJT#JQڙT %0wP}H[1 oPd]UqMoF$Rjb tݏ.J~!6G3( SvPAQhv:=" teX5Wt當L,Qq$`B ^$4 ,EE0 b.ϕ]>̵@? ,{Kp-fh:vh X=NNae15Hg.kh8hT!~`H{نҋj&I&9'ʙIG"O_l-)@nCٍÕ;gGc t˨OJ$duNŮ9P!ic\!*h_jXqv3`ʾU(ً>SasTހ&_IY}PL$i~RP=G^2{3 WAksC ;=?F=#~j%5)`$Щ[Gh\(`uW|O3aCýemVܦ+OiÍK,ׁwx W+H,`fI\i %4G9?|dN}Pu[/vI#LV3yT~ eqi#lafH>eS[!As; b5: k+&`JъAMim6>=u4P#Eğ`J'<\ 5aXHߍOKo[puQa\;!1rkb>l6vb .{ 9hNrFXSj.z^[^[Q6psպtkF?p`RK2r^(LCJAHn0]1-*Z6 ﱉ[:ZӲqWIFrP1Neuat`>mpSUQ C i'ϯ^,fq*ҙzPM5ʬj.X>?W'POSVCP]Y8o$B  ,(Y05Hc-Xy1r7(W$}V2Y_1G%^R pB,jk,չWuH&O0=V[9wSJ{8?7kV|=|*  \Ǽ*ܨNvWL-Ȇ 7=R& vT+1 nmJK!J=/ auaeY-xs4(WmB=,4GW4Zߘw]Qg9P`%8"UbA_(V5N bi%1@"*H<%loH3F齋[q$ZJxt<| Z Dw0J 9[ PawGA}̏Jó.?4CyrN ak`1Қ͛"!N+J:lRlOrj,$au iee/4j[1RʏrRvؐ}ʾ6,5g4-ˆ|g^iwzQҾG*53h0$4?Uҧ7 c {_lv\pS坼s ?qTV`)ڞɮjBjDXZwT{"B! |n+38+b^q;|Ot0=fqpLa BN/On2Վl} 9 q DZ-izO?!taTG)NHHQ^)K`O愿ŀ0ȱ+l[+d';+oŧkzah 6`a3q1.̗cn; FNsC=>Fw):z{v9D_^]v-o?َ]|}sjY33H{i {G>N=7ϳ t8`)#4řusZ!LݣmT~jE~V(=|2Iyf/l*07G:!|bwkW ()H XI&|,6hP`XJ q[RfK' Ἑ% s .lGf:&0ϲ60 M4zK6vC]zX!|Qdpcc_IA㿡W񯂅ҷSH~/@H|#ufp=v|.o8j vD/(d̈́Q@ǠkGH O5lv^."I_A{ddo"]d(`iW*oAd w4~izqz**K@& ,iiW襑Ewr tpB1$<8jUKط*}mR~qPPtobIJIcF|G-,&!a!F|w(p_TVn?y1JkPnE`[{As/Z/nKlvK`Um[ Ub]Uxr1R@d6X])^svVOLn j RfgAϡLsyy.aAYMή]*i{,oÿ3Bȓ duSOZmI71K, k" ?3I%@OΎT<>`jR->Q7cxԤ}]<][/Ç04*$gtm:sVI/4ͰWIS*X6BIm2ąZ-a9t4ep~aC'0݄*rb.M{o}0tp $pyz!pA[~8JJc֝TH Q +Pr1ẋ/:)gk!#*{LwmHhm;QI7Zݩip-ڰ|>TՂE.a+}CGJbLW6DǟƝ&M>|Afpy JtwW2{/&F3DeI11W PZX]p8DɒGbEoRḗ{KDR^ PG0+'H4ǐ40x[%JOa(DI%&؉8cHIG艌q2AO=o+S͓>QnĦb_? 1[Ji](;J}P j/[KE˩Pc}#՚䖈}Qy9E^9> (TvxVͮo` wԻKv$pov@r}.usϣxCKp BZz}y}qhIPlTq G+P+& ZN6_o'?l$uܝ6Kd_K+ׄ3|X)!цcƸ -n¬; P@5tiA(@-('ya%ь4hR*g1l{*~Tgl8Nñ. $,>UʵQY&XZcZ;a?4.]gP (r) &;w0@-LBrx : mIŽNσmfQY8_]3rZ^:W:b[| 95/z<Պ*AzC/|̟QKvȃ,25qt3 < IJsz8*z Cj~uWvTE6 Z9)yhXE/^:9jWj?)UpG(*rʛCf=.jSuuYҦ@|K6`aӚzck M:$D6}I?r9U υ􉼋;CdZY1QPip!&vi3"D@Jz+ ;[/8;kM%H}9+嗔.atJ7pWtyU WnB߷タX{"rg齱چ+6Z slib/_ YTce: ق|qcb,bByLg}ִ!|-YU?QP'ͭ^(wAS O_ 8H-LlT #S_x5LT9ն~ RvrCA`nʄ}'5~4*lb"L k%1@g5\*,`#jB׽CKm6s6 8Dzٰj],t⟑<{cCa'4Ʒ;Ŕc?Ljج92?+RW܃5̓VNcށQDLlI|Fh,oըnF.(`ϳ_C΂ &u Р'6wv9Icyrp4{Ju}m^:)D@_tJY~6o2d')~S/Qc}o]cOc*hƼ5?}u %ɜ' ^~YQï6!S,~:~/Z?c&6TQVƓ*B*M˰W,Ocbnu߀nA4,6\5{_ "t2? 8 b^ĘMj둚7St:mp0o-0EYrE}UiD&繳Ⱦ]4$J~k52. t8VTyNVڟn?yWh>JT&WVܾv(0ƆiQrDo3Be%/AYFu&mv=gԿyV)*;u|ZRAN"[T|טGKQw 5]^nT!\SƸZow|$GEv0_yc˫e~$JJ{PBJ\@H wFm# d6'K*EbAO\Qc;Qh?e1:A9ag7zMo;3ɳ)@H,A[2rؕ>gg=@JR_J)Qq\WkeS/nSƞ>}3AT߸ZɇAR80ÅzflٗZr}y 0= W |CH Nu16aD1|#zl3L^U}RpdkP(Ii"s .McGZHHXIvX(ےb;L ~&28$C 8s^ۦ/`:53/%~uO{.;upp'i_ZXWa 0N6*([\cJUMzly U+YYkTg'*8 (B~G w0(Ӳd:5@,Eu/\䖖9#۠ZX&Qh.? phK nCV 1E^|ٲDbe,^Eݭq*L 0`'Nl:h7UdK u'v%7m_}ֈ&Ɋ>}Dέѫf?0\u W:I_8MhiN\`F֙ѭĚO~A;R3pc/ݮ0;Pq9 ^r]jN}gH #.mN,DɒCB֪W+{ ,Emll97>+pe~zBxlRF?PE(#,L1R>%Y7q{ 9IEM& |$QUn3`#Pol~KQʘBfw>_b6+Cr?X">WKd: ܈)Qrɍ~ B,pZ<2e@feAO-Ӌظ!+/ {v, P}cIH<`ڌ{;32'9I'hn+fsM0xJ˱:Lpxc9ƑDQVDfI+HxLR?/ϴ=&'n 0ᙣA@亅^*tDw?Fl9!~-ac\NSMβ#eH|*`&Lݖ[vLO 2aRzr;.3*ZdJ>8(*iZikI|C൉Q&^6=nE0󺮨Յ]KP}4]ўz6$qM]Z մ 2ƥ]1D58$}nmCD*!FiO=Ȩ¿0ByS\O@v/o S!o7fPvO`&CP=?Н hKfL DH6)r=6j8X2rdc>V}wAVt5\AA/Am1:+yE|B!* j_~ pU4k͙O_{fHcU+9Dr7CMGfuMx9 NNB6|AOj* 朶9qM]>o9΢bN'Leܭ zKZ  ",n3>8sb1H 0z'BdH =UOJ W>JE -;2&-LI0ԯO^<\|}ľ5{+ Fϐk`dU\zArtNcbyBAIIyRlA+4'W'.A\+C;Pf]ʪIAK%R>N] "ȷyk G#PB 5Lq6X㨢6EqI C0QgjUĦx]V87iPK@vx䍿s>9r Nu)&dt[՛N="`1G*;WXX wu tx.7ed6_7Ə$"<;1E'*P(aSƟb8wب5Xh񭿽\@#Qi 'ڊ5lmV%RPJ2 jvnXKc "M.G>B>~X̱TȌA(\0u_r,7ws^y:_(,5!GqĦknEޓNW6Ѯ#伹X2ki~J@^U@GGQ-]c*^j^Bb%1F=ꐳx;2'`ed/ε'|@*NK>F' ^$$Rw||d1/otːNPS;qG `]B;р&_G .$Wxmfa@ =nuKkq7j\NSRE荒H䅸LWi _^+u 2gLe?cj9݃C+C„߶0Y>{k:PG]o^DO^T( ̧HH!ʊ ̀2IFySnXBDuZ|YJK|Rzˊ FKp b;e۶(Wzve^)|]TZL7ijNp)C݋ㄢ \&32pe#oRKf`$&+Â]_|O*| $唚 }\q1ZpmO9ϘPurTL&ȲEWxvu:T2 (ȧ2[@\`&QcI!Bٯ./D+JנH$o+a-ߢ(8i0awv-c4.2JsB=)TAQg?wX6iW,#Y&Ndnl㶫 uhLF]dp6n._f&㬬Av"+X'Gʁ+V`?FadK*KԺ;fw,J{@rGR 2@nTNFKC^8KwE>[RGv7=(9[\/)ꎲ.fM DЌ_4>Mo.]X!v <ɲ醋u\ritv9[ ,^Nj09s>7WcQ6 7c=~g/Eop}跜{iMX|\_4 qS:4bdgUōO$Ao47[GBo*BSA߇ sUaR] ,Z Oߕ4Ee8IT2PBt"KUZs#-%]G]BLn2u="٘H*2Ws$p RD{9;jPA"Ci Qf[Bs6k>{}I6ܸ$YI}s"Lj_V~8Z_ Kָ ¤D2?Oі@jwY]v* zsĠ { ciƌiTQ#ߤ!_H!hNc7n? 0|N,b$؉5]Wս&@#B̾;vh\FBŔ71` g7 ЉF C1b* 9Z^"s\0 ;3k[PO6*ޒa!#7:A&dDdPq2Brn> dZ4нwoLe)xOֺp cIpE<6"OY@GD\+GOHs&/,1}cPQ+h`([D !C:!R\T6s v094C #O W^K'Fv;?)nhC!X;2FhqvVHlęYʃb:VIئ?,[wO]rA`cF[Ic9Na8H1=uc\lq0b7v$FDLҦ,5:MnRȅGg+4$ӳm}$^xݣa$5n}=88Yg~+~|'p)H =t1uF. >h&jU!8\*Z1i0gE $&eo*>wY |gGhf.0&.닓iCPfZn, ykbF7`JaK2Yq,p_\ҩʗrh74;n-c)S7W ,m;)NϹ ?<&RDΖ077'23Jbu_9fl̟ɴeW%?+R޿(`0kmKh"7vMnscmO_|GT{,E~m]T?Z4aTM qo np0t)|Ah;1cϐ7 6Tt7{a]7k}1˥\)߯>Р bKʇIK@~}0P"΄;۸`M>V.66'OBQC]HPu)T#kOÞ([j[ݦ)%'|qbӌ|A]$*/9k/ܕ~[o9wוGW&1;D;YG3TdsXRۚWul]8(K8G!_wRC@谿7M>lg \Q(k7K@>l [ XTc3 a$:L+UMǞG{\kie( т V*þSyjRgЭz#oraz?Nw44M%VQ[ٔAW3P8um4 RqжSq47g6qNeƱMOW#Em!"}nHj@ }R:>(~ٻ7&X萰ʼnf5Z &3gU-ivQ1k"lQs^ToŒ}*bC`AVd"?K c;TFUŏߟB.E|H6_WXo"Z?JW&f%4G:<(s˼߄RP'0YGOL{,4@5lo 4э1- v?bNY]|ֶ5o+&L~)V𑚵aПdZCvu/ԈkAek1L~ kKAe3ԔoK6:ntKl0PACnd^t5+770L,ႧF W yvY BQb݇y2a:/ yݨ$\h!/vI2 ]I`jQ#C? \|;5兰0x9,!̂/ <9tI Aqܼ%Cc(՞C"_& dWg'r 'mZpR#@̨,LqX$0n;NuЂ(կ~>;{4']ΡpYoBfW.7o1Z\ğ0ō@:?ʠ^zj+sStZXN6<@ۜѪyl-;44tݘ@`sǥPk1kX++6BJ~4oB3v8!P^wjn ?eQDWC~TTK^UiH^-0ɰwU rf5<>5')T'6ܯ&c6G8FL7_?P5{4?Yu7詹d7 ܇F>x0ZBN|;d T stHFoqzBGy6Bn5NZou؀`#36stW'-<ߞk>og."-&|n)bWt>*Z--ٯ0Sف8MxKhmjVoZcVt` B5ͭrҤ%y#5nȆ]h gTZ92j5)Xzm 9 `bA$*5R!}TF@ICAnӮڗTatxK}6r!U^aXĨuQ:!¹O&K(DJZTQ]Oa7NLsa p&_8]H)ZK!2ᣔɢ?-129ޢ?yu\%vK bϞQU*(.#ťFL5>*l>D(3f.0[Ɍlps1DjrKMIyTۺXw`I//ACt&vƬpǐQ>fLA?hvj$=R!qqCp&_a";=꒒IcxkVG#o cQ3j[A{OԀ^#m j{g'_ PoP g2UWׄ:E+ O"&t!Ϧ![u@-;[/_-jlh`C>%0 dLC(? $jKk3[]d⛷rDFKp= ߍsnxy\24fq_˅acA+_ ҃?7U}4druVN {cU#A\IinBVvC`q5+pX"~Ceӱ\80%g]?;@ GdZ[5t|11ԅCçje]mtT*gI}Ja,gIs{&0wt191OHAٝ3)ք?g+=S|:vںP u7NꐞC&[URh$pcvDM*Su3Qn4LTl}%BAcbA]酧63ե<*l&i=7`Py1m^ ut;'65 "K\mƯ莠0g1xe7+n¡,(: ɂ`M½,:1jM)qZtm.Ktq|YAmpa9w9|v@;mGL&n(q98r9YW\j-KYI}ۈ~1 LU2ۏAREi ]8WcvH$g=N?ln>GKUR," }X֗l 2ʇuGJ#ħJ3?A4S\0o z?SşZ@P`{s@tttS/M= VYPŨst j=.;b2l"^ Vy<ӵP¨A_h)A^`Nz9HITXjL\ +?, 8ET _(dpGiaѶ\tLs'!o-vl:}.M;y4Al[cف9 Y N<6nݺBCpw{|;FTõN?:||gϙ攦Է98 k~ 8r"hߔ"W TW)qz\BQt5vUqfF&Bc[LW ńKkYk4sCc--myMd7_!!k *e~eɱt N+Aқ%=54AE=*dljQe߭_{2' 2q>;|dZSV>/ DmȽ& &@E%a7Vs˄ɗ.̱^N|3:u¾@-Ek"=0!;~N}':37,,Ҵ`5"~Ȫu\2=|h<./MCF7oaqbaMؾZ科#xez2"XH}HE9Fv],fJ ?"}W K)w*D'/d8K ,ޭ fWqw#ȦI9:"ʚEFdg)Ǝ*lY(odsLï s>mvAWD^bb,5Ek&X0G|JSHv)$L>T\&AOC7w %[)$VȘ4>3q H;^3rǹˠp)>Ow`5EdﻱVs}㴛 }P'%s虥{_F8UsUO*j&3XG{''.cK~÷Jga0)>q)Z 3<9טK89Ek `1.8}yɦB"JܛL "0wBPK9ix&r4>x9:"BD'4k_+LBK/ O/> 6JܲjXXt7'YsD덝)6)5-~xVt˥DS\h˿~BmF'0c/XbdP /de dJ|xd[`?FfKRMu{Ή8?mHB^ؾ7Mߨ Ԃ<┮?6{ +!¯e.Pqʗ5\+$#Ja$:k/"̂⼆lwccatp6XW -&4gdOh6<]fg˖ŅCHQ'G)%Xz7sqtKh,SrlR6#9aE˹[BǞ۪~\٪6G[aQ9N^ϾF%8s=|ܲ_4~݅%HI3yvaiPNH6φ-\g3)RϪӒܮ +/_gKVe_@59QG]m$Z*RT~B <4$ T-IEyu b"f+cAe!$5w:AH ST+5,u=gfM&|N[.Sz7ֽW:rؿL;\z}xc(+#[蓶@ MO$n۩Pf) ]zxQZ7{ґ{BQef¿%, bk*osI |Q_6֌3 sGe9 {f?pySB?LAړ< `7 4j Suuf'<Ż(j>0]VjA;LJ-։?<dd%J78Fff474e莲?:] 2I6"Zs-XvUun2dr 4Zm JOkTHyϳMihxcvbHaZu/ =oj4ZkaK@ܞ~ 73vTW`ͮ+gcg}^:EXD?-q(>f28¼$F/@eVPgF^ժ1Ju|x2|#Ez|F;4]?a6$*}ӐVEt0lB1K5FiD`o(gu}V.z(푾o!hn]'zksHWJ(niޖZߎK:F$C&PrrAOQ18.ȳQlI-d4%Xa;{Zx}!ѸkDU`P0(Q={݌r%gitu' Zv˿e;V~p kT[#j "U^?J4 SEܹ*WuFyUWuPluL6OX#cQmB:2j 2;<)$ mB`4>s:wã{l4k5M + JFh?U` 6cYˆ*2X_SKka}o( sE}jWL׽s$,3QR shC1¶l]\Y#/Y PX mNu~ h@[*ТV>FUA I;\P-%Ty2Vj Ywg,\q=S FG!2 8ćYF#jXaEKTPQu2r#OMk>BR ! )R *;TE|r۠8 MbFNa];c 񁐯yBdO2|*w =@Hl!HHJW.!*3, {TVѹBf]' &O9Jz$p<+s煸F ?+A}xSx#Tw9 3.( bJrb -`ah:淚)b%1qR/6}{J[\gu~@\ab)ǟpaqI%8䃝uNBSsF= 프gJ9wD˔Ux:p\jX@k}snLdT(C؍sF7s K*(hi~2wAt몞uPj%k ( (빅 ∶ d%RJʆ(*>Db:vQ`S"n}~NU=ϢqOOeZ|O|e)nyXg6Ug}XQXX F4IyE>SюNDyo (-ңH"ZBMi Z6CA!US_5acr20Y AٴftE }k{(_Q׫EU7|9nZFv#4J.ظJ -=56nC5/_C)\.V $&BnEʿvwI $+7b$SêG&l';3wu*z\BggL b{` ϭuM QOVR]PC`Uwȓ?6\HqpsgeRy}83gUմw`!`"Iyݷ WV.7bXL+̐C?ٚI[$#ΩEcR\5G ˪eOE.:MJlKnH!3=2w埅)A ܬJ+MusYA:hoM;53JMba֒UE3-gU:=3w+P|r"jA/]sc|ћngGrܪ,]0_Њ]T&c zt+=rԯ~Tg!^FV;r 4 *Z7PbDK$'/5͂<`qxIftV5"wp6ZtwEOʥ/#KL<=* 6\N'a2eX;,xL(l^?99@S]\~hخSDZID-m_bـ}s/ŌTD/g~k&k8tzTfDIZ@X]! IJT&6 Fu㺀1NTL<)#v@j(=ä/EY]h*1LhAS(`x]qpljR\:` <zfk-EцlKGq)/ܙYeTJNV=X2?2x&u5*,[z\3yC֔u0$Ix$}Dk{}bԣ^`@lzRf~тy~ 5EL#<\+|ZSo F) /T.HGPZ Gf_@JFnv 6s&=m%!> ݃ ^@?B=pӨ|'k)=`VˇOų IYF1Z\EƧon1uUu;w RJS#%>ȤxڛӂCFȼy[2K}4s1>vb:) ^(6͌ gJmhj)O{QEV68(aَMT%/|N*;=QFdu,{)VLp)e9xlvs8E2/4jb6QL=g&H-NhpԕL*̬x3p/ɕ<7n[m:uu@Q5slϮ-T|]D0{PhӃ?o 9'2A`F/l^hvkfrcy@$|ة`#$= }"%MKBVQKcrAJ4wvkwG"|&9}Y ,taD+ x" GId u)htu$B'R M:sѷ0Lqhz/&fLT D _S5w6; }!u ҀI"G$ɩ n!Mv;'8e ǀM.O >fĞ|ZSdwn?VjT]ܰАG N n0njn6DjrRLв49JtR  i[ryRoy0m[&nl| 4hK%A*fB|JyR`12Q1r]sT0F/]$^#X3Orͼ4HIv"ieht3o5%Y&VWT\SY,74FGwva'0\@w7:u`{Lwx)uР&[UhA,"'Ϛɋ>j,є/qߡ xcڏL*X@01M˕glGz \U99!J=xs/Qo6&wQaK+H%J H_ 05ʪ×RFOTA- j0JP!fRLfCAj  |IwĠNa,b׀A }{ O  HCp"Z}4*x=-6я| oGªTzCԛ}dH'LDbޕ] >w;s(=F~"w4@ ?}ʥ[ϑZ~v\M7+O)T n~sɣl~Ǔ/~aűk~+`,z*ѺTV :>esh܄0!i؎-Fē$EFPyupNLYciOW+b0bÃBRV\1T c8.8[5Hce,prh pS7| XbxlyYPm"c+:zR TT9DK)r`^Ʋ:#۩c~~?&u|FCY2Dܤ(PE G֩>_2X*J-i_sLn]" bc*(66f~n|cz# $9Ow=8Yt+Zjh)lX~">ojl:|\\%ၣ[ I?5?QM6&(nRM%dy 66NOwfh9UhfD2&,:,m53 8Y#›-hV_!%֓l3]#@.j?)T'WF\͂$8;Seni3vjSqdչ0 xaݥzAjJ08>4%VΞT]]s< K⦹\oc=blF3<c\iivb3c#o<;Y7.eܼˇ5Uvq(4 Y|l-?c#˦QWIx/]2#DI-eYxYC\!Misv?&wB_<\Lp淺omtJiŨgA}UVhy)v)ß)X|v3&C'W!l_s}%}D9q&`iZOIQұmRs8ɴ5H!:?}舲85&Zj5' &!G{!="\9x û42ǗNu9; lwWUuj."zhܰl7N[CN484>k's:8|}J *}B9z 77(J1ԐC =Y3dn`d9pՁnPA%0ߟt+{A_ ߄V"׫" 6`c,eI[ik~ vĵnuS A0L _ýSf|z~JX`9Sq9.:e03=ԓ(\PI)uVqC섚վ"zGn`JQ"e7ߗ;,ViqcE)tLOG8h 123n҅=|ׯ>?%>P 5g[gzwr$2C;3~$}S[Mڻlx FS-S_xd}qUP_nQ|  ˰OݤI+DZn7}r WȊ/gY2jvҞ!y53wI18 _?4`̗\;&d0,L3] r:^@h9.~iKJGg: }#/lgY#6-4V+D(J{7ͳ$kRT@Zw_?%qș2_^P/idNxޖ@Ή:PRۡ2ۛ[{p5K7&o≍yοxpU`Hi}@hzd[>Ŧ?ORvS߲lњ6C lm ]E.ϊV TP'$M}S ϑfֈ閑J/ #M,ɰ5z'|op>,FĪWhb=S@絵Q+cY!|㾛|SI4xbOIS]>9. s6*PG]ljϕ<]h}e YΗ;cRɂL qy.=fgMGPHޅ:ܛ)04;J [w">rue˻Ts0L.t `QDKĄsgFՀt^ G^qK&'?xĆgK{Xh%!} Ef8:3EG}$(Iz#?[XP?_@a %UOPۨe{NgP-D"*BH%lVsmypS]fN Z"I{} S6,S<*7HN7WˊQ#͆l|p|8'->nV S+w@@V 9ގnt%1y$]Oj*N\M_dgjQe:zOjwMil;\e!@9ڜRt iV"\ ԿFh XPJ̡&_6 7>q`_M}X3bLlAMJK CBޅz*&͑YFt-LY9 kcG7}WEۍ f?quhL]PvW8u4f_hy2ܮ?.`>MvaQFI3 nyɼQP2*lȜ5mEra[ l`nn%TQsfY|zaj5 ;?@( {bp ն0% "o]ta7:ֺ#qz %HSZ<4hĈ{e:xOOE8eTsX4ݳXUrEʬ:1 B>0gW`<? DgAf2[⎼+1و N?OKb#"{:1|и=Lۂd.P.rLyc[wpl |s|!]>n66:7Դw5*nV|1ɑR-M%Swɘ{µ1=y_ىc`'ʼn,-EqhV@&#ow;)el'VNNVCZ>B~zq3(a0ޠrϜj&WC’s=nX|iE ūfN2 }樖XRGFcY[V;JCwd6zsC P8Im N&7¡XԐ J t MŽPizjVR]1-oIǚ2=)?!ߕIw=s> =綬%/T^/PX8L@Z;l\;ɩwfKt|MyҸ8R `qiI0w( $vb9yЎ<#S;2;C@wP ԟ NsR7b>&K7"Xq:QKV;]5 q1 uKPO.萂[8Y̌BlQh@Ǡj"i l\%W AEۚmEk 䮏CMLj73up>~i%ܵB-i|'Q#$81GF{zO-%(_Y$$!gUfz@6k * f[խCZ?`4 M먮I6bruL gȫr7snNCq=t)r R˦ɡؙ.;|297*ə1@,Ps$J 6Mporʩ^zpAt`|񽼮1XQNpcE FQT~jY<37V _l;jx\ P/ƫ7 THu0Δ)]|lNQ n3T=@ :t+,ɤpg/jL 9;b$Dz4TsW]f). #XVB-|?nc l_8l|ulQu؜댷-AJ ˾>ܷ_ х(Z(<\r@:C4;=ZUg9{RuC8a@01Ha9 өO&]9N;S\N]pGZ*0j!=wT rnxu9Sa&Y?J=&K͆5Jd  #?PZ+u ǿS&73vxfTV d{+r2!n_>`&ڪn2W;J#Y>Q9l|*>%42.'0閙3#~HE?.\L"islW¿Q4wsE&Ʀt쳠%]Mʰӳu@+F`EE# 1Eb `MLie\c2K|ހPSBE1ջ+_4sJQ~Q &IEc%B]XeXS ~vb'́6U_`0UwlǰBV tn% @ٹ̴?>pc b (ztX2xNc]c@CqloOVqN&;dACw7F5 +dVj&FWlRGQ:Sfޚ-nIm+n;!JQrrc˼¼wU#7&"+L\^֔=i]4!L^[f[&ǗSZ%i^ 眴0>(wFR: )^7A= t${Ȑ|0m=ܱaNާb"kxI;Yj#GC8+dz;TrAͻ\eR,Xqq9K fsՑfkV[jUszT ~}Tm~17X@22sjBFAH.B@(K GNDP@4)v7il|=Jnab}93d\Lˡ F>?jCͨt)ߑ`os rj%[9su H"("E'+~ ew8D-!SԒϪ*4RtdYYwr}pmN-a<sMT& CY (Bδ|yD4OOaIu̚SY)KQ%/o 3~8,9S}3"`w²f*dOTo:~e,)]( A]Pm}4 '[} sEw(7dL׎]lt,'Gʏ1%KYO:C-$T圈%&։1:JGZx&^rum*[],VU\=?%@y>>y˜lIvc IHK6@A*Pn KO`t۫ѵNHG/яYq:,ѿU-hW;"ՉTw'p̾^tR+u9ةL&\S>~ڿ$M =2JZE}nYxrD ͱ 5Ës0YȞEک D*I(Hvϒ\kNa_rXd-!m]sO@

\xYQ"IOĈ(DeR?} sOHE;j1){irhX.$B\߼۹X{ɠ7!20 ƊƎŮdjEa/=aE).?(}Ӑ4OdevN^c\BB7ËPR -1 $Om*upjinf?Do|n7@nZ,XF-dq4HnLV%ffm_B5h{1iV$d_LN,@ȕeL͍W=χ%Xi|M؟MDe8C.3C[>v?]MlҐ2BS77aܡv:WZ=b# iq_g{P$r,Zt kb'oYv^TwE5ECtg| l }3,.|-d2>VH ƪ,V21$$:d|x8-gCdH&&*%V}zi2J0L `(MZa8+?J޹Ko'@'$'JDTJfJ:FT9\b+3X9q2X&O?F-,VK"8eI )*Vuy?8:d+;1"q :*Ls }*NȲVE| 7#%IKM_P&ąjV6ڱ7ɉe^e׆S׹fZ*.Vxu Q[IE &.;tqXh}Z-T[X"Jen/plF]Xa*(#)ues{>0v:1/\\Чr;Rot{'W?ۖd% w49йS-T3нJI—5mVϙE-KPU\TG7{i zӣ 5?[УrS7cw;y}4fn˶?L0ÞV.ZMRuz*kzŬ|JER:2|4s72A& TZol*g:q/*q{ܾ W~26ֱ2!K3q OZA{{ZjR$@n8@M62^jX*%^kg㡇'G2bVQj"u`ӝx"xV3+W0\VT`.%*ԑ͟}QvR]ᐂ ~ by9 (sBX5+ {UVӘ'[ΑBJ&J hw}Pv&jHjy7T/X9~bo}|7p%*_ƹ 6cX@/Y?NRbGdT)6z7xĖ|!9 Ed"'&eu=ctr~5 h'tMrhj5GI<,\nf2 e{ g P 3`f@@W3d9|=D9;|.8ai9{}wVv7އkbuJKK}"16fuPN Tǒ rxVtΗ4*f FO;d>r^̅D`*0zX5q"MU%Nl|NfARW#F&".}ʍ]eN]SgA0*ڦ^zopk%^Q7(DAXIk:^zdR doC҉B-q9zg7&XApևhNKvjLH.CNZU esvm)%.p*7yV*>u2Ws`][c٣qcĻTl,QUM*"*Y3sz_QEMn][]b|e݁BXƇFF˱VA;].-퐓}Պ SSA*`qnpɸ>pL36 $ˊ1X?np:&`dh#)]z)+vu {gK/\ 8I.}MVJ_KA߼.dj y,7YȂ}~z1zƓ?590LKB#`a&L+ϚVn#/D[O$iGsyƌ%O,5*229-6Nءޒt{,<=yEX@gi]j"XPJ]&'Lb7uG jilS.3T((.DڷE.= $HQY)0%,Bx;>Zy1=+Fy:]HznW֨ Mڌ_Vم]G 4\s{ywc!#C|+xrY BKO|?VS*1>,Fۖww5Mo-0vݱF>BIݩuQ[[\ja`F^P:AaW8zڥd:[5C_a2FX=OT;͗H8uΎY$guЋk1気C tCҡkypqe`XG !֭Ż!sҧUleNX*ro|ٳp^EeE~f;}ϻ>7ʆ߆`{ &vU-KS# ?_Ob-Wm;Gi g ءȚwr5An\=KyH}Trftbj\eY܎!LS鶝%D2Ui!CvB.Cor /5͚袘z<I|+dt&ׁ0h,?*Ԣ{IЍǃ%Q1[R$+ ];tAS(DA7 \Xubr`-[^%, -]?}?JBcj:u|rlcgQ_AgYWszn"sT!_RFf[7#"(VVD uuۦTh8ɰX5I-;|}v xQCX[6 MiW@:1[m{4U0n$ +hL!<1QXgDY*yakl@"?J*b5BYzX j\m5 ʸH䚾l=i &]b˳`Nd4_WYIf.ȈݢE"RJO;p;W/VyhGoZG? јRA`ZvS4 g< h#lԡ ;gG>')mͣ_;V}u($ uړUϞeL>u`rq,QkC 3 HkBI}k:NwMy,XDVS?"i $U(h NMf-ׇS8]T Ȯ`W8]( p0=EnB+? AS(2eCU=g`>K4}Q ĕIpYv pE5rQz?t~f;Z&% AR;/0T?S+'qr( [[_{'Zr+~~W*(jbg*pT8|!-q't[2ˇ=`D nޤtDS6Lo.7eY4da7"C?3)X{PbR BbĹ~ՠAi\MsZJFcce?)cOvSDy[{9nSH=9c'ԢN2cCǘe>5B(<\ 2AT'I||8=oP+v%IVsZ4` w2! uΖRɤ(>|G .iXYNqi`c)Foڜ&(sD^ :Rg}*0,lݘ5V~pe_TIjSBs}N%Yp.)'~GֳIEǫe<< 2]$d T|>4w^^bl!͈x;X`=,Ƌ;t[_al"EzT<\v5)ɧ .ڭ_Ց>*]>Vƶ%04fg] L|AE*Wx˛/? dm+(sI)ڐdW|ѯv1 oIdfMQǁs0X ozP&\Lj=Fೡ/⍃};?fZb%s0-|!ϥ UPqo~Oe 5Εwߤn9,3ޖŒk j+!գ+zI-&١[o C#ݮPd5R *92籥ރx<#'ۺE& 85h֬?y=]B33hHgUn UQż h7 !ds5D1=w\>X bbiwƄaivj@|xPs=&D ac8w/pDitD79.](4UmgҜ:~z;&D(5],j.DU͑n*d%dAF~OWc(ڝ kǜ2y;0WqZDA8]8 vմ%ZslR+gJ 4S df4 n7Y%GH|>MxLb6(jD׏qUq!+GV_4V_؂jAw<ynܕÆб\fI3bנ捆}zOT K 6Lr긓0ΓxsOME1]dDފ]N뫊b_}پG/Z4Z?#Δ鰇ejUhɿ5X >|%$v,P[KdLaW!NM"Fb~$$SZX0'G'֕[A}GDC4YwVBAD _F&.N{XY JBdkߢ.}NqUcjzbot~1h4I2&Qkmwu&1'3%[4F~ǣY& ?Sp$xGg>(Lو:gKW}UJHu=|s;Jw)(7<};8lgIhRV36!-$EABjF40%N{4VrR>]2U0!~տ/5=rz#7jd- V:;~ DREtK 5ig>wi蘇oRB7m,&Em(ؚ%9%oҙHCs j飷>Dr Jj2,А; i >y2s^\_Fo t1U8(=":6{Y7hkI ŋ tLS !!'™j>msgH^Qޑuo۵Dp(iuCw1ӧ~b:\:(%[*5FIԠbɞ)DijY6b(Jk"e\7>|*a u[fADEeEm%9wOdwgJ9*(BߖەnE>SC(!g]/+CO>vT[0);54Ra\k9|;MB ޱPl0J뽡)ǯdOn~<5K**=Mj]ʄkBEБK~Qyj@(uLƾ~,ԾZ^V &X Q?\ SԦl@]k#YQoPb}8q(D|&ώcr hqX!q8IPIs,D)Pb[?tEk'wy VdQKUSi0!U pfwÏ9iCU]?{;lƊҵx-ņOoPRIn#RH$Fw};>)9YB%4AŨ&FZB7`J,TDaCT+$1Wzc$W %*ɻpgKuw4:LC#mjAxhëCWsⓑ)#hVmaAo7ZY]d_9˖ }hm,v %c+U]ݾ>mꌸ\)o }bw5NB[?XqM/mNUI9%StR4Q}cs _@cW4 XiɧaS۟ojb1@W}-Q_6<T$Ƿ==^ :m<="g6@uQ_ W^0nA A2/. F9:,g~u՗b2+l_fccY^!a X4F?I%\;hz!/`*M:1a-P@&k5_C:}dOER98KًQwP|=RyHsh8Dn%H#RZP(@:*^UAܧF&bWzr~5J')ݞt UׅfR2QXQ7 䤋d8 .;CMǝ`688'N L|`CroPQωV2D͐ޔCﳗbt"y.LB`-C{9hW,kz iA=/C3  oh`8U_dP <@{z)X&j6QSl<(ʀŠ> 6?icbsߺ͂ yk3m) 2 YoGI`'M +-fk4VɝiUaveKz6` ʖ֯ VE!.k߅)w)ey,$TH/]]tqt;S-TMϣ|JV.M~ Æ֎7cdX3C:F=]U)By \{\MԂ!mz H|`V U`&1㝜sYR'NY3J5" ܤq1NFYZPP!0ڍ;bO]T,FC8EC:pw:;IV7\|R&?M[:& -ί(\¿|iw[d*:~?gԇP*ƴ3f_7 WVnɯ1ID~Ԇtqo X!E׺4>.aFK{= EGQG|{`q@(S7EVsh0Q4o~"5XA.>ZloWPtN"_9_p'oyeSWC 4q8xvڶx׋Ͷ[ 7 v~܆Y; MDžwdX !%w_#o7n8#}+f{.3[Q\1ӋTrNh%g@3yߗơɡ8c]L{ĚYSiʖ| ) J lIi0KeClasOѷ5벧fñ:{s0\vˆ5ḹqQwPw@y&"x iCk22LFi:z4EY`ϓ>z9W2PåMdGM\sc-f~Tn{6^.E0ii?A֑ 5:N|_۾s/!CÀ'`8ޫ aF# K'sq1ҘU@zfHyεŮo+wyQ/zp= z-1?FҌbMjĵfd6mRczLŒH!q1T0Z{?]ȬM{ś?auI@}³cM]/ !G*=J]$k+3ONǼ$oPxGŦ|N3te`-aD qla '?V̼ܘ%m3ARb[@|"èOڵsܱamp=ޙVV}.MkǸ:'sl!c-J@3 u>84; ,"Kaw ;1`JfF( ,_n"QBg` }pj`2J3 '@~X u_?a6*KyThKl00kPh3}"OC/r'[׉ўxmFFJLm1`ʍmU. 7sAl>C ~@]H WVq>T 2/'{@8/>s ڣ]z˒%s`9|;X)-Sf /Q<`Q;3\e"U!/؄NkN00twd"cff;qM/R`+ɡqbx"]]]/tubrrS'`"u +['gmj'@ǯ*.eS\c= '`ȉ!6_ $_R*w,IKôfᰆҍV܅Z{5ܴ3UfhX,aR5f/ D ޠ_v8i$]R]&.!_/Q:CpJPVlCg5>Zj̆8ZE$\ 0HpN ,neEEx *,.>t<:ЀBА6_dؽmLkCveةñz:va| lsLN1nP@C]g}$Fs`b ~0 Q&1+K::NFF(oV2ǂ'p2ޘj,QAYCGJQ^ [g%/"w`_)ҥ~3T/42Ş 1׼OG&<11 9k؊safڈHs(w_drtf?^: kAKpk~#0B(-m y#`H8Bta%s+Ɍz P?sAe.Pc3M3@ZQJu9gi1YшU+sF,;YӟSxﳺmgRZAVH]4#@$*F!4iaάqμh!b9Fcp̿iR|*̉VR+qcFwv'5;ݷӎ/ )+LndmI5 E i`}$ՄjU%Y䶸 Q+g"MGXSjϏ)ɇ-\l\1Eo"ý^ާXG J$3͝0H*CWj5S~j+ Gi 9Wu_|,eՑf&k._y$͵$6|{BFXM'3q^>6*|KMC ,6#]c +}E'F*+MnT*JZ<҅bd􈏙$vtt8@[/l/Q5ŋNc>H5Xy*Is3 |d ,Zl^}~ fv,rmsB$VJیyDVzM*^8P>>QC5JtJ5PmZZ<aJbvZU|),vJoRcB&TaEM9~ m&TF (ص}—(NwKFC4NWr{oTj _Y٦ 4[Bꊟth0">ܮv{NGz3.muUb))ܥԐWu!0B[}|uS R`XXQI_:& *GR+9IߠikmLY. CFLe*Ma~F F^5>8t 5ֿ>ƻwuSrܗa,[=hǀ;F&<ڸN~:!= kj&% $=2I ۯ+?[a-W}quO- Mkws#eBYe(8]aٱ!rSrUa+uv7rʺ?qSIߤCJdpN2YKLD"9gYW֢y"ۊ<ˬcw! V؄_oFV9W<5&Z on 7ywA9읦f"2\ Sݓ60GXK͙4t@lc}lve]gLx4`OA:sb35"=:&EZ{qK1u8\oey@VE |Nr`jQ7a!D\'[ ;Vf/t3B,k]o)4MŪ/CΤ 6:JOixQFʺ sB.S/Pk4Xyf/gE}32*b ;EL.||:"Q5zŜȱwQPxA&js+*yۭ]s;ok{Mq%-@FR-4@^Hefg+ɑ QiZnj ]Qm[gI*UGg Q'#b/n8gݶYB 鮼.EhDK#3c6/C?? dG+5R;N;9"?8mVњ Pk `(QO\Xz T5vFG_~9zN!?0ማIeѴp P2y)$@i`_ʀsB/>=9z8d̼>W%K/3 Z@zh rT3&lDQW+zChD,jӴ[xI$KT,V?:{aVa{Cbq?Tw>6\L8r?)AfHkG6+,2s6r޶.@B_wٹ!0daYFW3 `rZWtiK팎I{jGE??.Ѽf+7En!E|1I"` !)v=o2xX#unD&s^=$ɥjyVHte5lz_nXt8n,Ikg6tObNo;T M]Ќ5191]MG򶾐- n Y}4*nfcm]gA.d_C>!"Lr: ;zx`%uGF?xH`ߎxh "2 qj 6k\1<"8*]&M'bŰZq~8W-8/k>mNxnvΚHV̙#%Yı^ANdԱ$1GW1eξR9ESѾ:aVz%μ3V>|et3^cm;GV$іd79?Bڗ# NZ`˜隶9i^'قbx /(%V:6 &aH2Il2>ؖ̔E%b)542x|s|ڨK/W~ cz+ ֏,79ŲBfBi撡~o0!0Z <;~v/{ܾuu&!VGl0~ lb&`=@uЀ 3͙OɢqW&qMqnM qWBn!_4e_DM ՌAuIθY5^5q r8_|Ӡ,%CW}ҁ*/`wRtz *`c&~|zVYȶ-HC =\<.-s{:_lkgyj `FF$i_13ޚJ< 88<ۼrD6jWǫl@4T+[)UZ3dp XԶ[g(@:[]H9I(on]a8 @gP9b4 %# -EJ{l]KKGEIH7-:nbJ_'O펧=TPMؿ?I7}>dyxʂŒX3& ++Eq9Fx(GK5x#>vyD,i] 1 w|{]Bd^*Thn|j\H:`ˌ n%_7gaˁk6kAHH2L0r .SkB~z(']7QM8; ԕ4A8J+ZD^4u\ coezF4gs/0ABS3╄_cO͝ҋXF5i8ԥƑv8 ~~F*9$sq{e#3+7֠&.<ǖ=ץ<@~>/:zdwӀ*g/ %2D?=9RW3>DgˌD9+ Y說}7ttI3:U) ;f'E!bkoWM142qSȀojve3ax+,< trH'U4=QgAĝ%:㥻зc@|]k}_ 4c+ZaW㨼C k@h6?CЭxl=+dRp7S"D,SH(B44ԭ$ -ȭ)INPUJ}gwĖ1]ڮYvpvc(EDL s#5W)L..S)@UK4 G^h{:8,asZ NpFp޶uJg \<)BX"RݚpCCIz\xdal eGpį˶^=k i ̰X9i.F*[ybʳ[,L:,ɬXA<qea6FrO ehxvN?|[t!8kZ1t< =qNdqw]#^Lp/ j8&RލijM& :O/_ۭ*Wz~#,7D /biWvK\ƴl(}WgXl\p T㷨T4l~-Vsoп8RMai6E=7㛰7}T?ljWϣ1T|^*-ɄiӎnQnٟT"^4J1k $MN .";8!Ɠ~rz*Rm9nn %N  :dq6 }PMS| ],ʧ4Χ 0lar⽑s2T ubv˗A*9 ֛3]a:p9'RſI2 }zhEn&6&,Siګ> ky0BlU.4hKVh٧d9W|L$"}/Z[):8lYx. BJR:AFyaEƴ,vXZ?1REpr9UP=b͆YV\gٟz./ kZ:lb"[a'ygGУN NvvtO\֋@(t'p{$0 31|D,k\ (/ᗑabbxEK.#' $5!qf;5?#ap%&*ȑ1a5%oSʭgp}Z^}7ϱ?|Bq\'\^7SR&r|-H}2;מ^֕,\NY0a}Xeew +^#i{J"U~3 .x'!gPD˽^{^'vXLg=.ndfyQ%Cu,aclaRKþOk!z;F4O]e*/wK/ (+2Lr?5yH;% swa(.=]:'z|"&2V&Co't&:EnUO{TUT2=֌t ^ # `XkY lnF#Evmm{&~WZ,8֫Wjs3UnBs4maR?=(4 s?z4ŹBcI`Ϋ/|Ϭ,h^j 3Z&nĶB$]f~ͧ'KAa O㑆q/De_D7 z0XeW/Lk#6+1 SMhbgzȂn &x9M_mae~"'moxyӐFBcE^4\lL5֑.AX6h ʣDDG47^\0IDv@,!TH9W!CK *fH>Yvo@K򮝧5?2!HXRLX(6EGEjPʼh_ܹ63"FٮH5Ϛp̅Eqܦ7dvpar6ȫl5+cc ,qu7IBMz%?D9‹2GiR.&;C|$RY7E)}KQ&l;>?71^" 5V;QtXbv]fzrJ+obqEy|5sTX}GH-Ňg.s_wB*Ot3NR;.YQҙ=F5OJP YA#ˢwR3Kj0鞞\tI}w[42"^)V}";ٔ5sQ. ՛DT.}*W0YhPRDh4-o$RV/ۇ-z A