libsamba-util0-32bit-4.9.5+git.149.9593f64a5c3-lp151.1.3 >  A \/=„=>7 =O#Q(moO^}<  &wD)i@?y :Nu<܅`~H IXʮ zX5B:Lxq5($HZd,ڷ\*eHLFMSIIJ۰ema,Ǝɤ0W8:Qg}̈́FͽWWE'ŇQƕqoS$bb8f412ba04c9069ca29b182bd9981949e479a37f6e7951e717f5ebd6ef3cd223cfe5c3ae29935f277459955e35ed01bc3eac9a0(\/=„jVȾVG#w — ϝ;JE ˝QSeLr& χ v^3ұW ]<EtAfÑW=#hU]mۿ^M"GA[o!<Ӷ <٥<ȁ&"`J1/d3 !˅ ׌KPB J.Aρ5 =`cll:Ӑ:J0m\N:ihšj'uGTC>p>Y?Yxd1 ; Z +18HP T X `   '''(8 9 :>UGVHVIVXVYV,\Vx]V^VbVcWrdWeWfWlWuWvWwXxXyX$Y(Y,Y2YtClibsamba-util0-32bit4.9.5+git.149.9593f64a5c3lp151.1.3Samba utility function libraryThis subpackage contains generic data structures and functions used within Samba.\anpower David Mulder David Mulder David Disseldorp Samuel Cabrero David Mulder ddiss@suse.comnopower@suse.comJan Engelhardt David Mulder Samuel Cabrero Samuel Cabrero Samuel Cabrero dmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comSamuel Cabrero dmulder@suse.comSamuel Cabrero dmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./bin/sh4.9.5+git.149.9593f64a5c3-lp151.1.34.9.5+git.149.9593f64a5c3-lp151.1.3libsamba-util.so.0libsamba-util.so.0.0.1/usr/lib/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.1/standard/f8490f6d0334c3a4fa732b71fd01beb3-sambacpioxz5x86_64-suse-linuxELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=065b7c8aea70abe4237fba3a5e28e7d7c3393053, stripped$PPRRRRR RRR RRRR RRRR RRRRR"RR R!RR RRRRRRRRutf-86036ee8c92f80b045a2789c9593101459470123b9b079e690a283324f0ed9925? 7zXZ !t/>] cr$x#ǿ)zɽ5OPC@"Qu'ݭ',/f~;k~ɳ 2yA8a;Bj%OE0W{ol0P[QMLPvz,6Ljw څN]cֺ879 Mq־:IY DTi,4']6$`-m'20nvF৒~Z+\7Wll0GoRLJp\'۝38J-W}iu(c8 ]wm^J %PTݖZz"{1U$Z G _T,+tm;鵰obEnjc0"woDCOP Bfd łىY?{tQ.~"M8D(nF9|Zt#/=2T wJ&)2?;D)R}͜w m9׮*$ کƩx}|;ֺɴ6Dt򚓽P!2M bEo%õj"%ymh`N*ʜ:QX"@xV5{3_,_4H )UGd!*  CܛI㛀Q7川byY<+&Ȏ{d_ѶЮK9߮ ثx|2GH 9dƪ7Mjskֽx71L{eT)thSDDcO nGXו_t*ƾqﵰMY鿻GXI 36JoXO~Qv~ò֣ 󺺱=LMf3A[|ڭYNXG{ `G&|\$uZtɶ+)S:ߨ`UGՌiM8ega<;+CGg6ޒxqkKd`P )]w[etv ar<5F.Y^aul;˼?֑n!hb)q0WߠfwQ dTjs&PXDe+bCADWhWУ Jit='`9HH.ܴE@ :0AYFk G͵bFv{ڲU_D=d\]2m БH,u5Y)w56+q@Drt|ngZ{ 3^E.z#S$9@0Xf&U5vv]2I8Jvc"h?S- +e)V<`UXmSx%N Uqsf5Zs(l'jrdY'U~$~E|*ʙ՘#L+^2`Ky: 7XJ(`w b8I-sڪ5ڠ [^ TSP`A_ ED h ˨yR54ld3۫9Aᗕ}_;Eke $!䄖#^<^A/jޏ>(z;PP-Yko]rs4+~ŪaoJh ~-#p~)~( A"ʽ99f:(Z!zhu( &L4~G uRu RTunv>ϼ3ʵ˃VtT3bQ&ȍy)s=A|%e]x!sk{) bb1KǠftWXC 4 It&Eh(oSڥS}fZ~j{ I3:췬3Ӂ>XC-*MKV(R1>Gkh )E!~c :ᏹNlbacNnUq8~<}0KPIp]a[. PA6~D`m7=NaΖ.u{4ap6UW*՘~Ej &<_Ag( r>O^hU.b;-_#Ⅳ _Ej⻈07t2gpU*-L5WkkITaun$t.3?@<1x-mC-k00U|u?C<^oQS֏ԘD ."|_̴؛hbR deSX|8 LMl 8 H(比*}E NY豻8 58Gf=w=v=u^VVa L8[UeDyb"'Yܐ'kn Ua v.Ӿsņ_:sO8^- L^/IxpjװEP0g1@d@(@*<ၮNj#~Ƀ c{x@D:Ҡ/\,ԍ|]^>:щCk2*4%PҞ5PB_2nnX©ѓnm6 FP u!$&e+ 6agUi9K~:ߚ$ `(rm@(~hI?K5KBq =IC\,ka~^*2W_*upܗۓQPʧ,Vd3A3(e ҷx$ w[$fs&d"K=\d>B4)xd.X{Q1ea=*!78?TzDzB⥓8"jXB_3|kF:e!boriVƖ4[0XLAAWa- KłTn=(fϤ0I٬g&7OɢmvZf68]A\z44YXG0g@& XDfS;̴4Z /2bv"|åcɉbVs{^n"o:{C:8ݨO!קʦ9\y` t qu@щ&L_}N2$ ÄFEt^L`6߿r<)SĪ d|Qf0-8vOf8Fcv/OHb w=rg1}ᑤHxJJ2S5 _67^/|>~,iX,u<%xmݝ*-Nm1'X ^ksyIݠ; t+ڢRb=3ލ,0#<L@,L47Cmтb)|îDdЮh&aS}ʞ"(r@&̔1MA#k;]ƈe1 '}6/ˁezٷ+U)=YgiyV]WDWUs9g #:hg hUX6hD 0m槿fy4>kmZ3Uw3lFl[r;N߽8MwFj5{~ ֹϕ'I6t1V$LAMChn ֧a|U6|rR5wu ޻TS9ƽj 69|&5u/9QŊa2=)a 1ƁOT.V$kZ]LX(tPUg"WNC㻏GP6>&Kgc>Bl 5:.|rW( \e z_ <7+)Mӥggmied9ysVrZg$ 1-ACXUٌ;S;gƼc˹>+.OfS}*Cc|`rLHiT pE b+zţy#;:'4ҁ}T&w{d /;/~za ρ@^ s@(NOZԙuŸH+#0F}f׉(fԣ`M+{XX,WmlDB+卢փ!F$i`fQcAnqRxm2'w 'fZ D l~:~"~%}@i"XcoZOݽ+ڨCL~xQ#\Zʬ=Ox/4w82)^fV j9 $pDE.d+|p.$^_6炥 h8IG[d80誦l#7EߙfK_RJ׳XIViƊjQqCf :%RGsI94}XY]jc0pSCGT%U! 搴'cM伭I b,e/T!#2JLV> #w59R֋qwkEpx*#pִ%]* b\ANືϬ<;&)o="֐Ka!%jgZb(,YqxB-{_≃ZF5H`Μj<ٝC!8(DBdDOtOsОl!߃J= FWHh[-3@$edpNв֑ihņ!; J2$uCm4}΋z/5% ɑ\dYT; Vrn-{6&VYx$JRo%U=iPW׽q.c)uNCEd)7 B(,=u1F;貫35K> Nd7 of6U>#xJPZ(A_l>wJ'4j!2OIezZn3=\]iPKՐ=Ǘi6֓I48 ̺"8_SZ}M #ヷ$gZ0ejdCFN=D+dKݵ VPfXCzJexBxݏn&끚'SF;E??o{l0=H?GAxׯkЄ,aI"j`G^`r0փfL=D\?I;m(Kem˄cӈvŕjs睃YJݵU}OonN"oS?KtqJ7O @+*%J[;@! [TI:XyhF&rJ [8`M>I?Kd()K롋Bt{O5948('=͎`H//!wP%z]W)h418e:r5>qC@aagu~ 6/>Nx7 -3Jm%L^6bl L _ԦgR-09.cJ kγFɭ'& έ%DmYjck&63_4l,K8+ h:B^HͥXQQ vkNH٠ ~ "AՙOypcTz`0MD^ΑfA4cPr8fsr8y0ZJU2գ5"j(R.LT;zM(:{5 nxti\zеtHf!@.HHϔk*DNvl8ɣs}M{`g#88n:@(lOL/bΖhG!Rڜ.iuL_5*I#4v韛mߖFs|0bEjFi 2>G B0[|=3X] wz( Xvk슥mkْλFsцd@UaRֿLƀ3cJ8cZ7"`0k P2IP[˾==XRkSb q8;%qiBZo[gsCNCe Afp-RɄ':4f94@c4 ˪-ҩR[z[J,>;ZhvQXY_/{O;xL{K=~֝p4վ4Tՙî|f}E %DQ8k-'l pa4%h#KݶS@59;0JO 0|Pld|'gZAI:qs(,p_ d "r.0ӣsh|\h@[JG-,}3vg8ṉB1,(asA2ںL{Fi 7{t7S0R5W9C~W̟$B{n lLJ~ _BkrV7 ~ :} c1ޣ~Sml%\SքNFX.%E`,+LE Q#LQPs'nF~ΠV?@IP pOK†ĮB Jnx~@UG,|Y]vQ9sÆ9uXGC.:߃OhcD4ԝIL8͞K;M öР7=tbqnt"lǗ-,0{h8`c v]DwhuA3 bǀ6 u-bnPf-7MZ=%vXН+MGW?+ _JJ-WHƤrS36`ŋU5,x% :5 cDHr;RHJ5vFLxWҍ uud#O 9̡7rPEchfjĒ헟ZoZ-9p9.XIw_WDt}UNz)RQi|$%4 '؟*ߞ,ܤU]$U:y< \FZ'zXJqX]&' nѣ=T7N |x9Vas"ϪhF] ![؄/n%)iưGl3)b.*~-l7[Gfj6h![ZZ=c_6/+ӏnAZf4H ɕ^w8)C;6(r_2;_/|T O1U03.EmN,ХՉ̧=NTؑH+Y6!NS4{:~Zvx/ =X3@TATw Cn~vy [ҦMu?d@w^mrR;4,ʙUK sA-rUo~H7߄{2P@vW'Nsp-Tc>b'FU LzdhPK\è|>?T!3]ΧFyCdԆ6 ۘTL zVjt!6 Q [FKB[`Cm%nؘ쬋 O@'q6la5΂v` V6w(ПhNCGjF8Gw6CeENzv"-ڰ:WvG]4<>ANM`jAǓ5(Vz*cpή&wAW)I_Eq7hYm#-DߔNYzEC(N(?\_Or$ߺ@Љ<͘?C7|T~ km}x1q5-9/Ϙ~gAإoDt׉m7 &r,duW\5QQQVVPpCkD^7*jeivwK>>n6*]r aMex3?6r}8.fh>qֺv3/p(Y<>.YYUIh 㯘YQ4Pމvv87DNXp)]b%BJ4ge$.o?a4jJ h#~(~0bJ-ـX T \=N#nkhq3{]ht5vTC=XCw! 9+~;""1 +5rؕ!^~0vunI0ppNjڊ& a(61{zbK|!NwXsVP_QSq!"<sQq*D؆u+q?{.],S\l1, A됯l7OuicQ.b˂h5% z厶.F&c _TȖ:5Հ\L{tsA%ХcIpnrc.um-C%" &|^bD2A/+K }بo`ѣMGܕue7Zj@9li v0E 7y]XCV@)J0vݽo+W0^WvdU0X"`"sAy1E*~s}TBp+XJZ+khKvΦ\sFhf\X%+>ha2(,VIsM#-)r16}g3kr4Tk)֥BZxpFw-4[+N+N$y\-o%}ˬR8wb!=FQ6!mfJ[?ԚKNQpP-imZ%9r IpYJkrjTsJE8&gR/!9y41Kӎ&cMᄹB[æ653R0fT\9O܀ .";< JRvSr`.W-lwpt(/2zx`j3fJ s;ay\evqa+Ht+ucCks,@|V^|kja|W!X_IDBrzN؎\*4vvTרXmoT^ {M.Mʧٰ]Ly*n-6tfe^zԞ{Gq\jEVؑDՂ@YUVQaʂTa %If, f|\8~>D нuWi+)X!-/ ݑ{J~GM$Fg!*w є],*,G W]f4fr x+mmrű`醲,')ɷ[qtwxE׉QGسaW?$݂[P$ahLb7-Z~d _LN[5ۢB:@/*c0cs:lXYzɮq J&|~l\)k{X(QV< 1y c0T&>`u>C J/8( [꒧qP9Qh>(|wt&S; rM6FUgu-S =-Fٟ(S8(Ym|Єl.OQ7@a a&,~в>,Cԋ$u~yϣHj* !=UmgڡhN$1[x[Fnz{+ ʬF#hrbq H(-[i[yhJ+M%唛+K])Ƭ&B#=*Jn@I%T%vZS2qk Þ7oK[f)By^%<7M;|lmA'n  ^cd֭C~CmZIFX:by$1٠tᒃx;aR^a!"'owc& )K6!ۯ)([8aS5d+8`y+9ْq.~\R/H~_3v9έa"A;4@dU00պg9 a@vjn0FA%D1t.d}lĞe3j!U#H:LGxЍkl{^Lj]Z+dYm3!Z/G,3i(o[ m`P_U4U̎2S:8udf17_f9OsR`Ox3}t>$ NzcBV/YGC%Xɭ,TzZ\E&# V-G5Ga\QoEZzHPZ>;#?}{7#9]hT<O[+Ntr' ZP1\h0~wm'6:͏AC&{w٣bjd^W"EޱmaϓGx*Ʋ d%lXHcv .j9ޠUc QV Q/y?<2<0),C sO6]6= 1V^ p\u.TuxbªWa )#,1Zl* Rۯ$L- )_ aLһ急K2f-ԫ0ɆpCC׼?錿QB{ׇf\lTG#~BCCtv–=0.tp{T !'[]#t35)J*feGIx(7d5!\m_ҹ h%r[qq;(EĠݯue1{jۃk0߻ie\xɷ%leܣq(!h _ eZ*ڕߩcGiE2(ۗE!߉_)#1B`"W|CO43[l(,pL~sifȲ>aˋC"h\)sxђ]%E%cpd\\Ď6"ٞ9ehZ hJI8f](S}w\gL #)@n}ll%2I mbx~1QIv#}D;D)c\@GWDС-a\j;v0R>(墰M|7b +'J?ypN>1ګSwp #c-ޭ-azL|¨{obE "ٜ>a483kr=3Ze-aAa$Pi&;37sNLMjҀcP2 ş3JCeJI :Gu~r۰h '\쟦~Aֆ=&Zղ'(}c, ^ǯbg/ Vܿ@t6'ZEf/CgH3T}W5h?j$`=wp`4-opR͂=[Rk}I K *"ϕ*ˬ&`y/F[Iu/ĺ%=TA` uF% Qy<안LyhJ4ޫ} ؔF`PpV31m/Qp /Ygc/{n|tgs,..dPҦiteR:䓌dК55I= W^ODnqlV1 UzDz"h@p<~tYdĠ]+X|I:pZm+8HyUd;N_.w+Ѯʹmu.C\0L9g).a1WΥ]?2x1ߏ6o ܋6c|'|&T?.\aU-PS .)3^~JU@wOņZPȻ?_%{Wp,u'oYU92υ&)F䐵#TO"}!udt9R YqkwZ&V!:gF"=s 1[|Ν$E]L`5ЇoE?o2֠j nOS~k'4RG՘bKz`yprBx0 R8)& ZsOh6dxaKI%ZrJvc\b`-h(ن1J?yC*@/eE=)A$F`)UqcG)V g."l1=Q̖+}=TМU)n\x4B9 BsźLvu9o3}yB < eƓ&x8~;n)]e#Z$gi>>9ձ|Y `/?r\LAK^>\*(t'SHC.*Zm []DcLKӵD63lWA WdW1$VG 8B ^|[R'+Egc$˔`8,k e6GG5`\W~v7'W//)=t,y5΢ mF,rigV<&^d޺Mkj#^&[]˳~VMfRBv-uXe 9uNfF 8*c00cYRMə<6.ƽ'j-- #S;M/hDLJj[YŻ~&;D4lHࢁVuڒګ%Aئ{s|h:NU"C֓ϊدntb>lp=p JH*zKYI_;,$)!:]^dv}8-6/Z$&eS3t rY[9&l:&I¶%&$-ekYP1W80Pv#KA^38 aK5b._N8:vkνquJ'5Cv@V\0ydZcpSp8oGO emi Į$L}G$$Wʉ8̙Sܷ'$Yf2گ5Q Fa37Fo``bS C/\F 'A/L2+U7.1r]—ΠHJԽlA݆f֛jSutzS͚Ơd'<xCo0s5<x-$~ M%<PiӎCu $+^4ԓ,H:zt~  ps!>Z:#UuTRNwLL{uQDSf-`E+y5x;$ͻ  ݒǕLSo} ԏF>9kdžLg^ .B5ő+h DI3he9#:kxt^-}ms#C?A@6'a0]CJL}<.1L61 ]/Bҟuw3Tq%մ[iX K¼ǂb 9%Yj^kS|wfö́^m v6/bdv yNڂ k$#fuvERfL5ͭf&LЭ3JеIk` )CCyCg^ ksՈj>#Tt#-U&Ǹ~Jcq`3uɩl7x͘7R@llcRSx:ޒ>=Gf=F;qwƜmJ@:/켦 KevriKǷ|fk`C΍]_\gQj!kEd++2'`گԜ~H?-~a]O2?jT[_l*W8"d.fy4x aI"+ric) Qb#5  ~ֶT/x}_AjkCW,v S :z~Sa=  SyEcf0͖ )j1ʱWsݞClSY< >@ghCcztPhNZKZQY=dY]/#+(j[o"&#i1u3t\1Cow9ͬA֔>L-@89APO4ȕi7zX=5Άa5[kKD; aƶ+3^jW!Jv,Q iNLf5T2.u$ڟdG V> + 4@CZV[ïQO)ϹbÍ pqM #/B󗁵eWm+g:XmKFmmt@^4<(ؖ\5<{M`Q14ฦyx1-aVܴ\jnsk=H9=B$=@Pt3ǜ>b-}U#! R.V->2pB;Ad$ɢ* c?l\RR[ї+v;qk(tOx[Pk&e"v6G<+NJhoŌCFj40al{4zG[ LMRvgh"m#7C}\QLa?vP)$(4ovǙbc~&4clo$S!lrc*Ӗ[Tiޓ's"!mϯ6{9ɪ{F zގg}ٌcnߟBTXisn`*RUd/?.-\dU,1eg-Bzې, noD%&ܷ6[Pf7XBɍ T9gnc$>=җ*%6>VU0.oqT3j #cX|6e)4̘% ;؝h`,^K_SDC' v"+?%Q%F3(i=kIB)'Q1"wY7v5 { g(aZTR#Ѩtwun_)u(om\fqtx6q8iaS=QPw|`.nr*u lgEP]|lR^Jthu0f 4{?`'RJ7j\!5DX3sPپvb 2}id,1/ŐXy[^cQ/`[q_Q+G&5lHVRSTu _..7t<yK]Jxc7񽇅5Ǣp/jkTvN{ESoі0`ꐬ>'vgQ.M5b~q4ω d doc_CHM% S ˈd0>i\;@֮M j3Yۖq{_89ttФ_H?%n.-Y78S!HtIݍf2]V;5YPw%:lbi~e+iJȹ CqJXfk6``NH*ń 6Z y} U_C=2zrvzmpҦt te_p G2O{>g|^x^D1okr|Ly]i 3<. eo[CD c>1?b5ɠS2o#8Lp; pBά0g3gp?&aR蓞_*E-Raz>1SZar!9x7ۈIJ>ֲtVMɬBxWZz)}YûHM5v͵pо{CUƶhHaH2_e\>3]@qrCD] 3=f ׽͕- aA6K)&o=!7A!`^Hi߇܎Ri6bɟCT5h/*%_gsni* 2E^Yi}0xtnȬ/i5l"lX(4mpm.zdTpAXi`DgzϗvнלQq]eIuFW1:3oT{L? }=Tw}C_xj]Í% 6t(}ΝZڈb2k2Y{Œ& vȬ?52ʯ0BWԍXD6NOӰ 1왢' mV'f>f!l{Vgqfv3ͭ: 3>iڸ&3c=OpZ&WVM*&`>D/v jY>r+&+^{YMF(]^M(w>(8GR}0U=]O~ho~M/oa{56΂0pirD(Ok]#5_ŽU)!ExFE+&)f+`nr[.u< #K`L%v{Xa5 \WR_pHzwg,[nDeՙ6^!0ZB1  9gkT@r+g[V0Ek명uYvYb_v6pm-*lS h+ā_l FMΎLSURУy9S Z!~^ mɖiRB/^5 FY h vjtP鰫I#ͻ {*+Y{dѐԬo(J#«$+IC`4L[0sNe㠾$aߴ:$=v$s2fVׅ|/kksƓS8m ڲ_Nj0rw)hC9S&tw5e>?r&}vkBTc])vE!ƸC DR$2/RunLxcV, v~+՜ԑbi+>,YBvY8BؓPFP[AlFbհۗ>k78$564cX,^i9P~:@0gY`ʔr+4,>:.=PsӐRTиz-ps`(`850KB?d8K%^NMJhh8eN˵ ܐ6*|š muȃxM7W>ɡ!ֶ.?-83scTգ|w96cd(Cbtٮ" NFkh l:vrj@/QǿMV&磠r?aZ4C$͐f6k ׎ |J[2ƤH#- iGM!܀֥UUI<&ϸ7065Cn6ZSFC 8sլPW#:7i/XJR9s&LWeйBA%h@ kom;03)$;!0s2{#rt|ѡ㮀2zzh){ɻXsV'ːBј Mtp9'Ii@5)6Rޫ _[}p>Ѷw }eМQھ/)aza UB@`7.B ,[?K)L0Tm" ~qH2ܧ;$%MόuL`?=_bdxk8 ^82={4P+x骀 hU:NS Qz5+2_,2e8y%bcv~Of\'J@0 h}* r;1|`YG :ƜQ̥Ƭ>_DFw#Z47Aayᕑo=ش_gjg|"\䜔݉?_/ĪB.Ow:E0^hU ~q[ހʻhڈ39nPO7[emk(doicQ%fE?d/=6m]J-&ɓcH“h#b aR*8E]hi>OFZf;<m@hՖ%)}bA~8ÒIC0k:󉸌lco#V04oVhc\`_z[m7?DgCR$@4עiV~X*é׏K΋g0xq~QH񻝈R^o cr: NUM;=91D 9^?"6r$UƏmݍbuV^Lh#72&a%aj^_nlһӔ#g|]rf}Y);xję&, 'l&?EI" j#gǭ|&AݷDAQ8gAPlZv5um.- E|tY 4GS?43i chOT oJ< -a/g1&IG@ݛTzj;#\{b& tQ.):Ż;!|EMڅzm6ꍚ(܂ fJHīj*=x3gP.Dʄg8U(ԢELf&<t4?ƍd͢(ۨ>|:.p _X7P`Inp!5i"?a{No!s#5Z$oVMؼc7 UeagZaTn?)1TMgt#IPf&!kd0)BT*n uG46_!3N˛(UߙǗ\,Oޡ`-+3PA@~i7)fW4ԡ?_gU~|Q3%Wh|TTQV_a^츃)PqpYJegQcpڛ_mfqU`ֽ {FQ Hguo5lxɰqzv4Gu1~'2$x :9ώ,2P(oePvّCLi7ky=u_0axg* /'fǶtB6T[&EjFSәUC | P41Lͧǩlr,Fj o=y z#qoh_;hKe7R$l{$$TXr79:b@t3BNvu&‚k+AdSiyĬEn %oL_<k t_-z;;^j;n"lНHkO6XdF骶L* lBE<ư(|lE-MjHxߠ9qy{_dKWG{1Kl`e"g2&8-rچ$Y3׈,c'-݊a4؂8KuZr&f0UK5-?;Z0a9T͘Ov!T / qR09=i|e]g|X _9 wҎf㞼:XW PkzW,fvd V}zZ4&PuRӍԷ@5܎>.ކWAx 2N HɂC{݂ N\ L#&h_nW<̽] K6@x3ytQK ԕ-4=ieKoRxN`V 4}wj:PTTњ:zkKg]{LB v~\_UehcgB/ݒQRj0 D5/ڌ1CDDJ̹8饧4]{Rjeq0Wʀ <'T)|\Ӳ/ek"?nlQ(zj@@HD?TrDw]+ӏ)FkLLiPoRJ ue7J Ɋ &&}'aɥR&mz23T*[N0 ,.v_1#OkpN\CDKڒU8޾u}e' N(5K?Э7ͤ,#V:܍?#!F3iZa1aQ  &Rĵ/O*E/\AMZ;:ŗ7b@0%]{nq}DiK e_Khp|+x7|T) vj'EۻĔ(_vX_ xoK Obm K6DDi\G nJ e^{G.͕MWӬ <<Sz3Ur'),+D = tH}Ŵ Ą lE1Ixe~'i{, ͚^P_, , }M<&$ QӋ6`ؼ.ɨ#DɈP1+f63H͞±}%>hjh b!hz?yFp)ǚ#K}A3uݶb;9]tGJ! }jɝO0x2@MhYe3v5d z:s1~xؐ㗙TQŽQ3;`X^T3-c؂lJ50E=55H?`p'1*hgb16}kTZ|(z/XˆIؗǧxE5V^]VǽwxelӪo7vz q<<"Egn d!je"~sPڞQ#&8bF9X%*p4IiB_9xyRaL024[|$$!aP&"&Τ영K8KLIYz^k,9׎+2`ȴʧ J!+,[9R&hD*2o_H!yKD \e5s", b*v9ztz`ԧ&$cIqZ7Ȕ%2`U-nVT`7mX9XsF!*)hr<<;17 u {#LWSZ#~Mi̶gJ"̌}jTy9 [76gn (פVϹ37.9*ڤaw3U&dlY턀| ^FKš{w:9=\y77ğJzPA/ lϯ'jciVx`A;p+Xn=c`B\aZwR5[GP`"]h`kQbm-u ə[Ie qȢbGZקD[oYIi}xغ$bh3fNs t*%{7 JHG 1Ea:)JiQ>`aZٿ))f 7i0͖"x ysI1 :#WeNaaoTP4әN|_P; !.^~-]]˙==aWaOiY@:xDzN/dkF^bq'&y')ڹf~!oȲ ]-twD0(Qd\BƩ>py V=ovy0-xwxYƣ㓹8{1z꿈抱,(5N_ mlT+ C2Iʎ(!ay(wpCeΰj.8P}7bjE#JҊRymh"OoiJ o ²GH_MM+҅07'XUۺ6k޾qpOp槊['a%_5n-<8t@~=YDeK\x,~ ļ.d鵲K(Y꒺0D$'<{LzJ"11=*!šS$.`{θ'iK(M+~zQkƷdQ hݗgPLj%`*y*bsR. +A8z osApJzZ57c¹r: \`p'+p8QE  #V`NC9K9e@{ֻq 4~kF9b+P1IOYc4^hYH\USsb(5zExd!ĖpDvКvQOA d]tFikbSGGŢM >X|n_E@nէs'a;D9Z_ibG`xkt4yA[1-\!) ; V[je1k2&{-B kONr^Vjs,fܞ\şOn |X.BtZhiqkbl!U3X0I'h {^~hd;(ߙ== ܃ soLiDðr6+n1-6aRBդ@(d D$g A+ Mx^eEH qIVd *"s_i0wϙC.MV7Wh TzpV`۲LbϢEHnmEn NxXQ`nM#vcտp) F:|@ZsSS\Ek5Iah3ZF1um75!#9@|.#q{h{ #U۸d~RɷǫTrߣh-ϛz ]z# zb;,h$WRy1'2L/%Bps%E$h *e H|f]O#ȏ?9ǁ3 vްͫW&\ݒV9yt21̠`0y;NAgE)h#<8ye6Ƀ׵Tq>=D='u.w݂i-]%A;HE<}yp>!Jۢ gHzp\KӳT@Vq]]$גQ4"6YJ3) MI٥{_d@YڡyB%w:#* RgXz1 R5+F#[4ָ;ۋ^siE%|?1v=4de*;9Xg̠"@+W{ZN̳WQUcKΜY{]3*J1柢Z4Biˆ(jܿljŒچ}Yo0]e +1Gq<7 M+!bF tO9AqoþkrRxf {+)% +zdn`1)VJdRˣ CY!puG*.!SZ2FmLe 3ĥ):.zh8ݣ \2NVj_)?;m䝱SWaU]7-ϐdKaLdWvmv|Q\hsѯtQJ=] Rh&`N`GAdt{.:Pp zA"d˝q;ݻ x~h];88= !RU-? (,\&6mTgc Rұ§&ÚΣQ#@lF~ "Ane_ 0=^'s!Y [uE2%|F$6崨1HЌ1螟O (R5/ݢ:SZھ_uP $WZ~{v'a&˱RP'"j rѯ7Y:4"pbg4S<37}I#&I84>ƿ+Om֧NGy2 (AO tJ7uHfC|d=rGBھW]AT\^ hRA 9ε|Je̝NK$#K8E[fT!;D,cֺc#R*YkM-*p`E[)uyPc Pvy}tΞ254=M" R]|}W8z;_x0̨jwv{XSi(W\mY q'M4Xt"~yF,%ݱJY'MU<]&0ή gYn]D%UQ!QyE%Lm6fh$Swah |p}: #x5<Fz~ w{5&~bT#MۜCTe{*OY2.fN NudzTMMdjNaub,(yBxqwXVِLՁVHoW ND΢Vַ%GHՓޑjDu!{c~aYf2ʅn9hE<*K78bNEo%nbˡBq KyԽ! Mf+rCnr(|ݗ;!~J\@}n6cl]E 3mS8+Xv7\&c.IK[Kl?20#mC}gýQf!T5Ȋ,f]SgeBj* +m75눵-Q4iqdƒo-/*pX{ ɺE~.DNIJp߳1U៩U5Y2p uO0@a=-_{+$DYQ5.htwz4:ަkBUxO_lu &NF,Glϑ,BSRd m)%kNaנⱱ$ %w}ֲטsl(9d rOd δctp0Bh[S>LʛbP&FDkk>.$P0=B=Ã˅4vц:ז&ɱ=]4P;zՐs`4gI UUxbj%wN'ڝ!+cï:ūËaĂy+mL>a3o4  >,i.Itf D8aXzj N!.Ĕv f-kdK'8Nv CSC  {B`V\HQ=6BfpNA0cO}s?a7[!nɵ˕T!0DŽ8$} `a5XpA^B̍mүlҚ Ex% WG9Ӊ_Éjx YRdQ5\먩=;[ܟ{8+M 2brM 2zeQ -eU(|\փMLeMCOfp<>G$'D+_"0]a2ꡰ?}Zjm%5G.jSܪ7bI]qyZ+2, c-iPbz0KKGQaYI4Ük skr돯$^VՅ ?/VlfWGe<zao'ҹ6 A6f!$͝iY )7N? KU(?EZaw-='ne.Y¸?s.Y,嵑'(>.hsvGj8KFHM3 U4sN$BR}zAgVUnlj\Bg!ϐB"켢quK1VxOY Xm0K+轮U)7iW[ > =ƺ}= lΌ*7t\߄V(/U5|SM*ͥ31o4WpniWQF5%ݙ&_T_Lc2!=olߘh&)E$(YPZ9j'X LI,^h&X 7Ɔk;x4ir嗼"OvH,2)icF|!ߍA M|ȗYQ_%jӮ+VY] `\)Om[C(|{S|-[1dgTu8 ԽF/a΍blbmkf&+.w[x%:{ ('CeDd4)gmoD!`AD@*A@tQ.ѝ E6HlBd:S]fԈ5(|Iҍ|z8BYזlPs]@Q,W0`e=Pg""ǖvf;cPk 7%FGqmjY}VV쩭vɯUMq0oB}1L=4 `|ш-#Ied(lXՌh#^zؾYVm1EMaޚ./> }sZP+Y\ )&(,9d3=6}~l|KoflS8gs5bkwn@a' 5&*W<]/8+ms )p^Xa51:",T?~ Q^e3jf FOk/lU_73#v|E3/_h%&yS@W.r"tp>+.тW{DXsaCq+=~ru#BL`ksSchF7j ]Y>Hj4 7ޛ s#aBOv\i wݫLжPZ+,Zfֲ (Ux'79)3_GvэF$m (:cfM GA ~8:#),mW Z$S%ci;]WȆ7rJfU8+Cqd'vju ]ݴSbQ,ׄ}mt^b'%ΔTov:]3bu:iDžJr㉊JbY,]ۨrwɿY49e(?P̋L cl}D3߳L0Ua.zJ\8 -3;i_+IV\Hl<mSY6Jp[y| NK >-e /ӊYchy'(="@@.Fby4KflhtQN~ XChؔsu>1I1Oԃ"j9P*[C%֍/39SNЊǧj}Up&AwF/ܘ̅Y)%&EqReaROYT@{Kd[MڍhN%PߢM} ~Qvj?*b; LoKJbYn..;dLHAd R5?LVbq߿@編ђ:+/*DX. $ Fj|8֯-P?}[6Î4Y ^HAcjlCʭ`5=5~6W㢏p͠ʎ\jq.~d r v(7S |Dut+EՂb9ӤLNY~CahqH sn6\qh Bm\ZVKk}dP .8m=E:߾)a9g/͋G< fC%`yFx!uf~Hf0?v ̓H{ZtOUmMZ(&2gQhzB9WD47uiBq֗]4!OV[֎ďwv_+bN< 䉺{\ӝ`5x*pM9n N{(Ku:C:ĞCQ5ٞ?Rl]^Dg~O9 aO0KLCҨy7`9a(`m JC1yQbX 6&/'@Ǟtϝ rsګv9%qvu|*7w:,Ds6h&ߺ_6F+)y&߼O%jVU]q3?k'72i|r;M Ua9V6+Hف[s@lnѩӹ?Z0(9,30y0aYg fdzuME;XҊ(qP]\td(aMZ5 j w|#T= cQ0ef4 j)W/|tX ѭ{Ę㯜dff -Ků)ֻB5B/" zП$鄩zĮ&r]yWg<$|\ ; .dmFߗ&U Yyi`_tcgyɇ_}E+siS+X‡H]b-uX,Γ/D0ޒa2]2 F4+f4xκDS.X'g5*dnl+JCFAHF)]DkBwV{69߈~wKrw{c~5U}Q#|OZ=,!M `?t,%!Kzmln>$(p=c%uQgdDƺP#G3 Plw7Xd8þlAIr[dWޗG$QR]lZk݆q cJƚ\0+I[e `wf4"pC\tY7Ts.BD)lW8YIGFF{E_쫤 vWY==Gڿ< jgvePɐy:ʑBsxR_5l~Vf`0n1j7&Xr kg¥e!4zpQylW)%?԰ c.`nWYsN;ub|macOCsG6zdL>Wg )7eT 0m&`0#]p(,ϳ>@H:t#ݒƨ pYG$wpAsjw=8lU\۰ff?qFyEG'`X1NcYDSS>&̸tt4/,M^tQVqh{}g1ж?iܼu{? 1Q *)vݜ$Q4P5Ȕ: N&Uo upf3Qš74GGDAKȰPh@;%Z6Z2'ftX'ʈia7lO+-HܼմC.|齅2s?>f!咶mY9UkƒH.ϯU1,*q4Μd ";7޹=~u.=z\4'3?螘ʑ5r1.h 3&ֹoŝf5Gī`"9 62J/pntc ܥ)^"),GqAw/YƑL7wBʆz7S4kDiō_3p mzsFJ4[zxA/ _V_&6o& Z@|}`4ɵ "۾oD%gCQ61>Y C ͳfޤӋd ڿ`'9HƁ^t6(M5'vسS' ?]Pdp/_KN~nHx">>r agXkPR\%82f&gۆ;0Nގ$;3 wAJ5)Љq1fZ,=i#sn4kZ%icKl(Tٚ/GoW8Wp5*\CN24()'C}HZ,hXry-83}0h][h"q) +0GC)D(l.u; _jۉQ'H}a9JD?'`Pc1M3Ȇ;@L(|W˺<4do;`BEȭ; + ֆ^qxGi$_XMTPϡRd.%y9XT "ݤHŧfevmfk n Oj?jEn±F)Rbu*j5-xEFOzdqҖBCn0i) kpI?p,צ3Xi_=.9Ɍ>4I*FnyzEtǞCc(MYlWRF4="Ⱦ0M`H۫B[f!{pz 1FJ$ޓg_|25qG/k^$* ?TJX|wjC2v5%@f(yK`YtMf3pKCTږ:erW-}XuAT0lm$Goe{5O6]#2kP8u6AmUcpC8?q:I?m=PZ\X,S%hf%r] l>퍚1ѧ8SL7|Z.)7Ϯя_@[h}“­%)WP.rU_K?Uъ$Fb)A7E,4k-ae{Ss8~ VL//L3? cPxn%QkM "æ cKu;/޼kn;ӶܿeT},MucVE5b2}?>ڵӟ%GFe)}$ҽ ̒`7BM03aFuVу6ښQ z]U !drFrJ'7`*p5(;>%ٸ=gawc3zk)V!Z~Oh2_ZZӦ`m?`9QlVGb ~n^u/WlWڄ o0,5c ̪<"`r/:+ lPԕTU;); ! 09<gAZMrD/! z''$_;AW'0.Zco4}V .$ DL\7,sAөڶJX阁 GOpb+'YWlUC 7P ts`'+f4N59z=Pf?b9 Ϩv@v\v|xܞɠo @" oL|DdY/#5g('6c%9WsiUA.5Q }\Ba=/bbҤ&D)X}5C+c~3zz ,# _5= Oe)^,qm-x)Nĭ|;lH RDL;(&'ȟln+Ӗؙz4>,嶅m!F5ɭKbZFטOڃ'r5n`̻;|R:c3<lϣ&!~42􈉾 A,P,×* 2"9AZ쐌{ə`;uR4X&Րr0Ԥ'*&8:K`*3@\ <#͋'L3B)ɳai΍ՑƼZdvr烢G"d`{W0v̘ {Ȧ HcZ+B T7H1ߊʞ¬0qySΎjL)JɈr`<@DK!6aC~)D rD%ZToe$TRP? X)S*+ Ͽ,+Q`HQ'ml6\ԞVnӓmeb aDJFTE0y5ǯ=ӕ$(tʺ25!ȥؘc{A"ѿ(V *jF֨]yv׏ ȓ!gSv9=`6Ԟv8S)rM۾'HvȃL!hCɠszredqH`" y ɝd+V(>Z),p Bq&X̷J@ځ\|Ӂ8.\,^=gsOJ-ʧwmL/_^?BNrOO'wc~RKrK Ru.6W!EVTn8G1ϟ6)Vʂiӈ}.ǺJu))JwIiLegq*xEq5YNEѷؖeY-P+zPϔ׽'qES}V}} Z!WoN*챏\u]մsm LRA*D8#0* ˧-:mzSkoCx KŽ+u*do(u #]JG8:r J@ᤝ͚2CK"*qZ8\bY6 vI*sC*i5BMN:}"]НFĕwNczwYA IJ*r+~04(̪/Fjt[\Ƙ)W`Y#Рa~ޠ\8naֿx^8Y)m>c.G}  SJ!1pd[ZSR+v~KSF%PV=fB sP"2A`##4-Ǜ J6{Me)&-ĻR3>ww0o8Siy`9hNПM9jtMᄨ3^x ,A=D=L`"+Yl Cu.֊FY피Hѣ#g$1e8KA쐄yH#?m޽hZ] `lr"a+B[sqCD6n2N[G2Cn&<78eN} eߕ OGh\y >^WQe 8fTd_.a`TsATѐ``'3TԘc' mAҋ:lºJia}Q>v~Rmsv8kj6bdMdO* 8)&-SUc鵆kTB$st7GL$~ D #%.'2\\>t&(S(eߟWd2W8`(›Pl"~S$֭[*i[nʒ%`Gt. k%SC]èc2z֠Me2%Y7ida/oS&pxФNp{Go(fX ђ &Τ97ΰEN#˚tmS< P27"sdJY!WKKeClE\w̤oUXa|?]V-1ji_;i4(/};. 3Cc}=xJoHylwTJže-rq@;LU)#&}Ƿr!.#2N5r%x[R֮q괨WUWRoTO}zSQ (qTz$3ޝZ30)Q!"GqbM`y:c׾p%~N!  i`d݋.i<c?7Z+,X}PFԃٻwp%ig ܤpdv9CdLlgIk@Hrρ =G4sL4´$B= qe'sO:A&Q\rc .M֩ 0^պTАEzrlx%Fr-D؎D[= "caLujp0 d}r@7qg2(@PH^˜wj3T&yk0)6uʌBL_Ӝg̵]9 I?]B/CE˗׿hZfhʟpK&SCz3ˎm]<\wUj"A?$71aS^{vCԩB{mV"ȣ{iӓ=x-pհmd16=vAH؈eE]@Χ[}XAzHЃf71TS꼐F XAuZT#n]|Bǜ .ٺ9y*1y9y}_ĢrZjtXs:'/`pxܿ@:~  Me.=s󰋒[FG%>=_dulIZLQ\(kL4ثIEX&^^.$3"O[uN :0B*Dcj7⬡V$O7DA%LN*}**OFU8h"~Vq`,'qH).j{[uMc {,34U~B֍04DJb5IJ;UOTC^>jc6&dCN511Jt曅#5ƁEo+}zHg!t{μ74~S,~uPkPЉw5HJav7WSMo ޴ \;l9~lۈۑ;V78#ء@x%&_Q޽~c,=+Kp.F슚LtD`M,ͧ5Zsy;-)莵TBf`f@`+r%6>;[Y Уi{0M,cF)XwΓc T>t4˥kހ-2>yFdo苚jglv=D;Gޭ2/IB"?Pȴ2ZSL)Jouh#k#\{ݷU!^~[&F @=q @֚BOgUApz䊏Şװu]GͰ՚##ж$=C}L '.zt |4je`'gkGpG߳%4pq&i?׮K8M zDaTȹ Sۅ )RC7dcJF4Wc-[髈n{ju6*a~3\ h.m|{7]\-?%-QY63q2:œ^T76oِ6+BF*&9`/6v?a'؏65e>)=F\Y8\]}:^~19dQ)ıIV8Kuy&hܣ«0/pfɝ3qӳ#^G(i$`F[#a".0.e>E ʔOcH IU<$/c I޸f8T"JiLN2!ƇHcnb,%A` $3pbi^DV\1",=ǿsƶvv*D2~:k@4_垞1vCȆO6|}+l2;+Up@U4 DUiHy {M QyV]яǬ'!/'(_ 4(EBOLBKaĵH^I@̀4W_Ø;MKZߘ`|p4ϰܶZ'98Lv:)'jOmd˨]a"_~|e_Sg95ytFKSu?zVJ^-d[ f`zqp(}Q\#,q-D J,.SųDg)A,ӎѵ^J,Ҍ: U$qM)b%2qSEO t }K]g/5qP>}=L.94hTӗbόq_N*!J4.Nt*VI ʚf[74LZ4ΖrKd tgȍEz;}qًW>n)1y[~@ 輏!eir E.a0ȗ#B%b.YHxUz;'R¬1̧ t).2Fhh:G縳$0m\˞>T{H"571eiNUBX Tdl`!Hs#j@D.'v:%n[BgѰEPc]-LݒLrLL1q5v~MO37QǠX53sռ-*Q~ )24Ze;I.gi>Z{\BmðX6tTfvAoxck}ʦ.;&6[6+h:Qx(:oWA[Z^X 56?rc_3i$65c(/h+G+b7N~}6 ^^~ ><6kF*Z`l~EEڭ1*)S@:`TX2;6S(5NQ= anT1r'#ԳzB!^S1iq#Rva5y':֫ARĿޮ̄/)7툮̖$2EȤ[K:bi (KUHp'x6yKMy~У|>9Dqe^vz$PC ĉ; D܁^%wY:P¬hU|Nq>̲.rB^Ԋ]Gm=J˔NU\\5-@2WբA9XKˣɜ*XUA !63%Pϫ^yZa2K<;XwzZ5r>6̜G]24sD*-+MOG=}D|eRaE}pj_d}28FSJ`2M%@m'10 Scvt(K^8h8rT 0y8~1v6T ̋x~- eGD*=UAfooPU:z@t?p$Z$ қ݀}:T5Ԓ(x߾6ЅCP Y}tT{&j I1t::M9LFF1.c֭_U rM|Slʛkown111cO& Ѯ=. אk45p+Hɲt'mvU% ݣਙBNOLsc(yh F D\9+mcmƬBkz@0^uCY֭}F _{#ͩ0 _fi9x+{  遣tB8:*:q\;0O@2Y(3v{Z8ʹ* G?֗m#g,s"Tg!$Ќ |,s@rP p˚'&4&1X}7nmaJRK$Dx< {W>(401-vSr X哾)˱-Ȏu]6k9aej0$ƶׇdq ֖nw.Ծ0*J%حr]7{˄ @R;NznkTѵLOu|kE++ (s_CrɴWr$ Xv @w"Nq()O6%*{r;{q&lgߚTjМGN.xjKh+6TP7 9rs|a#pg)sʗˏU'Zxvi?d3KַM\_Y;/N#Pw?(UgdТdױԓ/q{yz. -6>sT[qak5HJJ/A ؕ#e[j)a_|{KűKq>d$ȍ*K pri`f;xvsD T m9b6˼H_qBSvGnڱ{+xiX1|ؿ0e1G24_@uz3eO܂!EHsbe*M#q7ʿ8 eZ_G=1z {=Uk-Q~ nhXרe"-hariH2&0~:FYޘ nYt{khn!EC! Vɂ8]lmp<,7˛M;:ZћΟqfAqi'&`!dϸL˵Dgc6/${L*! _4 [,f$>+ZbAyՎX"V/XB"kL(cAӳB aEJ5D _[x5o&O9Uۂh%%jdJm!N2FK#%I4#N3#4w|"P\`4{BeNYRlI_}.e vkj.T(Ghn~kVXofl6n6xE.܁hTy">Qp~'%CwtڽBv)΅a~i ab&$(\+7l-ҼK1 2!*ʡ:e8b"qز]|ʿiFsv o>q2l|q38G2"jgIF-_I*D-]xS3WMwc tp$$Ď}̴'{WPO&md϶%EoR B |"@yb7aҮzTfy2=C[MtUނX-#&N(t=:$ FƐ4q8* Y;yVn ^sZ3?6eLVYE?^ ͪ8t ^Vo:jͬO+ s;a.#Xa_*OgFF5]j}&@^\Ɠ1'~LMLC_l6(Ccg7;[#RP܊"tpt #7Pb݉R?X[d>eν*q]O\*g=vbߙTUz<`rk,),a-xh£@eɍ#pc>4*}}B;#`x}7^PΫp*<ԃVߪE).ցKGW=K nG7ۦLK"f/x+$P|*&rSKyI[* < 8Lr.t:. [-k Fsw{y}Œw2]a1q&TjXOw֠'oq uqGBhͼ}樾BI FA2;j;Vvf{`H2'7]ʤOn7?c<KI3|EYP5yWb@!#һIxGq#G}U&~o{Gԝw$RT^A$؀ y a-ʹ,CM(Z_bZ<*CRF( 22Hp%LUlZqnu05}17qik导n1^#r>#w Ec09:ڕ'y2. \]mk= N^]% l'<⏿$YcGP>бfUzB`"NmρEޓ}՜0vxe~,%3) dܞk3޷ir_j}Oy7^jt##4_Em}bqqb{1yd4S:䢐/%MN>\uRUӅ_Bظj*lֺym4:dHW(w~-zU`4{U8fj- ~{,qN'طw7pŴ"tt8=z)E;Hj}u\^\L# X+@0 S_A\h\Q'|#}}L]]iRP0L.t`b#)L.Rb"`h?Mp΋~lal2Dt!ʞor!U7"嫬xC,n֛GXc.z3 R2 ,+TpB6ק0#9NK5 ~o JD)^=[/%Wz 6!yڦJ㣜(J0z>\n 9AtElStJ#>i:x95G: w LE;~=C{i?49^ʶ 9<qZܻe)0JFe ?րHW:I(rq]hE/&\-QW7!2+J3fn"C<].D:i9)s+vmѿ[*7-kN >2>UP^cA7SC} ?3- #`eFXc>3to \5ڴp`FM9s{3 bAt$7mѡ"#NYL,%iȽ| .sȔ" T5#HП=h>;l*J85>fRMP6ux[lԭ]Y͗ytFA.9HH޿Nd,7RcMz`E3anϜ."WNJȚW*K~ˎ .l58(~j HFd- #Y $: F,R"G}Cz}5{ߑ|hؙmsj6y6ll=S&ކsDSEj‘CiXkLڰRA;R 18[;W9KQn]+(]fnzZ" L@[V-us`yLAo8?Y(\b[qϠ'({j hg(Ss[7"T:&BMl-x$FT ^ "#dߌJՔ2ur#4F_ c6ğu5T㈧P?WyJ !B#U$v]2MY$ GXBc\)d݀\1TiZK ?|riT7?rE ]L,R}^2cLWO+G#MWt"-:?XPZG$|I#e(N`u\t_d;:Ǯ" ՙl1j.|]DZ'̝hdu<aD.kb*0OXK GR3|Rfc﫳n}*/'H:-0%0& DP<W.EMGqyѮ/ ([-PiO¥\sJea'B[e+ }s*i.#LJf|wT2^n36SAyӸ>$[:93DJ_G #rTbeMzO0/ߌ6 kR!GWOM'\㸗cԁ`4t&CĖVƯ\ B}=MU1dcD ŵo@6AEQ#o&n+8 =(uu\w1auN" $fPp! wGEqƓ 8)>P '@ri4Vĉ!'G`tyN+~V!:+-rH"VJZv;noڵ^@e\4iK|g}ww,΂xO*[hFz,qٟgms*Q$ؗ:t? 9b=;͜=q -|pN+8:#ó(ٹhU]FmF>ub]ezFZ 9i #aϿ7{4e|3ѴHI(].ވ:dQ+uq΍.Bbv@z߳?gwD~mK[!UIR\N[6@?H(+Y֞U2X lCQD`9i+n 2o*1&8Zg5CVٙp[<$Pήt+%[aKQC6 } /$r<{TGtY2&+EW,r.b> yg}Rn :6Je s4&×_G q F`-E,dOָT "EC}!=-~e& IX6NNEzɚqځ'5KsYbL[N7ȯс#;p4 _~7`uLx}*Lr'p}UYdYpJIvJ ezTNSܓ*ן쨭!| zΥITM\rR \B:Ah=ʮNЋrw06Fov)k#le"7pk@ECl* D?.4oWݭEuxꋳTO>p0'R**Omq٪v氱:໭Q@kO0IafqoyTA}|:H%RWTqX\UmŽi'ƊT(wݬՔ25uQM^n/;h w'"諓J3$F|YC,BRxᴱc8]SoXO';輱{Sjzޤ7bL" :Z-(Kws.H`zMye0{t]:>̈́iITYxqf=,Wm(E_︵*#VPxtYQ(eX=^f էBؒWD]h9Z;l@ҍx[s_"兰ƹ R.H8&ٺ5D :4|VQ2tu"IzKo.@x/ Ƶ$+LM e/ cx8q0"e$WZ׮?m"yLC'{J\z^yByvh+DLD^l]8X=%1m@ "1Èߖ1ƈՋe ȕTSZ_4]18nn: 8Ybtf/4_sǀw֛vl;<Ґ25GǷ]9ci&sb"jl3r()^j mL(0ܚx$=]+󚗔#~>@{Uh*.#ۖz>XZqs9MZZqkOZqUW{4s*_0򆼟}@ԞFfЃ!?'^Ɍ3O# uy-̄W2R&t|Cg c"fw a  {ԑ8[#NGq~mLdd$!7:֠t 榣cs :4D2BuX;3㾂sYl:m9qnRW,)p+ MI*{y6fX+,>a>8CKVzn혀;|e|\F{(Bc@oJ5<9/sKF ML$C~r`Twρhג{΋t*!eyJ裦 01K<89 ISN ȶnxrӀe.L\7$eC_k|%6iq~{qрQ]F,ؑG}`0~R]Yσɋ1kL2yxfG%z|[*P5~4׫"#w =WWBpf[OeX{܏8Ё[cl-@<ݳZ\oHN΁ã<^[lk"H7͝]3< yVE ̿FFRc_?(B-B9"O|:>Je*_>(=im#Mͽa|԰'L6(|0 Fsy gX)vmrK6_FgkMۨ+<^:YI}rpds(#SXgb+WLGןaJ:U PJ3Ws#T$lS JrpY2vVClzc1_dB&`s{J`N5w 6YRi14ɐuH P.F"|P;>Htԟ#$^%Oʅ< _Cـ2}NF'.`ҡ 8Z ̜!TBnV>a W7b(eYm^A)T`ϩ8g./ @U et>X2̳!'-hX#,r H(BsAX~Io<}F{̬4 YK6)XXʞsW}lZh9\Rֿ7]9ީ0 v0ui.="N6ۥ46C Xc]0BJs)S out ɧy5)m3f+u>35%0ZtQP@=r$iW #Ć j7_`xEhL7g@?(ב~uShV4$zB*Jnm$j- PNV4/}őIpl_9&2 Ű "3q+%O@%; USQ쨎;F)ub'Bi竡2Nӂ:Hhwq{4vSkȔLfmOFQ}/ 톴d4YhV2r,҃Sx>"_Qiu,y%oJ6y}OѤ-K^@Z*I;5_ J\ڶQgs{f,S xTH4THAgF+'C>!Ђ$o҉ O)XdY?|kF2wѐ#2SQ-H6]IL2քl6Qji,f:`pqۊZ>'Dj:ߠshӂR#^U} %r/ďsIRW Z8bčYl'n Z!4W(PڌwXД_oz:2g﯉U37Έ9zh[0\zw. a]UOX'aGAEiJ,x$Vb6Ziw^ :%eJKoHf)OMRyW5̉0uD@W!u _=^񑓝Q*od#H)iW+:qHq!CeqVYK)iovgK'>̬$h9GS!^#rB4YI @ u4@=I|}njm=r9T+*@׿:ڿB|:ww ${wʰ)N@/ш](3U0W@>f E| N,J9}|T1ز1F+A>Tk=)0%Sv{ٻ vm[JVׇc{YT+~i_գ.޷A%߯tv7Rt!X sO_9QGӭOL"{?u1'4G*P1%XFd-q/5.R׸ig8 8zsoX庑n +]KU+챤Zn.KX5$,>[R=*oz86Br!ySR3&=qU,Adȟ@dͦ*.8?̹[[6i)frzz** +!4\#7߀K%(-}V7FG~J oF6R %DGQIPm՛$'BH>onҽOOΟR> f~N BM=wZԔ{ -&Om)[qy3U|_>VʼnH1x {kAg~mH2Cde5ʦ|9#+"3'pP="ռFO~;bh`Z/_À71{a6ܴŢ˟!+oٗ%lh#&pK>\\cl ;K=l2pOti[2EDDV%ZxȧJSbxM6;mz 0{bBd(Hþ/61.0JvoCI>А>gN'n J+ ;ΓLUAk&&oi#B!% $HڦłOǔ"âYD2xXT6I8G ۜr 6639vv9+ upYkQ">|e!>&Q<}e]H^/$#o0s{5wmDd7/gFI}!JlI$[t6M?p]bN6 Fzҗ9\L?&[m>Pz3(ƙ9%e&H\\*=LY`ǘ*4AgS-~B^bJ p% qv1*\i(c`k t /?F>N,%I&8'6?[J5r G&Y 뵠ptze [iX&Uvt}V,^gd^#;K*F=_ U<=SK\j_C K׫rh_I5$[(:lLAkb*єqKb-O-r؃Cc+EM"+.n鬙xȒVFk[>cBg~ė6ӯeZ%J*@=N|L iʳ0D춪  Euls UHt*Gbfd*W^8&Zd^<Vߞb^tLa4p"$RB-yȧI$8?u+{ +0AV* qלc\2˿!B~b,GVX319|p"EkԎ_ >-JGX+ &Ŏ/oBC<;_8f+Ƈ*:'3#!RwG~0{F(^0n 4wùuV`D"jq-;%v{.d.-O}71D"~J. I˹>WQ͐c̉b񑯅ƕ|6ge;X1cQA?B)y>>=Lέ~_X/ Wd$+Ot 'xWi)Hi W}ydpB! qo:)}"C. LR+k+5KM4Wd0^HMiQκMtԆWgU$o " A.2юlS@rH=x"#~!ˬPpIH w.D O8#%bv: lsF7p-[{9uDbY.4B $Uz_qT CDmz^kڸ9 )b ܎(ɱ%UQPG8y4/Y;A]|UT%Tp 2#|? 1B gBR|?!!Ed[q ޱm4 XGƜ^raI,uM{[(WR~zm.{BAMV↤ @Ns7fy49k #\\E Dtws>"jZ\Q1WA۠ʁJ'U{ qrЅiBkT-Ƈۅd,5J@Nn"Q$jC$ێ mw~Y/qȦyБ]A4 7ņh;.+}ٻ=]wxkW&o Gi;u m>~E;$y梒j _ (^LZ̈́Z=%I8b0^iA֒tY{\x.¶G֊ooS)M7VF9ZwaYv Bϳԉ ?НUbx(*yt^\#UDIꨠpt3EydvZ?rE ڹP1D7X| j5-°#q1fUwmsf>++$XگDv O3/6pŝ`򳳢id'YwytЩֈkw!dqff㬶ҍ>RR\q\y*3'%^ mi#*"iTOsìX 8 nv+rZ]n $D|- ڪǃ3y"%Xn.{l\0 +{=]4Öz+qq ~ )cdyQ$0*w"~:9u{5/Mkqn[!JOTގ`0t2A^"rSȔ?6SL?ZeYfpJTᵓ@ޝ@+@S|:X,9@z[-ےAkMoT@zRg-!\;{=K%M{IUpnt7sFCܫ-7pI"שŴ\7ԹlhU10Xnk:2=QVQބ[cDä a:aߣr&`I!Y5D(| 7 ۩ג)ͱ Yi5{"/Fta}kÞL]_`ZR?h;LnCp +vZ%*gN8RIj`T)1Jc+:-gS'_B9D~w /U$!ߟJu;(lvh}g) [#ܕђ1GSF1CC]%yp&7@|̸|sps%?I1:MQA D<No-Iupk/HSG*_6*JWP^}z{}'-v)hBus$?Araʼn{ E# DNX?⼀Ȩ-P 1 1(6zu35~X `u#֧D}tۙWf&/#A ơA a }VR[RCgC#}WNEY Z;b>q̜Ryɓ fW$U\crg2i>byARy_k7 g4WQek._/^e|v/DۊG%ٞlo v\a I0)ֵ5ZE5n,B>C1FRU[b-I vQL\N^F\pĩx 3oMcqrit-!uì#e/GT:ežV&pqE{M b!s#w}r$NUdմ`hПόe m"I',YZrm8TSʲ`ZbCp UP Z'6)V=Fnlu֕ka q*;u9;T]|roouNzyRT˞vea*Ro5c [NOw#(-5Ts f;2;({!jn05P6nS\=B--aMיJ&Ql[{\W U D.҆,*Sg^$l)j돰lk!Q KZܨ$spX) CdF_ʚ-Y ~E!8.4݌E.2Է6< pC%30[Py>:颽o5ouS]UY\ D>󣐰Bm{j;Q#;VYJp˰h S%?RH׻ﱾdenn ?1hx ^IGXV^Z^<"j >'HA$6hRb 2|֥{DHk ZB|##DysN+M4uw ?]kҴ!5wL:ݑa jqXRMC/kO r#)z/ޞ@r:Qmhpp G<(s>uABkM3˃w.%# w/0YZF!.B`rhQ%#!b٦p”g8oAST,c1K\(5a`\gg\0f“U_FCT'#Ll5lvs"apI\ѥܠ/V)z1ڢHx>!@ 'ZݳQ&v?.CN4FophMWzX.'|k4όp/EsS4߹A4w`OH/2Ln\Z :@JN3k1gm4iW; #3Yߕi'3n{Z%5ڴ>~xVE ۤc堂ilI"MjA|?jwNѭPXTktOF*S1 c l';؛Jɻ*8X6mq{f7VHGw U-8B$64U?(Gs啥.v1C͈~W{;o|C~yiqp\e`1ܗPH`AGT&A1бI'-WH];#eH<[v Ia{s¢7m$h,X0YWо'VΓ4pu7~"YzD^ǿ?*cUdVb( ޺eʕ>Rg3!;*J 24LؙXV hz:6TIA!sYOV#qhN{& {]"@?ZfUq1h_ ,B?LT* ?c/Ž.4 Ib|e~l:]2wǿ, ^u0ГV1AC0tbq>xx359FQVI_2ݢ {.Z|/J37Sa XöqoN`XdP*fOCSFҸgp'i|A N40iLڔnm2yl4֤ĶKw&`ClRn'_iO.!!x֒KYJo@\.hL]p/"ci /NwE(4߀ގ> Ta8ЁgʍIzlZ+dLO,tP.8ݳ5:v3"1lX)N,pL1ˑ3xDZzF:nBYA *\KJzSذTV=] Q(gXpezQg)):W0aB۞Lկ{I=$ccKH\ y:o{,׉ պMG`<^k&wv91Mb,3cfH|ЉF|*Y(ODиq@ҘVf ^- VYM b3N9. wn QU͞e*#Z/Fܬ; qs_=FErOM{\g\^2Yғi*Yg) ^ ދ˩XSq ol7\Vvn|AX+stNbYHR 9CXNQ.&orI #B@,Dɿ[.LNU%{d,8tHYrPÕ޴L+; `~y@OlPS=,=)3?8ÝUWh2x;b.Uq=|ԍ4KWRR~A0VoN#[!K!ǒ~yU敚wj2cH|ݴicM~h"pWTyE_z9!9Q EcANk>" Xh'yW9,;xӣ ܄mZ&U$t^"7 S5fI!ɵٜc(}ĸh3 f>װ[@N4hf{q6f YI@a6/]aW$p"1Vq1Ue?6 =7 nW0 h܂2{.Cy<A\*C-&Jn-b=KGm/!Si\(SȺվ8 6C`n7OCro%k! {"CEq{|(HffA-5=_,YN}^= {ɃyY7]ϥtR~Hh<[P:Ts 7Dti< iR"砫U쑜jBQS}`ͬU9/ƀEݯE7(K^ Dh}L5RX.N)`]8\dcjrݣ ꬿg"M|Qr m2VnbGݡ'~ۃLݰ?9B# +sȟL3Ƽ* nˁ 0hl*o!,ΉJ6j2:i5^PHH5`_[IrdaIm_#ꅴMֶ~V^v'[[R]eY(HqNNRo\<'qb\yݬ_FF|3 n/W8cQ CnE7}Yqh Xґ?%]s>j_Ѧ$(}ٍ/ i4~pߛy/ϳ3Q{FE&rdoqn#~A*ACv/u˱ NPRhRB^uϫ l_־ϚR~Z'bcb0GrgukU]aA,EߢB4&82{k8xsT4XuFLdjyȺYw"':fTO 3뇖8#hNYzZ91>ht`؀ iT] $}`G[mYf>mDBmA^AGAIp%QbIL)2I@fHu 1\8AѿOCai]rGM4BW޺:>E҆\EUm=5f^U (|U4XfHCǜmἦ7cӁv~`AA:?x헴Բ#RsM(o]HF͒gOL_z_Vԥ MS7 ]>Vr lcPq!"ؑ  I=}&R@*vTKe3 O|<\|B^7(S"5ZqWw>>*TS/J(sܝⷀHYGv8mclYWIP7FPDxrx^JNmu ]u0zHy&m=lvq5y1LcV;\ Qut<MwNYZỲ=X=!x햍hi/z@|x㙃c%y}b زVHG$KJdgC1֜Hm{SZ·gDmD~FF~] DQ\$ ?R1B6qSCCt}w/٬ ,jpRJmtɎt`JS՛lB=ibh;q.kT}p[r8cntOߎ @hGlrCLoF;7B[$BdLӠ~tf ~)v ׯ?\v=kȽ6UA`'>Jf$ҳnhOGP lb^hP i׸Px>O&fZnM*14 EmOT4(4wB,޵Zt>f>mG 4taX$:9cEP2!0n"j"+Md z <@Z,!n>b DMx* 7| WCnޢw,^ďύY\ #6 Tc &ި7oĖ,(6+HIz}#s%]✧YrȔhAx'CLEjbXH PBԢ'پ׊ ߦiӠl4]H !7 ]|f~Y 8ZкSAf\A!XnDMut u%6ʺ}K/_2=P$^ 50XV %gr }TGKJw׊6hEX@mGR9Ч)/ FT29Ċ'|gsUfO6~W4M/ d"-AmԎ=M~`q <]?#]}sIKM20pM^ϣ eS*d0|Ӥ lH/yUg;F><Y;бmd h/Lc@F?bRz?6U}"v4EҥSPG!Fg# ΰ.>qdhKDX;ZD R젻|3 76Rqe s3 %36<,>O_A9kP:""R%X;:Q`,KtPx^vf[C(jBjJٞ7p17!׎-ew,y=h1(h;,]yÄUD,B)yC F5<^q=x鄾XدȀ0_M9HA_#z9|J95Mz 10IM6yd!lM3񫜳`/ٓ)}$Y.ncNPiμy!BQA`ٲqA8;b kq+1<|n$Z!ݞ.q\[śˇCTٜ^HΙ'aOnئ,CN D1e9߆Јw]7QI}n?nI(BE>h~"S؟\d~˴d!SSx*2dj}pfT/l9 %<T|_IXz\¯^ݸ5̢^AIS!\5(˯MC:.^dZϰJIY_UO.=l΅ $bi,cQNJ;+5R2Bk5me=yGF4}(T$|It$&UP<1!}VxW&]JX3q?r0,HP8#o%Bo-̧]]R*7I w[ .qmOYZZ.OϲԔACbwofNwZp0}%Qn% jSTŕ>$jOim4S~(WI=t3m.pI ˾8΁sX+Hu`|g:lP![O$)H~;td,RhrYQnF RWɂSMmޑmI҂zN=.>/{kMk*kMվ,8(`Du] Y7`t7i|sV~n#Q"?*( Ek BVk ;_F˜7&߯w8Jic'`Jj)ʶ! eC cd-mbv~E]r@3)>0Z#̹m2nx93.Qڸ 'N]{0 Y#?.sHKin=+&.$ChlcQn. ~YY K?Kq+Ye'w@#)%nն"꘼}LI_S1~P$5% x`D]o%EQ՛ZŁI_Tcj>.M/` ݚĻ&Kſ7S?9{N1jST|#4/Ε,Ap72)$O~-yv1w'"F+DwR?> ȹPgem.(F,Aԫ!.s}~=kp: -{K[DpcRlh*;X*z\Y 3 6 /‡]=ʻ($9ef*:žzva7xϞP9vܠYU\L6"i kx *Ķ6"zcV>|.iWM&c(bu(/D%o`>|JxJ25m:IYYe9=9$d.Ձǖq|l h]>^yBm"%ZF.h5A@/KmX=޸s.ָ93mYZR '_dΒ-O'c5g{*Gۤ00T] YJ¸1=(p.0cYkbJv֚xI>WdZ@ÿȿSens ;r$t!P?3w֬k~K l+:Ҁ%Pƺil:σSH2&'%N# O:B+;7: S69h4cK@%ŔZ&^N\KIXA>/jBp§%A}b,(7"1v/Dʿ&Պ&6#a_6#-I&&lsA@06|FߣmJ< d5K4a]FmgG:qwa^fR9ky{03p|UޯF}܋d͖}q0疴&0sm7hjuQo :bW_"k0yА-&(2%]~wK;ۼ>OH(tOY헖SkJ%MGXT_Q^GY]޹:|u%Jf$$q+|X{ }${3;]$.38x0(:wѽD(Mc_djw %Q^cV}hnFWꖣD;jj{Dʡ} dMk&x 4|+ `i@yuaN8u(^:W}ߌA  mUۚ~DB=䔼%p5rj%a $ 3 +zIs,]޿ICE`s< ,-}[A.aJ({s:S]h7[82:ŷJ@ 5SNJ#N s|ڲ9!3$Wm7}5 Cicp9[c7%us<=BV[5t.Om)ra+m|W $6m0^E|7!03Y9(^֝BqjJ9G֕r𻵾ϸRR0X%|v]]/LE4{6w>54$ Dfqq-!! C ^KpUSI< L~xYB{_YFv0xZMx,_j`R^0o!-mU뎈JR#'r.0,kEgilUh.ލ1mYR^l@:U _MNMr]Q-մau`[L'\, Z k:BZ r9Ya9mC65F! \Wu3qmҘ[=k%|bZ~\yG4}el(nq3N5`/rA!պOXf5SȤ5"ߝ#ִ gxc ķ_JM֒ $NONǥ̎ v_RH f)s!aB3D.
irPw$ Oi@'Xbwsͯ=+u䮠"Ww?-ЏKtbā)yDX1KBl#'M X5}Hn#n3!>I#yg5I鶈{cE@ݶh"?گ jtĕ ##T FNN0r;RRs$B[&ݬ% 4ʭ4-EF{ш́nqd=n{GI,X=(k.~0N9Yy*]kÏf= '=ȰIq'.LxFKIAkOiǙ=H[лMGȠ'Dq;yFy y/Kg+"6O-z'dS,Nׇ5ߙWaTIW*ST-@=oW3 dǩΟmn!s A1  ^`C55+^zi$[rwL *=+ϗ7ȍܮH"T87>`-Xt(▇1C?0Kc>9 9F7+O-(tkQYw` \( 7O40Ht r&'/đo-5Ȣyc#OcWɠLC}fNC<Xt IE*3 o%|LHj?:zS]v.*Ü8>o)GP6WѪ|:+## +7!*s &0=B띷7cjVzf)ԓqy5/Wj[v1Ua1< 8,F 852y{Aػi%?,6!Rp{v ФqhwwcŞkMXxnVy#UN͑a56lɭuy"[!-c3}=knƝ;@ѤxUg闓d"Uref_%K)IlH:#ˬ{ROĩ@sRi4po (ᓖJliE{#f|MѨgA*kF_ʘeng(r⚒fMv|H&[:mHqTݩ<}fΈ ]'W笉dpYoԢJ(G9>?V޲E6\%4;Z$5}O ]PXcSr"mfA:y?Ml;C=t5 IF niY=vu9jq , [g瑎?_ڷ MwEٮii#8yI0A kY P0ß`TsZ_=.TҦ7uZ>fC%Cf@8PK.;:lOKBvx҂lh@la{A>r&#lx4+3l cv[}SւzB~~ܜX_Y$0RE,Sc1g~GDzKءXV Y (\#O)j%9l6=_Wҡ,-(3#~u^;wHƮe!QPͥ@X3Vl(cM\d>6?8n`~&7HL:te0*"љ%%"j3IMv8^;n[* zN)ơ1,bm%uDJpqxCZa*FN6">|T84M.x+ӷAAE-!X*=OY@[2KX9t$sU_qCÜSE, 3ٌt[@K5<;bt$o0-_cx= Dck| dBUbXQQla<֑,3r!񅃨3(}`N"k4FJԅ,>|H#{ͱגL_5ò[sYƔ10撄/ظ?g)?NAAS66mēzh WU i>{:Nĭ 0%o 3d7Kʰ˃ԓ($j8[[@j|H^}:Q x}.go/5Z,6kN ظ察ǖFv x^n <0FOVx.[CK]2|ضh\ g>!C^0AmU$o#2_ovxH1-R'kSmnX':MmKWiH5+:$@d͏$lt^=tY~ (M{ A'^RMLOx85J+siZtE5X%m4ށU|f,Af|c Lj`_ŬNtd `T?UZf- pn_ߴXO6qA key 3z9P\偿Vs~#" l:ky8FnK ٷnn =u/[#^WXy"_᜽;sL|NE REf27+&,Ys$ "5g Yesn,Y=)Hd|2r g/޾HBMQl6Vq7~;9Qfm_QV͌q?Ȓ7&Nn':\Q| ^1 w9艢B[8L5(*]pB6 yB T9W'v"[Pݨ.29r/AB;8T7x?\P7. XM]T=ySZ8_f?s]SܧWe\zdXbb‡?o(Iuphij)A҇jܖ5F @Y,pG6)'`4 ӧ"5LgөlxHc"X!x~7iXtKly\\d!?wL$ҕz;S#V q@s+Dw?1bvQS\9FWO ՈGx rSمGO9'zҎ6`go'aBҌy) c>pl 5?[ Qo8NX\qu @}1Pz5b%f!}s?ɷ`MN)ܚy^@ܚJ*Z42(&6>N2Iq>Eg|zyi[)rf=(Fg+Z lmAF]:F-OX򄪹{U_=,R6'hi|h{%sx;yB?1Pa;#L ו=I*zn,e= b5K zhZ8p[o8O DN#]:4SDr^p1 7_Ga,utg%Rx4<@G\ qAcHQ=:k% 7omYG+3CWjd\=6͵|*k7ys {9BAHD|nOJ _HH~ȰNk;90Hv76;u1OjG,7E3#N5(?HJE+- <3mPWIWiێx Tp۔) л{-9XR3(ux7l\{K-\dO 4G1.J5Qo=ze5㕿s'U6qc"+9*Ny.:Gu.h%|.r`#_}{0X`Kc-Rg5P#6>AI`(%~?08&|W!&G.}Z},3ۄ$o @M vN$jE =!,%a3iG . e!P]tNpoֲpqm[(WsOYz$ I5^M ;ґJ8.eƤCrS9ZH$45bCH z"^'ZT 09O(tR/8[^$zxDSTb;M+^7a6†h#Z\TT?v2wd"DP#:VqxK #]4fViϔt8z95 D"!OG+niQBcL/$vz&U~WDDRFBҢS7)3>dr*y†nqN>*쬡틷'R'O!R]tsCDyFCt//}I3pfUB˳77{϶;=8~$!P0}p-]"tdⅡ^hqҥ31|<jXݷY=-+sXC|ߜ0.y*mZ& sN=4Gm2w#**$wdK WqWB?t8/8& ߶GuR]![S?}FpB+=~Bp%t%d)f~~-MQk""t>]3fCgj^:;2h:/`] A6Y*з0}l,-7gPM^ВfQ&p 0( 2: hZ$jLƌ*+6wo`k<ٷή$2N^mqsǤZI] ĥUQ{p[RC~玌_'nb!-d WS6fdhO"r*ۡe\;$^#١Ip7.d~I)q ][=,a K%z 9{yE OZH(9ra4/b}oD#2Lv<o#bϻY:ϲR&tDŽ0lC1޿q#V⩹KJ~0p?炠"c`).UBv^4b.WF:Zj,a=/VwPHz9RMDLe|_ Q'2o:Kln10A:e l4ޤq}D }ׇ8u5JL9j'l1(@@52p|L\83ѩ9h2w| C2ín8b-Y2."c@fa#pUD]]i ^>@{j9|`VN|F-Lq8$(.ɗ$g{"86p˪ҍ!oYiji6G˱+XX6^еUυhx6H((>oο"kq*URg))'rg` v`De¢qk/\tdQ*xkՆjI@L=IH2V{(c?#'NJ=Jl>> Х-/m: !p:-;>3;VDaTT:vЕMMވv[q%}Qp+&( ,HǪ3UK8#sf rȞLOell Ø٭2VAdSxbx[樢͌BKx.$xB!5iiw@X5d75aZI?3-Găzv+oYE\=+"SlSˮd}(fvQ@if/`TiT ~0E3,W| >(52H5q)2)1sYR$1F$&Ȁvm0kKɸM$\z94g/J/MMEOT ù.]E0AK;edTk|XeU=*9#P~Rwo>W҇ ~mm``"|b!{RTGL _Cd\yeoiULHmJ>o=H%>]ca.U%;[[FsDi/ Mñ8 N a9 ֕zYՆ1օ柊J%OU%l ]?9A^Y&/' W*Fv 87D}ߍ@R[猪 y6fð}G>jR9Q"bVf"h™[^DWT-|yUCtvYe:*4#QsceŲ)PF0;^.H:P~堯x<'+gn=H5~;LK7%4 k"nR GTzmҡLDh;6nN,oe8MFoVߎ2xFpޱwa%S?,-p[\r"6RYat QUl|ͯ{גԚ>SjdJ}3kJ" )r,M=W]jTД/hT4}N j3}Cg& ~PMPUUA Y` o&{J)!_~p5?֓*0|WAq"H*BPC Eq6^CH:JPVI14+_Ic1Čžcc 1z(qcKj暃LWId|3fz \Fr,KD1RdjբD+tR2omC0vnwW"vJ {\ի%WBEu٦zq<}Bq'R.C=ϼfCo@w&jv;ʯ0@ &5\}R)Sßk}D"A(Zt"T3 r7A@d^6TL;#י|dWjR&֩6H <Sn"PW ϸNHHBpvٳg 0B#J" $K$֜4P콦Ό@k^`[S_, ## PwJ#7^7?"9j "L:h= uD7=3f;U?87Ho?xJI+y%PFrAon2]9(iR?rIX}^j$xiOrgA'dSM9ٱ;; !f%=P~ָdyFFFK?TQLW}ЁQlbE2g7@1%:`dk}Ǐn٘?jqk_ hupqKK U}Pi%m3"b8+Űt|Ѿ+lJW ARZ·~&wW o| )T@h2 [1πsƙWv#=i:Yt3Ixm#3#d?Zfl2::A]I#> Pksy^b}1IEz !|F"5噓b)gH3=PI(lU K\i:L;#ҕ{Nnm/uK8GID0WQfj͏"EE+cQL}pS @dVB.[L "iLjN]GAk1}50|XК iKoO40bnMߐ |ZVOd=%JNZ*$꽉*WybcREx*2pCc_ {Ҧc'_ܿ*oM:t X|BL !VP_-!@cNX-)Q0^- 6`-\oJ̦cf ?8%PUhul&f?e*a@;U g<@K6Qn Kz_<Ϯt͹{138kāzNEoF whv3q,8ҜZ1dW>oRcU~YRyrٺZJ]|C֥mD)6z荔o6HR19p@{g?c[*S3D.qA";#|u9ܳ\&kއ u2ŬEƺn50QSA'5&-3zAilSM{S6^:Z%*XEJ֓[zV>`K t5Dxu-?8G%6dթW#'>ڝ+k , F,}Ű(_@E/@aEuї)uq?$)gO(d `mkNb)7vnpGb(q^kF<eO4,pRmX5 &ZKJ~aL$|N i6AXO5#YǾL`&W"AX@Jlܭ8r) A-2sduU1w@XW$.bQrZEl 4^Oo_mrSz7M7+V6R2Y_S[;-8Aj>"4f1s S/gLrX1_XB/LU^ד yS\yUJQ|uJ6CY* I ~ǕҩFo/jTQ. F2y8$CLu܌O{)$*Qpx^=tj+.)6RloF@8n- [`lStI?`z/[ {ACۧ+Dit;fZz#K\+0TZcq[/9}s%$DjQPrj_U&E[ٍEtjѼ~9L`T*-wg*:F$$24i7j"@~Uـ h$1WϺm=3 X11 'c)7Ӥ`Ŀm#Y.Vyx\Sof,tPL*䬷y!paW?d+` cs_ ;^=*{,5L9md0߿[%#dsUPîQY#C_A5^gs`JY2>SLMR\(:aHH+gps9Vd˂MAד`:>v; (RyWU0Cn 3?;qqZ`%=C:9UEgXCu<4Ϩ2 f,)ͨrhnGPd!P$?q]ka,@}5 Rm*HJT]x+*zzv) Hǿ*;f̟,%< 7be MJuKI7đ7XjYQf\p'mMU_il߸ p#aSJ# "6M]p(d {Ty\PsT6Q(*9;KF& eRTXDOG<NTw1{\.m+~;$CC$[Maw"zWbV(pc3^T` Ӕ_kõf׿`uz||R\'š!p H 6Wk):C'IfGlzA1M҇w.OLՌ`/DK>:e07J/됸]P'$Uh|s Y1%>*>y♶cr5V3PbFYSA:%r=.UWu=P%߇>aI߸3gzUo 3!qM.#˶1i8抅7u"mP& i0m_m-PA5eR(e"yU`p-vrB+mϘUs#r&c *-1 oȘ5yA QOs#9$r>bj zߜ;<xt=(9 xg=4=%Vy41p“%mD2JNmpPuCHʶX_ DTͩmYW2 6$O P0=G;&/LLX0b!{lapQ \q*oh1}e-]bRW`dp5P]@fOR#cW'>ۋ܅Im=L"e#RPdSMrVXiX=b\(R@+2Zb:M;wuX5!Zj/!(ndw-xH: eDYJoI" &1^IYD2nw暽 {¶I ^&5,uzUWI,|}NRwƐg>B&2@BE)yC iy }()IyU cJ;yrg$mV"-UخX*gY`;u׆~9U0AIV[BW!jëgMgiɊ=clC8-]2egt |\w0E;kN q׀J V!,jr>2f# >fVʟ+.](|v^IZʵ UOuA4Kg~zGAbB"ݪZd7X)\ZuN?j6kPOgbEZ囖E3 Wlw~ID$SN15A &bk^'>zt (cWt/LLG0'Qԏ"HW1'hLH%7ҍ?/!sgwls5Nܷoi Fۄmk. K}S${xEx*f E<\lG\ cTz'=~8#_F883, vѫf';Nfa![ɫPeb%&EwfpOq:qQ@=@A R|:Z+wӘ=9i5|";Y|Hh`?ZRL+)WMM`hyNXiz BJ_}Qfʟ)=*38z&z: (͘Bc,MrkRbr @7>qɎduKhErڣZy݈Ep}:%(anje.QθA$3\&rj2~>?"*<#}dr&ijcie#9cr0!J T>R/9^89|}ۀK=U0uc AOwAVmG],_AԇpECp8xb^vY ,ϝƗbJ : 26?&lPGAI LOђ6L}i嗂. SV^^h |B]knp)3zR$ho$s*S=V IH=PQzPW F@9G d*RAVm(n|ޠ^s'v`b&%d듏CC2˭:ilD8w {2N&CJ*cf.qnbl;ua+ [n(I:Q}6BmB"n%'㴺aV ;2V`)MaVӱ,Wa/hRq@a[YN9QJwF' q̩&O0OK ]3_rmTOxIx`J Bqjxvt0-% QKًl.ާk 49{9 &^ REn(A X{|&^"tZ+ymb?BMiF&g62QٕKVkX>BvBNm|""v:8u(k  س~M Wi/b@\*XGs*|S .s]P zJdA`ۂ-*! ^2&[v O+/֪kCa8g Urgd]xiHTZe-[`h"%{AJO"2aNݦ{SA$7=''M+Ho< *[e?9x43q)u"Y/YA%Lؗ]= sI/rû>9YFC-{<`֤fg<y#(W!rFǩiA'}`6 _knq.) Ë mm(<NN:r6z7QQ5}8zX2e78qļ\bbx<UkDWǑW<t was0]8J 7hN-8=ء%[t܎ FIk|)YႤ.|>Fϻ|tѬ"jI&A( U:qp)HgWtp9侨+5%],"Qd;3qL0nsdzU"髠 ucHa&f 9]hΌ5Fz ԭ`c\= 7.hYh~<*VF9-Xxij')r5lDc3*lUMcyK,(8m-4FeJvбjM?:5zDZQӣ?j1ym}:y9wQHj`;'m5V no02z(8 pQr!Rm\\(a`n,Z,hyPg${VŸ/=X' faQuE^cZc;$#u0n$O]W\DOGݻW5FBq3Ɖmul*{?Mf^ovq]SM7x)@wlMcH$)IѩJ&#S ,~݌AOsu9j~H@~|y>oPU,Q|jqcA\`emP"(9㢎@퐤8 SB66(ArRIoqp pϪ`+JNsEBnE)>GNsA2,D$xާP [ N*zJyE<-*Đ%$4#71)X+-U_p >,C)*ԇL*{{$aӧؘ&   _ >Sxwh˗HK5oJfO۵TwDpo;tHMCeS#n{`4 c-Ae"| )XL>u:A~ue,7~+ 뇇E`A<稵rNO@!W3N9@*-AkG,ٲ$KܦBuRCJ+3b\G6{]-t}:>9bxM. [@xܛY5 'GhjHuC"nP{iu|h.E/FVlN [֥,[tc'3I5j _./]!UA*J.ɑI{1N9"˼ j[qBL ;{uTBelS,YJV2?>ШT yב]DG>$TeTPgQ"mJNN8&qD8 svSj;)+U]I%&-z7fϱz K0u?=Q# ~| ./5z@W^Z2/ۚ2땱hC{l-8> 8*RҠot&qTzDAN,X$g'g92K{0U$:DrEr?pqNEcKMښ_0ABVm&MY\ {*rDR5dAaL8[ 5M<}7ٌ_|>Ȟ( c.R KNF 4~ U7e?t/kY}*)Y&%]zQ4և땁WBbgdFd.ȼ PH@1SmSR wr6@ztHqRtyʼ*y4.O39Ko[*U` 壑].h`&BazN> ESRB MB1x(֬N'sXu:eQ13s|:^f`i, !8a 68.Ln﹊&ct[xJPzێ޹ϵ2S "EB5 l=BZpC"$4\qrK% 4=;P$1ʲX*̦Y2rQOk<51Fznv mL ~8O^h2}=cAlCMKcSW\qA UpkqI"W-iyT\)')(@a\1)Yqm)hM.pXfOۮU%2PSu%ϪTi 2Dswv[q=qZtd)ga:M#.~m21(GJ{Q>.SC#>^ ~}X[thBdori9`ڝD'[sy{ٻS'ːT(b ݁,}zވ{4ZA jRf渌bi_Q4b3yC6$KZg|Pnqz6S7f2ħ©aFE,\׌S37ctgQ?ݽHU'ǘf*cp$;u:}XH_jBd8s .jҩmQU&ʄS d1 ` X bL;\p~Z_t?ĄF~G^-*VT4 [cp_*΍%4TOm,si! 2פK1ٷ*# B1'UQ/85Ñ !?)ј#p݊hw .z)n?_B 8|[L"U\Wp:pY2U㤠>Y CY]TRop[lぉcqt dTxU(h݃!JdX2 ŷ$^ U Oc.;JVbfS9(.(ӇMɮPݺD_ef\Cj!_Nk.|)M @ȱM*FNNVJZ[ pކZa4C14BMMYZU 7va1Y @1ح)8H"դAqS d`:}d!cZw|u0Mj"tHF J;gҲqs.x\$7kRfPίtN;َb풶'$RW??ḧ́˄+@{B͓:{~v"}/YM`pVm0ղ@t m {8@YҢ سc:VC3,U9@{ 1o%m_%”̽\6"yېʽoԨ#{z1'3DjgITUS(!Г,a3c3U .<'[t=ӌDbeTHc ʶ;->np^. T}d}W@p)+.0Wrx! 5~{ai;("_9ZIB sY!drn5|W=[ojU'CVIĩl}@R0tX75Rme˓irL^,YC@3O#96౞ 7·O&X3te? EqpRojQ.E"I#SjV+4*tnV253͉/@z9/R+\Y+-,`3oo!uoѲXاClq)E=~boBsjt7365_ j`Y:&*M8wdݦS΂]7iPGǟJ_ұsdo-De2!|6Y؂!騞9_ 8N4s#|ABBHkTⴔZ)8;$](H{6il$(P+m<`YZhhy$xxoEbF׮[ &tF0Rʋr|v\4IRDIoj5] h;^`g:@sSAb*?zvj{3Vf#^a5*N Rd<hx&ʴH)z@M![4"a~,8`3j#A y!jRPxb)۞Ag3anH@dqZJCAFRuqv]WG虦%!|]Y^`FMﱵ %{Dp9ʔ,]BR{a>C8j/(yY;FESA/6h6|hiCoo?[kjOnvmYŽ=y2/F®iVߤ+#Dوg5+("\2N V|H"qC2UT9N k9#.]z}DT/\f\]{/7cpI7^%9r#|i>]s{j/ ֨P~kWnҴ$O4Hqꎧ~Ԛ'd{8qI5E>kbxڝvʏ4Rn =;d]$[ؑ8㸱[n4<*{o -5܂xiG$> ?̜AdLKK>U‡f-3n t9 Jt7#z8k>?S "F Y/n^>k ]kaA k?47զRfIpŷ=+9̳? KE583eZu}(#+1 ڗe}+HcRWS%n7(Z U_L'«A0)cpPu>(_t)Iy1>P4yěxd,a5]+'0rJ'qҠf]p=>-Iq<mRʬ7ב^R>DIy䒤_eY5`&,DhcF ַC4p BMh6/[PLcμ} Vl{w2wB%\@4weD 5+UqPu[WyW~FЃMTZ5'ҭ] 6[;C{OdAbV_C Do u_*Cɵ> FGHDI! BZJ ا@m:='n:k(2eݲ5y?)_}`YN(3(# GiQ%'cKD]4P[kR6&y'O3pk `ނD)vlvʬŵ'\ꂢOi*ødH \gO1MoZۉG3~!:VCBMT-D%VqzMP*>"Du5͠mRkFdj=#4߸E% qd*]A+0^;!P~'/F[2.B ]v١:XT ں-sl'2v-[/2T瀬q}pD~Q` 1Hv/g%_ٲOz5!'i8 oL;ZӰAK*tm.ΰFNSɿ}8 d.nOo+ |[)#}|!RW79^6d(E]Y(X%a]ske(dBmb\_!Mˡij)wX%9T"ڌgaf.nſf"u=֪n>pNLIy/FD'ò7m{[~=O7)+RAbI==0f^sf'ݡęTf4ȡ Έ~juSW CW9Ew->"h,luAE#\ ~zXϧYif֒l@o*p[~QE=1yR[AJM'!D Pf˺z ziA>%@-φqQߗ$qezzm77VXZpn\|n-jǢBÑ9Lg~d2\;Ԃ"6`>E,^|9R?}Uh9QAX<i~ݔcCin\z)̏W84V:݋v4?μk _zB l8grohӣ, V)M6A͏gt#M5}Jwnq%}†S.*ZV¸_R&gy~4 2kvFl 03oT1^߮,r3`7Ԉ,R(UIBq1,)g\ux=+4պ/Ow@xYe _&\˥w5ޣ|QΏvIdRl©Ԫ>/O<ǘM8DBwggN9hJ:d$KV)B MUYr1c@5!IJQl&| ɭ:(zߕi_`}HNoО=r"Hoc7O'&vpPẁ &*Y]9S//zy2ׇ2{[ Cًa\)eJ!P lO|IuO>{Fe}g->; S"Mu[PpSio4%ӛ-%!"P\0 >7D& m:aȗ+i4?ݦ ÂApT7o@zM~DUh2uFK5F{R\+ @ }_z|ZMl9$+[ΐjʔfwKD |\cÙ=ř!pCPPG*@n1ƒ}PC'Z &+LxUrB_ o xv c-r8Pv/&(+B&?&+149)l#=\6@\!iy VN}_}zU[鴈cݕjn/JNv`''(nGʛ3ߒ#1+WTp(M#qڟI8tIlCО,{:!/JVEHϬX-rЬld;&9p3Oo` ,Dpҷ.ДJψHPZX Y97PNַ*&L ¨ !ȬeF H_P"@5\rG}UXƛTN@N̵^WMMFG WotmhlIOk@nU zc` c^;3F8;0~i?*ĊBm'6ԋA C֒ƖD&sμS&T0rrP̠As:~&dUT9``f +hT{\n0fUL !J6γi,-SqT2;^E}ɓއ dNAjYq{@(Яe/"CJO:p+>_Q\e Fq\8mM$]GwIeӿWR=A@uMA4!\(5Ȭ!(5'#.kvtxMG*}We:JR ==bA1̝穎$4Q¬{kL.\I brYsQ3\|Vbtq-1SId8'ƌ ݄f)W%bR9m uEܩ77jȍEY ՝c*Z[+y )ɀws=x=pdWz% ͚G6_uW@k,g>Y՞HR/F~dK ǚ{>V0g/ >FUXЋMN+cX.M)ރ=z,GX^}a3?o M&+Zy_0&1iThWwͶKc'=5յtkWH hBLjSh)*T7mOcks7:(>;G^7D"/(I1mli!ȁxӻ)O?uAWxv!G+M ˛ `}+>ŋA%_+?M-+x_W"XNǺU*D,Ͷ/ _ uY/˧p^;5CgYg)ma'i.ĐU؊&8W`eNqTRv -Ԏ`zڻV}dbΓ+cO[RX|КJ~fXziG F}tYGx?\v-W4}tbK/,ANƿusB:3  0?3 6T5LF ai$Ԥ[EgK;<3@mf| kNnCf[ hȡxYB}\ A c;1Y)<186sFF d[ϗ <Ӷ>$p,ik8;p, K~m><7 Ս|ZM4BZ*1(V *M52j?b7JlW^QD[pП1L<پ˽$0/}{hH%?WpljLꢳUر:Ӄa=GIB?i*LњKh<ۡ r̜M.٫aW]SH] l嵽9`?͕v,ο{e1Sn p^|'BÞVV bNAƟ;yy5p kj]+ s鎍 O.s'cIׇqMyvYC6E| 1]<=!Bcr`I>r,ӒXSY*t]]Ru%P΂ZU{wQ?8X>I'>{fqj 1:ݫ?hZϝSQ\W+#\X29+ æJ0@z5D/U1LmYarG"vP Yϭm%b?!7Z9J(朢70h[(XȚN PFƵ* fU v;kv~,8 *zhrʾ zõ()-~Xv <vM h<ݶ gǼK+m:3rL3Vh^jd! qu;mAh(WBg;B=f D+N2V ـB"RZ!=FriHn@57 M 9i/*}5CCu`@"E bْ%:~RjFb,Lg?ѶRUB\+]hr2fp|XZnsL9`մpdDj"]i&\Mչ2AWEpl)VpaswYyr] ͚niYjI3 [arp l`ma #X9kNwr6Xh;W^jji _w.|.æ6]D%KoW5`AZhd * Є gb`.j- ;EEYhMJP/*\&~] "1F__,_k?[J_R4XgvK/Svo靰}LWS&Qsdejeb=Q!҆Z Ȣ9R? ^G\7 6stK ܕLtny/%)Tt=ωPzi'j׫YVJh(;ArVRK;laV3̻FfEʰLgP]d682|2e[t&v<}(KSf- ITM &-EʂxN@4#a"ko}P76 9dK8.hUEU}BKiLx"; !9y3,*)&+HF3@'y6oǹ,袵5*-=_uzhd_2=a,8$յ}hZFNTJa:U|HD Vp4S4WvrlV\6oK(!&cʔK;{$I%]c$u\:DZ|r$?StE_ S|/=%͝^0[5׾9큘 N_E^H@ 9VyBG &o;,ֵ͵-hI*`IP"MX'e8jDI/*d~d)滴$1Y崥0`DEJI6O`US:A""\FMy]tx_Z""k%\J!i!)C[z- ;)gXcʹ> /? ^92:Nb9ؐ0c ٪tY :FϡCTŭ2j !K_+?q0nr3㶧ͺvw5d59$ !sM Px'i)oZ2='޹*O2)]htıPw!=Ys) W |㱉/Ma@Y!Ɨ\Dn/- )PCG?]ņJhD{(MN/!~h?zgIʆB>W|Ke촘|qsYn$[ݱʌG:o^BZy@r^:2S 4te3*r) Wn/ X8gVV7*r[q%.LPΗgqٌJBzn>b^S.x黹bJ:`SwGlo 9ci1y7rnnCBR 1xo0#H>di]8ݱut>^;"H 1(_pi›3g;U$[cbu%E覐#7Ũ5ٳmF.F@-ð$fX " iS l.Qr8q9[J7%3sLm X@W:KmPOξwNE+͗ $R"믂h5-l2wY }`XS0 `s"j'dN߮>gC٨r?/5QqוP-C ܽm4$4{%a8yl,@ͱ2~=q*YZۘ^|+ /*^dg8aP/3qշʙ^Y 1aliE]]n?q\h,!5w0bx4@OɗTaۍ7t>قݳ 0P,MҶ$šZƔ,ie J$;E^jT)M&hf369umOp\45(_>-_d KoQsvkװ7H%[04_Z^{)%;umY=g:;ZI=…i7+'l!)|OP*ޯ.?+ejD2jIp|}z/oM.!2{!Njj, zܐz' rBmuy*[nJJcPU?wTLLJ3nn*,gv۠Yy:$YOHqKq"~4{h&lY|jOd,xZzYlkDڧ[T4iQݲ[2G1~cH؜>MKV-Yf_;LnIնv@\.M6vIQpBr:3QQ 1 ){ 6=Gf@E"VlCU W0&UPEAc~u [)r^reuk=@^']ΟbmE[8曢19>hj8|MBZ)7 Hp$^6D!)ddc]a5<$xzW&@&Kת^$veD +U gʱzXl+T_8 2$-ez9x6_FS^4qT4*ӝ,V!D&xkn4߼]_zl=E"]I;:{ N<[^whѯ &8to gugV-d%=Ъ:%k"e;uI9 !A9IFkgu_ghy1x]F$d~%N/[Z ;}iڃՐY$cF֐\{\Gr7C戗\>"O]+\Gw( C!G]6AG)${MZ*9mLɺgfp ,ʹ1OkX>= c6鄢@2k&ꑺh DUL=oBJiQ]CrFwP鸃ͩ@ :̟bGz)?E66pyݪcfet+*X/$4aY)a |9a=d"& *q}i[M*l-n 붕q,攇>kh7![MU&ΞV?DWK m¸!'<(zeR0R!_ W"lM@em1'n$]U0 ,Bş\m [Fvv8Y,^@~X[*3qKDe%jmc&n؀L#\$ 28oc{O e 籧TLA, Z.iTH:.wV#.%Zv/b׫k='M8ZGpGie%@\Y>&-B7hE{1NqIQe"'sVH7ƀQt6R\ex1A]9A0Y?%rPT??K<&')iL~fSV'J۟b !YWmf:e+zu[`.Hц >k!S%(% O 81& O R*!-),`sE Ô{2FId#bf}f3䦄oiop癩BrGǚyp}j9#7p?!jU(I\sX*4|iŚ^ۖv%b?*g"ApBxck]ep3)!`߅џ? 83oxai 2ӐB( AiW -$I/5=PֆQ!y\1 w:[|TmnGbݠ8-CRL|TЊlx[ iD"%Iǔ,a_&ChtqƁܱ20Wm?ɗ !rVAk{Q<#xz/amʜ;P cLy`([@3^ub@"Wq~ڼ c82Z{%0H 6`[F!8y^6[@p0մ*}NU2\wPq prt!TҀOʗO"w_¼ rRV>Z%[p@dLS 5V4:A6{JV~D` aXc:N2'!)'_cPP$OJ w(Cnѭ$.37}WtCv%]Bj=UBfxI]g⻥:)'E3J<ڳz#VI[dAڠF ZgC;_>EdC!+J=?/ D,݂~kl)h!hU-nB0W?AaiC_lKw ;-='+ep5HG5>,<#4삤*) PnyQ5 PgP5Z\މKR$ȩh\܍ :ќvf!vc'~Uzlޭ8U0;W2R G\!V}_o(M=6bdkM\O@ӨN6hQ<#/v8Mf6¹0ZΖUjTG%v?`"Ew.FSVq_{YAcsQ_.<;7"NP;1+('5xr{Ob?GNt+B|@iT* 22V; ?rfxO=r'YO~OmXbSXAX \]DlrG rOo(b~Q(EL H|wB EA$ԓ}b{ߎFHdpq)v |JvMiE1w1-b,u/r ;':w8g}w :Ҏ}afͬixTYGtEk}$(:|wu>oL:L2$1)^*9vch dKviR-6%Ph9,,0Ť)*)5֗IÖIKQ{Xvٌ_RYYfH2ae$W ˂!яFO},,cP=0w 0͝/[z)i_ND\! Qc~OfhhºVʹ@^#]a"(Gn=|gE`#޴^Ս`"<;/FYP(Q#؝5u?un@K*JKʈh4 $PJ; ۻ5D&VbSw:߬q8bޞXL/ idr="ѱ]=BX*9'5G>/pˮNh~*}b:B$:iJd!}w2` 1,+P?F1D\F˙ÒJDѿ YZHU0+C#a~5m*Hn.=P? V>~-}+EsdCp(PX+kY)]LtgD_νk< ?!1Fi%XQ1c@%J4.Yot*VV,meY0!Y.;V@0N/d!Eɣ I"q+.5g~lHUtqNwΐhjpcєCqEeh=@AC9cE2E728^] M}  $5>/1߯-Qhabɞh"NG %w5 )J!cZj'u&}9<$bT!Y VrKXݦV )Z UJN 2I2ן׫dKl/6+iA2FA&CA]ULy&ɺ:@M1 7b-+h1K\̃+ @Ԍp [ҿa@L6Ɉuw՟ Or,7&]"M6uq.ʌGݯsZĮfd2x|چ+ >?HF9Đ&Z4`F3"(ugcaI1d@+>w4f'.c>̆ p%t0p9w(gӮobc;?! Q 7tB?(׳rR##gfD"! 4M̞*r5cL/"srHi zƆ'|^HpBT'~7[ G*;C+y0rƽ}NJyq+}DZŗ ›,8{!cjG} N+Pu7aE3c NdGeR:"8CL!Qo$ֽޓֻۡi I283+lD-^̈́vqpT#:} k'ToA8jSacS g81qrü-G!\gX3y0~/JEЌ*~.4/GHD'V*:׷Y!Rip_~4c@+Q30~[@ViQ wzk.~oN6,, >%SmI&ZY敡>qtfZ55t8lIN[E,kk\hvNeQq vRT|  c3{-Tb(D {xcqȩ[ Gv%S:ڮup _tCzozI|YgYG֢U~8k9*sNydaxh[GPJDSy33&,pBg.bHSKDPԝTQ;/*4M-L!yb+S{I8=TC[RCes+Z棦2?Sg\$g<4XO"Gqۨ܃U˳Qסּ Pj;]c &e>f &UEOOvtD<_%믓1\TDus u,ݐD>n%m x,ˠ5tBUIIٝ_1`5Y+kdH7#b&11cL|gEE| YUE0.]Yr'|-&VΗw%$_`q,QeLUPA"9Y_1M7W)hIlN[7!+x6( J]{5-8sNQN˝F 5^*lTf /9nm!s=0ʹT.XOvZ%UP{$f\*h퇈g"#vJ.mG)k'/7z>_0t-ήؕ>s}iiO!}H3R Kj [JwγAAPޫGST1mČSkt0,a""T^W(E:NX؊v-HJ2eFeP'Q =m K9,uBlvϩq@*9w, {->(Wh,TUV" Z{\,H*r׌66;'vS]q]PXmu ͍n |TE^ob]+pz/R1<>o[1NPP.5 =}@[W((ryHmZߎUeWwR1ѬM Ws |9fyC䏝mկZ;xJǙ1/wJ@Ąu.3,Fǧ^W铡Nk^ ˹PY?żh/y)\j~-74! 8,6;g/:M5`qBK &R$ʦ[pG28e"Phq!'-Ȗ܆ 49L;alQ~=vaxhX?fἊnm4Ҋ͒yqu1 Qn8d+ZƩ=G}xXhB/!K*ž* p}Y0gކGr%b$5D:Ith7]vz#[i;2'w]!RJȼ\N)W;9gf'5":\PC,`;QD?CdxĄGOMU`].ΐ.eƙПOôfŖ3+/ʢo +A5$œq [lԚ3cˣANj9!ǴDVW%&>1MAeഁ~*OkQ%`}f8qRE1``=Vn u)6_œl wS()ZPm6AvuUu E֭0Ѐ *Qevi!!&ו=1𼓲qy;{UئYܾ_L{A~CBMp(,}n&,Vrj BuSK pyl "0lyi5u,kBPuåfi7af#g! zбSڇM|ٍ\l%JYg hJu.fے~ΜOmiH)9q {֌K[|/J/FlPJ+v\j2UU۵= iʟxG7yHɂiRÙld 4Б~FyO5nU|o;iRnmKe^"7!|J ɗ\|(DsoC2%Noc6x_/0Q q"Ԝc{׸ns(rLǬo^|3XG 6g4"&?k9B[ pmfjazᐱND˜L@2Xd%J#e`c\;~%U+_ kgOV>1hGCd\UqՌd-@2-xu(VڿIh1+b͍\;`0v1$c!O>*6k Q~l!sx< /Zc?XY4d1z@]+(B~{fԡ\Ћ QNW)g`)ћQg2Y])Jng5&D9zuȻφO^zzvWrjG\ys#/B yݘdB)TJ_ۆ+8̆-%¡Ճ:_pW7X62=B|;q׺\t5MGG}^l]-ɿ>lM'ckCPQBV:):ܕ9qw٨E }J)#՝0U[s% c0U_%XN'׎?H|֘9&;2@7/QW,bʤI $tnX% 5սqΘ|JuRP` jc:N10:ciT:k;BBw7,3k[w uWy)1֦pqp ɤ?EP) աQ3-Ez ?G2w2iJZ '⳩V5"Q3 RP'tϦn\OҡDsܟ_e))QXPTri̛_Y=RJy6)J"I˳s(tS=nd1cc҂ ?|D?)m_[F!iپIi=B*y~ph˟g4PaYR[]|b^1p0'r`ImC;,g wk7+5\ڤvf(Xz+gΆZ[DÍցs57o3 Ӕ(s6Vr IZ?rgj o[<|& r팷F#̸avo[\AF#eD㻽=p,BC=<ݲ=BݡYN1߸dyGx0P( B0+~6_bvhRs<[Ϣ'C2Oz7} CWo8⭇?ck]iZA@(+֥73Hxrk1 K9ظ:eq.CÒsv5ź%D.>-]~4^5D|7o!~Qi„_ "Ut1z T=Cڇ=luQYuIH&me'aVC"I>Ņg{tڤy~3Lv?- Yڑy!Ga-РDc^˽!FQvU_so>U@A 7X2sA<@{@)Ko8LtL9|`cl#r{JB6- NQ -yrJƈj;CwxUE %صGس2|'ŵΗǣLRW; DhHl8FU zT \ /~}CogpRԊP%~ dE߅sH@}H ;"?YA"`fΕdB>5tdjI˚x* /cvq˝ON]6L1Qç [%9gΉ\{*'_8<5U6X/Yk t.yx+#W6L 4C;^eSro븾n"c%}rA1Qn]?|z_skdvI'쒎b Bǥ_cEUM΋zuw[c[&Hۓ?M^ a.=% oÿ_U4}P.5 v6IF:3 ښcaC1[ 4ŋȱ^y @RoO\ 1VwU*q,ٮ􁒈_UW НΣآm6(vRm "ڿϑ U(C=$oՅfL{f_ul^Qz_1h_=!sL8K:/> t/&QDzZG ]LΟNomJHUcKk&R قZ[B~4? cOm` :rǿ4r(h7Z6eJ X]|r6F(*'.6.3$T"PvIc1b9R.61xG~? ՙ7ŜPXU= vT 4 %t(Lpk5IE{ g7\)8]+RY^MȤYcIP E3θdˤ`4WA @C29Ej}ýb9MeiGh+1`1(OoC<ͮ\Htv9^Tm{ T|Ε_z?b i__>)',lPW Ś_՞P `!]UUi%S%-6>8X Vv }-DޒRx@fcL [дEu߱Fȑ,PEl)J$X}W:a$x?_e ݀D3'!lG{&mHexxOƭ!?|YNg+E%;2Xhٺ'7K#,oZ=q|T5@Ӽ&bn6&=~Ւ-:1U7$nI|}j W<mC̅{Su{?Rz~1s% rT0Q_8>mAkmhib2ߵ+]~}'*GZ>55IKUsc #sx[P-@؎R!&p@rxaHR)4a;!uAjV.sd/Ƿo9d/0eڭo2VTj!-m͕CG6^Dr:~EAx?7ѱe6@2?6ӊwoMMw!GizlrQ "nOn  "nx 3AJVF)4vi~2맆@2 G U]&W,*uw,!Ψn$t2N~2Kkmd -렬P!byྨp?U=OPR]\*4}K ^ғZOpZdiqPodw ES#fri!4PT; jr)S-ߞLsw:E52cV7\oL _/fR^q?oU6z?/itP39 C,a 2B٢}vD@og'2%\A)PӄR=$"92Ѥȶ^mn WwFɐD;Be|YL,8.jx[oqY|cĖRNEn3Nn5}K[U{CS a8@5R^݄DWVV>(~P67cɣKRLv ?]%IvFHbjgq( BTEzi7ꖋqѡoYADS( 8GvxQVD?o]{mw`jq"܇SՎ @d0Pyܻt2w` JM-N@F`׉!'pk]du";Kvux̔ 0{ukK PC7@P6Yocf\4R 4Ld~vm:̊8Sw,y[_aU},k GLC>ބN>8%/nәz`%x(hVW26_S}Jǐ2d;:cCdMxd8Ua ,ܾe~]oy4M;']ȅt vKCrhn]h-;GS.{}[6NްNޠl '7pZm{̝NtCN<$PJrTr<2Sf]~g+%ë|E0JKOז+,!?Q JQ0/ ,joB: )ZZ+)HEGwx]il{aj{0  _kx 5F3=Cw8NVC(v-`9-& _M'xT~E8&D'~vNKZ) j݀:%b6->»@yt{u( H0lw}Dh<0> \56t׺܀7`u Vf#je Rf#a  R'c5(Y2tÌ~6[8Kin;|D"ﶚUӷ4"znU#^ȈN<_g֭vzyh<]jp ^!^vp?͙ V$:& #%;'@<=[Ry*uc>4Ar{sWI 2RMQYWV({O>IDp*N'`ѭ¸{# F䙔JdCƵ&Vy bkmtO^5sYyz6>{ak{U'7@E=ފY`. L^>bBZ$L&6tR] tj)\obt7~I<Es׼W/1'ZxCnVA1M ՕU2>6qNIaȆNN4p@L0~LpvGrP]U^3 aqwt #m#J7͝-}^܊[F jˌuTpf]P2CQJMȊӲSᕑ>W,!qiIfm)iʡ: g,mϔ>3Z_l*ӷҺbM.l`(0F-pڦgX5j•/Mװ` )6tclq/X74OKʮvmvXb+p$Ihkc_0}R皙 ]|O.y jr6Q^JuȮ6OE-k)a!)#bbZ-`)[)t.bnx0ohkI*O(kpճ6YO ҷ򺩊MLQC(*dWj^"\%E2> c2,D@>}7ZQei菌<_#ͷ$. >2Hgu0Oz6Nm˒SqKyydIY0tIJ[uѪэIӞ`3"gF6pwv\3Jj@b7W`a%# Payy+< & Q'wPp˨H`=P' Mx'S}MPzQx)+@ښb9%t8p0-E,Pu"6;CA=S3d =Rb?l`o fE{ BF..I-BlLU |=O& ̌%|#_|/Dݮ`Kw%?ޛh}8mB#m)=F&nΑSU[S9Z>sbT}`&o=%bh_ 1KCcE|MӻJ! ⨲bL5k_I=C*lϣ-vy87u"rTR[/̵{({ AwuK(i4Ѻ 5y i1a%gD\ƖP4e)<{~QGПa|,ԫ4pT=G ⋔]k2C< ᴸU,xŮ Gz|]vX7)(mԔ&yƍ]˧N!#/U:A.S sH~Ē~'W/ldqD ;o}; $7W8(&#J~MA>Pb (1D["X"+O+q]9Zel!?%Ԅ ,T)[6^ĄN-"jvAWb/_t\չK{c% F#=4PѮᲔM KfC8 "422: #R UilMIa ybejuDHz b Ļ%sEUxYl7O?j1W&cUu3409ٓTIn AmӃp;p]vE ow"`8fs%{\ޡ,F.;p(P^I6ӿRtl0Sη& z?zW1n|[iWCVP(mSq a^ /vc c W^Ur v3/L?rH:Ҽ͹Z{XYd*>AA4 NdŠ͆fW"ӮLFTxoڤ"$%n5q]Ln0D"-9D &y! SYsţYaFY'-ᨻ-=Nm7(%Y&Qj2w(6QA 2qm6JP>v>EA ˡ&9PDal>I?}11ƤUR}*XF]cܔjAw4 CH;se'62*e˯k6\j`ܿŹ:}3!dٟQ7*y\lA]Ta}U.ĵYj\ICf+ԲObCF$DLN2`Z%_=\/D2+H $@Jg*;NqddC~4@v̨20 O m )jS&iI DgJIRTW"M徨RwUڿ|ky R3Nz07Tz+jSHJX{okT^x쇭?C8nBH$YV\Ki V5h[sNԿ/+{72AM/juegfTfxҖ[6 UKuHrf\~HpJ-0d,*^-p>Xj\jFᩯX뜶}bՙ{#ƒ#Tn9>̵($4(c)6Rl5AZ򛢤*Ga՜ZT.,l& \6;5̀ZZN[^i!T9; W6j?pI|<2/`c]nrEIFt2J1Jk.Wk.~1k po?ezw20;Ҍx-^x, .lu0a0"+gRgUf=<тy nŹ'8;[z܏7rZnP{A "`ZL~~<(95 ̈b Xԫ#ϻU@}x["D1V;*wc .zڲ'A]馚{;p}S[ʁtJNda~GE% pylpKJ"f S2, Ґ.VxJ\.K"Uz4sH mb-{VԶ$U+O|> ǟ8|q(DFۛPGWD6&dE޸lK.& c`\qzfA޸+Y&& 1+J76.Se*οBUP>!0o{isb36p1pAZÁ-_auC{Xji+dh['3B pS8VtW<ĕW vA4Cnnb`'H|?9Qzȸ>up,CHM?_V^@+o5x;lq>φ^|SiB|9[r0^g)5wk{87@ǟQGÖV{/5m`1O?t |8dY} MX:C%ۊ(^~#oh/G˲jSf唴  yK`k.V&#a`eY Ko0䆩`]ZH}H"WVp̏6^|:>CGDg>]ey¿ Ihp2&}A󷑆u0Z94_cM=P!r*K̯+ C0HeQۉNYz4hQ[>{_Eb3s/X*:HA x AJP(`5R2:<ꆲfk;gӢ5f \O2M(:J"L?Lz `$SbkZcCrEI Y"nS3JY9PѼR: '&q 44M[KKv+!0Kݻ8&uỊpV*ESLط'/'hOpFn69y$; ɯ_: g|Av~r&ë}h#*awIaʳ:oG,>ėZwW#blե؀{okw 8KTw!(#?R)_b:Dv4h )()ʴOڅGTn_TN Sg΀v۩:~s5krgE lrB- eRIp8[nRhA߶M tkze?T}dH_RѪ4C@YA,mc6H6LXZC j^I 4!g4; :Z, %@&>:fy!A:3s۵)%Hl\u|I=(K֐>P kf0-7v\BzZ͐Ȁ-PPF݌2҅Sr&,c`jt޷y4{<%rׯ A~vF` HˡӻMXj z7dI2sS{R0D3ۏ2!^iU)n~G+St:Nny'BQl*~C6Vퟚ$3L~u53I: uF\zPvMSSzΕ^ nXv/.#:^J/54~?iN7PG ꡇlM&ljb"i{4G\6bU+سc뭯w5\[ׂwW9s<ϒ|j!k3?pȑHc~Ĉהp{u*pcv|OzE> /x2o\,'̖soӂZ)im H)(Gam~jKʌ>0g6V1qOy_YoN>''Q.ojPvf*'~֞7da9'OpsSQV"ӶF0d XUE3 rK(~:K:7.cHvL%βU]zUr[7D2fx|m[ sĠpUZV<\s&͞E'r"L)9,Yδ 3`@/qϣ `26K3_6B'NǚihdC ;Y˲j ƏKghfʬ]QM[W嶬堁Ӳqxx _2dY=iN%-myD 6{_ ډ|^l|>OF?߅! .cQCPߙP9ÏLFK禺TdUtx ΢7&5ZYТyY^xxD.UntRj-js-I=&-Qu`ԡHi{J=N)dS37+GLOO1Np/`p 3(ʽh&MEN~I' iI/ N9(?(=!+Z<9ͯ( L_æp<gr̨2-2X2g*=wxڦ1&Y"w::;EI?/Qa rS'+u|ןl vPmg|El0i·69naX XbE'>T6ΘR]c {""30bl"5I4v[~_p||,w8j[%E.|%Xa%ﴳW{:fL~h,VȨR06ߞqmŨ5ODG(ZC]s|`Z_aSfc2C5oUJ/Hsյob3,$-BWd5nžA{# Tx9p&:IU%ɺAwm?MR7DG,Q:8Ph0c/Nun XL>m-@^ߤv*j/ӚvkQԚyi.Ni65, Mډܥdd$QӼڏS.p(^s;dʾ!Nr$r's' Jr.X.nܥa!pS>G.%UfTr&լmO&lb.Ĵy7`ehc@ N?F&n&-KQ?bQ o5}m e0PTĹX3C=.[iK@u`#!k˳k@ We̹Icaܕ^2ɕj 9GuK9y+y=x-ǝm/l+8F^xxjBmdPRyb=LTt  3=]_vOʾf2]3@TA_#' SY?ʄ|ZГM:ݿ*QsQ†#zsfxRqh<ɤF||vӴQx (2lq"+Z יY<+HBPw#Z㼅z|S+Ѯo& +F/ԀS L,.AÛFT3I<'ht5mRL1tDSi~nE=Uqp1#}7y jFb!gq)Ag" DžNz,a,"s c=$\\ͲJZ'8ܵ;t#ݸ# <\˜lINh7ΪVDt6 х`c=S.ƹXL1-v!e?@%ZMZ)-h1.Q#teP)zFNšrL?g[c/M=14:vR ޮV잱*A"{^c &#Jpy~xw3!yR,eį7zbfݼ_Ipw"gB v%ĆK:'hU2dPD C_U ba Y>$rh%MeT#+:eAcHS8FRN8Zԡ=\TrՄ-AJW߆$ػ6;YS,~lN\xwG!ĶEFt͝P'5vPƿQoQXA*rmJ7sqؕhL׆wM @ݝ-}v0@cA9nMԇ ո<:*/_ɤ ߠ56̙+S-b㿲?=+^Eh[؃(S Dx.=Gi>7ҏ:ee/ EESpB}RP`z٬rHE͒3ɒ`.|c)iE ɵ@èUlƌ7 3C }yͣ7 dl"oU);%וoԆ͋c9} mXXDwǔQ;3ᰎUZASQM`h?.r`yll"ʙRՁ[N~]lt_E PoVzǏoI0dlXl6aTm FWcBMmFOr9m|eyrC)~.,QrjPUzw ej~O&e}&i}fnlxw+q%[T ] $xQyYa]ύûlxtܢp#gi`0Oo 7~}S67֩ӝo{(]^D_}$&b9^G¦,= #nRn{GxL :xǜfl&p5O6Crkt!f^gt\u 7(׋9;cΠׂr˖ҌA?`RI އ60f\:ru%AjXOvFdv)KXT#, N׈ѽDbUR&Ϝos̽DXC:,^PФ#2p##St]/|y)םv-# ʞKzy;)>`5ˆq= H?tޏ@/~LJXH1H! E:3h1279Oi;@- devLNwX$/ dݻǖ,ӎ´X*]W" cx1-# H 5,1RU/*缜}K4@$ݯ;C)IAE}@vJ8rc~MyL {:}`ixj\;z-ӊ܌ @Z إ+XyFb1ޯg82eby,_7tqc?zL"6MRD_FVJ^ȼ}Y z<)%{)Q* {bjq6i蟱Zڿ^iԃ*I4G-a)AջBl9`6 w^F'1 \^ժo.}כkTQ-V![(<;dWڄ0ͣsv5L4.eWv$rI0N6"LRҚ*^?6kF=\)T|7+)ͼG'jz( NMM;_Q yGγo0(ਵCucУ,TO/ryl9f53{ȭRX[D=XQK0yR@o5`z7_m?Ҁ81JKDVemN'x¥,X?)u/ -q4lډoՔ;Bf iF7K#Vԧ d7 (UZM̢ WajS:83n\EcV$YGEvkÇ%S+YH pk2>2?Dͩs`=#ulޔ᩷ |}D3 g9ebCAN#Hn%8$s7\Io(n 5}Ob@JaЊKҀu(Qgas9>&+`ؼ,4|Yd^1PHMM[ݐLLc\p+TwLrzf\!Dt+]ia"U8 ] E[f0]A-[ȰTz&9$l)ހG\v_~&&WgrvXSȆZh$ B`Aõ$4*$-T[ưqviQ F6 p,T^$;(!1W2Rˆ6MRp+{0|媽}[ӐCxBf^K^L+LIr M|N8Zm1ȢSWfFfW\*ʼntbd[S(fPہ<껻n_vKmМݼU^q# -(}؀wä&'G꥾l>(ـP C{ԁ `o LE o=4Mwo9Hx}Hz k TĵA3LN{=ŷy26`'X:TO?0}4#._ēM-͗YU2hSqἻa4cHa_ xi&A}$ӊ/]bӑ4])Hn~q_эFk3Nʱ宛V]bjFKĝ)3L;g(%krAPbl}Mqh7;0XZ0 *T%ޛ[k&jǖ/MRkbF#W~KGdӟq̇F̍x:3#HIW\ݐ ~tf|84QzUlMB}<: gBn=?miؾ+Wǟ&gctAK#ywvk&G&Dc}ֿq ӮDe㒈K"tki5hՅSUܑ#.!{-wdO!LJ3] ) O|~2Hlc.!9A xzꚬH\kJ?e7UO#FE2 An^vގP/!1nRL"X#o0WJS!1xb5%]ԩ֘nB)cfw Xzh/;}#yVv2J:sMSߩao% qONzHidX pĵu5I΅i` G`mEОȓ槨~+>y)c=a 6x륢A0PI@N!"d2`d:!R%0c'4A8g$,#FW]bk>L ->F*n講(,Rxde24g܇;ݔjw>u@iЊ@!ok k\(ەR64|KwP;g.#>XI=Vê/.!|OEʔۜc zfMF&!N.{,ؐa1,)t|DaQ1)3DEv ڠCϝxX ;PR:}lB%8ɑ/y^&aO=Sk,IuDHL;ёg_#INa:j1SxGz)ڨ|ǤгBxTwx3:ꤠܼhP W!~&T "O@`;.]+CqnC)eúDhIJow^Z|31ɘɾ5fTJw ^;B vFOr̰P൥FpAB)w%.j.^ֺt*A){̣.r- :O^ 3 .D7gEVV/ kr;qQ^"xPGE:{7G zr-s3v]%e8Q fKx\Ruʫݱ{Fu p'.ͤ+gq>t\^Vbo(]W0BP5duiAD\~P"zY*W 7cy2. aG;f{?%w>kړLS)\cD6%V彗 ՂP #RE|i'eT^U{!#odwl|`siJ2 $۝@eL٧'N~A~R!]6pO68: ttI#pس+0C~DƓqa[uGޙc92|@@iв]IUXӥdܬ[m@ G$ !da;az}¸L o}+^C {gm r-?W X$& @7:ڵAR-%ƦU2:#דk &ЬZco8X̣HkΤPvBRʝN,%let6# $Sبq3OGI9HnYZ/ AWlmU(`lM#zTL(&%W{!Tʕݲ;VS a`Km7 /JGEl@3+Y٣KV܅<'X{ K%J{[rrE^I8S/AYݡw 88=V"˹>n:4t/ߪ;t+&u>EHV5bJK" 4ӎ-wcXcu۩_nT^ef?pXp}me?/?%<>) `m ҄+=zi?@bBVWuOpɮ´N$?SU,`4(x9k iHSSX 7 //mNN6(+~KK1%XDjRt*B#{8xy+ApM᤹\6qٯ, D~uYogNomB(|iz "ŢYiG^(ZkDŽKuoJf YCAlSM]ktFP·|.$G>1U{ Mv(p:Leڑteϓf5Md5sL}/4Wf슴Pkr2bKmJR G}-=:bcaEwc>G_̳"lDE7yLSVfKʧY@wo/s`SOͳ{4#,ݛTY򌭿K Õ"{n@«*HE@̉3`T'XC+^qYvĽ -ٶo}l!K5QuU4!b'_ 0op4{ݥ^!f[jZx&{5doJlDbڪu~^M><wG0OwxRYrXh=Їtct,LF1]zJnرgN[&6g'_I6JZ&srNhCkCM0yYh;&ZBt_9Z&I,s;D D;b0_ B&*My?$A p%o33hiMcm绕]<]N\YXVyi2+T'[HxyDqk]MߩۤT}Q%[|΢l%U/0RnkɳgXY>ޅM3GnZ#(֐"$$=@> Vw~B " K4 iq>CM1]HO6 `$S_{DF4Kq8ȏྡ1/YmQT80E`w9Q>~_GvIPROfz(: <෭-GWsv! gq1>!:#vmB"Eb+t1J܃FE\WN">b+$ $` ,dIr0 5z٭qWmoؠf޶VNǛB5vgͅm&U4:RZ!N#ڇ 7c}*aVveMLs,JOhR9?"*RKoU ݴבUYwCjy&EHd9ʉY_&Uirz_euzA#D!Up` 1HYb^O[o.f==@ư^v35vf)Iu0^(ΜWtW~*꒮,gݓ e`ł7cr_2֋zIQgL:8@9C&/,aVuxh(W=,8F@Ñs+O܍\y?6NB1c`s I= AwF~PL)\>(.Hp6e<4n-SG3hjD 2.SJU\ >y+54+oꞩU"(rrecFzꚛEN/3S)l xY@xT6ω.g=Gb*Րf8 z 8*_~qj! S6v߾> h-I&~\JFT9*n*7\-}S l Aj߁?5tBab<7Oi'N5n܉FKfed#r $VHB!hH7OӞqh^ҡϹk$pɩLMJ:bt:?wAiJhB\ԣZ{_Asv[(BymʬIVjVZyԞ bTh $2id`|fiPvNpMca>/ʈ `$ktShވQޠE4_UQƨGt1p߳d9< ܦBC}8Ջ1ZxU|(ysP+ D<Ƙࣦ Q=5hmdW1cT˩5iV'k/,l dNvCɣ'"ԯ'z@FDR9*f?t4p\*oYJ¨KR. abse2J`IS A[NtfG ,o"4e =iAX F.TS߹ @erFŭ^۬aIwU= 7G $Ɨ %3m06ȭ]B6mn^FXY4wuǫ>[>J/jIfi4xsFnCmuz)[2Cq1ُ޻ hjmRR) i/98చ΃n!?:u? Lƻ+ u"gU&iF?K-`cet#+ CDc,Q TbCK9E_"tJzd[n-ݿ4PۓŁQOzϜi@#XݍV(~ xqRY0P&Üv ͶAA]|@ʪliX2Q?l$WcxL)5%AEBI5V^8m1 I0(K >9tivHp81hjT0$r%/)Ww{LK091`N5nhRgT06wa#)Lm%:& -mc%l{N,Qڴ 4f0x{!SAG'9-Go.E4ԃ.2CG= QMh{mIz"c]~ZFUVTCFsΒ_'ێ&W v.Yp&uVѮ'Py G㹥V5ѷ`=k[–==$one:e~9Q$8aehB5Xz3[qs#9e,[ly qch{Qn$A aNl9G3MZۄ{is0=0`.Pu10ٮ|1vuNܥ+WKaN X1o}!bgG_,jl_yKD$:|sQoӏg*ZԌo, %o4z{.̊'[ܔtN ] p$" $Pq_"1$zx:}hPl$ţ5#0ޮ)k!E\ iPY?cھ[CY<v.LM]-Ddhg`EBL;'*16Eǩ$jne#ڇsQ ѡ ƞ2!7@Sn+)qa1IC2VwG;5>GZ؄ԁ1-*ɓD%~6/4(qTJ6n:e#1N`xjH:nqn)Z80 k f7GaJ_E[n@ۈ}'c$a-ʅ<Go%c2MB'Ko;QJ-RPNHGРzoG;N c W5Fz~&a9e9{'26>+ {Qif/#Qzb10%X-uOU9!CtU51%'E9ZB}ZP>\U$ өY *\$~;fFi:GOS@w,cWhe,,%$>! pʋF/ h?`T~:cq Hur}1y3¤x IĜfB{Z[Ė8do˽k`;npOo/-Où P?#滈QܩV[k'37i¡qmR}4)8l?e[uᖕc bF ˡw DBr,O*ܿY{`VȨ%n_ 0mU__9~ĝws2ͰVb%< }R<]բܶfdM:f0"Ifہ7SoyZo§b*6尊isAqD':>Cd=^2 rï܊MIRn/i),7"ς.xZ06. ~wK6OX*.Thhw ..z5#v+l>B"ܔ< ;0B 6(b fKLVF,V gz$*=MWMLB&Votrr p eI ޶ɔVvSbB3 'zzB'9LE>tVkNX(&.5T:rb ' C,r; ).Hc|Nu0D4ok|l]Sx *2 Y(iX~FElsvGh_ 1쏆~5X,EsHhM,=gAT B$bτ& K`œ\F (gI&ʱX11[h/ktm-"C55y͕CzįհmX.VzKw"|_'VlrE&&Lua']U?l>ׇxv(؊&fbv l%BL.mVИ' Ir?yK(_oz` q:,7&hhǿfTkNT tZXq>PO[dƌG% *◶{2E-.)-km0P߫d)<}{,J·u$u"53Gͩh tb6%rgٟP}ۙQSZ1ȇ cy4  + {˶AA%ɣ4f8 3m[Xu WT#DΦw>-tI@ߓ+^&.=7P +f6-,2ʼJ5}קf l y\*d1ߗS' 4φEL_I]KgCLWmH9x A@xϭ0bX,Bn# 5bon0kI}mPz%ASJ nOaB v=$n7i:9[X)$E qE=lDG rxWu 6}$L[HXItNrmy|\ ASr< >_(=o6c8N͏r1'=胙D5ؔԱp8yV*< )O:,2qIRئn#Azl`|`k20xW7cO;'=64 ^ oVïS7m+v9P}lJUp;~ {eR_[7Õ揌VlgwⱺDsij è.b~*XmJubK^pG*Iz}'%NFJJhmm^y|6v+K4gɫzO.$BmEvWE#+qWWx*%#.=NI8Կ$vRNO*Zu4Rv U2 )—Yt1h'o tPq[Ewہ`A6{qlBu1P'F+z%2BrgLW J+cA0v O)eE g#ׇjQM_q,i8`)ߡ*&_(Xۈܦ;q;p 9eh:ؗcW KDt⢂.6y̔ą}*$aR Q$X6/gfOm{9 2uz$pߝF\>XG!-<(poVknR97<u% 䛃H>\4k,)QY zGqܲ~Í2$s_ƲVdyQILupfWHLZmC7#4xWՌ$hxdǠƐfJbŴD&ESXr*lѫTGm+?(t}}a(o{#~oOŮ#t%/Q y7N<Jd]ruTpĈ ,Qg6 *9N gCPD5 So# QƿΚ9Mb% *殑;hGh:ȰXZC*"\i>btDwHe81bs !.)xۜ@79gP=$,qc!e)SeDe}XʬrGmoϼt"mA511%o63sZ LZYT47'dYR?Ψ-oж-{*6K􊶧#}Fsdnjxߺwl,;o ?CsڪbK7.h=f_YȼP -E,&}xr(E cD{h;6#( {kI YZ