cifs-utils-6.5-3.5>t  DH`pY縋/=„`v8qߡ]~l׋O33wP)EdWyZ]f0;T288ta;,-+iUAf0S`Me$8T11]r1eƌcHh`o.)gJMs.5P,!V.r0s ݄] [BǸ>Σ O9H I2,g_)3{[:zW63e1c57bb8697f32208b56aaf33c97f1e8464cdc=Y縋/=„x3z8]%a<7_ͧ.=?d   Z %QW`  0   T>D  ( 68 @9 :BFGHLIXYZ[ \]x^bc,defluvw x\y9zCcifs-utils6.53.5Utilities for doing and managing mounts of the Linux CIFS filesystemThe cifs-utils package consist of utilities for doing and managing mounts of the Linux CIFS filesystem.Ybuild81openSUSE Leap 42.3openSUSEGPL-3.0+http://bugs.opensuse.orgSystem/Filesystemshttp://www.samba.org/linux-cifs/cifs-utils/linuxx86_64 240Ix8 H '8pxp >,2AA큤A큤AA큤YYT;'YYYYYYYYYYYYYYYTOYYYYYYYcbfef7a649eb150e974762ed143723044c95734a68b45b65a5dc7b108836427bdb5289bad3063aea58e1814380259a28d41d8cd98f00b204e9800998ecf8427e84780313ff943ea4c4bf51943b53a81eb270ee5f0c0a9a769c9476c3e016fdd06c85887eb060dfc3abded73fd8b857da49d95197d3d92b1453f687c6976903f6238f50c6d591498337f7cf3523b85ba9bde8999cee0d0613e40df709bd60e3d9c234b1b75ce87f3f4d7da01daf7f5b292f73e0f7bddfe997ff32fe5a56603011139243eb96cdee5314a5aa65447c2d0bd4c2c5ae5b98a556bd98284b16e9b2738aacefc17446524e6adf56b5d0280ae4ed78bd0b331a6ffe4885f6ce28077e231f4eb939d9b5cdb3931b1cfa43712238e111c348c722510468896b725c26df865192b0a7da847e49014e6c144dc2f9ac/usr/lib64/cifs-utils/idmapwb.soservice@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcifs-utils-6.5-3.5.src.rpmcifs-mountcifs-utilscifs-utils(x86-64)config(cifs-utils)idmapwb.so()(64bit)sysvinit(cifs)@ @@@@@@@@@@@@@@@@@@@@   /bin/shconfig(cifs-utils)coreutilsdiffutilsfillupgrepinsservkeyutilslibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcap-ng.so.0()(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libkeyutils.so.1()(64bit)libkeyutils.so.1(KEYUTILS_0.3)(64bit)libkeyutils.so.1(KEYUTILS_1.0)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)rpmlib(CompressedFileNames)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsLzma)6.5-3.53.0.4-14.0-14.4.6-14.11.2V@V@UpUmT~@TO@TO@T;T;T@S<@S;@S@SkqS*@RUE@RSQJ@Q,Q& @PP@P@P"TO/@O/@OȮOȮOȮO]@O OO@O@O@O@O@O@O@O/O*zO))@N@Nl@NtN@Mv@M0:L!LV@L4l@Kj@K]K @K\K\KKKP@K[KKKK@K@KK~}@KqN@KqN@KqN@KqN@KoKoKn@Kn@Kl@KjK^@KUKLd@KG@KEKEKD{@K=K;@K/c@K*@K'z@K@K@K@K?K?KK@KmK3@JJJ@JJJJ`@J@JH@JJ JjJ0@J@JJJ@JJ JzJzJt.@JmJ_@J\s@JT@JT@JMJL@JI@JCfJB@JB@J@J;}J:,@J8J7@J7@J2C@J2C@J,@J'@J'@J'@J+@JMJp@IIIo@Io@IԨIW@IW@III@IV@Ilmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.combwiedemann@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comro@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.commmeister@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comdlovasko@suse.comlmuelle@suse.delmuelle@suse.decoolo@suse.comcoolo@suse.comjengelh@medozas.desjayaraman@suse.desjayaraman@suse.delmuelle@suse.detoganm@opensuse.orgsjayaraman@suse.desjayaraman@suse.desjayaraman@suse.delmuelle@suse.desjayaraman@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.desjayaraman@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.derhafer@novell.comhhetter@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.deboyang@suse.dejmcdonough@suse.delmuelle@suse.deboyang@suse.deboyang@suse.delmuelle@suse.derhafer@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delars@samba.orgjmcdonough@suse.desjayaraman@suse.dejengelh@medozas.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.deboyang@suse.dechris@computersalat.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.deboyang@suse.deboyang@suse.dehhetter@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.desbrabec@suse.czlmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.deboyang@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.desjayaraman@suse.desjayaraman@suse.desjayaraman@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dero@suse.de- Don't ignore libldb, libtalloc, libtevent, and samba-client-libs at build time; (bsc#966174).- Update to cifs-utils 6.5. + mount.cifs: ignore x- mount options + minor build fixes; obsoletes include_paths.h_for__PATH_MOUNTED.patch + minor manpage fix- Ignore samba-client-libs at build-time on post-22 Fedora systems.- Add include_paths.h_for__PATH_MOUNTED.patch- Use rccifs -> service symlink for proper status (bnc#908023).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Add README.cifstab.migration to document the cifstab removal; (bnc#902947).- Fix broken rccifs symbolic link.- Remove dead code associated with cifstab file which is no longer used.- Remove mkinitrd files and spec file logic. Dracut offers cifs support via the corresponding module; (bnc#893575).- Remove cifstab file; obsoleted by the more generic cifs credentials feature.- Update to cifs-utils 6.4. + allow PAM directory to be configurable - Make_the_PAM_security_directory_configurable_at_compile_time.patch + better determination of default keytab file + better cifscreds error handling + uppercase devicename when retrying mount- BuildIgnore libldb, libtevent, and samba4-libs to prevent a package conflict on CentOS, Fedora, and RHEL systems.- use _rundir macro- Update to cifs-utils 6.3. + fixes for various bugs turned up by Coverity + clean unused cruft out of upcall binary + add new pam_cifscreds PAM module for establishing NTLM creds on login which BuildRequires the pam-devel package - Make the PAM security directory configurable at compile time; (bso#10513). + Make_the_PAM_security_directory_configurable_at_compile_time.patch- Verify source tar ball gpg signature.- Update to cifs-utils 6.2. + setcifsacl can now work without a plugin + systemd-ask-password is found using $PATH now + cifs.upcall now works with KEYRING: credcaches - Update to cifs-utils 6.1. + minor bugfixes + allow cifs.upcall to use dedicated keytab - Update to cifs-utils 6.0. + minor bugfixes and documentation updates + support for NFS-style device names removed- Added url as source. Please see http://en.opensuse.org/SourceUrls- Add cifstab named configuration file to post-12.2 systems; (bnc#804822); (bnc#821889). - Really use of the existing cifs init script; (bnc#697218).- Remove superfluous restart or stop of the cifs service; (bnc#804822).- Set parsed_info->got_user when a cred file supplies a username; (bnc#800018).- Update to cifs-utils 5.9. + new plugin architecture for the ID mapping tools + DOMAIN\username@password format for username= arguments is removed + full RELRO (vs. partial) is now enabled on all binaries- Version 5.8 * NFS-style device names are being deprecated in 6.0. * Many bugs in cifs.idmap, getcifsacl and setcifsacl have been fixed.- Update to cifs-utils 5.6. + -Werror has been removed by default from CFLAGS + PIE and RELRO are enabled by default at build time + better integration with systemd by allowing the use of /bin/systemd-ask-password if available + better checks and warnings from cifscreds when used in environments that do not have a session keyring - No longer initialize oldfsgid inside acquire_mountpoint() of mount.cifs.c as - Werror got removed.- mount.cifs: initialize oldfsgid to surpress a warning while building for RHEL 4 or CentOS 5.- mount.cifs: set rc to 0 in libcap toggle_dac_capability- BuildRequire libwbclient-devel for CentOS, Fedora, and RHEL builds too.- Do not call autoreconf while build.- BuildIgnore libtalloc to prevent a package conflict on Fedora systems.- BuildRequire libtalloc-devel unconditionally.- Update to cifs-utils 5.5. + mount.cifs: don't pass credentials= option to the kernel + doc: update mailing list + mount.cifs: don't send a mandatory ver= option to the kernel + mount.cifs: remove smb2 multicall binary code + doc: remove old XML sources for mount.cifs.8 and cifs.upcall.8 + mount.cifs: unused variables- BuildRequire libtalloc2-devel instead of libtalloc-devel for post 12.1 systems.- Don't package get-, setcifsacl, and cifs.idmap for Mandriva pre-201100.- Don't care at all what the real uid is when we call toggle_dac_capability().- Make use of the stored return code in toggle_dac_capability() of mount.cifs.- Declare krb5_auth_con_set_req_cksumtype if the prototype does not exist. - Initialize bkupuid and bkupgid.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- mount.cifs: fix up some -D_FORTIFY_SOURCE=2 warnings- Update to cifs-utils 5.4. + the "rootsbindir" can now be specified at configure time + mount.cifs now supports the -s option by passing "sloppy" to the kernel in the options string + cifs.upcall now properly respects the domain_realm section in krb5.conf + unprivileged users can no longer mount onto dirs into which they can't chdir (fixes CVE-2012-1586)- Added position independent flags to compilation and linking (-fpie/-pie); (bnc#743133).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems. - BuildRequire keyutils-devel for post-10.2 systems. - BuildRequire libcap-ng-devel for post-11.2 systems. - BuildRequire libwbclient-devel for post-10.2 systems. - BuildRequire samba-winbind-devel for CentOS, Fedora, and RHEL systems. - Add getcifsacl, setcifsacl, cifs.idmap, and cifs.upcall binaries and man pages to the filelist.- Update to cifs-utils 5.3. + admins can now tell cifs.upcall to use an alternate krb5.conf file + on remount, mount.cifs no longer adds a duplicate mtab entry + the cifscreds utility has seen a major overhaul to allow for multiuser mounts without krb5 auth - Update to cifs-utils 5.2. + cifs.idmap can now map uid/gid to SID in addition to the other way around + getcifsacl/setcifsacl are now installed by default in /usr/bin instead of /usr/sbin. The manpages are now in section 1. + cifs.upcall has a new scheme for picking the SPN on krb5 mounts. The hostname is now always lowercased. If we fail to get a ticket using an unqualified name, it now attempts to guess the domain name. + A lot of manpage updates, additions and corrections - Update to cifs-utils 5.1. + fix for a minor security issue that can corrupt the mtab + new getcifsacl/setcifsacl tools that allow you to fetch and set raw Windows ACLs via an xattr. + a lot of manpage patches - Update to cifs-utils 5.0. + mount.cifs always uses the original device string to ensure that umounts by unprivileged users are not problematic + there is a new cifs.idmap program for handling idmapping upcalls + a lot of manpage patches- remove call to suse_update_config (very old work around)- add automake as buildrequire to avoid implicit dependency- Remove redundant tags/sections from specfile- modify cifs init script to use /var/run instead of /var/lock/subsys for state file; (bnc#697218).- Update to cifs-utils 4.9. + mount.cifs: don't try to alter mtab if it's a symlink. + mount.cifs: fix possible use of uninitialized variable. + mount.cifs: reacquire CAP_DAC_READ_SEARCH before calling mount(2). + mount.cifs: fix handling of scopeid in resolve_host. - Update to cifs-utils 4.8.1. + fix mis-generated autoconf files. - Update to cifs-utils 4.8. + mount.cifs: manpage: add entry for "actimeo" option. + cifs-utils: rewrite hardcoded paths in manpages. + cifs-utils: fixes for manpage pathname replacement scheme. + cifs.upcall: fix memory and call krb5_auth_con_free(). + cifs.upcall: use krb5_auth_con_set_req_cksumtype() and pass a GSSAPI checksum; (bso#7890). + manpage: change port option description. + cifs.upcall: add 'l' to getopt_long string. + cifs.upcall: fix crash when trying to free uninitialized var. + cifs.upcall: consolidate find_krb5_cc calls. + cifs.upcall: clean up key description decoding routine. + cifs.upcall: add keytab support for unattended mounts. + mount.cifs: add cruid= mount option. - Update to cifs-utils 4.7. + manpage: add mount.cifs manpage entry for "multiuser" option. + mount.cifs: reinstate ip= as an override for address resolution. + mount.cifs: use monotonic time for timeouts. + cifs-utils: infrastructure for stashing passwords in keyring. + cifs-utils: moving resolve_host into separate file.- Move the cifs init script nfs dependencies from Required to Should.- corrected #bnc 641513 by adding /sbin/mkinitrd_setup in %postun.- Update to cifs-utils 4.6. + adds documentation for the fsc option. + mount.cifs deals with the _netdev, mand, and nomand options correctly now. + changes how mount.cifs handles the MS_MANDLOCK flag. + makes cifs.upcall prefer the creduid= upcall option to uid=- mount.cifs: fix parsing of "cred=" option; (bnc#618877); (bnc#620856); (bnc#621525); (bnc#623763); (bnc#627243).- Update to cifs-utils 4.5. + strip leading delimiter off of prefixpath option in mount.cifs. + remove magic number for max_username in parse_options. + turn into a multicall binary for smb2. + fix uninitialized variable in cred parsing error path. + cleanup mount.cifs option parsing.- BuildRequire libkeyutils-devel on Mandriva systems.- Update to cifs-utils 4.4. + fix a segfault that could occur when parsing the address list. + fix autoconf/automake problem that could cause compilation to fail. + acquire required capabilities before a couple of operations. + ensure passwords are not left in memory. + cleanup of credential file parsing.- automake: don't use @foo@ constructs in Makefile.am.- autoconf: define CAPNG_LDADD even when it's not set.- Update to cifs-utils 4.3. + credential files accept parameter names consistent with mount options. + some problems with linking are fixed. + libcap-ng is used if it's available. + the capability bounding set is zeroed out for greater security. + CAP_DAC_OVERRIDE is only enabled when updating the mtab.- Update to cifs-utils 4.2. + significant overhaul of mount.cifs to make it setuid root safe. + mount.cifs now does privilege separation. + re-enable mount.cifs setuid usage. + make mount.cifs use libcap if available to prune its capability set. + guard mount.cifs against signals by unprivileged users. + mount.cifs is more careful about signal handling during mtab updates. + cifs.upcall fixes to make it work with the heimdal kerberos implementation.- Update to cif-utils 4.1. + fix ver= option passed to the kernel + fix error handling when duplicating options string + make check_mountpoint a noop for non-legacy builds + remove uuid option + remove bogus rsize/wsize options + check for NULL addr pointer before handling scopeid- Add %version dependency to Provides and Obsoletes.- Update to cif-utils 4.0. - Create cifs-utils package which is independent from Samba.- Update to 3.5.1. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7. + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7. + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7. + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build.cifs-mountbuild81 1495068127 6.56.5-3.56.5-3.56.5-3.56.5 cifs-utilsidmap-plugincifsrequest-key.dcifs.idmap.confcifs.spnego.confsambacifsmount.cifscifscredsgetcifsaclsetcifsaclcifs-utilsidmapwb.socifs.idmapcifs.upcallrccifscifs-utilsREADME.cifstab.migrationcifscreds.1.gzgetcifsacl.1.gzsetcifsacl.1.gzcifs.idmap.8.gzcifs.upcall.8.gzidmapwb.8.gzmount.cifs.8.gz/etc//etc/cifs-utils//etc/init.d//etc/request-key.d//run//sbin//usr/bin//usr/lib64//usr/lib64/cifs-utils//usr/sbin//usr/share/doc/packages//usr/share/doc/packages/cifs-utils//usr/share/man/man1//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -gobs://build.opensuse.org/openSUSE:Leap:42.3/standard/dabd6c2f62635a50d67e86cc487cf489-cifs-utilscpiolzma5x86_64-suse-linux  directoryPOSIX shell script, ASCII text executableASCII textemptyELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=f10d44124f227940551173827cb23478b86d41a1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=db613b531d7edf50a8ee4b1543e46410976ef05f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=1421abf18b5ab52a158d04410abd3e4263f7b0b3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=191b119d9ab65f8447677dd90e7f96e6fdbebe88, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0eb1d3ae2aaed6e06dc050cc4fa55cb5076d8c2b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=837b583cbf01b711d059a123c340c5bf9fc0868f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 3.0.0, BuildID[sha1]=d0d20b086cdc8d5a2e296de55a4669330611341f, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) $-  RPR RRR R R R RRRR RR R RRRR R R RRRR R R RRPRR R RRRRRRR R RRRRRRR R RR R RRRR2м(p&et%E/?0] crt:bLL'3vi(@G7=ܚU{"G4I&m;a4-8 J%P[͊U{]Ε~ˬnc{17J`O<2Y2UI.ȿT(<ئCuN:M.M9hХbQj,喟!,2(6-E? G,EdYHڇ&̛_s]9#{XQG "~ +HIh\d4V ˖~]oډ\׿G=m`A10%EeHt_*~g߷y߆C-/ b!Pi@Ocg,D%u|p; 4rz)רtHpE Lqh 51 >?¯HҰ/=,rx}RvRM*LGػ?-hA؁f4+w GS'ȃb$o&TLAW QN9`&s$B<UijGK剘p%S TrS8q ֫Vȅ#"͐l2B= yWA&Ou}7l7TED{HfxJUѯYlArFu|W ļQ,<#,уJǥkky}$Z%e*Ee?"]lh@;R 7>bűUr/9n1jh_r5i"P;yi$t'h-Zm#-sg9_8ϻvހ!nDŽ:*x,pl,-5sch |ʎhj!> N6f" tbox}>HLd͑JK8_/BS98, 8O'L#:+)k'x 4<3a9I~k+3".BǘUOJXΑ3XӨbSak3n~FVJEjWoݗgaAey9\wrHACu|ݮI.2~BZ0xe\XFh>4Zﷂ23PgTH;^O uļ'rZvq3E(,80d +UC|kIle)ǀnZ_֟>AgxĪ\<qqRпk8ha$!}yI;2$ʘ]+XLlJLy"cs{@DhHIi ]]g~_r(}N-oA((bR-%^GWp?Dj Q)lX Y׽%jlwݕn5W.R4-n~G5QYxJU3& _Dl8{-v@΋raD/MHvj'=d*|ovI !49Jkv wYQm}O*#n" q?p4Hre#fȩPPwwB+Xp;A#҆_>0,z0%':d8BsV-nv YVh<1MŽ.f<$ Ţ3"'D9@Yd& ௝ tQr/^lc>#4dN E=Qf8 ,'[ ƂBN?஄]U/]qǩ}kKHHJ0o6&t%\%J &=|МYKoxcZghtXa԰ȦgHU+<MoR^D1 m4xU+ };${yc֬ A)z|OА؍8B^ $أ<;iӼi=N;ΈUQf6GYXٚ㾸n7ab&%Ti\A<#Pg^2!re1)Ҵ}8Ʀk`b9r:}0=5hp&b45ڟNS:dGOaOZ(xkTݣ<•WE#df#Tup'jEf&,g1$E#θTj0g+[61\$oP v}HWTd?mݵt %V.Lá] S*WVDGtgw&/}j`h~6 e.fI9` Fܚ\!aQbwQӖUݱrtSOG$t7~?Z MgBc[cd (Tp0+ELӵJW0|PͻskHl%(?]\'mcj~ڶq<1)N Vk[>X-Sz)>(E7R婛]:!}GW3!1?P!p_+?Pq )?#B, )"JN IGnK7&YL"^ɤ K}N z( ("p~ryzYcJWYW01CN ) :P(1<+-&t}اצEBc"{Xh%-@@H3]^~0:_㨈O,=M՚0H۫WVʫ8UqX\UR~l@;R(W= jga01rZ{# \-]-?fw]14eckodrbL)j۵1Waؐ@ԈYďC 5[jїmTDx, /Dy(C~W1q]CsGO8~;dvcn}.k3P.2|d~hcO*慔&Gt6o\dT~"w*6;`TG+prNgh]HT3օ(5SoXVӮ^–]SYGl)r$  r1.@ Lg;lBvdoS[@BtWr"}Ú?,V1^3  d"(l_|R D{ m3n=gdM]Xzh(ݜ,Ӭi>qVW)Κƃ[Z0̔ew& +qYJ;Ӻ LSNқcꑒ2ݜ= G 8mIa x!'j@ffj󚂄,5! +K'@2Eϓ<_N3& n~cmWTԧ5 B/]"M BhRӔ=hAODt5*W'[|'s5=嵠A]-9n`#v^"HJ' fXRUSőIAqڦa7$:ڙ7TxTڗI(hj,.sRY :K1CB0 4]NԨ{0:rsQ#nq͏u߉ݫ$_tnNjߝ<3 ̖TK+ {B)%mGAΩ/aߜoÌ~/k2渡S5- 0)rT bؖ㪷iuZP M!:U3 ,92Ⱥ29oaCziTUY/e=c? ,}%6:6pn޺rKd , .;1;c*_@EImSΌfZ;c% 婣6#V暁85VmU"鋿pGO9" 3NVmP'$/+sbJM[ \3Ж!p3^I 56 ~l~ 4.uǹٮI" oSw-"QY_v_^ҫDc^Y?]CA6VMF~X./ Ąw司_lw'k0`uL q̅ jb&eυ2GR;y&pvHR\^saA^q),ڱ廻ۅVu;N-ٲՙ\]r{+6mLZs/ =)X6W66(guHo5=e73MlFh/Uasߋcr6wR4lS8۷3$Rql*=f?k ^Y[lkJD?3zq.k0|)aN.bn=x֓ %8BIv}sM.e--Q mVyvYǬ_} 4.L~í4z;(Hl |ԃ&1g-l !6(grIw9UO`݌-p4 3ŽQń{ٍ*!\ xdէU~2!= 5[}+' M.aðh𪗡x!%Yv-92{6=!枺"pQS -#6kԗ08ܭϫQP{t3vɮ_C/AݔW)yۉ­l7Ͷhk{Wl_$'t8T&֞O5-}I$LXA8`٬|!zӳVH.de<4|10Y?z^(>+ԇ}bk_#W\-ԈvP]zD2Ɠm|/|q4Y7ͳHkт]*ivc<^q5j|Bis;ɝܵ(k!p PjuѮ`#!]خǰi .ȓd۱[@ zIKLn&\)|! OZ< +J+ݝK݄jZ-;M"?"D D{zϦgMdžFG 59WS߁8 ,*EY8NS'($Gk 6[FO7=luwr\0 $|x‘Mp vs6Y`Aҫ0 xOs:>Z j9>'͆_Jg!8ψ0͡B^祈P?)Sg J.˹\Q{ZщF@˴A1 CJ^;8TS^&_nFzAs۹CykFJ*%seKu6r'xiU4cdr#u-g؉ (^N#tI2v{jAQAb|>5#.~6ґ'McEʂW8Yڭkqs pÇQ'87{鯺qv3XI+K"t^aԗBG FneWiZ/8aEdh\싻 y(MGhlyG i=ֈj(t6B]t'Omiy#IqS%(V̮N4fyDnxEMtIOG<&VTM~q>/N>Å ř'"YA7CS WWja&~J*P/0Vcݘν5 1Ytf)g8rҟI)BcUu Yq`ʼn9=i;M?宂qlk;B 84t4č(lU~E,ƢB:O*D4ڸ!ԟ9;ea#7̥%Pw Y!=O =ŁJLKyROI3nQIw'9+a=KYKL[#P6Q7>AvVc4\d=9++ictvQp ?='ĉ0I~`~8aTobc t@I@@/7UZEBFf<ڣwyaT IqRR: ky@O1Cŕ$iApf*HDqP1pF/0~*cLޠ9 % :840R׽VEkB?E7Sؼ4}LKY ~lULTD"9K{}ֽPP#a/?/׹ ^@CU32'G7j P5!5ܝV (xiK= 9@hduYjdtYŇtYH8+ĬÇXݺ)06\xEjh]z#Xxߗvp4H>vPcMܬ7 *dd@m0ZGP$wtdd3j7bTn?~d -#[jfp}s/O`%4r@ufd抭;)k\i".seN)+iXLvm+~̥a3v8Qh^X.lz:橪TҨZU*鶽'DZ):cWIRRdiьGTL؀GFya\LJ F:! sYgڲ/5'؉^uFN;Zp^#=ʪ VD:R b}5 FR|_J|n8*?T WKPc\:}MoKK׎ԅEA7PW©{Ttu!; e-dQ:N'G)FU`Fr+,nrtl+CkH.x^ y1@+wX@G)"˚HMӶÄV ӷA])ʖ,a^Ӎ\c)6b$s*n3`7 -%:hY.R !V9I]k3U%kVT=$WvON1FbA蟆-+^!9.?ĖF9/E4ؗHeN{1hq=m|pg+"N4ByxKyN 4%II ϴ됯kM|$``7h>^l+]H܂aŊ #Nc1٪Ľg$@eA>L\E"^idҰ Cc0CH:Y# 0(_a.5ơ׈)&,UY?Uw8}dnpRnOerm$vWJ WC4:pTlYxv|cx cAa(S!v;ZV9  ~~k2ibPTd_]EG܊Kk60(2~>b" } .h".RIܖt}޺ju7TօAH;D^]XڎRo'Оmwǜo,O4.}yDDJ|yxI'oNNC d59~zdغ*sH 6X~|io5n{hMx$7 |nhxF$bC/8تĄaA.lR@{hp+4'}$|KWb؄D`NIdоcNe J|]y`7YgWHE8a:nvN<]..YeBT1%T֖ Ũ+`&4ysU < ~TdtՎmZCT)SJf& yNH6ޱV].Ωpjr0 ݐKllхAS"bYCp9H? Q*߂\cI[N1pgB}WWTgXĴ(ېy Tۅd41aS<a.^5\c"!*Mo֬H5퀯-Mp"J?>0H=O+OT!RCxCvGꜜ.LAM*R9H*yN V_j ,{yLZǺU1 7L}S)GbuǤOG*d*`]P?_ # g!cް Vmu~ˠ|E e%--]ѳB}2M ; ."8`6i$ihSuQƍEљ /lGء?pfz̕Bh-m kՀT<(y9_MG]'! [n(\O%״ۃ^G?0 W PlPsR`}<>u>ѯršT[2Ԉ_w{?)S*]G/%<OIωzDqs7-lb\9j2L슋]Q*qlb#=_oGia?fL<%ހ'wS;iY$ཧp\ݽ;Ÿ ?:A>;n4Nx)joaMNFj{2MpÎwǵ gUΎQOG 朷Kڱt<4n4P;oNK*#8XW̶,p'(=MC&b$`DiW*,˫6,Rdz]xE=_?6SMDʖZER5&3YZFE)F>Rufƭ[fga>LJ/QXctdNkNm&T8ަ$ʁ3LmikiQ|Co;G TPQ+{8|FXVg[;0gL<&J)ֹďB|YI3˷v $)+qUܲ"UvwNh#tjYi0oH旃Z] w:V^ea\goM7Bj>8yz*6ݎO 1neSIW #\'>  ,~<~]u2 ѢTl؝fcDq^ Zts|4ʂblAZ6*Qd:b'w)1 ~_HNCPoc]j5f &J%OT}`Tȅ3ʓeHA.tIhhH.iC%%m4fAlK/Zz% e{1=chYuJߘ|҃,T7E F˫w/- ca5D߹4.%@QW XVT?X~E!V9KUZǘ3[^ҭ2.a"Gt-z:Y|6KR1@T,_Z@1=ﶲ $L&~tE1,͓l1DQXdO OJX*zoDoC iB:R1Y]&%T%h<;VHj 4eISݟ0q(^q|KYPytbCX9boE &(T#\ ?O[$<Zi.$SV;ޛCB?y)(GU 'Vity݇VUY' EENZDfD*xXf#Gk'R E-)[v" 9B)Cv 8k=v)2Kmifz%.b)I5.S[餛Ervsye 쨔lU3W[41 wF)@wq fZT?giКPȡi5 ‹y^ mN%VώE߿:θF >E7)!DRA`` MTzj&}@KDQK[\G Ni- nV, Ft,dVl5<06_}HIj^mh@P+?<14 (-t&RS~c0j@ӣ9`tD% :  H<5^~燐RwVDE%(1T,'*&I.pӃ>T}QζT9N(híEUh#pB͉S b; XaD?@ ߨ˴@j/S/Ny;۶5 m񮈠 L x!-N vvAM{^47zzjhϢj YEX`|;a f\wn8dy} cП*&mZ8k~g _G}i2 -=g{ i~J78>%)aPMI'Z~v.P'D & :4!k3e:aZ'0akVQp*š-=)[t?k`ɬ/Y;KIyetsPpA]#xxC5l$VGfiSM3|; ϙDD'.4vv*J$ښ`G_ZvZ(q ]ߖ#t`e;zRڞvC 3W,aޅ1?zܨr!ReoXr[ƫ9sϥRZ"c-zHԛ\7ˇ!뻁?@h3Ib5'9w\HeJc V6$xgyHo (wH.i4 GC/޾!"ї({ 5zCw2N4;gx_A],I_CgR@!9f ؓŞZ>Iv|~_+黲;m7/|(yov\k] )溄hYv0ENu>PwQ !l@'`;1.Kaźة\F(Jx Fjo(ޘt[)岼j ٶjønh(Ц#N Md{W*\Јk=0^џ|B9},٠E4ȃİ(ѕ: i34@9HjԪ1T?Jk15Gf^[:)_ؙ:(jC?lP8;.{ %f b{6Hˮcn8ZfĮ#~-H0=,ި舻q}2\@+a*!(buNžlS1lqR[Oͧ9im|l3Ԙx$Bt++cMSi^̬¶u=۝6"7r \Vwp".Jo⿏pwUڙ~shfqfW&μ%O}0PmLz;pC)Zm*?\ijJ#hߥ~4ERQғb5C< Ruoz -p㉼J *KwF'XC |nGcSx!.)ߠR>J5;/-Vwd]-*iMh%F>kD5tI淎vQϻ^`A6}$xjE!r2v|(LYU^i8 yVf*+Op]!C،rƈ[ӃS||UCN!ޖ+UjrExs5 ~L蕫 sbp!$^AJ?>)Ign-dČa)}> ¹`3M_Y] Xr/ 4v-$^uOzU 9c] ț+'@y /mD)Q.5t8zVѷ"!nB)fN9AHCQ[q%vݜ'" YMy%{@֝p*lad髞"\= a2u+^IHм 6iM2/bhGN3Z"K^J8I <])WìΝg:? #nZ UGyK"ћ8Xkt|?.9FɞAcI0 ;9PCx80Y T> C/$^C1O{#QÀ<~}Ojn4+xyEd;Ttt}W怸wӘIG1G/ɧO'ĪW]`9U-DUu]vO3Wᇢ "fT.[[MJt|e6ߥz_0Ppd'[c0X.odi&C 51j&:s:[\>n#AMfyP920BY682B.^)R8 zVmqV.25 s@߭e<WUzh~mB:G1 wb+[Ŕ@ϳ=>ք?k wt0;*7 SL-N#?Qmn Qntu01qZ?Rj/L"Td f[xsL;'p8h)p_cjo+ik R\8mw{~iV70q*i|agõrہRw09&>,u@W4Ŧ؃#-DD VJwx\_Fm 8i()g瘡#J-Zt& e$-E9L*@&381؂|4~P2H+\ jiQ*>Jd-ivD `TGά@NݙZWmn ,Ҭqg~YZi;N bTo٣YxJxrͦHK_#,! VJ% ie7J7~8 /-3k; mQ|y6i/:1Eg/RuW1{VvS'Lv2`јݬ_U!V#O+=_G ܗNoڨ8ID~r-P*ܠ=Cm".g[4Y{OUjb(q(M+1ֺSlXoIE`M/E;S(==_B$z$EN&TZљ_B5 rﻣ؁̐4[bk`Cc-\S֘b-_'nqC\Ps!VdD8TdeMӪA>r{Xyx/øJV+0 XeX~"'(¥ cS|u7" #j*KS cV\Tx֌zC:.;j9sK6@_V}Sl%[:N5a "#̴tDx?SS0>̽VT.3鑽|*`Qӿ[ v+Z+-U/AQ>[tC c $o 3+$kM&C5cte,fq `@ Q{|)~dOkdI/~`yàeB#wƼ~3OR+&S'yc֥$}oG)s9S2_9簒vxם JPys@>;U rA]݋$ sp<{1tka_ܐ~fnС᰾ATᚃ ()Rm藔Q"9AX{Yqg[% J5LMD#?LXHUS9F#Y٨va2 OfGHBJK2 J{d 3f ,^S\FZhC Az#*8Q_@Py37r:>un>EOcF0~ޏ,0N7Q2pWUӚy@ܣ+/L<:]ص}:2ѬYUzįꋇ[~~uަÆ!pɸX}d7NM5J=qy~[ǹbLn7ٮZ2A&ncT7C/;!@"}yA,t転XmM!Uj6܆32Q- Erti['"8G}el3693X^p[c PbqC}q?Br3'I@ 7˒EplBMa{ 쑁5A,֥-~t30f`XCvY'$Fᣧ.?X HN~~os'Q0nH4|C { [K*GXӫ,ɡ)98|w/Ib\ؠp8_@VƙiФKtaHL^}\g1Z^-+ .-?jm}~$"[ yS2Ȕ\:["E,=) {/;j젹xãz٦"H/d4. &x[ILV_֚93VkJ|]\c5=meq&r蜠\Iڝ_8ܑ`}WXLqSL#oSp'D$w H[N8T׍@]2 H'D9ۑ'n .5m8cT0ڗ&Hjf ց`;rS8#T[~Xࢹ hB\"=yX)(4@)9>? -ɡT7v%RSie8bx!w#l7 6z^$߽0moVqo4YRn-?ux%g`6WrrE3yw{۰O3*r4e =UxҒP1h:x95nj+ >9KBUě.bfDkh(#' BmsN7ASlM9pS2Y.3[>01 A>4.47?4 (t+UʦZko4E_ZZtZ%t#`}JOٯguFJBVF ̔Z& )/᝜hmF{!z ArN*#"n\V7h;hF"̜^PߜLCSܐ+*IH/wW; 80}kASE㷳wSU y^oy\ oˈ\ ;ñ(kZ֋8Ռu &.1`Fhd^#m|)xj5P/E&K]kl P M\6钕%nvKT Dec4_aJB:mT/6cmҼ1D Ⱦ}T%KnX|Gw8̨7VwrRƣD[CZ#gz/R*ezZ> 7#؏wEJJ]5+N 5#9O/QqD],H}{YYqt<5rWRɗF[VQukтSA9/1G9`:st CٙmNRO'i ,z$m㉧egqH XSL.]{n`~x;2jacUQɟ-3Ϩ$!/JMTX^*Ptj~ 5yؾg*3P$hy=1SؽJx_2OY;:qX4Xʃj4R @Un3}рllufh8XY0ؓv|ū *^}'o+8m))ȾT5~r v!_%:R®rp>YGs+[Mb2XG`&13**2۷` yҀ8tpˉD8yVƯ[_zM|LuzMxI+fRV%$9ϫuT\AIZF/(oɳ^o1O# `ݨ!P7W١v,o3x5H8u,$YQHswՂ~ UĺcXw Oxˎ"_8'Ts n\}vRS'ڕut, PԤ+1iEJb %z3'/-eH !hn*a≔ڇՊu>DLL)MM'εE2~}~ڎ6`*i%D;(jjVM:ttbx,9֊r")֎xig (!̈0`~ Z0+kRR[VA%"^t0 U|9jH@;Aa%DQWb6tmKn*&"*GZSdTX_`1VUe0Xuo'w [AloJl"?7 JwJ5ZL(yh}Ha%c ƍ՞4{ J/uUln,0^^+k;_ QY엞kѰGWQ4#p=]7kuoJŮ?8Zy@l}Qqqnv^.o͈ڋ`jLVpM#KzԆA|~]A9| ^zUUp_J?6)d6qk؃Lݢ~ ţ*h}/qOfy3TYF.I^rl~[<}<A =do()*_h24Bd9LtߐXj2a='6^c UtyW~&61,RH8PE r7z9q+ WCj*,TQƊxIm0;(TgiP v/zME-/=bGZ7fb D?Iʽuo۝(}31 dz/z6 A Fb**rV.Aσڸw#P pvo7˪nTwoU)pEB`:憰WsA5Ǿ^o`qV &S@6o^n3 k^UcF6Yi(/3S%K*o aeyio8iDREN ].DLaQ x^!,Irҩ%tW Tqs=xWPg}1.f] #^J\-Wa  :hԝ_6·Yf˜Cqqm@TinNMqy2`7+IuޅM) W^~BpkkfVH/k2C9lL㯮8< w&?'ohm#Elf*GB ݼ0U[JSeŌ*A>$`` VC[:Z"FÜkd`{:%+U] ̛:W$fg`6Z:d%,f%g+ZX},gM_Hu5k21&ܻf zm3Hk|Hܩ5QDt q&n_F˯}ɨ+D3VW+O% 8BM*Gɻ"5JtQ]RUHԶZT#w)عG>0'G`t$D \TR=l\yO22͌S?>&?!#}/5/A"D!42c3p\l݇? JX`q#4H P &zRۅJ3?Af% V> /[IGĘ-8\+&0-LQO~8JCһSn4_'mݺT\!h)XX#Pa9F=wT q[`0vf"r|gw5_.`f^[jOF͛9MH8"/VzdWC[HwtQu[A8jyd0 6$;go(a\QK23tbR%U4J6inbZqW9c79},YpLBJYX*%$Ŋn&52^tvMLR+e"d:H#V帓:.R;U}lӑSW"2LӯuD i󱷸/g0h}=6Jq,@ muP6d޷M>N0X"1`<,)(0K]5 S3֍Uŭ0n yNrMD^Z ʰvS1GJYnLY<8anZ qQ,l}zaH<5*7`V9~k}zgmQB#Wz6c,Lm6Qke}0YOє尔c!*#͉p*YwAbӐKRĕ)7w$css2ҔztkkcL$闓`\08I{s{LKt=mGFx9Wu KcD G6Cp0[sG"&Ķ( ĿsaL"hkHB6):=} ,zdkO'#A- !BGi~٦?DlCytkL?*l0)>LDIX/GjmfH(k j+R{6,SOU6aK L(!UcKfx.'L؈3`hJMAc$7}&e)~ :Y_6NFVߝ kǂl'V1J/IC4MΐLofN%mZ R]O, `l|,AZ9 âzhy_N,18%2E8$#C~ A<-א&={Md&ߓltmVvH1n)pHA^xZlxx24,wBVbDٖɥGz(B/;[TMj"0m<W̝11T6 yQF@\i4i j=Jh 2Uw$!i͟t]x*]v':ߞ#65Gmzua#( s/J~M[[^L(bVɠIN^ 84˺Vާ' ւ4lN0vr%^|Yg6'=]Z{ppipJ9A(H]xv O ߭ յטUϪQCr[Eq5˒z~ L ?=̤e^+R!Uh 28B [ӎn#ɔpOމG24+d*\4c!X!yv&s#p2+b <}ɣXjNJ1lzB)9kWM&qmȎ?jZe!{SQ "Ok1!փ#B#Q; g‡]bQLuQpcB,PXa+OmӄSK.]73e{<^+* |sDž~xkt5zTY91yԛZ rl/ƆY/~k#dl!ߵm D X;+g Ƅη\jD~S nc N[1n@|AGgKoP=PK`fa gS!r_)`t+G >"xf*g|q) qWy6.sٌ.CXy_ {ӂ<{=flr7*QE@Ž >R4oKx 41NV#\z"lIEGd9} >| 挝dn<௠3RёU"=4]VO3PG= \9m柜(Ɵ.hL w眇X^Fߛa؁f&Q3O՚;ufUVV.Uo8EBb5?gUkR郘N!\Ov/Yad;^FcZĄ|&YN#[p%:ڃdE܄t)5'6a bDB Kѱȧ:?<*g#VvLdxIo]DǶێL%pJ?s*!?1}:FvSWXZͼ' uۛY M'LYwYaOB.-^WGT׉rʦ9_S <#F \3ǿ0ԟ;3ǺA˛B#^*+nuZ%c4sxFl4UܤfvӒ(ia!9:]C7w3╠wn Ť? nwi!-18o{&))^X~j 䳔vIh`+#mlXM`MǟS.>5nagG~PrO/ <1E q!{rez$T+;y:+q kD|50*~n2z$ٸRɡŪ )]!PS%:#Ӹ8*iHL(rתd>UA[e>wA [l>]Ɣ6r05tf;wcsmӀ,oj0?oC<4vԟZ&Gj;W64`>P=Si5<%I >lzuIH?֊3Oąٞ[7ȿfXQW}W=418b4l ?w~hu>JW~@HBaeiW(A*Ԁ6zEvHvA1#e_[u!4u@]A*Lj΢,7ix[֊x`^eԵ9\TZ z_|GqNI.켝pkơmLuy[3-c{ > t~S -@?6X~g8PQX2Z=+*", XDˮ&%[3 B{P,S hNΊrcRtS!93>WT0e]+5ĸsR5V 2rDYPЯJCC嵕b #:< cr ΪutcM~L K: 8$Zd.WQ@`Z{n)k]W pp:(mw$3qO˪hK<Cވ''P-B* #e|"j`>Jh(S\{z?󤔔fM̆҃PAy D9\ v_"y!_~azbTq-4d$FJ}߿"Jh|/6\_;7?ޫ+ġ jᒃ]Nz-65BI? 9 p!)n=G7.fV`䣐ox|yR2XvB 9z)8lWC<%[.uj[gbYMב3}yGD& 9SӌGň>,Ŗ \mL/έ%k2Qئ}grZy~Z !^USJGnM'~j/,)yXAreIg}v&bv1⡖keoKGn?n\UzgDs&ːﯗt8yM6p֐:Zl (HK;%~6t_22F-jbd`Vr 1| -x] w;4g+\d=d =ca ӑ X`oX#6>Jq()Σbۗ/$˫~iV;މbwG& ~b*vm)׹Xوe~r < O7 ʝFh斳zȬy8#Mh2׺ q[J重)@ R'sZI V>-e%Z`룣|*PE⢫TKC(}Q_Y֙=Dڿ^_=H|j<1\9h:l{pZyȮT5%=6 gѣ}}An%jxSmxL1 \\r%mV2PP^TX9lgfwhA?-¨Q,ehy"iހJwI{ϡYSp<;zɋ~աHXՏZ5cDGtm(UI.X=B\x,!?+*bb*K~ƃ\G4{5+>{Ըe12\΃kbIGq_] _h=E^veeB6JHe2E}|/aޖ MտEgp#L[ V4hT"K{[nU;=2rԇSZQa*XSJUa&)wU _"0!"j_(x0|InY"ߥp{%0h7`T'&K jqY'rji(8F̳/mZk>&`dAUDiNHkT+h091h+󋟼+em@]ʗ!l  fu Z|Z l?hGW0-^mTG<뻏Gbׄl[B>sZ,Bk*7D1 lIgD/ФlĴu`:;'&ɎcB~Gr )*‰hZ:x`uELEzVRO-Վ,1Ӧ7GD*% 4]pju7wiRMRJX% +5`!7 @㥜و"P^p\/zfo]rĜ'W:;#*œq(\Q/&*ߢ˼8C.NK1Xf2VZhd'o+40<ݼA3Ò) X!n0jY"GNEoZS'ti#Xd}ggϥ*:t 囆7~!{; tk"`KyÉ+j ]rvvr'8\\7“W ڂ~6TaqԸ{wH\1̌*(-M(&C֜ᎋHoKbN|1 aiܽAp8c]:nÉWFҲL y&b 9z/\ J&ra@t;VoS;A-[5{_Eƭ2;Vo[׈*ϮkI$78:isG !R r +cĦgM7҄3\zXLRC nQd蟕\f5̈́Aeꊰ泾q|% .\O71LS'hyD[!լyKR^epN-'j:Z/eMj*-7nX!xvYT&SV|ѓ1wA1=^iZd e)'ד,ݠxM`9:l)ԡ0=X< pvVorȯtϮcW3'`ai\LN*'hN6z4r*k?;HFNazV<+Qӆ4b`}aI j) x⣉Ά.Wi#ؤP+CFw, ވ遘p@UD+oFj 땺0_N]pؑ$2N/EqQ,Åv(QߗZ 7t01E=w?#Z%)|gkZKz!}] |m죴٩xFSg!v)Z_Wl4qZ k58L=۽S!.|*Ţ%RncQj<>"6.nC{~Å`mv3l^>e.'Q@ 6}PQt5H5*ؐ|7DTaH0rHNJ`emoʂ&=Hw>oi2|/_& \+S_+u1 6I+iۏxWVL]pJ?sW }*(k7_"F╾L¿*Jn8`ZȪcp'E+ѧS3@"Rg%% Zn^8up=$VW/taօ: 硉 ݫj+N?Ѓ>ۮϦg`oDQ담g|Dp HiLPՐ;-e}"5?bV#댁|tg_3,8~j$c@Z&b7{hZ `x P<[DX$[cd;Gš|@vq{_jHhmʍ5w]Ӽahn&.%ru>]uD`m9Q⟐՘.nG/O?aQ 8o(5zrV3 "Cn"wϓR`s5KGZKܯ]%ۛ^[11_ 8U=B2~f&r0EvmgSŖp"M r1Vn]ñB Yhg((=nldPTRs i=[/TRP(w9J>+rXv-i:{pn0ʶ|2o뗿X\M? kI]75fyʼ-+y'{00#Qos*Gu\v0&Y'h D*Ҫ%돔`WgJf,1vtϒ?JAmORE*&vr%R |OKH`;:x gdYkT]+tPԨ=vPE8.^7i[<Hnv#%$hQ ]({ku"O>ls@juFًN:0-[vBW[_@puhSpY~׶Twj ͆Bx"mkHYÃYWpU7U we_Φ::H4dfp'J~Ib?X^ϭ)1OVGtWGƷh^2TP@%ռ5#ӁXpr!'co% @sy/PήL$LrDO4lxY8)C7~0(oB }gK-3`@ Mg#ӻ=<"M!U8=;moL;f)2j-4^l4c*Ky|1Sr=`e}Cԫ.xJm,q }`_(ft&0p/SƒCb(jwCqѐWkqk =va*u̡$Fz э&pynxe;)[:f,:ֻbv*Ў^(@,m3n m6+C|k8vUK"pMps Bn(?vPƺDC%T_/&m$FW&4YcTZDY-%T\R2`$FQiT%㨬qk'!:iGrk|zT;q R22־ܚ/Mp-[6l+c`䑾$ܣD'CaaPI5h*WCtX,Xd39RXl`+Ҏ(4uag%_"4Fb(#=))ꌤO6BLaZW(o:YXh^ngY@Ue/P/q#V!v0p>~0J2/ rK9В{9`vq6mɲ'Xу#wb6ö2x(4qB*F*0UU}ғ)O[S*Xn1 ч%x[# ]0 FizQkɔP)#ť8GӘādH02E1߳ԙ5m,ϛ*E\9l6OmM 0'-sS!;"68KT+)$Fb2DS[քFj?MYPKÇ+wZ|V&=bq Qʐ-(8=x> (0\?3zNvA*Ruxe{8h0jk& 8؝ AF_6#E(58̟q7H}p C^+S}{M*(S)#fDEa|I`s*pA#8˰Aā޵U|H=U]9YF S`pKz# ǽ.#3>l:2;ׯ 'G>GB AB?td"5R 4@j?5fauClv%g7n\hTNI1kY芦|tI 5OWJػ POwTi2/E^lhh.s#(RRL!է.1kXKp}QX6bk1>EҬ ߚ^F혵B[O ZHM?}- [`Xvsݎ}uY8/8x N98_TGK%Tvoaf兛ģ)Ee03 }˦j=(CF5fr` ŎNXy[$p!@s@,R}u(t4։7amXa%dMn|Y8Q\XxV;.2Љ~XDi{<ũ/{yݸ w:ܖݹVεQ6oZZg^6L5+/8/:h^W0{Ϻ=UL`O&q hD{H[$6&;I7ǑC)v:,ŭx+=1g_"yWͮlkȤ}"㥭tp Z{s#&R1R`Q]jHY#i[f&7PxIic~@>N)u &Kl3Z_laI" eq_EKHl:C˯B[-RcTYpTK^P&Ha cZ|ZQrx *L%πE۲$Y# 0NK4vnI/cIQyd w3jH-:,-vXf;"P|;}M 75x |LI :MQD'k!i%d0ot7i)Uo$zWoiZt~-ILDEancFܡa\)%kYF\g8Ni0i41`TiB3]C;=k~* 34u@1'h Xخ0^NELiz 1Z&2j6X='bh~Q%ɬ@qhQ=ao^K`fiګ7"F˚ @¦HɮgL}B2F/?}^bk#,U8} ܸ^ 1c@,om\'e z&'Q Ĵ< ej LKJ1M^.;uW:]s7ӡ]|; x0N|鄹Rtm%ȭd7W&сӇ8TZa4mAV$p%CV./چ:[+떦:p%CM,\B}ㅍmJ2 E>[T b҃O*,7YOKxVI4Tr~ MyeQy* 8ƓX@5Z[l0)OCWf(Aw|]PNo9s#5_jIQ=MV(- Ng1eć֚Eݦ =_3n)9.Diҿ5L<%cb o;Zȃ0//"()ߑzy"xv;Y|@>ͻ A@c'TU0ݘ 7Z=3#]#:N `tJQvZ|rT Ԑ3;NdyJ 3JZ=<>^V%0 KO} dXlՓ#[ b*~|d;6y=<=;;Z043ɣK)e8?!dP9FDJ\PBU`KWډ?_'#b3d:P3 it^BܜflDT;&-Q2x*ЋhL79-2 40:%OSm%$7V[Ŷ06MR%TA6z\CxM~1bFتsdGz^']w^)vk ־~}E`հ[iPjwv{ژNJ91膏V Ɏ1U+1:qag>ehCU T^}`W M(+ 48^>PCLÙ|aT{-%K' w{!49J@$RffJCN"UtQvp+`Ssl<_ϔR~N_>%*_#5Z '՘IL"7'syzڅ;kL܄ vN3o.٩yfs|'&dI<Fxɏ?#l|9c0rΛw7D$!k_߼$ K*1Q^ FI}Êٞ$FʡR> < @;aZhkN~2hovp@&CFn( ;RpKUqF-:ڂ9+Zn{#]FjlM RFwz:%C:{ uMEˡ1bd]V|$+*MhO'-H> Kԭhpj +,gE-~qXd4Zg}T-7{I WpWpq$a#7w h+z. 0@ vs}aVf~y:٬*p~>7^ʅ@>aT3@}ωT XPK+ %fz* 'g^jYD3ՀM[C$b E?j(FICy7oTw 2KA=xضŇĆvAtפq$!CtY8/6Qws1z*Xa,# a)@@NIh\5yM:1hWs\{Dou~2?0 ^f:ㆠŹc oP+_wk͞(ee~<`* c}bPZ|Ҭa^p+K>(7]I@+LCSC2_A*Yiqo!y#Wa*;oEq g8>? }:$fVcX\&] *,h\1wQވi;bD3K [DdsRzeWVWKWç΢<%!Iu&!?K`qyM9CkO+)^N_ {L_SOZwVPauϖ*U"XkNөJ(C;7=3G5,TR5&'dw,fAe8n:o?1`獼nTW\< 6q`cƼ.\O61.C$˭!T 0}5q6ej8U^q:V'%i&Z}#gO']g{ p&]Wڱ=.y7.UEjӭٓmSXtH7,M+0 R>vg8]_k)6u3nc'qГz;DZؾ_ :CY>}@{tpps(_V{Kbq89a|Bb)b!I ASY`Hs]f>Rfԟ<$_IC؂Ba[og%t9#"`jiraFYM((ƋHxZ)WZǽ?wc.wR2n ,KkOnٶ^O-Fx(ywɿhN`AjVRqEF`# XYyf4O($H)Ge_Ѽ86@hΨƽg3m~ӳ2 p%aЕ[_ƣxXXa>H: C92٠G5(Pf~Ďe̲w* x0i9BVS6MPyf^$ o02HjF (a1_e'jk>vd$Op`@)s+M4MQH2$4Q MfPT]nkxhqrw : 0,~^w0H6&qyOT5D!7[;<+/!0m4?̾gr ےLu70(stt@ʹjqX,[hQJywN-tpT}ys}տ/1$JXn#*JIѶŇ5#,0##5Vlm!F/TWUBoJh_ꚫ]mY"@ ]//<!LMά̬ -4yXHM28#R6QY@nU]nB}#RNp!Ǎ0H ?oQPlicxή\s1|sh񽢙f87;ʥT}{RB y[Z7C&w-;nRP ț@FiTQv@,?tK\d…,ʳe0CL? G~`4p;Q#؃܂똢2A)AW븏aވ~8^Gqg5BY(Dz:ye%2vm'H6P AU~%~7E F5:ֹ#%y}]lX dsA'aDkrN|ۭŧkh{'yšu[~ ^5L/f1lv Q զ?# 9AEjTCwb6LJ@^Hbqћf`7 c$R8. ;,KKkŤZZg=k=/k|n".EMKSͩWkInr{Wa#RdcܣIgd3IJhXĥ(/dIez=<6qVP (`i_k +\t\Pxt 6`+VUMJ⋑douwS% ^hVa4b| /5ahzbޚ ]NL ZCW&- } rjRݩM1 p93WkmN9lEf ~M-Ճgn9p x-0G YI2B}c VLW$c0,;)q*(z}Dbf؏+%?% uYxM`Q[9'&Qyxj\JḯorQJF}%UpBr⭿1`=WNWlSwz0}N+Vm7e#ֱ3X.$%̂UbMad zCXkcz1(K:ܐ<7Aѝ?)§%Ә#:Rٕ? חU}$!"U#8q3 ~()ah ިxbj,.`&{Ji%Gfinw_>ÂU,+WTܕ JovE!\ i+Ĵ=OhFΟu7+Rwȣ o` W .hCcG o`@st+;~p5:G_:>gчvTB 5GyEWI6ֱ`[`@O* ]&)ޣ)Zew?ZzO&s;b<ξut6 @2xoR=9>8geŁirgq?}j"M{e'(Joߙn.0Rq8},nlV [&}x- &1JWB*Q%ppI^"}Lx+]AMpU][%GeȳH{2uh&-Ydg*WܣX?3pn ̉T+ ^({'H敺A]UhiO Qp@jdq6D~OBMuHP 0-YE mNZh:?"E7Z4Mh)1Xсǀ[ ;d<5&<+o $ńWLKVcy*$` ֳ%7uzF1YI%D.{M Ͷ?Rm7^8W)(Hj@ij} 0>s=~uW>NW̙jvFO{,H} rS6/rX1> /x< eU:9.WlVȢ؈r ^EPQ汰'K7֩)0H$tZWh„:k㛛gSQ4}MF=7맙&AAxWP{fCx Eh;אǠ())G=(_R؀z'G-*e&KF"ՀӉuT'Re,. aὣ<*r9; , sR?z+(+.w ){2! H*nj& |&SƬ(& <ԐtbxCsy88(ܟ3G8hCϡu#GW?l<>бbNUA^.d|V;MǀA%+NZ.sZ!2t: P}[J$]}AQܚ.؆~6$ J6 Y+E Z K_h{dp? &*A$AI*U 9llZk@sݱ ,!di_N6!'S6\54[eIc ; @b?$;l,$$&g_g4M_F[Hum1z#k ʅDm咉ZH. UZ7"x_`:jl0Z`n~?؏7wId- 'fa3Ĉ~04ݸ4vB'H.'[c8 UV_gvij 詮0P5bOG%z=$qFd{b-HNj50mӧ=Ōx:A2Y޼WjU$${]lɔ1aA#uaڕmiT s&69g+:F+p48bOkOi8vPx9-[Тµ n͐Q, Ire I%faw)nWIgT?lvyc@ ?j,pns\s:k<E@]"Ug+p:G:rYznw"< -:n)hi/aL- NfBT6M''[#@{9x3E/?}սIbsc/aFa-8?㎭W7*i|܆uW?*QySӚN,R wn u' Pbݔe-,EiCQ=7kU4!:>xh x4Q*YQh=1.e9#P0 d?0\G B'JUK/a" T[k\"f)Hx)~bfkWXAKZ''HlѬ2iCkYU2!F>Y3YTrc*%WVQKC9&Diww56HVs+iI#xnw|1zR4A'%zkU;v9NJHS}/lP~?8r Hu,E=œo !(AJJ0WfHmJ{ [$RrW( 0u&1g j! vi/3nBO_x[M=iKYq &ؿlD*)a{v$1[3ߴof!-l yŨQ+`-u#=Qzy! \i=vZS]9bw-Tr܅y>w+\dca'pN>*%Ċ:# ([TS U=)Cn [F@G @!պlD'Vʰ y:h6.lk _y8@<է'o\RLo%7V4,}NlL }c돖X*&K,ZM":gt蠾G^}dw`::͐ W$R?Z55\w.dLCt:Ivf!aQ%ʃܬIWc G(r>SD˦d%ߧ#j=2\S. Ӧ/LZ]Rigrb|X%qx'! μaIReHgshgICT=J Dhgގp=K C'Mov7F~WtP\Zi';,M*1?A3KHP_yBp{EReoeLBWF|9F|E"ey 1ᱹ$((}-TaFTe/WdzA_"KU RpF*o[&`{-n_!.\D?/BSS@n63:Ů&(!3Fxo= | F54鑌|r6dcG;:P:qNgKAoJX! +Xl*21h7%{9a!=!w r}#.X7S!7S'`PMk٦ƍ ṗ̝GZM~W sE.flRP6=H&]x-O ?@2 &XkM^Ozmy4L'XkBK?)I{@wC01uw&Y}aRצs%IfE/q\QqɛwtU| B~窩WzнȻX‚0c׭;yKiAݬق]"-LiTܩ'`n(Dz#L o9MfN۪sx^@㳰UER]Y (vY93Hџ٤\;bHɴ46!:T_22g 7-CLKn=kg3%7箃vvzeַB#> RNkcP6M,UuBO>mZK}p gU9wƱ9 sT[…@욮{m˘j7I~pm q}M]U7IrȄn2\'ٞ -wolwp,Ԝt95d8 a袇[8 704 Ŵss:h(/L@1ܪ pݻ"6zM8;%c&c(*f({%olA`ހ+2S=<1MT%I&v/b+"UBX3-w5lJS%ZGƃ:#YA"#A湙g}Úc}t6jAP(ʾ[u1_;b!@_b <7_ <<:m榴ݭ5".e |Zy0NqIdnDYZarƮMBXe$!x.t0qɨ8_Ih4 d!5l8)+{nwro. JO3#&GIxB9cvFN)L H11>ZOJ\ $L)4Gh+MBlǐ-Cs"V~`=@w#} Ty}V_PG}"4qCnqX_$h*3|r ~㙦?cDN]KYGH |'هӢFETs]XØќ+^n,q0"_aak~\1("?5]0-BDyH,k4I1}zDi͉ti\ s+mn2> [v:Ugڤ;_N6 *d Y`D` Ptܪ | l]!9T@oʃ{|}}8Yg3l9^v!dYs|QxMOH\^Q}osC>RU }{ۛY>S;G<6F;Gnm-wS蛡g >Uqpx+2I^gR2T|lٕ8<?l) L`;y2 "=:87‰Kq>x8wp~[~ t$L]1 z}ھa3Dž?`2Hr [Uz-%+ұ>HO0:1j928DgD -V95E9[rp4ttbLt0#tٓ2G b$DF- `׮׾1+Eޙw'Eql@áp֣BAoo6 Ɋ ~Bycdɫu8Oބ-;ȥAɥLoFX]2}vLqnD>n92jE ^zZ7!x>@Ő=#ySG NMU|Z M ,®V9X CE"q"Z.-P̚nB[ơgMJu^1 ,e=n\h az-(2b0u/6E}BĆJ?]0 ~ا>@4_rRFb1G1X :ҘgzTY0;ㄩB5^'nђ?-^u|k(6go(`09Yvݬe#&Q+hs5ȅ=V-X7. Q#;J.a1t*k6ѭ;Ŏ)W% Ҁ:SOT :>\gso`X LiBy!qzha)9YUl[$"i` 97(8Ah`8'kHI&cT4;<$qbInKq>QBv!g: χϕ4`Cd?o27FŽGZɣOU\hT4_TX [Z.")ŅJ Y(zq}NrO!Ý<:9I똢I}rk`+>3E@D|Ѡ8m2sp|ۡ0[UiqLv8xo,Sڭx&hñ4sG_+Axum2KfQYchi

B.fnqhly!(hzHFj67?BS0}ۗnGm7(OWוђ")"8q[ U8vCR>Ð)=.=ҫ f%'e !FS}u^F;3Cn>sJR 2*nbo|`20MP*i|8UA[DΈsc]@XK~r7z`2mQF5>0T>$?-Ïȗ[W JIz@oDWErviq %At }׉<\͇2BĪTEz~ qCA~fY5 s*1<]al?(]s*RV rdWL^tЊRSWn*Z<͇'v t!9%1JR]}-Wi?eN&-^ù\ X2Y%OlE!W6qwG6 ˸PD}E;tƙW*vs Y_NXBh;֏qqLm:ӅZq* szw>߾E c x 3;lXr'2q$l鑶VT͎OMՔR Vb獋)Ϧ%l(Ch, B.a\7Sa*˃sC+1`q̓(ζ{QtH{ -D0teAYՒى@FPfDóAVpGy{p0IߤH7=h+|S"z;[ le_|eB_Iby9c{kZH秊6iXrRՒMOs"4h}Q/2q+;O]"0͓1d^\[C*u;v"V9Dn4C17lk/ jks3>#5Cs3 N2>gllU܂eGuQjm.0v91 Cd~0xQksܓH$OIAӒ[8R\K\%&c&Zaڲfx⃠R]"5ي])-xĨ(Bz"']K'Y.3c O~@g_3X7:R_U`7gTթ;*!eDOQvIU[`(>i'D-^fEO--Bz>/Sy< ۗX$f0?(캚C%ٟ_Kr2oo3 e@z :9 ~? 觗1Xy&F-:/n h A|ƻ&n*\+B. "XF}DhnP}0T@@Aʡ<piͩ28:%c(`cܾeԻ/ZМ?:N1ICYŒ>' rsշq]I%at32*#>bs'NYEc.nu]eG,e ǵ)*kd?0\Ύ_ݢ}gyoCӎFCP:ZaݰœӏU- @iڅk꽋xDӋՀJЕYl {1JMx:ߛGT?a?(;#JWoDǭXj#'w;J?ٛ șA/ u{1QʗܐRӾ-6һn{t/d¼6>.r]A}F9xט|(-w>.R-AaʔyEuκcoያ"*Sm? ʹQz<,,RMf`F\š=F#NaROt.i\)!xDGIiWnB)A  } &nl}$蓬vqTvՈLsyךJO3gۯW|j&C@D ͭ]尰y?æ'PW6dX5ܹh~Rl7\叡f޼-([ԃ<'Q̇tno!|{,Ҷ]C:l <v@߱G]7qE?_qll"XBLV.y+z1܁w )S6krP>'YTK9.9޵Ofb,=mDG8`%5Ԝ_@m"s^ IZR,GS5,TNו2^FdLᑘ* c1-X\j_Ta$ #z*bFy荦AarKğ.DŽc3#,;W:)<"W[;tKe[Ck^)Ϸ\Is''6IdzKKx 2o >:Uj](< ܖ6lbWA pmh)"PQY E5Qڝ0XNN}j0 =KRNNhD1#2#:Uy*//UF_n ohxZVU6 -KqRV[|352fFaq2gOԬ4$84iy2h萁9w۝T8CBwalSmƮjq:G2 .iFsg0|XiNoթq!,ut)JT $^~4àΗ.dhP9ݷCs031ʮ>1V),DL^>5P5 T@y{;'!LjVh$Y捪BȎ 1dZtA?͞7 ן $ \#nyOwhCP?7 {:m-F-hrm]CUH4I.miZB@9Wq5%N^~o\y,ϫU+s"}G+/U63APЏdPfI1/ H2磺 ~sMZhI/ rҘsi!sG11qIxxپ/l!(0dUQPpb9$~Hc>pR$V;4=dgYyfZi82I*l1Hվm ạt'*%z)pt{#guMF!񂀁ߊ6Y2T0~3XD=\/%Ǭ0JBM9'xYϵw,8 vy"? ԣJLU0+%Gq*#\k,v2و9`+/)gӛJmݒg ZB;aeN|Tעk6˧'J'EN[2.q&B@!?vjs.m{es>cE4Klք1` *x(D7^ʬ! A.Op&׊nU+ +kVKFUz* [ۍ2E N51Ӧ(*43~l7, 2/(&[wb0L chVKP|=)`.{3VRy/vP)X \M-4,1JaR"Q` KلQUln_+^tȴ{ PDE!Z(Wl)XT;qeaĞ镇^K5G)5kzUc|RI;XYD3xoi2Cv9KI"G6|w--^L k!Vv}%QfbtsWx{Vͻ+,YQ6 *@a']lS ReSoc#^<룵s @V*wuӻᵽ+x;#O"c#c@rZYrZg/iy7Kg$"d gT NrT6_ 6bam8{(q[p3][> .NX䒭F6˩~PVb`^;.aϕ-IXs Fy#8"٠8qYqv/8)+|sw$kG;Sgb}Km兆@yIU}O0=4wӚPXn5RFG9k;ˡ՟okˣDC:'