libndr-standard0-4.7.11+git.186.d75219614c3-lp150.3.18.2<>,]Ӹ/=„YZ d'J?&hE4F`8KPhX8gjKYr*08L$y( 3Sxd>wU3s\r oߪ˫?(q`)ڦ,l<$у7ʌ{c[!Se9G֟M$֏cK=3; o% npϦo#+s.0S&v^Cv'%zH(%K X0rЭ e|F4ۣ6X>@1?1d. ; v ) BSjpx     @H X(89 :N>.O@.^F.mG.H.I.X.Y.\.]/^/.b/:c/d0re0wf0zl0|u0v0w1(x10y18z1t1111Clibndr-standard04.7.11+git.186.d75219614c3lp150.3.18.2NDR marshallers for the standard set of DCE/RPC interfacesThis subpackage contains NDR encoders/decoders for the set of standard DCE/RPC interfaces found on Windows and Samba servers.]build341XopenSUSE Leap 15.0openSUSEGPL-3.0+http://bugs.opensuse.orgSystem/Librarieshttps://www.samba.org/linuxx86_641X]i]x5dd6cf6aa14e91c86ec044051191ee1c4b9a60e8b985c8246170e77cbe68d777libndr-standard.so.0.0.1rootrootrootrootsamba-4.7.11+git.186.d75219614c3-lp150.3.18.2.src.rpmlibndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr-standard0libndr-standard0(x86-64)@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libndr.so.0(NDR_0.0.5)(64bit)libndr.so.0(NDR_0.0.6)(64bit)libndr.so.0(NDR_0.0.9)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.7.11_GIT.186.D75219614C3LP150.3.18.2_SUSE_OS15.0_X86_64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1]@]@\\@\ \C@\N\}@\o@\\[[[;@[z@[i[6@[5@[ @Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USaNoel Power Noel Power David Disseldorp npower David Disseldorp npower npower David Disseldorp Samuel Cabrero ddiss@suse.comSamuel Cabrero Samuel Cabrero aaptel@suse.comddiss@suse.comaaptel@suse.comscabrero@suse.depalcantara@suse.comscabrero@suse.dedavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- Ensure we build against correct version of ldb; (bsc#1131686); (bsc#1125410).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- CVE-2018-14629: dns: CNAME loop prevention using counter; (bso#13600); (bsc#1116319); - CVE-2018-16841: heimdal: Fix segfault on PKINIT with mis-matching principal; (bso#13628); (bsc#1116320); - CVE-2018-16851: ldap_server: Check ret before manipulating blob; (bso#13674); (bsc#1116322); - CVE-2018-16853: build: The Samba AD DC, when build with MIT Kerberos is experimental; (bso#13678); (bsc#1116324);- Update to 4.7.11; + s3: util: Do not take over stderr when there is no log file; (bso#13578); (bsc#1101499); + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + s3: smbd: Prevent valgrind errors in smbtorture3 POSIX test; (bso#13633); + Durable Reconnect fails because cookie.allow_reconnect is not set redundant for SMB2; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + Fix possible memory leak in the Samba process; (bso#13362); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add virtualKerberosSalt attribute to 'user getpassword/syncpasswords'; (bso#13539); + smb2_server: Set req->do_encryption = true earlier; (bso#13624); + s3:winbind: Fix regression: winbind normalize names doesn't work for users; (bso#12851);- Update to 4.7.10; (bsc#1111528); + support the new v4 Performance Co-Pilot API; (bsc#1111374) + quotas don't work with SMB2; (bso#13553); + Build failure when quota support not detected; (bso#13563); + vfs_fruit can leave lock records when testing for netatalk share mode locks - causing panic; (bso#13584); + vfs_time_audit is failing FSCTL_SRV_REQUEST_RESUME_KEY requests; (bso#13568); + g_lock conflict detection broken when processing stale entries; (bso#13195); + deadlock with ctdb_mutex_ceph_rados_helper; (bso#13540); + NTLM authentications using default domain/workgroup stopped working; (bso#13126); (bsc#1068059); + vfs_ceph lies about flock support; (bso#13506); + Using sendfile = yes with SMB2 can cause CPU spin; (bso#13537); + Durable Handle reconnect fails in smbd_smb2_create_durable_lease_check(); (bso#13535); + cli_splice() fallback code reads wrong amount on termination case; (bso#13527); + LDB 1.4.0 breaks Samba < 4.9; (bso#13519); + samba-tool trust: support discovery via netr_GetDcName; (bso#13538); + samba-tool domain trust: fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + conn->vuid is invalid after a SMB session reauth; (bso#13351); + Durable Handles reconnect fails in a cluster when the cluster fs uses different device ids; (bso#13318); + cli_splice() doesn't correctly return written bytes as it's uninitialized in libsmbclient code; (bso#13511); + Threading support in talloc_tos() crashes when enabled; (bso#13505); + Incorrect talloc_stackframe handling in python ACL test code (make_simple_acl); (bso#13474); + Fail renaming file if that file has open streams; (bso#13451); + vfs_fruit: delete 0 byte size streams if AAPL is enabled; (bso#13441); + Creating missing remote databases during recovery can fail; (bso#13500); + CTDB_BROADCAST_VNNMAP should not be used; (bso#13499); + Fix building Samba with gcc 8.1; (bso#13437); + Uncaught exception at ldb_modules/password_hash.c:2241 during new domain provision; (bso#11573); + "net ads keytab add nfs" writes only one enctype with older kerberos libraries; (bso#13478); + VFS modules that implement pread/pwrite must also implement pread_send/pwrite_send; (bso#13425); + vfs_ceph is missing async fsync implementations; (bso#13412); + net ads keytab list fails with (smb_krb5_kt_open failed (Key table name malformed); (bso#13166); + s390 and s390 needs to run with 'use mmap = no' by default; (bso#10765);- Fix ctdb_mutex_ceph_rados_helper deadlock; (bso#13540); (bsc#1102230); - Fix vfs_ceph flock stub; (bso#13506); - Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); bsc#(1068059); - Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048); (bso#13360); (CVE-2018-1139); - ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056); (bso#13374); (CVE-2018-1140); - Confidential attribute disclosure via substring search; (bsc#1095057); (bso#13434); (CVE-2018-10919); - smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411); (bso#13453); (CVE-2018-10858); - Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414); (bso#13552); (CVE-2018-10918);- Update to 4.7.8; (bsc#1099702); + s3: smbd: Generic fix for incorrect reporting of stream dos attributes on a directory; (bso#13380); + ceph: VFS: Add asynchronous fsync to ceph module, fake using synchronous call; (bso#13412); + s3: libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457); + python: Fix talloc frame use in make_simple_acl(); (bso#13474); + winbindd on the AD DC is slow for passdb queries; (bso#13430); + No Backtrace given by Samba's AD DC by default; (bso#13454); + winbindd doesn't recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Fix interaction between chown and SD flags; (bso#13432); + s4-heimdal: Fix the format-truncation errors; (bso#13437); + vfs_ceph: Add fake async pwrite/pread send/recv hooks; (bso#13425); + printing: Return the same error code as Windows does on upload failures; (bso#13395); + winbind: Improve child selection; (bso#13290); + winbind: Maintain a binding handle per domain and always go via wb_domain_request_send(); (bso#13292); + winbindd doesn't recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + rpc_server: Init local_server_* in make_internal_rpc_pipe_socketpair; (bso#13370); + smbclient: Fix broken notify; (bso#13382); + libads: Fix the build --without-ads; (bso#13273); + winbindd: Don't split the rid for SID_NAME_DOMAIN sids in wb_lookupsids; (bso#13279); + winbindd: initialize type = SID_NAME_UNKNOWN in wb_lookupsids_single_done(); (bso#13280); + s4:rpc_server: Fix call_id truncation in dcesrv_find_fragmented_call(); (bso#13289); + A disconnecting winbind client can cause a problem in the winbind parent child communication; (bso#13290); + winbind: Use one queue for all domain children; (bso#13292); + Minimize the lifetime of winbindd_cli_state->{pw,gr}ent_state; (bso#13293); + winbind should avoid using fstrcpy(domain->dcname,...) on a char *; (bso#13294); (bsc#1087303); + The winbind parent should find the dc of a foreign domain via the primary domain; (bso#13295); + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400); + Fix broken server side GENSEC_FEATURE_LDAP_STYLE handling (NTLMSSP NTLM2 packet check failed due to invalid signature!); (bso#13427); + s3: VFS: Fix memory leak in vfs_ceph; (bso#13424); + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407); + dfree cache returning incorrect data for sub directory mounts; (bso#13446); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + s4:auth_sam: Allow logons with an empty domain name; (bso#13206); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + build: Fix libceph-common detection; (bso#13277); + build: Fix ceph_statx check when configured with libcephfs_dir; (bso#13250); + vfs_glusterfs: Fix the wrong pointer being sent in glfs_fsync_async; (bso#13297); + ctdb-scripts: Drop 'net serverid wipe' from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + smbd can panic if the client-supplied channel sequence number wraps; (bso#13215); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + s3:libsmb: Allow -U"\\administrator" to work; (bso#13206); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + smbc_opendir should not return EEXIST with invalid login credentials; (bso#13050); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + libsmb: Use smb2 tcon if conn_protocol >= SMB2_02; (bso#13310); + subnet: Avoid a segfault when renaming subnet objects; (bso#13031); + 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:smbd: Do not crash if we fail to init the session table; (bso#13315); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Bump vendor-files - Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); (bsc#1094881);- Add missing package descriptions; (bsc#1093864);- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available. - s3: winbind: Fix 'winbind normalize names' in wb_getpwsid(); (bso#12851);- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigbuild34 15724612674.7.11+git.186.d75219614c3-lp150.3.18.24.7.11+git.186.d75219614c3-lp150.3.18.2libndr-standard.so.0libndr-standard.so.0.0.1/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:11379/openSUSE_Leap_15.0_Update/be996b7f12a3d56812e012720e2d8123-samba.openSUSE_Leap_15.0_Updatedrpmxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fb72a769ebb3519fe76456eb78b0139047efaf76, strippedPPRR RRRRR RR RR R R$vh]3BFNutf-8e17aba77d4f94ea1d7de97b2325bc8bb98f44fcf4ca50509971b0c5fc6ea2f08?7zXZ !t/]"k%kqvb^LU~HMox-osi_c UCQp9>G #Rv38?xjotsw8&K'19;K=A ,I9R7P3Ci lʗhVb]Bb*'Z4 swa)W՟P_58HTNΧm 2F#w!yUY(+;so~ R]RBOR81U1{b 8aw'nθChگoa5MY&C+ҘIKw} |c *5PDP9pZ~=c`r;^|0Rhjtշ ƜVsl.N.DY,2-KOcXKͱa4VoHe)tS!Ƿ}Ύ35) ץFE:?#kVm H_`OoF+&@'̾/䩕MrA/FGm<ThIbɁQP}r*RQ tQٙM.|g*/uzk{28Umq^͖~kBgKI])g13gE{74[+ |Tnb܇]aEg||ܢ;]`ihkuь2sy":rYM%5L`3̩㳵 zC//n{y eʣUJ(˯:Gxv/}_`웫RPDV =n $m:^ݩc$}m Ō,%\8t0Պo' EbEϖRI;hXsv5hț[Cj)*H"44A`^PlᓐhM9UG&9 [Ȑ*~(cVD|&q/- ,Л1Es)Ū>;I3xA. ͈NbLGz0[tkB,џ]\߁9qff_hJ> Aj JQ 'oS"d!mj#C1[@%[zORjm갮gw-3}T;/Y0J!wȆduV֍[HqL:xh:`m9\g_% 䛰^ I`}L_m7= NVxhn%2XF8.bn:@@HyYT_3 @Nx\3/Jk^6B Nr%//-Z`H\hd<Ŀj)n\;JVhhEY8#YOPeύmDj|?!~˃q:)x]YƷs7TP-%w2BIj4_" J}9`$$US,0nJ*&@᥸,|HTEO/#6zd>r)&Ĩ#hg4[6125bz\k68B`ۆ8fZIN꒷uC^ >)qrT8!T num_#tXJƆK銳dYHbx;o0]GؔV-NeZ-o<Z#S@$?Zwk% dHC{D$TV=Ątc?:PQ{Csj8bMl&wԁǵ^ޜ `t=ql:hԖIqz7r: i؁-:):~v౗iX;4XLAib,;_;ƕuB.pN]"apPV|,hW}Iδ_PQp`CAʒ.ti:F=p/Vbt' :(An9g;$mKkbQCUu*>d>n?+D_P[os:bIwRv q͖Q1)"m8$QEG 4ş͗ _΂CX,Xue8*Q8hGxπGTncW':;=c$b*Őm~Z6Ea8ۂsڞ~5Z^{ƀm|Mi9?GPbHQmWfs*QЄaYx8l^z=T_GeGȵEt?겆Qeor2FFEh54G +n\n3ܵ NUq\]2ћTz(;֒f_/O"\XeJ`XwnBׁEgFE|[1d֎pS ^;bNW 9 " 7F{I&uz@S:e,:")R4ad,* 9~0]m2<4}o,u:\oOa/M}JQ,(pٖϭMbgq:ݒl4-dF,wu7λy1-=+N )}@KQ=,M{ۢxj#/AY e-~E*ļpLo6E8o9{gvYUTnjx@]|B#b0#mzf^2To)ם(|VB#!"$JyZ5E#| Dz{>*K{]!%7õ|u,e&%szele-cOΰL>r/ ~WvMQu, 뷹=ڀ[mhd7ϼyZrpv葄tς 3 h& Qi tK+,AQyb:U nnS-hwΰ>G4?AoPd(vca0bC'ֹQp}Q''V%1ċx ?؜+*F O__ر[BIuY93.bgݖ[j/0 CENXLn=$oDtp?c@ef@ >ng\IdE~߯.xXûp&6F.?𾴵Y@K:hB<؁ "~D]βd^Z LA/*1IvHDJ+Un"Y>wZAܲF6lwLHu2D rk;Bouxm;R !zlx9\MTD\ 4iفVB/*|ZA%B!aY ZPdw3pA'YGHp Ck?[ލE2oreytǗ(46:s5>EC I`{u&6wL"vR 0+}yC[~TB}Xv<ϻ-3|4HU=mQmE^ı1[{${1U{AnaK} uG6#ʧ\FK*\\ p7'ei9W HEW=6 3n5}:^DHwƳ\ 9CM'>=FF\j3zU|ƚôE=O]|86|1-)Y!f\FTZp i[2ؗRm!-vGMjGg|v4/ƛ=H.q594c%>kQg+؎*n*_̖灈u`6e57#.s^k8D=#2VU/\kgI>bM^; 6U6@~eD?6]Q,>ܪ MOf4E|liRֱ`=9S;*Q$L-;a1AvB_b=b"S*(䁭U?o0}>,.R#p~挾O)dXH[f&zf>!_2O4ғDx&e(VJ=J\, #Ytptv^VIaϓ SuYBG:aU 4[/hIknUuL#1_q] a|- VVݽsꤺ\^.ٝMIJVd(LOcQaRAȽ$ aP38Ӕ?<̀/K9ZS ?OD$bHT j@kĥ[J#{ 1"k룭5zB ˀPL}YQ.mwE2m/"]5cօJ+-^H>@ 1%AA8/iR4(;͕Gڻ\cDJm,B&zSeT5J,Wxjo= /FE=xVk{ Y1_]Soמftp9tTQWI!ko ݿLm- \4LF΄Q3%х7g.>)Ҙ/XUKVXA,$mRŶl8$6E =־6PIr@ZfCkvobx9aOŌ[M$9vFQo`;ҘB[菦܅G6\gdj5=,keeFcPǙ }~7N7ܽR+M)6S9#uϓyTA miy&\ȡ$a>kl $9JAM};CJVP}>T-w5J\ˇ&ƴ4RƄ=Za.&O&{N=#(dJ`tN]Q2"a˙DUU^%*eGC|ORroHJt @B 4jv;m.i yAXOLk6G MC/ tlm~5ߕx}EGe q̈́Uҷ=GA\__JSh~wCHJQJMno]u$3q^B ^]8 #9D9UT MvflS<lrRkzꐜzTeg"`>A'aЛGnњK4PqmƅSהɉ8°N.2m:F49.,'/c`ʁȾow>pv{ B[o]uxt[p=UH]ubl( ( r $Epy|>(9-{ c7x,ό&thsO?rZv n¸)b>Z<+B Z&xW8A(lJOlEccjgfƐC?RSG<#8XJ|(ŵL ~A?yFIE_YwӪRPҒڼ*ݶn׋tY]("ǽm5 ٌ(V_iW=8-ʘl̩-u#qQL"~rBA%ṋw*0PVRq1yY4MйZ ?!e]o<$fTe*dD_n:&q?yfŗ$fqVU։F7'z;jX76ހE4}1wp=4P]TXzĻ|x6uUZ.Jw3PA}!tOg@r јr˹ڏ݅ʪJfJw N7(!*u/4SA˯1Α _l:xwj";)o۳@P1DʑLBvʽ4<E25R.1Sb9q䥽Kn>QCXr$-]K|6}:"% ;n%vd "l.+ ̸'s3-5뿩8OشGQ>0s QH1n "k2R"}HLKJy=?U䴒S3eFre#*;FoΠ䗻T]ocyT1 Qv$߽JKꕕG$xI Ur~q=PS~<šI\>˄"Ӕb "Řk'hJ `]v"&b+QLGQυѴ:GY\^O`Ul`V(2šhHaGϬC5u@bLNR5/;+mĉH5TZs䷯Cl#x/6o*j15J*wє֪RdՎHofg?}S2og)sJ?ܐ 4ԿJT ]:PԲF%mJ:mĻCX SՇw mHHwfJn->^"pȦSWʑ)s%XInñ\4 uD% _OW}}]c8!Z8N- yej%%1h^j w|M[4G>).Gm\F6\8b ةrJ~WXIl6(CT׿9>Н8Q::`ζ=:3J4&~*L\YCvEKaU45q` a_lvpP$uuk( toY]!Dy'3k \4?%Ad">R64MC\|,q0g!d/;]2@P^*nC y7! <sN˸^ gt;va&kYΠyVK`K^J_a>R PE uk`핻ً:)!'~ˏY i'ʖ})݊97-ct˭Ud!L}+w#XW`ә#s(|ˌ~EP7=;5 gzteH>4ƾe -QULlV퇶.Q>LŠƨN.Qm ?BU[ܖœF[4ҏ ׽:E sUPG𹆧УD pGt4PC 9;u[H[X?(`u k>w0Kܰ{gO<᠎O-eүTKtpJ.\@N Dd-azSZX])zZgϥcIJlHhc!dZEYp.!B#}ixs$M)$ך%wW]>6E$9&Ǫ496ѳ3;4 lAy3j*.9PG"@6PNT}_S]MU['}CEBꯈwr}!- (YIG=kpvTbN\.-ywBgF*L5!J}!_=%6fC=]TO|,ιô;J}maNK-N.辻U9ON 22sSԄ}鍨ok}#nƮ iG-P8拺{(1ݡ_xݞ3;pC1gŒ~M ^mh"RSҀ\dƆuf5/8kIXDe4)vd@ȿ>tºKݩ}#1´ЪtLF W$ر-njݨDU9)B" `f6D] l؅ W-}K¯Ȍurs^ =b H1Xn9 b:D{ȿ*/]"|ˎϛpO}]MM%̠*l{(HyDZx>sGKuOI.19X8LN%T`T&-+~[ٍ﨑RRsm(2[ݳbyZ՗2sA*5ZX56dosWUUR&q0ݼ WRQh}<1mS AJ- +=z֝V 5K)7Y~(-jFhZfbf63jLi8~1'ز$Tk2Ԅ2 }VyaXG]3UF`MWm 9qQ&[3m4ŅUCP w`?($NN rFEV5:ʮaQ>+I6NTYЪc[9SӜ…2&rvDrK18&P+dfkyܦ˪) EIt&\5-6vI-țOZߗ{--` 9_vӖA?G3,= amzS ]z R f nbk\:P5{-=wD~32#P`F&r"&KN2w5hx-I э6tMGP')J1b_>kS}ǝlty020E* 5l% 8"~ҼxmSw]J =,0T!%R:Cm蠯]\[(v10S$6Mճፉ|:^tVv/:5:9Vp#1>!o Fؑ 's`3f16eRf fUV9՝ @Q s+4(~SD txINKGf 㨖Tq7/WERB')|&ϭ tV4A%g;T-ϩFB)m{2*;g@ m?,뷕gڏAAWv(XLߣ {o\$V$Pnc\|wsԤ:/83~r-BԡOqF8=D|#!,HP$2%ᵯ(ѷ ^k;d-z/q|?4vj~/$o;~(>/jK}+mK"?ףUSb}|/L0Z08,e!@dZ?*5H52#jkbYUޑo&CĬt6 !_Z]U 6| %Eom) ( 9n(6s?-u9&zJrh?0!6LM=w)[87Sd1fB5Rz[[E} _P;9|Pt &&j x11rZt3ӛlG+P P|J2~Q^$!h[O KU&giN+W,ΓjJW4B&JXIu$AJk upʽ< &6K 6ܚKHU!̩im[xv\#㺒_e[IȽ+svU?Av FBŵФ; }/u<,_KGܽB>Gơb',\6"#'udYN{Xn/ ?=%bbTJ Y:[s_P 2ꇭ[5caXvawKMa6[M aj,0lbUAO;Kܕ(dP6m)R=|]?\k(ݫqؘ*]pj% w(F*m9m/0~=Qo@/|^6̺{ ww%ޏ){|F83aIm`wqzӛ>\L;PW{;PEo ~γdDhqS<~=, mr Mf(\VrޤeR'%SF2O)[ ^;Px*b]~A*;' XPfXkf0d?;"ąsf&rܙ`5u0 !O ohay~$_Hmrav@65,50 *I:ŕ>9eR-FDj*-g\V-GNlt'l{E`Q8YHuMOaJ,}P+p&,_ ܌M^ |\Ѯ9]K:c:C ,1AD m5io1 L,X‷ I[HU:0r }_?+Q a!V#.{Ǭw*oB=Ab&9"I';ٝ p7#'+JaU[sDC&t,S MiX6͂B/:I&iٱVx^q=_y_AYT.Z m&"ͨ*‘+`H.U* Lό8Hv-@]"rXHOxR%:4/d\ C;):{2&ME*=Ӌlw1l-<"& VCPC0 0G\>8?IlKcQ&}~I~ZNM:EBgu6}H>\2@+?ղq(4 =`Ru F"G]O($dbv ACf)ZKgɣпDrfUZŶn pP> MY N#"2X(`/)ofIصथ\\*1*T]kܙOMb Q * [š,IdΰJ 9!1I O^6C3Q o qQ> cD%rM0'EH';j+B1f5fC, FCh'38/npt#Q]I ʤ>" _`U.zϩsq(YRKR #XRٱ0T ohex_s)D?sD_ F@k~h9z?aP]$ѡ,C ĐE Wa^#d@m՝hJָ?Y3Jz tKXw0ΎaMxYxA)t ai$XA=\qw[$O!*̧{|VnZ2Mӻu{#$L;ݗw3n5LE- `F2Vw! [R1|"ϪcbElM $Ur#>x#_@,f?^Di>zR.›C~8іEyˀie|f6 M^ zvi܌g{*ui霓nY0"<5"&jis'}%)g,fM݉ F؟Щh*xv˪_p\A;uA9Vk.blXP l*U!!Ck 9c>xpQSZg׸bZb? 4vS]4({(\Qﰜ*Qs ǘƢgMd̮~Q!h'TjJe5V{HZ8)̓oiBԋ>?`2S>5 90yȱB?y[:U*By%o[ZG/,4Jʜk  񇧤7RWbԈ8o{lUƗ ,W8{Mז%8 !P[E+<*`ÚtӇ.#DO,]d*fbA }4Ç?ތo ӚI(`$o@`|v^Ejw9 WgQFT;~ٚ/lZ'3Qe#VKKS=:-OI']qzJT08%׹HU;y2 =~6kYDJL[ppI?rQݬ \0O4s1:/D3{C8ԜW}UTAs".MD1.XbbE4(+J΍Tx4,:=~@ˤ9*#(*N US^D|CAJ6r,|E2i*a} |Jp3DCvn,k9Y WS& IJ )8NEn%. ]gZb]8&OFN^@D_슦xSf< W)#qf^X$r]xySB*;m޵5ƬfBp#n&7a.*;PyĐkF*Zѐ)\iKY}.NE$q3u2,ޠ$'a(߳P^+e入zS1 PZ&k$Xx]vq:,:+çG6%)ȥrV4HE^­TIFw[o _i!l\Y:Tql/倾6dJb3 6˳'6ztn&ϽG!DlQ'vh6+ Hr"eԝ$MB%)HV .jᗵ=xj a1ȖykpXIsBbD\̼yC~u4 C U t,͐HF҆20q>i\-UU$!}m}Ȕ!U@ Z˘b#B%+f7>8p QMl1-w][˽S^ZCOƬ`Q~eA1-ŝ (b+&}hIK|֍z*M諸VnpL(7Jwn~R"ШYvəG&&%5w@"݈iIѣmJ^2c*{BF {*b(c;VaLo){[w$1ڼ4<Ԗ]vuYݲz4ضX+n3 ņHp2.x܆@4 d3 S Rxz%#Vl=#C3C6gz_;ydᄥEKZދ"i,FWb%@5^䚖 q{v' ՠD.R^d`$g}XPihYqMAe YBF`$涃Os;FKV׻t&lVq!wFqkCE*lw5JbX"Ő,qr޴W rE]  N% ` UYу-< N1rV&^4Z)B@bR.y28I捍mχɵHk2p[])!hәgz۠ UţG6pvDѐ+Έg譳WF;QkNN 6 5㈋Q/RBK٥ɻ]U'n$n  St*)G1'(FxnYt (~^҉F40&@(4fO { 4#7Rԡ[1ṿړ u,eʼnK&"|sLc|GmI2Quԍ&ǹGS阂,&:WSXSf8~lTχq%uj%&wRI9za#ڜUt u;C,Wxu}LW($BVnaM}c3rGX$mԵ('tAB` y9$pHj< V )ǥ#?Q'PxʾL32?hD@ϒ}D!l)1=gR FK(䵿ikOOqUڵ6AD1]"(i.vCd._DqI|uJԛHm3bP@'dp^",:&Wmt72(W^5hM{`p3sCUFRsټgk9u9!T&Ae wq5TOZ ˆ$Y͇w[_, %=,Ύ萐.; MpSjKO XO|BnoU9A9/5ʂyA[N قjbCM+tv;qgsы Y`XDM(HZ%L1\@.{ mf[kS8GZCzw|Ѐx-b&:LOv 'EKlfDYWa$}yUX#\Vɯq`UɍtW>RW/}pG0DAUeZ:"19IdE *jaw puNµs'F岇SR?Eee=S f0kGKrIq$ yk݃ǟm=!&q1RjKYj0- *}5o}GSKCYZy$zge̵(燄ϥmk'!AM4Ludw'׶0[Guwk|0 ΢RiUӨo式7#LeKB984Wtc0Mw&K f.;[/j-(u['_1/ 6JNB lXn_o {Pt}ϋJlI_<}%kyT߂$kE*̠B6Dr|>[KWn%H AdmCBفira-V)4cr-rŻZPv_k@GfU5qt\p18+onp+!Štǣ=X]tnZ)Q KY:,mXЧ)&uȲN߫wc-I_A"0Aw>oe^ֲ;#johW[ 599mksfGMw9DX)s̨5޾ij 3Zu5]Th'f8p wCRv ':4om%n;\pZR6qJ 窩٪=˽\sr=6>? xL aUWkaR8RJl泧a2kH2wsI9N#֞:J[Pֽ/.骶n1Kxo1fQ.4o gZS͟d&ӎWE|FZCr1kRĒī!|7TwZX$1=0o]Ò _R9Ϲ}}sχ+N!_Uf48tj:kڌe#n9F%JM]B =+>;L)'ߒͺj5mzhbrW>0+K^zx\s_n qϚ}E/m&B8GqLW Չsh.4~x'N5RLF'L(Hp硼uD/4{(1DȒ1נi SH ;=7. 08u]-8SSnA16hF4qb . 'hȼ+E0,ٗ)xr[#V0 0L:.I!\Z-;!S6nk߫dedhh3A4ظS þ ~W5?H3ϧT+sTI%x*>5~eu9"wpx5Y|PP|޳[ |՚=|r^] ǯsst幛}fd_VLЋ$qH*ԝnd0}U|h)9Z-)8ד*DfUDIk؞ODQv<-]At>^{J; T)x,C6RևCl~%!-Lx{밺!@4.wxW<_sNK8;W, N4Έ{r@{ȏJ pz 8L9A(Zu5lp[ Kj=JwP1P.QK/ (`xB.2P okx~jzW&`[:1Ed:"SVϼ[A ,)ivc]H8Mܜ3q)zBZ'Z%4 L!VfAj)yFobLF꠺K7U{[N+i+vVܖcYe󎯚{|n_ڤ٠[!yMqպ t2~$jO8p0'E$8{PbX^XEZ YO:M)½z]s.j jy/d,r߇|jd[=Vr [& [ڡ1^Cb1gcx;uG{_x?H)G"B6,1m*\ 'v[Ets. Y6Ya]X]p`ؚ %]PK}SyEUKj8A+7ޞ"a@S9o}i,} `.s~2ۏ;>B-3.|J`'ȯ2ęH4]pݐEtHq +ۄ ~#gO_͈'@^F(-Bc9 Jj0P -E|J̓̓R5rj|WHia %̚{u [hT'Y?jW1,%5M{$´-A{wr?f('\di[C`sct״f#Իd&CjJ_]yEjR뇺ڡ]4zκi^Psٲ<.LY)O74~Z,p4K M&+}Ru,ʤX@3?B vD0 Bcꦼ E[rEcREiqd޲I7ʯFqk'VǦ]6Dqvaкr|9>zp!bN3+:]usX$qk اDycKtD=b(ӌ̈bI(M гJ8JP+lt\,8K݉7pLF|`\t:t ƺG:$Ma.F\#|W3mjeǁ5aBG̾)N~Y&J+߽#› |zv`g=p"٧ 9!ȎH%l<pݚ#5Bf61`$'cJ^P`X KHT$ODPiblȄ|ƌm Q9ۂ!RrigrVȘo'8Z8@q ,6m->6CW7 ⹾ЃS5VYA\SHūi{- ϛ&E!}f8I:V_;9OͫiQ In+(],75TXm~nVs\ʼn/s&Jk{P~[ϲ>VeDc曬9Cu!ǷXIJ$wxdUhZ_u`gp[(I .4eҙTRzmn[;97:Dp]tTT^ ܑ.9o *cEoY"ʰF ՇtD=q':i1NQ*Hӽk:5~e *L@;?&iUx:쟚*K{58$GϼW 5lQ0@8TbZa #FvX>l84ss BJ9Ǵ7фQmk(ܡ6\d` L7 = pX^)uAbִl |QG{'_^F~Wi-f0)Kȷk eȒՁL!+#0Ȋ6$1,,25K>*(v7 *Q^j Y oҰJERd=.\m)Cb(Hkz q4V__I:%`M|dtv/&WD2К~{Oq}q(EFNCdyEŭzBW>OgoA}[]1TӕYkU G/4DѠ4Sr}ES$ݹ $Fmh>&+C`~V]<ܙ r>_/G d@U>)ADu1X gl vX"H bMg| +`:Тa0]a䪪148GȪݽ}pd!gH{6 qh,EVuF0Ks A+ˇ_7p1uEĂE sٮߗPTkXT6}?awH[K\~{}r<`m}}c Ԙͮ?ג/L,o I]䵦#>U? "ŞQHIn%h嶶ĕ a!TVLJ6xF3(HO9zI|6BQ~A?hrRyjqd.֝oph7c-c8hZ,5vgƪQ}=BSQ;@եƶ_*/yɏ&ȥ2gnuvXEg0OC9]}O vexuQ :{C[k3C\wgBFm^8Z>^(Aaܭ]A+Yz)")fwX}/NK@\vB[']5HK+5Ι"ئGC_@ s'|ΘcC+T VQ?Eh!~a:o#>”+}pl0c[>%hvA{oW*.Cg1MZe)2myI5.PZL%, ( (|\I1}RlR[ u~NG["5vl!v^,Gh ȅ B@T@vx*;Y,sx+ܶItim-h~8A mǿ7Qtyʀ>h/c(} #oE!qMizHVLzn{p*Li(~AE23@F }E P+q1fӆ䍨u]搰V}>$Q/-&!Gl3)4^1o##km\fUdžXȟ 痋Kw|RC説+;ޜu񖕻Dj Y254g%K3&xV25>8Mÿ*;ovt`y[q$k JM~DY:d`ꨅv9j)o]=XM) `WMrjCUƴ g ;Je1x{8ݛTCDq>@ƍfMkZk+F+ex>Ք?spDC)kϊ=k`w^oіȏ:[ a_)6679 k d*t1B؍6j?ԧYqa-M/mϹopҷ-B 1Z ϧ+v D:}GrgG=`m'14ВҸM.$Fiaô2zҁä#mZC9|1TtQOgVW 0%yiѕ}XUvw[&;SN'-A@G{޻BXԼi[ߟr y,RRs'&Qf xbJؚ:K4YW1^L_ (ڏӦMh$&})*I V4?:MDF_X ǁCY q_`|?߱d5yA ~jŚ#=:?惋iw;%\0iN{,[3 s,B8&~pl6  @7.2GYY]$ huIgb!g ޮy:Wcmm\.!t Y5c+eί:&~}݂a>V Jk1n;wIYwMTxj&|TKǜ#=5G5N2L&h7e-<:,B*bAz% G>wjM5{USce?vQqf!LѩbМu79_&L";ܑ*RM7eUAo .+LvޤLZDwsP'n-{Ǥŋu.T6r2ho}*:Talj= "IJ iw>9cKmf R 6 qI5ԸFsH`EOx2Ksɰ8ǻԡh^ ?~LJ]ё*?+Ƞ^jփG16bޚOrŨA8Gdh+^!`x@IOޤ=ذ=Ō;zՀT460]uMs,Ya PO$h uPooM+E!Pv-(6m& L}*y fLg6“%4]W!Rjmr0Ab r2#\iN?c`l _z _ tvF&:}M[Gt(WG*)`YO1ʠ8j}Y C|V1Q{Du8R'}$6V=tj]ćOF*Ykk*_<<2)gT_ceQ+q9RC,Ncpw/;N$a n.)zY[BfZi ] FjEkֻǘ9/-fĵpAp_j+MSm'*Ky"K@Q^ԵH[m} 9lf`Q#ݏۖ .[&#M_Ҁ0XgeHzt+PRC}8IH.e 1ҵJىRj>gh2 ;TL@ 1 P=<ҘD'o~s8=ö6_ۆI^ʙHMCF4mY:o=;(J>i+$ߢ}S9w(u 9w!H%MC@hhli`?B{֗ea߃z{S)VY ~BK|"d蜁7cToP,Mm0r(R qd\1-Ve2' \K -rb>uI#Z#1d3줯Kօ:>T\ܐIH1XYnI&3~g}a,XPq"VEA3oߑ ˀ˰hiO)K;Q8LlݫJ%p jg TjkşP8FB-ͅR:NU]b%Z$v BP"umP]XXKqhWI=g;U^!#1f*HЕ:Y@͛EmַZ+8c+V =u!K>"&5q.^s[a;I6@]rQz1\{!8YpKo(h0Eqhv+zJӖ0<'g9@2)=C`NcqkPCQNU3Ѓ?q]I[~ٱ{~%L&ԅrS{i'f<~HWbu 'NlŎHW:~n` hj3Ҏ )TEtX>krv lt-5]zr90 Aa]Ó"R$r&B|v< DYUeyp'`;o;`4-,c3ȼ̓>s"EhuZS b%:,z~ GMAK/xJ[N=6l8Ql+CqnudF͡P%}[iG "*>k4p3;>(^ c|Ck-Ն(2;Y0s<njk|eYkx/?őy/w.׫ZJSԾydo\5Re+T`.7%Z$WEd]emзlrs|3Yp悺.'b06lB\J`ErXUŏ'kt7}}/ 'AMq˙M|R-'aN.{O ?出$;-LêN.CSJ*'"9= ev?0j+\Ym_|s.t;\ȯ ѳRA(H/R.m~ Gf $n7oܝ%DF+&=cE:W<"t},N߉8JPhv(5gvV>GYfy6`mr*[$8zfsM #eӦfRls(n`\=ӽqil]6G"Y|t\KoRWe:'Pኜ10e J;uFim̐Ԁߟܩ]N 4Kq"`C$F௮Uˡ4*ީphI|y e|INAqJĝ{o̐LBs pߐ17`(yXEi,? sJwRyE Bm%,5o ukŦTʪկc2*f@V( %66n2͋-Z߹M'/BЛiZIVO^}'*̥: 5 n7gዲHxGc,Erō(|pO3Pʗ*OOq&LbH`WUẀlj $tv%z{2m@;¿ݺX1mߘIY6~EjOÓ-# 1W +t3_CmdHmSMo  v:r|xF!,B2Jlۉӳ)>lj=n:3|BhzG`+kry]T?;WSJF:k_0; `s l&b(l +Ipyn\h,ք@Ung G'k[뭒H!ڿOWiѤg}@YcV1MG;F^D5]joI:Į&KCr3w)|l;oC3iMQ񾒓n@-5O~^/^> n F1‡3m7Aӹ5~1@ru%~$j#?S)|Noji4>xv`jN鋭}Ubx]1Q/dT^ɂbk}jW mNB:ن&d@)5i*n=wl,D&r[50'hvWPH,A-魑c򾶞1XQA/LjPQxK"dc^ GU6 Bچ3 Ai\/D.q5H^:5ƯN%PCx( ycv/(3mL`Kf=cGq}8"$siW ܫPTB[Nh@1&5?KLYS$l͟%8>#~on?z:D${+w@5"w' bkr8nЮwq!`jqِq//}i}{U5;rÃY/fE!R]Q3,3\؂X*Һ|׹d J.a"G6nRR2Q>-e< ~lg5FI*'&xx2'e4IJ&J TR7,Fϳ4e+ c8~څI`gNp8~~8۩ex/0șf/Ӓ(#{S7;]wi~NI* /. J]IlaTNZE tB{yrc[;`B5o*+Dʝ.+򀳮cD+ P%=yL.i+%z+!`8SEC$Oj7b3֜`ӗX5SlM[(=NNs J}= :$dM'5K j?k7:]fJjr$oh&>_)3:?C\|O`WxۊXga^}DܺcXEOzېWTش</v2"Lwsjb{--LI.{Slev%Xu-)DWjz:%F!YTum"?}wAEUٞê`Z\O tgG43k!Eصz?K" F>QKƞ"*f~SBFT1K+$-DDjoFD(U6bN mg uANjG`m*K>-+oc8;S*qO%|f&4|s'}L: PVH;qG!N^Kqavpv7I,]P+eb\2|BV &cx1coc!ZL*lYRdOz.:C6,W>n{v_ܯC8чeʢ42sy ~Ja,EA(`jOl>K*]!}ot(HǴn}ï T^fՊvމя l}7b<~twTnGs6o?0By=@ e/(h͓@5RQa#`N*I%<H<$$Zx`弓\Zt@_l 56e g4p /|hCV*_˰*eNxWwӝvz64ީ.^FYJlcVfA hSѻl$54DQӔ5CWؤbzSy:V73S L a^\]YwLL 7^nd/YnJ_lzui8LmY /9SYِ\٫M y'iAh7J׼_"?*:YfcD-D ikށj\meL4~_xj\ĸR 9W )L׊: .k"&-UP]Szt`nw: \bp6Vծemg0Pmp1ӗ֝ [\_'(M *ZUsqE; cE.)K5+ں.)bQϖWS½k2 7V)-gOÓvtdjWe<6=\88?;qZU I`GX XOCʍ1!7b4:tB*ދF, d/cp׀`3G5ft+ڌzc'CVSmY(0j v0gZikg{άX O, 7E'֝oR+DP 0-Ia:m\X/HC?Os9!R%&)Z̍&dXa%Ÿ<;rve4IV @q3?H]u%<㩯N/rT^#n0,?$CB]g271s"Xe)/^wg#*\3cq(}{H.eEz-i搋![) ⛋6ҙ #3cxXNτIfUt* =ĸն>6G!7Ox.Xj^* }_YI(R {0Wa\ȅ"P}o[*aD)7n?:Mͧ peM8"a^ OዜD8ĕfmH\lrRbdCO̟#\8%I^'R0Gv֓ 6?ʂ.3ñU[adz]F'9~[v@Nd3Ψ7$n`*9t.t n44ye*XmЋ=~I 'h!$| F>'˜}}lyp9 B-0\ɨ5z408 qs_OUt Eͅ#՟ŵ?XCd\Z6xÐq}[ZwܝbX$G" yh=aBwYA]QucޘPza0 ZW5}SAtr_2l|}Ku3eݞf$TQ - +}|p|FZIJ(RڨE+$ ݸwR&^o&!AטMg^d!}^/6x}~!gy#º.0^oELi5;M5z&+7p+[M߉fC'>Z{ d۠n[aXf+vf TOP҃R4L֭L.Zr-H ^ʋ%uZ:ڴ]D LYd2}VTG0$0Tn8H>YJ~ib("(_g).0ߊr(OM,G6?EʖqP\MTA%s Rk0 YVȥKD˝Q#4D)Ng8qwqdA7 &F'f~Fh62 ws,巖<$ rބґn )|1_L~;wVr, M`J){Õ_ ' |>›Z HnA9Ipq- 7̝{obbrBX[avJZ %іgy]q3p#d^U_NSp) [$?Gzv X؏BFzf# / ~~`-鯵Z]xupEb6Eo݈{a  &wg GHU'z;m+$RHvg-٨&`MMo,op2Ϡ;&qRuqULOoiQL}00duV kŘb7jD6fy͝XD+mFq; %83_%l>CvrU_WMANq-X+j$H ?,4;`?;#!DkGV;6,%c _]p),;}S9zFn5!⁠#r矔'rU">iߣQLHWKmGႾDOj>$HUִ*tEw6}H2LhUZdԏh$ups`ڭ,4r5 N^ <ڈ^AP\ŭ"&=_轊)!7)6F:5xͨoCl$WHR5с"? q/7F>n n1+7`JMٖVށ~>)49jLiDcs-4 T4 tffiO_853DbL# 0[f8iQw2ޓN?tWH˧uҼkDQ7AzO"&LkALoUGʺLlg.Gi!"͈7b]PrֹSxYndn};^y;iks6v'{" /?BM?RQ@_ưY/4"4JUtnMG;eu×K<&rj*f E7#S|\g#e7?o^Sf5f^t]mvv;W:6xIVPeª%fK;͑)`>{jN9sq^8$B4|P J0V"E c(.ų)MrJt͢_.\)uBoA"^sG /XD~eLZ2At|\C%h9Cx[% _`ZK?Cp͜|/MʄSƊ:3_| .CWƒN|5&R-|bwߗ傩ŋVS:6Ig y҈Q #:dBALjcx7\!jp\/V|4 $֤u.$00¾^ޓrK_ܫ2Aw{Km_\ӳH4)`]̂iJHJ;/(#AiXгꏰ1v R(9UsLa߅Ծ6u-XEFP0 Kl_$d G ',ʖMqW\nJuL~ϞφED%h5婫0)rXOMy-O42pYo4g r+Q/<,xu[Ah$e]I-7;cLo$ƅ=9@HՖKwiJ%I55@TE(Gv|7;;u˽F䔲'ph{¬=)t~cw>T{Y*mdk *x%YOOTvLG)ue]kP@hڀ,ߠY=ru\|rFS_;kỽ. /R@IQH0R`TL+cÄ ЉwZfxs2kXӊs)WV#IڱJ|7L7$/'"r^Cnϕ7r}7v @RBSL[5Ôꦒ5\OUQ[[SFW: ̧%21= ~mUG[XY0|o_WTϘ8ys-&YilwZuZ>00rB T5KoseE$eQ&1KӠ:sQ䞯ƈ9!:]7#M1眔 .Q?)SHDPDo(-^O2XQ/Mr *Iھ¾ :-c?-u\LdQ\m6y".{}~N-Cbmk&,NDY M.`GJ2: kV`5DC^OaJ:#&SEЄj"xډԵXleM%}SXArxN4o%Ac 4Dř/%f#4n^u9=RqjX(O 4~x/q\XPY[KX9B#*pZ*TTtIeʩV?+vyڒᚚ>[9y"njjA}1"p8བ뭱 X]Q@CP_pK3^ElkD1۔P &1<)} {5$b6C/7Maw0Ma4%Ϛؐ{.r|:@4$XSYBY?-P|kPT\$`;8@TuL_ _Ǫ+l;`33CvO;e [^S?>/Dʬ>X|8e x [.RJz \'c(]·G7&Jue3yjWo<m5է\:5D\)C͸Zm, pN u@q?cSY+Hp^~'Fj 6HrAf)$]ؠ%lHpIV4El?&w(OOm[}D(8p!I=Ak )*Zc~fkȗ;涎y_GRk#_|rf9dm v[Aɵ\|輵M]UP#abd4Cpbfr99&^纈"Rl);T!AS#1ccAgaOHH6K`HOB0Jz*f{؞NЖT$DPuݟ VwVHTY|ɀ~$= LeK*`w0N .OI1yb?>r%wuBȠš4g 榢1_F㢖ʖD:2F=B?i8'HFR]0 Ko*pA&D>Qn{;OFxɼOy2.}jBE+=^D#)Mo7-]g&meJȡ U3^{V*2!,˗ӈgHX-K/r:jWu?3BXUx|;UߡHqiN>b_&| -W7>c%A3R3 Z[~xL*#6iVq .ډpL^i@R*sLܔ6G1 yE!" fd=~ZZɬK[#ێ]5^nJ]xbVoD=5 w0k)Tc r\ \/bHIgJ9%C>}Kv7 m?_KWo'A/>`EΔXΛcޟ5Q0ԁ^vNNxfD4um},&lCSIw Â8kh@u3ފNs3%-$*jJ>KJu f:+&(!0ы|yGQ9ҲPzCU DE9ld?1u{2ѵS_Nֲ0߹ϔ ;f׃pkū TlGD`gS"nFLԅ™7OR,f`!AP4br#Aq\ab#1{ՔteƔ$iPUכ4#T~^k-i{PGC$@ueI{D9}[A E,a>;TyY4MhώWE^A?@_tЂH~~.ZC&KQrti`h/LI4zqg&DoO88Lh73Qj(ՃTly] 4-Ŕ?)6% `N C銠 b"ܼwd㸡e7;oL,l /U`܇*qgg9n^|?! $#D~5"_!{Pzr~"*m)o-l%|VEجak ڮ`뒇>Jgzo%ɓ)$T 0W^Tg}1 &;iX`YMB|7\`/[ġv9΃]yF'hRAx%<}`w3Wԥ'eT*GkoQzyK5@Z5qERֻX̓U1f<:ED7.P TIp"mˆbYW EG޲P9FyͰ.,?uwt-9dëj3?ՙcVa62jh&R_QqP孏RSr%$]pT}r;=xT#nߐ~ i;Mޯ F3og s7~w75 ~(΢Za7RtxNMUtFgx׏WuUƌ t*par4Ss#ba_=ںcI gfa*721U$ h)0נ*av0f&9fA3=i4U<15:Ej_g $nnPv1ol9l*!];C.yʸ,gSEvo1DyRn4[{Uz,jsIR5%MmwO?Btp bslGjxB?RClŠ{iclFJsE9.$oNnJ$$ LCP #/$N.,- 8DG 3x[ r xɑg&B}*ݛk<©1B7\MjΗ̬>Vn›i/o *2ΧmPl,1xEȘ@ot0!_!h5𗵘EͦӉ hUv4xT*) / JϘז;v P!_\5Jvldc*N5ᠲ gfv6Q kU0bg) *!MI$ᥡAjn4C:,a8V'tS>Qǥ`&/^ا9 ; 'xqnFd*|LB" {-~D2 Og=Ve c +Mӂ5 2S<:W[P3'm*%@ڲ@|1R(1u)z?⳥}rbG0dmeocV @r;{H+qOw5T3Z(~q!o}8ۑ$.Db>hoTL;|\[Op0:USd!Zq)~JB:xJ+'KccjD:^׽eC& $_qVڒn}3E?4Xp(k!9#ru!V(}ճ%z Fo NF[}?,_ ԢBpX5Ǟ* nӅb{`t2V& $)2i.]9^|cJ%|&J%U"UU6O[Ac,B򚸆~u`bױ{CK|дU+N ;&yU7$j;, t~dͿG !?Hᦙ BL#wpE"H{_H1|,OO oe w{`gIܤ~J5%m%(KM"0sS?~@D}EAJmChSdh6%PHUx݉-s"cRJB ߸v37kO=/` =2(w:&,qK $2NMb'Lj|Z ,Gz!L~c,31=ȃ Ի|JCe'h`c#, #ːf44@Hawm8ʦ}O֩X3'-+8x(5 C{z 9IF7?6iÊU%GG[2tEu$h0dl.0hMv% eQ=[j,fHk .g]^XTJqh_"H2@shPfщHhA˝Iw!ʘ$lK$P2Evr`͚l]\%ZϺa}Ykd>B~#+ytdb=Al(q[ܰSo/?W4[3;(T~OA;>J3="HCMnXYL/ OZh7ګ0Jp#"v)<}Ja2PҸxj:P $CkvA$$Yg{F}5(r}صE5m}MoLPJfI0KI$ amYCutO.%K(N"IwGu?2Ȁy%>VG02= b\̤T^u{|̣8_).$fG9޷3pbAN܈B$)]dܩJ!ka JhY敊{/=4~?6, ̼7% k_Q:O.bRHR k;\\]UX9[VarWӗJ :t1 ?`IP6 ʾ*#.z(y:oo{W6A2_(&z#3׹ـR*$M[H4ϣ>}m07If}<:jT5? tܜgnwhOSl_OjfO^5.vxw%+E ⟬;O -V~Uwv e{PPʔ2i=+]'g.ʗ˛TyŎ2E`6*= ;9)ϫ !O9N-Sc@͈E2ʽi?{6Y}bhɬ{IoB(5cP=bx');D,MfuV]Pek8 oCHYzFO<|Z-kgGԵCVfpdGSf@V;[6[̀"YkF@^Aop#М\`Dۚ&gCZ[pE ~KJ2a@h,t[*tD flki3Χ\2Wl2.L+} %<đǽv;|;ۡU؛BmGSک1ͤ$+ {CI8L1 & [R>3 ޴55k4?2ke}}=:u@  |@U<%2Q[똗~2]j&.BK;a'1R4dOFt: 8&:&5qv)2c܍5p}u|M_/D mETezhUWZ wue =fd~j$^ڪe"xz30;xFr(K$gO w7pCU"O(<wS?a9ǐ W >Wx(FcO@_xu%2 }YMOWbCVG O1TҘROb#6hm_ ؒ[;g͸,2F#0M*Bk) C01u$!+gZ{8_@bIiv|9G٩IVH'XkM0q5P+*FLTFGQ~<;f`҇,OqF-+{-F’ޖ\Qݹ7&NC  ^l/KME7P8wBNQ Vm&A!G!ЋQz\Ork1BZ6m&g_E7\2D#mV|hcH/íVǮ,2Oà})2x_LsDݑ(mB?,Vvno:VcmpQO, WKEkb#T~ٍ PFh6ԄHF#H2~|q4޳1VowRi)%mȗr>`n%8߽/o̡Wd ~fLU$|߫~Sp#2LZdҎou!6ilNms{~H&>oTp.e arg^5W᷀Clζre%;t?%4}~i9gOB;\FCf5Zs 翦aK(#{N:-'# pr٭FQbBXآCSY}YNgJ.87FM~M[v֌5gzrls[MÈZ'f0-4{LQ!VjC-tD%Z?͉r0DKVqdg+jhWP,@G"3o@ӳhΛ+Q.VЈFs(±$SWt8Z BtZ i Lܭa|+c&ž/nƩ1n /QIWY-v"uY:>_c^PVZYRJ]P؉5x[;w/M% K0j(m]/`4HzUm+ZhT. WlĨUsv$͵M"xDÜrdto7ɷп.U;Fo\.F5b`_x+ytg'| ,Fkh>ݗSrP.F*B3e qI2QrDWk_C,"zb_λ;0t;Z5xyv#Dg 1ZRu @o3dѱA} ] !c:;(P;,3*\X 2 1_QKG`t+C'tyۚ3,1&9ө8`.;vE6&c9n@߹t 3}X)h "(ܣHy$TS*M-8`b/^YR ;9M{G1EęxkKq 3QHy ΄6Q|Qkdx66/+kJjl>*PYS`궓0L%1Å8 .6}ygiʮ:Yy_ۚ~>͞ G?/f7n[>' чLcr&|PRmp%ihh]  4XKE;t(Z BD[[dwҷD0t[Cgj4 peIdoG< E8uؒt TA256 gk&wܒb{YSپOōI+Q32?{nKTh{3 CZނe=$([mr!:,=T6Xu/:-7HJOS;#de"9Eyhj%0Gfszdzg^%QҙPJo#nY@l?W u.BES8Yzc~ƦrB)!ݐ{J@*'O7@4f[_`W1.1v|^-286|A)f=oi0.?7`>{[Ag!,Fosw_˭q)Y@DQxLA|Km՘ ^ Ij3Ce NF?؜ꧨJ7#SGz_04 4;[4kRTbwq;7j{$VFWo| ~݊=%KDMDx*9coFg CԕڧqOZm?: ;&=b*e A?_uBOWmS'pj~5}wʠ=@oyifijw%E槅#e$Z6.lH_ \Gs2A1+A6i)XiSi&-dsn(l ׼xlS2>{HԏbnXWEߚy8cWE21w7`s ѡ,QhsZ~1+Df=xW=+V%Vt7g{cp@r9= W\͝2W =;2I9Ext_p=ǦR>tޖe Fo`ănOі]bJۏ];*$>Љ)/gL<G"k0÷Um8 tUD׊B%5c)?5O p& [2չpT%ɑNA|F6\3_e稉,ߖ<%bt禼mR?tN1Tc<07CGcJ=p>YW[]s=[Kl-S@!n`4iw[ !ۢĿqa,]r PPIJi@ݤ>qfƯG_Tvz*܀{rŒ& UpmՕP|/k4s21(HBz;d2ڬ缝Y8A2j3s"x´u!siYk S!Ⱥ ^$E)C"Vs#W-E+JHx59^c_ijK ŢߐpPczrLK`uw*ed(݃VN\[T^Ǩqϙc D -|_g8:p$HUŴ6QFLb*/rp-L=VԀFDD(Mf;錷K[k;ȏuhEة4c8ƌ#k[@x"Cگ(̤4Xp%I0ԕ8<Ӷ MSHG ETo!M;煎c0Ue|KE@'#r1h# cJ/҅Ja8L3c[ wqF(mEO',/4 GkI^Y?hQ"}A1S% 9EzH!Dnfumew U]- lvK\^bxN1SĞ*Oaǿ0 VHƫkZ+m_BL*7WX S˪w^Zxe:9320f`0Eޯʬ!D2Pfh&iOgYRXٛj=+E~q6 i$“ݹӍg"*ޗ-,jO^Ӝu2H۸(VM *$s` 7&*Yļ2rHt;.3<-I6Wф_!<;^-:bbPPV}TWSWH9֢ ˻D`AA%vw\:jXoV?ǞM˴6dM v7 aܨ."OVLq!QTOjPs%g ]fP~|yyP*@DwG([mOy8!=3[O+17,_ IɐS=\6<1/h(t5yO80\f;\"%Fy7#qQ_/;nv`(Rcixgw1<\5l;gy8K wіFueգq[`6"NȮupQ"f(5mva27倱uD@3_>"ԌA$P0PS];UJb*E#_:I+(hkA&ҸyR`r:_tgDΛ5N.NVisb~JvΤ8Vbb>j#d#%@XM]*c:I9|!x[X񡮈(s(ڛ8 z(VGu/NGYtCR-r&%9Oo>!w5nU=ԦI K^M6Yۿwmf֮{5V#pearRWKXv{!Ny琱.i  *,:2(qay?y/;ʏ]ڄT~S""`tqA+jɫ_v_ՕafEOU!ggDki U Ɛ ^c F_| T;r[aL N9Pkl=E FsB 9^)KéH8cdc"MB05ZC;Sq$u1?g̩F4t$9lڶj)7绫Gm /{@ p=pF 9IGzka|&o)"?4!EMUjPlTnv9o%*{oafG5y]yJx߾dr"7ԏgӡ%P:)1SE߽úoB18Bpv8M@ t5krTkRzo^+d'c@#@XB'"_6qV19@Ukd*Wbs[R^׿qFhVӻO0\Ÿ7ӻ=el2bAv)30ǻ'Dt@n=%eDOe6MQ]-+*J AÞlb^^3$3# Y4\W!5˕=aŰ\!ߵ\CnշӘ3}&BF+^$n;%L/W J8ج'#=Y):;i8n#F ہ_6^Q2dy:̂8܆$dYU,|1Ji7"76ۀ_7EtC.XEWF!"OToyewڠuX |e<؅LPp>Jb)x֥[AExu #4P6ܦݢ4 5u+`XQːX b5fDs$&Fi(}`,s|ZgYl#˞^NcB&t6[Ԓe]qQ&Zh2T^ ;2J[Y;(ʝ?Ze UNa/vyT9Q)`&5vz$Mm)ClInwCU[g5H`?k$穥 M*Z{K埵c[Ij~[ڃu) d*2.peCG#p("XALſ5u͔Ym|8#!4tyi(!:r?3jȄRT iA|}֝XNw t\G-Eg5hHpmcܠ<";t'0 /,T.cLPbp}tW@6o;OM7if2Xϲ<$G9zkrJ2lrfL: Tg.^ `y]ezS"@-wQ6Ծp3Rsls)k}%VDZYQ= 8[ yu#>T8 <ǣV^cY!7] ) %!0-uZ*,@>c?ж1qmU#P1;Q%nq=Ke%,GOBl qvZ.ͤk/ɳ`svUS{`VM%" }ݶp: Q[,2薎 0Sv `䰓75}kt IxC2yi}]ftg]whWQpL4}TyH@?kŪnAW!uAO903{ í+Խt{^zׁ3%NblΊ:(=j3>tȄywlw넪Ou0~ {U^˭Hc~RI 3Ӑ5٪Hkz#D֬q(n`5"OM7:hS,6)n3wI,XQhQ`9='BvN)7An(iL[NTT[r+N9qDݸ!! tݯD3J=Ll\2܃oeA"wb$W4ڴdLF/r49Tl1bl)U#%ՊElOhtJѸs0*{arpJO+YDB_H]QwgݒOy"X;E{ i>U嘻"l \d-xtp$A$*z5"7Bf=qJVwb7p|QA ܢFS%Ve: m . z8$ O>;y r@o8VyB9QQqK%nh< }㲉$B QWU8c]py|?;$01@#4쵤%<7oGX%(ҫ%c1EQ$5R$&wɎLcSVVw|4v m 6Z?(n H%Q:nc"f%/#<<ϋ&Ȗzx+'ܲv9k]ޞr8_K-ٛM{c3ZCj5&DmDVXԂ_(E %( iJ 4pXx2ӛ&ܴ@j^1pseG[ (|90䘃$Q_LiTE3Npt|sfE3j.5D֣6\ k`Vȶ NP7oKYadUx#^z ^]#lϦvÁh!dݧ#ǵǤ(dd.=w|o5N{u󽓶PWI/_p;[m4zgoIy7n_ؕ mOD@w~] 7Mm0>9`*KGˢ[Pq8%Tv -[ [)-MORg'Km&4o38_OLkyL\6oGV>p\.gT[x7vtEuW0Zs5qDloXo./`uTHRZi~Yllyv5?K?}xN<|4 o̅/vb}0tLlبo.{B֑NZ/oL`E{|ݗý%7^\qx%]HQm!]x2;FݹHXd;W&~w&[09lUb:K^ y^ 7ZK'5}8"TԿgXx,Ix*dPԂ~@Ň)eRP 7-^8Ɔ愅 tw\-^նJ|٣ԋ#\.4 RVAB@_E"xO`V˚Bص#;mоs,h%f 'z8`$txŜ(.R?ZZmBs\:m]BTjI_\+TRJ#2憒Us !oÚڡN?wV.}Cky@fDރ-T/!LJ%άTe"濟+0`@|P1&yèF9%!xI5[5ѭ(ʜH/g{N-*znwsT-Y+hUu2VR+=b,xӿ_ϼxذ(%)'ʧB~E"5gπ XЩ@rq}(@:'-qD6oxo:fs1v@++=ږZКqC}:u\$ϩsM44#V(y?U8-u 9ב?ꚏ k en@'Ps<{;e@m#2 ?"$GL;䋪⇬K7i'TlH -4/ VNW4#WW%++{J) #36l#wvgfs>$ <Bvb0#޻Wx;-iP3//Zsc_WTl@=DұM~_l^^]8[a3W6mDHjdf`hsmAM(xTP= nV/cX-N G-^lf!7|j4xd~sP T{ 4&4>e̓SGb϶wYUlf`F>1'[†+Oh.͐KSTw5Ч--DS,Լn`]K䉴0YO/ظXt<5?ۓ&cѷ7iv`22"Fk0LxP{+.ːX13|h rʐ9#z)HF:)z}_O-y|d1C0zN|ϓ~~F#Pov.AP׌HLXxyjJ@Pp lxl˞\H\_#?bwKQɼ6/.!:q 1]=G8#E ;_@p9d~{>Ax`H{4,#@ :ڑmi=+-lg"OV<Ґ '+C>|WyCO]ä'B*i+̂ʮx8XQ@k]=0}@Ģ (KvEX*Q"w$HХTS,u>mI ҉{֗Z NOem{ƽWlhjK^mE#a=s439ZiSHEVq&W E䅹~[KR(I!hP2u+/'&HhoY}|=ѵ4-S_{KhN$Ec& ߝMKVz4Dٿ,V8֭/KWVl0(<Ŧ zߑe؋0O6E,Op,*C$^` \L3e9GBٓt-*ͱxF@ U%n"7!\$ G^q2䵹NQMlV.qa;»= CU=@ .?B?P;X  n>`!m=&V$#>c 'y' * kVVj'LJM x՟mD;6^ă=CIѩѽ|B' f»LHy=FZ4x,' ~9qqBf?15Iy?MA )Qt&beh$-!ʎwXC#%[(yCvz?g}#X CpKQf2Jy`:83[M,32HOaF>_<MF0^4H I2KluJ/pMtoGrj"@0S3lDSakCRۚ4NNecZνBu!Q0gBѢ-LCWZBIW:CUudx}Pq Fgf9GT¸͠d!"mz= `k{ĥAQoaWǾa$Sۭ݇9IZk2Z*".hK8Gt,i=iw2d4cyJ1?/\T~5^a1>&Ь+f )2(j0tk={M_IeV@ѽLĉP:vyx\IVFNE}0tuU֘[զMcE-PRIj6c]f*gR9vUΓP FULb`VϬs}TaEs@h8.i uWxș}p>!>BڂAZ`ILMWf/u^_F:JI!hvECg'gR(\S2"%*R,sV'3Ŧ\JG0"sTUcOrҬQ)ƈu]Jb)=p|Frs҂*pU]˿ +6^o\o߱| L/FX Ub b4`?ެ%,܀8OBU 8VۘVDޝrP4Wv[(aTAY#ؓ8Y5ӵ23ai9WP҇#DZfvTMH.bn_[ Yw3bPԼ ")̰YT0x2.Z lxiq rj2-SVW6L ^ K-VgJɹy'S_@|6 0GG6'[cmS?w\abDZxW0) oi?qc! xa2 pT-E1cXXR?8;荁8<EJga +@ 1*jTx+TnZ;ɔi,QGdKdy T[uxR`F{ش͐J4f|rՂ^L5~6]f>XqGhD|ﮤz.R0ywnbQ. (jRZ@w<6gl?kS4R ػ!D=%.8f4"667]h;$Vaٳ6KӑV$+. 0X~9cfitR?TfҡW Ђxɥ?&e4WM2\LLޚsF&?0 M~|S-$Cwlvq (l"Ϋ[&Lp5?"!v.8Xu"̦I% (/81NpI㜲?ǝ6L1?e^t""}]۴ vC+E+8C{ԧSV嶢=1gҮ*gxEЍ;O\'JW#yYr&pI.Ҙ꫱y=y9cDH@OcXc[ Of(XS:|PsLSX:_X 5,'32o%uRXu=%ZH*k{\ҎnGicvmX>~Զ٣k'5NF8]f8^>b#;H -bc+g'rXRf$KR9a_lůêW=oW hԖBv0F{3t_pp KtOG3gxl4t؃|nƧx:7rd_:nY>@ᝇV 3ǓQ iXB, `2: gKwW§2o[Ұ|TU٘d5,vӐb2㫔b/5eI?$Nј50ŤE,Sk`D MoSiQfaJS&)z^hZ PTI?!o9lØ3߹i*ǾZ]Q0H|5We\KDhbVjL彸|"M{2kFf&q2Wgۀ_;bF}]dNoi['$LIN6Ԯ($^ՊE8x#,pbc [9")S$l\xܧ-`" 2u, OK5} CdF-@oճށ ӷGG"k3E;($Zd%ZA]fn ׍ڜ} T5{8`觠h^tMƪF}Pq\֜S-!X!@yf43MÄ?"+0˜) ;x,jWF~gF~ڤE|D3dV~m*,?~H^٫}4߶)uE[}Gh$@'7߇ȗhԩKzSWYic6/S4#+( J 4UUI3sJ`wغetngr0F Ԍ.g;|zH,(^E6FOe^چڟ'p_Ir70ml U*Ţ(b^l)Ã/ptAzXz&u<<5DwlzϷK)&UCFTfdpe%n4kNљa_+ekG]ˇJ?kvօѰR֮lzNLzgy#~AZ׈ɷ{σ?@)dL !҈/,#Sݖ'cxpxlUUhd`9kUfkU73drt(:?jA͆1;kbh< F`SÍc*r+)*_ºt0svY^%i٘X8Zh_+ η3  gkZK)]7̺:_1! aZ"D1(#y-~,B~'Z?С<: o53Z* @Բ|2uJ&-OUqjw>ab 5רDX([& XY3)Y;7}uΠ 7DY9(,AN%=74Gik/ T`g_e'YM L +@mG6,1ʠ\ҝ̕Մ; DjswqaʱZ^Fdy$z{/$@ANZjǃǶ9tYO%*}6XSP|[D~4g[UwQDo Q7M`}\\NarQ ;+.υQɶO]l糏I?qmoj6kRU7oFwn]{Q3Nd{Ta! %rܔs=6)k1 ݭG{R jA\(M$71 |9pk"E!ڎX]Fe2|\M[8yЇGW (f*3&sޜy"-cg:1i~U>,"ʃ'i!ؑ؝E'%}!: MT_r{o$]XJ3lua2bBEQIzH7Fۆo*A"b01l*=iD<8Дq uU%_s$t!ֽ9zC9y963 uɞehɘ [xRǔ*O l_Rt"T ˃{ l+=\H='h#*'i]lm_2KCK_Q uhgjD&JI=YTFodX,FJdʄwM1'iWqίpBh53VTP\X|&l,hǎixc:}:JObxX_,R<]}1.&=z3k=B>9%e݅)E/ Fm(2{D!%)z$$xʺ-s-.Nm3,_d o n@zy`)ru[ئ-wJ+:Yc-]A!5}ܴt?@o]6ױQW/ODm"ѷ@gFW?k;PߢcI % oZ`=:o7q]S=(#%̠c}Ol\٦ {URl}P{te8[$'Βf)@ jc-g5z7$ 2CГr@ ?1HwJͺ jW/ò[mrHLC"Vj6~1^‡Fd['K_m*.%a|d(`x/zjmH>tGN @>n^6SLe96%7pCCcMi bV&wַ6YYө(?0Z%_Q89'2,<+`#F9%R#L-kk*f'9$(ܒcvv{Ar_"O'0 f; {ZC[) 6P.]h!@UbdnVީykVgv>Z?*ee0_s-q(gbn1_㛅̥ Sk^ei{9ڥ ;ϟvozD0 *Q-{@"g1\18.  yfԋF$|qEoXkWj")\9I2߃ Zb6ֱcwRx_r AMʂۺ=qi@jY.xA F2`Ro+>9r@obU!id܀U6yv9nױt:I(I5|NQt)D=xBס3' b|*b돦GjqB _0-eQBfOpcu)FSWX5Ns l7= ǣ4nJogm~ИX>l)F"PEEs#R‚Wj`p60@iFV1}1[r%XjZ(Ut=klOin`dyЈVh;X<ӮB摃NA, }Ea#Y Ei]/%PC0WtC + ް|;n <3q̩oq4wUZ + k[n0wxmCTV=e";cr1սp9EƉ0KBlA9')1Bx|a@N,+t G>W1q(06:[׵>Rp8s2 6 )tXP`Yq' V:wP0z91~rY-O $ P]Sò6*^Ӆ3e(!cE̼iwV!ܼ?~D"00ϧ]gVK 'wpN캽K_OӸ_ŗ,I%aa,/HL "ռ=%A&C9ൟ$1a~l/gT*(A[0׬!}n>6=|G;2ѥ>V"7k*C{>dYT)gWb/#f/ωTjOF :6gw[Jч0l4y>fB4_dJS B,6!ltYN|HezrJ5]$fV*X88"~/1%(<{*.g3? ~Rօ#^hmBD" Bu?y/҈tڡn bfC{.=܈N4e lMfU3=RnɹO2p!XpU6l Wt?^x2EEUپF0 -]$= JK=- i#N>rͩ:.3QL`FV {=gO;o)!TG}0C"NV??gy0,pjJu#kKn#fV?*qy$7bl e+WҐ{0W;@D$zxS127*;A;r!9z % KڻЂ`q]7`JeӔv#mh؊I>ʢ?3Q⃼1Žl>@X񞽥"y?׈zr2@innoJ)fj180ye7']2:ݪ)0'DKϹ1\N֩Cid$IǍu[ L㯂,H; K,2 *EFՄ|z7spv=:v ~:#_bG8?+yIk-+gʻ+ԹsF˯6S% K8l`s 06.hwA4|7nr YD[a-XJ y-TQ*3F h'4Qp>gw~+Cƹum[q»'Vs؃Apr/# G'%";xX=%@F,n'-2̋.7TOdN؈d~6el^.ͦ%\n#"/L! ^<SO"0"kEF^t=j_)v{H5%4yfofڽsRUx-@WR̦\dxyNeGf߇f<4SVs/Örp-JOfb=qӤjU6l>=mJUw t맏eHbRx:з-'+.k? h#ZYڿdnySFΘ;d}fk6~K%P3sS%hr퉯S%O4B+o4fم/v qo0%ETY叁|Yba0i690E,K 9Lsz ;AWZ!j3W%3i >aHyM8k'{MZ[c 3-;qC5`_D~;(t@oo9U-( g".N țUx !Zj$|gLSxnE\e nySޑn[,LQwk,[.JS 8k+J_}5rGV@阮6g\ҧuRΆ{eDq_M͌L!b/5i nef|7ħJR1Ҝ[*TGfŁys ҵB曑M7EfLCڍŹ %=tgUw e WVGB#0߽Lڹ`uӆ+Ъ\~^”̎(!Ǜȅ#-kƒyc zrT**'T pqt96J2,zݠ 6CP2v!,Ӳi8ZprN0qt%4Hr>B@Lϙ50~92 lZ.] m :ly v1˘GMvQYG, \d :j;"_ʷ֧}Xd} 7 |N''2|BMyi!b-N,Pf'ɬ?<'sdhpMhhWp@VI7HC6YIu$L9MnyyhkPYRG) }MV-k/Xr0AK 4 Dc3R0}`\fafS|H`cOi ^hjT?gSͣ:?5$ &QnM! dRtUMy$vksGizI˙)Nz xRc$Usb"; KnuxO9NC00T5>'#rCqo&TW0aQ1AgVH=vN?D_9∄lkccRE} Ç pwbQ•>e9CR7$X0μaACOQb*ZygS 'pO/sP {C;J١p[?FQWXKa]4@=N@A ]+3%9j9㏈Q-4ݺ*nQp` #/l+nO.iCM'&<{+;@JT BN E#CyB4v+:V~ z÷/:bf!ӱv>ʅ0#JEjO57*lcЅ-қ|09!˛Sߋ3Sgݟ%Y4eTzlC0EO|NEh??+$ ])l=nHpmҷ[˝,Lsn/^Gv"R&\2ʊ9 \&duF+[Q!MqμM૲4j[)F*xԸQA›97*kOILQO1KzTvPu}:('p8t]&b1EO?&-^&}`JwzzFyRb48!HKng\xPB/4 w ,fMV)tyƗ±78yݐ(7%W8=$lo` gs:ףxOk{O^c=twCr`0D:8P_5H,P(e[ƫLvRr$`pGs~n~cow .pνʈ,IIOx؞eiD$iXH#f+~xKb"KLpO^Hp:1&v.De^f"he=;1GrfD&m*u­},۾x2sWcX䙊Z~Ê0%ZC|T$Gp -ͅxGrd(ؔ! V,fjD*Q5^Zi ::tzu%UU= MzFtz]sgeGChU]cŔ6 6hgЍ۪p.V5rLI`iZclzj}(5EHR '9QpN+ȏфHuetxvP/KO\ s]~`BM 9}pJ&LΛJ:J|f=|bVE3ގߙbωpyُLwy!͵_S޸w܋/ID6f !X[ G;9~gp' D9MH%7?A? orVHH*gS&Xb> "tiDŽ0p/-u^%/I> TtONڝlE hi2JrrfV&j{bݷ!,٪tڴqi-oG l^ "30v*WY ϐBKLؑ|37S.Zd!N^ވ"F/rCFV݅{AC?-(wC ngsT97r>pt^K@B_QGCUe`=cI(K{Yn@ZU{˅~%>YଐD0NehC, C/x2ՕM/aM,fy\{&'AZ~$LaT5cіVQϛR.Sq)_4N i9N&vEyՉaÆ8%un!FMK5CPHAhONJ0)7a8+,+*6#z1aV?r zFCwX)nCqJK^PNVGIH{>[ ȍV~R4iOQ2"p<|6N2+\93;Dy[o(TQ%oچ %CZMrq I'( ;+*4fȕlzlQ͘mF^BБWq TYKULvCV6 Hs'({ym9$= lݖ6xWn%3k^GzC5Xy3D3ՇJދE/Uz#![aib@,gS-Y5 ph'g@{o9h63g)IL{z^ 9Nw]`dD3kDRZ(,$pB &!do/ yf{ӖN>"3VUY&0Pn`pq*SDqD4ஜ=ʗD hz!FZ9~ >1Äc `ԌQFi3 im/N9_2!Q]RkZ$h빰#W))VD@ؤėKw7e J-EKQ=}uT՞ȫTHO򚖰]>7U߳ZUZ,&]qIä 7o=p}(*'jAqcGÌziz+@W0Θ r)(9ҳ +C Wj@SJ[K٠%Ç \׫7KYTuut<u`bq䘣ƁMr}i`!Y>4/L>rarEgh?$ ;-M$OCUȾk J9>E% n?N4}FBK0%;Cͬ0 KwpIP6=9Ait\ö`⊈<8th!YsF.R˚'u{?uĹpocn'#&P'u^p/=i&-K.L^{ =1tĔZwh9  tBo>er*xpeEb/O*n:.+j璳i)r PY2{sa&ď3|وPen4͠V??gFH~9Dy{ skJw>[̇d,U9UÙԚϲOB1̿T6e̶khfnHɩ=Dt~ԟs(s!]KƂVo/ɿ#ƞ([S'94y Z77 \DUq֚{EkWD5] 0ZX{U"F̹c|aDOrݴA >x}] fYn[Wפ|غB#77>ځz|I EB)#!܄qAWqj ؕ>W?_l-,p< 2NO9(W{ FȚaQ/[r Wcc3"BidW ^<MɫںW\+k> "LW]ꗋ2x˪O̝)\p, q-۩e}B2nf)[rԥo`t4[H"f1)tfFh wapȸ#a=cUyV_ Թ/1@l˯T5HN++`"\3xŌݞFMIX|zi1g!'I.'Q^#IXZgOdXFF7.jqS}%aAtdTcj>@Pϔw~y[PBDŽS ThXO=f@%ˀcMu` %}nmetrl r<ç&X" @Z"8+uU;H <䫏 1H:˷Uk JXCDc"$|goPRL0-륕TJ@ړryT{󇕜a5u*s.,p81u aO_bG0,^B/Զ~2! m+"bu:nq6,?`'0 팕d6kU!΁cq HA(e 3ȫM-^ѱ+`dY#&ُɺi"Ze5S ()#|8U>mpԹ%_S5ɈӔNaPύy){ M)8'0Qh-lXWXa ,Θ>R4GOV6K]#~dM_xz4ܝ ,1`i9ok/ GO{/Q&f`ZBe`Ůy(;*Xnzw8.Lx/, )  SIAHlZn?w>!څөZR [5ΟcE jwuO񏛈,وngemX(4pIVDIKxLG|p͋K6̹+hMqR#xk{o6y`rzBxR'c~9ͮ+?[F,CT1TAfCStƓj|#W,3-j2 3|3I]yښߢx9 ynBCg2?" !/*hh8ѹB ibe= L$&yʼCNQ2w4uX"F;{CP~UodtQ?x' r='lrUeiCCjtT\OLjG%D\9OOچ $;+M~~",{ɖӑUn}{ pjs+?}40q%nD-Gfiֈ5VէlU=L AdB˒*RHe}/rU ~7pk9 y"҇lo$8Mx ]#m&'%텢l*fX|>9叕?~JҖqV6Ca'?[ASՂ@ZʟԘ<#bDO$IԘUB;g=Usy;5Bɘ'n3lb a`m"g^Ux0Ge9tk\ze{HLߣbJ+(X [;bĤ_/z|9_KBhW%6DӠWے?rGv0cFuV` gUCLE)oVLy`\s_L\ёSrp\%iI1? QM ;kCؑpY0"XSNu1]kd VeF1B wM'l*_ݛ7:]ßqJ7Y,x$P.ow^[,@O}QnwxVЩW-d{5zމQ*‰(?J>0/Sᔞ>;0h݀I46cw[$g>/4!=< ViQ^\BTؠZ[v 9BM6O+E|q%E0^K/n`Dه =g}KI1;*:M\0k¾\W4m#)ME>Q"e8%IƻU%s)̉(L}Ń15mba wHOC <0]B#颠`( +֟?AooRabHB Q&NgÞN.Zjo.U\w:J#ׄv;x=p45yD^ٗ+8YK ɦJz%a\>C"J|U<ڄp>ؖ}<筈@~/Rei&ӄ :5Z,`W(n+{b 1Fx,8$}U De#ʒ2"xpٰǪ$YD=EmMd$@є""Z[JJTZ 'T*fAHݓG %k8qQ_{eYQ1rP!/zJqn2|1.+nύ!M[ENБfaɰٙ_ekAGFtgĸrl&VoM0z[E<&:n [4:1BK¶]uWCmtv lލLZ~|Y.jP14iէ _|4W.J't@f?47ųҗ+g s@n+W0C參Y|:/_Ϭֲn*Ha.I,GN2@&@OH'1$y5%[y'.+ 4}b pnsb^\ՁWn{=9%?MAT!˪|A΁BƁp2y&4,!x2iRcYQ^MieHF;T.L{6;<*r1J*S^Լߞj`@S-ɐ]+쾲roMmrQ^a;@5uq;AVsc4-,nY^4]kIm^ߐh$QϠe֕$C = %Ưo^i= ;;dMwCqGE»#n$ G-fW(B<~mdɾhmQKqX!6XP-m z_s Me|d Rd2 1Cr+W+Y$ZJ ak\#e3)u DHuauqD0/5{VGE$p\"9Gby }^ cy(T(lo9f$?:Xe7+5p67n[e2^ CnX kmMSX,wXuKbHX7B=ZtFkbijv'x^ri 5tԈȀu _HN%b_AZ4(sע8COx 5CQGȜ]d?hާ"OSӾ ?8%8تu-`aU!BS L]di *wQX7n22xEv2cv0c"撺!.I V^ nw1n}%vj&NAKPRW&4?u*X䓟f}%>gmOnqoF=O|>)sWAqF"4G0FedzYi-i|,vdo:Hz3vTįq-OżC&xqs-޸D hyR0/-cO5cV ܼRJb10O{t\5;CӻmRT >lYF!˽IJZoy'7 N(PXVs;T-Hw6VPu %9oV%}ֻlAfOcވRo$A?ww$cv't"sy* 7yEHK_jA.pЮtu@ND1:<_qoG&qfjrAtgC: Hj%m 2GLz3m1k L1pqq*]ƜJ-!ι#A\(+ nnAΝo\0VU${'=GE\;Q闂##|eqr=fa|EHI1FdS>|R1 ̱Ɨ8gSoj;xx+9FxJ B^^qmMh$ZRF*BY5qѣ8^Hw(zDϚOS^AEdPB(')"8nۼj`ԿUzS:s<oMGHjg^b%TÏÂƂ92 _ge9e㷔5{/m`.u~V7{|)t?qA>+E]p,5 ܋Tk"! tS 3;KsEؒܶĝb#PדyF~՚ l^ p"!iDQ@rO*J1bOspBqעllHvcJg4Nhw}`4>"$(vIzOmN,ľ]3Oi <BVҝse*]oJ!8CM2.$:/_c[v |.1RfXPn0+xKhGDāp-bՑ9iV"EK.3TBS $nTQ34y~KOd:gl/k;*e2:}72jEgeҊl/cgn}U9Ua#Tf[=O,{ؐfΟ&tx?Y4`dxz;J&%p $B&ӳ>`{~y}z`mQ>?lJOpT4w:H_Q"[;<+)+BU(>NtVѤGx4}{|:uU`^\ @ yWI_;8 ?Foݵ#S$E`DYrw E#@mYǐ<;iOQ'JۢFJ"G68H}tQD~bWnř=K.(޹h]Hh0 X! /@]xUY1zƴi+#rT/u ąSծؤ12[sN"=+#{鿁YD c p8{`㈡}b+阩(zgFJUVgT8qn !͓c~gblao&x2 B(ͺRɟ}P}FP9ܶvɀEҿ.(ZĦ){?ԛHHJtL]*)Ky)1а{j}.cc bQ[Jaw˦:_V&*2=qY}{bG~gF/-C)p=SKzC14hGVڄ' 5m)Hyt,#,ȩ/4@0p*r 4IΩC Vxt_%7)O'sPj~1vjr9e1$vdFT~)呵^WO"l(TDᏌqg%rJ۽"5lf K|X+.Y)$g԰~:5ǻ(Z3,.\B`ș`HjDwZ<@BHHME*f7XSе4ۢ@ۈl. Ώelh Xⰻe_,m;;M:yw,ؚSz=K}o#ELj AmZ,)q|Ƥ{B--ي/{F eRbtZ \%a|wʗ[ݚs͌Bع8U|``#v| fAHT)&ǻ;HXT+. B!i%_;bvoD$%va(Xzuሞt]y2(Mk1wMncĸ[7X7_C:MGѫQ6{{mn9:#'򽴙Z噠Tj@PN~%;ҊDTp!P%k0ı_Gx=9&k8^ -, ]>u7b|o|qohǙ3+Йyi?|RL/b0``G7a&!ց#jY('Nc?t_.B0L?øPefBڮ vSGOx@ۍYCSWыƏ\[jє7<+U#F %|NS*" GebGJ/Ñ&~{mR)33ݵsJ/ĮǰL/h ө26O(wJC)x:rpW!q 7O?XHyoܡ)m#xFHw~gH$&G󃠷?dt`@~]ʷXsxNi1)6_ Qn/ =H{GD*?, vx?p; _ǎZ x26(3'HFE C@ eNH^Cc?`bzfB:3$8] :՛c+i֤pU uCum\Ac 1Ga=\O<\&ʷzє-";w((tR`,QRat8U~^2x~2s#nҬ*_bzl\s|OjVf!q+"eaY!\ź+܍}z/P kd7+ߩw3C8@ X&))ƩcLNhM^֘wqIE(<ȓJqFy4jw09<7@:y]3oV, @N%Q8b(sd>pb8Kfo+uUTw2R(-zE`Z;o 5.T2կimԏF~`}ض߈tt!uf% sQOl-y7y5L-Tka=!D-BݻaNsu$kծRp/l0p{S5LPnT#ta2ŗs@,e@̤X&eEX@BL$}凯WG,=j21͏ =-L~}٢zcAa'9,L~;~P2@m%M`k6oIWZkɥ&ޤдl&#ۑb[$N$8, P GMU6KWXizʈ[rDr(nxjN m}r`$'xJ* )78^=t#dhΈޟ|ߣI嗵ehh7j[0\8ZlnȖ$ T% ´^BW*3cO`0K6TdR[,+l"\:|| ۃs=heD(Bg۹"=`hBuG+[73!%:\hSEomEBa話3w2yzȔyɽ@ P@#*i%g5oL*C 8IrHiI&B`Lp_hf ﭵ`hޟ|ee+SQOYgƟ<bt(~rR4Y4=NV=cB(R<>>yYD<r_,S@'×(K'R%z˓q=j-K}o7 єV)ִ_Ypl1">D[ D `Ռ$S7ݱ$x҈I`g%C OSn@8k@"&![!g% U;xqԒ:tUZbn0\sRYz 6Edߦ}$@'a BzD/ !t{v^[?Ư6cQ2Xڼ_ 1籹cdzjj -:7Rϵ<1N@OE,Ak::u^uf#>h/˛ǭ.)Ƈlc,IP.@"fa%/_Ȫx]6mQҶA4ୀig7c2==H^.xU[&stl ۴7ؼ)˯h着pc,wغ|I;Zpetn 0路$&u'XD^N (>7S3Py?MiE$RƮ@o@)wyOHa$=y`|5/a#{6 dag5 :~2$~ qƧ!˅!Diqp&c t sQ/3ʇc(8h d< aHee?ت}iv2b^@AE`Ib~6!(P.IF難%[׃vƣ˸/N:|u" #5RM[h9sE2G&k;U d^8kŮu(N$`w:t,UKtݚys 0n.y w!Ƭv|˽B)2mA!*4|\g'čRxA8[`}A 2B`T$,d1#7g`IKg;ۓ0;Z fVO|Ŀ=7w8.-OGLrkk'3ܧ&#`C0~끵Y$щ*Uu끞Jվ9ZPe,,܀^XpkQLې {.wռ=CmU8N},uEjtU[nbtt'2&.rdwg" h)(]J,%mYVa 'n0;o!ymlkVPSȘ2O.~0ai`/&PZnMzj}gVu~]0m5‡@2^>{(clK|[ xI8~j 4)D;191jҳ%6 @isNXL ~7t$$9-Vw m%Jt|U煟p+GS?N`gDx`/p $JƁeCu4`&}_6$2?/.#!&/INj۷ q1|#dP6*uϯd 7~$Tq8gϳV +ߪԃH=hCZpZڷwk x@;|PEn+d?=̜7i@ǔDd0z؝l  Ǹ3Kgx({]E3rO&\7]P6O$+Ьك:[ vqŔcEKGkt:i.QQ6NhTWx@Ev]#e}E ~DbJ%bE:?oe@NTf64HPgYOdb-jI9qllJV_(ȹ+K=4R@ͷ$~Pq.EŦڣ-g5 $sX\pcӧ%%|+n %٢Q'Ϣ4Ky^ 7LDGBqynMz6LaR ac*62K˼ ˑl+ i# OCv6 z<pYEG».C %E2rD#:mά o-CYi 5~3LU=Ⱥu?]|C(_^LL>t",roI#}W"eu:!r w05L8q5wY~M->"jp`@̢Fzb lDxORS7D B DiҳZ1Q2\l1ղe2OxJE->\^nfle֋zl$y<t"okp#dnqZb KʋG?<& O y" . Cm1p' FJ+4F%_=!:nfm"߂^k܏ضfAjڹR\Tb.xd* '5'XJ5 rԽA؆3B,M9r-q,;7Q`)bŔTORH{.G+w+ͩYUI Wp7rZv=.fgdl/CvA:æ\R8~t݄5ϛi;E\rW">7P/N߱eٔpJ&6oV_^bN;wU$534+4J82iFν\OPqQ,L)$&9! [JDT7w Ut{a xwx_߼YTSQv $Z \KSE(>{NBx1,RF:(Bŝ d!/[ؚ@>o?%LܤkE=qwP۸{uhy=lF)Fl ]^ׁI7»P~5 &sFJY~b"6U3q>VVjz)"<a]l@tљ0C6:Y[SEv_9gJ{`F۪65ZCJwkAHi!K1Plgw ?3OL/̜ٱ :BJRR2zEx]d2Z &"0su{K93+^lm2ŕТTǻB`x6=_-V׎+ˏ.57PNjMR&+)ոΝn1a|4[sp[#TYIn`"._smksQD!k}$kĒȤh+Vg,kӊ"$E)?xC [/rǓYT ^:2(,'""'ً ΊvUZ;^/ɾh鍛4KkW:r$dԈ] ,D(u{' kտ~~;T]%j)tRZbAڕ P*u1wjY0,T;V( ɢCÔ)s}ܠ({<Pxʼno rJLM+T0`p !Wm(j8D"fAgZ#>u*$ E񔱮44RovXMgװ7^nj_)ok i.@B#= )ZXB^«(^xUF?1,H p\PؒA4:z! ;vcĕC_z,ؽrXns)Ps|[ uQ),_VJ i ė7H8Wx|+OUa0ҝ|-%0 ?M OT#W|1(`'>[:=ܡ&h5:kr%v( +Uh 8kƶ4.H8љ Y]?XZ3?'xƼh τ 8cÎC.`_!12E,0,'C4%dk:{qWX̔y]$:#W_Y оŠR̔۽׃`s@p:!^!zm i[v~K\?J{wZ7f`Hcvlסnv? Sn`E &2|F]^`.ۂV:^ccVV3g]M0` i{<;Apmj1^7h~v(gm{I;ш @uY,:Yg4 "/yevŽ[jFOyrnL;?`m{O|잵B3e,̱?a`D А,ѷ&@zC~yT7U5ɛQi,a /`/ }{g-"hp>>DYT$BȖ3p {kE\;O?]eTB=(p3gyaicV 1@+&21 VӓY8y^JiFZʃ?";zz`뿏!Lg% aSb):aSN^n/2GMrk#Gg䨭3-96|v TM0 D[1_rxg VQOnX|,DÖK)v9 6VZx~GmI5ˤG(@OR,pijslɋ{¼-Y腃c.a 0]7ހV|G{?t >ۼS9hYsM$͓Kg,RMfwCy0BB/1YUKD=2hZ4́y#Kw'DD7ȉB@.bUgaQ_~o`[ #0&*(,?S`?nǘ dNHwySZC"d[$G auf8-MOwE̷]W<hs`)\?U)EW]!$m=… i6>(we))y>̢*Nښ1ڦV*r!RSٔ넴XGtC؏ffjx0;rEyfR! I4Z8oi!]ӂDba3 EnܑwpG:Ŭ]+7nx>mM.yDAW UNdQQ~kXV!G`+I`#7)\v3> ݎ4=okOyDǐCT*-3II~ݕ+6w©xIlH'_~:-82 m%5tHN{RUfѾR;Vm7ClD &x[ė8 &﮳`B ھ !m焓Wv,ᾞO"+`N.쿵|UQuBQ ao'BocnS$|{r>L `[WGqSfôKRmd5 e;lA8Y؉-hL39>j <p>79T1fK0EoPpVc.j^Q6;Jᓾx!uh#z ܻ=]g@Ku}Vj/SNÅaf|p#aN)d}irKz Svqq~;m1ٜT$EeD0X.|#dFN :Kt Ek Ы=1b͸qrϖ;RRT\A/g ZӺ`La)zɛfjZ^[{0}ͣg"5%&+{QOv !jjx k-z2_ڑB< ^X=HXͅ_~; EUhoЏs":bdS(b=R\,X\_'5Pov_1?*w_5f+P *ZQ{3sz.i4m:<k6y"tU;=Q|sC5fIR AdW1l$>.5wvtAۡ kClI5n7R7= l0];}9t3kH;7WFކD#fUޭ"׳Ir}Y[0{&hsͳ oa8#i| fGCڠ[:ծE7E@']'nvTdexa疡Vb®FIB&c ZG kdGZ6o2d pcAMCimkH"LkbV!wWdU󆙫uf mw;apU:7U -3x>2(婏'Tn/9S>"u[n,ɘσ^hO&j6zwTI﹙ nE ~\=0[kٓɄ4i-:l`4V6k]D%]=.ZU-L};Y,}L/Xdn>gnI-. onuYn矶cỄ ä0dFۿEՈLą;PDq,cK'M$&ye,0N*"P"_x[J>t@))Ʀ\ԜL!ŸCrHGӔ񀂷`˚Z)Ԭ|koQgnh|4h!WZ:R^Օ"(1!Zm&D{.BB>_2> bI'j%SC@q"]p a]u]qHN?s/sxA`OO!\%}p" Yz'}nbCPfhiaUuCXp8"I]S#cwnQ-*1"wr84$i%V; ^eG[t#A3D8Τ NğDK$FQGu%vM3>AIjBWPqC0)u#;Љ/9!eZ!x|xw[Qg*PkTqO=%m>>(w2 ɡGY[ܪE -ON#8`BtC7%4;eݳlz2אq-hWힾ`ˈ`hiPRfA4㽷)qjF(V bRE./Z\*(R+j-n|cdxm5PC-C^Fe n<[xC?;z- {vZ7%5S nEͮ VaхRf@X]tLU,$0usLZauLK'wqW @^E\ ;\ed&aԸ!ܰc ,vuM2Wln墿:Y && 'I]z,8_92V7y~Xk/Z^[D="\) BFmn셢:fwST!MZkKgZ/EDTw_pf z&:;k!NdsHnLsWP%,@:갯G, ιM czH4j4+B?;iʧR]vBcgѦdF D{mr5l]Q%|A|](19eFgj\,]#붿Jձ6 {$\0zZU1mv-fV&=)? vDs Axvx @Yݭ493I[C;X1"WiwWIkBpY>: {,;$Ce`bgB\<@X-^yFf.^ WdJAN s~ 0V#?jw" t:~09p2`3} q!Pzۊ`̟$YSKiKs%s`6e=xxe5Ľ=OC S5 /nyD'5Oe/jL‘ Rk}78+6zə|o 9ň{7rr%3(YCuUڪ2Y*j%X*̓lz L}ftWA%sI]Q/4,S=yD?F QJ j lP$9S u`*n @iHE`qp୕!Z,_zJT.Csyph?-oRiưZ U0$C '} w? :ۗ= 5#M;,y~CWǹϋ5'߂Cu?D_O'\zr{4bʁԧ "fH<NeĀq w|p4뛦 +PP s6"dSl̤=px+71Q%Iu7^ŃEOu/e5.3ߝkW`]EuD7;'{*ocwG-G꠾b1h־j;ౡͱD`XaNzAKTGFy>]ޞa<4s hx,;/.u^2NCwIڋ•j)]6hiUu&g^' 1z>o#>%ē<Ց6\X3W6B}>A;YѨqzBJx 2q(gՋ`;"К 7oۛ QÀ?*9/Ddf1Ʈ|[?`sxoޗ3dٔ:_$.PDnNA6<7ݫdqfɄG^ uE^^U SaF:'] 9\-ZAqyl1_SZ =&4g m) uC>59v c#wD*L%FT6 0 yi#)ʅxB>1Y>^8}Tgk * qyɴq~4綄g,8¥?ghv ئ.&,c drkw>4 ;f툥$PL"N  ׎%r=23S. S7K>kxn&`5e#2ƃ따њxŻW%B77fF r(S,7@HQ-[-W:Oxl(v kJo9ua?`tE3~^ӫf]69] jU ierRfH!j_?8%y1mub}le/p0:/Vu7f5&Db,s-({c F_mX>٫ئ'?_µȞ'Z3Y.uX9f=@xh `Tn,bM 3Kd~|Ul1|cdKJu(6+'t~$QvKưyTh# Vǟ 1 ˛ďw}^ ~Gwϩ~4B s 7,$ˬpsھ%cZ>lgYl =ǎ ^s34ӻ;٠[-} ELJh/`_a5nF};A'zЏ FK[Rb<9vď?ĺm QbUYke x% 'uxnJIJ/fV )̘V{5Zk=yw9uF0eA+ܷ?>shEZޏ3p o|FGV9(DawdJMl2eƕU'"Y{l,㫼Wg;:֕`ɗ@B\ 6.Z:<9nAYnJRQ]aR*ܣRro[sljfk +6f.N MR$C> ع) T{təG؆s!^|.s5TI=Fm ԁ?: 3;~pCR: ![6 *4\F[e9txXBw9t+GfP%kLy8 f{EF8d􍞢s2 tnƻ.O<{o`0NǑPҶ&B?B֒s`q$ѻ @ZTf z%,K[R5oa#f-4v"ϗOnW&L`W*6n fHQBَ<󖠽UHJF>G޳A)nt@l@KZ.cԙU]lҚB[x{, .jIݼ V-v0!г4~&O3XJ J _$-Ż"~ISRܲ}C@!BI\l:7L $NxbTokMSQ? X:."ʁ=Gm/DqRg"-, 1USMA3(wz#_+5? I^~Q]S/4+Dᅓ Vgm7=H}X(nlh|C+r*6H^R%s#,9+}#7Ucl5v"Cݸe\p1Q;.z tSo{N@TŠ<zTxp͋St7V_~i^\ltԢaBLCq(-rȔ-gcx}iD+4vòǕĠB3e?mǫEQZj&`skoz=a644s߁W_}Ā&xk>Y b7D9|t^:Ҩ]b肯Z}"u86§דJh@ɹņ ~MNH:a ;&':lS{m+ …;k`!A!4u^*.: ީCB\h~5&R9L_2\gZb_lZvdf -3VH.s{7ppsBSDV M3;.I @GuF%Qa\,m2-%dDHԳY>ByQu$HrQOk&pK׵}&.5Uϰ2T{9ZVx7Fla5zO]‰Ps-La-O[[,vPIJ=`@bQ>7`B7X-PշB4*&:!sKbøȣ6Jte ӵNr>ZdgC5sތB5ŜMzaEc ^Q@|LìkQXMXaBqCҸ6TabAzBR"Jya=#wrhGNpwNOja>oH=!-S T0CY9[^SAZ6HPͨO׍EhMACrڿ1S x^BC$tn2xwFW8?=\b Ъ:ƹd4KrqLAi CQUAlyDI$%OAh#su `_Q">d n2ds6k3+͔ը%`1"bibçηUGEIW/is e O }yAmU\ZP$s*Qktm h=|&v۟๴Ib-tL,EVyH 1Mq%͓@bT\2Eb;-Z< ~75KdxU,HS>ig:2%tuڼ`1x8%PKں~GD7_bpz&]KWb^.x}lT/'5Ե9GsFUDȱ~ 2q\W7/tUG-^̪:f*JN?^I6ސe)h/ -h(W~| d h=R,8^w 'iSնpHWӂ7wӌ{Wr\kntőhQ@uGLfržh);ٓdu5dt%1:lJս:T%[qpuI }1qG2y^⋽ Y^L> 1 rzeड1*W;,Y ԗRO-||wi[l1GCc#/ #zl{'L-O TeO3>Oxj߀UaDGڵBuY&n-M½߹i,^"-hsO^wslgYմ{{;@чjkΐٿKp:7;,%tc>/qw<g6kLygu,%v*,9ۂi³\Pzw WOz77BȦ %H7unX$-¹̐rۊ܎jS%d7-(0t 79e%<߳i PKrgbYۏ6),9=Jlw=#ikIZ,EE%+c'̙Bv m,ۊm QJiJ_r"ᜲ5Fw>U=fr*9xdq^yti3Z ;.+u%aDE?.3tI>+TWEy(d {lu.UW' ݅Q]ʋ7}2S|CǷ5Ǧ-n&rh$_yJq_;'iSɅ0R/WMUVhdKI@hQcLw-:ibw!X 7 S5bfb1 AOK.&qZ9 Iƾ@&#~'MO7̓%cRlXމ6Q1;0VVd;NQ; 0%G3 rsO\覙5) MT,fRAGD~9H.Ih,sLZ+#os2T5b"ε@GU3G°7oл5W HߟalB/f,$ tMkx l!VV}(ɔ+,kݠWHnɖ_"h*;i|?.!;l9SDA# <2@=o{;vqّPdlg/"&8UKH [P"GBdFa.*d$ = \d!_unPTkQJMt_2~L*Pխk ~s0)lF )m1  ]5)6m:7|:,NeuPdL*< K&<`%vF=@ ^z-to!eJD1]֪4\\ŃAo?BrkĨ`87hDoDN6/M? Ebh$}'H'Vgˎ3d~QUzRӈYb7'$?A.{6QCxV `{ FOJ4Ōb7%!q()jå~w&:_ɡe#Q/'Mwi݉9rD"%6\Hcg:--F#?~ 8w Rbա)d/_hGKa)8t`c9Ek7K5ɷ~*bfMH5yZftQbcNij۞<|'6%} %-3~M?vC.jW:!A4Ivv4[ oJIglCv&w{C f +ǂcS@WBH4M@kG2mwDN$h=\Qm~}]"öFŶB(vZM8j°|t)kN] >yB۸`m7Y&8x9`yM>~/j(9@*wzD+`1q+ @g o@϶s3kXM._0`zI1;Y:z )2͊"ȃ.}+B$&1u=17Åp.`y=~>'G`/p{ Uz$ϗ}X 6{x#2Se ֽr%^/%n$"-#_{2;+T$C|mE$BY?O`Ւ` d!tlS4+e=vS_a'P~ ؝ʝ"C(N_GuOQ+DQuDLP߄0X Б gWGd!r+Qˑx"ێ~{CރX2`K&Kb!XOMz_JQc`8 tmRa-">W}-11(ݣ=[`p$$JB+t׉iNj枓U>R:[>ǡ~L^፺qzOԙ!I P @UޢY+h'WsZXAb֊ ?1a>һxTOpQgA'yGk\j4I']pZ~*0T={c$1@X!s΁qM~Ͼ)Ky >0W#fĖ)|YNkAdt & GN &Pu;G2 o&2/0cQ^%PJc!Qruk|\QXOŠ@ ɼ|w '1wtWϗ14ky^:h/^:@IGJ#P>骓A 9fDTDpQSN3W_Ced47 WY-jSd(jVx>l'Ҥ0lg׽=D^\;}aE0$}z.J~V RSqy~d=9sQڂKW~3 Z@n=x%LMF ٬( Oyj ,l?AYUP$Q@zI.]m-p;U(rRzah.G\ߵļxi-y)Ĩߒ -ʫYݥ N|q|t4z V/I]7B\A7)'ÅT:]P2 -g@̳ߩhў?J"]$Jc`"^Ne̼-ƀ"ZEtztӅQaiiLAⴇym"΋G / dz58V&QWv Ng ?tQhjnSEX*R돒A6̦N\PjpBwT2ŘA+2JTѡP`)ʾk%OD1ƒ5T')U]5+o. /$X`:$. |4 wLx h}%[B. e8rbYO=֖e&L(H_QjB8{aТER $ddԏɇX@K*6f-q0 0lLQ<՚'$FdG QY#H dYvs!RbsTU$&n9   D\#(sFQ*%lig3]\fa-oW =vT(n- i|N \/ 1M Zck!Sbp00lZR%{9]9e'_ m3l4Dq 08N)px\Q`:!Aߘ{Y`tXs09ZQ,[XJ5"C`Bamj Ud$#6^v2 @{G۪ N{5D ֱ/e}u{:lф2h|%Qhs‹挘NHTu050PW uW}WD} k/.WInJ9O倦4##%r,z\pH$1xz|#|x@H1Rۛ04U]]./2*N5ǁl'v=hmv)yDA>ދ[mv=J aW$oĬ. xwWZ0 N/oC3Y4̓ce$juo*˟uJ%!yS _<|W}]%RO){KHZ(/qƇ 6IfZcрyNIR4CYkc#nW'C/1U 3$ <8TԳQiVb씼> z{C@HVT_[#ViX-n[tvnnL3sδӣ~^3Ds6|U؆<9t\aZ oEEdc%#YsS}x]zз]-ө[{5#6$2ql@\xvT Ċrsad/E&0o~zujP|QfOKsY\)#MGGV.8*E"W~|d*֦/Jc |kT؞>V#yUZ`ZtWW:'E[ p#zK:PR Q! 󑭰j˿iWz6/v6&61n+]#"qL(pe佗nͩ9ūt迀{ t+)pA_#,!D F9%@2zݻa>|hyV\I\e`?^efR|"i QE'l|id CbHutC'lw/ )YV!ԓB=C71 'Q+\ISOu dQh`^E4GL8 YZ@p3J 'Nc Zߩ m (eAmWHbr]*RۋQ6"]3 YZ