samba-python-4.7.10+git.124.8d97fe90926-lp150.3.9.1<>,X[޸/=„1Koi$D$6wqwzpx-Y3%WŻλG(=ER s {Kb˂*iU'o|T1,Um{\ zz\X` ii¿ 3+{47)c2YPVôjRrYnz9qF$狠 +b@-i;Xc  s%,TtϧFץ>>D?4d* 6 M  6JagpFF  F  F F ^~F _FdFk:FqqFvw y<f('809:(FM}GMFHRFIWFXYYY\YhF]^F^lbq#cqdr`erefrhlrjurFvwCwFxFyz0Csamba-python4.7.10+git.124.8d97fe90926lp150.3.9.1Samba Python librariesThe samba-python package contains the Python libraries needed by programs that use SMB, RPC and other Samba provided protocols in Python programs.[obs-power8-031openSUSE Leap 15.0openSUSEGPL-3.0+http://bugs.opensuse.orgApplications/Systemhttps://www.samba.org/linuxppc64le3 (XrB x0 2+X @aX O@ ~X x @`L0 X( 8H 0:j4 0 +w ) "WmG5E6 W e    +nLc:|PI A*Q # !C)p j  (E8/J`  pa8 l6D5B3 & ON` 1_ D q )7T 37KYdq \ 5 C\&  $ ` Y1#k}: PR/FZ1)n42Vf>u B~ SLm%u//& && ~ [ p U: 6Et !=` -+6Cg p \] 1ppW ar h+ Uu;Lix  Cp  . rF)y'4}'P@P shA큤큤큤A큤큤큤A큤큤A큤A큤큤A큤큤큤큤A큤A큤A큤A큤A큤A큤A큤A큤A큤AA큤A큤A큤A큤큤[[z [[[[z [z [[[z [[z [[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[z [z [z [[[[z [z [z [z [m[z [z [z [z [z [z [[z [z [z [[[m[z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [[[[[m[z [z [z [z [ m[z [[z [[z [[[[[z [z [z [[z [[z [m[z [z [z [m[z [z [z [z [z [z [z [z [z [m[z [z [z [z [z [z [m[z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [m[z [z [z [z [z [z [z [z [z [z [z [m[z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [m[z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [j[ [j[z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [j[j[z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [j[z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [z [j[z [z [z [z [z [m[z [[z [[403bb3af99dd7ec350b49410096278565e597117154bc4e2520951f7b51ecc5d9ed312ff6b6f360a414d55db52538792130ed648aabb44d09598a44974d47c775bc154a06871d77791fcded2cf12eb1977397047dce39324a441d51a6afacb6b16349f4292a37edbaa63a8065da8abfaa016cd97bff411b2be07923d8c552fddfbf0baed7bd3ea62105437bab32ab275b2dfa1907c94693bd28995fea4468b2baa159614d55e94dc3eefef5585b2deee597614713ba37272dd64a795adbf642c2302cef14f0521511cdd63ea1bcc55dddf358d2e5e92dbe9f7c0129b2ade387aced21d7749ea6b8508b2d91d6361dd4021593fdf127b01d56fc705702b67b172d89e22f45dd1f0665864335284ecb56ee6f0d13c594e3335702ddb6a5eb5af4af844f9bf230f2c7a1406b80da7a8582911d16ba8954a50190c1a3faa47bd4b09e1081c98370ef767dfb4a2bdcaae36ab23ab7e4ff6d4148b6396df67d1aef90d1d1ed08abb9f8993f050c0e990ca2245da17621adbd1b492fd1c507dc719a70609d7082f0761cba634abc65c33502ae7b518a61573da55947ec87d58b52bf881a3ece99a54886633b9371c7801d6cb6c604190bd74cfee207f39ff9586d5a32c2decdeac3493c5f5204f9bfc8cbe927f2be276dca32ccbe22d26f6de62a8154e459f04cade44032d721438b42e63ebfa2dfe057438e4801dd4ab8d975dfbb9d02bdf4762b9f08d83f3ca2c5aa17006c4e6b530a6c7bd3cfe1b9cfe0f57b2b2efd93b71c06d79248c498eb74a822f094ae55dea0620aac580733ae2a7a45a8f010d034bc68c8ddb1dca8b0636b984669a0765f47994e069d2c4c10c9a0352d11159617eafe73cc70ad5bdf03f7af6b0972a703e0d6d15787f5e274e74dfe0843a6616c3cb4cfcfedf419c11b43ca477d3e575f05cdd4806f1af6edd28c7f3f8ee7cbdbf416bb6d13bcf379e1f13e385e78b1578a55dfeeea735233d8c42ec4ae3c564631bf2c44ae6b315281659a3f212ac05245f1592f53dab055a760dfccb6ba0d1e9302cad626c3f00d38547c1bb5e5d0c413d7e2dd199b86cea06f2841fd24d0f2c81b3b9754dedf5a5adff4a51708e084b548570bfb0dc12dfcc32576b1c801b6a0c9e482dc985ade0eb35839a0321968b1f8ced5eca9020f5fa0cfcebf4a17fdabb8a62f4927acbd1260392781e8e628c161d2c47110dcca6f124dcb863bfb09acae2ef7450a894b3a4ab957dd75466c22f8164fc18c0e65158920dba0205a1e6f92134001aaa62bb7b7e57b574e2c7ac18287469c888b924b87287a1a75ad4339b8c4fe3009ced4c8e8e9633415d7a9c5ac67c908a06fc81545a9784d926fe3f208c2dbca1b4059ee93c8d6a5676c978584d7f522c25c015c867be55e45eedc34cfc1818c37b9733c23beae29a04acf08d41a47bf19158d57250e0c9d86fb65180d795d018efa85acbda85e273560602273d9a30d259ab507ae256084da57af87999c5335254f57de849f52e45f2d212a9948f5d955713daa81729af69463e5fd18cbc9ba254f4d31ac88271aa6645dd80da155466608f5b3b2755088912d46c456909c19c393119a5cddad5405d11269170db5566b7efaed781d6bc7f0a3bb14cb01124d39ec010547a2b9d245644bad7cb4aa781251c0a4d7e5788e848368422f31af844438916f36fc975f817986d09ddb7a650992a77024e2e499b7507be5c7c61a663b9c412bfb77ba8229c3359daf6bc5e3eae2de2d826478bff3ca3bb16954eeb322a986d344683961125246ebdb106cbcdf0718446ae4f55c2d2a5865b59f30b0b4ea4c486a638daaeb850ecfb191bd7e07a5071084957a99e2adb7cd73754c9c446d80ed7ab85c970a5de420c27c35c32e9a0457d92947c23456aef039964b28d4681ae67050f6d6d5614f06d6215472be1d095449333a0dfab7a3657cb5ead083a7b95a0d74772067956cd2e3d14210a135e10641aeb642d3317a6a4f28938e2bd219383c7c1b66e33ab5bdb0d73625879a00db8f7845fd01965411d82275ed80716a0723fc97aa096ebb656934a0608617b9c12038c90172570b1da8de6cf602526f3f7cbfdb992b964b57bec19f9d3696ecafeed1e1a148ce15fe7dbefbd69cadd94a4d571c8bab6a813b076d0d4ea448d70a30db83aab8f0c61e925ad72222170b054ed8f856adf6f1cfaafe2a6b12edf3fb9631489d61a79e9e55f371f31ab4190730323b85e2279b36915ca288464a84f00a20429d967f446faa06f0d0abd9b9529d81fe7f07b74895b6ab0bd1abe6fbee105596e133bcbc853f1f89c2a5fa1b0e6979db1d47e839198e00fb702f51242e0b814d04581b51c8916b2b8dc439e1ae906fde74342cabc7766601a414bdebf4e67bcef8895d840dbfd8b437bbe8a62f76d534d4d8c1fe2f12e56ee093e9558295173fa5b074a71c59b6d92fd4c3a4924bbf8a9a994ca7c2fcdb7aa5f4a20d3198bd41385e4a3b56ed8ebab79eec49cd91b6929eb1feb5e6544c600870c1033062d6432888907c105681ebbab594cb94db38e0ba7189384d988fafb60c0d19e54ef18354269ee041709756c6292f2e3c1022c68da4a2e14a6b7c28cc57c163368a9f81bb9a113afd6c1d0849b083c90083dc6bc98e6686f7d64091ab54dfcead250a06a4be758f6e1b14ed93ac63c9626d67b067d4d21bce56d52b99d545ce7ba25e6f0ad250b3a242d8eec1e536fdbad6d92a708faac39c14b5e692d114d74bb1605afb25319a7572788fa64e7df11aa9266fe3274ae9dc7895482d56c84356eaa4a84880720a34219c487193b0802df75d5b96ab18e48fb8a0e0f2a1e0262c50c81cc6b9f834dbeb761dd45f9ed0a25cabfa34f752d2aa390bbb0e37b0e15b14f07ff176df8205454424924ebf3073a819f944957ff8c70c60efba8992dbe6ae0d8157868ca4d31f68848cfc50e5b89955d6255971edacccf13254aabf713803d08b3d37698c6188d98f10b0c1c40f577843c059361df4ba7df6a17551c220a35e29e906834a622c9f5c2137d58ad719860c450f1a101e013e5cb937b0adb647802730a2c71068a364950c67ed664043c096bd32269480d051e41e85193bb0c3fd202223a3621473a5a01592b09d3427c1606dace72278a785f1988973ba5c45f41046b29cac6567e286abacf776296a8a997232548db631cabed53e460a3281b128f31367d212f19f11cc80f9b50bfdb413d60585a0cdc8840f5b3074e39da786160b502c384df1b0e924f4c0ffe9e40a9fe7178c5ff1c387d52d1b420e74a3b7b9c852d2defb98cffe56c92873b6292681b223c047db9a5edb54e9622547459e578d47d08796bb58b33bd5981caf88a5c67452c1a9aa5d17a4254056713a407c88f5bafc55595e46f6e0fe5723cbc020dfb716ebd5ed94e278296008f116004802f2770e14a553abce0c0fbe341c9d20dcdd75852fc33aff87c48d21728cf5b08d20487b6a933c79cf88e9373f9473035e3e38cf9bb817a24456506abcc9c3574b41edfaee57df42dc2a958acd80502b7c9722b4e2ca354ae3642299d8b9cbda2006cf0f882cbcc23228c572d9883097f0e2734b2e068560839f1b90fdb015e5173809c79564ef8a08cbf4feb5e3caa1d4ec72423acb54819afd74a0101dafb70c46a0c8532a6c734c91afc5c3e4f557f94e013e1affd6584a284e19783799ab10b6970f498b1d2a7c2623e69880f3fadb890233c4555f4909fc6dbde0e9f06fd3e4227b95dca4a594c606e287b3c5ba6fb4aa4b718ecf1a7a18fee41c73531f8851673687a0ccf70c1dd1ac273a252eddb691a366ccca1a459440db9d845c38fabf265f5c3a836635d6cbc7cce415020655af268043e6a85e8dbbf1eb793407ba5eb09aaca6d356c52055f1403bbc7e55e38df5608539de036f5868781b435c5b2ae3b4c3022a1945e1f3770eb06c6a4f2a26e3d26faef30e2ced03c5f01080752253e34abe16b002b68f1bcf722abdced29a0ea075abf7098f8aa3f029ed69ae1a416c4bda200c9555cd644474f72f64e07233abe88ac5ae87b86db326fe24100c6bc0a47bdcb43acef9804ef20e8375b13b099b0c6cf7956483eeec30d4d687637b5af13c5ab949a953d65ba8f9150d266a0aee139b7ece8a5d23251cf731cb526577fb87e8a894a512fa48558ee903a908b01a41c9c01ecc6f580fa5888dd7748c05acdc02d4fb3259dbc56677d39e71ea86c4313befd2e11dfa6ba82f96a7f60b1726adfe5108f4a5fa9d2787bba825d9818f0a831783be5fc78d88fd082eae07c7126c7bf42064311e27ce3c21c35b81124b9568385e0c2598dc80cdca47215517b2d89c1b749f8e19250dd420fac232301545973b68d2ba8f22efb4956d358c64dfdeb1fa2acffb6cb027970e45bee3cf18f14b1f94110247ebb4aa15f4346733792044052faa12227d7a30910f3a653e14e1f23bf9918510ca31e0a7323b34e4d8327e97322ddd812189128759f5444020a1b0645910854536d755ea8a42be992fdd60bead1dcdf56cae4fcb4d765eaaf5332abe079b937548b66921d3d59e64546787d167ed4c7d9afb357af48fb636e953a2752f93c8e67e792d4bc8b3dd031681210e296695ad22504351467f57f7e3dc81e2a0001437a351dcfe665997d754879fba3bf5bc4a91041ae82cb62be8fec7b8d3af97d622b463ca35021cfc70d15e8dc59c707cc55074db25911b548efd7e1536ad6fee894792577147aecf8bfc4363a4ff211c7306156e6e20d863c5a81fb8e08e9301ebb01e0b6bc7b19a5557264960e1588ddad0902d8917d9e9f533c0ea8618e82fdbe2ba006c440bd179635f9169bf7a831480f633e7d88fd1d1e7591262b9b56f792cd643e07c1ec4e89f1d7159c11602d6f4b982acea54f2ed69b8c9c0e2aa83d36ef76330827eb17c86145d3fe9f017dcb2e8ff3ffbf808f376eea35161afc6311ae00084e1027cf1c84ef682e09621a6820f6c88208ab12408a75af932642779986b3f9aeb0d9e4d6dc734ddd2b8686bf3ac17de84d5562ed4bb3c08b4dd1c7df34a50e6ba7b27ad1c15c810f20ca66803fa4fa2c570aae88f20a5d9689463de9674017956a7900c07e63d3debb1a63f60a3e41d52d6407d966c85105e47407d2cee1c0acb092ff6cb0f9cf68218a7b954e6d6c8697d7b83eb7d2460af9b9bb096c129c0ce528c88bd015d92548091895dfb15edc81c8552ae7f090479c6c0afcc3592a7a040e368f065cc246949e03180cb92080f1242589941d933c2112cf7240564ef86d5639cb90d613ce87863fbdeb2b5780ceca8270eb845482afd6f1b1bd891a4ed473e0983a336ec936e909a43bcb885460b1abde886427e41ab2d2b6781decbb4a86ca4815f5213cef54c488a42bfd5fea3f0593413c67b809b82e9ab617a2bea9119dcf6286cf345a6675f58e6e6e9b0060433e8cfb700b545944ffb0b816042a73563402a972490b58c77f971547ec492d22b8b33bf6915f46aa1abfdfe37350f2c9f68eef01f21597da26827a840acd89ed41aa98771b989e7384dcdbfb34ea4d045cdb1fd2329f02af91992f7ace45dd5e3a8672c39595d5c9ba28a1b67c83eb39eb17f39036930cd50696be434d2d133917a4b3980dbff928f2ad130c2437e39afcb733b7ed5197927aeeac9af2e36d92c32f6511b3ae916b6f50459ffc707eb92d43d45683df34b43f550873f588dffaf6a51180a5c3b8458bb9b29419ce3158ef7eb2d0896304d18791569aed37452376e973b23dc03aff75ef7225946cf0beb08d8534a24e306f3fff2cc90f6666540a4a7349cc4a921c4a34174e295be99c96ace0ac6a3ce1ec846139aed2c2f552d0a97843021855d5dadd3013500df884d4c6b306193d3d467cfac19dcc595dfe16c684f8488c712f41ffd40f60ae0a016a135013c1a432a9ff46745d444479fa551b1ec1463632a314e6a3b31c54fd126f2c3517befa80502a49b7ac90c67d8025434cbfc1b3e943441dda1ff6bbe673fd3aff044715961ae71abb166579bc6348b978f60d2b0b8a9fa3d0c0ac51515c75a78db24678c188e09aa4f2c4bad814782430ba81158d3a35e43905e7ac73b077b373c3d6b44ed04803a6a16cb4740f94301ce258cbadc90fea8c559172fb4ca1acfff7c29d902b6b7683d5fb40714432aceab3525fa0485ae04e7013566941720c9ea85d3ccf96fe47ef8faec12530fe16698b707f85a0c6c48f0a3ad0fce0cda33f2b84f73c152a2c5a00e089116517501722fe8179b3182e6962208f98cb4ed03af95c8f957ed96154b96ab82747be1f07a6c0b68cf0708adc116f9e7002d024c7036e4d70e9d1535883f919514703038e54fefe3b363f2c2eeabeada7c2f827f7263c8ceaedf974fa53439d13c5304f5b9c09b1d1f7eb0fa0d89dbaa49854864bb8c83114a49eac3856d3a6af894fab4edc7ad306cfa806cd28e1cca1a0335150807fd42bb38d2d9e63dbd41053fa50a5c01641b3a966b509d68e112d34647ae747acffb89400519e46a5f036e7e32df4bccc7497f8dbcd0d909a6a69e3ca37be5aeac033f3cf38739e621550b312a99e51be49cd5ee41c26b629a16c709c56f8923f45ba53281e3d2aabb48c1a966f5e1ecca0604d6440f5d5d870be50c3db3870241298c8bfe3cab2d0a210afc809446b01e40e218ee02841989607bafd2d7164c66aa9a4d37be19b7e50ea30ec8360e5a93a1987909ad64a5824923036a8f8519ef1fb883423e1bf1c1c2686ce1f1a13ee7cd24a2c7b3172ed01d98557081cadf456b34b952ba626ddff99d481dfbd1824b4b164e6cc7cd8b5e3b32ab367e0c43086619bcb164f839bfea290b3e7e46bd9a989f9f62931e1cec810f53c3e2dcefe2cb9378bda61489960464e7cd18e735e62fcffba1017d6b7846f572b2eacab6093adcab0dad15d281e2ebc712a7964d5ff11aa106e15e5d1bef5a88c55f86ca3a1f1de91306ffeeb69ec49ed2492d2fe659c57ea26d9c4d9bb3820280795c6d906dae29f369c39e88ea3cd151bd17f6a9056f8880ddbe051b5c2892c124136bd64c8fcc699a6a028839c0999af52a607457d56a63b630d1109226f05412f3392815711a13439a06f0cc341f3bbd023c1ac528220ea329b9adf420b7741dc3394af357333cb6f8d3d394ed691bb160bddd719f61f65f031b69a8159304a18f9cf7e48e0755a35984c23b3d3c17b5ab0a97b6dcae4e75bf55b5ebac756d8cf0daefb4f53ef55b7161a982261558fdfbb6276ed90c4c311a2ecb8dc35671fb839c819e60d599b3c39cae26e8b87014b601dbb1d013f4a203691b41675c0146ac0e959839a97288ac740f9b542c7e4cbb025bedd1716513d0cf4ab8d720ec66eb196f746f0971f9a0508b440c3147088385a059959b7a59904898e5e5676aa77373726b1dc05879cbf655c697f9cbfb58a4f1e835c890b979cc75eecbeab1304d2cf8882650f58662915122e5c2a369f8eb2fef051c460ae050bca6ded56f055fc07b136dbeba021f8224e08c283b74c121b9986c2215fe29728a6b7cd28d55e825e150888f0fc0e29058799dc2aecbdebed7dbc24f69fe8da42dd257856189e6ddb59562bd2b265111346a8ac1532ee797ac473dc94ac3a770e5e436c140d87402bffb03c398567ada01f32083a0373615d29dc8463a8386a9ff608d67883d57095a1b2dce208aa5ae33406289feaf122abd7decae5972ed1543321bc8b8e40ae69d4a316b1fd48891a570fdb2ae13dd8359a697d4899225b8e3a122f65e0d175a8f7d1cc97a677e42ecae2d1473cdb0341bafff8aba0d1b2ba5fa89db53e3a8faa549078b90467fa3ed9fe7bc8571a60fa064ee626484f1e9512f8274ee836aa9c6c754237e631a36ee6f07e3bcb9e2d17a26ea0c339f5c2bf79bb4421fa9ce4725698550627769730667666d1c7b7550d00d45c2f387952071b9f2c6bd0801621462ad8c70582ec08834c9112650e9ce4758e6623ab63c0e2a4fddd8775c9d8671246281a308929d9836970e703d182cb350559649a536182c1b9cd4f88a80e14ef8da9f310577186ee485ea48759ad156223d20e82da107ffd3e5f0473eb2b104d7ebf5a0687c62d8fd531eccd3eda7a85cf3eedacccfd504ac54ae9a6a20245a0f10ba45a2f35c219129210bef0ab6aa6b42669e7d91000e9c5aa21da1ea8dfcdab2d6a69a7b555e9d92a6ef1c182c8225353465bd23380f3dbf24a19fffb59c2427e0270fdd5826845ed008241b705b3ddfbf77f4055a6e2bdf613458df7fd7bb49d0f20cf6caf639ea4a17c188201a2f4d44a8f679296f8978fa35ee4621e6fc46f7fc8b2503c1c0924131195a4d4de713304e23ecc0dfa360841f52d02f34fb32f60eb55fa063735a10681b00091f92017e14b4eacb98745d10a3a54dbe084a6242a0ed51cfb58f0ae6a51c8416ddf08cf1cea36bc5095eb8e0fc77c5b8c441789fa7c384e0627d340b61ed8aa60ad3568eafb43c983c0fbcf9377e4c6487d24651dd65ff24cb8d5b21ca38d6dc73ca1cb6df54c83ab0b48d2561f30eeea21a4503055c0f47f3db4c752926e8c66d5e6f8b47ca352931f1c9802b06c9ec78c36844b65853822c092bbb4e1c7f3fdb45d63a0318b3efbccf85ce798f649037b84f439aef7e149fdbcac88d3344478e11ac81fb548fd9c8334ea7a6b177342ba6f550406ff3fa2f478f8171234bffd8a0b636bc1fcdce5e66d424bb3e5e3686900562ce1aef12f21f2f594227e4646ec732dc4da2a0f6f213af29cc95abdcce7d250c85ce502b7c04c23140c63097f86cc1f173ed29ce57c9ac00b378269eff595c6a8b855791d0be8342b12c31f4d906647194e2a661868427747b3f27d5648236f5534fdd6ea4abf86ba0dbbb1749c979f3a7eff034210bd7e15a73658c3bbf2073393d261d99f9bc8427f687ecdeb808b088aa2bac5346774f6a81a7e1d6afb6a090607d0e644632051b3c65a10b7c2fbe57a46b76766a9598c93dd022936d36e22e928edf61e44f0572ae0f098657ba4df3298534aec6bfd536d7cf6f04dffb53123c11610b821346ba7d5495f8fd2cc457ed89b205b3e83acc53eb75a52f6b374584813a7bea0fde8e2ee7eab7779d6a9f3390d1d9b6f165d28c36fd1857f6645835188528947eb11737fe9635044fc93cdb2fdbd270611dedac0f00231d46f634da2d4d03effacc577df909a4df8347d47e2604d1e9602bbdc31a9d541d2446c0fc868854d8d39d5961fd7a17156385e5394219cc5a1926716d0c0400597ad1fa3611da843ca30b01ebfc11264d4e11f909a070009efbd0b8dd785403998fae12a2193720c49dcce9a61f544afea16911ab3dd1ebea30cc35ac32ec6dd7835327e8607ad73f5db3d6dfb2941e1c5d34bffbf38d4099a5fb8e3ce2479ba70248a127694f793795fd6810407964514b32c20e8443f75cd96a9b97783b0161f61a7565882f6a67af332d32bcc1bf78bd87cb84748ea88705e2be4a65cab69b4e2fa9024813865498baa518684cc1b3cd895978af9f3f1498c09cff05e042ccdf8242a3891d2fe61a2cd23bc30095eec6dd0779c96e579ff36986ab57e43a8e5768658d874850cca19ef1babbb1f2d71d3c1b4ce92114e9e5b2d0799f63e317cd571950a6c9a40ea0ddc98f364571f9e196cbf31e0e3c76c33a3908f3498325f0a82b18e77495d9b83c8a0620b4efa40421ef6ec30ad48d1e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855de4d278f6a8e94507b4016bcfee1a6526887e4333a37c6d3f000b34a26eafcb9cd62a993ec4740d2ce20b562d06c6226bcd2c8fb33392194889a47bbd0d6d8fd9897a4785c6de84c86c57924471228a47b57220b6c5861a12ae4b984e31e06a0a3110065d74972a98fcdb4f95d1f583ce399294a053ef7f4f42bab3fb0c48de2b0bc02a880ee05211c8894fda843f2f350240fdb473a51cf29967a5c3c9f9aa4ed4d98f91989091f7e8f3caf08d9380b34879d5fcbff9586c6775ab42dfe65824953fc40fd97fb8bf7832353ef3aa1d5d284533b979d7516f691ef802290162a19f53b1d0a781278607f857946c4d4c2bdc366ade135a769fd8dc3fd66f66035af8013cb83c80e3512a82ffdbd6e7e3d2bb2a7bf66bda0352f99db13c48cd755a685bb9065615a0ae3b85b74e0eb8729ca269d52bdf008deb45d293a4e975529791d0b57d1a2eb6cc0095b9de2fa5b334622cba5ba5feaed388a0eb903e0fc317e5c49f96a2b683ffca5e223b4583d04ee5621474b25336ef1262adcf3640f11290a9802f0588837bda9ee6f72d3142ba9c4011b433c68dd1a0b37626a1e4d3e829c9a52771115f9691554ba2b6ebff227f2da413b5ac62705c443eb0108fdfcc54f05ca932bdc4c2ebb7775ddd74dc2ce4405c85ecdc7659eefe990cbbf55787f3cb44ae1048036720a81eebd9be02d655c29513edbec5c9f088164e1ff035db12b87654c0a60e25ecda3404312e3c6ba9a6efd21f6bef595d0b10af3a0a0aa3136b84276965c6ea6df626f09bc91aed7583b1c2db7a91c7db2fdc93f67251d0a5af1d79dda70e2785b100e4d3c8c68c5c389f7bd25ccf3bb8c71148f6aed4c0e76eb082ca05c101eaea3a04040524e3da2011b7e0201e21b4322c5fbd09b8d0281552e6d045c1e69cfc30d48b715f6c5c9314c43ecb520d115f1688a63a295f5fb7f60632a78a152a42c36c1dec353db44970af724e85c9662c5c175b57e7e8a094f8f85bebf8043337edaa51b1b95fd8c94034e563938894cea87c01926d9593453440e51fd62658f08a4538a6c7f0d88ba4006ce8e0ff7403ae37cc51a788a1a299921c4a95f2a70b746818bf35766dd43aa8449b03b70c83e2cefc6911f61cd1ef5d21a51189e444c36343a81141b161d6eb9c4aa1884f43e7aefbb837d8f8bc38d77dcd72b3276d88e220cf8e94d1becf296930423f80fa066d6386d76dd7e1688114346892d50ba4dc3122ab8615eb3593c29c6432e907489c3252aa80f92e1f8e892398e87463f9a5602f126a089668a525940f476335615a6123c18cd1a4ca266c682732189917248348df377e7102655158b88c77a2f9fc2f50e8aca07ce2620f33ed1042beed95eaea7d989d961c6b8fc5ed28deee205a9c45003616ac378b9b1166ec9eab1351fea246742e81820277a2b1883306dc353002f2530a8608829259486843b14ecbac10ff2e42af22846b9b37e203798fe41160e36355ac1028851c9bed84aec6a12c77226ded96d22b3e8ff29e2c2988c9173176e09933c61e0ee9b89e548f407a75442366ecf8856eb832a80169aea4e891e95925bffc5c3579457ea12cc695c311d903ea5debdffbbabb276a5fa11f23375d3a8d994f90f3ed3a0cb6f73f0f1f4f100bbaa7867b59aac817ce52b543daecbc4e89ec55015ca119bfebda5516fb8df8578b0b6ca63cadebcf9b3b7bee6855f25e0e47050d9fc20e025837c956a81b2c3ae4debb2855291467b58e2a647a13a6b079074b6628c457968946f1c125ef24e8ba73fd330fd7006f62d7f7523f0460f05b0b2b41bc98be3ca8d19602127d5f04d54a747cc0e888f0540e1d771f19713eb88ad1dbc685f9c28a09732696553d450021ad52cdf4da664ff21503b11502cc73fad56b3e1474337c8a52ccd8593f5254abe6bc4b90a6a44817855c0ef31a856254fa89eeee239b6fca6b963a4fb01a1a04b6b3c100590811f64124951b90bf5c56dbb1af5a78426cec4624c41ebfd250b82934bcc38fb52397cd61abe75de49185e5a8df5e5e12ea8eea4a30f94dc12ce1fb5df51fdd3f9d4a2020b68c1c86d1126766e939526c27d52431747cad711003b067398b3c7b11c3e787d0cabca8b808b597abe657801e7a97a8348db45827e2ab041690e9e320ab53214c3993594919f212b51355fb817b5de7cea9e38d88a54dd8ca307a27d0d1fa184cb70bc318eb34ce4e5beadebcf399ad7f5f04e340d66b8dc3afbae31d1f72c3ec1a924227fe884897536dc0a104794ac91a91ce49f0e9604a71de2c60f0929d3d8efe27c010d1973d63ace3ece992741be9b72e57704f7e05e83cfee675e35623d5dd884d75ad267eaef8cf9a6136f4a12ad5371310296ef8a31edddb0bf3a4cc5e95a6699416a1dff4cbb20913be86f02d0d2681ea4f6466d9fc709284c508b4f1bfb125738f7888676ccbafb295687831aed1425eb727b655fc4bd473d86cf8a0962cf301fea0342aedf8e183d13b718e3a57d3a0ed905f79cea8fdcfa7a6a292fbdcaca06c4d6627578ae0a4bb32b9bfb7ac632afd247d882567ee62cc070e0a968ed8d0000f5431c52a15874c4b8e9b0ee6436a0e927573b253f39cdd922a61aa15dbe383ea2b2f131c1caf9db724574538bfbafaeba2b8470f28e8dc79f4590168f74b0240b3f2229bd64837548c5b84c22a3d9efe2d207d883e84fcc6dea47f99f1c019c1fd96be46733583fd759a6954cfa91137ec722ed944f93a26fb868321474a9062690ca6134f6dfaafeed2e77fdffa80e1d5cc0e265485fcc1296800538aa6acc5b4cbc1b4a793a6e57d194e1acc750350589bba3f7feecfb6ae990fc056bd0623deea465bf0da8b2f0598fada8e2960ab0ffb1920610cc732f077d5f144f7b5f80ef96abe5ac56a599a499d628e2b8c04452b2b9e9a6c1b0d544b8fb3dc67c2090b8c6e7082a8fe483e765864e55a4316abe8558197b54b562d2923c642643a17f4c8aa7ac8532ebff79948fc674b284675b517b032fb1963b5928824a130f95e972dc5f63dc95720c5c098c8e11d0317b129a16b3e89e31137ae3135166baf44dbfaf7385f72084c93a81c0b58d50b93b73f38662f9bd7d15b4168650787e96060473191ebf71cfcbfd7044b9c772620a323cc61e026a5a5e3ce021ae81247343456b18d4b5c1996c37de38cf7163303c7a925bf14f678197e151e777a0188ef7bbc3363ed3175925ffea323699b2965203bb11eaf708828f44b3166642e92a1f1a5ead5a86bdf8da8f64adf0281f1246a28970bdbfcf280b1bdd0337357ceb58d32b110b5b3ba84221d8b2d1f0b488c5f3f0cf5dfa87e4a95b8f0b78db12b173b109bcdb14e2301bcdf16c38b4e3c36b4a31097fca7768a30ddf95e91aa8e6abd27b10245cb84b4aa39ad4c20dff05e9a8fde4b51a739a4cd3f13b2517d1d5bc208a1b9bb6f7efa673a0690150f38946f628aedbffd094fd6a2eeba9b4d4125563a3076ac6814c63bf2a5b31e891d1a199b14162b99296f49a28407974ad265140b177696b5819f5f7e5ac318794ad9ec8549bffa1014ea522aeaa44908b864d1febd084abbb02e962e21d257e3cdac5893b5d850c30fd8648df3e39d9fc40f179f2d55e4f4c9478f67038df063aac7acc2acc2fa9b95f1b29e0b769d580a3667b2ccc22f85645261de5962f3fce95c5d94ce986fc0e3ea0cdfb0f474ce741fee8e4f95df49d8724d99e75186c314853de7fffe486f092b0a35cc94231ec9c2bd8d43e3c95b59bbc74ac156e8efbb7055d2cc44462afb54b5a6b6bafe1c588a60603a549eb05186a02e4521ffa8c0d8067ae826bfbe286e84a21571794e42535220fa13bd27e56499133dfd584af0840581bad8d7c0bdec4354c9b627d5b555a3f153fc5575467ffa54ba8cd729ff42d3acacdda990915024c801c1d1ce2bc2c1d7c172a452f6fd081003150d5b0894e24f3b690475ce2fc613b318a7ee4338b6dd98753279a791a91235aca8cf79b0b02397233a9d7a2aa3b5b5a0dbede879820d41c9c2864c315a26da13506988be00bdf05ce38ab798320e6006arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.7.10+git.124.8d97fe90926-lp150.3.9.1.src.rpmsamba-pythonsamba-python(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libattr.so.1()(64bit)libattr.so.1(ATTR_1.0)(64bit)libauth4-samba4.so()(64bit)libauth4-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libcmdline-credentials-samba4.so()(64bit)libcmdline-credentials-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libdb-glue-samba4.so()(64bit)libdb-glue-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdnsserver-common-samba4.so()(64bit)libdnsserver-common-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libdsdb-garbage-collect-tombstones-samba4.so()(64bit)libdsdb-garbage-collect-tombstones-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libposix-eadb-samba4.so()(64bit)libposix-eadb-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libpyldb-util.so.1()(64bit)libpyldb-util.so.1(PYLDB_UTIL_1.1.2)(64bit)libpytalloc-util.so.2()(64bit)libpytalloc-util.so.2(PYTALLOC_UTIL_2.0.6)(64bit)libpytalloc-util.so.2(PYTALLOC_UTIL_2.1.6)(64bit)libpytalloc-util.so.2(PYTALLOC_UTIL_2.1.9)(64bit)libpython2.7.so.1.0()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsamba-credentials.so.0()(64bit)libsamba-credentials.so.0(SAMBA_CREDENTIALS_0.0.1)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-net-samba4.so()(64bit)libsamba-net-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-policy.so.0()(64bit)libsamba-policy.so.0(SAMBA_POLICY_0.0.1)(64bit)libsamba-python-samba4.so()(64bit)libsamba-python-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0)(64bit)libsmbd-base-samba4.so()(64bit)libsmbd-base-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libsmbd-conn-samba4.so()(64bit)libsmbd-conn-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)libxattr-tdb-samba4.so()(64bit)libxattr-tdb-samba4.so(SAMBA_4.7.10_GIT.124.8D97FE90926LP150.3.9.1_SUSE_OS15.0_PPC64LE)(64bit)python(abi)python-ldbpython-tallocpython-tdbpython-teventrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)samba2.73.0.4-14.6.0-14.0-15.2-14.7.10+git.124.8d97fe909264.14.1[;@[i[6@[5@[ @Z@Z@ZZ@ZZ}@Z'Z@ZOZ@Z ,@Z@YY@Yo@Yo@Yo@Y@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USaT5'@T5'@T3T12T->@T->@T%U@T$T!`T!`T@T@TSS<@SS@S@Sہ@Sہ@Sہ@S@S;@S.S@SSSS@S@SS8@S}SxSg}@ScSZN@SXSO@SM@SM@SG@SG@SG@SG@S:@S:@S5d@S2@S,)S L@SSSS@S@S(S @S S 4@S?S?S?SK@R@Rb@R@RRR@R@RRRRRURURURRR&R@RR=R=RʚRʚRʚRʚRʚRʚRSRR@RjRjRv@RG@RG@RRRRR RiRu@RpRW@RUE@RUE@REs@R:@R6R4OR2@R(r@R%@R!R7R@R@QQQ@QQQQޞ@Qޞ@Qޞ@Qֵ@QQo@QzQQɆ@Q@Q(@Q@Qzl@QdQAQ,Q+R@Q@QQQ@Q@QEQ@Q \Q \PP-P-P9@PPDP[P@PѬ@P @P @PPP}@P+P@PP@PBPBPPP@P@P*P6@Pd@PoPoPoPoP{@Pb@Pb@PWPWPQP,PPP H@P H@PP@OjOjOORORO Ọ@OȮOȮO]@O]@O OE@O!O@OOO@O OoOc+@OaO`@OKp@OB5O>A@Ovuid is invalid after a SMB session reauth; (bso#13351); + Durable Handles reconnect fails in a cluster when the cluster fs uses different device ids; (bso#13318); + cli_splice() doesn't correctly return written bytes as it's uninitialized in libsmbclient code; (bso#13511); + Threading support in talloc_tos() crashes when enabled; (bso#13505); + Incorrect talloc_stackframe handling in python ACL test code (make_simple_acl); (bso#13474); + Fail renaming file if that file has open streams; (bso#13451); + vfs_fruit: delete 0 byte size streams if AAPL is enabled; (bso#13441); + Creating missing remote databases during recovery can fail; (bso#13500); + CTDB_BROADCAST_VNNMAP should not be used; (bso#13499); + Fix building Samba with gcc 8.1; (bso#13437); + Uncaught exception at ldb_modules/password_hash.c:2241 during new domain provision; (bso#11573); + "net ads keytab add nfs" writes only one enctype with older kerberos libraries; (bso#13478); + VFS modules that implement pread/pwrite must also implement pread_send/pwrite_send; (bso#13425); + vfs_ceph is missing async fsync implementations; (bso#13412); + net ads keytab list fails with (smb_krb5_kt_open failed (Key table name malformed); (bso#13166); + s390 and s390 needs to run with 'use mmap = no' by default; (bso#10765);- Disable NTLMv1 auth if smb.conf doesn't allow it; (bsc#1095048); (bso#13360); (CVE-2018-1139); - ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes; (bsc#1095056); (bso#13374); (CVE-2018-1140); - Confidential attribute disclosure via substring search; (bsc#1095057); (bso#13434); (CVE-2018-10919); - smbc_urlencode helper function is a subject to buffer overflow; (bsc#1103411); (bso#13453); (CVE-2018-10858); - Fix NULL ptr dereference in DsCrackNames on a user without a SPN; (bsc#1103414); (bso#13552); (CVE-2018-10918);- Update to 4.7.8; (bsc#1099702); + s3: smbd: Generic fix for incorrect reporting of stream dos attributes on a directory; (bso#13380); + ceph: VFS: Add asynchronous fsync to ceph module, fake using synchronous call; (bso#13412); + s3: libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457); + python: Fix talloc frame use in make_simple_acl(); (bso#13474); + winbindd on the AD DC is slow for passdb queries; (bso#13430); + No Backtrace given by Samba's AD DC by default; (bso#13454); + winbindd doesn't recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Fix interaction between chown and SD flags; (bso#13432); + s4-heimdal: Fix the format-truncation errors; (bso#13437); + vfs_ceph: Add fake async pwrite/pread send/recv hooks; (bso#13425); + printing: Return the same error code as Windows does on upload failures; (bso#13395); + winbind: Improve child selection; (bso#13290); + winbind: Maintain a binding handle per domain and always go via wb_domain_request_send(); (bso#13292); + winbindd doesn't recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + rpc_server: Init local_server_* in make_internal_rpc_pipe_socketpair; (bso#13370); + smbclient: Fix broken notify; (bso#13382); + libads: Fix the build --without-ads; (bso#13273); + winbindd: Don't split the rid for SID_NAME_DOMAIN sids in wb_lookupsids; (bso#13279); + winbindd: initialize type = SID_NAME_UNKNOWN in wb_lookupsids_single_done(); (bso#13280); + s4:rpc_server: Fix call_id truncation in dcesrv_find_fragmented_call(); (bso#13289); + A disconnecting winbind client can cause a problem in the winbind parent child communication; (bso#13290); + winbind: Use one queue for all domain children; (bso#13292); + Minimize the lifetime of winbindd_cli_state->{pw,gr}ent_state; (bso#13293); + winbind should avoid using fstrcpy(domain->dcname,...) on a char *; (bso#13294); + The winbind parent should find the dc of a foreign domain via the primary domain; (bso#13295); + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400); + Fix broken server side GENSEC_FEATURE_LDAP_STYLE handling (NTLMSSP NTLM2 packet check failed due to invalid signature!); (bso#13427); + s3: VFS: Fix memory leak in vfs_ceph; (bso#13424); + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407); + dfree cache returning incorrect data for sub directory mounts; (bso#13446); + Looking up the user using the UPN results in user name with the REALM instead of the DOMAIN; (bso#13369); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + s4:auth_sam: Allow logons with an empty domain name; (bso#13206); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + build: Fix libceph-common detection; (bso#13277); + build: Fix ceph_statx check when configured with libcephfs_dir; (bso#13250); + vfs_glusterfs: Fix the wrong pointer being sent in glfs_fsync_async; (bso#13297); + ctdb-scripts: Drop 'net serverid wipe' from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + smbd can panic if the client-supplied channel sequence number wraps; (bso#13215); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + s3:libsmb: Allow -U"\\administrator" to work; (bso#13206); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + smbc_opendir should not return EEXIST with invalid login credentials; (bso#13050); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + libsmb: Use smb2 tcon if conn_protocol >= SMB2_02; (bso#13310); + subnet: Avoid a segfault when renaming subnet objects; (bso#13031); + 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:smbd: Do not crash if we fail to init the session table; (bso#13315); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Bump vendor-files - Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); (bsc#1094881);- Add missing package descriptions; (bsc#1093864);- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.- Rebase File Server Remote VSS Protocol (FSRVP) server against 4.2.0rc1; (fate#313346).- Backport upstream master fixes for samba-regedit; (bnc#896536).- BuildRequire python-xml on SUSE systems only.- BuildRequire python-xml. - Exclude unwanted texpect binary and libhttp, libsamba-cluster-support, libsamba-debug, and libsocket-blocking shared libs. - Add vfs_fruit and vfs_worm man pages and ndr_dcerpc, smb2_lease_struct, tstream_smbXcli_np, idtree, and idtree_random header files. - Remove nmblookup and smbclient4 binary and nmblookup4 man page.- Update to 4.2.0rc1.- Fix small memory-leak in the background print process; (bnc#899558).- Modify samba-regedit so it displays correctly (related to ncurses). Changed code to use menu sub windows, seems to fix problems with display not refreshing; explicitly BuildRequire ncurses-devel; (bnc#896536).- Exclude unwanted libdnsserver_common and libdfs_server_ad shared libs and the man page of the unused findsmb script.- Skip groups that aren't mapped by idmap_ad; (bso#10824); (bnc#897969).- Update to 4.1.12. + s3: winbindd: On new client connect, prune idle or hung connections older than "winbind request timeout". Add new parameter "winbind request timeout". Please see smb.conf man page for details; (bso#3204); (bnc#872912). + Fix smbd crashes when filename contains non-ascii character; (bso#10716). + s4-rpc: dnsserver: Handle updates of tombstoned dnsNode objects; (bso#10749). + passdb: Fix NT_STATUS_NO_SUCH_GROUP; (bso#9570). + s4:setup/dns_update_list: make use of the new substitution variables; (bso#9831). + build: Fix configure to honour '--without-dmapi'; (bso#10369). + provision: Correctly provision the SOA record minimum TTL; (bso#10466). + s3: Enforce a positive allocation_file_size for non-empty files; (bso#10543). + lib: tevent: make TEVENT_SIG_INCREMENT atomic; (bso#10640). + Make "case sensitive = True" option working with "max protocol = SMB2" or higher in large directories; (bso#10650). + Samba 4 consuming a lot of CPU when re-reading printcap info; (bso#10652). + lib: strings: Simplify strcasecmp; (bso#10716). + Allow netr_ServerReqChallenge() and netr_ServerAuthenticate3() on different connections; (bso#10723). + 'net time': Fix usage and core dump; (bso#10728). + sys_poll_intr: Fix timeout arithmetic; (bso#10731). + s3:idmap: Don't log missing range config if range checking not requested; (bso#10737). + Fix flapping VFS gpfs offline bit; (bso#10741). + s4-rpc: dnsserver: Allow . to be specified for @ record; (bso#10742). + s4-rpc: dnsserver: return DNS_RANK_NS_GLUE recors when explicitly asked for; (bso#10751). + samba: Retain case sensitivity of cifs client; (bso#10755). + lib: Remove unused nstrcpy; (bso#10758). + Fix a memory leak in cli_set_mntpoint(); (bso#10759). + docs: Fix typos in smb.conf (inherit acls); (bso#10761). + libcli/security: Add better detection of SECINFO_[UN]PROTECTED_[D|S]ACL in get_sec_info(); (bso#10773). + s3: smbd: POSIX ACLs. Remove incorrect check for SECINFO_PROTECTED_DACL in incoming security_information flags in posix_get_nt_acl_common(); (bso#10773). + Don't discard result of checking grouptype; (bso#10777). + s3:libsmb: Set a max charge for SMB2 connections; (bso#10778). + smbd: Properly initialize mangle_hash; (bso#10782). + dosmode: Fix FSCTL_SET_SPARSE request validation; (bso#10787). + vfs_dirsort: Fix an off-by-one error that can cause uninitialized memory read; (bso#10794).- Wait for network-online.target to prevent caching of pre-network failures; (bnc#889175).- Use domain name if search by domain SID fails to send SIDHistory lookups to correct idmap backend; (bnc#773464).- Prune idle or hung connections older than "winbind request timeout"; (bso#3204); (bnc#872912).- fix FSCTL_SET_SPARSE request validation; (bso#10787); (bnc#893774).- Remove pre-11.2 patch which by default uses the smbpasswd passdb backend.- build: disable mmap on s390 systems; (bso#10765); (bnc#886193); (bnc#882356).- Create the cups smb backend as sym link pointing to smbspool; (bnc#891220).- Fix winbind service parameter usage; (bnc#890005).- lib/param: change the default for "winbind expand groups" to "0"; (bnc#890008).- Update to 4.1.11. + A malicious browser can send packets that may overwrite the heap of the target nmbd NetBIOS name services daemon; CVE-2014-3560; (bnc#889429).- Fix "net time" segfault; (bso#10728); (bnc#889539).- Update to 4.1.10. + net/doc: Make clear that net vampire is for NT4 domains only; (bso#3263). + dbcheck: Add check and test for various invalid userParameters values; (bso#8077). + s4:dsdb/samldb: Don't allow 'userParameters' to be modified over LDAP for now; (bso#8077). + Simple use case results in "no talloc stackframe around, leaking memory" error; (bso#8449). + s4:dsdb/repl_meta_data: Make sure objectGUID can't be deleted; (bso#9763). + dsdb: Always store and return the userParameters as a array of LE 16-bit values; (bso#10130). + s4:repl_meta_data: fix array assignment in replmd_process_linked_attribute(); (bso#10294). + ldb-samba: fix a memory leak in ldif_canonicalise_objectCategory(); (bso#10469). + dbchecker: Verify and fix broken dn values; (bso#10536). + dsdb: Rename private_data to rootdse_private_data in rootdse; (bso#10582). + s3: libsmbclient: Work around bugs in SLES cifsd and Apple smbx SMB1 servers; (bso#10587). + Fix "PANIC: assert failed at ../source3/smbd/open.c(1582): ret"; (bso#10593). + rid_array used before status checked - segmentation fault due to null pointer dereference; (bso#10627). + Samba won't start on a machine configured with only IPv4; (bso#10653). + msg_channel: Fix a 100% CPU loop; (bso#10663). + s3: smbd: Prevent file truncation on an open that fails with share mode violation; (bso#10671); (bnc#884056). + s3: SMB2: Fix leak of blocking lock records in the database; (bso#10673). + samba-tool: Add --site parameter to provision command; (bso#10674). + smbstatus: Fix an uninitialized variable; (bso#10680). + SMB1 blocking locks can fail notification on unlock, causing client timeout; (bso#10684). + s3: smbd: Locking, fix off-by one calculation in brl_pending_overlap(); (bso#10685). + 'RW2' smbtorture test fails when -N is set to 2 due to the invalid status check in the second client; (bso#10687). + wbcCredentialCache fails if challenge_blob is not first; (bso#10692). + Backport ldb-1.1.17 + changes from master; (bso#10693). + Fix SEGV from improperly formed SUBSTRING/PRESENCE filter; (bso#10693). + ldb: Add a env variable to disable RTLD_DEEPBIND; (bso#10693). + ldb: Do not build libldb-cmdline when using system ldb; (bso#10693). + ldb: Fix 1138330 Dereference null return value, fix CIDs 241329, 240798, 1034791, 1034792 1034910, 1034910); (bso#10693). + ldb: make the successful ldb_transaction_start() message clearer; (bso#10693). + ldb:pyldb: Add some more helper functions for LdbDn; (bso#10693). + ldb: Use of NULL pointer bugfix; (bso#10693). + lib/ldb: Fix compiler warnings; (bso#10693). + pyldb: Decrement ref counters on py_results and quiet warnings; (bso#10693). + s4-openldap: Remove use of talloc_reference in ldb_map_outbound.c; (bso#10693). + dsdb: Return NO_SUCH_OBJECT if a basedn is a deleted object; (bso#10694). + s4:dsdb/extended_dn_in: Don't force DSDB_SEARCH_SHOW_RECYCLED; (bso#10694). + Backport autobuild/selftest fixes from master; (bso#10696). + Backport drs-crackname fixes from master; (bso#10698). + smbd: Avoid double-free in get_print_db_byname; (bso#10699). + Backport access check related fixes from master; (bso#10700). + Backport provision fixes from master; (bso#10703). + s3:smb2_read: let smb2_sendfile_send_data() behave like send_file_readX(); (bso#10706). + s3: Fix missing braces in nfs4_acls.c.- Reduce printer_list.tdb lock contention during printcap update; (bso#10652); (bnc#883870). + Only update the printer share inventory when needed.- Add missing newline to debug message in daemon_ready(); (bnc#865627).- BuildRequire systemd-devel, configure --with-systemd, and modify the service files accordingly on post-12.2 systems; (bso#10517); (bnc#865627).- Prevent file truncation on an open that fails with share mode violation; (bso#10671); (bnc#884056).- Update to 4.1.9. + Fix nmbd denial of service; CVE-2014-0244; (bnc#880962). + Fix segmentation fault in smbd_marshall_dir_entry()'s SMB_FIND_FILE_UNIX handler; CVE-2014-3493; (bnc#883758).- BuildRequire krb5-devel, libiniparser-devel, and python-devel in any case.- BuildRequire libxslt and perl-ExtUtils-MakeMaker and BuildIgnore libtevent on CentOS, Fedora, and RHEL systems.- Update to 4.1.8. + dns: Don't reply to replies; CVE-2014-0239; (bso#10609). + Malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response; CVE-2014-0178; (bso#10549). + s3: smb2: Fix 'xcopy /d' with samba shares; (bso#3124). + Extra ':' in msg for Waf Cross Compile Build System with Cross-answers command; (bso#10151). + s3: nmbd: Reset debug settings after reading config file; (bso#10239). + Fix empty body in if-statement in continue_domain_open_lookup; (bso#10348). + script/autobuild: Make use of '--with-perl-{arch,lib}-install-dir'; (bso#10472). + wafsamba: Fix the installation on FreeBSD; (bso#10472). + Use exit_daemon() to communicate status of startup to systemd; (bso#10517). + Fix adding NetApps; (bso#10524). + s3: lib/util: Fix logic inside set_namearray loops; (bso#10544). + s3: lib/util: set_namearray reads across end of namelist; (bso#10544). + idmap_autorid: Fix failure in reverse lookup if ID is from domain range index #0; (bso#10547). + build: Fix ordering problems with lib-provided and internal RPATHs; (bso#10548). + Fix read of deleted memory in reply_writeclose()'; (bso#10554). + lib-util: Rename memdup to smb_memdup and fix all callers; (bso#10556). + Fix lock order violation and file lost; (bso#10564). + dsdb: Do checks for invalid renames in samldb, before repl_meta_data; (bso#10569). + Fix wildcard unlink to fail if we get an error rather than trying to continue; (bso#10577). + byteorder: Do not assume PowerPC is big-endian; (bso#10590). + printing: Fix purge of all print jobs; (bso#10612).- examples/libsmbclient: avoid some compiler warnings; (bso#10624).- Fix printer job purging; (bso#10612); (bnc#879390).- Update samba-pubkey_6568B7EA.asc which will expire 2016-01-17.- Fix byte-order macros on little endian Power8; (bso#10590); (bnc#871701).- Pass through vfs_btrfs snapshot manipulation requests when "btrfs: manipulate snapshots = no" is configured; (bnc#874180).- Clone the base share security descriptor when exposing a snapshot share; (bnc#874656).- Use appropriate HRESULT return codes; (bnc#875046).- Update to 4.1.7. + Make "force user" work as expected; (bso#9878). + Fix build on AIX with IBM XL C/C++ (gettext detection issues); (bso#9911). + Fix problem with server taking too long to respond to a MSG_PRINTER_DRVUPGRADE message; (bso#9942). + s3-printing: Fix obvious memory leak in printer_list_get_printer(); (bso#9993). + doc: Add "spoolss: architecture" parameter usage; (bso#10188). + Make 'smbclient' support DFS shares with SMB2/3; (bso#10200). + Make (lib)smbclient work with NetApp; (bso#10230). + SessionLogoff on a signed connection with an outstanding notify request crashes smbd; (bso#10344). + dfs: Always call create_conn_struct with root privileges; (bso#10378). + 'net ads search' on high latency networks can return a partial list with no error indication; (bso#10387). + max xmit > 64kb leads to segmentation fault; (bso#10422). + Fix STATUS_NO_MEMORY response from Query File Posix Lock request; (bso#10431). + Increase max netbios name components; (bso#10439). + smbd_server_connection_terminate("CTDB_SRVID_RELEASE_IP") panics from within ctdbd_migrate() with invalid lock_order; (bso#10444). + Fix 'wbinfo -i' with one-way trust; (bso#10458). + samba4 services not binding on IPv6 addresses causing connection delays; (bso#10464). + s3-vfs: Fix stream_depot vfs module on btrfs; (bso#10467). + Don't respond with NXDOMAIN to records that exist with another type; (bso#10471). + pidl: waf should have an option for the dir to install perl files and do not glob; (bso#10472). + s3-spoolssd: Don't register spoolssd if epmd is not running; (bso#10474). + s3-rpc_server: Fix handling of fragmented rpc requests; (bso#10481). + Initial FSRVP rpcclient requests fail with NT_STATUS_PIPE_NOT_AVAILABLE; (bso#10484). + lsa.idl: Define lsa.ForestTrustCollisionInfo and ForestTrustCollisionRecord as public structs; (bso#10504). + Make 'smbreadline' build with readline 6.3; (bso#10506). + smbd: Correctly add remote users into local groups; (bso#10508). + rpcclient FSRVP request UNCs should include a trailing backslash; (bso#10521). + Cleanup messages.tdb record after unclean smbd shutdown; (bso#10534). + s3:rpc_server: Minor refactoring of process_request_pdu().- Create a new DBus connection for every vfs_snapper request, to ensure correct snapper UID detection; (bnc#866354).- Fix "Invalid read" in method reply_writeclose; (bso#10554); (bnc#873658).- Fix minor compiler warnings in snapshot code-path; (bnc#873177).- Remove references to the obsolete samba-krb-printing package and get_printing_ticket binary.- Fix malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response; CVE-2014-0178; (bso#10549); (bnc#872396).- User error strings instead of hex codes where possible for FSRVP errors; (bnc#866927).- Fix remote share shadow copy request UNCs; (bso#10521); (bnc#870957).- Add krb5rcache directory to the winbind package; (bnc#870607). - Cleanup and consolidate the sysconfig and systemd service files.- Extend vfs_snapper man page to cover permissions; (bnc#870570).- Fix RPC server handling of fragmented requests; (bso#10481); (bnc#869707).- Default with the cache and lock directory to the same path to have both non-persistent and persistent data at one location; (bnc#846586).- Depend only on %version with all manual Provides and Requires; (bnc#844307).- Update to 4.1.6. + Password lockout not enforced for SAMR password changes; CVE-2013-4496; (bnc#849224). + smbcacls can remove a file or directory ACL by mistake; CVE-2013-6442; (bnc#855866).- Password lockout not enforced for SAMR password changes; CVE-2013-4496; (bnc#849224).- Call update-apparmor-samba-profile via ExecStartPre too; (bnc#867665).- samba4 smbcalcs --chown | --chgrp dacl regression; CVE-2013-6442; (bnc#855866).- Retry named pipe open requests on STATUS_PIPE_NOT_AVAILABLE; (bso#10484); (bnc#865095).- Propagate snapshot enumeration permissions errors to SMB clients; (bnc#865641).- Properly handle empty 'requires_membership_of' entries in /etc/security/pam_winbind.conf; (bnc#865771).- Fix problem with server taking too long to respond to a MSG_PRINTER_DRVUPGRADE message; (bso#9942); (bnc#863748). - Fix memory leak in printer_list_get_printer(); (bso#9993); (bnc#865561).- Fix stream_depot VFS module on Btrfs; (bso#10467); (bnc#865397).- Use libarchive to provide improved smbclient tarmode functionality; (bso#9667); (bnc#861135).- Depend on %version-%release with all manual Provides and Requires; (bnc#844307).- Update to 4.1.5. + Fix 100% CPU utilization in winbindd when trying to free memory in winbindd_reinit_after_fork; (bso#10358); (bnc#786677). + smbd: Fix memory overwrites; (bso#10415). + s3-winbind: Improve performance of wb_fill_pwent_sid2uid_done(); (bso#2191). + ntlm_auth sometimes returns the wrong username to mod_ntlm_auth_winbind; (bso#10087). + s3: smbpasswd: Fix crashes on invalid input; (bso#10320). + s3: vfs_dirsort module: Allow dirsort to work when multiple simultaneous directories are open; (bso#10406). + Add support for Heimdal's unified krb5 and hdb plugin system, cope with first element in hdb_method having a different name in different heimdal versions and fix INTERNAL ERROR: Signal 11 in the kdc pid; (bso#10418). + vfs_btrfs: Fix incorrect zero length server-side copy request handling; (bso#10424). + s3: modules: streaminfo: As we have no VFS function SMB_VFS_LLISTXATTR we can't cope with a symlink when lp_posix_pathnames() is true; (bso#10429). + smbd: Fix an ancient oplock bug; (bso#10436). + Fix crash bug in smb2_notify code; (bso#10442).- Remove superfluous obsoletes *-64bit in the ifarch ppc64 case; (bnc#437293).- Migrate @GMT token parsing functionality into vfs_snapper; (bnc#863079). + Improve vfs_snapper documentation.- Fix Winbind 100% CPU utilization caused by domain list corruption; (bso#10358); (bnc#786677).- Fix memory overwrite in FSCTL_VALIDATE_NEGOTIATE_INFO handler; (bso#10415); (bnc#862370).- Streamline the vendor suffix handling and add support for SLE 12.- Fix zero length server-side copy request handling; (bso#10424); (bnc#862558).- Set the PID directory to /run/samba on post-12.2 systems.- Make use of the tmpfilesdir macro while calling systemd-tmpfiles.- Make winbindd print the interface version when it gets an INTERFACE_VERSION request; (bnc#726937).- Fix vfs_btrfs build on older platforms with duplicate WRITE_FLUSH definitions; (bnc#860832).- Check for NULL gensec_security in gensec_security_by_auth_type(); (bnc#860809).- Ensure ndr table initialization; (bnc#860648).- Add File Server Remote VSS Protocol (FSRVP) server for SMB share shadow-copies; (fate#313346).- s3-dir: Fix the DOS clients against 64-bit smbd's; (bso#2662). - shadow_copy2: module "Previous Version" not working in Windows 7; (bso#10259). - s3-passdb: Fix string duplication to pointers; (bso#10367). - vfs/glusterfs: in case atime is not passed, set it to the current atime; (bso#10384)- s3: winbindd: Move calling setup_domain_child() into add_trusted_domain(); (bso#10358); (bnc#786677).- Default sysconfig daemon options to -D; (bso#10388); (bnc#857454).- Add /var/cache/samba to the client file list; (bnc#846586).- Really add the WINBINDDOPTIONS sysconfig variable on install; (bnc#857454).- Correct sysconfig variable names by adding the missing D char; (bnc#857454).- Update to 4.1.4. + Fix segfault in smbd; (bso#10284). + Fix SMB2 server panic when a smb2 brlock times out; (bso#10311).- Call stop_on_removal from preun and restart_on_update and insserv_cleanup from postun on pre-12.3 systems only; (bnc#857454).- BuildRequire gamin-devel instead of unmaintained fam-devel package on post-12.1 systems.- smbd: allow updates on directory write times on open handles; (bso#9870). - lib/util: use proper include for struct stat; (bso#10276). - s3:winbindd fix use of uninitialized variables; (bso#10280). - s3-winbindd: Fix DEBUG statement in winbind_msg_offline(); (bso#10285). - s3-lib: Fix %G substitution for domain users in smbd; (bso#10286). - smbd: Always use UCF_PREP_CREATEFILE for filename_convert calls to resolve a path for open; (bso#10297). - smb2_server processing overhead; (bso#10298). - ldb: bad if test in ldb_comparison_fold(); (bso#10305). - Fix AIO with SMB2 and locks; (bso#10310). - smbd: Fix a panic when a smb2 brlock times out; (bso#10311). - vfs_glusterfs: Enable per client log file; (bso#10337).- Add /etc/sysconfig/samba to the main and winbind package; (bnc#857454).- Create /var/run/samba with systemd-tmpfiles on post-12.2 systems; (bnc#856759).- Fix broken rc{nmb,smb,winbind} sym links which should point to the service binary on post-12.2 systems; (bnc#856759).- Add Snapper VFS module for snapshot manipulation; (fate#313347). + dbus-1-devel required at build time.- Add File Server Remote VSS Protocol (FSRVP) client for SMB share shadow-copies; (fate#313345).- Do not BuildRequire perl ExtUtils::MakeMaker and Parse::Yapp as they're part of the minimum build environment.- Update to 4.1.3. + DCE-RPC fragment length field is incorrectly checked; CVE-2013-4408; (bnc#844720). + pam_winbind login without require_membership_of restrictions; CVE-2012-6150; (bnc#853347).- Make use of the full gpg pub key file name including the key ID.- Add transparent file compression support; (fate#316266). + Implement FSCTL_GET_COMPRESSION and FSCTL_SET_COMPRESSION handlers. + Add FILE_ATTRIBUTE_COMPRESSED and FILE_NO_COMPRESSION support. + Extend vfs_btrfs VFS module to utilize get/set compression hooks.- Add support for FSCTL_SRV_COPYCHUNK_WRITE; (fate#314770).- Remove bogus libsmbclient0 package description and cleanup the libsmbclient line from baselibs.conf; (bnc#853021).- BuildRequire systemd on post-12.2 systems.- Update to 4.1.2. + s4-dns: dlz_bind9: Create dns-HOSTNAME account disabled; (bso#9091). + dfs_server: Use dsdb_search_one to catch 0 results as well as NO_SUCH_OBJECT errors; (bso#10052). + Missing talloc_free can leak stackframe in error path; (bso#10187). + Fix memset used with constant zero length parameter; (bso#10190). + s4:dsdb/rootdse: report 'dnsHostName' instead of 'dNSHostName'; (bso#10193). + Make offline logon cache updating for cross child domain group membership; (bso#10194). + nsswitch: Fix short writes in winbind_write_sock; (bso#10195). + RW Deny for a specific user is not overriding RW Allow for a group; (bso#10196). + vfs_glusterfs: Fix excessive debug output from vfs_gluster_open(); (bso#10224). + vfs_glusterfs: Implement proper mashalling/unmarshalling of ACLs; (bso#10224). + VFS plugin was sending the actual size of the volume instead of the total number of block units because of which windows was getting the wrong volume capacity; (bso#10224). + libcli/smb: Fix smb2cli_ioctl*() against Windows 2008; (bso#10232). + xattr: Fix listing EAs on *BSD for non-root users; (bso#10247). + Fix the build of vfs_glusterfs; (bso#10253). + s3-winbindd: Fix cache_traverse_validate_fn failure for NDR cache entries; (bso#10264). + util: Remove 32bit macros breaking strict aliasing; (bso#10269).- Let gpg verify execution condition not fail on non SUSE systems.- Add systemd support for post-12.2 systems.- Allow smbcacls to take a '--propagate-inheritance' flag to indicate that the add, delete, modify and set operations now support automatic propagation of inheritable ACE(s); (FATE#316474).- Unconditionally create the CUPS smb backend sym link pointing to smbspool; (bnc#850656).- Update to 4.1.1. + ACLs are not checked on opening an alternate data stream on a file or directory; CVE-2013-4475; (bso#10229); (bnc#848101). + Private key in key.pem world readable; CVE-2013-4476; (bnc#848103).- Private key in key.pem world readable; CVE-2013-4476; (bnc#848103).- ACLs are not checked on opening an alternate data stream on a file or directory; CVE-2013-4475; (bso#10229); (bnc#848101).- Update to 4.1.0. + pam_winbindd: Support the KEYRING ccache type; (bso#10132). + Fix PAC parsing failure; (bso#10178).- Unify the defattr lines in the pidl, python, test and test-devel files section by removing the optional directory mode.- Verify source tar ball gpg signature.- Update to 4.1.0rc4. + dsdb: Convert the full string from UTF16 to UTF8, including embedded NULLs; (bso#8077). + python-samba-tool fsmo: Do not give an error on a successful role transfer; (bso#9461). + dbwrap_ctdb: Treat empty records as non-existing; (bso#10008). + Raise the level of a debug when unable to open a printer; (bso#10118). + Add "acl allow execute always" parameter; (bso#10134). + vfs_shadow_copy2: Display previous versions correctly over SMB2; (bso#10137). + smbd: Always clean up share modes after hard crash; (bso#10138). + Valid utf8 filenames cause "invalid conversion error" messages; (bso#10139). + libcli/smb: Use SMB1 MID=0 for the initial Negprot; (bso#10144). + Samba SMB2 client code reads the wrong short name length in a directory listing reply; (bso#10145). + libcli/smb: Only check the SMB2 session setup signature if required and valid; (bso#10146). + Better document potential implications of a globally used "valid users"; (bso#10147). + cli_smb2_get_ea_list_path() failed to close file on exit; (bso#10149). + Not all OEM servers support the ALTNAME info level; (bso#10150). + Regression causes replication failure with Windows 2008R2 and deletes Deleted Objects; (bso#10157). + Netbios related samba process consumes 100% CPU; (bso#10158). + Fix POSIX ACL mapping when setting DENY ACE's from Windows; (bso#10162).- Require libndr-standard-devel due to gen_ndr/lsa.h from libpdb-devel.- Add libdcerpc0, libdcerpc-atsvc0, libdcerpc-binding0, libdcerpc-samr0, libgensec0, libndr0, libndr-krb5pac0, libndr-nbt0, libndr-standard0, libpdb0, libregistry0, libsamba-credentials0, libsamba-hostconfig0, libsamba-policy0, libsamba-util0, libsamdb0, libsmbclient-raw0, libsmbconf0, libsmbldap0, and libtevent-util0 to baselibs.conf.- Add or polish the shared library package summaries and descriptions.- Update to 4.1.0rc3. + Fix working on site with Read Only Domain Controller; (bso#5917). + Add man page for vfs_syncops; (bso#7364). + Add man page for vfs_linux_xfs_sgid; (bso#7490). + When replicating DNS for bind9_dlz we need to create the server-DNS account remotely; (bso#9091). + Winbind unable to retrieve user information from AD; (bso#9615). + winbind_lookup_names() fails because of NT_STATUS_CANT_ACCESS_DOMAIN_INFO; (bso#9899). + Build Samba 4.0.x on AIX with IBM XL C/C++; (bso#9911). + Add SMB2 and SMB3 support for smbclient; (bso#9974). + Add man pages for ntdb tools; (bso#10000). + Add man page for samba-regedit tool; (bso#10001). + ::1 added to nameserver on join; (bso#10030). + Fix memory leak in source3/lib/util.c:1493; (bso#10063). + Fix segmentation fault in 'net ads join'; (bso#10073). + Fix variable list in vfs_crossrename man page; (bso#10076). + s3-winbind: Fix a segfault passing NULL to a fstring argument; (bso#10082). + smbd: Fix async echo handler forking; (bso#10086). + MacOSX 10.9 will not follow path-based DFS referrals handed out by Samba; (bso#10097). + Honour output buffer length set by the client for SMB2 GetInfo requests; (bso#10106). + Fix Winbind crashes on DC with trusted AD domains; (bso#10107). + Handle Dropbox (write-only-directory) case correctly in pathname lookup; (bso#10114). + Masks incorrectly applied to UNIX extension permission changes; (bso#10121).- Implement shared library packaging guidelines. - Correct interpackage dependencies; (bso#10129).- Define the source URL differently in the case of a release candidate.- Update to 4.1.0rc2. + Add vfs_btrfs module. + Add support for server-side copy operations via the SMB2 FSCTL_SRV_COPYCHUNK request. + Fix replication with --domain-crictical-only to fill in backlinks; (bso#9029). + Windows 8 Roaming profiles fail; (bso#9678). + Fix crash of winbind after "ls -l /usr/local/samba/var/locks/sysvol"; (bso#9820). + Windows error 0x800700FE when copying files with xattr names containing ":"; (bso#9992). + Do not delete an existing valid credential cache (s3-winbind); (bso#9994). + Fix segfault while reading incomplete session info; (bso#10003). + Missing integer wrap protection in EA list reading can cause server to loop with DOS (CVE-2013-4124); (bso#10010). + Fix a 100% loop at shutdown time (smbd); (bso#10013). + Fix/improve debug options; (bso#10015). + Rename regedit to samba-regedit; (bso#10040). + Remove obsolete swat manpage and references; (bso#10041). + Fix crashes in socket_get_local_addr(); (bso#10042). + Allow to change the default location for Kerberos credential caches; (bso#10043). + Remove a redundant inlined substitution of ACLs; (bso#10045). + nsswitch: Add OPT_KRB5CCNAME to avoid an error message; (bso#10048). + dsdb improvements; (bso#10056). + Linux kernel oplock breaks can miss signals; (bso#10064).- BuildRequire pyldb-devel.- Add libnetapi0 and samba-libs to baselibs.conf.- Update to 4.0.9. + Fix crash of Winbind after "ls -l /usr/local/samba/var/locks/sysvol"; (bso#9820). + s3-lib: Fix segmentation fault while reading incomplete session info; (bso#10003). + smbd: Fix a 100% loop at shutdown time; (bso#10013). + Windows 8 Roaming profiles fail; (bso#9678). + Add UPN enumeration to passdb internal API; (bso#9779). + smbd: Cleanup disonnected durable handles; (bso#9930). + vfs_streams_xattr: Do not attempt to write empty attribute twice; (bso#9970). + Fix Windows error 0x800700FE when copying files with xattr names containing ":"; (bso#9992). + s3-winbind: Do not delete an existing valid credential cache; (bso#9994). + Fix excessive RID allocation; (bso#10014). + Add debugclass for DNS server; (bso#10015). + Fix/improve debug options; (bso#10015). + Allow to change the default location for Kerberos credential caches; (bso#10043). + Linux kernel oplock breaks can miss signals; (bso#10064). + net ads join: Fix segmentation fault in create_local_private_krb5_conf_for_domain; (bso#10073).- Update to 4.0.8. + Samba 3.0.x to 4.0.7 are affected by a denial of service attack on authenticated or guest connections; CVE-2013-4124; (bnc#829969).- Require krb5 and not the non existing krb5-libs package.- Update to 4.1.0rc1. + Directory database replication (AD DC mode) + Server-Side Copy Support + Btrfs Filesystem Integration- BuildRequire perl ExtUtils::MakeMaker and Parse::Yapp. - BuildRequire libxslt, libxslt1, or libxslt-tools depending on SUSE version. - Require perl-base on SUSE systems only.- Adjust group setting of the test-devel subpackage. - Require perl-base from the pidl subpackage.- Remove libdir/samba/ldb after install if we're building Samba without Active Directory Domain Controller support.- Remove unused ccache switch from the spec file.- BuildRequire docbook-xsl-stylesheets and libxslt-tools to build the man pages and add them to the package again.- Build from the package from the top level directory; (bnc#794744). - BuildRequire pytalloc-devel, python-tdb, and python-tevent. - Also use out of tree builds of talloc, tdb, tevent, and ldb for pre-12.1 SUSE systems.- Remove the empty data dir from the doc package filelist. - Explicitly use samba instead of the name macro to define the docbook dir.- Update to 4.0.7. + Fix a core dump with invalid lock order while opening/editing or copying MS files; (bso#9794). + Fix crash bug from search of mail=; (bso#9967). + s3-rpc_server: Ensure we are root when starting and using gensec; (bso#9465). + Add support for MX queries; (bso#9485). + dns: Delete dnsNode objects when they are empty; (bso#9559). + dns: Support larger queries when asking forwarder; (bso#9632). + s3:lib/server_mutex: Open mutex.tdb with CLEAR_IF_FIRST; (bso#9805). + Use of wrong RFC2307 primary group field; (bso#9880). + Check for system libtevent; (bso#9881). + is_printer_published GUID retrieval; (bso#9900). + Doc fixes for 4.0; (bso#9906). + Build fixes for 4.0 found during autoconf or debian packaging work; (bso#9907). + build: Add missing new line to replaced python shebang line; (bso#9909). + PIE builds not supported; (bso#9910). + s4:winbind: Don't leak libnet_context into the main event context; (bso#9929). + Fix a bug of drvupgrade of smbcontrol; (bso#9941). + Check for netbios aliases in ad_get_referrals; (bso#9947). + Fix tevent_poll on 32-bit machines (Coverity ID 989236); (bso#9953). + docs: Avoid mentioning a possibly misleading option; (bso#9964). + Fix build with system Heimdal of samba4kgetcred; (bso#9968).- Use SLE as product prefix for SUSE Linux Enterprise, oS for openSUSE, and OBS for any other operating system to define the vendor string while build.- Remove ldapsmb from the main spec file.- Adjust ldapsmb and nmbstatus man page syntax required by a newer pod2man.- Don't bzip2 the main tar ball, use the upstream gziped one instead.- Explicitly BuildRequire cyrus-sasl-devel, libattr-devel, and libopenssl-devel.- Fix libreplace license ambiguity; (bso#8997); (bnc#765270).- Update to 4.0.6. + Fix crash during Win8 sync; (bso#9822). + Fix segfault when loging in with wrong password from w2k8r2; (bso#9834). + Fix the username map optimization; (bso#9139). + Add support for PFC_FLAG_OBJECT_UUID when parsing packets; (bso#9382). + SMB2 server doesn't support recvfile; (bso#9412). + Fix the build of vfs_notify_fam; (bso#9545). + Fix adding case sensitive spn; (bso#9699). + Properly handle oplock breaks in compound requests; (bso#9722). + Properly handle oplock breaks in compound requests; (bso#9722). + Cache name_to_sid/sid_to_name correctly; (bso#9766). + Fix 'net ads join' when called via stdin; (bso#9767). + Fix segfault for "artificial" conn_structs in vfs_fake_perms; (bso#9775). + vfs_dirsort uses non-stackable calls, dirfd(), malloc instead of talloc and doesn't cope with directories being modified whilst reading; (bso#9777). + Fix panic when running 'smbtorture smb.base'; (bso#9782). + Use specified python for runtime installation of Samba; (bso#9785). + Change '--with-dmapi' to 'default=auto' to match the autoconf build; (bso#9803). + wafsamba: Display the default value in help for SAMBA3_ADD_OPTION; (bso#9804). + wbinfo: Fix segfault in wbinfo_pam_logon; (bso#9807). + Package new dbwrap_tool man page; (bso#9809). + Old DOS SMB CTEMP request uses a non-VFS function to access the filesystem; (bso#9811). + Fix 'map untrusted to domain' with NTLMv2; (bso#9817). + SMB signing and the async echo responder don't work together; (bso#9824). + Fix panic in nt_printer_publish_ads; (bso#9830). + talloc use after free in winbind4; (bso#9832). + Function called in unix_convert() path can overwrite errno; (bso#9833). + Fix NULL pointer dereference in Winbind; (bso#9854). + Fix making LIBNDR_PREG_OBJ; (bso#9868).- Remove disabled and anyhow obsoleted net-report and net_rpc_migrate patches.- Update to 4.0.5. + Fix large reads/writes from some Linux clients; (bso#9706). + Add 'samba-tool dbcheck --reset-well-known-acls'; (bso#9740). + Can't delegate adding computers to domain; (bso#9267). + Fix GNU ld version detection with old gcc releases; (bso#7825). + Never try to map global SAM name; (bso#9039). + Certain xattrs cause Windows error 0x800700FF; (bso#9130). + Samba returns unexpected error on SMB posix open; (bso#9519). + Fix build on AIX; (bso#9557). + libnss-winbindd does not provide pass struct for groups mapped with ID_TYPE_BOTH and vice versa; (bso#9617). + Reauth-capable client fails to access shares on Windows member; (bso#9625). + PIDL: Fix parsing linemarkers in preprocessor output; (bso#9636). + Rename internal subsystem pdb_ldap to pdb_ldapsam; (bso#9639). + Fix the build of vfs_afsacl; (bso#9642). + Fix the build with --fake-kaserver; (bso#9643). + Fix compile of source3/lib/afs.c; (bso#9644). + Make SMB2_GETINFO multi-volume aware; (bso#9646). + idmap_autorid: Fix freeing of non-talloced memory; (bso#9653). + Work around FreeBSD's getaddrinfo() underscore issue; (bso#9656). + 'make test' hangs; (bso#9663). + Fix correct linking of libreplace with cmdline-credentials; (bso#9664). + Fix filtering of link-local addresses; (bso#9666). + Fix crash in 'net rpc join' against a Samba 3.0.33 PDC; (bso#9669). + Samba denies owner Read Control when there is a DENY entry while W2K08 does not; (bso#9674). + Fix several resource (fd) leaks; (bso#9683). + Fix a memory leak in spoolss rpc server; (bso#9685). + Fix a possible buffer overrun in pdb_smbpasswd; (bso#9686). + Fix several possible null pointer dereferences; (bso#9687). + Make sure that domain joins work correctly when the DC disallows NTLM auth; (bso#9689). + Backport tevent changes to bring library to version 0.9.18; (bso#9695). + Remove incomplete samba_dnsupdate IPv6 link-local address check; (bso#9696). + DsReplicaGetInfo fails due to sendto() EMSGSIZE error on UNIX domain socket; (bso#9697). + Fix vfs_catia and update documentation; (bso#9701); (bnc#824833). + Fix build on solaris8: Do not force a specific perl on pod2man; (bso#9703). + Fix nss_winbind name on FreeBSD; (bso#9704). + s4:winbindd: Do not drop the workgroup name in the getgrnam, getgrent and getgrgid calls; (bso#9711). + Set LD_LIBRARY_PATH in install_with_python.sh; (bso#9717). + s4-idmap: Remove requirement that posixAccount or posixGroup be set for rfc2307; (bso#9718). + Allow forcing an override of an old @MODULES record; (bso#9719). + Do not print the admin password during 'samba-tool classicupgrade'; (bso#9720). + Make samba_upgradedns more robust (do not guess addresses when just changing roles); (bso#9721). + Add a tool to migrate latin1 printing tdbs to registry; (bso#9723). + is_encrypted_packet() function incorrectly used inside server; (bso#9724). + upgradeprovision and 'samba-tool dbcheck' patches for 4.0.NEXT; (bso#9725). + Fix NULL pointer dereference; (bso#9727). + DO NOT install samba_upgradeprovision in 4.0.x; (bso#9728). + Fix 'smbcontrol close-share'; (bso#9733). + Fix Winbind separator in upn to username conversion; (bso#9735). + Change to smbd/dir.c code gives significant performance increases on large directory listings; (bso#9736). + PIDL: Build fixes for hosts without CPP (Solaris 11); (bso#9739). + Make sure that we only propogate the INHERITED flag when we are allowed to; (bso#9747). + Remove unneeded fstat system call from hot read path; (bso#9748). + Don't leak the epm_Map policy handle; (bso#9758). + Fix incorrect parsing of SMB2 command codes; (bso#9760). - Update to 4.0.4. + Remove forced set of 'create mask' to 0777; CVE-2013-1863; (bnc#809624).- Fix periodic printcap cache reloads; (bso#9650); (bnc#807334).- No longer use the cifs- or smbfstab named configuration file on post-12.2 systems; (bnc#804822); (bnc#821889).- Shift the smbfs init script nfs dependency from Required to Should.- Fix SMB1 Session Setup AndX handling with a large krb PAC; (bso#9658); (bnc#802031).- Point LD_LIBRARY_PATH to the just-built libraries while calling testparm to generate the default share snippets on pre-12.2 systems.- Explicitly configure --with-ads.- Fix smbclient recursive mget EPERM handling; (bso#9633); (bnc#786350).- Remove superfluous quotation marks while setting the SAMBA_VERSION_VENDOR_SUFFIX string.- Do not restart the smbfs service on pre-11.3 systems during dhcp lease renewal when the IP address remains the same; (bnc#800782).- Update to 4.0.3. + Fix ACL problem with delegation of privileges and deletion of accounts over LDAP interface; add documentation; (bso##8909). + check_password_quality: Handle non-ASCII characters properly; (bso##9105). + Fix 'smbd' panic triggered by unlink after open; (bso##9571). + smbd: Fix memleak in the async echo handler; (bso##9549). + defer_open is triggered multiple times on the same request; (bso#9196). + Add extra attributes for AD printer publishing; (bso#9378). + FSMO seize of naming role fails: NT_STATUS_IO_TIMEOUT; (bso#9461). + Downgrade v4 printer driver requests to v3; (bso#9474). + samba_upgradeprovision: fix the nTSecurityDescriptor on more containers; (bso#9481). + s3:smb2_negprot: set the 'remote_proto' value; (bso#9499). + waf assumes that pythonX.Y-config is a Python script; (bso#9503). + s4:drsuapi: Make sure we report the meta data from the cycle start; (bso#9508). + wafsamba: Use additional xml catalog file; (bso#9512). + samba_dnsupdate: Set KRB5_CONFIG for nsupdate command; (bso#9517). + conn->share_access appears not be be reset between users; (bso#9518). + Remove superfluous bracket in samba.8.xml; (bso#9528). + Fix typo in vfs_tsmsm.8.xml; (bso#9530). + terminate the irpc_servers_byname() result with server_id_set_disconnected(); (bso#9540). + Make use of posix_openpt; (bso#9541). + Fix build of vfs_commit and plug in async pwrite support; (bso#9544). + Fix aio_suspend detection on FreeBSD; (bso#9546). + Correctly detect O_DIRECT; (bso#9548). + sigprocmask does not work on FreeBSD to stop further signals in a signal handler; (bso#9550). + smb.conf(5): Update list of available protocols; (bso#9552). + s4-resolve: Fix parsing of IPv6/AAAA in dns_lookup; (bso#9555). + Fix compilation of Solaris ACL module; (bso#9564). + Adding additional Samba 4.0 DC to W2k8 srv AD domain (in win200 functional level) produces dbcheck errors; (bso#9565). + Add dbwrap_tool.1 manual page; (bso#9568). + Document the command line options in dbwrap_tool(1); (bso#9568). + ntlm_auth(1): Fix format and make examples visible; (bso#9569). + Fix file corruption during SMB1 read by Mac OSX 10.8.2 clients; (bso#9572). + Fix a possible null pointer dereference in spoolss; (bso#9574). + Duplicate flags defined in the winbindd protocol; (bso#9575). + gensec: Allow login without a PAC by default; (bso#9581). + smbd: disk_free: sys_popen() failed" message logged in /var/log/message many times; (bso#9586). + Archive flag is always set on directories; (bso#9587). + ACLs are not inherited to directories for DFS shares; (bso#9588). + Correct meta data in ldb manpages; (bso#9591). + s3-winbind: Fix the build of idmap_ldap; (bso#9595). + Linked attribute handling should be by GUID; (bso#9596). + Fix timeouts of some IRPC calls; (bso#9598). + Use pid,task_id as cluster_id in process_single just like process_prefork; (bso#9598). + Add 'ldbdump' tool; general code and documentation cleanup; (bso#9609). + dsdb: Make secrets_tdb_sync cope with -H secrets.ldb; (bso#9610).- Update to 4.0.2. + Address SWAT security issues CVE-2013-0213 and CVE-2013-0214 which both don't apply to any SUSE Samba post-3.6.10 as it isn't longer built. + Don't build and package static libraries.- Drop separate build-source-timestamp file as it led to a second, incorrect Source Timestamp line.- Add server-side copy support; (fate#314770). + Implement FSCTL_SRV_COPYCHUNK and FSCTL_SRV_REQUEST_RESUME_KEY handlers. + Add vfs_btrfs VFS module for optimized Btrfs clone-range ioctl usage.- Add filter against shlib-policy-name-error for /lib*/libnss_wins.so.2.- Disable SWAT during configure and don't package it any longer.- Remove dangling references to Heimdal from the spec file.- Remove /lib/samba prefix from the localstatedir configure option.- Update to 4.0.1. + Samba 4.0.0 as an AD DC may provide authenticated users with write access to LDAP directory objects; CVE-2013-0172; (bnc#798364).- Add the missing get_printing_ticket binary path while calling the set_permissions macro; (bnc#783375).- Use the version macro while definition of the branch macro.- Remove references to no longer used devel macros.- Update to 4.0.0. + Honor password complexity settings; (bso#9414). + Install SWAT *.msg files with waf; (bso#9415). + Fix netr_ServerPasswordSet2, netr_LogonSamLogon with netlogon AES; (bso#9438). + developer-build: Fix panic when acl_xattr fails with access denied; (bso#9456). + Fix "map username script" with "security=ads" and Winbind; (bso#9457). + Install manpages only if we install the target; (bso#9459). + Respond correctly to FILE_STREAM_INFO requests; (bso#9460). + Users can not be given write permissions any more by default; (bso#9462). + Fix MMC crashes; (bso#9470). + Fix SEGV when using second vfs module; (bso#9471). + Support FIPS mode when building Samba; (bso#9479). + Fix ACL on "cn=partitions,cn=configuration"; (bso#9481).- netr_ServerPasswordSet2, netr_LogonSamLogon with netlogon AES broken; (bso#9438). - s3:auth: fix create_token_from_sid() to not fail in the winbindd case; (bso#9457). - s4:dsdb/acl_read: return the nTSecurityDescriptor attr if the sd_flags control is given; (bso#9470). - Support FIPS mode when building Samba; (bso#9479). - s4:provision: set the correct nTSecurityDescriptor; (bso#9481).- SEGV when using second vfs module; (bso#9471).- Update to 3.6.10. + Respond correctly to FILE_STREAM_INFO requests; (bso#9460). + Fix segfault when "default devmode" is disabled; (bso#9433). + Fix segfaults in "log level = 10" on Solaris; (bso#9390).- s3:smbd:vfs_acl: fix a PANIC when setting an ACL fails with ACCESS_DENIED; (bso#9456). - Install manpages only if we install the target; (bso#9459). - Users can not be given write permissions any more by default; (bso#9462).- Fix MD5 detection in the autoconf build; (bso#9037); (bso#9086); (bso#9094); (bso#9418). - Use work around for 'winbind use default domain' only if it is set; (bso#9367). - Allow smb2.acls torture test to pass against smbd with a POSIX ACLs backend; (bso#9374). - large read requests cause server to issue malformed reply; (bso#9422). - s3-rpc_client: lookup nametype 0x20 in rpc_pipe_open_tcp_port(); (bso#9426). - Fix ncacn_ip_tcp reconnection code for lsa lookups; (bso#9439). - Allow to force DNS updates using net; (bso#9451). - Respond correctly to FILE_STREAM_INFO requests; (bso#9460).- Update to 4.0.0rc6. See WHATSNEW.txt from the samba-doc package.- On uninstall remove winbind from the pam configuration, invalidate the nscd passwd and group cache and only recommend the install of nscd; (bnc#792340).- BuildRequire libnscd-devel once.- Remove obsoleted references to pre-9.4 SUSE systems; (bnc#792294). - Add SUSE version depending pkg-config requires macro; (bnc#792294).- Define library names and use it instead of libldb1, libnetapi0, libsmbclient0, libsmbsharemodes0, libtalloc2, libtdb1, libtevent0, and libwbclient0; (bnc#792294). - Provide and obsolete libsmbsharemodes for post-10.3 SUSE systems.- Don't clutter the spec file diff view; (bnc#783384).- Fix fd leak causing 100% CPU in winbind on certain dc connection failures; (bso#9436); (bnc#786677).- Fix spoolss segfault when default devmode is disabled; (bso#9433); (bnc#791183).- Update to 4.0.0rc5. See WHATSNEW.txt from the samba-doc package.- ACL masks incorrectly applied when setting ACLs; (bso#9236). - s3-kerberos: also try with AES keys, when decrypting tickets; (bso#9272). - lib/replace: replace all *printf function if we replace snprintf; (bso#9390). - lib/addns: don't depend on the order in resp->answers[]; (bso#9402).- s4:torture/smb2: improve the smb2.create.blob tes; (bso#9209). - lib/krb5_wrap: request enc_types in the correct order; (bso#9272). - Fix net ads join message for the dns domain; (bso#9326). - docs-xml: fix use of tag; (bso#9345). - s3-aio_pthread: Optimize aio_pthread_handle_completion; (bso#9359). - s3:winbind: Failover if netlogon pipe is not available; (bso#9386).- Execute the run_permissions macro on pre-11.4 systems and else the set_permission one if available.- Ensure adding the winbind group never can fail.- Create ntadmin group only if it doesn't yet exist.- Update to 3.6.9. + When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). + Winbind can't fetch user or group info from AD via LDAP; (bso#9147). + Fix segfault in smbd if user specified ports out for range; (bso#9218).- quota: Don't force the block size to 512; (bso#3272). - Fix poll replacement to become a msleep replacement; (bso#8107). - Fix wrong test == syntax in configure; (bso#8146). - Fix --with(out)-sendfile-support option handling in autoconf; (bso#8344). - Fix builtin forms order to match Windows again; (bso#8632). - Fix RAW printing for normal users; (bso#8769); (bnc#790741). - Initialise ticket to ensure we do not invalid memory; (bso#8788). - Fix 'net rpc share allowedusers' to work with 2008r2; (bso#8966). - Fix crash on null pam change pw response; (bso#9013). - Connection to outbound trusted domain goes offline; (bso#9016). - Increase debug level for info that the db is empty; (bso#9112). - 'smbclient' can't connect to a Windows 7 server using NTLMv2; (bso#9117). - Winbind can't fetch user or group info from AD via LDAP; (bso#9147). - Open printers with the right access mask; (bso#9154). - Fix makerpms.sh on RHEL; (bso#9165). - Remove non-existent option '-Y' from winbindd manpage; (bso#9171). - Add quota support for gfs2; (bso#9172). - Make SMB2 compound request create/delete_on_close/close work as Windows; (bso#9173). - Empty SPNEGO packet can cause smbd to crash; (bso#9174). - pam_winbind: Match more return codes when wbcGetPwnam has failed; (bso#9177). - Fix crash bug in idmap_hash; (bso#9188); (bnc#788159). - SMB2 Create doesn't return correct MAX ACCESS access mask in blob; (bso#9189). - Fix service control for non-internal services; (bso#9192). - Don't take 'state->te' as indication for "was_deferred"; (bso#9196). - Parse of invalid SMB2 create blob can cause smbd crash; (bso#9209). - Bad ASN.1 NegTokenInit packet can cause invalid free; (bso#9213). - Fix segfault in smbd if user specified ports out for range; (bso#9218). - Signing cannot be disabled for SMB2 by design, so fix the documentation instead; (bso#9222). - Fix NT_STATUS_IO_TIMEOUT during slow import of printers into registry; (bso#9231). - When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). - lib-addns: ensure that allocated buffer are pre set to 0; (bso#9259). - Make tdb robust against shrinking tdbs and improper CLEAR_IF_FIRST restart; (bso#9268). - Add support for reloading systemd services; (bso#9280).- Warn via the smbd log if AppArmor and "wide links" are in use; (bnc#783719).- Do not write the build date into the header of the default smb.conf as this causses superfluous rebuilds of packages depending on samba; (bnc#781601).- Do not prerequire SuSEconfig.permissions as it's already enough and more generic to depend on the permissions package; (bnc#782293).- Update to 3.6.8. + Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). + Fix Winbind panic if we couldn't find the domain; (bso#9135).- Backport FSCTL codes and fix segfault in smbstatus from master; (bso#9058). - Fix bad call to memcpy source3/registry/regfio.c; (bso#9065). - "Domain Users" incorrectly added as additional group on domain members; (bso#9066). - Use correct RID for "Domain Guests" primary group; (bso#9067). - Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). - Fix smbclient/tarmode panic when connecting to Windows 2000 clients; (bso#9088). - Fix refreshing of Kerberos tickets in Winbind; (bso#9098). - Fix identification of idle clients in Winbind to avoid crashes and NDR parsing errors; (bso#9104). - Fix compilation with newer MIT Kerberos which hides internal symbols; (bso#9111). - Fix flooding the logs with records we don't find in pcap; (bso#9112). - Initialize the print backend after we setup winreg; (bso#9122). - Fix lprng job tracking errors; (bso#9123). - Fix setting of "inherited" bit on inherited ACE's; (bso#9124). - Fix Winbind panic if we couldn't find the domain; (bso#9135). - Make 'smbclient allinfo' show the snapshot list; (bso#9137). - Fix nfs quota support with Linux nfs4 mounts; (bso#9144). - Valid open requests can cause smbd assert due to incorrect oplock handling on delete requests; (bso#9150).- NMB registration for a duplicate workstation fails with registration refuse; (bso#9085); (bnc#770056).- Remove backup files caused by running configure in examples/VFS.- Update to 3.6.7. + Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). + Fix migrating printers while upgrading from 3.5.x; (bso#9026).- Correct documentation of "case sensitive"; (bso#8552). - Printing fails in function cups_job_submit; (bso#8719). - Fix kernel oplocks when uid(file) != uid(process); (bso#8974). - Send correct responses to NT Transact Secondary when no data and no params for the Trans2 calls are set; (bso#8989). - Fix build without ads support; (bso#8996). - Don't turn negative cache entries into valid idmappings; (bso#9002). - Fix posix acl on gpfs; (bso#9003). - Make vfs_gpfs less verbose in get/set_xattr functions; (bso#9022). - Fix migrating printers while upgrading from 3.5.x; (bso#9026). - Fix typo in set_re_uid() call when USE_SETRESUID selected in configure; (bso#9034). - Using asynchronous IO with SMB2 can return NT_STATUS_FILE_CLOSED in error instead ofNT_STATUS_FILE_LOCK_CONFLICT; (bso#9040). - Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). - Fix build against CUPS 1.6; (bso#9055). - Fix bugs in SMB2 credit handling code; (bso#9057). - rpcclient: Fix bad call to data_blob_const; (bso#9062).- Create missing doc directories while install. - Remove no longer existing Manifest file from install. - Don't creat a link to non existend html man pages for swat. - Don't call the no longer existing libsmbclient testsuit while build.- Configure with option --mandir instead --with-mandir. - Remove obsoleted --with-rootsbindir, --with-nmbdsocketdir, and - -with-swatdir configure options.- Update to 4.0.0beta4. See WHATSNEW.txt from the samba-doc package.- BuildRequire gcc, make, and patch; (bnc#771516).- ndr: fix push/pull DATA_BLOB with NDR_NOALIGN; (bso#9026); (bnc#770262).- Fix shell syntax in dhcpcd hook script; (bnc#769957).- Add missing int declaration to the net kdc lookup patch.- Update to 4.0.0beta2. See WHATSNEW.txt from the samba-doc package.- Update to 3.6.6. + Fix possible memory leaks in the Samba master process; (bso#8970). + Fix uninitialized memory read in talloc_free(); (bnc#764577). + Fix joining of XP Pro workstations to 3.6 DCs; (bso#8373); (bnc#787983).- resolve_ads() code can return zero addresses and miss valid DC IP addresses; (bso#8910). - Can't join XP Pro workstations to 3.6.1 DC; (bso#8373); (bnc#787983). - winbind can hang as nbt_getdc() has no timeout; (bso#8953). - Fix crash bug in dns_create_probe when dns_create_update fails; (bso#8627) - s3-pid: Catch with pid filename's change when config file is not smb.conf; (bso#8714). - Possible memory leaks in the main Samba process; (bso#8970). - s3: Fix uninitialized memory read in talloc_free(); (bnc#764577). - Treat exit_server_cleanly() as a "clean" shutdown; (bso#8971). - Avoid crash with MIT krb5 1.10.0 in gss_get_name_attribute(); (bso#8988). - Winzip occasionally can not read files out of an open winzip dialog; (bso#8311). - s3-winbindd: call dump_core_setup after command line option has been parsed; (bso#8975). - Directory group write permission bit is set if unix extensions are enabled; (bso#8972). - s3: remove dependency on automake for "make everything"; (bso#8978). - sd_has_inheritable_components segfaults on an SD that se_access_check accepts; (bso#8811). - smbclient's tarmode insists on listing excluded directories; (bso#8922). - Notify code can miss a ChDir; (bso#8998). - s3:smbd: add a fsp_persistent_id() function; (bso#8995).- Call autogen.sh even on post-12.1 SUSE systems.- Don't call autogen.sh on post-12.1 SUSE and post-14 Fedora systems. - Recompile all IDL in any case.- BuildIgnore libtalloc and libtdb to prevent a package conflict on Fedora systems.- Install talloc.pc only on pre-12.2 and non SUSE systems.- BuildRequire libldb-devel, libtalloc-devel, libtdb-devel, and libtevent-devel on post-12.1 systems.- s3: Fix a segfault with debug level 3 on Solaris; (bso#8861). - s3: wbinfo --lookup-sids "" crashes winbind; (bso#8904). - smbd crashes when deleting directory and veto files are enabled; (bso#8837). - winbind_krb5_locator only returns one IP address; (bso#8897). - Wrong assertion/comparison: Compare value not pointer; (bso#8859). - Inconsistent (with manpage) command-line switch for "help" in smbtree; (bso#8831). - Fix incorrect debug statement. - Setting traverse rights fails to enable directory traversal when acl_xattr in use; (bso#8857). - Syslog broken owing to mistyping of debug_settings.syslog; (bso#8877). - s3/ldap: remove outdated netscape ds 5 schema file; (bso#8869). - s3-docs: fixes several typos; (bso#7938). - s3-VFS: Fix building out-of-tree modules; (bso#8822). - s3-docs: Add hint that setting "profile acls = yes" on normal shares can cause trouble; (bso#7930). - s3-pam_winbind: Fix the build with a newer iniparser library; (bso#8915). - Avoid null dereference in initialize_password_db(); (bso#8920). - s3:registry: implement values_need_update and subkeys_need_update in the smbconf backend. - s3:registry:reg_api: fix reg_queryvalue to not fail when values are modified while it runs. - s4:torture:rpc:spoolss: also initialize driverName before checking it in test_PrinterData_DsSpooler(). - s3:registry: multiple cleanups, fixes, and optimisations. - s3:auth/server_info: the primary rid should be in the groups rid array; (bso#8798). - s3-printing: Add new printers to registry; (bso#8554); (bso#8612); (bso#8748). - Fix the overwriting of errno before use in a DEBUG statement and use the return value from store_acl_blob_fsp rather than ignoring it; (bso#8945). - s3-auth: Don't lookup the system user in pdb; (bso#8944). - s3-passdb: Fix negative SID->uid/gid cache handling; (bso#8952). - Fix typo in pam_winbindd code; (bso#8957). - Fix remove_duplicate_addrs2 previously it could leave zero addresses in the list; (bso#8910). - Slow but responsive DC can lock up winbindd; (bso#8943). - Broken processing of %U with vfs_full_audit when force user is set; (bso#8882).- Disable included build of ldb, talloc, tdb, and tevent on post-12.1 systems. - BuildRequire libldb1-devel, libtalloc2-devel, libtdb1-devel, and libtevent0-devel on post-12.1 systems.- Add PreReq /etc/init.d/nscd to the winbind package; (bnc#759731).- docs-xml: fix default name resolve order; (bso#7564). - s3-aio-fork: Fix a segfault in vfs_aio_fork; (bso#8836). - docs: remove whitespace in example samba.ldif; (bso#8789). - s3-smbd: move print_backend_init() behind init_system_info(); (bso#8845); (bnc#730769). - s3-docs: Prepend '/' to filename argument; (bso#8826).- Update to 3.6.5. - Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; (bnc#757576).- Remove all precompiled idl output to ensure any pidl changes take effect; (bnc#757080).- Update to 3.6.4. - Samba pre-3.6.4 are affected by a vulnerability that allows remote code exe- cution as the "root" user; PIDL based autogenerated code allows overwriting beyond of allocated array; CVE-2012-1182; (bso#8815); (bnc#752797).- s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; (bso#8599). - Correctly handle DENY ACEs when privileges apply; (bso#8797).- s3:smb2_server: fix a logic error, we should sign non guest sessions; (bso8749). - Allow vfs_aio_pthread to build as a static module; (bso#8723). - s3:dbwrap_ctdb: return the number of records in db_ctdb_traverse() for persistent dbs; (#bso8527). - s3: segfault in dom_sid_compare(bso#8567). - Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER; (bso#8768). - s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path; (bso#8771). - s3-winbindd: set the can_do_validation6 also for trusted domain; (bso#8599). - Fix problem when calculating the share security mask, take priviliges into account for the connecting user; (bso#8784).- Fix crash in dcerpc_lsa_lookup_sids_noalloc() with over 1000 groups; (bso#8807); (bnc#751454).- Remove obsoleted Authors lines from spec file for post-11.2 systems.- Make ldapsmb build with Fedora 15 and 16; (bso#8783). - BuildRequire libuuid-devel for post-11.0 and other systems. - Define missing python macros for non SUSE systems. - PreReq to fillup_prereq and insserv_prereq only on SUSE systems. - Always use cifstab instead of smbfstab on non SUSE systems.- Ensure AndX offsets are increasing strictly monotonically in pre-3.4 versions; CVE-2012-0870; (bnc#747934).- Add SERVERID_UNIQUE_ID_NOT_TO_VERIFY; (bso#8760); (bnc#741854).- s3-printing: fix crash in printer_list_set_printer(); (bso#8762); (bnc#746825).- s3:winbindd fix a return code check; (bso#8406).- s3: Add rmdir operation to streams_depot; (bso#8733).- s3:smbd:smb2: fix an assignment-instead-of-check bug conn_snum_used(); (bso#8738); CVE-2013-0454; (bnc#811975).- s3:auth: fill the sids array of the info3 in wbcAuthUserInfo_to_netr_SamInfo3(); (bso#8739).- s3:client: ignore SMBecho errors (the server may not support it); (bso#8139).- Be more strict when using PAM_AUTH API from winbind if Kerberos auth is enabled and don't unintentionally use a bogus domain name; (bso#8734).- smbclient fails with posix large reads; (bso#8727).- Use the smbfs init script on versions pre-11.3, or cifs in later versions; (bnc#744614).- s3: Compile IDL files in autogen, some configure tests need this.- Fixes various deadlocks in if-up.d / if-down.d when running under systemd; (bnc#732395).- Update to 3.6.3. + Fix memory leak in parent smbd on connection; CVE-2012-0817; (bso#8724); (bnc#743986).- Use spdx.org compliant license names for all packages.- Update to 3.6.2. + Make Winbind receive user/group information (bug #8371). + Several SMB2 fixes. + Fix a crash bug in the spoolss code. + Add new contributing FAQ announcing acceptance of corporate (C). + DeletePrinterDriverEx deletes files in use; (bso#4942); (bnc#742504). + Fix cli_write_and_x() against OS/2 print shares; (bso#5326). + Fix 'smbclient tar' for files greater than 8GB on BE machines; (bso#563); (bnc#726145). + Remove pointless use_memory_krb5_ccache; (bso#7465). + Fix perl path; (bso#8176). + Grant credits in async interim responses (SMB2); (bso#8357). + Make Winbind receive user/group information; (bso#8371). + Fix Windows XP clients crashing smbd process every once in a while; (bso#8384); (bnc#731571). + Make VFS op "streaminfo" stackable; (bso#8419). + Add an allocation pool to idmap_autorid; (bso#8444). + Fix SEGFAULT from net registry export on not zero terminated REG_SZ values; (bso#8528). + Make DSO_EXPORTS_CMD more portable; (bso#8531). + readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). + smbclient posix_open command fails to return correct info on open file; (bso#8542). + winbind_samlogon_retry_loop ignores logon_parameters flags; (bso#8548). + Fix setting the machine account password; (bso#8550). + Make SMB2 handle compound request headers in the same way as Windows; (bso#8560). + Password change settings not fully observed; (bso#8561). + Fix double free error in talloc; (bso#8562). + Fix alignment in the non-extended-security negprot; (bso#8573). + Add systemd service files; (bso#8575). + Add systemd service files; (bso#8575). + smb2_flush: Don't send uninitialized memory; (bso#8579). + Enable inotify if sys or kernel inotify is available; (bso#8580). + Increase a debug level; (bso#8585). + libsmb: Only align unicode pipe_name; (bso#8586). + Fix marshalling of samr_ChangePasswordUser3; (bso#8591). + Don't limit the number of open dptrs for SMB2; (bso#8592). + Fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). + Make cldap work over IPv6; (bso#8600). + Fix intermittent print job failures caused by character conversion errors; (bso#8606). + Improve configure.in so it can be used outside the Samba source tree; (bso#8607). + Winbind: Don't fail on users without a uid; (bso#8608). + Ensure we correctly calculate reply credits over all returned SMB2 replies; (bso#8614). + Fix migrate printer code; (bso#8618). + Fix crash bug when trying to browse Samba printers; (bso#8623). + libsmb: Don't duplicate Kerberos service tickets; (bso#8628). + POSIX ACE x permission becomes rx following mapping to and from a DACL; (bso#8631). + When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636). + Fix the vfs_commit module; (bso#8639). + Add an update function for Winbind cache; (bso#8643). + vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). + Document the "ignore system acls" option of vfs_acl_xattr and vfs_acl_tdb vfs modules; (bso#8652). + Fix deleting a symlink if the symlink target is outside of the share; (bso#8663). + Fix renaming a symlink if the symlink target is outside of the share; (bso#8664). + Fix NT ACL issue; (bso#8673). + Fix buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). + Fix Winbind segfault if we can't map the last user; (bso#8678). + recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). + Try ctdbd_init_connection() as root; (bso#8684). + Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686). + Fix typo in 'net memberships' usage; (bso#8687). + libads: Fix malloc/talloc mismatch in ads_keytab_verify_ticket(); (bso#8692). + Make DeletePrinterDriverEx remove printer driver files; (bso#8697) (bnc#740810). + Fix major leak with SMB2 in connections.tdb; (bso#8710).- s3-spoolss: Pass the right pointer type; (bso#4942); (bnc#742504).- Use correct license, LGPLv3+ for libwbclient packages.- When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636).- Fix incorrect types in the full_audit VFS module. Add null terminators to audit log enums; (bnc#742885).- Prefix print$ path on driver file deletion; (bso#8697); (bnc#740810). - Fix printer_driver_files_in_use() call ordering; (bso#4942); (bnc#742504).- Buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). - NT ACL issue; (bso#8673). - Deleting a symlink fails if the symlink target is outside of the share; (bso#8663). - connections.tdb - major leak with SMB2; (bso#8710).- Renaming a symlink fails if the symlink target is outside of the share; (bso#8664).- Intermittent print job failures caused by character conversion errors; (bso#8606). - ads_keytab_verify_ticket mixes talloc allocation with malloc free; (bso#8692). - libcli/cldap: fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). - s3:lib/ctdbd_conn: try ctdbd_init_connection() as root; (bso#8684). - s3-printing: fix migrate printer code; (bso#8618). - Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686).- net memberships usage info was wrong; (bso#8687). - s3-libsmb: Don't duplicate kerberos service tickets; (bso#8628). - Recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). - s3-winbind: Fix segfault if we can't map the last user; (bso#8678). - vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). - s3/doc: document the ignore system acls option of vfs_acl_xattr and vfs_acl_tdb; (bso#8652). - Winbind can't receive any user/group information; (bso#8371). - s3-winbind: Add an update function for winbind cache; (bso#8643). - s3: Attempt to fix the vfs_commit module. - POSIX ACE x permission becomes rx following mapping to and from a DACL; (#bso#8631). - s3:libsmb: only align unicode pipe_name; (bso#8586). - s3-winbind: Don't fail on users without a uid; (bso#8608). - Crash when trying to browse samba printers; (bso#8623). - talloc: double free error; (bso#8562). - cldap doesn't work over ipv6; (bso#8600). - s3:libsmb: fix cli_write_and_x() against OS/2 print shares; (bso#5326). - SMB2: not granting credits for all requests in a compound request; (bso#8614). - smb2_flush sends uninitialized memory; (bso#8579). - Password change settings not fully observed; (bso#8561). - s3:smb2_server: grant credits in async interim responses; (bso#8357). - s3:smbd: don't limit the number of open dptrs for smb2; (bso#8592). - samr_ChangePasswordUser3 IDL incorrect; (bso#8591). - idmap_autorid does not have allocation pool; (bso#8444). - Add systemd service files. - s3:libsmb: the workgroup in the non-extended-security negprot is not aligned; (bso#8573). - s3-build: Fix inotify detection; (bso#8580). - SMB2 doesn't handle compound request headers in the same way as Windows; (#bso8560). - Disconnecting clients swamp the logs; (bso#8585). - s3-netlogon: Fix setting the machinge account password; (bso#8550). - winbind_samlogon_retry_loop ignores logon_parameters flags; (#bso8548). - smbclient posix_open command fails to return correct info on open file; (bso#8542). - readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). - s3-netapi: remove pointless use_memory_krb5_ccache; (bso#7465). - s3:Makefile: make DSO_EXPORTS_CMD more portable; (bso#8531). - s3:registry: fix the test for a REG_SZ blob possibly being a zero terminated ucs2 string; (bso#8528). - Make VFS op "streaminfo" stackable; (bso#8419).- Fix incorrect perfcount array length calculations; (bnc#739258).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems.- Remove call to suse_update_config macro for post-11.4 systems.- Use samba.org for the ldapsmb source location.- Fixing libsmbsharemode dependency on ldap and krb5 libs in Makefile; (bnc #729516).- Do not map POSIX execute permission to Windows FILE_READ_ATTRIBUTES; (bso#8631); (bnc#732572).- Add ldap to Should-Start and Stop of the smb init script; (bnc#730046).- Fix smbd srv_spoolss_replycloseprinter() segfault; (bso#8384); (bnc#731571).- Fix pam_winbind.so segfault in pam_sm_authenticate(); (bso#8564).- Fix smbclient >8GB tars on big endian machines; (bso#563); (bnc#726145).- Fix typo in net ads join output; (bnc#713135).- Ignore a potentially missing AppArmor snippet helper script; (bnc#725256).- Update to 3.6.1. + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Several SMB2 fixes. + The VFS ACL modules are no longer experimental but production-ready. + Fix 'net ads join -k' when KRB5CCNAME is not set; (bso#7465). + smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509). + Return error of cli_push when 'put - /some/file' is used; (bso#7551). + Fix usage of cli_errstr(); (bso#7864). + Fix 'widelinks' regression; (bso#8229). + Empty notify servername; (bso#8236). + Add man vfs_aio_fork; (bso#8256). + smb2: smbd logs "Invalid SMB packet: first request: 0x0008" and crashes; (bso#8334). + Add a fallback for missing open&x support in MAC OS/X Lion; (bso#8338). + While migrating forms, don't fail if the form already exists; (bso#8351). + OS/2 sends an unexpected write&x/read&x chain; (bso#8360). + Fix build of vfs_prealloc on SLES8; (bso#8363). + Fix the build of gpfs.c on RHEL 6.0 with gpfs 3.4.0-4; (bso#8364). + Fix the fallback to the deprecated spelling idmap:script; (bso#8368). + Fix vfs_chown_fsp; (bso#8370). + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix smbclient access to NT4 shares; (bso#8385). + Optimize serverid_exists() for Solaris; (bso#8395). + registry/reg_format.c must include includes.h; (bso#8401). + SMB2 server can return requests out-of-order when processing a compound request; (bso#8407). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Fix "saving as" of MS Office 2007 (Word) documents on Samba shares with SMB2; (bso#8412). + Fix 'getent group' if trusted domains are not reachable; (bso#8420). + Fix infinite loop in ACL module code; (bso#8422). + Fix wrong reply to DHnC (durable handle reconnect); (bso#8428). + Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429). + Fix segfault in iconv.c; (bso#8433). + NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442). + Be smarter about setting default permissions when a ACL_USER_OBJ isn't given; (bso#8443). + Check the wct of the incoming SMBnegprot responses; (bso#8452). + Fix smbclient segfaults when dialect option -m is used for legacy dialects; (bso#8453). + Fix uninitialized memory problem in group_sids_to_info3; (bso#8455). + Samba PDC is looking up only primary user group; (bso#8455). + IE9 on Windows 7 cannot download files to samba 3.5.11 share; (bso#8458). + smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473). + SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474). + Don't call smbd_terminate_connection in smb2_validate_message_id(); (bso#8476). + Samba asserts when SMB2 client breaks the crediting rules; (bso#8476). + Map to guest can return uninitialized blob of data; (bso#8477). + acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480). + DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493). + Remove "experimental" label on VFS ACL modules; (bso#8494). + SMB2_OP_CANCEL requests don't have to be signed; (bso#8503). + smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507). + Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509). + Disallow "." in can_set_delete_on_close(); (bso#8515). + SMB2 create call returns incorrect file allocation size; (bso#8518). + Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520). + Winbind cache timeout expiry test was reversed; (bso#8521).- s3/doc: add man page for aio_fork vfs module.- Fix uninitialized memory problem in group_sids_to_info3; (bso#8455).- s3: Samba PDC is looking up only primary user group; (bso#8455).- Add script to create or update an AppArmor sniplet with permissions for all Samba shares; (bnc#688040).- Add "ldapsam:login cache" parameter to allow explicit disabling of the login cache; (bnc#723261).- Retain the smbd startproc return value for correct startup status reporting. unset was incorrectly being called prior to rc_status; (bnc#723724).- Prevent deadlock in systemd triggered by if-down.d handler on shutdown; (bnc#721598).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; changed defaults and documentation (bso8473).- Empty CIFS share can be blocked for other clients by deleting it via empty path (DELETE_PENDING until the last client); (bso#8515).- winbindd cache timeout expiry test was reversed; (bso#8521).- Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520).- s3:smb2_create: fix allocation size return value when opening existing files; (bso#8518).- SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474).- NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442).- s3-docs: Fix bug (bso#7908) and typo.- Return error of cli_push when 'put - /some/file' is used; (bso#7551).- Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509).- smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507).- Default user entry is set to minimal permissions on incoming ACL change with no user specified; (bso#8443).- smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509).- Handle the SECINFO_LABEL flag in the same was as Win2k3; enable Microsoft Internet Explorer 9 on Windows 7 to download files; (bso#8458).- DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493).- s3-docs: Fix typos.- s3:smb2_server: SMB2_OP_CANCEL requests don't have to be signed; (bso#8503).- Remove "experimental" label on VFS ACL modules; (bso#8494).- acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480).- s3-smbd: asserts when SMB2 client breaks the crediting rules; (bso#8476).- s3-libnet: allow to use default krb5 ccache in libnet_Join/libnet_Unjoin; (bso#7465).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473).- s3-netapi: allow to use default krb5 credential cache for libnetapi users.- s3-docs: document -k switch in net manpage.- Map to guest can return uninitialized blob of data; (bso#8477).- s3-registry: registry/reg_format.c must include includes.h; (bso#8401).- smbclient segfaults when option -m is used for legacy dialects; (bso#8453).- Fix 'widelinks' regression intro'd in 3.2; (bso#8229).- Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429).- s3-spoolss: Fix bug forms migration; (bso#8351).- s3:libsmb: check the wct of the incoming SMBnegprot responses; (bso#8452).- s3: Do not fork the echo handler for smb2; (bso#8334).- s3-spoolss: Fix bug empty notify servername; (bso#8236).- SMB2 server can return requests out-of-order when processing a compound request; (bso#8407).- Remove smb child crash fix. The issue had been fixed upstream differently.- BuildRequire ctdb-devel version greater than 1.0.105 for post-10.0 systems.- Fix samba duplicates file content on appending. Move posix case semantics out from under the VFS; (bso#6898); (bnc#681208).- Make winbind child reconnect when remote end has closed, fix failing sudo; (bso#7295); (bnc#569721).- Spec file cleanup as suggested by the spec-cleaner tool. + Make all BuildRequires, PreReq, and Provides a separate line. + Use %{buildroot} instead of ${RPM_BUILD_ROOT}. + Use straight commands instead of macros (make, install). + Use -p in post and postun if we only call one command. + Use %{_localstatedir} instead of %{_var} in the filelist. + Remove superfluous AutoReqProv on lines.- Remove %release from all Provides.- Fix segfault in iconv.c which caused a null pointer dereference; (bso#8433).- Use /var/run for the cifs state file in the init script too; (bnc#710304).- Microsoft Word from Microsoft Office 2007 fails to save as on a share with SMB2; (bso#8412).- Use sys_write and sys_read in fork_domain_child to fix a winbind race leading to 100% CPU usage; (bso#8409).- Fix wrong reply to smb2 durable handle reconnect (DHnC) request; (bso#8428).- Fix infinite loop in ACL module code; (bso#8422).- Fix getent group if trusted domains are not reachable; (bso#8420).- smbclient can't access a NT4 share since 3.6.0; (bso#8385).- Optimize serverid_exists() for Solaris; (bso#8395).- talloc: + check block count after references test. + added test suite for talloc_free_children(). + license info erratum in the manpage. + fix typos and better differentiation between versions 1 and 2. + preserve context name on talloc_free_children(). + ensure the sibling linked list remains valid during a free.- vfs_chown_fsp returned in the wrong directory; (bso#8370).- Remove irritating "." targets when recent system libs exist; (bso#8369).- Correctly initialize "idmap config * : script" with NULL; (bso#8368).- Add missing include to suppress compiler warnings; (bso#8365).- Point the chain offset beyond the current request; (bso#8360).- Fix gpfs vfs module build; (bso#8364).- Make vfs_prealloc even build on older systems; (bso#8363).- Do central cli_set_error and return the actual NTSTATUS; (bso#7864).- Add a fallback for missing open&x support in OS/X Lion; (bso#8338).- Update to 3.6.0. + BUG 7462: Make SA_RESETHAND conditional on its existance. + BUG 8303: db_ctdb_send_schedule_for_deletion() is not defined. + BUG 8324: smbclient cannot list directories from a big-endian machine. + BUG 8326: WinXP cannot join a Samba3 domain with a 'even' hostname. + BUG 8327: Fix the reload of the configuration, also reload activated registry shares. + BUG 8328: Cleanup of idmap_tdb2 code. + BUG 8330: Fix NFSv4 ACL merging logic. + BUG 8335: File copy aborts with smb2_validate_message_id: bad message_id. + BUG 8341: Fix segfault in libsmbclient. + BUG 8343: Fix SMB2 crash reading with aio_fork beyond the end of file. + BUG 8347: Fix regression for HP-UX, AIX and OSF. + BUG 8357: Make sure we grant credits on async read/write operations. + BUG 8358: Fix a bug in run_poll_events(). + BUG 8362: Fix build issue on old glibc systems.- Remove references to disabled vscan build.- Add missing define, includes, and initialization to get_printing_ticket.- Use /var/run for the cifs state file; (bnc#710304).- Fix #ifdef CTDB_CONTROL_SCHEDULE_FOR_DELETION issue; (bso#8303).- File copy aborts with smb2_validate_message_id: bad message_id; (bso#8335).- Fix reload of the configuration and also reload activated registry shares; (bso#8327).- WinXP cannot join a Samba3 domain with a 'even' hostname; (bso#8326).- smbclient cannot list directories from a big-endian machine; (bso#8324).- Update to 3.6.0rc3. + BUG 7841: Explicitly pass domain_sid to wbint_LookupRids(). + BUG 7888: Deal with buggy 3.0 based PDCs. + BUG 8083: Fix "inherit owner = yes" with vfs_acl_xattr or vfs_acl_tdb module. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8193: Add new command 'enumerate_recursive'. + BUG 8195: Make rpc client code working against NT4 servers. + BUG 8211: Fix "inherit owner = yes" when "inherit permissions = yes" is set. + BUG 8213: Fixes in idmap_autorid. + BUG 8214: Fix smbd crash on printer driver upgrade. + BUG 8215: Fix Winbind unix username lookup. + BUG 8216: Make Winbind returning correct results with 'sids2xids'. + BUG 8217: Do not stat-check the share path in 'net conf addshare'. + BUG 8219: Fix SMB Panic from Windows 7 client. + BUG 8224: Fix the build on FreeBSD. + BUG 8226: Use c99 initializers which are supported by old gcc 2.95 compilers. + BUG 8230: Move .nmbd socket directory to non-hidden name PREFIX/var/nmbd. + BUG 8231: Fix crash bug in 'net cache get'. + BUG 8235: Fix smbd crash on startup caused by migrate_printer(). + BUG 8240: Fix Valgrind warnings in winreg/spoolss code. + BUG 8244: Fix copying files larger than 2 GB to a Samba share. + BUG 8247: Fix Coverity ID 2582: FORWARD_NULL. + BUG 8253: Fix Winbind panic if verify_idpool() fails. + BUG 8254: Fix "acl check permissions = no". + BUG 8260: Fix DCERPC responses with fragments larger than 1024 bytes. + BUG 8262: Fix build of vfs_commit. + BUG 8263: Fix build with --with-fake-kaserver or --with-vfs-afsacl. + BUG 8264: Fix Valgrind bugs in svcctl. + BUG 8276: Close all sockets attached to a subnet in close_subnet(). + BUG 8278: Fix smbd panic when CTDB is unhealthy. + BUG 8281: Fix build of examples/VFS/*. + BUG 8286: Fix smbd crash on premature end of smb2 conn. + BUG 8292: Fix a major architectural flaw in the SMB2 server code. + BUG 8293: Fix log file rotating in SMB2. + BUG 8304: Fix uninitialized variable in error path. + BUG 8305: Fix segfault in nmbd when using 'smbtree ...'.. + BUG 8307: brl_close_fnum does not call SMB_VFS_BRL_UNLOCK_WINDOWS on all locks. + BUG 8310: toupper_ascii() is broken on big-endian systems. + BUG 8314: Fix smbd crash with unknown user. + Mark 'time offset' parameter as deprecated.- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site scripting vulnerability; CVE-2011-2694; (bso#8289); (bnc#708503).- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site request forgery; CVE-2011-2522; (bso#8290); (bnc#705241).- Fixed the DFS referral response for msdfs root; (bnc#703655).- Fix CUPS print job IDs; (bso#7288); (bnc#701257).- Make use of the actual library version as part of the package name on post-11.3 systems only.- Fix winbind internal error; (bso#7636); (bnc#659424).- Improve ctdb vacuuming performance with use of SCHEDULE_FOR_DELETION; (bnc#705170).- Specify nmbdsocketdir at configure time; (bnc#700953).- Build the tdb, talloc, and tevent libraries ahead of anything else.- Update to 3.6.0rc2. + BUG 6911: Fix Kerberos authentication from Vista to Samba. + BUG 8166: Don't lockout users when offline. + BUG 8200: Add support for multiple writeable ldap idmap domains. + BUG 8148: Default to protocol version 2 for SMB Traffic Analyzer. + BUG 7054: Fix X account flag when "pwdlastset" is "0". + BUG 8144: Fix setting timestamp when touching files with CIFS clients. + BUG 8153: Fix setting up getaddrinfo on IPv6-only machines. + BUG 8156: Fix 'net ads join' using the user's Kerberos ticket. + BUG 8157: Fix parsing a cups printcap file. + BUG 8175: Fix smbd deadlock. + BUG 8189: Support shadow copy display over SMB2. + BUG 8197: Winbind does not properly detect when a DC connection is dead. + BUG 8203: Winbind needs to reset the DC connection if an RPC times out.- Make cupsaddsmb fill printers location; (bso#8132); (bnc#698209).- Add "winbind max clients" parameter to remove 200-client limit; (bnc#697461).- Disable logon cache for password lockout consistency when running in a cluster; (bnc#694836).- Fix logon of AD users with many group memberships; (bso#6911); (bnc#657026).- Don't lockout users while offline; (bso#8166); (bnc#692607).- Update to 3.6.0rc1. + BUG 8111: CIFS VFS: Fix unexpected error on SMB posix open. + BUG 8112: POSIX extension opens of a directory are denied with EISDIR. + BUG 8132: Fix filling printers location field when using cups. + Remove fstrings from client struct. + BUGFIX when converting from safe_strcpy to strlcpy. + Fix off-by-one calculations with strlcpy. + Ensure we always write the correct incoming mid into the share mode table entries. + Fix the SMB2 oplock showstopper. + Convert user-specified domain to uppercase in libsmb. + Fix Coverity CID #2302: FORWARD_NULL. + Fix cups_pull_comment_location(). + Fix double free of cups request. + Make cups_pull_comment_location() work again. + Fix potential crash bug in display_print_driver3(). + Properly clean up in pthreadpool_init in case of failure. + Make plaintext session setup async. + Reduce fd load in Winbind children. + Avoid a potential 100% CPU loop in Winbind. + Tune broadcast namequeries for unique names. + Properly deal with exited winbind children. + Fix dup_smb2_vec3. + Fix return check in nss_wins.- Fix to renew the kerberos ticket in samba after expiry; (bnc#669949).- Fix a 100% CPU loop when ctdbd dies during a traverse; (bnc#693945).- Make dhcpcd hook BOOTPROTO check cover dhcp6 too; (bnc#691969).- Handling of large (> 256 bytes) ntlmv2 blobs in winbind; (bnc#529946).- Package static libraries with 0644 permissions.- Add Requires libtalloc-devel to libldb-devel and libtevent-devel.- Rename libldb0 to libldb1 as 1 is the current major version of the library. - Add libldb1 and libtevent0 to baselibs.conf.- Don't call the suse_update_config macro before building lib ldb and tevent.- Update to 3.6.0pre3. + Listen on IPv6 addresses with IPV6_ONLY; (bso#7383). + Fix wrong output in 'smbget'; (bso#8066). + "inherit owner = yes" doesn't interact correctly with vfs_acl_xattr or vfs_acl_tdb module; (bso#8083). + rpccli_samr_chng_pswd_auth_crap segfaults if any input blobs are null; (bso#8088). + setpwent() actually does endpwent() and vice versa on FreeBSD; (bso#8099). + Fix the build of 'smbget' on HP NonStop; (bso#8106). + Fix build of tdb2. + Correctly detect and deny symlinks anywhere in a path (not just the last component) if "follow symlinks = no". + Fix timeout in rpc_pipe_open_tcp_port(). + Fix the build of "--with-profiling-data". + Fix Coverity IDs 986, 1340, 2047, 2299, 2307, 2325, 2335, 2336, 2470, 2471, 2478. + nsswitch: Add 'wbinfo --lookup-sids'. + nsswitch: Add 'wbinfo --sids-to-unix-ids'. + Fix smbd with the async echo responder. + Fix the build of vfs_gpfs.c. + Add a 10-second timeout for the 445 or netbios connection to a DC. + Many pthreadpool fixes. + Fix transaction recovery area for converted tdbs.- Add PreReq permissions to the krb-printing package.- Remove _libdir ldb and tevent from file list. - Explicitly state not to bundle talloc or tdb while ldb and tevent build.- Always use the actual library version as part of the package name. - Exclude shared python modules.- Fix printing from Windows 7 clients; (bso#7567); (bnc#687535).- Update pidl and always compile IDL at build time; (bnc#688810).- Update to 3.6.0pre2. + ID Mapping changes. + Implement SMB2 support. + Add an Endpoint Mapper daemon. + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Quota only shown when logged as root; (bso#7080). + Fix printing from Windows 7; (bso#7567). + Retry DNS updates when connection to one nameserver has failed; (bso#7690). + Unlink may unlink wrong file when hardlinks are involved; (bso#7863). + Fix 'nmbd --port'; (bso#7875). + cmd_spoolss_deletedriver() returned without checking all architectures; (bso#7880). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix cups pcap reload with no printers; (bso#7915). + Fix bug in chain_reply; (bso#7917). + Fix problems with "kernel oplocks" option set to "no"; (bso#7928). + Fall back for utimes calls; (bso#7940). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let winbind try to use samlogon validation level 6; (bso#7945). + Sgid bit lost on folder rename; (bso#7996). + Fix getting username in 'net rap session'; (bso#8009). + Fix inode generation so nautilus can count total dir size correctly; (bso#8010). + Use jenkins hash for str_checksum; (bso#8010). + Add explicit configure option whether or not to enable dmapi support; (bso#8033). + Fix smbclient segfault with Cyrillic netbios names; (bso#8040). + Fix file creation on OS/X; (bso#8042). + Add "--option" to 'testparm'. + Fix crash bug on smbd shutdown when using FOPENDIR(). + Ensure we don't return an incorrect access mask. + Fix bug against the new Mac client. + Fix leak in error path. + Fix error where Windows client spoolss returns WERR_INVALID_DATA. + Fix a segfault in the krb5 locator plugin. + Enable sharesec for registry shares. + Fix memory leak in "security=share" and "force user". + Add "net idmap check", a check and repair tool for the id mapping database. + Add new 'net idmap delete' command. + Fix segfault on missing input file in 'net idmap restore'. + Fix 'net usersidlist' not to skip every other user. + Fix potential crash bug in spoolss_PrinterEnumValues push path. + Internal restructuring. + Don't wipe out all printer drivers when only one should be deleted. + Fix winbindd_dual_pam_auth_samlogon() for NT4 domains. + Fix memory leak in print_cups.c. + Remove duplicate cups response processing code. + Follow force user/group for driver IO. + Initiate pcap reload from parent smbd. + Reload shares after pcap cache fill. + Fix numerous Coverity IDs (2041 and others). + Fix a memory leak in check_sam_security_info3. + Fix a segfault in the nss wrapper when libnss_winbind.so is not loadable. + Make "net sam list [users|workstations]" list only the right things. + Fix a potential memleak in secrets_fetch_trusted_domain_password. + Use the right credentials in check_netlogond_security. + Add support for AF_NETLINK addr notifications. + Fork multiple Winbind children per domain. + Fix a deadlock between smbd and ctdbd. + Add 'wbinfo --dc-info'. + Make "nmbd socket dir" configurable. + Fixed valgrind errors. + Fix a memleak in receive_getdc_response. + Don't grant SEC_STD_DELETE always to the owner of a file. + Fix segfaults on addrchange errors in Winbind. + Allow machine accounts as members in groupdb. + Add IPv6 support for the endpoint mapper. + Free unused memory in the rpc server. + Fix possible segfaults in svcctl server. + Fix possible segfault with client_id in rpc server. + Add a 'svcctl shutdown' function to rpc server. + Fix a resource leak in net_afs. + Fix a resource leak in smbta-util. + Fix possible resource leak in net_usershare. + Fix possible resource leak in 'smbget'. + Fix possible resource leak in 'smbfilter'. + Fix a possible null pointer dereference in smbd. + Ensure we send the direct levelII oplock break to the correct fid. + Fix private libdir and codepages paths. - Add RFC 3454 to the vendor files.- Fix idmap_tdb for big-endian systems such as ppc and s390; (bso#6901); (bnc#675978).- Fix smbclient -M NT_STATUS_PIPE_BROKEN failure; (bso#7635); (bnc#681913).- Replace jobs by _smp_mflags macro while calling make on post-11.4 systems.- Don't crash when publishing a single printer; (bnc#643119).- Carry error status in printer list IPC message, do not refresh printers if cups is unavailable; (bso#7994); (bnc#675478).- Define the libwbclient packages ahead of packages with a different version.- Use %_smp_mflags for parallel building.- Update to 3.5.8. + Fix Winbind crash bug when no DC is available; (bso#7730). + Fix finding users on domain members; (bso#7743). + Fix memory leaks in Winbind; (bso#7879). + Fix printing with Windows 7 clients; (bso#7567). + Fix 'testparm' return code when EOF in encountered in param name; (bso#3185). + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Fix "Your Password expires today" message for users of trusted domains; (bso#7066). + Fix maintaining of users' groups via UsrMgr; (bso#7262). + Fix 'net ads dns register' in Windows 2008 R2 domains; (bso#7356). + Raise debug level for "reduce_name: couldn't get realpath" messages; (bso#7409). + Fix updating the time on close in vfs_gpfs; (bso#7498). + Fix "log=>ndr_pull_error" in 'wbinfo -u' and 'wbinfo -g'; (bso#7594). + Handle Windows 9x adddriver calls without config file; (bso#7641). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix memory leak in the netapi routines; (bso#7665). + Store unmodified copies of security descriptors in acl_xattr and acl_tdb modules; (bso#7716). + Fix incorrect unix mode_t caused by invalid client DOS attributes on create; (bso#7733). + Apply appropriate create masks when creating files with "inherit ACLs" set to true; (bso#7734). + Fix "dfree cache time" parameter; (bso#7744). + Fix a getgrent crash with many groups; (bso#7774). + Fix requesting lookups for BUILTIN sids; (bso#7777). + Fix smbd crash caused by expand_msdfs; (bso#7779). + Fix atime limit; (bso#7785). + vfs_scannedonly: Switch from mtime to ctime which is more reliable; (bso#7789). + Fix copying files from a SMB share using Gnome vfs and SMB signing; (bso#7791). + Make Winbind recover from a signing error; (bso#7800). + ACL inheritance cannot be disabled in vfs_acl_xattr/vfs_acl_tdb; (bso#7812). + Fix "force group" with ntlmssp guest session setup; (bso#7817). + vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835). + Make WINBINDD_LOOKUPRIDS asking the right domain; (bso#7841). + Make WINBINDD_LOOKUPRIDS returning the domain name; (bso#7842). + Expand the local SAMs aliases; (bso#7843). + ntlm_auth: Support clients which offer a spnego mechs we don't support; (bso#7855). + Fix 'net ads dns register' in cluster setups; (bso#7871). + Fix 'nmbd --port'; (bso#7875). + Make 'rpcclient deldriver' delete drivers for all architectures; (bso#7880). + Fix flaky Winbind against Windows 2008; (bso#7881). + Fix SMB session setups with Kerberos against some closed source SMB servers; (bso#7883). + Fix stale lock in open_file_fchmod(); (bso#7892). + Fix sporadic Winbind panic in rpc query_user_list; (bso#7894). + Don't set SAMR_FIELD_FULL_NAME if we just want to set the account name; (bso#7896). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix connections from WinCE; (bso#7917). + Fix opening MS Powerpoint files; (bso#7940). + Fix endless loops caused by inotify; (bso#7942). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let Winbind try to use samlogon validation level 6; (bso#7945). + Revalidate the pathname once re-constructed from a root fsp; (bso#7950).- Require a particular library version even if the major version is part of the package name. Using the same major version does not guarantee forward compatibility.- Fix a fd-leak in libwbclient at dlclose-time; (bso#7684); (bnc#668773).- Update to 3.5.7 + Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Disable separate build of samba-doc for post-11.1 systems.- Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Increase the log level for missing PIDs on SIGCHLD, printcap child processes are not added to the children PID list; (bnc#666460).- Do not require a particular library version if the major version is part of the package name.- Use the actual version numbers of the ldb, talloc, tdb, and tevent libraries on post-11.3 systems.- Abide by print$ share 'force user' & 'force group' settings when handling AddprinterDriver and DeletePrinterDriver requests; (bso#7921); (bnc#653353).- Remove pcap_cache_loaded asserts from (re)load_printers. pcap_cache_loaded() returns false if the pcap cache contains no printer entries. correct call ordering is already enforced. (bso#7836); (bnc#625936).- No longer force activation of the cifs service on post-11.3 systems. - Add X-UnitedLinux-Default-Enabled to the cifs init script on pre-11.4 systems. - Move the cifs init script nfs dependencies from Required to Should.- Recommend to install samba-krb-printing from samba-winbind on post-10.3 systems; (bnc#661845).- Fix error paths in cups_async_callback(), an empty cups printer list should not be treated as an error; (bnc#661842).- Abide by printcap cache time, reload parent smbd pcap cache on expiry; (bso#7836); (bnc#625936).- Fix race in cups async printer services reload; (bso#7836); (bnc#625936).- Don't tweak with baselibs.conf during %post if not present; (bnc#652620).- Don't make use of baselibs.conf on SUSE Linux Enterprise 10; (bnc#652620).- Don't use --tmpdir as this option isn't known by mktemp of SUSE Linux Enterprise 10; (bnc#652620).- vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835).- Replace Requires samba-client by samba-gplv3-client in the gplv3 packages; (bnc#652620).- Fix Dolphin SMB share IO with SMB signing enabled; (bso#7791); (bnc#656112).- Add Conflicts to the samba-gplv3 main, client, doc, krb-printing, winbind, client-gplv2, and doc-gplv2 packages; (bnc#652620).- Add Provides samba-client-gplv2 and samba-doc-gplv2 to pre-3.2 versions; (bnc#652620).- Obsolete samba-client-gplv2 and samba-doc-gplv2; (bnc#652620).- Remove Provides samba-client:/usr/sbin/winbindd from the samba-gplv3-winbind package to avoide an accidental install trigger; (bnc#652620).- Add Provides samba-client to the samba-gplv3-client package; (bnc#652620).- Remove all Obsoletes from the samba-gplv3 packages and only keep the Provides samba; (bnc#652620).- Add fitting Conflicts to all samba-gplv3 packages; (bnc#652620).- Reduce unnecessary ldap round trips and eliminate invalid DN messages; (bnc#654719).- Exclude cifs-mount and ldapsmb from the samba-gplv3 build of SUSE Linux Enterprise 10 SP 3 and 4.- Add the _build_arch at the end of the vendor version suffix.- Provide and Obsolete samba-gplv3 to replace potentially installed packages.- Change package base name to samba-gplv3 for SUSE Linux Enterprise 10 SP 4. - Do not package libsmbclient and libsmbsharemodes.- Update to 3.5.6 + Fix auto printers with registry config; (bso#7280); (bnc#617153). + Fix SPNEGO auth when contacting Win7 system using Microsoft Live Sign-in Assistant; (bso#7577). + Fix 'net idmap restore' setting HWM to avoid duplicates; (bso#7578). + Fix "admin users" when using vfs_acl_xattr; (bso#7581). + Fix using cached credentials in ntlm_auth; (bso#7589). + Fix Winbind offline login; (bso#7590). + Fix Winbind internal error; (bso#7636). + Fix mknod/mkfifo failing with "No such file or directory"; (bso#7651). + Fix smbd changing mode of files on rename; (bso#7693). + Fix crash bug with invalid SPNEGO token; (bso#7694). + Fix smbd panic on invalid NetBIOS session request; (bso#7698). + Fix smbd crash caused by "%D" in "printer admin"; (bso#7541). + Fix 'smbclient -M'; (bso#7635). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix crash bug in rpcclient; (bso#7688). + Fix file corruption when setting Samba "write wache wize"; (bso#7715).- Let startproc wait for nmb, smb and winbind pid files getting created on post-11.1 systems; (bnc#520036).- Include the reviewed french translation for pam_winbind; (bnc#499233).- Fix smbd crash with CUPS printers and no [printers] share defined; (bso#7297); (bnc#637755).- Fix printing from 64-bit windows clients; (bso#6888); (bnc#640870).- Fix baselibs.conf for libtalloc.- Fix buffer overflow in sid_parse() to correctly check the input lengths when reading a binary representation of a Windows Security ID (SID); CVE-2010-3069; (bso#7669); (bnc#637218).- Use cached ntlm password in libsmbclient. Prevent lockouts when kerberos tickets are lost; (bnc#602418); (bnc#606304).- Add a dependency on nfs to the smbfs/ cifs init scripts as they require the en_US locale and /usr might be on NFS.- Complete fix for trusts with Windows 2008R2 DCs.- Fix authentication dialogs when connecting to older systems; (bnc#632055).- Adjust position of conditional ldapsmb %package and %files definition.- Create the /var/run/samba directory on the fly and package it as %ghost.- Fix preexec scripts; (bso#7104); (bnc#632852).- Add missing netapi, smbclient, smbsharemodes, talloc, tevent, and wbclient pkgconfig files and BuildRequire pkgconfig; (bnc#632770).- BuildRequire python-devel for post-9.3 systems.- Only create precompiled headers for post-10.2 systems. - Remove mkinitrd scriptlets.- Add vfs_crossrename man page. - Call make basic and remove conditional proto target. - Increase libtevent version to 0.9.9. - Remove wbc_async header from the file list. - Remove remaining cifs-mount pieces from the spec file.- Fix printers not auto loading with registry config; (bso#7280); (bnc#617153).- Update to 3.6.0pre1. + SMB2 support is fully functional despite managing quota using the Microsoft management tools. + Internal Winbind passdb changes to use samr and lsa rpc pipe to get local user and group information. + The spoolss and the old RAP printing code have been completely overhauled and refactored. + The SMB Traffic Analyzer (SMBTA) VFS module got added.- Intilize workgroup of nmblookup as empty string.- Fix net ads join when using parent domain users; (bso#6364); (bnc#630812).- cifs: do not restart during dhcp lease renewal when IPaddress remains the same; (bnc#573246).- Fix "Too many open files" when trying to access large number of files; (bso#6837); (bnc#619787).- Update to 3.5.4. + Fix smbd crash when sambaLMPassword and sambaNTPassword entries missing from ldap (bug #7448). + Fix init_sam_from_ldap storing group in sid2uid cache (bug #7507). + Allow previous password to be stored and use it to check tickets; (bso#7099). + Make ea data checks identical for trans2open and trans2mkdir; (bso#7188). + Fix editing users' groups via UsrMgr; (bso#7262). + Fix Winbind over IPv6; (bso#7341). + Samba sends "raw" inode number as uniqueid with unix extensions; (bso#7410). + Fix printing large formats; (bso#7423). + Fix spnego returning incorrect mechListMIC string; (bso#7449). + Fix some crash bugs and missing error codes in AddDriver paths; (bso#7459). + Fix crash bug in _samr_QueryUserInfo{2} level 18; (bso#7479). + Fix 'not a string literal' warning in netdomjoin-gui; (bso#7500). + Fix calculation of st_blocks in vfs_streams_xattr; (bso#7503). + Fix numerous build issues; (bso#7504). + Fix session setup from linux kernel cifs clients with "sec=ntlmv2"; (bso#7517).- Remove all provides and obsoletes samba3 from the spec file. Packages with this base name have not been offered as part of a product.- Fix a NULL pointer dereference in smbd of the 3.4 code base; CVE-2010-1635; (bso#7229); (bnc#605935).- Address possible buffer overrun in chain_reply code of pre-3.4 versions; CVE-2010-2063; (bso#7494); (bnc#611927).- Update of the SMB Traffic Analyzer v2 VFS module- Fix trusts with Windows 2008R2 DCs; (bnc#613459); (bnc#599873); (bnc#592198); (bso#6697).- Update to 3.5.3. + Fix MS-DFS functionality; (bso#7339). + Fix a Winbind crash when scanning trusts; (bso#7389). + Fix problems with SIGCHLD handling in Winbind; (bso#7317). + Add replacement for IPV6_V6ONLY on linux systems with broken headers; (bso#7196). + Fix cups encryption setting; (bso#7263). + Fix exporting printers via 'cupsaddsmb' command; (bso#7277). + Fix SMB job IDs in CUPS job names; (bso#7288). + Fix segfault in mount.cifs; (bso#7315). + Make TIME_T_MAX defines consistent; (bso#7352). + Re-fix a bug with smbd serving a windows terminal server; (bso#7357). + Display an error on 'net conf import' failures; (bso#7378). + Fix bitmap leak in dptr_Close; (bso#7384). + Fix rename problems with full_audit VFS module; (bso#7398). + Fix setting of passwords via 'net rpc user password' command; (bso#7417). + Fix 'net rpc printer list' command; (bso#7418). + Rename mod_name to module_name; (bso#7421). - Fix unnecessary traversing winbindd_cache.tdb in SIGHUP handler. - Added EN ISO 216, A0 and A1 to builtin forms; (bso#7423). - Winbind not working over IPv6; (bso#7341).- Honor "interfaces" list in net ad dns register; (bnc#606947).- Exclude the RPM release from the vendor tag for openSUSE Factory; (bnc#604049).- Enable the build of the idmap tdb2 module; (bnc#600822).- BuildRequire keyutils-libs-devel for Fedora and post-RHEL4.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- Add "net conf import" error messages; (bso#7378, bnc#598189).- Define cups_lib_dir %{_prefix}/lib/cups for post-11.2 systems; (bnc#575544).- Update to 3.5.2. + Fix smbd segfaults in _netr_SamLogon for clients sending null domain; (bso#7237). + Fix smbd segfaults in "waiting for connections" message; (bso#7251). + Fix an uninitialized variable read in smbd; (bso#7254); (bnc#605935); CVE-2010-1642. + Fix a memleak in Winbind; (bso#7278). + Fix Winbind reconnection to it's own domain; (bso#7295). + Fix segfault if hide files or veto files has no ".AppleDouble"; (bso#1206). + Fix parsing of the gecos field; (bso#5198). + Fix several printing issues; (bso#6727). + Fix valgrind warning; (bso#6814). + Fix race condition in mount.cifs that allows user to replace mountpoint with a symlink; (bso#6853). + Fix bug in vfs_scannedonly rmdir implementation; (bso#7075). + Fix handling of bad server data returns in client rpc_transport; (bso#7159). + Never mark external domains as internal in Winbind; (bso#7170). + Fix access by multi-threaded applications; (bso#7202). + Fix 'net share' command; (bso#7203). + Fix DN parsing name was always null; (bso#7204). + Signals are processed twice in child; (bso#7206). + Fix returning of group members with 'getent group'; (bso#7212). + Fix the build of net_afs.c with --fake-kaserver=yes; (bso#7216). + Make Winbind logs more verbose for troubleshooting; (bso#7225). + Fix a NULL pointer dereference in smbd; CVE-2010-1635; (bso#7229); (bnc#605935). + Fix automatic building of vfs_tsmsm if gpfs and dmapi are present; (bso#7231). + Fix race conditions in CTDB persistent transactions; (bso#7232). + Symlink delete fails but incorrectly reports success to client; (bso#7234). + Fix "printer admin" functionality; (bso#7255). + Fix value-needed calculation in_spoolss_EnumPrinterData(); (bso#7256). + Fix _winreg_QueryValue crash bugs and implement Windows behavior; (bso#7258). + Fix job management commands for CUPS queues; (bso#7269). + Fix smbd segfault if using vfs_acl_tdb; (bso#7283). + Fix core dump in 'ntlm_auth' with "gss-spnego" helper; (bso#7290). + Fix smbd crashes with CUPS printers and no [printers] share defined; (bso#7297). + Fix DOS attribute inconsistency with MS Office; (bso#7310). + Many disconnecting clients render clustered Samba unusuable for some time; (bso#7312). + Make 'net conf addshare' atomic; (bso#7313). + Eliminate race condition in creating/scanning sorted subkeys in the registry backend; (bso#7314). + Winbind possibly segfaults when trying a trusted domain without inbound trust; (bso#7316).- Add SMB Traffic Analyzer v2 VFS module.- Document "wide links" defaults to "no" in the smb.conf man page for versions pre-3.4.6; (bnc#577868).- Fix workgroup enumeration, for client printer and file share selection; (bso#6880); (bnc#586215).- Fix tdb validation for offline auth; (bnc#587014).- Fix "printer admin" functionality; (bso#7255).- An uninitialized variable read could cause an smbd crash; (bso#7254); (bnc#605935); CVE-2010-1642.- Ensure to have a valid talloc stackframe; (bso#7251).- _netr_SamLogon segfaults for clients sending NULL domain; (bso#7237).- Merge missing pam_winbind message translations; (bnc#499233).- Remove cifs-mount subpackage for post-11.2 systems as the tools are now part of the independent cifs-utils package.- Fix join of Windows 2008 domains; (bnc#567013).- Update to 3.5.1 and 3.4.7. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222); (bnc#586683).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; CVE-2010-0926; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7; (bnc#619787). + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7; (bnc#619787). + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7; (bnc#619787). + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build.obs-power8-03 1542067422  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEF4.7.10+git.124.8d97fe90926-lp150.3.9.14.7.10+git.124.8d97fe90926-lp150.3.9.1     samba__init__.py_glue.so_ldb.soauth.socommon.pycompat.pycredentials.socrypto.sodbchecker.pydcerpc__init__.pyatsvc.soauth.sobase.sodcerpc.sodfs.sodns.sodnsp.sodnsserver.sodrsblobs.sodrsuapi.soecho.soepmapper.soidmap.soinitshutdown.soirpc.sokrb5pac.solsa.somessaging.somgmt.somisc.sonbt.sonetlogon.sontlmssp.sosamr.sosecurity.soserver_id.sosmb_acl.sosrvsvc.sosvcctl.sounixinfo.sowinbind.sowinreg.sowkssvc.soxattr.sodckeytab.sodescriptor.pydnsserver.pydrs_utils.pydsdb.sodsdb_dns.sogensec.sogetopt.pyhostconfig.pyidmap.pyjoin.pykcc__init__.pydebug.pygraph.pygraph_utils.pykcc_utils.pyldif_import_export.pymessaging.soms_display_specifiers.pyms_schema.pyndr.pynet.sonetbios.sonetcmd__init__.pycommon.pydbcheck.pydelegation.pydns.pydomain.pydrs.pydsacl.pyfsmo.pygpo.pygroup.pyldapcmp.pymain.pynettime.pyntacl.pyprocesses.pyrodc.pysites.pyspn.pytestparm.pyuser.pyntacls.pyntstatus.soparam.sopolicy.soposix_eadb.soprovision__init__.pybackend.pycommon.pykerberos.pykerberos_implementation.pysambadns.pyregistry.soremove_dc.pysamba3__init__.pylibsmb_samba_internal.soparam.sopassdb.sosmbd.sosamdb.pyschema.pysd_utils.pysecurity.sosites.pysmb.sosubnets.pysubunit__init__.pyrun.pytdb_util.pytests__init__.pyauth.pyauth_log.pyauth_log_base.pyauth_log_ncalrpc.pyauth_log_netlogon.pyauth_log_netlogon_bad_creds.pyauth_log_pass_change.pyauth_log_samlogon.pyblackbox__init__.pyndrdump.pysamba_dnsupdate.pycommon.pycore.pycredentials.pydcerpc__init__.pyarray.pybare.pydnsserver.pyinteger.pymisc.pyraw_protocol.pyraw_testcase.pyregistry.pyrpc_talloc.pyrpcecho.pysam.pysrvsvc.pystring.pytestrpc.pyunix.pydns.pydns_base.pydns_forwarder.pydns_forwarder_helpersserver.pydns_tkey.pydns_wildcard.pydocs.pydsdb.pydsdb_schema_attributes.pygensec.pyget_opt.pyglue.pyhostconfig.pyjoin.pykcc__init__.pygraph.pygraph_utils.pykcc_utils.pyldif_import_export.pylibsmb_samba_internal.pylsa_string.pymessaging.pynet_join.pynet_join_no_spnego.pynetcmd.pynetlogonsvc.pyntacls.pyntlmauth.pypam_winbind.pyparam.pypassword_hash.pypassword_hash_fl2003.pypassword_hash_fl2008.pypassword_hash_gpgme.pypassword_hash_ldap.pypolicy.pyposixacl.pyprovision.pypy_credentials.pyregistry.pysamba3.pysamba3sam.pysamba_tool__init__.pybase.pydnscmd.pyfsmo.pygpo.pygroup.pyjoin.pyntacl.pyprocesses.pyrodc.pysites.pytimecmd.pyuser.pyuser_check_password_script.pyuser_virtualCryptSHA.pyuser_wdigest.pysamdb.pysecurity.pysource.pystrings.pysubunitrun.pyunicodenames.pyupgrade.pyupgradeprovision.pyupgradeprovisionneeddc.pyxattr.pythird_party__init__.pydns__init__.pydnssec.pye164.pyedns.pyentropy.pyexception.pyflags.pyhash.pyinet.pyipv4.pyipv6.pymessage.pyname.pynamedict.pynode.pyopcode.pyquery.pyrcode.pyrdata.pyrdataclass.pyrdataset.pyrdatatype.pyrdtypesANYAFSDB.pyCERT.pyCNAME.pyDLV.pyDNAME.pyDNSKEY.pyDS.pyGPOS.pyHINFO.pyHIP.pyISDN.pyLOC.pyMX.pyNS.pyNSEC.pyNSEC3.pyNSEC3PARAM.pyPTR.pyRP.pyRRSIG.pyRT.pySOA.pySPF.pySSHFP.pyTXT.pyX25.py__init__.pyINA.pyAAAA.pyAPL.pyDHCID.pyIPSECKEY.pyKX.pyNAPTR.pyNSAP.pyNSAP_PTR.pyPX.pySRV.pyWKS.py__init__.py__init__.pydsbase.pymxbase.pynsbase.pytxtbase.pyrenderer.pyresolver.pyreversename.pyrrset.pyset.pytokenizer.pytsig.pytsigkeyring.pyttl.pyupdate.pyversion.pywiredata.pyzone.pyiso8601__init__.pyiso8601.pytest_iso8601.pyupgrade.pyupgradehelpers.pyweb_server__init__.pywerror.soxattr.pyxattr_native.soxattr_tdb.so/usr/lib64/python2.7/site-packages//usr/lib64/python2.7/site-packages/samba//usr/lib64/python2.7/site-packages/samba/dcerpc//usr/lib64/python2.7/site-packages/samba/kcc//usr/lib64/python2.7/site-packages/samba/netcmd//usr/lib64/python2.7/site-packages/samba/provision//usr/lib64/python2.7/site-packages/samba/samba3//usr/lib64/python2.7/site-packages/samba/subunit//usr/lib64/python2.7/site-packages/samba/tests//usr/lib64/python2.7/site-packages/samba/tests/blackbox//usr/lib64/python2.7/site-packages/samba/tests/dcerpc//usr/lib64/python2.7/site-packages/samba/tests/dns_forwarder_helpers//usr/lib64/python2.7/site-packages/samba/tests/kcc//usr/lib64/python2.7/site-packages/samba/tests/samba_tool//usr/lib64/python2.7/site-packages/samba/third_party//usr/lib64/python2.7/site-packages/samba/third_party/dns//usr/lib64/python2.7/site-packages/samba/third_party/dns/rdtypes//usr/lib64/python2.7/site-packages/samba/third_party/dns/rdtypes/ANY//usr/lib64/python2.7/site-packages/samba/third_party/dns/rdtypes/IN//usr/lib64/python2.7/site-packages/samba/third_party/iso8601//usr/lib64/python2.7/site-packages/samba/web_server/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:9159/openSUSE_Leap_15.0_Update_ports/64242a6901485b8a6dc9be6117aa64d0-samba.openSUSE_Leap_15.0_Updatedrpmxz5ppc64le-suse-linux  !"#$%&'()*+,-./01223456789:;<=>////22?//@ABdirectoryPython script, ASCII text executableELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=b0156e6fe736a56771a3cb2115ce144dbc5c2deb, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=b6ce768d1769d766dd38a2f4661a0dae55ba8e6b, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=b2e9b1ecd4a189722cfc19dab2824b4bc0dd6fce, strippedASCII textELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=d3a71049816296338fa19ee6e0d425b681213d76, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=3e46e79c2aa0aa8855c947136da855d37375f122, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=ef37c8104e1a4b7080806f08659a64e964174a12, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=a3496c5511e286f1f414c0b6301252d16e0c5692, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=2da3cd3dd18183c54c358d9728b91822a0ae78ea, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=46847cbaa8d646d887e38a4414db8018cf654e3a, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=3dc29d0ad3bf2d09f50929944fb83bc966a4efee, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=80126fcd1b48eaa6fa2628c7ee606cafbd581ce2, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=438eb9241f57a97a48d334ac52158514ed8e905b, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=bc2e8536222164449227c85888423fe3dfeef70b, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=a14c0b34583c40da3ba131c4d0a8e2f4c5b40a4f, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=b2dc1d7e567ec9f40f7adcc65a771bc752af5c0f, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=594b3d16599de7e0cbe60dcdea718de10d0547d2, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=5a36c56c6af101e132dde61c5176ff3bfc1deeb2, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=963bc367fe1c2af60ebe945c07fcc852255cf945, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=b373fe8a6b116bec7a55e720489efd311c237d22, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=2927053cde89e50f0ccafeb9642ea456f311b535, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=fba217db35872dad4ad95c4c0ef18597b430b1d0, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=e26546e5f2e7e0970c6a85185f1a03d82132fced, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=125e67ea3076ee5c61bd1212e3d31117a983f126, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=f79b67758f3bd0c29566d8adf49c75cd1a8cbbe3, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=c6677dcbd6aa14c2f3fe35de6f84d5a2acd34a82, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=6ce2bb0729d529211e2d40eb6a373bb0b1ae9ea5, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=7e72057c407fbda7861e62d1722f2c18273903e1, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=63883573b70a72a147e8fa9394e63d4ef78ab754, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=f094007b3f832847576b58fc5c1b8b77ad7910e7, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=8f7c975089e9ce5671ceaabcde116efa9df718b9, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=64fbe43e76e360728c00c9c21021c6828ea8bb7a, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=34ee5b6dc6546deb3ed88ebc881725d37e7f5ed5, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=53d4902645fab412459c2f16bc334fdd9af57b8a, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=15a6a55c31a56093536802036cac16ca2560cca0, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=0544d970ad81142fa13f1af2b557421ce982d08b, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=fc087302b9224096adaa0a0d5880e3d9eec1b0c1, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=7b7169d79e5a82eb01c2c0ee6763a478ddc9cfc7, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=d6e0a6b0839b623a461b3b943b3f3fd51e5abba0, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=5a76dd40e67840f3356d7cba9fa8395ca848e884, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=fad5ce14475b5f0729e4b7d0b113593f685dd942, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=d87358ea5f92555bdc9463a6c853b63bb8070953, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=0bf745c8132281c4b38d2924ec171ef117d28ffa, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=285c2052f68fd112a21c5643c1ce01371a2de6b2, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=8bce83d09bac37519869206da3de778588a03678, strippedPython script, UTF-8 Unicode text executableELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=66cb9c3839e32f27e9fbe92c653005cf7e28cb7c, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=291390e3661f89ae62526eb703e49dbc80be1b95, strippedPython script, ASCII text executable, with very long linesELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=d4086b7061bec009afd41e43b7d03ab3c6725266, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=c1b10b4018df0c7901088387ab25fd38b32ce0bb, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=4a1be5569f90b29b830c6208e38bdc16ec55d613, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=93573efac79bef4f53c03e1f2e637eaa2c3ae4bb, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=fa2b8b06a0bcd0b363152837424253e19352e647, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=17866e92f3ed35ad07564bac0e9169ab01f4da65, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=e32fcb2670b5836e8029c20f10767984781d2a65, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=7761e5d2877ae984ff7ae161c5ec082412416e2b, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=53bb870b19024d3ebde2a537a0fd9104a532fbd6, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=a51141736670003eca5950b1e8f2b9c0716ef44f, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=ae392d78fb3ec126a083d1c983de1499b83f29c8, strippedUTF-8 Unicode textemptyELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=ad40d8b893ee91a428ca1c529c10794284bc7df4, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=106895ca7e67db0755d5b68a16b51a73816cddd3, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=faab4c35ca4a062ebf9d783c5ac432e1dff55940, stripped2QRShnop"<Pdw,DXly./01I[nopqrstuvwx     &'(DPg      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijnoy# #     RRRvR`RTR RARdRcR@R_RSRLRuR RR'RR`RVRdRGRbRR RhR1RvRJRIR/RRRRRcR_RQR0RaRgRRRUR&RLR.RuRHRFR RR'RhRVRR`RbRRJRIRRdR RvRGRRRRcR_RQRaRgRRRUR&RLRuRHRFR RRRRVR`RvRRJRIRRdR RRRRcR_RQRRURLRuRHR RRvR RuRLR RRRRVR R`RvRJRIRR=R?RR_RRURLRuRHR RR`RdR R?RvRJRIR9R>R_RcR8RLRuRHR RRdRJR)RVR!R RR`RvR?RcR_RUR>R(R RRLRuRHR RRJRKRIRvRdR?R`RR R>R_RcRRLRuRHR RR=R RVR`RRvRJRKRIR?RR_RRURLRuRHR RRdR R?R`RvRJRKRIR=R>R_RcRR_RcRRURLRuRHR RRzRdR}R RVR`RvRJRKRIRR?R9RR_R8R>RyRURcRLRuRHR{R RRzRdR}R RVR`RvRJRKRIRR9R?R8R_RRUR>RyRcRLRuRHR{R RR=RVR R`RvRJRKRIRR?RR_RRURLRuRHR RRdR R`RvRJRKRIRR?R9R_R8RcRR>RLRuRHR RRzR}R R9R?RvRJRIRR8RR>RyRLRuRHR{R RR=RR RVR`RvRJRIR?RR_RRURLRuRHR RRzRdR R}RVR`RvRJRKRIRR?R;R_R:R>RyRURRcRLRuRHR{R RRJRKRIRvRdR?R`R5R R4R_R>RcRLRuRHR RRVR R`RvRJRKRIRR?R=RR_RRURLRuRHR RRdR R?RvRpRJRIRcR>RoRLRuRHR RR R9RVR`RvRJRIR!R?R_R R8RUR>RLRuRHR RR`RVRJRKRIRvR RdR?R_R>RcRURLRuRHR RRzRdR}R R`RvRJRKRIRR?R7R_R6RR>RyRcRLRuRHR{R RRdRVR`RKRIRJR?RR RvR=RR_RRURcRLRuRHR RRzRdR}R R`RvRJRKRIR9RR?R8R_RR>RyRcRLRuRHR{R RRVR R`RvRJRKRIR?RR=R_RRRURLRuRHR RRVRvRJRKRIRdR?R`RbR R>R_RaRcRURLRuRHR RR RIRJR?R=RvR>RRURLRuRHR RR RVR`RvRJRIRR=R?RR_RRURLRuRHR RR9RVRzR}R R`RvRJRIRR?R8R_RRUR>RyRLRuRHR{R RRdRVR`RKRIRJR?RR;RR RvR=RRR_R:RRURcRLRuRHR RR R=RVR`RvRJRIR?RRR_RRURLRuRHR RR RVR=R`RvRJRKRIRR?RR_RRURLRuRHR RRzRdR}R R`RvRJRKRIRR9R?R8R_RR>RyRcRLRuRHR{R RR+RvRTRR R RVR-RRRUR,RSRLR*RuR RRRRR`R%RbRvR?RVR RfR1RGR/R_R$ReRUR0RaR>RLR.RuRFR RR`RGRdRvRJRVR#R R_R"RcRURLRuRHRFR RR`RVRIRJRdRXR RvR)R_RWR(RcRURLRuRHR RRRRRRRRRRRR'RdR}RVRJR`RvRRR RR_RR&RcRRURRLRuRHR{R RRRRRhR)R!R'RbR RdRRR`RfRVRZRvR/R RJRKR_RYR RQRgRaR&RcRUR(ReR R.RuRLRHR RR'RvRVRR RRUR&RuRLR RRRRRRRRRRRRRRRRRRRRRRRR RLR RRTRIRJRlR RvRdRXRWRcRkRSRuRHRLR RRvRVR R^R]RURLRuR RRxRXRvRVR`RCR RWR_RBRwRURLRuR RRRRRRRRR'RvRRR`RTRJRIRdRVR RNRMR_RcR~RSRQRUR&RLRuRHR RRRRR`RVRdRR|R}R3RJRIRER RvRRRDRRcR_RQRR2RURLRuR{RHR RRIRpR RvRXRWRoRuRHRLR RRbRVRpRdRPRIRJR RvRjR\RcROR[RiRURaRoRLRuRHR RRJRERdR RVR`RvRpRtRTRrRDR_RqRURsRcRoRSRLRuRHR RRRRRVRJR RbRvRaRURuRHRLR RRR)RRR'R R`RVRdR RIRJRnRXR!RvR_RmRQRWR&R(R RcRUR RLRuRHR RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR RLR RRRERvR RRDRLRuRR RRRXRRvR`R R_RWRRRLRuR [=Pޙ}utf-8e2d4603d03018de89dc9e4be7008d89cc07a0fd331fbc718c672443a60826e22? 7zXZ !t/]"k%oM2_f4pps)(zL^!z:1 ?>08υRK`>NlkgĘ|jsUu=R}~HKHNW-M[B y ~3iE-I;CN( 9 6޿KZehӐ™7zܝN(N;4~,Gsmmcog%?Ts(eܓD^iݬ:~v'Jum "'Rㄔ+$◈c/>̏fܪqJ e:Wq2@I1 "iH5wa?ӀKjkX͠7Z:,--g ط 1 "=֢Cr4gUm}[^@.D%u4J8 YdfI.ߥhdKIJYnf̃cҗ7>SH9,(rT`5Tmsbf F"q{U^7: c9yH (?׌iMz~BECF?\%cFO  ]Rd'k.!~^Q#o bd6*v :v[KK M9Ź5I%6>^񦰸h:%ަ#ihb.7`l{qTy"tkfW-hoc_n ٩޲^լi<9LI$&SkGldkO:1A_-f:ߢ0.;WMV -%.jT}BֳxteHk^=yF^&rj_B dR'. Rv}}R!$g5h(,z*n oVI\TX/ey[9#ZSlX4M.N#kǻ\=wænke6ŧ";?^BW᫑RC=`)[4]Lf!pHmO8w#ҒL"6 fA^ zRpq[{$_ R5oҹ[K4XY e;ȋ{lAu4>| P2m%!@3˚zs] R]*:C&$!=dMs?́&gb-2Hvȝ'f?a wSB5pdLoUɱ $!&޷Z0X՛VI+d҅*[(ͮޕn yѕt7b1XmVTl#{9%#Xi)78׽V63 kn-.qHX-Z&>2[>gK}f%%4'|wka˓I+ˣY/x^v 4|kv2?zq+д*Ǎ6G@Ɍ뎮S)UdL6,1Ρ͠}աHkz 852]'El~,E/cU]KUAfSKද<@& ˭zE+]o$)}7>ϭ"n|AiefW_3]T[KM"%qG)}^Nu }&H8 k 6 gɩ;U"`a@n4n{EBM ~!ҵbҹ%r~OsJ'OB |vt) cJ ^nwA9 {% j D0 8. Tqm@se u.`кʑׂbD+'Qn.DJo]nJ𪍵D}]ap<iuh{ kA벜$6\L.d RܳKϜQ]LZq=&8]v.aQ09T h)#IB>׮zRĭ\#aJЪBl9^2ш^A5imۚ/c[cw)Tr8c&rlY˜ߎsǍ:{>O8Y IFʙļ(CHHc{!gߧ cc 홬Օ-l;n&Ծ*?g0X(؜]N &-7҄pDX(h$ap4aGI;;-b/;k C{96tjG)[3idˍ ո#:oӋ0][q#Zd||K B:=-htjҡؚ_ʜ5\H8 $0 ++AUUӶjRii+ @%{`sn!hb+گq9r^1]xl A\#2M.|v;E6DOщRa&r o'f;rBR?.xZ.4A`ev~z2vj7uN"H)U0p@nbd[ AaOe""]!+[[Cɘh]̔tgG\u K=΁Sh۲oTH6CQFu S7Bю;G(ͤ$[չfbHJJ15:ʌ/m2 9m}b N.ks*e8mr'DR|n0Mx1g[7p%ceͺav[vyqkG!K+WF C6Z\D'WY C=Fat$_c{c~ndUi4T(lk-cWdT NݟslMJh<##MMjdW ߧ(TVݯՑDŽ\4Z}?L+e8}zS2K>ٹ# 8$mޜ.v:&Am%wnE=V@3IC$Bm%řeFyX!@ZGyﲱʹ?Uᄡ=G/j@/ rd_΅Y}YrWyg;a-Zɉ,_@%7&^i 5mou7k7# m|]w;'V_ΈȇXB%h[eD;phnֹ/YC*H*g % ߢ5xph͘L9-3*]~iouq 17ݱM _KQHƔ9Rd#:HdE9C)0d;ɐ<9dS>|nW${$ltbE MI"in713v>}u7Mrs)Xf͍:7KF@W!5\%9q$vቔMN Z!.GVĔ7'(8*S,9£ TBVIJY&4: 2濂 X4VD}z!,ʹ#V⪗Gcbފ \s& uAjD95d/ NI_lDI+ iEyI7{)F0˾rQQ'QतvuVlx2,`&o3;֞qv~[h-0KXa]:R^$mEE]AkHG>pqh[$Y@S']+%xez"$hFl"-.>g)Z^SAc/u,HkU+$(Jo[Kƛ}C<T>AWrB(/ZmJRyk]\o̤-/ͺ3h<)g-{-9W#L (?׼ :&"NG;7DhJ!&3fU X'$,UHB&g$Zұ· \e ¢?󄁫rzH}ՖQ *lz/ܜkPGyZ7zn8zF6YoLy_ [ʲ% h=Ǔ  On󣝲@bn8BgD6z{vH14 Xlnbv`U4 P9~1}B{nUr}fG/B$g#p;)5DQV&>w+΢ <wL60l5uM!  /;7-tDѐ U >> WNj7W{m&WHUF mX A7#Y#i/i(`D*$(FF]KVvQ;\ 1̫&@%R@C EdҊ\&$Dž ą7*&bޢFi;+Jy򁧺0s!+ r^HEV `ԔSORӽ 4pDv&UoH,APul é;v=ٟEOmI43ɒj []%nVSAe-m2iH<מex Pɦ<6닜\%s<2r?`g ;W6 x_L {݀Rf[U.k?$Ť67y|{eW+IPί~Xy ]'Ѧj~3ge;R1p Le,x& Қ!gbU8<^5 #M}qnIpCB>t+݆"Cc&7EBmݥ$W8>j_Gc<1XJל][tՎѠ3” 0> 1|LU51C&[jQI@( 59WUR'a{z|\4f --ٌmϨҺb `#M&BQb pfbC05fz[#8dț1^t7|gս Mvn>+Vh6ȟ޽?M*R5 eΊ \, 8afy K `$Ba?^*+Ϻ5Q&3Drs%Xbr:ZqȸV)ta.v(WOI#|HRE e^x }I U/]- +ibkٹ)0N8eb~USS2P䤶}%u;8H'EըC q2GzP C8 ]5EJmPtPK+| ?6 hH3X4227ii@3FOJJTW+%b<1~yb*.b*H9dG"5ur*p~#F#@@p-$bKrE$Naē$5MzS!{:FK090ʦ^+g@!YA;?W(x[ Vxh%Kͦ:Ua ~!xi%=SʬABtҶ$ef\[b5 ?A~o5Nv Y g8r-o4ROP*iM-p_>Itipv ж%;6eicw;K6C8=nmIXsB+ɠ#~w@Zwڋ [;I: /&춵bp":3Eصd0=P J=Ub̋.jb~ܓwhcpgi_pe0*Jv۸Q~su  :䬫ӧ+B@9:{Q@Lň Q-&^G55g:Y ԣacjަcB ÙWLF*mr zԇ5=M|wU6O`bt~qC0tV&m̈́7CkZjA *&,ֻ =tOݐDAQݮlYz1EGhBhlR2*ÿ|8T6'9A:7(uc$fx#ޒ\A)# \8B(¬!h}[>+lkp  g! 璼 4oiV'/GyܟɎ81g-No5Z$VՓ}HWC܆k/ATpm:e(.' `ͅOx|)KcR3W3 KQ~$#C,r+GJt6ɝ~ܷ6 AmOZխ-Vۇ:Di8? n]> ;駱9C5#pCH ̝G+_qd~D4\vHlgk$&(]DBdg/hI/׃t` */{h^*Q) kx');| Jځ|<.ܱkŷ# JLjB‡B f\\.mei {LqB}$mT.jW..jq6!?B˴c|0^Ŭ i߀+J;F /_ek5Kbsvs) %v`RF''1E yvwFQQC&X 9r|:[rUL9S=?cJ&HGv$o0Ug3 PEYHDW~sogn.P5ۙRd "(>gy,K|-_\HV02\4T Đ I}FkkrON qeܻa#,sȁRsj\E'j5 ~ZCu&wsSr ۱X'"5-SON~@pFk<`) &͖ р8D b=_ aV/ ? MEoN$/ހ-@ 򡈥Y-}Hks씹ED/p+߄QYws$VҊ˪ tH¨unERx?)OyT@%hY#N]}+V"HDIus1 6"X@>% | ʰch &`ӡč޻,ފR͋h' +U !pUO>@5 wN<T@{Ɓ7E:$M%ryADSńĴzY&\C\RM/e7#ȫeBOD'f|,զ xBEں+"rH.<3rq5[0lWJLB(6"U{efkеX1'VIDPԞ//BJ )P $#QDyO$}\ˇ&Կ+>@"JwIG`&1glaW3ҸKޚc,l`UXuG̔L.goF͛zRD{t kh 3Mx E7~k7QKH}DZ$k}"N5]f6 F~X²)揼5NT%g,m)6>9|Z]=PuHW{YÅOQ?}M.Z6en.|lh2--r70r&`Q}VT *3|z4A2vܸv^g?Z#=Ja?ޠlp+`Htr5G~mܕ!4O oʂQ(%&SZD!k̩.>6*wC;_0u-𠘒wZY~Ej !hg_L]P$?*3j:Ng΍&<.,?Z& W*iR2ؼ>6 %o^)X{)c-Lĸ?z:ZC/\ϳIpT \oš9wj;tU9;%6}}ǰO1|;W3?֢Mpx`aX !Bz5rj#+1)#U*0_6d[0wia6'esVElRI.=U[07&?#p?6hV}.z0\!`Bfe]&b4(!w4q\8_r`y_jR4aWMk4kTB亍:dR?lw+0bv6e%972*gv{̀?~bō%^7D>2uqGgGA?n}=,xwPHO"ҥ&id#`mTV9VZ!9=zKLGu{$('  9B,Qź ^l,l=b0R%&9f'r)v؁;X>9MGӵYJsX7]W/ aAT@9Y%ǟ,LqO^>;;=-%͈ fGt >&K}zZ/4%G}t/+7U $8ñs.ɲƀW>|&cސ0 g!XS7sW[&N %n&[D0M*l&EY3$G`;X%L9xa$3)ѥ:cO,7  *C@u՜/!kӋs2e~AwqWCG)UK;:0X\qL2c *#_5Zwjf-Ce~|n9kCQyWoV?"fmg6tP?NKEQ=D;WCb;eC"qֽ}!L*G'ȥpc|dU9fXT Ry#ĆrG[o,xV|'~)=\i;"NȄT6y7Gn=G2mau$@lP*N/I<v6&dNG,Fn sG}N@*c;iTbQ &wNWʽ1zTԫ_Emir)xҽo.SBMA/OO5/a]onaxc߶Tju0#xm1l9%މ8;$ba'@ní9ezs;hhh%+B_}߈p"Q;P wl0nXk@|4CIܡr&iQ$C ˝U0BVo+U*Z0>^ۿzn ZOk.(j~a w@-˥ov_huE$kQtIgxe뚅ΈKfZJ__&29ZW㾳 l<Lnb_iB;TCbWuJAui.!J<)?E]PVe3?wZw&]Ent&܉;{p ҈7iEt#/Q.O :dxcϝVq(`r G}m u-gu>>';KOٔ塱dI`2PK7D1M$yi%k{v‘*r$ IB 'J^)M#o n"B!5C;M>E3`ȮOf| eqg8$ɖ DΥ!_)OpA0᫝Lvv=*\Ěi2={ůF=F*' kJJGԟƗFTjw4vE\,.E8BC755ԯf7ԁ)e?+GGXzI>#H}GAیJZE1B;X\&|(.RY,*^:\iRs*$*[ՈŮu %K1e*Y8sfQ^~5=쉫F#z;$= ʼn};a*Y>pla;lGcނ|,5*98R1-QPYصܥk&Tnp6mj͕YG#5tHZ iN3YM|u|uǽPn,Zri?5_{˂}z r7a!vyw\}j ł#6 ^LWJ ǒ6 wʂC 5!zv-c9þC6[s%n%H %f\F#۵Y\'C/C. YǼHLZҏÔ hdb M>,)`eT{e+%Bjpgz߱!Hlہi/\ǣ|(?(׫]Y.߮b;ԓ^F՘-(ͻ]yNj1Eo}@OO)bn)BB!;=RJ|Tq븥ۢr4RE&]&>bj cR ATi(88kPB C}dkc w{Tz@~MH($ X@ItYހץ1WSDቴ~D"lRZpw~P #ݸИB~ˠi~ VIJ p87[ؾ4x?ԟkx-b_g݁"+X 5B5oe?[km?%?j?bG& xP}cF$.ڈGxx< 0e8gL ¿p7#E{GS.RN1@/D~U,y4~#n"aG hWk; ]_hSJj`~$`}8VR F|"ޘAIHk`(10V>HM7VizʴX7fwo` &$5(,Ŋ/a Ý7 Loԍ )XV5@ ~VStgRA3 }CQ?Z5P*%ӈ{:qD. 'rs?O]⡟TC\3LH= t“m@ˠz#OG޾?,Q}1^\d^}?~yYN7Ng[a:=JXv~\y`hJ o"-eG * 2K9@:M}1ſPqaQڐFY7J*3Sd9er{* ~W%^Ԅ*53r$QG8zLgSˠ .6VM L6 f/ףUoݸO>WJ1` >W8ɞw-LX5IHқ6q=v(;܄;аwKL@ˎh˭%T߳+IܘnA䋢TOsF$[ Mi m?{ 0ȯQZ֫ .c#zDҿ&GGBJ{ظX=!N81?>i]z-c!F4A^OO2hEQWCnuzP:ɢQf.A#&>8{z*s;&XH}"wѸ+ХE7n?],)ô넮8HI)3/b(Q/Tkz{TYȨ}.MF&O<%mdH6T1U|-zt$J ?Q=;wVg̀S!}2Iz,pmp|$k8N ,iz1OQӹ]ua}t&\tcU}~u y^f0F%,p8OQ֯KK!\8JO5% cgGfθ{woHwN^^{5wk3u ;l~BfU t`3U67֜ PVP&)y)ΪUPG?w0.iٕӢSt]sʀXl |*~9mJ#܀RGIiMDnj!bC%hqZKe/ E;I覔lVrm˻dz-ȝQѩ@ . YͿIh/1.X|NZծj˺不Z:CBxq|E61}`:Y%:b=SWO*7 :Bfx7.>.%t ;ߊ-dv" $Z][R )bc}n˹In}J ~@OTA{b%n :NwB;B꛱6r3XU;d5pVۃ˰`mϊd@@{42k"p7`.:&qr7  ,$u4\奏!n#*rx:?8܃y yn bn5( Һb[v|rs&o5AߎSF^,瘠-,c($Z^"I ws'K)l)~j ⶫPSJ4ؓ_xס@.z%3#t!4yט 'zAآ8"^=, $,``KB`OH͵ki4ԟi®eϊ``Q.ga|䵬%I 9wj^,ұXhxXeR WFS6 +_w)~yImS̵V7^r| 5qtf[hlnLg.`g@kuܯk ^JP6A[3؊.*+6D!CHXH_}n cL +sJjatٳhn>Wsz@I:/Ւ/{@cE1 | ]oA}Ĭ<&4ƪ^NQb^uPٺ&ʪ Ь\ =A#B=tQo2W_u#ӭKan1:hwO 'PФ'*ܚq!BED;T!(\7Hwiy, ?تRٙbP#27oa%֒4C1sG~k%er`;SDRt}*RZRgE[_d:#pNQ3&%r!|SYGAo[ѥ]+rD>"s3(LS؟s{N%xvjYkZTsYPOx"=f cAЧP\gJu);68A+>+U:PB9^4;X5Wfhtm|?L䢮L{Lй]-8ٞ+'ChϨ2XXv!e(=er['7GqŠPma釋_ahEe}]$H'` MĴM㪋s2xa%F%9qڎtvCz󷕓]]G|{p*3Y!ʃ*.$ħɱ) 'FCTp (|sG.tF봊^tU667ua>vj}_"jNRR 3е[̵gi6TK)zlQ81˲[ҥo},ٍh2I2֟4fՐb9{hXz d5߿{ qh̿kiNJI3hFȫ0Tjl/d"[?wO^Js<0!8O f|r%ٞY[ڴׂ%J@_PB8V; ک [bw[&#m=8ZQw3V`ߤ^ОjsD)uܲ$К{)\LEeb&ubY@nͨ1 =j^Q ꝩPYXYF5hW.Dr61S2jH'`Q~C5э6Nb1~ճ\\ L~MP%h @, )+8 DY=Hh#Xv1b3']6풇N]lʯ#7yp* z03Z^K|xSL"qrmDIdB(6~pi38(H>4'0U˔Jo\NG kiq{^#)ue4Ǫxj*;C=:)׽()IGa}]Q.@Z 9FjaHs[AoHe9}MOz?Op M e.^2  Ⱥ;GLT{9 p,jHoU%$>d$)D&GcrnEAɆ5EbOы;AWLKbcor 4* 6>Q) 7gJ2tˌ$Qz+hґŖ|B7g2g%\UlϊLޙ\4Cw.Aldf@JqDq: ~Dn,̌TEd=g:7K 4sܱl!l  Ic(  "HG(^^5фϠ]=#MsCGi'P\}=y[j=zW61#'PTiI3a~*YL_[)ѽZeHKj_u⦭Br+F1&0@{F}TDon\۩IU~d,u٘| aEb4nGcu{#i1%A<2*?x09äWW](x倅2SϟJTute$1%.=x";vk|vKrQѠǰ^+䪛_S2*ΦN'uuLؾ]IȢԏ;6#uTq?͎ZrS8$^%wUY%[ݢr) &nKX!|^@A1 62rM͕&k86ipGO!4D/$,Pю\RKm?*G|_4q)OwRa:.p3uɧXfbH@%d&\5tL?I]&1UnSۥNodڞFAFم Ql,eFލm& ɐ&a8VkvCސ\˻Ҟ{ˍBHU7C`ۃ`/ng> Ч_鏂\vQOBMD2"d+XbT3ziZ3`3 )jkAfw?*ښO=[Nzy;e3*:eihDCߞ?HO7{-r!WfbS4;W7:e݂7~U&M'eAގ}.cc8s1 NC5H6-2U: [&5/9r#z&Ĝ=% СX ˏgRq ٘V$\}!MD>'=~ B?($cc. HUYS|z*Q9QS7ZO9˾TQm_ʆ@HXH撔򲎹#e5Vcxy; 'T-Uxwhē˙ )>7(Vع;'bEnS@9 R͊J9ݶ 9KwZ;<+ p`L7D>Z=JNܼ(حޤ| |te,Q|V4Ƃۏ+K%\zNz&ow.rf C: ᰹(Y٩s>j09uv9a[;yZ7?}2#xveȖw6^qS"]jb7{Dcݙ:vp<@eA;ujsk7V݊흟R~ŏ7HSNyl^-i==:)V4P|> F,;N<RuYBpwt_Q!ܲ[._m9}Q ~OTI?maĄ)h|cō1qLӒi( B'1't^U^E:^!{-Ŏm/ġ>'nO~q1Y w=gD|-6w)_z"vyRCа&pE&fᡅ$rBk_oy악>;Z a v(909w**>BxT/gEUV_q%Z+['aiϻ pOe+L^X\v ÿaoĖJԘ9WL0&a#a]BV?(BK<-PSLKoUhrϸxO-|gov<* Й~窒NynXS/Kq6H )6ħ*d^ĸMIAAB nLPbCU4=2U^\3RbR$HpbץrEU+m4Ce4_ <\) 1O.3\,//UZ;,tKtR~k.F |(1:--Y߻$CnZ _#(Ҙ{%F>ѵA@80N),9#A_g:u㙊+~9 @_aiYM74.a0Rmꟹ}pM8T yĘ.,8$20/9>>Z-w ;ܐ)1۫;J;bbmJaT$~h1\c4G,U- ghb) 5U4 !̭sr|FEOqVX*"Hk2.Ai)4]{K{Kܓji3AC)Y8$h) mO#!T/]x} T}7ďld#d.Xga2,= -fF}ϛSIu)R|JćˢVF/ڈHg#F=]!ⶲSOɂF4&ئB1pW_TWb)O})@V|w?n!~si_VFru;09bL՟yXDTaܦ!q%rprɇcipv} ?*+\;Y'b> Os4mp??]Cs'֥1thzњ+YBıFqll Ϋ$i3Q^n!2gc>"&2;CX4>LH/PY JZ{=͓B@6+IVeI˸ŕH(R-ƒ ҳ %y TQ?.wcF>hS3&yU?}#{m  r͛%hOh#J. S]T'Ѳ0%WkRFґ)ABDa BgHϴa/In/1*n9!zyh/sJ3MNƬq7(Zgn\OA\~GXەlfAzKdϲcDKZ)X-[Nh-PYn=39?ρ?}?ట`&!sSYF5 xM}څ`p鬚0̰.cPi,`H^.,9 vr?Jɠ~# yD -g%K?"-|GN]:&CEb:~b5{'D]fHnG 2hfT@g nW37iK_쯆JxQmZ{Ga\ ;( ZGׁCHY2FtNŵ "=ܡEwߡ׵rZq&?gh摌rP}[M Ԥ=874سuxB~*:DK&L~՝ ۵sp{E>b:R2ťFL C=WsQ3"7{MF?;Cq'(H[ #0qbp Hmey< W5S(o#d5ЕЃ1> HV>r[Zpea 8dvU$2;-`E|JIDdct\MHG)X^́䏛-qVb*.dR :gFoTFJ>lFwq*(<ǗUP>Y 1R F M1= zN>\^VϳG&Hx;_Ytdޣզ/AOkhӵV] 8EejS֒~emJFHs ! [}އ޹'<fd,BX)5gpYP&T}Pz<K.-3v [ql&hrwCzkSQ?#cn,EU]ɲ^SH5cHnN^.jvsX_h RՃp =,$Pca[Xг:̤e2j|aІ[Ə6to~䷿STpSUr Hf;5dL%LK''9>!nfQZ/pR\3 GB6<+ܳ5 EС1XUj#sVeV7?E_ Q.y@t.kxMsm^ʜو]4bK2 zf!sm%ُZ,$חbk/iv+p1A4hTqxd o6 ‚0 /@ࢄ]'>'Ԗd<'TT2/[u8KIưםl 6yV m aCuTZ⦻EK00;jNs!|J01`W{;)ۜ`v;_]fj/9),I( {Dq kbd )~d  l~LsF5;>&;f(i{o~ Ey,ڕ0&ѻ+1Vc"6lD9Cl^cUԣ4rmW[-bUCpȠ42P"z c?"SY"7)d փB[(!jͪ`cUg"+\5hDLO񹊪ԛ%H%=}t֎H{ɻ*po{_fxK(e%V#3j0€7Akdʉ(ruU?w]6Ss͸R"ݢNOtIӡFNԏKKp*o\Oeq=@Fi) J)AS1@0\"< T: G 5ͥ7f.Uvakb4+d昕 00 ,հ|}n)bo.;(עz׆ޜބ,qh_AVXVtUsuo=}cR"m\|Q %xi5gɳebV}<6}'/XUtIȷGmE9s^)[}? zR, ;ӣrJj=VK(Oi8F -F p#څ}vI?ANb%h ᤘI9AwBYwM\9R^]v=)˛%_mI1t)r^X@6UVN&WXKń :/85&Uu`Ru%`9FGA6&Ȕ/6`V>$G6]>(Yb0 hyuggO9D(]eG!⃓ԑ RO 7rSߞ CBdr<Dj"lp);۬#*lzp4J>sh^2(H4)p6 < ýn…XěӶ#cu[{ &8_'$4D7(#կjlNU1zoR8`삭tJo~YY:: ԯ'y:ꀒ\XO(Wia@/J5O D1<?'aOށ/U^r1=55-nH\Vw)B|#5braY!P9c{cWDzF0U^^2O` 2ᷧ4V$fFZX2FZc0ri"+#EF +J \1er&cta$k#~&Z%C_sTV|<([|ƴd&ͬt>?7rfSaw٘9}ܒsq'oL r6 (M[ `G܂4XQmU@G[I?"!@Mح:׻)u\v_/z:zVmprȑg⇎|)#燪>6xJ㪱3?3~3=Jxs{DUJ=0=Ƹ e/HOGӷL?.+ !@noLǀPj2zr{jnOC=r4@cvkBsa1ͧjRՐTixeҼZ%ʙ3=,㕅XlUP);Ŋ]c|%EFbTl-w.#hwXv,R_-T-TǙ%LB)̫giY$q6Sǁaő] IӀݸan+g(t ح:,%,l[W˾\`hu+] g-fbbϫ*[J(Ķ "v%]\ GK%0\&x"ʑ >?jeUʬ L߳)B²@θ6?Ji1;pYb<3A?}R_E~؁es~g7|rl#;m*7S#$,C:xӈ |kSfPz$=f(N5 b,1KTA'`zEE{xwWU(L 'k.%M5} JjdQtG,R)>#Iu e^PDP EE;A2"6AWi ZU~Aho7] bh@?Ρd_VE-V-\5d{ g?`W 9 f`%e8Tō7|#|4LD_ǝ/d#뱲% ͓C&vzHĥzje'S$#  ;[}eq'ѽ9#[x}wÏ_uoN.ϰ~Xh]qshUlxlp*XN,.Γ 5-F))x㩦*)3\9IL[0} 9l1щSM%ݜ =" l{K)*Aʭ:@ 'AVO0a U@<=P? Q'GWl3 1Vg0*pnn?`ݔ{iV >O *H;&h$;@ybkpH?+F=0(y:᭦a+ \luIC}Q5Fvygi,4 uLuUS~\ev_jty}P皾A}kj{p'eey9jT߻XWŰ ݻDrʃ>Vy`fRZQ[ _Nnj/ ̉@8Mdc0IJQƅD]Fԋ/5!q x[=* @`'vȡȬeVNsѼj;o(UZ9?AM\ZbR?naʾ>F]{(t˿!֡?Mqp``3'R-գD o{o әhRߴԗ OמU<;bwhJ[8z$w4 $`,2@GM#gHLsN( a 5 .1RP|0>r6V-fTɨ6~%<}z GX7}YZ؜(MJ8ͬi ji_/Y 2e1Osʢu _dL@ BW޶qA {]0҂,2osSk,DH[Riʠ?#,=QL^VLl>QH-LݖIJs-}ϭ9 K;s_|Mcyi~m 7o9ww}0oz\gQdjD9O+Ov\# Aa~nj]n]<(ug1:̔cdΙLFj~BP/)t;VUDAʬɄNREfS(Hj{5x98HG0Y[~%BR#Qt9$#T::!)^hr0l{`1$~oԪ@ ݒҨ*h^Nk%0-)̅P껋=K#5?Gb NX'X2y{$tN} HYgo~Rwӛ,uEET,wBä-iHm- -;!f6b HS菬Զ|N^ |r^\["0PRѪw[X#ӛm{f9 ,Aɘ=[J%ݵFG7 Ӧ"?I@x,Ò#W/Oc_uŒk:Cw!2&R0TG\}I6;Z07l-cl =Bc"2͕@_FVW״`6]]ȩ f26sw\&a#1Gh!v@FЀpc 8+*&Bf3}SS9 8 ֛y;(_f D BS Ă#۾β*:gWGKaYEd ߘnŵ,|+*iYK:FxZks3L< _j\ 9z_&*H0;xLY &NaVϜ{&D{=.5U !~"Z\6UxmI 9>^&V)Y,2`e<ʰr["NH"0g G瀢%ey\D^CX{sM6(DٗX!']a3U3Uz)k}jv6OP=Ltw%cUZZPI {¤M yX%Cl Q f2u_4ŤM= 44 KAT+oy'Sgin,)Ja0nV{(x)~\ΟFJ凈  iN{6;3,H%W/ YC;9y9.RUfo‘9x+z  ?>t0'`|?7I=sIX8 }pki KD.3^?6[~)Ѫ{ΛJv)#;_)GvqsNlbRh5EvY\a'A rQ*"Ldž-e(|Do @/ Ӡ炌TmJ9^Q94j@3;kc xP1Μ Uգj pa<7lnDlzѨ, ߩ@6m0r*œ2-fؔ >#5\F @= s?COgkSjڛ|vd5|&U|5 ^LQ[z2DD\Hpu1~=&ul"~+PpL|6?qwܶ6IjDL# iҙ816')wc`7?r=AHx ~*t:VMQx[%.}a8V,7 }}Z1-otOT+Gf;8.S1o#zBSMTd6#˅45>nF'c*nk˻ܶSTPK TD">A"/Mj<.`In/be{iZ`Tu>Fpc!g;gs/zKeƣtUH]Cx(eH @Te/X&M\h4a މzAPj-ޝ97̕.wV(:]MԼm?S #uxI,&\H]ͩvc.2־gЉڟ3$nj9<t')^ H7Hu~"l#55"@?42-:(R kw6 c}kd6~+I@~~p[Nc6P%kBOznAYU]p$B a|vYl5+Dy)ٳz0fn ~Uj71F?)qr%_c#Lg5-}i"%{;fZ913޳) xKSEܛʉgeiOH5Z^ބsSAPT#fAU\,(ذ3%4:WMrB|/~=8jh a 2W*k$l*v4N[8g;L :Cu+==jdO,Y '@bIڨZ$L [ٖ }mwCj@Z,TEFw3l_5LGQ&5%x"qjˀ~CIV|nh=y"ZEJmxGRl'.o7"TM"ύDB۹-T70vnCVg3qwۛǭ3oe h, gѭ_r`nSBx v]ݧ{JQ!5f Z" Ѫg%P!P'rהD\=` v xB?/ +fT `00>]m]gN>¤F+ьQFWDQ>k:JTAhAg&Iz B0@2D?RD({kJ^U%PҥMCUUm23ޕq (*K?4j~\,Ysbav9 +n+G1,2;[#ܲTEJGiv| ԅ>څc !?z,5fMt0Dx^V)ಇK`F@P| ~׌>8v~L>%xA#)oѺ4x5)@q8X 9xpE%V/ 7}`.kA0Kڸ6'!)n9ؗMV$XbiKu_:,<{kK 7 g@HuW[E ؃kC l43x@L'(b*?Bi%4u--M>gFe T9%Y ]3p4e.şZ"|6 C"qnÆbir6mV'};k6e޷ ;+ꀤ32֧E]W [Ss>vy{Q݇9]%4H:귺gK"vIgvt3ڔx.kePo&սi/rB&r0xvbg&@Z+@_ukOv.PbS*Q~ HnGOw7^MJmX2[+Ӧ2-GFj"fXyBSY |_{$/u4%2cSzmjGgJ`9n`5g)I/+>*C>$SZaXGSrZYכ0áʾ9TT 0Rn?n ]%&R# FQsYWUwLaSY9b4MIŸY㟵]g6(.ٯ)x97-,ZKeD#XC:̟S-ߎ7<8OiJ6YW_cI n=1>wϼ&u/N S#3zSn ueAʁHi@ՆmjwyǮ]_NqAz6Ue5ZS4)~`]"z)M@ϩxN/'ݍuby諡4&)ֹ/|K(%[h 4eGt sٜ5As su2aƒ}Ul{Mr2#7B,{꿾چ҇M̻w.( $W5>VzTzu͗$֘/}ǛfI?i=mR`Ƽ9T;R젆M<ͷ9]*|l,_88 kԡ]l=%k1^6T0㒳WFr bolry =H5V1zluTkqDd̕9kLtoy9+0ѕޖI* # 21E%ҋ+%X2ءZ? !9eSLRMI>/OU-2*Ej0LsG*D1DΖsR cߐ;7{CǗ>h^iQ-7C9)tzureZ*?n'+];GցHGʚBu-!?08!9z3"\2ߔim3hߦgL9*XXwd~aUe~4 zSAPѫBHh~EͽpE2cS ;2*4ج32h 4BsqQM[X4H]9M:V!G v+b1XjoX~ёSZ&TI w}#1i*vG3eoDEӈۡ;Ktm#: Nxq#%괗w*a+KeFm[F[^RNS^y]e$8aSy1+V-QY,$&\o$~4$Os?-UXd5 oksyYPeVzdtI[6JPp⛅vd н]TwSNj`N rmJc+kjՂ壹=үEG1ǽ:勒/ٶs2K˪LGŇݠeW\lIFׁ֩Yzs]!Mh]x鈭CSX|.5txP3Zۿg(3D"|J.v+k!]a I>Q {E4 r+Z-3H1[N"+uP- uaϤєn_q1iNyg4Xe?H[9P >cP\m5xZK*/rf:MF:ށ]%uQЧN w%@'Ǧn ˳{zMh3B5VPJT5i%Dez76ZC,Ͻ˚8ۤ'戵h`v&))7\ɟF0P)1_hVvat8H pdJaR}]dNA!%9됩f֓x ə^ZF% l6ɪg1Ҥ =>P ".ӜY:/*c"]zWz ؞Sx˺{$oaw*ӸFvqI ?. fCo؄[~1F3CA2v%Sl؝~8W^{1ɶڍR0 uH-F rd'.LA*~Ij?Wzv'xE 8G @P->Nn@vNL1fvdSI=zF#" ,)H{溪{/' m˳ "ƛuM.l6ҿYL*Ȧ4gjpE}(li0D4MߕvўQ(ΫS _D*OՑ6Y4x>2 2SH"TP]a%օ4I&_T96г|"N7pL_\\$B ^(D\,o ڐ+-B5@'EN lٺ044s\DPqJ21Bo6C uҼ*a(Owa5 Hc] txsSfF,=eBZ?}y+bcOEs#tvYŊ"n7 "y):]$,0w:~$uyr|U$mΥ5Ƚ:p+n<:m)LFBý%|$OycG2ńN4Cj 8G}辰n:XAt 6`'Җ4}lEiOSrNLh$([ḰCJ?#B)BL ("Dj~ejzk]!n|["7]^2qHR,ck2+/߇験K@<ִYl!.@@PXjIe]j)!2ڝ[]YtPἘۃI~$V 6@{hQRm EBMw|M8:.tE4!CwEk!1l+㚄GzbXwm?D Dkܼz Fy2]d&`""Կ,UcIXy5X06*KB@c Ii12heZgٿ(Jjj:#NG2%{ 27x̓`BjDҙ&53ˀHfQz^2jvG0oZڒHP=fM"xv ͖Ԗy8$ǸA>L"A&q>YcMW{^RStv968"*$`ʪ哭`D#35NbSzv_8"*H2k %9rb+8V8(ƯGkuV i˰.(XPX$$)o_fUdrgQ&@NÐ鲹JUj_W6FSţU'.VGٌ0:g(éђ%d󰍆N5%}Q6>|^>ı 8h9O#({D2yci@h-]+gӘK045CJPq<g5xϔ`3kUQQ1鰁ܒ:v W/ zzh[Dݷ؄J(Ci fMaûjFX31ƌ8|<{2ĩSSGl{Bf瘳;Ȏ*7vB[*LӜvM䆬6CoyjZ*UP[pi|lywVž?Fb83'?Z|#>~ TPu{ҽQ u\b)rtK& 6/jz\}j.&ĒE9 es5_ŬQbh`~Mxy4dpʉ#!=LFN;^G`-{ŒֆԝX Jl$VyBh+&ex"qL@7nM<,?"g>?<n_uGƙ*C[IQb/է`dŒp"EӒ&sȞ,_b[wQJ#@/n?ﻟQ-Q*ԃ *+ilUc1`lYԻ4@O6Bh`0Bb Nc`G^'t2"Y]d2+G?B,`q;BOi`51Y&5t Y&V7-yx:sV ^ nc.Xϼ@N{c-XY4—Z% nJV( p⓼4Wց S0AWgc6Iмqm{0XCyDlLfdQ"@!Y']E$O vjtyJnOaYک.=n|G,b#g)i.A8$AgQ瑕UWɥFco&}e ae(n\5;Ģ\ 6{zY \"?XAF_'RYz[*Rrcl n*HLV;F$q^u$hu^܌%%Ro@wʌE\Z2,Y&4p3a>]Pؿ ɸ><[y=0\Wm_3koCVfVXbݙ4ij F+˴B-)`$- 8 `eޱdp6]EDd,`t5R#S8rz0ͶT"P(q,=<ٔu8^7_u]~ ~;)"Pޫ9h$M w^ u-xAW2 oSB8aku8?{>|VMZq T#78ͩ䦬(K^т,s`6Ǡ,4[)\|dgE-6+L6^c<%֡Hk QUұ(u`J,^F芙 OM%^}E/٥@pv nº-||?`RNGȺ9-yazHU\BOyRH<`Sٹe|@FB,Ut)+uL0e0f8uڐW*r4#DaGVOAKDhs@52M[ӡI'V7?2!Cn"%-9apf6fiZ篟5缒ZZ4e㬑~#_" ՚p+p5 0fApJw6(2WZOoȾgyᴮ<#%}H"-2@9IBPw"}ˡr9~sWpp%8W rg:mHley{}];ӗ¬-Y6슩شHeQ#Ffz+鑹t0+n.}AY_@cq*H3nȑfNwd{ƆQ0fhn{D޸prB7 Jb(@y*ЫL?s륝SO>:ڭi^΋| Mtt [}UW`]T]5ujHG2ć:o AJ A]UI&-w 不=;2]_[5ܛ1auݨ')%k'%ϏeVS`ѿzx¦\0$b]>quj@q.2~l< c`z yt4| Q*oN_np96y# J ^<^cє[e6v~f(y~"K*Tb /MA1W" ݂2{66Q$Tԟ>a a w0\Xlz$72iE.\\UZÏKL~~#!Bg/@MUY"(T圌{iQr\h2"ճb7"j`SrxS)W\Zm.E+hx4oX/ڐ92vM8m "K/K}4Rġ" whc`q5n;hK+/c"kV;$Me*6Ji@D;6^?͎{/v?/ s.<{9ndj|}$F{涗 j0;; b"՚ Æ$L&\n9xD܇>JbP7߃'ҥ$  5/P(\6.3h &,XO~ ۛ,v{poH]<H'&l1\ H̐sp#kO"q^;#y7&DUpɩ2p[=0HRרTCqtK[9@+F9' ЖJ 4'T&)>œdWe%D*5 $,ys#l¨F u!ϙxF`ڬ[Jj >C}aҵq!߈dWηϏpcvϡz>&Ed;O{dW\ #ȎRs2wحђ9dJcs X"0 .t9JC5UZCwVxWc˷{xGëI%в{geԠ*CޔJH]p$3VXR;e]EQa8s_zX}i.OGlP#W^م0(  lwԗ;=UV5UlQTu9ulZ9">_ZjjJ~\E-Y,x澺  '3RK^_m7\[|F-K: $|phsp'`mt5[ܰB͠ɂF& TW/͑}u;n֨EM_bI |LP-`O<@g8$%: HRx<ꒉ5Ӯݜa` B6@2t},V=.m sB$Sf^p2}Bh3Kmm#+0O:l,I[oU/\fInբ="p£ P Vgt'(Έ`Obc CZ UuS2vk돦MUnQ ,Us&DU%m>U=#[Nl\x;@f0HRb9:L3@|scD8B5t**glZKŗO%2-V9;@FqY3[f9@EÓLY&Əo+}pE+w6*M2Ƣ-u,,qȴ s$:̖YS@z}Ԑa}9r3-D6wd) 7r&Ra* $ju!"(XLܛ?l]%G4ʋNlKN?i%Tȧ4JβʼnKߊO.Q>DW=}ZxDhKԂԫ8F\ri XsYF4MٹTS$$0OZP7gZ8!CۢGnqlixJ4KszU|g 3dwZEA+sww=PeUCSenÚrk%ּ`4PO~Hnߙ^DxY؄ ~P&l e Í͔2YD~+S`ZrbM2YRv[ eW2ob4}gRɼ_ +#f>F֫P})5hLHCap1H&o ޽ l+ɟec4t/crzo#9ϕi8Ìb_K-8>.:"ͬ?"AF6urHժˊ*m*2h3+@@u:AWC&Z5sfvǍGw ]jwbc ުoJhjfϦ)ef n8G,mMlNrWcL <پw AaO>:'_M3VPlc7%=b6P5p C!I& Dh X"8QK7bM>:\^I/)+.4x"E6tO܏ -*(Dfom?e]k#/,}[5T~D]/PSwuJ?a_KVgbl9jlt(LpȂ weAjz}m<O?XhuW=8*,jMK 2-K(=|H:#9DU`@ӵFx5~*ȵ@a݉vӪ\6/Iko#[!FB9eP=Ql@AK? -AM8BIݜLeC :_ ,CLo,a.+ s>n'-cF~ET c12S3&'ƣhdo&v5OT#KMs|7vU ╧κ*cHUU9;~{bM0`Zy TbCCZ+ m?2MO#MN$$c,.:'EvC*Grhmm+2ʎ@Rn2dʐ8#?4'Ө=#j'$3Mwp {AܖAepjXBma˲*`T1^~>W}KgTȓYKʗS edTHfY2 eH™ӗ!g%]@0Մ`>_B,3XxbۂO$ K.cHV]%F|m\%o_"=n.ܕ3RZX!}Nw xӔ̈́T& ƶ\U/bqKY]>b_ӡE:B h[\hVl4In<0ۺ"#XgOWY~|F8ɚ rcyzY=}ֽA%WyK1 IOGDCclf)ģtSg}'Le@3~C`VUv(~ 7FtQ$]iMokD^ &j-t $ w%☃bxXYCQ 6.^ {01n+1DmJ<KIjcs +?}mNNɇ%<(NS]^݇vU8RZG8ƒQt^V@fB oUfυ9= &^Jo8/<p< nvoDmkV}yc,+yh?ZUɥRVR._9jB''-.l ؄}eM?uCUn +e: P5+]*B4Vh&.G2׳pJhxW-f"1N*=+%26-#K%!UzI\[,/S+Z4KG %cH< OMӍa@|B5l,wqEYJc;WoNc0%qMLjI4Xqd؇!+&N/=|oLSk*؇U67]mAжxH̀8 Fݰ _ d$ λi~hh8t~`D1<rtZZa yr&-cљ#.zQ9dcDV@`7 vv<$W^KTG"CUyi'o[a6ݯ3xx$D3J-+dx"Ty)y95o,8oBq] ˧ rɁKTr7WJ'A1㮒S~p?~BwD qm󪷳m 3R`!_{e2RX#u*L?}i:Z_l/䮪;Dz{VG[`VJKӓUnqf?7<6SB _V[XGGL'l*v+Jwdzi~i+}cBA,8JWǩqZco;vI ?/M濫CfHe},F5ƣSprw*.p@c2.@O `@H]'"< םR u"?S̾te E S,D?(o*`Y>wk$֭`A!)\DrbROi*r3l'H ]&+KSz%1" rIϘYֽ^5{XWtSV$;૗ܛNFyM!3&{X k<ʒFȩ0ĩoUP` I ޣdrQqO|)npKVT(8"KY}ʹ7H}>%a0çl)l+h:'z }Rh0"&ܑ|xIp3i1]@\!y>1&j nV>?,6`F /QsOF:JM`MO!nqmL 6E 4ⓟ_eWit[)b釔%j1 uρQ~ fP=ڢeؿ>$F( Nڻdgb6p]ДIrgFu;`rf. P 84avXf i=eQ@`]Nip҂dGvCJB!Q kCH%FwcvhU.h |O]?f BQYG#SkU_;6f{c\|fP6UZV>pD׊뿉Cl0ߨT PL^?x\gA v,t 84K^r*yYY:8kYR\r\^ڤ}7YDv%bWa6Җ6B cYƠx>[qm{zMX[:F'#(s\BB,gpIBNo<]mp~zB&[sծV?%rÆMǏ )?T{օOp G^ܯC-1Ʀ[< 9BR*V^^&.c0*_V|FR%DpXJkm'W7q9Ǥ^5\TjPVfˌVi~i\zҙ~?ץf7IŻx\Z+0}S9UCE22{F.6Vo #=3Q;zűKj'`B6r1AqKc`uaR9,SNVsV݅- ~Sy@/gb_wmʼnS>:{;+%$ a! I6nb0Z | !YFUU`\jNkijh %`I ᗶ<6pKJfI+ß@<3 @vlqܕqP-0XC6P'qwp ƂC\ qSKԇTtgU`JDb+?G֝nHwL[./CD~&{5 ͤU=Әkr"/ta /r7SQɯmML[0 Z7b8Rfu6iV>@yPa )DPW||}–-N5UZp0הWPF|$ N%{޺Y} ?tN\b]Ԁ9T&o|6] #Z* NHXO% p0TϟӽO`Uaʎ m'o^۬T8͢a_mlx{;;k!M6PXv-:L fd(ܟbj$VkAlE|AJJ ߪRt!,njLNIH<էHm`d e+YP}! 66D5qv&0Ƶ3~KSK~z7Nޓ%^Hdtw?P>h$$?ոf)i'J=*xK}GE5n7bȃ6.pH6#o'18= גG&[&`ej,K6ݾ\ \>b%ztIy`}q/SEҨZ-뙠9Er> /s#'>IWjtDdfW nI/ ļ^r$5ISg'3Rii#S~ؾ%}짠zЭ~q" 0l!.di2[V'U}(tIq8VX5Yg9j(Ņs̠*&c3sȆ(~T_H u;`i>բb"I H˅ ^Ҫ/}98uR+|Eo9 2nn \$y /d2N9ȓŸ%w vgWi Xf>Õ Va}͵ `wDedGec m<଴V>sʏ - `拏F{S!_bwl@YKxYIUZO;Åa5 iF>k$Ղj#@wy]Ҍu!`guzpؚI<-B3M]`Z+gz:s^'m2RbC ' 0i1!BRMJSFETKUmq3Q:/ԶV3V4# dXczѵvZ⾸w- Ob rWKtA*U<YU?4}9AO8IpVjȌ֕Tk]CuMD꽒PX]^ky%Ŋ3 N؏SiFeᯡZХ%9K#iPh Iu[:EdS1qVt8|RvY-UX 3̫?)jCt: r30^v8G‡^R9ևްqyrV}A" ;uA9lK0 `isj7cx!X&>E>^cDۓԋx B["}]6>&ɅLN}ۈy4dn ւ2w-ٍIYࣞ~(KILk mچ܁6wp 5R @"L2sN V!RE{9> wxLohJxk'R(]ҾγmU, $JeC,|I'?}"o `(h>kChl0*0ujD].]}.t(ItOC$-{('ȯiF~6ms6V'ЋG/soUS_75%`#&8~Fpm]MCM-n-t}mAq{9S5z]{ 7ow@VN3ԵTA]^:b x֌K0^ 2́vaH~0-rӪ1?LZ mKO0pϠȝB$By<><!9)Rui_LIX$]+fl&©@Rw:{έ:e|o.l_n*W(IN>@-Z~E{##;-ړm3a7+VԒws٘"[F%7[;.Q) 4s'T6S=f91I|qH&JpLc^âAaAl^KIFXF"╔Xoz3-#T zlKmxېW0 G5gd$^[˦LAM^tԂCd! jzuJ=ͩ |. |M?'urtB3/ %ﮞZiogi٫PY*L0f_jyWC#l\j atBBxT ^ 33_#+@~8%j{QP>l1ʔquvM+/IG`m dZ"FF. _}NaYaK0ƩP^wdÎ%}݂tQD0U{`&#o#ZJ I:"_Xeߖ/"+(+ayHC/F*weFfqxltkSGDhً I& Y-B q.SE8VK.'cm\8dr/+R՝mМp}Ph-u`%|CZ2kh30|I4 ~%JWI=-f״;ꦼmeM:l7pPosɇťv竡/Нط|{}U@.#nUZ-j?]*,+$"i+ 9xR^y^ nӭ1V 뒹CpIi:cl 1=i^PNz]Bߓ۠ݚ%1/Ƙ1|]-B'N~D?{7i&|սmcMoCj覣 Gl&j4 F. +6EMyKC:ycv f8.#Ctl'?M\]^][./uPOֱwRc_yXG~4=Z.p0ˍ,`>̥kBUk ]>bjC:)(`aykO}V.Fr? 5&8+X~YGLຒ:.Wɥʰ?Z˼hti8~ hF/lz&dxgk|+Wy5kk_V{ QkAY!gۡ$+ Ox7A YoVC-&XT 'Jñ۵@_-vM6$^< !OXI)oT)FXeqLW kx,IX|BcЇ]HvƂ!V1CT[s GbbE ğT vfgp7LbPqy?3.֌AcO~AUA^+srZ"OPe2xSϑr 5-<5o$˫ׂ)k| q m[uyPq]n^׶rxF4bu_\^1Ukgسf9bÝs/vዥŠ~{#E܆;^j",hm.rHfRGy^?vNmߔ Q(WD>1j/OaBDP~ Ҏ{,Vxt&w=\vl=SnD;˄-xQ~8x@܃* >#T.~Lj}>X8r-`)ϹGI̩EH6N 0)<{+pǓ׻l׾.ͥDua_9mM[0 fր|#o@>~^Ho>||:"W d/6Ø#ᄆU3E}v(ٙ e*lut{`r7۷D)OMTe^UOJ|ʃ87Q)fkMO5# Pc^|t .3ZjDXæ >r~ξi٫qq~Ia?m{*`|+ F|o؎iKV<4v];7g;THR8~켤+HV&+Ct L3()H@pE=\dcCh,Hf3,Fa*]g/,yyn ԱG" p1K?3*&,'cco~CGQS| ;y^f FS # £ % % ! ]bMFҙfDEM׶8qՐ:]^MF}fnswz<~80>w'沊!!//φͷ>Hsp@)%DPRHP4 @P2Hu?S ykQ&TTV aT)PZI|cfdppDFGD ?ۨFƏ{Q7s:q5vI̼:mGÉ#r;t1w 4ƚ © .C^U!T&qϗ!6{dS.xXd:-5~gǍz{q J!mU3ݤ OM<^˱MrEB H΁eg~aee%Ǚ4~Q$[ 4Y:O,f"SJLD >ڟ~u'i2ewxގq]&1gk2zl!%a͢wFBtP9 !ljt:5,Y|fgU7 }l\7l>Ȃ͂KGA{_*Sm8+Cu %"QK}{w C6!_3&Ū x(/G(]-uX56!EQqD?T{1Q1W%=OPnf5g^Oe<غPq9Ч=&@ҥlP+V" RS]Mܵ/35ɱ M%RVJ΁zF/Mg4<Ą1%`?9D{ M C}EĞi^]u[r2nu ,U`ĨH"d/6f%g"ݙf<*o2kҠBC"(k.0ݩdj5! |ǥ 6,wT1KjMU ҟ{_}=57J@)+܌;]kX9Ĉl39 %tZN|1$i^MC806@ށ06C]ML/(U)@ CFmHlUPl-2HA<*L ?>M<\ h<<#fyS Ҹ|Z E$:A/;Ba ^f1Uyo@i4Ո np/ h%@eZw7=$H-oUN K=l%k2g!A1_?&fXi 0 f50~.X|5wN.X HY%Zf ڐrnz]0k8'zO_8=t!@Yag4ҧ̴,b9Fi3j)#"7BE>찙&no>^${+ T!]٦5C"Z? vS`="@HD4%fIl3ö&7fXvŝꉢmq:I.`{_cv$7T0o> +JAo v5}U|Ciֈ8eH~^gE}: @4X &.%nAAIIILAz&h*d6(fʦR5U@MIABdʁ[X].:5:um%qJB %}~hu;̇(.{kAu= 0N U<`F%$IHE IfdFchf"!2b(JR$hH)ZJJ_=cv]7fl9Vncg0H  U)O/{2Px[G5cc97K"WH[{X*1p" =1CB>, W9ljI-끚bX>PA2 =hs?ڜc_<ؿ{ґ|vVqGݷC~%"UbgGWg#6M|ǶxUB0 μrLōt2dޢ0!C!("=3r7woV )[q7. ƐE07}>mǠP'ͺmQ @$ I XSn`/Cv_CdWd,)-ʟla6iq?{h`lĨ!my&u/Ēѷ*X\pyy۫ц2 2380CoYqd9hh%ݒօP=[ Do7)ZƈjHQ<~s>rGvgp A#JYCl?'YE8Rm1OBy $@BEI [rл1 1*-0T;CҾhj!{6H>"J)`ȰQTws˫Pԏ@O@x,}RfA =$Wxe$"~PX|XOxxs _7ED5J%؄6#]4#Hjqjyһ` ǘZ|IwfocuuH4>vq7FXJR40o H#0wsC2I؜,1Ru V.0̂OT%Y2̈ '.r+Y>/CZsW!|HV bx/=x/|~MZ#Mܸk=>U_!M?~~d 6)PJd)̞itps~ l_~AA(4Ʈ^gN~|H\ҜKa9y?0Q$\LJg(C6gf`3}~׮~ ox%R6֡<<6lc +a^uf1u\٬BoB#ŕ'Z>Hnj@`!mp#=)1nLFi7n?ct:TBTop-n|5f?N}|(ou>]6TƃvSR?Q#u/ ]qT㻛Ok\wL]zڼSo?BU8elf2U~'џ DY2U9Y^k>1"8||-wHm1̱})ξIkfhb S \|zʽ5,Alԣ ,۫?E 55,(g؏ ~j5gubek_n.]jO7/K!VVР ==]nDmnpOh/<3^!tFΈBNgi$P8BspNpq~wWbs&6U,&a3&aB( D"@ )h x̽p  dE ,M Ц! b(d.KwXB `)`'ڀ(* iSB&p0?qbp0F "!\pM aaыJFL0WCw빮oNܷ)o1gcCC!C(1J*&y҂:"$*ţUI/Ԗ scp("[01DHX!|7uMBaX~v1HdTnv(™! `q-JUa,"lIIJHP>&#.E P  0p nk+@1SN#q bb! i$Հg--;_8̳])rKd2C= W<%ȾƗr׏OL(tWH%dJ< D߻H32IZdWz3nt\мagr }#t;}vf$1d>Wф+NVn"(Ƞ J !B-*IJ-%PP%RP!@44)H JPTB!J- %PRT"@QH% ҅(R@ LH4B M-SB!B4H!AJRMP%- B"RH- B@B5@ЩH#JR#C@P(P4R*RPHBJ *P* H J44EUDLPЅ M B *("!BШPR"P@%4P*R AB4P$JB+AJ +TRH(QUPLDRD@LO @QHHU @BB,@HBU T-)K@СEP PRP РҀ?+ Ȣ |rn(Qo7ʻXަU;voίW;|4w){+^)2J f?^GB?kb-@k?Ѷ8օX#dOe $r7Wݥߴ= G'0 B(V:XO8f?8ׁ꼾H0 xkb lW*FY[ ,kf=;~4d =o&tnZ_Eb!b_Fx7PFS{ sl?*vg52՜Bfݭߋ˃P77wYOnj@Zw+6f~eaL5>dEܿx l g9#h|W̮7I VPL334.Zf|6ca r|^L:]+Ɨ*!EZiDGuZQ b&;(Hn `MeGȍBduY.bɀPx<*0/H HZ0322( k!hri*b2 殹4A+-ooYBJ/Ql+vXC} uo,|Oa`E7S@Kx* 5lQ.V\sbe.wѥGkXAzpǍ? *IH1'Jx9,O*|A\#.g73c3_ffs뱨\f_,x0{cj"k iB ̿ dHP:Qf'SFAf#d`"dbeWwM&V IA@ ݎv0 I7?[_cTƔ`FbOzLUM@W?t1 BDd^LoGǝi\ⷠ,$ԠFm($&:a6Ih]` JH" PP !a($ zm ҬP1f /;7Hm*Tdtb482c(*-HX=L` tZEˀ\T7)!1vڴ.ÐS I!HMT0d`b(" 8?( .Ґ\fR7&s-ORhW}i, pZNa.]vkRŔAǠ}aT!}u)6=(А(t@B;Kѥ\0I vijRQ38UMp,NlAZmԴJS#&˲2 RmӪ2;h PXXB90t2@D`*#00$LN90J`GAm $]îpR@Fц@pM":XR 7fr@LШПL5@Ш2ѐqHLp{?u!~gD%6".ʢsWaK8S\۬P&[ Lofrfń y+:i+!åձa9ΣUI, !4H6Xhم 8`&`VlF[*k`2uEsSb< 0XDu.t ( e9/͇475`MuL!0A(lN6iHhK`2 tQv^Ȧw$6d64:h4cBm@@,\E2)BL胖./$2ff!&)F9LC WDY6IE Mpc 1BUE$F QYѸ0 Rs`4[lkiiژ -i=lQ uGXCP/EL%s\VŌ8pE caCI`\ ÄyX#P`c P0qCU ȣ@[<(lD%akmȂN݂p^\,bhm hP;9p;)24l Iu`M@`8`9M]Ҝ'qU -d&cw 9LLGVjʠbUDP50+`l:)$p!ʬIQE'B"y7M8qIBsN7M`Ʉ+zZU݅,V\ S0Pd!54hf2 H"CM$$V0CHXRVHaؐb7X%9@5(Z=줖+&6NfcmG1x!C}>4?'~CuI! E~]<+~>r8PV_mx}ztXY9J<&.b-\؛E@cIڍ)F"iBȴt~S }bGX m ̨m:BET]H҃.-`.Uuey}O3_d{'ZUJ!lU80uR)KeSccF .`jTZ Bd $\F\vI}2en =ogEЍ Pe>eb# ݎw?~}i;= )ׁo_?fʶcIⱐY}'C#Ǟ=Іq/}qA׫G۪e3N-r=? 5ʝ [T _0ҔBb^rA?Mi2 o+ZPm @[Su9Et <;3ocDۯ}=߀{>L57ArD/zgEdCpJ O$ {thCPd }=EB^ #M[$0  ݠІhM MfT Ũ0h1 n]!m!F[Y!!1kWW)ƴDB1&C0,r[Czr(qeQ'͗?Ih&䨄)Z65\:Vj lDj6ٸ8d e#;"<)kγ̑6)6P=cffMK)Ff[42B#ѭX噡ݑA@9ib+N8Mփ0ȡLR¿\qZP@Y1P)(6@9UYAsekPzcUV[Ihnqjʃ ynD8!HvYЋ0F+uB1AqlHDЖdJT(!00l3BvޱP$9*RHL1pR͹qvdiU+J#$U9F5Dv6 :xV*hj,) HwՌ B]:aJJ f 3Aoȇ |(TzI!}$݅hn3usɽ5#IHt%vN8~h&2P*Z Ʌ5 #Tcf}( <`KB<ƦXM@PЙIJjAh (&m^{<.quE*"@򜝡2TODEwP*.Bh:}4o` 5CM GI9h;wIY% @RҴu|OfXTOfo3r3GQ6b h|}x4@tQ5)/N8?. 7e  FhP v7iS'%J`[U8Fa7opw#z{E%W k &~oVjb6Nd(!_yZd4Ld_I-A o$% R1qi @޸)|ܒ_a >UryTuk r A Q/to)Rf֎ b (@22Pj}M`;jrrM6>*Ã`,n u`{ر2~6>hotNESd M!H__]{' \D$:)QQn]W:؊TMi0HC$R!ǧ #m64Ou2syw"e8g`sdqR A0#A p:{-XS$ynif|U˥QHzv* !?ΙgE?f-9XZ-̉Dwٸ< *IrRԉ YMZɋjmc`35j0뢢}Fo~}x!, ƀ̇Zʫx3ݟǁcG9>wAݶ}MKۮeEJfE $q:2l%@Ѣ4uYlG?Emaq9L3|kSxK 2i=`zvq*>y2ZGS7'0jO\a(i) & Wt=/Dm r  XCȄCH{{h*?āhUQPx" LlGYz~G{mwԺ"Z':.&. zI-h+|ݞGyh9䌀(Z u T1 6~{) 4 ]${=l^TV7?c9Q^wY1Xͽ͒\:u /ZW쉓]t:&™{}. ]tvֻ5=Z&Xl`2SZIvL[m//~|9tkV0pd3M)l) 25jWF`0lb?|[07ce\}g6c'vϗgȍ$DCd[n"`8AC^&#@k654˃MAq/q_G\b)|A-Hs/rÇ? {8v7ˎ Sz0w N!b?1sC*,'gU\ϩy?l{0̃{4l%"t͠!eߏ *&0|_ 1e(c3E`qZV{D b4]?,VҥJgj5Ye)\3MW+a+Bz 6XЖ^OéQ۱0XI$* =e,@Dol訁 N >4?[T*4:1Nj1P }uya9Ǡ;4]2O/ K`܂si`a,́`C%1+  6fDԉqx.H#b}vS>/r 6h@ eprCj]o|\-D@wQaz0#͑JV$gS'?_}%$u2ci߫&˜"ryk_IT} iH L!s'8l6zoٷRPK@B%! /n;lU Ȃz͹!La3q~6第K3D>@ŵ|i_^:+:T,x+Z p/fU-,R$HS|i~-Qesc`m o1t.E?@_sc硝A*2礄:'!.R[.:m !tDmjTĂ@[o8\nQ.cKi~Ve|{[`P^>.ChxXq Pe`#o`í7LōzM^L^f|DAaۋEm6?My|D4Nt^Mݥ{m/Fg`2fsfj,F~wg*޻pG2>n4]X;(l'fyCK:SRzcvڵBSk2eٮ>ȧ" RVHD@P22`f`af>x1,fu>sqc?Y1ܻ㒭ゅ 2e"$"o< a\hSL: : t5"ikyVgYԁ X=4$a8y8!;E1L:ޝl$??{NViRTytWƘDbc?.葌gOn?΍{N$v]S;!GR[?-kUJZ>Þ}X-&!&}QCǩ>&%MRi.z|{J>*h 6La` LrVDCE A+iRYP$)IFԐbz&(i0p Y L U0Hu0nfio& :YAYRO>NAwmё! " FO~^Ki[~\~e1ÈD3$P!|q&SS܃DD P@@ 9?pg)J#ҍ.!?./svаΥRI`dQ@ߓtZEvpE&Cty VG`Tѻ̩/LB01洹M8^_S 4Oɇ`K fO*wzhVOrX$&LRfGh|4~i%I"ῂo?*#iE@\x oJL>oM<0QMR?Vr Aeb!m?y T!BDTf- l`NL. "uJ?Ehwٌph=`-yQUIN\7u>D6Dߨ p~KP0 %U:w`P]T[@}IdP:хf;r[G9m= 7W@[)4ѫG׏Hm73.XWLJ pý)a">:ؔQC ;wî:wlW#@pv~P!8g;޾R׀J.Ͱ1ts# KOmן^n碯.ĮZ'Q*z"3_×k..Y9dNjφΙkuR >[sprY Lk0E &c9|#,x["{Le8 5s?dW^۴}JwQ%Onn2d3`119@^QԽy.~m)P7A{~ HbYb$&ZWͻ&wIkP_ ,$?8$ j 2kkeQv$N-l٬_Lr#-uWʟO9;7M5܏(ܕhcc\쵺*U })Lt9HPو]ØxQK 3?ҜKvp!nnm{04^l>lNԧw k2k@kHPf̸<:1A)"Px>,6G ^ B>^T<;xENP9^DzIkVKNn0EW eW ~L᥽"u9s>ri,o8Ic-Fj^KF·%#A}S8#I![,woNDqZaq#C[Jk AIkdrLhq;) Z]njѷ_-A2D6oM4ݤ-72YE󆣔maD#ϷCEC-%A@Ǥc.9F,NSJLnwBCva̮1ۺF҆O=B DxU&+)y XfE{q=~}8p^gh>(}Jp҆gоj_fi\fNkKiU$NU&f/b()WӢ9T2 ۵ h]tt9>pCFp4ԗV,K۔n~;v#(,鷃xl+/ϋ6nnz:u ƈ ; pH1FߦIm, xqbT\V>;lH(i&dśjʞ\߲l<ӧ>fn2w  rL+ayWE1 <?zE}` .M r B1=9%Ɏ+ћ~ ./a@c>VD|/;I:WO0IQ8߇-?WN&HkvX:,X.n_zMFy/?#G-?Sv~^ݮw>|8)d%ۣ`6J0ܿ07&P"ɱd3~ rHF&EK}7^PV,ItvdfR>R KBD;cI?%2K>z;ju;F4E} =4=0m5Қc5XBUܜۡh2}Us8^ǾbLy -2_2A&{h/XOd E vJn] ޾̀P A$ݍ%*J)e*E,6:4 ج˷;8Ş=3 Ͼ̝{6<m5akgmf8έKJ];yk-Iӻ{E.hkU:uU͇۽ݪto9=vnt :롻[wn;׎MLǹ(>[(&@kON۳}ƷXaNnwy.aԞ jJ쪴WϾ!\}X{vW|.8t %$E@$+t@8Uvh:A!@F| _WNY݄}ٛ}vgƠt1v󽗀$놳]D%.뻬v l+8}{C꫾t*lzcuݩnjڹѫH^N>=T{}yfʗg籍WnWRܽnν{ e}瞳:`t3OW@x综lҍީxƃpy}mŠ}rxM+ٯ=uyz+Go{hpUe-^{kMGOQ}(}ԠZςckJZ_y׎g ݲk=t܆l9ZmY}( =|GV [xuB*JU#GSVjkמvl7V+͠;޽s덟]Umf͔{D&Fɡi LL&#&i``4ɀLLPi @& &ҟjl&I{S&'O"m56zWߢ@-dFZ-ooSR>;'EEw_X(h=QH`@yZ|N\9ī=_+Tkr\ٲX"ep;FiP,R K  j@ Ѣy5T"ps9h,hsy{!rMml3 : b[05 !BjӣAf@VM5Oo!ijIp \֫Kq|b]d(B-pm@, e)xk,s+OphĞG/o  0Q,2p匲b{mF/̽Y cm~m9h4f5G,[{,"~Wl-K3-SH.*̳01}Tv]^4m]h[4PgFZ­f56j "de`R"E if#9+ `UX:,A)+4N*\5]/:.6 PZ4ruŘX ˌϓbfʦב8c6LNf3!sj [P5}9h%7h *sߦ#y ҪYYYi2pQTح/UmP[fi[+][As[-ʪ]y`AՓppk^?;ky9gjmdݎMuYLH'աRfu4 =ŬrƗ:g[K/sF% \u1M8U P]XmxR¹=U鶃-Z˥ `:\}VuΞ&*, FL5[[[_u[&:3R̦ϩ^AmY5MzW$a2X+U{0}Acҙ6i!k6DZ+Vnp5[?'d3ʃ+UԪV6퓮uC/m}Bbz89T:(*zpe-+4$nֶ`ѕw\Y{\װ2jLg6U nqEUYnVM`qkB}hDE*Tr0T0XpVA[dU-PFX9w}.! aΩmno+.3Ƨd* BJhɺFʐsNCCJmP|:!(JH$HVңq_oڧUmkX)R-P֋t`5"%kaK1niX((a( Abwtfwˠ*SUrB-QV|!2CF I-NFJjqgBƽ0JD!%TM+?TTj EF;v=mUBcgO;My}ǙE'_jL|ζVF֥SRG >Mj-(^je]5m»VtnyFyK&UBj+Bfu5+ZEEII*&HjaA2(a:ж;UXUVY\uj"RcT؅M2ƉEBjL"湶V2T:pGDV680\MucLTLOeB [dYmԓAJ[欣(|(WԳ`C*QcՒCBUBXEY=r.ccMs\y-*ys)i| u3Y\eLe*^ՁY]sRș J51ksJށVIj]; em++fh }VJIu-( HBsED>ț& 4ac|Ա̜Őa/ub5y/Qa'n}g1e֨sX aPU9 >,sc G݃Y&?;"׉L1%6̳ % #W2#)WZʵa" "qT+n|gc_,S_; e`Y, ,ՠ)L;N[땕10 `ǼFŎ gtUS`*[EW1nW[HȂ+elP Wmpa[R%E8I >z',AQ2  tf4M8Ǜ 8!FwV&'Ay,څ(baqcUse7 @@f6`@Unc1ɬlģz4Gꁿ\" p'$%'~To6vrۯO*pאݻPkFTa@*h Dsg`2JU%=sDH9IY:ŏqH &ȫ[3@NIP4s B B-zOBAd_`eⰲw6NG6t5b\|/'m֣zP5L@G MF%qʜep*ضgX@U%aPKIa;6 /W p)e i[%5&gJHÌMyNrʥp75CB^~ĝ' 3vg&i@/A.(uBPPE+-ZiҠ,(&H,$1~CH#'r"9mKW' mBCSW^_N:a7f9+Hvjj)_X 3B k~/nwvs ?{~O}YN:B]ʻo&$EdATiRd[R-&':kBXeI\̋ExefCHFY4@$# $$^ÿ@ Sd{=׵RYat+!~s2o",v衜$tw>{ڕllmZ,D_E`Yf~ Yi;[uy֤,A䐒$=ƗvsBt$|.ޡNODr~jHTOkIQYPU}ȓi/n}&ݘfj.`cF, &ŒeCS* ,CNekM Ѧ*b$Y@3 T{vT==(b0cWN1UKjf@ᐃ_5C JP)qO _nV( f5~Rׯy~3İ!J1 $ @hih 6,"Z4,b"LjtF{EX2Me=7%13@`yL@41CBf,RD!NVHc 焦P!^x(0w(" iB"1TfcJl"(!X-6jtI0$Nč$lF I"4vڷjFƉמb]ym^zJAGM DL)J.LByH^{Po<`^-ddјc_? 1Bi ja~EI"Ĉ^^[wM&f6+$jlČ5MRaߖ~ţܞtoЦfHHEL_>DHɶ M)HU"Q~Nj{LD[!_W7rFfIAJvUPgYvfߛB=I !#"3(HHA4gU{ Rag{Fp S%abjVWF d%@Dm1WiE*QXsFL1(ƌ["VKLpKmX[U-ik*)Kfecm\ k(#&ejZ*FQ@N]f.%V)RcW(lѺ`m‹ 56hɥ x;΁ޮ\wY ,uE*DT7 (+OHL+].˝Bɮ]֍khXRb#ƙe&YLrl9A$9 b,Dkr)h15 L1cTRVDr%hلQ( BEdE4;a3sD`(OKbl;!n( *j)ræ"JE1HzE :_[GPz_]-.O:w]&kܦڼx_V ~,vtH6|=ϗv}ټnsh+F ,uoM5Kv,_Ym\jK 0X-n>6nA=;2DQ@,.f]U_`Ctϟ( OȐטKv%}Ŀǩ{0=aJ=xfđ#l[5Y"Ų%hl( AAM0m*FJ)4m~7')SXGH͌, ܨ.iMI A"D}DXbYjݭTХ)ٴDM|>B)`PhV}YKԪ5wO}E -2de)4( HK2s8U FDB1XȲ,FJPs'B.Lj4ђmu|[e Eꯕ97uuKYir=HX TR3-җKn; ;DM(MKe5ݙ" ᶶ,K.o1)Uf%{FDAX"SNtL5@0 dAL$I4Jlͦhm+M6 TZhv&g# R# ?˻Uy$<0-xz^8Аh*ƵF-WlojQfLl$,d 'z?2M/_K|)0UuYDrcR[ {Q!ΎvCtjђ &]:.KE sja|=S[y[}[ˉjl&PMj$;᣸_Gmo]4eӁԺ@L ujsq h` 0qrefL߼9lJ#huhw[u݋wvO]$2 ~wPbR~JS-b (Fp^>_&z]=}0FŃAek&S( ],l$$=!0E"I$/wi1$E,fj{\ qPXT\vjJOV׳ښUa6 nb̭, [$!AU2HL֬0QhY ,,Eѳm_ʓppyV#Y fTBI\;bNID"2$[j[6ҫ6ЕfZe4T*AH 6HI}S//iGXjVjEGjK|>5KѭV+E|&a<;8b p'|$b Aq8^)M*( rxdR˟i Kt|_z^dƨ`VfhڌV5Il7).&%edXQ`;7퓌+6g.盁*<NJ*I0R(0쯧ٖt67w`DAD=UoȲ᫚w>' cZ2LVT 57p,E7|WwAzvdey;kh1$ _~: DV7(iNѲzM?]0>OPVÎW"JTF*dKI"9A9vDi}y_#$Pѩۊ8Ei:E^ʎ$%(B)EF:6EAڦ9s ZNo>Hb͠0sG-Pntѹ]B"$at p9"Z=ͫݵDIțaS1Sn^I6 P>s(jՔuMЬRuɞ;.St$`ksKθo,TT`;Ws|oDēŮQi"DY4X2M׍XlYo=̢+(ȉʔw}o7FHח "0WaS[Es@yЊͪ4С=LQ#4 ogDRF@^.eagyjC:lI4&)361lҥiliVQK$%4b&Sf,$|"x3O[Q p/R<^/\ =6"B#7BqbA\&kI҉ʾY`rȖ %Wdކ?V~1o*n=Vn_GW2\Ƚ )v>.׃GNuKs5`xa[kQBwǓ\,Q2W_?]'SNegY; d*j,EF) )dIHҢ QL_22IdZV2*?48!+2Yy"HSbٕff٦eEY%j/[koQ5Fp12;@Fu@վz4WEr5͹l)]7 ٮXܮhRh,UҢ(qo{[\;[Q3 mm%fZKBЬUkղm.[@Pd"0Q6iK _&aeA B(aÛ 'B&xƲBH:L]N8@lM/n*M0mbTˆBFVtKJ4_'wE A=}4bXzPh[;]1ōof^7~y BrZ}y,mQI"# b>uQ_fV|`s{}> &_8R8as2Y44'b&$5-~ٹLnjfm CddR(^xBM <۬q6+ H=agFlU [hQQjz=_? "=-JK60m,NvF@iJۻ!= yox"jU^)( `㻻t$ƈ]H]Hy|8d9u {5Dnʥ:%!^Ya ''\ϯipcU{M?VCgMW~Y.̐:I)CVrtc fմy&bҝ?&4*Et8tw]i,ein~ooj^MAj]";0Nu5*uK*=j2i34vR" 0]7.>}p˄ UUek8,J6Zpdh;?I^$|x2BFH{xA0ixY"|+<cI 'n'W A$ڷfb}wCm (H88K\4P >[1(!|LQ>.J6dZ4mk93t\RR16 es ݳ W*H2$s6EIfuJqOS{Smbi*CMMkR$6HQ FJB;Y.$@5&. jU|?uBB B ]֨a 6JE"Kվ8$3!ekSl0pHCf-u5.,H H1F@ E(A?NύzkWC^R@{;dBLX$g0fnImA?ˎnn֞s& Y 6#H$ib*"SlC&Im( Lf&70QP1-]Xc^HHqEbM[۴ ]#080Hq# Uh ;\p @$Jar(sMdQ$U e6i["TMҳjMfo/v_[#,Yz] (*FHaP +Op))4϶!ܗIwҽ&)aRRTyU/cMb6!hQ$N@/vGx,vvEVxyo"e>襲(5-Y" _[;aX?3{gQ*f{qve(WemDP"Oߞ]o=fJV0!$D ?; =$ff瘻D~U A>Ws:MdU 1@Aߟ~)T#_?.w4~ZjkUV,~ǚ6Zia(g[ ^^Hb#6E'^FF$ŨEITk$4@twt|1Ol f.^_{m7w cc]l',f +G µ-U5lWn)d ԙe#j!@$IQV)E3Q fS1|*앵hXdmmlڭ  D&`ǗF3Q7*A"F-5K ܈e0DcZM1 6_G1#Υnp1MFm?M[njO&(T|5m}UM݆Y>hETT,6+;Xo+Nr2F@,8cF@1AAXoHN1̮ xضR۔-by߄EWnɓm2 Yaf[K7ç.}y<Mrٝ|&|Y_r)_~u4&LIHI2𘤃#0a09Ŧk@ A֡ !]&Uk05Hw2_ \xjl]ck}BmUGJCM1iduP7V +4UP>bkFjm5-%Rkn^r1>W5flZh}QگbXJS,2IB2YYf @ȬDvRkHwG"! iA/`FqX,iNL6rǰηjh,-o.0 {VE81!s݅]HBa)) :d42D(QO7RηyK4(8x u@.\ȱ`DÂqD E]#&e$Nl̾&穛]~^*qc kSp<.jطjkk\uST Pbā` G`auA3l2lm~;WJPD) \e(RN $oce $H!B#"[2x8J rÄ^!KT fq+9_7RzsXxiXʩA[ֻ-pqJwcNޞ\ף` XV,Ą08.~'XY$$ !()FmC^31`d8z;')88 #$X21c C(qY=kB $۩tsɒ\Ȝ=v;-;9qc= 9GD$Ў?>Ianʳm&?^"QHXxMmt*\4~?[fVkud^ؐ;k͆#Q$ $I ^ڿ>ͺոҰVg>6o1,t3=-Ζj2wf_->+]M dWvud>j~њ^ujuCUUn8+N9ÖV3<\oDbjF[S_YB"A A`y?yz)k2ݱ^`0Ȑ2yf.Tj'c9טޢ#DIhhQ #Xk;ʝ ڶXe-vȈDd d_GspE#-6.=콎K=ғ1!Q@ Nխ};ɹ9gM`٬%ٜ%NIPC)YI%A22CqXdCxgMJc >>/j'"=f5)"i Fsꟛ_g|f8qb%EC)c֯9Ȅ]jTRI(k*7oHafPtUUł?mVS^9߇}g1ξ:71|ǎx9.:ZJwZ;&:ޟq* m̒~P %Ee<{ӯWm8y^SO7!󶘊Mu5Z4B"E'v*d7/ A#࿩ɿ'u♫I<6pg2Q!ՕЇNP_/G=1W-h10XDBQWSB◻ 9k ;x<ͪ:bOp 8B@ᯰ^ C>*U{tJ{L.9!ڵW/FlZ\7-7QKrcj*-<֥\*J {ylv97ȁ`7 c҉j&QCGoŕNt H$t (TIL35k_{]Go- z VZd{Qb;; $ h}SV:͜yIP0xh؞GEmV`V=q]mV5OBRyhcw̴gbT ;mqUvUܤ`|ogJ ݧV N4(-:hYYγ|@cv |/uڴ|GNN _ Yn5_uf.f]0k7puz*^#|F3d*,ã]],8:n.0Jx*N SS$+vfJ[luk͟4ŷ4W?xbD?_1#8'BZfXՌ[d@͔Ԓ5wDgN{~ik! !{˓6Ovv lx&"B E3W_hK]&R"!{ޠo6Ӥs>紑D6_{~؛`#DJL@F 4Ȗ3f6oiz1۝dd+ߛ>_yU @CJ{v65mɪf6S]`B\00Y9_=jp5 ;M/>Ϡ{z1 ]bݺoof /r12Ʒmo^WZN36!l=ˊN]x8:GY߆!%o=Ӿ,t#9:FiN('Wf 3%Cyͽr0!w!q;"CfhwaԇR{Rw!Ϥ?3JB* J}Ih !˸ D@D1B+@ok'z "@Aɞ{F"Dt"Hm$IE wUIQ0"ʼnD"iSMUkXV6"DHf6 h0"7F>l+]رjE3z?:|b|(04ٲ[gxQ*l D3F31YhʚVM4ZkiZĔm4Z[__r0F9T,фڡV@I bI,iW}֞_'X (Q5K8 Cۦ)y\`C?_#1#%%d̜ aK['}K|F;%`*B(O qDZ*+u'kvA]q.D!02A$L#QFԴja8[CbtggFo6x7 'aN1ŁD# v &4k|1n.(zNߵɯEV6[Zm\`*0, u}!0l軪Ty*pǕ$e8j/x@(HĀA*Q\U5A Nw~(}g72 E H3u&eLAi^x)W *̞́Yë[v*@H2. FKK! ,剚5i7i5dA~;cQv\@CDBt=KjЍsLʐT(HTbA dRPc_ur,%L:_\1Ux{ڞ7Q\t<B!x\tDyҦ>)x%=70> )$ƮOtWi7Fs°XqD$C߅5<zy '=gW1 HHDEذFRC$}!ZDƒm/Q!$$Fpɮ0:N#SOcPs %QeN IC:HI6 v ۫-@B+Kq4fR4cz+ sbCӐV"`|s"o#r1HSd ">é^2g2nwFY뻒M/WO6CsFDXW[03mAf$~Ǔ[܊#;|=uuu\~_v"Ff``H+m"+C#0LHfMj,I !.ly5u`HH$BjY1%28u&Ռܬ83o_9y:2@ԼPx0L&tI=SrDɄ|fdTX}>c[9>;֋ Wr Y}Y. !G472#"jC3֝!а` wI|a H{r@+̰hDM]r I'ARY:;I5d㦸y )@9^ 蓥N5J6wX1/H|HXk&ˡ]AҴHv[V=&߰Mhlږ )ISigSjA Mf2!{eL$H "F-o Swqwp)`Z 1U"MG"c$4 r\y;7Ea{L|8mۀXV$ .AqF3Z#+[˫9g0 eꄀ~LhrT&Q{KT饐U"(] 9A$5qTX @@4c:f``@"j;cUIERr1EP=0=;}F#VFw [e$FKj!OHص3<7OpCQ1N]*,)VMYaёpH<AF@P7f maT6kC3jo|[acљR$2 ݗjW{Ƙrdq= IPA-h- $Gc\\m B.hZ4NÖNeKއkΆrdheHMC@ Z9WA8k0ѡ/AdB5;,` f{4 !cvdKP͂gv!m  M{ 'h$xg$ <}Vsh8 "dl}m}+ Pk`I!).A3Bs>Eo~~S^|&Mn=nׂ]H7`dd*8|\y\I(г6NKUЖgTs͵ȬXCt aUU@"H4 Cׯ#+ph٢48=*y$Q!Y&aJIe@d ƾ^^J-Ml4RFYXv .xw1Ώ .*g ߡ;yDvBBH{_{  $(pm w@L!n3ʆhA,r`]/wwu.V(BC)xIœ>D$D}n+سrMʴ,"0A(NgL Grh6 `jskZrn:4"г8M aDkP = oq*<JCըPoƄ|]%޸f j^:yg|nZQ#bY|ˆ2DL{3<G$ ,fwwӸhmsdVDQU zSҞtp띜;M62 1˦@9h_P ] 8S-xM9˺cqI! _ ζ "CvH+v \E%1/D$ @vΣ;hA#5P.ݐn6v;;iGieI"kBX.jN<!]6 H^K ̺t. @dRjo[|Q())̜d 2 2rw:%~l@ ] +QQ 1xwh, DXHT gB2;QDiU*U$!"H HҬ 7nFH#ENWkOH@$ p3VO{օ 8#4ME.s;Zrܖ+staF% S6̤/¶-@wY<qkwpֺ %גF[P_-@NBSqϬҎx}M ‹F̔EB^IÿW$k(AJŅ@62ZLG@2 Y4t^8K**e移șFk3w5apJNC%@¡Z+#Fl2p* EFk+ݳTŅ9!E/0Q`򽯅E#O`Ad:7\!"Q(ʺ6jy#cgV$ *4M3`8R+*V A@H*S$m[\miDq;~220GGT^A IA)Ĺ Q ,2(P㘲%KS iDm$J zH<) KHy{2 I.21\ @453jw.:v[T6[;h hbPD1eE0R*^ A2J;]w7u E=v|f !|&O;Ez@yΥ*p:*F x$Q+j PjDpzdD$?7AcBB;h )H,^$ =CF#DC0RFϧvḦ́jQ\!8.`E.pJg;<wֲ%0s&a cpڀc*9 !}bD5)Y h}uzc:7,2$B*%Xi}8Ϙ5YPYvځiw|ia~VR.D3 ROpZ`ɢ)b)6}\_W(r*⁦Ej\m.* EyKH 耮({%D>*P@KE 5n 8+h " EIP**.x** ) "("b*D R%)%+A@t4=mmKN4Q?C{)=*aRԻrynGs& S8UWjWטZY}O7wNuV(r\Ofo}KF*~O@}?yU]{? JF>'"=Bքy?еIvŵ,yԀO" 2"OiP" @Z"hD/;_̠ 6P? ߤ9Hzn" X,ʪ)gbPh "@8X= Uj ͿeX"lUQĂ+uu1" vݤX—iBQ-J]Rď}^TU؀"'4Cn"PCZ!v9^U@9pQDVO5so~" 5 DLǡI~j2+R3R*Ɠ:,|1g(#/eUUG""}NځڊO[~ P7!8 )àƜ7wQS 8W>u}/ f! 2ِ 7\ Kވà!:̳Q\sq 'oТ@C2(?4U:N|߿%A) }+)hEa2 @_]irux)/˫<*TQQk@Nb ?vo=}XjDQ>*WÒf}/;z7 |G9?T;@: :ٟEA8yqoE p_Ya´>PS>[R" ʧ4akgTêMAH>ߪPފlCU@oЯ]i|ݢ@G/}6rfEW>Ϋ)USAJĆZ2RiD(|گz=!D~Y=?G<'}w!b޲_8noM/A>}Y@X $D/tZlT9HEHu[gƥ = d EZK`R"~ zfg*u":΋AU\@=F) n'RkԳ)+f-9't:E˯~ /W;骦eLDB1IPDD@("G?h2\ dJV34O\.)i<9%u`"(!,.ۓP[q Jd2~}u46B|,謼 6L|m[X;D';@+ #1bZKW@g9 `rhH72Ͷ;KU٩ ~*JVLLɍ?.0F`HK@ #s9( d%#ICip%?Bs=ŠsA\muz4Y՗˚C)ݮ'G!Y_TykU(\^:j5V ѰM|t%{F͆aX[ %g6Ea& AbjT~{bG ӛ[֔WN%:N. TZ!]аb14 ]ZM44ТbNϜr@i Q z@DO aOn 'ʪ_w#!E^Z*q)]zN'&烘o[W. PJS/kU:qHI)t_ݹ%H'}Ȕp<H BC~۳ ZT[QUVʊ2-UQ[l֤5FFklVmUb[I+[%-ɶ5U`-kX+TZѶ[j6bUQŬmFUkkFEUbZ*֢EAQhk[QWBYɐijCؠ 3G]KU'{T%v M) 2J1 yFF&Lf)i ?ѤU+S?(_hH*bZ֠8 uHHaIVOOŁ*ܔztg#EQ7MzKڻ ckJ׳ 1C.Ib ā%EDשы $H7J5S,%q)!j$a,?]7A<Ga.tVLc9\~h͡EgW[kro- 2E]Ύ6DB1d dgfOh/Ч5yj:39ȽYr-ݝouT+j…l>ܾohppt+8 ATӳkA-GO|>&& "=UmD z) j­)Νgl{~#HXR(NyHk*VaI~ƒ"ЄcE ^2sxwժ}DZP7.jAL?e?R|+p:$&`&?{}p N"tc&gvW: $NXz=oc0lllIЍOZk"jb%1HDE `&C3*D6gx؈# $LC'K$-;9% ;ct[zvQȽm]$u>^sAQ "ixfχdyzvйr}}66_@uaj;OK){ :̰p"m@i9w|Xz47.ԦYב)E Ek?d뷞"Y5IbTj*ha|ɛ>G E-8+e >U5E E[3tf5C$iB(캖%.ߧ]^N ;jrC3VX䊔xHR2+QbZOs`{cJ|H!2EclkZfN"iGC/ux@%H¢įncU W<"!~$<220I eDx/+Cն>dEBI2  C #Rb0u[M&AMЅbRII2&ɍ&*HƑ)2c EH*]4~ᦋSO:hѢ42dĕ S%Jhgk~\*y9_6Ȏz,c^'o,o'e<ٶ]UA^GvoeX'蠚hv䝎,z?~f=)>Aq~VYmgд `[dhwmL\V_|4o(Βqb<_rfgE\y>V2^E4`r߰}?Z*wswzO7TrxVl`mMeIF)FѶugvsDUʹ+\M륉t$Jڡ;Q'|?O&x.NnϪ@ T%|`z 'g~^}9_C1ރTDƤ "C:[̙S;F{ zTm BTJ(KvdMrW1u39nDQ&DB,#kS1Xp >7QYr! ENCB+`Ajq55:k]5%!+KP(1egn "Y 'B>Y'7hd{]]{ަC+50HcW{u{tg3d" Ɯ? =M=?>!E!@j⧚ʂ#*y* w~<}1?HAAkF5*}m&|T*0b*‘546@ SKݻdz-hЃ BnWoLG> Y9:83%)MrAۇ¦} tDf13umB3G)i ϧ'E8>QlTn~2`$oRk#'p54 0Y5H6AQ~Otxа*#! #/qMf99ձ!flaDD:~gRABEDݍ-, ژ0 qQ;tPq|4nx>.kA`{YQŤ\cKaV"#C 5V#!?w=vkxGsQuшH@!rpRx2q [Aps#ZR $7$=\/Q7YC-3?X.:rػTގsrvcdz}Kye!̶5$qBl6]F>PEkQATuwa5Ɍ,;Pȁ@L$c!7m!OךHr)Now_fbVA5dImZ-mEZKbԛ)cVZbQVZ(EkETmV6Ѷ*)-hZ4$eo{Â=<<|\[Mny@G[75^w礞<>wU壧} {_OuR=V*}lpc"8w0"Fڏ EUD J- 2LA>8hS,'SsɔI#>2"Ѵj+>뿸yjv@PmW}S]K &x_Ү'8mh59*#zp1Jf.  Q!DxmO3Iͱ[7Of pu[u1+|ZrȰ:;g2@GրߢIƤ0U.BB<0~HH;絰Ԉ:dl D1`h.V~O!e)Y H"\7*Սf2 ;>;/?2bd*f$-!&` fVGן+xN7E5#O}~.tG5X%יj}{~g8d>/'Baa,4ǖ79[eW&< e+60AF{z/t/mvrT戜hO o@˝g(ss;ߋO>];D $XׯX!OB:P3 $}fA6jЍ)%Oz;R gAaA!qx4v6 A2pba-\eǀnI}K _KKP0%g4EkZ  hhe( Q\x:dcM Ӫz^@5q,"E& "Pg:˧Qq qb#HVש_i_ඔ]߁lb_t(ƪjXDB0-$vm"+σS:-|2k5\c~kᢆqegT~^57`P?lF"hʀ;?ס^OͿ緃)ly,伖d҇sq[UCgڪ _ܛ\!o,7 aXط]6{#ױ08R 0F@0` dGLـ@Pf@dǘh kOMfc=WC_&~ 8#T $z{y6yuvu" #|Oâ}T yP;qT!&,RPÝe7yl_lve=jJ,<;B"ߪWwqGQ ?R9m@;g䳗K+a#O_moxr^S!|(`jGТfb]jz.)y~Ƒ@V v!: ȋ"+"[c-%lh+&ŪFck5d-lmckXjJkFՍj6lhѱq C_9}G4>UW^j@B|ˊ'X7f )AD;AŲAA> EEfTP7 ϑނ贅ԁ -#3H$!obp]cT$ "ję{ueUNe?kܡ}G/t]]GR~iBWs,O_FڈmE">>Ogc}璊_yuϹϹvY[]!mm5z_߃l۟ygwHfxY9,k\/{x\}o=E 8)&d=~Wǩc=o1 ׳5eT#)6/Eī}? ^. LA: Ɯ2y&qZ̵zf:wrVuJ|W;Eϑ!1nL{璷[T% <jQLIGW*H[㷌|/lEj乘^w_fau3^C<ϴxۋ"ͣMo;;)M{_Dy\ZG)!ec#:?G踸t=\ . ""hRt:f;݄XFZ&25&qiV;w{7&pf([5u}ky'a^=v\ʌ8|9A9/y gYd>)BH!D[p_~=½WD0I"B~Cl:1Go7ޯ߰CWX0&˕DlRD_Eј]f]ybehh$5m m(QS))PT '5.]6Ι=k.rE{B#۸ݪNa'R8j1l[À$upKۤ=mML*18+V ۻUbwjxb<5U ,ΎD ~EV(( {ي}тnmM[bt^-b=7 qԨsq1{5F"r\wtKbˉeSonޛݑ$J |=ݾFĺL4QFXI&MpZx,8'v EQVki}.VUzf1,r[cZƈ+ֻRFEQm9ޖk( rzەv6UrcDwh 9eˬ|}n^ñasy&Pjt'3 Fe9g\PiĠOUkjt Ƚ7쟕[p=)\ ?_e???ɡ2Z7>. _p`}2 @@N@5x:@$ѯ "G#j  Ao?Ȓ44 ^2Whhy[里ҵ6KW^ߠD)X&Ο._HVh(A"0X %u~Frߩ!aeT?V03k|"EuCjQ"O,P_}~KoE ѱOv =9QcHHSE=UAO΂VXrb:EPWUN| zh0LL g-vנk#*år>&K,ӑ?E>31+bzn^o6F&\l֗[͖3sp^.6_YrYr+Wg(mGy;owkMw\l}m4w{U_VD\q_X=u};=riBPRcI-@?xj?}gtKZ<8 vtF~ˤtrϯl9y. _'S%;?]uŊPei|m2ޅ/y/:Fǘyz Gx?r5 Ɍ @V pSW._`4iHf}A WݸyzotKTw3\6WQ׌RǛt/@| "eu FZ0[{ p)ÌZ+:{fGQB#9 ۶9b1;%j^ptƋVxuFͼLS8wxq@4-G^L7xU WUU+YxZ7gTne쐝Xz(:=qN8.{٭\ƶ45a-v#3(pxq-^9zxˢ^Vnd18{=SMotӵZV멓/YsTRN995ky2 h52ӵ)ێfnfts;$RA 33U Bc ;S0ӕnkO61~/OK'K"g;{w/7?FHBIC4"R 4(!CaOhyw1c ACQl@\v{ҒB?DЂx:NNRȱ|۪_H =NZm7sCLfJJʐY0p+!&$ӂmRڿcbv(Rذ voۯIp;h!WۀHu.zX;4ZJmPmaoå)lUvVǬIs~m?jXcҨt%9W2BXZ|#) 2>*<^dNۡWk")v2Ҩb0h؀*? uU;Ҙ2{qaj˦-ؗ{]vdۜ"ئuO&4 qB -)~YwA0Z%üKQ ,A(@0E `q4 MĸAC! -6O^ik_9PkTaUFbMmywZ(VMm9 `xs̨%]&хKA]*DH0@H~I2 LyN A E%$ԈLҏL ex2 €*@&b"oWÅPf@"&`2v !d\Yy#Cts==U91e1 XVfI6M-Sb7͵[Wg@=`~r?l*qzi=gx4~[+!+mz~&A`js4;M c~J^}T3+4 ך#Pevs֫tJadά l}O:-e?/>s-R^5U4?qwRO ,Ww>?a?{>ȹE`k~y !t^\.p3 %)b,V,49_J(O`kh$" Ъ=T )VPM1Pa|zz|5߂^kCIX"7DFO/D4x1g =[aia~pX7#5`ON PeC2 3 R4K ?gD )֐<Č{R}G\Rk?yL5;b`SAMj]9 i#DD ʤ}NչWk5@ٖeϳG7'4۽=q{-wY>NSPdseH2*q b+  &&֨0At &xȇ/R"-TDb) Ta`yH4"J.g£T =fV@:H6͓I&ys0D CPQ{?D}^/mq7aD3h|oHl9k;\ !C釄:ꮀz6=d=-SQ{jy=zJY7hr<[]~:ߺkk4pvϟ=6 }f>^Awṹ+nwhםȰ`EԐNz+ujw LBAsAp;SYѳ.0PmN^`CEq, B5A7ak&u<;D|?2}s@D@?V (fAO;=|۽KRYDgU_]#||o~.r/s 'hIw?o_Eo?_wN*G.[vQtl^{3,{E_?t͠-`}X벷?'q9]KWY7Xu:%1ٻ~VcdHR 7\flG:jW5/ ȁavO^eeʤ{;q8>MeCj#É!7Njj"+EC`M(;9i@3'[(?%pEřPfLß;/]뵎m5g%i;#<;_G9PAkO73:η\F]FMW/|b G1\r̮WK_-)Nguux[nF^Wu?l>%>R_Ou8mINgm?.-omk0-W/gNѼwy/=ȁ:2#.@?Gθs23+>]eRVYV W-8!~ĠWpHLle('/2{m'G6ǾN[z[5>q}+Gsowg|dz< ߷0]GjLǀl>e@cx?~ڭumoG*Z:.#?ϰ飰ڰTZyiX>==k!w?Ozy찟~ym-mWo:6:H Ćºrj5F_Oյɫ͈OE@.Dl2"" w-90$ȇd@y/J#ˬkF39|}*?EQ|}_fL/l,wsجۻ9J Evg1#~C;o'9ȍճ?%{~Ƿks}+Ezw׎S@Z~{MJ >:U}j/?[4j̖Ƈ҃I4VFZLrFA$δĽo<ִDxi$l尌gΔ/OGj֟z }nu 1AƤ|kbMVς nQSm|;e,:o4UA UH}5PEUJțӖNna3Bt)C{5淘67׍e9jG㢫?}# VA@Jc!'}W{@j1ӷÅ'{Y.z0#nwU]h ;zn{,LJȽvQR\R)BQ)E &j!5I5BZ?~|72fF`)g,yn"bBFBBFGyо*%2%$RMB=~TBk8kI^ר\!$k=<+Z3N/Oꚴ&>TWf52d'N k(C jjՍ-{)pJwuQJTd&ZKV~yz !.H\6󁉨GaF.ݐ8< b Cu}@Lr̭:7lBfPц8m+)~u3PE%/y?I͒HD+BdF_+%gj2hLnP `dR$mQ 0Hk=(>U)`YF}zgim,`pW;bd&\#qp@ }=>_1 #&Ud%lEO hC{7L"d65kJv&2fn6ڝ.& tl\PϪ,`),?流-tX:vFZ& ZBJLDLL2@M7cjWY`SbX0i`$G{T{x1@9Xry;Ϧp:z3ЬnFM.AOiܣn(K zY{dc-\~^zO͇KJ2oshrkS;onA@PMT@UFȀiҀk[D0j+i_] 'Ƞ[)KաJkWYg7|ll2Tbauh3OҦ}6)C Em7.)q)Ҷ* >?b̘ymP=A{BE/u?΀uC$:;AiJA5.Ө"F'ab:˨: @ק!i5)[V:uZ1^+ -)lSi ._13h[ؔ`w\^ _`X C""}!]J_ۛrk.n ώX 3p8~iu =Ӥ֦ϰx]G`V]Zt9+v`[Zm}9mfߜ7_<ԁfwLhȁ!$edn[nc0Kb T [.r~6]I\Sm$2*cVC9T  DEl+Dl|߸񽧖.k[gs^ySx@qP<ǔoTzJ{#WWF*ցd %PDJBulAU˗DiMB}R 6dOl0HF5FU"dA(QQ)>w$;胂\Yo+vVU5 T&6RmnԮӴJHAB@RعKucbU,Z !! $:5So|s/ƿfo\zYH" (Bs EX[޵Z)`A+Fb5,j6m72RdLmo7QEhՒI`HX"5*|Z -mC <^x_.mJ:WH-'pwrs`r X0!MбOEH /_3S]Ip2) E E)nf;SĿ޽2_YrV"'L$D! `m揓kOQm| (y|OWԋNޛ]_=4cWWHf&~j]isCQjE %vыUk_oYf-~?ގY.>{*iB"݊~Yɢ^;C.]};8!!#B%Kj#yPTU@ZWqa :opuLP@m"3}}LWHPPϽC@\EGi&:Y+*tgvW<);wȹwt+mmױZmۡp=(w;T[5SWػjS[[f$Y{yՕ#5Vͫ(^9Fe$Z-Iռk.u5W5mƴͅHB@ T":-oĘ$ME  ul$XZ"T1"R4mβ&4f,*/^hc BlHbߑߠQXO}vA. (2%>˓qo!]fwԛG4>^,{ѨAѳPA;AJ+tg:1!iwEӳg',8CB7Ŕa 11$7Cew)""Pq #eР !k4"F"߬ lT!I bY)iHȈJ[W5_myHlʉwYU@O,lf~4|8?I" D@v\Z~1go#z\J[V߹ßހ/knܾ6C/Σ˫Ѻ1jypqsX'cgo@ SX 8''kOK@?3_kb~D8WiT &0D:#NHJ !Y>*ObUEJ=c\l1 07av1a"XdRJJa f*b T[q fYPkBT8rQAD`fJYì"!f2#lm*-li1E(Y-"5PUE`ӪF1*o ]㖹V ]o4lE &Wb+͖(حŋ\h4댁1+S!&" WynbyF5QlhF6YMEQF(-hPa"l;EE3yfbRKI HZ+%-׋o>\6*wL [E_ulT4QEooWM-WrV(h{Ƿx=VEj+]^v0VEj.˺F{Eo5k_k>ƍljbPbأh؂4DQRh Y6U6EE5+mEQmKuZƴF=-[ar"k *a~iOӥ+Hm`4C?kIm^Rϫ-~[@!A8%];:M<YĄBAaB1dXEBGy15~6˖U5ƍfg'@YwPk&:".?ZjXٷF@"TR6O`m-@|nWo3~ [p_Bp#"IEbب*g7W= OIr,Rn,n5QxbL.@b$4*#ijAb>Җ`9dw , qJuMhݐPY]sbQhlTmF ,m-m`^b<))܀]^y0̌d#@(9/zms6&FI(E,kC!edߊHWEGr͉9c;1``?W+yңpr .C[ Hj޺e#oCCTV?gkJK. BB$$"H?wWM#6fBX VuJ`@ /6Ya'$ELq|@ۀ Wl~Ԅԕp5 a}]0 |_U~&ps$/Y~%&j4_p\ZUI;~_&^s5O,¾fou`hf}r uknlX?!yI;m^De JV>% -YV@HiP(cDCm,pRaH &*b ,YK%(ܡIaJTD`@%\A j۶#Y65c7"pR  _lX=47oHA5P :q)ZtK$'mY5^6;Y 8{a^MƧCƍjFu ȣ;- k9ْO8 zK>$ݬ~`o*BUuFD"&MЧWz/wڀ9xx4 QEjWЫrxIXmwZ+Y@mkKOs钾g WFKB6~9[fc kd$EĨs,Z0Jp7@3obx-[WxCB4tD<"..;>ikNCxL] 7Ò4-k@lHH/ѾAx=iB7˿S9WZQqK0JuMWiK>'[?@l8ԀlE$P^ )IO" xoc_CgA}yJL3Z<^TN H{8fGK9 K$ZնO[1?K.yxLG=fѐk/ GUBh%-wԂaNh[&}|ZC{_'1 !DA! zIT'D*L$IJH 3* R*iH%'h*765-6/B5*u!OosFlM P&f tE﯁aƍIӂP\@>"UdwOZySY7k5oO AkJ02c>W7xQ)s3"< ɒN6w+bh*UGqgٿopuj!mvmC諣:zjZQ{Lϻ|o젎ff"noN9,KALYƷ^gzJ4l 3H!97z'`BI6Ƒ`^X\~D OPDmk쵶~-2.\uiy'?[SK&"c=j+"^]ϛ_h ;7'J NjoܞPhP""]}I$p;7u} ~'apzޝ˷`m~Ia HD`QBR` )`Ft@pϠ ~?a34S3v U }7W-  H D" 9i$J]#JI`rv$H>y)2P)]0"6pECH 1? 3 -9x=̆`>>uMCT ohD󁚃6 nEYT;>KCAooE)~b<݁=80$8"Єe"O)/\℄cs775f[@ b3ȼIxS")NLZT..38ü|"Qe~ l05oX.gQ۟c҇?seN<=ToZX` R0L֋ }6,?`٧HMު3ճw{1 EPsAyznwέeSoVogJEsR}]7>o߀DW7;7:?qcۀ^;+CwɏET̈C;pix?#鳹quOLjӶ;nTl߻^uAʛ7=: Kp~uqexKb_Wnp9G ̜!(m?DYs59Jksf'5<E9X`r,/.+{S,ݦ1Ҋu95m Mj~Q|?X "';y]5MTy;%|awيz8~/WPI> q @4tLb<}$C w<ܚ-p׶94*Kiy0js!%w}RNYWCE8IYsx#3ƪň&/U$\`?7+hn π\ؽ Ev4/yOKǡ> ~(<ĵӲPG8F3#3-q3{>9Nud(ł8ʌ8$toh2(IS*1;eG,8|i>[9 nC0BUW:~ϯZ[IN;9XwryT L1-W4TSF+kvWW(K H?s4'pw2tX"~$:7"".8Es=P@΋ͨmڳU91 |kˣ6&*p--Wؽ\No Y?fꪃSNq`NDf_-ךE8O^z&]xnQ÷[mmu]Twh=u[HF8Zz4rsC^ŇDŕ? *9  'g?6ur' T@{XmlS7l(qz>&҄tKeGyz ҞrP|I k-6Xձjգj6-XZj6UV*U2֘[hcTUتѢԅiI5b*ѵj֊_RhI5%UX5QFQ$DFA&0 ~]hl7r88N{gGBpAtlv'eRI {PGK60߇×ֆكWU-[LW[gUx97'q `|r' r TD8b嚛/g{g~:5Wf τGPNohnq7r6x6,GJ AP uJ!MCojskimjM\NWCA~GOUëZAU Q ސQu˱{O&~KwXiZ="88vibG)Uw_wBsuտ  !Sssg[YS7zSS= x8t}ԙ: @ @=\||f N(Jojqk)~#c&-糼b Q'F`[$Hb=1<֏m$WSPgL6@'Tp R/^;"0 fcq^H!"9G2Lx7ZC?8ޫ|l`!mWqIxNR.@i%}F7;pKxW5WRƷy: QF4QF2c@k4ŭ3c6 j`FlKDbb(ţFA%h5cJ#&LFlA"TQQh (,j1E( Ɗ(fIF1`V&l$_+noMDj4E!Fݻm QFJ"ɪ(4mEFdIhbHѣ$-}} ?,dD#KHDьZ}^Е&-j -%6(h1w//!j("ll[&lXDZ!}9tFPdi2b(m 'BE/ Z,yZbXv;M7H èqBmmM83vuǃ &ens((-hٸ# !^BH ;0>X+H#Df찢EgO~Ҝ{ݬe`~UJ~HfH(0SWipLlk$$ س=k*Ύ3OKS%Փ0SQ} KFE8zl`@/=1*B>>Va k HBjmY]& @(m,a8dӴ:onrRS3NƦE֗O%$@8a:'[fP ȎmFB8}o=m`{h=q>=dna& JpNwYKBVa3adA@n44S3O_XRl(of@O!RqX% X1 B$mI&'O@ǯB1-\{/Oᅢ pCP!g9(o`{KKM! ?@IÜC0g$=Ya~y`(V"Ķ"T;><풬B ]_v _ۻ&)?ّn]yRw\qhі#0Bk ^W* Q m&JBNNلr6d_͂5rS.<ȸÙFJFQ|.wA}N2MyTN8?9g8^_Fdrng PDJ֦|* n.ۮ79xCi D#gTQN)GO(;\n5ɵb^LPnCR@. *)Tu(ݦ  4X$ ")pږ[t=!44lۓz`)6ur(hkUM$N592Kv (jQAPap֭KnkJцD}_PK % E]No#Bpr^lڣ~=a捈ͨG708o7B!AuWS1h@q@Ų6;Nٶ1-7MԱ^NڼO9F2*kRL(>?wZg҄!Br?Ћi(lG˼hwU1CtXJ 04'Z0f,jf%!2^faCS{U3pn@W0ԜB!aJ6<{@N)RMb@M@&__J5N5o:N''&n}&gN擝%6/(*UsyEj/-YٽR֧ VL}.H9O3ERf XX>+4L]`&0׷JZEQSCyNvp#(iUI 8ƆJ B/X 22+ S 1MJl2@odsR/"Djd \G ܜyXnCRɯHcvj:cn k~΍sY!:v )kFt PBHi(vtS= ?!;f. 4Zy842Z}z>/V? !'LCSx(jOb`kVcj8Q]9La!W ӐH@*"kS)F ?ނcjlDZDM|ꔿsl:XAE!ۜ |phOOț2TF)8B1tB5@7 sd܊sNC꛴?/80Zr0܃:0:uַWq?׃Q:=]8vG @9vywn/'2P^loN 1P ]oV|^~a!#,Qj}NOi!g34(e%w`rqbH+?;9Ԓ.RwjLdKCٴn& ~0$42=B$cŭ dʡ$.C2!BO$"")7{@6yZ9P*D49ޅGf"wP"IOR) "NOQ=[{7uN`;`~:!POݢc˥=uPIj{=j٫wvj" 9[{}'V:p^/NogÀONݵQq6=5<7u\#DBCu5~7{Q"@v]sNX|/D?6,Y}}.^kFƒf pBdzw ){e;z$gO2o6=W&L7,Գ)䴟!$j%g_ ZB (q'̒ϛJD+38ƞ¼7:S;z:{w#vmעr=/]]욮c4ݛQ@PCz$ 4O"|f3ClP (H \#K+%ЊoZA:Y_;hF̚4zJ5:. N;ߓ^/1{\L\ffeyjۛz=׾H~@_u2? ^=8Y5A( Dw-rϫlwʨ?Wqt4CGuZx05@Y-ـ`_TZ>&R|B]32VIb*͖ۓو:ѫk-VڪYjW#XM. _糑nUWo*0 m髗=*9uyx6TT!TڨXښ'dz '@f0WnAD'թznv )Df@zA>Zo2@!|R__u)sVr2'9iyX;9[@ĭ˶.ٸ*M}<%7v`dνtUl҂ʡt@`t@va82HQ.(P^65o{߁@1>D%1,B',A 3rC4L@{]VS!Cك `(.Ev% T5#Ajv6A`PWAxyty)3WIöS]bRyO2^1emoYIfmj5P)1o+i+0>ʑJ" (qx. 8XۢJ7KO|j\0} f. 6?3bFbr9%)@/`tm 'Mt-jSx)(g^X0cj^FcLھt/fɌ-2y>6`͝ GSbn@k0)=6PSkvp#Yap\L14ѲŬ]X``r3ڎZvm[Pc̳)(y5傊+XzxZ >g. ĒolRoFNdA1*7..w׳e>o<:bޭ|w:H!^CqZXe^"TS^Bm؊n!IX2$2xXT Ji}77<*li\^:Xj!< ˶UP+hEy4`\pF $j Mr "8 @;*7Qtߍ_{{nm6CNr_\A! )t:j6:`oroy2iA 2+./3H)t@Adȶۛ\Mn5 4&,g]m+mMHH"2HkaޭWKa)"cص3 #.=B;D|VɌ׸è{72d}XH^H/VgŅ⭛i}?ͷ ,ZbK-Ƌkw[۝ۘojrru6g=ZM@-Wjyu:G9sS+k[鳓_1bE$ $kK?ro-me4k6H7;gU, 9{bYr(']EEO({%-4zeJkf\ٲ&U7 4#MLbtXMo=4UϺB[ $D$2[R/e~+-\QƢb@y$$D$TFAC:6 `YE!ETY_GN!l <"DNA#nXmH>sMLJisk:g|{3'c`Z((:89 =*N%H0BIos9M곺ɹMg8#(OZy.ȐgnrE'hSwwRUm%nl[\ԙ ̅lZ3\4jcvjEDd:t9>ۆ.Z\\7iBo$#'ꃉCJ9@HBH[_kч={HR[k`:k4D8 Z٫)g_W6 aRA . zY[=n␓!8:2R}En֕Yi+EF665{mxĴM(2+PEyZ״ Ur/F=i* +ʧɃp=R!]709tQ64z$Nzh8L d1?R RP:uFP@M JV{`u4C\ܒ@:#2[WV'i38440XwOqUU~}lsX4}(ChEW<m:OU4C*VTD 夀cV"E2ьteo61V %Z"Vmim=*]VV:M-uRP$FP0Xd~^@I(p &ͬHĚ؞4#ȥ7+= ƚLƐVw%S[iY,_6v6u:p'c҉Lϔh1QbϨEyY/xnV#(P%k N:t=Sx{Y3.ήuAs~2 | (@3ng~u)ݪ[/ӀemD__Wf=="Gش 5=?sW^;7BLJPt{"6Đt9XdZjFAp0z "wF|3.]@-佹Br1˭o;L҉w`&{7$УUˆʙ>|ۚKA'ӥ~=] q֞Kގ3+;]/kQ|W >*MQj @.Gv(F N`5<;o [݇z~?II EP ꣻ壗/n%x6)G BFш~$J*xWӍ/ `%Ƀz*ӿ|kZ5K{x=?[kدǺt5|5~^_5n˳U<$_=^mi&⺶O+zTݢ<}mudFGy}*pfDpt<\][3$ֳ@?!8iw[YTrfP lj9lp  IPjW 5mVUweDwjlţOYY$SuKӏ! 1"Ȃ/odP5@mK˗syq`c[ϔʪmD`Qb$険AʭOu3G?>qWI#ӛzzp"O~[v@Y@,q}< ,LxO7dgߡඛ<w"nzgF+v ^Gxf篗`P'ڞֵz%̷"$@vJ~XgU׾);Yqu_v[JgCJYF:ݧQ~ py8xۧrk _ezxQ& vhr lCBr<<z}|b3>KysQhVmpܪ(`{KJz'ڟ 7,8dvX)  R1JiOmC?>K~^0p9NGnMttAn`$Rg &f&sr.}+@ X $+[out$t~]Yam_fQ/˙пF8~Hj b'kҿJB]>YG}.ۿ[D3 =32.٫ S|z/[5vκifuߟ. "DDb6_ r" nnɎ$_,rjGg܃x,[ Xg1~ ~#0*] R0J,{?vEP~O'ےcۺU|6~EWrWSWN::T~Onwwoȥiq4:8w'='zZOĠr'}lP~g}`h A\ך"`/騡O֭%ӂ!;!s [{S7۹Jlso:N-?"ˇEҜy47%Yx}x%JFHs@: 5jT? $_Z֝͐"+n gMp$T@UX腨H1YD@]1R܎l֟k(y78A<"m*'IboyS;VH0| O 11?iLfzZ|xv]]!d9g(?diX7LKV7hnҢ֐"a-f?B,O ؑXN,'f9dpRA8T]C2FV_b̀5:0|WrtceR-  >ЀB1\.-NfwZZ=\d`A^_1jCSZPjV%)2I<! Y*%aՙ(: Jۉ1{k& ZU Xv~D⒇O"V)lAU *Ú;.tQDTώ*{C/j}wG^4h 0n\ !)a$Ds|.U;ږ mwe: ٰ{w ;860\&S-rwC@4xñy{C< RD(LDIDΚc RR`<{- _ŀǽ/]wG6x}OfSGN|pbg~@'/e6Rmmڡxvqxpyߣg.B˓ .nˋm|(veg?,9/ {B }ݜCmA!T.3nvYw6Yn÷oM;K{_E6CW )>KY\%AM 2Rrljo~<}vىhh>/20V"OxY<>t lIѬ:E0iӢ}?f"P^Xjjk iӯ=ӎxY|E!ޒ&u0e{vjlJp@FCyr;׿bwa~gA`2Xx-FwAd; Ot:q^\`ץxc0CC왹h5۶)]UV s jtǟy$VR$NB1= m{=YPb4HQL*4&X*AE J'CA ^#wSsPA x *(+qqτ `*&r%"r`H)aӿ0RaŧzFHjoM޵R"Q#Bɼ RXLVˆ1n4KXQĕ"1O @o.*  cPR_L m:E?$Nld@)-֖RG K3mLMK-sp\M)X6gs.M/' @oᚍk5bF(K=b5c!z "~Yd.Sh~ʙ0n%`1'H(nߧ>a&;r9UM-i/($ tE{b6d閷#BfA9[=왲CNV`5Ogs$⠸="DA)H *;gGہol/Ruڲa-8@@P!e7}y&r!> qpN5."&"\-uҘ.#yW.SыRO]ND'&c̳w' xН԰BǴEY> ØlSm☡"Pz,s5t$ dinc-}/͸=rv+C= PlG!׎86'dA&x7n/Jp.bU 1Qj`cB4LlMR oa8g枉6Թ0S3ճrwr+fZcDO]Lp2Na1c;;2K_2M X^j.fA W5jxuQFZشו@kx?}}Ն6uE[O5>@=v6dLMZ6rVόP`i*K٦ RŻ 8@0#{c M$IDZfk ciGq4~p9ia,&m/=^Tߜ̾j'@̊[G||?ln 5Tuz@Xd88p? ;{@~ݗ˖:{P̀Ȑ֧ :X  T[1'E=¼1럋2@]n=)g5J]09Ռz7_Yܠ ίr{¥4v^D=mXnO5}ZA$6,,5Cmi G zӧ!߃brg:ߒ~w.7N<Y]9`t7?U&V6P#zŵQ$ * 9|qG!|ڄ y & 5uBڢH CUlVXGxUO/UQ[!Yt,Ȓ?g7K@>OC>iޙi\!BVp7t#8IgmC/Hȱ W;mg̶"Jē, d K"`2HgPQh6ӓѲd}޹OW?^[Y>D%j_!YAN8bgjLPlTPN?L9G@޵'V4/A˘@@*"U m +p4nٶzBKUWz/=9]Ɯzsžz%mu[KR}m>@U9|= s.a g6d,;TZai$Gĩ&iNyNq/-1&v,;)/zIDw+7>Qfo}^nS<'X @$P/0 m}n~\̇݋}nO*Hu峇 eB>7qU>b79#:%͓ ʬ"*'q+5byT i-BH='v=; _rLHʂDakbhMAHig; BFeFg$*qUAws;Z}ǎݟh7q[捐[=;oG>2[ɷL9r? $Ɲ _[6j˟o ďk4vtJSqcm׉$ ݺ78j}?ͻ6C]bɲZ@|EۥA@a߹{wWC6S>G`w76.G.mz qO~^^Kq]xX{d'"H^=Ϳކ#1g_|ma:TBC{C8یd55wj'wgLZЗfvm?#rgiJ ѪƯߙpB1LUֆbL @*~XPc֠z7f[I|_?˙K#ОŞk@[X Ah*]FվTM,TU5lG7*b R_%3-}T<ٰQ.HQ2G) !@Hc@M9Ub$IYRZ-)̭ [n*ۋ?luSO԰p`F.Jg(߫ C†eh Ӡ0NYZ yQo^h> g՘z̓i>lp@XCeaؓfY]m`Oވh{TC3t@FVT \ Ź\SLttju@c|U^klʷaMsqr9[9s%bJnmQ%RPk}7Vc4X{K]]]2uslhݮJF"VP$(-ualZRw466kt4lYNWj\M[ZЮUrVv읕+mE2۪*e&\NY,hAH[eK SM6 d06 8AƈJ Qݶ.ȦԀKPaAFa$rh7-G2@p;Hy`$BR)r6HQBdPqL J[_aCl Bd@!̖D:P56b^vnh.RHlu:!;]31n y[ƨe λ<< N"їu>3taMՓ~=zl 7'=wksTʦ*UTDo~788!8Omvjjwi~(!IJKj)\8LYe/CӦ(ass|w #r?Aج[0p֭>kKn>#A3<\5 u⣛8٘q9A6Q8GhޜP`u?:+hE Y(DB A4#E{YqZeU; jC ȿUKRXBi$O|6kdvӺx#`@ؠ[dHo^5n׺?'lמ]s}?&־(bG-+-߇q+և/ydEűγ>2q puG@5P,0A!!59plc=f/`X}YDhg`8h\qL>ffCmQbZme&qyE[v`|s O!Cct`OklPG'sz{䬒i C!XJZQ3f]pYBȷ LΛ̩osx>uEnpW@؅ TBz!<Yd$ i͐&-TO.=f׫?'`|8 *}e2%A݈婛H~_*[8vh1os% ٖ%[FU3v[%q͢yZOWO3.yAN 6z7 ݯ`<.8]^u+*f{JΎhX!撟;DYnBwok(b""7^:}Y W;w{E9%{N{{<>x_#׏pl.{OjL[|Z|=Yٻ|T*kKׇo{Ӫej6M%uf4`a_h R&:u\K eE4iFRiKPc+Y˴1+QoЬ6dZIyI@oa/ډaͲ0DYKXILa?E=qM2l(g|v\п08"%% pL- TC.Tk#)%<ߎH VA1$-T( ɕJERR 0z~7! "^( )Ư5V{\T-Hs<wkmc׫C H.˃A7l*٫g`m A2f^9ί]gϋn^_ns@>JBO(f7LI&)aƘ G9\4!ZM5Ldm>EMQG9u d~+ͽ[˗ 7Øqy^H`&vr~P aw{wl}]:.cN~K_8t:pBP$1 $\xR?`m#HY0cLzAn[mW5 ڮX6KD%X|FqzG}&xJl1Xa֒>Cʛ >H _/&]/ M-IZvf{sWcz&]C >A S!HM-&âނH~2bt>{bK!}{( |vO> ϳDX#[fLaR@OQ@Dlh @ihOXz2憙#Xʏ?׮(čgͳm$9|N&pT jz x{;E].ɃI}uDI«Nzwހsx'lh[ Hr.$cѢUPbLCm78ga[s:̖A;$.օzl*Z ͏vǂee ͙m74U>H"1G&nbtJĆ>1"\!*d.9IlB.-D##:s[a<z0M TݩD܀K$jhTk2q0jao{H}0M3P$5 toR<̀:{v.]iMataijUkxkmmcըra$ AA@@|6;Sc GN*܁0XI=ڷe*Qy/0$"BL3zaI9&qT:؝gg(?$HΩ}oV@C_JWjr-(AnS2}`F|h[-= !Py[gYc^yr彏W{=aԓg$@ >.9܃ \]2K8]85gz.F!٩UIܨK$qP8%-ngډt~NI~_OYulN=oRq5HE]n!$!.gfُ*tB^{Pz,ll`4d=G\ ʓC6r?5os쓄YX!,Fۥ1/@]/>\&RobŤ+X#mH#'fR (/;ɗaH t@rB >IFb+bME=+_jO-A&G-ȶ̒ՇS5*6n8,`$>ӧ\ Xa+S#arXeDL~u[51V(biL5Og0qE,cgqx2spJddj*Lϳ6sV9ٰ} H ړ߶{5 |!e' Pi,`D ҁ$PqW&CasIr(e#*_QDz |MX,(qkq^I6嗑d8>Yf˓? 4I7Yo鵣niNN=-!f8\[eƨ.3'|[MV.ճf|Pı(Hajϟ%tsRRTTx7,/eZtP Tζ!ܯOԑUZ~J枛$h )g 3IV|}oXWsBNIN!ݦ̵wj\PvB%{CH b~~6W)o.;F]iހ]HYoɼT~|'toTDNGS襟yZWH廞%,([G v b Z,b_ĞvK>vN(h3DrQz\kDW&e;keﴇ&[`:Hcm)5.}NcR"ߟ[x?qn.iY=<p{k0@(oaKw~f5Wj f9kyy ~^>ܹ)+I[[ÊאTw."R#mj**+5{ꗚ6ص^jme]mfj[5VlsL]+HZK[k#ZԵٷWN9ޫĈ0" \_ӧіڽ[_"a5= 4f vx=qyv!QM5tH- D5 @1b;@`R$>@ (ĐTfi fe\p`" VJ Mc28„jDB  J w d\"EhȂ6@ 1K$ \P*(.XX VF@}BŽeQXWI0T41aKBcDGxKH.t k-0[E 6\DB ^?ѓgj4V0tk$×ի@M _Oo D?_i|߿XR)*mQ0ONIN9=i0aM P A) _Or 5ggusxj-B-,Q=hH,a),Q@Mp}EX7Uu@tFÃH%"̧i͈ ) "6vD/DP g2E@NK.?ۛiӰhl0PGWx෽bBgmv|Ng^ Qk|ƒozm`v0ᒣRpEWE'+`p%)\YV@:>³,DTJj3@4/f"|lR`37;̲AЅy!Vk\"E!AP흨 Q|lT=Τ6qN`,P $bӯR>ԴsAsOvz]#SI_F?oe56>F: TC:t΅ 0-B"%B+f e(hm.EID*AM{uo O Cf.fWG*lMM>vrɣޥMB`@;ymj0U% ]ln@`0R$̡P 1 ՒLJL"6AHY.@ =, &?C` XD6PV:Ԃ..'mzo%.Č$fZ@&C]H aRJV C{7D{Os]Ɗ4[.=P\ hs~[ٓdF|VbVYd!Vr2e ҡ+3jgZ&mfLvd 6X( p " :/mX=:ok~'M5i;uq&8ZA? YAHT"es9y=N*hϮ -ІuYG`iX&I"PcbA6>8>ќew&Xlnry6bԽobÊh &!+y jZPL(龾=,I2)8( KR#,Y`6\eX ,֭(aA0o{tSŇ*xוDz!wAt"!rQoh7lδC[cubvx+v %@)`z*}b H KQӎM8#ChU,T5rPEEEW(J <+֐SPo5].B:|?ѥ؁N*' c!oz^Ӻ.)9߇zρG޳%1r4;a1/s--=3Kjwv5r- כ(?haPf)~5 oj\X@I\}kͳ{U遨jP_{{I]>V0z TJn?&OJ8P)Ѐ]?a2kI$]7߲_ LDI%9TL'I?=B 7  f6ϝ63p: e2 cQ٥7imƺ̟ф7ښA3kȑ<9zΕUcru 5Uύ?CG gʙ%q*hoEV)X*A*MAG,1S+)*V2tIICa˙3O kxkQTKӽ',A#P8B9pK?_UE6rʋvuHtI|<`zQwV֨"$º1dža1YSL4 b3C=ύ oA $z IYA4# M)4u'S : |UkM6T 3@54J.({0nFL;o;'[UŐUN=i THT "Y#b1u_i<>'e%UL6x꓁( ,W~bRHcda*YƐ#O[1~6O/&mh" n.k& -SK d u%4ِE<+0!SBLʪVy_2o~ xuWfN}i-zպO{;k 0,P(ƃ*tS鬄2*L!')SȤP+բҏ$E?^Q⣨YS%ypҽlAJfO&71UDB+5h{0Д&㏋nm5EKІ cie҇гM6ZTtPfAkeE6 q$V+{kWj|s!st*l_ڹ߆ӗ/y=+S lvu$|wҡI>"*6q)6O72-el[ m'W[l2b_j?_ +WaQȳM5^Jr]CZ"M &&[h 2Ћ3Uk>f:z&۝bΚLFv^Z}zBūcE$fi&;<}0?]UOj93$tMݮی՟2 * o6 R CᰵE#W@id; K s|xd~T6مK@"} ]b^T| \?1+q[z>-ϝZfK9t͋u` j?R7"zTYP%lUVE"B X*%Xu] 1@3G% 8f?:+oʣY/ks\j,n[VMܗqz,F  <x> Ef?G[VMhf/_^+Qx7:o5OZ)|vfpq~_N<qie{EߣGep?``mqޫ:jO o{m];x&i5} p;{,ӯh<~2O JoگCyF(h2K":)" P^O2AT$ﰲT"53kVSm["lv]J+-o]E&Z[$Nq氐a #Á@!V"+e~$?&;WvuhI)A_3"HˆCg_M=B?EO#{r%\w=(؈ڈ~s(,!sqs|y1N>*_0A;JP@#ƅlL2ݟ][g{WKcMJMCB[u6/7R+p4]Kz߳k4:9^lqFߍU25jco3yFttCK?EtqUw}fU] ՟b=Z/ҜZew/Mw>eJM=X``{cY'ӻHm[w3+(A$)}C;Xpm/<; ^l@4ldDHdCo[5ƶCH"b0PNk3kAّ~i~_SolH;nxƚ8>1?G n=_rk~w)#xsIi:wg~~eCxzCo~\-5bmn>2m+9_?mGWy^^qNK,F x0`\-;Y&EAU$Ӕ$i?*i B ;CfSd$$<'ĿtU֑erF%ʿ9f‡53}}F[9s;D2m{6t=JsNr-K."sQ<ѤQ@":{~}tMܹ!Di*ds*,!3uru,5GI^dą?Te=qVK~@kZ zM.0Ɇ4[wv`(;Y 60|[{Ǚr?WNfa\v8?G׉ks ﹩W 7bΆ~ޟale=|Ųw5v]qwNzw𕯲7iQ=:ɔc2~GֶSO~ԫ2B]LoK0B#ƻ6i3MoyTשUW|?kƶGjDAY dvUhڱVEjZƵ[[cZŭbT[IѶ5FōQh[Q[bƭb jET[A&Ɛ5dE[Qh6VƍVF6QUb6mj*+XVV,mhbmums[Ekj(ը+mVҌkbƢcjVXlmQ5Z65mhɱV5hkcVlcQ1EMɋTmQA-hTX [mcتыmbKbZQhU4VUUPQ/P8ߺVFƠ!*@P/ r$( +q/uQ6QؘS['j\mm֍9ySѧ U3jQVJ "@ܟ5ohZfr v6jWk5D{|S/)NhR{OgT8/Giri"~+ލ>J80h ]? J2 6'$eM@DwXH.jjӯ :!r45<̟<Ԓsϱ;FEX_١1J@zG COճ[&[ ÝO§ÃI=@>~Wۮגwd?O4yd!QP )Y0i%0aqm;k{K{Mov{k޿kr&Ńw K닕c'gA@e{3십ΖWQ1o%u&e_u'\~͔T?]^X [hdisԗQr d [YORܓiu J,{T{2p^2?np(V e\ppXeB9RcZmio~^Lh~]FTPE|9k@ M4R(Lbl oEoxU}6 '1[ _V]77zxuL/;Gڗ}_R{gNQtuJn6l?oӻ=oP1غם38?#l g}bj2/O8raNk,{5_P}G誧r̋b(,4D"ghC K~1 A,kn,|Elߧ1)2@ a,]u&]׻VQl\xw{6A0Fh)gӦפ~zrT496'W BU=bE/$-*D` 0n5"Dj.Y! E R&_ǡ!xe!@tTmV]5Z4A쬪 Ž iׄE,fiPzi1D[o\E1?[zGxxXח9dٍ 4Ws0+1aFE3"YK"Pm"\oE)lQE9yoJtYAt P$Q 1 ⊈L)_ M*HE 4'p R g!7^a2d~gn@ӳ6X7Ui5X1q / PA,f${!HYHH(H"PHAa2!$Ă p3 B2 Ĕ€ IClaM' 0@@1dbDbEI@A R[$fX+ I|"^(D. XRB8bWc1y`h ,U65(sms% R"ŀ`KE8m}7iN\L `QqG 6qCy(mQ1B@f"e^İ??G_JaR%Vʀe V/q&wj կk(M*2fd*ZqBd*!GCg9m[#c 21@I$ L\?ϝIru?'p:ٝ?OSIT=b 'G\z岓 ruGB_z2]nUsi}y#i}/ݚh Yi#_;OĹV6Y~ ؉u@ cO?6%c>Z`PQ!k VRƋ Ҵ01o!EYF@?6 T &DD "L"QD~^[`#>iO73Լ+r};{d$a@ME}gc_:Cw]6hȑ!N{28[\L1 ` ,9XVK ʄPK2X" zBRH%C)uZV.Ψ|²Fs 5$6oQ6ޣ&RRNHaNh1F]hT($Ke%4+$(x$P9nw!aKS@21p:d5ÐԊ!EzM$$;fL)lT`*рAdl Ȭ4TT0$X!$5v\V4fa([&dUt YFv#ЇŤ("""$,BNPDEa}@CEBO=T iU/\Rֈ5F\ʽ+j7 fȦ hF)Hd8Ht`H"$1 dRE:1VT9A0R쀿*)isJGF.Ec[ q]:94ͳۊ?ǥ=-組wQNX[Ʈ횣IR6NP- `qhZ FBZbT;gFApJ>,:}  dQaQC t3&#FIVIeIoj!F $$D׷(yS2Bw 1Y u;%l ^m1[uE5$Pn(™6(3(! ndrdd8dV^D ߛ[%Qh:z2tQv!R 2k G< .X0(?Yg2qzhB-qC7N~NQ t{"3i*i6辜, J7lys,2pcX0-SLY2q# ֡Q@YhQDK_^sj~$tdf׏+D`@U*>nU4a\ߗ,=uϓ2T?L2IqiއwAH*kسP1U4ޗՔ1ZɨA2*Jwll̂ZSHz=8ƾ>n蜚ޡi#y>799)A"wAEdpKنe"7n$ Z(lGl B0 Hت,!*?piKglAaMfBu*gF$I$$co+OVb~1/oe&ש9=F@؉͈u3>h]ETLD-EuLHx(Z*BC !$Y  Y aI$CO"<&1Hc!8N,aђz;i/ˇaOx8yhNNucأP@aGFPQswrWtDA@LQD w^}t^(CH("9Juw-VVIwzkQڥu9 a<+f3>K8Yv0sp3;Lyp{Wv tiBFYK*|ӣUYKEӴ'FOXu Ga?46Jپ_ų&Ɛlr+vE)EsȓUo,"LMrs1ql؆$ ڤٛ]t݇0{ϋ:RAû,dv_ y67{n7hJ\'1 ^d;p41[~ $lwJd͆)wǹpMH$XŌ}Զ8$ '/PG>? Cti䭺{ǝXrLw=7ድyn2yok~S*`5fΉL:E!v/\DAsi`⧛i]}zٺy7jn8/ʥB;0/}EΝ{6ym&6=:ͯ[rnWLNkWT}qP9;"9zDZs4ȈN;꩒@ ;Ov奏r2tB$9}_l&g4 J0"u~U0'cFA )$hΰzs&L5}I ?' bϜwDY0a 0f Ff.n.nH֟hcI iʕn8 #⹼mm!7 ?ooziD=8`0YMM9b*pтA+QP(oD W' Kp2f0o|zٟCk5 O}9ᅣa ! :?~\Knm҃ǧPH!B3+P^M8tGY5M@kˍ㤓:RuoþxC6I Wdrgea0w111AH+% tz &a ۈYϨ™W =[)h.3xOM%uӿ.c'(hW 4_¢0*[ݹimD0i͟>_0D66l'༛A Φ(/S|}U@[;m85DOQQ*ALga&7b; O68M7BR[ ac ٌsLM~sTͶr_鿈u8fZ7JRU^Ω;?`朧ٳU0OXGjJЬrC̯z9>;%='QQ:9@K#jUV!úX}"z^[ƃok3sw h]*|o7rUcZEo?.zx|~B~$BsB|_>navw{Zsݸ[ݖp&&WMz~Xjf(w~P1B>޸:RI)(n72v_w! $bE%(~M0BC&:}{B"I!ndsJ߷@BA2y=_FT"K,J/UAbE}[_ـ#|.М LkkԮPxa,T0k1pvWEwߚ;`̀(1OqD= IȽlP{!T%A>5X3gt7.Wӂ~A(Z~n(wXv^#~_b}bvHJ3"rKo} \An(hJG4hLQd^D8O}=jW9ËttD҈\..8a02^dG͗ʲ HL0̝v;q6KaA 3F0lIXP57 .(!B$%1^ǂP @W llLs=d b :]C^.$=r$"L>t-j,!Dld6[2hujtЁ"IAI i\([ X..{fd E#3K`iD̦֚g9imhAc# ".Ep[:%q} C0S1Փ F<ӓ/ܙW `ÓS'`ɱkM2d^jD>]h9xG iITl(--O'DS;3hhO^݇7Lg\1<~5kږ3J:zRQF1Yj,WqV:v[*TD2FXy9.|2Ǭ//i,)ȗ@)T */<ik!-+vՕɱU 8R5+cU㺁IOi2XO$dIB0 /Z9R f?HLסZm'/8.4eUkUUxSaWotXX/vM ;9Ft[1n%YiZOף<=ksf8{E4Ou(`&oO” bf?.3F}y-hΥlL €(]xkp!ni:_ =4a +zAU ^C)RfԩVYZͳYU-l30Қi*1/l[ $%.KHӀy5Fk c5VT ,yֲ'HȄ!#FcS0! VӓGtUBa0zP匄m:oI Y?EyNS.\`4zV4T3,kfk@ A $A%ɀ˛t(9QP,I*℀ Pg@] mKHTF FX5'h ! ^ٮ@ kOh}BH2'H eM"Z-)2V`` B8#!}gz(Ss:Dddk`u8ِ4clj$VTQƭ5*jɰȩ5JX>W%iN^.Op g) M$#N[5jv T"Rlc5X0$Mߓg Yw|"o^Xk!;j;gSOo-Tڟ{.}RD]j4 gQC~~.iUg\8)Ƨx ;d CЪh8aȠ$P!$IVmo`ZE_1ѱN'8N(Ⅵ7ǞoŽ}m)bSURDd5ABboY~L ;$EHDjLܙ~ͥ><~vP3HBH#RW| 6|KYuȲ7i 8l0L!`ゥZoKf1Y!D3/ `A?u ѝe=!$Aq? dy)rP6@ sxW^}<{ᴶ~v\݉P$,LQˠSkl~&m)؇1o '~L-# !Xb5x,+e! q!;2[ȺQ =4F5B>ŠJjI,kLJCT,0bA9+4@ɋ)AaRlmˊqɄF vɱ޻ CedCaKp᪬1 ׁG  9z1@ b M٢ s+rfZ}_*;ݗTow9xGt~u_M|x Mob&s>K#u}xUӗCcw/{|7;v z]DjBe`ޫ2j2 ᐙ U9 Dd֕'T/sLM}oﭩCX2L`\\{83,I1?&fA^)lޭ(Hӯ?3 &=2 AJ} YM@AQE^sk;7!o՚A`(-_ݏZa0: PgTyXۨ h(8'[$KVbceSּʸ7]'OjKUɂhk?NUHQYE)$6&tG@cۭS=;N*!J3"=2x(ow@tκrۮn]e\:};lCJGިW(#P݌Űb{wҮ{ϯc{OujxsE$Yx(VL86tvژ7$t b\'t! 77ȜmU,uc!j]c L!J$* P%ڽu#cƘT_UK+?M_E.hvVjbI:ߥz}7~c _*+?T&P/:jkͯW??7ww[SX<OzLJı;7o?<53P"'$`,̓\T6HHknGaD6QRQ1m3R/|!ɬ&yTv,# 1-- A11b Yka $; 0PbbAb6Z" H _b+g)f_iɑ]b9R O.rc7g7o 7ok[zޢN* 9`%c $3E9F_R`E$[{s[8Ye0LݲM\5*"(VL>W?-~SxzJ|Rs؞TzlS:~ۊ1^"Y}_Z4(g'DAEPc()b @ƽ^c*  zugQU+v̑El8&՜P%P@mB3'U\RUmGvDw l0A@ ~ PR*K\6DC0E;,d "«tm+vHF*wM9UwX\5 DȑA/@KwhņiS~-ш" ij•p"]qX;\:sѸo1 J<2„jUz՘5Z 㩙dt黓QUYMeӌI eE e9<,oIK6lxç 88iePAF:7g-@;5e$ 6<4䄵*na kpt9 RAJHcRۗq% ( BjrF)djd DTUDb ÄQ.]^71tϙͰ5 yZ2Xnnw_?mol8X &x+sp-H-KA 6v`#x_/z 4F5)hRWe$9#CbYZ-G#Z1mh3vmeN14ba̭֫J`X/-Hv3kn%:dlʵ3xR0d`2)a1DԘRHI"FՆwf-vmFI A(arUPr\T CB}͵|3mECq<=iѹE/&;mzJE6Ƶw!K7;Ҷ9!UA""1vnn%LH}S ua,krbe8$r#Qխl!FARHR1NóL q^1WڳkP#k#`{2@. $N49-\0gvyf'}>Z'a2q޷" ;)`J$cj4dz DЙJU<:!]ڦ)LY; /D'`wtrw_Jv0kv9 * L ݳ^ L8E,mekjpgnW6l;˭MV:[b / mo(,"z \ V,XV#UddD D"eX1Bl ۔ 7 5wNQvͱ g;(Uma[u |v!$X(S%3Ydhm:ͧFmR䅒ALIxAe:tdQa;Jl6BajHa_ibA5_}}^z?u9uM(/%0n@vGb&{N Gj=ѷ|~ؓ5 Dw/nRٿQ7I~|u8>.^nR]gY@/tml(|-Ve-{Dۣ(pg2ToGt+){9+Ó[> j|O$ykuxk>|_IuUk,g^ca^r}GJ9vޫFhD6Z\md%aH ,)K4`HH( P =7^:U-~aL2eZQ,Afg}E , ]U h0BXd#.X*lszk k* `qeXVudKq]Կ^tY|7a F5Qec]:8?MeͯڵU Hit\Fܔ ڴ3%SsԳcnXC4|Ml3UN2׃g 5Ieg32Z`d륋цs,#Ye*7\9`qA~6Cc}ݬَK6P.fY &(2Wu$َ nYnLղFh$,MVNЙ>.4lhgWt6le Vʺ&.ۧLM3--PM4~]V'tMfv}ݵrr_R@9FrN/QkǴMW+Bb4Z:?|OuYWk?Z}8vӌmqŸXl߆5l'R&ӻ}b8"g}]g5Y9 9Z.}7q}qo MmӞ5&S -{\D^&*JX!bdMѝ|zosoVUPA^`ݕQiީB]9dpAHtM&&~Zq{4l0@`| v6ƎgmM}#Ev۫[kX PH9bckY(1sh (!"ڪ+k @f\@-20(7kc\ 8'! bN$R4&3LjwzT2 ,ӸE`5}\̶[(ڽ'T2`jviܪ˖aLz8̈%T*br2 !y7qd+XQd$Lo%AQX0EP!4[e Y(9fmnP=t<6p۔:_0Q V0c#͝g0ɺVG!RLdĵ9~{DOodQEnpV1[I~##) :(S4 @EV1:UVXP8RmDg F l^UO;A%A26㧚a G3zU-\kwU:H;O'.= ɳw,Ńqh$T(?  E8a;_!>Zr糯Y8wpo OgBi"9ƊUȕ"=Xog=VuJŘG!щ<6= |^H2ڴv08p10H G4UQhNOV9#"IﳛN*W*Aq tߤ:\w&1LI#(n6gk,A \`@ 5ߩ5 )qKS$Nۘ^ܬ4Z .ߪ-/C! Dl6H" U bNeAh0DI (DDU7]j@(B1UKʡ3MpmĆPpCճ{ Q ÅGV !E!LHXŊ"S3ՙ۬P0a]\m[yß1d7\fR{ s0S,JhhXS B[ZfńXs|SzDGh&dq@a‡>#Ć&!F ,'-p@H%)Úk-PE %-5 -֩BN$`!|C+ 5ͼoI˴\3.!( 4ɘکhQ0Ghx% $Y\iW1F H.{ĩj1dDMe_mRIZR=`J +F -hH~N 2d$b0a:tmD) qg M"{ލpc=.DLQ JQXJojÍ` bMr8 2TyEJ.AmШ EiUh}͑U VAW$dU1W 6D$X0$ :eޛ.Y`ot4~,񩤦'w E IemHCa7:) A 𽗯>ʿ\R#C.9X^wLa};|rK 2Fje7:amr`8~g< ",Djܺ9m:H{0kWErB}(Kdv&1ra ]:@p?@}DϪ9szCy134"mK`Q k C4.|Ƒ Ab %XBL5w(R tC,ƃW՘n6Bm0gv5L~IF ͭU0$́FYl3 38yk~ph{XSw@wLJp) zaRdhbk[,nH6DC,itҚ@H}OK /HLGۺɧc @/^!c>ϵƾL<94su^t$WRWmU{4DD  |һ́|L]4k IEt:wHHݠ}ܟQH &T=fn D$Ano_/_3Zf]Uڼ+.[ BX$X-z L"}ǝy5qdP^YPi+6oH :-z?eax4_]`1C{wA6sR(;htr@Q?ΰ"yEKkN_Y_0EyxPٛ*E/̱gʕN 1;nb}KdU?DDQ 3I5ShA`ChOmO( E"DȀ(uo u}Zߠ+ÞB*w+B|ގP6B+:fO*ˤUrjkΠ7,|5Q/CK 9|tVU1*Lq% WFՉiʧ\ ]GIY&".lPGbe?]=7HJZk۔+h`rБFv6{#T*V BGcMPB+:<"U%@DϨ@m"gu x{ew4hμՠ:BH.E]9:wLK ( T:}lÔzʬAؓj "_l#+Q9n[F d>u+'/8خ]4M:thE$v YwR({^T4&x2- C% wbt#=(I5`-3%y~Ukrz4.e޺v4I|.1/r-Kou,k-a??Xx.u<X]kcӓ(qexϨffR9h`mwhnAq:8 xq󝏢 C2Z[&X ׋F6B)Arǻ!&yc4+u,yԙ[l G3sj<62@Jи{#*oU\=d5llp\dPvU.{YV:~O٪ ~dñ_(txz0@W9rOw ,&hUn_Kݸ.…3rZ׫~3W!BT#ĢwjWZ>K^c B4Mp/ώ`@Jޟ)~eےG}{Pu@@YIDP$DFE@$$UdTPP@dA@$dQ$Y$D$IPTn8[gtX>,8dY5;MtU*Z* #8V7۾PTTאE]tL *:sk"}IYV.ÜEDE ϶~~~~~.Ae(?`.nmqqqqqa]p@$QVðP%"e>^19 "*&D6yyF'>1\T LPM<$Q] .!'@A΁ u[u0:ت!iutYeYHI4 $EH1 qzo <$H {ݸ #!nT w;w;sT9`5Sܯ/ 𹻙S԰ )>j4smuW\V[z٘\0 bF]k6@^wq#p͈ !(@M.9'-zՂH%{O蕻oj[Ҏ0aЖe\feR=B$GH!/# RˆNL;aH68坬%["'>{9Z;eB4!m( L7B" ;+Nich +5L[$$6`7l[Mgs~i@}DsVWt`Aؐ&~SrwN`Uq0zZn۔;fGP,Ȃ{9IDP\v^ƻ+VnO?+X7a9ﵗE_<5QQYj*b R<1k"*:TcRk1jP$UKEU4[< +wQ7hl cqވԭ, z{muEߊ(ﮨ(X<?dQ4QtD LTG"T((D@ yȢ*ҢU)-)_%;jȈ*b'N~(G](P$ @PI {% h"nj-vkѢ[߫ m‰0\YvZPlTW3]\Z=Qz!R h,o61" wi9hRo)DHi%Z\#>ctЂ>]!:WIdP_(C^>Gw1?KIԧі\e !ᵇ4 u`7 x3o42wHɜ{@8v5?s D56ƶ .W`$d8a>ήX []Rf#]'qp%@ߤZwx@Vg{fYx6bUPUC_Rڃ6Me0cׅj_U_ _ϢJ(zݖ-,h >r;s<9rK^JUx{"1F['9Y,'l&Y$y1 81>c >GesOщw' I.$9E+KtK@,lJRD!ҔT8}ޥa'y|mg'H{707(BaEMɮC$?K{s⽷o ٯ?bٛ0kvU- @<¸~DBHB?E Q K|B0<M⿞.<ITH nY cxwWrXSrG:p-~Wsp4trA߽7s Y)42ʠm% * Bihg|  ťu0ӐL'FL:>S;*:>mVB]8;Gia9Kd/lt;U)5+2?=;ԘCj]_ߛ¯ώlvց)@-Du1תi Yݹoo6Bߏ[':rXH"; kuCc}I붍"Lw<9Pye:YPg <w9?.Гi>OW{懷{V\7TF ȈIZqR ;n`!e1N*:~'#nHH`+;>Ҫ +{b*"mԇ ?j3wE'f[2sj FcZ`AaHY4vr V%9Pu>{7qw1P o HQ&؟{ZzJЄ%ͻ`|?i/hfW :_FAҸt<,'CdwU}Rqe{[W+@IEUP%ؚ AO w0jT'00{]cTju _'կN;@rr8C@ҀFOݝf96.UvD$Omj66Y{1<ՅA$@GAg=œo$m( kRWŪS%(Vu*~}DEx\uU}$U81TN?v^g1MIx rp(O<2nC.9yKJ\T#!E{ cn% "$Bc""CC&`! xV.7}/}-4z# })(J"I4 6U#haKSd9V_m~g`b398+¼ra j H` Nt y4a:(z0KvtvbHWsECrSfXlmOX~r'qv(x+Q^UIeA0&E ->H [)s\%=u# n7ap2;/O${ysi;{r֎6[J0)U@D<`'},`) _,P/XmY `*|Im~OW}w,PRŃT>:?MXPIڗ6Nib/p4v~' Ӿ' 6 $ !4XDi^A̵LR)h kĩsp *P(@eQf4O>fbHeWƌ6"RQZjtfu^O >Z-A98;z?T> T?vy_R5ߗ$2EtPm] r`el,Q ;bmI?V2›M$DV!$PUD r#xe 33Ro5/A6*VsSf) $APP$W%F3/G+MQr\oyl~(o-pƉT!%pAQoiyDɁf8߯ݖNz BB P*}rߨ|kg?G*q: xy@o) d×ϣa5Fdnxdv'̼{?J"!@txO OsylǾT5Ԥ_ @P2ukjg g諲$CS>%z y}>V4 hUլ"! =b k*ESlqg~jb('O2+S`{{Ꮎ;X렟6EQP Ȉ8)>s/(r dGej?K8gMaOڂ~=fÂc!H 'uq;J`9֞|j4CT&M̻J"tDi+(L!;JeI9r"A_k"z{'NJ+>rB>1/% h @W~ׯ+N=ʠ; :N!(0T! \zVGl'.Kpy{K~kY9㶮ޚN8h@H(|aYͷV*GyhfENWG@AA3U$n QX$QR%"AVEX"LαؠUY ?wǀ ~n_cɆMF>a,U"*,(D Q@.*WWW6KhH[/5ѱ@to.$ݐ:J sY@}Xs?b倇C UƇj'I/La>6rJ9,=KbLua~wPu9,ɢ{'yDzNO_UE}ar"3"/k|Hp(kLjڶ1 sUg#;D@B'Ռ=đU(DyY@9K|/DZ2L7u׺:=RUvwmIvϣMRhgKQHjDДeRfBϣĖ~6-5:[ZigH(jL~{+xOڑ)YaNlC{ma-X|-y>PQ6]| ;y{pGm^M|&|*@66Ză0D}de`F$^en1`TED0 TEB XSDťGlo7ϚPZd)`4l0ڋxct,v)U`Cc@ZKAYܫЦ 8%@ )S}H .Fw7FwϧC<[kgS3'_7_W>TCJDMJJZN5Wm^`!54'?IsDY!"@pkjABW鼜ʕ ջOKoiH<{<#83A`-(,Sk2!2:|wFIpM%fݐd$7gՐ5>/`J\08֋ @(nb$.XӖI\: *ǃb htScEhc]A@ JR<(.}Vm(&J6]nQN ˬ@=4Z-l>QyMM_4ww76=DA;ъ(OCr䇧vM_[H80Tb@0^D2 9oWwdh2%F+6k5clPBjd!%mml&j !&sCX?4.pNϥz*%Syy=VCb|K53-^<'} ,@ۗ@C+>=ɱ@Z$DLK J\"~Gsx%b\ sA{*}O ֔p:KvzOhMݤ6!uh0} 0ʟ=4{_%p籷ZߔZ>Lƥ왑.bÕ{)B*!z)paN<> vsSnyϞ |9p@Fmk I"5 Q ieC>R yЫ}jGLP*7 I{JGDn]rqQ~g_ݚ?],COqAj{*O\:N@mMb5օ"ۭiT0ze.=2du4g4] 88n/S ӂfEH'J+%et@X徜bZ4UߢV.ɳV ?;O9QIjREU%Krئ?`VҷW2&8HeΞͤ5m.F̭ FlTR,T ~ wtϧ[.>XQ_ctvl ,` ߢ};*M&"ԉl]kUu9&wR)[Ng~\^6XXIeڼiİ?c‚RPL{$>Q B&(w$u|R8$l߷6Z(ygQT[LJ0m:*23Ѕz&U <lxaA9^c-Hh7=lRe,ѫQP/ְ]܅ksa%zmU88F2`0EK[xvKxV@C|dw:4K{LP!Q!iKNrELsT] Z t 4iaok{{zN*2|/PlCCM~$'[269"ʔ\\Sų2o;<|֎ǶwBd56)16e o_7b)a)G&`4XyL8K=\A>GJz#%-''F̬vrX]!guF*\*:}^ _~ޯ~ '+O:9W>[jFDdwg[9_{K/'P duafWXB Ws 䝅 퐫_q0չRZ&B!~':D##<8:w9 hSTXbN(;Rho׏6AQ8hbHѽ560{BSm+#Ȥ(2( ZpMEe80 ($^n'g@B<`&əa:b#煣zmwm-U1J&ԠGmV.~@L@'{d`/8fraGMLodΪ#lǃ}&x#{FOok!d=VvCˁ7H3/3o`L=MYT,'=W^#O$rdm>e$pWi@.Ԏ&nwQ'gl;8g Q6y)\9î:@S8WuկȤ&XzSY2t*ΎOmyR=˦ZS|+>iR`>#BڽQSps\+!"e Z9[ڕp}8"M<mٽZF:0 a(L;- cHEQ 'N0tU4 ʤd> g>IyWIG^yA-$vI| 9IQ8+x]$ _7)Natr% E@v[E2p|:FH覊l ,TWB<_2o8ZhjV˷-yb]~sJS1|!/m ˀ09Va5x~qC}G,et(Gc#v{9pFu[%8T4jG J5N#DŔ㐻/iey7x8,T'`C (m%c$O,t⋷dɨpegHycFA4CRlNokp;cM9,ۋi00Fb3Uz&nLYqN||S|r }c0ss}у;TRebԐSMp!z B9W\hֶo_ppjO`ҀQ)=Cb6AYy;ݔ_XE &!d>mJzR glWE4Cb< ikKqB'ظ =U𕎼+)p^1i e-ڷkI;@pJF^ 3%%\u7fw~2~`;j IH}q`[WSD\w8M4*MG,?"<&6vکWh /%h>9' upB eI.džX8R \lDKފ' ʷ!w~ ^shjkG/2堘,~)Y5d9v$qyA$ݘ(fw3WtlG*ػ7^-ܦ#v}@? -c1qj|p4_%, ~%Y&dJ?`Z1Jk0W.EYJ==y߯.47xD-ך u`*2glH'8`yY".#kCs꺦ǁyտmŭe[؀ ="iZ =pifH2sǘG\FžƮڴJeLD%~oZAbיah(%q$s+D}hEAe腕Ub+f{nqߦP]Y7X9zaGMљIM7"dwtdcf@a#R}&s§E8y$@P~l빿%z3p ~às~};;7m~R4<ȹ_LiCfHA.eb7tUdE@Z&S$>u0|[⫓lۍIsJ#l+g  >6vW⭲žUiw\,w|rĥoZ eť7ۮL{oʎre?(zzD1IM:,de-Lbh;yfvG+̗E%2_יEXXR@(Ż]QTT߼ .a w5DwǐSr`ͲZTQW\1s}A2-V'"}yk bt[iO.rBߵY9Р^{4Hn֋r oӎcxαY5*+t4UhYl/Ze^xJ@lcHȺʝ >~VbHsҮ?;G-_yOߍ^y NE4:AI(z3qχ}*<(^r%TOWVܪr]sɠOnxAϚ$I4RUwIPwXԴ|y}D{iwk,"$z}_>氆H>V'llGn9ƴcfم))}f`crA߸ } ĹDE/ /Y z8[Hs Ѡ NbuHl}BYYFmZQ7_GE!rkd7O~=5mE?~apt2vi;Q~<2f _%71*t؏8AS> c1bq(f)ys$: XnN>Ʀh5$KC[MHW3{h.<*ig2KM4GHO|?TcaJ oz{g-tu"Qsk% WKM"!.[ Y.O6Б2/"QܠٱVe'yiQA|Ezq+b 9϶o\l[ܸI&X&uim 0*:;"&PB Lq7\J2% n2*iv[ G.E66W5f@?h9T$`i='a!FkZkb8{. Bΰpۚ}ӏmewnMjf.OD%{Xxb$r-ҳk]&_yI3ޘH0v_n"Z|CXT|8؊w&+B9Ȧ')ˍBuh1=񝜄oaVlPvKB!;#\HP+>Uo: Pf!Иw4? 8H>vX/FbrX*Wvڰ?E )t[7rf(|Oi<(;hYn7/Ob7TEM雉yBGe)iCOgD%$ͺ#؛T&" |dg埜։Dk-'u0 4::E+?ߨSv]qgU"]' ,ߝH#>p*`o^o*⽀ZcDӤ FV:61ZV4[95&&N?; %5ztZSP$sRpLu׆ _\LRf}h-MpyʩiV'=̌G馣mJB.` 7Y 5b^pk]~~M#=WȖJ뷔c^mIDP΁2e#_bspN=s=!w1Lu5+&v0DBW gHJ_.%Tk()H2ƫ0v*U2 ~ v| %UjjXiW ̀58߶hUH{L6Ƴ DƟl4|ӄr zgBS$e ]> Klh+J5q(܉;@:rɫ ݍeʀ[ÏaH9h:V}( w*t\[%# B#ԅR1 B8 s>}4M%YuT8M5p&14QaO:[CG?$D;{-j!~[N$;mmC{0tGT: {?(KFާCE8ivH{;L r/t_rfd#cyj#@ι~&nk|gLeɀwH$]94D$0 q &!Ѱ;/v7l],q*{-fϮl4wj#W2]3y\3X6[籾Sf TZ9M1]]bGkb'r/I h#3%! dHŒ1v@9PB_b~=vA{ZǖO2g 0*+wF%H& W:Fb*R_/ b.U]J"􃌈GNz+4 d;1fıpTfT2:%KVԆ?nyXZ KDsu ~_EzAyvҟ;l<p0~WwίؐΪo\:j; r\ w> 3~Nr\i9ᒼ)}7~|TฃROvҞ]zhyZWJgJCId N@&EC2l.͖zuUjq+UoZ.p̣KDI$S_衱CU^&EaB-IJ+:=.! ,Jg%0j,1~} E$TRv?I bφ Λ:V#)!ǧ18טXna֜rӠ~UsOaƏVhHJ>C*)|Ma$hl=H1DsYl`)_cz V!F$Ρ/9=Gm?Z&[P`O' Yg1/E*7a6} T+3sTȴ⡽?*HuLIs-C=ZJZ ى\L:YS9ml-{ ˨)DVO6I[Jb SIo#>Mu0LKlbUxe^aa0+ 7Vf(> Qڸk@/9wF$^\o}U=`X!n!\ȋv2|x"'HvW 8lb~ ^#Ta bB)d,GN|Ǵ#G* ovm`L!9PN`?SQHE6>.}eE$Gհx1莟E0Ā4!91 v'ܐXyL7wMEz@4 ؼTt%v[QZfC ȯ4qq( ;L. W{5iD%#ꏶv@&ofMWd0Mb*Q-)f.VX&p5l_Y#~>%Ć:i}.VJlV0Td|8n*rMl)]~F 2s鿅5Ja웤$^eDqgC텭DM;ڽ";Q> *ڊJy]_#vX!N־H^-\\حb:fz 'WwI?3Vԍo Ѭ̿xHws+"h엻?ŦZEx\୙΃2 a\WJT{87hhY gX# StARskl<\sZy 6,) #GHHn@@o'(T8jWZfE$ĢrY}+e4u ɗ1\aFh"PJ/yKYa_ uoZî`IJǝȚɜ !z##d'E;V@ּ߁KB/9$*!u4[ey٦ CHc_J*8`a t໛ 3:ܤK~ul\r_J꾕f0טՉ`apѼl'5O[d;@ yO.]"s~w? מa n)p#ޓ=e/CT# 7Šgns.rv#q=T*@_衻/ 9ɶzmmD<^TdtsRj~J]^}PN\ wKh b+Jz=x}#b.-Vgl苽cA(d/Rb(S< K 1$GP)M3F+ʸ|s~^aA29P^1/$ ov60zE}uz~Qcwk Tb#"LL:q$96lsU:{GJ14(32OQj5( jȟ ICO$#A[$i37%Dٹ̱u9uXg}ٹ^`S3HIz 0̅5SY~g 9,rġa_<C@Q%P1R\(>]˟3վ4\ ܜ%\̱Bagv~m7ɑd\qjG%yg;bbWnp1:NE!$~^)vF";ӱXA sT7멬 y(3^TNv%8s#I$ [f=Cr`z{s\-]x_1=:s??W%VG +ݵ2$K"@jfyx3sZΣ#!m@$S&LooӪ[P;nuc?ED9}0: 7di^5BƂ𱏛,.517g!z&׻P3J6/&Op\9"1lۍӍ9M"HÏ=287ILPn&fd qJ24y T j_[7eeE̯Iȏ0򵇤xn\M1K"z7/6JµHGP;d2e)װo;6)͢:)y2)#Oy9㸶0;$U y_E$;)CGE'tfҘ|.$`:GA/~]vJqdZPuwE GAmw07DS!<CȺA\k ae 8&\r䜛AnNէ2~NڿQ'@GɡkʳM5%(7?م-jQm B<])2`.(޿A<@n_nlRP>W)S.V߀S"qA\&X<)$0 ó7Nf.,kq)5ydM&Rv6e,q*7&2F S.[0n0tv5Y]ORSHA':^sbtK3r8_ɺEY)2trDO F'R w`* <_l7ٹmZ}% %EWI=u [;qi6 .EQ [)H;'_I̅LAf~8R@$$1ZD1 xJJau=$K@;o\@Evo3bUa.K6+̅B["cC GZw@i7݊>U\{7{ 1ĈXu ')?ˡ.7uCMHH4/*s6_I[;L?uN~G&T{*oQ7n @q]ZI/߰Ml`$NG㊥ԙ%"V tGiMg!X ja$zcTdZaEN DHRLn ӥd1R9CGuaϹ<;K}S)Ӓixpv 7?{ zUv Υ)n(hu;cew&' $ GŔ"uPʑ~N9݌H"ŒN\Y@X1kQUt( pܥsOsm<\nZ8^AjHyl -nKÏyKfv/JGc" zһ;.&^&d^<, ,\j 1Hm R_{nYqpǙ!^ԖFqcUDZ'/ܦEzuif>Y[ ~K3ik$_)ZHKi4=DŅxtۼɞX;zɵTp0bVO"#Y#'ԨS8"X ,G4$k??P*yM]%n5䬷=8 ~/sC쵪rV5\Gyf5n l}o֛%N ^ոBa2)s>vb}hzvB#E_tH>a>wSj$|dX>~U()  ^ X?p2w`V&e`Dۈݦ$ Ў~Q$;?\ȭf a=䐳*=F_!E"< 1' ü.DL41퉼DT'1$8n[WA\١dEZ?>/6ܖ8kWrt榊s0q Qنi%G-ڵ?܎J3xlz˩<0>C&L uCxeo.wZ^|~]F`/4GXLQ a[NA85VQޔs7 JNo!٬TX9zV7pSM%P>my~iđ壃JHG1eT0?Aj1&y&Fӵ3TWbjqǖTNpZ : wjn7l){tH]d|Cj^37ʹ[`h,4&M:, $E߯ւt$eZ#XMn\* BlӋ hԪtj`x# eo$"!1TjYAZyH 6߳O^=)u"W}ENcn,#}OSƕώGF"dawdĵqO@u5vY7#KT.$&Xwoc/l=+DP4ΊREʏ}&l]l҅cK =s=?{u60BV7:uBB~Y}ab#eh2̜^.WP'#‚&OMEu@ ݬߑ k~9hwPޜDH{RjGS??7D{D=I PuS@W/it]y+w1Nl=;~ؕ lsCC( mٱCm` +;<ā!6:ҜmF[rzSNiC㌊a{o~S(M1nuv=KfSu¦HZT)263X'0lPWDakCH{gдOYຠҊfq0"gSD_]|,A]Y[0 P2Z.)#,iu?hd{i4OAA*#VRò8fA$;YvO9hPt\n)ͦU[Xel& $<?g(^`j$a@هb`+9~^$:UwH6S[>=[@WGiWؤrm[\X9k;Uwr~q]=ǔA1 8J%7g2ֆEt*{^QCIC__!OU.MBdC`i TA NS*5U~+O&Nmȍf跻(aNTߟ6of5{]:n?=4u^`ȻF;%eXYM#F9!Zr)Rx4wOTȓ_MAr_ :Q<ӣBTWHyfeOq5DF@B!L)q{?7/F`Br360Nlh-`"( R+Slp KŤͪc *e27D޼"ګ Qs_6cq; +ڹ%p(z{si|זpc<,­+}x1qaGßu wF0/n^YA KH$U>!Tms$c}-ޫ!>Y<;Q i ^ŖP+m™)G +>^+ 3E8XF--}0yKs/>\A@lV2lAz &O9+O˻\zq0rA"h>Rv_:nY#IZxUvz4BOAfȴV[,GtLhVNgo'b>6\2g2Nx%Ӥ0dk]n@SnUA".턉hZF ==ܸyd}9u#|pMlj(! XU/i,ڲOc(Mkco TvL< ?Yrkcɚ_I͕v(W":d^n~:[y3dh7mODԆ+ZAM'pjyiqo 4q X! HxwZ!^1k|F+3}lDabG;fNJkg>{׾ uikj]lݘP ]OUBСMEfݬj{V'Tkcf= K&29UQ} P<`SL,-Hd2i&zч׽\b&}fkF5 _ح~FfB!G?*v @ Wӄ$ O&ٔtiUTk2uPw!ͨLΰeEW1z[H. rPk+)ڞO \$o`Hւ`8qٰo;*®b. :U׶\E l ^dfbahX$Nj֙DNar9|t9o8Y9JWa!C=q+ ϣ/ak?(A=t|g$@}7+D$lgSz]ce/+|\0,C;푌b: + 0_jw;o%Yh e@V*.ؓ bޝky-^ɔ `RPJiƣNøQ[EGq9XPLvde&aǐtmuI黕pi^V3ًP]?Xeu(ЀMWŘeVQ}B%F-qݡo}vG/n ;y2X$ә @No;1A^QYZ\4T'ǘx|x- M>XRj zR))KLqa QɖQ$fw/G)G~K;vW#y(.Ƴw.[ZXN{[]I1Xw|G+ }~D keInudӴZyݻ|[0qMJޗrW%VNsnīLWr%Y7i5T,he qC dV}GϾo2S}|^y 6Ꮮ[bpe^ϋEMi-G+d;SQ1:Ev} Nf;w|8\(k(䯮.U /N =$gN qc\©ZlB|yK$frGCMJ Osj_QtpUyN`[Ėff@e$mH R5 VRDk'4ԍk0@ blYlf]M3"({!W<B!15ԳmIO5KofƮo"E0[aB 慤xe@|WAe}@uaW`Zd"QcX@(aᶎL(fl` Ge?aG`6*V˛2b)|pHt}mY37zRj-P2hďsn;nn;Lt'q8,Ggv_Ʋw|OԨ'hk $c,ӼñpFN| ]ݟ*q('"V4bx#]@U*G WSm  6_ h2Pǚבּ҅l\;(* ?cJS^Ͻj9! -^ʫ<,pDʒI:=fOXgy լi0:𾷄q{0tM0%,0K6pK6-/+rt%3rjk,,&LCF#,& Q=AY8\KUg;d[)}:" 0 m vVU/q:o|DtLv0[´ŃI΁GbBfQ\I4k<'w5Ol_Gw84BcCq}(l }_Ʉ]pw}`{MNkKBU Ivݕ5hSDQ} $']D}אrxxYb A% Iʓ8i1yŲPj9\0a$Q=[LZ=iFnV3Uv!%إ.J~@/kwщR =W_ ;XZ_$.7[pa 6㦹cN&P{Yl#kTD2W=h7IyމX:yh̆mOLf[k'l9@dz+g*c/BἁAh|ʓף́ bƺ0%VoȷCV$3oҧ@o@dm:i-372ɷj)C#Xx `Z` N =#(۵~>&G >ʶXXꔩǨpBklWP|V.R5G9{Ѭ!?h-Ak7~x Z.u/ͪ*YA? "`˯-љ/Sx+!~EuIU ;5/['y_!OS bHDzQ,|QĆb=bPR#Ϧ "BC@nKQXpq;JD{+.\79NzcO;9NwިS:L;cc $\A2WV0u75`[t%qu*E\HPO6Ry F è >N%'[tJ}elO (xսODITr 3>ZϵCOER5ָ+=6P% B Q9]s4 ݖn{QĈ' yid俆&ŹRjG8]8.|[*;@Ōm/t dx5p쭦UDm@`Ri<7EI͈_ÎNhv_8ǛPu'G:} Utj`?J6ۦU=Ś\4mW,1A]pS2y.E͊%coΌFR$?jW^Շ5.o)DS5𪡴 CBը>.G־B-}x94W:[svv7 " r.:3yd:jDLRMqe 2u'd0;=r1dszpY省odi8^u>+[R"ppڞbE:6 构.Q}QvB8uGT՗=i~\n&c[fqM'l HGN~е>ܒf[Z wJƐO w, +  YZ