samba-client-libs-4.19.8+git.404.38b26805d4-150600.3.12.2<>, ,`g3p9|?"'mܱ.̇xܝF nv8ZGXۛ*,6kbfI5T;΂ m6 a <}UP'cm!tT-]C1qvՕ.놘ImT&d?p"2ahOS{,1X]={6Y"5΢y@mPmq*Ӫ "99_Tz|ߖD@f2ktX$D=٩™Jfg]C?d. < S 9PV\v4v  v  v v v !v#v&v(h(v*x_d(8%9%:%>K@KBKFMGM$vHNvIPvXQLYUXZXl[X\[v]\v^gbgOcgdhxeh}fhlhuhvvjldwvxpvyH zl|ӀӆCsamba-client-libs4.19.8+git.404.38b26805d4150600.3.12.2Samba client librariesThe samba-libs package contains the libraries needed by samba client programs.g3s390zp36GSUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Development/Libraries/C and C++https://www.samba.org/linuxs390xH(8XXIې G(H7'gx0X wW''H7WG'GHKpx7)GW'!`GG0'W7XXy77(W`]X'7''g('7HAg2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g2g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g3g323767d6f956e40443066481a501528e94473ca7797e509057c8f70f2df18e2acfa7b7f31748dfd3ba50defa7cbf16efefeed885f3276ad7e00a9fe501347540dc8fec438626140c772c4106ae0925c7c6d186591a47b6ecf4e576b043095c5dcffe54b1014b60a2801e9d351b666bee3de358027751325448352a6e226073bfe2caf0617c33f1df2f96a659eaa02045245a70cf36267a9f7ecbc8145a4102a75e6617eec300e545a3611af0b59d7615055629f76ecc06e6e98d264738e96c08369f513687279694c03b3250f90b7aafc9fb80591dc488a707c35ab35c82ebf7d44f3263a4b0bf421db0999fdecf96dcd492ecde4745d0fbead2c001211da797ebed670f269ee8e7fd3146511797548231354130b688d1d80319976c875ced0261278f59d77709d6e584b03adfbd3cb71d82dfec6e30ba9668c29201c2b89cc110d61965bafa01bd0d31322ffc61bf5ae058a8cfc72bf802a4522eebd95cd44a4f5975e85d1da3cbff1377252236cc9ea7743ee794ad7f3574983c955c0c173dc54b36ea4ceb4e44a0869ab31962d9555069a3a80a0137c15b68e536f0b981d6cb83868fa0a352dbf1f2ed2d222b25fad21cab40a1ee7c308cd6a151561df27b3eaa58126f2e3a3b8d8a7fefd77a0c7853ef32ebda6b18c88b5862c8cc10a0e48a8b16198a13a4173fb9de4a1f92d4bb56a4d18ecb3222a0ed9277b2dd96b73b4528c5c59c2be81fb970be46de0b08a53492ec59ef4f265bb15b5c568b5b68e59b9d80d8b0d909e602fa77c4fdda72fa1d27412c70ffca6df6266ec2c1eba560482b3aed55d25dbc734441f19b2162ea1707a076d5dbd9febd47505dfe3edfe177d0f8024efebcb91f27620d59763bccc39852d81eaf293b61db8f03fd45c70952acf87e47fb430b9731ecaf7ade7cd9914deb018947dc1953ab15c72fc07e8a913cb52e0e127ea7e6a501c089a13775b679a825ab9a6062920e8ab3796f9a2651ce635a4e844c7d3ceb742cb487a3bfb5572783868760b9f6371ab271dd726077fd0d0eeef4b34e6d275b1981bedca11f3ffe502decd8730cb79ce55a273f7c518fed45223df2c257eec2d2e095f3800d1420825210a4a945861d449712f2170f641a4ae0308306df6e5fd07dade5b100974222084b6103bc3b3ed838799712941747e796778d17a4a8aed33a1d8c29bf2c5c8b5fafc5a54e1d9eb3a32a860ac8b7f5bd5fa924976a6d7e17a603b1d9834aee1cc698dec66c76e809392628d4e41b91baebb85aaa0a1ec2770606cb3315569c388e1f2e6123ece8df891982a644bb8fe108ae4f7fa1e03186bbad17cc07e792e90e1ec968c328bcf1d1f595fb173e36c0aaa2a9c770f260cbf6ebba98a94eb18fedcd77fe8456759b39450c4a701c0ffcd55d0cc500d6267954372648c1e36ee7f902ebb60f610dc2368ad840ee24ccd0d76e4febf2729e2a6c9f142837cd72c461a16407a82ed2b83aa5f4d94343e757f3565713f94aa8bc4dc6e3f9b9b3466f0aff777d47ac89dde21895b0d1cc73b7c5292c293706e571c097d165f5b2959a83555ca264f946798c014cfd77f3e1991f54d169d8adde8f7755020adcc992f526c9f24899db90ca92d3a53c44640ab09803fd2b45cf9cda1b662ccccd075b6f589516dd528a51ad8652a216dcdf4ac35538ccc42ebaf11ce20fed028e4acd131f49a60f5d86b326d4698305b920a6511ae660792d0e220977e4b00fa83375a226d9bcf557d913a60c997ed6dcecdc4cfa640b98f4f6cda2c15ef188ae9a3e5e28c9c646582c77324475908478f664cfd61af2a4331ae5317a9963f545fc181cd65c637e002c537d6466aca8183692782cdd0ffa2207c9cd898dbd86ecffaaf07b3a16f07911a62655f60553a7b8bb4ea60d1a109d058f55cb0baf8d88dd8c62bcecb1a3103605c1b9796ca256333d73c9b749f35fcff261f5f6532ed942da83a42b8232fec4852f052d7ade5d80e2b02a115632add221fb496da84013cb362ac9cd182eab1e4f5c33a65f55ada205321d87d79f1f2e2815ab9abfcab4cbb583548f878f1af8af2c20ece1297b9b23bb4e239b68f7fa6d2ea8561491f3215ba8b8b2775e87a5c5d3f4c609d3f30d0d2c9dc7ef91a4537ba5ff5a07af0f4a45312b4b546a7dedab1c3a4a1f610c599c1642f5c625474ec385359cc4b600dc8eff122e09d35408fa704121d8c96a203e3709552c6ac71e1bc1265ec07c6996a98010cca169fbeb370b46c73155148fa0892e493895ab9f5899bd33989def803f66f29c680bc3d07c02cb48060c1f024c773ff37e6d44f1bc5f1b147ffa16e65b29f94e30dbee1ea91d329106d1cc5d04c89d00c0a2fb537c80a2c981da45d188c4cb4b451acd45479a245ddd4f156081cf44a1dcd50de5023da566932fac815442fe0a7cbf2b1d6e38c4b9f060f79413154d725d62cb5a19da816c1e4b1b08a478db6a02ab5ba6229efaf11446b1de2613695afe8907a2eda41c462ba7ab451d1c637e1927da7ac8bf99d8a6b5a7c5d45d9ffbbb4d2f40eff6acfb77a61bd4802c9777e8daa81c62adb509787f6d66b990d8335f650fbf1aaedfc6f8ba064090277ab843f5b1218451e4da744c8e168cbee2a4d954b69bfb67f8e9abe70208f100f0810a13f3b39bd5d177aab48c1f587b5500a991f1612f53f1e41a064dd6f60d99a74d6079d894ef7f2551940a55d84b9b02572721253f4102dfbbdfa776929afe6a39cb2a4f6d282b8b7f75e252dd0d0040b67097f01799c04660f9e7ee4135a9bdd3a550ec4399cb5c9f17bd7d650ea39eb4a4cfc404dca733c53f7b899fff69693c5f480a8b5947c074aa7d1857fdf2cdeacc0c5321c4e6d1bb754fb8e32686bc7fa1b463b6ccea17fa60b8abd18ef81d5d9a8bfaef840e6a5a5c238930e3689a2bbf89207e20cfcac4ec09dbc074ac52e94c8a2dd8374572ed1ce00fe7925ef9de53d07b1d0a7243a7cb4f336d25a4724a000cfd16e0516360ac146c542e757750953ecdd2f40674835ac7a9f5cb6bb39602ff2ae13857967b611128cde9bdbed67e11909619b87684eb45e4289537306a8666a4083852b7a9a20a1dded5cd073230eaa83a30bd6a0c3f315a9b261c4a38158757f0ae4657eaf73ebb28443c0b05fcd377558d3a496c21d4634f5091bb7ae4d78ce7dff00a965b0a079add28e04c5a5627df75ce23677492c829aba3aa45ecb48d4396e431cf1a96d6f1603334a152e3a8a7ad8a7211eef46e45bbb42e394b1e500a0fe9c28a15f804515445a9197bc7ffe1701c6933bfb5a47e9c21dd7e14066e3c88a96a1ac88a03a6f88cca2a8265c6a34d3dba36129b3117be9f75672ddf601b2e4a030599e03f723c02274b3ea0863d655cdcebee39381e9a5c3196636515833f213958b0149993b056bbad7bf228d00c0e2b3f393fca5eed949e089720e1ae6182b4273b4a6313ffe097a506c74d8e14525849a0cbef99c7d3442c498d5a106161c825524600369c218fa2e3f95e409eb83001d56bcdf6bad2140dfec0418126acb5d326952fd2e44f7499311654d9c34281d15119043cc568cc0d8dfea0805bcccb870a8c9fa41483c97c50d204dceb417cc332024f3e9491ec2e43a450510da9bb5e3ff842ee07d6c42549e6f02321910136c68ab66c2df1eb6f7a4bd008ad09e914ed3ef0c02d8d8b866f7aaaa810595ec0cc04631d3aeac4df7f1ad89680b59f606e161dee6500c288c574c788641373647276ee6b4b0a890934d1ff306d3ec82f00e8cfce6bdeeefd4dddac2aea1a708402da173bb19a522ec75c2b96b340a79262ec0764342d4954d7532cbb5e7b4f5428324e92ed4542be00309774fc207f4d361766171652a115022e59b18e021348f9dc7a010d902d28b266cdcd6c72c2b6e880569bd82a76b980cb9cd44c230862709bf9ecb94d2a25e495377c27477e48c32efdaa60f15841fd3f6c601a45924f4b3c29884954c4ec7411f4de1136b4905b0d6685acb493ac99046d87f208a0adfe58dd71304166fda0cae7dd0e2b5928beefc1d5361b570b5dc44c0895758774aa5b34cb0aaa344924e9b53f60cdb63adafa651a05b0b865763b1dd23ee16a521a1838a7c5f67f086411a819049eff0cb797eed3ad441a7583cd29320d80a04687e2ed8311a43ce2c03d74bd692025bbd380ade950ca609beb7593d485926a3d8e0fa6b1b8e3b77d8ad8a3797f991966f03d4bcfaed0ef4975f6dec75424bd91544d64ae8dc6d812448c62bb30c18a9655a944189112b7fdc9accfc23f7b7849253a6d1e16753f2365e135a4b3787df609aa33874b27e061f3defba6a6d4a266b712f489786724d3b465c4b766c96497552baf407121bbfa78e5f214cd7aafcdb1743501c6d5067f7817c6ea0decb60189e4acfb6c2bc194aaa9a65cfa89eed2d7flibdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0.0.1libdcerpc.so.0.0.1libndr-krb5pac.so.0.0.1libndr-nbt.so.0.0.1libndr-standard.so.0.0.1libndr.so.3.0.1libnetapi.so.1.0.0libsamba-credentials.so.1.0.0libsamba-errors.so.1.0.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0.28.0libsamba-util.so.0.0.1libsamdb.so.0.0.1libsmbclient.so.0.7.0libsmbconf.so.0.0.1libsmbldap.so.2.1.0libtevent-util.so.0.0.1libwbclient.so.0.16rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.404.38b26805d4-150600.3.12.2.src.rpmlibCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-binding0libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdcerpc0libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgpo-samba4.so()(64bit)libgpo-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmscat-samba4.so()(64bit)libmscat-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-krb5pac0libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-nbt0libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr-standard0libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.2)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.0)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.0)(64bit)libndr.so.3(NDR_3.0.1)(64bit)libndr2libnet-keytab-samba4.so()(64bit)libnet-keytab-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetapi0libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libprinting-migrate-samba4.so()(64bit)libprinting-migrate-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-credentials1libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-errors0libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-hostconfig0libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.25.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.26.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.2)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.28.0)(64bit)libsamba-passdb0libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba-util0libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsamdb0libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.2.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.4.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.7.0)(64bit)libsmbclient0libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbconf0libsmbd-base-samba4.so()(64bit)libsmbd-base-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldap.so.2(SMBLDAP_2)(64bit)libsmbldap.so.2(SMBLDAP_2.1.0)(64bit)libsmbldap2libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libstable-sort-samba4.so()(64bit)libstable-sort-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent-util0libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.11)(64bit)libwbclient.so.0(WBCLIENT_0.12)(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.14)(64bit)libwbclient.so.0(WBCLIENT_0.15)(64bit)libwbclient.so.0(WBCLIENT_0.16)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libwbclient0samba-client-libssamba-client-libs(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld64.so.1()(64bit)ld64.so.1(GLIBC_2.3)(64bit)libCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libacl.so.1()(64bit)libacl.so.1(ACL_1.0)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libavahi-client.so.3()(64bit)libavahi-common.so.3()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.3)(64bit)libc.so.6(GLIBC_2.2.4)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.5)(64bit)libc.so.6(GLIBC_2.6)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libclidns-samba4.so()(64bit)libclidns-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-pkt-auth-samba4.so()(64bit)libdcerpc-pkt-auth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_10)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libhttp-samba4.so()(64bit)libhttp-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libinterfaces-samba4.so()(64bit)libinterfaces-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libiov-buf-samba4.so()(64bit)libiov-buf-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_0.9.23)(64bit)libldb.so.2(LDB_1.1.1)(64bit)libldb.so.2(LDB_1.1.19)(64bit)libldb.so.2(LDB_1.1.30)(64bit)libldb.so.2(LDB_1.3.0)(64bit)libldb.so.2(LDB_2.6.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmessages-dgm-samba4.so()(64bit)libmessages-dgm-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmessages-util-samba4.so()(64bit)libmessages-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsghdr-samba4.so()(64bit)libmsghdr-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.5)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_0.0.7)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.1.1)(64bit)libndr.so.3(NDR_0.1.2)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_0.2.1)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libndr.so.3(NDR_1.0.1)(64bit)libndr.so.3(NDR_1.0.2)(64bit)libndr.so.3(NDR_2.0.0)(64bit)libndr.so.3(NDR_3.0.1)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libnpa-tstream-samba4.so()(64bit)libnpa-tstream-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libnscd.so.1()(64bit)libnscd.so.1(LIBNSCD_1.0)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-cluster-support-samba4.so()(64bit)libsamba-cluster-support-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.27.1)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmb-transport-samba4.so()(64bit)libsmb-transport-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbldap.so.2()(64bit)libsmbldap.so.2(SMBLDAP_0)(64bit)libsmbldap.so.2(SMBLDAP_1)(64bit)libsmbldaphelper-samba4.so()(64bit)libsmbldaphelper-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libstable-sort-samba4.so()(64bit)libstable-sort-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc-report-printf-samba4.so()(64bit)libtalloc-report-printf-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtasn1.so.6()(64bit)libtasn1.so.6(LIBTASN1_0_3)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.2.2)(64bit)libtdb.so.1(TDB_1.2.5)(64bit)libtdb.so.1(TDB_1.3.0)(64bit)libtdb.so.1(TDB_1.3.11)(64bit)libtdb.so.1(TDB_1.3.17)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-setid-samba4.so()(64bit)libutil-setid-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.13)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)libz.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%ascabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfiglibdcerpc-binding0libdcerpc0libndr-krb5pac0libndr-nbt0libndr-standard0libndr0libndr1libndr2libnetapi0libsamba-credentials0libsamba-credentials1libsamba-errors0libsamba-hostconfig0libsamba-passdb0libsamba-util0libsamdb0libsmbclient0libsmbconf0libsmbldap0libsmbldap2libtevent-util0libwbclient0s390zp36 1738945413  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuv4.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d4-150600.3.12.24.19.8+git.404.38b26805d4-150600.3.12.24.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.19.8+git.404.38b26805d4libdcerpc-binding.so.0libdcerpc-binding.so.0.0.1libdcerpc-server-core.so.0libdcerpc-server-core.so.0.0.1libdcerpc.so.0libdcerpc.so.0.0.1libndr-krb5pac.so.0libndr-krb5pac.so.0.0.1libndr-nbt.so.0libndr-nbt.so.0.0.1libndr-standard.so.0libndr-standard.so.0.0.1libndr.so.3libndr.so.3.0.1libnetapi.so.1libnetapi.so.1.0.0libsamba-credentials.so.1libsamba-credentials.so.1.0.0libsamba-errors.so.1libsamba-errors.so.1.0.0libsamba-hostconfig.so.0libsamba-hostconfig.so.0.0.1libsamba-passdb.so.0libsamba-passdb.so.0.28.0libsamba-util.so.0libsamba-util.so.0.0.1libsamdb.so.0libsamdb.so.0.0.1libsmbclient.so.0libsmbclient.so.0.7.0libsmbconf.so.0libsmbconf.so.0.0.1libsmbldap.so.2libsmbldap.so.2.1.0libtevent-util.so.0libtevent-util.so.0.0.1libwbclient.so.0libwbclient.so.0.16libCHARSET3-samba4.solibMESSAGING-SEND-samba4.solibMESSAGING-samba4.solibaddns-samba4.solibads-samba4.solibasn1util-samba4.solibauth-samba4.solibauthkrb5-samba4.solibcli-cldap-samba4.solibcli-ldap-common-samba4.solibcli-ldap-samba4.solibcli-nbt-samba4.solibcli-smb-common-samba4.solibcli-spoolss-samba4.solibcliauth-samba4.solibclidns-samba4.solibcluster-samba4.solibcmdline-contexts-samba4.solibcmdline-samba4.solibcommon-auth-samba4.solibdbwrap-samba4.solibdcerpc-pkt-auth-samba4.solibdcerpc-samba-samba4.solibdcerpc-samba4.solibevents-samba4.solibflag-mapping-samba4.solibgenrand-samba4.solibgensec-samba4.solibgpo-samba4.solibgse-samba4.solibhttp-samba4.solibinterfaces-samba4.solibiov-buf-samba4.solibkrb5samba-samba4.solibldbsamba-samba4.soliblibcli-lsa3-samba4.soliblibcli-netlogon3-samba4.soliblibsmb-samba4.solibmessages-dgm-samba4.solibmessages-util-samba4.solibmscat-samba4.solibmsghdr-samba4.solibmsrpc3-samba4.solibndr-samba-samba4.solibndr-samba4.solibnet-keytab-samba4.solibnetif-samba4.solibnpa-tstream-samba4.solibprinting-migrate-samba4.solibregistry-samba4.solibreplace-samba4.solibsamba-cluster-support-samba4.solibsamba-debug-samba4.solibsamba-modules-samba4.solibsamba-security-samba4.solibsamba-sockets-samba4.solibsamba3-util-samba4.solibsamdb-common-samba4.solibsecrets3-samba4.solibserver-id-db-samba4.solibserver-role-samba4.solibsmb-transport-samba4.solibsmbclient-raw-samba4.solibsmbd-base-samba4.solibsmbd-shim-samba4.solibsmbldaphelper-samba4.solibsocket-blocking-samba4.solibstable-sort-samba4.solibsys-rw-samba4.solibtalloc-report-printf-samba4.solibtdb-wrap-samba4.solibtime-basic-samba4.solibtrusts-util-samba4.solibutil-reg-samba4.solibutil-setid-samba4.solibutil-tdb-samba4.sopdbldapsam.sosmbpasswd.sotdbsam.so/usr/lib64//usr/lib64/samba//usr/lib64/samba/pdb/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:37359/SUSE_SLE-15-SP6_Update/b6fb6fd06a0afae1f83ba160476a0246-samba.SUSE_SLE-15-SP6_Updatedrpmxz5s390x-suse-linux  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f4efeb125449e5546aedd6264ba157d5d243fc75, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=cbdc6ce2c716a3f3abc03e7b5ec6a6328b0cd08d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=af1ffce5203a97bbf03a1e8d038c48fb1600a2fd, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=85a7ee8bfd6751b61f657d9c567546e44e470926, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b572aa382643f9562527dcec542abc955945057a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ba0c36ab3de6e304b79e7a404f925c8a59f1b503, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a5c43a0827763e9b1323d594ce6a73c51e5f26a2, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6fe21041d1860128742ab837b0fbe90886b692c7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9801aaf4846937d25419337916ce1d591a33f6aa, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=48750b40c0072db2dc1631136179325328532b76, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4985f6d2f4703ff036bd573e30e7141f2cf75c85, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=57085767a3cb95705468e5b8aee198acf4ba9fb6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=47e5384ddb575017a32e5706bbd389face189e8a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d2b388dd12817e8f9a578afa6f90799839640c21, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=449c9c0a7caac7576a6d221a94496be4eb2233e9, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=68186d8c9dab45425edbc0d0b1f4c3dc164bf5bf, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=cbef9ef1abddbbd971046079d6377f2ec8a0f277, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4bda5f05a2dfaf9136d92e29b3d2ef099e47c2bc, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2c027dbbcd6b53d63e0e6ed6b1fe85f85a3b27fb, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c588ae86b0c724b496c27109cebdaebbda773649, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=52c191e832e346c91a2f410b04b83f47aab770dc, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=40c9de647f399be2effa2c435cf9bc6792b4d725, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=abb3f53bd96dc5feaf0155a6e14653b0e9e5f937, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c00de7b608837f3849326bec16331d1385dda94b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=10f1aaa4a4456499eb22342c14e8bef990e76c2c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=fa651562b12ba6740dab9be6c0e44cab8216759e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d46361802db2be871576b670175a58ebe743c1a8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=55d8369d9622a733824256626866996982fbd0dc, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6490c2b034bbbc09d29d420e1ee86d1722b13d5c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6daef6e1a1877e50e5d02a910d213f7d5339ddd5, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=afff65d53e181f250281f036a231a0f0c58b396b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=76b167bc22094002598a369a469f28db2f622dff, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=5a9969621864e07a0809bd97b3a34e83c21dd74e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7f8573fe8b61985e769f4cb3a65b814bd0258f87, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a57c05d2330f1cc69e37bfa9170f437a84434113, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=dc0f08bb455a1ad162a295f3965ae0fda7630226, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1415105c2bf90470d976424c430f0ad7d4688f9d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ecbdce1afc19eb426c9d0eebf7d4bc241be93b43, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=86858a37024a368f55882fe06bdf4d6aa090d0ec, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a24c48ac138e2aa7b0ca07edf8ebd88aba55210b, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a548d8aa0eb6311b0de5dfef01a0781a1bd2ca01, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=34bb450a049b3e7cc98e17bf54bb2b11ab4f1352, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7574c51231ba36ec17d37b26982614617d1ff1e0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=15643964632a8ae7fa3f0c34852b1ba856d5231d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e4ea40fe356a8c4a677e6fa17e49c97a59c65d54, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=5f7470dca99da9b6f663c9f01a93e9faa08b7b0a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d6126c32d60eac8b65568ce0d815169d1a5e05c4, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c9bdb28706a428e41b08ae2978f66a8d704a9970, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=373833e5ea2976c0d0568a061632784837d54abc, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=8517ea73b0eafdaa984a064bc3b0efffaac6c047, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1664aecff7743e18f8d1f040e36400aa290132c6, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9af0e5d86aa9437a5c5ba9d230e543ad5db0717d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6fd1e631f241b795915375e85f7b6cab90a22713, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f0c03ad8857f7a4bda86618ca2e92cd54f4c70c1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a73cf46fec7db2f69470b1d9d1d247d72d21f3a3, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d70aafb9bd83ff29e768b0992abe9ef31c675ae8, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=979e47475cc495a59350afd8c10250c862d3e017, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e71886e340d1039fcf632056eca53dd58692aae0, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f973dc5f089ebba6bdcffa670d5e1189df9ef453, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=e9f8f5936928e93153a52df800c5ffc5c7b67909, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1726eee00dea9efbfcafa4ace7fb76f0e994aed1, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=80f56641232913b32f836993f9bd192908ad61e2, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=2578a6fc086f2765df8c26b81ddce202044a38e2, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=caa68b449ba2592060feb7ef46d7ac199f9c689e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=9dee8dc33167a396a81d5734e8c87246190c1310, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=ca8ea4c0ab1f1621aa1b734450065e90eee0abb7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=d147a36351329978a296e9b2ba6fd0258c6a6d54, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=572c2ff2b1bab406f21d653d29336f7827708864, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=24a23e2ae56278ed91c09b7b3a3f08ecd72bac2a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=64b1d98bf10e31cf472bf2bdefffe1d4eab4edbc, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=4bcc915c3c3ca5d03b59ac03663cad93fd17eaa2, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7ce118b76e5a1b57e2122c3d40fd5c00f0f2781f, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=5392bef552dc01a61fb11fa10df9d4488023408e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=498694aa24ecf26791e0a2233529388682c3214a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=dc17153e562ac762619edbb35e10af86db7340de, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b3460b0f76c01bbca71adf201d6bb5cb2944a861, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b8b04c193e5b32ffea2310d8762ff3540746c864, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=cd818aac898c403ee8786c8663628d5cf5d6b804, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7d9beabea9b5ad73d5e30dff5f24b40bad09ae6c, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=fe28162d9b3aaf2f71d6d9555bc826f81c735472, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=810f83b7122db4808c56b9e8f5c64c870b9f919e, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=43cb0b0351de572e42bf6180f3a7f8163d5473aa, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1d65f4290cde41b17bc0bf71f0e54996607e9078, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1f3cdbcfb6631c5584eed55f170496ff0214eac7, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=25ab7a708e3bd3de6d7d0a4dc889d904d16b5adb, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=cc21acaafacabac58b18c7c87e73b742c3d30315, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=f0398384a54a6d7d7d83467e17cb8e45bac9b7dc, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a7cba5201cd692eeb75da907674653956ec63e41, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=b1464f2e1961c87a0208af08b6c2bee3829b7000, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=855901efc50ee401665d1f25afa681c726187b6a, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=61dc5022510a9f4ad64743ea213f2d84c5a53887, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=a71ce56f3ad234e7de9e707fc29d8a6675b5e285, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=7c59b234a604d550c2192270769c45b2dc9394b2, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=310cdaedb5cb2ad4e14bfa53789b5f4fcc47e2d3, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6b3276add54440528d7f3ff130301126ce7a290e, strippeddirectoryELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6f133013249dced1f5fc335ec279e51f54c9be52, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1dd2533d5f82c44360400d2fac7e7ad9bf05ba8d, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=1f3dd13d01ce50e790f265ab143c949483d9c11d, stripped"JIy:/<Ox/X} +Ogt| W~3Fg%Abz . F d z +   " + O j"(B7C0 G%2Lc )?I)%2+ $  ;'= 0!:!G!"(3*.  $P+P*RRRRRRRMRRRR'R&R*RRRRRRRRRRRRRRRRLRRRP4P3RRRRRRRRRMRRRR%R'RRERCRRRORRRRDRBRRRRNRRRLRRRRRRP6P5R0RRRRRERRMRRRRZR&R*R'RRRRRR,RRRRRR4RRR8RRRORGRRCRRDRBRRRRR3RRRR7RRRRYRNRFRR+RRRRLR/RRRP_P^RRRRR'RRRRRRRRRRRRRRRRRR RPbPaRRRR R'RRRRRRRRRRRPiPhRR'RRRRRRRRRRRRRRRRRRRPlPmPmPnPnPoPoPpPpPqPqPrPrPsPsPtPtPuPuPvPvPwPwPxPxPyPyPzPzP{P{P|P|P}P}P~P~PPkRRRRMR*R'RRRRRRRRLRRPPRyRRuRMRKRQRSRRRwRRRRR&R'RRRRRVRRRR8RRRRRRRRRGR4RRvRRRRRRRRFRRRR7RtRRJRRxRRRURRRLRR3RRPRPPR RRQRRRRRRARMRRdR8RRXRhRsRRR&R'R"RRbRRRrR@RRRRcRRRRR7RRLRaR=RRWRPRgRPPRRR'RRRRPPRRRRRMRRR'R&R RRRQRRRRRRRLRRRPRPPPPPPPPPPPPPPPPPRMRRRRRRR R8RARRRRR*R&R'RR R RRRRRRRRRRR RRRR7RRRR@RRRRRRRRLRRRRRRRPPRRRRRRRMRRRR$R'R&R R*R!RR%R"R#RRRRQRLRRRRRRPRRRRPPRR7RtRRRRRRRRRRRNRRR RRRURRRLRRRRRRRPPR`RRR?RdRRRMRR'RRRRRRXRRRbRQRR>RRcRRRRRRRLRaR_R=RRRWRPRPPRhRRRRRRRRRRRRRRRR'RRR.RRRRRRRRRR-RRgRRRPPR'RRRRhRRRRRRRRRRRRRRRRgRPPRhRR RRRRRRRRRRORRRRR2R'R&R%RRR.RRRRR RR1RRNRR-RRRRRRRRRRRRgRPPRRRRRRRRRR&R'RRRRRRRRRRRRPPRRRRORRRRMRRRRQR'R"RRRRRRRRRRR^RRRRRNRR]RRRRLRRRRRPRPPRRORRRRRR'RR&RRRGRRRRRNRFRRRRRRRRRRRPPR RRRRRARQRRMRRR&R'RRRRRRRRR@RRRRRRRRLRRRPRPPRRRRRRMRRRR'RRRRRRRRRLRRRP!P RARRRR'RRRR@RRP#P"RRRRRRP%P$RRRRRMRR%R'RRRRRRRRRRRLRRRP'P&RRRRRRR'RRRRRRRRRRRRRRRRP)P(RMRRRRRRR RRRR$R'RRRRRRRRRRRLRRRRRP.P-R'RRORRCRRRNRBRRRRP0P/RR'RRRRRRRCRRRRBRRRRRRP2P1RRRR'RRRRRCRRRBRRRRP9P8RRRRRRP;P:RRRRP=PRdRRR RRR?RRRXRMR"R'RRRRRR8RRRRRQRRRRRRRRRRRRRRRR RRRR7RR>RcRRRLR=RRRWRPR RPAP@RVRRRRRRRRyRRR$R&R'RRRRRRRRRRRRRRRRRxRRURRRRPCPBRRRR2RRRRRRRMRRRdR'R&R*R"RRXRRRRRRRR,RORbR RRRRRcR RRRRNRR+RRRRRRRRLR1RfRaR=RRRWRPEPDRRRRRRRRRRROR'R&RRR:RNR9RRRRRRRRRRPGPFRRRR&R R'RRRRRPIPHRRRRPKPJRRRMR'R"RRRR`RbRXRRRLRRRWRaR_R=RPMPLRRRRRRRMRR*R'R&R RR"RRRRRRRmRlRoRqRiRnRhRRRRRRRRRRRRLRRRRRRgRPOPNRRR'RRRRRRGRRFRRRRRRPQPPRRRRR'RRR8RMRRRRRRR4RRRRR7RRRRRRRLR3RRPSPRRMRRQRR8RRRORRdRR&R'RRRRRRRRRRRRRRRRVR4RRRRURcRR3RRRNRR7RRRRRRRLRRR=RRRPRPUPTRRRRRRMR^RRRRRRR%R#R&R"R'RR!RRLR~RRRR]RRRRPWPVRRRRPYPXRRR'RR$RRQRRRRRRPRP[PZR^RR]RP]P\R R?RMRRARRRRRRRRVR&R'RRRRRRRRRRRRRR8RRCRRRORyRGR4RRRBRxR@RRRURRRRR7RRRRRNRFRRRR3RRRLRRR>RRRPePdR'R&RR*RRRRRRRRRRRRRRRRRRRRRRPgPfRRRRRR'RRRRRRRRRRRRRRRRRRRRRRRRRPPR'RRRRVRRRMRdRRbRcRRRURRLRRRaR=RPPRR&R'RRR\RRRR[RRRRRRPPRRRRR'RRRRRMRRRRRRRRRRRRRLRRRPPRRR6RRRR'R RRRRRGRRRRR5RRFRRRRRRRRRRRRPPRIRMRRRRRRRsR*R'R&RR RRRhRRRRGRRrRRHRFRRRRRRLRRRRgRRPPR&R'RRPPRRRRRRRR&R'RRRRRRRRRRPPRRRRRR R*R$R%R'R&RRRRRRPPRRRRR'RR%RRRRRPPRMRRRR R&R'RRRRRRRRRRRRRLRRPPR^R\RMRRRRRRRRRR R&R'RRRR[RRRR]RRLRRRPPRMRRRRR R%R'R&RRRRRRRLRRRRPPR.RRRRRRRRMRRRKRRRR&R'R RRjRkRpRiRhRRRRRRRJRRRR-RRRRRRRRRLRRRgRRPPRR RRRARRRRMRR&R'R*RRRbRRRRdRRR@RRRcRRRRRRRRRLRRRaR=RPPRRR RR'RRRRRRRRPPRRRRPPR^RRRRRRR'RRRR]RRRPPRR8RRRRQRRRMRORRR&R'RRRRRRRR4RRRRRRRRRR3RRRNRRR7RRLRRPRRPPRRRRR}RRRRRRR8RVRORR{RR?RRMRRTRQR6R^RRRRRRRRRRRRRRRRRRGRRARRRRR R RdRuRRyRRRRRRRRR4RRR*R"RR)R R'R%R&RRR|R5RxRR@RRRRcRRzRRRRRRRRR]RRRRRRNRFRRUR3R7RRRRLRRRRRRRR>RtRR R=RRRPRRRPPRRPPRRRRRR'RR*RRRRRRRRRRRRRRRfRPPRRPPRRRRPPR^R'RR]RPPRR'RR$RRPPRRRR*R'RRRRRRRPPR'RRPPR RR'RRRRRRMRRCRRRRRRRRRRBRRRRLRRPPRR'RRRRRPPRRPPRR'RRRRRRRRRRR&R'R*RRRMRRRRRRR8RRRRR7RRRRRRRLRRRRfReRRRRRRRMRRRR&R'R R$R"RRRRRRRLRRRRRRRR RRR&R'R*RRRMRRRARRRRRR@RRRRRRRLRRRRRzXG'ű%utf-880479efacc257b14a75d0aadf991e71394d72878e284ba5002dce1857ab6226b?7zXZ !t/]"k%DM2_e#Ȅj((KyŻE'WxBPcVVJlդ_!*k"~2/j, αy̗yѝa?{iUjUyX Y(@_Zńw]7$<Տ4x_s_ɇUg֋$UGB]{|O'","e C|rJ'Ma6Άsb[I>zV@qSmMcyug`'N+h+,5?x({^%FpH܂ >"kx|(fd=+0}șy/hRЏ -\B"u J= TsıYnȾBttT^z.HFa#׹n?[i֥,I(:Lg :a&/}rIr<7Y3qۘfAd ioaVTT7q>j- M_3VK((AMe}YNR3]2EOpL #Vt O{SР\=g#j[EkZ\{NaO=y־ވRLqmf!Hr!h3*Tl>S'Jh E=yb")BmtXw,?ޓ{lFi!w.E)Ubb~t~2z{oYq%huZV- A52m Iڝ^A` "Ѯ _k#뀁k1%+Ibnj_",&Hֿ55\Uw2ay淫PͨKKC#B]8`U~} U]d{*(DQY6lqtx2ݽbO|W°l1X|OCݩ3,x^޷@HoԳO[PU2E3gyTfR)9AͰ:uE9)_'92v ^BdOHg (t=ZDN,%.`OMdٔPztW\Xϥ,)>"B#C&WyWl~nXSX;-+ Na>ToW?ymPUYGUI:Z!M YsbI I󚚝 j d2BG=TS 3#+5͖ik<$o ʇXcMyp&'^>B븬U.Ou:eC ˟I/xN4n<Ҥ@EX]&%UyIHy|K2G'Gln5Th*<ܒ!:@4^n+mk|Au m?@J**4VKElPcǤ#&Šl@O!FN +\EaPzZ?D xPp fu 5KS&H9 y-g?-I@;po.sE`oԾV Xz)Zz S[7ޔiˆMs'1vڀ#@?~XܴoyE9uFy zz<3'5 +Gb]o^_4l(2\fwRݹ L#`xQPbxhwawxmA xɩ/6nͽ +CK(@[4CYнWk'1Mȋ̿ǾNpy[\1\5L5"un^UF0Z]*T8aֲQ ;@ aͯG1xxjpmDQ悾^_v8T ύ_P)Ds=J6Cz !ڑ0k蟥sQI?(8ҷC`drQc^!صgaukdJ)ei;9s]8}09G|p3NBLI;{ R…m?Gckls}_S)~/[Nw߶+&M9N т*v{"e)^ZP|IEmiE7hYze6YDC_Gԙe!Mk {ʪE tN$U2* r?QhpXݻ#jiu ` ) $scO2bN8Yq3:O4z]KSl+ԨEr+ZHz`u˞gl9Lِ(GH ' 6VbaBLO9c,]wckc 2u +V5=j'Nr6:i㊭ y8ηKKhļ_ߘ"6x bκr6‹rGI}M25&|BN̙Զv iK"}3Ӱ{:j,mr3{_o;YV9F%8CY&\.JrWfj$StP~^|8^Js2DDnj[U!cGBAS6%%-ruvz6Fd9t?70}:91k:蝯i5˼.s1"d;RoYC'7Į̟x|)yW0|[f>R/O S78 ԓ 5#(T,%BC(Д1x DLD0{D Jﰏ(Nˮ>ݚhdKV&F坨Ôu-|R~) i|>@_BH/bf՗ Fp" oRQ ^'cNm.pjuȹieju )"z(tTNu oI.{+[5+>եӍ׬L,FsHV'{ZW.s`ݰfڜ%lE8EKh֐M9BE_[h܉ʱt10NJрug' A'n"ExUe\B$a73([4 9U`1R dTVAHk,UΔFǪIK>Ey/(u\b4=к|lc f*'Lu' 2!=Wz? ؉'?KO@ZMO hEM%RCN 5K_{Im<%7QlͿDݮԯGV~"d4 sEis#@'T缯ijÕ|UxHΧ GT9McIXpQ/'Y> Fb.oH"0mnSh~0tDnLMvpNRMeۂIwHM4SYz1mPS;ym66QֶˎvAX9qu阪H >F]x">xpp2 WRo m,XWx{u$ |ՏLuhXY I⬺Jc i=*;Dۚ`ÜQ~)NV.vK2c$4k @kB7B}"h-`$50 s_\%tqvD#iL ^2)_hZ Né2,^5#z6xgIb U8X%q|,|LNu^|.mglfN}^7ӱh z2U+3\GGt#А/NZLy<Ç?n,^2&R`\8J" YgO sGr\F Y6Fj4<ҒEM:ts ]Yajg];}!8s onP: jC شPC,17%98ÐKםp @Vt}$%Y%IsWqj懚nS׿ӬaZUsZ Lc~*x+tR>?zH@ $'U, 2 %Lq5ot?:)ЯrtY8*E/0GDFb.mp!7ǷkZUZU-Hzճ^uy\zl~{gGRayl@lw/ӥ|jK!J9&pZ, yA8%k bo2F.'}kwosJ4r0GC)[s/Lշ^PoG#Xcw+ޱ4|ÀY\.8!_,<3]VLb$C2kfuйI.iP, '~HL^t<=B(gH*Re~4Čړ,Ӷ2|dkUA+ vep//Mc4%l:W(WQ%HNJwzQDvjy[m1I7DA;-؛Y iu3j~gTf^e+8ۄ[ d۾'aɎ7fE_dAr?|8"+o;x۴\T-VQeBR-Q-;״S>r{9BvCǛ݃C_Zg~7{:^Rub"k ~A)&b@, Tx^5(iz[.z7v`SwZq:b"g8t! *M0D,5P| \h'f3E)WqFZxbti-Hbg?y*;8y9wAs z&_ k?+ƋAPtYfFgu>EnR,k%Y#e@=M;>jI bbti-qN!Q ".ɚ]}gC^!W7KyM* ^L-FXo8uFMPg/GUVmb<~uw(Tx S+/'7UoelB0v!l*[` bt"\w=M|\ŀ[9mS*ed̗3~ 'Y se(_s#q Yeg֙ʟ8#7yM^K%.uVʉkew@f =#w;OWV I'ǛE.!w#^ZhX^r#o,rʽk[୓JV@30B^֯ɦyaP)`C&:R@IV!_صj *\<>3sn%rQ)BgDjIYt25ubiS˦eItiNZn MBf^@E2  p|PԘP(!_eygvz5GRM 5DMǜ$(扵=Te~gs)Sdo)籫* |dNu‘̴*f~q͍;G-1~IuF{mMױ ҧ{P_O YUelnAj7t#GH-c"mTj8g_~IpysUUեgyPfҳS01y#7;-|m&0gOܖ%ke8o:{xP(|mǸ *-lvl aR#k Prh]9^QH?:!c H۰-mjԖ8_x ՀUBmM& !JzKFkUB;+ ?q! .)ܳ2cF߇f]{Cw \#5#6]1 @˳H%;3xx~e礿88O8E }liY}F-TMj=$"FWp#H'yР ?:z6Xj?xmEY]hcnrUw' &mB"]cȧ)[߁\_^W՚W*nzf`6XaHFW܎|ݥe3쌦3%ȝ:AͲ55sd=HQ Q{$Ь)` 5͝Ecc*dhhCR@t5J` A!m2FCYgߣ/Bnɔ%tЖ dAcr.ZH!j bil@ ϵ7f/ЙLNk aL,$ePpoAs6b7̎1y˛"2ѽZ V3p,Ծ^4a tټ6AqT 1:tW%{![RUw8&uHzF28Wm+N)x'd*8I Njx_HP(V4ŰZjMfE}ݨ/{tx ?jaVMˊhiw]5yW.UEsS@䅴Wi3*Nk=iDP1-6M?a– 5%m즈q) =ӄ#~+A8VA™g;yM|Jr7] KGKspđ׺ni`lk<G^6SZ|iN-@3)8 А=( 6vGÏʒ "t޷z! Errڜio25ԂXĠIϼXxx:qH]VX|1Yc/1%Q}SA,7v58R /ZzL[2nt VRYK5w;X<} ډ^e9y0|_kfUC!''imOi(oסC?l{gң@gR'HsJ{*ؤ2l0q&zJ )Z[Q9,smĂ2_prbt g`fAO\4O x,k kZ#VG6~v 5C+t$\\L9#57+*P0]Ȧg&ôAR_a vB9SΖ75֑ |k@;(3_yO6P7=I[@ޒ=eH5}Rᜋ@ϰ8E-]8_ι=h'}WDkO>7O3=0_|A#twbPwhAќj;Q/F1nM* 9V)ܕ0M[l\g|x̳9p4k٤wJaCCVt^_Tn#T`mZe{q՝|}.[!Da=xs"D @Fc׶3|g:?g+u+iH&w$ԩ㒙EShdxF΅[)^y>|Y|()Ldl$[t uq`?䲹d$,E 0Mfs>/Jg;p1o>hh3{ 0\* ,24Lʼ8 {pjFmlj0SzbYzL0P~lV\c-OB DP~uyhhab?|.jX q묮E:FuH$D]ճXO9ia@"dp_GJ5 q(C?hG'*aQ[m/ߟGcGN:] @VYrD:{dcRPRz-Lj(fxi$<^ 9"|PxlNΆ7n79ʃQ%T#S%5@gDr-uWkp3y %-`]h,Mr[!i$M_bn?AJ0OC… cK nԷ;Cf/.0  @^1qr/Jf]Wj {D]G(c uQb*EkK⥢4}wt Pd&DL$OK|mx"qc`z7T]'9w/@5)J|vr]bD/8[^.Gkut{^4$3[o4F>4@g$ Q +>\Hpz>O9=c4w׶#T'HդS8_I2d4*uO7pob;D^5` @ ccF-a tH/< ZLOq: ۦ>eƣ46#;å 5? ]t{(F(.qHxJzo.x|# K sD7Vq<>iAa"|4QA%=Y/{9/idjC# :RYw._ΗNX{]kU$"瑅Q_͢^]G)A\5ki/5tBM h+@<gWH[;I <<\]=d<̘lp 4jE=^4tFk60|:r^G5T <[,B[W\])̟qfξyX1y =5lQ;ʐ,j `d2R`6✢^njJ(Ƥ$cD@ "3o{ƝH)t ]`?m9z~Xi*q06\"3+Vc\8APډG;ɶHv-̱O={k~\a aQZ7Q?aBxi+ kW)EP,^k )=]L`pOEePYjA,y-!*4 >Ж|T;y4ەSi2 ?Kk͖~X)rM:nu(Dl^ 6c\%D@{ߍ-brw5clf\Kt9Y^m=ixEe+M̓>Jo #+~ICσpߥo|,>36xV)qٌ+{+&U P[Qs8iIvp{!O*_(1x}sWDׇ]|g]RZ+}XN8m2ܿ d.ߩyP CM;O֤23P2 tU8-G"99GEjdnH(h%/Z "ATP) jp-W_<_GKT._ M ߀ܶm?S*;(@#װPz u􎬱Y+J6|&OӹEվ^c_VlZ^$x,\\X/V[,D3P/pۀZa^h+VcAhlN0˷>Ml[܀J|QlԂ׫vWq5T+*ܧM}m0.Q)@S]]\)ޕ4$öu Z~tђ|ԉ #~6+ IZ}'}/ Bj ͢e~yFH]$N% B?4' mX$JkÀ[i1ɧEá^, lÜވY~$77 t2j"[sz"Rw(M #}"0DEgpo8)+AP؎4sNeފܘK/̒РG<30Mx>RoGyJoӺ73d_(Z QCj1N65'2}к( .M1uU}О!.>3ӫE}HVo^Kx nNWZxM6i ?ׇAFU'')|di%S'{MccYq@j:u?ɖ ,6~`~nw Yyږ7D4u0rHKNzǀ0{dHR- Cm^'B }Z51t]`"g~R!k R:P:i^yxks@IhZdϭ/i|~pLl~#Cfbߣ=/F~;ނI к/b[8k:o+ MC`H6VNmz*vÎ`]*1 ;37r°9.-M@ژ}e$-k%lduY+W-d{WoRtΊga?b>(dЌ 5Ty*)(AuߪJL'4n[_&8d=AC!HpOBmESڒCRVI|2PdUdXlk%٘"'/E*'U|t2yg.YMݕws|s;C˙_2 @|tVW>9h(_wH;'_{)O!CGUn0ZwiT:R?sUٸno.*I) 5,Wn~hmRܚ.#*|Z$7S.?QU+cXkh8MMK U2C#ZRgdEiueltq.*r**MIPNNPbVlJ0EBf!%⻼^gZU3%Kn\@̕O3ѤIrlDuoXQ"|A{rgw&3(Er =͇#V٘MdC_G7kKVL7vב c<מ붾r&)zK$F2৤t% ؿ>l-1DY-vꭖ7Y<1l!IrIrb8. Cm|nU{fm-맦DM*sH$O') u ,_u:8(h~^ۿsbm!>cI3gj϶$њ܂T; '|'nXЭ6}Z;'(o'{ȑt͠cFGc+bhuig, J霫3V{9bNLR0^ttt.j&X +o_c[[alw[DKLFc EBѝa2+X%7 c],{F>bSaJ1T'2y{` ,Q5U*.49F{pŔVJM-e*e"*EJdVd+ v3nw3UOp-@ ٸڊQ@ S/Q94p ~-8G;9H:;4+$%nKOY4iw5F?4]oq}~/ʹT|5}8˩^\]?I_GHQT>acynY~kJ,G,t6?"LׇGWz/ge a!k{2ĸ+lC?eWKx%[f2)gs"?(Z%=Ub}JWT֋|"]=A$jٍR Pzk<͝` djyDP0KϏ"ZUlB/PfKy k`gma!Xٮ'*_)C )mB++us &q֐fLQBIb};+ ,Xů[ކtO!F(^^ sDZb-.?fnv_)ڲikvhm%Pnt;P~/W8s4>-uԲg^zUcvN"  bPE!&< wDL9:5/wH1.kRRoD4(zYꙣH%غhş ?E+T 6y!nU@Gb}` g /Vl(\>aQvP[e1-:8ih2B*KP{1_f w"91˜no~; эavkGTiٟ?Fۭ FR$ i Y:YǍwv~Wu-A?0{xЁ_ :Hjؤqpb{nCRo.~CTj:[Un0qZ#E̋s\S_Z^z/$}(=J&G>Mj6b`$K[hCpP/N_B Pf`E54ua/W`!ӁGI9}c^ or`H6!PEa @ Gkyh͈+$:'PuՒ"|_ ]I=@j}-[t,f9VX(pzeCt_VSūf$#[[3 "IAU1p?Z\\:N<-^ ND+3xk}o CFj,[PWt$.jTM7d dvU1_WV+nǁ@gopQWQhOw4kjk\> m»ٗAx~d(q!rEXkmc|)d$:V8hb}A/}ʌt&.P]0}pJ⪛Mkv'`iZmo}%onHU%q&fXS1NG#%x2pr"[7rxJwҩS)cd c j.,ylW[- _b!yADԡ`\.slT+z^ؚ88Ճx%O3|ЏIoV;rxW'f,u^n$nE^xw4YU?s&GQqƷ =2_"ev +LKU65:T᚟KXHMFNtW:hMt]gQF۶ypT>42ش`?"MmAה; Xו )a_b}U " PxВ4v \H&ëőz*F`"_r$J&&>!mREY x_G lgLjkzhRD]'{7ۗA)OЭN+ă5$>R j^ր=v9Y>奉I27JS(x.O3੹m1BTPK=aσ""A-leذA:]\ҬV4NJYQ:iGJHK-7 ]rtb}82إ8Ћq]/Ԉ7 xo}[Fnt<(a_9ܗ!x')Xb~Cj6o]5?VW-0騯F@ځ0*p!tCTّuI*IUh A焷I1Ni4T0i7nYhڀ`/=A܋XC>?wBD> _L)r: tJ o jEL3! LWEAR_~Pt.61go⮜v*]uWV; :Ar<`) M YƮ a/l%82mZ"%9.9')O\=r8lceKɈg#֥>W\9:%٭&S>I5U%Uͮs.T6ϻ~L\>Ȑ9]R8/+VpVv` |~=!j_-Yn(;3A3!#tg2>MO[qI7؋je ݩV4M ֶbkq$*}{Y +ڝe4 *_d>mI+Kh*i\7 F Dbsku8UP'Gέ SY[a."E.yC# [67#]϶t٬^nX/4"T;߸Q'qB ȆKр}z&%js۞U 1eA6qk8/WY/_}͗YF cuc\qǃ)Z rkY]ot6Kbs띝+6NnV;]=L;k&wvXa8nex;&DiJ3AݍsºQ -x&kV {B;hmGNL~6p]_m6xzoA+F3Q?+%f [ .zL*f^yqIB>CCM\}f5dV*uUp״s^K7DD.j>T4_iBoaG 3$A>s2a[uD=p`[uC*yT(<`_)F }`K NvE@!2|~$S Q|4a2,䒓$Goh)PmdkЮǘ冝CDǯO E(8wHzbаhdoަSYK>jqvm(ڤ 2[k7~,y2e poV'ib ةp+˷S*gS,&q|H1\#ڟ-޼Q b6:&17j6]mJR/E%gp0 h9~sM]kːD캩qj\;F ]ftFġ X=б|ǭ`P߃XaPs7E{-חx< j["Z-% `)~6a`nĈdZ4/cl?fX50F.ga3&.yOMsJ~.EkJBs|,@NBX @t~pN Ą8ȉsyO;6^ '^P#P#J\3\}1e+wBjWg֫##u_0 2N22lo9v G֧*yox HVMlsK׬Z~gM&`HKh,8@+F(Xx9挗yeniiS>Θc`k$G;Ja7Tr"eaޫ$ɋȜ\"b\5GT3*l!2 &#9'yFr…(&K/Yiv!-'%*S!؀vڝOz7 8j'$CAjPtS>lƴ QE;si3L3JF8<.e0U7"*-ک81̵zSJo GUԴ1h>LJ| yzBtr+}RJ`3-- o`:&dsj3FW8AWZZ`ēW!*Oo UAV.쉦Jwrd@.3@lHUzА 0<4OX)!^ HD =*"pѬ縃MR9e溢mq_b٪sy2^r >3Oִq#}8Wk"fC~j\Y[G3鋗p!lO?vڨ84h68'G|*{>,9 ^Fa=8cժJe:<ӏވK #%SJ*0 曻9{ķ ߜK#<#^"T^oF)4 r柾,=|sPkȃJAĚ ?X/ .EYV^&5%9n d&a?o =! R-s)29v,/nfZm$rTLf`!ь@K ;P/b1^6nܩM bHaiΉ_fs(F볪{w|#*d*K)X:&5"z_S CD|GAuӲ;/ŬbpbEuиXI ACL9g͏`:׮"[qޖRF IauuQ clEVq5T@yz ZmP`O3 ZL݋Tzv'@'CoL0}[rTkIZ6X`{Gƪq]X0dA%i}wSO )U1iN&/}VrCymKDLYS ᬠ iB[ &a[.>j&8m_Rmd- ZwIykVqWqu0nW)0k UK%aqhSνe{.} bSj)nkXM$S5BQF p ч;^js5ۖixTDϩ }.8aSspx>օs*d; YUxͿR{W {ۺ2|64=VNFX&d:핃UoՍ1'1P,"K%wM *FZbˑ*7޾`FIر\}fUU! `yJ`[Vl~DpXɧ7=ó})50Jk')⮇C YĖ&%)ȏU_ S47-g-5+2v'z%A(soS\ {?R/Miwmh ~C%Mª ZqJVK"יX*㕮\n|(,.%jNON h%E݋Mtߣ CϷpJ'`#MBxwb>O|S"rsqYPQ$"ܖUgƨ"gZ8m#Q3KOZ>!8- yJT78 ξ(hmKOd%L:>g*6NqN+iR|gY|;pI!w r[UǪ!̭yINP|.V`k'DtidX2h_ruHipˍ+q6 ¾ۆ#dx*a@=o)5.lhap@ƹH $CJbHm@1bȪ? Y-+1X_١ޙ ݴ!Y2n wܺez2u)gVWbȥj6vEfA(I/2 +k&WY{ϴ)luW-┇J.KD8PUsU)Y/2s9|PH>T#K[.G˃@:$J=4m,zbP x`@MHl >"Sga*tl*jC3ddjP)^Cꀫ̮!)+x::*L48\R٦<$Ovk7nVX9'xyKn\.Sl¶}Fq ]ϐ/{H }4_fW: [׉~[[~mz6 z&K*jڏdmR{1_ZAX!͏z=V1޿\8 3PwK'y ?Iy2^ѣ *{zte}<}Dʺc}ir1J(r =09t$`)Sn>̦H#+ډR|_IkGwx&ёyOy*`HZڮtGKm:w_l8 !lq q8b+(. bSR.̯&\ j rƜ:d§}ƫ9z9#4ap6q!R3Y 8E9:qqxDI&7ءS"W@*N FAqZ AʂyLP|E0}rt q `L<7yxN( TN]+ٻ \x** h[z•҈7ϭlMnt[TL jsALria|R7pέ[47ٻ?&<{MAEmmk*B@,pxW8"FZX ¤$:\/qj$@lQްƇLotsl ũ4hh(W衊(D|.(E'YvbQj?XȔM|{$R9Y<@ /OmbL[@+Ӣi8}w\Wh2m$DtbkYXqђqX ~ ޚ<_-IpM6M[A08OyhXAVxaJڽr JarڊpV`}N?'n䊑Z &Yu(H> ..)ma7^:X\'{Uu͌J(,C0.(G -DdMv^W0G.hs1&Ci 7F߇bsο][L0fvNq^wsyF@9'[>l3v>,`g"Axz&F8%`ʗrb-t,>x= k,ݞkxe^L*A]5ezEnOWY"d&H7`MɮR~F!)^)] cnPR9l%o$#jxfNI>{~N8BtteZ0xk=:3a& 6\ƠQZՙ|jM}Rӈ)pT` Nt5#GyۆNY'fy]@,K/'qG (RYєnϚ/ARit;8`*:gr9j^^&*mp5R7I0:Ut;P$moH?_{IF̳,n./|ս@*ܾPsS3),f/`@Y-(RCC݂w4/yMuÿc ;Zʲ=yRqBdLگu#,52$V&4HrzO>1w?A(K7yٱUH۠oVY)&|H<`yHja~zf@'gU%K5+(lA]b]j9${V̨XNp$шuצz!/2rSG]Ҩ:2AmǼiHoZc\Z?23C,h+.2v׶=/h-sί7TVP wő RE!DuܾZ'l d8GbW[njH]ftq- SܾQN| agcJfBɽJoT +z6^b@>~pg&I0?ܾ$jQ(aӢ%\i}YwdsSБ`iM&b:,P?ٞ0GE^(n%7Ջ?^ȼ`'O[.bńq{zf=t1L#rLSTک "Ӗ'.!.Ȉ{P"6љ=8h&n|~Am GQދR:sn޾@xC8o_>| cBQ 1޸cټչˣC$ c fg@0 ލV 3Jɝ/]|}xUwǚfz`-nӦş^ܪbj %J&MedqS>dAEDt:ݼW(!ARu4)w+y(](:B#g"WrrW&!|:?:n.BVkrD 7HRE=\zӝݰ1hwSKtN0Z' #JwY[vF"\D i2e x{$tM7rc&L(i[ܓ_bۙmR`t(CAnr0}s뜁YVjmd3\85قwbx?CZ|j9Ng!4CJK2N__F!8-0YM>Jl=y>;b_4Iq_7X@b8Fi΂/{qpc1Dg&\;*zh_grdij| F9:D kL=ƐzP[g\@s8:2&T .v$ [;X<*疁rCfw?%Aؗ OśahjLg˫spI _XhDB9b|GakCxjt$ˇVbuYM{"Gƻ}Ŗ s^k`^jhyn!YP^uU_ H؍K6 T?W[umNEt̀C3dNa32ӅmK#9. 7|-qF pP}4^@r>ڗڱ^s=KEmpu|x5Ƥ8N˴m,fr}=.3UB=lZ&H=_Ka~o,56B4ˆe꭯] i@:7'jPLSV_nFC3=JAnw]nXٳR1ǰGL8+tf}J81qe8v~轺TTh |b2V#C#bȯd +CM*ܾ( I ^`@:A.2BwxKJʈ|e#%83bٚү}-_ml`&P,Z&¨E`>'S,l3:DAeb;XdIsH&l1 /J~f Dڤމ} }!uϯfc4A.HA~:M"KcX ;q7Om&T\tkW:.>zr7]Bl|]"Ї)| "?Fmߠ-U<ɆXn98ptHl~ Bߠ+7m%d۽@šmK(*'Y4 itГظ Yc1@eKu\ fM] CBr̋ҥJ%Dbb`HHz$^I.ౙy[m rF8z=,Dzv#u9y r/uTtgŮ|](_ QX)!n$)D&Yu#~+s->/7 Ǫ|0Ұ={ohZz|XӃC̃'^KUti41 }L"HZ͵V,@u~/^XK;Gͳ1IdW!|o**YJrs;stw=Xȭ,TL @c>CbxzV  Pv.aqB!VnZ'HwזnVk']3M,(<A+k1U=6X(9qwjxP)g$ʹPAHC'w_Oo.#lYh\a)wA`vj0؆!B P yٯ=FmҪI +V:@w1>$4e4 4(ӂJU, ˲{DV)SMm{,GX?CTo3G+98a|(O ([NCwo߉'G_ ECCz PL^+ZfD>X# OHxN a wjxd9K8O~]musYơU;\ta n'N x" _nHlHZH:]:: ) HY >$$DJ f 8 Mg5H5uˑM_7ޝNjGQ )d1|h}$;s~ S7SATk +$:A{X8~c&Bej$ $x@{T찐իΒ> 2`j.u+%>Z̺ǐW~)=PLuR N|礙-b#]Iw:/8nZY%" ޕ'Zӌ;|p `ܧr {HU>x}oW3ub=ibFH<&"6V'xԥXqwj0mzgc:<T:@+# NԓrnEDZ]YѼPB?$1 ;T& MC7Cb:q,Zmt~BT/^y8 ^@UDz} I+-m T(Ўĝҷz¹0Bqhu =rCH"Z. ㌺m(go%m[.b6>1N ћ"}2)钽LC; ?ӡiˣ!SNwg&XE GBݯӀ] YT7 ^{r"*2k%8Q}6.B p*`i>,=ƬYhVqCxMV,B=| ~P.K!Ԇ~뷼:M@hkјX'7V.r__m_$@-Ehb9輕yƒih 8ܶhk"JeOB?n֟R t aZ7I֕9|,$ʆ" lܤd^ڎ !n|BROw.8(*f>^ugi-|qUB=P{neRhyyAQ1po{Zb3${G+f$,򞇞H\#7*q\ ItRۄAV#Zc3 D \QtZtbʼnZ@XjesO_pPj.lG ݍ~>bMo6]r4)eU& O,W)Yßk0iWȪ\T@v JݛL@z]H>e: Q]e禳$f-ִD9FOaw~\w%we;)yiLMHM;{u$eS"A.W/T_sH Kԗ=Z=GKquxk' /cN Λu:D /KP;pmPafio\t)m\qe\- +bVq!ص@f Zݨr"k(7fBJB2\jOBzbm~̱u XmHzvra5#RPiơg ( YB]tb! / r,U՟VbDQsIWnx3~WZپ:DY{=rr埆Bx{p<ka$:"M&J]_Q.xT﫚%*G8P:AʭRHw H26lRxC8e~".h3/=h ʙEj=ǧ(CǂT䒪UZY?|:AV%fY*]@Ђ8K28%T7CzdJ@g /Q@| W(ޓ$M.і}IFALAoirnNPÌBp 00>E1l|:-novTd^`:Np,z5ysWvRlA͘(ȹua"(YXʈ']="ծқXwY~8-<q]ħyU`wM\㵦<l4oɀ{E*&HzV4+Z[x *흐@;s>ъu@N_8^܂3t<]j ] Z.iXA|JFm$X8eyA#QlQ&dB qn:4:SވTc8n"n:tCIg.Jb#A~ć(M٣{70|47["R={-3]uxq{+jG3e[b*Ot ?Zθ%$f@ZDIsMEPn۱_%ӑ/66FQx8Q썖Rv{nY ZW}P5S'v gQN"o/pGc,+؍fB8T,:}{ /5ctzx؎?u@2mT PFb/&X);Fy5{ųGL$@΋5 ]ᒲrZF@[q#eb4^-j%ƌPXC@ps~fR +_^2"{Im*o0~fLaU=V<Co+S=&F$%؆p2G-4ŠmheXX4 "˭L߈:'oHwGq2j6 DV+%2!kE8 ]fƎzp{%m!Fe֣£Uws)5f#F(A|E8gJ&hgl@rQY 't6cU!obk~%r4}'qWT'MϘe~5+f8.QFR e}ycKx^+h7p£>N{I*)m*(]flD6e-pY Xe{+vhOPp9Wđˆ#T:8-1e=і*0kd:j+8ΌcC 1Y4YeQ!@k;]SwJ]!!W})Fpξ< >GfUI'5ig#&6 FH[S`:Fg#-L9*y/k򇨖 IΜsWWN."M>Ӳ$j@iTPa}]z$xȔk-A- żNlc33!G:>Q@0 ~+ɚM7vtvxPwҚޫ oHK&^\T4))BMtySeiز@EhI 6e뎻/nV1ԍ[n@ǮedC{ fǤVr;Ha}rK7^d\XᖳnޔdM[OѲb"UW9͐Go؅Q<4,OA ߙ2VS /*9}#d9jIOyML`(O x<j&Hí퍀"&k,G#꠾@W<SLY-\eu{I42Ss=JJq' 7Xl UODFD=g|M 6řϹ`/$'YrAT;fd0ӝ,Hoa=*w䕚W"qMhܘdilg- Fm4FkD{]Y+jRG_ vu9\1q# r.Iŏⴉs[[Tڨ&vʚbzwAwӭmxGx~.<*3&7NL5zf9au Ij1iF˨y=?ẋ#(iu܌H]{*w^!gF p܃DD E%抳yL?P~)1Kk$+qlr6uoY4$<؃$RfT% 7ҔOY:B' 2#cOA@=ES!38%F DWxy@q&byEiRi[CR݈ K!NV-Lv*miꞣk,UG|+ckWIn’*+|JQg6vNG,@e ~aӘ\`F3HT\o!wH 4Tjƕ+UHT/P4B1ҪJW}U4zԅk#7wAMxf^M/=Wi"|H7m`1ydTpx+aJ`7xQN_#у_!X|.hdOML,gB4D^ 2)$ 7p5p3.uՒ'c<ϋѿ&*7GNTf|eTmFH%l[IؙR حAUjIݳ=RUH|̘s?4=bEݳzTn6&/RZTzA 6XxY(StzAO y q%8j8/VZm(=o`zQA-ˆ /MM  F'7Gm#yOv&-{n Z= rGsAN0Ǘi<,_rҝҪ]8隔r!ɫvf`5uJ}a}lgx<;9.zhK|LUSj1]07;9Y7Z!?߰yn]8q!¯ݍ/B)F`KP0/Ľu_>w`M)s7X<be~ d@fs;\J-D-=?t ` 3oQulU"m̻pٞw}$S!n\-0c%\lMlkP@"|0aj#83 >~B]"pXz^ULYQE]ߤSL/t13 [= yrx^M)."a~RJ@H;˓F4,f"k,s*kXȉq 0-(=D((ӏl\W{m0/k}\ۉ_t (M>NPM~aQ&wPh# :tLܑNv3<+dRe'8[jfbAc6^f?Kƒx^s FlO|W%Q4a2C^86B11\^3zpg?m6/݋CNz=78rYҵ"/. y.Ce nHh̡eIzq'r_?HwuF(ӉV*]A)2`qٽ(pD]Zc[^fwJ@eEOãYUJzR#+1|N{̓+jЛw= - ,M,VW t&ZŕDFԄ0WF7;2謪%s=cњ!}ZWbɴ~<^,S+g;×8fNsA(!'o(鿅C1.CKD ց=p>S<¶rF2AÑ_WmK']빲g{mJ 2|W'lok]ymK5zk`hA_m+4oD"BD!;W9w!3 c.AiTu9lhX mp^XNCL—jJţx<;^ Q!?Ϊ䩠ۮ }`D}[YtM\y IĘƆU"\Jd요7^yNΛz[*ͺfOm4)ah`@)X쒢ْBX2V1*[twF9uڔ#o` `65$G"KXm§9G9aJO33g{uw w"wJtt37nnFy[֍ 7zi%M;kUX.i9"> h/TuD $PvK22*`#@Cg=zRC0i"g=ʡi`q )[:XpW9[''.õOBZvH'j^*GeidZWN2[j^*nQ `}x*ug+9>Ry0LbGǠvNuݒ u܍h X4̓#>(Hy'!H \ft}x6iE?í̕[:Qp_O1fgK&(԰&vIeC0*/tA<֤%0 i"]1cG3*NحU{5`y['ˆ-&Ao(w}&n#W s1v6\v>)qmvɞL|9QD)5ar[P!8xZk]EzĊ?" \g&l5B(@Hx!VIS[ŰAl~Bӊ#>&'O5Й Y?4GsvqSgߗ)1EZp a?s%ϼ}QU}ldA-޷P(aŶL:޾0Q>eO4m|4ك;Zg EɘxkzƴƞuG9L5T,X:&-ZnTyY.}L^ƩV6 ΌWs۠qvLC"):ulkwVe+Z)=㌿B=p˔xШ̲~n>/o1%fU['߱.8^m'OwE=vsY;Ŕ,]mxY;nGR븊_B9)ȝbBiPQ*'"^G^ Ǒ fo8)?⋪(~D}MDLe-VW"l`SyK>]vԢH'Ȯ.[Mb(SUގ{CPVmtI7xx$%:uʯ8(mb>FG$}5r۰jGnb]ٝ䓦M!! ̶ĤJT@#D4ʙz'{ch'9]J+>;mKJQqx'e,2`RZxO|ԊD+ҁ̲iݳ<-z4K= L2e[9mt@H)}CkY,/Y'b֫^ 3}?87`RNA|8 Ee߆:tdE=CC#m=_$?h\Qhk(b V)5fg/ )jɜ|pYh.PZyXeWFm 8ʀQq/{=Qml)yF,V(tLHq3Fm } e zv>ݫ`sH6֒]qjZwqzg[7H`׺\5q?~MpZRDzz %/N~;Zw!is~*?ATyqAqIrrWd0+qRNuZwhkwuc`*Ɋ,p_&\TsBƛ93#6,q3*aO),ERCuQL7v<4tp kTB9ߕGJz{=l ~zz˴峲4GesPxFZUyy 2&$W Ƭ9Rڵ3ސfS ~d! tTF6BLѷm#J?<LovO@\?uK}IuKrԊ+4G&+Of92kK{FulƟkϒ#j/L:Ki 5`y+`TUpA|?Mg3Բ&/S^Gt, &L}@\1  <+f4J ) K^g[/ܫ캕LUyE>旼n;`gR劄͇Dpd AF96xEl4Dfg i^ {.z~ob&ŗ=܊8N_P<޶Ch'Յ%Լ(A=eWmlp)L/>_>n*~q*k\IprlCW^ҳPH|p<,v-)UK%,Z` ݁.,;`.}h@MCW(zR ȬO2ωKkXo׃ d@@*|:ǼޯҶ㸎`&9C%1Nk8.l[xR`߄,v 8_ǿfY'G5Zk h/Λa:$HTt,WσRaONAs<Ԥ@4rj @OX|]d >4jGAN~g.7GWW1*^SKDB6 4q^R)`cefӐ $δVj4tpFTL6DiSMm/mQ7Dx@Tm0u`.qrA"JRXތvgHlSc1}Z%,Ab m_ 6&Q@iw{5GYMLꍌHfq[۬IE%Jg8ޚ]On~`󐠿Oq-,0ev'EUP%AqY`",58}x@"fF1 Lp6%R644{v3s*"pma﮾x`*,ЎhޒJx%Ky̼tb(?vR1~M_~XiQJȒ?,2=֭+Ov$Z$Uï=eS$Љ#2coUԑJCL[X˧su6Z=  *A ZO xp:*BPl&/; W83Cƞq+`{"hc5u}BqD¸^zN IN7oR`uT :3~TƬ$۰JL4eoEqx¿ria4tzծ<Ʃ(j=!Ye$<)Y5~w🩞c LpjwhALԕ[e37IM%hrGsXˍf|{=_,?i*'B}%*,xRs:Gr$)7F7cjOp'vG!==ݠ(P _ f5vx9J `@[_Z7N:CKČ0;`} G[ksv54mĮ.ˆq鮑<--~4x&U%;"iM >q^A~9 Hn'h#05Eh8hfB r1""ӯᦤs3]"@fy~-+!)U*߶w-Șs(=SoRN6ăX +`XȸfgkhΊ 3@E)08Q8~B9=&>}e7E ȷ8~z |Ē کJ);۬QM#5C/Gs2ܘGe:H&}+ ÈOZ&DGFZ~nmOGPEE|_+y #8Y5x2tĔoQ-Dl u h>/[VG$k>g5 \ ,܇b'jB_`cebdγRAh? *J?l'?EӠ%zޮ.!Lp"N!j+Ў'5p_;+$-)g#JKٱ̂GaVlD5CyϘk=-)ގq.lLy..$ b\b F::]awQn )E묀mAm|B5@nEx41uJpW*r{ }Xz4A1W0- Uh' i'=M q{;7ȎJX8.g5 SXnXY4-obWY-˺UȁG9 /0O i`>KV3WX){ƻ]X#FF|޲ yMcj=٧oƑ% X SZ5^(\873:fm{NmՙŶfyftX7#, R nB})xR/0zƶlN=:&#~(i^;]vLa3y!ӤށgẎ#=x1qcϵ4]Yqg_m?_'"%4Po;uNf^͛H\ho[!q]5} ʦBp )5{Ö$eWqA ^8nT]-)-K_ |{ڌ∪v5o F82 G_Y~ ,sc`gT#ױW`4GEySD ;&s&^chkfS={>tdºZM8{79B ]">dQ=(gFO#xɉ-#(Cۃ)8h=iD-^]23587)zn]bZgki?E\At`R_T&~Z.RkqU f?#޾+'jʞ:cTؖɴ;\1I^H[t yJAk&5d1pz~Qy4à$9֝~+|7yѸm7\b5 Lvas ) (HGl+[y/#H?*waċ  >,U6/ ЅWp;%o80>b8I  FCLݾGTcRv{ł힝oVZAoۉ&\U?N]ZʬpI斕H[hqAcHoiKWW҃P|dL] 8wh(C<ZH WW_; P暟,*>sL EPҥoMXd3 {2#ҦG:RK-`!˼p"e Neenc`_bQi1ؔes6q_*KB@N^zlJFT֝BBm-d"61%`$r*N@ʾr%'@/@pR6ycR}ZUl82cz1RIpo.=yOMhjjB]x:CZ=UaS= K=w!u6Z|W"Ch<íH da1 )l3|0sƇ_t:ae:䋖|gdoe&@5+' (N]3 Q~Җ7~$Ul L^4 - z('W\ԅ;$H wZG>cL?~]sCS^FaC{$4!7jg'ugdLjV4~zNA"XIatt#ۺEjCzGU5`È' :"4e5*]H |9O*}@^;- 98LD3YsN=@hy)-2 #o-bI~HzlqˮeF)V9Rie Co *=7p(_n/Z >3D \GxS^I%tOiVՔ$--*Q;xH/PŨ:ԢK2F̚/*:{B, г)ӉT7XψZ筴Sudj3bFpe? ? f*F۲AK"N=YheN,̝};%+V,Q-uN ѣܖĜ=U]iVR ӌ8ƉY+F Ӗ`'jgOO.$qEmGA tr_N0tf[/x_ /7NS3|Ks(|'7dQ(Q#CC5bzD\ʴ-V c~yD ѭJ8y po"mЍ<)!N Sbj&nwxJnlh.$5&X[ ̽Z]V:W8nmO 00To9ra"GQÕRAL$#uw{Ugjs=QwaW;G:*@;(|%0+ď] 0ev je픡'F=?PRoY 7NwsC%UC+u<濹|h\ a"aIVP(]0&>uPQ{o[n{4O8'`Wr5@mڿ|?4T]CԲ?n2)7dq`ϒ/zq~u$B qCvzP5եףǎаv4XDo.'f:oqv/mRYdt4?L٘]]d4iX-no+{2{W!Wܷ#M=F50] ߲"n9gH/"{@l7ޔHum;r#VrElRBW Ğ j9qK1CѣG_f/S95Fr'3"హRF:]jz8Xč_20'.!AkI.La#w'O_< C>QŕoD?tZqL;%fm8{JBc@ IZ 𝟫+R \UWd a2 衰UKc\}3%0ʫzaʸK^5@sZ^̧*rEFE>"ՍJdr1it1*t\@#s&5ᏀD5h%4 U?Ѡx<@ !-܃ʀ!Cya%{4GA<ѷx1U$fVNW]382:3xU\O8!:_;]FM!;]巿*`Y$4}!蕢7oJc65OI*JIq`4!ؾ.2;dSo|CTOܬ'j/*i U#c~4|KأLy5b{&53&8aex <'wkM_ujnߏ3%-=Q8O 9҉; 0L)Hjң?pQؽbfbAAoʑ@DAGWהy]*'`E atT17_wؠo0)`aD41ϥ@ u-g 2V-2@d8.$3 c*VR*Vm4#0 Ggt# [c\C7e9v8TRkܐuѺ ͸oFv8g-0SK mrٔy5eMZ*gRn*?ߐq'k`Rd~]Nw\5 Hڷr@}*Eu]֏iz?8{4XRm|S Ho 7!9)_^"Ko0Rh+Ņ kX*Ӥ3&G,Q96D?ܺˁ ❈8$DtC#.D3`C3|;s133ʇ-k+/a~75qsP5Nͨf FCB^s{+V,B5G3=VL(f1'#4"@[?$ؗ`N^]WFɬb$EÔYLj4Em?M\yO$OJ¹ͨ?ڽu>vҺ?[k\[ -cs`. nO *'UqQ rPkM.M_UOk?2smDM-]tJVӴ`X|Т~Ec;[?\ ?ĆC}K&A^vF2z<Ҟ+%  =~_"%(g[[>Νu~olc gcl,=ƳDMRF2n>;8m!+./Pq XUsM;9l`&X_il OvR e~:9PzI>aDNNN\2vIA6wfpb -M -N>{J0oWG3* e8arҰ i~}b5V%=륣Fe,O\TeCOpUfټw̚FN큀%Gekb7b@Ҫ%obzK|nXhoipgJسQ߆MU9J/5o*>&00mhDT#)(bSqm,h6%-l]Aec'T1+ _L,[ѡX¨Nt")/e M~fo@NjcYb&?xw۱ʘGˡ't3[JESEm}EO7&:.r3/l?X z$i;{tH Fw-s 5^Nk1Jf/~3Jl5v@L}:rad骚;$3dYxa|&7o~Љ֗ Ns"uXו(aa?Lj Qb~V GBa h'RMWF{EBKNâ1Q < n oXv D\rC8) `+Xug\L Gr4:O37o>Q6Y&2!e:Ⱦ/R'aM/<=[Г4G$ B@&UYد#YxvN<5?:ct!\$:QS$`w$j&&-_gJ0RDf h a؛A!Rq ܸaNRP2%Q/Lf+^cRjwd&ѺeǏk~9p3$.N0)BwA-7ʩfoͿ9XZqXI,KEMpuW9@;ɣ3͹t !`&Jȡuɪ-H)\5x]ospQO9?pU/Z|m v )H*{bhxڍY㈦Z PKH>TDףzW N>uK`XpjXEX_'ȎӟXspzYuoMO <2eT*bK-sLcͅ\$o"I;=16Ll\&} WXƉ^, $Kaܭ:k$i3Ex/^ [Bd-",v˖J (D)Zz+yeb(Z܏A46NYlTm\/zUGG^57жw9i.k;>dE2& >۞!@#ֆMMiLyA:u]D ^aYE5LAG_gM,Utk1VY'%\,Xy-X0r>`Tcpp4ߓEt/%%kIJsF 2R+ȈT=LxͿ_ ^QsGXm\{g&oIB]9*ŭ;{)tY4VITN"`؋ ܯn*w5?I(̙`Dύ-cqFe A<:yj Yqod"=HNg-jxYV/ Lƿ7Sne^qHft5MLau&q|椫uB~+ڬߊ{iG/=ou䄶}S9x}ntao=Jq.1 | E lQnL?~:nڵ:CBnY2}ȞS>G> L}NVyc o7U?VM;o7E 1Y_K'~G+ *@J%,}9u0tRS=[`EG;'" C8`tyXII2 } b Nnö9,.ԚLncc%>0$Bש9ZD(b3xmkTy{2 j}=[MX#%+%u#Є5nq&x*VWoCVh$n䥈i#ͷ.lFhDDBS\4~nV >!+[)#(֗fcrB v`'[x6.kḪ.#e ը+O_oR}w,=T1aB_<ˋ];c_׻"=9 Ⱥ|# 7o#&:U5}8k"}$L!pC]7]?2L9?{y8C=NFAloteY hr#RI/Iaǡ SL2/dbwttJHgn}PFۣ"V ]`W,UMj\ttab$]$VW#}a}J9Kf˸k.B NGn;'_6wpS2)y1\l?S޶Po# 'ź*{ԙUD$KZL.ȿBhi&v9̊n ^^ͅ(8?Z-M>LՁ"ϐmk ;5zb7`3 g3*3ڛR[E{3wj28,~*ݘj1}8 GuI(&hg)* >X-nػ.,M9Biu'!GӹL!|i"AnZ5YCL.֥^U kh-hO FDp)b#VFҴϥ ׊#$ `ՒUE $HNmxЮF]SEVmYGg'K*k#pᦠ}/W8R{uy[W^U(;C2i_7P齾ĽAdPb2$!9ni$8+(Uʿ)F+:.%b^D:.<a"d;C<-e wNͣ5ߒ^kDQR\`)*-)Y'%OUtȎYa,IzW:r ƨfW{˥7gf$.`hٌue>́@;E.oIL.E(ђs>_9NuV s̛W9KreroA`e:r).曔TO~Ҙ!۳e}Vbˏ cF*0giEc^8o=>] D=e!Ԗ^Zǰn*͙֙~rE;M:H̓ r/Cy$wc}aM&8xl=0 Bк8x >Bi85zYXQ}HLjYL(1 妽;30Sv@̯I&΀s_-p֦k`@{}|waS_~@U)r}$t@3OAvMQ+VRzL-+ Kҏl.)lPm4Kwٚ L'vInݔIr #.M޵IO$dՌtM>ͩqă.-P9>Mf)꯾G{PI!0>۴E]fu ywZd JA ,9)#eqDC6QaYw&b}mTe'۝FKhc/.xꀗ\YK]O7C hevdO"s*9J7ОABE>d.Wb* B?\aVBi{Uũݯhˡ{;_ D۫ns< :i; v{)<԰OF +g3ٵw\ uae2$i̔KFLȑ%YY %.@u{iE/]6DoumK([gia[ͽMFW =?80SnNf^2{ӡ51[zH{ҢpѲCyNa-S]l Tdw*`%  30B^KOu%xkB,[ߖB).V_zvq;VgxFmc"f`#e0޷q߲/`J~WI0)^k?x?y%JX SA5=9&H u7] K9BQaɄX==I@j>cުLPo|3WH|ק@g1$-J)gnۀxEDokr&ovdՅilVt;ә?@>>i[`#c @YC~ρULx>qiX,Av=/=<8Q@밇# *եe_r`>dqƖ8Qptw3sαe@#XQK,8Rk5Eg2 M0j+T%7,,~[l\)He5[8:pC=9-o/r0pd.>Fԕ8E2qXA4#oOG h֪a]2Bm$kޮWX{}AV]~n_AxVY61:!KAHG)d#W&ǥbu5m c嘄;D*$%0INS,y(24I5^D80?xpYR<869j޸LzoP,lEJb v|B搊,]kc]05lƃȄadnrzQ>ED6j DZyҡ-cvE\p3%\Ub5Kzk!VYB=O=kQ{=W):vQdȀԫ?$˔)]n|I'ޖn:M#hۅoD5l?rؘ\-zYi Z"waPU2&;Nx$bȵ#g^쇺Fk͔mxqm "vi=y3ln&.B>Ȱ\&!^Z+JpM/f;'Zg{&M|={rSq?)&bv= KeMY_deDl%A9` 0-y.=bDK qr{9vrKODW8n1"cLt5i`]i_#,~;R57eRךoRa$|_ ږTN7\tiest+HѺ&g02y)mލSWlhhnJ3y_q_!~b ^Rg~y^PDڼ\.ywcfmEO']ZkbF@5F%UCYɭZ&5Npddn9EfY,An a8я]V7L0ʼnOk 9(O-CM [ ֣`CtץsJ,3 evݳ:؈԰gaW:bYI6j~xq Axғw^Ш)(x$Q Az);-Q0yvEAv><nOMvg |`-KzII "$?NСPsC-<4SyG}dT=c13Ƕ Kh3b̸눘0JΈה 38ls8h03gvRN"cov GOiQ}k rӶ*Á8ň(z^/ kzr U5C:cRx"3 k|mYպ49\{/۱.xk#N^آq5iD뙐]SPn|ʧcbpRm'kb'p\Y *)Ӳ>&u%́%S7Q G;p_ݐ:?e~(kޱ50QQUy>q،'9'ki45P`ֹY X6ZOΨ5SU^Q>]U'vlp᫖z\ګZVUU,<{AU.݁W_*PҩO1s߮!Wi[`훸F[g`ַ/hi9K*=*h, GF}pFG*j%y9 ? +q+lΖZjyE] va׎`j_ؕcW +5_2Hw/,U\~mn66 oS!@]X)zjR#9Em ..z$Ue,Yhʭv{M, "`e8yzUoɵz x_:"z܋Y]69h&Y4 rܫ}B$ qȃdЬvm@$*KѤY.LPnbjdc67T1W dO*GS !UsGn򠹥w.E-w(ē%ԩ,S&v}d02oҷZT,BAS@u,l?]7Z#jMnYnQ>Sb6be[1IB'i7M-+L@@Jd Зdۃ"Qurʪɕr9K rbZlכe$I/73rՐp]ZRɃ؅ Y^ɒ̡V+ˊ6zRVVlx ~GU[1SA2[9+؜^Ujd[(*G.~udXu`:Y+aN[VaFYeIB!\JU]lN,L; örZةnۡzա`r3*-19pE~` XR6l9*ly` yqEחQ(沙3`x-ySv*0&4!qt;!DښPl= Kޚ]I ֊!4ZUH&ES\6VLjjKclpIL !B<̴v9xnACcj(spB?&ݭCerlX(*Dg8vt* y3UAR{h[:PhBTmhpE&RIjh:ɽL!" _z$1[`GAsmr¸ Ą !@ ǂ^{\|50iV!@B-zEv4AYBbe+%NB@ =X'^ZE]_)\u!BFN@K=f(H&}В@M#kyq@ñ$$;͎WqqHo_´ s2 Bot:Cx@׷ֺBHpxlI$SI!$phI@ InB$$|!2BII :JBy@@$L@IN;!B~*HBLI T'H nd!dBRj0!0 l!!!ӌqmIC@M' g2c@1,8XevhB#- #߹vuJl외bMw' PhB& 9Z_YnX@@AKa5ղu$1KsSl-l*iQĿX誔!s[* RM1o<[B&ܴBbP1 ecwPRϪ.]Z*N270Ef_kiy*F60qdoenСbr|ʄMKe\mF)TگMP7¡#IPJ`S)熶Nu.hVvH 9 +5V4φ^3v*ua6vmݞk1߫K*贑0Yk&q0O3;tx' a$*HHI')|iGWlR-u#9 Î{[.I*TH杰TCΥ)Rʭ\'tlkziz.AZݷzin5e]nۭ;0hq8^ǓGn$$8VX`ԖFGN:RL6IxݎM tGSNjPʢl Մ0ؚ]svyF˒Õ=C}.M= VĶʨS$K,gcY8̖=>ώ{BҠ;LsD)vcg{!b\Xϰ쑼oج*f6FJs(aK%3blՃ"I '%$"au[q 'j}Qofn36ÚUgdYrTahS,.'`>nQ ֞γ;vS~[BB9E4ur &:u2hueVM_گ=\$m'-qqƛ(U La7܂XbzwU m W:MdO6΋OK.>b+t`LOf䬺j[1ʣ԰8+03JVj_Jʵ<IĨ8:d5ڵHb#7[> HL;*h)&|yd,w9ibt[s?k:r @FSU+7þe;Tw? ,;]O` # 5yLr)7F#|l5ky7L*WӾ2A\VY,?\N(L l|ի,ݍq4KXx_ǔHJo!!A:ɪxmv7[&[4Ǻ%=l9zrR7_BIaO{h(* *'".F?R,()UnOd!!ntO>PC d`$ ywTH*0b@eɦaHnJ7@Յ |РDQZ?.0m~~eOl&9Bgx/L}!9cDa5Z+,ԘjWCW"_z5j6>ɻT0.ckGb0w>ͮ}(idL@{52+Hw1Jq +Y))Ya@"ZMݛ0=Dyʣ"ӜY]|3ߍuFK_xqSf 5bHHzx;=]1 ;rRo,MZΆؾ(^5~ ?QQVovasLn` -qkʵ@~ ;%bb 0@Ywf,ְhx}N_ڿ mLM+#~&pee7i>Ea@gVm; K;ZGl!1 i( 2wR)%cXʓnm⹓dV-dlgPݥK$ [bFI(1F`Vʁuo $o|te#oCy}wAͯ)HNWM!PSeW>bVD@RaUڇG RY1A41Wa5udrZsGPY<]6x?v ,I?ޏ?i)GKJPH"$MzD xz\.#i j)&a,&O󺙙:%<__NL2/yte99 ɑy$b^DwQ"9_ iU< T2g8!xkbBZ x/'Rt9t# &|qagDM@v3M:eIW^N[dHs| w銤o+H*TF]@EL&rRDfd*m齯g<<N=ьE@&9}!0ʢ ;vI!?$ lx5G?r y^3W(̀=G]c>YJ H\'^B 7_5ia !)Հ ?U`<|z-rحiŴہПp@ЀH"R:Uמ{(! -P{n*r3VB @>fEX]ZruxJJP%'dmRG?6Ftu?\w jR\CdnGdVxoٷ%2`EH"'(. [#Oΰl"T,V;N: ܵdHYګ# .vW]]KuWιӢO,\S?}#h -‡PQ,2ֺ;CQHG2* v1zԘQ i0`fl=iT.__qp2`!m)î7;Ff;;7n8|UӸ&^{t*- +j+$\>mjrQ'3r;2^J>Pd8 }o8PyNW/ؾUЉxVdQwӡU|?<up7 3V=ʚq<hdIOO[#cfњ#ÝQT+Y\mX"TgTBHzr$MS!' ]IJu>ceSxW7F9HJL4\IJfJ.噔1GřÛ~:?n#Z%y_kp+0x9 : k,XI5(37ۖII^܆Yi lCf@ISdj^BuC9+Q rR޲STyg)ƙ97<{)z@Ke4`Ul `hI*ύOW[He5%:i QHsK\ytimW;JȆ#A9 'wJgx kvo˨ɩ:'Ys]_3<*Z:Y7#+ְ1oVܼmQ@|kvPq<=>ú}V-w  JAT zYgZSwmzqXHeFFv$T(:渒@r${))41<ٴ*RrZTIe._q:/OՑe2CB$Wr+̗!P:=U}jy1]E@bWQeOU4wh;G;qV?'5 p)EVpwtçrP|Msq ioɁrY]Gc$+dźsv}Ʉ,W"hÙn-~̳ wUKoWS:Qג!߶R۾3Z\ծ~\FVVgtRso>z9`XBDY^Gйk5CDTL1FUp8:Pm F{&֦/YiQ6i'.֛rgKrtF|Yy}}ocv7z2vR{]wc͟+Jꢫ?/`[658mhftLp `NRR$CEʽ >M;ڂh#0705AJq4nnۑhd0N^w:;ދXgXgz{ҹH'+d%KU1LɎ^!wo u#}=D/o޲oo$o,̑oo;70 ,V[KI^㵞5\ ޶n =캢*d6Y%ίkV~jr@ Boq\طfEPk#?Mvʞ:$u[iuγMDz)ʡF<<5l53dvԦr5ܓc7a5l A[䧀;ݎ* иpy} 9v q8:l;RN۞^!҆ k_N}y??umS">҂$60Jqڙ"V 8@m*2r0%xӯ;9|qMʆXWxz"uf#Sih40{s^hsqw;5s3]7K0e*,<ۯcnsM3YXֹz;/9:6wrsZy]w+2A &Xp<)7p3Qһb[zz= ȱfՙW"_NjdfUAdokIXO}pZtU*'n֬P ].oB96)nmI{gxXׅbs%ˎz)|%oD0[S! |PC4uzY; rT"ަ]jLe"d^I]o znVҭ%J rjX{7Z6mYAگRhu6Fi[La&C5.cf[q^'8|O~*k'Ku܌.@,OaJhl`q8T٨ & v  <ul/ 9f|tYo$rJUjx@z:Bvh_УZ!u*7v/]HeT$d\sӘrC*<  ?rO&E㴻/wY X\ņR@Hr'Cn7 @^*:UfoO wѿ%z[eoNw]ڮə6VQwڪL%WlМZ%:IZ~я8^0(v 7WeD0#f(Y uGK|*]3/I٦YJHiX1LIwGv\KzMx"( kyG-$jGG2r{HB\BB,%Ee`@KCf^&{:/wWtw9:oTC$sE6Z>@S `R?e~ oAb(*~BUVc41kOn!Y~qV`pn\x[gt\_M@"јo[`aMaQvźX.Ž`|-z*vqZ4x |}^c5Nhn3TCt+0P6Grkkz/GOsbv@KNB #Beqgܵ@17`WW==`c :~Bha!P~ GXRJ * k; |hPJrv<00'rңn`)OC/"( !~򡗔BCNZb,dd+3O!BFac*'Hp9k2!I I#!ƗsibX&6'FF0V #i)AN`f ]3{ȹ}M׾7jg9KG?^sc9jNЕ'\]x #C|6~Hfb)],_4pp``\a(!( JlPNٷUa?݇.}o֗* `KWΊpAK}抵3v IZ9OYCP$G|(B%GZ1IHPA7RW]J\|yR. W%8jvǟRc`K pCz%|_w}=Ws=o4 tLWfM~%\2O#k7vݤ`)>dyCXba_3ܚgaL)hUg-h[)_;2(ajUܝEb` Ja0QnZq#zށheN*R*V/?nqc@v2oݦHW~d cP|܃bRjv—;F,HO'1 v*찕S<ɺBBNSnUYQ$zJ23ܐ#`I@ I4'j.½}~ל\itot7Ȉr=b|ϲZ/pGӕʩv`ȎB Gj d3O=ՀdE|bXWZ{ !H0' L~)Q "YdċQTkR=-*-+\lȉWM 6VMZ;uRxMOe׏l. 9m,@&$Dvʏ|ޕ3O* M22ZYVl3 j* aHnYV0;]`x0_ts*eDՐl 3_b8ӣ|==H{k>ÇnVnĻ潇VD3f[zcͨQ? ~ׯB9.2eA`E0JzTvO}?Glp9)+ ʌ/!mtqۭ\hi !m4x$U$6 }'Z8)H%iX{r ($@#KAFDB'`V L20D}+ ~MI a^T C鐕 %d}.\6Ӓ ܚ'û}A^dƑ H,ATv3 L&I[$F, zbgS1֙ϾW/6vXU}3_1t1}~bǒBH+"|ԟ;L &R@AC1- COÇA&& P&EX1XAO@tYw.O&$2V(c SVR LX,\ |;V00$<0jY&}ZH:i~B*u>~Ruѝ<~%!$P!b{%aHT 6 ,PXB Вha!BX;'A/L'·߈-8w*YFJ&ɿ ɳT!i*;NId晗Đe0[%j\J8~ F;HJ>?*o6г"\lpXWGsxlHu'uK0e?ٹ %|3Oi~;V p>E>We)"% l."L^eX?˹?:[3rKcOӬDWZrl tFQ47tٞ,=b&xCi\Q )E TT7"uJ$OaS+W/P L:A0]0 ME,vL4[PaE9 Ktvm$@df`wD},@-Ţ^Q3j!bbXPG~J}kaT0D&3yct|!AIv\yZyNVowdGjش"ivoQ?ɩ.EζsuP$qQHL.G4-}`xr[wy5R @Ev6+xuS"κq@&P fsQ {bGєNvƲOT 2HHb ㌒ZWIH|Rt.B?tq7E.g=л7ͪ)̲{ vi Z!ĘѶ7HAWXP6Iȭf2:=j>9]7g>.Q. 󗅅okXb=PQ ;.dZk-d=ꭲЅ%ZA%Bwmb"GaVlSzޯCjb02h4SYB4=~ޮ,I5dh-h/ H(JN%ij&}D|QI=2B""3@d;MWzOA@CͲ }8lA>tX Rd 7ïuG,Xدǚc۠P!AAJ=|q{` 'Sc{`\FXXH gJk=_Iv'RyeD筽i>Jf?BP$["j? g k`>gJi  uֆ4sb71kmY*@X@2xȦA/? _6Kᵵh dϪFce0W=x<΍xhs"QhWe%/4e'q 0<O~O'gB@'y, QWĭ{dz&i.%XJیX+Ǚ)ř' '<̜zC&imſ*>%*3M;JmqT,I)˘vi)nՙJf~js}~ɟwtA1x4AF^X0=rYGcv3n(M PsofBQ5ɄP#l}Zm7{U+gNX ƙznpXpWŷempEd'l MxHU:VQQ I q:fՙUn(ˢ~CaK2l'UKjv7u.@= (DJrT0P` KIa6ayH^\z DN#YZI%ǟGu0xpdvr3Jrd`TdX၀{OO6G17wҬFDpD) zfw?cK ADR8TvVuFR >n $,_^Pc1q5ƒI&uA,ugXsR$I"aLl4 A pLux@(c-F"\2L@d ECO/o} xO I :&YGBJ`;S8g~DQ@U!wG $rѯ%^~f#g xXv(b 'OӢo.t~ ǃ*zcTԩ8| `__o>lJdMX5޷y+VP!㘖`PFA4e\g_ Ϲ]'^׾琾>G)B>:V@}h C-LH|FIKSqGLU,N\5tB{o!vD1Bc)&?8khgʡG%Xa/xHbkϦ]ur+U ur uD?2ON̒k`i H@Gu7$;ڴdpwxߩS#v6S`q`=W+ U%~a;S1@G?`"L~V$3wt!) \OE"@ B[S#$BHt#[z0ۮt?yN(a 8d->3}T$&xNմ%0'@NəɿC3ki] v'J)L):$ dʁ@aѡ Y$L3RNqv@+!$bMLPNm[R"kl,L !E2̏k#Iy5Te,T%ʯ2[2'T.EopDn2 MñtwI㠚g|{D{ʥ&>\WXBihRٸ패׺ي3=L^74aJ0ָk#C[:adlwDPt\o13'L6:Xޘ]t"+$,CКYgm g(l-}hšNIԨ:u__AO/TL52 )`#<}.ϩiUє0@ Ȍ jwի3,8zJNJCʃ=uA~9Іpy-\J>ًfBQ̌9%6@I %#}o wVk6ƦZ5d5d[\szU 0cx9*څF׿_,ڈNj7{07.[&M"L%bD0}?̐xO%~,,R*!3/!AZޓ4!҃LQ#Kq@rט¨>(=~b|39iBH/O0??j@= \?,QCªL+}Y6׸q̑k㪠V@JdltUVMlLC3jgsRbx`T+}ȸYS1ml"M\o!^+wvn v忑YyGD, Xm,~~O: a`{˅$Z -;z` E0@EV(1,:ϙ[%t{i":?v 穑r\\./@SMěO !Ot?v ~-cgu7\cs=j|.AO?,t/eHZPU[M7?s{+W✜='Wi>˧XNrsx(#%QTU!t=[X+K2= cpraxVp[\ī~@0oT-Vg7ٓ*RHL@KBÆJirw\ ~c/OްGL A`E,D@RA`VdPYRR$kHVC*EPW)'{,4Lb"aEX=~O$Vw!ʀ /#f癖lrs)K!$DAf*sD B'5U/}1 S 㮥=-e}=˃۲>݀1( X^8iǗ_uXl_)rʅE͞Lݽ/dXyJn_g |IƮjBD"(4=YՂ7Iqz|;wh"W&BeoKA404LH*gƹgffmvH&FH[=txy>iW):QڙjȋQ}@g_1yǎBڤ=[_Cޠ7w֖OkTU6q':f*l8g39w>5^ ;ZfVz IJPVRAttՋ[hǛkw$+Eiד6PAŇ]_6># Q 6] {FVat˱e,0Ä0O| eσ|N" I4$q@uB'}W1O.7U5āDHC4DZHRۯnSA^)= ^|#<󬮡zkأdJ@!UGuZavpΖ,pw#kNŻg^KU`F,jhB!W(˪6-{u| @|*Aũ(PBNrYѸ9sC[WqwYܗL">>fc1zMpO&еeC<ElO79Y%%angnF6,g F`ҟ.rҰR%"Mgqccaܺl (.m~CC :WMX\' @#uRS@2iYYdLigmHI;Wxŀ#4HE@̛Bp`T C7?eEYܸdɼe eU\g$6v| 贁 *CӺO퓆Ad`;}DHc.3.t>bKb0=huM+k"MɵqV \lbtno>Ӯ5y@cK12*RpJ2ҋljg%!C9erpX)FScnsu`hs cG!Kk߿HqtAýߜ'wf3lŤN$Jh&hǞb.]p3'RCW} yHrÝ1^1ڄkr!j ܂\Q8P3s'.[_{T!/?R b.: +1M^ƛTԕ BJ%A/@1:9?c'+pУe#bg)OԝuX5@o&R)M@[7A;ߍ=5}Gu'"GM[5ɔxVZX̓v3I$7zEpv" zX KٞW-&$NH"B{.Ovkg>*,W~ a^֗'EPԲu n4t"$!VKچђ-,CĎYQ X+An;i,fvIټ# :t&eOS߭}&zMæNHe1of6VFl|1HIKyS@,YҋV 1%Ԫ ".IW d5pu&=hcVDK8P NX)'w{?{H"L2 kTs猣kYF& ,-AV/p5h-((;M%":,c#cYO g If#oF 󆂈Pq}M-ieوXAqHi&&&D!n @0HA=|Ԓp/$~և.}=HiFxH!$#Lx(fcX%dz10AD5YK  d*gM$!&֋#." P˳b[^_Hv~@N?ʑ5m6nhqH$-!\k(8kZ2ЃCL7q7nկ>mĤ! uWJYf 6-FV<Ƿf &%4KgzVw>˙{{vV֤!CVl6HjX*K2wo @i&^b 8b}i|j1éڧ'miJ(ahUP`%Hҍ,20$;SQn df)JL Mnz>o8**ŭhƓ'K~v|O l}"-d2V"r WcbvW,@ AG{6ӻ{ҀB@x9 Ш.A? dE(g &HShvu2!$ FέЀ,뮰$W]MVZ\Yi\ <ϩMS]뛽 ; w"X(*R21@EYPPaH , "`J`r؏%^Ocpח/@`BBEk9]e&8 -LaB}sHpo:A[6N޶;J>]t{9j v(GbQ?-(1`D TfwhsRj]}bSk1 }Í+g'f更YXCw4aUFoO瞷z*ֱ3>l R̅2dS!' %6`"AB́1) # p鵃f(ō/~KP|E`egf3Ԁ@-YP($ ,g1]e;VZ61@ȡwOLE DTSl-gEh D 2t4pX7u0JT80CGL%sYͽU?5ːlƈ& jm9xkqX6)B댧L 5CTE${ZKܼ.jԠ};C]wNt! NmgzJɀ 8ZzhrdPЁ Ϸn5Ժof:+ŐX9B+hVbci1LVַwˬ]Z\eD\&Tb:\HfKY-++V#Ġt)Rc Ch`2%ADPJִuLt !! %O}pe's޼pDiK*~t3jnJұi* eQ-Ϗ={ՠN˥Sf^Zɶ|CB5~|8ChfE:pF# ] ѣwCAWdǧMQ\ *?G HAC]cb\{:kKxII"D4D@ *Iwhs7=B- $.?+΅Ro~;혣{SC,Qal„л;:퓱3&:0@R+〛Eug `9wG33r$/+u>TLa`_l#(VKCLl& Ī9jtr:Xa E APi]PDp4'aчN&,G3NC!}Z@>LmΚc&$ DAb7/xy%eɋ2MM^pʊ*lZޤV;VBfB7ɒb_SiTO0+f- Pҥuђ*,Eyu%4-chtWoБ"3 z؜çyHDDbo`u3 1*g~A(07R8$߹pD; ʰRi$׷x)A\fL cÕće:6A .)E_Vm2[ ܓ1\I(ʡ!%/_*Zd\bEx*b~xmJ3ˁjH{u.PDW:pM Ffda\t6sݺ6 ňY$zخ:PQX6/| QmҖ0Ls6)k. 풜<+56CjD?~f޲9MƼud^>^㥍r!(ɋ=dFQ`mж=[LR!i4-QudޖY[Ӝo}e5zяiUq%DQ+).c78oG+$/_y_ת Y^֬: 4F,Sj׳~;Ǹ%o{"uEZ"Ǚ;IR.&pE۬4dKCb%eu2}*볚;֊ic#Ucy5kjJ ڐ[]*j@3ޮK0E7軍[i#ZaERZMeTMUybu6a\X¨TuT}* gPAd4r8U@b\Y7Oe?'.dڴ\04 N@yO6p^wV5\.zV򹂭'EQ0Z9a:[gݹ7(e@rc-.;z-4kTY!>*[lqF H@Z .orq.ЀG_0$$l>=-dwZM9TqڐÛվ {+nϫcW&"վʫGioPip~9ro5x8#cfQaw̩<9=}0F=-*g.1jit_s\cԇ{wZ۵t[cӚESWlKd8H'1's,;ør!]HKgi>sad5Q7|əOۄc$z=*^M_C9'ct[,w>znhkH+obf*R߽6~ﱎd&XR[x t׼#M[vNb˽XN(t\ѓ_:jDy='i8=:-boPx n s7=so :6.yo5ȿĆÖjIV1ڱw)EE>l`-.9H, k .S57O]'KyEj*4`qf9[G#LEn4 1TCk-|媊clWFj:۔UsCjȟ˖ʼl?:=eWtxܞyr,շx]^{?=3ajsT*Y0mxDe4ۛΟl=sZx6>M&tj/̒n]M"Q}^Al/Z2)AS:*g<,E)z2nNe>@hH6 6FȢiG .3ABܙ3ycia!YBjJ[6 1Ґ'3VVUO6h,9R])u~)Z6E8Yftʣ3?mCx-Z:=y˪9\:[$mkO?^/b rx- |%O@^j\",EXR!%o,y>K$!i>}F'଑;i"/H])'λ6]> ķ~w&Xj1a:^2B! _?kub$0" B,#F@" }?.$J=&t/V2W FKDjFgK谈UhCRdX@P mtkZrz?!cOͽ$,>to~ΡFD yzN0!{AoBk$Q $ d̳`4IMJHVIX@/P=Y[HQIJ$,nyHvhxFf>ŚMҨeO@VHDd} )$(@3\ >-~84dDJKǖR?tz`Nѽ)Ί[K!@wЇI@ I$Cc HC3JH@)$,ⰒS $Xl’LD8̹$ I=OnɈE?ڳTgm(,fYd V!d (HBnu$@! '0`d~ +P+`$PD <߿Թҩ5,3ؽr~Z>=d @!@0!& z) )Ĕ[! -ȨE(6XCBHE) HY?M c 쐜R#,`)X,R~daY" ?pII$ l0f@ 0RC@ o^p"6HduVoCukk[lswc[_f]U?v#=BI!!C *j[ _T`Ul_EGyqSVdR Cz! Clu]mڷmضP$(}^G:ռq^^1jε935>'}bR@I H#!#o>x}_.؋~?Sw{9e&ث'3\B]0 faŦL~iB/Z>Lʦ)U;F O`AmD{}wޞ7R И4zaojm{zp7}/8@C- XYš"ЪdU5# U!H 8·wՂ+wXx>&t{hznYwKIE#tL`!\ 0B0t^H!R]h^$g4 gCޞ #%VC ^lb,=adon1a yxa6}p8FFNO2Ό$Z4\Njqu6̮gխl/g#?/|?)DP))BY$'^9B3"Hǟ_AvGdžTi2Aγ-3lyOxN$դ82b@"?ƨ$$`TR@ I"bhO{FI!?anD bC!o's4 ,̬IY$|T8gxtzsIQφ0ć{ZGw[{I|몷 6A#5jo}Ex@ĒIP Y$$z++BWw+G&#?rTĮ8/l-r{ $h OvBhoˋ@ \II0'(6г1Lt}eZ t״ڎ3 BVSD̀(y+$!f-{WljoD:Pj{30}bbqrbY}V^V+\p$,q'?Oہυ_b}[*J$ВqTH]s7 &-V/亍Wy9y.#<1W5뮻}}m@GDF !KВ*,I Հ!dP @6ZaVBXPSCPC$ l6[!lQo) -I F[rk_&(cyJbv )$rN3*(}(Z_iirae#[r WqD,:0I[wOɹ>$D!!+>yfP BHB?Ф!!ta(HD!a2$XXI wY5*fH15`{K^zޏHr [fՕ$3@5O֪-'rΑTO޴=z<խjqi꺭UQЫTkIecm?ra 7̵l…jPC%JXn{q 7\!_&WQ[V[siTEv$~zhH_=~F}RHw\yʨcNlW*sމO1.(PY@(&%1iײg[5o{qHm΍]bw l_ŧkޜ$M(s!ǀFI$ g=c-B(̑j@lx{h/Rڮܽzp%q pCXkSx]4ՎN8 )4"w/WeWa̪(\5:n?вBQ <|.7 iv|͂Ld VZv̮.ٮ}O!r#OT|(7Dae(@GnZz.un桐қxr ¸Lh<:{>"+6qb]g=SxHB T#%AwFf6B8g E$0Kx%湙mӋqwyx<RN(P^wmfiٝ8~ēYѲ\X(:LHD@Ht"wb:֠AĒ3c}5n#x>7c<\nM + AJ2viFHD,ZX*/ y.Ⱦ(XJ!ӆA-f)4F NNSG`]gJ<]$ k%HnU\^Km[̶$!:f0Kbl`f&Eg4IS:i4qLg,0XtY) 1IQCH1T&%`d`q ,&3A?4I/bXNdq /”AbaVUѢrhL3ǧ8Nr!0[_n{f ɘmq_sKdU4YJ\~}G0NQ(k)<9쳾3hz:#_K~QZa7> QxhqF UU \eSMr=A+️?Ϗ`abA[]Ӱ{f^ά yG`̣^ia'0Xc3i4Hc?:;4~Nh6z[NU:IٱonG.*ᇅL8Lx(~QiHyRw%:$e̺\@b)z}FVaMϸO"澅%!*P>_exqn˪Bn\}KSǰ죋- Sf$R+WB&UIҡ }v`0[!,Kҹ.=37s3ɛcpd蜇durW5=6g7 3`inI9~YX+8y%1*) ״]]/{Yre`,CtO?I d0b 'rS(E"E_朻:Π dGbP"%DWjO3l9H[wU6*$3= +`M56d3e5YɚqA>MD !zI5U7SS)@22Dbbid,߭߸HI^Y{7S%M7S3+,pވEqF[cͬͪ!;,;6πan$|ӉwwGQlrCKIEslñn*!b_#A62J*tɮ5,k`|.t1z7gs7jG7ċs7-.A#F#8sw^قͧ?=yf.{<]m^*A  렭ys:*M$qQ6%=ܲ[n+W~^Ty-^m!(qΡ@)(p tcC~E6>ncv!HشՒp1@H.[F\d~:=$O ?+!_xvf#. HBF/>4{N[/T߲3 3-!x鏝 7L霍7/__o:Tvd!tE@` 0 ˏ#4[ TݲS(Vˆ)P'=9t+"?3 9`)J@v*â \0fk&P\f̴}m- -׺,Z & &K8%uk~y׬g(څ)V !%, \H|"eT/ w`/ MA#B`2>(iC>sܳ)NiMY%YD,!h܄kUpJKG$$YA)a9z]+_C7K4xF,&!׸1EPXɋ~:B`WӼJ) EaժwQ-1GzsK]gg7,@TQ$c$Pw&YYY~s@tSHO ͞0^___yu蜰mbZ=%t;.f& ;m7&iml򻾧jH`"PED(D d[w7"!=ÀNbvmHгF]UgPȲքkq=;f/6f"w{jK#!)!7,0HeJJ~6G[^B$hTM'`y]u+ ͗Ua9^,VΞ^5S& S#r/vI%W!i3z=TaS$> C!@ibſH^p!]6`̙ޯeA @>f ? Q͍ȉ'u{-z?U{;`UA_z_-XE_hif"H (u)'w,V&\qVP֕3/p P7+7:<" !$D$|j3M$msݽ@‚[Bl~Cy]puz7$4X(E ,2TT' n4LWH>b:l 'oy|߲Ύe ($@UX/{kv[i f幕H( ̸\n{AD9ܣB R& ^s}mKWݬ5B 3~-10Q[M!bUhמSdx}QdI+qDD@?XFϧnUq$Im'E62E]8?#ɰ1gPHÝ/o>׬xB "߆}:Luٝo}c+g+f[GzH4 $Ϙqzz3ɕ$ A@THAbPY  uguf Ab`# X,E "Riiy#s/X88x>kY39[X ,Z~n^~jj׾3ҲJ}A-}+>leJlD s`wZ0glH"KRBIz N>ʵO_y9zbVKʹ+! *G|<->F? ^GmneZ T<[fi+)kUH9x̝>axTnU.&{ٛR҅Kf|teV Ss$tB/a b(*9,dSM̢T+Pmy*|CP"" )\|<^vnrg>I7,V㵟>tr}YSםLa5坖L$C.W) 1H LRso>.u]Yu$ ieA6TRB@ G璅)|迒m˿WyCS2bqqB8Z 6:?6p>+?2Z"l2۽sDK/ODg7O7 znZz:GuիaJemZ[K`#[}bŸg$a\$>Ȑׅc)/<WpS"@3P@  S~x l/s[NX]ʖlk];V)OB&rW1Q/w<Ftk_$,ʪYb3AypW 4Q~Wi0(MH?חPu(78?|˛DFޢ#(1wPKecCM՘jƎo`bU[8P7)H+A4UwDNJB@h :JdJj 4&"啽@Qؔ }/WzNJPCRy `$>긂r; J-i7H5uq{@􊻪:JF>ݲ۳pB@EQl$K pVtEMBJ&P\]$4Dƕsʄ)S$dž=u@KjGN G4omЄ:0;쟗c2S(U!z.0%g1[5( dsęB/"`;MպT ﺧ7Ƒi}"+O᢮}\q98/[j:6m\c}V2'⭬@xK+n'x@l٧^Sj=!m^,\}km}%UȾTf1;6祐ڂa!qfi'7̧: hDCÜL&7]7;*=PʼnB@\ Nm}:斮&wo[Kݭ]B{|KXV"2ۡ}[3UY>,n<}~KG{E= x5 q.t-q@6yd84,­.iSKB *^S D8 ,zE`TRH57ۏ@)a>2TO/>Gbpl8AVE4Gvh2A h6u_? ݻ׫Jq.PA($֚M@h2!Q(XT0 Mt:ʀr;Bia^f ) PkYh}[ $U̖ (4"ZZҽ":_b>,:-%:u=Ml _ O]BLj%/\^"U4*լ!X]x:wD,$ , <0 ٝޥ Hi_H 0x0y#H e$PT$bDH9֐&w{2RBCI  Ciږo9:BC]{ֽs$`f[)Y Y ?JiߛD:ȴŅ S"$ tF6"@-s၁/KAwSXk+3KЇV$ BM7Flmp an)NTV=isX%}T]sFk[U*^7jT$$%[R I$>s $ߥhK2(OS i Ro]*؅5 M^s,zgE~-JirŨݠa5(+ǭn}8,$ {:%jkef`wM" sHy"":AV2ݫ(f,?'e=DC%A T%)yT5ǫ0DC@i0t2o QMb6ILk st{ݳvÂ|JY9W0!d9 f$ 2BHn(d=voXq}b&{~ a5{{2pW -'1vO997ig;|O樚j>fk=jWwzp*BCx!|a$ {<: ``(rHHL& kKjQF| ɋ*+u99YzY.ڴf DʢRͪ9؍ HLٷc%wkIClq_c}<,h#w quVr5hA {@:40%7,5 z_Ϳ@HG$ ~ILׄ"B@7<ޝ6 #M<7t9_]8N'&2ϥS<|NVex,&>h>VB &򠦅Wa"!VumI;]WlM%֙b uw. !$q&-I/I!=  -IV[7W]¶isf-\..Oo9u{ӑ #rCM$7SOgEEL$4CkyU Ϟ-ûοl4%7m"ia:,|{D11`:FO$AU M٩+7]/-B6[+D,@s߱LJ}.؄򢤓e;E>vXlXnSivwwW*HA k7w9Chi=97A~ 6J*wG^/Ӆs+rdUnǺuMt8 l'@t-U&.vMX"B~zds4jPtFEw5ͤ ^fbN D {nqٵ U2Uty+J`VRO@FKzhQ3:p+(5LsjX]B_r~Ps^^PJڟD-VF! Q [p P!jw94) O·H~OSJi-w\}\s=]DXB,)Jd!TDA:j1@TYIGWYyYgdDS=֞mܫuQx=M}Mjǝ }& Aɀ4 IwTnm|=^s9D:+c]r3dƪV$#> (/zÀ@?#k ӐviR| {WC-1 hT uG})^ϊ څzt"B.ȠW84$Ҥ 'URi5nJ0+䃗`!+N >O6|0 (HA"E'_=!@/fₑbnjcJ !$x">UoNc&d ގΫ60e79Yto4aDNL{Uu :]StZw%T ,\Ge:I{?@ B^Z3L)D($*=; Jc'xgz?Ç*(NOFn1iSv!8%σ'xup\Q$Ȏ]:na$7|(΅{œq:XRGÖl9yveKU3[uMm4 Z׺Y:~^]BuqB=?0TUߵ yℌ/ȔX8v4n!gzSsXW&2yv7[Ssq% p5djB ϝSDp- ;Y򞼔6ʕ+y4T՚PJ7 Kŗsrh5r1 [sƃ o,3ѧH@ J*@@tZ'{O[Dwvan..PZ,[ed'_AfW~IUJzP#6_}}' "!d'ӤCpЗ;ȓ?F>&~כ1^/>[maz'Wkcz{SvWITj?s_: {Qe\I!ˊQkjX|AO 2G J1Nj~c[D8_O i~2Dv~P﷎W(^>mrubҾ]YI/`]g bo(sjևAZK)󻾃 S/a cЬDF n9[GqF"'3f]n =0H/ミ,Mq4ڒXe?m0xv@n]#;Tny{փ鶒M;\W]v 5|cV]z>CxȳlpdƢ8HSCӓ]p PiHXߢe[ؾ.ug֋mzO9U_K@m_.Ğ {2% XtzmOuJ:DŽ` %64o}c *'[+ϼ0=.6uX=LId/?O]XRҥ֍Ĩ^lE:@y9JJOV٩F%͗2p|½[Yu0I$'xUOX@h+{y#bbQ`xu82ZeeN=6J̟bhan}Nړ+_µ: $W93D{֔5.]s=q^WOA$m8{৚AڔU=)^% +ym&{VW8IJO&/潄C. ]XgQ'|PoWJI }4oMnbP s@}!n־M1dd>l]Q٦[s_g#4X/.IvH7)j̻U@@I4;̖?U5BESA9lSEd ΤG=vnÇ2n/}kQD'һdgє:W%;(>2t@&gJbY@VS/??%쩂⃦Wڽ~V,;_7jI${ }I!2 mG+p)־ 9YVڠ?9 +L̪ݼe;5{{[>*9hs # d$ڑ98svI~ݓR fRMT$3 M}MIXN6[lQ&+[ dkBJ&rN2hBIf ī$آ] ϶Cۺ쐐2D6,}A S+lOZ" 0ZGl0^bN(\&I'~bS/"vQGxw2Hii`n7d>.}I!)s'cyO*$~6؋8V"I$0L$>Cv]&L&uɻhߗZzǂNpCK+WKvrIPߢD9!_ە}u'2eҪ^Syvd]Iz<YL e} @@BHdaBd vZų0bΚxߖ[Lry?fZ7_HM4•4n<A2-U8%mNp9G6!rB{GޡISN̖5̝U棻%S_Skh] R_aHr2e:F~3JDvՙ?}Ю#wgJIeNңCg`'H!RvGѢd~54MA/sBqh{TaZ{s0VKyZVZ_9>XFY&13Qؘ)íM11|Wū~8xv H_QƗ߮nNP^%Ȩ/sY~ݙż+'T]7BV(?.VETyk ߿ZN- NbÇSdi1NvU[- 0F-^3dL/U8<^Ť(Q #4" ͅEv| ٍʧYD~(k_ߑhL d ( }.`8/`1$8׊'/n>W;w ivEk.tUI8!*~Y"/IKΑNHEl\㏋B|S$m-چtaG7#A,-`]Q+9Ig#@@fE;M]" ɆbvM$B _nC<cȿ <5Zm* pcfy $Ս,H ' dg"-5HiXOH׫xϋݑOa3]\FRѨO`aU+ Ht{[Ĺ-'k ڿ9iEP`3^p6X,]:ɉ+hXɶE։ݮеQg\ιVg_݅D`#I3BA1)A-eub^1.oƬ欔>0cYN/87U+\er=^7ȫSzϪҗCW> '#qJv31%/@B m|јZWcMśB泻$ZoR@)IVA77lTPQ +8aGv-7`YOq`\i:. 0/>]jI ,M$8A\EZ4~Р\Jq? wG0vop;JF*? }njyKMk+q{.ݩ% YL@p.KY[*\d̡Ǚ~ R&( ׼>.g`ؠ̃"Hc&A۴~}&=zdE GbVoUR,;ݍI'-Meq\kdB(Ad"QB!j1Ab*Uֿ孺YQj2IXrIEHH/F=p$kφLP}h8]={5.UU*/xwl^Ur8Gym1" ,)eh ڰ`*I 6z 3-c{uR"Zh)%n 7.5iLy–ج`00V $oRh"U[^K\xD‘TQݻ$` >Au!RO`:H&9Ht,$ߩnTN 7{:=ibh43Rs8?scoYr3HjERnX!TIiqSgx֗cW1fo<gkf{%bWa~i 1 J{e'BUqje-S10)H wlNnm/{ezxhHQy}R@^*Y tf5ʔ-~#/lgu*aeZ9c4+3Owc.UXWiRH>4U*ToO6BY 溄x䀄n!@ R5;,|&3]L?C/u2ʟDZqVw !$g1K2'`ɽH?I$BOP2@!8:ZO9cƼuuּyeuxY)_`:aJrre%qRhhe{SgˬшKqjd*?>-M8w'cA3/)@ d e2Cs4j?M"=B~ $ )??.o~SJ?wuc 9N9|P!#@X[T!+e d#SAPAmT+.p$jz2"}]&%p'5. rO"mI!$)z ?E}Ac&xg5>že9_EWdR"ꨆ[O{6b> O2{M 4kjS.*K?I_'}~f4,F2e1wZ|MH~ ٦cSI!Կ\JI V8pyD  RH}+T>A(!v4HQeV}hoyX5K[ek&˷E4Rk_YY,Rp\@@KxDe zdjΎƋ*2*XwB:hqyR'Vl;8NU')$h$QD_D&'la=%pI%M'BL *KE 2w,{i+!kD*\,/xg`:Z@v .E7*}s+Y@r;ԹrD "{JNZ߽U&MRâZ8h|-m-̆d(@"H MeXx Fg3J (,}ߑ,Ʉ| .C ᑒxx҈4bt(Quf 8<s+ =E%}Zƍ" Akn T4wXS+g ٳzVؒ4KHht"EjX,8pYQa@Mq5\}r(*W~XD$Y{7.k0$3HsVN:ʨ]6gCT9R#}=`W m3w=n[M% %ć^ 6w2sQa]sYw ˫u65ݤ$WHP2#.*_WW>GuВ7t1{<|m:cdGw₩s$ϑ ȁ#~O"0̙.f-}l" ƉZs*X oSH ;.sO0'B)oxǿOs h<mp"?u\7|<+G_F,+2>m+y^.^Ρwk3by/\3":{2fⷭ~)1]86;5geTؒR8;P'z\8Kr\]fvu~2fv,%u5tMS2I1_Ist8SFK {IgqoŞSs1I(`<*P9K?$ #Ww熧͎erMuz7>8ĥh7MKmSsjy1;N; m{oav D(c%# ybnU`+]&E:p2 Oq+Wj:yMXV5 _!o.AGP~Є>~N.[@E&%#poÕ!8sI{j#Pou;annZ;$64 ):٬2G4'']}TUvul:48Q 8z^[:gU}K\Y6m"W#yٕ6v-WOec~Hnt3p]4yuUhܥ2q-8CɃ J%Ƃl`?8N`\SW=/l+A##MG$X$ ujB/ȳ+%&öa3Wl.Ea,#4yf#H -Ic i˱{̸!^4XHw ׍mVS0ru09C~ jzV/@D_:Pg[y+k!B@:|rຆ>>:kl*g{-ʁxLi/$GI!7@@G}#~W j_7{ڠybթۀ/0kl>Ax+PCI @l~7ӣViuNEi:_XbO#"W 'hPWȧxЗ2/4.OQ^821f馽>ˊ,~^{_oQ8u`R7V@Ҳ?6{q!t =!&^Ȫ+Oo aL ߂!~;%2C RL g' b,UV¶ߒ8LO=cZkTE! UoT %rIS+7W[R^̔)<\ X!"8ڟЁoalO-QCl1iktsׂsZ04u=Mϫ󛏓o6CQT9=+ݾK܄'wP: {}F@ާBJHC$jJFnǿT;Wnw _M[5 ۠sRq9I$?DwRs t1U|oZ>V-oIvo[K}n$p '`+ܚ `hHIH<'\(>9kw++ey>6NcGG@1g0nzT`D%`AwuޟG2 RB18 ĝn`q6rԞ9vv#I2w;RH\P(g/eM׬ Sj`tQWͣ i$K@!%HC~X"" _(n8uМ[Y&9 ]cz.^ܚxy $.P4 b_uBa!Wa?wl`L)a/v>O#f i햳M TaøҲF z>[U i(}JU"$fh~"R ݙ6W1NA"%a3|Colc`ׅONd~Mq/LNQCZ^a33Ks8ǔ{&T鋌#u h@)ĕ"d?/΃v"MePbyݮ(*R|9D3ġџ aձ9/֫Vz R܂ CcVP@"|2BoCG@LFFAH!xJ(t+VIܱK)eLKXSLU;XN[{b|Sf@..giUke0@!+I BRSyվmCDyA`: q8$'1wPXCA t?-fs(x:̋[-57#73981  N2%r*/=n >Vؾ&^?G&UUn +wFRRR#&(t)q<$FzYk=K3"۞e p4ʣsyv4m.!`^(]^*\je qPiVV}u9W,%ñ,OpY<5N EV$5X3c~j9Fma/ҴX,HV/-۲my"`(tUv6@'cAXWiw9. Q~l@u rX. Rf;-$2JT݆tBn2zj<] ,Pz殗VS]:@'0f*C"pz֖D"ٙ^1K !J* HyA|(]B*b ]HO9׮YYt7VU|8{I 6 6>%iVZ/.+ u 6k;lbݦ ,3H\~nϼf踏<{hq#p~7/D;[yNCVu3/.z٩ö/6˱jgvL+=-o̱!tђۼ"ةw jr|u yNV_]gN bJxw*LMwpK49ݧ'YAt7о_ΕV;{UveͧB )oj#C4eO*^C|DC>X𶖍loSFp#ΡUK#3:NA(,Iqvwsf-wyP ljv/~7pNVӐY HD˲N$&P ߭SfR|aUHdT0h[*T h߱6vrRW~eB}$$WOuo*]USظn/UWòbg> R&!:ꐯ-䖴rOGE3(z}&c`1#jI'b_)#U,{߹WF܁[$fzcB };yA׻%eUs9 \TpKA_qaP48}VmlLbfB{OoHgOāz$b){R2h o~@z?#۷u!&!|绩ou HMJX|o; )ocZw!zb 䀄#(}M>~Wͷa>F t`5 崙&Fr?*۵&~/i/C.GlCZT0j!HFϤ6L>T!l7ll]3\Wn8aDž05m{oRAehZS\UUiFQq~u2|ONq]׾T v 38}hszWZǪ+]ʙ91OC$u~GX=K$?v!8O99>"ocg<|1pII1H5ЂfЄ D8g 1.ȱЫYʍ܆S (WG$@ L3`y qm+QP3;bʭ_g+}LV""H&6sB\1,uu`z?#~BjuKFyRIs$,w2o#ӷݮ~ʶ&{OQ$!FЄCqGy,Q/ROwy=w%P&8eYBvU7(!Dp婍])mw_wܡ/FNY4cPxd* @ NB) 1YV3jx >vQ;љ1wPW$+Md]!,=xL-W]V7`V{>'7iAJot@> Y7;z[@GX|풮)8kY?ojL{[kGGj3sXT=G?$:AZff+>G|b*mmmQ:o/O<$kU:oJ \$t/T$6^92ÅSRPD`%ҵx߁qt9Z8\NE\tҖлVEZҗO"-/f1H$ ]¶f)O&=7V^ِY<>",@72,@Tp_~,]KxX"ժ/9RNKibŢ3nCW77chn*^9bQU,o$~tw;yf a-@W2[,45b0p(H *5++.\xAV#[Pm/Pΰhe+g,^,T_]vg2s&_֓i k@1 + H"ŊA`&yyQ7_~W zx߮k!a6 M"ul%]uEt38pϼHG+nSuӰBnEzlI %EfsX2x@_"]VI25V $UÿhYS{c&u( .W&UITVB.U8巋67[8Ģ,QX DQE5~!m;G:,pQ#-8фr^6w:7^{\yF⹹KW%[HHH`mx6dYłA"E*  DH#o.[ U[ԞpmU$#d@ h:+zceh ֭'ۿNqqٺBaTfV)&EEp")OuO|l)L3Oi1zOF}d*# B(83<`0a YDc1DEEWOשTigXfhr;w;u4Ē\@HH,`)%}m[nnCw,3uL!J EHAdPTmyFN`| <͚+xoMPj`c50% !\T8BI+Ӛ nϛ;Z*,!S֯Ų=i&7Vj^ $5Ga^!|0!G%= jȭO Ү *,]s;bJI U2P3/=C i*u\]SoƧEW^sS$)C ģy n|n_+~TQCrWnΚ'&۵!2)nNe_.>ǩ|+KCtJ:]pNo=JS=h1s5#?C=j?/^2w\sgĻn@\QeĪNB돭H.Z!WI/UGwu+XB`xp,jkw rTḩ*Sy'h0T :|8$r!ev_l&-|&6͢ 2#9 !DV!ϡsrƗc4thl8Mk!+i#TߢC[+jm(з׭s_. s6o&.Q.=w䪹p9np[}_ŕY2_IO9\#BχHs΀Gϙ2[yHKRmE^4RC@@mVВBd-M]yCz94ju9,Leb J2c gO/&:dتHe%&[? "ʷ3]JE{rnϐZP> c3A  H,C.X%FYȨ89cxC0 V:D(h4VMQI,&XBpId6 DD ,f7KKmY/_Ӆ 0 $]3Bided;t.U3S:FOc࿙BHPϼRZşq(*#7nuk5oÉ5-E ,DTE3EsT95SysdaޛGT7/!RD!LWʱz$n,( tٻJ|ڼYV3Q73b;`)rfW*gBxѢǩ\B'%HPJ(DF_ *Ozkj+' ڮhLV֪Y[ab\fK\\\LXHkCEuJ"0lR )?:͡ y M qL:;]@:Krwqs`ydn1BPǚh<[LOY3`g^m8 x"i-BOqĹcYV(s%腱ReF؅øqZ8ijw_ĆvN-۞S4$JxYwWA.]]EYLHKDkl[ gUU$7K%[ĈXyL,wZxBԪn9 XN/Zб=n {UnV iZdnŗZi|;\ 2G5ډO@b!`L6W#n.~WM~UM" [}w$x !C­h̠o8as¢%L 'edղV|I]琘 H)d80$IyU4<qގ'h'c@# ޜ-4ὑ:Jvs-NB5|qo~ھI.v6~'\MM/)M븮5s[ǤiJx撎>=d7ld|TJݒy$>!M*kԿyH:Xnt kD.>)(>RVsk.̿S~l'UG['i>z[J 5[N^yܪ%Q1d紨:6!; @@S[Z* AojJAPLy[dz|?e 6q; }ٝIJ2a-V&NhEV 'm{MP< W=ƅwi [dxS*u\}[`rOl;m*% 2Aۄ0'a?|yؓyTs怒V`jr[k"LP|mפ\&* ̥*JGdZ*߱uHD|LDyD`MO"Z9Ne#kHCA~ڨ2"~pBd5Z6&ċW:B_+RXy}nKkᒼonoUfNlBMgض# #S77OrJ_{9J鰀KKiW021m=|}G3y=K?2 oV@oܤ`=&bS8k@ u(+{b%$2" >? @tH'Yh;zg7D]PgA$Lqn@!$ j$JJ?SLa,LQVG '0dI@`j' ʠm> T@np3@0Yό͉n^ UR\ub-eZԅ/n_qc\q<9ЊIfBbA) |WU"L3bzi]6p]7@ yIAiYKuWwYH  T/!PJ`775GU$R!OYxDk&['7LCM?HL &{U)1%]% βWIPi2oqgb(*0pk!?j\MںU/m"1ICdF('7hOF#?Mypa3^Fn?joδvט}7Ct\^ Rmt ($jLbF8݃(u"5.^3#rB<I!!ݸ2%%U9.LA0A q)`\T7pf7rUѢFoLhzoopsaÉ܊MQExx[k9֞ 9][ qB'(e@#yVk*:TyۅkhN|uJwT 1T!ѡDGRkw'e"{cyU ަ\s33KsEYK <E=64PGP0H$34=w\KԀ=A(}<4Y!~f#G ?D.UڶWI )xV2bwzTߥ6]/ϒu#wm;DMndaH\(Ǖ(H` CbZ_xY*Ed{f4 åd9.dKavE@j/ą$OHVQں-cz:U.m9xqbٻ,QI'hK 9޵]G@4_ -JUMv[rjvW2N0C'qQy3 ^OLq.&7[+bi$߅DOv/̢݄ni.sqv^A:x膱|l̗) LW`z@ }{OvC55S"iÊޗ~5HށGO5FMJ-`i,? #sd|s *^U]&%[bI[#!;3_d0OpkP G(@7h$ K]=e-_>c RG'rh)DDDU= @ec6w[07:'Kűc 4tՀ_`8!i+%77snًf`YGV$"_6#H]tt[>5hQ3w?] :n2޶_oBrZZ_&vQFgUAUUEF?sʷuz5x^קγ a"QeN?wM[ /:$ Yf[ WK8i@ݻ=M/=VȷwJ!C#]#RT/e:zAD1!+-mEowE[B`bTt!D_s~+ukDR#]^wO<ɜ&NUHH<+p`xΩϴXAAW0AG7Ƒ"B}a.0C3C%?*(q `났8JUJI>Ӵ]H41֕4*%eSB>LI X0='fuo{D<^d/٦1b2w wyS'cdz lɏ:e^H3t jI|7$RVNc&IRw]dP|g7 yliC [d_U#&%hWΪ_(v=ͻqnZb EʕK\k^iZ~ul8m}^yU.#>ᣪ{*\R55>r[`2G|k+᠇yoOU}?Ӻބl̟8<mĬ689j5w_ ݩ=š'qM=|{5 rV -CikdW_.Ri#2(l-~gy6d,ըk2=y nY\̠~8Eӛ2-gΝIՃ+ W~roz96Q^K~ϕѢ_&bPpR[{^G#4/hE#`l;)(8jE[{]Is]'ޭᮩg -526w˷|?'$PQN'9 iH2c#d?{!]Ye0 Q ƚ ]Nojׁ@~y/ΡT09Ezjl9":zDFsr!qeT$~|>oH YS-T(UVԨ?Aƭ D۹kZ8R":|fZ@,dߑ^RI8Y]u@Ht+VV<Ā-옣cZ|]w.g/eV  "( KsbyIvV=Y*Ed# 6Em)r UhCt) nGlޚ/&T#VO>"\!Q^y۰l $E}%9}}KЎɎ{6|ZjAjdf#qeEԆ+ 3Rn\bO?aEA"Ⱥs-8:3$4@ӽȸMQp3d8ۉ&P._Jrq DӁAr)-Jov@i{>G<u1w>U?> UnbQx$)ʥ$uOV6h3A$e[4Z+a Dhֿ<`ZOkWB?Gչ} ]A /b;A)ԤR:Q1YiR2̔EˍVmcL#yi_ ^?xGWT$sXRCTc _&s ŷ2~$0zBvC2sy$n330լ[ڴ殟I_lJ)G)gC;3H~A!<:@KJ  S NAǛǫ,-,.io!/έdZse-%JXEew#{ %Q: {e2@?$''GXSsr *9*,6?tEϡ%bpE]oYz6KQQ H-., /oUlѧyT׾Lb,X "1/7| WC&Ԝ"rAB'"rAP;ԫB>Oq9I;io~}^>[{yvH ־AM?kB sN;0?G+~ZH( $@#^ 0-Go6{ OM)^;4a܀Ku/f4B#k%e ӦKw=e&tlC V7Yd$"e(l V"n,B p`VbB.A2@'2L3yoډ. ǹ8v>xcéGaKJ3XZwqK!_M#rHWMP_J8)l#!㋧TΡTAv '(76ݟ,75Y`dYT IBI,7D†Εwl.@͈)"UoԿFεa_jaښsr=Ke.pX` Ȋ+DXQb+?j}OwG\NL>-R BGڀ:0Yk;fFE d)N@vX b$",ER(`d6o.;,ZsFMuM'vs*?FAI "'LPuuڋ9N :UVqIY/!14(#䂑Hʙn,#nvxmm |U  :SnKa!1iҺ$v땂gj0Q(-fUfJįG,}iT`|kFHՃE$oаNH{h' I J *&UvcsQ(j㘜+?dM~M ::l1ꔑ#WϬvMnܟasWI\z{Ua8qY{BDWV D]I@$pB,îFC;RiN=`P@֥'W\~=w/xNOګd"'7li 7U:mn-E)S.ꖢ,G^"+vGYVvϛ:oǃO'MRvD.zyƊ9rD_IG.PQ\+^iWl}ݣ$+L_i._CCT4rG% "Ul+;+ZД&-2?yOv]9TU ɸB_^|yyi8}as#k VUycd_oVZETPDZ5Vud.]9?uW<{?4 dRBl3a '-xaDY|n#܀PDւ:jd%H)Ӂ.P˃0`c IU%xwښE8n:Ȗ#Jl_7!ߨb(BsA|SG餎v'n* tXT.p[623 tG C?olYYz! (Ϩ㕷 yQHQ,U_2.oq3kd ng1ws4]B8'tw$d" j}#<5agJd>n30o1ʚv& T"|̥oi?MkVI2GsLZ#|sп_#>T]l? jemPI"fթ>VLECeMmV OQ4`Y,{!RnL14r j$\DHRHm/ۃPS=D;Th{_퉹[;C(=9>nNYK7(Ԥ~׾Qsِ/\XBmPB ^sG;ِMDCU@$$胦l;&[ᤑtM]TzK4_Y<]n;S  F0)`CLޒȐ+"ZѲ o{)ɘzaKxaupXDdH"eʔP>գG3wBtѠ(GzW.U̶ž/w>ʪθ?֗DQH"*"T$D$PYQq'y.̞w6r;݁6` @Be6IKq8(%OYx9tBLe4t~$)7WV59!j2ݸ@AӾHiv<״, 1SinUYRCI=R~'!u9A`A:t28|_FHgK Q;}IF\`I*HINSQ3(LTBNGɆ\[yXW(|ɇ/k5cU@XI?sv/bS4mxOc+S%RL ap`XQ']wL !/(dBelo ]4_rw=h'RP Ml w=(r{e ^}"_jh@~׏Ěd+iXAAgY mwsƌ a', U {]e~+ͦ7,sRbC;bzV~3 *'|iIS?6p,s!o8KƸ[K1ranK9WZp3@x%` *2) RW'$]9֞!*dhNgPHPuIϴJ֬\`p 0ZW#kjF J+BÇbwZppUlNmR# ; I .v4 w:FZVTM*A1ZŔH4X0Dm {p&.#"n+9&Z$TIKT5oqC_:;˃d=Ǝb1Xc.Wu5hmHROS.I_> ƄzI=8X=cL'2[vcsz.vK-%~%DQw+vJLOֱ2b$eI}ҟY1DR';Ep2!F5p )$N`^Pn)lDswؘAUXDzqfM`Sp5Eu"q>unO?a&LF֤b/m->n3gpRF@ BXJ$ ۱P*'8lQ Siݚ4jչg4A DuU-1VbtBS Ia^$šF-q Y9OeFep1" zq!}cbl؏C] jDd!ۗf(yl5oܶ*hV&m´{Dfv-5\6u<Q FTƀ@kgҷ#]ΞAã-M:11s.w0de؋W@51};am);δUuH( wszwhn۷e08fDD%Ao-s騁%g `BbYDggOsmTޱ+KҜa 5#>)$E^$`Q屢ra۬EDG=9dm`rky7 nsj9I-i5R !j $̞vGyH,ldIEߜA,ZA1#!ZSpj}BVSe8Ir}<A9Gd s"\@;u1R݆t){J5GlaF˹ :UyZ'8]#%q20g ʫoL$`zaO:Ñ41XVt q5N/-%QΡˎ%r +]W,B!JzL뢴eAU5ݷQ[q~wO뤎Nul^8 _ Erfj {~YQFPꎸc 3#Ȳt,1mS-̪uLL#Xkk}Jk8;#zuNRBu#s+@e״=q ڕOmm*-9u?n?̞89]E,q(wvwbΝ]ax uXف#\$?c)r҃zEȋFpOs>T'1ı pG{Qڷpt&/cECBTuI?@=]B=%{_9S{ 1omѡ>u{?#>OOncLz)AU?e=BHm |x+ x4[CnC'O}IEAxV˅wwF?|d;P&T*kn pɘzK*nFQWЯ @t˒۸R܄0 }WXbao^5o3yoG. I\[<Z># Ϧ5.^7V-`tuM4)=J5SvsocO5; ϩ~ \~kT̥;j)izL3S-ENxֻQ RuL< /`@(~ ِwR4"Щ2BLVCo7x5qb%-UH"-Ꮑ_xPLbveίQ4t/6ᤇ)fUesJy-!l*W+iKd") ӆ _zhF_Thڭ=)41I>bm͊.]W"x5rkoGxDRBAY[3gL*V$)S8Q4T0ud9=Uė׺s_~ Hq][qCDIvU $% E PYN5i0`MJϬLy_1aOF5۷_zV}f"U 6]+@>$N9G?&I}_q}&Ea!>LV#ENѥ?ЙU<(-_!{Ǐ:]{*-G_J4T _a.?Cvq"fdY&j%~P(@: =d@Wfoa˨㨖m xyx %kcrJ;t\8f08Ѥ7Mmg/~k؎o.wy_(<>sC^2/_w{BUrF0bK+Fu.?KhMeVܱ OJk?l"0x4Gkݏ\4\c]Fpu Q.1y8:T8mCkzO pLn{(zD W~mx%f~}PD9+NUI ārɳ^z #{*~L Z0h<)(*БB8^C%!fpg_S?G/dysL)(JHrHBpHZ"F%5wr3.xU|;9ڰ">,WW^qzN!ǃ6A$)1A;ΌPp zŎ~+9p}q˔j?bOuu&JT!m7Pxv]t-^3wO|NtRI 7 kxb^{(h o}udJ 9[uG>773Z,2&f>/ǔXP7 d@kvǓ܂ER:UNnOε 9ԙ5Yvm^k3Mw?j8aJM6GNS{x;Ӎ_gò+gn;A.x0odQ ]< N|SI(AѝFI0 (ɓʥ@C F)7=Zݎ,=0b&Lx?YQe៩Sכ$DH H M8Ԅ=jn Âar:9fx:x8Opos@PBrb&P[ER,KH ",U^*M^. fmQdЫ35;K߸֘(,o4gA=9PE1Lg_'aσ7 xx"J֍S&\eY 7)XBB&u[wnGq䏗Vo[" (%TV (e`Tb6*JMK @H(+ "2j*i~F Fhs<ZG~|;AT`b{O;OalZ I@Ak (sJM0:Jmߌm8 J1W?F kJb!Vw8 y$ ,^I}TuCh*TcCT&V~ ~!F2,QAAaPQ;,_qlL A>M #1'{Ca˸&0 D<ݦfq+{zoWyK?b}^ n7 bXb 8+q݆ 5xڴ}j&/\PQ2fa}$g;:ij$c"dY Vg2_eedwH@FY"Xn.->Hg^Ÿ; <S@+a[VGa{%ة5̆㻧@I Q7eLJ Pl^L*R_lUcnu:u9eUNAe~ 2٩~TBnùIQ ZW/iZf&(rM=㛡0 v_Hx*ةnяJ7NiQnfI%Bti[R̦* ebAs".Z'Ρ T* EbSZ&g)}t ю\VxhjQUذx u;%;goqt9O[ΈA&Д i6ou <nP!cEcps xە_=vyD@uOPt{[v,ɢ"߼h2o VH2BEn/0)PP_ \M-^JRVռ[ZX^9aLy*E6 \PMxuZ6V_*6gird1͑]#QCLDJdTu--Kr5߹˅sZ4^P*muLZ5-px'@u]r%T`P6n.hZ<8d܋ێs~x,.5zy:H>͕dZmu B) p4]+fT/]5/nJe&cUn[ VUށpf0:[P_Kfߺs99UT#fCX3{P'R*.~wթ +xӥ:%Z<Rdab *lҵ]M?QU2w_~R /0\r&+V!n8g9UjBt$ӤG(u*jk׹C%|%{ӈNO1ЕectgLvFR$^Q*U$MV[ݼ,oe' {FpEpf{2dhYMSQe6 kHSij%*!;XLR&e.RBP*B1 >?BgF-N QEт)wlnϩV(zÛ;5wa2S*ekLv0Qfix "o R1>ȻqU&Z䃐+0R͛[tkDu}/ߓOG[ԓʩ2ܚhQ*9PJHGt,5j@lpXw\ڠS`kqJr5*Ȁ_p<^c .6qu} m%V۶wkZa!a( 2޳ hlHW M7GrL_e6,w y+aMIIV)+뵡t*{g.Kr/[wU_w MP2 !y'dXORHG`T'w7)?0r ڱr&!iUEGh [[Q }`)" Cq8&{F;y{+Y.%t@rA"GOl?+f~Q(c"Fh/Z{/I W3肸bux27 ^IZ{IsVŌ'"Z9ʔ/,qP$^8OktBn ǹjG!R8|R8HGan 7 eZVn COҠsf=]B(¸trpvy5_}^fC*Yp~ۨc@꧚{2*$I E]%#tSL?CD>TZ4"Ȱ"׈Gsҁ?Tza}B;OY~2Z? NpscZ}awdM{>뿿n==alcP4u?J '`=u F4N"1[> d=/ ]I׎&{R:HWWEcSJ鿭u1wˣ"SjKB7^=ffR$%ھMZ.;Jn.q+:X(ͩM߭]/[mNaGj#z0"ޡS jR "$haxlEmBy Q ENDlmvJhxM_^ϴyv)'IJs^3˿O xXDHȚ \_̭Ԕ;QYDלoհ$˃ _ $z!T${L")O77}̨;,Ü9F2ŌpۨpˡmP}z?zF3bѧ_Z#wfU@ō4 LX@o"w$I8jY(&^S)a%ڜ1 N}9ߕrǙaѻ$g >SU\jw[xK"VS>?q=r;^Z=h k긍;S#rPg9 <ϥ R c˸ Ud'c<:kU,P{qX0 LRG}/}cu_Ʊ? jS߉Z H1rh% oӵxЬko-EbBW;[ַuPگ֏i?lH# !h$-oLk'%_]]wTL2eۏ8>fFf.ucT Dݧ]ѿk@CC䂡V?ED}hud'N"FL3Pq/oX1%! t>b U??IƀEMMX"0^xG7H@E3ѼVEfdh'pe\: /&+C}n\̜: 2$ @1PڋCr# =!ov ,YƎOk ֫~v#K(FuKH./s߮ws˿3r7@òbjSseA7\ I޹?K^ '`Zrȃ&]M+buw+\rQ@Ω3wŲB?'Y'6Ve^U0u;y wyhe7xI+2]jx"φk!J{O$:9Ty6T1/ϊLvez}jmc%R s_ ̈́7wBՖSUcH٫?-֌(1_g)cqf̾Tqf¥13)L]_n &7qske;;JoQۨtBHP }'O~ZOb=%g&!l-뚎?w/?X0gc#[L(*VP.rպ>20*ZSI4om]Jc+^glvWSv6t _%$P2Ժ h$RB-\?wjw, c/&ah˂@õ޷ Øxdt:wObmQܤodh;Wl*j}m7](#*Aoo Em ~h~o[.oUn#b'zG0D@boZ/)l< ?s~x_\t@XE$X UWl;y% SdmnC30 !暇HU,Y(=G[ŷ?YhIJ旿oޞg(%ׂ;x5>-Or/,6$XSLfU~N04=]wXA|H >\)+*6 Y(tsk$F+$@$CVdP;_@pfrFPhB̡]<xi}XS T OA `@DQBEc$Q`#(*EXH$Y(`H )oC~_}̵R^.X7b}+ӻyP.Qq#miDRSS]é}7lYD7.SPYkJVa:Iˆ]{ v^Wmu/O#vTZfj;-玖.7狘*W$S_ŝE{5;_&VlGPnKwEy[Ʌ$<!@Ik-0x=2GLW Qpbɟr- @7ҚDgQ w-' L~;+9Ke{5Lxê-&rl㊰D,L:P2IO%FhGaS=Z`,4Dn"ubj^mI,ĒUvDj y^ؖ:6/EώA||wBC5 8]N_`Gyv ,ĺ߹8M <=,/)|EiB~/ld,uzwG*I|Mȕ]ުˁ@upBQ>]A1O&䊯xk},T!rsp?wy][J>wQTo>=@>:Ek?n mi]k6/cסbH- sؐ)yC`섁F BG.hT^QhPj'PD`,EY^ΝAĝuu/JjF0@f2恿p51f7^Cu]9H_u("tv<g^ lomb^`]"nreȂN"97 dWDߛ|?@XҿK٫<+%_Te/ٻӼ8Fk_y%%&ZGZ~SNhy4ȵ/WrU$-~ v68MB{]W=Z<:ށ|mjgH.ʟ4Zy>cqX?ޤeHݎ=w"jVV3}Dec?Wly}:8ʁeWk2F-?zg չO#Gof"``kZM'?"QF; b^ݭiCud=Pr0!bM@%^Ƀ6X=" cllÒ9 cTF"$?+_h]O>(zo^b;; Yo@oFm3]T_u@ $LtpIO rԣ[gt8R@,ĀWx",mF ة# oq=rvwۨKusfɣfDHY3h%D#I36HfB"cUiJ.ҪdrIM<-iaHMB⅚q"Y-S] n'=D061$ {?# O -1sכ B?#u)T÷%Wk-Z-'e?v pc'5'cge:9 K~&>˹ٷmW\GNE~jOI"ʥ';Zʼnw;^c7}{e݉$"~ê>تJ|2H% {Vv}CsA!;Wv*]ѵ%GݘGHiokjy.bXSDfSKgz C W[]*k'> {NB7@5,Kt|^ՏSOOo򖄒7=O(7HGա#K\J3H&" y4#y\%!$);>I߰Cpͫ_G?sf6~6^|o%GlGt>e"uO /0gQgil줈[2Gcs49LK0api{֟K+뿓hEC8,/L@(ǔs _Xt5 EAUZW%oUBoz,o&3cHq &^)&Q#ߕvV='nGiI\'VywZ h$J}|Š>(Te9(jo|M0#XÕi0R*h.f,sTG,JIjvrU(衝OFRV(x![.@ TUm2@gH#PFpBy5J;VuK<_n=ŪNH'7i@!#I"! 2 yޫҖO<_r~/_ԧSL~'ŒN :^md{Kl=B@oDRFHD?%>ΪbavS@ʼn39"0r=q [9TIZuqLvٳi hZ{۪4C르M'uNKWևs~T;fW]b9Ge' "!pF(dɕںteomBN,/S*2澴֭'.m,H0C.`"ZcaQU}uQ\HR-!W-#q|/oWX+4bA y M#{O٩Es}L@bY|~GP [d=33}eY ]n{uvǟ2)YJ:o:WOCD/̼,1;lEq C}ᑠB^i`bro,auQ|gZҤ5ad^U5f%^}RqiAF3Ҩl&bTO!#m heżD. ?&1&5|j\6^@\rn`TmBBcˣe|DH|B$r$pæQޯ/%wlBaoɅ˧t@#u %E6^hp0$[*Q6H¢f l!3}o '^H"ă:~:.qv I;s 8[%٩#TUT\qujhxy&6buOFDۗ-I$7ɭO$֣=u< VW;nG~ 1'~~;3~C#p$uz[ʆΐ@ C] 0"_WzWKvok(œ8DyYK%5B7F58ֶo},PPvپܧ57΍〬XOj[ 7_, ݢwvZ-(8wïVTeWZ7̼C;׹VD*dI=CDH)uyDX?&!u@!ŪZ0butxC!|a-RY?1F0?~+yJ K`-+r2m:jWv}0w6'lUƯĦ3,|ċ&.\{XYR",z_yۑ#L/, a"uTdã[G:*7zaNn$%peۉ.|w`a* DqV`Ȥ۽0i%mSxoow:;9 U}M8ciR{բ;N9dncז!-]zXMX'KK*L&vuʻ-&7R!uI ]*tS Xҩw١a'7-pq/1TS!}+//Wp_GkR7àݧ83^aOôR+q!ywa%tG]KF~CZ'`X˗ ָ&O@H%E7-6dw$,fV.42v6fq6hWBT g&y$I!]G?Z+ktc "-:⺓)δ_FL[:FWSHrJG3dC3E2;zNٱxZ>ÿ$ ȁfcvX;=[ۄ5eNfF '5pS\H pJK=}~kUC {/rL5IV/@P%s&'RI ) !9d!P?I$ I whN B`IΕ!@,8DUɲ&m9f7?wݑJ@.s%7^u r@|ggv|A3jb?s^B?)%(,Ś]3ʳ-$\[*Q&4vGmutItK#@T+qz %#sM޷NW3!l أ̙wjѪ#C ǂMVp!I)瞪>V]\ά"D5}Ap,mG~2,ֿo??mgb)`ڡlԒG!v@,o-Onr1պZQ f0^g38mVz+эda n7lvr l$FR 0Etj0 af>M׺]”?21?\]gœ&OG|v<>mɗYDs"I9>7o8Ʌ&vd_8 }u-b B,Z }o%_}%Zy/ȼLg,UY~qlw/@"BHDuQ=ף ϬYg_73?("졻/L ewk,Bk4 VG-x!zgA[ݣ+ݻ枥q 5 ا5A)%vJF+sX8jui0ːNY2"2|M.в?C_N1몧`F]dl79-kȶ Hg7i{vpET&l9޶^Z whDEIɧs5-! K;M"idi[ꟗ?i+V(xBCg|k^{dKm?pԤ'#PRW~7YRνcr$PӰU+̯P2|ۧL&i b;|ў[7Ǒ\WGݤrľ РA=[$ɏLizH< ElO\H$z.v$sikuRAG;KRz|],F?x;fW%1iB#V"]=  DHE~g^ִ2r sڐ:¶= `t6xwR1UE\SUϙn|NQerM~ǃZ'mUz3,|cv,0&ORh23$W#3 .RP.xܽ{_GfKn6/̸OPpAQ'Au *m<ߚ#ˊ"O xTq/uϜP&ʹ3)#1fܒ}у H"2'I ȁ){eL3[-M.Z7I4܃q"y2#"62zw/f3rhuK*37߲@dA"Acj_˛0w \UurmvQVVD @@Kd5AcGٺh1hg<6E-Q96)Qq:ѧ{n1w4wPAe?/FZ$G(X[?Е G٣C7;aMF>yWLg`F$/# >#7__tO M [>v0L@9[Sx*˱dM!K5+N`)kEUC31E!~X ¶C9_7AgH(eЇ H .1.={%med6P— Re0miHabdEyoJխ+A;s^!fKlւ' _bꖇsR#mq Yz,ÃB=;+Y`xL@GsXm' HMQnwo]3 ~ħ7y*/]0h1,8+bG>wdǨ=+%0{VRfXé电{KWrUn9k&΅şԳD0ZH"D58_qB``4%vgc7)o@+y}mUttT{cX+X6yIrc}{&s %T?+h w2ŻOa6wzd5 Acͱf~En<$;y+_CL"+m^^|Cy~O r#=JYgxZVULz8c*Զ@=k̷jd9M#\hf hsѕ2W7v4_#rLbdO+dV%9c%)0Q:(CV W as}!4 K%RAӼUX͌0_Mb3_eEtIgȭ ̀'%dWBzl#r='!b8g.[8Tx^J3n(UTd5C <z O,/>Pq~ni] 1ZجȣM8,^[%p(6BGh8L }נwS)4i  Tt(8$1j{jI5׌4iUYOwާgv}}aDAw}x%ݯh^_n ǵѱBLAĹ;s7F?A H.$PĖY^(%UIeA\,T-(M`hkLEh2YDɹpq0eFPs;í]ҘhW5Ϲi= TERUE3,eK1.Z !a:gLR)-X/v2Fā֐$Z3Cpb$# :f**?/;LQ @ fOGAzϝ?羆|nILM 6CC [K冪I?Wؖ`wgWbWnX{zsȩkj\v5KWm UaJ%4)zNٗ`\wI !IXp EuOIV!)qWޕPPFVlt2[e)P墤QC_{42NʰRQKJ*Js&MJ]UWiwJO_W}3㶤OFę|`Tm F6+QW)s-C²Ѹʦd*kc} (-b-=9rը(F ]p]S޷Rw~m~_ܬS ZG@lfD @I4'/' )k[`$JHܩ0hiT D K-I|mzOd?OVZnnF'⫁] #+ ud3}ҡMé{7W?cEkÞ}eG]˥Hr\X[sݺtvq`Ib *F15׷ŤmbW^'-CVBI{$~<G\tI־1R~,vor?$%A8x}1"cuw{1R*0/(k*b7xňyl փ) Hsq|·g۵ '\q'ϰOzϱ"A bց!D2S.<]=yU0[]6>qAu%JzsAwN% a WV*?C712?wRs0P-JVUb")QAQ- "U"EmR,+ *Jʕ=#bRc+Ņ*,"݆R TƢT *ATBY*XTEmEK` (QMeŋd[YrrXOI 0uh<8H2r:R+3Jok;˜6h?'jJ ! A@;l]RB"|e!=օV~'z/C"43l؇`k:F՟VL9q~af1]{ ݵ|k9W[_=ڟLV_㰦ʻпc,M9F c %޷:HhmJ+Dލ3a#2 '_}V)!}Rz+j-n؊{K M"3O~ReL?!&X8fҞB j#M7t=kv{rN'AʻmjMBWЂ㯄3URǍl &,yo7O95+>e8z&uҴ.Y~V+!ZZTf}{es?'u5q2k:K#B-g`KU+{ȕ OC+FvJ"'C][(-b,emfB7f:"kgCW:yᅎq(6ڪuIapH`h(^AxEZLo8M4pbɳ7g#w};bz~u%iڭPQuTt|ȝ{Pf SY ZrwqmG3у{~+E3i ,)FLwMeI9y` F!+pZ/b48שPkTTGn[QȷKE} [.hʻ *֍9HNM{z[PYr7+fkK+Bs]]{N{Ի"#){ּoۣag 2ǸgtQ QTSOt5Z'oKV~;Ip4нS$.ѸF22[1J[>Js#j0O[=gҫwDEK3~ 9. <+]o~fEMC$m$C>ړZP@ałZСP|]IL1ҍ*,L8'ebDw r[S]JCi{o ;WkUS*y,J^bc]Ͽn3IKg2=êd.3J>fJ鏓|!QgL dxuT`XUsZ05(XshS,¨z~Q[5I~o07V܎~TFVt"TNsdrvqS7B~,;?!v=:vh 7Ad-NdnAf})=LE)lCy(3 *EuYh]]iʷ Nn'u64څUNѹ6 sôcf0+nbvuij%kQ*f]bNg+QUլχjTQm젃w[&)ƪiJ3 0H I*$rOA3 3̸d?5 vȻVuaƛuӒB,Iܩ0qy'B13dgצ]M;igJ4-x7MEP R2Vu%>A؀yo@CRR-:؍3Ȝ̱>&dj 5⿧4]`#Z! FQ0H:3)&,s9XHg2ˎbAV!p5I$^$pUzRAs/W]qjNԏ c3jieXy^0?es%CdHb .r!A%h^JFW'A.Y}5/@X LۻnӱbK#p_ q&ஔîN.z8H_8+j/^J[bDݮu9ًe]Sg Xj+%TfJ'Em]mˑHs5{2*̏k}i31NܪjNQ_b=)c$ aÔBֶ&HD"`,UAnMIWv6Wډdȋl}~,yW;cMH gڜkϙ>@C(N(7035eLd+NOȎXFJ#$eEha!"2`a8SdԵa$t{JZĊv\܄ P?\E rp\VlINBK0'`1H6^g7G WIe pmrf "B(@A!v+2P\mq{>W0H3 5 ~kqdi>?}O]ʘǭaa}q0au/4"$ 4uzfۑfo.PNohʐm>Ϩwh'QVEPXʆ T/7vt#X$bnFDq:hf2wG@㬖;s[癞:u-H`SVݟB7Dz[\3-'p0.Uڄ/c*CL-Iu@BX;NXb.0ˏ87,qCfЗܻٴփV 0FE;VF_a%:96lʮF(C*d6iIѻ \[)jN %k!Uc0IٲHVǏ(kUVw_,_*`YN,9g]O&>jrq0w C.L&/SyߦV:ED,9(!ݭ׽sxf|ɖʾvG3Z y//v@݁έH&;O17lˤ ǯTBU} *[`%.9$QTVp3#5Z,YyuDoxfI"af5H i"^5okhA>r𿗴XɞET|ІSQ<@]~Wx{@B+HȮBK3QKȫ^t[ V7Sֵl\2D9 ::'tS"OF[o8ZKޅtϷr:|;a!_yؿfnxQ`:MF9=f_FՕ˞o*9o~ kuqXiOQ-n$uzݹm2fl^F&)F}e|wPGnߤaua52]dF%{QXOjP /V" G17t8@*vD D"1N=KUAw"FDhganxk b1U"!9@LCvB(N>B? 2D5omy|v)@yu"{lچ}x{ORݯK˾Wz7oYБALHP [=@}s&ՙI=6͵f Ыf-vﹽxРl@Fv :b@ `:zp ѣe*PPN͠@@4tVعv=3n  5}::(AAXQӣݎv,!8{- ΀;{֔{q']xzu݀m=7ئZe'4䶩@ĕ{j7d[:.ˮu[eO}sMq^QM=DLmowJi]t+<( (i5鵎ֺ4luԂnt.4gMe棭nw0bZ.K,kA۫t2lh)Zk)[)xuA'l4T޻9vþڀ}z֊zwenַɽX:4:>@r(2*.x./z>9vw09@h@ @4vkCF춦v Q eU`=@wQUQES1CK麷=swr/Zpj=׮{PSmzvִ{8m$}wyQһ (|pt`h@P4tP@ϰ`)" hLL&AFCM4ii4 L @4Lb24Ʉ&`0<4Pi    FF̧S O)LjfOSTiѨƦd b4!4P11hi @ Ѡ##&6M14b'3LL$O<0LSldMOz&=OHyS#&aA& &&ITSMLi)?)슛IMLeOP==PH{Tz~Sz~hiOԇ(?TƧꞓM 5$"i 4Ѧ&ɑ2i 4a4O&0F& &#@ h©dijzzMO <=9 4~`@ #>s$dBvwD!cqhl0M@\K0)#Qtk`f(ςci3ƿqeC;s !ڠʍQ&Cƺ"C) Ö<|rtP#$q!,f .6*#gǔ ?*zQ$jp&&͒Z HX@A"$RY"BHE)H,Q`a$RH,X BccA$-wH 9n`SmR(( ZH^*)--@ [.,FEB) ,bŀ5OLcPX)` RHEH*@P) "Ad ,Y$"Y`YF $HƭizDov*/!Rj5˵#$<2ɞ$?1GkD!(UN(&eR2mQfƒEVn:%O5 AXgEg߮yU - Z8RNUqA[Vrl8>㘊T4ôze( P}:""@`!B얈*luOV@%5dzgS4VY qzlCZ$I r4܃iɱ&Fҵ%2Z.]NjyIk2jSE= j?‡[nfvfdqo2n=2&!$k|9?ٮ.s~]#z-xC>L[R#]h Q%Ny^Oj8a<}91S0vgX66Tx^OwE=b{GW\3ͳ{irN jnf\YBKmHkm\8ZouOhUgnm4;(~nاunbX`5bn#uEt7SI^eDf(Tȷ>]FU5wdckgW]2跽v.nGueTuݻ`fwv=%ץ߾ ^4/cl*#۟Q-Di $xG#V:nQ7"E%<'᝚lr!t8?>5s^k|#v2XJq֨Rg߻uܺMܴ:2 —EEWd)h~׏mPY\S8?=>WSyim>| ˭0?v.}Y8Mچ'29(qaٺWvhOfѺW-;>9^\K]=۫'{hX1BUxrnXpl.ot몚}Lv},J+kŋm5Բ)xt>Ϲx> :+Ǔѱlv vKDڝӫ>^͎_OD˳{i?v,^o&oUxMwRR+qD*nN(,ߚS/y/Tuyr_U}jl+^pvzb>ןgBCӑ$TOތ+Kl/I$[a Qjw}(ۅ,۬*=~@v_}~25t56*$wϩu:F\x;TfKCl޲Q үvˤ?5Murh;~C{$ ܨEyUXlI,&&?Ğ/$XM2H?.W_68]]=۰nC::yeg8O.nW┡fd~ Gz(.=S|M<7n5y6Zo ѹ|V2E_φ/wb{]LFk^WMcM7`/9uŷN5-c_KKX<^׷Cj1]m#kLnVe綥曻3ǡy+3{7FKz 隿Q]ziqy?-}g.ȓFgWcMe? /V+ix>UGc]ed9f2:$QFv5L忻tz9@>cɷT= E7)缝^>ʇAZ#/Oc/9v7=n-#3%ƪݝO}Yf 5鞾*_'4r?Ԧ=z08Oo72Ja؍"erfȎҬ"#[I6B~pLDXITfXa4v3VFMxiX8z۫;pAB/ 9_LK7PɕD~ٶ/+Ž5u~,VKMmRI .lݠ\zhF~N#6UGrFP_7R 9ɞՌ9m6{)ԱRb%Z\Qf_5 ֽkٌJD#cf{τscSq1Nߔ-c*$.6VW֬Z4N-+2im?+ym.&^/4y3Z-'!|r<V4rYw`}|!Seuڹ?dӓ_ך)+1|mtyuLVf'j΁}gnETo:֟x|qU6#=|+ƫ9qSA'1txB6+_x&ĢqwZ?G?~Oe_Ȓۛp50}dPVW^+chQnШJWl')(zy6G/術9%tS{\w?8!"oL9^맢{}u(*9~c;sY gk/ ǥpǛdnilɚ3z%SƋ6~|{e~1+t:CF^&a46D=yklGWɟbm0߶&7ٖɟUF^mIZߛOo@ k#SEAM=9Z5VpuTu@|&7}]Ug'x YM)ɕwMǧKKnPK6wjn:AQRn\n XM[=#MF=vt΋f;z<^KmԺ,CAWě/}\{ n紷_Tkn= ƽ Jofxvm{lgz^=L#p[]a;g6vU ϕMo4WuJVQ|CG`x/n딭9x=쉷'r;^8*:1y9W}l* ~ĺMf-uwOn KJhm8m4dn".S3:/-[׿8]"n'Tm V9vd@ B?nco ²1cw>:D]=*jPId5 WЬIoa-VCbNSfJٛn^R_Z7t"hTO0j=h޳EiM͠/6ӵ1v3;l1U=@йr,vqN87 p ĩi3ONjN5Eڕdoy Nbr'xc̦k }򋠮~7mBG\ʢG $l]̔)# cBv1EW!i+R>S/K$?[.бI[1;-U%Yv*РV+E@X/^@ R'p^.}]64pu6%#Kh|"+ZB$Q! !ϻc 2{`V$q_C$qvQ],s;ƏvVe4 cU9qA=w,JhB#u RIi]"@0{WO˗R߁_J\#Ӕl@kbie,pZw04-Ҥ $:g3O%+ƕD[^a` ڡ3A*P7,YȬ@L%m[iz[׳ AE x b?b  xH'cҌw,+y+N߾Η'VGK\ A ҙ x`C*(iG&A^TΒG@M=% bV\ Zu!Xx`jCMgˌwV! W’3Ně(*V@(m(fJ Ba^^AI7#Q ZAhB@%9)H}xlCjtpyyw6ykXn^L߸JKQd7bAy:s"g}>r $0pJv,E:s6;cljP loGh:J޴^5X<_?qb :.-7yq2u{+=,A6Vv;[Ȋ^cƙR9b:I`f iTMZv`In*Yi\,#,xe·X(g?@ zqſa$|hP.UGcT7Be6~FDY@.B-!="J"7SS^f."J`z!TGayfTIL8]A ԡdTzja 0j[!usT%b%$+J&)Xa, ViʫV(ƫtÌ4,6*T)-YGQTDA`akTIP٤&rH(zT6C?GL㣮xY㒏*t/{X<|ZPTC R2hMVsV٥[6&TI@%Q2c:F6-r-b[ö[mXe@Y08!F(0H@Q=??-3^PDP֐@1ca EYHW_+rMg?>OҕthZC9?drYP~r^Ha2ݧˡR riK(DH-;m`ڠUDgk-d qXѬ%6"l p&( ăj#ZJ!"x$ y=~mrЖsbs0{TH)? t}o8C͒Ysu۲%w oMA  "bA0" (""JAbU$E\bM!0.HfQ{xU UEB @00/a<r3!ËRͳ?ũ5\E~cGN;X乁A-e AaMI/uPXn\I.oP'_뭀"'?k 'z;7I +vmlϢrxǏ3 (5&xu[8Π@f_WIW("IJSWk8 ߱d9vB@Y7*F">q5x ] F1S, U S(yĔbB)AN*` {;#P!db.U-E,̂]*qlwqN.t $8+ $' ~?듛=J@YnX4-(I 1U!9U 9 Qb$۶&v˖4P$͐LC $-UYIZ5BrqyloZ=[wկUjSH"[1eoFqtN!h$EOR6cGxfHz[}W[r*,0PڦR1alK]\wԠ/mg0dҶV"/QN;IXX2 1+߆k|aAƙw\;k",gp?T,m{V(q^^}~ABޝ{zu_(Co={-z*EJesh| ә[ Ue_+dШ/hZ~ϗ4/OQ>tvT<~aae+?V~U$"jsO"'IߛEȝ*N7O`VpP),goJ"Y7I}DJ9淚Z/)+,nN%qoWU>c}~5gNGˇLPt4@9r]+ %s ECB|՛<~}'?<~{܊ G)XV$3rley93)@ Y l3&a{as*KHYs]`7D1r$Tp1g ߚ{?>Si qs59гeqNа`$"a~X*"1<Gӆc(dg qx,Ȕ/y7qf6U|Ho\{P+ǐffvcx  }*۹ųU ՔLD2 8D`@! Q1 ɐV]U}64IFY`,îFLԶQiKtD60"A T0]?;{9O]_<魩\5jao)k'e[#D柽Og"LTJ\WP4r+Zc=Gb9z&p1STBbEhEjYu,*USo͊ɲs-u ٵÛpZL%Qn L-d%_w37UO\S)%4_X洒`łbͶG|/rxvWR>J\&^aK0Eev򬴴c F[%fDe 9C=ATY1q㕸bd$) CcikٛmL!&t;+徔JMoOJ}Ofg|9\>by&X*,eȲ(_m[ȌƵ  |pl/L4}ٯ2hp!!b3)# M$H,ʡ[`BXZ.=ንyA:2F2&/<*C7A˩⍂@i:F3OFoaq;l[7͉\g]3. tS9b`-X:c& 2v·j#y^-1\hĩe S.al̾HȪwdD[+4f0lR]:)T {BZӹc !482i+DaXHr(%`j.GiWvćlXqMtTMXxU`a!]\2@ȇvBa٭MA Qd֨ldZZn @D6kz 9N?CT:dVBBJ;|p57I@oqE"@i%PQHtD@/=|~~b()TXPBBi9B+_'H3ԝ'DR7r.z[ Tٙ" 9/ )UG+AVSX2ްg rHwwnF_SȠ@(Jq, +b+#AJZB T*M*H1Pcd((2ai EYFBꂚdi "F(,miZEЂ4$D*Jq1x) bcSҎgBwH1 Y3U ^g>2/[Pi ك_1^L#Yb9@a`KJ@h"Fcs0WSq~EwG;t37hfTJ8]\o377͜u(գ% \*IF&pHL fRN!ee-mEUŷdZT*E[NZA%:}8)issw\`ݴ0m~6g7ll.ak-'(F(aTpJK*H0& B][us"ʼn9W,2_z{Xо`WJEWbTp39,-jTY"H2Ӛ#~Z#tM*PJa #`Ca@%K{DKN+Zܶ", .xJ+- Q?.[]F< 1`W՞lZPhYX(vV,򬹠g6on܋࿳K5!7zNT-qwl0dH \=v:'ɽd+\_Wn/,'X:ueo} jzּP~UWx%قVR)Q=<@,RI@Qi j5D !zx^ D=zoҦT.Bh)`@aQeT݊<41&^V#*!0ʼ6)+kpR8^6 Lufn'Roa V`c~kjR|TT >Twk!`dH͡ÀpU`$6 *C)c@_w.U$(E$D攨#L/-CVAQPkE9QK"!S[:77q*u%0Ѱ! `)n nqA,E1;[i-=X )(Mv9v%s#f)@m\Q[ FI,f*ֹ0`I/} ,E" Y2O;,-]MFeȢMtDPp؈^n `AТAa8-KdlYʢ ݝV,oJ}v6nׅGyfVD͂BONwevxuޕx !{ezɤ{h[P9xg]7d6p@;!9K{gd`Q1\7 Koi̐BfeL61kM]mA3lnB8,9֥&wreE#dxlųKjp6P**(hG[U!DC u,;Mj{}hoN 7kC+7ڟ%+שz*%kxa'ɑaOhaeVD7 g+OG7 E\jc|8c؏HX#yW+UeV"aNEX$P-Uv,R&6tٲիm2`+Z `; L$3"L(f*;:`\68Pܥ'j6mE(ScL[-cF9|RH&_mF^HV%tlNb `Ի,\C8hnߋF/W] fRLk9yKkӝ:a3D,j6MccY{9_ղ\2dln`9sTN)6Y۩xX[zPJ9m2̰\44@=cqC˞@@˃rꞂOJIPMɅp -) ]qTꘑ@nhEtd/@P`/!=-m&d!Az>E#kX"z/2Z CʋNUB-ڶ\+ėp"襓VgY؜@AImˈ.0vX"| a0K`26լFlۺ7ș n19QuWR | BYՂXS\6SL5)"/4P)wQ ݿ&`V*jִ/7aٮ*dA(RFF 4! DW3FCW# /*#1TSJȃC$<]]N*M,! _ D2?-,v 4m7_}]%kgȴzz :+qqӒ?u\ 0Ny擟fOvJEo >]EoY.^W gtQv`AD4Ȃ,L$c Ë PsE(ٜc ZaSa:a,njb2b:,BMjDLKGz] b%ZRRu0,˒@b˻ruC"$լ4E`Ej#$"M-PEUwYToTNHPI d(rStАUB % TQK);&Q$gY*ag0 j B7)< {Iutf`H&EӞCZ=8Zj=!wDo:2{>̯ Ca TGAױISMyib=%C*CA޶*BbfM4sCOt(0cޛG?n8px[n&-!B%,u Y.VלG(sAL0^gvYduOrSaǸ  O׌O !B7@8ޏC'-:4ӡF+:Ů/YocUB*F 0՝b EgUQ(+b᭐$&!KrrXr փ0N. NDk4m1oKc*'&֟2fiFW1F?Ywb_rAL׬ \&Vh-W@WX'=:Sc@ɂnCkV4 BچUdňKi^e@ak* #AENwڂʼ@nxP䕤Pv$@eXlHNVi?zQ8[WC~#" Y&6TpZܩ$&SL52Z@ސKQz3_̒eji7]|0I@э+H&oqiAalA qI6BP' s99TUr=ae:= b)0CWϮr?^zOFeeeJD7`$ Њ PlJ%HU i `/5+Eq4pl‹Z;UYՓUUh*2 M(yyա (<"dP$]2e4Ti!K " Vra([Li\*+y{*Jw&Cd90),+ R,K8R+W*R)(A& J  q2]5(xbR(pe%Ѿ 1u5' M(XdD"%E7.2+ Mkd1'+/&(ST^÷~ʓN`TJEsO`L+LXRJ:((C9ԐDsܪ/)dGFj^,Qnc(RJ UZMk N }zn[ajZIem7- A(BR@4˜.GEDhf :5XJD\cDT::wR(@4ibNԥC " 0v Wm{@vV-]!fɫ&ܶn(Q DѮ\1*JQ+킑4d N5y{%RJDx|<-K=iҋ UV 3n7@Du Y!n:F|f GuPZζ0Iʈ!WVI,q?mn?'r|j{ZxSD~o9@a}'ѩq}|-px4z~r&W ~, ٨'\,Թp.}7M'd] {n9tpx ].?FrJMK}{ox_w:dR=KM?>a(}+-k+qh}q4?@h):Tҏ\Wog- hcMsk5/3XJt鳏Qv>uV蝍Mۺ8Fm?!?1E_z$,z=;8"wkKxO=M{Q_a&(ic뿙=6s/Be|[k ~^CF/"Σl[1 _eCv,$8Ht@MVgvݣM#.Y8;Y~1Ѝ?g:L-8Y^Iu=.4Ÿ}]4:>!ykqd `Nki %7|g'loY8Br(`ܖdާX=Dy.>+2iƵ6?|< O~*}gmp`*0fXPw{3_TW[AہMѱ~)צXR0̆ZU`> ~J6ϛNi귋+𷸲E|/ Gv__}qr|wJѦP^wn^mCۣ|Q_d/\+sw2X&HRkxm đK++{ڔNG9V/*}îQA&:'+"q簏.&=P6õr: nW]ǹt|_?Rצ/_a+5?vpp :fYUWVK\]kgv$;>;by|\OVA[gݺO 0kB2}h4%|b{8=q) a6C@ a@oZ7őyD;೔wY {DQݝ9&Bɒ0|^T<{?鯘+:!y @ t_^yv xw]OokCӜG52c5wtM|{pl.a}:>Hx|]~:57=T<`G:ۿ^7ܨ[>p̆@1qG=}ԟQ!7! <2\i6f)W>g[nfޕ^Nezxߛz.iT6Ͻ[SzsZ7ǨͰZŖZWFWGTr\+Z\}~˦j'Yf>&?Hwior%F ӒC~m?5 G|bstv4tw]Oᣠ9g[z]98Ws/#y<^7 k'm-L_}뜿[#?qn51?[=lԏ3j21_}[C؟=T=¡ίrkN,ݹYEnO 7WKu)컝Sg+A`廹.[egOkε/|mgjƪn7 ESGhdON?Ov{sd\'LvmIMxS4-fr[g v^3VcX rxWjCzfr،bʹM{^pç/Y>Ww~nG6u^ot!]yinbi^<4''"v# ^ԇ|3_i㉺6>~ݏwy36wu#?`\wItwJ+F-f{9N*Pg5X/S{]NH͆_l2_7zNeo_dQ^@0_v>Dz#]%WxS[ϣb3-3LwKLwN.QtSh۰炧Y|H9;y^$ZkΫpn`63\"xѷ*v;4Sל׬H?E/sxerpJhݜ>>Ík]^t,z&tso588ƙVr#(L'#P:ΩYs cAֿ~)޴4Y %b:QҴJPi\^8#P^H(:z[/TY73b2ȸQ.ʹ6#aw5e:0_p/gWtW>ָSR[WPKqi'kۮ*7|Oaⱐ Friw;]} {,Q ~nwV3N?}ae-dǨ*i>Vl?L 9ilew*55hE)d󻝏m+ðbCn|+[2^k?eռtCo\c߿: ˹ӡVc?۠GsQcM4oz>'mHҢ_^:M/fFe P2d12NJC!B(E74!GFKL!)Ҫ,kTE@АPY$aIY*ߠҡ$UH 4$a&f;;?S~יt]?. $L `>_+G^/}WلQsz9hOwLG0ڇ~9_W ے=x?+_Q8]֭SvIqؗnWi?iE^ܱӪM6k?a<_8 .oGy{yBۓoZrk[/0Gcm+P.S]>Z`2 Kĝ3Ӻx>k`$}uMke%tix)i=Xܱr(S$t[>no[EJ5l5{L~F򶧅8>[iopU0R+QRG:vLMnY3}ckq3c9%l "cEUĵ- W[ϔa=bWN>~{&c?G$]x_\ѷmʜO`o\ZIʋs4T@3Gb;amv>o) /k`&NESt5}f`Gz Z:Mf 94W;#A=YFtO7MoB}9j xvqWxjߦʒ]Չ|[Ly2߼D\}x_lX<\V,JG ݼ3J q9~|-œ{ϵn1~__ EgEuz4:Jp<+R}[pAx⹎R VnXX/T{fsFݮ]OY㫗|? /w! 4m ^ꉲ^:7"-R>g:6V]W&T!]yl^pώo,_;/k<_\%d2^a{nWѯ^wYU;+ڵ\z7W;"@{b`ok9JVX[ +3rs볜_ W|>‹2vӱaVjڱAk=:c#Z5Jݶg4ދ= a۷y.w,˄mk6cv{MmB^]yvRݎ)*^=̟ uԧ*sm]n|^c'jn #~îi~p *W>^/H.۵ss.P=!?w?I|QbvQךHobij˟g5idK"4Nrl+dVQ5 JxMVW!ߢ;S7=oN4{t\΁l3r`MY߲,_OaOz;֐WQ\!.:۵+ջ"ӧꪘ/u{? t%sup9#Xh, P˻0H}9-; j;k^ܓ[50VBI;l%@+Be=>5ejmJǞkf#gI 2X5Z`9G2%S/|ӥڃ9]S\6y>^g-udv$_Zyl^:7f^ CpVK=TyWZ*{O~҇)Jc VّKFێQ3GК?M ?(sɑQԜE0ʮo * q T->@{Ka.bX>{3>y8 I|1&{'X 'Mv$tfj1g F/1|͵y 迼cJ69?3jjiP,O@]s9o~Ż?1g"a@E”H,Os-ۈ3`HHmwǰx]D;{vh:?V&0|'\|Q̱yM>lNV+)~4+J eu#"8q//7X5n y'2C4,g^гd Qls9qٱ~  GZI4K5(/MXh î/~AnVL]4f[coemmߕ^]ti\T'p(2f0>'h/!֜<9sw'qRK+hWfy̋nnk\?ѲڬҜۛZ$o`d7'h[:86cj zb^-9r7Yo%K^ h!݌ 1#k fKSS/NY\Hc]\0oya;nmr*9(ۋe <@.6x~p9 1\xLs.hXߡkmvc' 7rXͣe!c oFIM4KL?_C(:pSPF*(@1A1ExkD$Hz~Ѧ*iڢ~&L$o}2XI`}i$ķ? PF9a@xO`g >C%!+EKլzP & 'TQ@[/q^d_Eaiq~3]/ pK+p&UZeg,Q `%21qʯ x/7a@ܐ K+i/=B1QD`g%\ g4Cpb ^wl087)B36ls!aǾ[/Ã~:'JyɄܠQi<}kN ;kh >(ƌa퉱b}\{F3,FUjmΘLx $Jƥ1z2&TI2tw s{ݻ,:_t̍Ux1]D_\ƛ!IX٩(5]GGeKyS׃~hU/ee+)~ۚEu*dz ;١+'`$*jɦX|MsdCjъX0i)G, 4a1xx-msKߝbu>]B;G"[xĄ:caeiR57 75`V:Ȭ) /TCn c`? ,Ra%4wW+<ڑ#S`1X5bs(А`1z>Z-H|`!wNGAC(=Xz2[ LnH/[ר^7uy% dbB۔>[V!xROǜJ> `֑ĭ^F̸Иl $nh ڽ{i7eyG6[yZfss"Kͣx12M,N߁EVo/Ztdͬɧ2a xxG8l~Ұ?!>eTL~|VYV4 Ш?5'SҩǖD }'12%D- 4rY)旑ѷ_٠aԢu}n&v~+s=_GJO֢cY%;38 _wdA_y.M(^^(HE #5`G0h>Dr[uQ`"6A@`IvdaeBH#Qbɫ$$jc$fyba)p$0Kff0R1*)D Ɍk`!b\UQ/fKA:F `-nXfI]T![XY?cKS~w}>eem5ng/s |%jK\fS)c8>@D)-|6/'&u3(?qgeju-)_F՚F2X4XYҶPL -~acw'vۆ(H+ 8ݻF&> YDbƐC)ѻ;mM h?ϿXd&.Y!~ӆAS`6<DDF*U۫XXGPMsN S <IS})!=G FI,G 5RHbT Dx2^xk"Y][zz2q.rf%FF4\;zs[Hjҍ=fW-s4FAyȁF MeiSo;⽴hbM>#Hx8wo@1︳=r]7jSi{"^'Cw^%蝛o<yv 7ECNa bp }u[nDu0!$i].Jk5]Ǚ}ia0!KYE!R$ 4y(H+d}^+ kfমAfp6Fw`j:^`d[,uExxJFR 8B}(S[ھuY;[.J GeeӥSob|R[O+ŏs=j9y8wQyѕNcDqx>a8 "68=FK70yM{g͞IHms{a1۬fr+'Z8jVk+~!5KȲ[0{a.>> ==mbTIU))emeB>$!+l|w) ڽ{Rl ';+| Z}|W9th)uϷ <*[q#!HBi*4|fT;н_]ݔ-Ѱ̘(K {F_[޼s.\nJc Ng+ɓϭr_5@ $8 !EBV?}ޖ?"C*2Up}) PVy"@4v% WF8yO)Mܗ4N!{j~y? ᰋlUoev3Z8rbrv4-3FF Ǯ'`}acIUjG[ 8jx$L>_.#| +_x,GAxᅋJB1 mǗ۸$8<da|ŽɈXm20\niW(hD{zTi6R|#yB7[@Gb{ |JUs^+|(? -fr_;)g7O0:^RCJ y!/g/[za8|`lX,p_a7w>Gф!&_@P9 CQV߳wnO4v&_鿷ս6K+5 xi@i1G LH<)7Es1ɸ}Z-A!Ac nԴP惀C{p(n#rAO,'`貰:nEAR鰟Y˳:`bIKfVr9Xq =CX .kFD^L=#t1fG‘L ߿CY )iyo'$?-|+_"|K"^gi'эsR] Q& *t=H}C6 j18& _|k[? Xo.` Hi/(8RƊ&jx!N;\ \\!2yZ*eԕ$ r*&!5jFNj 6JAMg ۇAA db"vY LH rlZ)b(I :UVUHKeHJEB(TܳKU&.YQV /5X1E ,VlkMń@"urQ!BSsLʤ2Yۑ5,,XPZ@`Z˞fm#e7HE]% ^6F'y" iW)* +,rG&Ï2jDY^.$ٔЉNG hjF("X _Zosw~٪角 O>Ϗe`.啞Wkα`r6]HѦN&-; |y[2a1.lJ^C&iIC88 h<1XJcNL\Ž[!'w EK0A0rTfn Dl,(l87U-1ܬJfj07 BI8Y%PL:S@ ޡaBF56(i 헗`VE )R ۍ SbZUU+rPfb_'#8RD@  A&xQNvv%i{+x{Ⱦ<5i@ ؀`ISVJMbjjkpE0)t $ZnY僡G\:/^p8Nx T&@:k&hM $%ʒPrЪSQb9 l+ Czrdl)+DV*,;uݚ[ :4l"N&ζA=VOm-FDB0y խRwR\ctb|LXqF͂NJex8ώ-UuP֕簾,e^y!@sLN`@fZNgr$6S*Te-Dj.»aI Ld9D&ip9(АHna*ﻴGpXM˦ZYXTXٳW\KkYd{Z†kbc/,3d2AdƄoiTduxϊ- PPeЕSV H 仉WxL$%ʢѦ +g "fa<Ѝ? I `Umuma RGrU$3ҨWucl0Xmz 5g7(1jDžgdzyb*ADzau]5JDPw`nmj]$Z+f @R aq$T#(>O{ڱ ʗho~fxJ9D8]b+H;S#,62ZĖ ؎g4jop-  H)2@A M3*3YeRdUa1td)&vLC["2,ekL5D #) D@{D&fZՀj&U2PJ⑺뮖GC T< `4 ֥@5.:\4hl"fmTEE([LFYS6$*JEfV&8^ 4R9"70R0ƻKѥtQtMuA1jfl.PX"F%RS!E*3Rx\[(`v1(6a JS.핔DAgTG,D%%Ւ$285ȱP^[eAײ*(*:.a1>SC~nBE@4uL2rr3 oh"UѨKA S!p0wiIzoʠ,AjU BتFq #< 72`0gԜ]nUWUwT00un z&HmbA1; eZՅLY>g [(WZ(ݕUƪF߫3-J*]=-`r6764KMi  m@e*)6"@Ú)qd22Bs"n)y\*3\DpH B@$ ravЌHFuD &q|%Nvz͔Xj=!&dU@IM!lKdP2κXgS YL2FaC )Ƶ24,jC R{*bɻ /L^!2Džh3 hT 0f(e,F"( qfMJBVRRfeFB|`/f(uI-vnE`JBRB#U4nh}:Oo`:WYVm驢½0)z^;7<ٛF̘|@ mI@%6Kd(.@(P,)Edշ.]n1ι۫n')Eѽ Īm%C Usj=yk MdHq6xlgc8(I$Ď>@U'֑=FaJ구'gKWPzDkUu]9<"rmyuJcĔbsL75!:%c*]7Y*Cb}%ڶ_~@y|)l(4=+*al*Nsnk:Ԩ78嵳fT6 kc8Wj.#3D7ŖOܠ .̈H)ƚM{j)1܎gC7nlctR%A$M`'3P sBl( jLnͼyNy6cѶwezK\+Va )-)Z< >sOA<ܴki)޹ f'bU(P)-F(0$زZEҀ#8Յ %ކ"C(x"QTkm3%.P+ ԭiQ$^j"iQ@q`Y" #`{#,X(faF;*" '4<S e.yO6boG1 VvV W!dܰ"Cj'pR(td0Y"Y0ȠD 2C)ڐ\ʲa"Y2lFJHڒ!R,1Ďw_OmxMyuݡ[.Y&LͽCZYvn(j%2 !÷;fBT@撸 aQbԪaH]3ZM ,] G0ZR'yfkMI7,Q\[X4!P6ai'M틧Du(R\=a1:!9@G$iJ""L]{x"ee,rk&rT ` 4*`m`NV6AXDT@8_\kXէ #xfIE(nc!b E$T;:M1ōc ׾inz<7 6]?5s@[N/=6J;p˔lS30J9G- 'Vg$ʡPbUreddǥ ɋ3Ywx}@zLPIvm%dYµzcN@IRhPҡ%T$PAToo:pÑd* ] 銒MjۚԚ0fts!8rXiTDF[7 cjP"Y7Cksvr'E vil9̧LShPJMtVE (ƓgB09Gg~p<~| " ^ݖGtErZ< !n` :)]*0PLbbDe6|UʄLIe-r[4t7E4q]wW(KbG..R(>p!(Ȍq{ڮW8o^},m2TRf}pI JxYh#;c7- CcUj~6p"€BP5|AbGW@0@k=w^ CKP}LUn,o),gbQCh)zn; 149-%Z׉X5K28w5Juhn@@LCC@\pg荘!TL4|lxmOA(S]%I1Pxjp|lmpA}& 6TɧX[j%f' .Q»ń!L dtdc U1qkM1{ Pif!hV*Pg-bB]ݜ-e`@T8W28T3k@L^!MS q|liꀠ0@rU *&X[,c|sY#0$ "0![إ*4jBy4jJZ[BdXu&NtTCee{! ͦqm.mg3d !hCeofk _4GVV  */4FQvwR@0@r U Lή}}Y*hrvY@f`e BXDʵU@!j*!L(EUPAU DG8lg2BPKb $ 1) uwWYj DB12H+ j2 4U)9h0)2#BbG(2Q%dQeb԰CHD8U)=((&ʚC! ɫZXwݳ; Ɔ{&!wtCŘH!`̭`.Э Xf\&35"aZkYmrBBM*}?T#좂H ,]$|9`:֬xg&$<5Au.2yL&5͵ܥXD}Y3n9iyY؁r +uҤ@oq|S:lVheU 5fOKyA[wR~Խp\=k`ϫeժ<8&,Bl"P[^hV{ Cc;rRlyy᡹y3Č^c uܬ5j@qU-'J7 I7\qulq S*k\;y97]p{aE\(rcمZmW` 9 2E=Z5dʻbx `Cc.4]ۃeћC,֢$iZWR Z&(ʦRdURcJj4P$B`wN`(Vt@(@(&V::ZBBl! ְ͘f@لC)!Ԇ:A觹?>57]Wi؀:5zwb f8<(exb_ StȘVPCYT.TRkZbU/F5USyf"/Vͬ,o Q-4ΤlwǏźlVx!KE[,wPK"88C=f5WLQ XZM6 PУȗaι|9 !ؼd/z E[*Mv?〩~W؜?zʕxD3c;n&ŰK(ǚbXӛ1C:_ WHs&E@HB?%C^aG[^׏>LO""6|/m38[X†iQŐx(!?oDC d!#O|*8\u!$DB_HVᣭ)5^O.ѥZIի&,ҡ"4uV6Fd@@IVnE$6@DY!I,2$@@1 o9(M3Q,knR ZsbM)aK˷ С"zo_dz`Ura}df7*='Wl{j3.caeslk/ו4 Eksʽ]뚲#zuv`&h7ku{)PoQ+$g ^2f5OgX,Żd/̂.1uz"+< w>gf(_E!0{^7~V!k S0Ezװ{M(/=4X2)Coh'd[b'vŎ6e<+߆)ezư+r"? M`s}1J/mY:Np>^!b.G4Mqe18voRӌK`p&FY#Fp13ד !I4d 8Wռ'LhγaiQa/QkB))!PU) SL9ƃ'g~f-t ̹H`-8BB0 ! z`;Įz<#vNn5R,mI򀞝MX>Tla=M8 X uPp "irtK((@(BdBJ@PFzgu5^ 䗃~jD+yaEꊜb4EfM[a5a 6X)"rĀe\;e 8Seћin}^+Ķ?+Bm tJjV<psW"]7v_=N Xn jޥ.+g3T@õU8m Bl?-1|rw?.ld˅ż딇<">骡X>e^LȝasXjt|ZIg>t_/zP4}oPs#$;R9MEefc$u-5, C:%2Cg0X1brEa*ILH iDX&0] 1pS[4у%!&L^3}9+yh͘I6`$!$hp^;/;{]K@vhC @ d- ê#+Y?מ0yM{4RA<ː'SqbM)T*h\8#k.Ϡ|;xZ s̑|a3ǎww:Sڟs[40YFESq^R# # 0U Zڋ+4N58_f+:nVňQU>Zbε5&B`#vkabZ60cR*G(VJgٽ)R@4h/9o̘=ߪ$J(MP*<* #fJ GB(ó܍*E<6eқ`^:I"˅W˽jV0n4CKJAѧ(BŲٜanIP>8+&s3aV PPKl07C,Hh-4`яոI-&}"-<%av " :9cmMdB!UΫ\klm4-ƃno  wO$DU_WOy[) $k(:T>3 't7iΊr:KMEc(9QM=MW8ʯ'\jƙWHћHa* eǦPŴ{c#߫yXyFTWVDP{YWz+Of@=*uػFgj1vaNhNӔ{ pPcJ.W ^ɵPN-<|D16\ ي9J AQ6ŜvtmOIr_]E݀bA[N_;rS]b'Ϳ6qۻP"*Gjy|L$Pfrv]"ʀ"Mcj7f3s.J)K5CT4Vf]5NcTrC8{-ߦAB@u(*RLq DGj -Y95XKB6pZQȱ`u?j37#lus_Rn0>D8)X7$+![aVE4L&z!(Co&鹕i*=b'H!{Di`Ls*V0 _{{^+Kl[KZnyqm]M56+AQa]<]wh 9G66~5ԥ)}MU@d^۵r:ڮY}aZtq #KֵO<nWW)jQ@s%qNO'3u%^WTfˀŐ=) !.Һ UZWjW{p};vЇ )r -Gd8*XK!H4'%/V`p@Ҁi&"MYPJaTHf}_hUWEU!@`Q 6 K7d""ȤA 0AqP(AAҒ X?4.|מ^׻W I KA$,h +]r8.˴R)i lԕ|VT+4^gz8 Js Л`X06Sճg6x20~oh(]&"S=ZAM}y[W:-䪿1\ 6$; Q7[.J;j @7rFIp,/(' +$ߛEM8QhXp-ΉX{z /w  Fb.}LҽD+B(OYD@fF8\ FH2#v37劼c$0bjŰՕ$BQ[(AUWuŮm;< mˌmdR+,v3PkaBLl)H q 2k8!3У1 7eӈA B;$6IRcKz*),n2@рL*@a`aqG:nScN E5Xs0o^ +TR :N& 6PJj(: mj DC?jĢ L}۶rAL^ UfljFJ v<ޢL5g\ yo5ґm6og=6f:ᠪ35f\R>po}`5xUN04UkBϾ\c#x |NU~([uT/d2b3Aʦnڸ"FoO2@;s5Z+ G5}DZr3e'zat<՚Ӌi8]LPxa&vTcW C&֋j h>Tf2{D[ĭ1@es8yCẄ́jmĜbhvNS<+>Y^(sMݶ{ڕCꄯ0>}g>Phk3YS)%'XpL?,|}G}QP|a55j5-/-U2j9Rq oGGL6/C'{oaTNo $lRăJR W..]a] 1׸=J4 ," ш".l4o1c{-ތk(c2dUSl~bM:ŕD\\6- [%ڃQ6UfX뻄` zXNɹ,+@P +* ",+0Aq(_`zft4L3掁P;$:}/> C/Z,>a>h>SByAnE\qn{<&|X) <^[[ݤ'yM6l0`mV1)z^]O^?]"dI%E[fQK*. ƒ '1cjE*^[5ީe2i\ϮB 5^bq2(c9wQs%/2mR$qY0䝺l o-.NRj畛ZU.؊WBm ll4#_l0 :v *X.͇$/\\z=#]8\o[{)_x ',^^z]]/[m[9yݴsTGG2:{VpU WT'L A#@5q{ڞ@Бjݳe.x9{8l;o]'}Eauq و:`1>c*0s,"Ļ R-52IzM 2 UAm@$L iHtbA䲣rn^㚆qtr[K}jtLjiIs5nmo(1"v,so<(54;uHvz +mTڙTU`|6޽W^ͷ ,$P АKbvTktxb4 lvߎêp߰⼩w5K4^zZEbaG>ź$a`FI%LJjM[fzXs}== }"D!p,[5|.od11w7s+l^bUK.`"nP"۟ҼG\o;`jṦ)j*ڎw>Ta]#M Ʒ8k<3m(֪}23 ^=%ťU0FK!\+!.,nXͣYŌ=DNng}]mA0%|m!%W^!«_Is-͆TkX+RQjh :ξ{&ox+c} o_מOs7*kGRMZQu̲abyׯ'A)Yό/xwa  lBn7UFH֐3pߐ 6⹙ +bj}he.e2ynA8e2v ^桙`$AP25a|tUS{HڊV1#ׄ cKuK|ဣg\GjT=P:~?5k<31y+ "QVӟj)plb=7j /N+?ikGun1zz)LVg Z!i" D$HxQ"LܤGJ-!J9%֥4IȒ_~-_ֺD4$$4/}= k!&`i+ ҽ^(6WY|c=z9{E"W6fUzH4){5-Ի-8iOy96vA7$`) H!T5ڎ|oW` PrJ >Kal@T8+bejڡEȪyD pB "c " LJ1LW bOP{>{&c[Qe;㦜aőG|z1fF.#kgq{Et1uz"1풹:S)^n"SnY}u"u8_ `;h( \CucUi" Mlw.'}E8VFNQg]ue( @'2[vʔMc/&AߡacѭmF靦;sTwzC|렡-@Fj#kʏnGe ~NYb3ZbJ9[64BRLҳG31nmR(@GK1EU\,l`vf460 P+i. 3n"ޔ_yLJ r07;=a}bf}oB/'Śe FGJw0uzeM&6 )c4h֟. *_. b .[QuZC84a9`` ]*E l)2L&囼üIZAZW;$gK3a'q1li[??Aa6ST'쫅Pt K*|sKIZ9xXQBK&Zv&z5zRu) H2x(0' @OLZ{61%Ki>t?gN ЂbJ>/Po˦dad#S Se0Jfr@|:2(8{6ɽ֚MOUֶf_C޻GN9;M\e? ?mamdm꟬ʎ0B;4_^<_Ni'ZEAq̌4@wTſUNmU`QagmeG$ aEzW-:YR]jT@ !–@Ȣ4'k2/J_3P"Y6߯OX5Hņ1ٸ=kmEsݖ:q9V׊*DQnn(2\UoWp|]\m\xє׳!X ;AM ʁgZ#w9;̇aM;>`Zh9ByN-)4GkS2)El=f/]7͆N5Uo~ ?[?W[w#KKf+tR{d h l`J 2V2w2el 3&#"IUQ3η>ȇuG=+R~q I;$~ $=NHuMI C;Bt(V## (&_gN*ЁMOwAWo se O>-ġT!SpwN݄慌<Ab B}XoQq ab|ZH0Џ;"ry}74TQb 5w3¦-) f)=V36BPYlPc=Ⱦ-aҮ,5DE22aeP%V) B9~lpGdCOh8u͔:DE!&`"?/٤Cc;wx|<7+ {PC Gݜ{*`(AA&fA04nFǁk`0O/5ɀ'ebL=:gJU&B:׿"d)!9bExb>ԎlI}35Vol.F4ڵ6GÚ,D-{K)tX5XrA2VTY+Bwj{h/OTD3O53CW˽ߦ o3/tOK:y; 茋$)J#(2wO顷;{=sz+߹}z>wmCOdeVz ט#rqVAl"R@ʌ+_z6\,;Y-i~ϯ]nm‹*x(FWMJ Yfh"J0IP"ySkǾȯpF/:%އMi0C0%epb1es7-{ʋDK`t,o][ oNۻr.,D~T8v6-1e%u%ΡH桏Erq^ui'o_?pYh+Q+)YN-fPw"E2 ̰]hυeş2wqs߼9DBo\~+3,8Z߱z>tH3~%<!s+p=W|Z!0%R !'_I?bQ9Ue\$8wv>ͮYkmTA@X+&憂P1F^{*][B*^#&6.*^' , aq=}l(QF2[W6k58\󖎷C]fc [#Qpv<q0ו0$lxUQ2zh[83K0Zܼ35[>ڶF|@NԭC>XTȀb֎QC`w"E.-eH rwX_O/5OB#F!;9JBd 1z2H}ݟ ^5bGfnľ^]x2 i_Zk,c7.1"e߿~9xW_NzXk*5>7Oqao@&~↡G@?7nyv-?IA<|ڇʴ`>+*\:(ۍSќzX"r``\Ȼ3 ouM6ںP0՞'}-h )LֽQZ[0 r=j٫3`QxIcMUoaq/'jm~PXLSJp1YI5d{sx g7>mjb0*8"7kbfʎd,E&'WoO6MC~ǁJ.k :XGʏٖku``Yi,ۺG\Po2zjdAySt/lU1#~ry],F_#0jbaJRL6 :X^TYm!,!0G}Ps"KojFO J<Y, c"^9Aa5)?n.}hEC-|Dh>>&.(vP9W9%3"@ 40B; jߤ,HO@)'*@ʁы81uх!%@A`\yl4:N־' /wkRv)8i'w7ދfh'A+Q!%$&9l]Es %!a,R$ };T`&0 $/BHkP?Hdd4)l!!xL$2L!I&R [  On̒ 'H`HY!\h30R ùOBI10d&XN+cHI$I ۾s@/@;FBHOd#$Mn[C?-y- T@ ջoB@a I'9= VCmW"X* #W1-P=?/a)|'Q]~Ls.Qtj &蹓@{q˿ BiF!T"YxxHG].yݿԼinp0d$4$ttq!$_hHCHIzt $5ղ /O@zv"N={8B]"ڔ& !+ Is:?GNg ¤吐 x_qR:_#I HN! q$%qRHܤ  NKھ@hI @?vlWT\I!&$$I$<~* % &$ uI!? Ry?! He$@$&CCP@/I!$!' @>I yHCbB!  (H{3Hox8Z'S$XI HCQBBOR OH ! Є*'^ BI$B5$d M&Bll$L WJ!I$3=%B2Q aDmR@ zz 7>>=&5RH[ꉋ?wźN 1@h~<2@ ֤j rIݠI&$I0MD$oC>Q)ئ_[}T NJ@RB>rYqVM$X'd1$<~RHzdKI$WϠ!$a $a $C$ P$:}6HHu ! $ $ ~ ~ H ?B@>`I> A$  d} IL$ I'd {VBH@: Bk0I= [r}FB0 I'H@2 !$d!XƄa=S GjOaB餀NI$0$!>@ N-'d rh5$:vHP`Iq '9@'iۧ,|?svI$5Ua CNԄ $zC5:$?EtRB|4$ n!6Ct~mQ1o=c_P)4~'m?H$'P vί/ =Pc=k{Vl:D>ZmbO6 s!TC:Q8G4ԒM W-W=XHY&<(|yo`Zk5jhQyXJ~vψQ/m;vmyը߹{cw-^>_s&t2v+d7*Ҡ]֋0%<6@.[7l6 :"I Fu+Ms{_U8r˙S0YU5,`-*SKf1Mc,Йrމ':A ,)D+#Fg&@WWi9}{iY55o~= 32Z+W_]68]Tc[bO-aݤ~+߉3;V:3as$)be;+4yXq)D@~I}Qgk4ΰPM\?0 $(Qbꫴ7Nrm7o|KֺSe~=QgVY~L=nlnzjfa(1$rB}H۳?nD.jb>8Ԫє:]_ ߌʜ!}L3\@mQsjO[dVWLl αAlf 5TQ=, W [S f):3&bV I]^}׬z03T{Uixa_b zJkZp6p Xi*O+b#P04jyJũ Jf)bhU(vbIfU.z^|u\Ÿϡ[gC-lz_}>I%+x&ot4&PF8lLr6NjN{j=˨E)[^ʃ}G%Ba&-Lj7CŷVMMF6̬[꡿2:1 [ Y_0 9Ka-l)جi}Qŷ3pQٱCQ;d\٫J|@MP}H"} *ժIC0ҿDXFǬ&>I_ܪ3T!@; q/]wlWm׃TQ缚pLBQIWYۻ L./be,߷6ǣS[]?^\|HiTWea#rͬlYk?QJ$7;xlN@BŮ,mhY>\lԝQ !A"3!]}-'WiŻLZP;R=nS.HO8Ӭ:n YKi]68 HD X h@!M^Ɩʔ]8> ^1I-kgr;~%-8,HT  YIsU@\:LP$4:nps]t:́;}mOq CA7{: C[C$$plwHIvЁ $ <[N I_ı!$&$:ް@W olI$ErI IHzٵI $< I 8I$&c'o bBpP I1&I$Ő!"l ;6@ ˪@Yyn@& |!I;4$!p$'2a@:@   [ CB'"w[:H2x>޵Bs@ op'HH$8~<8 Hy.ڤ:unW}oi\BqLک HhA/Z6(5( Z)hG&#bмbN*M^w<N& @*ni0g߻̬@0iuV2Vs{:%zr3jw?i $'{.B:IAEm-C{#\r eheM4畒u2-2N 2q !D@^*uak{El~'sv %Z$K/mU% TSsyd6ɥkSSN*1ؽ*\eݹj@ H髙ausr(fz'>!U(^GWga^+_UXg^k3ޣgA$*@sґn @PVJջjN`8p-A;כSnڿO5 vR nͫI&v왥\w p1/ʺ{)+/.&^zai"i!<**hQQBӾuRJmuFCNn.y@ۢ=-4>k qvoߊ)5hco?z6OF`m*5LIaeit}Sf$bd((Y"Xmnrk=)FAzڝUw_<ceTL2񧖰 x:^^Cy1@ũ=y3̈́N߮Z8N mGn.O8x{}l=N+o,Ho:q`b&YܙL_`{I$` VQOfntm=Zw9md9/cq6HcL.keWRܠD3GRSg^t봆lۀ]KGI !pX$ߥ\[V Ε(CS؎3 .|5&cI٦ 1΅,PE1TƢ[SbW5EaS!ZB6% iǼI!$Et~7Ѯ,n T$ "JHGnt́툓-QZ>CYY=-бc!SQp,DB b1@4^ WWOtPؿ,lRvώtY"ksfPec 1zXvO7|y<ϣM_RϒCZI)-U=t 'V TC.jG)?>:{|ѪS!hqC"\؆B021i#&,mr}o/OuGmٸ/ 1n> ;@mPU\Ѫ|yK\.~_uVknc2w뾟v>ǐV,w}#|bN!5#u"fқNDXek?x2ֿYtsL@kY?b-))LQME" 5)8d=juANʪ 3L˭}t%H|D0Lu,?}{yQ=hn& BY=a%$?O@ن<_|.o{xjs4 ]&4}7% "P2!%cQݤdFY^_y( {):^r9|A}gp+F?qgNĦm(;% /X̤jZb)S4\0] Btm IB5Rqd `@䐛PP8!ń$Q?[2oK ,ڴTLd#D"d4Th TgZ#t9 t٣f6C"2>[>~GֶFfRҺٱ&J>$t! Mv# BPrh'mL 60ǹˏ~4f]E ._T7W~`C#0!T*B3Uʭ"PI+$3} 2ūK_r(u!Cţt76?{.9:r6ž*|Ȁ<A#>.qVȃcck*E 3?ehkIۻJJ?z2NQ6fs!2&n'aKQ~$Cj/zo SkՋ v*3RB2R5vlrv`qE65LZm,-ԀPg \m81jcFkͅ)b"6=l^(1sa\C&&y}?f(4X"M_SD\uEj'{-Ѕr7m7B1騒&Y7ZZ$)\**YVZ,aجNM8’@/ nJA}HCHyXE|PծO$x/KڣlOn9{t#&%1RPYM1K\_Dl 1Ad5Uhrd`no)wc˱hh/~e?(D"73>I'ó"@,o)(@) ysRZRְݏ񂤆[M(8u)LxnBM56QKnapP([7Jo% $HAdCD̉<?HV<)PR+:?!ٸ5sӐI9v/8lMX#83pO>46k, Qp:&ւVA9~\6MݯP0 WbzX8Fd3݋tg&-zxIנLzTD ߡ=GI2NlqOosN}Q"fwA' 5 I(J!<MF:U lnId/0{Ӷ\2=ʡ?j7[(3 u:R;YZlMG+KZu6;kuW'U(;HHf=rWp5cB?T^ph$o&BX%Wط}uytWJ}_3?Cĕh:.z6x+@;05hP "RVշ9 Y _w 5UAo.z/>Wv;Pfy (24ƐR >#U JNt1_:ΐH3b^^ERC>L&VaB!>\O+TSFn9mj,*t,8L6 =*:V<U~@I@ j\u V.2s'>@3 !j-x6E3 ˨NJK!) Af_O+GIPwxI"uq׿/Q >X_Mm83Ws rTSmamry?j&/J?}J$E""@6riҳY;eϙ6ӭ[1M?rؠ&gHlzh4fhq&6KhafX#A)X Жl.4׭myZJD xlT~i7;Ѫƪm]*X<',+Uoa͖\ֽ҆`Z NFH/0#<#e:0chXi%X'v#D._e*Us~@X҇*։5J2Q'FG6iVXl5g"tT@\ͪF/}U.i?iJ,t'{(\[zlk%zR^}hfNFY]D199oy1*^ho@1Α9|5%>Jɬ#YߟQx!!:Pzѥ:6Z|{Y‹G78IgU˿6ʻ5!74qѝofaIOQoO.flB. .=O7WCtM&L{،V`ICZ9뗤욅v307;j \8+iv-س}gdB!s5H64p%tzVlE.ow5Ű4 tU*INvM6^MH k'F\Y{׻mͧQg eNmZ??swޥOS\_lxh$ȶ9թV=mjҙɒlfa;RnyajMJEUFfX7Sҟ?8cǵm6D _a=NY}ݩ`!7t/{D uʊqWzVèIdMBb7(g fkQjJNSY7]Z)G0*ZK)8?ClAr_}^X!k8T&-jS]h(ZCQaVd+%c6^;\qc6?87KTOJg+{]qAm+{;2 Σs:Y5x} E'HL_)cH>$@qSzO]O2OGҦU<uϿ/Tg!Sg F0Ġ0]{FQk PR~ K Uy$?&Gז`d`nfw#nQբGgZپk͵91Psc}oVPJ}2Qp,ۀqT CUZQ+ҿ] +TPW<|S@IUf`0a@BnB)7=]JA=:W} @gĭ(IDA! u3ȹ:2Jr)K,sUVޚ+'Hnu ,AQt2GK%"FjBɗ`7xR.)q[k7ۃ'%8 )"ah\v H5{ёb2'`"WWh1!ufbmxqՀxf:NVWG4Ĝ̓xU]-;B+HI7Q{]-!8cr?.)_s,zX=D\X~d*Z=W>ب'Y:BE{%p%DZ&qciP9N| a_dHr,@B,kWfN P3(P'fpt ;{` LЙ_@_az˯蚵'sܔL?H%Ef!*c'bXF>Yx_Dj(>:j?{tIlѳLW-pR|$JI'T&j@OЯw? s!0֞S>g/3X̄%^]o+x*7+:s^sU":֩ Sϸ { !j}2Bk! !I<$vH]PHJU2B @,j$袨s.C" _7\Q[A`5RBb3/>߷{9|FNkZʞϾW.}1'9W_.X7=vTU2~9ϡc?mT ]ۣBWT'$2|{9iZ2v;7xG\~;um}z-|uAC€"GIGID^?5i cħ=دUmC %3jԳˑpɻ\aaAAF&ziܺѻQ3AO10R'[G$!| ,@I (@56]tk3p)*еFr6&Uy9=MeObI12wАfB/㰵e$DGe(BWZѬKn>:] %GE*~M )ݶE`#KaiՙJ*)ZT bU~@4RB2J1J|K <mJh}oXL$X dD"!) M@ IMޡA <2hj?.@B~0_.ԃ)Vf$ :YхԊiN(jCSֳ'W_诺tCe ]DbT, )j>պ vj2;L,,2 4OXʓ$pɾdT'y1 EY!5 $"-ABN0 aa RH( Y9B?!-PI dAAX(J@))$Ai%2*F>B$āJd)I`, Z AR@rdMqW8*FUBS-¥TALw_;Go /P)I]1-i% Lb) i)_v~V./.$- ]co u@"d|j(`IC)"*3TL`'RK2Y`TݥE@j*@XWvi4MR*tR[tBH( @Ei%#t[-bh./HVIBcBeMwDMQ.'$)H0A%D%CQ0f+ˊU42S_ oMֹ7OzsFT>RM=v1!fhY%@P!LٲN''f%߯! S`ZuTLVb-hԲCdI%S~&d* Jov YmX[yN(Sg101 ݲ֯}}|/'|_6qrgJPR غXai{)^v*}u^7[\OttMR[ݢĊrvBR˫$,Þ}{ pEUC* 3uHӞpa+ȳw'`. ϻPD@Y>Ϋz?oțKzrYIBcmP~&HKԪ1V F7߷CrE!B`}I"$=<>wMX `IS¤yE|U l1{64fh1%O#yD$g! /"5ȓprB{);݆]|iּ\(QivRICvkL~̐ wXj?!%BHyi @In> .x$ B@dC$ \_U^kRRe@NZB$o)~#9=&az6Ǧ|ab-UhC{j;th82]%2(d;T@Y?U7YI91"E-^Xv4bR*A@YFw5 RU5y` `Rsp ;He쵊+k79 z, }? d1Ry jhTK0ByI-# .sݿGSګB(G( {r=f̃~+1vFݣnjsu&rd!znngUĿ0IL=zk]lj Feg8ݪPd0ȩiE`w=թL|dDuPq|OW}(!{r}i*b!GQ\SA?< цDϿ0Hٸzj IJ[CztY1!g)hu3e+QG U} u~i k PTi$d .$B0B[ Z$;)ίi=r#ן EEG4s LjL wc',Wx4Ӊ$MqWgv%@ RXlA$"#F Vpi@qa|@usU /jyG1JIB-9CVGųĞ[/gKC@<da%Jyi:-j C$Q10yg}v?{r@'yO҇)5$rkQzwy%|(Pn!$>zѮV:u4Ir[3q~ɶ9}#JJ4V.DŽ@Ǎ1It)]cFT롴Q9dWs,Wr:X7oQX.ם[*CmikG}MkW4sW#W%ܿp|="H,~w{_CGso?OV!䮛 B(F }Vw1"Y  rV-qx;<9%ZZ/;9`܌V b$ꃻpպHN,R:uZbŦf\?P݈̈́tyÑl' ͢ <~/rxd&;[wR! bGffɑ1y?C2 QnDr^X)YT$}fۮ+ Rpg ȃ:J Y@doO'koH}?}Kl;n@$,9 J)pj+ G(. N|pMIf Ǣ d0'lC*0HN C7W_! cB2!.LD-ZI&TBϑaPKܬw?/}^{I+[LJF[ BYJSNYU0J`=]j%}aC $k=l N-%#HO PD_ OJlz=?~1FKϠjU\kțŠY_n,`Ka!\؏R[\&٥yN?'$/R@%=l E 'Ԡ,S$Ȑ;!]ABINjq]S"'ySBZ2SCMe ]pْICu $X߰&j@U(%P[/:Ùh6秝S6V^ysW ".ϻuqЊo^}͌ۊ!򽍠K$+PI@8[ܺnN-p/B $P̅"bIL"t_7Whp3t֭!o?kv?$d B(>RIBP>I?"$b;}uI^s?ځHĦC,dCZ)SN6,Y]H"BJXOqa>HuvQ2éЛH0AY!fBC! ް$RI!:!}H,UH{!.I& Is=];vx& }P/W/=݌B L,lgaxe0s0 $Pψ$0 B!v8ӧH-BSϐ #93!WcGbyŏq|oWb1 zpQmNHk~|Z.~Byv[v#Urص~y:U rooq ȣc4ɳ}ClU*=c  _"`j0_3hQC $t~p1le=7Hńd +mȀX@cNA H AH,$`SXbT6s2TxKɍd ֲX !wcX}Hn(rIZ Wci! B1@pI `! UIY!)R@$ E l=jBoI @BAB*ՀMEItL hP@J 0AEWiCˠ+,Qldkᄆ Zׂ$Z,/ΛpoX bohFؖX?7jZ GWԲI`4R'T-JB Gxx6v}nWF]Kpd%LPK |Ԕ0VH5D Eg~N{B"/^ d)SC/uT%EtU2?ζdYqP8ro']IA *HH YKN`֕ %L?U ltLJ],87W)~Hd>i'k~ѾG05P-[f2AaV ATNB*F&ė5d-~.v}O[huڽf=7Gl&'u v F93BAEDH)4 7yMvQ!L)IUGBH0"T~CG[{Py]6m RpD[n VAr39g'OjSr޶!)>d $ $&\\&-UCbf qrr匂0 TYeVVD5%VQ]j'et5JkS  NuyU`ap(?c۩hm7+_t}qEMAM8#)R`;%)>cCR@BwC@O8vCw}9 /H==힩XCR4]‘andX&];.V|HbN+H!)B, a]yݤ<;W1RӆOu,"07yIs"|zC&ݵoWIQd$N[LH(2S$Eq\W&ZO8>>?S]TQQ1/ga~v uoɢV7 (}; :E@x Y 5v U ɖèAv TMɇU3 JQذ lQLg8}Ą6 U Z}E⑐'!^}"3#5Òm+e(}%=ͧ(+fQ]2g]m^w-8Ʌ5˩rxPel0Jp9X\(톾r8HFRAo¨ ƐKT']Ae()g fg;mZ _f'թh4닦t♇,5[!j;-)}Fgҹ*`1=m]e;V==`@S~tۘUsN Ac2_BLX4Ƅ;HvrjN e|~Cz/K)'["uo"rE[o @ ֑o)}i&sƕSjz֣EQux:ͺ@uh366H+oi<%w]R ,xDy Ya% (.fZ ЌAĸmZćKR9͕hp-vb&n&yV.])@|.# }bLe9!J2Ύuޑ5GW-#O bL +?@YChXa%2FU' /\Z3!v-2 H(uc!VR`#InRRKN&)ĜX29- zMj=&@L:csM]FCy,g715>]< F'ꜘOWH}W$:(^_tT>N\9i 5D-HhDɢHsN8U}fVGUC$i@?bS`ss $FaVJ,R~ 6CRC+ZOh9 .GJv >Јo3^ k|| E$eVH,,("ߖQ}>,F]l=#CAo\)ǚ q!}-1OX}%¨Ln$C0ڐB8QK6ٝW i6nĖCQ0P]bax!S$-)I:NHqFZ™ ?f6f6L2% ! h9"U;v/ןⳊof| ^Wq/ @h Tn." f@z.N*-2ҝcsﲌb^g)U.2i/!Aq 9ǣb ]-$㫆&΢w=qC|+٪,rn=|9 ~ 9ַ,} 3f}5_si].- ̴*dz~JSAbނM" ״~a-Z*ŵ'W _]CSpM$rś]lr F򅛏Hp(+A̢-tpxܖ\%D]Y_:2iWǠ8bY.џj>D FI6T3+0i \/lb/.YTK!J&d@^^I4Á^$ P6χkK693=t]5 ad'hݞoGב$6|+cIsA yl7&fs^αs:s)|$oGjW6 w|r7Q׉"/yboh o,>!kjP+)VC>w]5{x߿Ƌ~*=/ni۸殶h8|>cs(+)\yHx@#<{ v\{ZGCw}YFO3eﯯnL6S$ΩAKz**R,]1Ǎ\PNH1CmpZJHڢ#Իg HX9Ox-K+b;o^| BΩ[O:L- v#7V`dcE N)3I0K@PWy^eQ{^lJ;҄#[IVX)% ge+A N#6B#j!STZ6={| *@W1覶}tY) t̖<$RxԵ_4iDnJqw": 8R: xLJyq9Lڌ7 wt?*ðbX lqIe+Rw`-qGKx׶@y-7( /?3|i<\UlYtߧwANZ#BuΛa&_p!j |4W%z9ڕOz 8yYyn*(|t}(dvUUi?L!h^ԲMbOCS"*Fsy t s==u`|2>꒧y jNUr[l瑄:߱HN;I&'ݡdTCz:H`p H|,b@턄=$ ~B,!$`@ @4$, N/!߉.'"͐F(")#{5'WDΪ)B~, :adžޡI pHI$t ~JHBzĐ0IPa 2y6Y,(C~x]V,"aY>S L$B@_)$$$Y$B2{C* fBIM|rB^Ẅym +__]C]s[`$H@s>RL:swO @BΨBI4( OamOZ@ OI'~Zf~M6g!ٲӲO$<I'|f! o2a!!2d h ɽWɢ@!$S) )$ j2@8% $$ @Iz H =[$ FH@ymcOPr_ rxM;ufbsKwqWA|Uw#bSBONhҹg|&$F $itI:_+G`@TD}_:ƂGJ}k}J?jy>.'q$B=KF o;O Y<Əqk:3\H碰1HM@D !"@ Cyr{bI41;΂ HHh$T ºH~Đz'WP h@ ba!1T$'`dw3Pܩ4W?igJRI9i&<I~ac3JvdjXQED9@<~ GBcw2?D~fwY?9ciTdU>m /!@B8hw T$ 'TϴH $IC& 9(K$BA!$HE HO{~&Ƈ3/@A2(悍o1xhbjβ>ɖ7ծqJΓJyڲ@ynהlMEwB!w*Ť"E.tIlJd$Pyys1@qA|{n{K֙,2$يXL'BBi~ iHuxHW*'@ HГh~$ 9wm*O`CYBwLHB?a'0ÃxpY,s=-IB%_Ȑb H ]O>}Ҧ?GhM,O^!&7n=̏Y[Y+ $OcgMO2SvW-!@@B@MZ!c7V:Z/C>=x7J@=¦XH,9Y t'"Y  aIP}d2mqfL]/1/<_Ij|-H~[q8[.X(nABV9zm- '{?A^ 5T4)2 0$& :0;H$ =!(dWU(ߤ!N$K0 P6X(bcq)e$"݇apr5l\z"ږquhbv4&OXmTEgoo9l2$a@q˽/ZNY'Ok,Rh󽷰A`Şe@* S"I#( , EQT (H,O6g?-Y{sLԇ`+AVAB)^~W9vާ  #hYpdn}7GxhAܤtM,Rx{:5=3zƿU]ŬE"0X(J@r;gn(V (Ņ68/կ!e(&1KPWvO" ?9_V}g{ha҂UaͻáK}/dSigXa3耸gUEX7`OxjgD 5O :mg=u!"E,dILt]4tut5rηp*j2 *%1ɽV£k6sκbZ#~$U D #ÿr;Wrbݝ!*#c@Bg:E0gՈ-7ZVRMFUAd?ZGYβ 0׹+ y5W^05?嵄2ؤ#LGxRҫ WJahS[ ٩ =G^A8TH}#BQCF* N6c:@k33}%%#ZyNwFvŨrd? & W؂=A,_5+:cH szфl5;Dbb]9#[^f_JDՕ!Dl!(ՒKcfmeYb,Id}Z]k΃* CD,TUTkcU0QiZr6%DN!~<ŇHVW6j]yEiPy_){z2 EYIW;d;̤݊֗IP69`bZW|`]Vo7-X]&[-=OTUR{)P>plU)[urue9\S&^ (ڍiمJC)y38*i,)0PP d%$XTIb aBS%vs&eba 1EZX^m%3џeR@PR]%I,1xw9Mv(| FնZ"-?aKTEfQBPj8`z?kLl=&,=zY̤$ <&eО ]24&D׺%").hUiUnFVOMPQYA&4%e%4T]рGҠ"FggT(TID&wX_x9~&oڨ$gZYRruGH RAuKAu -bЀ%*H1vK{=bb@~skPTm~ 3&"yƄ=/}?:LB$FԖz96,YU*븝Ʊee=L; fM7U+fIKO: HnڠW,^a)QB8%"͊9y12ha[) YuGd±zfYhؚ0{;#図'$vkЯCˆSA(m/<0Ȩ0@̞1Ar 3ҹnllƠZaIEIJJX]o׿T^pz?QE[Qk4caM G”-(mjnOVCDw*.[:9uxf9(5/[,EA1 }FPiC۱bV.9X5&l&$=\@1& ^kݴgŶb]ة1 ţxJ OiQ·ՆlL_0;UyՖfE}=u1 qTER1 ) TY*2S< L!k;8>W›RwoPKǎT NB6>ULN1/97=ѕBJRL@H Z2H#tV *1p9ȟa9deY,x>0%{S@fYAx@e^/Ey<]RfKBJHfDh4"w7 M/ {{m{ݝ!>W;ijM1(/hH[ZOl\^conx@H$V3HF/σHYs~:'S#32By%[%Z5^/B b4[K=m̙.y5p2a;[8k꩑IЉ$t :\E zŢCWk^nD`Q!h;:BAĥ%*U G *Hqm)Ո LDAxAE ({Qa5P8EvujRGzBZ7TҎC!] x6F6$sjգFгSFfqvYq'4xM3"`"i0IIjTI5JU*L1RID[s)2F 2"W=0I ̩c(jUiu8*4ZQA!p uj%`]1OЋ%թӍDZ\@{)мĭDQ7IM6coO tU"59p_~, H.Tj_, 7mx4kX͍ú3vpaU:NM$xh 9BEC!Ny]EٽNF`󨾖֗&  }~xվpl7a=,IN"@4b5ƁQ!&?l^?ҙ87F֋h]nf%9X @PGN`ji& G "懳$&:>HM4,MոCķ>Is߰Q]%fD>skoE t8uI\7c%xͺ},iCqUBS>,hĔȔ4.\Я?Di+НsJr[UTvˆ5 ӽ< >B`[]&o_ I늭quS`9pF TV#Uz4͓[{Uat}'pE'0^LI5BCANhF6 V݅aˤ3=hTeI=IO_"3 @pلX5oۜ gL$( #T$ګљEjgIEeT,VI \1"b6kxW^dkFW(N}} 6qqpS| + sȱrA[Z bA5էǩ [''(W(w ɭ{O#Z8SG*VAH*%x6[oOm!B!Y l摖u[LTw.< 9`&. ȊeK[ÝFz5Yk2j/jYn{bVU8,\Zbʰ6Ib͠Q/'~ٱ/ +` G+ٰO _N$ H72Zb α^Cw|Zcb0lLiH@;!9X2T"S퀹2W۴0k:+5gG]1( ǭVZQ![",<-F@$xiT 8H={!"P'= $HHZI`Vτ+fuהIjo吿ت*1$n9cJGy/d0LUYAyIOiu nmP0{CH!ПE̴q;lM{~Md@&MU$#a(! V"$n/ßgz)M~?5ߤ' O9)"zT[zRËsZI5<4H4@eT=8l7H"*zs F;w[fd›BCCmbH˽8N2]/ʬPG}S·yС7)Ho?Mx}>޺_cqO6|BN4yUxW[F2BG!5LhkЧ`Wx c;nf=wY?UvuۯBXzJaE]Zo}sof0xvf.ZԸeQ?ҡqӕZ&V W}Tl|\7X_ =XU||_SEw!b+|u%8;^Բdp7{1x>B%hC~p6o- w+D G  %& @*\:wjom(vgVO{**qO_;Vt#Ofڭ,v14 VDLݎ$pd۳ ޟqT:Jzl3T%BR8^{\#c3_V;n1͕YIRk5==>'HGYdfߩpDz~LH"$q8tsh?wS+;*A` BƎ>C~d]o`R;sm‡_MVݜs8vÈ@J!yvãГ\wOoN6)!l;B$I?RM~γ|m2L3NܐZ7&B2{J6Ӹjl5`, d_6eEZkd5Egh h0/h,`H[C'KIfY ,Q$'@$q$NBR 'hR  p[rL3cyr;7NGuf~-BO5P>U $ Hau ?e G)i~Q{*xǎ%Qֱns/}o~vIwY6toE6a@HAxLbY/T$@;I)8HJ`(,$"j$e%T^ = j9?*_:IRH3ިOjljHBLMvLZ>` V,$j @ HOsszߺsu(@W"f! tjžh:˪!`"dP@sf1>bϕ\os@3 +VmDT#oPaZNI rϺ6FJz9rcnBA QrQԨD #FJVz_z~EREfUɊ vȢ:'"KE Fg,)k,vJI%r N DH*(*@M @PX0XDPc"H DAb TIY""hE%'%3SGa߷urʢH! >#.mݽvHk3 lcϦ)b$d !I"S$wpdO=kxw*nߵ{OzRlfƯ*I!@@ '{/78҈(kQǿ,]e72^Vt6Uˣ,mu^Wl2h??Qb @6p,r#y43u'#ƣ{F8LH (Pq{ 90##9PcbR(e>EH28T h^QgEA}C+==F_X 7 pBJ8l`UMU,^ܲЊ;@TAIMR j$ l%& KCMQ ֤l e)u)*?e/7v}=?P:}dӓ)9.E!Kǂxn>.exB@ B>#'~Vछ&c! +#.DY+8`CNB>)^;5Q;e!I"$<@!r0G_@N>v_` a35w*mfɺ"0fD;AX 0\ 05)NIQz1 |"q4:Wޯ~xGwª?h¤ _ȴ~g+ЛHF`w}th%A ^atCۻW{&ΓND /#J^+$'$ Y鸥t*alhf %Tm44ܬ#͎)AGגׁ) 5h\ c뢸kɒ ̊P*`0y&ԙk:zY_4<"DHIHD$ !:R&bޢ/y44A&g%b r 13j2 R1,E AR7%Xe7|uUr$A=86*h"@ "ݠFB+@n\JBAtWr0 P9bkmvԨo\>$DW^m]Ғ+űX2pv´] u}ܟYMxE컽=u_d=/h $mȴR 'u3nA$"W8MsYflO>ݣ08m{ ּc\vIfo9Z&)srdDl'jogg9E&P*@X.CE|Ɲ-T UKh/c+ϰR؏GoWïx,\A2B1-s7]jo_>$`U6)Ģ .BȥFngԿou/MKIl'f=K꺖qZ]ݼ{7q[eߤ`ZɁ*(g_ 'xտk1Ps|8}6$X>~428 +kCā hb2%'UJfwnM<~tYҹ.%c[Eԟ'~]ݔP c}ݗ ;nk|dOⳍq|NEfe7cXHlsF~}0ǐw4Ld ^:4Jh@;FKRV;hN.z@RS9ItRe􋿂,6ez*?J(ֻzv,]hbRЯϹM$Bf1q}f<1)ʏ {TxQ[mxoڅcJk }=T%A 3$|eE?A^x/^lNgj\4T$Ϡ~_w9\3#J6&lRWة#q>Գb*sD5?5=Mݥq8mrHfjvjq_JZI J\M*Nл CG^E$é؆sIoZPεUbVH~V95Rym*j *0t ".+ߗ4琋沷z^G-}:)c14_l~i  "A@_T B;{S)!@ hSRMN%>*Yr񨎼D6lŪ Y$?RCҤaXHq~6u:XlپdOW9 ֕cqJ!>RC(X}'2&Hpt/}Ph/\KռWݳ~\iS7_8}5$ ߋAݐ徠L %" {j%@D$!3yH( ăV${}J~;"C}8 L`B:x mFej7CA%,^˗~OB 2yUΜuMZ!`#!i(ma`GC$ {^ lw+yM[!_WzW2, wGyT?4 y |6Ȑ> te:Sr)4pINĨn2`{N2>}mP8b 0s!Z0Z01 ~qBy$Ɵ>T% $2-k:5F>^>#7? Y&R }a;0m턀 3G{C@Que]]H T;_6\oEks&3ϊ}k|tw` z04ô\$l(ID@u=ezéd H@H@Hǔt, ;M76YMLMƄ =4-"?HGYrIj$K uЋB$X}ZE'''d%?ɨIHBH?$!v`OP+~pOM'y<9Ť Ҕ'=$$!iqa]8&$0U11`%jqRTz ɠWuރ~+$UC,O`hjOƾcPA2 !@O2(_}ٚoOҿI>:@@` SIJdGJ&ة5]$XI/EbB8B+?iY*])1տ~!PgکXR^: 1>5EԻ}F/Hj3" 0 WxDn>\f$Tάםd8.pL ȕyEB겁 <݅)ȥ5*R&[Mr,bZl,݄BBW> "Dr}ȥ@@NaWbw{V[r#Չ.)KJlf0ױ] moa\HY, \zک5$^I{, wk&npZI9&&eG0BpāP(=IH'H)S{G'G2]˾jlK}Ē\ȉBhS?;Q 4 /Ӡ>c4M3 ʇ=0}@bLShJMȖiA /u*K3sڷ*ݍ(=ÃJzt`\(Xmxui'` _#`l2+1ۢ[ JRUiD!(7ݷTX$M vHaDg7z d݋K}C8$*O~]rJJ|~E2 *?ВL2+I V=!pA$WLA$f<>nքN@QoVjy?jkW" @$w[ ΍Qv3]/bݎwz|=3IC%r8e dv6$,;q_#]Bɖ [;kċIC3*~i9ۉv$ ly&Xj+vpsAJPvLJQs*Tc.7%s@$vʾzВŊQs*pFdhfkJ*;gv'qLc-'Ndeo~,*ZIDC&=a| 4ykH.ĸ8v ,}N$fmdr>> 6uO޾L:Oš2lbSxP̖cJPD2.^xCG B+i2N56.xҋ|E/&`UPuf1ñZU?$ в43ZF$Y(gPx+]zSy<ϴ`$'|ܳ )>V a:{V~s/kC*ֺNUmw?M ,ʤ5hwi>|I)fo@UZjaji,_T/˼mZVkBCeUO_\_>ӣ&} 6M}t2_oɂ};崚 ^%$!&B'ê NWeR5SV/5y$Z!gؤ3dI&BHZHAdK_'2P)+[ p~$>70JD"E4,Gt> n3._fXq究H3p AfdH+ܺG74{sJ_{?ͩG>,c?#T̴8iJPM4gTKnV^sy}ib 22:lv䵣\U,|yhawOdPt]ݠUJdf2=Wd7]ԩ=AQpl8 UIu)h㸾:¡ Ӟ<cw.s@2؂2b6Q{Ũj .?+뱲c7{ֵ~cʍB / :NRqTGDh%d}E01e&e{ bn \nz%K޼y7`6FE sχWר|2sZIօ-jd 7b~IAWp3H"o_؄G՟ - +Y_jnX7$TG9I4ILJFAC{ٯ$y4sRx 0AϟqDU@ C1|A9CVM2See{I]fY0Oȇ-UY,G4-nKdb:̳F2_wܛ n_XW8*""zkҺy;rzm ׿s6R,}(H㚐Q='Se򬌨v!⺀^-D1nrp5 $'!Ze3ؿ31lmV1dE+f1lcmp[x QV ")vz2sGAMh[,tx-s5ix@ײkkoFwI|,{Ou[5~gS(N DOp_}C'177}{{"*( EQbQb(PY`(f]ChwvO6^b$b T"@AKZ H`@Er9R(hd p|55[{j\P~cs~\.vf$2_O/>hJN*gn] h<]V( b Ȣ,XE*[Cb(@,"hKc^Z9_nn("EXJ_o>~/hPQ|,E}ɒaJR*o۟.o?OH$nAǛOS&EIZ}Q3& L]nX7euXaZ$*ݒ!H*+ I]ţWNp ZZx@ /= Jy @ )2B]F619*qtsl0E[=/YS蕒]py>bko[t4k퀅1/ܯwy5r  q󷧍0Ji]w\؈5P91y Sl+v zÜjG0muIBv^,kr +fX VGX05#Y 'P朻@T8Ȧvx{4 jϟGoSYy0˄ AX*2DЙN{kbVyUiYmv->Xj)s%2 @@?O6FBV35Xh S xppBIG>Q%[|{*S5OvKSujc˧hlTG$J٪ThbӒ_dJ2;c1IşA) d& I=_bzOPU|D[msZ ״52arj vt1.$=x:Y܂LGIvI+$"ٖ M8zxT4L["R](;=!AaAK^VAY}@E hPHZcHj+4 3aƷ=Vͩc '$ syh͙T`Rʏza{sGɩd'S#CO8]2)z-8 ؈iYun.Rѻo6ٍ?md _^}khEALs~^d!Lbd7POn d!?hƻy׷WȡG_8+nޭBن5-pO=~/ԮP$՛nnl[e}y\UCǐd١ҫά?$$nQc`BfЀ&M-6uQ;D (k~7C[3R v`06IR&դ }S>I&]f4e [}_U~3lY[iN=mp$H)aMk0fy:E흾>fkf@@Yg uBe S)Ak \~f$?e$vkZYB{'hHBI0AE{T-sTcˇm< g!Ǻj|pd$O/ WѬzqWiZxܺŇSyaIm)q7P ROhoIJD$yjV<}l}>t8?Ghh壊~f/b} @,V,>vIvWo0_q,>9Q)0snNv ##>R$t`#ʑi6X!-*/+ .C5ZegIHQda2N2Ad$F+J`T U?Ѓxsp&!(N,VX6Xi)O3_jX`B!,&ձK uW#4vv4SDB mKpgIq{s>HI`@jZ\v,}} Z>{zG *@@#챧#[PjP*}ĩx=c/o$>G35vc-%`mkW BA $ oA@~đBܷT/jS~!]9h1eUk] 4A~_nvL`2E$P/N 㻳tNƿـ(le$x.{^Vut8'L莃eXD< -t0h2" _p̉7Q2T!"RHTAVH ŊH"0`+( UE*gIxX[#{ŕPDHDj4#/^[ةa԰~dgصP8/jU?H(0Ab1b#("(*b Sh] ,bցޢRZ|d5 H!uQYP{LԎ/pÉ_ZĹ"⌋7J5$.de, + !?R} JQ)& VCEegjJݷ6,CvܚB kʀ\xlK"9L C}NUAQ"*1ײXc> N%dF̐= j ~8fsC::y|e& D1οƝּ{\eǖg4$#aAb(Ҟ/F~SKS.3ѥŒI ]K[g{~JHho' !MZnUĠ;QT4 (r8oص GhQL&[0z&Ա$B4pLxd~n?. Լȓq1  /!L!S@aC,4TAd-'aJwcV ;u_hNN{D+Y`4 q$|z;qI%|*;,vHಝsG5PRix)5VW%@"x.YT> @MAn'+Tvަs6l" @E*PL2j~5`RCл j'K5Bj)ǹReJvNNf},<)Kߍ:)չLU%ʨna(ҤJ[6 }OCDUֳv~9jZO]&@BnjƓ+$a/ePRFX8ngmL {ǯYI*H*EdHG8C<8nL9h8|.RuI၃MY:^h( 0P#1XA]Vut0:N;@ TH}UY¦5(v]YZt릫ٴΥ XfB%qPP E䡅Ph6u0.)"<0aQESuގ/ Yt*tt_e1݊뾽g۞Nëa^`uҭ1;Ntx^_P?wUm71U1@[ Id[įU}4̀`JH&T͚*(PأZ-w#b+/.8|+ۺ=@)/=2 ==:,z@WDsAI/c|f~jgrs 3buV\.miy,0FL 1ȫ-u&PT (B) H YQ|6`uD3!бЩkbb!E)x_t6uiX wIS|(UC84ҳ@\wݳly Duvg$4 vqq)S#\H1mU]3#/3i33 xF`$"qFn9*k8ɠ=*2v'fC^$&V:<'p[}$3&!-Tz' j+Bru%oEp|)B)FRK0CXHm@va8.D<ݬǔgx1RwB,H:wrW E[땝T9bVZmz)9l5%2E+VH.d@[RX*VMG 6.#V &"dkg%}3QHR`gbKXtÍüWE2 RUPčboUbKnb+,`U6n@jH0*L;T Lp^kݮn%þ@̌@ρ6QB/&)Mc6JI̳ ! @2ץ}_LΠn.}SD(YgsA03_5tT%5JBHI (1^t3ngQ1炈ᨊv4;舊4G(L10V%/JӨFD Vd8{h1z0Cx g&sV 8ꂏw-Q8I0D'}_hQIO=E2&ªHqʊe:]l7&C.\V& 2D5TĊ>4KxEpH;A¤jILTe]B亡LLL2 |e+) l?.PQT4Tעֈ%+E"uN4ĤbwכwM6f5ƹBML" R"MպrQE ۆ-Eq$bƍ*aA0@BKl~}5~οF'nvUAcکv#뗏GrM܉ unH RX쭺tg)I,l42'Ϧ@t]*R,fߙ8lmil#7&eW5X ^hhB íjШBo昳kAfj0?/uAiAf{8$-AdWaQ 3},6xP 0}W!a8[^O}JU&Y+o\s>/^zCINrvv@N^3͂iY>#!XLnTnq DaݦwO.>- $mP OZmg(Ah1$԰]6p +=DWsh p}V „/}M͛Uw@|p!0yo0F 9<)/%L ҟe7<G~2w|A59t g}`y`a>7oUFlZFsb9U.b坪Uk̫.1^R3k,ˮ`nK:l[X݋GǗv'w}}E (SenYŝ Bl *6t]sI ?knRajTHZ!#SOkE5wZ&??.>jd '~#Xq /~_x INEPD^ [woµUrv7 $ʐl$iB0b"F"adn['gU k%g4-JИЏ hHPIh@5phpkc$ >!#}Mb:KK=WaIMk[F\W7wnu?/=MXl@mm@Ro%B) 0) 9t5hO)La(f)rc!UYp! yEoKO!":z]!L sN_{(~ct$b`գ7IDQ!w@l$RHaP+e$ߓ dŷ/u>Ë7؊K;Ji~ia{45`"AU5|]՞MM~ЈT^}ot@&CJ2õd|Ѷ xDwK6l}8i;֘ɷS%|@u91`$tbLҘ,t1Ձ[[%=Ƕ="1LGK!I^$Y>PttuϦşSvfoS IJFE腞r@~$D%ބw:Q@?rgv}.Ϛ`g!S 4R$t`|= A#j@T 6(FTҫZ U *DF YOXV؞VqY]xkhðwDH>BU]CK R>;[|̆Ϙ.EpF {R`2LkOmEשlA>0UWK'cw  f0 ;@bݺۺ횥Ehc0l@F/`Piw3T)>&f?=\KE|rP@C]JR BJD .dJ=w;ah\s _LRGikG|NOcȻU1dc>Gsj:*` 2|Tѷͯg1|J4|RQǮ=-)VfSiTW&ӺM3%N E>.b@ۧrA [嘓|2K bsD>.Ct膣*JOX|z3]{d&i$KV'V >ÐU,e`rmVa(-6!& D^{mKZ=9ԻI_ÍXTrvNo59eb\Ph 3c cUꧻxQp09oz;x0hψnKys=(Dkv!5v;'?5}ҝ{Ȼ H.k8!dUD$v6:kP A:zGw6oh%Vdլμ" X +nW *40PS/<͔G!{f~^R;VI̻賌; E1Ċ"$BRHFՅd,llB.P UMR>Lo$rPûɷyE0|iؐ 1lE9~bLv#<𠇇Eu>xhbThŠ\1Gs8K^!4Fvʿ4eiDW^_v^B5B"<~߰I蒐YܴwiQ^bLV3g~>rjZ$x3?A,K)=|7Aŀ4D!(ßPZfT|,*DXXk @U ﵓ 1ژQNH/Fbez?UiwZj;ϟ<1(y}a`m<] 0P`Q;H@UVpՉҖ B5|p%P˩M:تG2y>tKgD'B(7n~[>OheY&z"[S!᳒T.Th2㘸yv"ɮPqxIt VH!kirp67j?{hYQ91G0orx‚<DY"h= YIV> " >q.yQVBB6j.bEb (~!I ˰o۪Pl㭩3QFٽVt*jwzeBP!"W@za5U@{yF_YL)*7bZ!9 8!=O7B 50KNh/ZL_ 1*C$OU<2$\OtG-OZYO:H q.K>Q,PYg@Q^/i7䒼%;#tS@RIǴ sby}v%\A*x QɉV6ASVsAhL+ \u1+*"K~&펂dNy{%b.Bh#F*Z~i:I~YTTm;"$=/Ke0vu@Ik$ܕT1碭ձ !iH 0FSpa+<$W6:Sv,* ܊XOi641yH6oe_i~[DU >7콞KצE_nM:tJv}HY$Y~ ֤ӳ76:I(Nj=FА j[1 *טiCFO:gu Җ5_[.ߍ?7zWC;i\i{jo>\\϶=y߲ARh">o!LƖ#ӷ>BS48|ߎz_Tڷ#ž&Kjdzz4 8ҏ+uM =<:YȢO 8佊|ůE m DUR/^>!C7/ -]m4٭u/2cƻ7P$g򾧫R^:JHM$e]>41oRf{+bi$ I~I|@0HBD*W|{+gcwu>._heݠ@\1;[#:wGKF?gQpIR|͏*967}}hK0v[u H]DFRDե-r8oDLA<)@dpSGr5%a#s!_Sޖ:Eʺ}_09$lY'˷{<+dM[jx~eԛi}l`Vv@@C(qI4)0WI5sk/.44b[+I(rsN;ygҜIi]sSH$lO mS?'@1W7h]i;%} z}voDob^߹HP9n;l%| MFh3<Ώ{_/a(=>q RD_D2A f8|s먗+^;˦N؍Sj{BĚ=#e?}mFucu̫N?Zateaɜf%4j^Zo|벘~dOS?l?KDTE"{o5ix$ֆ6rx?`?#gݟ666`4>g&5`Q{KJj;[+%,EIrH `mzזD3?WYn:ѝޯcl|=Ofi%b{Zҧ ]^%)22!B%T q|hh' p՚6{:Q1F*[q~;#rh'tuzd?!6lϘIܰaUIQ8)$^  Y!%dWf<$%x\*@!<\>] sPED|ViPvQ!Cd5">y/^q,ug/_`OUm %Gؼ0ZY~!O4G9bZG}l͍mipYV<8@Xj*EE,9=PDN0)xv`5M6f|EI(U:N*^[$#*SP A&Qc֊,%kEz |'0ay/FJ̋Q%㟍+)L@h\HY 6}F~D{6F3A%m܀Z5}_/y ˎygQ, RHE==UE|9OJYRkadcXhyV0/`A1>JT @ HM 簥?WL{H%0 +h.s[|pm NWU'2t1ƣZB2FA(J8(aQԴzιF,bJǓ%cYJA OZ6ϦLP{r" <>RCzn̋/]*v;~,QT_76h-FrKKhrOS\75$΋*_RU\J08? g`Q%NK~ﻅK_?: 3C Ɖ<?sfF^r`=S,ؓ.Fs}Cd/7$]]ya$!w>+-}oeOퟡMy#RErf_ΌsS=W5U.#jOַ̊ a-xZ8+BNzQ[ AMzHyM(h.t$•g9< /Y#&Tt'$$.#X3ݞx{L'#oђIIwsD 'Cgp-KHaFI5vzn\bT7wn{=]"E"#x`! `1)NPy 4CF2[~a]$9bT!M্t%~#z./}`h}*gj<+,o;ϹО`grE;)ORJs_p@k?Y<,ç?/]xtz` #+?ՔЈvA)h_suF"!BA4HB$LJՍnDsJcp̢^*$|wPP5w{[ YeNWSf??Rj #)H. !ϥG[`Ϳ, KO]CnjqѵV57NI< ',qz#IL '0OYM3s?].^Ռx^_XM\6"Weq iMI]Li?xw|=0q/[ l+nmvY+֗ ֻW/ޞE&A)XG L&b!:)4^ORt.L{kTI$PBx-K&Hb4)}!:lЁ?_\\I$A"#p׊|QቴQ9ٵT K R)җ\"_!zR(ԭa`ZQQh˼L}:e #*I:lݒ $dZC"1yb*jВ`m/=O5{ffAaFQ(| Y-1y?ϔ5$R I^JwMc"5\Lla\/ ~t[aAGao~'-a/BId29CMQJT[6ݸk]PѿKV ;ꭍ쁮X"U79 {s_A ) *1AA@QF TPUT EP"(da*DUF "E0`0b cUQPF"A*"Acb bE`1()d F PEV("^f:1o-B'ca'?f?-˹`riȜV wlIuQ[ 6f [?geF=f~M)!zۆFq/n[<ޅ>a+oAA~$lɄ >jT"IhtU{{gq,r 9p"""ǒP*Kԩ LKo|nKF)JɲzLo!"PY2+;Pw SZ/}d9ʩQp`}iڷ:_?!Gc/a gqy?('[gAJG$GGශ,VXA9up5:y1BB"%/' a߄=[ IǚQGZJ@α&pLs$CNظz(|y$r(i"?Ne*_kV7kg@b(؈zOdܐBǍJ$ P);% \I~SjR翸vRw%Afphs{ P1rC ,HX5B_vVcmtظ>fj[hECJT $̑.Ɂ;Cn60M[ ƀ %HeS)34PT@I٭1,S+#gVؔ[tLϨi4 罧迅9k*ax4.LP8KfVI/;\T+Y^e|#eH[cY ( }BEKyTZ0pRqUP24"0V5TᾷH"""5~޳ve*_hCzWw(贸QJD@c <~W'6d E gZ8Eko],ra)cԾ>Q>+)q&k!)!"ȪL y1%P*2Й7bΡ]Z eJN)*!tdMVxFLN%hDRC/żur{. t5<;ʁCγ :{jbI8\J-2[6I=<~_!:Q`*J[X6`=H@Q2Qs $ R 3I^ÿ?X_'|T:l5a!*d 8 \`?0Je Oc;KdUY;*D_mnO#  !W^@XDB|˨uKir"((9ƕ2zzJb≧TS&F2 c|J>@ }^Ma)|g< }þw ̞{b`@e3?손 0  *HK {{,xm2>tsKu?MDqF{&Q ʓj}cg󶴥HisQ7NL: !!ȩ܏N;bŜϰ%*B}f{EُE%E‚N&砪 V>ra*@ɑݭk?z4 U#?rlTT͈Q]*(zf!hAۅ>D Ȏ&`ރyoe'E (4htyh&Q?! "\v))$HOij~?ߟ8*Oy;+ƽvlSpɲtΑ)p0'㇯< rpD^DEz3 7TcͨqU $eMW#ZY~5HN?#Wu]c˫z M:5](^sMltSA( TP IlM߸7zEbGwNj使ʙk?pa4(h]FϪE@[!(BPe :ӝvv _F%H-$ryVTAe>BmT,7ߑ_ӒfqZQٯjE#:*sNOs3S3#nhmZ2eZUu{=456ۜ볷{Q<%RdĄPX[~Dj@=K7nҘ@RI"I:1h`^׋}*%#y$!JcJ=xԺRӅY2l|? ܏u}5eTU[܎:kWp;A\H1f~Lvn> 1Nѣ"!lIeLgjR7ˉɊ&%e&ήr+{-4T):y+ rN Rk$/s3azRV Ey,D8%?^1 Z;KQ"  Fkq5vl@ڳ &{ )Ѯ7ߓd73o?,kf G]q ^Hgippmu% 39K |O٨ܖ\mUS'%h[)?!(sgj$\jlZMvxΊ:T uGX}8XA#~d:1B?&kG) 1G;A$qתyZS/^AFTʛTa ۫غz@_;Ɖ"B1[rtٖ^>9qQoEDZlX|ϣd Ddh$𷒐Hrhcf Б$!BJz243򽟥7沞LB(P}jCRG?V-|_@"ԚJN) y -r'r&$o<]7?/R(]hyV.o{nn=g'б_lA`GM*1xM њ}yM.w˂IO2~wQNoH))zSJԕ.g|=%gŚP&I,U[!0_ۺV@QE;(I?3?cVҎ)7Ϛ>TJ_Ou)Rs~  2?5p#aHA2+!CcN(Cow;˩ӑ-~p幽8^ܶ~IXʈbON87Y3j]x1207#&~B}=.XG  \čr!.G A&zYX`]2TfSr[_>ػ1V JPW7|%>N:/¤AHrs=^WƑrrl|143*3 Hy=}Xv0kL !Z:mkI[ct@4P8Su>sۻȢ/8 9\k dd$šcATBOBʄ|YT)M^k.i( G,bԁQfFAECh $ҝoq΢,Bs-Y}wQG"4NU.)fyg(lxCv箷bO m%o=w_mԑIo,ښo=p '9M *&DcwtcȱDžSZky""+$^5-=,M'oqp)J~ĽKkUK!W[< =k+UAgԒwmw Db~rS𨬡 h$:RӅ?S(@?\j^C4:wQ7פC1b^a||9e#I*LeҝU^e $_AX=8v݌ ޜh' nrgApx~{=ƣ5!ƉI Fk$~!h[luH҄eוj#QgZ6zl8($P" H(ʣ7uci PC~ )]\2| gv{Nc`АL U .pZ+U6U!lYWԐ,0BUIDK%"d0 xܡ %%k[>{xT72 r:\?VY\w}JK!I B\m obCж"MJ^hsG`\!I:J~ FD u$QrxY}ٽa"ԯcBu)oI^(=XQ>5ٸCPmjQJb;[_k 9 8,%0fW[:L 4]n\Dv0*HۈKPGٲJMsS 53lUԅfMc8 ,'1JID9#Y$V_ -KiY1"鼡9@]iT6 %%+4IAS8D|m=xPtw#ͻ.uiO_ViN.GVKI= X8,N_jˢ>e8;|"`ϓBEDhSaj'I)^F_&eL0謔Lu?k׳kF~+w+YzY?^+I< 2a#XL+3hݝ)7#z)"kpl-!w߅̫j kp4YxP!A@!/_'65j^iz䭂|YEo(ZHػ^m'|lf'j=H)dǰ' x]vDś:*GU8*m3by`TPKe"'T:U<$EQ;;|.;HKP36'^FHlql*Nf;뺣7ۯ&#"&=K1VPp|){UPaJmW]<4'%[DqOK\̪KNi'?rh)tR}KVInҫ2=-n?筁o6NqZɠ%e~PU]GQ0ýJHqf{ѧoUB`Ғ}?4`%g֬RB@nǣ_dvtгJR;/瘽z'm@I>:TV?σrJe_qy_ځN~"X/FN9 }:/>pz>yRCsӓ50ٙ^ W+\0$M Ck6U%:i!jZBՖ]VamLVzƾ~AbwF]q6J0G0^z`w?ZXRjt @0;*&R9R+l7uaEKo%W~C  L|smU1*ss/&VwOYgc(!͆{C"K3___ \5)4iQL}Os~Gӿk4N~t˶fN|/&axyjH@ ҉uR04J'~Vn/4o[\hog5bz{(5tއx$ jN-4UZ5o`Q$6ÅG.wG{ަ$Ħ%`?0" qm3IrGO- V,˘Q^ǦY!C-xY+ .t ,$agR[C\ G"tE6נ ~Qv"b`(_XGTkL|l&L $ޭF$_n|\,Q<h cuj/!@APd<ǗQ4gw[6;۬8#d3AqѝeQz i(5H{v8S]g[r~\=ng،wv.R"0X641?ThRIg2Zk-h#U! ~ʾ @t_vxN__V ޷6?/y#d $@j>$jIߝn_GJxt%#R>>a6nW/o҅ [g$'8i0ID,5Fôz۽ fzZE8$%̐RE@:ѧ0 /u[bxۭHQL X16ӕs\P*t몳]kŃ6E"50+ӥ,7s4B"&J@Yns0ӱGWyLg +s6BlbzXѸZ=Ja@  mE"UҼ=68X=`|#WN~w`ng| &:>Em  xJEW(uj`3LN65 aAX'K1"+DHipQ9 $H+az'۱Y63Q_>O!"֌d8ɤy$84M"3gʿ_MZ",'xӇ|e'%і’+j;/*)PO3 FgsnuyhQ`HڝcハMxR.1n#t̶\-\?ľkf5zߡB\΅hOꗎllL=\;=Gx@˶oqt7ˉq ;sH&U_@HD@kNd7ybRUHc3cS$yHU}? k6%gOepS03 4m {} 9EpǁzdzbG3ᧁ7TyD1}7֘ XUTXYEJRJfD@ `I7ԘLjv:~<]L/r3Exa#|0Q'+=Cq֟@J_~c)S2ai6c%E1-vn zlP$Xsm-PĽŘ' 0M3ΖzFE ( EUH(X(*+աPPD DZ5\1r5AB d`1,{fhܴ47d(qA; &.YeN_uC^ \7 6ڠX'W A at /٣wT$hXV J{@##J*UO겒话Z\WZ2 RSݲ^jn b0QD)s.-hv)dPv0K0 %Wܠ (xucH?pHL p(骒:LQc$q#_dY0dFC6y.- wE3 fԏ́8Q &30h5ѣ퓯^>0ē-B :#ʅkHҗq8C!h#awg5#j$0BܱL /X@X%&dibqȢ )뵫LUQC&M. d7֬hL /"dܞ_mpJqZcϷ˷{nwc;o Ɲ$].#[1]kD& $ Sb::=w6Y+i໪(B8Sg˳Ue5֐{7s*3nɓ \<*9^ѐ h.:&L)ʵfgSJ*ȻC򱑡T|@O5"_F;*pXَq'{rC5QGT,~ΊG)璁7_=_hMIF1O0X&N)XR3# |2cϻ|:aXR>cyP#;f3R@8hcSםx[m" ufGN_"4H.`ӿG_w>(w ;wz3lt9Dm7-| .xߎG P$<~8\PtbeeTiթ TȑxcODZԊVZ_ьMQVy)O(AR ,xuҐ^\K!#!>Z^f~yPB,nX#ZDe{"Hq~ۙ fy̷,^g} YdDRiZj5hgq ʵ7/{C@R}3(vndB9Z3l/xPGF_#SZc)=`w_<425RXWu7p %ϗcS_ M際Z$V;K̕YѻW4 \.n#zm.#Il~Q@sIcK_:+{_U9lՑlsN>h;uoVjfa冫իAX?fژ<÷#} dVhb*|#I(?RZv9+9%$.56hDя?;AiO ԰s=>JG3S!hتN_jh=z8mޏ-}{)Ŝy]P;o}uM`fp-76z*x,v{yrQq<Vk }38@F Ȑ&w[jWK QLԧZmx?3y6=*8 zћ]_bRc- wKAPAaK̹zS Q> VELIRW`י{a.yT BZځ *h#_kDfJ ¦ǫp_ :CS3UI6!@DRjY)Е!lDRd(A(U$&R^:ُiQYUr RH(MJLĉ H6Rc[y Xp愼VB -vgqX5=$w9LpqbX;J?ŝ~]=#8afF) &2{^&rWo7GvQ8c~C۝=N=\tj<2k+5;R3';=|k@WuW|_5b1ȣAepB2/Z Mš N. H*{Dts5f31-x?U1욦%K"AeŲPQJ pM6ǥ,/d朁(Ok\刣ly_'>f:fd̫1&aS㧭x[wwOeku8' uzl6ef lfhg+VQ ԓr6n@K-V wdln ʬ`Зc87͞ua NRn+bA)DJE 7uob0Ox%Ok~~ZjT*0"VjYs8C/V jv-0U\h"B_\óYO8g7e Iifa_Ǚv#T'lT=T罉j?2>! @H L:}?sSR+.:@"_zjCZ%$$!PL)?hٝ9OӐRbʼ^SixΠV1p.a Oז)̵Z}*UdCY!V s|?CG^ƴZRן=& ??^J Ix29gMENޑ5n5Z.qq7_5FoϼT Zҍl,{>I *+U=f)uJIRz֮ UB#z[fߊKo )Oud[ Gr_+T"=;p&]V΅]¥_S=z Kgg|#cJP!n1֢]D[%%X*~UM>NOM/_tN*3p-vsg}$Gf b -s M Uʯ Tػh7gB,L;0Wg!4" U,aQ*,[5eܓHׅ9Y4Xx4 +掣Nj'~Bxp&~)tdEf]`@Q9FTt*k'?*9^UΤ'rWJ'Y KIV=h2Pd[$7LtIw.;GĪKǡZME: 303;ccGU*Cn .@CHH xZ!<*4}РQf @{3?"Yr9({1c7'0]XwaG[c~\~/Wt.H;Dg<*gZJ` qX||Q ؀c ^0uJ~\n6 "aPJGCHEe<}uȎ( em/Իq?bʄ=> eiO4вaR/{5ܢ[d 0  ^ŒnS^#c5H̀k]pK{e=jKBlMԐ!ZF1Ͻp \|kNhnIe*ENY,<꜃i =>byyz#Dw !Oymr_ߦo?K$chNR]*0Xe;/]P@SԦ?wDTC`b8>y[xΟAR7Q>O[.-`l|}u??7ȋwHSs oxvCÈj'd:c_n\wp\E8,:?UIjP;UHf1aKwjZ(O//գåovKVzc ۵a<6FX7@ykCyc@Eݘ< ehܣ-rTƚFy1A $=j-`nk$+7ef !%)8sbvLuaKbw0w6r{Rxăok侰yk7%1"Bzv &CeSSXtP;b[K]|{|{ yv$ ( ~E'һް,72Y'8`tbM ">r{6) #ӹklPN],{~!WIeChpI]#(JRȢ# .)fh{:3$ ErOn.+Ϲ\o9>>;Fu)iL(YzE.@Jʣ ơh|Ft>8(r'!]6J,3'eLm YV"-ɢVp0@dH Ru[g1t)8H̒x<- @X-3J¼xf¤`Y\p?mqͥ4$%).EzZ08s8Ij՝.p원82(Rpcʼn+bh!Z]x⭝KdHjG=I,.Q;Ux'5Rh!UےiZ.DQ6}QJsٵ}/7<4qV+_>$ϙ&~D' hi8~u X5KڧH7wAc[3F,U@9lM|/FFEOL˹HĖí|U!8"t{f [\hu5 mtUGjxzl-oB ߪ<'E;R~)%Ofе4vȉJOx@"F=>8;2K9KDmC~/̍6Gm az9=/i7𝾛PI#X􋡲BaXy^R\^^*}}!33TKdp & KN i}](ثɢM ]&oOKC &G)p^e%*mZH?eP:%R3,a'g<[ q3[/x߿yK7Y N>gW[ı7bL _'CGXeR[8FӘaU",ѧ^5OR: &mDIw958sWQ7n,_*UIr9FSѕq{h!; !H жTPǡM=LCD%LU|q2"ff-@05 5 .ҵHYxJ(z(B0W0)$(MV~C1)T&b8[洊#`v|zׅQ6aܯG/e% " YQ ;確eY%*tHsp=9ƪ)3%OY@s$zJر:v%ڭ>FM%:sW\Js1 i+%AL7UgG^9_EEP^i8 gv'^V-H礸)Y-U#{@]~[fm18ųd_ "x$73`r,E|/xJV fs:ۊ7EY ڗix+;wuƢC#Iq%qTD6 @4&c)$ BQKM1ފjX5`֗N:Qj$'/KMYmbzCf/ì<|c[|!bW#Oa9 PqS,9@=c0wd-xjOqG"Q2HL̜TZ4;%a8-wqU bE8oLHؙM_U|!bnnn)oj@-E .tkH_V&F¥W,L4S$xbE:*өbK4 1&7 "ӖAUSqFh?׈5$felltVPg 8?5{[$Ofd&lu/i~#"LxF6wu塗y.5ѧ+ze\NɃCjhxq|H{4Z:t4 SXXWKLg^2rpP֘,2EX('kº4?u\ V%cRBg/yj%=v-hBRP96~N>^6pY\vW&Mc U:ci^MI!TSojc_傉_VGA+m)AڞݮsR@Kɀ$jZeiҚ%S fsrAi-\lұvVp8{臒jI)nmJ3zת[j"d``öۚâX$}+_ھ;UdҞ?!ggq-|2n$zgkNJ8輚^ٚEinVK+f2˳Wx,\{l_ $BY{f3a8$S+&w/HΉPuYdhJ1^z *=}JRO>ittOQ)ixA ZuXj 4 Io+= U^=h?۞َbyP҂! ]PQ͑/M="f & ?#.]kFcxXM7k8&u H[ya=]QQ.X<_k + 0ug_Ȳ΍DNJ3Oz2S@Ѽq]S`/4 l0f]h.kRo_#T+ٵ Ⱦ)>&^%p3psY{jDӵvkZw6%cݦgo`lpG$[Go_UN^g?!̮֣x`ÿwPI$OT’#:Z:Ι@2_"31pEM}j=@_R&YmJ/*6 "F'/` vs?7i6C`l8E"ṉ2h {8n{Y6^zd OlGrG:$q2#EP&M2.Z*Kv!@;uU}*,PKG1SχU]C+!:Ke/YZz xֹʆ "zG^ؖf(uTA9XY.R74*jWOvV{x{`m5~%';t女'2(3Tl%9ljU 8Z*XPI PԖV=>ɏ1ΕӕpJ!$kvAr(<^X \% 6(reحUM^nf VY3 7K$鳟=rZm/?6s#sCv`8ə'[U/{/1eMf35A'&T!ivvrZ ;ipxny,>Z{Y>\k Y:}T1$)Z3Jiq 6,X֚j)$IŸߝ$9^0RA#\*x2>N6`4DŽCj2Vęf[^ v%jWV2-%>T{SeR^I`yLO4lw b̲u,̀{ZdNqr#V#1-VΏU9WF>אT@S(wAPx񺙨C j[J}PҋғRԐ»>c=>owP;h $RxXH,x'*l?Fl/HJ^kz\{ߣ`cH#oԺ9f/iVxslk?m|Z'ȂK`#$%MTU>SwW &>&oɮ&!W]N?~_'zhd?)KXE{ "ݘHɊs'֩QDTCNW^z|{qwѷGu+k?cUIr2i'y]-ʊ7WSŒ_FO۽}OTI쎞Mվvf}CHkz'ZR}4Y@*2,0;?3>͘ZgqZbxtnQu֚Ic3נy<C?h[_=8\t36rEFF)G?{ʈ(хT~mۜQp A 9JY5T3o jeO}3/ŀGוu#) "˻C^}/8t~Fw^gǞu9̷Px$Q)XAEѪkZ&RA` 9J(" EH)"`#N*2EE@UP( H,bTHXE B*5~A`xY>_/\=^J&9NzS:6@7MZO>3yh]OUWD Yi 3V-y'r#9;]!28ӝC듐TVD,?pUERsx$gaP򆡉ߒuk ̲~\Լ8PJnj$K5,iI>zڐgj  [ ݌REWsޛâ6l:08q[Pԙ[f'oP1*"br!m}uY:_H𲷗ԓEՖu.m3+KLx4qGk#WWPp[_ac6 -9j1L )5vqj`Y݁U5siEFԡ*{:Z+z^*]J{H%jH& YZ)YH$T,Ml%s7I/=l^/HTwSiJ HVrߵfqm G=ir`ϼey47t>aw7|2fE[p` ElI7,2j~/np+ݘl8Њ,)0cwqV$y>gBzo4G[\pDa LܖܤUN $ ( a:L M_u'{8i'.gj ]q _J-HYEYJ=9V/5D.3w iKH|}~.{ףKԜQr"9xq?E)f畬HA%SļDdSOK:/F0Z0 'J4og˄TVO5)-j!`Mh#5y 8C囊 $ˬhҐ@\K<=QyWua]Ĺz ^? uWkˬH@HiBPY%!=o&,11Ǣo,^;T u4܍Y̸ g)!JA a%mI5x̯{VH*g.U|S+=Pf & /@4K4 $럹n֟ Ɔ,HY"Dnw$G<:}a|+?_^)≟* a"٪=ao^!<6FY ,LבzKep[v%u>ga?uύEVR M`Q% 0W6ӛ0{}ЅjoX7U&mW'uXYSp63}cC7]z3B5XDg|$o^S2)IqeTE5\^CBJ6#j]׸=妱l|nd*GЀ" 4Xa5k\mF ]Tf<`QsE/ğR)o>o^ lHho^:NbX8vlf =")I8leBYu$f(bp\Ŭ?<'2cjuj*YSE([I~mȫoz6'*0^8dV׵= Kb9ZXt H.ºسߨ.eS>C$z}}MA߮a1bۀ7)E񞟄 ŧh.Zt9|/hyLGH=, eAYfYʗ}xMB8$>-4ʍlAKZjFTx'(LVhK&JQrCv2/4:uC;5vq;o*|~|KtOv[j2L/N^/]]҇g5۰)-%$8V5'c>L?{e).a5o܅5(0AK4)@zVRs7iDyOadxY-5=ʳaVЪD_#ȁ<)ux#cS}mj> PJ9z{_|lw`{XG@`\u6k}^%ҦUPIm6VmhnBT(,!Dˣr}{c_i]JkhPu=srkZVμBL&vaӤEf EZ߹s~$lX.&v95Wr IBIξ{$ 3g}Łau.?k9洑0-WaK:Sv(av-9n1]iyman2 KJ `?hR0h}!f^cjB`.I]=Z", u`AX9|2fЛ=Q2v_uCwSDlKע3#j aAѓ(]VF}Rxd$03cV6PmIJً+"pۺp9 brJ~ApLʾTuSsD?3Չ抹;HQ#Y5^<\yV&ďhhX27d1$"ZG^ak3cʓ ߺ6!,lٳMZ^Fk»9\kD @"Nfv;7JYUQ;5a&95c]A3'vFw֏{i%tN53qQ@vnSk:?gȲ!PHCC[̻g}&h){\Ia{ۋ;c\WxDH&[tSؑ49X^#-Sħ(%l q=k+ð,,4b=AglYy2]0(̜F h ϑ YolG׵SH9Wi i4;+8 һVL:1sB!ZQ껹=uLWVjunXU\hAB7A)_1ab2ʛ6=9H,; o4Ň3x-zZ *cOTGqy7=_VE?qz-i+^kyFz+zt|"8k *Q3dÆ+`:M<-"_Κgo;jy"&ABVUĹ8i;ɖ8g Vr_2\Qno+_k3`>럫Gρ={g'YEYgU}tVx[';7g>ۦz#҉{׊miR@Ad&l& Tm9ZsO(uvU|t&^__k\՚|[^,-Bre=Ow ^>G[-ˏo޻fT˾[v5eۓ?SWL̺7]ȓr fTd\<8*ɵٳ?^e9'u M D$'dc|$+fwPmAzGuBtzu nj%U ;jvϿOck,Oci+9|R eΓ°AtRm@ egua)$0&݂UomaC|`r-Ȳ:f#,${{YʹygtJZ3(4S":^]{/D|6f^`F# R,> r׃aam`ڡ}m|_t]nʼngRS7, ͟]-ey$M=a:tr[{ٿV5柁tܿg_ap{0!݃:[ ݢazвfnpT-3dpg*$bgCOc^E/&Dgpl^.d7@8)^T>A2m*_i-!^㧷/7T;BpvU5vGIߛV̠r *햷2)/l?uz%ŢAwaoѾ;oBP".$WD_Uhf趶pOejw+'u ˺߱vŪ?a4܋xMwqO5 *>M!:Tq{D˅j^b,=Ο!TF@0?GH K=siG#;X3`% $ft3SPToPXq B!2xVEM-M Vv_3;NJ{,Ks'&uuJOfcy :n8(H\9qqUgrke"S{eGb˙eG|;0Ž*LDCHy --6lx|[hԏ#wV}JIx0Yva켗~Nc,k/I4c0hoʟ-ףaNŽ'(XH2JR[& wѠ42FCaSe?2ˆ1-LLf WlbzyV]"@9*Kk;hZA'/dLqH-fE6Kj*ˤ`hAF9ШFeRjf} g錿l`h&@cIhXJIe6qRd]=^Pң$%))IprhgcFhJ༌Y\Bn,6b e-D˧|Zf0wW p<U/漮Whi"(H&hI>(iom'jN*% _(N givZd9V@6ƃaX%SvȰ@2򖼩4*JUsN s@@V8a a B{#0%^xi70Y\`J-ֵv,>3DLq%ao: ;qKN sc筭xpZP cY:׳ř~nA۱˄Y`[{ҝHpga ")5^@0zI/aW]o}jKvf) Sһ5WIY!!.y?b|%* ym"" iug'E1@x ץ)|` /M̀ |FxٺB]ah/j[lWrJ;jms',ҕzꙐ„" ic, /ZU6UħI7e(r9ÑR!GLZ~/%AN ! B=D5'lcfL`sz$` kC~7gZpBJ@38p)˲W}CRN=PZӛr.IVCH_RFY`c[fOȵ@愵,3^8ʭGS2{2C^5s4S!*DhAEYd i2cqZlOݵ]~ǙG Y}??}moYq _!̿xڧ`Sj媭6] Ќj1y~}-T'(Q*O;].`0)H[_¡Jnj\W@csOQ9hZ7TK'6bzWQ%a {|^g{W5NbFZX۰7b=MgbeNDrA< 9s{>{InC̐xFQ_ ã0"Unwof譲{ϬlƇjM{P0GlmHHL\ړ:{_q.)'Er:+,\с s\SYl#0iٿ\_[4T=-9$-Cf6DJEAFC3H "22_1c5fCq/}Fw-0̉ e{i1o\-B2n-0rG_`_ 5pGձm鿿sztaB?z>dcQ/+&.*PYЯ*0ؼ֡SgOk1[wXcINtxr06_m(ijeefpC!Y(;7 Zj6DIX{f4^իl2Wk'WTN,=a> 0zXQwWhrf&scWag#^@ D"X(*/RKVOsjUw"_O uikٿ)*:7mu*@HIYPNM<:y>X.,srвC%rcrg pcvHfZ0x).2 *h5ƶjш xC VNcClѻ( Hhm>T ^Y"%taPIJ,TUᡃ3gKx Jc(KY Stm`8H =B)(7 ݀@ &a$bDJ8p(S!nq8p޷LfXr.y2Gvi$@Ah68, ۪">5uUcaBr[T{6vQ:-Jk=uX"*2Y2-iQ-Yt*6}%8VuePV`h:V–RbBcrʧfT*e2UXfnlUb2uy=&țYв )Mɕ.RKuZ4Q3 -*C6h#P^bfc1v"i<╭2g CWDHT\4|`Y^8CRkE[O1<0)AXYCPwrҬW ޯXEBגk Bg $=k˷W&`X82j+jX7xZ˟]s_buY\\ *MY47z4ue`k:pB[:k^׋^ŶT4֥fb~=}v欐jKq۶.^Ĉ⽥m[+ּrd3`NU0ӛgA3eX_Ⱥm~2̪]Rɱ<{2zեҔ|n1&"2E$(5B2S e0PRs@$ %2)&Pd((B[[$D`1"1b%(((`IK,dd"DH, a"ŐPYL59!I&l%$RII)B]]ogXK!nF\>BD?UHi+_MuALK!I@R@Uq55PCƠ@nVÄo#|`9$0,JKkϯ$!^',k\{rz+h\k\KիVrp$xQڼ `Z>s~^ -О!{ggАJ&gog$ypڑ%nFkA )E3'+jVTLx֙> aPNHID,X Ew~;O.`stb#i&. E4EoR۰1ϙ88񂊶jic] mOF#YVT2uF/WC>^!! egLkuY}6vS2W@C"Vzcۮv^|haqˌ 8ڴ`o5ݲٰ8n$yr>˨rB螠SƱ>R&N\sғn1UwftYĬ»~<|]}laYV\FpJFM>?Bߺ[/*kCqwwe@0HEM{]~LCǕkx- )4Eb6bg=$Tpv/ڬW-<VhYǩ8ʩZ(u͕pScz! aztKcd@Bm) \\+nfE)=bwl߷zכU+A $I>-0Y-zN'WO4=Vi{~Zl$Tjp}hѧYɷP[2*8W+d"N=5IPDwK4Poo}Ǖ!E-/)93L`a$4U$1 S0rDyObc.ek,> 0୑!_g1QɠKOtsgߛ~x])[w7ݑnSkIX~,n`/3zha+Ԁ:ҀazO3iM"udK`dTN~MKOkͨ]M$Q"x~O{:E 7 QrFO& XE`(ablxou<=?37'ݝh9w,D*6 `M(4TP&tYX0J!08D@MM>Z0SXLX\-jje*4rw*'6k=:DyyZߕzCQ=YXk]{ rDd: I|ZXCI& ()Z g@Ga=ʅK.s>.)\2/[Ğ4`;p׃M V>UF*%{_nP@q&ypKf ikEsY t̆؄lGkzLlbR.;Ed}M: I>%2s뛁6o3UI= x?W@!=n/_yh|I ݪ*VKZLݘŊ=&6(Ke^KPInyE\!PXDKV#| RTɕU!є&`7>if8 ?DɤAo: EOSeN5ڐS3$> fI5:XQx%E]\ ={h]—ԟO*,RMdvJ 6l:dJA՝50CdDDV;bQV4+)0 Ah*En`NLyzjJ5y:%r8&[ݱyb.7_ӫJ] jQan5 fby ބ-qhŅv?0ؒ[ NQh1sysQzlkMخ,z7y831\f8t51NuM67UN ׷gc^gVju`Rfc^PW6IU)}ˣnj(4nM',niD8]'u0lgMN t$p]mD-қ#W\kjlZbHLvرYIՒ6KSPp;4IF rM̘ !:D`GK@QUTROŨWL|2hTdxȧ @ ,ϫ_7Grk^6m};'P4α=AIY0Dj8sdw}1,q~ ?W]a-%1fzMCg90''#2t}\3׭grruUUзA/[ Ox7f` hf4=L$-ulyV]ݘ <?XŠgmPk'k|yD b#@fIk,Ou7ΆcsD ~wݏ~9PiU#jm3_;iYQ [4d $dֻ6ubӂV=]qNí0vh1`?OSzIo%=o{ kNuxtvT%UHvZ:p:D&[2Nݹe9|yҳ$?V~ǫ̍ĉ xba,rG,a;3K*%&dir‘G&U>gFS!sFvQ#Zc@YN|h bYKwˆ9],GE ]\m}N cJZ2=PP_^}+{;ĎmS"W& ^Mz~$& 1tNKbb8#+|4ݡ5G~<-JmOVL(ok,`K M שuu@;.T]*fI,hȷ"̆dʨiY/(Lj֐M +ˇ&soߨ=b倇pPǫS2sDs͉U&ùX=G5wuE:22);!a7*uYZDb<ʱJӕ>XiB MjKo(=x_qMhtxiWC Zd-kg!VCW: Oߊ9Ll^d"B.~ҐAf& Ii?._xTiY@JВa%qv,=q}g^+o?״J|vix(ѷR=N/.ZZ}guBBkx]u  6Ѫtż.tpUxd!q)yYP+msavKh-ͥ%VFws_Tw<*&1 3FȒI}p%RĺGeDuM Uv!h Nc gh^:t8 ޯ'@@qYO"w1Ith) P2RIR#\.xA[KUz Z}SE kB)8fSR_{N_VÈT ㆰiXVaumgVVͮ}lN-A"':mP &,  $zE2̀"H"4)* סG.u 3%jvRo}ngFXun fE IGyoxG! hX&WfFa&z:vއrQ@xJ=QzT=UQKE [7$Z@qx)]Bg[(ms^G(stabd&0nr,g>ՇAucچ&ùT8O1kq7h ;T/y!/pQ$c2d;\/۾z<*d؜puMոcn[p<ߤ8>91:w6n<WOzu&⒥+5.ݩxQL+ךcNw42 8ߵvգT:)].pErnIx%B(j |[IjgswrH9) OcD !^)^i% <_.>LbT3e"˳ 綔 ,ό%,^,=# Unbg#T ;B+uN)} !Owha)"K,z"aZG9C0;ҨUrN*QK n}cߥiW=ヒk5njau27!$SS}4,9"bRIh,/eMνD)[>I-%$!{(H|-'̊2>lf|gV3b5V!,K%M6N/vv Wpli%DB2<{929#gVX9 .FF<ևvv /%~f--%sO{v W|ȏAD{ fTzw'v"=dzd6?kРm V=:QO`"zx<M$S𵕠>䁗Hvqė#2$?dKy6fppmau 3:]kDQSev,EӪ~L22D@xtغ<ӳgha]TN,b|CF">}ݑh݀~?xm}_b3YCg؊7!Pe׎``cI +ZhJhB)P2k!~>rZY_s24/8z5$L!R@H$783y3} yJ=.z(U3*C*?`42$gh|;VmpUa{/Viޞп]b(=CTu$v&P@I>I5H|_3X>e;mY%„v|kVFKı(#t(Ē,'!6v$<^G 3-n7p,lA8|?1&Iy뙄ҪEQWxwcw xvxjG]5LulʺL+;fyG{ 맕Hr4ntZ0u!amKYY0aY|h`QcJ!"$iжOJNv{K'{x+Zʡ'45BpeQ@`N&W #ǛSXA[ 54+= {t.GhGٚuOK7ܑ$)E45S>J)Ā5WZ*z^HXqJ-X6h\~$ZАA!j{I;Oy`#7,奕% #dSѣ ٍ(ަCԨd̒ACTFr4x OLy~g?Chq)k%$K>ע֭|s5 (ə'@D_mXf<6ڜ]K*&BNIFQx4R# 88Vfwy"L$8baX) TWsmow(OOM/ظ)AA݂Yi>CF1EeO=仫b65cMUf_?773'e=MK `{(u%@$;lW?ԝcd?qI>V-Y*<ƁDNbdXǓNYj;"S_顢3RoB0,`z@^Fd >Q4H $"4Zx2 ֋Wn_ BJ),F=SJCHQ?zV(z`y.[ہ\;+}VBY wT_)n#fէmCzyދP9ƖI~̂ Pkx%;4QaE"G'q64(,Fģw^Vj́*q)CJ WMB~lb8s6v p%z^n旙cCDFdHDFf3$"H҈nЭV h+ |)yVf PyDZfqxݤ٢eJ 2\,꜔1hWm\+::r!(IPʕԮQB6ڧ˳Nw]>zBT/jh-qvlfh(Jxcx>Vsd$HBԲtE@٩UBX>ۻeY8/ゎJ"Iʧ<7 "aZe8kPhjZ7X)}#FJ)=7gdoI=OGUz zm˗{8$Z -?è嬔!\i䴽kCv25@@g6BЉKK{'Yfcfd>}fi~Z55r}×آ,Mm?~MAa @X/ A`(]ޗ}<%H/RB(6`d\O;[sDN¥ YUUL^tW -7ṆPڻ~OqɂE>ΪҢ F֩y۵_Sw,p:Vw}|KZ5KLM-v)/ D4gđ5f_'I0:eeί Q,6LGnzw%o&()T~foh&B7mf`?fg/6RZZTP¨*Rs)2@J-9G^cWE1h;cX&ܺ}48UN )zP %Rf@ϠJ{"ni!Z@IR D08<_}|!W @;,kN񎠕L,dG2恇RUS{͛s@#g5,p 9Vބ0Ǐw/6@B,՗5ƪ3K81's"Ux?ݭc5ہU_I  $N :]h4ľ{L<X|**MJM PiӰQuyi >_-¬y9}?fy!(*GSipkkw[juAK5/wqOܪH="Ԁ$w&c6KխK7;zv峗1vf9~~*M J)iisP(H%ެ-TOXˮAf_\TYDS E~2Y&Yf M4 SDʉ_]DF;2m1a"@HF2_i85&j0HPQ,$4$846/RKo h6 ô{M[zT͓kc?•4M" 8hdIKE p*ؔg)PmHM CWa捊.eФen{Z{M/% "~ŀ!*?%Аw{Hƈ褱PDY`ϐkCz ZaDߣ{ndIFOm[,.wHp~;W*m_UvK†ǥݮ0e:J4ٓ ~Y^&T7P-KKM{*t=,Yں6>v a~n)iu,C x00`ҜX`PHPF9QجDke 06U 2\@`12L#biTx3kO#A( &C.iNRSR`PUU # gAp'phxª<5i+^YC[RxU# iЪ  Ca6W׍IՈ"9$ 4Z(jbep!,`Q$$Xb WHچKI!t!Z16L۵IL;9(9%AiRF⼉yU*4lRzzH5@f0,!\s,h^oKBIy&sXji z{>t@ 6k:$(b޷\svW@@Qb D[= $rb@ 2m\fg忪QF# mO?Acr$&/BO)i%-+[8lRlZ<ݡWnD<9x{췎 jxJ$R*,';U ,TKqe^73dT gYfԺs+qwt6ؙm5Oyj׷"|0ԗ T+;Xžwǯt:=?zNKyXS>iMg/4/鏠( cW1?%]0%ÿȑb;Er"sT}\6ðlpS8%!?#AOek'V~;^Q9)| :blѩ\U^&%!^5z BݸM qd͏I.Fy[k*|C]S-z@ew4q 82K@qz>{O>\Ĭf҅ 4"Ğ)S*/HOկQyQ 4a8Xű][̈sQh>~ }k%𕫾h%pҔ wㄫF4;M8Gxx>2U(ybdq0KJI$ed pfuN~kUՋ/c QT2G}Y7nWK"qC5m&)xdAL?u:?dKfdV=k%h&RD+ bӟ]XsFz('b2֢ C7.w٬{?ɣc:8/^ƘU z7kdDD?*Cc hmT"*.> dqmY"Qbh)"Dm˜)UYe )bŅ*Bş´mPD AE *ҢBXRL2TX(( 1XlcmX4PJaSL"" )/l_d9(}$A9_9 $ $^κ|H L[L= OD c  ڵ-\*,+ZW:X${奖AG:Ҫm6$ywTb8|Ψ"F-@i4GT5hSՂL͏ +TQt9/Q'ؽ 0;i~SOGxa%ڜ)HS/@*oUvG"S<]isJtg|7C;&g]OaRAO^+rJ#{3/tWy&cgFcl/{~&ޔc1woNp) O?G9il:P0Tb꯾4nޘRPh faEN,R tiNIA m>q^ Cx@βJ,tލ+lgT !vԪ2?cӝD,>)r6Yz`}pM-7<8b"m_zUˊ3UĸZ396NE2-{t@MmXpS1&MgvtxbVƖ3>ok.$`M:ڻIgZ̺/$Sk\ 0‰ST'^d v.0Me=8rIA:f(23t/L"ؚ= ݾ_k?^&0m'&c :;)za'~(4A2VMu'Y`/}bv3A1NF.TfznXwmQw~5K ii6{l!= @,0M q̝gjVhZA]]]H?R-zMzIz=r zcxQw/?"UZ>m[xVb@㩷̎& ñW= ;hݱi8 |Z;9mUFY[:9~ʫh$ECn=4"rtlmރKWe#W~-ܒm< $#> =sI,0BR *zƟB%#Sf =|vxW4K]B8jϫ3XQfLS!u8R X6e'LMO ==}Ě8LP=Ca(*X`K (YDըt B-Mf\vkǵ0xk4]KᾡhH!e:~CC[vJr66QVUWOe4ڛOi\I)ezͶ Qsn7o7.K3s̩TaqDD\ִ!a9FV e9qZ(*O8]DRhN͂FB\( ٞ$hؖs!Jg:}Q^JxPi8,ifW-xT.U}2ݬ0@C++,ַm c.Q5Y9t:p^kÃ]rmR?mwj054(V=YZ QAJlJ!3~8eKsj8Guu$Ǹ 8 $/rL)@H4!t":uӠ\1 H @%O ݖ1{cLdŤhx`9K%8OpȝfKLLm $8DG%d)V*2  IkQ`c0JpΗʭJZՠ:xa:77*m=&6]UQ$;1܄֊sllmBk/TנLx1~q=JCG|wmMaL mWHu(2ȥ-S0/Xfr@"}Wwzafdl%yg.ݝ5B >`]Zg ><ͼ2Ee)Ῥ=ze1}-h=UDxu:gQvEr0a0iMXQ`0zƐCW^%lo~[b荵8ͅxp&Jocس5ԧ41fbIijU<IBAU׫,PΜW>6ε2 fGZzxS^ mdžL 樇j<i\5(R[O<U[FJ9-"hvzy:k o:Ҩ˟}T=|,evUI*jf!u7#DOI8&y (z>4VxWW+pDhlǮڝ#%2<<,91 D09*H@  FVA(Vbrg΍d"d=Q+jA\oR -oh웣 aI u$KE&O?3/U}̂ԹwZW|Ŋ^kߵH1P 2YNIޝ3ؾ|: Ǜ{,L=eoVH{Gz%sPO)]ݵj͌s͏9]z.ޒ5.x'ܡ Dw.4bR%5h$?| %(r_428RƏCNlly.A{0z؈%# \]&lj@ 1t)y/(%cH DZc@#==53T̪b T Z+Ĺg!!-aX]^wŕ/2 iRa[d+2FBzzvCIB$(zMr[9UɈОl(K?L|dL9̩i|^ˊ+ej l3NaɇY/u1k(nb a%ʾlPj>|,B%UtHLa;l{tnme=B\&3QQF/EAVŦBC7kAΣ`VՅqm%8fi=^O.Z8ZKwz'K`\+ZywyX3^_o$v{,])`\i)7J{P"YrZWUY9 X LWeBL`T$9"iuI_0[48̮)TU=yP&!%ʅzU[w1WHZ%حi Ӌ¹/R Iop&=pO%nмʯHGڥ6v hTwubD[z4Qj-&r+JR>KpGZ)4QMHzV #+ّmU٦N$ qr-jzܘ|5N]4VÉ$ӳCOSsWJCe`|,{{ydg50G?m5 :$zEΐ)2|5)bؠ 0G1z_R%2{/)/NH"vљmpvmeFT͝78B 7x ,3݊Nwɳs ~& l=ή͍1sgȠ0B3 !;2ȗ2޵B!pC,Bէu4ݮ 8Y7b5m"GW5+MiXf4fxC%6.#@>^[[-D*i>#@HrET1r}aЬ<uhk2G^Wsw=Z*ۗV|ϕ!0Rq?(8uS.E]MWǪzy;1`a|\6@W%?~Z܄בvt$1  Pv]x%̂oX^j{wN ɎqskKro!F̛N6_>hdI+ G?&(jQC90z8o: eg/_NC H MŻP=nQn$Q´ R$h6HAg2%QR0d$$f`Ҷ+6gmK<^gtig+3;Ξlre/sneTϻjXmnhsFh,E n2"1(B}(cA 2')0o\|{&UCİꖠ.~Pi"kn8Grr}5-^S5 RW|Vy[j|ƆU@ b:l!6xW~EV|'ru .xăzz\bɮ+O90b "C Ʃ#:FϤPΤqxˀN/ $ 5|56*p/=h\jmzMy_r.[;š%]LIy=b;g-D`DL7d(O=LLlf)̽ҏD-Il&+i XGi>Xs蒚dvL@;[1EXvG-NUwn FgLu[X#n SPpR( ? K1>EWfʍx^Y].4W\Mx4 = %zyts8>^cw ^}9iii]U-âG$} vpl"%8j27N o#M4Œ;PmdX׾~o*x(ilU}櫪-MBNg?@_fuo|T<φS  EVfޱC f  G]j} #FUx"!J@.:9LP@b4hR4m(pz>q!]sKk{p;5R/)LmcUZ!٪}mQrk6Hl_TCY^5PY;؛>J? %+S6`ZjZ}Xw@ JcPaYL? $u.e_IOchX՗RېͧVC8N,89"E"l>3I~@ ԥFքǕjCof_~~~VfF|ރ}"Wzi,4>X.2s ?b_ 8 p~iԄ $ھJ[-߭~Qw)Z[@z$}kQҫ=Ð0rEj"%;_S {zC=y G" Xˍ4@ϫuCʶ!<[űo]}La/0 ǧ*@Vg̳ʭbrBU)GflK5yKKdhLS!h$!jQH"7H WJaXM4N ;%DBEbQW![͎_ oǼxo{Z Q`VR@qfAy Bwtx W\CwGU5J{Ra='N.6V鶳!ikZЦyQl&H-얣~1a8*/ދiqcF :XՃd u;U^؉ CCvohSBT(}k=S Z\ژ'*o߉ߣuzٱϪflAL"s~S;YTzՉu3>ljliAq89KlK:i˻tjCWS42$~{,C%a pzϕss.H/;`ϳ̴U0gi{ uKZԕ 6qSѿ#G>ǡ`SZ_@ӥx`qs5P(~#ufFE(}^sJ*ʋ?oۦLc|.<5 (fHLeCPqGȵrcPܛY'>]ՙ# GӍj lYU[1r ҐF/oƚg3tCq̌OP/h^mS\Y dYetJN뛷ۤfy>r=̩^A޷Sfus+6J݈[YKc4vqN*i$XIvj+xae_fQ`Y'IYqO/Zn$D x,{Y^xtyy׸3Bnnm8 -{mWp 7VI%ηw$Du췏 SvS<_y^ :: VHi}ěڲNG&i4^֬U=ىq&{z~VrlqQ\u='spg_ORn>H4ԣ YUlwOwoGzu>G)!IB6e< A7RXh!Yz߿ ZHMi< Ύ XVnh 2ۍ3_G 觶B>|ض 29<.wdpý6gUOloTw-aaS=mb&SdOJ~SOɢd4Чm2mѩi4FF10cQ4@4M6=CCjS @9ϴ8;tV-& +gq3#b6YXKu`gU`(.S_[;iXD8$V#d !! ÿ?_7+w'}d`$ B H! < 9i6,@>O]qqOE[)uVR &^ ca  ; Eތ1`K)dR@f䅓 T?PjFv(mY:dB(dUR%0f"0 X  [/ ^;>'P:A70M1sWߛW͗ܽ~FAfk 0eeWwIf;]K=k)L& SwQ_.3Nb\9n| l!A:j,`Q]G3wPEUᩰGM.r9 n&f @ET0{$ʐVlV5jM4~ +CDh- DBy/pja[)|TÉo Lڐ1% o=̮74!@L(MeBن>pܑ@W[$ikLX,&\Q/Ys> o/m5h#H|@Zs0# VZ>iP0F$J eEK_22Ҵ@_*6boHpY 2R뜡2ĝp-O-q%d2nzI9%] :FGA2NZhW\"?nՔUq. k\ u.5D} ]a[^<μ#< @Sh3<IŒ `49RH( g]OO߱Jnߴ KQVWI0M7TbNPO-P }\ӉY%Z˸W]\H5w'iLi[j-\#D)3PWrhL80 $5,Έ@ˋnQC]+E& A:2aKG֙j N 6qY vʌlO_s'ԅ.Sչ$P%ibuK"p ۀ%$R4]ZAbxR, [D5ck\ {+<-,!tP &ڠgëjsx'ZbnQQ c₯ŒtjIPռJJaXWH<@YS{BR; 0{$yF+ov*oY'?,Fŋ M"t24VL;C$B1 sO^,ӵoeQMJ`xs,X܅,($Q=zhkAMh 3Z688ki<|S* H s]E (" )4T_1̢}USÊ (G%y(u05&CӃ:@S"SbF(mQRwp&V/4XN( ($>*Ĥ,SΖD$)],IQ.ϥ E( \ qF &Ł6,:KlkK&=&N})M7- +CECW?udv*~SV)vP8[&1 [@XɎ(FUQ*LBӒ"٢ * UK;,Q@ a18piJ=@"9 M5;HkJzKh.CA $8u&3JX.{Uh؋p~B8%>WcKڭ6TcEƙTpba,?#\+(d3~}z=~bx?3,y"͂Y(zmˮֱ!nR݊p "(#NZ"]FBI)#tۂ3S pј^ۗ(HD D@$ yYAr?J1G2ǰ\i$,o4=`v9qz=SrYS)P-.7[V/ns-/*?t _еD>1Z9kb %:ަә-PzUS樍_y~%5.Եy`PqJI\UmvsԮ5~ >@5 MPBBᮈy."߬u0Jz0Mm:)R"rBEA kAHMDO}Ǿ"(*Zf!Z#Ax,օ'bM Wת<ٓ3Q[x?#fY*ۊtьGD4 '+*PdK*55JVxq [>R1_ڧGEj7yMְ&uw}E ' }b^ۧM{-ЁB(d#vdxycđ|H.[RX>&yv feuBtS`UαV 6и$w.;!VA~h=CZ*~Q 'XfzhqtqzE n7na;Kr*0FAv<8/Qͺ:}m qrUIlŷ6ڴ ݃9hO,2 q֬|  װ[uFW"aPNTkqa&󦸰' .}m~B55\4Jh4lDe&M@*GI<~B),N1íOigiO<~(H-T`n}8*ypE^q~sgm;rGr!&`K<j!ѨC2茺0WDO6u{LF꺖4i1ubS ;S4bU&凝 "ivz'yn 軌h>0vMA(H cQ%RRx$qr7- {cA.y:돣-h6VG>U3϶mo+$ r`0 z{ %yyZπgkf9LU$.FI4 BT@v- b8dSHb榬YZ Xal!Ca"A(ca LMDJ@$M$0h[O r=ЮnR˖K;Z'Z>ˬ!Ξ;B04!iEڏ' 0)4 ah,cks);'fn@25o}xv|z6Fd'cGuAӿuJY1rX;71CZ< <뎷ɹ>.LRs%i"\E23 9% AL(3[n3MJ-ϒc"XDpJO}Z4c)Ai %,@hʽĊ-t&ڽtHB!;(mc ŧNZt]#LsFݻ9jF~ɁT[k+P6nP7\6g9QpB+M<}ֻgT_qc`{euӨ)(?ǽѹG|xWܵd\!jmCȚޏO*Ό.BV"M-_a]"˅( @_]aMY7rT|;*WTeг-ye3~[1Ozi/<,(_T0#:b'A(8`]NWy”$ZӬz_(lr'huA;JsM֨1Dѭ[ NoZW׬f"&7q2sV Cncs^wuYpi>[,43A).)X;&PvPo;A t99+ LWP @1V9)"v0 D"j+0¹2 1F[P(ޡķ^Kmyr<twig YZ