samba-test-4.19.8+git.404.38b26805d4-150600.3.12.2<>, 4g/"p9|x;0$ Wa]mBWHHIx O+H]Wt^œ Qtrgw0׃,đo^.b:c5H!aZJO-̿YP8rHD\WL>rQ4P7,Fuc@E}kV֙6Rg/MpҌ;J\J:s-Zh*܂?Hb]1 a'dW1%4D]!vNCtYչ>@?d ' 5 a -AX^h     *p 8(:8:%9>%:R/%>@FGHTIXY\],^bcd<eAfDlFu\vw<xtyzCsamba-test4.19.8+git.404.38b26805d4150600.3.12.2Testing tools for Samba servers and clientssamba-test provides testing tools for both the server and client packages of Samba.g/"h02-armsrv1{SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Applications/Systemhttps://www.samba.org/linuxaarch64  @G Rρ큤g/g/g/g/g/g/g.g.g.g.g.g.g.g.8d71c64350940b6fe4d2849ae0f9644363ff2a993ee567f591cc1f030d114d67d36dee046dcae2ed01f3e2160f3eb25f0c67e52331f9ad641885f90a0d6186457743b7fc2c1917a58076e72d5ab46ae07f3e9c3cd823ac15bb25215ed8daf196e260aea6071a0616d3868136e384252f9bfd31a3c7befa87797b604781b6a4f5962484882b616a2ac26dafd2ea482b6660fac4935aa2ee8cd13331b867b387cfd8013687b8127a0c2da3228f8c566bdad7a1fb70052a6311966f7e993bfd1947438bcf84f2efc53401881f56fec827d2b45e122b0656bdf341f0e99d7dbba977cf6c249c630c384c4f3de001ea54a8bc3a4ffb241e7b69214f92639a54afdb2315e18f7bfaeddce2eaa53e69466a38e2ae0fb2f20f96a200b9b3da85be90294e366f993ce78291f1f7f3bcb2be64dc52a6c484e8678a32046e98fe7c35ce4b36f8bcc2c26c354f3a9a89b45b25f9ee62a7bd26a5c65bd539a62be1385530f01da96e9e825c7de506afbbcd15edba17c36dd670cd79312254509c1766845819014f6b2a69722d4cbe3598f6a760113ccb93293bc12cfc639d960d251cca5199b6b53ef2168f264f8b0e7c18e087133d221004566fbe00f7cc2b4ee18240590c9arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.404.38b26805d4-150600.3.12.2.src.rpmsamba-testsamba-test(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libLIBWBCLIENT-OLD-samba4.so()(64bit)libLIBWBCLIENT-OLD-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libRPC-SERVER-LOOP-samba4.so()(64bit)libRPC-SERVER-LOOP-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libidmap-samba4.so()(64bit)libidmap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_1.1.14)(64bit)libldb.so.2(LDB_2.0.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libnss-info-samba4.so()(64bit)libnss-info-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libprinter-driver-samba4.so()(64bit)libprinter-driver-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libreadline.so.7()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-net.cpython-36m-aarch64-linux-gnu-samba4.so()(64bit)libsamba-net.cpython-36m-aarch64-linux-gnu-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libshares-samba4.so()(64bit)libshares-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.0.8)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.26)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.36)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtorture-samba4.so()(64bit)libtorture-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_AARCH64_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sambasamba-winbind3.0.4-14.6.0-14.0-15.2-14.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.14.3gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%ascabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigh02-armsrv1 1738944290 4.19.8+git.404.38b26805d4-150600.3.12.24.19.8+git.404.38b26805d4-150600.3.12.2gentestlocktestmasktestmdsearchndrdumpsmbtorturegentest.1.gzlocktest.1.gzmasktest.1.gzmdsearch.1.gzndrdump.1.gzsmbtorture.1.gztraffic_learner.7.gztraffic_replay.7.gz/usr/bin//usr/share/man/man1//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:37359/SUSE_SLE-15-SP6_Update/b6fb6fd06a0afae1f83ba160476a0246-samba.SUSE_SLE-15-SP6_Updatedrpmxz5aarch64-suse-linuxELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=970fb560005c03c3dc21d8cd2e06529c636f7efb, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=ebeeec30dc6fe5863be0eaebc9233e09db3e4449, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=ac51b124ddd5d5b25feeddb9489e33da9fc80a9e, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=c41e778376b92aa22deb3680cce5dcc7dc5495ba, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=442d40a0eea42f26d29b9f1f912ab0d0fc454936, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=9bafe2efd120af08c3f9af3e2f5f3f7ec34fbf32, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)5g523-RRRBRDRR%RR}RRoRR#RgRRRRRRRRRRRRR+R>RRnR=R$RfRRRR*RRR"RRRCRRRRRARR|RRRRRRRDRRR%RR}RRoRR#RgRRRRRRRRRRRR+R>RnR=R$RfRRRR*RRR"RRRCRRRRRR|RRRRRRRDRRR%RR}RRoRR#RgRRRRRRRRRRRRR+R>RnR=R$RfRRRR*RRR"RRRCRRRRRR|RRRRRcRRRtRoRRR}RiRR2R)RRRRRRRRaRRRR+R(RbRR1R`RR*RhRRnRRRRRRRR|RRRRRRRR}RkRRoRRRRRRR+RnR*RjRRRRRRRR|RRRRRRRR6RRReRRRRRRRRRRRgRR%RRRYRXRWRVRTRURPRR#R}RRRRRRRRRRRRRRRRRRRRRGRHRFRLR[RRRRRRmRuRsRrRpRtRqRoR RDRRR2RkRR4RnR;RR/RRR*R5R7R"R RR9RRRRRRRZRRRRzRRRxR RRbRvRRCRRRR1RRRhRQRRRRRRdR$RR=R RfRRRKRRjR3R~RRRR`R\RAR-RRR?RRRIRlR^RRRR&RRSRRORMR,RRR|RERRR4Uhf@4utf-8bbd760ad2ebfb386a5edb00bb8f220561eb6aed86fdfed445f3fca6dc5692d0a?7zXZ !t/]"k%42_fR6mH> nBh]3JiBO!i4=ru!>T*^T3Z6l0NafklIG"~.NGR\ޮ]|8N8&82JI֞[+7`TqG?YV g,R;{)Gƫk'1yյ`i, !uZ3zI^1&YVKoV|~_Nea"A4ABU#z2,I5V9q9j?,p5ňNNW2SI6VBP\]se,;%ꢇ7KX"o+ٚߗȱėc!-/,Kۆp>O!M"%2u9h4+BOMs;a쏾7[.Bb{ܢ$ƥ-${@ Zť҄/MO>P\޾]S'¯  )+Ir{#pުIƳ҈zP dO.jzw5>bXw-Y,f;ҝRn0WTʈGYJՋռޖ.pˍ;ceqCϒOQJ%< '\_;& Co熟`D Fe\/^_Jr_πw>НT* a8LXWwaSeqL^aj྽fع vʯU_ߦ?YM J9f}v;{*|Zb#Oa܌QIoЇyRe/fQ ̛/mi҃ݸ(lYz*s^כ.3C*]U"q|tZˮ:K"=pJ` p*~cz^iCN"T(? ~o78B+\(e 0X49EeuOyujgoՆ)h<$+S< IYapw2,W=:L`QxQ5wJo/{1\P.EM9F V4g_7_c;/^OT, [&>hߍ]+y:w;/pےΣ/黖mPp<$VryՇS[Lini hw/~!#@΀a?ƭ]aZ IU% od@RV:Cdf#\%7C?tyLvu' (,sb/3 #E\d:YBy@CТj}6I!;6y'䎯P;8DK#y}NGw}+3XP8HX¶v+٪>~O TZ61(-$4=}Y+C =9x.b) nGF'JYHܔk U㏃cAƱQb Ȇ9Fq{Pexa=M`/x5tkBL|\E⢱| F9rSWcŹ%`hC8>\c!*e'S5Pd(s,ccHP#Sy>$G=qxݓmFO@9C'2lzq_LŁ`F*Tts \y+& Ur+5.)&;\wl|&+}isw¥waPzDsg_Sx.zlůFֹSٿZAY+ũՕł=ϴ Bwçf+"oa-'*ZUʝ\|KjhNƂhmW$,$XuN^޼2_+Ċ鏁.ji`KF^MfT/l"`fLB*N&Sl@I0{ą !6L%XyKMC|屓ZJ{#I˃WW ivEɑO Τ.D[ -c̊,Ka˱LGgm<ԽbGGl&d\Yopj@XSO1<)0P/ uŷ]{ubߙR=ima:4uвȍLN7ꏝ#4$z$o_7Ưo c& ifIXYm=t^qnb5+\quec'zxn:N}I?b!`uRMO7K23]ZKfgoy1Y &:zԭ^V)U\ZhȆ踓I5}di%.LL˃. =&Ka~>&̮U+,C Ӛ)"VѴ=.m{Pop#D❚:kjN$n/ ~@M2ڌ(oMM1^}kNΌ@v0|QfzՒ3 5(Bjj"`]%mpi楋&bYH'6+YjFֹ|v`Q pָvo>$\b JU<&ʗei%sR|`sLvt"@ZV :[ 6-fWFt|BAQ:UdyٲMZM_[# 7)rDg@!MBf v_0ޠ PQFρd>%)뿿9EvopFQuYGbt$.U WOa_kA@^:)wp] 5@_lMLDisՓ2"%!(c+%B_&RX-$:O5N`XGOw5)lnwS٣=_3Ͷh·4|8CB`Y l m{aNn̫] mLhNQ8\Q ifArA)z"kO0z&3]HTeֻX3ʛLeuV퇯rߘK؍ݲ7لm;;iHMMZ F;)k4LWB&Q:\&PvXVO}qBmV{9|:CqPl};.ೄ*|:DkӣFɴXW0g4aOQ?2vkmIo=U;pwFDt^5& jW9 X4\;cwh<]̯ݤG+xD凎K 0#aH>DX̴xڛ&Tx@x#_G ~Pd7XU$p @d*(ׯdh<2MtmeM%#r`V̔cJ m!a@8i Յ`J`$s=ҎSn8+#DT,IH<<09V"oQ>C2b#oeEt799l_WF_夂BXF=Hq#}b^NYh);7c;}7<&GZ w4߅_D>{m/d{ƛ]k.?GWRTzȡ%s#vKh4.RwaJ9#AiwDyoNPئGH6{^WOeKN?&?ԣ_}ruF.`X3, ɋPrv%$xUo]C6ME=[kSme%u TJ I]㞎$vr+&&EVc"%nE !3Pۂƈ9L/.,K`Y;ψYv^cx_ D*/4Oj,迶<8ݹ"AeuݑNr%#Rƥr q`@ (`Fc[6 gƼlAzIE`By>yF qzzOR*=0s"a/\P .77Yhń@EWէpIv12R_VJHN6 6zl8 ]JG>>L 37g ܫ% Dv1gԨo TA#n|lh޻4j*CMpj ÙO4 f`2ZrbdVWhwŒ&I6XBaYi!sr(pm8vԈ@lǺk٬mW߼Yt哈FhP /ڹ:/fOxX14xU윺Hn pSOTtܒKCg`;AuIބnׯ'S-KQt(hv,u36}k{늜)w/5EG1pQ;z@6EՃo瓳Nh" U! juyF-gy.&WdqQJU5 潌q j? nr$%‡|I6p^I G"e "pEA ^9vZ)i2b KC&J]AT $%$RGSjpl$lH)u@{U +FQv2!u14@7|LoTI '^B %F[Rce?/w?"NqLifϳjsR6(Kr4+]' q 5z~BmFGuK# )!g [`驈Uܭ3̆ SR,Qsm?S {>, ቮ ^Gs)~ȃ5ZԮ?0|mO괲>ȑG JhaL / ɯ#B;[[4SW; Smk]9[E餛q6ȳ7~AIk"6wēwQXf̞LUOakR_ CzocŶ7]Av~f`h~5X &F*.)s,5&_DQ18i0֤矸}hU\{X8s6\Dh4rOuj/5?r}Y" u),+JԳJfQe 1dJ?hd.CH$?5c{tdwHR>WXpѫΠ#f-ne_8PYI8LQLp)&nêU %Z-5~m&1{wb tJl/+W$q|ۢq7(~,$73V Hmq?'!uev (ѸUTs?!b+&Ay@TtBx}N|b)7owP֌זo"ogۙ-cb1pVtz?˜<.JO^P!4 g巽DtbsK"%QUOe4]ްL[fCBTR2MΫцaѐc^ezM5+p_i%A±%! C*_LD|gt`F1<>.fF"UMȑZr bSNٕ! Ah@ [ʂF!4^1s|k=An.9$-Y3pJ9~&&OxH_?ӮqGxL41MF<-r+ĨӸ1'Ydw!<|JoX$*[eSZS#b0ׇA{m&گ} Aza&R4JJn1#ξgK̇4]&2^ɦaK4G[$ nE_g%ڱm XrcıܐօMʯƄy1[mNf9 EL=vC9.7Ne]罁'<:px`%Fs6Ls])!;wZV}N^՝L8O>c~Κ&O&wh$j=,EMԓmBun#ػRF0L0M )q!CZb^w`c*w}j@1h:c;Wp{+SdTXNP-3Ѫ dIسW 2d3!2c$.| eGNfQyoA[Yi$}j9{#Lýұ$rH!XR0=wyjZAlw"aӈvݲ!q[O̐͝/މ۹R Ë,l;~^Vc^ߏנX:N#Rt's.;ۚ_44'oFBlI]g]#;dyqƏogDr5/rBA\+]>HF)IFqr;k>YYIѶuZ},?v2S.iSaE ހm*% 25c)t|vA*114 MFq'}(-n;<)TR)o+9WN/SUW{㴹lUz0m4ajKSH'+عz!uUT:-jB#M6PRd!TB&eBNbX-0l%p@}'i Fs#t nN vE`Dn pHorkݳQU"E`=A.k2RUm9W*NcS(r/K~2>BQ$\bS][K'b1QnYBD.77s15]G.moK;ڶSjxZqDq|t1*=6>k=Dv h$;we8.#,^ :*074 uyj։ q4d\7G"M-S =CK:̭ }Ƀ5+DLӥ#xU7z.@3\;AqrwG^C:#OR0x>U!LiE+<:BgL+f+2;Ái iEb,)p3AQ9kn\9^d=e%LX aзd*itWwc2 ~I ZmU^~"2dz*}28cQLHcp2:e?D35X`~{9ACE7ž,R?[.<#^jX 6!& _15L<{gU#X[{( 72y)&-E1l]%|hShkztqjOM-ҸU1ڬd0͢H(ni)~".SlQ}H)IF:v*fVTjl^8:#&Κ( lZ xFzvi7Hj2uAYQ6R{|#uX˥t:K/:!@Eg Ln`;jvRw(r` X>|8_ 82I3IiL oY# ٪*ph쿦H5^g ko?enaܚI0&', dzpwU` Di8YAf ̀YJHavN1N3 hv ;I"W"y gDe^ i }ΕHhbeŽVNҫÌv Fx 5sЬS%nnsqhT Kn f?gi~֢;\-:,Xz6\F878G#]CB(@2 EOB\lH_a\F1,'!xmhh eQdž*1asUٻ5wAg̈́ U8䚗 XvqF=It 7D81<p+&'ވoFYWbjjaRdacϖjϢ@PU?3VG8釻?&~`ޢ"' AǰX~<,HPoID!kaT@~ЀX>it{GqEW *UmKdha)?,K>])ٹrYbYǏMq{f& 倫gB(gxf_xʷHt(>. yӡj~μH!xYƻr؏URdpês6Zo0ss:xR%%0 -gH8<W Z?$4HGro Ҝ(w}k㪕u)=̪`񙹈ٷݸ>Žaͤ!> wi8'%)]ߎ>u譐3*xl\mYi :@J"qq^=>S;gkMpT 2N>7& >OX>PJ>Ɏ/zV dӾF e\LFQ' Gf&(_h&_9aX:U?yY&9sa|)nW~ 5de`u -/ M x3!1]ѓb/W%/݈3^`o)O@Dpjz(hR/JuFV|tG)Md@ ܣ vU.q\CcwGx9R kAË(-2KD0VӲW`z/M H{XDșԛfqOё(J6i@Xw`4Vi3t-?BCWz'-=L4&m UP Y.JRmFlT»fgqI!"<^簬_s>f=xGD̑*xt01u5S I"`rT,_8ƞ+d5 lXagnq-ϒP+!dWrno-6Sffa4S kjUdvcBCvs>4T+I逍oX[37BuE×΋=M̅ehr؍ElCFO!:Q 2uxSb)VgE]qr2,-׹l/r} /E^Β0' 'KE_=&">ҋoϗ@9pp ]}r_l0mmwB^V5 &-Oa#r{ʍ"z/,B6<F4wJ+XOkUH,|;,+ UI(Ǡ&9}etیb^-?\x?fFrs\Ut `-o:LUzԅEl %(hv*{] C >. BouRrFG5a+\A]u ^?թ1 !1/j=kX~_UXo~`3u EXw굊1)Mgg˶k`Hb=46XFQ/xlr)͔s) k5z]t%}ig-~.hc*^B}9"%[>fq'dKU|zp1>( /wkC8E?q ᄁcgeal>?%ιKCYm&Po2&G8S\'Zؿ9&7F7J1 »}(P#awm!i 6 /:=C4̚{@{'},(-\|>$:jF} Liơ9%d?P tDc՞i}J0"僧}h5.}!G AjA$=T ޜ.!gn۳H Y[J5ݚ) Դ"k'|Dc|zn^;MkaܔօaEW=*xr4}.We a=Ã653$rF-Ƴa<9;9ڪa4;?Ę_hr$ХdKz1>p )h6\Ep'0lj{:,wH^3oZ  mAWCߤ=oET^1={ȣbBCoXQ)J#Z}|8Mm2Չ'([!<*"DMkGw]IxvrQ&V~(d#<łYuAlчϕZ8gӋ-*}AU')k%.Ć gÏ-g~R{UwR4Iat*4~)->dR[ƐI$aS%.8 #2f x*sS2-wif4=V#nd#{ d qx#LP8yaf+ 镂J:y0`Sx+-@JB!Y''7~Z1v.}_RJ'!`9C 'DO=CFCJ姢^"8Db>+%"{<( KĹZ]vdAJp a)qm\dsC]zd!bv Hs{~/{b(LpYbÿحaʿe\ Q@Pf<)\ ;iP>jR:5m~c'I({"Nt2j3VP'j6upP.%Fy%L&z/sV`B a>D'^6 ''f:"(Ean'a5qb iY F"Ы*!.V |8?CV?T -3* 37BU+ uE?#j`(XYff0;RQ@:Px\I#)4R?Ao;Fo u?4ZbL. Hx-s~mux֗M{ @^H:V?"mwվ113;6+B0US12FMF) LO2bx7 @ht0Bpth^echZ'u N)_sG1'e̡,y*L. 3Zđ?3tg5G0oqlܬ s6 4 <n5F5s!}tE}6:QSZ<  E=Fd ;/ܵ"]c- 2rJ|@ ̈́7s(a*88؋8i. ԲI9B @L8>L;$r6:X]Ohٞ-i>4]2b#G$wb--ر*۫վ9$}PS>b۾ 4DkuRF+W;j*&lrKe R̋9NUTSl0hm;eaqQ () /ū(IŠ&5Of 1,U:>i50s}DJF1Պ`|D9R%" wj'P+t49LM5~Via@N#ָA!`)K M9 zZMLL1uP5ՕMEP7,ʷh¡-"o ёv "<~mN3Ն[yvYsՄ)A؈Æ^ &MxGe.ГpDǶqSц{U~w=t!*%65U#Lh-V!̀'0௰.' __! q0wBTC}"$,N+؀"y }D^l~dWĈow4{4 -IFgǢrB Z|[FJi.I.?H.(70An" ojWC꬗gik@.cMbo\N'): MU9liNKR5)\)bX]wg >|(S[VQ*iFɍM輐mJGt(v7ESE|B*8Bz"ʉ}m{52 2~v ')VOmf% %rr*/H*QqZ LATJVn>bR.hmFn!?!:ƶ| K7 ʜAجw?<gǭytJ rCt= КZ~軦S|,.fv<=l1MLy,84$@pWgt׌lBv+Pq 4DږJ$_-)m|e)<46ķڗ=}J.{R /lo,>8j#ƒ:17WJvKݻx:Q-UhD`0rB^034ю(NjX&b/W׽Eh;W80{U<5qRk@^@²ce-ϣYc(>z YR|0@(St# %6iw:̖aMM@b"b{8&M[lKOo?I-3$Ypf 6˵imײXHr[0 HфXA{0wJ(؄5cʩCI]fu&cHl5 kC4Fa]1^1V¡;z b'cڑ٧m#| J*ć-8p%aqM-eQ,tKGʩn?$eG Y H۟X!=-Z`e>BVwqVr(|۠W=% V 6p]L/HvYIhRjo]YW),n.:*l{JaJ¾7h~[W@H;^o%hŘܚo7TbzGef1s6Z*coؠtV卅C{|T`{m^wJ'ذDCfR3N-ibji50 I^w"!uK͉K_r.L- T'%[1&&7(J9*_]*_B9Zp̒x]Xn Ԭ&x$xY6P!"8(ko?oA+E!̰E$Js{_fcv _XSc۷}|Luf9\m^ a"XE&ߟ$ [2Tڋ͏^qy"Jz}hYk~J/l6}y>a>NZx]v;hYWȠ?nHHq_]S=Xɽ߅4p4Q$1\͒3 N\TL++?&1%`lG=VW@ Ly`Q\9A/P4f7"aw}[KVVKWR+zIPRhOPx'ì[ ߙ37kԹ;X+PIsMn&&'V>6bw?90}5px4 :590Jw+mWΘ6_H,s}o? aq\6n`"ӯ"_=eMz4fQ@K\ކO ՅC Ȼ/g}ۛ#Үޛ.yLKMdl1/d:>Ѽ&ە43bE#2f^=h/ΡϖwiU}+$M9QWJ2LW/+\n:N/w)K*p`w$񊗗 5, % a8R]aAy`9?z_]N2=j?={1>u]Mq>-_iV6oShfjL(ô8j: $k?$O: 6)S?C)ȏ(>̥?ӧ {]&vdݯ6^{hxQ8 _50BС@ 1bH&ZVpIa@ [ĻT 5[łj.dVe^^փ-<G=(p2k('6X2v-!K}lݗk?"~(ҚgDZĪ=TH={aӧlCZ5 -%ܺxW览}=J ,<5O놛{h QS9 >Kƾ_j~ $mS!N6

fSAh'rWw*MIϤ&HF~EgyRA4@cFJIHGZ5a9ȟv}UXt>$HA .Q?/u'z}9 ?8ݹtmPm;!^En\j7(Oe`f Cz5r\zN"NcLOοTӛS MNIy ;y$D0#[Yre'!SB_l s3䳺e9x> .hRAVv$;q\ɓE}%drf/nS K?'%Qz[ك0k|0/4j5 #ީ@[ cpw:]{0&GpTMff*_F"e"ًw ѓ֏3=mW|QfHS ogAj0~N&W戈EE g)ųњ\F2@P夡)0r#YNwhz+*e@~#Ӝ.Sg LWۻҌ&dƄi&|NS A.4b7 >x^JpςL|.UN6 q5!`@ĬDjg /siT).0k]nj{/s1VvƠ; hVѬ[*&"̃ s+&?GYx]ٜx)|~1< +p.L檬Pups/%Pg8MkQzYѦ(Ʌ^'Hyj1x^٢dvù !aN[UHʹr#>`1Z T/)>"b<> zY̟| wbJ^S Xo nE\t#V-;w~҃%yLv?Eub>sE~FGzڇ 0sD# oW;>̆QGMq]F%ݘGMoƉ m 9̱E1lnIpPm<ҝqa֯KRš|Ao+lӽ\ ݲx7Ym,q_žA}NSо@\.'}.bhZrNIǷ ~X(b/J}n^yEcJ@릅]>)F@3:?fv S#yu4-b]EZK*ܤMbkр|h3Ke9LŦn&Rm݋S8l4(Zi sY$Ғ!KS'D RÕ-M_޷>]ԋ8p٘MVg[y06ˎ`v .停%FsM]@߷uv9!mTX){jӤ #$@>}oP4أoF9/ԇW8,t( O$@aI31C3,@,V'3…]H|&#g>1*UN8+8ip#6˰CVYBrb4wxj~Lbob䃼7آόuW!֒ܢ5q9ِZ@UM!:pqGYXųΗNF#M+Aq,E }ƹoB=eEkh%b%mv cg,HJ ~f-_%ejB}d! !(g$ ILm@g"sgsM\Fbb:ɜӳ"і&x{*wck:kUCaPv U K֩ŚŽ p??_(olχbh,DE14uc wb(+(F^.baU!u q&JAithV?TT܀L~#7J \íkǿ)π=u(l@p.me$=X׈MC_$z)feU*7 »C\ ׆JH0煸K: psgxtkcXFm+xmR8 JCƖ:(@Q:!h¶}l=OW!gE+VO '&k߅1$Dh.w^;V*Z?gO}o~yK[_\˞'g2g *wF >tmu)['zxM!e{NPǻj.?&YupU+!mjxSKLd8t-s1C c*/zi!g022Ce֪?\\h8eI٣\>){@}4Ft7'3J, >֓8woVЁ}t i `7`ԨXa zuяR) ;[(%b)@ 4Q ׍ސԉcv{U|p!F9Li6I/ܷy}&,5CIKDk_raaH @.W0:v8 S^ı9RHjGX_RK|'e[\hz%U?8bRNpi.Eu{M3sG0D&"OzʠcS?+h%4]Es[/-ˍd{ [ʾтtE/l] tD,1J8{5ijӍ>ezĖ"ў88b.+'bbg+ Xv+DC*oĦ -F3UY>1_@9by:d6_v(p/HW&]Əej!W^W 26aY0==iKW/äN?G ~"Ƭ.zPvC꧜KL:z>HlzDu/*4ݮ^l>'&>h\ QmЩ?LW/,onYl\? E?wj"s9Yb+ gzY]t&34> z+dЄaxb?Py e̫*SPAH>?? 6Ⅾ3-qкtwGĥap)(4H2%tg\ e%_((}Qץ_Y?G=,'K ZQ; ,+Wd¡h:AۋM:P=먾 ؙNdԻ8 "!b7)m;h%"q}?02S^.歔_QV)D@!w-/;>w>e/z}"jJ՘ 1⅂'$E+M-;UH>7hg&w,a[l1`(j@T. ''a/p&0# Bb坤A(l}pCnubȼQp09Da+T4 w~ r-CxsFS{SӮp'X} L#JY q[vH ߦ[tcXmkj u}0|zQE0~|ү[ Wˬ-AzRFīҙ\Z:0é<̍)T-~b4 (Av4ϻ1-'|&2 J0T9B\fYDK>ш ˷e2sg9-xȫgAU؟SLb/T>H&ϡw;m[*5=.r{괩vI,kV1923rq>cE3|#|n0WoE$Zgdm8h5NT+J1,"$P6.EX%URRy{,z 5r*͛yהJ[YI* +|(}Jvk?Q)rr , BO -YYE~ f5Zۙ{/"v+ݦ&FD>$*S:'f]aВieA V 0.f I~ӧUd94`ra$1VfqF>o@M8>P1^W9AŰK)傷$B$̏fQh'߄5^Ƶ[o״­bSjۼA,RnSn_S"39̼۝oPHek_N᯽޽q8|1M O Y֚XSc*uq:< %Ց;:5xP+ұ?YڮK><ݡUN}|G/Z!f xAVF;&M{U~9S\ljNS,RP Qq}.3Hl05$;n$;npSB3lUrRH@ZY%f Iz03`Su2tӱަuOsg3>D5ӑd(duOusүߍ:p&5]Ot't9э0617&\u 6:e3t{wk8>X5BK+d(b@JQw%P|"DJ9ֳGS3'.C&yf'NYѩ,bit?P\7ʌqPf[]wUr^ሏ7͜ L ̱#0O"+zI)a`T-3POW b@JhMQ3ѦbRe#c G{D .e"qD5_xΣ-8~+!*=L2%R@B`>ݏg%s(AYƱ EY*.BD"q !۲@MRB6,ӡh~cn6o56d*ؑ(gAէ|=br+L6rPPɘ { ǴDߡ"g5¬xIeQ9LGZ3Md~U[כq(X]"=soSp}w]K\,7Ac^`k'(7Jp=tnkȗ~T" Z:Eua7ݚ2SsJ =sMV#?- hXt-s?pn`Ufi[W _G

>n +Us9p-pQ`@$-b$]k_8Kæ}yFAtCfa{0[t_빞<  V۱}[g +| 4ggߔǮCwsOkOxlZn<)x _sUe S*"feBBfUCtڊ xŻ{7 ~ƥvPT:0 Zm 1SW lk/rSd Ԩ9ϬK!څS|'b3OuBiW#MCfU/)7ĮI &J?ѼsfҜ@و'Wr[Rqbm-@$y/>֑j~f u)r4Hu$^BDƇ&s~V%NZ.~,1O4hqs:Tc5y.XW@\e}!Hb5&R& Y8}aRčh<6 Ł9zU;XY|OPMbY--1 17<[[سY/Kqo#W aPLL$=y5\?V]e۫i<5+Y'0բ3cP'ɳeH .gGwUuyfT0HD)bqcm#_5/gˋh?rc\_%ōW/-K;[Un?UJP!k3~X_:|iWA_t{[8o\`mވ)NqJxMH)vmon/uS(8 yAt0,MCUYʹ8p.v Zed|]9X~:ЅWĜ>xOd>UWNW&2~H0T0B@?f{$QFdVvۿ!҃$U4I8'w67/w?GD'B_X^T:J5q9Hpk\ɒ߷(^YKxٔw;97ҏ{w 1/mSCɽj?Eu@CSzJq{wcP}wu-NCJjDkj4։v9*X͒T_Da42dŧŶ>}%A钟}sHoO"V 8YgEm'C7f^ۙYl1n|_b2<7쑪I0,dq$ɗ/?#0."yku@C!966^#/*/LмM57Y;.Fy;0FaX]P FG-[mg)1W_k8^EunH٢./-6Tgc!|Wb#!r֦4 lplڒE4`0]WޡL= bU7VQ("C A۔ϋ2[;T" Dxֆ"?qKoL*2Q򔳡;O׺bDCC\Uoy[gTq&X!E 뮖"m[2 +!$B~MHB(6c d%aBsVzIه_$a"=E) !0O3k _G:fN A,'e;iĺX倴-TY|à3{bKœݪo10̶ڭ!FJ'E:,;O@h<>7[c)588Ȓ"@J4Z_/ROŪ2_vD&sAY/z|=ii#h2fqsZ?vUdci,#u{(u'b޻׀G ؜wbK ؁gЇ'@b<ڧskR;˦dP$XmM y<&?5D)ZY}W<8Nc n\87x,ApO'̂I,$ձLc˥)vRJpe ?[8ޟ+dS?(SMx p5x{zʍo|ˑ3_!C^g==bL7@=g ;*7 9C#mJ9tu4x+d9m^tSvNuFN2>3? rX-k$by-{TEKpJzk,?sθT` @E~&ֻ,2K+eզVǸ}҂v$7Hzn.IRZ88[e?KvmJEfR"6ZBxiutn"b$oՂ^N:6H¼N ƏWDgm/ҁX,XDPi7꫃U3]xXfC;>Plyz\|y:$%*_̂ e$ ,NHCm| ҚMY $֘D mY'DA=p,7i"б!}~7׻\lx%W^YT7<{3<>S-eJoCȾ|JvchvNƵs$l^<[>|Ó1]`Q5gxiqbIRGLVtع>)⵩î0BGDk~1&t%o{P+Le_a{VM@NL[TNˁR_U'Ve8ѥĉ 8W:X.5!1Mc-~mma k~4whHT% 8=F|/--="_ӏM$2թ_`5_ܥȕ[V\}+!cBIR$pi6 1=A欜MvadӀ!׋iFu 1'iċ]c¨2x.L6ae¬Ļi*Z(uCv@Ms[ܽ6A@`TT ?PhqfwmF tC:AqS6vG@iׂR'@ *,hb|=u13xnjez-|^c g|͗T,_ҒøB(eYHJFQv*ƊC.s%L >*Nl*+[T#W|vMSU-Jo9wG W#cgU \^]m@X}rqsG[cTxzo0Ɣm3 57;2jI Ŏ۾b]` [ো}FtAoT^7\Cuu!sIۨi~:%xfӉ!uq=S#CyapǦ[w}zղއ"[ϺJML:gAZ_9~~\n/[!z-">zڗ'W_XpݒF\t)sQ#)`@يyZU᣷7 9qq"EJ ʻ1t>\7z g.JI,7+04n|L:)k{;Z#x)OY:4?<=JcTB0.g܄eszv&|,DjpBڃݖk}\mlҜo0180[;W^~N_Qn/Xn3Al*A8t-w ?>V4bn飼A`MQ3X^M SS>tYrZ53_xm[u?@ 9'F @*y(3 ^U|_,wgVYZkA#ߝcĸ M=A!ww>/"߯:_fJU !V?8~CV$_<ͻW @oOyE_&w_]D6 FN ;xS)jhNMF"5f9|̔&G Úk(ps'0x+cɲXg,|@z[ͣg#>\!<^y_ j YF#Vp7,^9"P&.jjwJE[< 0yR*Hj-̹:\}Y='Ҥjw$T :3[,=β>X3 tY;p1ҾT/#\X`I")vt]xV]vT0Eɏ_*9+(NcphlR]#!h"i[ξދ^CT*M=C;TA{=5($n׀H.m%*FN!ɅL- 3X#I<-gBG@p^fN}|>gI=.-I-=Ӓq9J9F ZI-A芃v|#zЇW_ݡ')w+3oAH2:k)X"d*_}FI\VG0d^k_gVXh1bkgtZa4H=Y2fDZtƥI ?-Ӏ$)+&N^ҿmwb-jс]q]Ou3͔Rk>)J#,gcW#oꟓ5욌5_]"T<;(MŐfgģ17 QưE,ݵRjG2;ۡ7/k%K7xIAoɤ+XΚ@F]@slHM{k +xYzX7Ԗhq@ֲtJ0ϓ4G ܚ| b "$Yދ whd]22+EhEp0s?/%wƗنkƬ E%e 3ԉG(O8״ W#8f;T}NMQy)>ٚ>18bbvIo'qrπ-Nz }7̻r$,W S:玏EPoVWΒt4^uP#A?a;x?bml׋] u JAO;FL5t/O"h`X!B 4;C ¹6]8: A*ɲ!l5kaZ-:IЬX_%c~kj%|;`zF^= *fsdU;z=F߃zC2k(Uw{X2ndOxAq5eń۳אؽHù]!/ٽ~͑:R̾o{(8\I 0!ss$Wڢ3i)A03ܲ6"I!2{y,|\ִ8c!KT-HPTaiga}x[KB$C~I'e"|}oΪJΣU5j3v29zU}kcNm) ]P뮭JS_֡^lz[@Æ +$8Tvn]#;*X9Dz*RX F:ZyAF|䐽Aspbs_\J0> 7<%5vIؽ<4;%i^f(J5$ApC tIۈe_jTO(OVhZ/֯doϸ/ -\'U=US Mݍwa1k_<80 R}cBKVx>RҔ@zMXyxyDB`5@ӟukZX<A=mB(LuS/K1FϮ:Sǚ5dX#9@fFvKj K`͐GQm!(^1+ ۆ%3J(t?ɐV_WA]4G魩H>JS;`B,_"*j&':  0Gdjbf1D@\k` 3A)K W0M(X+pAڧ IdXeIs@t(b*P#}q+[?p}|g?u[Hd3SH#iWdfnXO Υ '1]IkW`Ҁq2C`u&2O"(b=f G6Vfmڐ@ Z"8ƅ4%ę3R|sgةfTzV¹Lu6ڥx|["EѥOzZpA;(tўMڔ,/eºтxJ(>\5+w!IGnW){YV-OV{">BGHM>Qt5jtJ T.0rbEs3r0=1K>+#24׾bY~E*HJF[W񎚋..P۴!ve{}em#i!ZuRMʤ~rRkh޾r9|HYȰS֘R8*]3TTYyYYRed17o߼B2ReMZXKx wGmb "FՋAV -NZ$!yn;U0 [+7"_H|OSSQP5hԏިtܣDۊ7t/wyIh( S%Jݮ-a=rI %*L/OXlZQZ*zqÈ{Qh*_!FHe(_kqKAN8n0b4ԳyxAoP驅e2Yx#Ƕ{~GitXQnS{nϝi~33]QS8վF?0kBrW 䈅;tǩ"q'`H^>+ҵD}򪃾=c؈- >v79Ct 0:~߸8T;J=-[ Y]‰Q=aYSb 479pتv_)%$#X0^5)J)I՚>d9ё0@ְvk~% Cr0 ǀs/ ,}ONY]}ɜsf,:u_g-)Kii?lL]E5dGi{X_Fܪ_~|0p0auKoїE'Os Dg$2k bfY^ЇleKm) ]a>ϥw#<WyDlTDvxRg䆖ħX? fjP&«]*[i .&]A¥pw-yٶd?-4G}w\v?b5#.W<_f"۱C"ϹTE?BQGA;JDXTj!ߡn?73 bFĺXfTgZ( Br}2s}v{\;?0;NKϲ?gp%mp4ZN5WŧE"^k!D;H=<)tVrn'&5ӎYLA|9jF0K(I~c2m.c%i ,`+ͩ&ÈyHw8Ev0$hә'wbB?k9H YNE+]0Nem7H\'<\\V QϢg&jLvxulMj$S>8Kv!wrϐ,.zrOu o=9 BCRyVZ#2T~ݞ tZ^k;?bK^Lܡ3Dvf1q wB_ ds&"d݃3 IğG8N߯qiitޡy#҇&Q]$~3UAZ2 r0tdz)C@߻Mwd_y!gK#}xDiu:[؋ Jnq$ђ-VȔb#u07>< ڟFb& $){?K ?^eI\]=~)_g-L?nmF{j6 c!KݗjA=3Gn,f Y"Z/ǚ9VTuvY$~;k2 yn(Mhco+Hw| \+c=VcO 7&r}wR!2R*Zc_E)S #5$`'K*x.mT^f .۴0@Ai&M,+wRng } 65lclYDn\$hɹ*Tp%`xq&a7]:K #KfPtsC?}'~5GeїweNP%Em &.٨p6}Psߖ٠8f}h|؀6j:IJb0X@67g# 3TR٩d&;eh&Y0J2/CBG~V9KM`ݯt־x= Ha/v.]LPZuY`T5zQIsWFi8F68q=Ι5eɰLZAqsfeyBQqO첲(L"#L,[֡E1\M71"u'*@7Ʊ{A+7S,WpNzγ9U WUi2>f00Q ތAŢ&>d-I1>YU{q>7ZО"8#"JRzBv?G.BO}ub cˍJdZ{夤@no1У%+Ci\ihX~*07!#!h GmL8kŵx/T|%F/3cBjQH|AP?7繤1>  nBKrk<D,M3gV E?I^tL_;_ 2vv+8=Ȱ1ㄗRR"(8pDٚs7gh#NjM76(5<#l+^uGwĘ0b?> nwY!e'+F̠v"K_~$*vUL5+gE}O1W"2IJ7(Iɧ?xgF贈6DFv=)Z .VtW J`2H&MVP] au\)^)x1<lZilɨ0)ô ~mn%aR H2dQcr[!njZ$۟M|tXZ.Y|/]yu9S(|T4ʬg\=j3DrD(bOG]l˄?g-,}R.x\/B ^F,i׷{!:Ƞ]H{9B HxɄ~=M%GXȘDq2!QEA {8z|Vvl?B%]HC799m)"iUЬqd5b`zɞfY;\#tuW@eD P\9j6>3GœkN/xSE_(ׅh}G.]Y3VgzCflxb{ZfZ|z[/è>(KN)GI\B*%zxyE8&ZR^#s6êֲ)L)frN'$Dæ+vbo4 nbqP\2KJ"o в|ڒڇpZӷ4tBL |D."raz|=y(`„EOM?+]lEDpW+ Er]=8@ nf0Wֿpl "5Aꖗ-(#Qi4ĉ :ql~dQ}SL~,< ׮V @]{ 'V{fj+ɣyT+E5 "ɞ:\En2tWUб3L0s"1υ8*myG#q="}<,ԺS! n nW BrG2bo':$Q'MLB$* ֵ{i=߇ rY@?u^Rw494pM'&C9woOg} Y -+q5SKQ'=rOWi^:I_tk48]UK"h4!zJ7s;٥^wfMQo~aJr_dRh/h$zmAm/8zusy[D\h+~?GF/Û_¬LrKm@raXJX~9/&1 Rj -~te[h:2Mւc֭7ROh,<e sJؠU^S1q-:bB['Ϸ.%ص.=4r {ӕMpP_Zsu,@8N;NL~ B/Q׿4񽨗MOkDV >) vpGon_Pb'X* Rcnːgh6dmQ :t pJ?Efwj+>dt*Ԧ9Q  , pC{|m;i7(5*i:N4 *Rbw z^Ϥ{jڢ6EsyϻOk5:wR8zTPHȀGa6^8 > DvrD#Dq]"#YSYc^7)w)"8MG1<@cܝ Q%UdsB^jɀ}DbU'#E8p=bY1և갍 5MT(REGJ̲;-aUO|8]F#*}SdltK{W7eѣމv,(`0* A>Y'-saɵf7E# [ׂ52 }2cV!`+c khOcQ(C>qXO<*45L[Ln?xn.8`eI2J(k@։lX/C%[5M2#Pxs>LbpeRq{371Ooq[LLFFKԺW4$7Íe:j@H_U#(pdO ڽ vBGB結n/Ɠ<cJޞ;h]d qa1g:=◹kÈ35~}\ƋZCT;֤e.Qt͎Ox]$}Gz6r܊զP>psK-M}zjBmRn}b/d`K5Ͻ9#Հ5KY.Qqmh,Jr uLJ&Nf1wt=h0No-O_I/ 5 K&JɍA3*TRo(MY7ف{KPlg_fRܴF}$CplI* Y2BWp6EI\zMP'*L*JRLaL~6ɉu˜;DlurGaR_Ajw3Ŵ{$8y?%(`;1u2>ø`5$CoRX}aXk=f4 [$Z%LZt6O;z L ` bt851u<9a; ԚtA%:/۬lǝ 0M,Ÿ`÷"}Q .8ftw71YݞGp*';j!Oۂ&FFe;T(AHIĈFSw拺YE+P|C4V Dk]O_|> +r."턨b@*nh.x@tI{^BSc@Nu'#L,U̹k\5 ^VeT2֡2].P;D]G7]#/֏4g[Sze?"{s ȉMVL> =o1 :${Jr[wLKpo5;ZP1-}_(ڗgB n*cv$3biDx^Z({N1kanvù-,tF>{? Yw)WXvLhSI&N6c>{],9(=sQ}􍻪s@Q&*^ 6]$*=KܙIS"GlIfr>e>jſgU7SUU^nif4Ve>k\8G*HĮ|>4Bx ;2/QwEJuD*1gIœ ZiN=Ǡ`. El;`:TJ 95x d}%R +\c3~bk76//g~l#m=!y1j#3,sCXP[gJLhV?Qo*v|Ǚeg@.ۼΰ;/4e9cZ'!Ǽ+2=ŏ^zLP$.\Pge{ː+.1Aht` DINE$'-JRT?midóJ XV}"瞠x}@\A0,Cв#Ycgh ׼E1nƔHA&S,q-aovf 9'vE;Xvr3_m9u].e3m9Г>#bL9V#jbKEoO<}㍉?!(Fr0bٹobŤ`PP R-ś7fhAU76~4W^`4lGk}u:x`z'[TJC|$F ܫf?t9+ٛBN DT}WͶ׊+߈&&)B@T]Sԫ]^9Vl8 c(M[i-tqפo7V3vBp8Xl1S.@3<38bhP3%[ǥd6V3)`k~1W[Jwų%`'UUN5AZbt8Ws.ԩ-ɽ^x4lA8 Yb\-зTMkbح0҅$\gRǦLQ3ea?nLQ!^ʬQWhPsN&]l4% !9ㄏ␱t6N-ɮ܂+S_Jӵ)oGPO)DokTtx@Z:cttM c-e!yif9}9̰5j{1TK B  mnK60`0{L%Ouc-8i$(׿YfÏqv솙9i{KLO΃_c_kS&mA1< fnFN{srINV;y1a.Mv3^?*.R=AGq:>/Eb(4f9m<>\D;GilTŸWΈanYTg~OE @@{@߇K0t(Id8^@m7(eŏjY5>P}@)--WF1Aq"HHz߱P-v/)1x/1JD(H}ݧQkr*[KI ߏ+}V9>&fKr!!b@GteÂ8s 4Z7o‹LyqF_@W+?>)374SA;U]~?3向Qn"HeA@4b`.&Q81 cdw#[#m  3}D@mJ]) |j*]ZY$B*aY%&lV褃Zqlcf[ (b8>'Z~@|hfXBCAJ>ꢺg Sr躟AW0qdYGخ J2t\(uijf@uŧLwdD7MJ v飴0CI~B6wKq7zltVD2 ݪAЧ$k?b5:J?)SiYȮn'NtV PPJaN!iM&\D.N2}qUwZ1]3d˵߇Cx r8=^ iA^ P {(t3.IAޝ kk۝3qG-\-[A(PU[ʂ6=>tG.z@0dCRVRm+tбKEqZ)=n(9@n:2x,; ۟ѭI=@bF#MM%ܱ[xchߓl(>*J;@uBtGpmLzE)0ӈOؑX79Wh L/7xŴ 3,lU{\6_XFR.Z8(@ޒ;[OpL2x63\Yzf7ӨowB:29p* c$ VJd8X?!'ԹəQ/J|XE^E?Ț(;`X`Y =l)#guo1Xuu99OÆYrZG\lDžI"䣒4Ju=ArRe˳[sGu42U5좈 ! 7+BIBDxePߚ~fUUeTf{mkø'#F>H_ayb!a=y.-H \{++9-sBjiAxlz$ L,$"A^86~H!1ٞ%1r>bwǼw$zS_&o i- UQMħR5ʓ0f&3 A KQRuW{^PE($咛Ӣ亀 l'*nsү/t\KG7FH{dKL/,D \5C}[x9D08 QƂ&;r o?\헻jF4thp.4tM;<;ݙѭ^VJc?.32Y{Dp eb 걻k'h;hgBrң$Xl&\;~)_GSNc3R.C l=p$c.̢FgXBmaEXPp~SbR&>D?%xXGS4 $'iP6Q"~WMqyq-S}4o^s~qqKk|Xyg|bmk:h)Vd%𗛲 PlqH Oi>)tVO\#3|uLO;s}r =IODC|!3o[z~W`zsa}q.vwvt4q5Z-n^EŬ;vsg\TϾ22V#9hMMM.Laꨋk [jQ_BڮKMRH":M(yKf_.lP=@`B&h4K 󾥿?>5J` @#ʄvqfOR,o su37BOG?//!X$ +jwu`*TEq$D! e ' D$C#e6VeIojߩbÒz!zT nRhW-9qQ!vB ٍ1~<#KZK*[Wnn8* urāt@̧$(82I ǹb{v/g'T0n4}Ba37܊u`zH%q8noͶ %k[ǂє'=fG^z%9anR?[@ه*vȹ@.t/=CeT"IAQl}inxUTJƫWl -X!: w:,%aJBw р8me߳ͯ$;ҚhI#wd6.)_6 :Û_ HW^0O l,n">CIH NGbu˰f$Z=S#v~Q EE_gã һTT\3Mo;:x 4׳FJ7&SťC{j>hqę[ HS:l@ܝ7${~ Q/+ňrFENF3bi 뱫v#ةdtCHE#\!Ds,=pno9kGBd(Ӽdld{d,H^ynbbC#qQ[~( *To248PPZ0] __JWx֦N{R1'C1`|Gd T6&3疋VMv5W[읾eVK-szKFmҖg2h+h,\p)I^m:(a`^ #gHULEW!*ۑO9xA\~^3l7f>,8Y~uf@&rasn#Q]֨hA|(~SUCʱiXӫWg" =ۙd!"я  o Ip kEնI{#Asoo* eK7dMJwˊ^ #QIzf ck;h9ܘ<:\aG};}%דÉ@3husofl@`Rh,9>g[C96l(Z1 s]}2NdUK.iAr5gWry X bcw>WI:\ހm$AA3Ȭ(ƼCXl7A-ܥᠸM:t? {\x\C2~2m09+lJ[HQee*aHt4UYR" hegx_VГ#v|-ܙ$pBNBB;۴ dw&W5%wa/DE5Bl̈́¾|+A<q-^ZR joθ Fy°l %-uբȖ}ޜRe:iBxCnk;}·qY1%|)O;W^lV%5Y'+Y-O}o:~Jɼ%3ůH"_u1 8k Ʌ(nM21x=< βS0V^.񭞖b~AJy"uJ!:Ӕ)n,p%<xlG=eocQ>pSBִ5{ۢ.^pCT>tF9|4*A{*5V2B(sd<=׫R!CB~GCRْZ 2zYh"{6>.&Ε,9~5#{%XP W sg&Lł {eFt}P3ylcIIJ7{fOG٤,ZsZ67ʙ)^\6g E8leqc9PK6P M<-.kO-aSl˞ 32תlɡa>mxjS!kIRC٤@ۆJ0J2Þ'Q՟3^՚17PK#=BeJz'a~Ik4~d[&# _k{h0uft*CQ3/ԓOtrOb @]K<ER6H ;Vx#>6uX'"Oˊb +}X{ \ RZLU@l)Ug/;9;&7Z׼!N mf+,W sKEqCL- 0.Jw_o[(cÉ(deQ-{iamPU8}|Ԑu CE])j]qZ`N-xPceuIDߞN7'>(|eRb-N* ,;ưZ4q{J>3yZ%'O+vBl2EQh][:E?|\) ?[:J85@|XӀ:MV{_h88N"n2A>16 ز r]dž@۶M"WݧQ`͍V6eT-ϩuH܏٤|lJ#]Ov|y ,ѳI\Nk`wbn$,qoUEf"=A*iYX%ψD2 I=#@+ M} (3# Qvg0 iEPˤH- G]=V)kbkwEL@[8ܑK ,zQ$gBYԔloؗݝpbptzMVå gY5/{^g!@ǚԜ]緣E55Y,V w.R,%+u]AV^=.+VC%4c%Kbv0D= WS٣mw 3P`ygx@VAD<߲ WA_Y HѠDtM~rnP##<0~Et/ط0@h:12>ѶlH?Tܞb r3!S<}M!2v޿+K$E:C O9ex*|%]lgV=kkwcZ9<y+sC2Rg yCfIe|_:KOxQ6L}KW"| gwrj~QCEyUʽu{[/x@S:E?[(M]}gdy&p6'Vә^+ZYMsJr@zIHKr&1へolԐ\TlWEMcٺp['^ۓ6()c֔7*K5@?}r 5{spḩ;\psgE-J2Y\`d{&눫soìNJŗSiCߜn1mL(g`jE|J/SZf.-2xedO@ԝG3z?):vwqdZ_T,ii* 紶6 Y8dNd:ÎW5]p?YW뀝{k58@nkH5K"o'U5Ivz]F:- e\,/ؔ̅C,d?TOK!umod1"-Mo;ߔm )5I\74:䒙metb;c:cfLK VJ5EhJZ^չ-q3Y LOGZFk4š>Vٓk7[Ε,׃>sjZShXW܍)u=nI$&" ,"6\[,jЈBxEq[ ˸ʅ (w%R+qy>[_ TMFH/ a>h w?4.ZٶmwQ%@qk'AR%v 8Ή`;q*ПY6iYf YC>/jb{_. DQ([hwM-*x{}u@ְc׌K=ֱ>;q @>QI;kV 2H'D>+O1FR1kmب\#Sn]ydg҂Q]D{SR$9{o7'@a݆O֤+gfnS\RK.oY1#Tÿ, }7 81߆k,qG}Ռ;a8Ȁ93BY_bבsy}SVes:V+0@uW8_rϲE5 kDJ^N]4` YM+`԰7B.-LvVGu-~AFL;:ΎCM@mTq'ؑb{Nۡog'if =oV2x.WI¨d'*)=42^w4Z;aDXYscOF6  g6u|ƜiڠXr !Cj"w4.qGMR]e+L&l zMglκ9itk+yi+w[ k Oipՠb50{]iadj̱)fev(ᣐiV7+mc#ɲ4m xǂcHQ<'k.:U&焋lNvvN2D8!I 1)s Q0&]Ʃ|*у Fy 4 詛nY:cFj䮹 Ց/tOMVm2/#Bd.&qPWTd'$Sq`6rkԂ0[lK%Lx ,NM p^þwiʋqXt + \5|{w_\:;7u#IT-IOѻ ZvݯD2U1hj7v-3,Ě-LVG-AJݭίqQ5]~KP̠awQZ\j6WSR@-jz4ۣ*(ԛ"R T5Tڂؗ1 EeS;97G@>د-llѰ j#7z}"@`E|O`3sbNMRvR."du P1[W%e j֮3$9# >TU={7饌~W;aʄ=P 4UgwyZw zg0j=O^?ʀ7+ JW" g B{DU vTYHޢM[uxyo!~gz/V =:qxWv1fYŲ"(zE2i *{c$Q nx}G?6#ȱA> |8@."b8Yk .2yop} ͢v̹GRS8RN_; 9Lsi)b5s~1k vG}j&6+eN7Y͟$Aa(n !!PSNÁSxJ! Mrcԑ4l6܍\;k)>rr{/kQ3?8UE y.͘t/@2Y ]g:ֱc4gˣ/Nd XahVC`(d3ȉ}U0ͨ X+oUfvA ST;y}]]N,sQ,:G}vIsj|4(ll@[=#w|c&H0كD; VzU] 22i;v yڝt}Xګy[tbrʼ?nR `'hfS$twID˯^2&6=w@Sk$ PiS |s,+$Y)Ҏsdq6qR`y 7@7 *&a 75ƚK=*k袵zd?~a=#lUxݞo |ȕI- .--ʴw I]3),kMBOydHb,FR.zpD6%MH 3S;,(s6fO1;_}Cz96cxQ.t=u}֘91,%1%_OH 7 2&pEhހ%zW#r#hCV0j9suSbNsYu U7ֆ\N,dAd!7C+E$.O4 Qrق1l) E8J4FR?HZqu6-X^OqjyLґqA,Ծ#El< Ѳ7R*ߕ9jB<lnoW %8ad.65߳nkn`bI$eqw,z҅Gis@M}xxUK7̣/7~<4kA:Zjpv+iw%~Ԓ'HV ϻY яVPRbr\5Zú t}LҪJ;>0İSSx`W˲DQpLcy-:)x `(٘ݨ(w3<[ "fz(Ey%0>p٬Cn1=^%=hL,ac16~+zcP <#dd|bWLp$ ye8 ՠpYnfNщ. NxM?KQR{mSN},K^K:)ufd (w~z` deP WsQ5ZX׺X3s-O5uՓ! TEm1%v LvՂfaۊ>]ESQ OM딉~HRJX4H-44\ZFРsŒ̲4zD_ ژP%\EU05:[8v8u{K-W_t0|q<*Z>i8gj\V3XX0HTAV"XOϜAbRm6-MJrz;$+h*n6e[nG.R~9 TvQ7/)W%?RBX'Q1=p4ׇh|ƕˤXG@㏷ԆQv Q{#IuFWy:# FR/T{![r2:`5.׊yKoWFqz3&,+? fzmƾ<*,xÒU'55P8}cT:MKqT˗ O hR7fggyjh=(w]l=xљ:ș`'Y33#D4יq^tFӟHHޠVǹNDuٞ^YBL7OCc33g>(KM6QQSjZ!bf/q .<)[t2s=?YpR*$fsmDLքjIeBg0Nssjةto qq-ЋނVa_hT! WM*4)r) =kx7.շSݶQ4vBtS S';⍇<ɾC:"WY9֌8(n_ s) Ղ!^Zc'J QSm]z7t&,ܱԗe];.RLK30hKu!FO[3~gˏ]_ 2Z,쏯%椵u ,탋尋P<[ߺ)9'PL>\#OosQDB f'j9ofzd!J s6c#xc䲽Z:Dś B%;M0le\gY5%U qJ6iiPX "@ըSEuZ@#N"dmVIlUԨ%5r zXh82b;A{&2&gC˂o۱@4Cu2˙xr% 4q;næ ]* pQSѯݮu[$HK3 á^pO mcaz>^:KV B JkVm;6q庙cя: N; 9{̰y(5-9TFWmmw5z|-$]-tH͆Fۄ·Kɺg6_l1T8|V~Cs US[s9䘻z!Eƺm[z;'s "%DQ `SSS?r{} q\9>ۻuVOn]no{t<QR$ ;[]x>^ mmj*9@ DH+O@H>~Y`<q:gGiBQi ~dDi^)ʒaBL^?ASȂIu׮ѣ!X#+-/^J_oyݫgĥw?Z~񷇸)VJ.npxO {96Oz^,s4wzC& EazIS}ZB[{{cջߤXF]b]1nb"fʥsgDɲ|"0?0pIa"NodyeA]ƩJ(@PfYH()45&jaHȬ*VtnHIe>v $F vvy'["KW~gDq-VH0oo׻ڜ& ݨKx)w$D@K@ 1)Ns 65mX^Z,- :cE_qSgy/ Dy-:kw#GvEZ )qRQkEyxk<ɩqξ\%IGP2.7nbdR@Mݛ87=S6t@ D@֚?נmw}PHZԇqvӧd0DtkxRqr,G&Ȅv==9BCrC; b(&J4%APT*h}ak~?M[~w>'<~ؠP0T=,A4@^mu&5e1U{W'%fY˾Yy- sDDȈ62ʸ>^z4챎YV"L" @x,2 v1JY#w|U" *=$#oxo~_s>7<mNĿ4b 9"#"@7w#f|V(' @juBqi^P 3bWKcu4@+( rA )9 &$D6 pOnWkF_=*?)@/W&G5LTdW>HCG>L ݡ;L0|'@82N.`i甘EUuKFEÛգ1y;o{w۽Ox s!t):Ex7V2D$n>Cn1-lȟ 5)A0 ocݥ%R33 &Uלf}k:toM-b֥0F*BqDr¨dK-2Ћm.A()K$E!s$q4cIFѬK[2"U)h"زKa*,R2HUwHlWhŴ%YH%FJZ $Iq8FQ dVZX\)Y#%XՔ[ J Ƥ$dܱX%XUKim,Hi $UV ]CDf&JbHQ$$,#Qe0pKJ)V2elKa 6Dl# F0pG,D$Pw1>7ݿ u L+HP 40OE#B.f.f%!!7Ċ8C(4ToDu3%5 Z8G"RL(5 Pk$8l~?7z mt mcj`TeTCfgu6s`9t`:(-:]Bs{duqr,$"$˘hm = @,LK1%AJ1%J@ I- EP4 PR4 вHLJS@*P 2PQABP BDQSM$A0%"%+UT#JPH-1)B TD DP11H%( $HPSTLH05#2@RHBQ!@oëho (@ l'TΓ] @D0!N\Q `{y0/ dwI[ PHrCWA(p7 %  L!r9вs)"g$ێImPMfZ@DCIJPP(Q2MJ(SH/"`1fWjL1X; P7 O o*9q] 7 rv#HK4"JlvSP(a/Ssb,itZ)!rsl4d2.z6Z;N)9B匐sH1 T\ՃK4)l'B}b\DVCy%JH=MA}˞ظڵRՀEEQ@GʨyRPc6E aI'T.l xB^{c;vY$b| cJL#Fsl,v6Ρf4T-fֵ險Y'ct6BHH햐3P=pbYUv`H HJo#{3$8HD݆ YH\F16@m֛N:Pw<[o$68b6matN"HS&fyhi&фh夼@P:C3B;[ v\W7ܜ ӼӡNP2ل2 D!{%i%@ !4Jy=)iIHJBh*E( JB%iQ)iD"@*iB$ P`&FiHfIibJ" hDV&))"(UhhbP) ("TFBB*DB"RRBP&bi)$ T) & E$B )d)3.Ҁ4gtz6O1͉:4HO16aWd=(`BeG-ጊ@K a<'AIy͔ `~lNs5 c&')M_Hn`Ct O}<{f@1)"RBVZZEhZ)JZAJ(@)hV!BQ JiR Dj$ %jZ VZBZUhF)PF\ q;j}~0z<'<"H)kL2hk=X:=7;v+'_cs|k띌 qj/@" BeJar97l"'("@(9)Oxޓoa6:`(?'~'t2؂3%(Ow5ddb 0$'fnwf@INºg~wsYޢ$Av3P88hD@ ]qzA"d@_q Pjأ*͙jF 6TDTOAjʚ$RE)\K$A-I˃ib0'a2WQh # 6vW dFrF:1'ڲy('0wogҞ\H>/y7h"&sq峫Gch`w٥]3Qp3vo-߳:3??~AnOaswB&,*}| sƍ *P~ޟAt," fBd*.KPYK6 PЄ(\B GC]ɘXV@P\PYIQF֒-n#/77yfT. B1`"2-e!^!5@YL4ݪ E0I*̫\nՖXIQ-"ȅpX "שW 2nFZ⋒4Umsfh!A(wz/.AB¼pHK3+f ndˤA.5w6$eZx˩ .(sU"I(udTU";*aYCd74nSJ+4]ZؖSn$rr*(#a*"B$#D 28)I!bK-,([ fB[2G 4)mhe*c2bHʐ\`ڰc%%%T&K--Qe e#,\Y!r" eA,2[JXS ۯD4q^/@H@-?8|wx@v`bơIn>\8":{poϝ&9zsÛ㈍\i(ՙe#[Ypi'n}y拯0w} H2ٵ;vw I13L\)=ԛ>NIZ}5͙NWN8nV-'vˢ=:B")7zfnG=]0϶G];Nr8PnAԂ9PBL*QM,JwgPbzF/s )!t%;kt ibֱјd`h s *kG2bEPVUEqGGI-d([W2DdG$-`QjɑlT)Z bi *,rd$@l HKȍ#+rrd(,־fٶHXIE2LYU1ߩ8ooC t5tU4j14, p -(4 H(`n&*(UpVdqE & .b"C*J*FHEF҅)Q\E Q-YY;4w=rI&SD#\̀s6clNqEJ4Ho$M6(?mm=H?C@o?˗As֚VC/VJuC!-QI ]G>oerNN=y7e݅˒KNa(~<ߋe0DQVN ]b=%5xOUm{j??yeu{v7"!/A!;4s dv|lG"<2B-A4HD.TI4ːf ) (%@DKpJ~5K#G k H8dإ) \,ق͙1J hZR0*bJA̸R֠*0X\qrI`6I,m`բ&F V6 "Ņ $ŹbV+a ;8 ʂY+@r|h|],+d!pKhJR 6E EF B(AB&QkB7aQQa-Hf"j惤p!8pLTP?&x|G1ٺ>/VlcB?&x9ѡ+j5MJ㒽ykϧ2j+XR҃.U@4^ lrĺ @N[\ @d T0j߬1 (uۇdR{=6SDk޹dlMt?@!!Hj4BABjQ1$$0p8O_&v&6#5*nK;rY_—.;r_N=W0]fs5$wT$I7 I|_Kmo ,!<;C*I_ڧNj+kkhgT><@U(d%b)*"jJB(i") B%h*!(H%(hh&X$& %))"fi"` "i("Zhdi(&B* $ (B"j( ZIbg ګFA\2$2rZJ&FbADUQbbJ2wv (,` P֒ҩFE Z pLCx FrhJDڬ7(()Jj)V@X`DREE P1 BPKW 5m  EURai`}bV*f0 L0f*BPa*T\)MeeVkYiAb ˚!p FCw07 -2V!(hP"*d-d+ TBE " $LZȱV*eIXH+(L2E2E0'p1$%ƒZł 8N@O 1*JB$4MZũUDPd)*̑F@##I2J v0Es1  Fq)H" ijf#$X# sHkJ,( 5-k(c`كN8&≄o-:@jDEDLU hZX`,Gi+kJaX֕ PFUBV ͓:QBT%aQAb KFKhpԮBP)@d M4%9T#l -J+!R$%xkV2\6Zĕe)2kF H4$4%1TIAZrHMd0rR)[l+JR PH1E hMSabhxNLDr)Mpţ@8DH1mj2VLrba dHňAUP\pbEZrj$CJJAd4b 0h $61ƒ%hp dT@ B #QjY2BHFdC"c)3E a U- TE&AM@dDTX"RQ mY 2.9b,HR%Rb,BaU +"@ @  U "Ha/SGKmW(|s҆ d˗-BdK ,b4cCo/x)Hh  (^3iCod+ٌgGdWp.6NU+ȠBLB_(('Ps KrKi[F[lsrtWv_0@8OT7"B \E{Z]GKc򒸆Sx!f(:mJGӀ精@O0тcᶭ, tnCs<ͦ(-(?@N]OݱN&r<6U R3U鬗F5Fe? sJey-uՙ2vtoM"po^#U$dzˑH"mq\iz_Sx7tm{]ZDJ%R" HJF!Rj$ )b*(()BP REJ R: 1 @{xMK.Vz@zb"ZZPbhhbQiQ"Z*)(A Z )H? ( F"h (XZf( i$J hB"(%|/Kb^ɤ  3H@K&E$%9#1 ;•3e)j>8?0AvI2SX4P4 EE LTPwb"-8@ $$5DAU5M4Pґ"F"# QUUƃ$bihJ"R-.e-*咡L6Aa7H,P$YQ"E@,%T]6Ѳr،ܵ V 0Dp3&,0,_CCG 4TDДtZV 8(,THGYdB6.`Rlh0TEXa $ȅrH L H"'4`9twэW{'0ݥ;Sd C-~WoKKp,/`0uM綧3T@Pӟ2Ws~O3m9;W>wO&^rßR< fݝ۠h v0"ȌP( Q]C{USlBhj "#fRR,g~ۑm<'? w۳Y~&PL˜nHqw* ;;^,D%ЀUx"P ±!^߯y׎;uΣħv;P,T'T)O4o (ZWMCA8A?Nگ5sLf#oU6x@G_+c)I("d<C`]#+iԥV܉Z5[hﱣq?Ī yZִ >&f˂cc\ao[c BMqͩY zD;eous@Z;Λ]wu6vv -Uf(3f$d#UZmcN01WOq]"G45?qJ F˟#[˗/}f;>o)#n1slG<ؖ3M# v`39~ g#Nnad5vvZb *)]$*,^9D0o `c9lU!>C&AfjR.@5q+7+J1 #{DQ0=cj%e(ؑ+rK+6sNmVե+̄{m+?q!ov}-fVe]=ܝ>ֽ'DDtsz[pBmhGR& _-ovXdW;-> ᚶCB_A^RГe3.:>cv<\2ëw櫺ɿH|vД;վ(j 9 5~QܡLJh䡬L d,Dٽ@ `c ,f%uj6Cf ۴[@{m@_ | ^ * AIqR?hS6x xm% >~~߿ ew4{t CGVЂUs8!<a5?o]WZ &G-咬6on 4[0L%L.Zc24Vr rPo֭-3^*7 wl͎ey^Sϊ ]|;+ow׺qN$$ux1/ ?;`7O㖖hYhnOWo~6E#o4ݾ?Fw{J{>saGGQdmCc{M6Uh~,k,rF`ܶZ\~U~a#_wMvR~ oUvu'KbҖ̍YE]ev iϏ3U}ω?X'BѽTJMu5l&3Mb{o*z_Č=W=39kg)-[6G3`tXcr~_R41ߥm#teUlS`8W{[7т:Wج+v܏|zX.ZGOtzaȖ[uRgZC}$`@0l8wQx1}w>2ɢb?Т7r0@z6lu Pe1GʱbX}fF9w|{>6^DM%Yd 7\7+&)FE`j~GӮ&A'*XE5]Ux1{@sl03>˻ID5>cߐy VcL&S횎cӞؼ}?L$^')ᙹǿUCnң NQZ[ܕD1ܾ:C"A~ c^+l e)lqop[#lʰ2hPeimmV_E!1L*pĊ̦%>>샫ZҬ &^zRAA&oF=ϭhl a3#("(((uVv\_Sg;tU4u+%}\ yC#u7P 1;ĘLousruh`:B BI3#0 33 `ǃj~Nw#)3}P)-*jJTT|̻8U:emO_(gJl&DIK;x:HVkK[#;227E`~YiK ST*XXESEbgI'fth}o$vJ9d]e0y_Qѡt,>fxTY?|yWZˬlV}ggmYW 蘫TB4\*aLI13xT BoeІd6Q],#bPQ$>hٛ 2bu٪u.ȼ@$E{y{nx+K62=+)~>#ۗ;f2.%;xpȽW h`.5%4@bM " P\̇P.H l|8:ƺ _e!:Dyh "1i'1l% Q6̢ %-Y{| ~)qڈ}3C}-3(5cy1s9aȇJxܰy ׊ ♜OW.yv%Scg0Px0G$>3 H!f#T!M?4e]0 %,D43+mjy``s`7[:3&tr՚V {j}26>ܜJMﱖyT/e?|/:9w<6  8{u5r>Յ%ATYUj lߋ‹+ͺlb[*ڀ$*a6S&-V č5]u$W?D& >nlezW_ZĶlƝ_&lvo mv ~Oe:Z5l:yQ-EX$EB3{|rsS?kE=KSߏo3ɒQ$[n<~c^wVǛsֽ_DzLm  i*S'FMVҏS[d u`A$B(a( Q@0Ö{blE?R.##r*/ʳ9gVYQ>!wHنSq~kXnjxLWUȈ`0 iȂ]Hb,[o{M'3}]7[+%@^W18?m V8ϫʗ>MjLV_]<w5{dl?SM{^)\7OUox9 {@gZ۽l_j h.88%}B"%"HYf"iPCin>p.U&T*qeTJ"}@2WK^n?Ϟśl WC2 gc"(Ȣh>zH^lQE DEUHpJ J@iQJyPqT"!E!EQu~<PS$PD 8BzU?*"G~C`WaN𞃜}SլIhMb}٘F<>Րi!4-6󴾍E ~Z lmfs ~2xS/xng*)iz?bVٮt2Q}Wy丟w=}ũ7g]Z`Zk5'PM1~:$]g%z㇗K!J'bw1OnͰf;i>/u_~g?5zIEl4qUk~.ď yV~S 6X*߬0Ў'N~ukr#]ź^bYP ]6lSs|(k>g׈TodpP[گcKoTLhK#0jP:] PNvtUD0`Nq*!Ǫz>T4Odk1_n&N v]٦@^'=0"FW'ɶ}<'{՗xa76~_w^?_ю+ėGCu{}ǦGm|p8g=ț6C`kׯ}_+׿Ws]|{m~w p/~}?%R a^ec|U?Ot A`COU`5px$VTUCb@(UtަEP\Oǐ4'SHSȫxQ _fS' B( AK{ϰāSs ȩD?_`O!?ۉuߖ;2mG[G{f" 0\{ J^ؔ/jvx<%:pXS=R5C{QDk`r<d:яyWCTd?#fMlA73 HT΄P_v_@:7cC4*a8PI R2AW !jWN! J)x PR ǡ,щ&̮0̎n6Qc0µg[( ^š^[,햱o~N}wZFWPd @`Q ƥO51 %dH CIXJ0R:r"@rɂ*)XE bbT eP2~25 ˞^SZn:"<1DsR(~Cy3ک==oz.|g?BԚ3 vaw\%(MԆ CH>[rzIrQ8]8C槒FEkXUߓRa2y~:q GZcAHݸր IRsE$o}n y51ڂƴVAc 6:kx@UmLMP)!I_㫌.\FN10mQW<%'Elѭ{#4᝼ WНVߧɖbT> :cpF(\$͞w ws۶zrsmdeiq7tֺmٱΓ]k6~̓WX#d"9j+&1BBS"=J@2$0 d aTīSb-$o\Ej*A':)C"(%A 61B1dQᯕhD~9;@ nUԛ+ܛ&"~ DT*,zK,YaA/^/=n䆅 ̈́dɂ P@HED.9USP)M,IU5mB{\X25YiSRTeK,v`3qnJj=q>G7[oDbױ/Z4戀o@-@'D |Z[ pk`Я=Jp倭,fp@)xJ4,:Haf@% m@rU;L@b(āWDQ@pDe}uC#$"&FzcmfzC:pw Y;"T 5Ȗ M72$JD`"j5!L# @Aq"hsχ.v u_ !cR 9F5'tZ^Z`g? ^к2jL4.X h\8^cfպ"xb~5 @ byjN *^gGWxъ:ȃf_3n\q6=Tw24W=\oW]}UO7yP9XӡԎ`CA *xelT$LPq:,8-{s^h{6 >CD;<9(Ӎ(ugQ2J+ ",܍dZ(a( P;Ya3{kKPPQJoO@΁4.yWBS{ױDg9_]78U6cఓ#yrC ^A*:o7~,1 eT#HP d< 1_2>GA~#G21 iA@aO7sWMZ*u4~AF"j#G N?#1Y̜@ImY)6Q$*(ˌ < 0``ٻnq0Y ,/s# 8\% Vk>L(c¬D\ietƮw 0fEQTT` tHSHZUH^u dKsThao٢0H# * OBゆTx{|w;2P!%01 @!( K4Ɨ_yUW&AmnD_oue&\Q/Û|.`PUQ0&8 As|I q{folV SPRs QFv}E, )Zvdi<L<9!}v; e`1 mCFIql( Q1fWj`(M6 t^R~pM@×%hnno$CД UTg`UHT*CiY`PإMSU'F_x`*x{3#bxx7"ocPb) 4M޾ZXz:\-nF RlJp,ɸYCI(%@y/.4 "hldI2j|]C;ޤ,%e;ڈ"[֦9fi!v[k~>g20YBtg>qI=mcrIy6j> Ö%V)DmO!+=`on& 7Ng g~țk[p7h.I{b("u.T AN8.ܐ9N9<$n]MJ͑zܱ]CdiNmݴ،!]w_{Ybq9f$o+J"srNz$ٵ4hK?x~cuq}W/3]{>Km|Ժgas_Bљ׎Y鬔rX=v/o~o/n;iD 2m[wOKs/u?5Fsb7񷗪ѕ|'?!`LǙp\*/HM_1AD˳$)r(@kԉ"(<ˣPR/ٛϪh[=wՐ00U4zb2zcyv{se#JrGI7 HTD~L"r2)*9*@)U3C$H;Q5"B>AL(MsALA4 ߄O 6air" )槑;3=,opL` 9x$`ŒNӂk=e ǭw Gv;x;[$FD~؞W>˩r% [34Z{ޫ4Wy@T=%qg[d [ߊK|*gTS S/(?%_()Ju;gAB"G, fr )R-j~J? 6f}kՂ!&g1!TP0D `)UYH5cRfZ'5f˳ jHY ⛡U9i3Q4a64QRuy6z*p T@= MUrE%H뺯p gd2\e8#"CpG-#2Y/0RBu=A FYHĝ*՞ŋnMt:%rMzCRH J{J5=ؘ>:>utd{Jsn01z T5_O j+!!&fEG( AaB< Kkn3-x]m8X3ةwJ[ӁYhHEjhIHzXCE> ˸Pq؞Xqbam;{5p2~ڪY0G&yiAu XrDa$@,82'9Aj|y@`At8,Dk|և k%!7@Q˶0 #57k#b"sn:Wl>=ġ,z\TWMg&3PP8KN3; JOzxM9uO/G_M6_dPO j\*$oO>(M]O@ x95灹NϷ@U"AD֡, GoV}=+"W0XWپ T"DIp){v-!SPIaKVm:;?S/'˂ýJFwgDFdûLj!I)CY0fBXHda) }~sݧ_w}&Mlx 4>I}DL?E'OQ=|V'TlR$$n͐r>/߆s9NǂQ3O  wQ\E=+oG @؛ە$&P~ bwTa{;AiB"DzKږÀL]J2AM|;R;[g l۠A]!hݡ"pڣBX67o zk"P@f'A؏@ ɔ^@`v>3hrH'C^cCoַlQJ remXzQz6ƽ"!0>=€"'|!H">k#w;W. QM'hI!ΞB58]1QtQl a`~;x~ZX}C0-=;Jgp4z>v=D;?⎟dFA^[Մ!>NQ=v8θճu T3`@hDnN?3en@Ҩ7[W6֝_W joh73u, Ϫ<ÿf R[xxRi> pҙ;dH 8{{8G:{р O,5,ɺmTy Gݞ) ɛo [=6~TgjvȵkRI&ep)VkW|.1]~J3Fm 'Ѩ /^5 %,iQ fշ}-XKI/%H{5O{FK۞ Ӥ~Ի{N?j! f)J$$Cا3?TVO};Ϻm/ 'IH 41n̤O:6(Zi:ƞccYw{l B^PoRwwqp#Hxo,E1;`V"Ue.67[vGTB.PEj6uFU./ևymf \j_p# 4:`ZTS gϷ}ݯ7u.N ^g1s0!f3νVFd^M,G&<X e'wܞ@? 6ͶK]o԰|/a4x ]$I+Ѡ5# XDn+/Ц"*\!8O*OeSi^ϫ~d fCظ0n-]G1SBnI?N8.L:`ld@2@N! \p_\Z.~):\ѡ;Y3 9^d0MO^3rB w Ԁu/^b {<ݤ\xmכaүJ=Ï/>FT}X0?@0dfFD`2Gie& q{N$0f61?ǹhEC+›0B@E2SV5S !@- B8LрSyo/_Џ kͷ9,;'_i"u& :@t6$bPm!ZbG`,6-7W8o⠯D{Lmqs C89swAfV/su}wR1 b^fk?Sn=Ϩu}_񧆟#]H,D'bo=nbC#yst΃#Q`3 ] 3+mޏ6by/}m#FvFKkf^Lo^LHɤ$05+T8C離3m`θxSfv:ͷvtFt?Gz2-/m{/y;iR)7+/ B>)td1=㟶Yny{fg{(VN F$ԧJH0BT,hd&&YAb !! @F5" ^y/r  `hbdZd(an=G٘~,ݦR#OE称ݣ5ԓ2\n3KYU &mT'חEU A[~@~j^'kAM s۸Wd6d !zϯ"d@7kOT;a0;J*&J@ qFi HCUz9g/#(<9Bi[OEΰe-^nGܙOw MjX(X2NmQxF"2/eR\Xe@`b^LLrok+=}[Cb8|S+ԁro3 Xfj8||8U&M@Χ%[P'Ȱln}~ VP/RYK 0 j_@lB1˧ P~7~cZo7tDդȌ\T>I]ǟ['y}HE^g v_b}~:^M#>Hx7Fr [ Itgx9!(JE؎Mm˗O$;7*V}U>~v(3sar:u_k@,`Y C,Ѥ:oNmy3據g-OuyJ6E0!=(L}rը;9 vDW1+՞7]-nHM KfC +WB9Ӟj/*pC7&w H"cU@6Hx.J ..ѕ\1*-*Z ֦,֠FwPN]=.T$[W:a~4mmYmŽXR@.B70@O\Ja&]cnt GrsPq87Y?6A׻a]u;6-85Rg6 ҕR@$+ggIJ q5fBZyJOZ^i!-$[Ed\K-ٙ2yNs>6%$"R!`(lSJ00&gZɩYo^^s6Qg[h _l']w/f8?FC9vil]d Ǚ:[䰄݆6k@.Vqyj6+*~ׂJ}詠f U(VU}pW!)Mgmn͗CdBhH1 Ĉy~ xna5TP{Q f.=֨tl,VٯetXn>/g|ש4W:'Tv-KչAPay.LB)M_=ޝ mÇ+d}]| T]jK0ˁz[wQ8m]" \B@2Cdi2t_ФZ#lvU5&sEl5/i7on*/WUz^T=4.%\GSѬ|>x ,)NB1"XTD@SB)C0 _ׅDRT P=C"(pR~ oקU49*h(Zp)h}ԀP g /V=t"dP"I^HC9ĺ!$r2@ $#3n%GHN)jbtܐYg<nq [9ϣM<\2v,Y?xi{{Q۲]N7NOň}Fd>|fJ{/Kȩ7>;e!R@B3 eoMj1`l40Cdp?/ed7>8.kI{\bK(Vg͛B3۽g&3"^O>yb/lr*Uh6 "C*G}e*a~=az,du h%}/F r|B J֩\A|FA5* jU<`*m9=#= A*ݐO=C`n8b*?]oyzW_ :1]~vqr;Q*L^Ru1}8 *S3sPKn(, /[rg-44}2Gw X;"'msO>/-lm{\R>NSGeˊh0FplTIw+vWd@P6ս3V'~q}gOWXK(Z Q"6T)>,9?$M#βS8->O _ӉJ+\":8 }(/[8;6Uy|~)?vy\`Ud$J'=zIqsG'}U^Q͉@!g v?Ժ]B5юx6nR7@wp=pگf̣GzBT=/|7 c8a\h?s;,wYUyf(\?_Ic_;zÜkϵqz\L濃_|p@aO VUXYյ\mUu2:075/+5Pe$|_w"OziCH h–cHom( Ad1i@7K@Io]%EgЧ/[pV v!jOfg7n%5Һ}>u^:5Эn6X KdjvzWatb؃Z{]^]X6@G-~@] xUq4S?FgS[ܺ;{CuN\')n^]gao ;W|xА֘J//wudgp;x 7!)Ȥ8ZD)P4@P(!} Z_ ]y@C2x "B(d(ІFW>ads1gbk3\ֿ:31f3fQzRc[=xs9leV"DDFcFHqB@4pW *cح00r75 FY wi DŽ"}[$0`L |~2~NO3wodo# G(O:0O7dyÁY8OSUU}9S}^H< yE<,P4"v޿<!VZe~lA @9! J Ros?;}S1wwgq9!]ט0 soT=ٌ蟰]z8O =]wv/{j1tMb3+8V`!.D  A [I_m2`R/`*DD t.dQt("ey4+QcIbb Tug w_Ϻ}LwL O vWk1 ~A7{!̛KG/P vNo)n>*ftvn0x޸iq9Œlv귓`sA_cH^`;H3]EO4ֱ"dGx`ޠd]&aEt~LR;Swmʶ!{R[8:Y`.4j?/ڿs_ĖqjV700\*a 0c=_}6fj5}{5FFڠ%gi՟60Dk)L 98JL\qu5Ƽ3| ? moGa'/7ͤ8:EŵBTMcmUvNC%&}udmo]/gcWA`x.^p|k>uJGNp~dh&Yd7$TفyMXUykd"iQps A"*bU4AĂ?"& Th] 4@$'/>>u-82¡}U +0˳p~~3Cǀ$u̥Ef{Zj`xbh0?׼3w}&V zp}@e e喱4QHPl`8ܗ.w㞍ձe渍||ϩ|l>1CO')J X0>N<\Ã"2?r`o 7cwZrm8=]9+OEh|v=^k~lf7"7#1=uPwV~{(&JM@ Œ!T)Q3PDOC & ]i(u @JK`'U < Ъ D B'c*y"ˑD;Io_>#5gS/"׆wU 7y}jvgNQo[2`@YD0pK% Jn u/ߣG#z&W)<_XY338Oh9Yksyr!/̒IBC I a[bH㻇N@(~9lmCk_y8_&T!Rˣ?I#HґU3k6UVp?& S#`H ~P#'z6W{'b!b~޾\fv饆[[34%1@okl`#zy=dW>cnL/雠^&no E C}]~?/є)Aj/*%T==jY= UBs**л@d%N~і-nw9e|ԿqKbs[˷vURi+՘"qhŊKLKl*ϳQWCD_?oC崻~54'׮?^p H>P׀v?CKwЂ^:u{<=B" %MTDMDEIRQ0LPP4+DXS@Q$E4IT TP DMC EDSR@DDQ% ID$A,m41ϙokq@ N$m~طM%p9ABpaQ[ti /RnOtۛnAAS/*\87d/Έ-'`"ni4[͠qxȉb"ABPT&;! 8\΢9{|`T }45e=g0b[SӗS$wP޹ݸv8d͝w:u*ǎ9Q1iϳL{G>8 QD.tXp󺔄l7)-x dz%ǒ`r?^~HAEG9܇wX~e2'UR.!Sǚ =bQҨHP7%(@U)K` `L?f&^kÅD( ={AYMkjyjܐ`W;[38SA "P eWt ّf@̈yxoyr}n=HאpHz#sye&*7395D>dKUڙDY8}J>ϊ+{'MGеi1ôV USIaT矃M%JYU_q}mcsqvbsp86@2P ET3B P %N߀p7+!mH Gc}j:S#ɴGX?\]9("Ѵ_?%ujWSh)f>S9ƨY35'=FRz0]1i;!|8?w^5d:2S%{ntS}msHiV''p{$VN?xLs{h #%)Mw}&ƺ-e;n8V!q]OXK uB2%-;l9h r]29ie Ple:o=6oAePϫ+G}9kAb\~ M #klA6PhШQHIgi°b! bDg `Bap^[=w4B`C$3+8 1zKxgf6jc5ƾM|Os -Lr $̀2@"jrd H8*K$fF`р( Kbu2Lv]xۋ0, (i)02XB X` IQdZ?c{^\OT'3^i@ ^/Iu u0"]*s0 MA(`2rwX%z=4{e?,<'OIi(=IJ#׌30@b3y$-ƪeϚn {Ez}];Y/^@v$1:g$6wH J9RWi)ڪDhi)?T=U7;S-=t?ԃx?tq}?#1@wއw>''Y͇';94V/s Sz.X鶶%MHE"/VTBDž荸wԙl'4C,۠tCo9Ϋ5'!)x`? PR)ul@[m" dJ^.Go7u`U y7Ԡ]Ob D18E]Q<ǩȇB\&Z߉rJFWir)-Y9En ޽<9)%a¾927.# tXai%!&-^l߷RE(`VXXW)N\PRG2u)g~}~m̏񭧔PSp3}-C4^ }>vm^{nw45 >W3\ 4X鏙kJe`Voyk׭6Oڏ[;1߫Йvd`7bdk\̩R|+ύ`IK")ATU .H~Dx̆Ē,m-e7'&i0$H}̢Bbwۗ1v Lu{g)"!([ JasLkrI$ŕQQA `Г(hMo{oۙԼi*8%X,!_sx~\¨,wb㈱Vny7CodO@ǔWTy*ʆ`;ݷD"VS,\%z /ra$SDdD"Ta!{v"X 4ujYf&țUKՠ/M}ӔD$%I ID.-S5X|շVAn8ê5VspPI{e&]Y[h/zAOcpS3biѻn{\䂐!P$}EM1j TyƎDĊ  |KUZiĎ]օj$Nh zX-B*' R?(5pn FaT_3@.w[/^ce(IBA@P$UB{gʱf5e }ŇjrM|N}{P>RC<5NKW % L*!|є|96W.jQ (&8p˹R" LXxSWȅ:C{e.m]QF+~>ljI <{4euWVҠ(._؟"$4/݈vxut],a ݞP+ Hw'b6(TNSrNCH 9,iJKV(#SY• SWR'n uڭQE>omӓAZ)Vﭝ@Gp[e/?f{6<%:n&uԄ P%T yT6%L D+Y@:)Xd>3Yl}炈uN Z& א}OssO+ʴKe\DOϾqnnͰq8MTD!{IG_@qu |@*H Ma_HuTQ!8ZAWI"T (:R4v 2-j >KpB AI3F" CVlJHNȤ?+krD6 2N@: n" u  F--H'.=}HH*(r+'7)sђ]E ([ %M 0iUəRJ .TL&1}%hkP ʐ؝$Rv|H2jS`fIN܍2J '|" px9O`hev~0ǥ?J_s|)a0`nb/AfC$D  U䚪2rL6]*". L+MgPgYQ *]QIܜKH^o\l羶w69U+P⩢B>;T%\U*ؽ56BIk!dUDѣ,AE;1HPG*E M}9qӟ@کYY$$E%+5F 1[:Hư:=/g |i|ivCE/M82'Eƾ~qEޗŤuqyԤu*TnG 6R.Yi78 !M66 \҇Ú\U>UB 4H kPI Pr&ff.ZpSH[jRDFy>c=^:;WۚǷxI_9=#. ,:4^R\oʕ-Ӯӏa~|ӠfCnY볮BcG"APT|]L9,x .dJ0m#I@lK2!EMB0xy:Ľy;%t$G4Ӆ HPSBRR%[Qi BO4i 8E,ETQ3UULLUF*g|/hyyUn5+{p t&>$bZ1QC-(!Dd@+!{,f{඿dcVUl x _r =,t+Ϳ+o~j1 ,:Fng=y%۴Pv| Q;w_Ggf| ,@QcyG E["ΩEY1ȕmGsi)!)vspU棁LR|ߕǞ9 W.w0vXtL}Ny xP"@xK$6ayl]T]{6Gx~4W09&W-J:r Mad( oM}xg/{==Ρ==f`JȲk=: WOl]`bsBTXDd8%!f ۞%Ǣ}iPPR(*ǷtA4PL҅E0kDN2`_^q2g50;;xωuzܦyw; Rs@|gI8TAćexF$9/@̥8E"ONOW1 *q͛o81ϱi rǫkrH=""cWFpdUU;ş'u!=:̓|8' EcRl  Q }08S!|B e=3hM!xL{SwEإr}TJ ]͉WcNdc49lUEqFr( %V"+PB__Δ 怀Cb-g4wU@AQl1)R  9o+/ {'c/Grh$p*]A _ʬ]V9,l-ы[:5>s  t|&4)nPMTKc(՘NU3TRL UΟx+D-;'H״6W!BAyuw[}6Ov͈zяkʭB5 ;^lIEgy]!nku`0(pc0š8q/pNq>H_=Wm T5d,fMB<*÷%@hJa&j[rq`&bަYX_D@}{ME/ڠejEgFm$gݣ m8G0If)ŘP2Nq%Zr_ (*G#q'˧@fF&UтLKߖn0=`;w@9u~%aLo([km\,e٦|:v^A(J`㍥䐯e\MUczd`>.ٌq L6vp98VTӕ͊J4b\@̛."ZH?^ cՓ][FޝƊ4cXVK,Fp[1xIBDdH-kP؛ˎvVx5(09edϋY]s8z27pQȒq qUuΨ;}aUs;]w`;F pՇ~:SE١dEy ޠ;rc, YMb 59p!!q,|H6 Q,gixdr* FC*c46:-䱒MSl X*5 AyH'L oO4ԚӇ>ox^ogE*"% Ɋn4U-]mvEh$=٨R%C]{9aH-OXa)(bI8P7J# A(H*f3D 1Y<܏`k%L8=H< f'c{J&sK` 94@ hdk.7#` U,<,PfTm@IP#GKۖFCa}ˆtg fJj-p\L&vH•?PJlLfds7MrWIDґW/A,ӱoө w'U'm]ȵW>JI@ni^mzh-PDaLDҩw)):t}o[{\6"|(Cv

og*hʔb,`i NBq6ڒȃBqNinZ׭x0&՜gy7n'c!M LBGFW!I8W΀f]e&=4瓜#Tdu߮狁 i~,÷ٺ0yww{z&4i,+(y LFWD!,qe6vvـ3VJX(RCIŻC=3G4.ʣUr@( ^9TQC40t0QsQq N3*gʗOx$Rۯg-nTM:6n-,:Ј56WK&q0E C}M H ft r?=P#eGkxt5 ESKKA@PhXD[ِ+RH 4)JJD>8eš̶C o v?\|`l&Ц='fMAlG[mo)Oti9:KζC& *Rp}|BhBÉBK(B`D X⼷9-t1Όq˖bHfByDX,yD*)%Im^~w7eR8$[rHl'+ Je"A(bt2]IH BiUїhl[I p~=MzVZ][nv=l.×nO?!=`o)K?T"'\X-kX)) %R 4EXDE4Ma (;&ӯn'#$QGGiP#db6Z6P*ieڂ/27N@םE8C.`T*Y{'PHSv`Cτh҂t ߂S5TDFjOav=!L# sC#RBu #5|Nt7<31B=\8\TU|!${ǁA1P]r7%4t%ku-~~G459ݺ$=YSJ$b,燙6"ŊXvgB1B  rs&U 8|L@< `Q Aqi2dVZ3Ѕ[ajD=VM@hh)@7B_bBJu v 0]R@'*ZO"򃍰3Ȳi0arnRT=sGT,j8\<ז3XRknY?A9E~MrxT pQܺ(SEH3/ĔFA9vR:m 6vH1ٺQ"àI!kAqCgP1 ,juΣ)M$PyPYZӀYѲ֔U (A `EٜV uG MT@QQ0@U}Gf9AT)֤ԭՒAU8:Gq: (3 VC((C b# bغ1UT=щr xm8-}ۂ>ZR@EQ IKKbdFTAEATfZz6pBBJ Plc@S^VLtMqqpo 'HFAƃ/׋&/kڮ2sMYA6c$D )@B])CMjHR9{^kv:DDD4W$=ŢI, <(tD`n<7dI0pDNFx{rvli.ԂF̠~3i<\X(=]#`+kذuߗy3#kjڬSrW{F8#)fથ/E BuL#Ca|UM3 TQzYIñCKmUka( ouSX šĕ ՄY,51(+zu_@uW`$*HLk }EL$IT멨>TBpG^jn,勞br@(g?Ϣ3G:k>͋V+|l0€g8F]3Qa@A %j5BDXa4[ND(w'e0fÊ/]i`B!~!V[:P;:1LTɕBHYyyC ɇn-5iޓ$7>ބ1[,u:A[*CI"F xlSFS3R5L9uig_$^X\y+u\gQTB+u(脗%/7sWS[o+;n7Cd0ɬ"E'87;ܾ)͟ڇYe{mJ@ş p+K,!A:0z%y͏/DDA*5# KH !Zh_gѝ|%HgfAT,T* XΥ#x =T}Crݰ9to9bmҊC*h!n8*^KFBwtʺwas^kMT#z!^,s$*R,ΩlX-xs 0( PBe@14M d%>$o4˩5E)CRbs7I ))15s̈́96`PAIg@GN\Y^2-^_'8@Q`+|Gkbs Jz 8sue ]u٠=q01rso2Ƕ!BH*bQiwI+-]$6!F~<Zb\/KlLvmohdՐlpu,U>=6hw7w{l,p3j%qiIItdڱ',Vflѩ;o,&t~^o FBQwoCBGm_ ,8 c@D@"؇s vSIHyٶ1.A{fPW ooAD8*w̖d- h(2J 걧  >gnV`dPR?߳:NX'~fi9a&']TOqpTǔ֛61TM;3I>Eה'uO[IBc?$2&i0Ͼ8ys&MF۪Eʯf s$YnG/A# 1']~ Uu1c +h;^F`>̾HhIUR*~ v|rA( $" :`!#i(ZKi~br7q(w! :I%\M ?|N;O~gy{@{7/8UGO= PO0u>{P7`"p5!І[t.TؕZVJ(R"R J(PP@@"d`솷);>&u3h@>XQ͡zS7=|xBr~߽g1}a(/[{e3WR]̈)#eBJQ4(C(C}""*}mX_~ݵkUegyY~~}O9}i|Ԩ/uwzo϶¯ʞod~3Ƒyn+d#R"^jGЩ.**@D0 c<(p")PdEB#0FJLsvyvス=G1H -=@2T( P)A@A)@X؞7).q៝ 3B}i3 jE?V Lyu'REXe0 I;${ۣͥx{sɡv\ |RY$+ᥬEȅŕWs?b'˻J߼?g P Q!&y,c S!!jJ`|07MSZi28Ad2  [k^.m|n'hw_ω+'Ѵ ddسѱ 0v @:m0srb|t@@@)@b m(ШbP_AZr}Gԁ~=Kש\,>+_I6L%N]b$ z߷1js_ ]"x(;< @ ItZRDC}oۿ Kd Z ꔜ dC@&2i Ifjwj0:^~#rk<9"i  "&i  fBfd2}w>[{cΪoO' 4Pk}|?G\et9ځd`[mFL)'5]DI y2 ts7DgqC1/vquou>\P-u7 !pG?bi@YJTFT3B#1 ,/X?^ ͶNr>Kk춮@j" 15bf0#W;# j;25A.) c6~hAr^}׆xr|>!a.}20Cܔ|QMA*҉J0 iFY#*@dђ r`"tvdv@MHDJ2 .C$i ]M@$] }jUU GaY֕Ũ@C&< b[QU{ʺ?tG~<Էۺ9=Z?}#wkU[ޜ= Չɿz_]P͢ HQ0T׻$ <~LmQ^t*mlP!\?@_%&3;9T.]}~}-Mj?~uù5vl2#k˪drHrQ3u1٦3aAgYv/aKῙ6ޟsKK҃9 (JR -UGȭ0{o-4)-\S)sm#bV*[^AŽCk<} y ̛0pR {WbL E Xc/9&ji ŗgm=7y~{mkxy [Ϗc`9D!Jv#TĮ!]k@a ) MRb-3N~xlX$p! z9;*)Xsw;%vC&vԮ4 T 0kj.Xˌ2K*wï,DWU ;@YӀ'1^KSrp9O6 GGa HMb]sJ# BJ/s'g2klʤ/j2P\ucSGFy~W{X?cܙ]rF{껔ΦQ&d'`-!&U'u^kH YJH2`"i=cQP;lۨfx/Xud3;yI/ Ry>3q`$b #m8|r!.|?Di3=[]yyNQK|Y?'R*kS[U<%PW83T`X>үt/fl?&p3Q i/柷3,8.Tn^it@>]ն 8ȆwJ]Sq:!ՎznVplzLg t>ֹMf&f)3()^__ς{v02MV͏:8_'b0TjY](яwaQLDuwWU ]ht+: ?J Lgph\ci/W| ߱6yTGn*R`0s{ J!Ӌn2g]LDršv)Z֖O ndz|(xx9D1c77 Td}e+ h$Ѧ1pOyZBB_-YoCa:eS_g\ sV24m7ʈ+>3rIaGδ4Kl2kv_Tݑ}T.*&+{y+]l6#2MiĊ!8[y\gF1  i,%DMwe.)*Pk_) 9Z7`o 9,L= cp֓OA0!Ɯ?~0!;a>,[3x ֓-YWLJP7˻p<+VqU;{d@;2~yO v3طёgk=g- "YIЅ82' ؂f(s2fu;$%7Ղ` "puadQd~j-nf̌Q|_w!x)x5eћյ2ph"ZҲg4+RZP  E܁-#~?qsHY)INn۱j#b} ?wQ=K髄?Xv0[x$׎!D R $: ,;_^_Zei("L}~xSlX.݊)Y]cUHjIQ&``R!0R  wlyR2$NV13+Dlznj/~kGzB7Ȣ :w6Z Q^At g> La;][.eKlh}zƦZz}]o pyu/̕k(=?]gQS'vOe湭?y|I$UE]1AQMUTQ5TAX0UEcW?$}6~HeT緉" lVE~w'yG)B*g<}0x|\#{kog?u W~WNsi|;@5@G+A5`z7S<fzr5תpiD͖QcǶR4cDFI)Eӎ',@׾ !o+=rHIB@ (3xX0Ra^&W/mn> PvbEt*B1WvG:k`H2fFf 78_.J > 8bdasT$tⱂ*JN7h#Wek5څN#7r Us; O֘oߟY./O"ZQ> "d^ڤ6Ԑkڄ $]E 1]EH7z<{NKWxGzHP@CCX*[r~Un,LGBH*ZC"BG6L]vdZ-j,V\Xb/?_ +/$I&S*` A2,.Pk;z2(m Y* eeq-1]v̝r'7VQ Pc{Le \abUO͢lA52i!X)DI4tp@[~L̝`MRJ%L} @б'e՞d CJ03PPYU{}}-SQxt:(΍Pm" #d( FT1-8iFȿ&"F!7cƷ$bR*RH,4lzA0{wyVNJƛ858#W2֎"-1:S{0ww_.ZY"z(D Au\ 7eeK }5G=Bf;IAk` 'w"t\D Hvsٟ.  ȥh腯j9dQޜ < S|UPjǚ{=W׋8U%&V!MH.UI/Ww.5UFJܬ5YiQh3]0dǵI0@"A _6 !!LP\ݡ ,H3"AJ0?J`Yem)ƺDBro`@SlC(r q¨ *^†of0[Sw| Ò$S@A?Ұ~^%!n|'nl ݉a(aWFy_}9I(b.(>6Z$+*B^\v6WFJDo}(B!,P^(Y>xĬ)9i@em:+d#ٕC2fJIϧqj=a2TVg63)|✨2F*0BƧ ËS XR6gMM7 oZr/"\VDiOOkwXI8?C{t`T%Ð3ssJAe Vn""'W-!d8WV  Oc;ScJq}!7^b*1@$!Y 5,g-$;]419 B!cccOe㎾u|xd*4SD$ԭ?ɍdH2DDG=8hXBuG!$Q4`M[ܵꝆ|;xU(r;luPfGq6Q,X%$p+ 2٤fQ(p R \J)BAr& م@IX_ѝ7"f({8f UxUU1Aӵx{ }[#ɱb KzDAOVB.@&ǁw.ϖ{L+y3YIJ*'uq9D QTJȨY#c@qړ14 kmCKnH$ECJW+ z7H<$H \ aBG\'m\9^Ϋ }2hF7!]U[+5ؖFH C&:ccˊRk(MQ3V4 `{Q]"2 A^-FJV/|,r69YiCQ9ŰPmU|eҷR $~xAkNr,w=&( Ų]Gf<@u6r{2*@@q$P q+DAUQEBDS^m'h=SLǰ0c.;+&0$e,D*u9eq98Tr?޽fJʞPTŊ,q W-CnZ l+CIY#eaA<(=ZA*'Pv#BSPNx?{z#Xۇ/n*qXr#.YҮ:-7z*Turvj[jjXAj0&ִ Q=M+.)!XJzь(d(d*V@d |{nc~А11ښ^  6  E|s>&.pUX04 &YצCBEDD YF.5^?NJ-WIAT/g!d6`NQ;DB'vLa>RX46sU桲;ގRYl_M2yy)Tgpog]gKs9q\CQz }Q|9^~jZ$v 0Y>a!{@4U|* B f'bUΗؒ޴;}~[~,9ˈzg %[p^hXzQ7Ao 귫QJ/ۋdYfأ*!YE58!w$ŋoT9O%y|&ŨOeoN9L@٢ x7{$]E,dy3Fe?|oZ{~Uf( ȕ>?tH6DQh7>=|* "\B!̿$+GlVnUIF!޵}sE .VPsՏyT<~SjG\6RnLv\[Lz}\Lrd$JA.i cp9;=32H#7"pynvRM\ ?h)â5G`r(/ 'JGԣ w@rB$.xހ!3CI0`J}??{b4c`){R (9,sQ~}ѿ߷:ij}0 $V>OǞl3iĦxG# ) :t?l"/E#VHpy/0HTHL5Xa>w?yN;ᾆ 8MȬK{Dv.w۽eS`M ئ~e8Bd^6a@GEu92-[ ξm{vIg6oDOKk%1wr+̯ LÕᑄU{}x-smJLUw[!sQS鯶dkえJ(5/܌!78|"@^eZ$B3*%h{[_7R{qoR:)&{L`砅)F%\v;tR3-wgqmNr&kkc@XI65bVMd1ŚT ~2B@z:yƁWm*c3%pI(@ ߁}m?r5lWix2A۟"띖1ZqI^/~8*J"b W{O (f9mz~U"0s{EKcN5 ~8[|k"D;浽;c,v뾏ws|v& axoƻ68]\`*Yˇ^N<=TVj)9k0 J-mCX] vyi[D m[n_:1A>ِSeP#)ckwN6@3w] 3  , %7d^r;sE/Mj& B]ۜ}/`rМi "n* A<' ~?y:em3@ fH``j+L5Xbc{̹S9p[o󖔙D[$ ǃP;*0=pwk6?ڪjRG֎ Y\{˷nܻro|{Nqn[%@g,yd95D;kBm*c >'*cX8Xj0LrV4R&ZU]SXE[$RIe{$y!q}Aʸ>ڤJSWm;}6UZHZ D%;IzP+)9 &}r؃9滝 TOG#Q'n͎=0D$(E(U2ڶ(=f3N$y$2!oUKX@D ǥT,i"r(N\"f'`Fݏ] PYJWHDq+™Wل3k%fDŽ7!P V^T ApA1f ڥpY2A143!XvCXSxH̍nSz E]jD ױ*_~B ȡ'zfsJ)_4Ӫ?]* ݪ٫_P=w3x}MݟQ?}oGw^@WRpj !=ex7=Pb-^KAw~g; **B(2! t؁D-aSwmƑpPj-,.H%TH LK{S뼼knG]i ւ1PHUZWAȈ\<b +Q1u"n-\xoГcmj|T+}Ғ(PuQЌ?Gġ]/TJk !Ʒ=׃&xD=H-S7VBpY_!<*XҪV,q*C:+h^"H 0 K3&h~x!r0 %qv7Ee!)0q_ "P@e{8ҳKJN;$:b|CB̎QJ_P$P@(pCoOS^"$ML<ڕpJ s[lk-wd+zd+T L"Ec;U#R(dQMBqp'$͆1( }v!BrD?mFGĿq;.}h횱%gPb$bι=\:'E%e3RbT_y 0ZN 9JSih'uO}ۿ~~|~&1RTYe(2oh`-]8稱fem%H:R{f 5ԧ*q#ڷ<CH ujH 1[x R1I`T@ Uz ,h$35&@P<A+J:Fxp>Q=4߽ļـfq<'F7a@R=܃/GɇN9`!ݝ^iy$b/6!N =osd~_=:jQ {-tH`7Y\?b="KbLpg jA(d}f!pL0HIHؘ,CFV 'B.%Ōf͓;}X!r:"f Rʋ0P!&$[\.du3dAndۺۖRpEr(u\г]#|Oxx{Hm_b%[YL?:{dnIo3yuD,)J2ԘK\uɎ2q"PµIӝm+ٮћĂ-E[2{K'Qd #G 7/Mj0S%G_ 6V{C b߶@x<3**qfog{t.Hz99?y'"!>)V0YNAZqdY||k}'tKlB  %3$rFVj_oo}v ~,z__Z^јHQ P?g18#Zssl z('s8J_EPSlVKF $zX1L2+A+ ~-a^a)?DF ##3$*iA$Jj;1I. UyZgTW1=nw=J~ 7dZ*IدY+ =T=B](7pBA RJP$BjUI(  zKԨ 5WW}xim Vղku2c;ܒ`'ٵ a=_ܴ|N^1#!Mrzscz5x  'Ӝ$=,Sk@@հHPċ#%߄+f_+( <^@lzH~`\ƫa ,=]B,s]iU Xw[OQRDiz0crC ^Vb!l35sr>> bk8߃tEhسַZ\P F:0O {XP EU;uc6*٢л;큀 nMA;'o~֏[mӞn#;7o&@jY/\֍ vGBH(PAc#q|fJ&Ѕ i X9U; aw[}KqmLlw@3tC2hrɆ("r(:zs & 4$YB-ƪ`0ZQ#DCZ9n#<21 !w۫} % 'NES{X@͎p_m!qaUOfA;]_Ag0L{_61̓Y Wt  ,ʷ&mxo׽yr~O*ٌB{ªa C]o%eghƢ^7 }r!!lNBUI8W4YUT5P(3@LcIV) V)<5:>~Bϖ&$=ð +#ǒթ ѱN`G(\ъJ*p懠e z Aʧ@MRNe(x>k i0WO`>Q! Gv&#SvOtvps8)}OT@Cϸl{OvY,Kd0fP4#DDR31ukV.?C 9a%w,O3E)D B) gy#Zt95Ǖ  p`I 'b 6f sL/`kgyBkYVD84~ݣ^p=>ah>>Y l}ͽ~r*(?QKIG9q4ޟe"2Hf~Vcmѿ@ș&x@ \Pl9]mMJC8T9tq{l sH&ÜCఏv SՅ̾wTO50j ~1o.2CJ"(#J!z< l7ex@>c*n Tt _U+rݲܭp"~0;(njK4"aes;QY˃(WPQШ+^ݰiӑtsB1K,.qV @B*OeT|eR2`= d-# Ȃѿxk}ަ+9)Z T4lξYw^rcV&j(oM?k~7\qٶܢ.vVpSSL]]af ~h8r}dpw<f9K_~{029#Xok)/JeY*9>!ޓrH bzc 7]>jW]s ĭowc2*.g{:7M1 ?.U%B9A"WB<󈎢 ,$*)5L8D>}@\Q2h U sHj  F6͉q{sf1aiA,=q5bRϺGڗ=EUT*5PK{]@P<P9:i^_ j/֛}xW 8%d)o,˜\)t9CrX}!5e;bOW2tSC4P6n)0HA(;|ʟQޑO sBLMT >q!( ,TYidT7qR۫Y$U-_`zv3ㄅk[0Rj~ڰR0Wx*\aMfo'8=HT-C ] ee~vO)ଲ( T8&3 ?uW&3R*_ǽD&BC_nYL3/)lKtU" heS6JNWvm&:'#gM~x}e{DD8~3s z <8/ Hj * #Ik|KŅWqR09Oń}$y \Vg3ˤbJ0@? zKZ`Zk13 UG1][ l'abhqU=cyBď^j|*9lr 됏ĵ@}*`e ۏ: &8ȯjGƢlq(7.l@~24B~*N12B`xjk˻8˜'m<˿ʧJT\/:P\gϺ骛4@1*/m3w~vPNhst M*wU4r+ dk -=mP͢JWf((,Lh ,W-VNjzKGOOMSG4E* $@AJU I[N.@>$ '@2\Q(EIXHt`mnJp& <(A}r]DQ!TK%0z՛>;y 9)!Q^ǔyCy.v#*q.̸Y󮟪b<8*$gw;m1XL6])IBs'H^i~x.\ Fa 2`j-Q+*i2j=ku;5&GqJjmiXi+`]hlwnj'8Òȹvee'+cC8:=D*Se+3@W0 ȁQ(1|m-;nlke0L^Őܬ\=7!֯0C# vn | ryv$3tחfI= IyJ\S9D#= pœТQ^UǙJrt]nI#l+[</ll?7Oƍ.߻GtV ι "~>arapb?F1ua2 ݯ ˇ˩kɔO 6;{屍rn\fAd]) MN者U?UFӪ#Z:94$E#,(d;=ڪI.D̫X IW=Wo(vR,^k3@CHX!Uׄ@BF%fx# "H[B5>AyW"SӨѣ.cz3q RY[b(ܳ̃ ՗ZK3'j"eX;`ps~G\ʄ)A>ՙ q??Rǹ9>vw1^^?f:e]3r/zl_yFdG9#uaGBVV1l(+.(BR feF, W}_ySS#ρ )هelOUEn N b%C%%RtG :hagzއ:#rou)ܫc$B!n=[\+)*ft0x `QvEmf$b)ngޫwfe9i8~?#m3]yr6w7Ztx{MoWX#"a!ALL}lf~w1:[1 W+yH#BO|j#kFv.ڟ8G>XՌgL1ßnA`vԥuUXIm͝ LCU eF _rsbKN2<3wtv̬3:ҡiVBC\FEAyKQL)YZ |k(uĨq:Gٚd.4˿Z e}-sQH4 ұroj tBT]DȀ?+٫~2KS|0XfJ#3{qdoTriK0&ǝ |'OoZP+p~ϿrDTA#]>(/#[SvEgwG ?g͌wVKI ǻ(k;vkO.< = )2O4@jJGiLR(?1+D&J ElUC= Ql&CJ %m|ߧ6kՎh:<= "[F'M4XPA  G{6B?Ӷb1\f#؈ݪ13 B,g'>ФKоH1nM5b0T{5,2&@~Ll0b a+ΈS|_7[mq`y#-dE:?rvCdw ]*Pu7wU7=z*B0_G՟^YPn n:G~w YNrnCFA[]DGo0j[#`D(1b,CVX†D$B$ y5\h)U楀1_F|,' &Ba_q~-ً@S3Fl}zƬw)Y<_^+"nz%VW,p@.'3Dqй&~SkQL_kTGLJɕ|ц)~5co2͚^go5ՆjN9w 54m: F, HP~U]4=Q떣%]?ө[G\fNroC=be͛8mMv٧?jڛu,?6XgcZ-'ԍwf|wfpVOU׉vS[} ]roh<黹~]_SzGNFuO}ˉ4Uάl5g VHaEy': D{[(px+et_N şyKq2x_ϢNzbEV[Obѭ>&tI>N)bjW\Y[5ifypLɿݩ6)}jdj$AM#BR`ݶemh9Ы,Y^].1=^D~NGAPPOnr=>Ʈjc[V F qgѪqEF@)\ Ѳd[m-/J6}*H*XlG׫ /:-WncRTSB3],<$ l~Րtgf$Y{:2}M9a˅E ,Ңi DGȤQ,ÅB*XoaIx_վf4UQTq߹| {W:wz@|CUF>lPJPk4Q;sݬ{@̈̈iDpP9_P72rL#C@Ru(8CS N?qgކoSqp85~8w{|N}z>]Oue8J2вQʛ.{UAzLF3¦w&o~mZOBTSYm=O=f;C^"o{?1w-{ꮐ159MkIu9N}Eحy"l(,2@&%% 0[_Qv7mR(w8z<AŐ:!q/cf6L%?Ou{K6CRo8tᇸ,_TקBC({?wCxEU(9_΂µ9hB0NLLٓNćO.$G? M'vטD˾iZ/ `;JL*aCViNI\5hNq^D 7lyjQLrV0h@Es]VG |n68mX,eά 2:Tȥ"I3(òhq5NI3O[qi\]nMP-K- p\2-D&dcKe+n "HpH%b) Ba?8}ܝcd'\wYjs?K\/ٮ_x}ǵVSV ^'fR^3#C7XҰKsQ 405bmC,39I *MyBHADE0mݙu޳t(qhrODTΗVB1G7圉Hiy+9X_9]W-g|}' D;"^'="3PB  GcՋmw UU@>+v^TO˨-C%_TS'Mg;~ PH:?:$fIv*h먡͈(ºA`R r@"H@Mt'Q]./Sfp1R%N/x%WVM!ID~N~?XVQLtpf>\ B l(v{tKd#< /Yy U<AWEԉh'?g#0r}dn:Ls9mN^zÝ!O?[Y wyVW9n#Yyk^`1h<4n]t2c_iQ??ڟN ߇N;΃U3?p'[ ];XirλRr=$$i_7uU:'yl\˫]owן2< $HBqIZ}K7Q?Q|)ĐJxYSMp1l}SFUgyw|&H5Ok|N}DRNgb(_RNQ&UJ@قU XRإUsC*L3ڻjOo!${-4lM0UaDv#B2 GhZE|3O}6a/" J/>ݟCaL8k=?m/?ɑX Bn:%@gEV[ k*"1]CA_t?݃> =ۮDA"PaZ-fhU.pg9֨ Db: SJ)>>-o6oe\^Y~__A4M$7t> ؠCWΎ-_`<js;slim!Fn'nJǿdT}bxYG D=<^M^stMu}]L"Y"ҺjKuY̡Rk@4B4cQD@њ[!d1;h5gYe;?ԷUZC#(nS~xN_JW9oB+5Z~K]Zwr!BPfe\aN,e6P'ফu=n]m(\?ά>Nbײ69 3Tcĭ -[7EcSjrK\5 ׷\29]..‡tvIwp0a/=h]֌J J*Wb)+%SThes2Rl"B\y6( P:^{'2k$lg$Db綶F ƵE+Ea d@,"T vyP E u` : s]Kx!#(`<{{"vB;zvu<:iꒊ+=Bs'= OF}m  a˓ˍt(zx&;NJǍg,Z vO[`tPX]XMHT%Jm!uu U@8eJI+X@LS"HPjLSL(ei%b.E7I{,E0w]bmf.P +Њ=u1J2Q!`qH VohM M2WF V a C&0FCL|,fUFc8HD4Q 31 luȐ!**(61d(Û Ib6.#R@m'oJMmLIUJ%ظQ#ʹ97lr"bC/9L [@@DӄVIMQFCPBHH+GS,ph1(D &#v@ȞICZFwe FF3dsb 1Em[K)\x'5bз9X"S˗ԲAf.*m΁pxIٗN%lc ^OC98 RkB|>~Kt2H^F@&CL/ ?|%|V:nMFADhՈE٘Lp{6L jb䎦I>4*qld0b˫IMtc3oL+u$뮄پXVΫ2#˔ꗩ:g7Yu)fo'9%nXn&ꗅ:g]ssKđtxupÌNe%#N]]Sa:Nw=z.F8+{lnn`T+ӓN†o݇FcvY 1˦ TZtФXaĴOt|qg{sL \=ȇ1qs9}cӛtǣ Ѯd= Íi&+%Źﵐ4BT{.ēx*ݎM6N ^!ӑ&΃Kԉ^/Z.YNCPomCO:,#!M|;eA4:&1"eY+&&23|onEw8Yiژ$:*LBlɤȅL+z,/zkq 5ăzIۘ4><D6'<ˣy2tF6SEH \.%FZL7wϧvi6N}ji91J [ A`;7PςqPY B tK˖*@Cq!X1!/.t5Nn/ 3sq=3(妵,r%TBHZr1cp1RR.YXml  0YrVMxCB43 SHnpÚMĒr,(OK[λw띷gX/V@qx#nY*Ý'~]z!~ l Tӹf-s L ^rM AD`CbKuG^ti?{c`;3Rޡ zg'Iׯ)7ӝn Þ~/L]:(ӍsfAW7 <bN% &jPmLE`JTYs`M*p @4:CJMx9d۔ԁMbdCNޥ)C%Q0DF6;vBH(1feq[E205U9 F`hZ`I1`'lX Tff2G!͋7fga2`˛ZP2U2LUsUi Ȥpe(]i&0HlmWіH7XDSTbDF<6!#vDq:/nQqi{.[!`&`۪o f=6{% v[&FbQmvh KIr6#*K!w.!PC42hWoߓ:Nw;1=N#ubu/Tt:rbs #۞\#|\g;{4Tn0X㜵hk+0I+D!TPą!(k$]E3y 6(' 54U%b7!"PPv#:"$Er Xbְ33Y!KUABPSd`o )bd(^vhadU+A [%Q[M @hfK:< ^ qx)9Hr@ݓqkh ̙  */-PP;E$KQAhΌ%[`ڍ$Rʄ(lՂ+P VJ(U&$!(RL 2+`a{\vޅC,HXQjT3 A 3I)C~J⊘bk;C%@=1RdQW&>#a^2#lF[QI&"bYU+XOaѶ 8Jmb[Lĥj5=&sTJ"'|,9[8;WRy0^Lrsk Ëf܎xP "ƹ$(Ob gϢҜ^ۤPG,!w7OG;w77>\wouN !lCL.uSRov]jY tel+vР7+Phq0? x0p}.x@x T *8ɜC _%ʼn:2tՆܠf{ "tg;O=c(zq,1z~'}sIwoL**~`Fߕ0;86>ש4<=rngz;ެC*A`^ eYC G}`#Bd0QM,dսd$PBܤ$HJ3;͒.!GXJ VV)6B ($NobZP)7lT,ѣw"!X%rWؒPwFM[tɈme%3Ve! *CX EJJ@J3P`Hh * XHH> %ޒJb" (1 AV0RBQ*Tk*R*b HW*B-R,lrpfeL E'w--Nlí խn(Ԝm P܃?EG+E9y/NєҲI9mdQbE(,\jŘ%F,dAYX[K*EXfHV1I OC;ݒu-pÍR((o-PS,N 2H)2 $d b JeC ] *k,-*1dX# ֊- 0{e| F6ٷuIPYT e2"4EdHHR@U1وmL5"VEDa0͐"c-!#["b":ˬ+\Q@6rɉ$u2 qARATQO.Qxxz[|{P|2GO#(OJNGxRڱO+ J|H ĒJ)LGƞ\ǟ =C]j;Z_׵3[YI@?mdA@>v-Ab="7 ?ȓxRX _NT3 B/h+p)Ɔu':@](~}cmJ3?5~&[ n9bH Q_&sv-h̰FoX(`5bL 3B.fh0w#Z`GorM|1xukM+n\PzG= lp/4)T(hQoǷڠXlf `brRR;(_0`,(fL+@D$V PIEE/ ?-D$(!(p&@#&{X$`j5le-O D܀7(dTAqAU%RS@FJB/_г+-yÂ0~#o؂䇞h+F:6]E{Ҡxv{9rhsE&|tj}V"בoSQǟW 1(URH'znlҥ7 s__]Ժ!'tE$#-2Q2!(R;yӯ?ok /Bc`57{^OFEwÿX$ %I]{" *63O(yƂSZLP|kPF;"@8&d)Un~PM ,s S-w)L"] HYHj|V"M/_|[l0z&weeujF9Y0\Ej_# BߦBj7 vh5 xF+*jmRjG\ń" lQ9CW]l`W9l7|{mͰI}5 }5p]Hdldc0͒?@fy}9d~H 6fA  H@ْ0iinߦDZ訮>'0o8:Gov:30kdx =IRqX+n2~ Jyϰb$f$& F0&aLmCaF1!ޟZ4HHBB5 YP`pI`ЂO5aj+1)ь9V lvG0˧Q(z+WޫBvGCSLս>Cx fh Djw|Gtap4: !I@(`L(YMb],5WZ.'<O>*vSd&$0%6/O0Ժ { +JO@=Zls y7{>ˀo N%q~Wݩ~ř~K+YY7?cwU 3ae2AB$aɦc2(f",rpswF&D%{׍2rٻnT&TQw57S6?IįF0s2a`ߌ_I)Bf7 _amSˆkԳLHve|Z0,oRT.t߸PhwEHg,HMgWkV \ n ZRq_d(wCaX"?k@b1/S*CPlTu(|{}6C{t~gpgFF3pgxJ8_/uDbXG ž4jնA 7{wlؙY[hHoy.w/lkd?v l?eﳞgG_sNLsix(G{rA?Py :9?x\ V\= /VO[y3lĤ9յr6xiohG>>2FD2{U^ES߅0ߖO6AX C ܡ_ʭҟ @,`40@huC: e# Ddj3$Ǩv,\ɌF=cl>Ҿ<:K `~}A[hTlVJ (JR}{e&264wc{ȓ_h_Kt>:zf#9DD@'>dތaBP]xU!+nc;›?s_,O'R$nC}c3XVC@jLOF. g "  3RNs I7eƊ[vZw _OӇs\{p++nߋ`ɉ)9sQr4SB;oMex.I>0h$$H1@*H1ޞi:gk>'N?|÷~Bs2ZXsaS;Ctk{|B.ܛaG9٘CsT6άDF*)1/j*X&*i࠽Ae oz<ҊRR`.vG֡SB\:` 0(>'h>m.B=H1TlhDwqf s,Ek>ƅeiE{ƦsO82ϴSAx^9܃32'qk0O.q`@S<\|YWu`B$pe3,^{VQJ,϶꾊HD845bn>T( Y(Yl140bcW}'@ IPaEךbTF|kH۵_+)tG–~/I©*2iT$ % T;}J:lPs^80Vg%|OJ>s-~--![ (#'nzvEYVrå\d;̊taz0N f75QhUM"DHvӋNާy͊QSk6E\'L}OmTH$)* ł'2u{v{Q( v|zP`KL,w1snqs9O9@NK q~hqvk<^aù!BzUAX WocOryJjn;VQAwvCXwQ RpZ,ul>T @Owt|Y $፦=6pUzaJ!;,ڞ&3<9 ]˰Z٠h겑9dG{|O"dܟԇ& uUT4εF +DD+@l%b(?ΦJ_š!*LX1sӬ<iO/r|#k_6iɂs P?!($9wǒi Q 3{d|/_Bo|u!s{'ݮpPG{@߱ȥ1,vW^ Wwy{pFk}TNLoSdM"#{of~)7?g\gx{`셂kwϡv(AP,(BR/4$ SesΙӊiU|swC!pY{sT(@w FnA.df- 9OwIǽ1ľoZ^=MR3!c WPL-QkEÒr PsH(!zM>3wI=*( |D=r p( 8] o|2\*z :AFf+GSn3,>Ѽ`h i$1D#H2t_ȃ v>-w:fG* 5'hwӍ"@.-%)\vmQAp{sHU7)>~R7D<,M;O?};# 3F RE1&$`8>+009 Pb!Si(5,h1 m _lls1|?ỉNŘ:$@{$1V@^bÅx]D;/dgE;bq e_(K5CyGLT 2KTa; HvWYܻsi M`wܤ<7 6 A #Ju.FX>azţ/ïrݡKCOʜ]wb7H{7Gih:u;vW}?^b0$}˷j}\><%uP@ "bdM ,XZ^JdƅIMIP釬xrs2-h*쳘\91o6,Eg J$ R W~ X]*0*Hox@I|/NLxPZ?]nUmjh2&`BD_?<7XqXoGfdw/Sb(_H3f"U** B݄\ <G<^YZ.9Pdu @$ OzqVCB9R?!!{?@ }K#>1nt\L֘pgfExkD]58qgBDނbSOz5ù~ou$wly{;f"װtܟ Z b (ey@xnzE5u5ˊˀvdWZYҩLeb,<?dz؎䃋`P[Ok]!e%Z)}P@Iק* Q,0BJBe̬qױ ItDPGzKhTc?U+s>\oy΃unI2T}38ral ʄ&I2h@{F7[3bnFwoM*Qz@b](mًnyl ȡ$fj!cH.pER܌{~f*j!loѦv g3Y&l8 & ߦSk݀yVS;5eN솨l1ɯն"i V(z%`Ű` X&n83]B{*38r2Rrvaü5b"N jH/(08$'@k\xl &@vo($1|">3IG崏 +Ak$(|C{ip Xٵg0XF)ꞧ^',*#"pȯ XǕ ,apCveL]:Eʠc) Y6:RGIvH˽h`ɸӡ=5:򝹹 eFDAisXymOó{y廹u"yn}z%Ӎ㗟OvvqZ} @-׆B"q=n*votXHuOy?_?]Xb\2"8Y+cŬW@.b\YA:8ϢX#0KDCpR зFo79CpLKw>D&wi[ܞJV9]w U*^Q;J%ǖ>g}'aoE'R5RMhr]_5B@xTPqP{[Hq붻^;S7̧^@$5"(J@ C',_?p/Z7{)khPBQy4OAl@,(߭B@;guwfiևuv|ȴPFvvR$xO'"߻ /~-8`paNIʓ} mFrYŜI$)H@1J]Rp]/}%ma!L>_; by4r>z%mرEQQ¨!WfpDj]Â#$HPT@0rd'{Xg1TvPf5 2z&t@mk' x CߐZY>N@"Vp ^Mv,t"U!^ Kj@hGAoom `<7O P gT`?M"=~m:S 8P3*A eF` 4?7kϴoqn?f7Sx`X!fDԶK,T;"hyBM>| !/y35.D.A~ xAJ. N @7a@S uW[ysP6aNnPA @XTUZh fF,Qqޱg4w.[R6'^ihfX5,%W#)80{^/{1&`^1!6u  @D& D:zM0)¾nTv"WឿJ ' Ay<Ѐ{ [$oq)kTU]0ҠB ށiW 2=>Neή!I{^yl~I^S}MBkʢMbq,7?iezo)Ah0s%A?uKPK -`{Ք6 4U؛Xvn^~EW"e:RQ> '~oT 6I̿OY(L.G31  ͈؁Dp~S_uiOP5l"4ʉYT2pI`~ٛo:\ˏ nޏʓL(W2H!9]$ecTA85^~Vfͨrw&w+%c3: l ȎH~J) p9snvp)33'F7tz}CVUf6A[e))UY;EW̳椵TΘ` &᳨LFe9BѨ /+ N7Ll\>zw+[lD3f.GY@͒`\] b !A0GG_A` M hl̆zEtHER(5+Fr~yxlv ?' \No~&4Xz1ݕj>:`%d(vT&YÆ-ӣ(,_/ ʂrd7ќҕ"kS>3J'}.jW,]U|f9P_ixk˓ؒ^|'V$7aLTeiƶy |Hm.s<:JM9)3Z;-+=KbmLoo^'9>?;OV'2MYrNf wF36,;yedR!~& Jwx2>y7Xl ,B 2ڝNMV\v+3' ڰJdJ>^wQCY.5+R&/D8DtJ ussQεl``j뗸f[^pMFq>4ǿBA@# M>ﭷO)}V_g0hb27Omqv7a|ݽQhͥ; ~__1}lTFQb\ -%*:JՐ!rr A V  R.u B&f RBd-B IH2ѳlqy [ԴẔ] !+ ˨;[tB왳۪Pڕr Cm{. ]?dR9osk=5GhtNOOCKc2~vaEpq8=q3b)s&ICtִ@ ͷX%,^nr6Wf>ݳkaZLBH6u*QH2BEPnVHHZri'd1{܂0@R ,i3#9]Oxns;|k~9x0l_tW`:@o@H39R-f 3f]eMKc.tsxP"O ZbI+T|Tٴ®SKzCW;!`^ׄyb0 )s(@׫=>7s8cg=(K6=kPeݾ}߿<IU([m0(HRI2a? kpP?&>6?er?Ƨw ^_$X<$ HZ 5_T"Q - 0%HQO#rQP 51^>?TJj/FɌbZk_ 'Ix`ĥQ]mm XQ Z_]nYjHG6WuY`Y~~nC(7N؂@eN{V53^$39A $ sߏ9&^:L[#|&-AOVP/6 >Kl#\5Rf]*1#j#jgL64Z,~%ik!^4=Aqs/oy 6bDf VAÂκh/n~]ײzif^%fzwvesBPWـSUb=VOBc^]#.>!7sGr_d~gKqvw]ƌĚ<^Ch)j2:B>W^q-1 V!U \g_ ;YKFKn{6O\?u?=v:EsM"1@ӓ@T%hƮ@7J\4 :k04%?AOMVnj[qayi?ݿ c[ nF(6akxXO3Rl Y|WdwGY(6?Btv7xZ_,3Қc{9PĔA4TL43Tyi/㼬'bho[޸]k~ʤq d@( 1l0'ټ};6p'=J!cwׯuܦ[Տxrf7n1dẗQzߚJܥե8lﵯXfԡ&F J}eSM\5_5|vte5Nnoؾ"ZZZp/k7Z*㝯7<{|)oiU')bBH琏rB]R]Kkle54CP5PN׉])FIm8(nWܲ|ջC;?w0|3w_^S[Xٟ~#L|qݦBY O w.y%B mk[7[Yҥ8FC6{WE$$.QHRg@8y/cvo }۱nu=E˚u];Qoyosz?r`qmmd߷{#̨M$ * Bp b-/v;`)ÔT2IBT< +@A|r ٷ/7#LD:^nG=i8jբYg|f=銦~5͘>g QxwdoQV#jS#4(hD`( ql u՛lଏ 3U6<.]خtRXjhnPDm\q軬Y csbx[+c Wn|6u>nXZ󿙕QA~G 39yqJvy=|Iſ6Px?g# ቝ- !!0U-ծ̡RJ \L +Is_~WC8Lk['؛ v7gelSD` 0j#FsAQ(36?wiS:C87NaK' LOy*NIC4fFea{yjf]gh5Y=p]Gn*nq׆eF?3H.kRWpiG׃TIU*<1 \(ѣ٣t6\98!0I\+s^:-Ós n6Đn^r<^V%_%c}-c~"?D w^Fmw uxJ.@reڬ&`u;~w(bK}&Q#&~*,?;r_X{ӗvo7}=,/t Ǩ`3FZzMGVN#XPuR)3pW2d.Uku>ΎG;t79j5o[4ہg}55b>7$o2iAIu-F5b.yD^XUl-:<]( @vĒМ*1XsQ#pC#fܘt*x ; h/ 9fwZ ;WFvLcT,xwr^\lO2 B-S_tqd ",`Nvtl?xARttbJV0}4ʨCUyOC!τW97Z [QlV_s勽岟c_n\[oİ*x:&# 㽽qIu" v6i(ٷ[tCg5ǰIԛ91ٰ{K͇MB¹U!{9 ^dCGDi%ӧ R$H؃%U&Pb%R6b .+^[D*ѐW?n\v\籎F EM{W*+M?_X};~[I;fvvfsR$Z@D^tuLi@ s]/5RvLb?x%b}vrojC(V3=(>?}0„G/P6d{"NAJ4!Kck׷+zY22/o)S$1@/$@2_^"^޲{}GoK:+^/~"%;K)O=55wdtVK=wv:G;a+ڍZǣ c @42D ^} hVNIdb+%u:KJ Y/5MFAiL/0= =lT_^~~>Nv6;66w.D*!4dff e%}4x7ȣy< ۟Ws؝G߇qA'V_WzݗK){ٰ^"?Uu{ޖz`kVg;&tk?y@ Ca*qID ]8\7:U P) lTI}/5ME■7z.q[gɹI%7֕a._m_:Cx7ul~s꫹lU`gRjL:3{zF󽞻rm\: |&wQ{==Ο,5SB鿡0;pO57^|8,R9Xn`a$y z $."CS>/D̔R"H%z/iN_>O7Y͑GGs`bABpO>q7mggI F;bZwE `0hv,<kmd`4\l‘@Fka8>K 幔oַEt\ 0TрF !bEW|9nucV,HAQL_y@A?[mɘygv4*;nwy)E^! m)>@$̅I#ڋY7eNϊc`XL5W9Ժ:L|2=~U '$~ƌ_df%[vt eַ{iVa1#jbzתfBBH>1QnA2{@uϝ~% @c,~)#?lۭy wR|Git_O3i \L~?u>,ujuf('&mZKn=姘A+ Ә@ds-?ayK~T} t7={-獰L\&;V#u|]=[: ?%y'GcSeV ؼAr$@Q `h,;e(5к}7`8%zL9i9޹(1蠱zL6 wս?qPJ}?g'A\7~eL5' yOyt#q2<$xQEEEABGHM$'M~^Q@ %(h qNML5d^!dv XZq%ZVh&:ݼEj>/FX8\Z/nXlxkuj`!e%>gHeϟi=V ˨5DpᤆE_m_+7yMzJ?{诃*t HվlAo]S5VQ o @L yVSHKh#۠M~{u{%Y׫s4*Veid>}?9|׳>xܥvyjo/P](do[X;O1~ۼ=UFq'\;`srvWpHjg09 )F^Er?P$_/0%JZ6GVLKF8P٨tF%WmN-Ȭwwܸϴ\M?Λ $Mb),(eЍé\9_§9]vN ë?O伖^6Fȏ_u#\pВZ8ߛvRVz9nƼȰHeH EE!;]qx.Rv&UTe418>/`^vlM"'oQ8+5]:5qRu@S"HAbC/uh*!5#fhW(`.'3b9:J t c}x STS9 ~[64ެ4D=N+du^~woui;>ҡmGX7M^ϙ}n ?y):cXK9,v+^Vy+A}  I%m`y5F*%zH|XM`q+c!ǚ_énwtTG>ǷG\Ow~s^E'^jXbL·cձ6ܛ ٺsͫ*t?6昖ޏ[3~r~t|02T=N'*~H˽iol>]_Adk1Y۲Z(uj^LJM-q &Lq>^5E ]g| ^}196y-6s'm+F/0qh*%7[/챟lkxkEGa)rM&+7mgwѶyO?ƶR|gwWrQZ[&2[ET?rFa:5xf.s]CM;b5q,˘Uovz4zޟN{D0Ƈ?sfJǹMX4vY SOeOg~ubeg^ק:ZMGy9ج3YU׸ruէ=zgM%oy\K{$/z+>£3FE^>'D\, ^ԽID>4KY޿cz, En-h7=/.|.뻪|.^| 4GPZ F6 g"Zc۱DXG7IխYe8 T_;y(P*xtW:w+< 8 s8+h1!cr@lRHؚd&;,l;hN)>" ij%LDkJU7$$2魌q2O[$Z*dٙ9wb1_m@̓i%5)%!W"^\GDѹc^2}TP5;)!a2(!^}GZUHe"My(1ҙipc*Gas/0'?Y }`4[Z/RSJWQA IQ). +?h`o=}Q;VEf9(gZVJI<~3t-"\?%HȈ{g8Zvr1XyU'#]mbLIhw-ns ,^Wlit׊THW잽׺퍦-ʕh3n9 aC>U̘Y׊פ=ʵzf,,E[(8fog>_Z(M>|H=?Vg!cUBRGOQC+nxJW)e'Tyq67*۲R`~RazɲJWX2RDvYFX!M|M銯_`?7LCy$aY^혐 /_Dy<}tqApr>sEPIYھ; }f2KJbTkJose8jH1@ ><' 8ِ40qrwmtpxDpNE-,(nlate2bpqkSyl;yJ)H&& 9y%^ `I%+  ^Z:w<DCގDo' q F]_i2$ E}R]" ,osϗLN"m^qɂGmjgvMc{qwvUIn7C:5n6S7UmXJ 71q26`pfv͘0;V([Fհ -Q,O1YCA+i(pouҀgZ.ْٰQ(h05(yVVRd/$Ip#FKsޯoVߛQยK \u"fC8p:zy}>̫|C5 ܸ)5 6 "9@p?oД,|+qQFpQƞkBB e nӣ0@*{6y r=gׂ@$@ #Lҏ_cT^wQyi9rl FFG!stۃB% KOENj7&V([[SW\߶sM~9z/r 1/C=-oȽ seﱃo] <8h$`wcY8>Kj4W4'kߗp*d`'~dT_sWxv1 45\_/Ѕ S,>Af2f  oZ|dKn^+ f?f(gzYlTGV50ă0Ai0H {i{h`b#QzؽlZߔdYDf?]k` D|P' /sPhhqL0 NyrH {"{Ǹ* n-ɛ1e>o6GEQy yp0 ˱ dVcR gւ f[w5*$DIja$'2cxO`NH܈ܺYu0C܁ydA* vzcf,)J(f£~0X$\J'L50,-MPP-h*/@d MhjT M@Ga?욀@jOc@\WCGd>Zwuu23+#yr\M_`b7캚j! LgK*ϟxv+ȗ,6a}}mq\ݻnAK>dZݐ2q5"HBj.FvĻ 0u0abL| c.'>\Fap~ۼ3x>c0<8igx͵2r])am'2SEOod~Eo9x<& {W5xa-\]w3 eR^Tٚo߾͛ru#áj~g{ |g}{b~^sUc6K{6r? nygͶ/ W?LS4 |}cSpx/a76X|k_z$6 H2ϝoy$pgyДBO+~z :YVbD/P~h?C8^.!$?VZX5be ^aQ-_=(9+9ٻ~;AjlɫU_+7u$ݝ'yHTǞĈ|kLW Z5T]C`=5ZvL3۾CX_o@R|-GAֹE(@1Zi! E DOg@68pi6adMdc\oﬗb[d"smEU@1תNʴȜ Um_7gv֝Qg9 a9 Njwú+7v]Q|>zQANwUٻGzW!o6`^Zw\u67M;IfrQP(k )i٣!BJ [2h Kv5F@hP z,I)Mh(lw[#{c]݂bb6'qv]X;%AcvrƧv"(zPmRB}t>{>9>n;ޜ]w7g⑳ET-I=׷DW 8 4 *JA@*  H( ZE $ 06e{JV(H˔o`[sbNݻ GlZ2Q%wI!wewes+6S9뾇^ON]6[Ml hWnQAsn}xS㝮XRnamsӑM[ꞚWv ͝6i`smh<孵۸)4Rer]UHW;f1t={]REt4l%k vwwFs)**uaOl}=lGvvM{¢:@;it`UR ق"UT(4('ԩZ uӠ[5Y۷u>EF[ם3}@zנEޫsůw Z("l%Fwۧ϶ t{PԹݍi]wnovL7J+2tv[.vK5۽1t{ogW@>5sTfi awl*o$\gRmvh $W()z 2$cͶt!Ts`n-dUʭΪ'v h{w}f):S7mF:ub$vѭŘ+"Ps!:CM M4#@ =C#D 2$M OQ=Fihi#F&5A)&i4ɦ@4I #)i5?&PbSO"~zziLz4@44CG O%)$1h@&%$B#"bblj4ځ2ɠ@ !I @M&f&LE?dF)䧴#TTe==Q?TyGhSAh4 #5PA4@&Иbjbm)Fz'ԟhi=@M F#M@uܟcJ"WW5oAN~ՐhDa1, fJ9 ^Հn<!P!xj*L'nA%ʈAM$&)**JB%T&eȨ Q"jh(h(5gWO77lzM>XTBAK+d@>(ZЇ~CTv̏'c"FD,1Q<2Sz_y@~!4f(|U`%~?{?:\T*yswxʖx]/qHZ ƝwxL452Ӣs8Qł~λ#m$ TT &kД3 NDp{ޥg:_m¨@ѳis jFٮx uI*@6HEO]!1Goٳ[.V$$d|j52+y\͊cQPU(M1%UETIV(JeXHq2h>;m^X1*&&J"IB"j% 4zǓs6BcQ6zpueO+/YhHD%# ]EapEE}NݱIPgLL4Tu`knwU5&sfغE pե.1EKM?sd&"K_N+I ptJ")Q=7-v F%yH|Io 7 ߊ 10%/ @&Bl q9%糭cj XY(`ue9 gkTҡ=>rgaUk:sdٙ#"Ld:Qn=c=)f"CXr$S%+#/Ba"bΑ9.QS2T") ˝$`Ă7hmڅQ[j[ĵtӶ dSDrm.LBh&]+0"cgA1h.҈Sf{3cgmE2.=%fY];Cd-&ʙuPnj-fg]"V@\KcgEO3WJ6Jܡ a]/ms)4΂-_}5)YLU2 1*hq+G S%4J[Tm{"5[??-Y͂E[$ETfv [*T2 SWk/6Ռa?6>귪CŽ]x۽TOq2{]jSVa){z5{1L֬ۗ\ RM֔ާravmgZr 2n+m0\rgUczwaWXkF#sL:z> ,-gRW?tmhy-;IjvPl *:4)le6ET]?p5@1BE/pv?otLksާo#&r)&"uxzfBrs*c6giU/S{Šz+ӧcdC gngV(Gqn( 3&W0_OKC(NzFsXVV#f:}/=<ţ=euVPa4EO2Kh=oZO520ZJXUȈԪ ZRxt Eb5 U_nT֍Ĝ%HMŃCɘ̜3 h2#(3pm-V'C7{pIR jJ"7,|ʬQSy)ZS7X,u5-U5ʙn'%CT9ʙ^Q]Yu[W>|%;[MZ [Uz1{^vsj. XT`^P4`'r !0Ĭ zж'lOq<|MBޕF$y2d1"rd6%NʐNy가<+ZqkKepO 3"ȼ`MVzMVvLO c#PQ=0J)" {1R)>dOqDATUs#mQ[ȧ*&!0 NDX^fNnw8ά2PZIXhb#e el)]&[0UT\3'$`2{im[c[ӿuPt2GLFQv1b컲U۲֭\<_Gq=t\$&bE΢xz Xx O*]>d ~#c_س0F1;?KeXlƉj|%EEOlm*zW[F%m.|x+Gw2<{B ٻ; `E)L#WĤ 4 vuA9L@DWO^3ZXDŽUJ];tw(1R`pw)QDLwm<58!L"PmSOȅQqid EŃ,=wJ QU`s{(-W#p}.Ly|ީVA10\ ^mEbu{1jLJ%)Yhq/OTn)S~\x "{>(UE[vQ20TcUա3r^{aY׺i8M4I A) m % #l#ͪъ7*O_-e,0V]8{3hԦ¦Q4i{YsTq&态z#u!nolccS8)G˹ @$yhwoM=Xkm˯ fӒ'd(ۤr~7mB88\E$MOvF:hÈmya$3bG[9];j(/E4n_E3srm5L%ܶ7'ƻr4IA44gWSVag[C˖?7w(]!#b,,D08h.n& 1kf7ٲR)DKEӨ5^ӰNsC@z^# Eu`ȟՁ^'W+OX:\9j:UA6 Y}?nЦclF/8A ~, O&,i5,:k4=A>a;NTbBEm#\3xkz9/UElԷ-ȓPc^|2A?=l}>ҍ<8Mq[uijƏOL>z\Rh:|m ܡe]Џf}n[pn.#(="5vtOsJVԣ~w{5[BCwZ-̃'f̵5It @'G]rCߕ_#8*ܮl;|mk&*+GMҜ^\|R%vq3=5J4=eDsr'SY#J .u f"$ =! My_J8; PlG: .dotU.Ve8Nk@1)\m pBE/e_u'50DtŦPX0bD#h""!iؽiu^khIbuT `e=*mZC?, JW2DHвpq̣v5%Yޛ@PB'i98-Qס(Ӡ}+GߦE샘'"9./հtr@?l?)*ms.lLg;~gڈV ޽UNÿ7F\j8gE3hD3<,D")Fcg'A- ElLV VV8u6$u~!;|x?" Z'x܄'pJp{Ml(|Z jjhhr `"b*&hR$(  X$s93Zch4Й\!U~eR?>{J}B-rW^ЋC(l/FI&K˒Pehky 0lN'ys7u(}mVs+ GVز5x65 npNLHX@QHBC.@RbM}rk6!eNrOņ&ThVN}{3Qq̥"*kA,"1EDb%yD,A@^=Dl{"c5DXATR)/yr8p{<#|bm± Eň'2;"E7SYX8rK[<;בeǫqj"%]s73;.jzZoiu'zVϣ֓Y,ɓϏ%ocx3ɷ] 3&W$SY BdX)x$Znx+ۇpa3|*V-G0[(([抔5?w|ޔp G_WӌF1y q֙n.y?ö.loУ*6^fRk 1$qHL$J\ḡ3䶥CVRcN:֗'F}ѶE)ڵ Wz*EDC7:AjYp_,bQ\.")Sbn92:?ʺuL?=5g m\Yz WɈ>d$AmF8u&H,lHKO~HM9>0J QL]hmSDÏ>M#yiXmM/aLop05%+Yjh~qF.0M”s:,_";Q,KhSXLN3Ks¼̖(HNܒҶ*:עv\fJ/*sC%H@'Y^NoJ71ӽƉX]^bImj4j4fH<(Pp(&DX#]r[k?b(-:1S sYvɷ݁`42/຋s,NF&J|oyj2l7ooQӫ(zc"QUbvGy6n0iHu<:vW]fAz H ۳{QƖ\B~͘rR5VuvaTڐu= 9kn\N]WahEٶ7V4m %UIx!hDD`cnݶ2 ƁdژpΗ Me#"WM& ,GQ"[weм,Nr lcn؂GmfscAQ,2NV&m0Q^EP@Gج1Րcl8q쮆%,mjZstCy0fK].+1dҘ.,ZIʋӹu&r*gkNNTs*3vzgSv%5t6.v((8Jv%Hmv"kVdF\LVл"҉ldJծXQ.q3HXv띴cl[ȶ*jr`!v<ț-0&26 Βz˶V$'0QQeLKGIٞtgHg.cu˶ y7.mg+ %4Չs-Ɩ 6E6ZgSaS+n'I7 0KuȎDeP$fL9 6g(%u)d#Z/+̖ TI8LUEESmֶp$dBrqBڭLIQa.CgZՒ6vI]b.u-K!+eSa`Od!(E.]tZ+·7TmLz\2d]VG-ymR9-NrITػRrFm9CD-VѴc&vyˑlfmdPsFλN7YJݗc8plɶ#NsUڛ!=Df 1ɰ6-6MrkQ!uر28!3tlljDysݬ"\·u]F﵉Co'Ub0O QG}dV'K51d;Xx-M%nJk2S1UshCŽ5m sR)&TT(w 4;d]A>~5κ|k-Y(JIcRԴȔ!L+C˕$ҊM }4g ߳e\K͹.G+^IfoQnݥ[;wHM-6Gu23^Qړ02KӐQd0 VێGOчn 2]r }ܮIrw*UIc"BM!yQfx!!dHlmxQmK9Õ^^E:F{3e2"k/l$ e .y98Fc=HIæ6ͺ[d|ڟV}VO繷wmH#TYj\KV9uȶ)ԷmqcI2՗{#s9>pme.(i4cSC,Zڣ!N+<ӛ+kemfb {tݹ3'5k+5D; b>#Pd#(p%ZSSy[ŒTaƍ'y^JDaD6p_uE:ŧ&57sy4E=rdY3\Q97Y^ۀȏEI},EjDWDZT ۤzavGV1L$ƕ7$nvFiw:>WNMk =$h̝^#~g!*?uou 'p'V۝bf*ÀA Q(0UE~g>q㰍Iu}(q?ND2 (X!\PPB"38,6{=Ŝ]"M.J_j[)Q]C[pLavnhT * DE'JsF_g. sxx˻YXDˆB #dJ;< A煱o*ז N&  87/x1= ,;v&D;S%,UDLD5`Ei5)m;oi;8@'#- SأIm7ݧp$O6Ԗ"}c@I*ELTO]%lj1"ȍh8fVE{t b$!>m R ‚b")v&7B6"r%|(ZBϰͦqBu[lbAY9E &A B Z7j)i{`psoI0b߯]&c"YXXkV*~EEȨԥ%$Pi܉z}q7sp,ƦPXM&KMf8SDt΢2)UU wT6ĊG%0g쫀?TN3B4g-o~~_>UQBcXĈ*VmJ(0(' 2-/o᷺,gVPG Z,bMoہ߇eYN'[dU(aTXq}J CF6ٶX|+e:5D%>2AM+osq q!h-g^ ӆD-!$ ":tsrRI6*BQ(2,)k{G?z88Agu9&4wZ % L8/4[Ã᭹w^8:wf,.ϣ: V1DT}ezse X Z]b\ar~~>] 'QZE:1sۄfY*:ti),ins),RFPP"ĜXO7_g=B3NHy<03]^4{!= (H`o^UW452Q-?y>y8y tؽ15EWޚk'?>~NJTjeBQ%EI%`ȹ.ɭ>q?% N≴$N\zqQ[.'NoKepa(I5_릹Is-BE79C$&H` 0' /"uj5@tcϊ>GIcn= ӦtAmQM^B]ZZu'@R &mAS^kҦB l59dBb"w/YՑLkc)r؂66z^Q(9Ĕ }D U$D2*?o~S. Pz8V"mR1R3mew aUUwfS0f Z5%KPS6&UBA8`y ވf 0~w+zE;uN_>AOQ |~z$A󟭽C~z٠Isug *_ -os}w7\2v4;oJZR"ΈO(,aS! ~\Vfp>hC[@SHh1E5@ S7=ـi2GMfOk8lj,)݊-ܘ˟ɔڧEh~*gabU3XIu2:ّ:X*YVF'ޭ1."4AsY^\Ey@ReK)Ψo4RH44B-4 y%2 +Jᩍ0 (T:!)02) H !5&@;NO8@+rLuryx'wjW{(%!Ab@#" GV swK v~gT崁ʀݥf=\Eiga C'ĉo >?2Gim~~#?99]0)` u&J5 g"A?u7*=\{ ~e\7AA 85yNI#M&Wh^~81 %> h%4'wB(~" mCT;*}w3(=wծjolUkAu/w5jRLmh6Z[sI*rǷYߵ $ӐCp`D < -}8RC JQ3A?W6u)pu==ae֔_G ~efX|9!"PݎߪTLOg>esD~؃Dž ph ^6Ɖۄ)2 LP 0-('/MF"oig+mJBMr{ /z]mNߟ<0hU$ʠQZ#eK6DZ4SB}|۹}='Jٙ[,8V#R88s0eȴ(0;H)>\0o>^ƅZ0!bJqAWy8$$Hw&nT!}6-LJ)*:^=,Xg ޟͺM1cN]sfs&|1Jbv9?1mCE% D.9 K"ExS #| ʪ\oYGVt&"Tբ%lQc8u B *|`1d0C&uEŔ [F˄8+wzMߞ-)SXb @)KC_z.k댿my?&x$TWV0z\^l, ͱ՗tZe*ԗh}Կ,Z:.o8Q8-\5înV~yȢgn52}F}gQ  ^V3~\_?ûuߗ*UƳOmRkUk[I ;b\HyNG ;8-]PLc-r1rʆF#qT1U70Ol=VjR]3Iٳ HQ]Ü:n$m]lL."FΠ۝ra&6"\[A3 5v^RӰҫвL -,T 3HVvnQs]11fgg"2m)aҚ+ЈGAkMp:Uh؉ʓäw[Y f8T DzP)| q miU~AN않h] v7IVeCo<7W,(Byܤ%SkTJNQ DKn&Q^I0 @3Xخ2H%!R,S2Y먓/5|H4[Q59[vDTQݶf"&9dϑZ5[C[ |>ؽ9,0OޢtI4D/sk|DmZ2DHPՍ\B?ub얹7Y?-q mKII˓䣄zХ)Rg#DIJ]텺 romBKg0C\f/|JPPS={JF:2/uѭfq॑OVTP |ppW2!TrE흟%.-UW$n\ƺp͋ᡸӑ')B7&&,u ! ΪLZfG^޺ϽKJFr) Tx@8Q{GY~3)a>(qlf$5Ҭ R  $R|9Pꃿ^~$5 Uqݷ]^kHaACsZv>oOqI;Oc\c3%0E\M.ab"c<^i$(0qTDp}ZڄgoHaM'TSQ}O?kMđ|e+. ,h 3 yعVjw_+))FfwRQ.,sS۳ڳo|݂UgudFP4IV:+$K1{1򒐧뽻_}"OQ3綪Hqk-$^$0jgSti񡁡`]=# w҃(צ6J "9ġBI.gpi B ޻OM{K$+blUZqcQ|B-[Wic0=5JNQW=S]';dLaT^v}QuE⁉*gT-̬˹s 8">CDrr..*%j.rS &3QS*ugG'$ {SsPԂSZ#\Hk^_f"3(YjQ$PI<aktR1 a,X9!+=O=Bj?5 K*k :eAڿ^a.w;`BUMbsﺢ<14TLAMAE$5SCSA D4 @|gN.~7ϳxڌ>X>|C![GH0H%#Oq~~/7.(_U\ӕ wϠF/.s`bP?xH ;cWLa>'^l=lqW:l"$2[H`$H gfNbko+p4_e}xHWgk]9z?V-uY&~/ebGs8>;â!i2MF|CwP:bgc'h :'rԫ_Iq2(/,R!QA>V}XyB~5DD?=_&G .uձޡ).O|9JP1<{~c(_n;xhg}﷏~x@eN!HJ#o. 0?}QK(^~5ssy.{Ri0XC!83؟:N)ߞ\뉴7^(>| ߿$!Ň YU} $UO#ڊĘ/MJ F߱s~עÖCU޹s^"AC%j{.AwbrXPGwvܽ(9xshQP{/G F3,'Y(?*2U& &?g~OgZ蟮)3SӴxWǭ^gk[De**8єF1" >UbOj( Bܴ;yvϚ/L=.3G˚̊&\}( =Zf/;6|/biB$yHPVf ;eG̻E>$T("{ف%SzU-^f>= Ы_DG/NQhdܽUӖnU:w3&I3t0P gz`Yx[F}^l!EK[d>Lc"#:[<R? !1yyA (TZk㣯W1- KU'p%bjM_Etrq'I/^Ѿ H4~L/6Gzwɬ}t6(JIs );MԊBNQk-ň4Ś`M㽸.!|LL GpPKG!; }{)g zS$(5ϝtx' !% J~\N\*0֤KAav릚|$ΜS/ضT_׀XVmo &[5*±RTȑ^@#Dg{*LS%9~ÐiiK~qQ*LVnJATz5|ܶOFjl78,IfAŠR? r kU$Ro-oΡQPy]N>gJlӤ+u诇N*cΤϊFXɜr|_>jSWV f /Q%|֪s ɪX;Bߎv-]FkQ=TQ(ɭs=L2أ&ѶןS،SM1e+ h&/ Qu>r;(RIkK*N6'l߳3,f{$j4{_#o^?=JE ,2Óv5:5a㎮7{m}1Wa6x}УU*ڪ˪_B>%?|V̪svab>hdj-ö4թ4הlJSe{QUկ' \']L&tn-3[q\*mbT\_'llJGNIt(,1Y" ..>esE-Xtn{vwLA, U3BB*p#w2<Y~%^̼+K+rPx•K"YA A$Nfx&32Ը 9bOTeF3M"떒GE2pZ6u5 K95J(S G\q~`8xioGVhU hi]WtKkjr5Iif3;~o^TcD()$$%f45ܹwSmPhXuAkcӉ C#AqS]'Vya#?ûՠYP! G]2\\TTNdRa$tdsbI gY<^cTCpRxrEMfL9晰8xgXU[ܗ{&!EmF ]%IsAj9[䱰`ZgTm]FP$"[ j{ LU@e@UO D2Obf9N0ekU`<ˌ﫹s83yYj}tch u($4_un1=`yݜ%8_ԤCs *~JBrF0,b;IR|9(_$@vv'Wܐ{qh<LRA SQQvݯwαmM14T 3}qi%Npª-A+Quk7qiӌL$"R&qI*Z-? D%zg0XSN%Am~ט':(C즫}cZW_wǮ5튪ŕTP+Vwfb>5.6(v_o3>\ W<$jg|e H7by᎟wU+=u|ͳ!0 Bjy#O݌S>hr. nO~!PbF?֖"-1XX-\d\3AF][}^?Rq#?Qg=j)=;_:c CqBͣ-V~b/fE><_k4lko'ѓ<}Uyqq!]JH8A#(2j2}?͉]ܪc)&UhqvŴj =)fbE &):o<A6s9;0{e9:HHEzKi O_u*t(s$Sd* [݋g _5!AY&0@S*ߚ=QF}Zy<|UWu )\OvTeX$ y\H1耔R$TV{xN 6=yǥ#9sYP& 5HRj6;'M|̴ȠT @f ST;0、UژlxfxC$8E%*ƺO %'DhsO lb2o~>$ܡ߳qr<՞]5"b~F;1("ڊEsGq@(y,5CAȊ2UWlg|{ 2XZsoS~os9D?@M ͧ.~zpZ/aS)1^,&{CK||!Z*^=u힕_ݒcsLuw?8O~.1x4go?{~~WaDù?>4ufXh?e(?}D %<8$yUzm$@ALp; =\K=iBz ,^VZ7}oHp21а`)4$zT~\Ng)q*E2L]U&a^\KH?{d.uԿ k%HZVj-Wշxݫ y +8$! ۴k~zZ2%f!J_C SdGsQ*Ww{PR}5X]rb LGr>\W1\&%ڱ |gNj7R0K~0**h%ml]'vҽ鏊^a3*tXX< Ah9Yj:&O%.Lѷ{-}@DH~$J$NکF q(V#ՆeahJ#~ޒ[-$ܧ(Irčl&ӄrFcNehd@T[Xm4wI#OZB(f4E1*KւP$VۜեgljbF:0zًށ[7_ݟOA Kpq#Ie&r> *6A3=?(A+adSm.7`*ZX0$SUߔ < h\k!Ht2|wϐʊu$˞$թn׎fM4MLFױ9/8q#[Hs.`n 5S]-+e.ܽ!#5[vl ;Æ/⺩PQ)lffA.hq%_Qp66u%!1AUrYV8*I\WiMxR T=~KW8&%AG?ˌÑ E9eyXEbT mL@/i Fp$,e?r+i6G(P( cGo/U4Z TZns+9|K2RTX4`+l%+bJ6 a~Syһ/(f^¢36?G¢bop!r(u0 $ԨB$+7-Ǥ5s-(`UQOz҂kc{DŽ2)/Un6fM}w݀PwzB s}ٴPY .r*>.U}aTY\"Ŭv"Kܽ|)[+cuh>cH`}˵GHXy+eO5z }齻܁uayqp= 4/;ߝBo~aBjKys#%;)Ձx-0(! æC(wur>nADALNI$I4IES}lZ_݌?} =\3Ѥ .@)pL?O/Mn= }kT1opHEcUQ7WZ[+XQ}&qX'*\UWr}>'Ǚ#{OBg NQ~uk: QvֶXG7Fp .'h-"}u) \p׵Ҋ^-'jSF `Tkz!=ڞ0HM :P1:sL"U*W]w/ٛy^3z~?S7 k~T?ͿQ,~*!.ߩCts^::|=Pc0M}Hneǹ:Mw8jU ~6oW!SpyW/DSJw1 bؐPahoOTXqjTTL A5bQG7 I(QɿB==|8k&HSaED((A1|}zp^m:nbJJ )E2|pc m_Ju*il!˦Ug38Z+2*.s>(6 |atmhbr5p 3.eqb^ٜxx'z4ש;KffttE%B!0q^}*~܇ P kS;@WU5mҸT]uU'l=|,>/콸~[;a%[_a}ɌF'KtPO/pufira-bUO8>6۝#sϣ;ei;Zۮ5sv&gjig*E?5Ab4 QIϤK5;:V!pNbLX.-g=Mݻq|aV]%.6(AAS˓>HI)T]|zz#7-],?1(2n`I i^Wd&rC%7@k!('nԉU5&UGjΖ*K[:carvy qAZkJ0ai`q< hB)#GC>%;S?U6kLzs>kdB$I 5Ȫ;$@l2ڼݜo<6޵howbU:\Ψvp:Zh:G>+tMPd,&0"v Ƣ=.k{PT%HVT!$/Ͻ.}RR$#.Mw}n{9rcV#kl`DPaKDDM#¤P @|n2vM8שJ2۵w=^ADnuPM )dg..qʸv:Sha~~W ;uG _j2NgZ M==$q 敔}~D@EKUU2ѩXY | /n'$5RfNdǚSwo;(e̶q~#Rޚu44>,YxkԛuLYag(ScX?7+H+{ t;%s:_w4 )pl#_{ga*Η롨ðĽ'"[!G+s4%U`T3U{M\o:zAav4sm~hJ1䛈(Pr;y%aW(kەDG | GucB ""ocEY:TMk')z x9;Yҁm0'HPRH$9T(^tUȜH@5WdK լI蕴iC|~s՗ᝈHq+糲PyHP`0˾8Lr ?ucUb{0U=gM_X~G}q LBPTATS,-I,T5M5ϹiwytypDAb_'i?os`rzBQ H=[]"8Ԯisj;k%Yji(Ƙ[$5'Xh=o iJ>oq}϶oO>_(lץ""N<کP 92fŃ×k s#nv~UA!nCW=;J ?'ȸbwn!.| [b:)R/.S;y*Ljے Mƺ{㲫 ( $;L}OeJ{frᣥ1!_/zN C"[V1hBMs*+URO:hsBN%q1xf`mit-Cہx(- ɂYj}M4.m?F@eF%LC (\3[vYhw?5`oOmǟ}'FPF|o غ֯<<ֱK nBADf3z JR2i:r_3 /FmgN6۔ßjK,`bMrD ];o Aހsv1PFE`AB%ꏥٴ.ʹs>q;$= KAE" j"JHԙ :#ȥ(gwZ Jq,|?j"ZښF,#蠶]~1X4kuRVrwڡY3חї,fpBIꟺ()g[GY<莊@vg0W)~˗O>_El(I7aPpq9s6*ƯQ0V?(J%Pyb$a(=dX9@rAݭ*5p|`w}WBʷyS3oN %<`Tdd^8[dנ eܞq')UJ܁9W5CW_QD[ {1g**JLMPuJ{='h6dFF]}s"">%X?C7u G\QP{\mD 44G'QB@!3.ed k=(g7PֲycJ;7ޛ{f j9ٖmTN/W۶! 5U~}aHy]1cP^' σp$@Tʂb;K'Vms?ү?/dO> y_,>U nWS k9'wUS4=hߩb}fIdj7|7|ĨtDEA3ۇ_}p㎧; :PWgjdGƞӛ>Z)I:̫ 3 T)l @Oh[Nj;uFO-k~2 gW8 tʵ+şy1Z`l,$$pBZcQR^J=P/AVӬ^M!Ɯ+EU[+@^?>4u`0xs臹 uyx'Xq~o[l$1UBnˊrxh4hbIB2@y3us|oV>u3]'C0z0mnZ?6@ϲfɷ-mC3Iy#Þx<PDD5C:D*O^ BO3QBB%#SgH"],(B/f'Zw!9.\]锧#I=v>L 5G6Hg \Umͬ!A徢AUM{= 1edmUو8UC(~cӤP;ZNSwMwsH$ DYpE 0BpJ-@"$~֗__rUY3(ZL!@(QIV ֦POo4;*nȻ/&o S׵YU BBQ7xǵ>%Js-[P0CW&81kwLx(0k#PGFqGW3b^g< -Ѯ_]џ''_l2$C1CT!DW.\$it1vR$jWӱiGhҌED|+x3ȓ$RBb>NY,ٔť8L 1w: [HW&sπ./s?~~E]TfO#ݗ)ixҜZxuݧoo3@;?k||ōJ]PruF~D/oٛג^/JTNۗ5SJv3mfjZYf&%AL'oA¾X*i{QS0E9#3 :37ZA&R*oiÅ-r0p<; ժI**4N4t~c8$2rDJ_VPՏ1qQC&|S,,Czv5 KX.ov;_ `>…pcV󕸶 Rrb]H;0ѝlƶ&D&'=ƟER*鑝s$Nzäh!0Pk;J鿫_ϞK,%DA!٨'fN~;r>ĤCpo*rM=vvhQ>qGD29dӱG)ϴϪc/;o!qR,aVk9- j,#%Y6G]u=`CN/]Vep`ZQ&╈2r 3At~׵Ϸ|C5bK=Wv6̍4)zzM rq!=ASޏģg7/3U~ rhT**b- dbu ^}m CTmz$T\FEh.;8JaBu {"g@ jR^wœ|!_FUB":= / 1WdҗA_s%'wʶc»-lu-5II1C"ε =&G*nĔ3Ꜵw^=n Z+gRho jM+ޮoSE f0vrWdlqAV$Wݾle)i%S[D`-3=+` ѣpʫ8@0`eSSLf'g{ѻ^zݜ 󽽅^)9<.>s"g2viT' ŘlGNܐRA/]=q@$g]Qa\ H٦2SόmsEHɦHn :4z87zqn~'멧&js0n؝O9 1g =,iVeS*{~i_}Y~l\[Zn=L2HC-c]Ŭ>ȪaX19($\Y]]\@wRޅ >VN)m_|}w@Fp=+³cP}ǬIF]ia^uZ6)MR3yXQ}hK.^9=q#Pq QC+Č9dxofכs&**(9Up;F= 3RrK X@ : OOE];"R WFJTE&g'=vrOh];'bI6P% @h5 l<:ل\/s YDĀMLAP[*[Sޝսp9=BA HD |u?t2 <1篃濁(fQc; \r*Nz1MD ^>u$A@3"N-(;ߣs6wȿ[]Wi3f/]`]a6{j7X87dԀۮsUzWUn_Hk0=)Ƿ3CلVCJ׶OPs*p(Gt*EXLY( u eE z(2ȧmן0425r֍.W@}f (Gـ'/ƵbH3ãw"i V)pܾ|v{\~?\^.O/. I( F|cc9mgJ^NMx23$Tl@Ook84*_ R=no)wQ`U*F.wޒ88LiJbGuwvb{ܧʙ`iT Kel.DD=e E%k'/{}>SqHIWDOs >ė]fR}vXf )UNF\Ad.; |^T*Y(a^./- I: ۳x՞er6SR^)EQ@o^Ǵ KjMT.Z ¡6!q EBj7"nJʡo-.4Ʀ6MsRDu@BkdaH5weif3D|޽q_=B!pah属DbN@sig/ n L(72;Eg:KJ3>`O'kѲ5B=w<0zzzD ٘{2e7m{#@q֢)E{ d>寪UsƱCFQnsb1@բf[\Il.k|m0K"f|H4TM5Yk,V^x"vF L?%6͍px'=7in髷kAқcދ,8SiAI]J$ib67FU+Q u|8=txV`򢛡Kmͦh^iZ4>"!#pR*ޮX#L|:U<c933bY= joJ﷿~T^ЁA:UwpuxA n)"u=ըSĽgԃᚙ[o#iod;d:Yo>,c5QS!!Z#a^D6nyq Mm/`hS U(@UT%c]OqcJT}o#5$COmI(A]+w[_g wUk_n(L=vY\s+%g yOšK9:1l#4ox{_(>rMH "ս&XVv3q#D,+`0w :.'x/¬J3 CZX1tsA_8YBc%Us>d HLze*_#[0P!Z~$6XUY)d\ށhO4#;R&_o˗G':뿥ZZqg?Ҏ 8:OQRc5GRiH_ဠ &?{$d $BdIu!xI]d(H,.Ȓ aB:xpHT"T`pҜvց"Yd8JX KA $ BQ+, my15Į໮.v(,!F70#TY r#;p ŐP0ZQk U!$o vwI Pa1jn!H"(}A$EDBgDHe3٘LT H.m)LhHvql'qLv%{/9b$V"ti|A`AȠW r٬x;*j\qt+J a`sdd" o>@3C!;(p`CNόx"?`!D;K&E д+3 U w$KI􁘉I2LB–|㷐"`U%!B)HHЅHSACEI$DZB ySēbkK;c W3AQAFqr%f1'8c(  >{t1e="ē4RPPPTm뺡aDA ̂2d낺PX(Gv  rQ$.*O (d8\x3(t2"hL1WBTW9r :Xb~6Ys8損QI"0PP+*@)85M<4lW”P{D+FF:pJH@)2"AFͰ-Ș- c ĝ°~o񽏓@s<{dᵮs:R=DlҎ)}^}_-GPDq# S,b#GIO[^zJd)]IaՕ8H҄1AAJESI 4 M$QHiv DtӳJBs<,c:.xuf~sϬkiTIB @%+BUQMč1P-Lk 2B2JDDg;Hܬh}\ R%ICBLPl3vHA(&0d+jh"( D_ȆN-tf0N]65 {v 4$H-TLB!B2!P1U %* 2_rJMRДx-Si("7X{V (*IЙv(yOBl$/4( 0* ?>]l? 0N"9 fOq[d˚ f%<5*o.Ҥ@%-+HD"R(BSBHĥ!B4 PD=# ]2?|[KUJДD%JДhISGBy"^NF`|: c %d!PvmHЅAUL1L34fDAQI!d[>4kBhmWۊ-â4Cͧ+GMFT&7u ZHHIؿKzujMdI0 rJG2d$u-Pr8iЂOY}|WoriGŠՖE@5mlP و@U@=CT0bh( Z">uɷLhj"H"JSo9l/" KMd%%(Q@)57Y%R@ID @%@(2S$ !mU=6pQLULːUEUASA1PTQExJLD`gа ;93*|1F%:*^g7G0CBH,(BӁA ܣwMq Q0a܌_;P\ &Ff%1*(X*f(mH ^PP8Ў҆DܢcLcjTEV(EV[6D2uϘšQ&ITE3͓CaUVldYf6;M.$C``yP`$Y jev@*(bN($E|j{\m9K%U+ȠZ YQ0b,Tm+ x٨mXl4Ѭڸ$Ͱ7sAUbPAETQEF/[ċEcXo&ɍ"Z( H.FART( h+r=u hbq@ d f@81faA􌦆ba"(y<Ȋs?TVEb1UU:R|Vt=¯Sۦ^P{V0Uq[b*h1U*{G|4sFW^]a TK H'G4|OgKMfŃAtYN>g.dUTrAEH )GCR;XAMRSXAELPđM0Uւ=<i(lxa1&CHm2w- 둖!dI!1ٗOۧrDġ(BnMy9;#f!$h(**BR\љ†öo3~:"rji!mxj"Y&@;^r&btTrb*"b`A[E " * QyX3řHzR:S٬x0G~# h&`iaF`idP(ݭ$oW\f[<AqM Vh- E 0AS*:u4r}E` "P1tª1UETE^\Aך;=XJ'Ub"1[fi\9@76dA,YQf.潞btN:ջb9.>ЄcIAC O$߬ 2?j=4žҏaD?A9ޑX{;7Kxh^ZhF9@yaZ JI fZJ!%J@(#)@%V ` i@-BH;٭c37ӠKtp[T+vWkV֩Ӥ모K\3DLӒ:o)sW@ƤQ7 upfLSH2U5!YSq5ꜷo>aB?Ŝx)mۆZչY.t0-ɽ@ggތ,UNnp=D"z32f˘ݶƮC]5ڷNN6X+^b˩0))BzEWi7%+3}=h_&5](mfn/~FooVs MJ (-ԅ(IXU0،L9r 7:9MݝΦ:Nud0&ݴcf7c3PNiWZi dz"6.hlX2g#h],Ꝝۧ+ӳ˩\Bൊۦ6!V] هg=);HmGABOBsQmkbΜJ" 6-}E >ke:=lkM2;AnTN[t٥4+sCijK.mlnBvdM[C8 s樛2Ci'Zk V(1\$'dWF-(Lٌ˩ulN(fZMviCɷEEihء,l~g 2.sdb%JXOWnv&krdȽ6Ohecvz ׶3ى4W .,Q6W~&ic -ڛ1;tPN&dwSfm*Bjq:)}US&9-΄hmݿĵ+aҴEuo8t{*PPt0*fj%tVH`g4j!wNMxY-h|o];c}^8ƅdZqGӭUEPKo%\6S09&0iP]V{(*$*4^M_ExZz'/g+X,&ulv-IvY+olH) ]5T{l\[E\0JdXi4XIl7Vr^Kqq1ZqNxo X!g)!6R0g#U]bב7'H5@a)GEް.袂MN%U~k1@Bwڭ'g vmcL%sЈ'muɐRDQ];x1*3 Y3ӽ</Sz-0KʵGGD+bT|RT =?llS>Inix1b$kI k^ڹ՞ڥSt;e$nM?$.A/?o>8 j%9DG&JSS++-Y*r.K0g9 X~BKE@b%W"0*ssrdqd+Di2L:Fl-#CɶZgf3$fv{%jJGK֭J=R#ܼۘ;L*1ªK\X̊"Rk[!>\,b&m0|T1W_G:~U$fUFPxX@y(X`5;;zڊ.76*0Y+&a '%UeA\:Q V,EM~\ Oaٛ[t~q(U惙G(}1}M1jntWhqwmd9ڍS恋jVprBxnzwtCs{b;̜.gpmC7:..*ќ8G5C DDTc\V*w=lp3;ekeWNwwfr+0[ xxɟQQR DSKJ c7)L";v}W{)ȎQTbl6;Bc{'q-C*bB=U|?Ba 9(E Э 02$XUH`QH* @)2 RdpϝIzu'«rG!H3(4 @(JJЈؘ"} q9Å'Hcތ'd/zJQE"; dRd DFA<' q2)c-QZTԙTwz#NF(U!TT\Dp)߆pԋTQ$= ®9 Hfl:%Hiyz5IBIE\C7)SAvSmd%j҆BhPRg]S,Ԁy꜒ŨP$6*M^XAְa 9G<@60NB)xj3lpڠh@9H& h:k&E3HK8f;H(1#PR IQLDRP-(@CB*+ @ A(D! G N\w", ĄD s@UzHjJ VN`_ԱA"*(r؜dB ',Ej>ۀHIȰFDHP"}_[zH)%QVS&!."PD$ a_*]=fE#Dr`12PH13]ܝAp%!!tTgLnqgl)&IecI8s#mҋYmSeښґD]jv%)c3Z嶵V8Il(kkeBlg.!m mM+M{9Ցy(ՔE,m)Y2v!ϹAA9ι(N <iPNd&° ۦ@04k&ȉF"aq㻹77csF\-짩3YQ9- " C{آϻDu xB։<#4N)vlp{gdPxϷy_kVR\|6@)\{ޖCa ݓQ,{*mh?+;[tZ %u&}'y '6ɧ2c^z(!FԾoD9b{όZ{?\sL=T7'Z_K kcT<7S{ix=TO>ռwKhVwCeO=͙>'zO "ƴ'yE[Պ"C+$QI"OcAb"!m yCHy|B=}o85.TJ#!YAmm"('֡ɘ*|&>; ֓Rɘ(Kh CR{!lD*5t_ \ icaN"^z*UQG smNaXFĂJXޣKdZ{ Bu'O!T\O`ᴪ *(ӎ QK[wIg6hvH zC+D*TLSG)!* T!dA%>Mb~aEdzcM\]RAd2| d@P!}d'oݟe,-KIB(twb| }E)2)%fb>T7!Zڍy'NiCyOxNm À*%xǞ(rmww CN[e<ʢ* TAe[E@}g9gJϛa&;9ChdXr I$ȵ*=B (B0A9'xd_Њ홼jZY,S IX@2ύO"_#FEK*$&d"E_Rd+:y Ī8z‹+Py8H`|Ԅd}:']+ղ:'+u>MsDѴG5$RC>LRGQ}]vl(/09 AjKbha(0 oT5~nid,X=`{fl4I]N___t޾O'ؾDmU 9&3ȡʾeծ=ItD=y$}Fo[t_sL>T"ØH)Lzӥcbq=\|CDմeWnp,b H= $בֿi>Oֲ(>,Wgj~gqVwmGwftV =ԪH}O(c(m:"DglM,.q*G*Dl )-EjY=>JVޣvfB}\`5+F*;dQZ)!6IIBm5T(QłA%ETHVVC1kJĢ hؔ~]/ lfغYiK˹9lIJ=!?=wzR%A{0I3f}5>~)Hׁ4G„X bYkVV n Y#r.Tȩֵ '1y E*@o֥FaRFW|ZXc J& B@#aN( UUMl"7xHF dYbҏiYBZcV߻q}J"%bJ6( %R{1"c\_ɔv-dE֪%Ƌ Z_Z}c`c}g'Z暅cq|UPDא*tHuג[k풽zm;r_zua$,(L 9D(4YHl l>_[<+MSZ+gR_b**0S(0IFrVL*Ӎ"3EDG>'G_M+' K 0(+ J0FIRE(v7B*~3 'sj'x$n~]^ WGY @R|,9=0m֚}ŋlEw^-zo'%)ޢNkXhD6EwJ7q&cA xL(r_lt+`M(w{6SYG U}ӟ~TUp,n9 &uiݎMzu<ϓFzBQmڊdiO|Y eY9EDko&^kݔQ檖Ȥ|eڿ[l}}mɞ*7&'Q-OB\mOw*kr_VmK(w7)Rnŕ.naȳaGN. \ϸPz| 7YXP(9(+ݰo }h+98z}a̙Iu^v.Nb+,+ic_wdP< rZq%BV H(U%bZM@*:(9gA@8IQh'E',0Эis-0<4|b3b|rRӾ=>Cr+P8{ёA]ʻFiExX=jVrVf+63IfV 30kzُlqڲdɕ3W^ۺRs5"+T" VԲJʓYU{z{۽ԡN=/ɟqahh&| 74;m)Mi:[F0QkXEsNEzŒ<[ }R!iu{C A-'BZl* -?~j [cum*{y7{qF nn*l&}eKk%̈,֤Ps|!|Z KK%A}o7S)DyO2{y:楂 #R 8YaSdw r$L.%aQEEδ!&>,R(%?Ss84I䐚0ưb ػ@>Ry>:Q $m `2c2To>$$[o TT-aV%5HY̧St. T:'6.7>!mpIb$ʠQ GyJϧCSE|=T"-F \gш=k"7!fdlF]cJ2sC{$+J #7Gz,y!X Y>@hcXO@dr_XC|06 5)ְD3D7JKUD"ǣƏQӓX&ؐ#GX! Gq 4`}hdւdHf w =2NPU/bǣ>얌e0:yZ|R=,:,wwEﺞ^0SReA:'5f7IɎy$+6 adD⏷qrY a zk"h>wQk"jn9Ca'7= Ł.?:H(}k,]erZUfN5ẞj9"ɩs 7 Ub,Bg$CNbzx7}|پv6!.[ZVr,Q &dZexa,Dzk\y=8)@늠ڂix>Zq𯜯 |k|Z-\K&q̒ȌAjP9͈P5vsee4R6xD3S7u-% wp&㊩v=8qxS!id%d'NAgYXp+2S!z͛QzDr d@QCrP$ cc%!kMSBR.ISZ+AWb>lO_j\YsE-DaRT"±,yNm,äΆ7|{uŏRM4vD>o^"$Fž*QgHghe. 3^+"3#0C,-B͡No_9R蟪t<0"C0\Nx24GԱ1IFKR4h7QM&fleMMLN+ "Y&@d=l~$$_6)F~{L#NՁjaPAQ/5) EDQ-}7YkQg_z>h*|"[,x*ү=sZX9-)Pb_xc~8ͨR"bfFyT@d] O(hNjJ(揓ƿyUUGy@D%:0&(L^!%J*#I_?\}_wu2{+dY iŢ:߄`ud 'IYYXTPQHu-Nn661Dmkɞ L򎧼ܒ!)(B!Dih_% JRRoD[.b$ V(eb(jB $"@)hU( $(ZQQQJbD@(ja%E)P"QsfqsbBR$bX* bTpG aN·┧憭KɄtlw@QX",DU-DZH"F*c,TT_bxK*.,+' ;q6Dy #.C=?|,74$%p{Ṗڣ}Zq뚝3(!fQO sHsR"@ca܄]gLс5uƴK_뽞q̼uϼOzT-a%vhM Άi:blΗl=Ai"3^H)|^(ϵfE-3dUk^Xt6n:z]Dh[T/h8瀎LzgNvEXDYrN=OlCMϩ\]9RNMupaN!z=!L:%TB{u= PլA~leO]WvӔ,[zLH >#ntaG֣Di$a_vcϼ>F~j~0V~5=BiDh۴G靐tKNq!D-j-Njego./fOI_OZQYeW}71ҡmOQ1yWGVw_ƛ@.m],s5@MڢȾPw']_)oƾ':Ec 7h kӴveW `nY_嬡78@=DyNpeP=7d9A^v޳`;9?>UD")DW: y" /ېg\vOzyCOa.d=z'!ƵDqBp @2aN*LD3b :44?zxHz[^u{zr %P 8HQ,~?cB$Zk(KΨyÅ,T&"!v}b}&Y{f'݇^g $L)>9~qWwSA6.|߇)d⠖ uZɁ @DP@dP i=aj `u],'Ѩ^ȡ["6bS9|4bې[@B , xIA*wuU pTE[#@DDA ZX5=}MD\Ք>3S~i=ygw@ @B+Mic@ܤ 6/ñ(vnٰAء3Lc= L %'YDGY8@}wйsH=;ͻBz ÙHd NTM]TD9ܢe)m!n\,=V,)BO[1xer1DHPLiN;ጠtNNrJgZq 4tjepڛАmxOH9FspI9~oo'COG9mruWGE UlVpy< .E}| 6 ~J[7yv,s~ˋ֓Swۇ(ٮPh.Nѯw׽p mʟIb4qJ ~O;322b;)U^;(h gyW~@A fJ(x./(8(`"3 KsrtX<ԶfKvƨD@7850`}> NfR$+6sWۦr\C]w5UDӀph EDώ2$'*+'K]x( w3ٶzePIӧC D!ꊥ/JI-? ߅ ot<^Lnֱn<R()"{.fv9FsJ^{t4 @gADMu82{şH;n<}cxD¡ߗ1 L~~Ǵ@/) ʷ$(B$~;.`>;zXV\PP+È1;jn *wvl4ќ Q=^AãaJڠDc H`rf[i&,xS"1T.ffw?YGU;NeTބ_eۘ{5Ǥ;#pK_o۝!uv!19Zx`$!@@BHNEt7%M8fF5=B~`!" ]/͔0Wtb,FoKч%kUGos {osADDptb_zv=;!XJ}5d߇?q~O'Gz{%ČFHZah)ǚF4֛JAw]w?JK =A~Myr-M$A5߯SC$BSǴ\W>?Y AG (Dɞ*hwB ރ^kb?wRh8 r@usubA@Km:)]uA\<;jVTM* ʈuSz_o[;ޕjJg?!]씥X oç;X xynkfF; %S>fTR.hawyK S?TWfl2rg<;5ίEnWǗ_s7r猗vzw] @+Q}(D CO~h)+~G~ch֦ > t4.5[sFx~VN' $y@B[XB# Qo`P`A{7D1!=vPi9V@{ntxf{-jm=z#$n% en_p$ @e@}/񒽣?zoυ`Ixd}O!ɪ7PcO}_j*PFYנ?2 OLADnЀ^76jdKy At^ef~>ɡ\FS.Ϣr~6so7%Nz#?Km#A4Na_W2@1څ?9D&cqAED(Pl38BBUP܂mU[ Z)*=c?c5Ӭ}h_sk"TH#t`P0fU( $&n?z}_Ve#m^?%:LW d%tH]!Jɒ'ekؿ{} Ng^?)g lPU1tGZt馥#TS"Cm2N"uڏ\m? oH@Ww}6(-ty61v!gΣ@⮒B r(P˴IQ3ǂ=~@_WFB>3=owJ4^<8q@k0oχ="2;∛FJn[}PTAqZhkuu6_sq |B=_Ȱ$8 \8oOU)FHޱO5ԣJ:nKN=j_w 8)\2b TI+_;=r=?NgzsOX9 c'Xwȱ_OoYli7q0S.^xhj/A|_q1(I~!2LyHn6II[Y1!pNoOZ_hy^eQCgyC"l%/|aoܸ?4קxoS~h5_FUPW{uz#~7*A)Ģb<~pͣY9ծШXA_ Ƴ ZƱ8hrGuzݮ05X/NmAlX:/\ d$V c\-tzɎ5&+@D A Q5+55}%T X0Mg/8̂",Zݤ 잉+h5N (DB@#J%2' aiL"1PNcߍZX>Ô9I͓=,/ok D,MR>?@џ|#{]4"+tv8AB lf$BjB< 'su=L~ףM:`-d/ Pf9UT(ߛƟ2c´ ^>"F?@p"TP Jָ}򑺒XܡӭjGpV-oVj tgER Vj7}J-U]7P.bp>h8- .\`9u$@EדO=[?UߧL ?&V́O`8O"pri|q}'{FcVK/y$?GUÆ}?3FݚN߻$m%ޫ;wmή3୲W CU%$3[m۸d)[+iP77x,*F2qF[UGJ+$+#vk|T`<(a7קWp؈:TBERi]zP i`AY\HD%ޟ_|QPxc]< ~#њ@,ނDOT !=_^l s0N!(,cM 2HpThܛ=zϟfGQp/ՇZx3ro,LqQD5s2?kBF A&b U"yA';xz0~ ,1槵sщR61뿛;~qN_˪?zlӲV'>H3 )?xyBP PaPؑa=$3[|ȱO.|^O4Aҫ~,?vU.)')N-<5Ovo`?'d)(A** -ذԘuoZֹJ ~ qlTS =si IbɲA s:F#pCRJpq 3c Eؐ}}M f u&BmތϏ,w2y #OiC6XtTB[2Gj__Vr=.Q80j wplo)\0ܤcb\19?Φ^cݟeTPL w m/S+">] wD$:2._ܗ}rOg;\Vs@^R]2!F!/WB6 Ө;ٝ< sYBt `Fg(xv&m# m.e/~/sj82eFA\=y]ŬVWk5D=C_$d?S3>gwOnS*EрyȟH(@X2 2[XĒLm'ё%6Ä$DY,X_@O8bqH%D))D_pL D(/më/[p BĽj']\cϐo1Sg@<@0tr" x̾0 zs{|˻{< ~L}܄ZCx'_*/_woҽA,S3MpFq4`ۙ~pe/ۙ9#O \3;s!{z=_9r{6!^T65}܏۝r>/P9pG@(>Ĉ >ӦIX:].Ct)%QK >dvKs/<ETfP5FŸgO꺀)3]J֨7܁}nP%ȟ FTD1+R~z `g{s(²s)3C RИTdL <\'29PC(=K~<RUaZV^P]q3 ([(99]_C{=QQ&jSB &T!v~O/k|8xjߗӌxXy(P@Wl> Rī`b*ʣQs_ ɣ\=?ԯi$zP8xkNNP7ေ,aꊭ_բ;aKYs„@1”Pư/YC ".<$Tc{':ڏ7>^7dN/NKZ ՛8SPBқ+`5MM0T9(&Kyh|n;v!8VټPMDŽ{*p{9|[6`Nrɣ:+Bx^ =ucLTBRT(]'Ֆy]5a>%4\,N6PA܀ #ͷv;)`+7(s+oW>vUVNcF:Às_xͭggrrݛRR:>yUw[VǨl؄*P`vC@ұ2hDPƥh)! E (|rPH.omS<ͫVVd8`"@LG#|5Ҟ>Yͼ{-+#Gmm~[{ܿ:'qTx+{BeALU{u@w1ztK RVPG<ܺ ^#A \=eRREׯ[=Ũhݟ,fKʙY6Wa$Dr1žJ-?$2noV9  (LΘP|Xj+PCؾh-G?M#P)JE (#=\מޠQFq{'v$Čw@'s;\z2z ;ILN((( -p]YV}JA^mzO~ԋ0byB;clի4< y#'TEOQQ:v]dI00Fwr4lz^08'uɻ"Z Q>IXpD9d;&P+eȆ ef%ޝrvj@>} rA|j?,@elN)3sS $_iAϻo-bq(9iZmw,pzzUy~ڙLj#OhN+DkA|9+;Qu쑢Q׿nK)}(H%ɚˣtEW DK v?TPi-Dwp =_sk}I[,9>0x ם8 bp+F *kׯ>Xkuo۞Z)˒N`8&댈$ H/?tsq[$*y)~R1~8ptL_-~|h.oTIKj WHԙyOFM!dufRhC俾YZ mDDV >>\/8BzT [>}4QDCUi#In,+w֨,Ng|[.Wzu-$IMScqⲀJk'Ԁc>ncv)_|^lAXZgӴc W*{wb%П{*-b*hܢor*IHvbH!ٌi*2,d hs/&sNbEgtGŠh M}/fW7C:^Z:/#k1DKVX,?icj1>8Uo 8(@QIf*3!:}ū8I+S.[|JoQM8xż|gQ|<} %5u0#V1`5jP޳Dzs]eaz?oEZnbTOC&+AV?ԢD >N79>Z ~'F7.x¬EI5AID 5I^N"~0W Ww]&Y+hLfG6i(WkZe l⍦-P2Z);޲WPvЭljO;=}d_kDH7T%f0"*mKfѠюx=Nʙ4&*!(B.lLI (JQU7 '2yu26=\9kN1HhAy/߼Xڽi5+ Fb0uKv-'_ dmgH%q*_g ¾Mml%Yy/]]z\;Yx_#rc!_B=B*&Ǘ}+n3<8^ avmq GU,| *3ⓜ~rNO dr*Lp*oÃ޸vڠGPY*`2BO 5PskDcs","܄Fo<a z%Fu^5֟3y%}zP.Q*j361mR(0iUP˷kW>.]T (1,B|]HG'NZ=]uaٷI6uTZ!N^x:q81@I` eu2L`1pP Bs, BA: KZK9vwF xG2n3C,T^mQ%xf~(ᄬ dw򿎇7ދwli~k^MKV!B N[gw_F m_pU qһac`<%ȥˆY.{ xo`o2 '( B\5'|5.\'fJ"N`Gٖz6$>nQ>Acllgب6j"Nn bKeVfPĖp^0E^R#舒@ 󉒩9F6iÜ`8ϢN@@adq$x4Լeӈ^b\VxU  0`@]'qBɸ=*cEFyEhݤRh ő_gr#Y %xMAYR'@2N3CStHUPd^љaxz`@BމKYf}!ڒC[^o9Of.~'*.GvpCwtIVkN |;@6H+oLW$aAپAU7^9qUWzP*K=S{5A5X Ab qY_4]qZl! % :Ou8i@n0m旡9oRJ7%@3PC($~e`}is⫷>5.%sPe>w7˧;ES.Z0.%ckm(ϱ'q8}||!jɟb{8vJY`+ ף}F'zw TzcQSIB:$ t``r8{_{@II5dbN`x#p0ΠysO$ 0YFN5}c#/Q;l96rF=r iZ3s4u6߄yC0mh;9p @-Aw a?c(}5Tfy`Ă.w~d:;vCI_rm5)]qAJX'] bPaitY_?΀ 4L ^+݃u !! x2ѥ_p.8z3%fgeAGΉ"g 5t>D@5\I&!#9=zW-mzԢqGؘN T_Ět,>/+9 \@8~nAT*$dP7rp%[q¢Oc̝ιm$2{XK n;\\?S`}B&JPme}JCqrw0n*#`֪Fldy{3m`@DAi+49d+M1-2CZ|h ksxce}/L߻N`hnCц⌗I*{Jvv@;_[L̯!񯐽̈́Q(~heEKǿxy0);}1xEɇn=$АĔrzOݝf,TCmLuܞK1IwDS]s(+rb}gOR<90:oY[G'f(5UǏ'Ŭtv#(jh h% I@X5 PX"A v,$0`v>ΖXp.h`5_ 퓞&NԪ2~1?;wQaU p}Gom]HwmػukN`IAhyR/Z 8I٣?щmRVI jl=[uOΣs1[]m nyL 1dP |j-r 17߁ P89f(3"4=5Ƿ.>TGUua'^Bbsm  AEPNI:Ns(-Q&b1L<= 뢰PQ#`!.!@v啦쀦[ki6;0p7Ld9d ʍFHnrVC>͎`>(gk*X(q % 1b.u+Q_dD`$@*W=\o;~.ssKo= U^ؙC" PE+"4`2A*#DZ[ߍb ˿=>:/4*$Oˎ/'b8 $M$[ڛ) $I)y9">{{U H-J{Ճv@)g{lXѴh" Eԝs ݰ - -pe2qG+w쌯~Oq!2Idl8ژ3|Sr6lDh_Fa3f[Q]8o8KL˘"فM/Y%xKI0:V+ƼVjeTپ\d^HzӜ3l ;;l({~oj1 "*qo#$߀R'QJCtbX* zm`bRA)ρ 溿 gV$Jݶ~Qjʨ.+RܹLT@(\{0P9*խp-ep\ͣɝ|`M5jӂB45wxhliÃqkE9}QۆZ0sDY0A t"T"?+iD !rtbH^ְzRL+@\8^Ndyvǎ+EGP/\2 /1$M$ltbd{:,pEg[:*kfnN>a4 ·2z;_ۗ2R{tE"Y2ʃH#rAl~5N< ɮmDRM.HL0өp5k]6*,.Qp3<l0 B IW]zݣ,Wrb %x!4-G4rT#|n[}MDiV:k:.Akwr|*ܕ^'>XAǃ7̀LH^2)K29-W~)?rt7>:Ĉ11g9=F`MsOWf40\6P SSURNvUjyXx1ҡƇxѿ+~Gt$FBL{ˆt 찒~OXLNOgk2|BPTH ,wqg`PR)PR; пor)5?O'eȺ` ig 5;  iv{]=fw% 5X2{Xf sc_ ϪӀ[#Qߧ M39*w 1 .m݁9y8'^9j,(T Ft_C>| R ln0N XA@";X{X"f-T:# h7=КNbb)A|U?A By6C WщI}("!ה!)d~4uzٝ)2:¼X+T-$hTHLJlFxmʁ( $ DA5PNt&-<[1h*-&e2Pb:86`4vvB&p<ӟ (ĔAJW`>9PBlf%s*G6 O=䈬17c|沔Cu' Rh(*}X=SDE^ibzy:>lzנ.m$W8}% &p BiǻHKReTnfp7ۻ [_|</ BL*QU3 0 Cgy)d7ȕAADnO*FV"(  eds3 e:oGE:ٵ@)`W ΍m17U1׏y07{ G-?5׳)I T.OU/cƯO;7Ο>|ϊcP129b%TV*R12/ondC\)ΩæC$Kf .jܞׇUu/p Pܞ=Ȇ9fjgDW >[Ў 1rL|y4n<#ˌ˅ѫW'np,L#AY~Vܓ5YyYo W΁;eC=Im5l;L+UNFA.TQ4dCMBP$ @NbOyYϗjg Hy#fM\? ½ʦKoOD␾d۩,nIc+=xe&UʕGXXD?&+;ܮ>G>#0܎] {cc+E׀y)Z\WåOQlݘ ^BNkXCSHTE 36AJW=-KdԓH*Q105#g/ =}|xZ 5ԈE;݆"2> \QSJNNk+S+hD.>@\+yez)w&ғߪ[ΪΕ}㢑$a m8YVۅ|jKjP0bV/tS }og]}u<8)E5C!z_e B2JFG{ܢxf"$%GGGO#@ R(߿OxI.$i/DFc: Ft:3~]^i`gZ+2la,}= %.'|=񪷟(&Q5O =ѬR_)ՕTm]='sKM?_/C~eaAՕ3:?C}1&$ @B ]Jj$s ` 0%s1H)2B)>?n=xmrEj2 uru+ ǍQ"4ߡ :ɁkoiU/PB~8q> Z"vb$֠B ze!}Y֟{qPL]IV͍b<9vX',ĹHnDsoL6Q~~ޚ%URFXqZ)eTHpFEq+<h/LZ @Dύ5N~߂9JfdO[[J$A@PA$T] m~(1O̬ f:ޠCQRq}bZ4sg}g֪Q>KdĀ!#Y^ l>M \p5>\3H=ړB`:Q KbKH'1kt+ Ą(Easd4U >2tHIQ%g=2RK5ju.X ;|ЮdHfY+:3eUɾz BTō$e9O3/JŁ\񭤹#gs^#Қ+>ՃI@W] fs6Nѣ,GZn=9ӧfuڊ4JVBJ ojD d$Tma#cH:t-=mAqSMFjin7S$@HAۖ屩F;fPeg{kW A@9zoђ_è,B8cOH۫([]!0=m}֣>*J2n9 E2I+a4#,FcmQ4 ^DB 9yEk6kY:+c Yh6vYr{98kz"97.2%D4#84>}GWs?>G+}b:TQ$5;u eMI6S xa/O%?JQT2`9ftdL9vMRgG$'șdؠ|*cd9A cAAAavThoS(~Ĵ!Ԋ pQ@`Sr'PGwͻyma}wRCQI&^,QDD@8DPA|+77^n"[I>.W*D@ )ER* "* U@Ov "{P? ={'=>/9BTڅ8ޟ_ "" P^@V :Wcj&:t,5.ўfC4; vk>`qϗᗇ./"0evg2wg5fTiڵprcM/k~[Q%Mv2ljݞ;Ɨk)|WȐߑ%ય?W<~^bIDѿR:qBtHѻNYtu31KAPRfzKioN--Xd3N ݊)UgʁA^0oi^cEݥۨO< @qfye($|}nMjЀ:{=wՂC(ԛ? f\[*PX=-ׄ>(cg9Lg=+|q5w-?b)1!DB{׳^"0ӇjN.,J"˜jwP DgbN.W俟LTN*oT(6'pWď=k$G M',۳G ~ut?{ߝ9@K{}%öxI!bofBwoYQs0{lOL4d}a}Z8Uwp~Uۗ H[j}ޜiuZ$MpէGb ˉkEDށ!,s Q]w.CIQTE xppVOE7k.;ԇkߵ|&?!zOSg=CxFWsOQˠP4~QMHx3oj?_VNUSN { јtm-e(1m!`ɭJ\d&+pHrJUsK@$BuV %0w+pd'4cOL/IYa!w$Pow <0A@BkP ~xRwݺ/DYB )FOaOS8;=e1l8Jj4FZǿo^S(f wMc<?bC'[]'Цi(2uoUki LGUȚCzLf>JmS'oI8!&%]:~/fɧE^v/g|B@mun1PFfWuPQ017{N $ $T%o 1Շ_ۓU X>IrTFr>NEYhRJ1A!P[< F6DpbrksP=;wo(`)5h R0YCy~;3nU'W4,B3.ٚ+ ]mٲ2LK<Pw[o#D{;5D_VE+lhEf5YĤO-}iM:˗blv"uFhI'AKpaeFˋ[бn64 P8\GV'j! xstSΩJa$X[M5Σf P-,RtIKyyhIMuQQT#KTLms>0#WN_kF*P@-tYUy%Y`2I9PB"vq6u_O/%)aAgՋ.ε J(rsĸhJh pXKL  .CϠreu_n~\_KMZT Q`Pff=6&DJ"-!F5~p*v"pxZid홊ꠒ" OԬ֬vDA[ԁ0DGe +F \&,,`-;VEKG{QV%%SzJy"|AH$h<˄blhR6|S~_#y}/hO^X(!ńQR™HDcT!.(lMq&59pw'K\ܤXX@W|7l٠5R֫#SУ"UH5WeAfc:d(sx)Tֺ::QW -FK-+tI(FʨYI۱ZNe2Ef!UNF}M]b, J1i5XBUMsDgf0wDpBABH,+Dy`IMG$/:[ً5XhqQӖb7Ӛޗ%HIF+5@snD>|0k.&AC lLeG naq0_^\[t*n+UvkCh$qA>=_,pJZިi=z{3u6NѢ] 3Pi%yy * O3A8e0 "EJ)LsA0z%_Hl_D+oKOe>Gr!(}#N__AڪO-7ZlxCE ?፡;1dӬ V7r EMgsȱðG׃-~>Ag6֪-8 L1q,FP|4ccQ#Ъԫu[g< iHDP?p٠s۔oͶH*C40q8y&{c- 8"Q BUbC5=  VkUPQ"[ 4ާ&yR.ު1I.C . wzx7wJ/^ C ITPw"Qb"<>y8^8飳#s. }I|"h[t=++$M/Z4EY uT}5R=DZZOfUWjÓRI@+ï/U%w5q'@yBv>W 5K*i y/RK :`E\ Vyi(}H?5z/<F&l PQFک0I( X=)9| ,Shfk: ֿ+{樉" c;$|?@EA#\];ՃfAčdGxZ}mv>:_fA I "Y)8`vz6(g4R*K#ڷ,ɕlaVVM. PI^zHx ums%Ç=#FUfXtsM}VdV~]:5k5ΘlK/llaR eR>BJ8NV9z6#Sk9=M"+yd 'Vz}_{ bE (Bg]\Jtܜ7 ~ڠslOhxAx٘N>TEA^ |+Z@5tRRtZ.ݜy;#*ЅF&! ʨT'6AݲBAʒ׭wTn[wF5D T{O/SnpdD_;,IV2\/A\7_ɩHK3A! &(H2`U\J-AΩ*"H?$EaBj*tHGb ř#]$gָTNQ=A(A^_̛%畟<_]-]v|3icG`?`kk:'X^  jRQ$cHMBi6 =TnHUspOFan_[k;-UBD n1Vδ}.剤LŎzɑݓ '/) LXKֆ6%0%P h In6m]yqr6G3cDO۹`B]?> nx@ *֜}UqlS982W)34)otD&(V&e9Šn kZE ̇^*t}ka f2 taݙ+7vj4lsZh_C;:K GP-䧼LJưt77rJb&@w,׸% ̫9T0~c }q(&;숶3Ԍ3y3dp&`"%~Gφm >O=$6]5t?ˌUQ@E4T8yA8EBe1Kj"|O/_pToK*4:¬6"ppqR̸% UڎW0rM4<|aZz_O2>QGJ2Յ rUmwz~j\4,޴EY(+"z^3&0yv S^i:=+sgغ˲u\/oukfPQ"_I3jC >5η֎Vl.SUrPEMc9=a[슰׶RƟd!!nA]^{uoF7NmNtwWɁ4@we;cR @C 5 gQX_[ۏOΕX˖U=o>M\C~ev"Z^8z^EgHgB#5UZnz#.ѶOqDfM֠J2\>?p`\,z4_JrALX'>HT0}\~*䚌9\+?W3Of+1TAGdo8eIv0,uDz3)%cײPgTRܿ/mYXY'W=L<Qh,LE.IWz (C5M{BHxy.cf[Y T ⏘Ø6$\ Bʹ q0n|7W7tcjFY=nʗPi/XٲJgw&"^f)x׵nP4R}2n7Ա9m6Ek(]ٿ\>@`Q9 a%Ī@g_yJnnaOBCax,~I=ҁH(""6DT5߇*-MdIMRE9`-0AkFi(&!qfE!KCPT~1&R%ޡ#<)E3ÛWP AacQP L3M* )rҶ;!r( Z.3ܟmb^jC(H܏ QDAel]d24R^wdne4Jst =,=ޘ%$ r HHS(Iܽ  e /TJ ]Wd^L`Ո+ۑA[¼!351\(yGUȤ,0**a!$Q($ xb$ NI&[V泥@1AS"y'*ꊕ#k.KfIRcP#w/dBdo2 PJPGۏøL޺t2KȢU#(RIK L$*}[_21`r aduE{[EmQJ+MQp#rc&йݺDMt9yw)\j1Ftvzy*`WHyzDbv5:a[bvWҧYFua7 s=sȈ"EbRڜq :^xPr2PR/#04Sh}N,P3*qJTBQ[ؒ"Z2^`*4(zʊ~bJ"#P'U"N9.BC,= 2BK#w9S[1Q"p=U9^y Gܢ90+A>aNV /6)-\ת^o>fcY(kش^ng59L2۲S=t"93C{qGE,ɝF(***=su*T)50O)Q`^AADF 9%9UYNa-Ͻ|0H"޹ [!F!K"$X5,L9)Q[*9FY̬QdfhȰ  < ߣң3X,#ԻUO$;E""Q*"EEXÐ6h y<Ó5E5P-=L;Hx EܪTUz  &5\mΫXw$4alm|ߖQ5^>7fjzo&:xͤm$0YoyADRK`%+AVRU@zRn/V2R P[XֳP5u̬mW{JH4(u~I=ZXJwz="3+ g^㲶W0'~a ֝}cޕGHX}r(Z1J Y%hih0OCP]TODdX$X()/IYR,?v[+WQ)*JPMJ*̣IFXlF""MaiAcC~RPy5ED^ܑg\s3%Cu*tfнKa^T>^pFV@vcSq{y{ qD`)aتbD/m*k摊Aw(y!b8y㞙[Qݚ-f\%E4gW鶔Rdd+ڰQQ~j`K~e=;q5v},qth޵PIQFw +>%1X #ĵE&;n•N*`!qzr a\Ą\{7wBߪi0v.V×|(ZtyFA•nqWTQ̢{Kke琳?඿^E=24Y[g6ȑcѪ٧s6~#aLtf;ux=Zv}O6dYf{?;= ndb* ayĮ'UZvCdbpޭR>DGVlQq ezv!̢iO<0pS馘T^;_qo~3oAKM *  K`TY]Jmd;=V29dC֮p\zϥZ f Dbh|WBUEa7m#dVy1= 4-sp<΀ԮPt-DnZ\IV2ۭ?zԢt\wFR2&zey݅ڠZKXۗT8jT52e%k̃z5֑56<ӮfZL2 ?Doæ啫[ w<]RJie33y][hӅ]|[=kAz:@ |goh$Tbȣfjy ! A?G3.y=O0LIB5xROvoX/IxS*1œ8#f m4wqZ޼G$Xa|:܍9O, A-- ۱mG8) $"舩xW#<*%*"NqZjɀñvp-}t0` Yo(ѭ[TruP0ZZE O{L $33;Qufφ6ury_ WarM4Y6%w˟Ev.&Gv a gc!:evAX 7iVUK e_6; -5}DvT4ogRjo_h^[tϷq՞!%DAR?5Wx \vQXpH.`B=Hw t:rm3"+zwL?'ߣѓɹðf3f|ӭP;t)@G8Po*4ݲ=?NL.u>E"xrz9#\hyq_kbk T54@}"d;s0d'}9'ow CH4z.i63/=q ̤7%lV& I%ЃO 0&Z+y#Ə\QǂHCQ`ӸQʍМrmPWd6Tk\WQYAo{ (GޏufI~!кIg$^Ey<'8Vfg_cI3.sitSxE plbC^!螣Y,}H%5˶+JޚZ4 &⬒񅪭C$|I 5rBo Q@r”UET=/E/D3 ѧ:|H R Kfܫ|D Gs3]v(SHhoRR>CᄄDIN·&v ^}h~i>sPRמiO6ѤdI@ݟK9G_OʈD@ADEy#{׎GLQOcȄkѻӃ8}譺ȅ.t﫠1M0q)E5Kk 3[5Xk>dGb5(l`(2]6 N s5jOޮrV6F&ҫyӱ~ rQh{>{=i~Iۓ?+%E73+Xח+.Pik/arE$Xjp4t:WunO Ϭg{`mAN!L0~+- $">-L`,|+9yVB;J0m̲ԝeB;2> /~AhTb0/a#7Sdu"{P-x\alo8<|J#2m!C2J(6* is=d8f [ P2Ew7cu|볭ՄXe6͑AdA0,1”G"lʻy`$}3dG,+%e;+%@fYig'*GuBqŷڢ5آJ0r%K™n?svkϐ7 th\UUPK+$C@]oht9<P(=ެl!gsnq@ܲnHWh~kJ naxmgL׺adV8$ 2(rx8,1ŸSPmדu> m3 ]vِ,mx皑x@cAG1 qD iۇLxs wiV&֤@q=ik:J j6(.=ׄDz^QB׌a FSqZ/&yRDfVA̾('qctU <:D* JL'&$j'WQA#BmqJU*ܾƮsu,+EnU.Fĩ~.Ml,0L&H>؉ BTWtu'P랡U6Rlk ,l2 *.eQpn9 ;Y?Z˲M2Z@L.,uQԕP^pjŤTv-!a-g;dfR`اQ?|{ V{mڷ-xpgcDtIW JYUso)~y<|?7ibb E5=/^O@E1DDOH!QuPSiH0DאY`NğU Y1$0unId- l?zk7wKk>慷Iw -#ݗg.gꚵG.g̵Uw/4(GzV>| sT =+]suNL^\Y*[=H!Oz: B4LOvvR#U AdI-(*|#'!&wHq)Ue]UscV,Ql1v#˪LqU Y2ag`(hEM 9RY\cA75qnЕtUEinte[S;359SJ%MO^H Lh YVkWz xF}69/¦A~JSAR:EX!-{xdӭˋ81q&ݑ٬o'96.IR8M*(~1|Fq))AإZM!o?j;{h#R&ap*gzpJ:(Nˮy|'CГ%8"e >HXDki_WODcfzT>@}d{\{ͪsl)Q0G?H굽=ߌb{-s`۶g^Q4M ,`2C Kߴl⌒Do=%6Jm sY 2nq ヤҞ).&#+}c_BD@e4GIaQ(t)P>E&aMozxsBՏ:iBƷ]Uv'%"R~ Pwq.@'XO;Ұ"8G$O߰a}L1X7e cimNn\i"09;F&m}}Yz8_]w՝{rbK| ((Hi$fxTdRE8LFĜ]8R("J(`ܹo@uLPFMB)ՙ؛"?'I`feC=ށ⼙hBg")Ñ Ka$Ϙ` Ou$ X3$BT =3ʒ(gKm=7pugl^Ta WI $ׇVVeMʬ]:6͌-`4eqqhq3 -HU,Rr̨sQ{sIUW2ZOa$\KdtɪʚOx JM st޵u A VvgCg:s(Le]sS}f د*ÜoN&v2z,Q5Ҕ DӶ`s{n?52ɣ&mڀZzLj͠= ]d;O2 y &vڏ,!TRlM )k7D !SN{r.2{̿ ¥~!l߆tWV"Z,Q}ؙE(u~5 Rs*[Bi{U^+@Zxu@-JdXSsEWMk (7uM \ry&&<$Q35^:co Ij;ejS9;Ihqxv/>FWey۝RHXRtZZom"{Tk75.qK3;]Hie$zV^7G7Uޢ01"grf MrQkۼ^&SQ|,OMx.xQ=7kg:"0J$*{Gm,:%vL-CCn:j]q9+j%V [7Du#xzTbJަDwF,i^vV- pCf /sU=m3lu0R1Âa_^оwK԰TܭacYʼnrB%DP.誘z0]RfS&ʱx-v{ָ$b+9e5ӂ@rFd**(3,L%͓0e*EWs5~{GZ4 (dESeݳ2~?,+X'gTPE][H +|@ $&Yx66%!7LAd=b(}O찜o݆H<6 ̆T‡FeFBs}.P;D/j%\ zf`BE-zZDEF0묟&zʉ =*.Fa%(Dso*DK@pR @=2(Gs- CY:={>>imrˎBn`J!`/U6jr }߮jm\{Cbg؍4? 'Ywi(@03l DP0+WБ }:R#SZw~>ׇPD>DLؘ X1.YZ*27ڵ@5C +02t۳vcpDL"eގQM_Ɲ~$Uvn"3&AeAdM*WR߮@*!uȣa$2T lӇ_(Fc ОdٌF"kӂ`7Rb0KHB@RH%K5-d_ D4zV$3UڭVa^)Z {Ufȹ[kg16gώ| JT$굞_fK5X6'I&uy!E(z 9iHXIAPUo}p7,cɿH]HR%=â#"z*c7k0 'ôf[G?؆Y,&Fф ٖ!.NyJ8M7%$~햷 Q{E3ݥ~'y {m I\ru*t p!-#[Phj_Ob|]KWN|?ޙf/庚&__ ptҎk=KUUEϮ`Īqcjt5>4V@>\[\Rt>Nm?A|P?;V^E&wWM˜ۿO {.u.uv%g0ujn#uZ=5_bnR\j>Jʫ{?+NµVj;Y-]M[M̕]^ȰGyT}#̹t/ُoxm ,AZ&@{$FV| +Srt& [ a\]w495Y@Vd+\Melݯc K" hfOK?+_KuJ7O\"DDB5¤ a$ $o hm|N3D LPAJry_/km+uO^?*Ͼ AI$ Ž@bԡ`RDʛ16SgDbů(tsj \L=?vIgHM!MgwC:ʩJ=k*w: V)+1~.hIzE-3uN\3a3y !r#2eolĝD ŀ X2`EL eA#ipʦc 3ޕ4wJ*yjE+QW'GG vEk9DEXH? &A2yut(0DB5aT2A$EK33E,F0 2RmK;TɃ8m{5 ٙe^1Nb0ٻ+:|/&JyI/*PewQ0`AL6BW ( c"X)wr$|˅(d3"QJDSvOZy3'R "z̬"ǩ7+^W Y3&y[a5&(?|3C ,_ǵmZSj}ebLג(S90S3|ʩԢ͙U +.Cb=RcY`y *:`CM֜(')5[oIDKpRvsqMҪ)Z[f!ɟ52}I\`[ (B YP%{$:7vن4œ}wt2@aX(,6@;5s<_uk&k*TUĜ熆x@/Y"C Hd:Ղ._ŸA<<1t p)aHh5c,\B 2/EYArN=si{,GF0EMi~mQ3KmUbr՜bŒvZ0Dg3=3t .\X 䇕m-,pfR JE|P1O" L1JbrV|h(& hOC( "ЈVAAKd̔4D (\O#$ Kd9!B/ ɒ"(gR:cPMԃi)JdR#֓ԙ+1rV$F2A(KEQ2)wmo*,Q֠ gT "+ QOivhGjHɳHaYP c]JtC(`a+./d<0&grrUF$V*A@QDEUPQQU"bٱa1y#*"UJ@N$) RP)EQ~7pU/,E#A-4`#1t鱴 R\ne5!@P4AD1! Hov-R[Yߤ1QQBX("())"J.'82!"b*"q,!DM>-#qeeak3a.U52JĥhM- :ф#޷3m2Ԃ-M7X1_s2wvub( 8f'G9pU8% jxRF$xg1Ѥ({9RIxN"kBݑEb$$T:%02pG0ax^E`I36rp-|hGm}"(fy[l7]Hy'}9:ܨQ4eﹴ.ldԱIh[EE#5F1=|}0*]Z0tXuKc u~,ܳΓ&t:Cn_ᵰKNRy]1w;)k\{ŁU]ZQ"eV@PW0vx?hIA"`((qr@AYXY&-^Y+^nRZ*g ˗Z*Ռ2otUPD7{8 1^//71zP<2"j* `(jaQ%*&1Qb *% AI"!rDb JV3 ńzwC/ Kh CN(m#Af(3>B!,pD<%^ Cڃama1ddL1$SΨ6Ț" i{ CC.ٲKCf(aU<5 3Qg չ>B_6O"1Q|V!LՆ譠ԧmoJ s@o"$$EG&lHU+UR1)ȱ[$6:K}X}͓k;۫ ^NK%E.|ť{2%Pd@DoYo~l G(&Ԙ)i;"8aqx D qb(I30$7S$iV ?P!Q_'$C$u2%^D!ffIP5gF##]kȤ9^jR)Yb `ou2HBcᨥh 9 gȈ$: U).K71 IRiⒸ &Ԫ (QHD I@r 4PlPnrijJLEy;02L2 KQ `)S7w#7h7"N$s%%1dz.$ƛmUQY! t}I#BeaUyًz<ӷ\(Z*18ذ4}͙D>nzyLn5Ȕ"8N^uV Vnd՛kNaQ*Yo+ 8d^5Ļu2th!GNPZPq)&&,%J &l uRQCM#M;B.IQAgI(|,$B&3R1fRH#%TD9,J!NT NQzDE8^^Y )%2 1)̆($J3f L5&NQt]$DGx4@9!t(TX(B$  3֑Cig @ЩRDǦ-S0~z$V5-mv ( 0m )V+Kx8$7CLObVށ I˷L%L3lR0ʔEY8':yEJlY",Fnwk,qG8F МƝQ'g].M`T ey۷8mvY* CNhVɁ6D[yg@6e!7<{.9r|٠DU]aʂ<+%k+SO;m*O9PNH31D ~$Qyib_ Jd*H1d+ۀȃ^jI'dklZJ8rý&k5 $OI0 (4fq}# &pLEqͰIGG. nλ'P (- mH:-ċnq&da$ϗ[3x Av8AO~ߪ' @&$j}n'US2[ȭj_I9=8G>N"P EFT͞7-[:0ȪyNybQ⧻萞%P!aJW!H77uψS7kfXa1$i*r@>,_:=atv_f)/d;7>oiϰ|.})&EGD'KYg0"P i30RrLH1&Zr+3(T>QƠT+5$THSPRD+f)#VY,P UeEAAREd.%Aل1Qa)!ZL&aXε XO NB(dPB, +#! =RW2C'p HDB~0ƠzEP?Vτ R(K1*h 0S̟RN ݒ[ %trVP¡ JU, o@ YYhZZgF)98 *eP^99^TxhSG(*2kD1@0Y`NEC"lmԦQ}HQd*å dcTd b@qh g0R*pe0 S()**a*)jJaȣ*Zw(f쁌*ƍ(r#+e#!jHǧ5Wl6d->K~dDN j{逜HL&&@CDy,a8CKI${0FO^6C;H#"*RPQBD%IQDM)CIAY9BP i&?kDم(z䟾a9` iKeFDKOiŐ+ Ŋ}l:Ҵ_;n kdPoCL![4VEKw+3YRmvqs9p£%BլRlY-X.SN{̵L%wa.q6 4_- lJ#Cq;]:+VE)WoY1YpY 0Ф DO*ո ǻ 3V\x4r[`bVpbDmp ZׁG7l;4$$!f˟*!$#8Ad&2UO_!ДD.$$DX$iS_wS'HF9ti#EM%% ABRcϑvqTH#UtGddęRmTl`NWDV[f6DF,R)EcA >,?;^S9Xb)XN 0̜sφ?Ǥϫ~œ~J6`5QRߖׅ9JXlmC5(iz9ʢԍjM H{yYfҲ |$<QIZRjZe{|T j2*XwJy*x&JʆdE[dd?8 ъfy3ˬQ8답DE},+$䙆AۅEsΥd'6,O"'', -¥aR>1vЮV-Y9 2Պ}&Vg [9ZQ4K Acpdij.Q" Lԍ>H9sb|}C(y>aR,,XW9XO2BcZ̊Hy,E?HTNd+"?2(,&R"  )OEhL2ZڄXAV\a!i6#KɞD2Iӳϭ!ו7`&SX!۞;6Lb~vxXJSvsrTC>yB$$63rT4;Nek'c ~۾æN,uC v0e!@/f*d :oNiX[@f5klQ)=RGJ;tD׎ ·ix2縘8ob1ժH6(hK\P,~I^{38dʇ!  Pb+0G )h{ "P3.ŽrbOW+Gg)k̫2Olf/ā,k6dfPS M_ĠL5y{?u֕&5Ԋ8Į:N74ϝ:rJj2)!irĻJ?,1I &V7ៗoRa8`]qT84-.^,Ϳ ˶-Yl=MȰX0R">2C &EFb@P&E!a~3bװ.)9moJ!PrfWP2L IQ+ b0 S%dpEDC$#ZSsPH@LK|k kEGYTP"&Rhj$E2J ~%a4z~XEA2(6ɤ(td>HLDA!mpJYRmmi@% %"HC%_x[k99.FMjQA0)ιr (j%rie2! eGPuHr 5jZ!)W$D ) aC&sR*=6"0ZfL!WbT%ZTr1pXBqe,T 'rL"@ED$G9,30"k$h"!Hz`6ؓ%y521GA 2;&@9Ǧ2W&4DM3ADKT1QSHTaDI5z1iL"riԝJ_ObhU3TTTT%%41044UDLUda!Vj"bX6 IX b$hxL nDA-V5ls@YaLm]`VT';3Nm!U %C$}ԣx1:+RkMJU;f:c6agf o>\z) f9TJ,TFcVnsP0jskP`DwZKA1*SU`L(HZtQ]|VU#;[<|ep9LtgDHvO ~F1mQٿFAۣۦ'TpW_ء}s)h`.tR\ӧq8R:@~-ZUޢͫdma&2a`AsUj#]Yi=C<`p` B_{9,ŻfEiz Gqx¤vqXX贁7@aT@+Ki^$ ~(E UŽsk5}LF2gloG$vafss2-.'JӔ϶ȔT`e|] ȷkHn&мbu+oh=]ܡ"NTU.pvrJ-aHڱ1s6vPTJ;yd9PDIA{2RAs,G*㜰#V{k9﮻8V.\a S:,K{WE;@f.gBS3c?kOԺ_=PڹM=++)c 1Æ$;-!e>,:C'dя~PH/xqbmKJ{QAg>Qe`d+H~}"FHi 8366\Cwr(w9S-ϋQ8 WjAl cUҍ4o-j;+]g~eb"30Ѽ+Da*gc6`/TEw05>gyESIl k+9L2̕0RxIkl9PaCnttsHu9Ҟ6gSM=,*ƒ!Te'tZaA]Z c^y&fAc0//rURT͡3'#b:06b0"d3fR a\ YfdJ*@8<1hS zƬ9Hw-Lmv3T_(R᜘;!@w!&zf*7E' A]С[a5l Wq 1氨 VL2ۜecE#*>Ncv(LacYTE",EɃާDzLJsOs/˾6GZ_]ٌwu#uPUEXl *ٌ1NN+K8>g{(=mn%7oLjvKj`IB"V m ~>~9NZCm( GdC0g05g>uN J>L'LP+po{=e۸pQ"°PGutyX"-sH1ˍt@5 칄Luo%|O`TYk+'ls"aڋtRIQxqhYa)?ׄقADU`ak+n}SI !48~ oM/2k3Q=G߲A8wf0gsן\념`N9+7Lܑnkqv#9,G0rr΁ PWp<=Gor Xi$ʭYsaFbF%y+ wӫ(7݈*357A1(c1WO]ؘ" Ȩ$ȱ>gAŦhRs???Sh:^P2+rͶ^no熖⇽fnqSpϞpfvߥGL$Er;RP de@zK^L/]sxQ;SPA|?- Q9|I@!]~]ר"rlU=-DԠ@^o !*ȾshD<8 l!Gk9h@b?|@(DUD'ݑ|{o'p6R,*P~iAw,õ=ؠFKO{vpnNN)y{0&L]Cs "T+M 0%;OpjgZtgآ\m=QSƋ,-Xs('m㍅3+4V-"&H>__cIKCV۸[Q-;UÔx w%?־OҜdL,D ~"z@O)@ MFÙA"L+PDDE˿c\FUCcD%$EQ2MT!l]7ZVBKnfKOEڲxnբlEr&% -JzY[ffƹXzb)'hb*8цy߇Lc\2kC#eQff<!)!:Sr/H;WvBTG . Aj8j=d^(di SpwFCvj9mfYsoAcLB*CvI P:(>LQUPr++;ѹ(Uȯ %oOOO˿=7dUCqb;.UB댖C"tƫZY4s\tCh WGBPa OPHN :^ΆW:y\22ePTNW:pDĄ@qpPN ӿR/TM3c9Aa ̓B+Y[W)Yl SEh,|f"=3GǧͧY~F+ǯ_vC&TOW0 \Q9Q؈ʇ\{ Z7S+(w5C2kLɌ;řg9븤ta+79Hq(%{qO:َ7җY { 'sC|Cz^gxȌjS;%À!s Q'W/x@oVJ чG g:y8~Zy ׃0^F1s?NM_o"61;(A ET.66r])R%#&qmb&oD/J]!Fcs_20W4tQd36a}̀I"(#pD-]#4 O*dQB-ٌuhxk2p`V3xf^cwb/p_>IP) QߡKd?W#=YwMdH*t„ ݮME:ݶ.چ36T1`T[9p%MϔKԆ2XQݔ$s$ !L0j 5Yʀa:2VY3Wn|MU:_3l) @ T J/D( ?)>_~LG6kxyj " .<|AN(ޕ>@;ᘊLA^G@&f|OHP̆C NB@9}r:AP(=תNq0○"(n+l0nnD1^>+)L /ih TI96DEP (%*P 1HQJ"$~td2AIB*b%Eռ|UHzP7N*잿>_m:i> @2Ԏ F>T{p2„q=r~t Ha&>hۏBM yPP 9c_;}\䎗j@6d[1~ _-/j"'Gɪ̖z|x &|DT)&auH#Ҏd"{ek A{jcG0R@CtuS3*/T;H=qR A e{ԅ۟\|-Z#:x8,Huo53 P#bT H ~URR @ %#&%Z?1 EiB! P@+ eC>_oލ] WCLXL*@w$7l"#?Zji`ժÏ ?adH~C}deCj4 9:JHČ膐1^gfATze<:^lԓ0scbt?- XCM% JТh9h r"ҏ/ W\$;Czf4J Pwi90stB]6"Annߎs:ߣ >.J?#;kyKP@@ȍ~LOւ:_}|g'0|,)M18O3C/KΌ)fӪ-\ksI̒j69ξ@c|Ngش]S\DZrI/5є/GWGXP<8}9ځB HLeG |@p !=9}L****sWyA:B =iA }%THp)|drPx4A#ٷ*Z8I 8E)'y][AC.HBT@hJh)J:Q)@F0\!">8%RBWiC%"pԅ"hyI .BH2J@iys.ͧA(Au* |pNjs&GokO2UbҴ)?|_vw|$@x.tP4^+i|X{>1ub;HgB|@1މº&ziUatQy>lhn&!vJp!=b$SaC>0>~li\ԏY-Å1S.m{<$)`E:$C Xظ\BH:@d"R%mlCwq 06`{xQH9zP7w'Rry0("]Q2 BACJܓD|t?TՎ;Mـ$ U0 :C)6i OE$7dfߺexA"d=Oϛ|^ ChЎ„~ɍ5uKZFڱXJfV Eae%g̊9֪v/40{HR3 @yc>Δ) 2 IX(_Iҗm@Q9rB*ZGQ05Fr1#bwh8Q+i l Z^×,I'Ц>Bbp}:?c0`XO̲`0eIWz0vs1oĸfUakCVsB;~z٧ "&m v8'Q&' Or(zR?r |2&*H ," J /CQl'2tTXA@J9Tf 1HbaNZ3ҫ)hC8۾s7Nsf4%!ǥ4eF(ԓFZZ%a6?%=5ͶC҃wW${Sf8Sl$$7LXnˉP,x fzȢ.Q"I&ӹnu:`/׈j+ʎ&f`ve:~zM*kuC( w[()8! ' 2?O5Δ͝nY 穰Zw|O;C9a gd98^\D#1F/L+^Z]ͮ-D dۀ@PJ@l}$9ծrP:6r,o#7{} O@vxGN}ȄO_$}su`^'}/ը~mWL+s*Ej_`~O@iE&TDS>r孷莃H.\>Cm&ԏ7@˜gs "X]]U\x5۷lϊ}`8dfԫ$xN)_E BTE#"d1IAV~h0a /K.^$#+ƞ|bꕩuAB~߽>Qnk^qɱLFYNTVkiV$Z嵨eBCD/M(x3]u2kYyh,FTa֚Q]UANSap鮰P&?Lمo6kcEaszkH`B7X(/`'2L 3.vytk;d!`1UCH:7ηQeשݑ1@HBIU1t Uk~:s6ڼg xf-@ZhB'n`{7RbuEBEzbbC&`1`0=&st0>: Hb) %l䉘!}1$h>qcxRc fIDzgI6|nC-wxHnl;8u|ADk+ {7}y9_B8?M(35"<CZ3=Һѡޚvv[5{PA8:AtΗ]N79 CĮda8d|P2c*d1ͷi1F@D"! `0!_r:]&\D7@8 '~f (dJU<]00Øq&@qoyZّĄ_+9>X#02 pYwQT.Gf;$9KOWpl]%g|~3J殧" (j55'v ǩk,IPQ팦'7'e0!Sjn9`bdb1[.F`:VնdZxIlWa!B<q8ly5w`(#*ۜ(ɫg'A!DG2hlBӍKU/![> !( ? 'Ubaf/nf3k mR ]Z,OD!p;FA:2) d9sRdS #` _hAj=8I4P(tւR ,4o[2֙a+#Q Kۻ^s(9G]cOu$:P=r^W.L_mdߣؘ&Us4=TumLSU84Ij`e0s*6YΑP)`n}qExo־>j&& cBP#~Nd}]yWqr¼Omyҵ,w;tɪnI gxm{&-HXE0v.[7@8J1BA+?gH'Bg$B(/xp4%3"/Ԥp̻7 gk$U5FH7c^qel™ p U"u9"RLGWJRN,Q@R!9(PɊ눬Lpl"$E=+l1h0٧&+rF9{0)j #4́Y@GTG}h?6U]:HmnSuʃn x#FU^ܰ#}RwCQ AP~1[Kvna UZaN/%c R"xl*']shH>M[CѮknJmnK_%W|ZO  DR+k 1egmhFDd,(\AG&3MCoVf~07g5\nrji]UnDGPE없'(RdrG/]Pb:P,:F /CqabcB B#,PT զYvNjS}Շ"5 0sMlKaܹ淫\}SƉgmrK)j !3VW3Df  ڒD]޾ngi~.?saY_ m1x(#_}|`΀Ԣ"Dl0pMD ݘB )]p*Q :q,|EUԮHlU09Ys]pەB`x;#1|o=1JkjjERR6fFِDw]"57ZQMknyHQ]uwSXTjlrz/W$$Vي Z-C9Z]^%8qAlFTVP`ШRF[E .fe93Y 톩_8%M}MJɅf#:#^Jiޙ, 3! Ctjv=~t-)a9 .7 xuN:덶DvVӄ}&-ؑ}V.6 =EmǑM8up*έ *5,0hu{+͎xkk=9-g9P ;JDnO޳IA(9귕f"[$oI.Jt37:ԁI(PR_)yNg_^e6O7P(+ A:Nwܠ$;k:\`:z=-(DE!G *b }9"cf2U웞pY.,'TEv9'<\ ~V] &lU~{m;=CvI}&r j CaχO7> ȑBqd|1Dz12'{<:>o6Azbɹ鉷= c 0!et)\D C~Vv@C%ܲr[c8FHͅhgiC G͟A>yŪ^[3Ȇ+f{|YO/u2|Çe~d ID@`CQtrY,7Y#Gb ?k99bSgHI8DӀaWi,plo ޖY`,UTF%$VΗ,D 񓜖5R6.&~ dי0S9CL <& wϹuϐPpP\M _8-dZ\S 2 ̨ P h B/Vx'~>~\[;jT90v F^#63WpA!+E+O5epL1JQڪHGP\T: ĒtKnF0>V#*_:7ۯ*<ޅ<^=CBRA)QvBCMqї ߒr >*R>Gn{_3y{@8 "nqA"/a*[+@v y .(XLhʜ:1չP 5"dP#Qdtf4ox CGHld%xװqvysob4lk I0/WǢXMkPx"Ak8ƶ"1=|MװX agH:BHSAu"82m)@1@2 %i\ ;`C4gJ>\QN}z8W['Cػ^gTyH>ml6qO^'i$Ep(eelgGMYYu3*'J R[myifC"kD͸sn\9J<Ӈ0WE|RB1-Ћu>[elF6,.HQ^I UE=LX7^ɣVx;{ﳊјcb,zϟ:O%8P&.G"we!x1PZP&"JL9 WdzM$v1AZ减6q3M8`9"r-vgҸY Ʒfd5T4f~w?@6/"y}OG㪡"I<=Jthfu =|Eݪ(QܝG<2(DOdvԠG m17gTw3>h _c MsB"b*m5T xy4C—5tSv=8lb;d:5z6[F)rT&QWVe-ZtEzr]k`O& :O1C jAsf4oW˖+xOOqn=K/J"qm]N +`\K# 2>Jq&r@o'??Nqbh39&h,q*$ĭ`~(k*!];6R;D$%j! R@ l%t4%OOzݶ>s۸iDp#yzҸh|َw;K]߱}>uKϛ+̵*8\qҿnw8"rg2g4ѹkѱ?N$I%d:=No!a*<9S[ER`'"%wڛy< piѕONG՜Pb6 fW[_ NxGi2Aɞk=ۨo?돦?|Rߥ[` ՝dG4 .A\ zJ?)3 |h\<5f\)ۙޥwNw~y@Og֬G,P!JŹOxaorɔ2w@uu8@W4.i;O;PHL:^ 8X~kgQ2vʭS%(8kWE}- @w?tl17DC0w#Ϋ pC_˻pٗp |q@(OK-?+,D˿R>E]q6d+iz}3Ƿg qq_?n.Vٗ[~ـ7N!ٌD6.a?[c45g}PpsZ/~?/zS+clqZفO# % )ۭ(s7QD_iC 7e?y^0К IKU!RAr$p96Ե B>iRnZ%CQ?\` }1Qy|ch®zҾxzm(61 b;ߖy4TM*.sdV.bxJHTb̗jVosHBDvH?[=Q>2@Q؀UCjD'xjY6P?O\[Mpp 20;%|R^EGN7o=KR. VB,5zo3n7\uҎ}hְ/bwq*M+X#5ٮn+_>r ZcA@+5;9!wk',; Gb%/bQeٱ+FGt&mrnwEŠ#C6tP$? ܦ$ vlξ6詫𻲡fĹ2ҝ20>t-MaMB q1mz{w_t7GminBl%=ʽHc)?uµxvG!}|<=]9GDGDl[uFxUr||OFw j\/l,r̝\> @uar.#tpN@kç>Cp7z@aќgݱNA9܁ť6nȹGӣ6|dYV?6=\Ȁ>y@C  y<xG?_.?Fp똌"+{/^|uѴ}C-u. ٱa1Ψ:[hh/vÏMe ~ԣ/Pⰿ7GQ ZnO mwFQ:,M~;H^Lq0 ""T(w/?ﲠ?[yL"15̃ހ-aD4(ĆMbֈz Y(N3sH}OM1?S{1F(;iʷvDFcUPܟdQћ5}TX9:yp< $6/q 2E/)3}|^h}$xr}Zonݞޏ>pPw÷@6Ԧ^W'ˑxQ} R>ҮfE>nwȦٯs;yqtu^ϯmTX]nO{<$ 3Se1ce5[5w"IV[[Mv v }o*knv6ي}L@r`;v) hB.;CSkS@7mP ()Sʹ1qy϶8(Ҁpmb8||( =jZ y8X6 ي  )Yh pCp ki8 p4 h]'unX%m o:0qnj 8X2zhGHW{NH4/[ '6=$ׯF}u{{[jF\=v=w)+ѓmy}9}}{_{}_m7)]Ӹ(PH ns鞃˄@(B:b>Rb|k[@tbư/w2@8C&ƚYAJ7]v5:+T6@lr}۽6}s\:bx(WsrSUTE跋\˨/jѫ@vg>eT;KbLcӡycݘgР XdwZ4IW׽T/,垧+}bz+nJ:l۷zj'Vho>z2P3;W\s^P=!OntD}AUty=z,٠T z;΃m^Uqtk]2P0:H*lX=v{T(ۼyOI37MppqE{'qm> 4dL@`h@0hmL ɣ)LF@i<2haPi M AM&0b<ēj#zS&S6zQ? W 0zqIC; S5@1 $ki] r|z?Pćo5+~ё鞋N=(2**Y,'vfք? BFһDN~Qs+O(oJUh5XP+f2(IR%U*0Ibl՟+ʻw?>O/:ٺնl>߿s}[[o2uܾx9S"#`V IRㄛsٵb+vpq Z]s,y2??-oV;n@mqT D 58C!+[ VO9aq'C:m߯\%f~Wuў͉LnL Z1U7eB7&Ģ* ֒]ƍL8q2cwW)1M&DhW %pWS>B4 Nhr2DDTM4o}:uG<۠P|cޔ YDeYRE $!j0y*G&GISK AuH"J&!@Q>ө#r_(e,N\3 u1(F|U$9wE%nu 17z+(أh,R1Kخҽ/~DZr-ҍ9^cm-L3"o@mwi./QTU(G5@ZH-D Olr 1`́$Zu;~JǑ{C'G@vJ mPr2,#ܯ4 f|:%xf (,X^ *0Q֭ђ&t`7::w1JplcP7_q5~ Cd@] "H "m@ t{?};#i苢rA=U5nu LWt(fE*X#.;*ʘmɂvVp ޞLmBI@ , \|v `SiexOM5|-%!?R_d'veeQwU9o˞qcVY~|1\%A,?ԭdl*fT?~ lJ_⌹|J*LnaI /yBD%wCR#,^9L1iB1yEoFh5[pO%HgzNq!TG_wfӲslzz]ƧM_{/Tf>SG1qX51ݟ}}wfOΟ̿3K. ͉'Ӯ j<|M6SE` } EqpxF\(?&a, R^PX(B! {+;t<7v:e9j%(j^^`PP>DA )? wTY?8 m_Mwe՜+k Lsf|4hU5es߃ԗQ :X*,ϣ1K/KpBj $Z Q|p^latu"ɶѡ -W [u`gp:$a( *TkOֽe nq,3 ~y/ݟ࿃?x1Oę1B<@8c&L򉩣X1}V( }{pTU4sT^b՝Dke 黓%K#Kqw~sl/Q߯Un}aX@Aq.;P9-y'->[te{7Uz~$F%V5E,ٳ|CECH!(HUP:0K??6.Vrϫn9#FW4X(edݍwrE RHd\bkUA 䶞_ k8uQ͗UfXHv,u+'y$ng <-Tc_̀MA(HJ~8 r9RQ m4UfT Q.ĥn+-b0RKTڗX*`#E51DU)XF#U%mF%63TaGW!aDJ%UR",i3?8yܺav'_NIVw+ázm>tuo}OaJ飗GO}_0H!'{6d;nu]d9By,q2y36& |M<{]z:}!Խ{jf5ciT:9j~AyoU[!};Mz1E$rHI=ۧUHd(E9,]Myuf?vZ fD}ߟS|> *)d B4! k3)2<)r1Mi;xa/@@s&}]T3!&;C&'uM?OmdоO-ǙJM+_!vr1N,yHxw_.:wӍ/S!kv?Isp?=Ͽ_((cZ31e %`QO{Oip9"(QNtaYɭE G)jF v;e%%Lk U@ CJ'6b&E6t=QϟlrkU!*2dV#.sawu+1!%)t]yy]!)G OjԠ2TBP|6p9bV$Ol؅ZHpSPa,G(t|gڢU6i5ص2DAD ynbcAd Hc AB%b 3E,V"$!&frV:OeEU5Si/&, )@45bZn]´2itt+11D8Y&[jAq+v q;8(X6e$<\AG21diKow.&a1+P)>~'}s'dATTU!P*Vc6r=;Hf%dz×}]A. 캓(Q=@!!0#v1I#gMQWCu U$h 5WB:a;_6!;j1^=B$,.kD_@z C*tG;(ʕ}BeHN_&⚊`.µ y4X̛h 2fټ6LdEIBݼ!e\wP( 29ʫ}# ! BB[ۦMViAAbQ/ "J:ҸְdP, ]d)]/l2Z+n)! "aFFM;RH% mLcgԴ 7 VS󯯲M,Mt]YOωmJD( 38!7u6JWǛ"PˊJR`4@@PA:X_y` s)1f$2Ú3ek Q+ܶCEM7B;{ҩ{K䥘K:U3Ъ泀J}eӿvۛ0%2{Gԥs!e3@~L| qS ڜ]`D.9"hXβXyhU!쑞Fۭ(oۑNT؇") 7]hz Ȍn:ͽVw5h҇!5+1jk.#ȂC:^-ok0Vt8qccD}0TCU잋fse[ï{_eEi}Oб6cF}ś!7eI"2( p|c?$ɂ",Byxp?{9Ҩb?- w7_tbX[`%)}/[Nj GZ:1J/́jK/y f;2z~[OVu: ? 11O) Ը,+Q89@*Syo6*rT:=#!TŠ9)KQ|D"F3[[ nA4Y 4q5oORʧۛ>^[LUH5GV9kyE Unޔ#O (~Q1)$#WN_5PJ Y]!~ m߼T~E'(JOxpiI:QaKs~u3弖aB  "McЎ\;8LcKVk_4\̲M/*D /bhWOqz32 HnGVA 661LtZp`xr9_u6 (=W?#@Ց(؞6 )~gcoG ‡V,̅ӆ%ݒ]u%Ā{㹞"xDX{Ӧi$ A 4옐ñĬo=ٺ0%Co|[8M`[M4SNMqӗ4Vʜ5b$ 2 Y{U@I*1 ,P:u㷴^TrrA'<(q$1(l:k0C5xi/Nc~:$Y 9 + 6("Sj|1¸%ᛸFDN& E‚^N_D`5EցFr X& - qF2+<4 `e ]X*mOUj̅oݦȋ )Ѥ(WנC5q jq\r4HX Sr>ת {`?kæT"|>o.x Yax]eUhW\ fzkkk=K=4Sf1": JPqHHQRuk~&傂`. *V 7SI3*1-A=/'{c@lMjV,zX @ $Nb 9 0H*@PtAe2sBҨT))zArg{:խN AaH4;p,Mp~2yo??xx#[Fy;|!.q0=ׇ_ʚ«.ʉ(~1Or٣X딇aշu=Pf:rP/ןQP^4w5 SVQF&f$;'L>ٽ'mPʚBW3Ԍ(շ;gqiBU$ ,:x'W/L SƜy~y'|ZJ5stL%qqZ֨K uǫҷ'}]<,>Dp|T]p`F&/S)x f[㮦= !wN8)eKh`C]3vuOǍ-qRݭژeL-ʅƯt5=<ڽQ΅&Mi, "~Τ>>u($vozp'PBPYHm kL馰Ӽj# e|j%BO<i 7nQFԵB 3 Zw3ըa&N‚7*9HTdi!AdS[uu@|c? { 6~1fWC ' "L^)} .](,DhoX !&"cb5(-@Uh -!ma_cu~_>?CuJ*5xY$a>:;f"SH=r y2tA:o+"A!#<ӧ3gVZcb۟kFhE;9YdwpLbXVZ}aBhmz:<̄x,GΕI?Gdr:Hp fdt>xsa~wo }k1+2泥lt 횰 wrt * n{bZx.Aw˕/4G o( 5uDPjM\Di8Q݃tϴ @GY3D'wf0m48s4 O<\\z|3  M A(6QYNP̗\&p@zΤ8>ީ~DT1alA<'2w;mƈL'A_ܘ }@Cr3`{2y(0q,܍ /j@:2(e`IQ ;!d`1 0_ÓYT uUJ^+Gy"ezcGFk@meW }@Ε,s$QVx1Q I^m?uS !vLIrK vݾ  H_",-/ovZ TX;l84aLBP_ pO4qlmSvnzd3Eϣ ; CPlJvn+̸/B4N3E!mp^WQSҰ'Fh26vȈt4f ۲j;̵N~S0(ڃ72A4@1uKpmaiZƂBm4 ;' Ba*٦p$H-*PG1KLd\//{u }(U ?ggLffb q>^}:tEJrq"((nfD>7a^L{!֣T9)efE-FUKD@qK.#>(%s;_j:,_K!fd1bDAzZԆnsi IJ57Ċ,O9Plh l  )3x u|g~9:s:()0ؐ)<ib)]`$A#VIM((>+0@,tq}&:m {CsԐS yRά- +4fҚb@oSԼ ΅{((`z=ln{Tjok'tr ԕ$dQMJGt9 5Mq7Q> Pp uvz t9ڡ,YbL@oyR7*jo߮.791gGp!@6@% >߻Ec<@ @:}`ZC}P wi!U` )K]:rcnz=! .=OF:g]b &*ॳ Wv7HA1 1ȿQNin0Ij5C_HB93inn`tpPz3ޅ5fRHՄfqNeU (iQP],K%rz~G9_u>g`v7ci^E b$.H6ָЅ;r׶}4u0ʬz^ΰyEڝRx3S^5eu"ס5 lK bslQqTzL"@yat ^vJ ;%<}OG2>˳֙݇V( ,r{iݬN+,i1ĩ}o A^SA{sfvisOaDP5GR廜҉DO27{} yYu˝l9.\I;!P;STP|l !uH8z D'n\Dt؈TN?`TI|D9 O +hJh,(˶-@6* XG5*s<΁hW7i@#yw2'׽ ,4]<^=dA~ϕJ)N&CDD;^~`X BI&;TK1ah.7mo4yV_q (u4'ʬUV +7<:gkƮ3ՙb>%{|+T>qh?b"^$1^]6E ~|KVukգvy8b8n 'Ĭ|ﭠ Ÿ(0V;/١c%YL.{5^ΌBC{e5B'wAFHUȈEuѠE`i ]b!` R_0f*oK>I&S&'D(v|Ln Z[-t7(0'Uhi8DQn*:Cu٥E4coQOrhy&RPuƹ7f Qnkwc8-bPPp0E((4D EjT jpKHշ <8&NQJ60]gx;dFHQ,;`I`g7 >Ok?8q$_a agI6T@wMT 7[cԸSsNCJN4H'^%ڕ03q|: ~v19ZWUh ESއ|W{AZ!7* ךZYY)X}8NqKLbb߁04d䓝l'柆aJ$OݒCjQFµ* A#O{a HlU}<( |-\T(grSPv6ѰE*ɵAk A(C8'/ɒY?gGlƫBVА#v򍜦Jgߏ_-~~qU;x۷Qo8Ҡ*zmsb"%IT##.:8>% HH!a0!XUz`7;tpە99/ȲE:ƹaQ^9˴] jc\I !gp]ҭ6Jtv1Ĥyq{'X\.&a$ @pF,s,nP97!蕐$ ek @J_p,A%@ECpX&9&ؒ z}I{Fp:f.,lR\J>jȆ`TVXWv)!ApzF(h%BA%x4_V 0*N&9"?ᥬ;P@w xHdr xrrT:/5 h. v)ba@9Ѕ#㗢/NE0w#2RWiT([cB&OEA4(h"ejOD/Kd`\|/Ɇ lm 2^~I'QoVIV7qn "+ Q ܶHpK, {Kٳwo"`T4dŘ,*!~iJ?f6s$jKA2Nq1XP K-q\Ry;=,@3FF톤ЗaoݡNiwGR}/aϟ^hP: 7C*uk+q/0:q| {l6&xJb`P M7@ݟk7ދöQUZHK nI?=E*/Ng  0x#l-+$%~bq@Wy>f\4&a{w6zOU*t|^\#  HGi"+_#. tkamhQ5Ww,1Gu~>==ͺ%&ӻQ7v}ݏ6$`7ez8K;(¨iJmu2Ō`,S>r,rQ [,/kL/[ٯKi4 0錤$. V%XjAjr?* uCD>ʓk_/ÄfӴ;O[>mG:Ʊ*fuN#ڪ HC݃ a4K55L֌[Lf6+X!cEƠPjpFڴbV>ЕIny*۪&$T)(=%TC}\P ${m^P耀.G @8IozhMTձPx%@ۛ ߌ d7(}|GAU?wMz"|E0 ݤiMnL  DN(@ xJ9y獻eȘ׳\rhdRdJ (wh j< B^eM@cXPLQъY-@%m^ɣ8&B-lZOY4EEH͸hH,6j ,\8;2j% +yL]lTxPa OT\D uBn6&aX5Q  *FE<>mh/Q Y-uƱ>mdH^!Om#H"p6[ڞF87Tw=nOpIɸ DL-c,vZQ7|8ԩ^lpVzC%Hqvx <NH{B(b+k/AoǮs\Gy(2Zn* 8T]UC3`J%q1ۍ_(jwLcBSnP*)vMtKN/?4 (>D$sq/oV9EL8ƊdvxMn)HƤh:]`% $6o<*ݯM(+Kt{Ǵ=4+C|R$I$F* !WqzݚvL]#i8}!b p'aԎĝzvG-9r@hL > BRY8XJcc;m)6-}< "` A`5;M9_J ZHijiV4iiy>ɬLq L7W!:h%ҕ5HNbaQU`{o[x(#p|>$> [z9yuK@Z2\I|eP)kT\4@ pX 1qӝξ"*+  |:Re 4fi\uG8kcq8.&nLAʝ! n.>d$VP B@\ ]r5Jb2l[y.fmٍ̰e IfUG#L )5 SiS F>, !(d[]` G0nۺ)()&Ԣa_$A!!(lT>c vK.avmpaf'$Ÿ,3|pdpb6qva a1c٬Ar)!1ɎBJ)FF4A ݗg#Hp<t#:P_bmFD ]@CPT#H Wʃ~Q%1!/48Ruv@ y*!@H*Dx{^e@s%*$ l wvumvvuv#΁" F0YfK֐"̺/R1.Mu%Bv+-ܘaww6(dP;⒥H$ `$@IB@`n|ܠ7;fP( 8bXQP )4&E@ HCUrkٯZSs-/CEC0o  qPZj$Sx& AV,08,5)H%TJ2M`FfQ`4 ɺ\3nA+>{>_"Xh!>jTzj1Kc `/ۈt`Q z;P݊`3#"6ܡG u"u9* nJ-D9H`PޙŸ-|^qsRj%r kէfVxsmhP:hI>X~Q - /} nFH@ikٙȣG*3H'} $ $BD% LR$جm-,@p>;=hPktC*~u@HڒIPe}x`E2)0֊@)RUEM L2`;87Ҝ}Dbyu8(p!1D6H%v)ԂS)̰LBb1Yih2c\7n=LԕDYfdd a) 0Sy,qn@8:Տ5) 9!"`0WP(Ď@C!P0&f&xk%P4w?qb(V=y^͍35|1E4]GPIQIkFT6ѫbUDHjlj1A|i*J`ځbAdr\̴mq˂=8sS@Q{0oG7W,͒'sn/lUs^5 |6K$VYj@ SLHDH`>mh0Tp)@Y e3=|N-ʡd؇4(W{C`-͍u!CKH O0smnyx̨2Z klB=:`TfᵮDjJ/ΓL-( d]05Dt6(A)cZDuj E^2"V P> р!w]CBCzuBPF?0;[~PP*`@PPT=_q"P1(҆Pnwc#C ]ox$uաu* BR҅*$T2hR{@W朙URlU@|rJTQ>?ëlE*@CQZ-JhѭQXjb֊TZѭUFb+QVѫF[hV6+QmE4i)H BR55QhkTQ !J *4֨DZm5JJB+H4Уm-"!<^s9rI Liz0y`kfkQE?'GO^z=;wx_w|EWR}n.iM`%4[YbH"Z (w0Hﹾ[ B`"m* &_ Bm d j~ |,M(*h\bi)t9=#^u^)8"&J-,ЛlΝRq()^wZ (ZPӺtM "u}azqqI МbffdԦLڕYh3EY*7 (X.S\8?6 ][E]rbtƜl ɵjӮxT<6I!dm A%D$5w3ny9\+\Q(Rln.`^TAcMI5AMR&ldF*"q3P 369eݯH(X։hK0ʫݵVZ$IPϞn%0np:*A'pq !uױ48K1?{nNoUB%IuҹS  P[ݮX. t'>1tҒJB1D1iək๶yQTTeWлbzzo;qW'X(æ Pt$ (dF[l @E`)ħr'>4<;o߷mD(905 |#BUc2,CfNy:da6BCF-׫* ־U]%J0[m_3ktئbmMBV$9FF:j:dJ١ѓ"rFg T&+nck<۠plT>e  {iH2$Y2V1Wՠ_'IB@JL&_|eAtzq`+nɣL;"2Y25[~k @0y?ELl6d3'[1{p>$pԕ7mC!\eV料{nVg{K4B [LWK[ T<S&*?(|Na`2z6_ezRE xPg[BV+0Vb킈YYiia ؒf8?ؾ/^e*/ ٙ8ċFb۲h! {`MmeI >OchpjJ$@WB>{Xz sszOiA2!ޞvL7">N/'*I!πBXXՍmFhضڍlF)EEElmآ֍Fm 4- 4ҍmEQmPU[b-cIj#[EVbŵF-A-P%*(P-Pjض[XmR+=/?P~ s ߓھG凧$S?u =#!s(d %.v .ϗ`=8; AGm =LvЦLJ1415mi;nLM Ok8AL:xg)v RF! TBUҮ|m(>'zϗkĈ 1c%7n먼ƫaxo#oaX]zt b<ЊUT3TfЇITe<*FRG~,jvod  LR,}5|Q;InO۽O{j2-ac'>'NrvUхwIwYm-=Hi 2ގ9szR:;gq:{΅ 3'l WDUT4%_J1r~}3ZIk(REFc(KC2D1e~LZVE~n e=V-mSxydd} tȦ{6!(ųX-d3c"YFMS I&c2Jd m,&1lfildM6)d,Um@Z j RR*MfŤԛd!"Ie&h4dal%D$&$"C%` ,h"M3FSXb"DѢ!ɢʼn4Pe3 X$TlWw C)e,h4FFdF bhhAEc2RiBD1Q@k "L0!Ѡc@cZHJ2L! I6J$JM Lh!`I0bMb5EdRII$FCFLbJfB3(`ر-BX 16-[1)*"(E<<^%9:G6ۦ [`ɝCb5Ƚ&6\|Ƿ*Sk>fKs3!(ċOh{OHw֫5_v*HM"Xc@Uڭoߚ" N)OͿo*8@dlAs{,X?YU/< v;HM T E%-R5PCS.?pGͳAE<?@^7)tg;hJPe0hF+1(MQZ6XF#I1QE*dQLV*1RZՋEYԲl$RZdb2 $JѨ*LKX"+$C6Zj1,̓iB)E#3!#"؍cj4,ъJf6-L Y2HX0lePjƩ6#TE$I5E&(ȥ,RlUR(1#Sb*20E) b,mPH d&25FSFJHe$6cJ5QhA Pff#ED$f$Yjc+&5b5bƱA"DD0@`dA3f"((6cFb0(SE F 2A CeDc V($`YVvNɀ"sL(`cQֆ01<J:{qx~m` -xϤ;jPZqzIE#AMA%:_q1EB )0wx>MPo.Ao|.n玅p8 s$񏁜Jei:D>}JF&m5m2`5MTԵFd)4,Lwwvr@a RߎKZFml4ZgmǪ>MG\Lk4c ol"aQ`ֈ#1‚n{)7>t3IZr9heJBbڭ)0*Šk\LS;V:A_~cZP("=!Gxm ep 3Lj )vVxՠk\wo!!x?ʢĚo}M*cJ٩1M=ִ.гE@'m)X+/>3rQ[t:UUT.x*<ЩxQbÚʙ)# ¸!#8 44߽,;ҕpw3N'`^1ˀz|?aaD %r)de5ް:bpcSqQ={Q-2k5.lrb 1M= kI1%$tQ$wsscƸcTTRdnil+76Il)Jk(ش+CMZ\&ZšU.0J֝$QRm[Y,DڪEie92ZgD£Kjۈxd̦N]iV[@V"2EHP,%X`1k@ -JE*RX6˭Ka])`K hʃ]r &""+l uyWqg9{sjԹUYj emѪ0m-j)Du5k 6`ɵ5=M~v|3y粢`*8]Kscv`ksw$PVIC}3`NJ>pЧmBcY(V.Bh5-2Ds^MeV)iGX\#َ Ck563K C9#`h*tB`fNL!jtaq3" okoyַ@7HI| N-IPV%P@<0|OiGkZ'xsp?bKMa66eEbJc%0TjT&$ho* TRDj9]fr_mpT|IWS(䎠{X(Dy\'0ޡ̕N4UO1q0%VVIV(@)ZBU:R*Rg/T7"/LԉֵBـh92BM` &H_ȁU(ֿ٘.ɮUbj EjVڟ 4_phqYkŘ6ndVjbÁ >aqJZ(iJr?um<aJьWҜ+?\ﻬ}g?z0 3&`5 U?^CǺHC*_vE 9& k $čBQ  Rž?Ws !PP^j)!DV(O:o"J5~H0@D|?-iDF?p7y @=a=QvҪr=ZQU%kPDx` *UO{ CÊ-myՋ (b6@{6b$+XPyL d&f@FXBȤ T2(@ԀPA4HV:,,F<?>/׃tz]+S>MAqbJFQԩ3zYbkߚk@Дqn3$]`^)f!nY ɱ`kV$nzdR^; )4ͤب6Dch5Z|"ɘjl08HTDؔ9sl$P_5/ɴ*;(Egޥ[!me3RS1-j\Rah[VBRj$g4j7 >G* UiTrS$lD  Ԣg+Sh|Bp 0QP &@ M@pJbvPtfЉUѸ'ZHIL1AEEFs'n_C\VNÆI3yޤ2wS8/I.jChMP)sr o֔aj+6ҶʭmݴQNee-BULԚS+u-(ޒA-}р^7C)& h6I3š&RnrZKs7㑠7+&$^N~=Lʜ9 3) f:!3!<`X* -lmIhc6X5FţIfhšE&34mI&m!(Q-HҢP*rAd!RR'ʔcAT.$I;I ZQNb!4X:ƅ4w}. RúvJ,Y8CAE*ɠ"1-%)(FUj[̴IU2%!dmEKblMJV*M1L[dɭTM-&[dԚ(VJQ[j-ԦKmF(ҢLfěRXj.TQTEJMG0t\D;) 'V3_4xj S0DR,9k()ɒ,X[`SBU5Bv֒@#WwkHE[=xWcIllʶ`TJk\j.]v50Z-T{N`6,EeES\Mu\Ѷ [I, Rn¹CpPv(u\H(Ua" E;t '3p)HN1چMvZdd4Hq̇^M|I(HaOZS%e&`QPX5F:\ (bBx;LE[ƕJPzɍI9IeUPcXC-Z(%^:]0=X)}g||t;XIfg':0 J#ɻQK!PgĨ5̕LrX")DD Ld30RIRC;I̗Y[P Lm*2f0 i_% $”LtqJŲrE yj؊i!օi ÒKASʂrIRZOvL יKCk=XfAœ& "4;u dgzQz].W4k2NIEљ9DVޙQDk-FG*g<"uY#Aͬ+HUE )C'#!P D2(3v7 B9VUjܢɽ^#Km%-Fеj1B2g 0P;֣RRWٙYXx<õ%0QAa֊y:Zu*tY(,=R?};+˕rͭ͊sĴ[M]19쥺-f@@d0 9@9T]8qix$8re 5J6kXPոH6@w<wpb0$䑊0m0t>Є$Ɗ+a@'濓MbQ5۶qbX[&(^)!ƭ&Փu!$RH!JJb&O@\w7@ ,/RʔIBebQ q hŐ?u^ Ҡ7 Fػ8:] Tŭn,!.Hm€Tgup0'OF0(' w8b':"Y!d6mA4jʡl$iZ(_.MRQlZUm`ujm}V7}qLwƭj)kC)' lRL)ȇXju"TT '$4tdC̓vr'|jre|,A2J2#; kS!`X<FbU&  bB^6@QDd!>F }ȰB`j$h!bS2m\%Kb٣I[dٌ&J-&UD6ƍ2lmTZfITZBR6M*YDf@|B ),D @ "$#""<`'N|y{ T4|2nA,A[ݓt ;C9Ru9洭`vF 1d*7/pbܧ^cXUڐXLzkOVȸjCP%Fi0hv! Y|o*"Ӱ.QH(ZR 핁Ȅ-i rLA"22"2m 9PAf㑑MFp]sb镋3 бiURQ* +PLA=]E7 %=@lqpDžjxV?T_u\ ֿmy\\|~{o//[#vч( oֻWZ-bЄ%0WUNkVvnյ%!0?)lBl;?OK* $ZM8/1fӆ *wn! junܯT FnvIXLZ-`tn  ]Bk^rkrǟ8;Q3%LW8(PybT)1  M2=i)3άa2lѤB@Wk ` rpo 5BjZBRҀ&ص_ֱQpdXAbӢj'P3s[g@aΧcgQ `u+u> BNN8mc|#ߖrGGm£w]z0V>6tdVǍWɝ%Ǟ|RM P)eGWǧː(vQ)ٹ樋6vj.r7~t]p"/R Ez^wMC~NBUӢJ!(4< YX[ȌHg"&{j ¡#ظ:7xrcnB7PpZ Q~F _D7D*D@L!ieѿ OuN?mt*9.m  C9"UX+ eyP(`(YREСB(\&RV>\%gagW裍1sCݻW8ŴmMtrMwx=W%_ A_|)'h?@?*!((DW`@SQ6TOhE$`w*Ο%@@/@A:# #Bˆ]C-%`A*ǿSB2#utm >cdC Z;neGX# OO3164G싀b"!=_}VF$C~=6վ/ݧ($&jD̪E?<. ja~ϺP^=|SJvC}OX?+׎g 72{7|ܮ:qRSVcA20UDJT]DD RvH;zH$@@ibY<(}V A˝Wc(SlP8G@B(d@%j8{]Ls~tw!V օ~ *)@*. G=[ !xd ?b~?C բ&?Vj"M?WM$ҨR$ a;CY"q.D#DwQg) BR|>D|]˾ Su9 ju]Y]3]ڎSyv%Hbng҄N(l \Hp?!B Hj@}jcQM>l~pPf7^A<_0I&P܌ȇp߲D : Lˤ fZRFdJ I)#(!C!au_Hƴ 263YAyQ Ŀ}WvS-{0Ɂbpo{D?{汃R yˤ3-^61bY}.[p~o8/3sG vH;K`"v?wox65LHߨ@R=w ;{;[˖"|ᾮ~*w~{>–נX__o/< X"~" t$}L?۔>fm齆E>zy8;Q%@׵w'c=8WK!b~@ e)4r^dPO]~SD>qNɟ߉|k|pA 8gj*+ة{)#^ˋ |E`ARլܩ ݜpiK{mE+XE"+b6q 3$b(H(Š@!U=d ( n%O L#>{^sDTK` #*s>!Ǭ2; NӕDATڜiF4Ho8(Z&4S nxz/Jģr.gk&q հY ZuZy'ny^_Stwx0?HNOm2R(I{o?GH@ P ~X>:嫜.B_wjBIUĺJQRInvdve;9ԊQfL5!1)$52ˮ4bM !}M*9``TT/QbAV#݌u(w]D5S0jk}EKBvI Ujl}fWuo<,+qJ%T߈WG@tgmyHG q_D],q[GP&pNjapchVQ&g"=iN={ X0gK5&?O?2UJ ݏ!yp i,_c($!>3Yal`:6':1FاAS&ݫBq€K?;~9~/ BO ͙ $Ń"iS R$=_ Esd?ܘayvBBά[Goc=t5C@ٝSٶNy){i\ E bpL‹RW*yU!?~kx _968bLT#<~z'"҂o͂wbi"lG;Sf=q <f4(^2 LbJ1S4u^(vdZ29#"yԨeug?.Fa+!Wy?Wr&*.kQ5ۢlBS{gOWksH$Sd'{=<}kue0d 5,Mn1wϿa+lqk-B)>pcu{C$F"3 EC(K:'TDg _x %@4Vo/ 鳇/=.%~ 5 Q\[q"i0j(?98{̳Vx}(wkC9'߾oƁ-D fg.o_oQ0g8) (?N$#nMX,7k@=wc oF_[4l>fJ߰oCn4'ʽ{[./w4="9@'kb(ϋT?4%(į|nn^<,_o'`3`JTX[ kK'lxqlچ_%S WT~K1/S#Cx%u~;z8",YFfv^k[}%;po"agq1le>'WR)Z6':ϋtD8V_\.Bbg[҃GTG=* Qz#Y=Et[u0Ӎ6ĩ[QiJzaXˍ8jZݗ\yձω/^V?鬌mua|9sylª6Ă!BOɃe5]|zj5y4? 0W7Qk..=y_^vT JO&:9LfљTOXÜLx m@p~y0wcª[ |_)N+¶~}fuh<N|w@Inj`,ָb q,Ā0@#ԐE&Ūr"(PD$5NV+6$'V=E:d \hH l[5VR U[[7*̐z2QѾ 3i)ȅBK0xPV!b0!ãAmz&:ݟsM!R+we>!6/![g/)͊M} ) ^<^2^oD 3S_W>~mzraeף,]Y6 +H^Ol.|uw[eϛwu|+6ͻu۷M~ggG~MמF8cӫlk rӋ۳eE=׽TqsEZʇ?ŗ{U_3F7g;^{}&@6po^0 3[5{^^*=&.m&wr$nr*O07[GM2.kC%t'"Ơ 駥ގ`g|87XXlc!ӱt>;{XI*.2339Q"GXOvҿ;R 6gE`5g`67Mb(q32ZP ^˺q,tp%A BS8ΏW@(PёB%D^v(ڋS]3ޣvϳz:\um$ِೆUft_͖vGۀY-y)!lH'VI %9'%?6~r4\9<~-;F[~+JK[oPmo l>^ܺ<ɾjۯ=j诚}u^)eLeS'աj;R~w9o̳ipI~%;Z}>{BQ }OͲ0a 6:H9zoz3e [{VXuH^z{"zlzuG0Q%G=d,LG'D4i9OlExgIBmwm(ff~_$9ӹ8]WiRIm*]vy%Oh rJ=*9=qm/v) ƍ`(a)uc ^܆dp; n=C$]ps ̗-w{%e_8>Cr8fHjl榜^_oj`|l1#Qh$1F7B}ܢ(_._B} L?v%W߶Hep\KB!H[8tK~ ~̬Ķ-ۆ&2YRQm2'REԨ-pq?V_ufGx߲\N\JI@:(@P4{:쉪<IY,c;S@ǂ(X ύwns'H~%>o:aTZ  2rXajox:kÈ6ޕ_LB1"MD@PAGEWP(@m4꽆He}p l&5kN'>Լ^jC8"⠬!2w ^TOBD7* t ynJg#J\.g؞Ȉ%URHݥTO8w/Yxbذ}_k/x>&7sё_[n(DOp %#!>Zwx&BD$bSҡ`kCi&+?B DG^ ?DFi!Fc!sd(xc [(z.(쳊Sɣ<+qy%'ZWfI7[b1Y,sU=T)}<"J۶6Gx<ÑY!&: Y eAhR,(X!?[r 801N8$$I` m$5.M -6%,Z.ZDCD5 bCf9dS2:>NFP_ƅ"! Ӏ$N^/:R^9|B6`TCy K[=i 빥nQmkδuI VO%JO8@:QB}$j O^@n+@С6OP~Jśve59":A'Vth^aa*(QѠ!U|5?6l>PY(UM:u| _ gϒ>O,N9`DTt8E}Qf!pyy'XXcW+%G D򃊪8&(B (9B\<7|Kˋ:/>h1pSB%QUr4?Ӓ y7?b5Ffzr¨R"} Ux >>,z~GlQ!O)F'xҊ!Qy 8MfĐYV9%4A'UAC2!P[*:?;5,;1d&oz>Y봠rP\=xyA}1UʮV{LPQ+׮.&U:p@Gkgt B'0qJ A1l7 7yQτ.%ǽ/w8.zHSt/|[|a[οu1J'S}]"@ZQ8%'?Gg&1oJ:XVcst+X?m:o>'q,s~D:E&`ݳc~﵁?ˇ-Ww~8>@^=z\ rj3>H*__;YD* p\:Jz(8So:aP\v ̴퐿<uy((C5CDI&HEXB ZEDvqLr.u2|KB`tM`._ >~b鼵Ѯ"H^ EN*/i־k9>^;:4I%׾tc2 @|. flDawJBg!XS2#;M/*F,InTۏuA  CjXRP{>ߞ_8KVJ; ,Ft-*'>x)#N" ^L˖F~k Ȁa XO/8dLhXiti j]Փ%JE7 Q# bVCsI4ۓ{X }1{g8C @I5#;ME f}@ yc\,ݫ&cd ;n8)M`H4gz&@"yp|VPd ߋBP\Z_9s<+õ2OpNI$ǿҲpL/65J61!F ]O'7z3"Îϻ4 MqRqE`A@( &b Φ+ TTZmhNgydfr-9$d6)PAJ|=`S8AP$! 5ѵ )!&׫P).z#%WM,RY&p5mtI(z"LYx\=|U$&FHÏ,%;\)N9tu~=m6=sHFLB%a@IN4A տ#S$yR4뼂dF8T$So՗!U9!P>\'Z8r! PBNj6SaQx5I"Ds+{Yvs Wyy28U:rqI!]lD^S 8!9',w]j p|_;ZF;b 82=b*jXLe*q*;ŷMQ%q00ls W\IyxS#a&ʣBW2Y|ГqY(9KjPf.vWȃ'a"QK56w:%24D( PV :EV#ZZ?7$!hS5KcsFm^2EDnEȗyNreD[=mh࣎*3@Ӹn&:cT&e[ #@'IdFE;+as䘥ؽ.iy# ߆126bT{v0$+K:fN`LRpd. ;#< 5j5MU87ܼ,@hĠnW+0pbnQs- C ^j Ú0J/7M<) nnƙ@9i@U8mP]5@N ȌJڡ#g4Q@,TNb1 pMapfi‘pܺ衦:fE(@WtX8RT~z\-X.+`8\ɘּj0&~AIāT!sop ȡ 0yL,RPأ{8̏?]Sc2JV6u X}4<Xz;\ihO-LbOb{H}+$UH0:ᷱ n2L*O('$1 XpnO"g"0!LQ>LJ{髻ΙkS`\:@)?SIaa `$p-Z:٤&.@m%^FN%-H5YN4Tny~Z$ӤKi ?%UB "]l ͧ֡XQ uY JzQƣ8jY(C@ U5㗆 'Ob{;n׾Ti P4J7y1nVoBA Zo=yRI@|jluf 䤔1[pgMp1.y"\(eNjr`hZؼE2IYʓj+"*aEQQ`\YLᜬGau%;Nj-9 ^ QĴQJol$K>Xr(z\* AFBW=yi2j,i)r1s D`R,RV JŌgkϟii:UB JXADdȵ`͉yN]rt#*lp7; <rS02^҉TB ?j15D&Ij-ʇT$V_ o*M|5aJtu۝{e} FT %YL@S_5b U*a%+<RBS;:r|9q*AFTJd%10h ]˟Ř~g~]}3 Ko\F7&H%sK.3'|JtDbĆtܫp"^ٷ0HdX7`(? 㗆,69!묩e]<3\^0R.gЛB]Q3c~]+Q Tաn ה mgXq7J;_ϲuxgc?+zCcpɭDAA*V-2.{@kSwlygCm1'7czgKgϘY{LhbOB ngL=5r x'e/ِ >ۃ6BL=iW!聭9"׻D;Uz:6~{@Y{7hOBj=(+suah|2"$dyTݭC/7 B djv$&*w "Z$C,:2vEG&!^odI~Jn>+05绝a{*9 / f0S*)Ó\|OO|!ـxJi$k zGUkXpQ<=\I]7)IVU}+S@էD.uDLQ9\0VrcLo6&Fe 淒ԩ.&0[sa?Bp) (YJȔ Fc@( k+(VQήs{ZbMi)uh :Rgِ;$Vm;}3*^BfP0(T* -va:T% s3nsd^s3oP8#|mHNӎ73 ('&0/,F SqnHcOZ pKhE {scIBqos"::aW⼀ͦT E#u]Ew!Cl{nyQSqCY# DRp"ud"K&ܾ"!Vەf;M:u BHHæG8=\ :Ӻr\n|7yD.@H8sB8krkWRK,sn9_U >.w3 Jg_C"1A VǨxtÝQ!LgssE7Z^J jqЀ^9 %Qf.N  {7+Q }CBW(NEc{ݾ3ȪpѬ4D08UŌ9P>BrxRDRL+Aθ+UEK@Du2ևugc-S)(D(q -¬D!|[c`6.dk3A6?QCa]h?AV jP q$b#ۇ͖Q^_=K?;P-:lTcХkAq\B, uP P@'K_ׅYܒ1ķ bZM(2_ )+ASW7@zhim6h`gj<Ka67F!9߾蜗ˏ)TZ:FŰ*h%hT) R|A{ Y Y i[rbDΖf O Ї k &S%ז꼁CD%¡,|AyϑB!Us"^kioZ@AIZzR`U EA/E!MDOPvy{6HZ3 T tсܷ(Ħ!-HdsUTLM$j3rQS9vWrՁ:YF:m.sK7WFMf 0(L2ą/:3ewyLwlJS9AUGLb!ESC@, j2z9Q̈igrN)G$zx ʒkr(}Uۅ=ɲ:}@NKxZb `FԵ_]U6`E*3KfzV6X ={.J] .~3!Q2` K$"pSk#\)jȬR R;-\pus!Ж^bCɓ%fNJ,H X5L(}ك9p1T8D.YUZN L@=O6uuR{hsȓD8 0B2`My<;7(Hm0/ zc pH:RMt~u$a̐qy9xy.ë'P`@< x{[3d/3GSGn18/pK"BKs%+ 3"j7TD|v.>xW ^CJf%*ć,>$K׺Xߢx`#9gy0/kJZRwx 6Y,7{G$De|[~zY.r>Sq~TOF9&4s|'u'~br L{JjosP;_9(w(]j#Q}f >:(] C3s=d]7Ub!Mh ,D 7E&jlҝ^.7ͺY޷Մ1@>/aThA\5 ]­|, LErwD'ΔPK5c_fqV>}w$ Ɩt!+cȗ S}]1Ͱav) ^z-2kIqY(P%QT[f0@pNsd>SYPE D@;]NY@ u[_]z x! 6I#km[ (uhՈP p#!Qil, b86)R|60$ IњxPD#ffø+\ ÎxHAV|VfB`]" Pb7P5d x pVe@I;<Vum9u8ר2!ÙC 4={PcPE8c괓D t ӭ#z "R@̨bkHSdž_<dY []9_*l Mq[Ƶmz+̶{9BQqHsd`Ph;7pdU~ܛGqĝ1'wsȸ,m4A{N&asm;\FR"MBcrU]g]6vh$"E۾BH*H3N0J;,Ģ /E.7a#*)gƄHC&v|rd Ր ; 40$q u.7*HP,֒(d}d+$<Ȋaowt;t!$GT ^)*XFYYY3&NZXjZ&˄8NL%ЀTN0hyz(av 0 3^D UR!=2A׽@KfFb|M STR+f]>_gfJNTSrN/khaXA3 ~=g=VE'xCyO6|d0zSδ)_+=LҀ#Z4ֲF$.A- F"Xy;/`ӢJZŦ쥼n8v"Ԕ"I 2A>̡$TC w2m.ȔjҺd4~f3w6!D,vk/AN;۝ݡ'p`ylu9#gfw4"-mz!t!]ƴq.ZD6J 3"6e$0r>:sl |m9l6 E+":ruRB2 HTP((ZiVM[AƔ[@x0_CVB PAdǦREԨVAY! QS6B=d!Ŝs2h3(#C(&Ao 4(DU&:P?}4mDd5}JE*KFBf7,4aRgP8 ]pCO>;@;nП8uȽ\{>VUtZ 9jRzyT+)nk i>o'=:I45ʇݵT"2nh2—Աٛ1Ny/DUil D>6WS3.j!eaQ!wu}g4%mKSGGkO諟 o]U<%;FYӂ$QFLEָg9H7Nl- *(L-qܢhԣ\|+c؍YmM=Q+.Mn=a %c[JZ+?ₔJa/*gzkuߧ]%ώU;Aq+ ЎϵUkJAƟ/k7uGYh+Ρk>FM-ݤ eCWzf85@򯁮1X-S1D]03pXx5m Iq1<֗ab?I:q/Gyh?S ^ hٺV{lfcS6a1ApOKaK2a O01i?"t,P@Lg$%^},I"ӽo1/D?]yx$@Q|O&W{'C\&xK>>$C k1ccĮpy):W|z΍@p) hcDBl; f T/^)ʋzi m}&jG4\>aX9SC@YY}xHWڀZ*SD{i`UdBu8Urq QTc-8=!窈`X'ʌ0`*Y.^*!A01X?`;T\s$' E=O'|lZАĺMLa$r_4x j c2ya2ASdxCD=b:hPw@^(@73o5u>JI&ctmp)svU9Y pn:V$8INZޭ7VCc vNS!zp]mD%_է4tcAВ@wo \i/!GծP06l 7C,y8Xʟ %2 {ar.z*~ɯPuD]O}|/j/9w_IqaۅHC Rؓ#v ?Mxj '?>ūasP-x+4Zuް 7a7/_ڊv2Mu/??c1fT{*풁s&@ Aʩj]ᝤ18G5EPL|O V1݂kq'>c3U驞/hZ$sSKq鼄&GdFQ'Knٍ*=ðd w6jPRcM K<|._V'rEX5.=Qό}$w;Za@mqQ2IÆUC!ƭ?+}X0ܫg MoS8sSRplN0"9ԏqig|=s|TV&%[MUȟKh͋iasLJA*2n"|XN] Z@BtDjʴG*NPNH"yPe-eG 21$'S$lb f#j{0kpA-bl%aW_m%2@PFyf U|kB/o=[fID_^d NG;"+9&ޯ_Rx;'~iDG~/9-{n91I8AqUxxbFc(FW+eA-Gzxq{)l*/^-SPxA0ZmAk 0$btCPS?4M+em|7+.ذؓj /c5zÈ-Wi~fA]gZ% CU-sb-/Uh,K,>u)BśmQuxp_d<-=-jѩ I9ׅ.!I2.eGÆ  !# S`dLOMR:Aqfz cC A_=M'U(e&qL1j%C܏X;BBǙ3iЫS<ѹׂ j eĂZ?x*gԞ3ߗsْW'.cV^38 ;TV72ҲI`еQAsJq:EDB.NVnoƛAGa*0ѼV× XiJs2QR[QZE6 5[Reo$)KZHF|/ɬ ^=JSsaQgn MJ"3Ǹ+W` ȤW_ͿWUj!;S#\@CaUik̳s >k)rjz31r"M0WUj\˄zuj' ;#=rJrT@>GI OEFbN8ejEXK61a7:gm~QsMp: ,2M]C9[[!x?mY]niyD'A#\3.*Fؕf>T'(Ck zYtJ"]5 =\ ?̟Ka\/$Xj;CF/gu>h wȵ5M/S.S\(KUAi(HoBqvkcʒ^  iVGjټ kj w=z#RʋU"Ǭb®7r/CZ{R) Vjʱ'\VYV=Z _VJ Y pNPg5 ]dS ByPFI}~mrjәST3`E7Z )|%p&h<ꐯ4[e}J dR6؛KX|uQLUwFQ~$@D ͸@HT"cihʦ-dr "bx\~dҹ3 2l6vbfS(" EЯ ?|fo[&)FrdSϺlCk=(0 : D(U|@fCU ` o )T$ESUʄ5{}OrLo4gJ}HkdE<_r@40ʳ"E53 NG˩jسPӅyc9}h=MnKt}X%}y`/$.5 :)DQ&Zugc~ъ봻Ԇ]@3 427UwȎAo O//rLgz[\nT{ĥ'G.081 D5re:Y1(=TG>dWxh<։ d.~s(,Oȉ*{KcJC>ֽ/_$ ^-{o ܌}>P'_&^<;Uqy/qA얷bos8p`sXFQg;c{?<<'gdGhH 4:?X 5kH.?6i٬0f4jK;^ øf2 TߘqT.#=|(]hepv܄TGဉ6f=7jPBxjK1g2M H7#Gd_"o YaF9VN\AQ=9m&}P(LX}l?lXn/a^4e.'&0]AA=ޯ#2;C~=zӍ#UU(&F9uIx?G/9֕Ϗ?JDgIho!QM$^pL߆Kyp02㙑E x iĞrvJŴ8at;f*Ş_~ڻ<;j-` wjԇ֕4]8e'(j|LP#WY5&WbG7=y2ѯ 2gOR *UpLߡhT7,R{G&.}ќsf`യCCh`ծŽզ\_zޫ[_^d]sFY֏r*e?WUT#ޟky^1/^'8a|r\ֻ`;ob7/2dD;.9n=-{Y-ޚ`DEN# B0~)Fc犣nCG|nhc#Oʘ1Ns)MiVͩwfn7OS1sV'FA)U X(4)B<r08Ңc,s#M'ڨZ7Q'ROdQ05B>Pe(;ʽ1i˳zE'2x.rʐWKCK$nTr3K!wIˡ[H9KS]9Ѻ!0J2nj0͈>e@L{x RA yx-͝i;1ּ;A9pku4 ±e"1s3Y<exvȍ -S֫ U&[jt|YaWӹ|K.P'1}j`K!Jw"E_ JO(Bp@NzMXe)OWb"-g;) ^N(R :0U4(ۄ,4jkVmygK|ގ !AUI<^H" tz$./s*Rn.6.`; kuzI,M=YxK"}' ,SwdmjՅ<*aMa0rWv[Wv!ݫh)29-G(~)Wx fPeY͢/+ƾ..?Q7K*ANBreGwun&0\$ҙYͭ^.;Gt&qb~w:$zVj4#'Z°Beы&d8\UĊC8hO38x ^n675mB`KY6|.L-SSaA;(k׈4OjQT=apzՅ@XB *@Wh 9$+KJJ#uQ7|՜VO$`q`>'0n[}jI_o6۲7g>  Gh(+ ~ )!'$>;:RKb!<$ i'2p9IzuxNYe4H]4-ZW<7 7m%(哂 7iTErD~jSQZp1b4u!:3d 9Qkgyң̀~M =#e!xX 3Nwp9E.V6>_|&y`}m&ۂ7iպ-2VUH0s_@]Bv.}i.㩻ծ;ZQK`X'tpA_iw;qn|'3Ɩ_WC(*k$:7)e=/P'cʌ!i9guj{gI0QJ) TާGVF*̙HMpY5XVp œ7KXAy}5@Hŷ/S3>l\M9?\-YDy'$>=i*A/R#3`,';𝒗g2e{0igŒ0tZe\=y^)WcG'nPl+0|KAx/Fviy9835S4[X=Pq)0FFmFmE`iG Uk=KU% 0oLo 花Px~wq\!+շQG$S;!J.'"t;:^sTtrO pN%! ? 08mY>U&RIG0|U?V0-7Zw,W|;խ=K].&VrSa\4EQ%r4†b_A_}049=?FSԑ3;cguwεLgL̝Zθ\{Yv'07 OщVlC( IvKJLbv-(5ѩ' za_A9.*r!'R`l/JzkK] CQ>WaV5?$7r8'9В*7*:,K\ٖİ0l@ҩ8 8($L:tc5HrO86 %-U+={xM(Km5 '"vTl*PdCsVߑ O#0嬵ĥ %kҼzЦ,9 =yP&9hVyWA^ʹU,U0>Uo)8ye{oS-E (z"ș~{ ":4y*`fn+D:vAãr6~rH9 ۀRܠ*̦>H/:vQi$Wۛ*ogۚ0ey#d8!>e$̘ Th[uY,4iBϓ2+tĸ%yzMXf ?Ξѵ;9-b.:7 R8 Zz t7lQCQ t0Y^U^Hۋy .V!w\` 7RDﶉQ !< ,vZ97ǻ ukv?ޠ NӼ(8<ԑ,>D+_<=\>Ê 6WGUe=b9)#+A<}\e([OJS2U`F/VS= ƌ20ܤ˂Q7Tu$11mO3)e;5!bk^8C6$5;zK [y#6J`L}pT$]rS;S8V[klk#sɹ.9 A\r5R[b_*dpBblQ5_MfȨXL~{)֪v3]sȒ0=b6J&ENpjP:WJrXA7nkƟ3u`W`Z@+'3" mja?xY2C/+LZ; m"TVqrWm!ok5Z͘uOkFXk\6JSn8})TmQ$1RZwvI/WuKc(ᔪ_V6MV**da0k>P6(`"ZsB\L'*g5Y'h̓]>sV;9 pȄDu0f}s^oABGO)}`['.L#hn~Wk&~ UқZ\ë!Y]YݘӋhV0%EZ)e[ 7#`AaLr6HMkzAn< Ψ/zˢ z}-DMe!ubbjViFe ۙVotbE;mcX4`Yx!Rm<iM~0K(_^PYjAsuԻdN;ϱA<ֆ?2p"Q[y@,qy[8~/Y-0=o#Dn`V$X(k'm|9 j">~ lCZ KشrPvg.|0VSQTqa]vo@0Xōq U"F/ճI7+ Fl8(6n~?ֳ@:>Llpd8L 06MBHdZqfrv `|o\; 5RIy(Ԙ!y:#s@ޗeAӴ f 9 }y AVIo{N-d [HWV(9p>wK_X:iQ.-J/xEMɟ̚篙Xc:(nmL}h. qdsX3>gT`GNbUznq01izM|0IF99:DNŒ'9X` ~Bė=pF (zQB תc6b,ȮIZ;U8$!C^?QvX6Q 8yfQHR.YX#i_k&6;TZSvN͕Ybz'<ѣŠr_hxHj zyWmHSՍ|::Qnfи)+o|Wo_`. l+Rk{ucq 'pf6N?+RI歍x*K $y&H':9H*dCwY3/.x?e% I6 {1q߉at(B)Y5rqu[(^܊&I.)8g'<09J;QY ͤcpھM Y)UlOW\('Jd1*6 M0C2<,‡%RPҿ[T]oI%CMa#,q1H)ܱ"z>.f`SbsnpL)ȱIT|tݢh\kEȲǂ`qiЬ-i%ǩ6ٿ(ՄAp8MyDQu:]{HnjB[J]aZyÏc\ y/uU39Xn4jgBŻNe&H"BBVH-)%D1UN\թ>|{SHBŖX=+VL(U ΒNHr#[&1Vjo0´j#WO7ߠT^h@k$Y 4(N=zGQxM*)?>[)d 5F޾J(1s-h2 λ0C%9}-0IA,jfM1iThel?Bժid#Pl .'~][E8!qOIюC3?1/űN8Ãee1@R`S @O_X$!R8 8>HB%;saŅ",l=kPyXZ&V7}zZU- ڥ[): zM~ /c^4pfңu}\%`ˡ\tΩEmRW Z';v$ǽ#RTBo%ش<Lň n*lR,CIɪ23t/R?/:MW˩>Zk`$rW׵c=O*F.Lإ/yt\L5kK{`ĆW݌}4`Q*q5 ΞyΕ"/[W T:րȟf4@i7Ƥ;''N~Or͌~)L;o LQ!QʓCFzݎıd`pxӂpU6kEdװ; tqgz ka5C( K?K'x C*[Rܵ|iKnQ~Y#4-fB}8|_5Fq'ԛ(r|%y!xFو~POvZ]ѫ}2ջ/szL¯W 暭ÈQֱ 6Ž 3\2'Q 먻ǡ/vC1WT]sd[IKSMg*qTtrG`7m*մ&b?xJ5;[dxb2>HI }SC Pʆ(A$1 -GOw * K?mVnqR{iK]w&UvI8yZA msky5R XtGhZK\5ҟS$]b"Bk4ژOyn~}jR_g*wKP$U'Wq!luP&#`|J[CCdVԓ?f||h7^8^ŨmUpvwBٖEb$b4Vwi7&Ϝх*-aR9oo`#-# "P :{~(su9 O$]E[V+A-C]"-dpRǧHOc(dɣMJ|MPNwRȂ>NA/ikaFȬdr5K8rA!D85u[*SXOmS{XCgIJOCX|@%B[]uӨΙEXvM gh^ע8EkCa([23$}KvYB3rWc*[fg)t4/YxmR~m]>qZ> rἶF'^[ڸ,YyKl-KԸ9[;Ays)8}TanX҆9o7@DD#Nh7$.WX9x }"1G 4levUFO5j0ɻܟy88=\Pm.R'ld\f(i:9wOS]-cB6NQaİ)E0zR>+En$iYo V's'07žB[Ny+uJUPS,7mzqQZ:Ǐh6F{6N93/ƴ1iؒrh $HI׫{'t&6-OW ~[gT_;B0RY1wTgX*FÊѭi[A!6x"Gd5Q:ȅ 2L!'5y3'Ǖ|E%MWЬ@O17,ȡiuIvځgw[>鈱j9Y¹%MQB%w9)SQg('V"5`Rt:kD)D נP5_`]:Cp[ϚK> fq0Eov=cbz a'&m L_q&{UnS)\+:5~ם̫Ȭg 瞕 QnM9w<ڧQN_HΧm2 b޿d~ZM8H=c5;x3tӻ,S:Osff. ?$LLeǦ(˟3(Igb9 C?)abV"Z.gևi4Z=q Wsg\QWo6kNX 15*a'5\U֪QҴ > &A⫂O.~BR#9s!װ=1x,BK^msa"SQW3;lQkls/ݢ7lU4/^'Z$ͶS1|%el1Z:/ǨϺ%˫(ӾQ6*QJ7OKC3E*C\Ķ/Pm1cn5mMĐUʁ-S]G\+$B l.i.ܶeAQҚcvDnq#I%}+@V( VNdcŦKTp7y`ǞE>LP;wu7;x V\yڝ{ד DGʛ GCO65TΆ:a"O;yS{Qe%y l-H琉{?׿9$Ϩ.*Dge=/\pڲ:G&H8t{c NSOp9˗~51`;\6kfcs@w*D82MfvEg}3ZCw3p~s$XZMSp @ 5 pooJVC<ߨHQhs) 6RBȹh$F$d..`qi>bBגH, Gog*_4ۓdK}U>i@JEMk)L_\t?o0z1,d%~8VGY6-ʶEkٱ~$n˳7߅.xXz:=QVx煘yhHT a@{fEb.kRFd+.nM X3壞9LXHg`:Nd(z$2S {fX|2E*ə^wE8/hѢ D:@0|5k?hcAywF\<fv,>:IP "`>X )$| J.:-8t(c.S;r&<*IJ[pȾODmfj~ܻϑSU%ZK1h~GeҔRXT5sAQ+sة/ɓif 9jND~3 <]<$rhVY0-&8I|I 5̣_OLZRS-aETHnQ{5|g*'8 j:RWnԈCJ$cl A'ɰHyWl'w>zЌRϹ=ǀӣLY\\Xle5` k_S?eLu#gSy.ܨ!5WQoa *V[ -!dE4Fܹq/{JIլVE 4nXsO13ڽ<D`P5 6H?⻥qQgn_ [isj8]&ѳF?'Lo68I&Y+\U省/[Pv!A\f+j4>B.x;?zܵjˠ71|;$i>_N1Gs$t6C\Zu%JpF.2ZG/p\՟o]:Rde\rC6v\@eOmj2[G Od֖Td(U_=Sn.@/7s,FYjzO1 JI0BV5$c}WZ{q?\AwOAgҙћt8U^j7Sr:Kʽ'!,P8 kFaڈ;Btfmv{A ja lk/FI{YQ}|gJ6сbXJB`% >6\ d/cVTUġ]r{DoZ$mw82"@z,\DvCjFx> A'>*fDe~a&Jn%anΛyd'/=$>vSb9.ǕWm+بGpKB l=M2k81@k tsЄg!`ndy3Khuʻi=d+F{!iT\a\Ap@G0?/hvH$s {MѴ+q{Vq_ A FpQw]HlH Rg!A!>h H uq jϤӦ[kaO%3O1JЊطNS*G#3ס5GbC[Nl~!8^og}ҬJ'V˭yzy@VJጭk/Z{$DA8F6+P-€`2)E&7i"04G8?#[8D8Fl.ҋ{ #bV5|##T2sK; b&W5Z}j}%=)-tR[O9Dz!ՒcaFnz[@;L''| HLr3OsJEg<TeI;2nPMlg5LP(@,qzY!Dcbм @OF-h=sEl1KM%Jz}B=xG5]}3yCP>J;}_=j!(S%\įWr)CRiD3Њ :JaT8RsDqHvK/{X髾PYe( 'HBD>O+{C{I20*I6{`WΤhcƿʕW;Xτe¸uvDor<԰K,yȱum##o@\H_ 8?ܢյ=*ې G!)O4[#{~X'/]O #_U 7j̹;(~=*#pjWuU[/ؚik:-K9]v[w~QCUl\z^ٺ04֯/v#@R#W;+F|QΕ%6* z$hqh5 N{/bkC{)@+m֣bo%"zIRNzu'H+Exf{J8nZȍ٬*dޞhLAHYrT8&pm@zyO)γI?Je(]4|cL/x;eڳjByhWeosuW?nbv71:6+ FRV=-ƣ#(O׬tmVլXkU&Հ5 ;Ql(Ww{֢ IxOrQqtrl{Š.ud5g8K} Kre9*7?;dH 6/@r7=  ۴IS S!w:gU|,ߛ1 'g<-j:*}gbݫaS+NzdKp)Qf_h\d $#)↢'\R̙v})\'rM(idu+Kڥ2R7g:D +֝ YT0!_iBr_l"e6&(]o0;ǕRD0gDڢa86LZCk~=fxZLt-ZCm4*+ No9a5򒼦y&?+pJn2#l]L .݄& W խ=NlBf*B@o&mb1xYM^{wG?`EHR[щ4K, ܤ+I9Ǩsb,x|w*ǐF{?{tiJO }KԼkz(` cWE+$96{#X**1x1qmI6G|F1+XXo!n课wP*Q0 O6m@q|s0FHRHtb \q)IKǔESeAbٔ04.lrd ڵ?mMc]rEw)pڔbTgy/"J2YQ94;=5O:Rڹơ;V<@}1!ڴ%:Ly_-j'5pJ8dMuha͹ 2y xG&vq 9׊*O>#E ?fm/8E|GyIiw 8D1VT.> ;+m!TċHou1Ztx=y.)(^ )c> X@d}j8Jjؽ-vg_Dr N73]qQ k. )F_ gVK ŅJ70n ~^ʕczV KBx<`WI|޵D6ܑ6C>R74WF,@=J)Y\Q1 > jQ=fνUr}GBTv;vz" \k28M %܌{ғyJ!p?V z.2*3PtKHC2!mRcLfV6w yK`f{k~Q*W,OGZ/ًXUw c?!1k?)Ц?p7:6띐CZ7t7#]dCLw.v ve=I_8\X;,ܐiQb{9䧒~:vFB(je啁wᗔsSNA&([Z0)ƿA]*d$=wSveDۣ+X(BViLliXb1f=f$X\:Utoj* Ty֦o/JۦW>;DjagG-o"iM)/ W!{*Ql.2 k:qň d)ˆ50 3c'Њh-:dU j/DG~`[1ef@?U>?dB փYƎYj)*tAQ{\M.m(&|(~AvђAhW$)Svnѳыe^AZGTp0W|!]|j2ۙ&%h^׭&M*\ßO&A'("x+~/զ^n)<&󋧼rſ+' -`F.ua1,)XOq50iU'QOs[<wzw?ҠIJ5 jR1 gli\:5*YD͙ř@8"QZ x~g_2cqSPD.ˆgMq.YQ{B+C흧v{wx(^AqƸ5;Q `(U׭ĨkrM ܖ%~ɾ|<8 MA4(>UW"{0VH^S",' w0E;Z/jJs+fVMapTx`T ςDaCxV?%~Sr-X 3QЊˁY.Epy.#.i7m$o CعxPکf6 +.9Pgz͆?;5сPA }y f^^foKRt<'e}^& |JGf-D$ )xz$^_ 2rYw32Mq6*:{?MX@1lhz}G}?|y;]kARL h) ,ah'E7!}z]V.;G@̻ vLֶ:;9ӌkT5dwGt3C͢mQ:{ܱ픉w=_p2J5BD~֏YjlʁEuf?\y߄˱ͧ񢈄NE ={EW˼nȪ>YRSLlBW$_ #JrU[t= VY?P;R-i:?sFՊUcFe?ܥ șIfÇ>UͿw;d B 4_-j>Z%YǦr%e򢁧#ʝ^~>ffaaDMzZzynd&YҒKn'Ryy'69l\Gl[SP>΂Ep*`G򌃞 ըeQ [Iw2rO@tao,~1D c:괙74Aϝ|b B ܐEy5@ibf,_\0@.@WXlSzg9f`W sj};ڐZI.vS>X8G[`ߋPe @l0#>OE̴v# /0e0n!Ji9gO.Qҙ êXR*6xNHVsb}?e߼Bnxf/,Vʂ oo .Eh3[Ρ{Y58 ݬ9ki/lآM]r  ŲE\'לr~oVV؜qؚ LPęw &e{Ja3l|FkixL>hEp1A4&$t7Tik* ),;J0^ ] '538?.Vōrlnʧuʹ>٫V <^WoI8]y踎",AͿci~yxjSИz̈́+}5wqV:#aDW:?/F;6zcD{*"UǙshV=(ol=~lbok a{AN0xTԄYMkqx=O/om(0mYs)~>Se56bQ@JAʨJ/qPՊO4vOw>Uhs|SE;onZ/gr8l~k0HpgL(5lLS\\{A9-U3I&pM榥ދE7؏??П=%}p-r闇L#Vۼe}-Y7Gcs⠿|*?@5=&0]q.ӼjKK2>'bq^=GSbmA/.4q-jT*A5&Iuҍ- f2lE 0S8vR˔4kf{{8RP`'k=dC =K!Zd G[TfM5PGs1q6v ۫7v 8ުХd( QCF@$P^yr;W:?T5*'sbji֣0 %ʮ޷OK h`V" "+]*v , %raqhF\Sh2HoN Ñ 'R>_%oaJvu"⎴<0CiKԅ[S݂j |OdE//N!f|pi>F~+PY/P͐ L .K! [4FELȦGWᇴ%#JdFbG N uݮAvp=F8x7w[5ρO 2^ynݯQY 'h޻{y>Wt?tdӄ[VHǎf=zHI 8J j2QqD@\ Y:tRN_'ሎrOlGx)CDUn5A|rDh%7; \W")DC ɳa4$&M’qADktis^q}ޮ+ټ-$N -BuOSK$6 vNIqN2oX=< 8ܙr=D6:Ƌ lVә_JcAfjoYO S_LdJ>|,Hm<}35['pHh'RdC!E©,S|!nri'">7]hש+v`#o8:luJݴR9&t~׵%;@ Xn|U8^30Z5L!W6yJiʀ8wa1[GwܔlW4V 7"ep[ekk4GN]*_B0UwAlW_>ۯf_ΒK'&(pukk`(V֏F $xF{,xVF *gWygL6[ -ϴ<Ԅ3H)% R`?㓨4w;z]o< 1V *MT_T(JC6Ps$qz9L>%BJm=SRPM8C/㧧Ґ ; 6nM0{y,2D`fej\2V1PAjd3-V.dq=~wl0(Lx{%a>^ۂ QR6kVMm˦,xhz6d_x!H ˹%B_/&TE9%ᐖ `wcÈ؏@r*Ƥ6#歊ޖDx@F `6=EU7,nw Hh He%ǭ^ U y؄zw@2:8Ȯ֖.-&w#-8LJ[OD_j?adItdNY8;tM:0?QG4`og(aB;&QsHn!# {VJ [6v NCB!!Y_V|ӻyi`J aUS^Aad{XlZfVO뭋$6W@*IvB7 CCPR0eJ #c@|ƌ$ M\D=|F9L ]8w@ 'P0-:ТJC~U԰P(p7+KX%mX~7]>C(L%+vCd].<;o8^i+|8zVrynn( ?UZFYear2ZHSazPz!rJ51^CMKT?xGXn/Wo"@o4j 9ND]rYr< W.njOZw<2#7yuSdW8g0O7#ֶ*1*LP <>QoPi :#!irG"cZb@CQ;"Z[罍 AI O nm k&1*+x?=Ԧ:~M$ܸ/_o/#_n鸧Ethm&hKD7ɤ:`Wru:pL'0mc/bŝ1{qGWDkXIA^{[Dpo0c vp Y5dMe-@rdhjP߭VF䝧^90杶 CYDZHi Fg*o=ݏ_f/!) XX kk\7vE5Cjszɘym(V_#xn$1kI&=cTюݱX1i Aeqth#{&u~HǿNkkV1H?DV܏wY5=c)[nWϢQco~_d3RYG3x,?K |7_]ܘ)pc Mrm4s+U'&vGvN /r֮ bdІV}j枆&Af=H`7р*+vn "fgf}S'hZe#f-tM^^Y}I=ŕ3 E6[_v\N|_u +WAin;κMjCp(AۉtpAwJ Zn܃^V-şLrE.LnVAOi*/ q0e3]-3yS-qLd,mXh1,jǽ|b=ˆ"3kb,4+2@̩/'9]LU\'W8b~$N=~d33g;}oOw '!mPX C5S^qi-!"%Y y_Dɦ@SzHrka_5*d[J3gtVnCΪN`m:aUR4ǓgsoB8R|ar_{OV {aovn, |}V!]GE=L.غlDqB\Vxh\KL=o@D8C7GѦiG6_Dr(9S|mL.Gz`MK .H92wysJaa^c6:RsEuڼy ^h͈ҋ R8Ko5Zg.>k!9c%+.M*?ifCd'R$;0*/GxY DHeѥwy\5"JܢӺ7BU2J-^H'?WXlr#8jnо_)_ڙe 8iG`d!>u="myUƎ({"h  y:9d lFWАtNmCL8|ѝ߶ۉ|FbR8ɺnń+3/iwK[3HT["Ay0uqveqGgܼUѝTƷk&'խum v gåh1&j26a ~ZS9%F}"([~: ЂCW+t. seݰȞ(^ܟ>j%8pݛgcyLqNb4'*#dA ^[8ٛ䴜R4x/+|V,%kG\1J[# ?m#}+X>ƒ ,.dY^ѬC#|s_HsXqpj "i_|gn$5`ѯW oض\;x}ags{PM/wo<-"sbO`+3O|L>;Pezn/xbZL_;!LDlQ-1aTL%{x)C%YDtc!JCF8Q؊'jǬ *bDs!猌HX"og*KψT[ޅvjece:_g䞘>'L6t6E^s[t66UL$c5 .Dj5G3y]X³iwt>Y")Wn +)g ~W,G/a`g ~.8 .@Q4%C!g}ӺT|}tSAkݎٸ?zb#cES hA- q1aa Te( [}Ǧtm[U`īgGjɦ Tl\vڅ DzAF4^p 4ik!9 [t-N``)V{yznӻDZoBI{&L{ DخoR,TKG('=Z8W_7Y잉~.+1xurIVH1]h4D#HsSH7o05#|3o60%}<4o+^#ٝ^7^uAxℐv},[f2 mg0o 1gYJ0ǜ'^p1[s[uN1xB7gtд7q]wpxZ,FNԉ]E~)w8+x*aZ('H_tJϑ ?<4rLr|BbӄT ç\shgBB<1?u78 8aTXKvorDI^SU}\=ȕ WUUqu{^s>cKRz`6%yiTcL 5{Ep`Ќ-OAssබp88 &5NWӰ/0 A9BZ㐎-b[@N]x 7D~wuȽ+lu@ CrP! a>#$-Gv~|٨){wt I`6 eiYizp9ƸHH3ONㄒFFlKa<$AP؛HAA.]'>rWWV=%AA7rkD(X#=S0n-pbVSxUs4+ S`<[g쭏 a$n攢-u6BT|{ғ&Mu#Y;14Mꇗbr}BfoBz%xN^ EX"\p0AIJ:PG56/zp< 8/S8CuܨנX&pn̷ 9nE1fD.ev[d ziq>e`F"CHn-)bCxFi\~xF=wV3kx\%qҞ!w#BOF  jD{^`Pf//BVRvY Y>jHћT8NAW7\SL.wu@ +pन+R]:FHNZz16w29z'5oW aҸTկ]S;L/x皏@Xp{6%4o576rc10VPA vFY8?JCLe$$$G+lq; oV՞c*nǦ6M RdހЦǘzwZ,*!-6P6&4s$d{*z{V4Y ;WsK:q~^ '"+ 'rt.`泵-x%ɭX%jTm bI;Ц-`=>jr$"xM8KґO >O[C.CrN8ԬyAI1Tۼs";%A\YcȴGD4z[pɺ ) B2GP)uxSq.::~'8Zz/௛gJ4 ,M?)Ô WI[;-Yӷ+#g #~Q=X+3CX`(tn)J *VY)S;N*/V1ZJbǏ# TQ[w!;&Ȅ\zN%^Jս yTԱmnBRފv訛β*&KzM?O8B0b_f :p_c}OT&`p UtQ]EWqln1&銄3<>F&82늙Y6AӚ3c.\sN,QZyDɨAf/ *}T?st[7$N &0UTHaQ'U/A(FTP$.9^mY8(}Z&rink Ϝ9[@>ıFg>`iAZ#T <`` `~/rAmHfCq0/`4͚ZqJW܊*A I)i7e$\AU8@:9^n _s(tS.u_5Hb"Ev+A(YteBC-ȲE6F4δ%0-ijÃLPU0.kk cHgtfz&ߝ(Ai 쿂V®ғ] _9q&Lc ǩ12آAw ?!6 /q/+ʼn8tʍ舠)~!l5a_q*X+Zx$ 8s}jfم DQz&Ij|^}cm|hpNw|˱:'xƑKgZJ@v@%ɱWhdyϟ }Nf vI_c7!2; ԆͣaR8E$+h AەCgB0qp*d`n/6/|t~*uhIݹu%Yɬz[TREryiTφ͏ WFØ¢&ְp/1*G€玢1ɑ77%͈qh#yctz)AvTeeNheb}~8͞LZ%b?p{q hU HbJl@%B֢V&`p3ddOˬl" x%ufD;z;8?r%O4?ydĒŝaLxڒ=F _ntQ#9Β KpZPgX~CCn ijp%M|Zq׸Ϊzҹ-LյD]&a<8CKԆWnS^S˗YSʨcr3K}Yq '*;d @kRca@swh./Ruvy9ab0sf3K䭷^lNpJq72f Z;WCFV5Bcꀞ]r蛀jf:%7SP(pU30>8̞Kez fRpC ߔc.m. lVKVP_a-D]$wߎU<y 7/"-^(2Àckע_Z`Jיu J[1@޻xIG"e>H^P9kЪٲևڶ[JG1BeGt^,4b܂d&Af0Fi败_QfLi}T]ATzL$ TMڳgdh8`50K|ԋ^>G! ?iǤ}Q6F>*$0\a¯qTXski9"Ȧ[0+]~0zkg_u%BˬI-ehT<Oo`#{wor~qn8pxq~8R`gm F$|ʷu$:-F1XϔGg#FI]bő%IG&k;K̼ :ҎZES!+pNVyoV@Xq:xypZE)}~JHLC2=<דhl-QrO#.Flϖ*.\™3|={Yrc`L\߮0q92t6ކl_]22kxBuˈF{lQXMǤS7gAEct1 j,R֟B ,I}t/I‡QG+5n7]0?,aԤc^z!!]'\Fr4:&F*rI&j@hxdPr:?bE^$D:wdlفC{T[6ˡՉ'ń'y3~r*& UR1ʅۯ#Fq&7*sr˲wEYU&V^*@mZPJl#4PZ=Sad(+@#cbBp3g-&FmB~f)C q.+Ի:bG4Zz}weU+oHw`>R!KjG9%WnS8$_3T ]ih ֧vw"hv۠ }$dFLD?j*ʤ{Dtc͉@MV;$D!%ՍpE=j~50b . 5!r[I.dHn1"*3\s~)..->3f 0N\pȿFwJ57}(#O?w^!c N>B4P,L߸yĴv1_bo=*6,=~zd,k([~' @+A™mn\+i!\.B\۳=J{M076:p TH1ўI1QW} qk& Y,(aZ :ڀc5;f S"[~=.-Wah f6%s˭j}WRX{3DbUun_] U춇XY'{,}3yf3U@؆ ' D!8 r62 }mI?(TĪvr}ƶu&#,r'fC' (Q '~ qWݡP`QQA۸kHY_#"2'!G4N3F4Aqlk dqʜd֕LƫtaI3:~ZzB7SFzEEy`񉪜=jNk82*6˃}ئ!q~; C[M9ȸU0q̎u1AFʐHC'|%ΣPVPeu~ BSsc$_,9bH挐M:hLm-Ťi/ٳ}JH^`Q^X"`φEr;Q4>Qƛ=SMՇxw|qBq~,E2Z|#jy8:hi8Vt XpS>z2Xdr%,5D U[&3w2r{fyHn Fibvh̷;ir{Kx>ZSg7p<i/Up7g x8\zȲ[!HٍG%Z{18wb2&j4߶ lXP6C'2' yM,_v#\=vz s PjKkOh,=Knը8^ u1[l iehyO}lC;ac3bWI0PkGFss ; NHvbM(}uy^@o$~s@ |}D=7V^sLF NV3Q7e!gg}PLT̎A.jx$o}/z:PDG}L()\@ vcjZ7SVwKYᤨւ9V,Փ|V4#i˙SyV'1oYPLLʣתk9ť\#Buw. _f17d@i[2PxEЦf {;/QꆞfUPX )n-SX[DaE "ϲ:?q2vat'@Vj\y!&b@SJpK#ok}Qqu]a; }W{?*(ץ{! 4Nw$Y\jϦ8`CX])8yمmFn߮Z?nmqnIR$[ `"m?|-9@sJCPH;@&,u̝ +yTJlߎi4 ]Zzl+^`93@9qkxv AbJq'xQv67אx>:%x0jp=#RK}Z:Bss#D^aX@;/]UeQi\ XkaLA\Ν@ogͣQ}5_$lZ`C9aP)[gC,7Ia$&rL)S&%<ٳdå;_K E]PZ3B 'p~4\o+L*r\3u%F42M|Ou_t7p-ǹah-bG7XE dZ[)_86Hgpd%+1a /wh>`ؗC a=HCJ[=FeK9 o6Ð18̮0%<'iB+EK0^E^m|XTs1 P2sv:Ae- H}[@NxQT[XPwG*Yе)Le=}OS LI?ruaПUE\^lI^Ȃc&'ko`@(0/Bp6{zW>Ec~c7hA]b%J;-jLoH,. kϘSU՗(|&)4^=|W.f/j7i*<4+/*v nR?pHƨ?"}De]$dٲ73?t/3q+ fHW230x \UQx d$01B+ܯtkYu3[(ʌո[$8 1Q uŠ^5{|rk$t"0ib~Xױk+4^egjX5jq|l4/Nx>UPJ&G= .|ٿ*M%$ցMnσ # ٓ1saԔ(#~D;[VJļr]0i_/·cSͧ epA Kk~6.}~AyL6ן!Y!yM턛<,t2s*?Ve0q'rj ^g{E* z㴳\s % J;݋=zlTg1!W g$/f!ϵX@4Eu>:YzHa Je8Fa !8oL㠽DQX)u-w/=dKҵs.ɲ&ע0^ DxLL=zLuG iV ꓧLqt/C(d#pnemښ#p߼H3 Ng lPn=@Cl=VC3cdqPt)?3;l|cKj6?# 0fpj(*ۖvwЫL|ⷻqxzճ5ybR-itQњ)Ug>6tfuѕj)•`$Z_@_0Em4*ބґ(c%N+p<>sH36&|cR-ԹըFL(fks*^+;D ;Ae}ye "{DaFVGAJM9~ l]<(4ꃅ+#Hʂ2?ZlqIE,t?y(|IzԚFJ"&:,)5&|nbH?SB yV䰦IYs~*)\ɔW?fWP0$rR"%@x_6DGdvgKЪٲ0'q;#GЌpQJ\Tj0˅iXVb'ܻҨT7AW&9 J'Ӷ&6.rT<VuSg/ ms6FA'j 2fr*љl8C4O.ZVeDmi ӥsP/_JKb8T]s]'Mg[k6Q 4*B|q0bߞ(.oFPeNRa@[a֐kWs|۩XD9QA6zUxpZ4Dp ç؛hBYllJT6*^ʅ%,   /aO {mtm_+v+ν4]P#o[{q-`0rM=^X5Ǯ/ ;݀G}ȼmˆ 6-'0o.m: tvIeC/ E)z-إ5&ycľMu6`F&WNFW>5* 8HZPe^y; kaK!)/CZMvWN@Wy(mơ EnRNgڵOo=W!$[ lB' >k7 e\]={cJ լ-V[>9]nNA? #[3 G'*oy]<`ZWBYo  q곘 ܽu;<).*~ 64ɺF/1X!GKU.þnfS55wEũR"K& XfZG|Rн9H @)-Gpi:EB"Omg'P _$uevk*ߦ0N\N 6tGaKImY*9Fs~fm֟z:öl1ґz͉ JR徣W89hWy3 `m3FI`ɰΆQI0 SJI@&Ӏ1*G>5?UH^ۘgB[phk+VuּnsV֓|\ %略w>s^P@ڹ1ٳK"̚Ͻ05L A)iirej0ʈ!ONnTs^OXP¹*l0u?F*}l\բY8.m 5GɀrH}G }歎!Ti^NߐH~"z ZByZ%'t$MQn f O~Aa4 JIm@t>1[tG=W2W_W+ ZVilıV+/墋f_IaΔ^yw_ gcI[Gge'sxLzo1> Fx?}"k0Xgaa´{3/EϚo` m|y WO=_ծs;(&o/XZM$'keN5Fm0iP^wuWӾ0 y?ĶB UXhL"r1wOM|F?(͋q{s7 Aqq$OS$lʩi *IT;f BQ|;S۩Q}-W.W*ez:TԼ&Ռ3L:ݏ!;oE)~tx$]3hLSL]UMY8#MQ®զ KtH yMU&Hp5 Nu,^)ED*Tc+K`Q-={у[V2ׂ& ԣLݬsQe|rKOBc(0Ѱ}Z (zp±0k3a&ރT6B֒H-QdiKݍ|VwHm0L%ϥ# )GSbՃIPy:gZ 䛢F &XtKDȯy>D]?2e+!ڪ,;\UMlY8\g(<ã41H2;I+DF;:"|^]CmȪo.Hw>.[qQ'䂾c0@^ʹ |ຳtkiO*701gkkVX/6f-̚p=ٌn=0ߒpzfI廒3M͘gG61Qb볰}>NڝNbbP߳(~4!'m44^fӑ˽g[;CE[رj-M@fI& dliy߆HU_- 7"#E8(>6t*T-0_ӟC,m-#O2Gx˜uPT4m ~:D:)rhѰBG #үzM5)ᝣ-&}OݿHUl/q# 'rU¹]rnqk3n&Ue=&;\R R+t~Ds&U9 "gEkBhVS+(Z' N9zp Y% QLq&h5rN]}MxGG1c,Y9˷Uvzث[8ocZ")=Յ\9weuTHРC$m_TGCCUB /%(مFkňí|~noщtSJcy[_uN%.2m/ 4QYJIѤzdࢭ%JVNuS!B@36 , /Hb= ]k͊Έrs"Cչ4?s$\rk3, ̓-];yk%j+>B;4M t4_#T^z[sLet͚{nKwD1SK=H`X`UdѫuP1!}lL˻AA֙?(hm]\_pKnlp^n-+o9/?;m}w;>FG3sڔ-$he_W6N S9uV>Y*U2ZPs7sY7G_#g-$udr W{چ,P?PLiU}5 b,?_Nj?hM׉y>Ywc0kK55ۻX$ mt-ݣzѩ'մ#K;LyN? wD#k4 .glXA k9yW'Y ۪rޟ8z'-P~P40 Hۡ\ϵA_Q'ĭpTPpW (d8'+tlYh[CU807VaMZn6<'4iXc'~>Drqdqp¨DeZ菌>k*ʃ g"Pԏ ' I[fH$ g>q̌wȳ_ +0`0)Cү:?<噴QpA?C5bfY2t>0nMK(Z4ɍ|G^5U!Cl%cE1~{TV<1Hf?W VugiVt@ũ{}5-z @D؍w=rψᤌ^ τxi1C3xWL+m*35EH6P8&*0 e{%-ٌ ۏ zhg4 ZS<,->Sy<+Sˍ󄝓u _[1Ѳ/5QIqExVT{ ֩F|luhMl!cjR}hb\Ҏjl$UCle OM hb7Z) MgYS{@HhGBXf37-"9ys%ȢbnK ڡɣ՚e CUL̹B2{D/$#͔Y w0Mw۟ %ZP-'+XUuӒ&$Ui,;f} I* &q육ZXkH ՘YH#`QlKAks #[^Me6iV,(uC)iJ9fWg2X7$;oϠ=m]uń8ZWә ^0xZ8D_3G]zq8D!*?wBnB5jhSd6I^xP8LD0fWUGRYl6/HSFr$fk54WXC/VG-_j׻:nl̙wk䬲e<_R iM#v2 dQ|6j$ٟ}u[SɿksP}|rkd>M飋*?j)̵2r K d@T Ok>j0!M9|sHm;ES]DW$0K&'E?9J'Fә* [i?֚8lGy>'`fM&+=̑9Z5 ZϚ~񜞸íec{ԄS} ̯;YL+&8 ,R7jq^_^g9Z%ip+RID d^' 6Sb4Ř !wkA^x%lJ{c b7Z)Z #x$A.mu?ʲs5yiVJZFrPr\>B ǻėorG IjĠ6.jy~#Lǚ0,aqDy3X AqK3IݨZ]|GƎ:WmQ>o+hZTDMMJwDNSc78e L.D""!LPHբf'֠8ѐmb00r%gM/wiWλ R)x6lPA"ʻzZ?s|B)z)~\FjӒgK- BήϢّ|({߅/d0-e `ԡ(83Y|G-s1X .}"P]l|:9^,#᠃"ܻ k/.h!`P.=rrT8f{*"&4=|K~rL m :umu"N;X ,MȉyU(=_{\S`UJ4 zqzp\ p\3 j)ԥ!=iu(+̞~T50 J J`dg|ۦ ԆSeA) 2HSeiOc>_rk(^6o,n382&KҲJ2,D30r1pԂέǿ[Mpݗ+B[( R^5sm14k?}m6s8&TBܖd䑗ϻQj؈n*}fSмu℞Ɖ3)sz8~l! J~_bUnt#W]3tM0MV/w7lzwWrUQE7L/Wk & iVļBp[`]к+0Wϰ ? l,7r=~oTq)Ac_yc7BSC%FopxU5]'> U<`yYgƛl>3ERnۈ0Sv\vwv'K\@%+L~M͌'8]y)o f__UZvb7.yqlr@|,7q ۥ _R2.>q\P[p/ޙmR1RCY&xӏ̣Db\ķ =- PKStyaX*Gĝd%l+DNbYK[!_7ՕESڞϕWW"f4BF`==7&fwl#ߍ]k02l)gvcZ^’#"ǘ #:sV#1lpz`- ׳|l L6Ytb%Tg ʂmޠS@8l:[֎1Fz$q>ԇKHdzD Uο8%n| 8&49 b_2B{$⾬g ╫ FJhk8|@:5ʡ@n\׀\'d[8ci>oT]\n1%~hhX,gi5ZP&4zo{[iϑu IPI`2o!11BYo%[YYhqQ3/7W(4G!79wfm>8K.% EG)_R`9`wdG qESkYtM&>ɼBh=Fw*<Ω@ }vr̲+*=e]%406LZz[oZ! -cJU۰C6cYoX*`0unuuo[W0C<:߲B bmI\ۦ30n> +4;H;-K=8݃,uwW8nNbMv%EdQ^ZSobf7m;HRQFa|$L$T NӶf]h#T YӚiWm̞>#n5!u)Vœټ1VpI[~ xѕ*4J}?r^V8)ͺ/HZu$/H|dVJO)%71} e(rcxZeYQc(ZA]Fb*))Y @H\pV͕ft2PEXӪbB\꓊R86%2Z0FqOb )_<]fu5-u}:P+|+]OZ N6bXCtQxE;U+eP =}I9-է^>`IlwA^A3PPN cv(&w!rris{x89I IԖ57k9Ǘl͚֍@!dʜ2aվѩGj F=7ޙO5FkTN9u]XhT*Y8j L~0ȋ]Ҽʨ+jk6݋;򑧸8ϔn6azN _ǨWQR9<8">RmA?U^zGG+xڋ6 F r;y`/?κ#7媩FnҎڀܴԳ}`QN">ٙyߩgڨweU4z ߻dp)aIQtM+6)ji1˙!6.5}. -F!F{󐷡pd85,ye$︵ߓ+v3H8ؐVgV@7I on>!yb"7=EJ6)> P5r@kU&o`uq&k,9ޭQ]֓RM͟SK⒖oBuذm&)m7],[l1*n)A;)FP؉HHph[+.;3"dBEN\gv_F(}J0ݛ Enߠ=xW7_Ͽť1#\_]+8-˲ šg2F.5>adVW9 u>rii?] OҊ< VI] .;PJy/׷Woypb ,C?~ ScJ~bs#z`LQJoq&Z aN[hpfi#p!H#]rL"OL2%:rmY[|"]ԥT]r `*Gzs0,>h}rbMvgi߆)kPDKAT4PN WM|AAuЄ<:o\ȓaHr-"\]\>ۻ eu%{RN>#20Y×RB=cmrDjA{ UTf7E&f;jX\>'K|7yTXE0Yae? *fxuPƔ mku3>M J&ɚP>j(GO G~]M>:޷RaڸkIS;ҥ}8 \2m3v֯%McB-yf.`|qu6}A s)3i2I!Lb7cg9z. rwg՛6-3 km$ԏ1Q-dlژ'nkռjOMH1]='li֯LD|J(eD,Ylf-X,7"Uj 8'}57ܬIH1e{0KƵ8،Wa"0i (;nZgүiӰL?ؾ]ڢa\u!̩ePY r 1 HU[#'9eFVVCVҬK|h)-3]y],NF"{X`:HCgEjF~4:Bc#xpVlĝ\2/Nxr)n}&b`/ KVsmشKu>lWO7c?}Gt[0#I \Y}GyėUfe}e?IeFWd&(Uj^h;O_a^289ct=A>Cń#/# vҳ Q5myuX_c@vuD)JثMO OS ),<Rtfl{N:r|f$Nb&;\@uˠ6/ybˮ#/Q/b׳%nOW^ل2yt[w:Voɷ"W3=IB/ r  )Ps@BkrjA3viX}%*E^ʦ #u±sF:HhϢ 6 5M$t:-^-зI#ͭ"58FG@qSvRӷl~}d_:=t#K)٪%I5XCĺsXXeFatd 8 ƔOV*cS  )[0W-j~SJ$P˛>|a\ =21 豑0seҤvz:1&Sջ1/bQ+t)gQKAB 5%[oa=?ـ P::KD5ÿx3;Eknફ@QgxY5} JcWW0[RN10c'M`㡭;e9(Hҝ)w.Z+4^c`P>3^"bnu@M_\(k{՛޸߶5ֱ_)l:s?ݛ,/mb.VrTA'V#/ a%ڗ#W5^ dI# -94IڃJgM?>qb0$+X:@:M:X.oNEu5+X9؋RW.`"Bs 7S؀|:z\\,p񱳺`9-kGLju:VG}d|*Cg@eFM@+~Aj~P zGFs(2 ͗R}.ޘ WQGPFvbt2A0&#8wɷŇ]^}?ߟWbBٍՍ[qRvgmg%mp)7j&iVAȵ5>] S3}dXbǃwme?#ۀW*c`\xGSbkqgW6GÛ8>2GjUO J7*JPt/]K%eGe\V3=NycI`i?]ݠwDA#۫vrI:ǖP3Ǯi廱i-#/ `c nc:ֽߕ0'ȔX8UUL9NvY%e~m%N`=w.({K\I9`VX73}gk[#f騙ZKjvwCNZp!+\/礝WH\)yK:x"x,CѲ->E@aS,j^2[\ö DکicqOj-ܽs`(gVIe }t%6!-H90\I콚jcr UN?kfWI6M~ͧQ<2zv)V"RϊW|J;9¢!Lx_Rv\$LeY`fY%޶ue/-!Q1WŻWg28x'D\)x/SmOq*ތ=yAp:cwHHdp5|CvylYGnւp+߄6=VWRWaDy M>rGlkq<h6|,P]=Gf+<++2MDDCE|Țp(c*~ܖ e^vᖧC1¾cIDVo3]u"G ٫z&xǴf.?HTj E+܉~7?ePO1$}Ec)KΑ &4M/֒Luj8(Ңg/X 뗲N;rj^SΡNEDh}{%E=O"g`3 ¾9|˥O{;`*Cmo/5-]d؊4lt@zRIYE[)kUpz '6D+KI\;R*C;|=l-6ޛ1,%7Ph%9jۆI `|Mk~VLLS޼8# ;X'& <3p?0ҳ/(#?֕TIUI)3ڄ+3oodBSWY =ihfY)Lrv>ώHDdCtTb069yPN,H%=1oV9nRy;(?BbFO+Kf ʁlb2䒵]6U@:ez؆`z|c]hJ]0&hs+B_ E;t!55_D׶B&:$)M}ePL&Wsv.9E5,xJ7Y)O^OI8(zqyT)ۅ](G >7{'$ClQˁݒyH|Bbes$^&g+eBFX2A/lt 4?i/k-:uӳפ{AY/T?F?RZWM%Jf@W_pG>9c tqM>"%{'}l)ϟ̄^빦fiO4$}r&)^B7J ``)GOY8*i)ǖ 7h/Y#[XOfL/9hwaJ_ex2c֓i hPuEI.p`6)kB Y!ߙgaÄ J󎼡b(%tG;fd}m3^C"Ah8qv*.,mG0x0~C S.Q |[̿=Eݣ6gdcon/-n "^;ЯgYOn|]o*26懇oj2`[gK3H7/x21+?c'ɞ\j9VCdbFMjOQ ̛yu ٥SQBvd0>l4 l}x֧uMBcg yd!RVƒSϫT C/g L֘p_̛"@Jy5УuU`L7*tl|xo_tD-C?!} 3R+1 *oj`:xcb=.i0{u;GO:sǦ4AWA| Ap8V& %>C#N< ( +=-QN!ʠ&q}k&7_EIC~`h8 ;zܟr$T}?nb71 /SmQZ-}+ij1ֹ2OLۉjB_AM5#-x7\C>A(}685;]lFU~\/F婩RfI }تBB^7VDBn 㡹ځp߯u6k~*$l7`=6=m;\jfJvz|'mAwM5dL>81%/I;\ઁ: Qa{}ѽz{++l̎PYV}jMDFiG8˻3 #n}FGk/ܯmri(5-sBCnGx&2? BG1_#H9_>mC+OÖ3e`i4KA/9t,@A4H=qI桮-)ZJcZi$. r~"QSD셓Ng4Wlf+j0<ヌ֣YIWξ^Z⛇2B3J? NV X/߬&eoX >$V X_a\vTy^َ{6 mOp]Tq0R$5#ʕllfJvq &Q1@kmێpTxD镽l1GMߍRQOy ]ck]=$].2w.r}{8P<;%a\ΠZܲք`3uS r6CxEF5Lg;˽&QCIma78iQ#2Qy xm^gI(xa~v*hbREPuZR^vhrAIc01}no[tVE5G(m;I'U(A WA2!@{2p#B 0/Sc_gWCFT^ (.GkuTƽ| H mQh\ d~ F?