samba-test-4.19.8+git.404.38b26805d4-150600.3.12.2<>, 8g3p9|ڿ6ϱpW54+B@Rzˠ,Dx{ghUh> B)T!P86`nH^̶)(:P".ΓNLI2Wtﭵ,=: %ja=w<l)fIaR,!'R>@?d ' 5 a -AX^d      &l 8(:*8:4%9>%:RG%>@ FG0HhIXY\]@^b'cdPeUfXlZulvwx0yhzpCsamba-test4.19.8+git.404.38b26805d4150600.3.12.2Testing tools for Samba servers and clientssamba-test provides testing tools for both the server and client packages of Samba.g3s390zp36SUSE Linux Enterprise 15SUSE LLC GPL-3.0-or-laterhttps://www.suse.com/Applications/Systemhttps://www.samba.org/linuxs390xsHH hh@G Rρ큤g3g3g3g3g3g3g2(g2)g2)g2g2(g2(g2 g2!2605365fa93ecd2bf6f393c447506373e1985039556ecaaa0390731dfceb389b18ea5e25f97a0eba6f33ca5e4b3e5d895855b89be341dec842e1d40a30a3aaae5f6ddb38835e37c7294eea749f14d7b2ab54be296e7f41bad9443fd29b9cef2b41e49f06589a7de791f74454ce63937635f57b5822ae24842acbc5469de5107ad8c993a67c562f71c2ec07672e399f35a10782e1839d095bea4d72831be3e75a83db05005ece4cf2b31a3144c9adb87d4ed866696b5fd5200402b952daac208f438bcf84f2efc53401881f56fec827d2b45e122b0656bdf341f0e99d7dbba977cf6c249c630c384c4f3de001ea54a8bc3a4ffb241e7b69214f92639a54afdb2315e18f7bfaeddce2eaa53e69466a38e2ae0fb2f20f96a200b9b3da85be90294e9af12fdc91f4c4ef6ab549761b9b034e5d20c8d272f63285d4d9a2221642560ef8bcc2c26c354f3a9a89b45b25f9ee62a7bd26a5c65bd539a62be1385530f01da96e9e825c7de506afbbcd15edba17c36dd670cd79312254509c1766845819018c0a3b158a61e09aa150b067b35da65ea8997d21f1147a97e9a39a9de78e26a2f8f7aadb0c4543be9da0572d4bea60c6244e472fa4b316886ecf6e0251160c5crootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.19.8+git.404.38b26805d4-150600.3.12.2.src.rpmsamba-testsamba-test(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibLIBWBCLIENT-OLD-samba4.so()(64bit)libLIBWBCLIENT-OLD-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-SEND-samba4.so()(64bit)libMESSAGING-SEND-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libMESSAGING-samba4.so()(64bit)libMESSAGING-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libRPC-SERVER-LOOP-samba4.so()(64bit)libRPC-SERVER-LOOP-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libasn1util-samba4.so()(64bit)libasn1util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libauthkrb5-samba4.so()(64bit)libauthkrb5-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-common-samba4.so()(64bit)libcli-ldap-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-nbt-samba4.so()(64bit)libcli-nbt-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcluster-samba4.so()(64bit)libcluster-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-contexts-samba4.so()(64bit)libcmdline-contexts-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcmdline-samba4.so()(64bit)libcmdline-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libcom_err.so.2()(64bit)libcommon-auth-samba4.so()(64bit)libcommon-auth-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-samba4.so()(64bit)libdcerpc-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libdcerpc-server-core.so.0()(64bit)libdcerpc-server-core.so.0(DCERPC_SERVER_CORE_0.0.1)(64bit)libdcerpc.so.0()(64bit)libdcerpc.so.0(DCERPC_0.0.1)(64bit)libdsdb-module-samba4.so()(64bit)libdsdb-module-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_13)(64bit)libgnutls.so.30(GNUTLS_3_6_3)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libidmap-samba4.so()(64bit)libidmap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libldb.so.2(LDB_0.9.15)(64bit)libldb.so.2(LDB_0.9.16)(64bit)libldb.so.2(LDB_1.1.14)(64bit)libldb.so.2(LDB_2.0.1)(64bit)libldb.so.2(LDB_2.8.0)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.3)(64bit)libndr.so.3(NDR_0.0.4)(64bit)libndr.so.3(NDR_0.0.8)(64bit)libndr.so.3(NDR_0.0.9)(64bit)libndr.so.3(NDR_0.2.0)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libnetapi.so.1()(64bit)libnetapi.so.1(NETAPI_1.0.0)(64bit)libnetif-samba4.so()(64bit)libnetif-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libnss-info-samba4.so()(64bit)libnss-info-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libprinter-driver-samba4.so()(64bit)libprinter-driver-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libreadline.so.7()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-credentials.so.1()(64bit)libsamba-credentials.so.1(SAMBA_CREDENTIALS_1.0.0)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1.0.0)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-modules-samba4.so()(64bit)libsamba-modules-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-net.cpython-36m-s390x-linux-gnu-samba4.so()(64bit)libsamba-net.cpython-36m-s390x-linux-gnu-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libshares-samba4.so()(64bit)libshares-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.1)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.2)(64bit)libsmbclient.so.0(SMBCLIENT_0.3.3)(64bit)libsmbclient.so.0(SMBCLIENT_0.5.0)(64bit)libsmbclient.so.0(SMBCLIENT_0.6.0)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0.0.1)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsmbpasswdparser-samba4.so()(64bit)libsmbpasswdparser-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsocket-blocking-samba4.so()(64bit)libsocket-blocking-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libsys-rw-samba4.so()(64bit)libsys-rw-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtalloc.so.2(TALLOC_2.0.8)(64bit)libtalloc.so.2(TALLOC_2.1.0)(64bit)libtalloc.so.2(TALLOC_2.3.5)(64bit)libtdb-wrap-samba4.so()(64bit)libtdb-wrap-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.11.0)(64bit)libtevent.so.0(TEVENT_0.12.0)(64bit)libtevent.so.0(TEVENT_0.13.0)(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.13)(64bit)libtevent.so.0(TEVENT_0.9.16)(64bit)libtevent.so.0(TEVENT_0.9.20)(64bit)libtevent.so.0(TEVENT_0.9.26)(64bit)libtevent.so.0(TEVENT_0.9.30)(64bit)libtevent.so.0(TEVENT_0.9.31)(64bit)libtevent.so.0(TEVENT_0.9.36)(64bit)libtevent.so.0(TEVENT_0.9.37)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtorture-samba4.so()(64bit)libtorture-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.19.9_GIT.404.38B26805D4150600.3.12.2SUSE_OS15.0_S390X_SAMBA4)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.10)(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sambasamba-winbind3.0.4-14.6.0-14.0-15.2-14.19.8+git.404.38b26805d44.19.8+git.404.38b26805d44.14.3gRgR@gMgp@fٝ@fxfteԔ@ee5@ede6`@e-%e'e%ascabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comddiss@suse.comscabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedimstar@opensuse.orgscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.deddiss@suse.comddiss@suse.comddiss@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comnopower@suse.comscabrero@suse.descabrero@suse.dedmulder@suse.comscabrero@suse.descabrero@suse.denopower@suse.comnopower@suse.comnopower@suse.comdmulder@suse.comscabrero@suse.denopower@suse.comddiss@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comjmcdonough@suse.comnopower@suse.comscabrero@suse.denopower@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.comnopower@suse.comddiss@suse.comnopower@suse.comdmulder@suse.comdmulder@suse.comddiss@suse.comscabrero@suse.dedmulder@suse.comddiss@suse.comnopower@suse.comjengelh@inai.dedmulder@suse.comscabrero@suse.descabrero@suse.descabrero@suse.dedmulder@suse.comdmulder@suse.comdmulder@suse.comjmcdonough@suse.comdmulder@suse.comscabrero@suse.dedmulder@suse.comscabrero@suse.dedmulder@suse.comdmulder@suse.comvcizek@suse.comdmulder@suse.comdmulder@suse.comnopower@suse.comscabrero@suse.dejmcdonough@suse.comscabrero@suse.deaaptel@suse.comjengelh@inai.dedimstar@opensuse.orgdmulder@suse.comjmcdonough@suse.comdavid.mulder@suse.comjmcdonough@suse.comaaptel@suse.comdmulder@suse.comscabrero@suse.comscabrero@suse.comkukuk@suse.dedavid.mulder@suse.comscabrero@suse.comrbrown@suse.comdmulder@suse.comscabrero@suse.comdimstar@opensuse.orgscabrero@suse.comaaptel@suse.comnopower@suse.comnopower@suse.comaaptel@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.com- Fix crossing automounter mount points; (bsc#1215212); (bsc#1236803);- Update shipped /etc/samba/smb.conf to point to smb.conf man page;(bsc#1233880).- Update to 4.19.9 * libldb: performance issue with indexes (ldb 2.8.2 is already released); (bso#15590). * DH reconnect error handling can lead to stale sharemode entries; (bso#15624). * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699). * irpc_destructor may crash during shutdown; (bso#15280). * Compound SMB2 requests don't return NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses MacOSX clients; (bso#15696). * Crash when readlinkat fails; (bso#15700).- Adjust spec to split out rpcd_* binaries into a separate sub package; (bsc#1231414).- Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated; (bso#15699); (bsc#1229684). - Update to 4.19.8 * Invalid client warning about command line passwords; (bso#15671); * Version string is truncated in manpages; (bso#15672); * --version-* options are still not ergonomic, and they reject tilde characters; (bso#15673); * cmdline_burn does not always burn secrets; (bso#15674); * Samba doesn't parse SDDL found in defaultSecurityDescriptor in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685); * We have added new options --vendor-name and --vendor-patch- revision arguments to ./configure to allow distributions and packagers to put their name in the Samba version string so that when debugging Samba the source of the binary is obvious; (bso#15654); * When claims enabled with heimdal kerberos, unable to log on to a Windows computer when user account need to change their own password; (bso#15655); * Fix clock skew error message and memory cache clock skew recovery; (bso#15676); * CTDB RADOS mutex helper misses namespace support; (bso#15665); * The images don't build after the git security release and CentOS 8 Stream is EOL; (bso#15660); * Fix unnecessary delays in CTDB while processing requests under high load; (bso#15678); * Dynamic DNS updates with the internal DNS are not working; (bso#13019); * s4:nbt_server: does not provide unexpected handling, so winbindd can't use nmb requests instead cldap; (bso#15620); * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664); * "client use kerberos" and --use-kerberos is ignored for the machine account; (bso#15666); * Regression DFS not working with widelinks = true; (bso#15435); * ntlm_auth make logs more consistent with length check; (bso#15677);- Fix a crash when joining offline and 'kerberos method' includes keytab; (bsc#1228732); - Fix reading the password from STDIN or environment vars if it was already given in the command line; (bsc#1228732);- Update to 4.19.7 * ldb qsort might r/w out of bounds with an intransitive compare function (ldb 2.8.1 is already released); (bso#15569). * Many qsort() comparison functions are non-transitive, which can lead to out-of-bounds access in some circumstances (ldb 2.8.1 is already released); (bso#15625). * Need to change gitlab-ci.yml tags in all branches to avoid CI bill; (bso#15638). * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with SysvolReady=0; (bso#14981). * Anonymous smb3 signing/encryption should be allowed (similar to Windows Server 2022); (bso#15412). * Panic in dreplsrv_op_pull_source_apply_changes_trigger; (bso#15573). * winbindd, net ads join and other things don't work on an ipv6 only host; (bso#15642). * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636). * http library doesn't support 'chunked transfer encoding'; (bso#15611). - Update to 4.19.6 * fd_handle_destructor() panics within an smbd_smb2_close() if vfs_stat_fsp() fails in fd_close(); (bso#15527). * samba-gpupdate: Correctly implement site support; (bso#15588). * libgpo: Segfault in python bindings; (bso#15599). * Packet marshalling push support missing for CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580).- Update to 4.19.5 * Windows 2016 fails to restore previous version of a file from a shadow_copy2 snapshot; (bso#13688). * Symlinks on AIX are broken in 4.19 (and a few version before that); (bso#15549). * Fake directory create times has no effect; (bso#12421). * ctime mixed up with mtime by smbd; (bso#15550). * samba-gpupdate --rsop fails if machine is not in a site; (bso#15548). * gpupdate: The root cert import when NDES is not available is broken; (bso#15557). * samba-gpupdate should print a useful message if cepces-submit can't be found; (bso#15552). * samba-gpupdate logging doesn't work; (bso#15558). * smbpasswd reset permissions only if not 0600; (bso#15555).- Remove -x from bash shebang update-apparmor-samba-profile; (bsc#1218431).- Update to 4.19.4 * net changesecretpw cannot set the machine account password if secrets.tdb is empty; (bso#13577). * For generating doc, take, if defined, env XML_CATALOG_FILES; (bso#15540). * Trivial C typo in nsswitch/winbind_nss_netbsd.c; (bso#15541). * vfs_linux_xfs is incorrectly named; (bso#15542). * systemd stumbled over copyright-message at smbd startup; (bso#15377). * Following intermediate abolute share-local symlinks is broken; (bso#15505). * ctdb RELEASE_IP causes a crash in release_ip if a connection to a non-public address disconnects first; (bso#15523). * shadow_copy2 broken when current fileset's directories are removed; (bso#15544). * smbd does not detect ctdb public ipv6 addresses for multichannel exclusion; (bso#15534). * 'force user = localunixuser' doesn't work if 'allow trusted domains = no' is set; (bso#15469). * smbget debug logging doesn't work; (bso#15525). * smget: username in the smburl and interactive password entry doesn't work; (bso#15532). * smbget auth function doesn't set values for password prompt correctly; (bso#15538). * Unable to copy and write files from clients to Ceph cluster via SMB Linux gateway with Ceph VFS module; (bso#15440). * Multichannel refresh network information; (bso#15547).- Update to 4.19.3 * sid_strings test broken by unix epoch > 1700000000; (bso#15520). * smbd crashes if asked to return full information on close of a stream handle with delete on close disposition set; (bso#15487). * smbd: fix close order of base_fsp and stream_fsp in smb_fname_fsp_destructor(); (bso#15521). * Improve logging for failover scenarios; (bso#15499). * Files without "read attributes" NFS4 ACL permission are not listed in directories; (bso#15093). * CVE-2018-14628 [SECURITY] Deleted Object tombstones visible in AD LDAP to normal users; (bso#13595). * Kerberos TGS-REQ with User2User does not work for normal accounts; (bso#15492). * vfs_gpfs stat calls fail due to file system permissions; (bso#15507). * Samba doesn't build with Python 3.12; (bso#15513).- packaging: samba-tool domain provision requires python3-Markdown; (bsc#1216519).- Update to 4.19.2 * Use-after-free in aio_del_req_from_fsp during smbd shutdown after failed IPC FSCTL_PIPE_TRANSCEIVE; (bso#15423). * clidfs.c do_connect() missing a "return" after a cli_shutdown() call; (bso#15426). * macOS mdfind returns only 50 results; (bso#15463). * GETREALFILENAME_CACHE can modify incoming new filename with previous cache entry value; (bso#15481). * libnss_winbind causes memory corruption since samba-4.18, impacts sendmail, zabbix, potentially more; (bso#15464). * ctdbd: setproctitle not initialized messages flooding logs; (bso#15479). * CVE-2023-5568 Heap buffer overflow with freshness tokens in the Heimdal KDC in Samba 4.19; (bso#15491). * The heimdal KDC doesn't detect s4u2self correctly when fast is in use; (bso#15477).- use systemd-logind rather than utmp for y2038 safety; (bsc#1216159).- CVE-2023-4091: samba: Client can truncate file with read-only permissions; (bsc#1215904); (bso#15439). - CVE-2023-42669: samba: rpcecho, enabled and running in AD DC, allows blocking sleep on request; (bso#1215905); (bso#15474). - CVE-2023-42670: samba: The procedure number is out of range when starting Active Directory Users and Computers; (bsc#1215906); (bso#15473). - CVE-2023-3961: samba: Unsanitized client pipe name passed to local_np_connect(); (bsc#1215907); (bso#15422). - CVE-2023-4154: samba: dirsync allows SYSTEM access with only "GUID_DRS_GET_CHANGES" right, not "GUID_DRS_GET_ALL_CHANGES; (bsc#1215908); (bso#15424).- Update to 4.19.0 * File doesn't show when user doesn't have permission if aio_pthread is loaded; (bso#15453). * ctdb_killtcp fails to work with --enable-pcap and libpcap ≥ 1.9.1; (bso#15451). * Logging to stdout/stderr with DEBUG_SYSLOG_FORMAT_ALWAYS can log to syslog; (bso#15460). * ‘samba-tool domain level raise’ fails unless given a URL; (bso#15458). * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420). * missing return in reply_exit_done(); (bso#15430). * TREE_CONNECT without SETUP causes smbd to use uninitialized pointer; (bso#15432). * Avoid infinite loop in initial user sync with Azure AD Connect when synchronising a large Samba AD domain; (bso#15401). * Samba replication logs show (null) DN; (bso#15407). * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346). * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446). * CID 1539212 causes real issue when output contains only newlines; (bso#15438). * KDC encodes INT64 claims incorrectly; (bso#15452). * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449). * Windows client join fails if a second container CN=System exists somewhere; (bso#9959). * regression DFS not working with widelinks = true; (bso#15435). * Heimdal fails to build on 32-bit FreeBSD; (bso#15443). * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441). - Update to 4.18.6 * reply_sesssetup_and_X() can dereference uninitialized tmp pointer; (bso#15420); * Missing return in reply_exit_done(); (bso#15430); * post-exec password redaction for samba-tool is more reliable for fully random passwords as it no longer uses regular expressions containing the password value itself; (bso#15289); * Windows client join fails if a second container CN=System exists somewhere; (bso#9959); * Spotlight sometimes returns no results on latest macOS; (bso#15342); * Renaming results in NT_STATUS_SHARING_VIOLATION if previously attempted to remove the destination; (bso#15417); * Spotlight results return wrong date in result list; (bso#15427); * "net offlinejoin provision" does not work as non-root user; (bso#15414); * rpcserver no longer accepts double backslash in dfs pathname; (bso#15400); * cm_prepare_connection() calls close(fd) for the second time; (bso#15433); * 2-3min delays at reconnect with smb2_validate_sequence_number: bad message_id 2; (bso#15346); * samba-tool ntacl get segfault if aio_pthread appended; (bso#15441); * DCERPC_PKT_CO_CANCEL and DCERPC_PKT_ORPHANED can't be parsed; (bso#15446); * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390); * Regression DFS not working with widelinks = true; (bso#15435); * mdssvc: Do an early talloc_free() in _mdssvc_open(); (bso#15449); - Update to 4.18.5 * CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). * CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). * CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). * CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). * CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170). * secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384). - Update to 4.18.4 * Backport --pidl-developer fixes; (bso#15404). * Named crashes on DLZ zone update; (bso#14030). * smbcacls and smbcquotas do not check // before the server; (bso#2312). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * smbd returns NOT_FOUND when creating files on a r/o filesystem; (bso#15402). * NSS_WRAPPER_HOSTNAME doesn't match NSS_WRAPPER_HOSTS entry and causes test timeouts; (bso#15355). * net ads lookup (with unspecified realm) fails; (bso#15384). * Register Samba processes with GPFS; (bso#15381). * Python tarfile extraction needs change to avoid a warning (CVE-2007-4559 mitigation); (bso#15390). * The winbind child segfaults when listing users with `winbind scan trusted domains = yes`; (bso#15398). * Remove comments about deprecated 'write cache size'; (bso#15383). * smbget memory leak if failed to download files recursively; (bso#15403). - Update to 4.18.3 * Symlinks to files can have random DOS mode information in a directory listing; (bso#15375). * vfs_fruit might cause a failing open for delete; (bso#15378). * winbind recurses into itself via rpcd_lsad; (bso#15361). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * a lot of messages: get_static_share_mode_data: get_static_share_mode_data_fn failed: NT_STATUS_NOT_FOUND; (bso#15362). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * Setting veto files = /.*/ break listing directories; (bso#15360). * "samba-tool domain provision" does not run interactive mode if no arguments are given; (bso#15363). * dsgetdcname: assumes local system uses IPv4; (bso#15325). - Update to 4.18.2 * Log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * Flapping tests in samba_tool_drs_show_repl.py; (bso#15316). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Tests use depricated and removed methods like assertRegexpMatches; (bso#15343). - Update to 4.18.1 * CVE-2023-0225: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. (bso#15276);(bsc#1209483). * CVE-2023-0614: Access controlled AD LDAP attributes can be discovered (bso#15270); (bsc#1209485). * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext(bso#15315);(bsc#1209481). * ldb wildcard matching makes excessive allocations; (bso#15331). * large_ldap test is inefficient; (bso#15332). - Update to 4.18.0 * SMB server performance improvements * More succinct samba-tool error messages * Color output with samba-tool --color The NO_COLOR environment variable will disable colour output * New samba-tool dsacl subcommand for deleting ACEs * New wbinfo option --change-secret-at * Net option to change the NT ACL default location * Azure AD / Office365 synchronization improvements- Fix DFS not working with widelinks enabled; (bsc#1213607); (bso#15435);- Move libcluster-samba4.so from samba-libs to samba-client-libs; (bsc#1213940);- net ads lookup with unspecified realm fails; (bso#15384); (bsc#1213826);- secure channel faulty since Windows 10/11 update 07/2023; (bso#15418); (bsc#1213384).- CVE-2022-2127: lm_resp_len not checked properly in winbindd_pam_auth_crap_send; (bso#15072); (bsc#1213174). - CVE-2023-34966: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability; (bso#15340); (bsc#1213173). - CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion Denial-of-Service Vulnerability; (bso#15341); (bsc#1213172). - CVE-2023-34968: Spotlight server-side Share Path Disclosure; (bso#15388); (bsc#1213171). - CVE-2023-3347: Samba doesn't require SMB2+ signing if `server signing = mandatory` is set; (bso#15397); (bsc#1213170).- Update to 4.17.9 * Backport --pidl-developer fixes; (bso#15404). * smbd_scavenger crashes when service smbd is stopped; (bso#15275). * vfs_fruit might cause a failing open for delete; (bso#15378). * named crashes on DLZ zone update; (bso#14030). * winbind recurses into itself via rpcd_lsad; (bso#15361). * cli_list loops 100% CPU against pre-lanman2 servers; (bso#15382). * smbclient leaks fds with showacls; (bso#15391). * aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse(); (bso#15374). * winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR; (bso#15413). * smbget memory leak if failed to download files recursively; (bso#15403).- Update to 4.17.8 * log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower; (bso#15302). * Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c; (bso#15306). * test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners; (bso#15328). * Reduce flapping of ridalloc test; (bso#15329). * large_ldap test is unreliable; (bso#15351). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * mdssvc may crash when initializing; (bso#15354). * Large directory optimization broken for non-lcomp path elements; (bso#15313). * streams_depot fails to create streams; (bso#15357). * shadow_copy2 and streams_depot don't play well together; (bso#15358). * wbinfo -u fails on ad dc with >1000 users; (bso#15366). * winbindd idmap child contacts the domain controller without a need; (bso#15317). * idmap_autorid may fail to map sids of trusted domains for the first time; (bso#15318). * idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings; (bso#15319). * net ads search -P doesn't work against servers in other domains; (bso#15323). * DS ACEs might be inherited to unrelated object classes; (bso#15338). * Temporary smbXsrv_tcon_global.tdb can't be parsed; (bso#15353). * Setting veto files = /.*/ break listing directories; (bso#15360); (bsc#1212375). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). * dsgetdcname: assumes local system uses IPv4; (bso#15325).- Update to 4.17.7 * CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext; (bso#15315); (bsc#1209481). * CVE-2023-0225: Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users; (bso#15276); (bsc#1209483). * CVE-2023-0614: samba: Access controlled AD LDAP attributes can be discovered; (bso#15270); (bsc#1209485). * large_ldap test is inefficient; (bso#15332). * CVE-2020-25720 [SECURITY] Create Child permission should not allow full write to all attributes (additional changes); (bso#14810). - Update to 4.17.6 * streams_xattr is creating unexpected locks on folders; (bso#15314). * Use of the Azure AD Connect cloud sync tool is now supported for password hash synchronisation, allowing Samba AD Domains to synchronise passwords with this popular cloud environment; (bso#10635). * Spotlight doesn't work with latest macOS Ventura; (bso#15299). * New samba-dcerpc architecture does not scale gracefully; (bso#15310). * vfs_ceph incorrectly uses fsp_get_io_fd() instead of fsp_get_pathref_fd() in close and fstat; (bso#15307). * With clustering enabled samba-bgqd can core dump due to use after free; (bso#15293). * fd_load() function implicitly closes the fd where it should not; (bso#15311). - Update to 4.17.5 * smbc_getxattr() return value is incorrect; (bso#14808). * Compound SMB2 FLUSH+CLOSE requests from MacOSX are not handled correctly; (bso#15172). * synthetic_pathref AFP_AfpInfo failed errors; (bso#15210). * samba-tool gpo listall fails IPv6 only - finddcs() fails to find DC when there is only an AAAA record for the DC in DNS; (bso#15226). * smbd crashes if an FSCTL request is done on a stream handle; (bso#15236). * DFS links don't work anymore on Mac clients since 4.17; (bso#15277). * vfs_virusfilter segfault on access, directory edgecase (accessing NULL value); (bso#15283). * CVE-2022-38023 [SECURITY] Samba should refuse RC4 (aka md5) based SChannel on NETLOGON (additional changes); (bso#15240). * %U for include directive doesn't work for share listing (netshareenum); (bso#15243). * Shares missing from netshareenum response in samba 4.17.4; (bso#15266). * ctdb: use-after-free in run_proc; (bso#15269). * irpc_destructor may crash during shutdown; (bso#15280). * auth3_generate_session_info_pac leaks wbcAuthUserInfo; (bso#15286). * smbclient segfaults with use after free on an optimized build; (bso#15268). * smbstatus leaking files in msg.sock and msg.lock; (bso#15282). * Leak in wbcCtxPingDc2; (bso#15164). * Access based share enum does not work in Samba 4.16+; (bso#15265). * Crash during share enumeration; (bso#15267). * rep_listxattr on FreeBSD does not properly check for reads off end of returned buffer; (bso#15271). * Avoid relying on C89 features in a few places; (bso#15281).- Make (32bit) samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Make samba-libs conflict with old samba-ad-dc-libs package to satisfy installcheck.- Remove non functioning ifup/ifdown samba-winbindd scripts; (bsc#1207414).- libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally.- Clean up logic for PAM migration settings in spec file.- Change with_dc default to 0 (for non TW builds), ADDC feature is deprecated and will no longer be included in >= SLE15-SP5; (jsc#PED-1122).- Update to 4.17.4 * CVE-2022-44640 Upstream Heimdal free of user-controlled pointer in FAST; (bsc#14929); * CVE-2021-20251 Bad password count not incremented atomically; (bsc#14611); * CVE-2022-42898 krb5_pac_parse() buffer parsing vulnerability; (bsc#15203); * CVE-2022-37966 rc4-hmac Kerberos session keys issued to modern servers; (bso#15237); * CVE-2022-37967 Kerberos constrained delegation ticket forgery possible against Samba AD DC; (bso#15231); * CVE-2022-38023 RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided; (bso#15240); * pam_winbind uses time_t and pointers assuming they are of the same size; (bso#15224); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * filter-subunit is inefficient with large numbers of knownfails; (bso#15258); * smbd allows setting FILE_ATTRIBUTE_TEMPORARY on directories; (bso#15252); * The KDC logic arround msDs-supportedEncryptionTypes differs from Windows; (bso#13135); * libnet: change_password() doesn't work with dcerpc_samr_ChangePasswordUser4(); (bso#15206); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); * Memory leak in snprintf replacement functions; (bso#15230); * RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression); (bso#15253); * Prevent EBADF errors with vfs_glusterfs; (bso#15198); * %U for include directive doesn't work for share listing (netshareenum); (bso#15243); * Stack smashing in net offlinejoin requestodj; (bso#15257); * Windows 11 22H2 and Samba-AD 4.15 Kerberos login issue; (bso#15197); * Heimdal session key selection in AS-REQ examines wrong entry; (bso#15219); - Remove deprecated if-{down,up} scripts; (bsc#1206444); - Adjust the systemd drop-in file for named service; (bsc#1201689); * Paths are additive so do not repeat paths from named.service * Prefix the samba DLZ directory with "-" to ignore this path if it does not exists- Introduce without-smb1-server spec flag; (bsc#1205104); - Update to 4.17.3 * CVE-2022-42898: Samba buffer overflow vulnerabilities on 32-bit systems; (bsc#1205126); (bso#15203); - Replace obsolete python-gpgme with python-gpg * Upstream replaced it in v4.9.5 -- bso#13728 - Update to 4.17.2 * CVE-2022-3592 [SECURITY] samba: Wide links protection broken; (bso#15207); (bsc#1204499). * CVE-2022-3437 [SECURITY] samba: Buffer overflow in Heimdal unwrap_des3();(bso#15134); (bsc#1204254). - Update to 4.17.1 * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Flush on a named stream never completes; (bso#15182). * Permission denied calling SMBC_getatr when file not exists; (bso#15195). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * pytest: add file removal helpers for TestCaseInTempDir; (bso#15191). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * Samba 4.5 sometimes cannot be upgraded to Samba 4.6 or later over DRS: WERROR_DS_DRA_MISSING_PARENT due to faulty GET_ANC; (bso#15189). * Flush on a named stream never completes; (bso#15182). * vfs_gpfs silently garbles timestamps > year 2106; (bso#15151). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). * multi-channel socket passing may hit a race if one of the involved processes already existed; (bso#15200). * memory leak on temporary of struct imessaging_post_state and struct tevent_immediate on struct imessaging_context (in rpcd_spoolss and maybe others); (bso#15201). * Since popt1.19 various use after free errors using result of poptGetArg are now exposed; (bso#15205); (boo#1204279). * Remove special case for O_CREAT in SMB_VFS_OPENAT from vfs_glusterfs; (bso#15192). * GETPWSID in memory cache grows indefinetly with each NTLM auth; (bso#15169). * CVE-2021-20251 [SECURITY] Bad password count not incremented atomically; (bso#14611). - Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689); - Fix use after free errors resulting from using return of poptGetArg exposed since popt-1.19; (boo#1204279); (bso#15205). - s3: smbd: Fix memory leak in smbd_server_connection_terminate_done(); (bso#15174). - Disable SMB1 for tumbleweed builds. - Update to 4.17.0 * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Cross-node multi-channel reconnects result in SMB2 Negotiate returning NT_STATUS_NOT_SUPPORTED; (bso#15159). * winbind at info level debug can coredump when processing wb_lookupusergroups; (bso#15160). * Make use of glfs_*at() API calls in vfs_glusterfs; (bso#15157). * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128). * `net usershare add` fails with flag works with --long but fails with -l; (bso#15145). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Performance regression on contended path based operations; (bso#15125). * Missing READ_LEASE break could cause data corruption; (bso#15148). * libsamba-errors uses a wrong version number; (bso#15141). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * New filename parser doesn't check veto files smb.conf parameter; (bso#15143). * 4.17.rc1 still uses symlink-race prone unix_convert(); (bso#15144). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Manpage for smbstatus json is missing; (bso#15147). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Performance regression on contended path based operations; (bso#15125). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). * Fix issues found by coverity in smbstatus json code; (bso#15140). * Backport fileserver related changed to 4.17.0rc2; (bso#15146). - Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update. - Update to 4.16.4 * CVE-2022-2031: Samba AD users can bypass certain restrictions associated with changing passwords; (bsc#1201495); (bso#15047); * CVE-2022-32744: Samba AD users can forge password change requests for any user; (bsc#1201493); (bso#15074); * CVE-2022-32745: Samba AD users can crash the server process with an LDAP add or modify request; (bsc#1201492); (bso#15008); * CVE-2022-32746: Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request; (bsc#1201490); (bso#15009); * CVE-2022-32742: Server memory information leak via SMB1; (bsc#1201496); (bso#15085); - Update to 4.16.3 * Using vfs_streams_xattr and deleting a file causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * Samba with new lorikeet-heimdal fails to build on gcc 12.1 in developer mode; (bso#15095); * Crash in streams_xattr because fsp->base_fsp->fsp_name is NULL; (bso#15105); * Crash in rpcd_classic - NULL pointer deference in mangle_is_mangled(); (bso#15118); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * Fix check for chown when processing NFSv4 ACL; (bso#15120); * The pcap background queue process should not be stopped; (bso#15082); * testparm: Fix typo in idmap rangesize check; (bso#15097); * net ads info returns LDAP server and LDAP server name as null; (bso#15106); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * CTDB child process logging does not work as expected; (bso#15090); - Update spec file to fix the optional Heimdal DC build - Fix external trusts with MIT Kerberos 1.20 - Add missing samba-client requirement to samba-winbind package; (bsc#1198255); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Add sysuser-shadow requirement for packages using systemd-sysusers - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979); - Moved logrotate files from user specific directory /etc/logrotate.d to vendor specific directory /usr/etc/logrotate.d. - Update to 4.16.2 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * Reintroduce netgroups support; (bso#15087); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Update from 4.15 to 4.16 breaks discovery of [homes] on standalone server from Win and IOS; (bso#15062); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient -E doesn't work as advertised; (bso#15075); * The samba background daemon doesn't refresh the printcap cache on startup; (bso#15081); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Fix samba4.blackbox.net_ads_dns_async test with bind9 >= 9.17.7 - Support building with MIT Kerberos 1.20 - Bronze bit and S4U support with MIT Kerberos 1.20 for Samba AD DC; (CVE-2020-17049); - Resource Based Constrained Delegation (RBCD) for Samba AD DC - Support building with gcc 12.1 - Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362); - Update to 4.16.1 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * Need to describe --builtin-libraries= better (compare with - -bundled-libraries); (bso#8731); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * Username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * KVNO off by 100000; (bso#14951); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * smbd doesn't handle UPNs for looking up names; (bso#15054); - Update update-apparmor-samba-profile script, replace non-printable delimiter with more human readable separator as sed can accept separators that can appear in the input data. - Fix update-apparmor-samba-profile script, sed doesn't like multibyte separators; (bsc#1198309). - Update to 4.16.0 * New samba-dcerpcd binary to provide DCERPC in the member server setup * Certificate Auto Enrollment * Ability to add ports to dns forwarder addresses in internal DNS backend * No longer using Linux mandatory locks for sharemodes * SMB1 protocol has been deprecated, particularly older dialects * SMB1 protocol SMBCopy command removed * SMB1 server-side wildcard expansion removed - Add python3-dnspython to samba-ad-dc recommens; (bsc#1187101); - Use systemd-sysusers to create system users; (bsc#1182847);- Install a systemd drop-in file for named service to allow read/write access to the DLZ directory; (bsc#1201689);- Update to 4.15.12 * CVE-2022-42898: samba: heimdal: Samba buffer overflow vulnerabilities on 32-bit systems; (bso#15203); (bsc#1205126). - Update to 4.15.11 * Allow rebuild of Centos 8 images after move to vault for Samba 4.15; (bso#15193). * CVE-2022-3437: samba: Buffer overflow in Heimdal unwrap_des3(); (bso#15134); (bsc#1204254)- Update to 4.15.10 * Possible use after free of connection_struct when iterating smbd_server_connection->connections; (bso#15128); (bsc#1200102). * smbXsrv_connection_shutdown_send result leaked; (bso#15174). * Spotlight RPC service returns wrong response when Spotlight is disabled on a share; (bso#15086). * acl_xattr VFS module may unintentionally use filesystem permissions instead of ACL from xattr; (bso#15126). * Missing SMB2-GETINFO access checks from MS-SMB2 3.3.5.20.1; (bso#15153). * assert failed: !is_named_stream(smb_fname)") at ../../lib/util/fault.c:197; (bso#15161). * Missing READ_LEASE break could cause data corruption; (bso#15148). * rpcclient can crash using setuserinfo(2); (bso#15124). * Samba fails to build with glibc 2.36 caused by including in libreplace; (bso#15132). * SMB1 negotiation can fail to handle connection errors; (bso#15152). * samba-tool domain join segfault when joining a samba ad domain; (bso#15078). - Update to 4.15.9 * CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). * CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). * CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); * CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- CVE-2022-1615: Do not ignore errors in random number generation; (bso#15103); (bsc#1202976); - CVE-2022-32743: Implement validated dnsHostName write rights; (bso#14833); (bsc#1202803);- Fix Use after free when iterating smbd_server_connection->connections after tree disconnect failure; (bso#15128); (bsc#1200102).- CVE-2022-32746: samba: Use-after-free occurring in database audit logging; (bso#15009); (bso#15096); (bsc#1201490). - CVE-2022-32745: samba: ldb: AD users can crash the server process with an LDAP add or modify request; (bso#15008); (bso#15096); (bsc#1201492). - CVE-2022-2031: samba, ldb: AD users can bypass certain restrictions associated with changing passwords; (bso#15047); (bsc#1201495); - CVE-2022-32742:SMB1 code does not correct verify SMB1write, SMB1write_and_close, SMB1write_and_unlock lengths; (bso#15085); (bsc#1201496). - CVE-2022-32744: samba, ldb: AD users can forge password change requests for any user; (bso#15074); (bso#15047); (bsc#1201493).- Update to 4.15.8 * Use pathref fd instead of io fd in vfs_default_durable_cookie; (bso#15042); * Setting fruit:resource = stream in vfs_fruit causes a panic; (bso#15099); * Add support for bind 9.18; (bso#14986); * logging dsdb audit to specific files does not work; (bso#15076); * vfs_gpfs with vfs_shadowcopy2 fail to restore file if original file had been deleted; (bso#15069); * netgroups support removed; (bso#15087); (bsc#1199247); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); (bsc#1199734); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * smbclient commands del & deltree fail with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556); * vfs_gpfs recalls=no option prevents listing files; (bso#15055); * waf produces incorrect names for python extensions with Python 3.11; (bso#15071); * Compile error in source3/utils/regedit_hexedit.c; (bso#15091); * ldconfig: /lib64/libsmbconf.so.0 is not a symbolic link; (bso#15108); * smbd doesn't handle UPNs for looking up names; (bso#15054); * Out-by-4 error in smbd read reply max_send clamp; (bso#14443); - Move pdb backends from package samba-libs to package samba-client-libs and remove samba-libs requirement from samba-winbind; (bsc#1200964); (bsc#1198255); - Use the canonical realm name to refresh the Kerberos tickets; (bsc#1196224); (bso#14979);- Fix smbclient commands del & deltree failing with NT_STATUS_OBJECT_PATH_NOT_FOUND with DFS; (bso#15100); (bsc#1200556).- Revert NIS support removal; (bsc#1199247);- Use requires_eq macro to require the libldb2 version available at samba-dsdb-modules build time; (bsc#1199362);- Add missing samba-client requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.7 * Share and server swapped in smbget password prompt; (bso#14831); * Durable handles won't reconnect if the leased file is written to; (bso#15022); * rmdir silently fails if directory contains unreadable files and hide unreadable is yes; (bso#15023); * SMB2_CLOSE_FLAGS_FULL_INFORMATION fails to return information on renamed file handle; (bso#15038); * vfs_shadow_copy2 breaks "smbd async dosmode" sync fallback; (bso#14957); * shadow_copy2 fails listing snapshotted dirs with shadow:fixinodes; (bso#15035); * PAM Kerberos authentication incorrectly fails with a clock skew error; (bso#15046); * username map - samba erroneously applies unix group memberships to user account entries; (bso#15041); * NT_STATUS_ACCESS_DENIED translates into EPERM instead of EACCES in SMBC_server_internal; (bso#14983); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Crash of winbind on RODC; (bso#14641); * uncached logon on RODC always fails once; (bso#14865); * KVNO off by 100000; (bso#14951); * LDAP simple binds should honour "old password allowed period"; (bso#15001); * wbinfo -a doesn't work reliable with upn names; (bso#15003); * Simple bind doesn't work against an RODC (with non-preloaded users); (bso#13879); * Uninitialized litemask in variable in vfs_gpfs module; (bso#15027); * Regression: create krb5 conf = yes doesn't work with a single KDC; (bso#15016);- Add provides to samba-client-libs package to fix upgrades from previous versions; (bsc#1197995);- Add missing samba-libs requirement to samba-winbind package; (bsc#1198255);- Update to 4.15.6 * Renaming file on DFS root fails with NT_STATUS_OBJECT_PATH_NOT_FOUND; (bso#14169); * Samba does not response STATUS_INVALID_PARAMETER when opening 2 objects with same lease key; (bso#14737); * NT error code is not set when overwriting a file during rename in libsmbclient; (bso#14938); * Fix ldap simple bind with TLS auditing; (bso#14996); * net ads info shows LDAP Server: 0.0.0.0 depending on contacted server; (bso#14674); * Problem when winbind renews Kerberos; (bso#14979); (bsc#1196224); * pam_winbind will not allow gdm login if password about to expire; (bso#8691); * virusfilter_vfs_openat: Not scanned: Directory or special file; (bso#14971); * DFS fix for AIX broken; (bso#13631); * Solaris and AIX acl modules: wrong function arguments; (bso#14974); * Function aixacl_sys_acl_get_file not declared / coredump; (bso#7239); * Regression: Samba 4.15.2 on macOS segfaults intermittently during strcpy in tdbsam_getsampwnam; (bso#14900); * Fix a use-after-free in SMB1 server; (bso#14989); * smb2_signing_decrypt_pdu() may not decrypt with gnutls_aead_cipher_decrypt() from gnutls before 3.5.2; (bso#14968); * Changing the machine password against an RODC likely destroys the domain join; (bso#14984); * authsam_make_user_info_dc() steals memory from its struct ldb_message *msg argument; (bso#14993); * Use Heimdal 8.0 (pre) rather than an earlier snapshot; (bso#14995); * Samba autorid fails to map AD users if id rangesize fits in the id range only once; (bso#14967);- Fix mismatched version of libldb2; (bsc#1196788). - Drop obsolete SuSEfirewall2 service files.- Drop obsolete Samba fsrvp v0->v1 state upgrade functionality; (bsc#1080338).- Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1173429); (bsc#1196308).- Fix samba-ad-dc status warning notification message by disabling systemd notifications in bgqd; (bsc#1195896); (bso#14947).- libldb version mismatch in Samba dsdb component; (bsc#1118508);- Update to 4.15.5 * CVE-2021-44141: UNIX extensions in SMB1 disclose whether the outside target of a symlink exists; (bso#14911); (bsc#1193690). * CVE-2021-44142: Out-of-Bound Read/Write on Samba vfs_fruit module; (bso#14914); (bsc#1194859). * CVE-2022-0336: Re-adding an SPN skips subsequent SPN conflict checks; bso#14950); (bsc#1195048).- CVE-2021-44141: Information leak via symlinks of existance of files or directories outside of the exported share; (bso#14911); (bsc#1193690); - CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution; (bso#14914); (bsc#1194859); - CVE-2022-0336: Samba AD users with permission to write to an account can impersonate arbitrary services; (bso#14950); (bsc#1195048);- Update to 4.15.4 * Duplicate SMB file_ids leading to Windows client cache poisoning; (bso#14928); * Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error - NT_STATUS_BUFFER_TOO_SMALL; (bso#14932); * kill_tcp_connections does not work; (bso#14934); * Can't connect to Windows shares not requiring authentication using KDE/Gnome; (bso#14935); * smbclient -L doesn't set "client max protocol" to NT1 before calling the "Reconnecting with SMB1 for workgroup listing" path; (bso#14939); * Cross device copy of the crossrename module always fails; (bso#14940); * symlinkat function from VFS cap module always fails with an error; (bso#14941); * Fix possible fsp pointer deference; (bso#14942); * Missing pop_sec_ctx() in error path inside close_directory(); (bso#14944); * "smbd --build-options" no longer works without an smb.conf file; (bso#14945);- Use pkgconfig(krb5) as dependency for the -devel package: allow OBS to pick the right flavor of krb5-devel (full vs mini). - Do not require the 'krb5' symbol by samba-client-libs: this package has an automatic dependency due to linkage on libgssapi_krb5.so.2. Automatic deps are always better. - Do not require the 'krb5' symbol from samba-libs: samba-libs requires samba-client-libs, which in turn requires krb5 libraries. Samba-libs itself has no need for krb5 (but get it indirectly anyway).- Reorganize libs packages. Split samba-libs into samba-client-libs, samba-libs, samba-winbind-libs and samba-ad-dc-libs, merging samba public libraries depending on internal samba libraries into these packages as there were dependency problems everytime one of these public libraries changed its version (bsc#1192684). The devel packages are merged into samba-devel. - Rename package samba-core-devel to samba-devel - Add python-rpm-macros to build requirements - Update the symlink create by samba-dsdb-modules to private samba ldb modules following libldb2 changes from /usr/lib64/ldb/samba to /usr/lib64/ldb2/modules/ldb/samba- Update to 4.15.3 * Recursive directory delete with veto files is broken in 4.15.0; (bso#14878); * A directory containing dangling symlinks cannot be deleted by SMB2 alone when they are the only entry in the directory; (bso#14879); * SIGSEGV in rmdir_internals/synthetic_pathref - dirfsp is used uninitialized in rmdir_internals(); (bso#14892); * MaxQueryDuration not honoured in Samba AD DC LDAP; (bso#14694); * The CVE-2020-25717 username map [script] advice has undesired side effects for the local nt token; (bso#14901); (bsc#1192849); * User with multiple spaces (eg FredNurk) become un-deletable; (bso#14902); * Avoid storing NTTIME_THAW (-2) as value on disk; (bso#14127); * smbXsrv_client_global record validation leads to crash if existing record points at non-existing process; (bso#14882); * Crash in vfs_fruit asking for fsp_get_io_fd() for an XATTR call; (bso#14890); * Samba process doesn't log to logfile; (bso#14897); * set_ea_dos_attribute() fallback calling get_file_handle_for_metadata() triggers locking.tdb assert; (bso#14907); * Kerberos authentication on standalone server in MIT realm broken; (bso#14922); * Segmentation fault when joining the domain; (bso#14923); * Support for ROLE_IPA_DC is incomplete; (bso#14903); * rpcclient cannot connect to ncacn_ip_tcp services anymore; (bso#14767); * winexe crashes since 4.15.0 after popt parsing; (bso#14893); * net ads status -P broken in a clustered environment; (bso#14908); * Memory leak if ioctl(FSCTL_VALIDATE_NEGOTIATE_INFO) fails before smbd_smb2_ioctl_send; (bso#14788); * winbindd doesn't start when "allow trusted domains" is off; (bso#14899); * smbclient login without password using '-N' fails with NT_STATUS_INVALID_PARAMETER on Samba AD DC; (bso#14883); * A schannel client incorrectly detects a downgrade connecting to an AES only server; (bso#14912); * Possible null pointer dereference in winbind; (bso#14921); * Fix -k legacy option for client tools like smbclient, rpcclient, net, etc.; (bso#14846); * Add Debian 11 CI bootstrap support; (bso#14872); * Crash in recycle_unlink_internal(); (bso#14888);- Fix dependency problem upgrading from libndr0 to libndr2 and from libsamba-credentials0 to libsamba-credentials1; (bsc#1192684);- Fix regression introduced by CVE-2020-25717 patches, winbindd does not start when 'allow trusted domains' is off; (bso#14899); - Update to 4.15.2 * CVE-2016-2124: SMB1 client connections can be downgraded to plaintext authentication; (bso#12444); (bsc#1014440); * CVE-2020-25717: A user on the domain can become root on domain members; (bso#14556); (bsc#1192284); * CVE-2020-25718: Samba AD DC did not correctly sandbox Kerberos tickets issued by an RODC; (bso#14558); (bsc#1192246); * CVE-2020-25719: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets; (bso#14561); (bsc#1192247); * CVE-2020-25721: Kerberos acceptors need easy access to stable AD identifiers (eg objectSid); (bso#14557); (bsc#1192505); * CVE-2020-25722: Samba AD DC did not do suffienct access and conformance checking of data stored; (bso#14564); (bsc#1192283); * CVE-2021-3738: Use after free in Samba AD DC RPC server; (bso#14468); (bsc#1192215); * CVE-2021-23192: Subsequent DCE/RPC fragment injection vulnerability; (bso#14875); (bsc#1192214); - Update to 4.15.1 * vfs_shadow_copy2: core dump in make_relative_path; (bso#14682); * Log clutter from filename_convert_internal; (bso#14685); * MacOSX compilation fixes; (bso#14862); * rodc_rwdc test flaps; (bso#14868); * Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal; (bso#14642); * Python ldb.msg_diff() memory handling failure; (bso#14836); * "in" operator on ldb.Message is case sensitive; (bso#14845); * Release LDB 2.4.1 for Samba 4.15.1; (bso#14848); * samldb_krbtgtnumber_available() looks for incorrect string; (bso#14854); * Fix Samba support for UF_NO_AUTH_DATA_REQUIRED; (bso#14871); * Allow special chars like "@" in samAccountName when generating the salt; (bso#14874); * Correctly ignore comments in CTDB public addresses file; (bso#14826); * Fix transit path validation; (bso#12998); * Fix that child winbindd logs to log.winbindd instead of log.wb-; (bso#14852); * SMB3 cancel requests should only include the MID together with AsyncID when AES-128-GMAC is used; (bso#14855); * Prepare to operate with MIT krb5 >= 1.20; (bso#14870); * Heimdal prefers RC4 over AES for machine accounts; (bso#14864);- Enable samba-tool without ad dc.- Adjust spec to use pam macros; (bsc#1191046).- Adjust spec for size * allow some Recommends instead Requires to be configured for cifs-utils, samba-libs-python3 & samba-gpupdate; (bsc#1182847). * remove fam, undocumented and unneeded.- Add missing build dependency on bison when building with the embedded Heimdal Kerberos- Update to 4.15.0 * Removed SMB development dialects SMB2_22, SMB2_24 and SMB3_10 * VFS layer modernized. * Add the ability to set allow/deny lists for zone transfer clients in Bind DLZ plugin * Server multi-channel support no longer experimental * Improved command line user experience, unifying the options in different commands * Winbindd no longer scans trusted domains on startup and will use enterprise principals by default. * The net utility is now able to support the offline domain join feature * New options for 'samba-tool dns zoneoptions' for aging control and to mark old records as static or dynamic * DNS tombstones are now deleted as appropriate and use a consistent timestamp format * The 'samba-tool dns update' command validates and rejects now malformed IPv4 and IPv6 addresses * The 'samba-tool domain backup' command correctly takes out locks against concurrent modification during backup when using the LMDB backend * TruACL support has been removed * NIS support has been removed- Fix 'net rpc' authentication when using the machine account; (bsc#1189017); (bso#14796);- Fix dependency problem upgrading from libndr0 to libndr1; (bsc#1189875); - Fix dependency problem upgrading from libsmbldap0 to libsmbldap2; (bsc#1189875); - Fix wrong kvno exported to keytab after net ads changetrustpw due to replication delay; (bsc#1188727); - Add Certificate Auto Enrollment Policy; (jsc#SLE-18456). - Update to 4.13.10 * s3: smbd: Ensure POSIX default ACL is mapped into returned Windows ACL for directory handles; (bso#14708); * Take a copy to make sure we don't reference free'd memory; (bso#14721); * s3: lib: Fix talloc heirarcy error in parent_smb_fname(); (bso#14722); * s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in change_file_owner_to_parent() error path; (bso#14736); * samba-tool: Give better error information when the 'domain backup restore' fails with a duplicate SID; (bso#14575); * smbd: Correctly initialize close timestamp fields; (bso#14714); * Spotlight RPC service doesn't work with vfs_glusterfs; (bso#14740); * ctdb: Fix a crash in run_proc_signal_handler(); (bso#14475); * gensec_krb5: Restore ipv6 support for kpasswd; (bso#14750); * smbXsrv_{open,session,tcon}: Protect smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records; (bso#14752); * samba-tool domain backup offline doesn't work against bind DLZ backend; (bso#14027); * netcmd: Use next_free_rid() function to calculate a SID for restoring a backup; (bso#14669); - Update to 4.13.9 * s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success; (bso#14696); * Add documentation for dsdb_group_audit and dsdb_group_json_audit to "log level", synchronise "log level" in smb.conf with the code; (bso#14689); * Fix smbd panic when two clients open same file; (bso#14672); * Fix memory leak in the RPC server; (bso#14675); * s3: smbd: Fix deferred renames; (bso#14679); * s3-iremotewinspool: Set the per-request memory context; (bso#14675); * rpc_server3: Fix a memleak for internal pipes; (bso#14675); * third_party: Update socket_wrapper to version 1.3.2; (bso#11899); * third_party: Update socket_wrapper to version 1.3.3; (bso#14639); * idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid conflict; (bso#14663); * Fix the build on OmniOS; (bso#14288); - Update to 4.13.8 * CVE-2021-20254: Fix buffer overrun in sids_to_unixids(); (bso#14571 - Update to 4.13.7 * Release with dependency on ldb version 2.2.1.- CVE-2021-20254 Buffer overrun in sids_to_unixids(); (bnc#14571); (bsc#1184677).- Fix offline domain backup not possible using lmdb version >= 0.9.26; (bso#14676); - Require libldb >= 2.2.1; (bsc#1183572); (bsc#1183574); - Update to 4.13.6 * CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). * CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). - Update to 4.13.5 * s3:modules:vfs_virusfilter: Recent talloc changes cause infinite start-up failure; (bso#14634); * s3: libsmb: Add missing cli_tdis() in error path if encryption setup failed on temp proxy connection; (bso#13992); * smbd: In conn_force_tdis_done() when forcing a connection closed force a full reload of services; (bso#14604); * dbcheck: Check Deleted Objects and reduce noise in reports about expired tombstones (bso#14593); * s3: Fix fcntl waf configure check; (bso#14503); * s3/auth: Implement "winbind:ignore domains"; (bso#14602); * smbd: Use fsp->conn->session_info for the initial delete-on-close token; (bso#14617); * s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error path; (bso#14648); * classicupgrade: Treat old never expires value right; (bso#14624); * g_lock: Fix uninitalized variable reads; (bso#14636); * s3:pysmbd: Fix fd leak in py_smbd_create_file(); (bso#13898); * lib:util: Avoid free'ing our own pointer; (bso#14625); * HEIMDAL: krb5_storage_free(NULL) should work; (bso#12505);- Spec file fixes around systemd and requires; (bsc#1182830); - Align systemd service unit files with upstream provided ones.- Update to 4.13.4 * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * lib: Avoid declaring zero-length VLAs in various messaging functions; (bso#14605); * Do not create an empty DB when accessing a sam.ldb; (bso#14579); * vfs_fruit may close wrong backend fd; (bso#14596); * Temporary DFS share setup doesn't set case parameters in the same way as a regular share definition does; (bso#14612); * vfs_virusfilter: Allocate separate memory for config char*; (bso#14606); * vfs_fruit may close wrong backend fd; (bso#14596); * Work around special SMB2 IOCTL response behavior of NetApp Ontap 7.3.7; (bso#14607); * The cache directory for the user gencache should be created recursively; (bso#14601); * Be more flexible with repository names in CentOS 8 test environments; (bso#14594);- Uninstalling samba-client: Failed to disable unit, cifs.service does not exists; (bsc#1180388);- Update to 4.13.3 + libcli: smb2: Never print length if smb2_signing_key_valid() fails for crypto blob; (bso#14210); + s3: modules: gluster. Fix the error I made in preventing talloc leaks from a function; (bso#14486); + s3: smbd: Don't overwrite contents of fsp->aio_requests[0] with NULL via TALLOC_FREE(); (bso#14515); + s3: spoolss: Make parameters in call to user_ok_token() match all other uses; (bso#14568); + s3: smbd: Quiet log messages from usershares for an unknown share; (bso#14590); + samba process does not honor max log size; (bso#14248); + vfs_zfsacl: Add missing inherited flag on hidden "magic" everyone@ ACE; (bso#14587); + s3-libads: Pass timeout to open_socket_out in ms; (bso#13124); + s3-vfs_glusterfs: Always disable write-behind translator; (bso#14486); + smbclient: Fix recursive mget; (bso#14517); + clitar: Use do_list()'s recursion in clitar.c; (bso#14581); + manpages/vfs_glusterfs: Mention silent skipping of write-behind translator; (bso#14486); + vfs_shadow_copy2: Preserve all open flags assuming ROFS; (bso#14573); + interface: Fix if_index is not parsed correctly; (bso#14514);- Update to 4.13.2 + s3: modules: vfs_glusterfs: Fix leak of char **lines onto mem_ctx on return; (bso#14486); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471); + smb.conf.5: Add clarification how configuration changes reflected by Samba; (bso#14538); + daemons: Report status to systemd even when running in foreground; (bso#14552); + DNS Resolver: Support both dnspython before and after 2.0.0; (bso#14553); + s3-vfs_glusterfs: Refuse connection when write-behind xlator is present; (bso#14486); + provision: Add support for BIND 9.16.x; (bso#14487); + ctdb-common: Avoid aliasing errors during code optimization; (bso#14537); + libndr: Avoid assigning duplicate versions to symbols; (bso#14541); + docs: Fix default value of spoolss:architecture; (bso#14522); + winbind: Fix a memleak; (bso#14388); + s4:dsdb:acl_read: Implement "List Object" mode feature; (bso#14531); + docs-xml/manpages: Add warning about write-behind translator for vfs_glusterfs; (bso#14486); + nsswitch/nsstest.c: Avoid nss function conflicts with glibc nss.h. + vfs_shadow_copy2: Avoid closing snapsdir twice; (bso#14530); + third_party: Update resolv_wrapper to version 1.1.7; (bso#14547); + examples:auth: Do not install example plugin; (bso#14550); + ctdb-recoverd: Drop unnecessary and broken code; (bso#14513); + RN: vfs_zfsacl: Only grant DELETE_CHILD if ACL tag is special; (bso#14471);- Adjust smbcacls '--propagate-inheritance' feature to align with upstream; (bsc#1178469).- Update to samba 4.13.1 + CVE-2020-14383: An authenticated user can crash the DCE/RPC DNS with easily crafted records; (bsc#1177613); (bso#14472); + CVE-2020-14323: Unprivileged user can crash winbind; (bsc#1173994); (bso#14436); + CVE-2020-14318: Missing handle permissions check in SMB1/2/3 ChangeNotify; (bsc#1173902); (bso#14434); - Adjust systemd tmpfiles.d configuration, use /run/samba instead of /var/run/samba; (bsc#1177355);- Fix vfs_ceph query_directory regression; (bso#14519) - Drop liburing-devel for SLE15-SP2; (bsc#1177245)- Register CTDB recovery lock holder with ceph-mgr - Add liburing-devel dependency- Update to samba 4.13.0 + Require Python 3.6 + Move wide links functionality into VFS module + Deprecate NT4-like 'classic' Samba domain controllers + Deprecate SMBv1 only protocol options + Remove deprecated "ldap ssl ads" option + Unify asynchronous DCE-RPC server; (jsc#SES-645) + Replay multichannel lease break requests; (bso#11897); (jsc#SES-655) + Drop internal byteorder.h header from util-devel package + Remove final code for the AD DC LDAP backend + Add AD DC Group Policy Scripts + Only use gnutls_aead_cipher_encryptv2() for GnuTLS > 3.6.14; (bso#14399) + Fix %U substitutions if it contains a domain name; (bso#14467) + Fix krb5.conf creation for 'net ads join'; (bso#14479) + Fix build problem if libbsd-dev is not installed; (bso#14482) + Toggle vfs_snapper using "--with-shared-modules"; (bso#14437) + Fix idmap_ad RFC4511 response handling; (bso#14465) + Fix panic in get_lease_type(); (bso#14428)- Update to samba 4.11.13 + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Protect netr_ServerPasswordSet2 against unencrypted passwords; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: Support "server require schannel:WORKSTATION$ = no" about unsecure configurations; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): s4 torture rpc: repeated bytes in client challenge; (bsc#1176579); (bso#14497); + CVE-2020-1472(ZeroLogon): libcli/auth: Reject weak client challenges in netlogon_creds_server_init() "server require schannel:WORKSTATION$ = no"; (bsc#1176579); (bso#14497); - Update to samba 4.11.12 + s3: libsmb: Fix SMB2 client rename bug to a Windows server; (bso#14403); + dsdb: Allow "password hash userPassword schemes = CryptSHA256" to work on RHEL7; (bso#14424); + dbcheck: Allow a dangling forward link outside our known NCs; (bso#14450); + lib/debug: Set the correct default backend loglevel to MAX_DEBUG_LEVEL; (bso#14426); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + lib/util: do not install "test_util_paths"; (bso#14370); + lib:util: Fix smbclient -l basename dir; (bso#14345); + s3:smbd: PANIC: assert failed in get_lease_type(); (bso#14428); + util: Allow symlinks in directory_create_or_exist; (bso#14166); + docs: Fix documentation for require_membership_of of pam_winbind; (bso#14358); + s3:winbind:idmap_ad: Make failure to get attrnames for schema mode fatal; (bso#14425);- Add obsoletes to libsmbldap2 package to fix upgrades from previous versions; (bsc#1172810);- Fix net command unable to negotiate SMB2; (bsc#1174120);- Update to samba 4.11.11 + CVE-2020-10730: NULL de-reference in AD DC LDAP server when ASQ and VLV combined; (bso#14364); (bsc#1173159] + CVE-2020-10745: invalid DNS or NBT queries containing dots use several seconds of CPU each; (bso#14378); (bsc#1173160). + CVE-2020-10760: Use-after-free in AD DC Global Catalog LDAP server with paged_result or VLV; (bso#14402); (bsc#1173161) + CVE-2020-14303: Endless loop from empty UDP packet sent to AD DC nbt_server; (bso#14417); (bsc#1173359). - Update to samba 4.11.10 + Fix segfault when using SMBC_opendir_ctx() routine for share folder that contains incorrect symbols in any file name; (bso#14374). + vfs_shadow_copy2 doesn't fail case looking in snapdirseverywhere mode; (bso#14350) + ldb_ldap: Fix off-by-one increment in lldb_add_msg_attr; (bso#14413). + Malicous SMB1 server can crash libsmbclient; (bso#14366) + winbindd: Fix a use-after-free when winbind clients exit; (bso#14382) + ldb: Bump version to 2.0.11, LMDB databases can grow without bounds. (bso#14330) - Update to samba 4.11.9 + nmblib: Avoid undefined behaviour in handle_name_ptrs(); (bso#14242). + 'samba-tool group' commands do not handle group names with special chars correctly; (bso#14296). + smbd: avoid calling vfs_file_id_from_sbuf() if statinfo is not valid; (bso#14237). + Missing check for DMAPI offline status in async DOS attributes; (bso#14293). + smbd: Ignore set NTACL requests which contain S-1-5-88 NFS ACEs; (bso#14307). + vfs_recycle: Prevent flooding the log if we're called on non-existant paths; (bso#14316) + smbd mistakenly updates a file's write-time on close; (bso#14320). + RPC handles cannot be differentiated in source3 RPC server; (bso#14359). + librpc: Fix IDL for svcctl_ChangeServiceConfigW; (bso#14313). + nsswitch: Fix use-after-free causing segfault in _pam_delete_cred; (bso#14327). + Fix fruit:time machine max size on arm; (bso#13622) + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294). + ctdb: Fix a memleak; (bso#14348). + libsmb: Don't try to find posix stat info in SMBC_getatr(). + ctdb-tcp: Move free of inbound queue to TCP restart; (bso#14295); (bsc#1162680). + s3/librpc/crypto: Fix double free with unresolved credential cache; (bso#14344); (bsc#1169095) + s3:libads: Fix ads_get_upn(); (bso#14336). + CTDB recovery corner cases can cause record resurrection and node banning; (bso#14294) + Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680). + ctdb-recoverd: Avoid dereferencing NULL rec->nodemap; (bso#14324) - Update to samba 4.11.8 + CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850); + CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - Update to samba 4.11.7 + s3: lib: nmblib. Clean up and harden nmb packet processing; (bso#14239). + s3: VFS: full_audit. Use system session_info if called from a temporary share definition; (bso#14283) + dsdb: Correctly handle memory in objectclass_attrs; (bso#14258). + ldb: version 2.0.9, Samba 4.11 and later give incorrect results for SCOPE_ONE searches; (bso#14270) + auth: Fix CIDs 1458418 and 1458420 Null pointer dereferences; (bso#14247). + smbd: Handle EINTR from open(2) properly; (bso#14285) + winbind member (source3) fails local SAM auth with empty domain name; (bso#14247) + winbindd: Handling missing idmap in getgrgid(); (bso#14265). + lib:util: Log mkdir error on correct debug levels; (bso#14253). + wafsamba: Do not use 'rU' as the 'U' is deprecated in Python 3.9; (bso#14266). + ctdb-tcp: Make error handling for outbound connection consistent; (bso#14274). - Update to samba 4.11.6 + pygpo: Use correct method flags; (bso#14209). + vfs_ceph_snapshots: Fix root relative path handling; (bso#14216); (bsc#1141320). + Avoiding bad call flags with python 3.8, using METH_NOARGS instead of zero; (bso#14209). + source4/utils/oLschema2ldif: Include stdint.h before cmocka.h; (bso#14218). + docs-xml/winbindnssinfo: Clarify interaction with idmap_ad etc; (bso#14122). + smbd: Fix the build with clang; (bso#14251). + upgradedns: Ensure lmdb lock files linked; (bso#14199). + s3: VFS: glusterfs: Reset nlinks for symlink entries during readdir; (bso#14182). + smbc_stat() doesn't return the correct st_mode and also the uid/gid is not filled (SMBv1) file; (bso#14101). + librpc: Fix string length checking in ndr_pull_charset_to_null(); (bso#14219). + ctdb-scripts: Strip square brackets when gathering connection info; (bso#14227).- Add libnetapi-devel to baselibs conf, for wine usage; (bsc#1172307);- Installing: samba - samba-ad-dc.service does not exist and unit not found; (bsc#1171437);- Fix samba_winbind package is installing python3-base without python3 package; (bsc#1169521);- Require libldb2 >= 2.0.10 after security release.- CVE-2020-10704: LDAP Denial of Service (stack overflow) in Samba AD DC; (bso#14334); (bsc#1169851); - CVE-2020-10700: Use-after-free in Samba AD DC LDAP Server with ASQ; (bso#14331); (bsc#1169850);- Fix smbclient crash with double free (with unresolved krb5 credential cache); (bso#14344); (bsc#1169095).- Starting ctdb node that was powered off hard before results in recovery loop; (bso#14295); (bsc#1162680).- CTDB doesn't retry outgoing connections on bind (and some other) failures; (bso#14274); (bsc#1162680).- Revert: Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- Fix nmbstatus not reporting detailed information about workgroups; (bsc#1159464); - Fix querying all names registered within broadcast area; (bso#8927);- Update to samab 4.11.5 + CVE-2019-14902: Replication of ACLs down subtree on AD Directory is not automatic; (bso#12497); (bsc#1160850). + CVE-2019-19344: Fix server crash with dns zone scavenging = yes; (bso#14050); (bsc#1160852). + CVE-2019-14907: server-side crash after charset conversion failure (eg during NTLMSSP processing); (bso#14208); (bsc#1160888). - Update to samba 4.11.4 + Ensure SMB1 cli_qpathinfo2() doesn't return an inode number; (bso#14161). + Ensure we don't call cli_RNetShareEnum() on an SMB1 connection; (bso#14174). + NT_STATUS_ACCESS_DENIED becomes EINVAL when using SMB2 in SMBC_opendir_ctx; (bso#14176). + SMB2 - Ensure we use the correct session_id if encrypting an interim response; (bso#14189). + Prevent smbd crash after invalid SMB1 negprot; (bso#14205). + printing: Fix %J substition; (bso#13745). + Remove now unneeded call to cmdline_messaging_context(); (bso#13925). + Fix incomplete conversion of former parametric options; (bso#14069). + Fix sync dosmode fallback in async dosmode codepath; (bso#14070). + vfs_fruit returns capped resource fork length; (bso#14171). + libnet_join: Add SPNs for additional-dns-hostnames entries; (bso#14116). + smbd: Increase a debug level; (bso#14211). + Prevent azure ad connect from reporting discovery errors reference-value-not-ldap-conformant; (bso#14153). + krb5_plugin: Fix developer build with newer heimdal system library; (bso#14179). + replace: Only link libnsl and libsocket if required; (bso#14168); + ctdb: Incoming queue can be orphaned causing communication; breakdown; (bso#14175). + ldb: Release ldb 2.0.8. Cross-compile will not take cross-answers or cross-execute; (bso#13846). + heimdal-build: Avoid hard-coded /usr/include/heimdal in asn1_compile-generated code; (bso#13856).- Fix Ceph snapshot root relative path handling; (bso#14216); (bsc#1141320).- Update to samba 4.11.3 + CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). + CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- CVE-2019-14861: DNSServer RPC server crash, an authenticated user can crash the DCE/RPC DNS management server by creating records with matching the zone name; (bso#14138); (bsc#1158108). - CVE-2019-14870: DelegationNotAllowed not being enforced, the DelegationNotAllowed Kerberos feature restriction was not being applied when processing protocol transition requests (S4U2Self), in the AD DC KDC; (bso#14187); (bsc#1158109).- Update to samba 4.11.2 + CVE-2019-10218: Client code can return filenames containing path separators; (bsc#1144902); (bso#14071). + CVE-2019-14833: Samba AD DC check password script does not receive the full password; (bso#12438). + CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040). - Fixes from 4.11.1 + Overlinking libreplace against librt and pthread against every binary or library causes issues; (bso#14140); + kpasswd fails when built with MIT Kerberos; (bso#14155); + Fix spnego fallback from kerberos to ntlmssp in smbd server; (bso#14106); + Stale file handle error when using mkstemp on a share; (bso#14137); + non-AES schannel broken; (bso#14134); + Joining Active Directory should not use SAMR to set the password; (bso#13884); + smbclient can blunder into the SMB1 specific cli_RNetShareEnum() call on an SMB2 connection; (bso#14152); + Deleted records can be resurrected during recovery; (bso#14147); + getpwnam and getpwuid need to return data for ID_TYPE_BOTH group; (bso#14141); + winbind does not list forest trusts with additional trust attributes; (bso#14130); + fault report points to outdated documentation; (bso#14139); + pam_winbind with krb5_auth or wbinfo -K doesn't work for users of trusted domains/forests; (bso#14124); + classicupgrade results in uncaught exception - a bytes-like object is required, not 'str'; (bso#14136); + pod2man is not longer required, stop checking at build time; (bso#14131); + Exit code of ctdb nodestatus should not be influenced by deleted nodes; (bso#14129); + username/password authentication doesn't work with CUPS and smbspool; (bso#14128); + smbc_readdirplus() is incompatible with smbc_telldir() and smbc_lseekdir(); (bso#14094);- CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync; (bso#14040); (bsc#1154598); - CVE-2019-10218: Client code can return filenames containing path separators; (bso#14071); (bsc#1144902);- CVE-2019-14833: samba: Accent with "check script password" Samba AD DC check password script does not receive the full password; (bso#12438); (bsc#1154289).- Update to samba 4.11.0 + For details on all items see WHATSNEW.txt in samba-doc package + Python2 runtime support removed; python 3.4 or later required + Security improvements: - SMB1 disabled by default - lanman and plaintext authentication deprecated - winbind: PAM_AUTH and NTLM_AUTH events logged - GnuTLS 3.2 required; system FIPS mode setting honored + CephFS Snapshot integration, exposed as previous file versions + ctdb changes: - onnode -o option removed - ctdbd logs when using more than 90% of a CPU thread - CTDB_MONITOR_SWAP_USAGE variable removed + AD Domain controller improvements: - Upgrade AD databse format - BIND9_FLATFILE deprecated - default process model chagned to prefork - bind9 dns operation duration logging - Default schema updated to 2012_R2; function level is unchanged - many performance improvements + Configuration webserver support removed- Fix broken username/password authentication with CUPS and smbspool; (bsc#1152143); (bso#14128).- Fix auth problems when printing via smbspool backend with kerberos; (bnc#1148539); (bso#13832).- Update to samba 4.10.8 + CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267);- Fix build on newer systems by modifying samba.spec to use consistent non-relative paths for pammodules in configure line and specification of pam_winbind.so library to package.- Update to samba 4.10.7 + Unable to create or rename file/directory inside shares configured with vfs_glusterfs_fuse module; (bso#14010). + build: Allow build when '--disable-gnutls' is set; (bso#13844) + samba-tool: Add 'import samba.drs_utils' to fsmo.py; (bso#13973). + Fix 'Error 32 determining PSOs in system' message on old DB with FL upgrade; (bso#14008). + s4/libnet: Fix joining a Windows pre-2008R2 DC; (bso#14021) + join: Use a specific attribute order for the DsAddEntry nTDSDSA object; (bso#14046). + vfs_catia: Pass stat info to synthetic_smb_fname(); (bso#14015). + lookup_name: Allow own domain lookup when flags == 0; (bso#14091). + s4 librpc rpc pyrpc: Ensure tevent_context deleted last; (bso#13932). + DEBUGC and DEBUGADDC doesn't print into a class specific log file; (bso#13915). + Request to keep deprecated option "server schannel", VMWare Quickprep requires "auto"; (bso#13949). + dbcheck: Fallback to the default tombstoneLifetime of 180 days; (bso#13967). + dnsProperty fails to decode values from older Windows versions; (bso#13969). + samba-tool: Use only one LDAP modify for dns partition fsmo role transfer; (bso#13973). + third_party: Update waf to version 2.0.17; (bso#13960). + netcmd: Allow 'drs replicate --local' to create partitions; (bso#14051). + ctdb-config: Depend on /etc/ctdb/nodes file; (bso#14017).- CVE-2019-10197: user escape from share path definition; (bso#14035); (bsc#1141267).- Prepare for use future use of kernel keyrings, modify /etc/pam.d/samba to include pam_keyinit.so; (bsc#1144059).- Update samba-winbind script to work with systemd; (bsc#1132739); - Drop samba dhcpcd hook scripts - Update to samba 4.10.6 + s3: winbind: Fix crash when invoking winbind idmap scripts; (bso#13956). + smbd does not correctly parse arguments passed to dfree and quota scripts; (bso#13964). + samba-tool dns: use bytes for inet_ntop; (bso#13965). + samba-tool domain provision: Fix --interactive module in python3; (bso#13828). + ldb_kv: Skip @ records early in a search full scan; (bso#13893). + docs: Improve documentation of "lanman auth" and "ntlm auth" connection; (bso#13981). + python/ntacls: Use correct "state directory" smb.conf option instead of "state dir"; (bso#14002). + registry: Add a missing include; (bso#13840). + Fix SMB guest authentication; (bso#13944). + AppleDouble conversion breaks Resourceforks; (bso#13958). + vfs_fruit makes direct use of syscalls like mmap() and pread(); (bso#13968). + s3:mdssvc: Fix flex compilation error; (bso#13987). + s3/vfs_glusterfs[_fuse]: Avoid using NAME_MAX directly; (bso#13872). + dsdb:samdb: schemainfo update with relax control; (bso#13799). + s3:util: Move static file_pload() function to lib/util; (bso#13964). + smbd: Fix a panic; (bso#13957). + ldap server: Generate correct referral schemes; (bso#12478). + s4 dsdb/repl_meta_data: fix use after free in dsdb_audit_add_ldb_value; (bso#13941). + s4 dsdb: Fix use after free in samldb_rename_search_base_callback; (bso#13942). + dsdb/repl: we need to replicate the whole schema before we can apply it; (bso#12204). + ldb: Release ldb 1.5.5; (bso#12478). + Schema replication fails if link crosses chunk boundary backwards; (bso#13713). + 'samba-tool domain schemaupgrade' uses relax control and skips the schemaInfo update provision; (bso#13799). + dsdb_audit: avoid printing "... remote host [Unknown] SID [(NULL SID)] ..."; (bso#13916). + python/ntacls: We only need security.SEC_STD_READ_CONTROL in order to get the ACL; (bso#13917). + s3:loadparm: Ensure to truncate FS Volume Label at multibyte boundary; (bso#13947). + Using Kerberos credentials to print using spoolss doesn't work; (bso#13939). + wafsamba: Use native waf timer; (bso#13998). + ctdb-scripts: Fix tcp_tw_recycle existence check; (bso#13984).- Update to samba-4.10.5 (including updates for 4.10.4, 4.10.3) + CVE-2019-12435 rpc/dns: Avoid NULL deference if zone not found in DnssrvOperation2; (bso#13922); (bsc#1137815). + CVE-2019-12436 dsdb/paged_results: Ignore successful results without messages; (bso#13951); (bsc#1137816). - Update to samba-4.10.4 + s3: SMB1: Don't allow recvfile on stream fsp's; (bso#13938). + py/provision: Fix for Python 2.6; (bso#13882). + netcmd: Fix 'passwordsettings --max-pwd-age' command; (bso#13873). + s3-libnet_join: 'net ads join' to child domain fails when using "-U admin@forestroot"; (bso#13861). + vfs_ceph: Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245). + vfs_ceph: Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). + ctdb-common: Avoid race between fd and signal events; (bso#13895). + ctdb-common: Fix memory leak in run_proc; (bso#13943). + lib: Initialize getline() arguments; (bso#13892). + winbind: Fix overlapping id ranges; (bco#13903). + lib util debug: Increase format buffer to 4KiB; (bso#13902). + nsswitch pam_winbind: Fix Asan use after free; (bso#13927). + s4 lib socket: Ensure address string owned by parent struct; (bso#13929). + s3 rpc_client: Fix Asan stack use after scope; (bso#13936). + s3:smbd: Handle IO_REPARSE_TAG_DFS in SMB_FIND_FILE_FULL_DIRECTORY_INFO; (bso#10097). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#10344). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#12845). + smb2_tcon: Avoid STATUS_PENDING completely on tdis; (bso#13698). + smb2_sesssetup: avoid STATUS_PENDING responses for session setup; (bso#13796). + dbcheck: Fix the err_empty_attribute() check; (bso#13843). + vfs_snapper: Drop unneeded fstat handler; (bso#13858). + vfs_default: Fix vfswrap_offload_write_send() NT_STATUS_INVALID_VIEW_SIZE check; (bso#13862). + smb2_server: Grant all 8192 credits to clients; (bso#13863). + smbd: Implement SMB_FILE_NORMALIZED_NAME_INFORMATION handling; (bso#13919). + s3/vfs_glusterfs: Dynamically determine NAME_MAX; (bso#13872). + s3: modules: ceph: Use current working directory instead of share path; (bso#13918); (bsc#1134452). + winbind: Use domain name from lsa query for sid_to_name cache entry; (bso#13831). + memcache: Increase size of default memcache to 512k; (bso#13865). + docs: Update smbclient manpage for "--max-protocol"; (bso#13857). + s3:utils: If share is NULL in smbcacls, don't print it; (bso#13937). + s3:smbspool: Fix regression printing with Kerberos credentials; (bso#13939). + ctdb-scripts: CTDB restarts failed NFS RPC services by hand, which is incompatible with systemd; (bso#13860). + ctdb-daemon: Revert "We can not assume that just because we could complete a TCP handshake"; (bso#13888). + ctdb-daemon: Never use 0 as a client ID; (bso#13930). + ctdb-common: Fix memory leak; (bso#13943). + s3:debug: Enable logging for early startup failures; (bso#13904) - Update to samba-4.10.3 + CVE-2018-16860: Heimdal KDC: Reject PA-S4U2Self with unkeyed checksum; (bso#13685); (bsc#1134024).- CVE-2019-12435: zone operations can crash rpc server; (bso#13922); (bsc#1137815).- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697). - Add ceph_snapshots VFS module; (jsc#SES-183).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Update to samba-4.10.2: + CVE-2019-3870 (World writable files in Samba AD DC private/ dir); (bso#13834). + CVE-2019-3880 (Save registry file outside share as unprivileged user); (bso#13851). + py/kcc_utils: py2.6 compatibility; (bso#13837). + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869). + regfio: Improve handling of malformed registry hive files; (bso#13840). + ctdb-version: Simplify version string usage; (bso#13789). + lib: Make fd_load work for non-regular files; (bso#13859). + dbcheck: in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816). + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818). + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854). + acl_read: Fix regression for empty lists; (bso#13836). + s4:dlz make b9_has_soa check dc=@ node; (bso#13841). + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832). + s4:librpc: Fix installation of Samba; (bso#13847). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793). + s3:lib: Fix the debug message for adding cache entries; (bso#13848). + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853). * ctdb-build: Drop creation of .distversion in tarball; (bso#13789). * ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838). - Update to samba-4.10.1: + py/kcc_utils: py2.6 compatibility; (bso#13837); + libcli: permit larger values of DataLength in SMB2_ENCRYPTION_CAPABILITIES of negotiate response; (bso#13869); + regfio: Improve handling of malformed registry hive files; (bso#13840); + ctdb-version: Simplify version string usage; (bso#13789); + lib: Make fd_load work for non-regular files; (bso#13859); + dbcheck in the middle of the tombstone garbage collection causes replication failures, dbcheck: add --selftest-check-expired-tombstones cmdline option; (bso#13816); + ndr_spoolss_buf: Fix out of scope use of stack variable in NDR_SPOOLSS_PUSH_ENUM_OUT(); (bso#13818); + s4/messaging: Fix undefined reference in linking libMESSAGING-samba4.so; (bso#13854); + acl_read: Fix regression for empty lists; (bso#13836); + s4:dlz make b9_has_soa check dc=@ node; (bso#13841); + s3:client: Fix printing via smbspool backend with kerberos auth; (bso#13832); + s4:librpc: Fix installation of Samba; (bso#13847); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:utils: Add 'smbstatus -L --resolve-uids' to show username; (bso#13793); + s3:lib: Fix the debug message for adding cache entries; (bso#13848); + s3:waf: Fix the detection of makdev() macro on Linux; (bso#13853); + ctdb-build: Drop creation of .distversion in tarball; (bso#13789); + ctdb-packaging: Test package requires tcpdump, ctdb package should not own system library directory; (bso#13838); - Update to samba-4.10.0: + s4-server: Open and close a transaction on sam.ldb at startup; (bso#13760); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s4/scripting/bin: Open unicode files with utf8 encoding and write + unicode string. + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + Fix idmap cache pollution with S-1-22- IDs on winbind hickup; (bso#13813); + passdb: Update ABI to 0.27.2. + lib/winbind_util: Add winbind_xid_to_sid for --without-winbind; (bso#13813); + lib:util: Move debug message for mkdir failing to log level 1; (bso#13823);- MacOS credit accounting breaks with async SESSION SETUP; (bsc#1125601); (bso#13796). - Mac OS X SMB2 implmenetation sees Input/output error or Resource temporarily unavailable and drops connection; (bso#13698)- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- CVE-2019-3870 pysmbd: missing restoration of original umask after umask(0); (bso#13834); (bsc#1130703);- Update to samba-4.9.5 + audit_logging: Remove debug log header and JSON Authentication: prefix; (bso#13714); + Fix upgrade from 4.7 (or earlier) to 4.9; (bso#13760); + s3: lib: nmbname: Ensure we limit the NetBIOS name correctly; (bso# CID: 1433607; (bso#11495); + smbd: uid: Don't crash if 'force group' is added to an existing share connection; (bso#13690); + s3: VFS: vfs_fruit. Fix the NetAtalk deny mode compatibility code; (bso#13770); + s3: SMB1 POSIX mkdir does case insensitive name lookup; (bso#13803); + s3:utils/smbget fix recursive download with empty source directories; (bso#13199); + samba-tool drs showrepl: Do not crash if no dnsHostName found; (bso#13716); + s3:libsmb: cli_smb2_list() can sometimes fail initially on a connection; (bso#13736); + join: Throw CommandError instead of Exception for simple errors; (bso#13747); + ldb: Avoid inefficient one-level searches; (bso#13762); + s3: libsmb: use smb2cli_conn_max_trans_size() in cli_smb2_list(); (bso#13736); + tldap: Avoid use after free errors; (bso#13776); + Fix idmap xid2sid cache churn; (bso#13802); + access_check_max_allowed() doesn't process "Owner Rights" ACEs; (bso#13812); + s3-smbd: Avoid assuming fsp is always intact after close_file call; (bso#13720); + s3-vfs-fruit: Add close call; (bso#13725); + s3-smbd: Use fruit:model string for mDNS registration; (bso#13746); + s3-vfs: add glusterfs_fuse vfs module; (bso#13774); + printing: Check lp_load_printers() prior to pcap cache update; (bso#13766); + vfs_ceph: vfs_ceph strict_allocate_ftruncate calls (local FS) ftruncate and fallocate; (bso#13807); + lib/audit_logging: Actually create talloc; (bso#13737); + netcmd/user: python[3]-gpgme unsupported and replaced by python[3]-gpg; (bso#13728); + dns: Changing onelevel search for wildcard to subtree; (bso#13738); + samba-tool: Don't print backtrace on simple DNS errors; (bso#13721); + sambaundoguididx: Use the right escaped oder unescaped sam ldb files; (bso#13759); + ctdb: Print locks latency in machinereadable stats; (bso#13742); + messages_dgm: Messaging gets stuck when pids are recycled; (bso#13786); + audit_logging: auth_json_audit required auth_json; (bso#13715); + man pages: Document prefork process model; (bso#13765); + CVE-2019-3824 ldb: Release ldb 1.4.6; (bso#13773); + s3:auth: ignore create_builtin_guests() failing without a valid idmap configuration; (bso#13697); + s3:auth_winbind: Ignore a missing winbindd as NT4 PDC/BDC without trusts; (bso#13722); + s3:auth_winbind: return NT_STATUS_NO_LOGON_SERVERS if winbindd is not available; (bso#13723); + s4:server: Add support for 'smbcontrol samba shutdown' and 'smbcontrol debug/debuglevel'; (bso#13752); + Python: Ensure ldb.Dn can doesn't rencoded str with py2; (bso#13616); + vfs_glusterfs: Adapt to changes in libgfapi signatures; (bso#13330); + s3-vfs: Use ENOATTR in errno comparison for getxattr; (bso#13774); + notifyd: Fix SIGBUS on sparc; (bso#13704); + waf: Check for libnscd; (bso#13787); + s3:vfs: Correctly check if OFD locks should be enabled or not; (bso#13770); + lib/util: Count a trailing line that doesn't end in a newline; (bso#13717); + Recovery lock bug fixes; (bso#13800); + s3: net: Do not set NET_FLAGS_ANONYMOUS with -k; (bso#13726); + s3:libsmb: Honor disable_netbios option in smbsock_connect_send; (bso#13727); + vfs_fileid: Fix get_connectpath_ino; (bso#13741); + vfs_fileid: Fix fsname_norootdir algorithm; (bso#13744);- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Fix update-apparmor-samba-profile script after apparmor switched to using named profiles. The change is backwards compatible; (bsc#1126377);- LoadParm().load_default() fails with "Unable to load default file"; (bsc#1089758);- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- Update to samba-4.9.4 + libcli/smb: Don't overwrite status code; (bso#9175). + wbinfo --group-info 'NT AUTHORITY\System' does not work; (bso#12164). + Session setup reauth fails to sign response; (bso#13661). + vfs_fruit: Validation of writes on AFP_AfpInfo stream; (bso#13677). + vfs_shadow_copy2: Nicely deal with attempts to open previous version for writing; (bso#13688). + Restoring previous version of stream with vfs_shadow_copy2 fails with NT_STATUS_OBJECT_NAME_INVALID fsp->base_fsp->fsp_name; (bso#13455). + CVE-2018-16853: Fix S4U2Self crash with MIT KDC build; (bso#13571). + s3-vfs: Prevent NULL pointer dereference in vfs_glusterfs; (bso#13708) + PEP8: fix E231: missing whitespace after ','. + winbindd: Fix crash when taking profiles;(bso#13629) + CVE-2018-14629 dns: Fix CNAME loop prevention using counter regression; (bso#13600) + 'samba-tool user syscpasswords' fails on a domain with many DCs; (bso#13686). + CVE-2018-16853: Do not segfault if client is not set; (bso#13571). + lib:util: Fix DEBUGCLASS pointer initializiation; (bso#13679) + ctdb-daemon: Exit with error if a database directory does not exist; (bso#13696). + s3:libads: Add net ads leave keep-account option; (bso#13498).- Drop more %if..%endif guards which are idempotent. - Drop requires on ldconfig which are already auto-discovered. - Do not ignore errors from useradd/groupadd.- Remove python2 build dependency from samba-libs; (bsc#1116900);- Update update-apparmor-samba-profile script to ignore the shares's paths containing substitution variables in any place, not only at the beginning of the path.- Update to samba-4.9.3 + CVE-2018-14629: Unprivileged adding of CNAME record causing loop in AD Internal DNS server; (bso#13600); (bsc#1116319); + CVE-2018-16841: Double-free in Samba AD DC KDC with PKINIT; (bso#13628); (bsc#1116320); + CVE-2018-16851: NULL pointer de-reference in Samba AD DC LDAP server; (bso#13674); (bsc#1116322); + CVE-2018-16852: NULL pointer de-reference in Samba AD DC DNS servers; (bso#13669); (bsc#1116321); + CVE-2018-16853: Samba AD DC S4U2Self crash in experimental MIT Kerberos configuration (unsupported); (bso#13678); (bsc#1116324); + CVE-2018-16857: Bad password count in AD DC not always effective; window; (bso#13683); (bsc#1116323);- Update to samba-4.9.2 + dsdb: Add comments explaining the limitations of our current backlink behaviour; (bso#13418); + Fix problems running domain backups (handling SMBv2, sites); (bso#13621); + testparm: Fix crashes with PANIC: Messaging not initialized on SLES 12 SP3; (bso#13465); + Make vfs_fruit able to cleanup AppleDouble files; (bso#13642); + File saving issues with vfs_fruit on samba >= 4.8.5; (bso#13646); + Enabling vfs_fruit looses FinderInfo; (bso#13649); + Cancelling of SMB2 aio reads and writes returns wrong error NT_STATUS_INTERNAL_ERROR; (bso#13667); + Fix CTDB recovery record resurrection from inactive nodes and simplify vacuuming; (bso#13641); + examples: Fix the smb2mount build; (bso#13465); + libtevent: Fix build due to missing open_memstream on Illiumos; (bso#13629); + winbindd_cache: Fix timeout calculation for sid<->name cache; (bso#13662); + dsdb encrypted_secrets: Allow "ldb:// and "mdb://" in file path; (bso#13653); + Extended DN SID component missing for member after switching group membership; (bso#13418); + Return STATUS_SESSION_EXPIRED error encrypted, if the request was encrypted; (bso#13624); + python: Allow forced signing via smb.SMB(); (bso#13621); + lib:socket: If returning early, set ifaces; (bso#13665); + ldb: Bump ldb version to 1.4.3, Python: Ensure ldb.Dn can accept utf8 encoded unicode; (bso#13616); + smbd: Fix DELETE_ON_CLOSE behaviour on files with READ_ONLY attribute; (bso#13673); + waf: Add -fstack-clash-protection; (bso#13601); + winbind: Fix segfault if an invalid passdb backend is configured; (bso#13668); + Fix bugs in CTDB event handling; (bso#13659); + Misbehaving nodes are sometimes not banned; (bso#13670);- lib:socket: If returning early, set ifaces; (bso#13665); (bsc#1111373);- winbind requires latest version of libtevent-util0 to start- Backport latest gpo code from master + Read policy from local gpt cache + Offline policy application + Make group policy extensible via register/unregister gpext + gpext's run via a process_group_policy method- Enable profiling data collection- Change samba-kdc package name to samba-ad-dc - Move samba-ad-dc.service to the samba-ad-dc package- Update to samba-4.9.1 + s3: nmbd: Stop nmbd network announce storm; (bso#13620); + s3-rpcclient: Use spoolss_init_spoolss_UserLevel1 in winspool cmds; (bso#13597); + CTDB recovery lock has some race conditions; (bso#13617); + s3-rpc_client: Advertise Windows 7 client info; (bso#13597); + ctdb-doc: Remove PIDFILE option from ctdbd_wrapper man page; (bso#13610);- Tumbleweed doesn't define the sle_version macro, so we must include a check for suse_version also. Otherwise python3 is disabled on Tumbleweed.- Update to samba-4.9.0 + samba_dnsupdate: Honor 'dns zone scavenging' option, only update if needed; (bso#13605); + wafsamba: Fix 'make -j'; (bso#13606);- Update to samba-4.9.0rc5 + s3: VFS: vfs_full_audit: Ensure smb_fname_str_do_log() only returns absolute pathnames; (bso#13565); + s3: util: Do not take over stderr when there is no log file; (bso#13578); + Durable Reconnect fails because cookie.allow_reconnect is not set; (bso#13549); + krb5-samba: Interdomain trust uses different salt principal; (bso#13539); + vfs_fruit: Don't unlink the main file; (bso#13441); + smbd: Fix a memleak in async search ask sharemode; (bso#13602); + Fix Samba GPO issue when Trust is enabled; (bso#11517); + samba-tool: Add "virtualKerberosSalt" attribute to 'user getpassword/syncpasswords'; (bso#13539); + Fix CTDB configuration issues; (bso#13589); + ctdbd logs an error until it can successfully connect to eventd; (bso#13592);- Update to samba-4.9.0rc4 + s3: smbd: Ensure get_real_filename() copes with empty pathnames; (bso#13585); + samba domain backup online/rename commands force user to specify password on CLI; (bso#13566); + wafsamba/samba_abi: Always hide ABI symbols which must be local; (bso#13579); + Fix a panic if fruit_access_check detects a locking conflict; (bso#13584); + Fix memory and resource leaks; (bso#13567); + python: Fix print in dns_invalid.py; (bso#13580); + Aliasing issue causes incorrect IPv6 checksum; (bso#13588); + Fix CTDB configuration issues; (bso#13589); + s3: vfs: time_audit: fix handling of token_blob in smb_time_audit_offload_read_recv(); (bso#13568);- Add missing zlib-devel dependency which was previously pulled in by libopenssl-devel- Update to samba-4.9.0rc3+git.22.3fff23ae36e + CVE-2018-10858: libsmb: Harden smbc_readdir_internal() against returns from malicious servers; (bso#13453); + CVE-2018-1140: ldbsearch '(distinguishedName=abc)' and DNS query with escapes crashes, ldb: Release LDB 1.3.5 for CVE-2018-1140; (bso#13374); + CVE-2018-10918: cracknames: Fix DoS (NULL pointer de-ref) when not servicePrincipalName is set on a user; (bso#13552); + CVE-2018-10919: acl_read: Fix unauthorized attribute access via searches; (bso#13434); + ctdb_mutex_ceph_rados_helper: Set SIGINT signal handler; (bso#13540); + CVE-2018-1139 libcli/auth: Do not allow ntlmv1 over SMB1 when it is disabled via "ntlm auth"; (bso#13360); + s3-tldap: do not install test_tldap; (bso#13529); + ctdb_mutex_ceph_rados_helper: Fix deadlock via lock renewals; (bso#13540); + CVE-2018-1140 Add NULL check for ldb_dn_get_casefold() in ltdb_index_dn_attr(); (bso#13374); + ctdb-eventd: Fix CID 1438155; (bso#13554); + Fix CIDs 1438243, (Unchecked return value) 1438244 (Unsigned compared against 0), 1438245 (Dereference before null check) and 1438246 (Unchecked return value); (bso#13553); + ctdb: Fix a cut&paste error; (bso#13554); + systemd: Only start smb when network interfaces are up; (bso#13559); + Fix quotas don't work with SMB2; (bso#13553); + s3/smbd: Ensure quota code is only called when quota support detected; (bso#13563); + s3/libsmb: Explicitly set delete_on_close token for rmdir; (bso#13204); + s3:waf: Install eventlogadm to /usr/sbin; (bso#13561); + Shorten description in vfs_linux_xfs_sgid manual; (bso#13562);- Update to samba-4.9.0rc2+git.21.a1069afb007 + s3: smbd: Using "sendfile = yes" with SMB2 can cause CPU spin; (bso#13537); + s3: smbd: Fix path check in smbd_smb2_create_durable_lease_check(); (bso#13535); + samba-tool trust: Support discovery via netr_GetDcName; (bso#13538); + s4-dsdb: Only build dsdb Python modules for AD DC; (bso#13542); + Fix portability issues on freebsd; (bso#13520); + DNS wildcard search does not handle multiple labels correctly; (bso#13536); + samba-tool domain trust: Fix trust compatibility to Windows Server 1709 and FreeIPA; (bso#13308); + Fix portability issues on freebsd; (bso#13520); + ctdb-protocol: Fix CTDB compilation issues; (bso#13545); + ctdb-docs: Replace obsolete reference to CTDB_DEBUG_HUNG_SCRIPT option; (bso#13546); + ctdb-doc: Provide an example script for migrating old configuration; (bso#13550); + ctdb-event: Implement event tool "script list" command; (bso#13551);- Update to samba-4.8.4+git.37.a7a861d7982; + CVE-2018-1139: Weak authentication protocol allowed; (bsc#1095048); (bsc#13360); + CVE-2018-1140: Denial of Service Attack on DNS and LDAP server; (bsc#1095056); (bso#13466); (bso#13374); + CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bsc#1103411); (bso#13453); + CVE-2018-10918: Denial of Service Attack on AD DC DRSUAPI server; (bsc#1103414); (bso#13552); + CVE-2018-10919: Confidential attribute disclosure from the AD LDAP server; (bsc#1095057); (bso#13434); + s3:winbind: winbind normalize names' doesn't work for users; (bso#12851); + winbind: Fix UPN handling in canonicalize_username(); (bso#13369); + s3: smbd: Fix SMB2-FLUSH against directories; (bso#13428); + samdb: Fix building Samba with gcc 8.1; (bso#13437); + s3:utils: Do not segfault on error in DoDNSUpdate(); (bso#13440); + smbd: Flush dfree memcache on service reload; (bso#13446); + ldb: Save a copy of the index result before calling the + lib/util: No Backtrace given by Samba's AD DC by default; (bso#13454). + s3: smbd: printing: Re-implement delete-on-close semantics for print files missing since 3.5.x; (bso#13457). + python: Fix talloc frame use in make_simple_acl(); (bso#13474). + krb5_wrap: Fix keep_old_entries logic for older Kerberos libraries;(bso#13478). + krb5_plugin: Add winbind localauth plugin for MIT Kerberos; (bso#13480).- Add missing package descriptions; (bsc#1093864); - Fix dependency issue between samba-python and samba-kdc; (bsc#1062876); - Call update-apparmor-samba-profile when running samba-ad-dc; (bsc#1092099);- Update to 4.8.2 + After update to 4.8.0 DC failed with "Failed to find our own NTDS Settings objectGUID" (bso#13335). + fix incorrect reporting of stream dos attributes on a directory (bso#13380). + vfs_ceph: add asynchronous fsync; fake synchronous call (bso#13412). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425) + vfs_ceph: Fix memory leak; (bso#13424). + libsmbclient: Fix hard-coded connection error return of ETIMEDOUT; (bso#13419). + s4-lsa: Fix use-after-free in LSA server; (bso#13420). + winbindd: Do re-connect if the RPC call fails in the passdb case; (bso#13430). + cleanupd: Sends MSG_SMB_UNLOCK twice to interested peers; (bso#13416). + cleanupd: Use MSG_SMB_BRL_VALIDATE to signal cleanupd unclean process shutdown; (bso#13414). + ctdb-client: Remove ununsed functions from old client code; (bso#13411). + printing: Return the same error code as windows does on upload failures; (bso#13395). + nsswitch: Fix memory leak in winbind_open_pipe_sock() when the privileged pipe is not accessable; (bso#13400). + s4:lsa_lookup: remove TALLOC_FREE(state) after all dcesrv_lsa_Lookup{Names,Sids}_base_map() calls; (bso#13420). + rpc_server: Fix NetSessEnum with stale sessions; (bso#13407). + s3:smbspool: Fix cmdline argument handling; (bso#13417).- Move libdfs-server-ad-samba4.so library from kdc to libs package, as it is required by some client libs; (bsc#1074135); - Update to 4.8.1; (bsc#1091179); + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244); + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270); + Round-tripping ACL get/set through vfs_fruit will increase the number of ACE entries without limit; (bso#13319); + s3: smbd: SMB2: Add DBGC_SMB2_CREDITS class to specifically debug credit issues; (bso#13347); + s3: smbd: Files or directories can't be opened DELETE_ON_CLOSE without delete access; (bso#13358); + s3: smbd: Fix memory leak in vfswrap_getwd(); (bso#13372); + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375); + ms_schema/samba-tool visualize: Fix python2.6 incompatibility; (bso#13337); + Fix invocation of gnutls_aead_cipher_encrypt(); (bso#13352); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + winbindd: Recover loss of netlogon secure channel in case the peer DC is rebooted; (bso#13332); + s3:smbd: Don't use the directory cache for SMB2/3; (bso#13363); + ctdb-client: Fix bugs in client code; (bso#13356); + ctdb-scripts: Drop "net serverid wipe" from 50.samba event script; (bso#13359); + s3: lib: messages: Don't use the result of sec_init() before calling sec_init(); (bso#13368); + libads: Fix the build '--without-ads'; (bso#13273); + winbind: Keep "force_reauth" in invalidate_cm_connection, add 'smbcontrol disconnect-dc'; (bso#13332); + vfs_virusfilter: Fix CIDs 1428738-1428740; (bso#13343); + dsdb: Fix CID 1034966 Uninitialized scalar variable; (bso#13367); + rpc_server: Fix core dump in dfsgetinfo; (bso#13370); + smbclient: Fix notify; (bso#13382); + Fix smbd panic if the client-supplied channel sequence number wraps; (bso#13215); + Windows 10 cannot logon on Samba NT4 domain; (bso#13328); + lib/util: Remove unused '#include ' from tests/tfork.c; (bso#13342); + Fix build errors with cc from developerstudio 12.5 on Solaris; (bso#13343); + Fix the picky-developer build on FreeBSD 11; (bso#13344); + s3:modules: Fix the build of vfs_aixacl2.c; (bso#13345); + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338); + lib:replace: Fix linking when libtirpc-devel overwrites system headers; (bso#13341); + winbindd: 'wbinfo --name-to-sid' returns misleading result on invalid query; (bso#13312); + s3:passdb: Do not return OK if we don't have pinfo set up; (bso#13376); + Allow AESNI to be used on all processor supporting AESNI; (bso#13302);- Use new foreground execution flags for systemd samba daemons; (bsc#1088574); (bsc#1071090); (bsc#1065551); + Add %post scriptlet to clear old sysconfig flags - Update vendor-files to commit 880b3e7. + Set samba sysconfig template variables to "" + Add required daemon flags directly to systemd unit- Specfile cleanup + Remove %if..%endif guards which don't affect the build + Remove redundant %clean section + Replace old $RPM_* shell vars with macros- BuildRequire pkgconfig(systemd) and pkgconfig(libsystemd) in place of systemd and systemd-devel: Allow OBS to optimize the workload by allowing the usage of the 'build-optimized' systemd packages.- Enable building samba with python3, and create a samba-python3 package.- Update to 4.8 + New GUID Index mode in sam.ldb for the AD DC + GPO support for samba KDC + Time machine support with vfs_fruit + Encrypted secrets + AD Replication visualization + Improved trust support - ability to not scan global trust list - AD external trusts have limited support - verbose trusted domain listing + VirusFilter VFS module + NT4-style replication removed + vfs_aio_linux removed- Disable samba-pidl package, due to the removal of dependency perl-Parse-Yapp; (bsc#1085150);- Update to 4.7.6; + CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741); + CVE-2018-1057: Authenticated users can change other users' password; (bso#13272); (bsc#1081024).- Disable python until full python3 port is done; (bsc#1082139); + Remove contents of package samba-python + Remove contents of package libsamba-policy0 + Remove contents of package libsamba-policy-devel + Remove library libsamba-python-samba4.so from samba-libs package + Remove library libsamba-net-samba4.so from samba-libs package + Remove smbtorture binary and manpage from samba-test- samba fails to build with glibc2.27; (bsc#1081042);- Update to 4.7.5; (bsc#1080545); + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193); + Fix copying file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181); + build: Deal with recent glibc sunrpc header removal; (bso#10976); + Make Samba work with tirpc and libnsl2; (bso#13238); + vfs_ceph: Add fs_capabilities hook to avoid local statvfs; (bso#13208); (bsc#1075206); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + ctdb-recovery-helper: Deregister message handler in error paths; (bso#13188); + samba: Only use async signal-safe functions in signal handler; (bso#13240); + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986); + repl_meta_data: Fix linked attribute corruption on databases with unsorted links on expunge. dbcheck: Add functionality to fix the corrupt database; (bso#13228); + Fix smbd panic when chdir returns error during exit; (bso#13189); + Make Samba work with tirpc and libnsl2; (bso#13238); + Fix POSIX ACL support on HPUX and possibly other big-endian OSs; (bso#13176);- Update to 4.7.4; (bsc#1080545); + s3: smbclient: Implement 'volume' command over SMB2; (bso#13140); + s3: libsmb: Fix valgrind read-after-free error in cli_smb2_close_fnum_recv(); (bso#13171); + s3: libsmb: Fix reversing of oldname/newname paths when creating a reparse point symlink on Windows from smbclient; (bso#13172); + Build man page for vfs_zfsacl.8 with Samba; (bso#12934); + repl_meta_data: Allow delete of an object with dangling backlinks; (bso#13095); + s4:samba: Fix default to be running samba as a deamon; (bso#13129); + Performance regression in DNS server with introduction of DNS wildcard, ldb: Release 1.2.3; (bso#13191); + vfs_zfsacl: Fix compilation error; (bso#6133); + "smb encrypt" setting changes are not fully applied until full smbd restart; (bso#13051); + winbindd: Fix idmap_rid dependency on trusted domain list; (bso#13052); + vfs_fruit: Proper VFS-stackable conversion of FinderInfo; (bso#13155); + winbindd: Dependency on trusted-domain list in winbindd in critical auth codepath; (bso#13173); + repl_meta_data: Fix removing of backlink on deleted objects; (bso#13120); + ctdb: sock_daemon leaks memory; (bso#13153); + TCP tickles not getting synchronised on CTDB restart; (bso#13154); + winbindd: winbind parent and child share a ctdb connection; (bso#13150); + pthreadpool: Fix deadlock; (bso#13170); + pthreadpool: Fix starvation after fork; (bso#13179); + messaging: Always register the unique id; (bso#13180); + s4/smbd: set the process group; (bso#13129); + Fix broken linked attribute handling; (bso#13095); + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132); + libnet_join: Fix 'net rpc oldjoin'; (bso#13149); + g_lock conflict detection broken when processing stale entries; (bso#13195); + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197); + s3:libads: net ads keytab list fails with "Key table name malformed"; (bso#13166); (bsc#1067700); + Fix crash in pthreadpool thread after failure from pthread_create; (bso#13170); + s4:samba: Allow samba daemon to run in foreground; (bso#13129); (bsc#1065551); + third_party: Link the aesni-intel library with "-z noexecstack"; (bso#13174); + vfs_glusterfs: include glusterfs/api/glfs.h without relying on "-I" options; (bso#13125);- Re-enable usage of libnsl (did got lost with glibc change) - Use TI-RPC (sunrpc is deprecated and will be removed soon from glibc)- smbc_opendir should not return EEXIST with invalid login credentials; (bnc#1065868).- Update to 4.7.3; (bsc#1069666); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + s3: smbd: Fix delete-on-close after smb2_find; (bso#13118); + CVE-2017-14746: s3: smbd: Fix SMB1 use-after-free crash bug; (bsc#1060427);(bso#13041); + CVE-2017-15275: s3: smbd: Chain code can return uninitialized memory when talloc buffer is grown; (bsc#1063008); (bso#13077); - Build with AD DC support only in openSUSE.- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- samba-tool requires samba-python; (bnc#1067771).- Run all daemons in the foreground and let systemd handle it; (bsc#1065551). - Update to 4.7.1; + Fix exporting subdirs with shadow_copy2; (bso#13091); + Currently if getwd() fails after a chdir(), we panic; (bso#13027); + Ensure default SMB_VFS_GETWD() call can't return a partially completed struct smb_filename; (bso#13068); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + smbclient doesn't correctly canonicalize all local names before use; (bso#13093); + Fix broken linked attribute handling; (bso#13095); + Missing LDAP query escapes in DNS rpc server; (bso#12994); + Link to -lbsd when building replace.c by hand; (bso#13087); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically in zfs_acl vfs module; (bso#7909); + Samba fails to honor SEC_STD_WRITE_OWNER bit with the acl_xattr module; (bso#7933); + Missing assignment in sl_pack_float; (bso#12991); + Wrong Samba access checks when changing DOS attributes; (bso#12995); + samba_runcmd_send() leaves zombie processes on timeout; (bso#13062); + groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + man pages: Properly ident lists; (bso#9613); + smb.conf.5: Sort parameters alphabetically; (bso#13081); + Fix GUID string format on GetPrinter info; (bso#12993); + Remote serverid check doesn't check for the unique id; (bso#13042); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + ctdb-common: Ignore event scripts with multiple '.'s; (bso#13070); + libgpo doesn't sort the GPOs in the correct order; (bso#13046); + Remote serverid check doesn't check for the unique id; (bso#13042); + vfs_catia: Fix a potential memleak; (bso#13090); + Fix file change notification for renames; (bso#12903); + Samba DNS server does not honour wildcards; (bso#12952); + Can't change password in samba from a Windows client if Samba runs on IPv6 only interface; (bso#13079); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + Apple client can't cope with SMB2 async replies when creating symlinks; (bso#13047); + s4:rpc_server:backupkey: Move variable into scope; (bso#12959); + Fix ntstatus_gen.h generation on 32bit; (bso#13099); + Fix a double free in vfs_gluster_getwd(); (bso#13100); + Fix resouce leaks and pointer issues; (bso#13101); + vfs_solarisacl: Fix build for samba 4.7 and up; (bso#13049);- Add samba-kdc to baselibs.conf. - Do not wrap samba-kdc's package definition into if/endif: the package won't be generated simply based on the fact that there is no files section for the package. Allows the source validator to ensure samba-kdc is a built package.- Update to 4.7.0; + Whole DB read locks: Improved LDAP and replication consistency; (bso#12858). + Samba AD with MIT Kerberos + Dynamic RPC port range: Default range changed from "1024-1300" to "49152-65535". + Authentication and Authorization audit support: New auth_audit debug class. + Multi-process LDAP Server: The LDAP server in the AD DC now honours the process model used for the rest of the 'samba' process. + Improved Read-Only Domain Controller (RODC) Support; (bso#12977). + Additional password hashes stored in supplementalCredentials. + Improvements to DNS during Active Directory domain join. + Significant AD performance and replication improvements. + Query record for open file or directory. + Removal of lpcfg_register_defaults_hook(). + Change of loadable module interface. + SHA256 LDAPS Certificates: The self-signed certificate generated for use on LDAPS will now be generated with a SHA256 self-signature, not a SHA1 self-signature. + CTDB no longer allows mixed minor versions in a cluster. + CTDB now ignores hints from Samba about TDB flags when attaching to databases. + New configuration variable CTDB_NFS_CHECKS_DIR. + The CTDB_SERVICE_AUTOSTARTSTOP configuration has been removed. + The CTDB_SCRIPT_DEBUGLEVEL configuration variable has been removed. + The example NFS Ganesha call-out has been improved. + A new "replicated" database type is available.- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Clean specfile assuming SUSE-only system and product >=SLE11 + %{ul_version}, %{rhel_version}, %{mandriva_version}, %{centos_version} are always undefined + %{_vendor} is "suse" and %{suse_version} is at least 1100- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2./sbin/ldconfig/sbin/ldconfigs390zp36 1738945413 4.19.8+git.404.38b26805d4-150600.3.12.24.19.8+git.404.38b26805d4-150600.3.12.2gentestlocktestmasktestmdsearchndrdumpsmbtorturegentest.1.gzlocktest.1.gzmasktest.1.gzmdsearch.1.gzndrdump.1.gzsmbtorture.1.gztraffic_learner.7.gztraffic_replay.7.gz/usr/bin//usr/share/man/man1//usr/share/man/man7/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:37359/SUSE_SLE-15-SP6_Update/b6fb6fd06a0afae1f83ba160476a0246-samba.SUSE_SLE-15-SP6_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 3.2.0, BuildID[sha1]=e9ffa36174ccb07eb87c62fd5cea75479d5991da, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 3.2.0, BuildID[sha1]=e94b96f68382d2d9123027e15e10c5174f02d119, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 3.2.0, BuildID[sha1]=a20db7ef68fb90f4d5cf9133e1bef3ff75280aab, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 3.2.0, BuildID[sha1]=5305dbcb09b22a37f55cf8e936c89ff890242347, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 3.2.0, BuildID[sha1]=d038081a5d3aa821c2a31b7a3cff1cf72cf89110, strippedELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, interpreter /lib/ld64.so.1, for GNU/Linux 3.2.0, BuildID[sha1]=5c2d171c24ed853888263288cd1ca2f0ffa1db1b, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)5g523,RGRIR R$R(RRtRRRRlRCR0RRR*RRRRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRRFR#RRRRRRIR R$R(RRtRRRlRRCR0RRR*RRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRRRIR R$R(RRtRRRlRRCRR0RRR*RRRRRRRRRRRRsRBR)RkRRRR/RRR'RRRHRRRRR#RRRRRfRyRtRR.RnRhRR7RRRRRRRR0RRRRRRRR-RgRR6ReRR/RmRRsRRRRRRRRRRRRRRtRpRR0RRRRRRRRRRsR/RoRRRRRRRRRR,RRRSRRCRRRRARRRRQR3RRRRGRRdRRRERRR~R|RRbR?RRRR RRRR=RR R RfRR*RRRjRRRRRRRRlR&R(RRRR^R]R\R[RYRZRUR$R"R R0R;RhRRR`RRRRRRRRRRRRRRRRRRRRRRLRMRKRRpRIRrRORRzRxRwRuRyRvRtR5RnRWRRRRRRRRRRRRRRRR7R9RsR@RR4RRR/R:RRRRRR_R RRRRR#R}R RRgR{RRHRRRRR6RRRmRVRRRRRRiR)RRBRRkRRRPRRoR8RRRR!ReRaRFR2RRRDRRRNRqRcRRRR+RRXRRTRRR1RRRRJRRzXG'ű%utf-86d52204f08a719e482928437f91468393061ab1830c7cacb5a0b4a311a536599?7zXZ !t/ 3]"k%42_fR6mH> nBh]3JiBO!i4=ru!-7Xko$'J`k-u N.MטMaQ 8ee geKB@#W%G!4n5YwvbdX7L?\kd*ԍA,<]imppdXL^dʕJ`|cu VawR)/15 ù.ł8;u/ߐ@hªWovhcW، {!&|$Xl R5ٵYG.Z?ALrߤ,8KCrΧI«E|'1[s WSPɲ5hO)9'Jx ȶ4 j[,POczSsRENoB5t K S $\QU32A _|:&դ$whL\ڧT]WD}jxy{V#7Ȧ}; 5 nإqiJr"'t9AZPyǣ5.\ݗBuN˼ip^P;*M|ԋăo1*M6^Z <<}ix*.S.;M$]`qXsKxgp{24'FMU+6Ce,?ٍFVrb.\enh?Bu~*,wADD[r=erd>jN@B!M3&+sG}ԧ> uxfXLM%Jل)< ;h‹ތ/r?޳*%e Yee{I$ օĶV ai;^g֓Noμ:a8Ak;%""I2ec8Hkcb#ydLؐ>{(y2Q7{ VS9ɍQ%BmLM'N}K6om6[T"(,d׆_aX `gd-g js$W445@qYQkiJLcTA!_l#B[4E?]XbҡYBwi#Ozn,vVjkMdZ(pFۥgb>w8Vgi US,њ4tږ|e1z :^o:xnA#vUlC?rW!XIx8^qO'L:J=L;;i,ՖLQ8RI!< _.f}o?|.½-^uѫ NZ$8ʽ7\3 s nYe[Zz g[9}i]t6#.W[<Ã|8Xsn`6&8\N'f<+ϝ Nk _׏r iykε3UlWpռXM\kk/r 7[$ Q{fbƖf/޲ j6߱𧥗Z;ՎRTMљ&:RMQwC00&^TF;ry;@5m 8:|iӲ +#ЖY*ڝ6,9ue~ь]p+=dÉBwYR{%uʟŋ+t@<P27r|.Z25X1ނ\CN#\BTS*3Ђ9S-dKpK҂(KB&d/t{|/Fm&$-AxNBjbM-:y7$v.0ڐm,5ױwȊ!bGf+n CFdqM} 埲}1[yv Yijl@vj`[hBa \ձ mj0-;c#v`z{*9 SČs>F{bT=nՉIǠ8v2)L| :)rʉV,ae:ATy_q,f`vtق93p;ϜHՐ3}٢H)O=iʖgKSo{ p?(wL`?:QT<L2';xY'i [ NZ&=L^!޾&L:I HwD<^DLb7e],8v&ԗk>D$\siZ}6Oo 2YLjEv: Qw܇s))}vLDEO'fv:P,ש,bB{Y;kq_INORY\G(Zˁ(Hl`X i-C㴨N]Y}Yw 9N8FGŪaǀlA>K2K^ӛWd,&~: OOi4R^RrKxI3ƬrCvq&J n@d:t}5$'@ӺRF.EN7 ^%b Hۥ!2 s}1-c'JJtd5#r7ܵcO5hV]TQn_fi8:CrA[4' ~r5'P @TXY s3:6'1Јv8A#n/0Is=LGJe{r!b, ^LO2`E|FR/diz$ķƦ6o<-P~eDyQ澮xD^#[k 0 DR-J+qv99M0=uUONQ.,\hlf3.T7B[+tM30L޺\؆Z{!2K|;G1sا@|JUAO;T@Ӻ!WarWN^DX5 nI$SBǥ=FWX}\EXd-(cx,pX:zwIrMP B+zh^LC1(?u+ECWQWv:fK:ԐKԴ hv'U.5M`z6c wH jm*Eav _zU028gXPb\`RLD0H;=+Um,%sO<;EfQpXBV7P9<ͪ6M&7+?oW*liI N,E}@AaaoKNۙ)oMRMz@UvqYT 6!oGV֯! l/=d~Yn$\G>j 'yΐ:ùak]ʔe Awe#\5vP9z3?oi&N`1E\1e@B?W̏1eV*kw1z()Ob / d [=$Xe:*:N87Wx#nlM%YgETz^Z- t̻@S鸬f`bZFL'(omʬ-e$QZ'-e7n$1!uk='1k`Pp.l}]d4,3^GVy&"Uka38zRc'j37+:~mتv@%BJSJh2V֣"O_bǀ:t*_B Nen9.=HյrΑwV xpCn/_Q_ #TY;~هmpP@Kgv6Ts]Sj21mct(Dp\6"(#Yԙ;~g>>5p'`'$P 绂te̜G߳_\k}uTc|ڟ˶m齡SBނ2s򩶗kɃm*~̤: 1܏,"ww՝t'9s!+ e|bp/G%fFRVV͎Ws۶okκEH`Fe+&E)+~Qb=`e_XŌ"@sUf 4ŽCk8~&nP+}>mA]ݓA>JRjI vx+ rʩ' # F0ӣ0ZS ϗhzKDyk< /cxP@Y&x;N` Oi[}s >]cb!\+ 崭NF\)ZW b0B F=ˀjx;ԞjCD\ڟn)1v8/ FIj9k! F8!Mm"D=;gRQ{ mۍ!CgYD:h7BПdT3s8ס~Z~p.q_ԋ#aFņ/{5 zF"KۯV&<ʚ-E8%ߙOe|"zn Z8D#_`/yVngJ+ IbU9 ׍wxMu_X-萕\3*~hϲr Sk `7KY%KMULou= 7Kb_-_CSC؈?#(Μ販 @׶5=l3ߡv0iK4x)(rM@_ qMzd,$Xr_,bU'Y[Ee֝u,CVuKe㪇א >RO=Oj[@cը[4p۶WW6yᄏTCT+P:с/~eoetӰ.mJȻe]m{S7 ݰUDיwAq/ Fw[/6?!>GCeͽ(]oiƵPܳaPΛWm23HSZ Fa#Jmj՛7 Bz=fy~s)i`f\}t*'f*#i>eSkcڭ.: ㏳tE1.z3A]H=U+ .1lDK 5Ԁ LmҚcrD9`@b\) ׁw(qk+He}M #jMKn> MҜțѻuGZ"Y|it%M/ZLF 9&^۽ hOkXY հ5L悪#1Qꖫ\:G5xe2n 9jǗ8| }һIakZ,&kdDhQ5l9Dra_uUg__!۽z?{vn=7K֢9-I53&b'-efG] 5\@x%Q Wh,Fu׉ZF$H}J.}r'Hp6cYǘaiN(Ħ9~zz8wЊ9;@?q!=Oc>:-GD[6f[JeUJ&<=)ZQȤm)LۻjZHng OB ?,Pfp\)bvZƜPkrA)F}W ԎR}TXRP,OR@sC1 #KXUN0 .It,|lLC9M3B%h!ɖhsM~g徾jk/S+~$_X#ߐ *urts\N~CrZ:CgZJ1JBq4ڹ@FPRUU vB^Jд$~JNSg?nﯛ1?2AQ Yҋ/ߊy`:7PTRLNrO%mwDn=ҾOҰHY~7fEYge? [eփ5h_.U]2@@ޓ4NbU8wʑ.cHr# dl4xc/?'{s*Bay_ugsXʍ?\O\˱*v[PP񠡉I^ rjWXmBX|Y!6( $xvpO)f|R+Il_a9cJ%"ĔHݥu'ֲN]TUC Gq`?^%fru">mïQ1T6Y!wms!C6Ǻ{#k8] N>%P#.@BYaV>}.gB}/!,*^9Y8rG vMɮ4,> =,~əmKMB- ~Q5( B_崛:m|ȯk̐QŸx(t5P[EEijKT5rIG;鿶j[!~OeBBBEC&.٢ 4o;C>~䦤"O{gP9MDR)d L5Q 45Ǵ;?+ UHHX >xW~ktjz+~ŻoMĥMNJ^Tb 7=-U׍\{2MTLa ŋFET+G9jk2r7iqdCqx&#:9tAU>1Ry?Z uwr1yƝY~(ؠqƈu5R4 #($Y s0 SNm=ʒ:޹>:J/Qåu&ES/wizx0MF>lx :Gӓjr|bF0ӪalhRYH[Gn]|#M$xɏ|l_xcdw%Յ>!'WSJ۲"Т;4S{Sy̳B(YWj` (HI*W`~ j/ku]SjlkJfO:@hH E\6pd>ox~Jo`QuS 'tFi-ˑ4J?]vw ^Ix_EyF;v'qۈ4iC7\u[Ϙ!( S.OmrD35cӧK "-6{KR{҈ }A׽_sct ;ǹIMN;nb2'wV-r#PlD-fok!+PKZ9a9 ~OX AXf-%~pFŸ+䀸IFC4e.@kG/EQp)̮ ycֈ@WEk{䱶{eet]dѰHH( s:_#OSt-̫wh {WN\>]FԇlkXsmHz5YKAoX(7=\^ Ghߕh>ї0iϝXicLLF.O=_gI>(_kd&*Rt#.(g'C g~Qk=U{u= R;*#,^0 ox׫fz;7gF9N܇(>1X/Y`, >Gx8a'Jgdr݆'ʛ o TPqucg @ilA7yF30 lBTMͥ 7pՂA.$89|C$B)'Gy(Sva%~mi/LVΓw`#AMrҢ+ڪ 3^MӁN)bY5n8N+ל9df(SԻdJrQw*U O̵;!V.m}-CK)/p}\&>wRǡkSCYxKN=6'hJa6AZC2:hh=Xi$(gݛ΀eu W4SHs~xu?J^Љ^kPMaӪW?&ӳ [Uk!H}>.F `Bϔ?52ԕ}d7M}O 'Ye5B]MNsXH GOctC8Ct<^6-Tvhmq=n e{Y$cGgHuExm:9ߋ#H54}f8d%/[ J%lڣzd ?7(vD+ei׏N59 F(` FF]q?㋣_%*?$>-dmtOA$IHOAl8=~&cD_fnQs?,. 3ҩƯm/eA:nͩ tq)X*b 1L S(u~ͨvX_h'8ȧ~HWZ7M2:ݲ~T!Oh)7n>2Bl %2| %6>aTx#x!1a*  9T|l憳eE~FzhkM?CIH|RCZ$ړp) U߹]*T)o,5[ Sw ^ }F/PdXnZS$al)_>OTln ["^& o^EhLJMȷߙ<m؀cKl Og@߀Чzʘg9g6ZjQ$e~w%b9 0~@?qZPUpB,P? n+B N"ӯByqJ;oV=JjhLT iI.6QPїɑGdtsO6LHR;X>Bϛ!>E TQҗrNE}\*\*Q d; ̉1BM 3HVǛ̘ͭպ_x#ӄWN f HG|ڳN|_;<{vȵ|ϞeVV114s8״:#ѣIXk9UۜKT /_4׆,׸2c5zMkzJԷܗ%P ӗpٰٔ<̻l0؁dכ g$e& E%asӷڰ۲a̸f5(謔Wqul6+AmOTFK?š5pA .sKqe+FM磊;\DʁdH~1,7{rs"6 9e䏩!hwBR~>" Z q~֐*7UX$u拖B GiȢ|ë# AE[G;6T  r@ATp%BI<\0{pbxRٱ2]1a/!2zQpOԞ12v p# a hnNm⦗g {^h}񫳴#T;o䅯?b˶_/Wm3/X>!)(%8uk:(tfa @+X9MJIЀ?u'P<ݣgZNx%0'eqŐ#eRf䩨e'L z|jZKۇ瓙&rkWi}<#]#Zv>0x]P/"?O[&C0E='*q+)&.U =<?V.M}A,t=G1 G wRY(EBL¾>'C8Žu2 *TI_[`-&.ʿð጖=Ѹ+Zbª3*_GV,q(qwq}>St/+9j?RCBΞa5Ζ Lh^iKa6Z`4MlKkmb<jxXa;(oni69|sB)w)"۞&gJyd>jtᵻXPV ]'kV-x;!ʛ١R@6!.{'ˏ\3al/bT*T-\6hBe#E ֣JWʹwJTw6сw;ɏ:9zuUf4&FȉmGqV͹x. RkF?!!o1KoC^Lt3榮uURDpaoh԰/]I`AMG6DRzߤcb%ZoM ~rU\ϵvaJx0rHc]lܩ./TPB^sjLWa&%'[90mZsÑUiQҍU y[Q|\.'!BU_ Ip$_e. O,w)I|bL532Jt;@ >~DqWǜ6W1>/CUdHL~e`6[#h3 Lt}cMn d~ vǻ S3 Ȍ@!RulQ-` =8>;ЧגWj+ Ps$8 a]yKY3cj|M/ܮ1 E!ФrB"C VVLr.#̫˛s/!ղK1uC )v'Vm}H6 %k.g;P Dxje/aMԑy }k H_軽8[oOK%(;G (!h w+}›lX"%+.׺;O2â vT7&[hŠ =hS`G9Z('ݛNUM], | QyWeΟU'œyJ<.sdޚ%܀@z1Rk]0 p yIJYP"Q<7ww SIߍS+\2# 8Xx^· L~O2棑\%ɪƻW5O3@zSMKdnyF+*Ϗl yVFOVH !'Ώ cv6f`zN&׷~GxbńAoeBPnQ`yncLڭ0MZn^yi#5%QKUI{_Ga¢B\Ǐ'4VGB SˈwB|b?5N0ib2]r$qGOng 1_cb! Y;^иw(ϧ:qJZ$Pj^8P}-݇:*L9:oȠ]!F*oV@@I'\ng͞ՇՊoHK)j9ެÄ{;[ Un6\).3ޖi%"oKMD*?L'XsgI~hm`@͂D2֕%NJZ!/,:bk?ZqNPl3nJH=oPݍ9Khp% D\spfo6\+.=~p4hd3]dXzzܖ'a>q܌ Oе0 ^U]'ҭU7^<ڴZ0-wrt|75] e}@>#)q+svv)d ,+%Oξ/9$󖤃^-Rorv1(S@faa |eؚKHAZ2~bvsMI]TUS@/K9sAKΫIJ? Fٱ2⭼ m å"{eQxi>z=&W!,Z i{n1;CuxSZ>ElC%(X2Y^l5 ͭb3<S2#^:FJ*QoG!VC$LȀyk᰿CG4ȉj: I*W Z~[E<hP |a_֞C7BUGv{ 76?֟3@QDbeĪf41ic2mzئɨ xPd=!1JWCkۚCg2s꿒Ї3ѓ۵C<A? w$t> .|p=M^5g%~+:(BWlwv<صiC5ӭ$k\MWcЀH{T hk)6 {D`Sb HSp1H˞ELd{=NlQǩ«`MoG/yǿaD t8=} J##~0>gt 澰K@E 6jn#X!Q+'S OIȧ%ʏR4&㯮}ɻ NVC1<35[W&$3~bsv.00Q.Vw_tLtY8 h^==)glU$c;SV_7rH _`Me}ɍn 5_@ capZW#Jvg=9?+fyY3`<#<Cn n1Ѭ U6# 8Nj; #>S>8^7-}ZH 0]bd9G;{Xp>FVJ&_<d*ϵ؛#GbŇ?L l%{t%v5S ,r5F>?uE cjb*EМ!^X0O;{Ihf@LYK % X{56f<#@qB5-B^^>6āKIc u;=;CQj[K7PSdi=לNFI\НˇLByaߏL<2iq(܉ZED;#Bd/`Kzhp]Z.X -ht!i+JU-wCI2i;cպ\S?ʵUJ6ƓA!4ͭa;gGz!+8)+uI;M&],Cp qa 8[آEq-Q4ۮCi9ii)nᗥ]D@8 [ybX^зUf$kaߓ._!!Qն.+t $>ЯHN3'\ jJG1('O2Zinhm9ǭ1ԍ$5ě鴺l&PY9u/^:/w*Sx/β(Kiui׫˴4ˀdB^䬣+5{oP<ؔ^xW*#.[mG'OdEMFB@9! REBL0s啿 g "vFC!~;+u᫨4kBK~ݸv¼Z&8 g-|@Sdkτ ;0kgR:,/6yG{YcA%;, *~͟ 5%>B6$Z/O{7WbNg4Ǵt j[xd,՛r;Y! n^@hxM@bꪇht'wn?T-;5¯<-]ٖ.wr9/jn9H WC|RNa=Qd:ew5]YI#a"ɜW 5 8a1li谓b;e7|X?hO¡ AuvбV7b_.5k(Wtff32qҏ}B7ѣJPb.fe((4om1Q}vڽUP8ےԎEљpUf3k~Q،Mh`Ƨʞ3#c{"(Mp@#1 /a}"rhJhj!jJ{$3&jWQ;LLu#. kXJ5iK?Ho2@dow`}8[%5L8 5zyV]!BҜ¿U<}aA - u|N?4@I=kjӀQfE47*iZs_ڳv̦RDeCc%esxsP7er>T=ȸG|hPHzqNu.sFASXi~ٍWK)c~! 1yf90Oo#A4QAr8F$,caK&g/I% dhHvbH{e78Fw/șEғUDW-d=GްOZ}Z|ҁ!RH QE,m-ڵ6gRRU}q(鷛M[fB[qs>w"Т={k@6 QσEmz[Jv_~ iyw5mvRŋ RD~h @tϡYaw3Wb%j/?huaʤnl oJ0b_Aĥ1i=Qh2+wyfXSEo54jhqpZMߞ{1!дoQ&c(}1#' "Oc1\%뵀"vL1P3s({\'kqYG/jt 2u6nd_Dɝ Z tVq(2`9"yF&P|²T%"SL I,!{B2%jFvq`#笵'sF1qaU90CsȘ☊>_dScbr-,ge\ɉJ;Ao#&,]5P>\z[c2;`kk>&uka6wJDZ~{1ģ}>JryAGl(K, WRdjr_^amsSg ȪY>ײ|zR+i.:=͔ T /V܃hy)gs{rN1M#0l.+QxrX#gPׁW (%\/XϒJp ~ HE}T\3 ݔmse.R]hFHXq[e SŽ};.Og6+6gVdD8'`}u>>V džK N]4go+hi]/X# 4쬲;2! * R_ ' ,d-zm *%mZe+qQl{lɓ,v !mΖ6} t$e'C'`" ΡRI|ΤcTf wi8۞L/QG> G^yu>G4z %ۨ- ,Hg%99G*{*b=`$ypJ N/eP—+[Vd&/zsyUjo(sZ[s;4m[)if~Ϯjed!r- d:C݋<}4A_N]lGV[EEH<3TU6? I/7%Ct z|d(އkւvuM#AݑQ::͔:6e(vZJk4+iM)ʂCA梉탬VYg69jCۼ;j1U S(N,qY \cxȅAQ?þ 3KAtv-0P宧Ļ'wqbo.Eap8Sf<¿Cc  yTjƊa<,]Oh鼍-h=7^*er%j҇u\ׅ$2@.quBB%"#MijJ 雜{*8z-ym҃lVʨ}V\;CqE$H BZi)=sSy:,F7RK@-" kS5ig zs3J?V~D\} #qARC8ؘ(ΈjaLؤMy?aO) KDn\_YL*.BwX[(Xlri#a K *pۇ<,bv]cĭ:gN5eYuQttʟ`4ٲMEq=⻍ mBVUbv{aYKũ+Rƛ`m;:M3Ap҅$ W|}HZSu)Ui]pO3|vVpm%ͣ8 D\i6$*{Ƈ'YeVdٳT9WT +*+WH$DH`TQ哞zo8PwDV-gB9J| ŊM;*+6$$1k=tNp8nȷ -DЉK%*Q@+?\ eZR{K)zz_.ږD*Es (D[Z"zuN"I2Ʃo$#li4x4YR SQ ~ԧ9BZ;4-Fc,9#гT>Os@A6?F3zKl+#aTODf|_ @EYa,c%/y߿:Aڗت<<mP v&>F I;<hlܹ=X\7g\,LeB:Zխ )Eu@3&9w II?L۹ep+ïXB]^_5} ve1:[v[xAiV!WezBU&Jkv)@%%Vs?FNddVS\/\ (fq*n^qTҩOS=uI3oo{qE*IL:g>M^8<ת肢Cm]튚j-P"C -3\,CExO3u&%aV mv)щt3"W5,bvi "6>bM=>B|K"L"%L7]QU)^B8J*9J'竘~%\i.'0vXwtzR:zoLEh!)8.ܡZHDɍPx3w/>7ZE΋Ï78nUYR4sz7EU"iδ&z;?+Pm*sg =62a2$v&sxVTdl#?ʘk`~*q톭Hڅb6!Ll֘zݶ|?FYȔNx𪑁瞁ˆR3ڗ2?éejix#=;u8˪C}t*ͨ~CB۽@^Qkpb5!D *062DeFռewQ><4ȱз]4Z- ژ[$G-U(A0F(7"GGM#[B_om4nPk|C1Kh8^ى+`j&%V{Z[$M:2Yt?PK,`Qd5|9+VEy#=Hx ,!=mfp n664r#f3@zHb<6{Qp ¨)x@H5YL|:=7rMOpNZQM" J$ is[ĘJHB9TkxY_jU29'Kt[ j#ɥ8SL*#JQP OG_U1=j;h V+yhHvT)^|~/ 3o1 ?=P2pR [͈KHuȈ O1_86_^x6(|*:Ow2 j0 ah_ nڿ8;ؒDawkQXgwIh`fƠl0S:-'w\y_W1}xo0f  B1$s;'>^|\׍SS>7ZIf-ح4XNNNuĹ9&NV+虐6D!ʴ\6@t 8v cx|mN5tЩW'$oTgA{C- w5럡b.2>Z]z`:6܇%-]"IgbX jOX6OQ@9bPPM =slj0q4mvk)x…m*WX(S9?C_eQ _#GajL]ckɪp"+L0Q7|ħ:zH)Ad4%a=څpp۰2p26V4tA]~_3S IIΊW/ny[\u?uXBip=ghbf\h0>zGDvQa'^E~,%ˈ톨!@$ A79ӹQ$SS5ctY/dLn7Thxg8\pHk/a]̯s$mAHb8yjGFFU{̀'ߥQ;_ڗ,&"WsSQ_/I5 G]ڥ]6Uy `[W\5Ò_(X Dn u;NQyWѱ<'O#yT y oNR}G*J[8i 7Aq%-k$&ľt2 4XK݇n҃/(^Ŵ4HCjysX蔇iZfNuP3v1_2*Dh#ćsZ1L>3c֙e@%߷bO]e0^ K호pwq 0yذ I\Or1M2RG2DѼ22;b!>pdGYi#@-*54ՙ'v̅zD?]Yoݹ0E O *44kb&_C+}Vg(6I)֮9>TGr7 Y8t˜]:)^t+OGYwI;\C$6=ƦfK*g4Ljc9 XXQ,M:UO: 3s5c]oc"RRQ ұrH !TmfJb1fxxWŧGY^0s!#Gt_T NJ>ל9iK/tx(L 9T^ݫ4t ],ɵl]T #8$sbYvS#)- ~6eIy؇%0MBBH&C۩R+hܼќhbk%ʳoGH=o_Jt#@$`{'a&-s cΙٕ%"3|}Dca+} g.|N!ʧ~ac|6k l)|%XTliLr3]*|{9cq`zxigUI `oYDN411.Elww}!Wsv<-Uoz5qt//2<V>CG R. ]7L;!֡ydi@ȬӹPBNoG6ё#zZ%~xU"U4s⩘ 4Xv[?!i*@ #qw]`ٖl  =A$YMiqΙv?I--5_S7^R#Qt0Md`nUzuΎ`6PڿXq^a I.Vq7eXӤs5xxP',bNaP5UxF0E_2uSxŒ!$:*a%no?7c6Ō@UX |3Wb.WV&9al̾C!ƪH>Alg dW숼9@Ch\yn\3o@n*|ۼ%6=ADZwV+" zj6m]Dƪ鈽!g'A+3^ RQ1]IDW:.QmyvE9FA #˦N@VRR|U^¼0yw[輦=t~zG>O}: /.l˵1crfjM8DC`40B|8*9 vx:4ɨj%́KaݯBB9\,+owuB.$pC# #0Ӣ8f ѣ}66貱J)As-8FGydx#׶|ut sd7E ov5^q+±(yC$pb"r9J-IUl#wDBFkc6fu{ M . 5 4zD.k4% op!|`MaF*d-*Я*)>"a]|yOzb u_D2cA t `VbQ 5<]#߭aJ]aȋ!ZZdk"&hq ]ƆUg.(>77 $\, 3Eɑ6rsG-9Շqa>Iȭ7v@ٿ_\5昜YNe|g8-'WS(ZpvcJ 8ҟB׃OqIA<ԓ>ه*E-wNlp?a;IԻ_ްMlYs*!I 6!O5y& VxY~~ KjK@P0wkn*Jx{PA[I[ =MJ#d#{/:=]"2f.t@xAijHrO&ǧUnXt) ZaQh}bv s s[x5($Mj`akw>N GiE?75Q'b_]*׳/hζ!t=YIA%RpL5.hk9]WPn2ύ ԩv >gO-|]Iv9p]G0 SK'Ӣ VrÄZlck4"\pL<-¬&bauφ =HdU$ZbkWJ߁R"Ҥ[_&,Z?pB`g]{3Q0IƠo];s}XP0ڽ(F.~)aa0;Q |4 1M Gb@4[놧= D3uϰi_ zϖdr~ƻ.їA1Mh'lfB1I#E#O((Ӟ_9&;J?" Ҏ.!4.Fg7e(J=kÁe`!3,%RO6 9{mb6$RpAT{j^#j`%8ww+L]8+R%A&Z.Z9sxIG` 뛖φF ɯSL ?I}-2ζȓ#g#8~#q?Aid̂UzT1":s4vl}c"k6|,a-Ω)*-?*IHVT `E?W׽`7/U9GDi1>Fpɼ:^wn϶)d/[%MhxeOcT4OӜC"𔢜 sI~v$Y7O-qc|Mi1BwSAHJJ|,I[ Ej"4jk*+d^ؿ0ӑ)6_ ԓdxnT@D:HȨ* T,l?vJ蜵9fJͼLLYRvĖR oUrp?XU4}|][)wB. j3#Kv(& ?4ĈUʵ`j%v<%iqɨ P,4anP-]j0e*;<9>3$ },.]fL6Yy0^Eom^n>z)u;IT5!\ǫF0FPnn;tPSCCuO7uCQW9Orx`%ʻdm7i᪇+zLbZ;md7*yD0M ʦoO'lld=vVjr-LA>4[ Ј Qv@˳<9-g<:M[^ g.ڑ˘ML-6h*ECv܌䬓(XAOG|^}6UF)dӠOnF Č1.S645He^oJ*l=v Y(bSn-H0!^$󊣤Wm PD=t ȡա,aHӬQd{pih5Rtu9I/kP0PWH]Evhm7{Z Ji퓹m`I`rάXVUL$(%lbM`{ļHg; Pzy:Ƽm}[mUG=Lڱ).=d"OR ΊV-D6mM M5R0&xoeevI]/ɿ@E]N7䃲 Ͼ <ԨMxDㄲ`wD =cmI Q&R֤])Q/n2y7T$ 7NynT$6$LD(NrihZA ħX_)h,{nysds < Q"{츢+_]8cWa|LZǙ$&fo.nJitݵy(YE`E6Ei4{{:86.f^A"I+pRCd8=vTu卮@2NᡚB{E? gxDζ,~zL҉:1>\uRqPVvy Rp pωsC=\EǗHS]ZFWmgr ur1Dz֗% Q@uAꊵXm6Es+g!whwV33b+pWRƠr$EsrUן&xt>U`.:W?nW".:1eZ+fz-%S>t;z0薔Ȑp-N"›vA\x|E'٦I[Z:hȷ yT~!ҒU3_! E6oZ^"b`(`'1%qU^WJSl62w`=޼ܾ""ޅ/^Ա1ME@m )٭DJ_Y#_F+*J\AG!d?U 8jA2iEGi@mN1˃ޫJjhڦy?I~?y΁}kMIRΊC&C %Eqሴf;'MQxj~w'RxuNv-,\Z*q>f; iZ•[GAaKW?_fC:ݗy h+:EG =ӻ-~.>=EY@8ZIj90D}u5J0w_%))Y0 ӄ}juĹ?8&qK/-NlAJØ]$@HvoQ oҟp7M%Q7Ut{e `{QAo [ !lO[[UhW\l# iN0N=MIqg4ݻ)CCƒIiq#TlB¶ȿj;^*su8bK'MO!&+ _0Eph$C*/LXV9o{@ FY¢gkfgWuzW+w@h=4qβv~@sZү\Źc&c7jSK u'~C'W ;nrz֓\khܓe4t=j<WՏ\;P5Ԟ8eNb[sݰ(Ih1&hgv>bHٶ@J4dk h@oH,͘tkBJnƉ}4I16IsaX-ՇY+Ni;lG:&̘2d{.\aL@oZKˁ4͓s)TtD3O`upH}7mVBuQHp3JmSg"%7aŸBXr ž͑nԠG~Ҷїu]сˮ'Xko혀׺u7a-2\гNXg6TFoZOwA &Ī8]e1?{BB?CyF48V;7}R 圴,p2F+!|@_r!^|1Yu;Je aEgn@X2U9w\v(xO/W'`@%OyQEɟ~壈Գ6/CT{7iXwTP?4:8_4Y*A@o y  0=z<{}"pd4D1# `)p. ;I+|Ha"|k;MM=|!=E5ѶH6TŮiZASlhVu"~AvܮoǪT)x8p](j/͚2#:xuq- *ax[jee=G"o W#7JO#ذZ:ե_F^H&te!y迶,lW}8Xd~'=ւGk :qN")(A71t{=cci7ߖhw.p"!Y=pR,OU_CהBVW8 *h[_U/ z'q,%Sy!,LP7ػ#sb٤2,*ƹe"%܀Kq"XH~ n,Ət-p79ŚkRX9rU?n8-&4S17mzޝ1vp if>lDR6fu`~~/vyjX*Wq$NjGm6Wr?P{G^MDZ_tYqNx|mWިr>c]̧_V򅱚Z+llI 7fOYAX +XUa$)mNuPZ3EP6sxOF8Ւ ̍w27C؏./qu}]:Df{vFBr,i`47)܎ [nrA-E.p~'QdvAD%[t ;ZD1u&Jaiw- G/NIwkbkIf md0Yx//++u‰юUҶpQsjڤjChnǛN_xzUmO_?{qs/]t oh4XvVw^@K#2>x:)G]P=!.wGW<3yϨ2 r#ebM=[mabšeeU>Q7>52'|ۅbY1J|iHE0e|:Ꞇa6 o{IQ}Ȼ_.-<.l.rBИ {w؇G0+f[ۄIؖBgVyl R@l/bgz&nǀ|Q$4}\Ɲ n(j(A5VsZ>m21-\-a`!0zR"Iw({Wk mD>_ :>1.t*vNkIZ0~(a"fH7mou9R3JB1IiF<-l[{ q ~ƃ]ȡ-Hhm-C֡߈Ɔ+}WxQm;^m:zPt\yARf?;M9[H opgG?ÌV\Tvkj;m0\)RV5u^)L9wǡ XJ¥!mNV;usKnXİoM"J^/&vnF0o g' TV!lWu ]#Xz}Y.KBrGG$QIi9Q e ɛs6}LaV 0j'Gd : swb7mlZx">Ky zJqPZ-d̿ނā)،`c:Z#Jo ڼ'.jP\X!gi^\Oqg&3c6}(SesMOIsDBH3@\&s詒W`*а^nĠ{V>6nyI}_=O}a(-8eY։j3IELbKݼ@}JkCZ$7?:A!xz=ROPW3̑ی鵞BKS!u]n@nuŕڣg)GIňjRH"v r:ji]t[9?r689^{J@=P|Ei`rYVu]NflB-KL0]̖rVR[`*&|W- w+-e;3/^277m_I eHp}hDyǕm>dMz)N\95",Ƨ1k'yՔAw6)B3ݫމ${ݖnw_?JQBHO@'{ WaS@V` 9CzQ!{B~n a(S美;up`sB:<XKQABcbܯDyW^8:$4FzI`Ɛ4j$}/g|V.\7'8d_ϼˡ8p=քc83))]g$- IA 7tO)ނE΂\ }oסħ>8Pf *F=`"m@[# 0DGh.TKgɹPS0 0"U;hf@4v!Hv+>T+姒roūQa(.IXvض#e#Tgs5 >zuÏ!_*V44w6KrvZ؄,6<[h ]Q}.C٘n<65gz-8|{R{4(BFatn[Vl7t)T>>zΧ)-aU;1Κ^aڋ.{5vC:GQmUPA)ы<@]կY3@StYZU$vUݶ s$$ETq!ogڀ]̊ QleHUV+T0_EY}*fS uӦ1$aYf]J:Ϗb,j'.Uy*=ùd9~K.Fy8]fP-Ssp2,K-U BPQ⬬ yǷ$ +fYŒ3 $^<%z˓h.%"+;k9 :k/~)Ițt,H/odDx 3bCN3J2LX%Gy=UfA RP^p'P]к;pipZ>8K5'TV$ /GoΚyWCh{<\)UUtfC*#AY(doK3Ȳ:/^.׽Z~V+"⮸` 5δEHΘBE2!'BzulIe8G eNoTt̽Zd!ֳ5;( h蒒 C,%وdh :K3c<(O[M:зCOm/x'"N0*`;&6B]K?&GSa=oae!3R:m,&2oX_r_" }5v4 UsQ(w}⏖ufɘ$NJi%{#},!q7!#a tD *g^V_>9ߡluKe< ȠBMl*<ɏ8Eއ$BA|%Zx?<Z \:t#s^e[1.=$n Li6FsmN?1J-dG@{Y}uqm|٧}J76ttoK`~(Z$c)={AsQa}奃j0 s5e4uJ.- mلmd%2!hoQe#|/Fb} ?3KMxFfPId$RbF.Xmr=O./7E2D[Zj.y]g\Meθ'Vʘm'P.e\ipk襅ш_y\2AnBJx~i%di0s;(fG`p5cT=?>` >BQf=/[[[ر>uh[DD6` r+5FepEi]VveFuuj`bEMvԕhň=oLie tvfښ+8B~ (Q>)IIoG+lnZp0Ac5%g~W0ݫa<)]Qd$wSVSh@}JT+Jeh,bpneL*Id([j8_jA(#y]QbHX֟1߅ & P`MgPWTBfk |W/ꩾ1Vd̋u!Y XX40Nv,)VqXQahtあAQ> $r}AejnrXZ =DAULbuFSG:v . VOH%u2Yf(8 `uQwg {@Drx(`ߴ~4kaa[=&aӃu(W[wLD[8=D+~vqfq2hߏeD]mEQC΃6gKnM{ 0@7Q?@a]CJ>%HKJUrv>Kb#;l8̻]d%Q7›tB"5gqTqOsY2f)Ig+]: k߯{( P->ͻйg/ \a?e*bf{AԷ,J74ڀ<ǒke- Znr rPJn"x?/ TP TL< IhQUu,aTVw; 6 ohi_,|]iYV\'qKKNƴ=Kxq2TAK`jrN"E9VH]ݎ) :J,O@zBӀK(EÙ 4ʲOeQv M9I:X}g55KRr hAIh~MO2a ,WISsTl: i6I׃2kb=@%=lXګǃ)b&d 7; xس2@,zӂȺJ:P]7[4Wˇ4j[x,'[K=0hI()OsT%am-cz. Lk 12DxӴ.- ̗wա䛿 -D}$4}|EF΀zdlUu"*UD,ms;2}*OhnzU>dJn!%CtP5x[>}_Uo>E4G)kS!~.g-RzAA@{Li7t5R Ҿ%EqSaE 82$p j U.4b?LjZ]!7=2FT]}'n QlP)B\w[t(y ^*OO" ,[tخaaQ]ҺvA ɆSx2`69 K~eOpY/= 3,H;e -?wD)ۖ6C]X.\B0)1nm:{3,i@-9=1Q93BҸNll_;̺O3P92NE?O' UPRP-A)qT98&ãUzvLr`CO.+"Ā(IeUhXzd㭶}ʧAW;YS8D/|t3;CB:Q+*ܻ%eC dzUVRONG46ݗ/*{9%XMŎJ́'յAFFт`9PS\3OD7P3󇍒wcSE bEQɓrs+-^BWƃ5sY{S9VX1k%ن3o J:c ࢻ,tW.;l.)_^EE~˝=AoLzEt+Fی҂6 x<0ޑ[TSDPWz+[2o).#UiنW w$'4)T􌕻Z X߈.3+v5D.M|&{TH&۷L8w96BӞ'& !  fn|$KCЋ1n{b}7%=ndvRO4Ɨ+_?&ǝ"hQN`> ZW]\^~d"k.$6쿘X)ߖ4,bK"ԅ7wlB݅s&Hg.e-P5l!OC3J~!ٌ=SS\^+Q[vݡs=R׊zllJR Q*⡢qEߓ&E'Z˰sw 6Ѫ [ ~5Z sq<ݰ ALpɟ@ hިijƤM&b^o Т7TYKF~7n\U $s h8k5((7 #s߀mFXhM ƙy0 ,h]?ZEr뎃$`tw#\Ks"yM#t|buX"L<)ZtQt.I{ȩ-l?lPPOGŞ>A\XIع&]3@@G%[f^•n2 `<0?AV4%I;{z!LPt,{֮9a7@Jҋt[q1 w7b4~vMYT]k=boI9ZPm/3BH {䎼/"ʠ{T '8UGG2bSLU"ز'"ObF[UQ08wPA!òN|!UՔfڈu}0()u@hH`x=kؓ>G&#IUpGX9b"C)]h ϪVH= ~5'+"GoUf[+y:gY;F>uSuõ D ~}V_gɂ[ <[_HT э3׻I0h4\mpHPΤn%8S(0yi] N2b&`ѫߦԍ_vO-觽9/"l[ Ixn3x'B`-BWEAL9^dT+c6OA@woipQ +AM/f4>4`ԣV 5DY>FO8?׈̸ZNM2 ǡ(),_ZSrv.8Z֖et- zF΁a @4&` ?3@/r-V0 i>R~czB  0q%)+ޞM&扙tRڨ4U:RM[ģnRf0ۀ(]ɶy{ k?c@[ņַtI!&Vc3гNcb)CSHO6NL`'SmsPlpsG;,li+6O KKLe+xx2Y\\v VM] X攫?hQpO[6f?H$_ME=JD h>0#DS@LciIYݥap`5Xj)$^1NC>v"˰[ ߸ZU} N2r0 ?5κK*ɳ3k7h޷b+ :x#ƨ /kgaR%OΘ|Y!rҼ8"(׃& WF~gXђ@IP0~d!O/7j JohDVk*B0fsS] IdMQt'D8%4_(B1Xs!>ZC!?msJ&R%NL{m,$Į$1>>mŤ0jgzRΞ3D+|ϴRSk$a[*ncYQ@#A(5$+^_2~à^UOG ء)VcY4Ǜ|ppFG+)!Xtϕ}wsL:;di_V BXӴ\GLD^ L-20yvɸZyKԂdq.0>ha}Le^CjA $MI# .Fkahi[A5.>1+"`8,dmdp#ӽq- :ƲUUET?`=.5)X8.aWIY8u2=6&貝uS2?;?* l[ GyV5H74 e~7Jn4fwxQse҅$:S9?dwYTKsgBMc9x8_ ajC\UU-f[N9@fxHJGoL?qn GV֫I|'t jEV,@au2dJ&7z0(,B5\NYF~O`C |m񹕖[\:ϥM5!j+HtH>wcBhwU_'9LXSq.vf<Paw~a,ɱR~|fϧ]n gAZB + MCSVo1 `*Kk kd!t@mheZ>sOWѢΏ@jU&R2ghv-v4)Dmx z&%+ &BĪo<̡I\.TV'osF2og1WR9.|:re'x=ecK hݔV;p+==/gt8!ꌲ7ɟf>s#[@%7F2+Zjӏk%.<#.|̟f#",KjM06Uˍ$?_IwDM Y!;]F3<hEOݲ}(m{?6M7Mhɭ(zl&Re_ӐZWBJrH°2IVe&gz.~JJpHQ {SO8MSj 0 KH"_gRwM@aZDn_Ӝ )vܿ.YMk']RVQOi%FuAiSWhߢ}OGR q>w||Д.Fq96GwIѭvIf(mSe,/<9#%Ô9CsEQjxPv̢g'G0Od&BH Z\@cH:ޔ7tOByT1X7K04\ QkjX&]Y1}gD MJkSҍ^i4EuqGrW]|=Z jA5HU`&Rۗ& cd /D.ޜO+e:!DZe9?x"4363c?ꃂF+IB`zMD?17HUPTmuvw|OY _Asr*I ;" 4O&:G;Q#㕼KUx66#8v(GI+4"we^t-1.Ƣ!@ ƿ'AK"e}㛎EĽ^Y[k:bUT_z_N {D,iEw x盉o4<}t_КBR*ҺXÍ?1R2)u3QRV?U0Z G0pf5BD^(|M)btY nS3S G=Gbi ph\g|||lD :;LR$~>YvH)$[0Yx&4Zxta5𪝕J&5BcjCF/ħt9gSo4WHóxp^ D>?HhZnRKP9ıq-&6#l/Z8*}mW/6%6j"ZϤe.Gn_[Pk;;-""xoӃ"s<ҳpY_}M@ c}x| X}=r~L^k}Tj~I ZZnNl5 b[Rb{TBG_e\.j@2@c) (UQ]Er b'ۅ CƑb*ݪPAw;$FuzpV#^5(_mԷёeUY < u,;9~x=7%N{*TT Fw/.@P6bgo>$LMTfG JnrmcX  =0o@wcO`#ڸ.2Oǟ*[v 8cjNe9Jѕnv[sSF 1{>?y Z~5^hes-*޿]t c]jz!.:^YLj Kuɦh*Eo ٞ0)6EBf<11 Y5)ELEԣ&w;VXn u˨AHrB^Is=)95PLԋvJߘ9!SIH} ]pw8OcLq& R:pz,dB2@Gi|I?킗8LWQۂjT:0[/A[vD+[dY6=2~)d$F*'V?͎rL}}ώ1 S+Lk~hŹO`<ƘfFRTN%qaMh`ތ;qZ ${>+ʦegϩh͚xd͝q yl$4UD|_:+S6dTA<⍛D)qq;Sv`FL'@O \եQ[Ug]YYw̐'|zkl5K)LgkSA=-B)'.^[G1n n ,~eJ#{[Mk9@m*^vu\gIRKQ@~3EƛOaI)/YlvSwy@`䫀ekCNxYROPy8H]8-ܖwQs,j,Nk[Z&f% m'0R]"&X/W-5\nhN}dy7oM1I=IfۀP*}2ZAHQnۇ79=pVEo(vNyݨh6Ŗ̰Ð[<_gE(5*X1ucU.DB% 9Hw!Ks{hCHFT ⮫ qn>3qJ 4X+>b)yBNϥ*H=b 9&ҠHSϞ%(UBjHJnEqC煜8AQ"< 9` l W>טvi/mƻ"Cy*B\1"?(YԷ`/zF81DUYͦDV!`ٽ^/ zO`#}:5Xh 8a$7٣% HA6!0pG[MҪ113ՊMp:/}:P ~{4r0eh)NG5`;sddhm}X65ON< T Kϟզ ∃"{t&$I +Pƍ?JݟQᩌk,5mi" 'K÷4 ίnjI|U6@2NMjc)P演 S/'4<vAЊd:_^K*8$K͞T|Ka]ꦲLz7m﫺]p=Le sr7oI;<ώF,PӥY&u_(y!EdNwmad?oV\뵣Rpp@p8aA/RüŽoHTmssuSM6B|-| @9v_s5BC zij}.,ĊM8WT 6CˀŋRRW1WUX>/?BB k}Ih9@0Xڽrk7~Gʉo[wx~jDB7:(.!GL#0e9tXP9jWTEd-7Jѻ~R@#(y n w+iSjqs^N)KIp"~?ˡBc6R3N2}Gx_P Uo BBy3w$(1ӝB<^Sm&ldkzM&+Lx]KgxJ AG6"~z*zB{|A3֫1lM@!l&URl &{V$uRK֫ tW ň.ў\ +S\䮒/Li9YSz>}2&б]Wd;kuHBSY_#9#}MaPý+FJh)0(E׎J.+47¬k#EZ-Kmw d7әt$0{C{*BEUee,$Wcte˵o}lH ]Or6szED~,N%sUCa1!^S[XcH)6G-?';G_ݸm@ޛ}()0Oeo_nG#uK5|p2 nDԭ"Ak3HTK嶶~mۨ)7ɖ[U@cTuߤ|/91sVg >.uȦ)-6es)DH ґC>#:)!r52 'xKc/?81Wf[_{qv kKGzM!VhҺpL23Sn[ވM?ho Qx1ÇׅKEH(ު0. Cؓ[65ix{#>3Зh=<?TiT/_Xq@>ו ngp\xR ^YY’~Yv mI"Lړ `i}1u@@>[Ve|AGA}yŠu.3?xWr e, + Ecs@2{> *_u tɏ."T7#5dkØ lsڷɫ"HRidTFD_[ }!ROZA^O@#@z5de{uɑħ=GKYڪ98aA}U8۸0ꫳj&}-%wW¨ll4" $pMF:Rp}w!LX2Ј *_ˉ25  1.n$ި{#AN^*|>'+[9 PF>j>2(4խr 4/)&Tq(=; 2fDp]&ONBQUPdy͍1 r  &Bq3VzKMd@G#dSbYM_OaٺK)7V%xcUgpCٜ઴)=mC+AT;^9Ѓʪ^;r\,|ĜGİFo-dVwޯJ 9꽂ECYf&ّ%@ RwAԼTsM&vB:-϶WqW׿#[1ńB.kJ`y6eի$'Eœ7'%"Z_"'N:)'G<[7YyW, :Rh۶Ȧu jJ_.R6=뉫:HƲaץw-Չ`[$[Gmc1pKJǗ+3HWv`)S#:ɝ'LKaV?qk Y̛e jb?q8E"EOj<|9U;pˆ˔`=-s|pö?1:lSf#ΐL{6hZWytb2|* 7Z՚) :R` # X'W_i#Mz%0ae;J Ȓ6BM&h5CqeX8T۾XW}# <1KYXu< ލcfge!}e}! bP -)?E%HQ ʇM/XĴ]Q2)܁AѓbM=F`.#L(+ꠘZlkԝ}SqsDJy{阂Πh#E%j)xkY*K#L11XZNs|U@xy]j@p,h Y{Ƴih8~t[d*,"2S /.(b>{lu^ AbvkAJ,٤^p"*Qn y0XGz\FPe}jp5T"樏өk/k:igGBShŞ!pg.ܲ䌓ߊPU(]R1K姝J[RQϸsڅlw?Tb0j\eC({ ?#t}P?J+5p~̹c(){Ki H^y2A1~&l-!DVcCM_ N&}g$ kHj?F=yqhfz8$3-+ʧ}k(ĭ,ɳ8.vX2_]R‰f LclROVwRR^G(߬s^f;uyht}udq \wuy?*%c*u23bA-sݪ `( t[H$L¯ҏnds0~5lA7 4Z#Cɉ̞MrZPڰ* ,`s&w?k}k-1Za"hX"gY' 6J8?r+rlA#X!b* =W1^ġM8i1 `~|Ye]~5Q?$&~w\fHy&@Pt|!IJC[.;O&!-5D <54ze\<(A0Raayic`(5 v\: Ekc1 9e?NpOZo}zjh%-ۙQ_BTS= +G@;@`{7ղKZt%߹C|0K"= ס}Y/"x_NCӓsil*6w>~Q[..QT7M24p[/4yY>, pm3LUL\ 00`^]'3.}'yjq8Iګt I\:o̭+$ojB0(A= [fwR 4`B;7 a{"w9)[=Hؿ?J cr/f*{;>}E|*hMmw6>a*,[lN=#!R]_vGG6_%Tveeޮ4ؽ #'9rvySѵZ͠ eN?Y'ְ_{.819wv.JjýÌwFYK2#PXK9r.ѳgXԩaXܽZ0Cn, 7جk-|T?)ϾD۟{5L~UqP$a*O0p·۳d6KS4u\Hd36TئmِI^B ʾKud@Zwůz|rҜfߚ s$῏r=GXai's89Ks쵑6gܜħm2:! ?H!|>\D _"|YV v_mL!峲wB1$OA(n>1lœ{zÿY(2sRR~R|gˤ_q Nߨd=wT`rVk+3L.BK"W`ߠ>%%@ B_Yo3TYseLL2q@pwM@ W*X+jIJJa83AA0C'7H}tx^'/ %5P)-;$s 0hLK>$*9Kba[lq;}XP󄆅n|;t/12),XH򳾥@&a~u?|!|"|,;tu#"u7hMpy9ɂ}iRIGO ,=RFTO x##3p+87+ڇGZ8[ %Rw$ !iBp V¤?Faw…Q lG:#'j܎9s^d- 8- Qق]N(#YcfyBqHqy#Q &Cj.N4Sla0gyݸw fB\): +SK $q֫q ;:aG~>A`PD~v%DC^N%h~&O@0t p+^){>w .[l.P9,e3p$x^\\whr=Mv\A9\DoS1 _$pPu{b2 lz`9{_ʓ?Y=eK2$$E۹9i.Ra_YJ Bk"Zq88^ΰC@56rX!9]Yu1˅TSlj#) `u/V@@~qHvF}` z?2;YOmI!Q$CT8쎧R#mhւG*sy!|@tF8Ri" "/E3N'v3M[©Tx۬7S" ɔlDU'dڕh<+ehaWF -$BY]֤V{&oR4AG{'a݊ 1\N P/Ƚ5I=}5])N tXOMPPۙ劋QA˨bSz@ _rb{T$1?MDrz,I1J߬ or'-DYR;x[&jm|6 eYL ]'m=<=?JW\@> :}^i`+ǡ`KGjnqF|y}d(s9<^$eelnG@˭G؟'}h/^h71ُ<^mvp~uPu ۚppC\fCxMA7Qv:l:jo}<˶=*O&4[^QRk ፟5vu;lSir1pÑELCzuBCS82wq8(.SM,8 Kݿ|p Nt`gJS/$yU1Ӵ La?}/$dh!ǝ3*s&dV{6SrKl-􁫎ϳ ^zY:Wo 0`LJ7)ǛUUUUNTkhZֵkZֵkZֵk]۫]p-kݺusu]ui뮻º~놷+fiMmLTHM4ҙikZֵ5kkZֵJt-kZËZֵk\+ZªUvꪪMUSEUTZֵŭkZ"ֵеUꗆU]?ݪ,EYeY֋''b.,Qŋ11ZŋG#S,p;5Wn,q![ؔYa ,,y뮺뮫]4k۫NJ.YeYeYeYeYAdVYeYewʪZ]qt[tź,f k뭊뮺뮺뮿k,,,6WL.RZֵo<ֵ5kZovUSb~~Ȳ",뮺뮺]x/]uuRֵ@M4M4M4Y-kZֵЫTκ뮼,o,U l,k,kj뮺뮪]U<]!kQkZֵmk[ZָskZֵU.#MUTk*떺f:uu]u]u]u[z 6YeY]p>c*)5u]u뭊zDdES?SuUUUUֵꊪ_VXr5f nU]u]uޮޮҰ#2,ŋYe,X;,,*uUUIVyB,5eYMy(,rðAYuDcYZnu]u^mY%_ [ŋ+4c,eyX,K,஺ZURUMT ZҵmKZZָV-kZҫĮuD!]~ɘZ^ `ǝMI10G(Ǐ6aGx5rs+& vC0UGMN; TEQ+)vKp=l~Ͼ7W.W$U|_:i^vs}M3u2"5)֒P~;4ڵ|$ܶiʦsOqP`&-U(=D CYb(z|OK*4P=HxSPvE7:**Ǯ6ڇ8QO[= E> GIp:tI)Ѫ`ŸS*G դuAy >IQ@lgWU"g{'ygQ޵ַONPV1m!0 4|6ßOK/vQ207< V> :Y,v`j!ہCh-c 0AR5v> (doj~ I" )DGv޿[7tӚ`|~GI6UnnKv 56Fµ*¹(bDCI 4D堂GDyO, %>>45T|}.y1^R 00uzwm'Ɲ>2#lCI>fDEOq)'jO|dqb#}:hpSy.np ^cp0\vp+W[L>0"CtxNG^`1 J|uz9]1z]>x1g )[ :%DzH|ҀsSP;lI9KۛFq_w"6h(U;:{G;Z0Ǝ0(ødLhTW[?Ϭ姎TɭmwT4=|\VvvGultWD;HyQ.N(Ms{QuEw֧UikC[3 ԟJ%4rwHUz^|]׬| u4y?gm<*DQQ8 A sdswzWc=8cֹd5JʷV6FHeTy %^&[ׇ c @ P{Bz֓ ͙S~n=5x$2u,k}ߜ>ފ562ۍk{wU" fd$BA@4~\}4ʪXP%tՑ(yWp4cz̊7< HAMWKOp+zs+%R6GH" FrLFn-<>+ VCyMǮc 9-1)XD:dΈàm@|?b3a8NPqE1$[rխ噽E?#$IOufFF^^ۍQAC@ʥ[תGŋ#{'ȸlC \LMOb=g']x)b'@<2M7&Rgjajj[{cͮԔwW8Ǒ 0~BU!J/vz:yJUG!3w FfnAqJK6 %T^b-,<ܰlldN,jUtHkT5[ &:b+6lT.R]Z \D$G{N^89_cy>GO j>γZYH֮wFSY,k5֫),řTԵTL jF\(H0KS (E I j7I]ՍDRӚAXiR陙QK:\$`'W"ֳFfp[ I$d`ݒ(:ܵ,*4ՈvZ{dde63eUJ.LReqYpI3ȬFFRQ6)RsTUFe+4FF%'!j0A B7l ϶7A  "\ QeLoi.7+7{uG*w'>c P̨UUUCbVsPbW, jP Q댪{x}ոIE]G{ Ŏ+(U9ectjഏ8.>SjmTǏ2]aAE!1110brw/P㳖ooTvMMq6%%AT{K(`Zf]/Gbs_vۨ]~!ݧ} rg뮺{yc~q8#OdY‡^rrvrg kqXQkI–/~,s9>>=[paz\8oũ]NgTL1G*:J\Θʱ'2;Ҩ²B6?qRd]z{qgt, !;@DȞ -$ƹf7MpxḁS]))<=hʿ̒ ]WMkK욼j:JYUNw.wqg`vM=,وTq߬)S]1zEv ~"b$o/_Xm%kp/ܭS7" YMfS=i/i7L+۬U5zV-e'l%㖆ާB`je0ީ]mH.[}W,8t^/`?UƝ| a})ddl{k1\H:~{^8`R%+oU@@H¸곇hmQ\f8W83噖8(9oHXBRRmgw>M"q崻?gگޛ=Osij[4 eeο&T5nuo 0P DeYӵX/ DkScuȥI`aZm{t+IeBagۣfg䧩U5kU0zh+sM[#o\Sf{SΥK7&* ѣS\K;(@,nn]BZSY )'h%yhz*8Mj TWftPNĵ7.[&f!q778 kn{s* ^ GHңCIn|)[Rᷢnl]߻4TR\^rZd߮vx;,u:7w"dww!0%0r1-轭yt)OiPT:wܾ7  excò%LSkfuO)G62Ĝ&L( U xe 52fZL:~;W3\o{͔PتЬ9@/Xf Uϐph/q;p.w(bgȽˆb塙LA q>q%YF){CLY1yβ 0 c'չx6P* P{N^x;˞m}]/ 'tD,}ᄑ`'AUE⢂ݭ !|oW겸u7ch9x"LE0@"ޛ},އOPڱ78Ǔ??A @8dy2x[vqڱqh1@hyy4}?z?""fDŽ#龷7:? UPc0DDH>kOewVdM?yvk鲲v=P6 =>o}&=?{h#\\owU EP.'j|{H""e]{^2M6x+%(IEOof.I#COovw+N+=v&_q8⪀E -Wp8W _V"0 A7_&Qqh 43oekto<,+<6v~&;?/2NQ/P83 k`-A'}v=^!# Uu"T<0 $ R:i ? zKx>*"t/mvMwYvo ) eo}l9̽QJ'6mo%s?w36ۋ@7j6F Hٻ _뭠A+pO0P7P =}>[`h;w͂y-Yw[{T`+`'6ok" q?s0oqUz <OXg#q>lyW܊tP+ @#VCI*i"8C j(vFtDb"&$dD*D)L (t{\iEG*u1)}AlmAWr UT6"P ФDj |{k{+  \Rh4 ƊX@롍5P H Y| #Ϫ?en܅'~ ߰e5{XyT:u8]B PCZ 0e96i[[BtmVԯ"ZɩV#:q9_c)_ϹZ*Q%W9y\p`zuZr890:/܍~({H??l]Oi=~_O87Ըtѱ.ϻ?z',!htxN+}{rwH} /+wZMO\cIU3#"xli1-=\cşvQ(A]ה+,n0]U^F+lÓJ [B Tm#o孟=O{=,RdIJQ%#<.n5 Γ{/]ȋ~y~k]6_Wd>eh?!AWohz]{]N^uݮ.u!Hx\"z<';OU\U{dDzTDkPZ5T+Vz늳 4H޵^ڎ[^:r}3 /8ʐx9VuJaǢ)oԬ'TG]wY<{ݞ / }ѿE;h>;kBHYo=>7nguSէ8gdV@< pg!Qb* ox#EZZ*3p\dޒGBDhSij޿ػx$zH؏?pϋo?ΕKƋVyt_j8PD`@i"")LZULec_钠S}ϵb(/-5k>.lv %67Jᢲ.a:s\CУR^_f?OZxzi}ͨͅzB9ˍo;͚W:Pu r@Yi`ږf^LQtQQ.q:SYMs:<~dkva}3,~o.kn2zWyʥ@"D"\)ݏ&zsY~%9}7U;̴q~k/C7Ƞa8_xnr?|^/TwMvA]Vw<mp8I0 2Q ЏO{I"XXdelޟoYʮ1&?kuqbsҧ1Deo1hm92!_H:S=*8-03yt- T"*:⣭:Ή2tOw ,˹v+y HjxseŶaxٞdF;vo̫ z$+/uס%0]X]+.w Q0ս[le[g>,rvp7 Ŧr65eF˛+o!N}n95e }dvI #]TEHVHFSdη%9׵7fdԥd@ ÿ2AÍ%@=1H*I1"t`$D:wuf|! 9u^N47(6'2JmuzXZ :D7~cǁN\ו9e- `b@HAM.ŸoI{P& [%ǿq&w|֏ks,b34\L~8r_|+h2/VG7X|d͗=.B^kg^j 3s$z^C R@?*r7J12}Rb8ɬF|kg$( ާg~N^/BB߯=7Z,mMY)n9):M MUB!g2jV@I[SGrcDTYa^%T櫟#*.QHe!B*Wyc`LDט1F;rĄEPqr#__e^#Ӣcaҭ\q̤Ȯ[yU@,(kf+-aAl6PJtZ Qo͔/$ 𛳀S@HP s ) n`HMXd: "wUVnJ) S4UʪvJRT@>. c Z "Pu_WDm<9AN3,bvY^쿜-Y 'Q(9i[A>kHl|͍Sml* _i^n 7{ZGqr+psn/E"Pc(LrLMwX*-*`-oq|Fg+}>KyF'[\)a) N8RmCvj-%l%3? ^I߶|Ǘ_XԪm\jGȱy[QT`v(D;G`GWy;}Su4'Ftxut30:Him'&&r`Sp/:QqVuϦn (ms6x7/vt3?>'[\94e mGQaWdw\,g'AxWԼ'3~9RcR&cz֛fGYv ,#5<#2׾^@0fyDNyOhe.7?<~"P<Ƌɷ4'~Ζ&2y$ #?齁xkѿuE)jID Qf$<&@J __]}#@OПvixI ՄQ,I-R,\q?\Y@'iUKW/DIxEЄQH T!TXKh$I4 =@ެ,^-m'gϟ 'gEkEyՆT UH$)Ծ"^w_zuuܾIPHPE ~fOd@Oµge6tC0X#@Hչ*˩ X@橥ZӭY 05ag/N/rt0|? ȵ=WÎ{{ׯ\zSqy4'T6N͝fѧԝX`EKK[͞7TS"ڮѪYM$~3l)yƃ^aI9 I2,\Y5BdY z/.:ԩk30m"RF.9QHN+UGf.L"h.3t:0h)It_(J?dJT.11Ѻ*9K@:+G~R#QG;@_u2dGL:<=$H}U x` /B: E L̿1niU;۠φ]bQQ:d,c\r)cH VFDF*hVRQDbc b(7Xc\pn%]j+593ۮ &Ĕa!X,QHj`ՄJUZeBH\LY XQQ--&1J# 5M]i%cF)M|<5 f F F1LJC'D%Fi b*\Eأ ,cX9j&(Teb .4zݰV9kE(Zk5,ĬR&@U4b1M!,uAh9e/>34qmF0DYmbȡl6-bʥ *"c"B5AeVLr/!,U 黨j|OUO/A-0G&2g@62*RpqFw>AN*[gyB˖WP̪$Tw/În*./(#؟3CV{~&Zϛg,ta~wL;ngMelgk&F`4%IKN-6xM̰[f _YIlbwf XsJ $!B$@EA22HQ2`CUTP44O2W`(jׇzި`YS0B٫)Lph/Sk F4 Z|L=-|v|j+i8|s|4|t4l7@sr!\w#3һg_K]!+k o" BB /^J`V" ^m57!mwA%ս`!pBEA[^~=]ߣziƍQXs$+у祋 /{T,mZIj傪,Pt>u7U}R DL!֊k MYbØ=dXY&ҔX|!!96SWS+ bd;W[=!Xt*;_fzN\½m Z S袺:Yӭ!Rr?b/Z$p!:.՝^'WY\9/^$kwHW:_6FX3,DU >s6m`raڒxz&#Eyf/B-M\ ݸϩuM"y|Ԑ' 'KeP@Yߘ5Br_5t q $fqnVH*-2\ #cN`~'$zrZR 0}K H4DD"D`$h%=9}S|" *"+Ӓ5LR@9#LҫMޅC̻ i2o; +D[8$TPDv j35x"`+EvO2apd`ìV@DDd빈OIn]6_Xy[ncd^;&uL9LcXcC^=ˀMEF: 8%e$0,֙f+ECʻ/kGPJ.VX4{}LqA4g'w\<<=ڌ3P2Vs0=, R6c^ H}ǔ!,&62N ioqב' h`iުkwf5+Nu~- $MqWY׳tE+KZї*adbG!0M%-85>cQ`'W+>~Gii>'b `{L'<\O:nIjG=sQl)[]9isڹȭw>j }a~ۄT`ݙv@nb<:de "^^Z_V2e1\]JHi.hQNφ𞰺99гftE#j?<%ImH*J BUEE aTK/jF {ʨק[JJқ$,dϋ jd:p0cZ&  .:zwڳ2DA7T*8I8V߈:G:ˋљ+s5\@qot(,V!ۧUWxzz92٭`%[>+k( BPp πfaCgB9HZ21bIRFG_9),nI"H\~fzO0 x!xMi1]y42¤r- 6؛d?^7d JD7~o@A gV5}%7)A|{&;g7x(w|e2_Dx2HOeA| j eSsVF! APe+tSfٴ1Vk3L;2 FL$ꦠJȐBɹ9Y*^x9~BȭY2 *dz^ ƒA\~`d>}r;qT]QQc]fCڠNv>=4F_.xc}"B%5m31 zt)/*2H>.>oSqLyvl٭NqXk}okKZ鷛_DG|:B&_uǑ|qmS ATz+ӟjP_UB t" h Qq sMS\PU3|7R"W1@$ E% Y7^(TT$TD YEO O$d v8kwε$ @p^rup!D{9f|h''K" p-Aj^!v)yZEBboY,Zӕſ.^_vt|2,+7n ==6BEBE0/]b9Sln7!Z,=\|82E(H # qo4sKoVẠ"˙It/{lt:!tZO:}w3I B#1jp4;B}ci.57*|$ a@DQm +d3ܢ)=3,gXEj Ftw9RE *USe TKe]ZPdknuJa&X6e4-yQƻi>7T],A5$54d^p[sWɔrIQ#r`0`dx;a=ZfI\ U`y:(,EaV0Z65^e!~}:Rb?AE 뷛L˲Pnqu*iCg}ciT=BҐ V Jb ?)0ETFߟ/;Nl&&+YPw |e^@TnJ?zdxAV*V"_V[FrrjWTΌo F8[͎ $ 2Artg˔OZ nvW27塌&rWՕײv"f8,*c(b 8KW(kR`2U\ a=&A48AO#ݼGmb]vQDHV0@a thP@IT Ύ/,Ad'D!dbÝWdT]%P*GXAs`Ir{;2lj)"?B4UGM-b,Tf$UmC\Xi?ֹkg6(cW:.0TA@ڲTCW-fXi10j#:08J(#$PXeCW2LHE0CIT A)YLUD\l~gdQ=9SLA\LIR9N1 SXie U71-JE#,GZYͣ,Y*\HY+`")AbEQ`m)X&mUdTV*; KPXC`a}k( EPg[c8L` b;c u`0/'L5\aU'1 &(ц0R;TZ( CU,bZ$ӤD4ІX3XbV6vZ+5Xw|6v)|l$(FB,t[#wKכ+ ,&26dbB)dQbREQBdP*iF i֨E1$U+*#'+ "AT,PȢZAB@,*I,1XdJeWMd WVTbYd\LM2!Q` *-B A@BXQ"feʂAAQЩE#ZEh,fI(,PR Q#jnΑλRD^57yn f};X^U&A|V@DT>k C`lP)aɀAx w*J[4HT!"ԁΡ/ f iXHTPa'd[D<)L1 ]Tz 2c?z ,Ą$wgjCM4;P6 ChEevM22Bg*e~qI !Ձѐ3W2 }~1ݧl; oWL?5=Z04p;/If"4@ȧ_i TċPwϞ }gu|xD][ b Ʉ&*}u?P'DrC]S4ĴdRnϒ>K6''2<~M}9!Մ:RȳN0fB'6CJ}VI訡̈́utIc 1&~Cv4Td*,X0:Q! P{N{oNryW<&̡%)Bfcb!NL1{}M#h .V{:#?+mH9jt~c箛19h?4\HHI1@14,YbUe!XL3؟_2|" yQD @BӪ8Rju7ĩ~^ͭYW1 [M6?NOC.!nsf- 8ԒI*>Tj1MQֶ@,֓sW @4aY*H%'"BA|9)\yPDv9?|߷xmQr(;ziNl&B 3p.h33a $X˞+(6M,Q56Hm06)ڀ !tD}_`VaQ1EHtJ+PpG@ 3V1%_+DVAmjD--&ϖꢵ?JtW$CؒOy0/ÙC|љo[Od W'l+':Y~}5  C'Tx}q>M$^ol$T?cs逰X$`m WO I рQ7M^4ɴ!wlhae?n$iK1[UD.&x,C$A?}H'ۈĊp3P3 () @m l lEA$1AAnǑ)E{A&&&li"O)+*paA=13K{uQ(((3TXmJCr%{]eu~ Fwfuf 7twKj:  +pWtG(fϵ!DERRF*߇d.Xtm9C]V0wS7e۵_sBM"T,Bm9U]ݰr݇4gE:(@$Y$-?}qBj",XuMqgw.49$䝹@EQ{˼*=N1:}n #_ 3vpɯs:yx<ƳGkwc*$b8LH-?c :O_CZ(i"y~[5l,SzZ)*bANte1d(':ݼ^I;C\^PSt}Ty'9} zT3O+hPxL$n 8܀ $ 5cg.<} sV 0swK4yDlŅFF[NLM*(ciY"H"kZiM6;aOqMQ5O pWBCTR(|ޫn\O\929*s Qq~Cx}vmҏ.wZ1}t噒*a貿-P 1έTO~L_k~:js95&rXUuPqP IPe͚}KQD˚<|w=lP^]5J?vfff33333333v~?ޓmX5ڶX CBV @xHIi Cl_'G{/j;98@0L$5Ob)cזs=8[rj"Oe`fr e.JaH EAMh;}Ih L Np^^/=}+hٶ]F \롓١ʑ{cu :-5 4!/rEG3w3( UqHP\F`@@` 0'և!?~cŷ=yo`УGXع!4"jkH_ aS=Âzs<@^fy~y^'<ǘWd@xeM-oncG6Gl;q@|\זG*fm7~&f.GEl/>{H,ޭ等mHp%{Ck~ޱӭK97kwSߟt}~]Uuo'ͼbSӷAeo{ȫΤ/{5ոƽds?S}Cb8緷GXhXae8r44̪d H v^^^___^^^^^^^^^^^^r_^^^]r^7} 7FE2&qiL*tiO?Yz0"2("}_² Z(pyD@ `"9_^AVᕽM_Ǥ $* *}|$/D|;iT%VI<Áʟj_w:aBI+ J9BL j[fd++.2wzFz2?XPS* ĠTP ~)2$rj]h^'/GG+vݿǛ$^_! vmS񼜚Fr(uR=|Ɠ5̠gãIMrߊ%d'.ԥc YuPKrd-k(Uګh|HW5 o Շ=} 'PP|`B eHtCAxkO7Y1i}+{ʥ"" M oЙ>s?mi,M4IeZ)[ W/s 0 0 0=mATRD718-mh`4)|dr#y0?4(~ޝX9E~4 o)_Jot8*@+PXv 6{&tIؤ"Fv /}|<LeKO=?KfSonʜlJB7EeQv,n(@D_/twNjŴp<ϫ_nG  7OND $r PK@VH\EMzHNI:'kܘQ2_`UӂNh$9d} Q ~)5w1Eunb&ZX I3H&DEY!ՁKlǿv 1nz+$$3+8L]~o99yfrPH8TQH^?ER՛#lxxL+[=4q|Lh8C Cs_NhYiғK\gJk ˖i52bwWɎ82-pֆb&f145z՛b{5v@ǒJM^k .q6h5GF9]ɀ櫪C|f,6P}M`UT.v W;|u/VzJr^Gʕ^QVAP @5uve X,r5ӣ:͊E#_gha^Gヌvxqb8 )@]P̓@8n&ȇ0R #Dgi>U 5@o:GZ-|ܷ}OG}h us;ȕ0N3{}uq?Ū))^ۖI  iS\} y請N.*ڠm9y$`5?&9'{>G-} @V)>Cx^(-/ڤk2H$ sa$;Z02 }d?o>#&9g e@9iNlxkETݼr3-_q(;grnxF Q3/2F0.L[E' 0J*G <aԍ83>~@ベ\eԏ:;W&tH(cE@Ȉ$x p` H@4[Z 2ERW8 Th5}~;VTR:E}^0w4 |ԇ$MWC<[(w * ф43kfN}s-M3du sٙT%ʹ%:)ޮ^?+Q $RED s]M5GB(Q*3$P۫c{/]?E)z<9֤ JoH$߰ľ^fS7,(}{SfTi_y3[e8SZV( +ݝniFEʗ 2V9KIv&dغc+D\=^n|hހy$+~ װ; ?uT9/&USIClp`Y0M]g/`aN~[,'scNi~.PāZ ] AA( ,ڧFS;, V)]ff٦e0k\f ,@EufrMotHȉ@/}pZ`nRjV00Ԭ*A B!@="E &΀O-TjI[R6oo̪wRL\mb@O {[VH?m[r0uiY_Կ}zza@zZ84Wq3452&\ wOFDJmGm;t-0#u^ZT>FOo?}|R{KY@L+}Y>\:!@M4`fК_y/XH-@vgE:1)co~H5:L0D = b:EgMC7ֲBOӤ1kfIK'?d<a:7bpSP/=q0A&*XG%(v>~vuMkT#2:(TILрY j/Q 8ֶl&J|,(3(/M?N}UUڵH8 -{=<|nk]eA2 mp݆ZtOh-Tg0cDa% 1V8 VaEAT.w3`b]QGyإ:=Eqwݦ۹ezz#%<Njod@`9M*qUΪY̳=8˯лv.8| ~KrwT0@vQtH(Pm\w e~9YPlp{{ pp-Q8M]Y&dUˑx:SIES$ @eL l^?zUVڷf/jC*vۨ&L4-֡boo"!ώ>Z+L NyikNOhͮǃi0 `_R/뽇޷m ;∗2Tyvù!śγ6W$ttsjk{'0K`X%3jPbnJ)@&6y;_tߴc9 +Ҋ20ز-HuRCy48V8n6_o?ooj&0pDq^')U[ײַ"u/1OmyX?uH/vw\yt[1GR|X%sw^jY=`oݒ2ިUu& D+V¬ʂyvd89},_UC$P?XJE@;.7s+փU眪/3/`\^R "Y,e N4/^yO1jz:CŸJcq_z)" ɷ36 Lc@\ Z>T[]Qϣn.KxaJy15T2mM\~gU`J@_Q&IGGwoZA I@AF 0=M"#ߙ }lj]rc]~ԙq{/OzfKH$Xʦ߂RqV?<ٮp*Fu!EpYϧOX{K88IeV"=ACɐ~g'_ .?"ō݁{kr (Qk)=R]ZA>+ 7SoVxdy9kk[M?CܸVx\Gɿg x+u t}g.& {GUH*S{yFwA/X]G8z_/D8 eJ*UR^K,TR J*Uز#g#}N@PBALa -+F}2OGR=|26+(A g|k1y^GeM%廓b5EEHQ`-P~x:*ՆHR`\DƾE{h oW/{C!W4۫H@\wM7O:SdZXeO42Tw Tf~Xɝ[ (¬^lfS Tx¤ݴ85Ob51Ώ 0p3Y|/҂WcU 5v=k^뛵$h/P˪WAX4^Ή9Z klg k,CfmWW*5VMK×ҘܐiQA>o+5ʪr`R Fa5#瘟v޳OwqɆ7i/}tq1} PYu~ݶhE<,pWAR8I LKZ .oݯ |ƚ{L1?R.{oSgg[6l8ϏaM@BJlHk ޻++S,,t'BqQyg<3O,BSCax惻?d;uYؚfм}n&$~HpOe LːC[pq1 ?ubV{|[;;3C?ah}[3w43_$&'uNh>'- JMia[L |D6ak-j".[;& Z& ~N&>~s`ȦVj>mM="lUυFߟ/JN(~U~6}^Ո݂PIc:{eAQsz(\94VZ][.O=[o{l2׬%t?: ^-ϝ7cKQ)v*!5Yb@CEH, 7qaI}1x[UHVDn?nM D|ۚ |Gݣd9$/ Lmjwyٮ0nn!1Ż묥(do/;o.khlԙ/>;;/}zc KҢuuuoxdkf>5d3S+oϭяO%a׶3mK( k++/ ?ijEAr^nR7k Uu~Mδ@&:ץ*" 0` rP 8?}} K>4r߇w;$cs)+Gv'kMAf T}3vXw" Uw#nu]u]mP떕=Um:뮺뮶uP/C,+1~_̪v&QP3t4"kP-4Xs MBHD򬻒J|Jxu^B*(??86/ R?eu8r[e6"> f]z:LMu}OcVuswgUuxф%4 _> ! <\ZTh3QeWs}/FhnËkL^Wy\#y.Aw|o(gI_up޷1m EO,*8"_} *)H*AOq Np-ӓg M1I6kKwD,I$G 0ЄoJkOؔ% @I%JgyNp<kR<#5A?m~Rq!~ـt4nbC]7;_l P@ ٳ8F ɱ<`nQiZGvL߽iwxwYD>W|_ʡ(=~\DMC篎fk⊊r<#:  6dFΦD~d 39ijT yYr=GUۓ< y}̆?Y9~nc7 #afff^X~WeRd0d~IN3踚Te[WJ鶅w^:NqJ!1ƴ' 8tu@=Nwf?_=;}޴AEEHht`5*aCSɷj u݇D5 $IBbH[G?&W/fC [P[\=[qQ{z3Z1,:ZSQ.w67R^{OGAf9|?Rn5oo )҆{3c2q=~Ooz?.NMw,eK~Vݶ?WfzN)Wh_귻[PAsX 00<*URX9aВ}EC@PSPsn3ptU5O;#kckD%Pbq}'Цcԫ# R#tzԠm.;NԛYd!!b'WE8oM'i?%]@:X/Y3'IG8I)̊]Ii(:DtRUF O|16)(@&;䔟ҝzW[5-;{-xTv9S 5m?AFt#g]$uiFn2G^)$\{@/TORU"")BY99DLO13 gpO ZuϡH &C/~DA}~-dSBEf\LYXh)rMj)t87ŎfjM1+^hTy EװW.g-rL["O_SC !Ce ^k(DR" UNȷ::>QޜƶH:}J-eC@8R?/}y\<]*Wj73 LDCo)JV81UmEς8 [껿^0$ FrDS&w^Cy he,|L~J_}WZs+]I(_szzJv0o@tgXY(TVCX2YmLIDD79ZO]zאuՏ?1 5 NQ`𽥌Քm`NQDUeF VzjD1uWӛOp:CΙ <B@I]ʥ)^7ɠ 0a/ٲ$"_9TODPrwWm%}#x!5UUMI橓#$>ӊ>D{_T IH ")F hI{pv%j(%ɨ_Z_G }dtEZ=o00*̡g@'(@l,TBqgJB$bJ※)Q YuawiZ#n r͐RIN(D>Cܺ#ϯo1(*(ׅ2?yIkPsf)qTH3ȅ%=? >6߽cͅt颁$eMXRK$bmQOOOc ~$,9V%0m`|S6ň,j%FD`˒o:[~=,AS $&`V^4>Ыa>9l%(׬PM)!p1$-T_pjF%@3V75 HS NJΛ=Ta$6d(BRUBIs3%*F8~F2:>qrv{Jzpw:IJ7j&y2gz{;8}ܷ'`) ,R YR+`Wg]3U4oKWdλS2URAzaaƢS>޴\eո@.^]ɾY@uD?[~լ" Q~bZ_u@z8y;ڷEOO/A!HQ2'K%?Sà (b UTB z,0.} Y'N']  ?؎>zva}[ܿE/ykr(VP`hyhC.Ra1[o%KX': [ٞuW-dp|ڶ,wyn8TA/uviׯ)w=6H@`j(  C( {yy\-b Aq!1kҖ*lJk(3J@3\dFP}Qq@ /ame*`f')S L%e@-ozhhnver;HYfd) QT EϞ}Zمm|:Y1|?]z_>jH $:6M#].HɢUH0h6{fw'eγӖ1_:뫜%M]| AEJ0!XGM1+ ]"FSP(յJ=ϒ%f10JԵP0j PlVJƴJjCO` 5W>`n]'Aфʇ{N%T"w ZACp@ѲyB"|ښClYod+ o$֓Ra=L4ki[B  Ǘ{L寔"恉(ȠBӂ]̚f4vk;wBm90:J#E#"Sz):%bkp? N`%zĂ;%d* @!rgR$ q[7@PWCgo!ykǣ\ToK=g/!ovb|mqeTt`3kZggܞה95]Ʉw鵩n:ܓ&~7R)tH,@b:T}DʠC_:g0J̰,jbMC(L5JUg%hJ*) aV |MJ<, rYJ!wJS@p~8<4t$`( Aq[pw7aZS"zINUҭl?$4x5#9)\XRK `x&xPBNCk(РȖ 6BQz ízf"EL:*s-DO,-@,=O[:AI(UF1"&[Xt7wۛQ~/aQV>6S:-%k^`,pnͦVkF:LC\w&m#iO m'k;s$ T LNN1(vGɭa)RoWK"1uޡs0:t"ss0E !&91ON3LPӲ((KyjBJ|x/.ȍmͮ4Zx‚m8+$"%&]r_W6OPq''L^f%qz1 lJHLJUHMH"BE2#9V& Vш2A%%(mDb #3Xtw81g rzs1P!LBB3M!HXZ2KA^5 rVrIM廥wiS'&$'G_ =*-E ڲ1l6SsHTY_S&k#5]k2.&+(nYKգ_!U /MΪfګ5Y4m,֛ZJ!Ӌ;<|)V5g-t)V. & 7qN4 +桑\k8chbp&uVowÇ:9J`,e6+qui]ݼf,:q ڔs P}n:qMӌCU+W'.4Ǧ1gDM,}JC8q::CEׁY ƙn6+)&1…!,R۬s&[ѽE3+ލ;USMMs-޵:r3uwN\5riѣ\8qiƪF+)|"2iqf#BP qV9턑TEɍ $Qe[ ժ$&z*1(+nJ8HG !;,/$M >$aA$1\WZ4F*e` h72kfV,^:S5+N9w*$@"F%:/ۧrxRdׯDNާ#+鵈(_F&&ʋaatkȉŇmWV5ݼf[fO^!*@7_Ę+ )Shwegef2;:z.2 BǍ%261j|=GzL>2/3XUUC+W׆{zִaFeLk,y]r .O;M=59''c*i+DDX* AAH ,DBxz;F@A"cp#E @AA exwYf}+P@Ӥ: [J{:EBT:^eJX%UFiR)&M7R.V3>[5. cTxuN6Q$b-(& 5e2f0\w*o^Yߩ^M>Lşxt< 5x0Ş.Tფ)]Mrmri.P7Jy޷K8S-*µy;954amUMLuG "iji :5]fD[1b1CrK5cU71o. B/E=D FPwYl8( @[%<4+# !t4K^7gRx*и@\BӢ GZi4@u|z~~Eބ6(+>;.!ID9R\C__fݡa5iHb ##[_|C*+L.-28i|( Ao:Ǜq'wfU8D$@LP̭6Q%Er8;Sϝ b# S+LҧJ)UD.y3oNV 1eHEEً*ԡFs,1fWmZl՞6 گH70fH%ΛbhBDWf"^BHjaKxE :mV]^yH=Mh!$-D1NvnؤE7xmN NɑI$!O}uݶim̏z5w'v|Z`q!geӹԐF"b(B0ʗٚVotm_Ȑ٤-AUsDa3H~ Pi[Cl [[ibjD 7ausAPXS5 ԈFL,1 H˖A$D!)km\>(q{`Z2:[j`qAx(pAlWV$LӫgapxL\C` K@V0bdh7&<"7s nT6=m\ql<\|V@,V1b| I5t$30 efuHj=Up7*![1fgxvjNpo0IA,B;1N\pz7ӗ>Xd x(gFUMA?հ^@_ +{4NZ\kko Y@EAb*DH3xxl<,Y,Ȍ6s`UC$ fWKq~񐷔6dZuqA2A@m:t vaVYԘ( xmhA $ddY!١P0TbĂȠH)Eʑ,@(X,YQPDT`Ҫ-+ŒR(4v] S (bौM")Owt+TFf "2ýEqa!m ubWP֬8.y̝Yѿm Ʈ~=sg" Z1>ƺ\hF @>ȁa OؑOyyn:B :#jN +e`E }nswvA/iwi: MI#Se]TP7]zX<&ϳ3:.*Vk*1q\%'(c0r?gnD1а@(Hu&p;i:ﻈrZjy(HkgUgW^,+ bmtrs=Z!z/Δrr7¨}DsRH~[ϚW.n^7%+2TqO7dE*+M&*w:'zlyW.=zq3f:p`b8A -*f|BW,PSZ ^.ΟӅ'EP@1߰ FAkXAZ\.'@LRИNZS+u4J[\ڛaժ|زh6k']Tζp&DSAk6{xqPR(8 6=so0A=r8UDURE5g2 /~(o&JFR[)9  !goWD8*db Z@Czr(jq~>[_ԇ1Y[熰y's,^IɵF> tf -QO:MhҩUhyHc boF3XrN(PXXMݗ9s 1 {e8chҕ k:0ǺϾi()؇yd>kKRC9;)}jEr!`_H _xFf-4ApԒc4()j !8 |9U@l@֎jwDŽU;!/E\QP3t(-9LG ~.̫7zIxPdREPjY0`2 C9i:utH3 "4B}xLM J%F;i&`ZV(J NN>4FDw_%LD J2% У5TY >.;{9wpJ1P5i=i凨CQxQl:o"'k<ߗWz槣GH $D$'?wC|=u۽me<}&#Z̗)m3k.Όj%pFf:vO&d PdUgui1lD IZp`eك).8i1 LCH{EbqϫJqu"R@\20Iܜ0;M)m Q+2$cC,ɣT̫y{yC&VlE6Pی!.2UdbEj.́QvtEer>,ՖFM2'R|r~m#w)Rmg e0 ֯_B@KH@!QR=vN\\\qA @`2@4ʩxMtI.^! "B +r94aEu(Ͱ "WF)T "M[ͼq3 ~~NP8!kLMyx/8@0A[.i*]\Q|L0]jRRѝfjP8% YXL fdy YQqlk*0)qٜaQE[꧸䶇J-MI0„C=EΫzҞ:ۙ kVL8!lߐ}]<fw'!.C٧6i''vN<dRKv6gxMK1Yj޺ærbo9rs0aJyӇc%:aj*̕)M&MC9Gi9'-]yܚ8-AEV'e`Kg;Vlfےca%[=+M̡@X ĎIn#6[ƧG#Ð$x̼8iRm!hP &\J]ʄBԁDHa嶪 _3\*XrWi5mU35 ڰXi3eqgkR q ;vAMyΝ/ɿ/DK4TmUf 屭˳׭=]M&#`hu!Hqt@D[A**Fvq^f0H!o=ϩl0`) 'EYR=P#$ON=wn\]C*h2! 3E)xH| 𨲕[r iYZPW$&%Q9͆=t[TRv*?AZ Y}1EˬfeA (HMo'aXVqkڅOywS*6dSR.KPٙJY4:/S(u2p;? G"E0-q^jLY`CBNNMd,!Eʠ$B&^\]Ko(pJ4Td+$AѦO ف撕~.|?OØwE0}A "uLeT@gXVU\E9fsTοnM8Ǝ­s ,Dq]B@H_"y~_G.s?.Vˬ/tcokହgɭVzP>hZgL a%R2AXV5a4܎)CXqsRstZI;1.^,Q!~7<<1OK';4ѵ2J("_-ȇW<:o 30e\f6*ʬʬQQP= ΌTQ1UMɞX0 ^s[6b2$0 "S\厼Cne17z;09h NuQ&+[ ##oc]0rMָ()p# !mYUkЄLʤ:HMe甄1$Пч_7gEQ&"OFgG2'ND: k@PI[w @)ٛpUdFe@cT0r{@5[Eac0B2Q~AT8Jq\hkTv@9]<lw(4C_(1m)\S(dR抮R8e>_;4R2Pr>% 0CC q  , K!#t8ѰDErbQNK5AwrB\`^b66wL(j5tP3.W<(Vj DDW] *+ &]BƢa0Ik߹Cl~!(e{e>8Եz dqFt  L;zP8Órhត缦fP\)u qqgU\l4Yd8|BիND6R ΅Wٺ3y`ȈwnǷQ/x4t \ۯc!IƈNdo&wW.)mcR :ԈUǿ*e]S.ECVHIricX+#LHS3#W:tf  V]Ss649<73zjOkTM8vkD@?a$" vb *(?SK"gD H0A|noafi~gfr=-+C׵Wl* In \tSgrt:^ޒf{i}# 0Ɋht]Gg@IMH59>ƻw ' &]icٛr+]ﳱ`zֶ_j 0dɓ&L2dɓtpT6B2*r&#x~~~~R\ni^^]}z`;t\ m_ ÇCo) iĕ w(B蠦<^6||À}6uvEJ"n/a>i"S5N9wcpѽQ>o?Oě{?r=R#s$G`˶?A9\ea~?@:Q#!DAh @ȱF, H6o.VqPk_dþԎ#\j͓v3?:@Z!w \6}TJ; 3"#K[(| yicsD4?<2o>Pfn RG,xfQvv59j0ʢ1*2G-Pb7? <2iD)|wJO:a@QD@\o`^]^mDOܜ~[{6jsx.,YWs!|:aDA1j*8y_4="o c4T ƋoлxEG3_D@>3`Y5DE '+"4%WeRt^j0!U @ٚ뮦loZU_kn|n&-Z? aUepcAK) (@zU];0e|eL}^LubbIL$]|#wcaJ`VaM[gO9,UoeOqH^_'%EAlY#Ngr:[`2t={r,ұXL D8@ iGrF@%kĩL{K1yHۯq3&Ws]Q!&8٠Ip>\AT(@I>?!X]޿M{Y 1$4۰OR^^ՄU =[oWPP/,ƶ~=WٕǙwo+tb]%sb96 D:hWu^2מMUS4,@)OK^HѓvjϣWejl 鿋C;cϫt.K>t4$(aâc7DBl=~}FݹIVqTU6>[!Hg ~PcT9~l{_s-X&a}U>w;igl[$ºf_M4Z!L*~re 0w7K-6&zV{jŚ];'79 }N:5&XEYb&%:&%l .SB=` ^?T8> jr4Ոhp?n?wb}+޻D .7 t*3PV,C&$&@Ba*ncPyn=~oϿ`H#l,@JfxYQ<[ 37cUOr Jg?{NNTNMq[y^/>?g=nhZգ)(`7hprnDo})&kE7=e}qvzA0c1deP>UC^β`fYAua3u_Y?r_Oem|%7E9*JpcT$2$38OtP7Kh}=\,寛UU_}Ӂ}qu5$}>I+B q`+/~lefNӳ3nG}xoG;w-;ar'W ~7d &L0bL2` /E@sz,̴t4dT<, ;R!"ݧ_}iLoM$hz1ӝuxg _Gt*Q;znxSηj< IPb +o'~t&OyBBLj)0z bՖL};]@Uol?ܲ7dI$"|w @S|\uGԼ[i5p?=υSeױe41L EԘ J/Dl@`! S85|;{8maX7̴@1KG0.zU!"NG~ϵloQjyɺu*,%P)o޷6 Dk,v] |۸x W.eN;}p%6Y2=ˮgAUt[.G\̑HOgUɟs>lycd^m'LIXNUh' bV@L+ŲXb@}]7W1djKhaaPХt) N }vzHXq  T_i:'|$ExpA^g>z`TD݃ņc}uJ;(D~aQ]jFgraM^[\7el S/Y$?GNZ9a$ !?#a}B>!K&ŨQ)P?R+ DmM%76D0 A1 Mtҥx419}#qXP(8@> 9*&W*G.eS_lX^V!&PsJ9~L/˺`6?o;?m{;h0p ! 3uh41x(5ZwbgR0]a3 k9Rti2pp\#}Zm‐ Oԉ+mu\][yjjM۞[0T@yE8RH hbpg3I&?y qhdD ߗV_ AɼePu]۵/K} ;Oy#0b,EEA"A@QEdPUR #TA`E`*PR,bEH#bAT2EQD`PTUa "((TPX,UE@PR*HHU"t(2("XEEY"$DbVQQP ,U Ȳ(R)@X(# QEC\R PR,Xb"()_RȠ(DUP ~+ԗpHx-ztZhjk*/Dž9~W@fa,ܗ!;`.m=Yt:5-lp}@ѥgrh.ƹ^ sSmW7YYRޜP{\oʁ5D?Zڤ5Yr0~}ٻ/=tXI!E/?_Mvd* 1?C /x<9}Ax`PYfzĽ3t <$PXCuëkDIw1tj|5VI @'L! 1†( odmryeX%WgT/>P`2fDRhRD 4MO3> W<6jefFָ]9FZF`HҵREXbFyF~>Lڕ)eGwR@Elɉhk?"ӗ?ay:DVN.pN~N,H 'MRsz}׊eS Mo."^:nC,F">yeէ.< L"D$VwJ4&*M08~{ @q+\o%׍EرA/XE5 v ` Y) 6:1ƴb\xU񼽎3>X*dH2"## HyޣaITYӪAi9+me_O,¢#;o7*s /6E'g΃}޾T{a]þ[y6$yPZ{ytmwG{c 𹟾pwVyK9Ԟ 7g.z^ŝ$]bzTR X000/P y~:6 S0 s^5zDFNɸ %9IT'}N^,H|7HhWs2 $1R !!7\ A-Eg)Uy$_a$3?88g*?"N^K#589Si%Ԓ n ܐ3W,!̕Nf{D`Vg:V\Z=~`b 1P|g6K<+ߜCl2uA>&q{=Z:_r!.<Ƴ`\SO/oXt8:4`K7(>#6w^Lv]$x}|A1эUR@) u }b4ړ-(#I,E d/ULɨ_d`y5-m'VÚ{5j? M' wG/=]O H|vFZ 0* W^0It ~-;|;h Ћ;Vqқ>Em\>? y5s!7 vc>x)Ѹan h\XQmȟaJcL`Xe3u 5ɚ¤PEDDH "!Y U`o?U "THo+kﺾ^4~Nv?)3 b6g2zmSjT GSCB;NKr_GL ל3RuW-΀ Ҫ #9xqQIևWv+,RP4yN]` XQ7k $ i7z't̹В2{.(@ [! a7C " HHQ K9Z$j3+q$*BT*s#P8UOSaBUUS6u}2eQ@N? '_ygרzo1t ImVt3T0qb 0ٗfQ%'36enII. 'c@X5$oLdCOMJ&Վve-Lo$?&A:>pdm〧|?BA@#Sٴ乬Pȉ'epVN%DxPBqh:{~L^?0d 7HWwS(_"HȤ:DCc뙳@JֲB#"Wb=Xq8y]/^VSR"Ncҿg%{kSUʓڿ)oy!?#!",R" (F( `,Y,O̥m&RV ~Ud3_߄׳Y#(WEWWu zOj%;Q{3m48w7-3&q:םLkھQu޿_7;[M{EDP" 0x["l}6=YCX }/QW·GV^~$Ӌ$sb0ZR`ݼ)= P?zXPRA`,V(*IȢ" Q* , UO}P A߭2ATEV) Ċ((U $/z~?{͋}_=*+", QP>B*PEPPYW/dfgdH0@n+Wڎ 2 fG==c<].ٛ/*bkp;y?l ~1o!S@r{Q*6tl}[]D MWB4gSO:QhxOޫz=E[/;À -jp݄]P qS"" 9u$VG :Xga~Vx o* ACl@_ LHWe T9s;ncj ߣ_SXWg_w~iyN)AFa'Gc>6O03ܟr$  n H8)'O}T@$%.x2r +Ĩ5ƙp.ZD: _ݎQ~ s%m6, 9#gvqWTfEy6ᕉHV(:(]Lo[ v;.'~ @pO7>dxz;pGޡDh$v,8}aߝUU|gZRqwԺŒ"xH%+; ,ڊ)ui2I$.Er1N|.3$Píig_5߇TfRc P4tȧ qTԨTn\q\Nt@K@V\9D&HJCbGt.4*uM3Ntofr~cGhT=VUb΃\Q/GF|gmhM4 Ag%YG}t eRuŽ2:q/@DO]1(9?Qzlo=ID|J~2wkv"y `ai5c "ʊܰH1u͛g=Ӈ@O~w^ WMKf|+׷f98w2.0u ؜jA=ngesN?|^oL6|6|=Ʃy6G@< Á+cÞ6`ҋBtl^h֮7n)&Axy7h(m{L u>}z K~g>ؽ9DoZYbdxe8Q 84rDWo_GҭwEwxHL@RDTa2J@I_{y)o7C>nߋֻ ON*z$(H,DYHdV 2 HQb(T}ooyo!l(D #I $$dI_kFEO{YOk8JH *X EUYD X,?@FFE⹮z $%gK}woirPd WѶ%ҵs5x3E rB<@5-D #L lGp<'BrAER,КjV-.y\sN y3顆|]}o,[mZgo ɦLz( .egSo2I~+#qrp٧:#;#}%<ohw .ٰ(@D,NeT)c eN*C?" K~ z }4]U ]6z)&Mkżd;Nq4Mj_{Ct܏9xBÛ34I֑r~=iݠ@k\:f)!~ M?|S P!Z@Si˕ ~:1BA_b*Us luRj(D-AHu2AyA 6.T-J I [1 [~3*){# !Q4Ul*gW[x>A8׭q Yʓ+$̂/jYYQn;>xۿ!G3`ScG8SI3Xz?lDvq'$Tl² T54v{{^(<U~З*{?>V?!>ן_-*ADL f9VvCbл^H#Nhg'".J]|Pf]#g:%~މP jXr;FME@0Q(~#r $Տke*MEZEUY"'B^szP!Zt?rh\&j=SDsf!TZUس95/`ʜZ9>5N+P=Wa)N1() ޳dU@eU%S5@ls'L&^tkd]z*"mVrm.\1";*ky0!@?:Gtwe:3rk5 ZT>4܎[ 0(hRNL7c}_>dVp5obb' f-3vsș|w)p}`'>*Kx%=w]UJmPeD bb;jJ [])H*]%HlG.W_yhtIMa&IaoD<7GYuLlWQ_rhc)O Qv S Q^:M4IĩhCOm35tCs =2u DѰ c b/.OࣣhFn#[hF/33)/cT($b?"(lsA*@; u׉˘L+:忖KwR`#I]`.&dbԂ{JjüLUҚ1?Wh)[(ғ+e`]q" ԇN{ .ZS'J[SC9VXaHg&)mh >UF~BzsMċ??qdůZF[_+ 5ыel˾OhL>4!*\i+;&ߦ߇# wzSnYUV>l_5rϰa l(# wϼv$Maȕ׶o|qI8G^&?ţy#(V 9cImh<:O_p?MjXvgxRXk<e)W$ A=lV<5v3 !Er攲"0~?*DH\F8@j59ݾ7I촿`@4{q@MHr4b+a[b]!nۅ~M˚4kUX%l*tPXkᎭNQێi!s:?g K<oxULoZߡqafg}A <,8^Ep~/rPH^ iεQ qI" 蕼_Qߋb2o}JvhbQcɠXaDr/-];JYۆtݺ^³j,QbKf@K"8*=W,eJ9v1̨&lcRDٿ}o=s^ µk"ğ/~0=XwF@V0(X_K*=Ɛ2K/e n sxDۅC`W0״E:bC -Euk:D` kN@.᢫E B7`| D>c )ua9|UZl :!|%&OTUh c(8.?{Yǡo^"gV#VF:|[7vM3\JBᕉ !F"}Y3fWBbdU۫ٛm5 Sg"̶2Et[9P'4SX3'h HpJ]:E*sZ.;L2W{&4YvG$m(#qa$dbݏ@5 vnP#vsVnR$XTYnp7 D`ctW!%% XFp=CE]vl{H&zX+S˷ !2Oɣ&UE6I_&>R;֑qW'I~-zNaɌA"s8SLT'C>L2 | -5}P>1ZK ]0v~5jxvSѷ Qhwpc|Zci|~ u&I]7{5'DY}{,[p>{j=1 #1Ter8U.c70%lAm4S` r!=$Yě?FڠdK[C.RvM\Tut5L 4k!)ʂ4TDg'^c?ڔkȹSao]nCjp])>=W6'uOVf#::x~E{A\(q2lΎ~DSXRR|R>\VYlIJW3%A A\'Kmc;$h%qrNT?0-^jl4@Ĝy$Q[$nn}`eAYלk> !VΥ+OV->cu?-e؁-|) dNqms`x2} yO6v%SF7gP6ؿa(0}`}d o7&.)Pɔ?-`byZI0mm9F d "-֦~hBR>B7[$p#'! EkᏤw1'2z,!@  ṕȯ f.T[UƝá@-3la(# DʥO41ۍ AL˓PX#Cr7P_Nj >F 'Ac< |KCn ]77a&j"9`jl/~@݇b:p aIT%l4]<P]=ffSca \ɒژ~EO\r4X3PnzU}sպCC:<pxwֺjCR]qmWŊVt?0mʧKز(+~f̺5mxgXY(E/ºf(^j#>=)+(o$U[R!+udƞB0B"Eܦʐr%rH~OL,VB\М-'n sBN #mzǧm1? #a2:HЊ>ʪ堞8dkRS j U);KjCӘ6dYE)u aƟ#V7q!Ԯ:{IH {Y4ɔ8Xsy'Jor2<_6n.JY|X~4.]#UqAm{y鲣2'[Gj.8hv B91.G iwF6]u]jJHC}P>HϹƅG>LXY H$Ǒ "l|м $yH^S62 эHfj0s~U{MU.%,&b/cq L)~*Q둚qP|7!f-}CvKNžr*6FEB$f=KsgH{Paʔ=R衖{|M6Alꩂ~l!?Ou{ϱ.>qHWD.P(㏋YxkS1]y(tUI,?)0}lJ5&"d "J7bt! PR{3{-3mOJ"6VH9p8n9܊chN*932w %/558B$ɰ,t>fDg(VRgďo̔1Avܷq]Ҡ3Ou@ywqfX ȝS;8!LC~j2-.i$;@2یh =.#oz9VJA-bC'zPw!Pq"~U`>za`{=f}iC2k6ЄccxR+S$ Q@V]ޖ)ʻ ml A&q˲[|w" Rh|7ਰ 4 o/*n :T LISA盂Nƃe= e \VQx^:̓Ar1W2en23}\'4&Hl  qDJ/.wNM,*Tr"켚MMn1>rSҔ]uDm|yOp\雉ܳLF?@o_J(l_ZLJg</wP gF[@#rOo},껽.(vnfE&PObh2VfK8Bسύc O۠f/kBqvL6xl%Y^Hv%z;P~*Sl>֥/썼L*ٹ]x%/?@Ds ZfZjN ^&6p6'ސ#IX\?[HFa_n_Da^)E1 |*ifT#DZbGy?x-k k]d29c;e@x lN$S]f0ƌOJ֣|Kp.J9EQ{Fy`}5Rt*)]X pU/Ę'd)W$ˇȍ^٧ mj>cOa7j[wks?+GyVi MNYN-`^oRxP`?&s%ْO&an&k'U+?5p 2,>zU p3ǨXkSePfo.}ϐ^V==.ȍ &hb*8[#d^{bNvE׵Sh(<9H '"lϡ / Aۭ![2mz'tF#X$#l{k-UPѦ&m,c[JO>/Ct˂?`I;-Uٵof3*ODPwt#LH)i$KUY0?FoV%T뽬:utB'>드p fSw[UHcK##ڻ6t$څHQl@|C=1n6 ^Qv]D URM5;uPf\&m)(]ҍ(OjPh!UA\{{-ƨ|T}]b#B&wzM%az+za>ea-Ņߠbvl|:_ŔY4xű ucM[ 2NpBŜ+R{iNrwU%7tV/37syő+eJ)԰}#9'J70WC˗¤>H8O~w:T`_1*{x۽{ kjYT]7 IQz=@Z-]T5j#qO1ŚL9Id桡S]88K!.E\o_~;ӃRp/\G}koGxcj>Bjx?ʧ _Y\T}/e06Wע]IĬq,@ږHEfٰBsOsl#x8}ax D?P!FZ;E#*xrOMɩid|a.|]bo>8.hń ƇQM ql/EC䋆쑁ޯ,giw{P []2YLLuX:|C\gF$Gİo {_K[] |/,p&8˖bܭIۃh-Pt}6H [e,V{[۟t{:?x(YO?E3x'D)C=厛k\6QĈ)6TzNc|?'hW"h\c1 >CA3`^31zg3jwR4'#t(MI`3|lT[oC8:9T7N`DLKrztcIKw$*DvLIM*T+N|fxeͷE g 0Xe_2^1W/~j Ip5ѭi܌ B'j TQr3|Z#ڡ"'PʗQzO_=',dٝ~.YQ8ɕ:Qi܊&hƎMXeζNWjcR[LOړ cNxB|X38N4W0'd¡P`5¹bVg_gPD*P ›)jj2٬؁3xxޥ{ bYm"`\JMYIY7LCԦHFl Q)hGl~I :J㖠d1aE]LqCLIh}ty &,# 1 FM;\! 8 C4ϙUuǟ}ffW|ldqƲhҧ#T:,$O>"3NQ5y<!KEEv~!; "~Q8}Cgty\w#~;ݩsBU#y!Sܫ2|LA01_qF9Fxi1!nbXx}גܮ35pJF3c7xjql|ܿ:_4@$?uʫ]@nF^C*ߡjFn,}Du%UˇK&.ۛjSc"QjL? Ӻ9*WŁDDAU.o),T旟H}5Jy~j.X4 5r@08ջK3MޕScň PwaНYƸkЩ?Evy}XF7EV5II63_mދ{mdA"*MXY3&,ݡgg[::Q3{{imdTS>GVЫ#䖧JzByrJCh'wR⼚=YC ` _u;jSA9'tUU +KUVׇvv}Gn?ӥhq,b_u5ex}1ջƴm'gH/NUq ஸ7aoyFD=q1ۓB5(Kңܬ5r5vA}PRq`Q8H>4`L`$$Q'7|ʐs#l,X~MAnԎz\S 9mrX)!;-QÿI!pwgS֫QVb 0S [-Va5ҭ|9(',F,0">FLxUf\:''%!\ٓz1(4. 9(Xrú֕HEbuz=.{u&8Ph{9Njc6үZ2;Ҭ[/j?2ix89{G{ G_b$p/ڜQD ieG" дsvDHeW skj '5FIQ^XlݧUsq6mWU]{٥!IbR>WRr7|Iw3ej>:XR);:nF7T0Gd$iĞn9R_DJ'i钹O_ VGl1R{A},8{c<À^j(9ﺎ0s;4`F+#48wt)~ܔmԽmDt\H;jOu%Nuy׷"`(!`y܃S0ZCY63Y@`'r}g;=׀@Kpb\#%ᒆk`ox:!'k+NdCmQT;uVd?ۜXS4'DEY[9/ܷvۊvE~弖Epի!l6qGVuJ)m]>5eů>ܭ!u9`2L,=g;", iW_?3Ζ @ؒr%*'.s~ >Hb8z3SRi/[AXh(W0[y)k: 'Y!cx r:J OhlUv6—I6|>q~l0dX7h#a%|dݰ.%Db{Ry*=^XDJ0A񧧴|ein:9^rD4)N[M J+¶N-T#E=CvOFfOM'b*U+k%IpKM]uAyC%v09jܾ'(}t2`84lh"~v j: 8@2DjH#`6mom`sӛDLz|91a *P$1P4=T)w1t,P9 /ȕCâ19o&:޳TPZEvB8%:502΄p8~oS6*W{8<1ԠWw3ϱf?fMn/FL/(dZL=8Q H^[sr\Kvhv6+L4FcT]N)#HGFAZ׷ǼY"ѵ: `S>˜7Z+)g.pH- mhMfY̭V5nr"!W Xsb.Pyw;7\v:]ɺ%B~~+mSAߡg@ UYCZ/ JR~pipXis6_ 1r+Lp%dT_uRYk p~&ve%t+<lz^7=ɺbE!qzhOBݦm0cIK8c7T*I}jh\8ُ (ŋsg/(/1Z;,;:XPBWrY z+ cGS7r80cC&UD <{XI}"m{nbx`o}$G,˨k)H & "|0hv֒pe{8ywO49X W9< 9AE{]Y0"щ"ӱvXѫtl9"He]\#0^ %RHr`mH،S@ ,r#reGU(. 63K)y= RQ9}Bddԃ .hTTzMD!1_'ۓ 98fD;+ W^+} 2u*\ixStxSuO"!lœbu6 1V 54y/+]XA@Ly  C&Wmω0F4n!LS/Ghޜɋm`EU$/Y)QI⮱pC{`C D7iu;AQ{s"4\ɀuma,+PS=T8a, PN^_^:p"wЕٗ9]+L6N=𼔱MQJz;DS :Q<|b-0[x[{^֥,PiRueg&lɂ|#) ~cЎ"+1mf3ʑ%IqS\7:EAl=u{*g-d0/4ym "7- `">b̠\w_6 uFGYm~"^]Ra7B;UF=IS>Wg/"$;Ũ!.?68^,a2Y^h7fWgh\?/3)HU ]RE5+W*Pvur/xsW!u&TlΓo`ʛ08dI0pZIe ӻ&ڹ0Oa,+,x;HNz<#$>Y!Wa:`=]%p3pX*MEG$ϧ+7~2jK]|A(m%+VT-7ᳲz(=[V K7V#VPIwmhI&=xYt됄ے:hCZ|s7+ Qk ] 2AN䑙{mytd砌𻳤#u$& 4|N|C:`DJ{k]n=X-:Njӣ |#X"QKS_]B)G{v4y0cP?&o x#jj/{tl#dXapZCqד^] њ\Pz$u*=;1I 6 _uQAY#41l=ɇ5`(W5, G'&?Zv*_G|Kz 6"ܸnmA4Z"K`ш!.]pUUNqgivge C.@oi׬;EulAK_|}/wv?+?p{;)M/5I`>K;`yno4J1r;l^wPzt\0% Vt6'n=,̥6 Ya`)Wjd \[Y ߅^T> ޘ)*d87+SFCBrw[mE?*+")g /%ދ>yUjjEXcZf6/zaUDX99߹/UMVHMʄ ],qZKvKwhUlSh8-O+[SuO(@otSq1`&g}MH&Lj/6|%ݍV-"NxC h'R\? g5Gqo01vy"q1%(Ī5ZbmQ96:+1cY-Ua"+͆0r g>/5Z`* Wb05 4" G "A7m Da7l ӡ ̣Î8s@Lc3-|B7rtLOPd[;l I,=rg>e+Z+0 Z˜1Ɉ3ⶡoUm)D  gm霽X!TW3n"Lm<[fE\CJ gp*t(Y m :bH?5:VRCqY1:dʡB%k |WBu |󆿵P5]z ٸ&?z4 D֞$L(K\Ά?KSbX𽗵'h8tcD-{(OﬤlsG}/ ]vQH[UNJOjvn0-oKYwv)mtASFa- EF=y܀Tzykʞ,ÿ9dո^ k-36}nQS"tA$Ma6VV XIHƐyIM:@Iekrw&J,;+',7^ t=hN7{&L|i> N[XbP5lV~>a)gYx!9Rh?]6ʹ:s!vKGO )!%[oӜ/D.u-d9alf mW-,l]֫S yƉҢ,x"mhLv!3r$ٵ@Y^50Q6_Ux+Q_*{vONt:Ġ5Q: #bǎX['_GzP$`KI<"k}Y K*c.T{д,dۙW҆&/#⿅vߠ#Rfc7/dpٚu')JGj uagAP_ 8S4e\k_j~ UlW2̷+}˕kH+ TÅ%Z# Yg"ʀZc[ .bI K|kUo5-f %Fɼlwa!d61b*ypwڤ7,{_VLPW[:E`H?4jC72Q*ZQvvcgA"9 \* 6Lv #.ۚ{Oסu}9[J ],u<9oX1Jfv`ZiEI(VHg} ’5hk{W~ JôYP<"gF`~~W2uW!l h EbJz㧓tD;8_u^^"i&߉zYF[V@4x ֭goB@쭈:F3Ijj ,=o{ e2 J>3E$'1bه1W\t=S ^._ǧ-\ p%c9s"TVOe.rI';}+_/[KϺݫHITrT#*#3J512V5R% >˔zόiY]r$4uNuj&_V^A#}g==Z-jk;3eWsPLpKɝRɉ8BhABFN9F}&g0'z%\.=gp" z xHﱹnnh0K#T[^ձ - pXDuP.i %[!f7s#0/wiV>\x]s)aq)pV_ 3 [ O@Fs]Wr7{xXw1Bh>o!EipcK/r 'N+4\N";%߲MiAS&?L-3՞ޝi03怍m; =8NV<&"cdQ#R @ ,9PЯi(rS)Aʾ?S8ao|MS~ufz7mn~n˹XRS-]`s4<|r~6a ::l*ZO3 w }I㻁ZL_O\aM), 3;hNRXPX{WXa"uG9$FJIÉeK!/%2j\J7bƣyOttjXWFxբ$^Y QJۗ`A7Gh$ [`Mp'pClP@BZ'D)nV hKIKibk*D>qH/*igiNI CJ g?nc?}MWT~]xfg=_j=1{KEGA]bZ-~J B#x?qZ3\v/3H-džAFf7K K:pOOכ"z\Zq9WztL۲UkSeiGfl^"gmDfE!fSA,mlHUo) sj_\@=aϽ\87l x3rwz[AqB \k*UN' k܄pf l\\B( q>87d P:Sg@z=.' з~ o 1z0Da jv&m{N{$eiA~0Da0A9WWZժ.ECH鵄>L"6T'x#Q8$p]]׺tr$a(UTJv@3|/A8 ֗X0çF(aED=7POYm lZ>=[0n뀍I*q)n?4y'S}9\}pISn(NV*YoCN!_"LZ% d?BpK9Ȯ4n|_߇Cb_o֢.XFC 2?(4m֣tM5_$ț93jڅN#w3튶h᪍T +- |km/Ug!Z?4ST$FbBicZ8mU~lֽʉ2 /:f;-D=/0 U!@iE<©ł\/*VFfSװ6maMm[)hPiE-O3yYv d[_e3Pw(z'PJo- xԤ O{Ł;$GdW>evp&P9l޳b!^<ȓQav]0-4u?#.*C@ L廦%p0?ֻhs#3Wfz_%a]L} +O%4$ ThHCyئGpjFjGZCt;gvM{!3en#,n>J4`j&eTE赺J[cu89qO[!oy|'0qE̹awG9kx*R6[M*3&!{.zP1ϓl2վ5p5֒.cWg1鞰 ֩`rGJf]gGahnT>Z8݌ Fz+fhj:Bxkƨ]|n/z޸n){'k"6 pSbHҐQhK#2C@,i{N8? w:-x`;Q(")}|t 1Pب|CYR8 _yP![JtxsLw@eƛX$JJus[敬E+.0ѥPoc`Otxncڴ+$*уg7XCq:VxJX4^%N᤬ئIRB|^zSJGо';Vkp&4^Ӭi$Zn3dw)8A.h-CXGaEE1K7ʣ%iE轸0h ҷ(yNEkВ/h'${/>P9'-Fx؞=A53c> e5? (4yzꭰ.LXG)`y3<)S[;]KĬ j58HBcRn z~. vc T_e9@{=tuF;6=LC*J+n9t)@?)Mr+iHz[)5AV ҡm_y/mkHAN ۊ_.4 @nZp I|lGVvORN8>Hm_KJZExjyQz`(҄Q{jKx5ׁɩGgXT @qV#t2( %K6+QE2M.yvWf6 yn23f_P^$|S"Z$p/q[-?8$wzLfۆ߬Ѣ:j!94R0)s\I܁E@njrXVھ!=Xhݹm*j{Av-;/nq9` vb _ħMךyј Cdcʇt@>GĖļq`U+75>9S2~M\*TWX LJE^d/;͚ZG7I^ zlD X^=mޘ§ tw~] kT# l늒U}\'9'p.L,惾jaDnFw%:6'_ }Mq`^ut%nhMJ_jZou 3Ї:/ߵ1}˶eNL*oEx[/ϧt{/  lt\NCEYKاAgd*?q"XvAfMm~amdž}eO4/9V&iL5m~|@Tl㖱b.TrDfLf& `O{#'$:8cŞrv]}ʓ?{4XG^5l6R} e Morpk8f h^!D%kʓyE/`),/) kB6D\SöR9LV Yg?[+#0wmh`|w>YzF}%$OQ< rYc'\ªAGlpYޡ].vFrD+ A>=5kfaPa..Aik(m>WJ3d+&bO>u^SfnW*i\f &k?P=HU[?qna_]w jMO.8, f! 㜏)3 qj-?4N.f[.'yPʊfZiI`ѐ|kN VMcmTbNZd\<[>U33 yI2QCχJeۖW3=_&Tl~NrقYҽw<@Ԭ\Q3=lOɟшJguBs[9ina8q{6p "s[6@iEQњKT^ /Rt@]|jlqP6](ُe@ 5UG5\IǬ޾YH0wnH~j3A!PZf sP-ާ"ߌ#JxH H=VJ{yp i=!,VYS"!x5%Jizm-⻐WgV^\߅>_䀺Ommpg ійqĂ<-4.1kּHkߪdKWcӈ3euڍ4Le#tC mb&ib&'AJq~`Ke1`fDw}L.KHzsXr_<߾j oTa{6] Q zQlqoqYwi(T$`4xEهI9+2ySoar˻T|oȐi9!Ȇ!^a2,T!ES 'pSagNSkj1C-WPu :[MH!5I|:E=>Lߊ ݭ.nl^(ڏ$7Ʊ(GbMƊ͔͟FdGb 3 `foK>.8 WVkջr&.nH0x \N(:5Yr keGFc/=eWGDO-EMN7 ^ѽvtY9,=qn}^(+e¬$ i?DDY_O5ܶ{?AtʂzC . ,*\8*zOOsG/ԈpHr!ǔ_G4zt ^6>.*!@2-"aypgx|OM3Pڅ+Wq3 ^ #(!XIhg \ C͜}iR;u!i'-z;N y2l<4oOuxH G`Yz!A0 ŞjϧV3%HŢރܱbiAdFQChųD$T@ڒزWA,ÿ52>/1݊ "]OPO ,/bk)yPX^i ?2H1v@tqSS҄H{t,O'Ng(Ɲqf@]FN, ]@tI!e;ik_iWjL{[iI/?'ḑ#@3a)™DƤi;QDsaP1LC{)B̊ӓo5)?{眢%F|;id8)^RiFoZoD 3'lm8?!'/y-/;qt-soWSeSX7WL%{5!,7J߀;XǍehd8 i JKqF)Urgbk ܦuoa "O }׎| 8q\H6vm/Qa MLLdz #}|wzW׭H_*_ƥ;V2 FvA 9MpQc]6C,N**սOĂR,a"},,^4[̀񪙭\#&p2zkSOMQT5Fpiz%dM/k.jᒧ*9*gtEd3Ӓ/<x`2Bց'8 -1d?|+%kzؠam8;7fmڤjNZv},*i:!gE.;$nY_uPEA 1@y5yja G'>s'' ,΄E_t* W3Ib6X=Vti]c)$''Cx9¬;)xW<\!*LFG[5uyuhz5Nwzd1е`6AxI|^}7u]nKKD)nN'@us uqIJyq$Cf9Žkбp ډ6#oN=ȁ + ;ӄ7.O ,-.(-N08&|8kapT1aV>|gOۭ(֟(Uj"c ;,7=W5Je.M/ Pcc%mրGRٞy߫p9ɛ= 7 w>ݤ{GJ, ~oIRr \յC2"q\s_YVk@s@0bBes!)8g{wQU\]b<)m g9R8 Pf#MbNew'_8*8ܞ Pң]릭vuz;R9~yf+r_h8Ė&*^'6J`SX;+∬g_Ou` lHqNǑ>.2Q=Vs s!,Fp,~O85rh`Ƈ #€""a,0@^x*GX.P29lu&ɫ_)7\Du>kϤL<%dˡ1H>⭱YJs5yf_.5} *Rkx\ {^UO}YT=E8CA87xyfuI}3OFl:sB_b+G eAN] 7,ޱe1c.%XVwt4i]$@ pa- I>NPb ݌ZB(š?ʠI7QזJ'8*V%dY0<o`t _s7Q=[(kKaدq)2` Qi|吲l|$2P7e/f;؉2+t|v]׭%Mqhrq}Og[G/c(s2]UuνyVN-ZM(tygY<7G S̾|zק|]2. 3QٛǍ^HU6AI6^-- ]:7(\97rNUTh#+D2t~JqjϨ;wrzIOd>XNo,0Zmn `/b4+c^oE*`r$+ l۫GDW#*A]&įZI|/"H*݌5R6O)W;cxſ2Ĺ[#fD!Q٘S?}Z/5Ndlľﻏ眇s7,Fr=i|'d \m8kLһ>h㳗k5Kf_@)g+ͮس FkSWV\ٹAۃq6ry?;sNxijlUc>*uJ!)vZ1c8s-ZjEIAnmF)]_7&N-ٷ5 L>?CZHre5"+Z`rk[:<Q/ \V\ zGik2PKqCD%B1qK߯"5`Ϥ]r+ PIt,Nls2M]ɸްKew.a gJj&^gPdr~N#sv!# I4^TR6-+\v *mqJ~VaTn]&Oe?Za ^:%B(D֖MixZ4>, iV˛]*&`j9LFxf$Z8 ƱAzDho f/vAkT^$p`xaJ%D堅ıdXSDYZ+/2&  A*^! "qVW1BJ?6ZA" Ү5|@4VR.]v~Zo(=lAR.:7A~9xώ&dÞ(qp^O‰3&&JAYvQ8-zH:FsW})Da*r[@u\mrٚWU#z?.ǭ jX@@7LIvQ: fq;{pܜŽ*ӳ\}RG'07Z*5SQ|Bʶ@H].j}-+:Oz*tT+#9\Ip-:ij\;c v*]H0j}vzfi-q Ɉ8$fƔZ,8i=߀u3Ž!i̕%/<>"׈ǔaL7Y+` 2h54Fl75*\ơ mEG}翝KP91o܁^s . #fӚnjsβEI cI5XFQVRIwQt *꯴Y::X5BpٮdA9{(0cbT;Md Aj m()[rë535K+6)٭M kݱyx{Kj+xNS н}T YM}Ł6/+B#fTaTXA5 jc).Zj'pkEΜpI&t) ɷU3ɔ.I0X LN7N,kɸZ״SmZ}e ;0MfeC2{g o ҵCh6 !A\oh}w{ 4GZXEaw83tw@iO%OԤģx |,X\47;A?D qOP+7 FoAi&Kj7 ӥiVQG@Pɴ^;7qdk-b}Ւ;q̾?y"Úg[ŖB'nDI#hasr>pC]&H@_KkͰ&9`] F SFbzj o yT4_ƠݎD0sQ 3ΖUj]7:YlMEcWvj-(` nC^Fh8c&+|B=pB?/_2>s_vq s $:o+GҩO#pT䗊rBJ1)k9`YzaxʛCeU/&?.ݓ'qQ4{gٌ;~xJpԪxo|e*:[AU/^-9/3>T/6HGk걇v[B }_D?PjQ *epXd1@Зm<T#ܥa7pM)MK-*n/e͒i:ם/[f4_$UaaFص8EC\)\" Bn%>&=TZ\sib1h|EDK-0WG44>:p}N)5/v7]na60t7z5xbDaؕw\~??hj٭H[30j+IrHe4B#$Ä".$Aź!WƬDGtnl |+'XQ,-!?+-&͝ ]2!F yaF4JEO͚:fh:`axW5|rGB/[e0Rԣd,EBLx:\ m9E!^,c=&~SC:~ xC¦peQ@\h-Olmf+ iR+!@ӊ8 @+[)7R6pB>p.q67Q[s(S˓Rs%qKx(. |Mj 'U&$c  [p**cFwu{ǓbG٧OVP~zD\ _MQ葢2#i*'r.Z*ƇG)Icwv,_%cn`Nqx] %bbUvQzh|  MΐoF KKj`)C3bLuzN.Tl<=|;(]H7Ip"9"nsH H ?B\;&FECmg`->^hV@~}XKGXPģ pje/NdOJ`rx S=粟ʏp2<5ŹU:%:/㒽@A [錘8c76a>_\%}V_d~efXFJ< :UL]6X$?197`jC/)_+0tho %vEWxl_+ J'dSt-EyV)^Pʹ׎@Pa@1_6y>0~i % .58phݹՀj;qx^|ڐhTLn]:zm>QVyyv Cf qDߟ!V/>ūvZF]Cf)nhE ]DžV}o%9}dǮCd&ʕ/1⠒grngNJL;, _x b`FυAcVBݾ|X6BEx`Z~Df4Τn]MQ>4bZ:΃kpwdLRhZ^{N{3ra{!352Em߲餅cZ)LeV2ta~D˿ $@@˲H#זGth\/`͎1j[ҽ#clf$3rnЮ98>hXAԹ`C@t \a= WFO9ڈ ųd1=4mי^}I*tj<Lr'X3vSY n>p $;jjIHi_hs /-N JXǾ&_ #+݈DW]8krOuDIELTH4Q|F!RYKo <R\뉭-b_ܾ3j29n5CѲOJN'wTM*w? d9~Hi|:Q,Qx×2 AB\Yu@'1{4a̵kEQ휋#9`= K4DtB6Z.(mdMqA6+ȯ+Y\M[5'5.[peW&35N#7E=CąBm]o!]eROUE]@ ^-!qr=8omS%l]-OGᶫU)HbA*\0}p98='_RTu 3LjH{&%##ߘJQ=(2^┦T1[K@\S }ReE54Gمu{/PV[(T6i҃ի߲ ܞpuuaaLv+/ymǪUwKo+5Fy֝׮ 0s6Vw\Tl5TQ|or9Wk.A?/0m^0"6gW)#g 7 bݡC{\%0B{O,`mB;ERهm( :q[;]k -:AI> ؝wkaDΏ]:ʡaut,|l`Uv=>>)tyi$ɼa ʖjE͆3`AY_"J ] 9yq@I:Jӕar_4ޓá} 'ܨ_iK]߉$c6 דK(DN(TSnDev鼧%kxS diwDGRhOlEG18 Uifc[7:f ^1˘&ګ!m[0+2Y6q&)<`3WFl qgKY7߄kGƷc^-[?R "VMGjF+NY?b%y%+Uq,6*bj49?6MjݖG I,Pnþ&=ieʇ^CZt+#WXs.` hR Y1ABZenwE"|@)QI3N-Z:r|%Txb!!|7tE]l%^A/ܡlҡ,)kԳƉ,-@`wqyX '-6| Q R9N/o Я=ga'D3N:)jҏ/IWNCs|h R&4[)|Kw.,1a,Wy{&[}Tx?JɲR;ݿ@ ۄAveC򋦝 rI[PeƧ$2z@ҏ6Fw1g,M{Ht7 r *,@X-R:0oʬZOXأcuƟ]l Իc[/f`Mm*x~Nڕ2_$!)h:3nȁrKXbLX}|=m^ "+YZ{r%R_ŭ61=[`.uQI8 z@Eńgǻ +iehd\ Ww߼qźJȹ2ey=|ZkhjN[E7#~څU/S3k 16-ȡZ0Qxi7/0P:;@P yDZSKW-_DtaY§GF0&,?" .@{R=q-Hq,/~'lc98"439J}skQs۲(8Uzgvg} ( <<,sE] AtՊ>aRot6TLazyij Z ,Xy*FCڗ3cv(+{/eb'5N>ciq~amjʩ{JGBvjYKK%ww-2dMAtt2ex雳o,&;ۙzE4ߛzVv)@ŬĮVymzY7X\!˃ {H&8~eOa sVWTmǭUd:;'\gH;}TjĒZeS_[z[/ #0Ќ:!$DjJ`Z`+"7#挖^OC8m'E }tOzӑUgT1=9 *:Wip?Z@J!碞ݱ!c% Y=yjg;;5 1J^ jh6 IJe3)Jy ;)w pvܗS.) _WS9>t} |K) @ Le>H=:_ᦘ Xΐjgbէ(iY;x:d,}{?& #qe Y!Jf~-WeNO @Ԩ6FcOb-}ZjP]34:mo܉b|h P2mV9lϡsrcv3VKfܸ4$xE' Aǂ?M8m c>(`2@sQJEqeG"ƼeȬxl$oSH{/hŌb}"Hți,/7.Ve׍ Qj\ OG<䤏ڽs٪3xU3v7#H uPA"T%guV{ [(l 8^xT 2 3ҁG"E3TzŘ mcGnScR&gf=uE S߅?b$Xm{FN.m?$^6{J,!no~Ļ帰!'Uxj^1XMqHS28[Q KR_l;1gz&0 {)C틊Q)BS0ַq?NEmC"Gl6M(΁7x͝Ө/0o #b`LVoP"M:>sVYy͍E ZzW͡_#CWM!)^@%^]&p6*$8D7vCGL O̙maWk9vt ,W.2 i_⻃pcv?}K'(UOG_hWw)`(=#mLw =%sPQUrմ_q6gVJx0ZB_!o:xb7v(((jXrk#@UB\6/nG;SVyUf A?Xе3 G dgxF!/qoe^vw_=f^'IxBlTd;l@pLE)\\LL&;jԬ2^ ,^9QoTtڿ٢Eq>ʆx[|MgL¦wh]Nq߀lkN|zٜÞ0G8^V&*j_ 4?4k{7"&UI9)r19޾2+E61½b{N%`Aܖ"A Fyat>Wq1VpݚR$q&TU.w4J `IW ^D@ \j j#X_9bMt*|m8dTuڭ#9PD;Y!~xpEAxi%A( PbOqp>:,ԟl2DH +p@ɳYp4?X05"V(#.R3&WTR*N\lN,b0SW-QKLFrE9k2ʵ3r90XN@?Py-l4ڽCts>{185F # u-dn$<zrECP04V+' 9[ID HD'˼ZG!7HMG#}mX?݄py/%҇J`2P꘲iN⯴Pjem=r%*RU-] *hy m]3H`65W%ڼS%k x0\郞 #eL[]6 ;a;RKlt98=LJX҂!8:IQqVǰ4g~b0Rf{Xs3yy8~sf*@%/;3`JtwP\t ސp)giL9gX_ǗlƚxC\ 奩.عӊ7KNb]61?aU #4.fذ [񥉎|e^髰J𴗿Q~[K$-9Ϡ%6i\B]E&7 b/+)-b2nPo2p2^b:N)oY|Sٶl/N=$9W Cga7 Xw{xxuosȢ`sv`KnKOa%&qM׊R%f$ sp`$ҥ iK>N F[̂+0[5 2SyHj@=M etKy?.kc?G&@j]/m/R>t5w&0PRTOAdmg% h1EsiwP #ʞmqFv r44 >q{jÔ"|:cj:yմ7*̅He `k^I6n2]OgĨnzAo$,Y)K&>qhL1YvEM/ ڄ=f?PVRNi@;A/1S!x."_:-\RlL턜ȳsedR {xy1pΈ:0]s8 qT$.tmjhzu; vY t-, f썋p},zʹԯ(Q&3'+7"LaPYVn ߽:6nAd_}3(Y@|i,w\FD&I6&ҹdE~E?g2/Y9;6yz5 q6Uwz?BO&;Yh{MlQ7WoXA!c f?˻BD!9$^1μ@㭖\d6"ׅIehx|lz/FjQd<@H>%+X<l11M4<3h;| =:jdc0M 9okNrfPW q{FM`mdXSŜȇsur EX01;\Ep5Pŋ̐ey=Cz IRCxzTtjg ob!7nD˸\*vA({PQGl'13q &""mS<>֔B l(IwvO(Ҵ|`{NY%4q{ :hGԬwj[vuHL%@A dug )TwW~i>2@#"0=xԉq- zIp^n; o4R`\M8t*Qsx-hǹ^.$Rz=u6'O/c.Mh`Qf?DqoHjeI H :] $#M_]Pz™Hx,g*_( 4w !E;+K=1>; m_CĿ(F(\rC8Ȍ7>GF& Pc.( i 1w~U* ЕE34maXn'by>f9A Fm\;d_=A03HT@n"^ jӱ(__-R' r3`ǎ쮎LϯN+rXA?=kBۍ־{wKSDtP3q5<0Ue}Tph$H",>Èҗ N> &ii4}6^UxY,y(3y-q HYhժLr[ֈϵ1YC6|r6"vGش$$!J@d8 r%Y^QnzBڙ,J3G)!:P4J`rxtihwaWA#'Z+݇m~4iS $HQU{s%JE ^v?}Ngv0.Z bqo7фUuCrS9bJah;>Eϣ< [ر=@ D=.tϼ|'U5?-UCo,ql4~zbb*ܑzxᄩp5Sy|FŸ1U\z׎Ng哱}șxb5#6QQo"wsZ%V+n?I9֌$ ;"̮,Z8#.ÅƁq;exm)ݎ P2 =hY=*Q Ũ]c\n;o?EBۧ\Hmx?=O\6R Y(KUԝ3LY/q|!dӫ]OkgK4ɯ1_,]^Kݱ`ɯI#{-Ss #~\&Wu]t*aIƥ97"Ta2RST[bTHB1j0+XY'&\0@ |s;s D6jr`m ioW~תd6b Ja趝/0/K8iICVu` CZyA;$p҄:p;;F'Jva6hEsF352 ţ(Cw@#2tIoT͙e 4SyJҋM5sR%C3s] 섚e dj22j<'qDSV--JsybxmF6Om` BƇK A=C=<[/ ovEH|h Ճ)~]m~ "-QTbj!d{)JL¯Riv{Ȗ?KKZʈg;Gj!E[|@M#p&D/oXO'B<9Q)#A/>h:S[as/&~y;cu#9M\tFE+n"y/emo%5*[&B28Anl;w쇰ǕB(੼OKA4-d[ ǕMi /$QЁ׵!gPz1#l2$@OA&fWU=~qtH>H"-6ji늢^(0+Ԡ{נnfָ \qx .݇$>`e=JD ȋϡ)噰O;uO& 6$]dg\ %nQgN>7ڕ [arDM;):? g (/W"1xÝO 4Ɖ·Z%=I?rLuc8ݏJ3P?8@ (ΐg{O7Ċ1l #[i86?ꍦ#>rKiq*:Ŝsz Q!y OUu/7pFXøCPZ[jØ4DW l+^_nN`ʆ^1D1|1N g+ Q-Brq%!ZJXm e#Ło'>.* $ۄzSܼٔQSHܨgA`$(}uyR9*kQ 3o l/JYNGs@HHd6x?7#+ Cy7`[ʈǮUO3@N:%K^]xX]>`)q+WR+\NRd;zWenFȕK3H$Nxi\yE8*(I-dGAα}J۠lhe)Ԯ5&q꿫LBMX'^.`.d98nVQ&g߯<`XPz\1@Pglf諚%52&ۜfXRmP~N*9:||aL>聨IlߣrtXfaتn;i8SYݽ|L_TY2蠹S'W$DqGy-1sAa%yT ޕ)P La_uw\&QēEIV~Q_Vs>}J( а!cq"ڶS8%o\%`mO{dWga. 7ƪg0BR6?`U=>e.NX_N 5l'JrNXܫe= JnKmrZ(Su+fJ{ [S"j$ 1{}ϲ` I@CQO/G%~q H$;9J}k6 =33nQ%Furw47,|͖ސKЊMW-@U'Xwi!XYLä'p!*J" ?1ȩq 9{f9j%(Ö(`=ٍUxwBwb=rしmSAQ·ƉCJE0@Q- >^͈$9ېo$Ʒ/H;MʝVhW3fGye}.z88=\ΛS7,sboxZJu1\.ȁv0rm++t[%YSzH^oܸqi#OE:kT D x7h ϯ8: &c"q hD%h>Qww8V1.ZN|6g2veJGJB i3r6oOjq}tȌ|qBoH5`f]D!*mV/jjxj5#*H@Մ C-_)XM֩}E;ٲF'IJǃL$m<DI~$zK4K tߖGQaxߔt|PHyFvDq)>1'~wB0 d'@!8BlP𫔲q./y]Pl͌&6c-(&4 fxX];W{K[c)pb#`3$ȵٍ<V #ެ]E4.r[(itivKZ!z~Xߍw0jJ7n\F ^(A6Ax0~5#[A,cit }$ >eV4emΣp(.JP4Vi39.U$ /< ڰ-⦞=[wԜ־N5eŬD@ 5> ?Ժ/k);ѸIԂݛ e)4&:>ʂCDkpaڭF{Nnqi+łM:p&ON$L>_ZYA5FL^=|n٤&|z1܄4p& V|/ht9&20`Bo۳RӏD2c.P/ө塚'[J e=ՐGtMᐧ 8&Hk@e[ljshPPe+RTjC~½2{ ԇud6fWg;.m.*+r^(iG?>cB: oTP!MXj#&q ?ӵc,NMbs57B ИF#w6UwpX'T j/%iF%1f{h썶z6hk2DrE) bR.Ë37 -/^m4W~pT,.AІi/O}' hXy~'Վ\0jX-[նsw<H5ܧaN:/9lȸvDQyɣtښ+3{VXVXqV=< Ӡ4s`or]4F J=;p4SM>iu?FW?ӭЬ.E/_ŧ9AU j8CGD yFFY [:'K9ݰ[RvIJiCyp`bM&EVžEGYѐ='h}M]ިi) 8?7W;o#x/*MoGkBϰfRN".9|H^^Cl&3.-:i UlM7R/VwgkH,/|h_{O6IrJx {/+}ԉWM| I1]$,p|mIg4G]KUEk%;xf܀LWp8{AO`cz}b\ŠRďc"Q=)r \XEY+2,hZyb7p@%=Aw_ |= (e'_ iUuT iz)]7ݨeww. aU=&S:+ī@YSf,G2ޱ,Cɀp~m̓H,˵d i"=vZ9uu7_*]]?p•L;-*ZKcBgjj>=7Aց!}xbMMȚf:K ̊nTǕ.y\u]m,bUoGA}9.Aùx2!-/Ytx_\0&Mj`1:=B ڐ<} jP0&oZWQiwydGz&9hu+n-6ذT RU?ZZ7.H;k80Śfkv1K1#ОX -^N+O!' Ùvk$(>S?ˆU|<>?J_?]9 mx"} E@vg2$KdK7ݲ2;$A5tyҳ0, ıqb:-2tl"Ow9ųk X36 ';L9'Se^y^QL?8dO>N(_UBl:W+  xկ BbqSU x \CF8 sL}QVGIyU:V ?@jg|*2A"'#+|9M,Ot6,O"f Iq(JTfuFT`uka=ۄ %ބb>@<pONP+_O^^ij({?qR s5ZXQ!hz_7/O GA?o|ҥ29irȣ0bA:@Pg (_ ,sPaYytd:zӹ.. ;v]e̪q(Ѡnʽ%Oi۔Զ[6֐JކA&E]e瀛߰f7e>Mܮ5 c](YfQ8_BIvPxD}I'S){} $=`sid}mskpY^HLpyW%lݮHBn-qE-7:Z6F1,+Q{X"p2npp-*ZJx Gÿ`.l1t4,G0Zl K;刢8V.ݑp%cU.IQ޸ԝ'ZܸJ޳||&VώsBjhr EZM`J K|2W Yr*5^O@+ Zgj/}z~1*K4R>O!|1lTE:`NގQ7.ֳ+&~ܓY$l㻔1 p$).u@-}ߍұ;qR RH} F-H2$>(F#BҩkNqC{ MN8ETj”g†2MI",k$Q.! oxg\a` CB\F̮ܛ+7,atKf^'yCᶇpxYQk;ꤓlu'hb<ֹOb Fܩ ))1ɣ]f&d *jJ=/gw ghK׸c̃oz1vx!FTު&g jJ!5{8kۣ\Mܰ& i ,.J~+%!P r;nY|a+8^[[[% $ǽZO7E ̵&b3d1C(e{ų?J:H M0UbBWMx7jL4$~'GW!{2-$W2_[\˜Op~,bwXא lNdþz/13+zh 1ƺ1ғ?u-@ 8C XvD 2#Vę&h.zD6%啅uvO1gk4ɒȍ]/$wM| UEmED{1kDyYa1/fzCxlWO"ךXk2ȅ$wB jhU';2N:AD` יsfu!ÏwvZ5}6+ 7¤1x m QGxQsv"[X ɆBU1m(D-l>v]0[IGgf;awnd>=CjِqOD/(b>:*DJtIm Ѥޣ<-ofYʿX۱9zg4s#܁QMvfb]'F&e/L]wQߥǵ¡i[i{׹\I>suw}7 RnxM!DU)^*q!x;=]mID|ޜ͑GbP+hHzzUft-_OE/.Gcl!(yqJ[t"sh<<k|'L: gD K}ڣqrpa"s}@.C`])C'b,ā 'ԁDCh40:Ԇh u^EeYQVpAƤ改R%ͭ(sLՈ)]kv\]7-A7D\,a\(+Q`bAd"Z Ʀ# c(%Cq vQz,g L;3,{W?7?6SqNnYR"ٰisQљ?ӈV3Pl{k om@,Н^@\uUo27ue)D;yCDKbO 7@Ev/\g pM =</A@UȯET(1#Y^.*|3Go+ ?xX_K&àg_KQ o~1:OkL#=a{A&גT\nDSfIqz+1*8jk":66Yy`2H>e\OFչ{X-OY,/ZJ~ eDm*k残hLϊ;,їth>.^'MjvyE9lj9 D-Pǰv0$ E5w yW#"6bL:䟯,[c=, з͕&DhԁedY'VƄ< dԷx:ڰ4sg{)(  G4_1直+XthA>$&揳do|9l;K_[P@? X̸\NrmA)d07{{mϱant7JZJD/R.T2\i+Dηhr`sWg!\G&ـq >oEO{܄jq{{ cZKVu7κLR~Š9ιv Gߍ;fyZ!Z j== o'ؾa'7 ID|^޽ ("'3++T$myBtb>x{CjP&Ԅ?[%q)V}ǿf70œA^omߨwf6>>YPkG}g`kHU$?6';kxGK RՍLIHI+|_¼~䉐K'tڢmc!EyeiA=K)]j,Y\UzICRtFH=2pjBEǗ>' һ;\AcCffּfqlj Ppʚۚ?HGg1s̸1ezE{Mׇ;R{<.&X`L00r;@ZaKSvf ח.3,Qᬚ~VWZ̹E/^)2ӥ9i0kJchgTo! M,u 5"rTW"*_\tiV.tnvkZsMcA ƱZIL*˶B6 [ä8թAisƝƋŴgL 4L/u\uvZ $~Wb`j+_LFXKGmqɌ8Mp;Z.u:a6.bg,O q\CF̠ Ƅ+ñ|v ~m$G6,9)2L ye|429s  㺩Dm&aؽ_BVfKQDh!9J{T! XsH1wp.Rf ٢POz\c4pV U*Ҧ%kM5 I"%}SCh+EBW#OFW[}ClT$!c4q1YV呱gWl]}fA~}0l1=-1C߁<_`V V̸iwDZ{45OI-M8isf6)vD{na%.\J4.dԂBK2:P hG‰O?DP-cLʘ/nb;3ms4.`I LIMݬN=nFScշ;:u_5nrVU;=֮)T4~te H-7 EKG~ǕEcXwY iw[]ya53w h+*gX 2{y{+0a\"} %iS>yEٙSG)qFAv^άOr>0>Vé?w2D<,"l~\TؘC>fd?cX;"65IDBvi~}9mM nv<ཷ&gU;0dmDW _2bY#NN"Xd#^R0 6vfll[Tol=:ñTzԫT՗tf(BhWu*PWx:k8|fLVEFk{2ϯe{/|ʳ#!4#\H#{[*)狇$,i(@ 㘥D?y=ukM~ݔf; H4$T!]tHr Th?o9]sar,/֗ JмU)2TBECrsxEWX]#*YG1aѮr]i5:C4 $Z8rHMB B@8"v{ k~v#+0h_J'xfS^iz{=s)~nb.€Z#fD`_O;m4ߎ h LܮGTF]1n镋'4n9>RL ~M'և9cBh@Y1ȃۇn Oޱޜ_Z 1F &"_(gQ+_k9FD_"wJwЇ$N T8ǀ'R7<,eJ;jtW㍜㨠N-h+Uխ5Җ6Aў>d1$o 9vq}Z uM3#c$)IV6f‘qlĬ $BNpUMo ۬meB_=,p YwGe߮t?#r0edՙ3)DaL:|ϳw97fQd̋][0Ѽ 0,$:2^سi,Uas.1;~WB:DzmfvZPqp{*\$=V0`!gH*8QpdhvEHUeYZ bgLd3^ ÝXHkaT.WEe 'Zɫn i s+CZO{g ԈvފC-!DU;xf*+21F]9dJ9&KP5:<{)mC(JZ:$<ɷmnN9퓆~'zCjOޣe#ub*1 wxZTr{n|xɌZ:~?'Qʭ/T^1:TejKkD8^ʿA}ږ|P-,y5uOJ;)^ItqDLD5+YP,Rq&d/:Ew;է7F\ue.i04wEH5F SR@J#+Um[22-K:82zz@wP-(s;i լt)m6V+~r@4!O)&U[ɵf#OgaB 92;vNvjϙJȫ(6G%%ud@v;çRj1rqܕdk@j?JMO8B9CiGx2 %,|'ܿ$96Qe0K"], ʽx>% ~6ONcy;$7FL0 AGggeeyiY!踩zB3EU'l`x^ebE^ t;XhC(,Z crCD zDO/KGX# }'tCaU7ybaT,h}|l\N ng[fwL9MM]ؤe=qyw~k>OSf<*f\GbqIA$e&r%i(*hPg$Y/'Yi[5ߚ)߼ak/9Fݭݪ/rފ-_"77WVNE;3+,1﮵ț5[%׭t&n \j&íwf(A#5+@4޷S~N]+&^2ڭ>o^.2b0qiwz.Si]0ۜ;}l|ʖJjWƿʼn\ ljg=|~u}}״2T[ ʉHn xc/Íʼn~nG_uxy IC a$neZIh.蟈|Eƀ(:OK|eoS(eGs|Ji2rRjSFZ@an$x@$0aeeD)㈑dFj5uVVRB$SSҷ_m7v@|zX@G{>O @X2[)L`BM(2yhP)#DR3%84.CqUL5/S=oTds#B<#oSp$?v DY<^4b3~4ogF}΋pTrWC6(cDv6zύ7]3 ;yּ|Ͽ_}-j213rju;&g Ͱuzt0`˗.\r0`rbb gLAc""ab`_5/O ߾?%}~⢣8:]kR_)^9% L 3ʜ 7缐@t?M66 ~_n^^(A/q~6C}_]2LmMyg^~|eP|<\=%QOg<u9μmMk9_臨!Dz]?oUẮvR߽GoUYkN*OU^w]pЬ듆NO5 B Se5HS[*tQ@ю[Hm){׆XUU?*X386X\#mvĸ&_x=5[X'A@n`: `:؂XeO625jY'?r@kEa6$=*P̟;e@m̶G<j.d*᰽pUd)&ŊFRtp7* J<1QpW_Os*&0sٓઠkiU_fPj,vwP~9%InNw㺸$PAc  ks}fqpi%< Є [k|C~mnmͭ-b+C:4'eWg~|T[:22Yw}Rol JI+.f?\RVc XgvwVvrѯ+Yer/ҿHR亩(9āYw q*K>jQ92_g6(ji7c# Oc9PΖ=,h*M`bx-0q 뢩1[Nr;]p=ٯ 9THrYlO&] E f ʏGwg3ng&N K*OqUZ*68nCKe5ƏӐfSOw-ɬhoNx bxV^@t:TMôBhՁhI ?qyÛ*Q[3οb9PP7  Ŭrz^kUifBS^LFI :ϕj;TP¢3m {}$Ldlc_졂֒/ٙvOamjkl&&xV I`PUԻvGFdMYɅ6o{?5Tf`3J݉U,1,k y熱u( k-/[!TYFW<{/vPYE*qO#2.B(\'ޓ##{KzhTrI%,`HȦX6yr 0O_m^[AE eۺyy}z}vsS"T@dLmu̿QR0q]Ns俯OU--,B=WUoUx !G_ a;3ʉ\ bdAAA. |eQʚ|i}jGX@b*UWZ "_ X5P a`;0 /ʳ#5fN8ӷIyWv7ږ>fveXrTGd)'Irpk)O9D%TPxܫ/L^ZA @R?Wmr}߆ױ` B *q:1~|?h(x=N&WSF r/ڄ݂"$m,$~,g ɹԯhw0h[<7}L Z0P7%ЖpY pBQД%#l'y!s=}}?뱽NSoT#Ώ=\gh9\WяtECߟYko<<~w{.{yYsr|eqw{lG`~O$Ɉ&L2d &L0`r9/aИE@P>>>>RtloHp~-n$, rhk>zj_G}hb!)pNz~:ok6y{Ÿ|57b=$`"M [Mc)~CM$iƯ\zҢՏDg]4;;00@^!!? _2Q>-b! 2F唝[O?t,#7s׮UTp<.}&EV5.BǑ_nhտqκKDQW>+hLv_y?ot?Wh9ʵ(b:.̄IZCg0хkqLU%UPJiIe\$z2"&|R$j!u{ޥ@ĒFHCgȠV@&ZPXh(5{>OՁ7Kmw׿t@To}%F;ӈG!&z 'Y6ZRӂh Aک@|w#c .6˟t1VCK#2Su<-{u@[ܾO\F:p|,_`|QGuνQ׉MLUyq [Or&5?S]ϳ̏+ZL>W.vì6)RƷ{!vhM||bm/=٪mZ_O" aukyzET^oNJݪCIJy攘=G$Tc&B0j?X~ X2LJVݞgzկ̌yeD2Nnrɯj3^?[oV oT9M e9P1%NM Z>+|~"ORr q9 U0:‹}l{uOǟ/"9ᅹn?[ >`GuKMW`)U}𽯟t5z켆g#Re`VXBQJ\;l^؀Z@ct]͇\^-PB[^T&D){\~.paW!pSXnEM\֫tq_oR4/L׭10_|rTFuO?J[}{L8NA̞?9I[@&yw-n^-9a$?msю3۳MWɲH?n%DDWmU 3}+sz+'Yû;l인n.pSw6MZ&Emfx-jqx77r8EïZId|&J>x:&5żʴΔRsԏ{1ZKMΆ#OΡ{M+*2BhĩcSWX* 9s,Q5cYLE$4^zZ㼧MW+RSmUೄ.tM;.*T/39iǽ֯jMۚj-,Ϳl܈ܨ v 7f$*C9|fvT'ljuV J,y: <zw߉;+ݔm-Ymҿ\Q~/]z_NUEݽmGþ qRi/{7F^x BX,K*Xva%7-M"UF5!aβGhzfW³ bz`M#dy{9R Q%^mE)+ sNJ8 }_*ŧ|A&jQb$4CwpkCPv'{>Mnk @8qvv ߋk jAx&p=oLcNnW%UfU[{o=:eS]9\G30JJcu[}#?=.5J c0dA % olh`2hX[1ؒI''wNA{ȝ-+JL^[́jYx޲mO^CESxMC7q83X[VujwY8sUj9RdE;ᯬQX7 URE|~Uf>(Z^M.ͪ|{?5sVksd8mz!ĉ"5A r{}KN'T`}'m" ^4fvv?/|0R酷37{0 }8.J̓YsRUx8uU=W>G:N05#Q(A Ʒ*sB|ZN`=gIb=w>FgQ2U R]_@0^E:FJEn Ѝ.SO{&vevy;Mς i?7b&PwvDdEk /`r]xj#)NI;SUhZ.9ZMKS)^tf$~2KЮlXlWb0-fC"u-Mc(bo %$?#k{>kcև*vCaܗ؟O9a] ;zS[Rq'b:\;)RL= ,bVť-10K>V]w3{]uUǛuTUJ:3*+=gIkT!x2c6E)7:ڳw8ut}u*]ud7VP;\_J PM :NRZ.+xX5ٞ.~#-_f\˃%Tҽ] TYo TB̯Ae!`edN@lڽv2'傞n*t?f+<קv; roJ&8f hAsH2Ή`xqh'1 }j>2U9k,gsWF5QC{|&ØNp: Nhc~_KB}M.ߔlR j[i:%UU`C5pURUTZ(Et):HmbVxVI]XՉB = ksrk۾7*!#okTjSZ nX[US먤kJbF;H ngBAZUUeeRe*)T]jWγWw04~aq.{q :Nˆњ1x>~?y;2S ѣwjֈ=5),\o0q;U<{#ͿB7e@?ȹ  h,2`͢ r@ μ5]55bX@\BTCuɀa{ۮw$`w Wk/s'z-&#kRDV~xWW7ZkR`0{WPxRֶP?``b0?4j.𫺨(/PG;4-i35G3t \/P@$:C稡Q?DDɠjUD-P.`a0%EP[z3Rk.nxaǖa- $RwM$!&xDС}kX|J.B)BZCP5c'd4*p0*3|R3Z"[ R;3};1b`ӫz&7X(uuaMf>{ȼШ2,]Z U_ ڋ*&'\jvv%>lí=(M-.a>]X ˑAjd% \rx{⑈ɝܱ (EA=`ܘ}ɯm;mTb{6XSCUE-UƱ-Wq!(ϊ(c =c\zU+^k5K;%;CCiJH_]H~oocam ˷`HxDQXQ0M4b_5]o?\E$oK92)\L,Gu!QY]Ҧ~'n,(Aڑ_l:t)k'41 5<ې (k)P* v<+&Fd,bA&"DYFt{cZ@\k_Y&O.f]ŎÃt3F%wݯ;(*/ق?q;g~׿>çfr:`N ¤jrb7 QL2evP3uw UN .ͩTF/`ej̱W-TkW6pQ3=;1k,WGKxoLhi\! ҥg-38wZu$ 4M@2y0|<_q7TMgMol"aFy#zҝ )B2H*FD*P*rmMP#J|H&,mINFЁ".-gqDEC0 eiQ߯QCD5 33x\CП^g!by&(HFj!k ,?bjr-d>,ݬ/v#:[OPCpӞ͊rCABݲ *YBWlq. U iiFZŹ. /ldME!LwK dEpǡ2~uFޣ'KA.*3݂2CjH% !>єnB<ȠuPAzFxgL "ktA!aEsMAAbaK>c'VGd<GDzb :5-{k{.Cz4B:YJ_d@6\5Ʉ^ z44fޙDB"ϻMBҘTX08/f:u bm͵kdT3t \mRt%fB2FrdZR9D98x zsŻۻ.@s,,^L&.Ne\6xvіB Go-mEѰy:fH2)vڷ2v4"xN,ۛ X|T>=T(BzmR+ Ys |3NEsYr)rkcuWlv 3sss 3 ETwzj{ vL8Rw+q'*JrKo*VhΥ*3Fqz="#|<xLoY\ VE`$qϕͧ^{M^ #" s{.)=w*||߻yx=.kõ@>70"[4z^1D9mݞbNWBtɞy~+7 =o2X|Xu1 8Kɽya+9CYSʌe3=4tl 8&t׿gS;ygj'iŸ)ؔ ˏ->؆ۖ!d2 7MF_^}|H!m2)R\dFHO--GW ̅o ec6v{JaE8oGf²k r&a53{yt)($ oRjGx{I)!b!ΎP(7+lTY0G"gk,mQ*UqcUQ!4﹝5hlm Wμ@/1H:@816pװx+EFU'8uȌ=_ oE(̡u=^"w(,Ar`UUZxy@йv`:}u^nɺrw>ݫ\{yũϮngvܵ;jMٻ e{݇;nh+_t5Msx駛j!muR8]TݷwhosM1r ܢn%JQTPn*[;CCPP  ȥ !J Pjwl4[}:z|>%iYOsMq={m' ԓhs\gCf:|]==PT[_sP,ݳni{"Iy>[tIN=g +kӵXOC[v7N/|؃{qT{{t0O>ス={ޝ76zacó o{.={F[ׇak=}].v^gnmcۼnU^Fn9[C㺹hօ _9ǰyN3HjKhu=x;sXwwsk6 Jgrt>kusFx}]}14vwvJ;H|ǽ\n/{*=i*ǠG=٩k3=>j_o7:! `e40wgv`[N7>Wn˾_cWowP-+׶;[}<{80 (1*+>`ns N04@}OB"__xwk [}>vwn;a/s׼{}+'4@BZOy=xs (UC wyv]eul>n}zV^`ue[p7-\uv9=z:}{æ:ӻۀ$!uwnwuw}W7EζT{\۩A@ᦈ M@@Ɉdi&@ &`C bS6! T٣jxF 2 M4 LFLTM=LSMF4SGOFz4i6GzA zGA"! TH&vf O_JkTBWHT;u"|g٫Dy%P-ȠkWch*T5 !6SQ16]m/Q$dM"$ _;za)2(f&Pd 6\C{ $z~ S~>}e2XRY"FE4XH(ڋb %JZ%-dX5&mT J(ɶML Tl"* ~vײmƾپ[-dȃ`WoTk$4Ce)T "O . L7?ß mP@@4j4ZFc%Lfmi(TfYKiK*S6(ڔIhk24MS6 jK);]`$Oj16үvm4?ߤ76Ən"v~g;=ꏰFMױGov9AH$( j!eh;FF%.x[w>1"qk؝{rWOV"+g߉Y?2 40AK'`ꛞ@H-_yĒ2? DJ} `Vc@m:k/zD?f~JCY*dҝzig\\c}sP fӜ;A B'0]J3+P[2="M{x4JΛ0tTNqm{tvȦp+MIʅ"ה+L#2z0~{m38ۥpw$P>2Ppz ]Tf:a خvEӚgN9fԂΦP  0۳uASNXT@L˪C:έބʹ3.P|s3~Qpǣ^kpJ .LPK3!s!pҬĶ}%'Ѳn n0!gSU,ѿS ܢa $[jUy ch־e6.ۘ=u!,YC7៻#"Q7r%P(8; j+oǾgF65Em2X|[kl)ѐR) @\ڋZ幮k񨤊jx巍m|JQRFdrJ2{/{=W&L𨌫P*P+yZk'R殯^SϮSrrT<0en '1E2qQHdGцh;=ᕑKr@`:e?#\HNaӭ҉q=C 6ڊTh[0&X,>(ّ4rzl)JdAI3:mMR0"oD*k=x860!@ HHr&gmw<쵩71bKWkzUڛn~=ܺy7; H`y Bݝ,dX$ kN%{ Pd zN99rvq/7boEC`N pE bIY@YMΰfٱ$92\5-! nD.ުwhӠh (JKy*/WZȴ08 4I5D&+ " pݦ O% ӥ$UY1po$0+FVo,L16KA"0"M賅ђ8[զ&nz4J»:H\c[0A]tqwq-mw9S%B[J!6-!8sʧEE'TE@ͦ;/TraWLP9Pބ/u5*E;g٠QG[ ^VQxݮ%Enguݠm-aK̗s;8묛t\4IKykT"J (Nʧ qp̖܆ukzF*Mm`6#JУZtHbC- J )剻@ pn4if" C(&\ў ժ7GcR+YDDQ**8*0(222 hʣu[s[jkkE{jm}v66֍Zxj<;7т 'Dÿf8ulJ( !ω:AfHCR'=L4nis+c"(\L؄ !T$ã21̀W4\NMO'FW`ڍگ #ĝ1boD| u;`B򵀟S(eTjKB Ta--{(Q>ߌ\L`E:"LPcHC X-a=R@r($v!vź8WR(v-!L E?i&JTYH0be=&s)E8}ߺEoPF, }ˢ1I;ukJ(G[7WsQgXt-pEcz{/~v'sqW*>2% =_89Ჟsws1 wn;C5z*]c)(>L7}$ *㖬axf@=&^!Ao N%wc#/ f٢O6ΚC=R,}%ysNs]sVӶ $b%9V+D̟6$gtbXx_{O3x\Ss .aA,Z9zo{}]HVC Uli7:R_+^eX=G҃" oC(y48BuyyelH[cɐ..A!H#up~k nxSzAIێ]|RsRA. n0}PJu'_y8-C`33HOFN17HyyR{ho^"2RԠqzl-]#̉ň @"?\ wzEhR&AH3캒cP%w~-;ݦXJJ@׬)5E]3tly 7 S 5ZڪUL3s'١2C zͻg(RĤ]u>_%NTg,s3囘[-HEa9!GfmA]UzJް{Y|8%Ȁm&\JqAY"*uMV@nMg9$ffoY% `{ KJD<}&EA31/46aGB8Y煮А~r pt c9cY-66z>3C-=VH[U(ia;nIC7*xyz0cbo༜jgB3L#YBLbO&l,z=\* IKA=id& W%ҊC1 Zp=͝_Ռ&nePWք>>_>>)eN'ͼg^]S7J!7mqBl9i!!qyC$ Lr`rnǪ;3ޙǎ,r bj9׺;0gLngQ `WJ729 "Uƛg4;˽B✙LY$ t4]O@ kٳx`mFDۡMR X6HCP@05X}Qx^#UE9$Fļ v'JWO?ԡWIaSEKFBSQBóNoƛȹBJSc488x@9a"b>$[1s.$c?Kq1'ABD` JOW?=:9pm3-T{X/sְңˇ*afcF}} /m t$L֐$bHOȤf4i`xۙ,#NOP;:fi8TS-3\&9UkGw 22yׄHJk0VEY"" q3`ө@ EiDDP3=UÄk@o-ko < J-@04 9~A;A Cw>N2N:@?3DL}5!L,)YL43@*Ld$ d E U%_\I0d )KaL,%2 =]CC12CL˕f3Hg&fU"h cҷn^\+Ӌ:jgV.T^ D̨[1ATEMRl I d'&l\ ly):0#Eb+ ȇDO_e"Т0 |bC·Bxru".dN|]p{n^}I(,<ю D33301 BP w-{4d6h+WoﺼLgIXaԺc6:j("¹=U@#@-\/,5ث]; t`n5eWd$xQJkEp|Tw 3\*~<| ( O2 GcRJEMXG+Уf+7XwnaG=,0Fkl>N.yUb N{#s@me &/pda`.P鹊[b%7~>H`I,=wDS,–h?L+ =U::\N2^I:)3Y\5#6i@]IHwe輱  ٱ2OS%&IbAbD{ƹwœo㦸'^Y]šȬncV,32:z!.hM㡛t+!hzk)߻q6fC `akQ^#Q7`ncX;Qf-,46MF \b 3ٞDLr/¢vr΀ՍIgd)EAKy\+âڅ3im3\HzAbĊ6㗧ҢkG@lEhmnx{uv@vOH$ ]8-Q{<J=w7z׸^@7|UB^@wG]NTԩ$f(F\T Tlr7Qm,i M=[Quӳ0eRJ!clOIhrMg[(!]B†oKDTF2 BkXj)"MaAbiD ԔS I3`3rrf :W:Fp!Y_iT2okyRz)h؍p~u5rfTh)¹p'1(b/PL sT h) %,j*_F7mӵၢY" Yķi;I=B2gX22_Qcj@# P%ً@ uY$Mw{ @@WqK@׽V^ʦ5#~ PT0:)X ,se ESD ; ԴRnD6i(CGrdʕF3|.8EPOuЁ΃PỉJPoćWYާo4˼Z+FWjmE6"@S!?BfM!-5C8[N{!=:wXd2ӤQj;D!^:eN 2NM1L\VC@X:WY M^h7m C86Wes FOfN"prv@l"sAIDѯ_k!G k5B֧妭vbaWFU.Ȭ~!HO 棱tX]U".$mKϻM.3zF€}Lo}7>w @"vgeS5tKkMSR1C|* X0 @2ETD'I&H$O( 9|y yFƧN\V~znIM=:H.-_5'~^֪r!!QE'viu=:뇀Ȓ(~"J Zd$jiMIEji5(R5i#{n IE`H TEIϻwrj=>topZZtb4$xC;Yy @\6ly 2$A,`HoR7!-4x4ke`d8 %0n`Ûg2p)2ra޲^-T AD$:,."Dqsugϋ-HnExB@-P,Jd2)eOTэ` mY]GY'F7r3RLqwi}_g/,>o|ayݞ#Ω"mwXy8~d}CD1 6CőঀJvʂ(67۲>12톉vdؘhAKd~|U6/ $s5IRF33sIi[iM5vW23VyB+(,XO)y0=y'4Ifw04d)-!h )C'% C5AIJDI ݻ60*!xm@%5[ov{LupfEϫa*8hPUDS=QWWT=׍|CpRA|<~sg AYcE3i -{]>_f~r KHwQodr[݁t 'Gc/}U:Twׇ=CyWW8GN8XPpN[p^XqeiX4$z'&kψW;3pa2QIZjͻ.zg:ycjX!>aX(0jC <@aI+bP7!bH[h9QlsPjgšw!IuZQPFz`x!1%Qę'>ǧ]P{z騧mmd*D2Hʘ!h`p.I)\M[)ЁHOLh0r#D?jh ^d*sߙ0q&Cbܦo2(M:*7iXHlhYĀ 6\mwnl Ö `0av"MqFvM#nQ5)/a\ eNN7@υ(] R]{x`hצʥ- C[H Vl i7R=cHHW! QTȢ0=.g'3Nb0TV:4nqk8FIPyYGz tͲʲ,|'pTTHRv :(`!8͆dXgg܁q ^XNR,8mD}:\{I)Gye7)`!#"5bփZ6mQlʴ$ض66([ڍZ1[hի[ϡ"W%wPWU/noKe4@;ѹ:U6Ry_b=w~;B;]ZI8x !$mRp@^yzI'\ mXd :@U`Bu i>vPp)i) 3ת;L/r]̲?v“(8tT]n׌x PR:G>@"㹪 jDLjT] E4FEEjQo$4-k ꧆ n@݈q^t+Vex$ BRHk˻?{Mz㲭j7XnEe(0L  xi]n9峈l7\7<@2"P 2c:|e"d؜! o JsHs=&`Ή@ΉpEF(᳸|6AJ`CD?a PaMAm/aӘק/܌=4 K)eC\+LA@}\ Di/T(Jm7VCN[en-ZCv2/L}4`j<>sVLj~B"(6=pw^%b/ pF-т(wpOӶ*^ʅh+#[ϣ{uσL S~ZE(g4{| ;6Z( Ls&Ztm_rt;-k:6F:wNH]H@"jv4 a - Hv)TE .5ªRQD'"j)5L*)OWQ#ulD,s9ts6Qˡ{k@@6|a7{quSiDSRP+}laﹷn$uqKBг83\É 6ck͚:dzzc~LiY/NVQG "͆k+bVHueCC fEQ9fonwcë>UB# bCV*\K T񺧵\TR"]3Fa y[/(SN^T3U⼂3",EjP"$379[\HsHӶ$ƨy:@DNl-<'g.dQ?#@=~:U&^:+cy0D `Xx_ATr>貺1kM 3fJ Ptut6FmadBHh\1diAJ* 9Z`sYf4vM7hE'~B!;C|X@mI;ncar84 3?CF[q,;R&нvΗ~Qwv ԀJ^~yqh HX-Ep(ȋM0Jg|_sZ $WjTkc62L>gKiJpKd@W:9ۚ&W tȳptv|eE-9aMf7sNp]ZJ__1&.z1=gѻdn ΦiA4&EDiG fIf@]g[ރSZ9Ų6;53DBdh/!:ft՟ŊL16EBK{k:]C6@f@҆F!>@rF&V8'x8@Prن6%h|j57DY$pf@- r 6[`asYvk#1`YYEf~  )ƾnnAx_|+{"L;)tFD.l07ﻙ!V͞4+6ʋugP=ҷjrD;-r#fJHH m05yg0iHHȦ@J0ׯ{2ۿxΞ(sAbj8zng͵OeQzHM5i*/ .\^#xaqoP9c\urѿ`taY(k/2Jڌt&$=Vy`< 'od`j?GXR2]IUD}js_@P&C<3[(Jl" DLx/G/䅀[k`h6 (AâDS&%»,X_87`\;wCL=EB5>4 ߳OLjC`j&ѴSD.˘ۗ5Yxcn)  L>i D,"VLqȄJ K0ZB"./t?L^$)ZH[BHr 3x{W#M$'k ^ F1l;tU$D# #GCj0 ` йgȼ!5` 0JQC΀g|pϵd#$9ٔ6II M-g"ﺢ%X75*h w b@W &ʐTD5mI {PX]ʈy^Ez *f#OsNmy |xQ"{ KJ"fL *۳mӋ-yp@Ϩ ] V ͊u` @(ɝ߾P ͨ:VH,kjƪmAkŵsmUKQj 5$#P2k;3:(\pmRn ! P7G:+&@ Ba3d&MWȬNėLSA_żw*DOͷ|՘5u5u7kZy w OyAUp i$2dr/FtToav+b&'8rrFu-W l[t YRWJT"V3| $T|?}'/h"|)E^1v}AFHBFuSUnr ¾fuƐJpo PڷFuκ ÔxRD k"v`B&U8xQ a|Lt |]b*@P#!ᆰnY?GPo%t+qpQ/:GG-G(r(\jv_I JfȆyhsu@ą 1o2taiU2߈ !:6ͰWA]7xWkIRi7%L0T̝̀0ǜz{m{@!q-$aĈ)"w VHmc-AAH=.jT0-Wr}!3r39ܲ,=BЛx/N=T R_uU gĭSB$*hJUXK56m[#ztN4,g+Hp`xHYN~WÝlD ^?ϟFѵnp$bx^O&l7T/Ezڙ $/ ߟ"u/v|s(V$ۊƒ]8ulYa%P؇''`|ՎaܘGR۠HP0u3<`,g/}<7\όg 1(n`s@% "Zgvނ%Ё_eB)cJ匂WpaaIb|ﭜ\n8YN|zm~J/GCG \12dG mm}Tnt ~B%JH5<}4)WSw;Ђ spuF^Df\RcM A\~ ny{ Ii}2W]x$B^l@pX/>`ģ3cup 5z2(+PcGUs'琩^rY]]LW,j ~ Ѐ-<1\T3KM[^C2wqwldlvfi*Pr~SRpo"LNh&^|1BBnQq8Z@ށGYhPdMbo <\J1`$$I$q LMT4 T /s %#2?[r WvN݃1E8z5.LMc>J PD*}MPJ2_Lp~RߊғH@ F3g9eadc/5< &O<3^,DU֩1]gQZʄ1]4!.r1oh<=G8.ugez'{ĐcPq =ctiU/tB&;_3XLa:1ؚԽ.¬F]LZ"CQN&-&z=ZjY*7 I⣍79gNpm,}gCVqz-nsSrJ>f|E#V~V9?!`NwT, .7IP- (* /M<fi >rqc$ П3:g6pzf !5g[pw^*okj": 3AibyxC+ZF_5I|ޚ$X1f4nČN)l@Ta1"(b΋5]Zg 'mq9L z#i@8{kP/YP g:3FLV=;wݜFK^mOs{\՟*3w7)HG`8s(~%\iH )MOFr+CXXNυP /-΋gѬ&$%Sͤ0s"'9f/ $>dIf ;>TeO c\`ʏ3<ُa_ (@Ge_~֑L_Cg5RҎ[MEsۛöq cf&;r.(q.4ϰl,Q^{+|1EgX3^yb5" 4,\- weYgͺå=^quÒ'z|lN^_so4Nƃd JGx*u@ j}׬!8 3ZQ|2d'@ۏ4k8Ɋޣ47.h"| D1 \ق怢(9xgaGwwv!PN멓&vxͬ@;5|EVݲʯG"E!D`թ͘X0m63k5F.C ,"ȷ)9pS} y"YdP'|E[zRP 'HQ<f#sp0L%cLɂ%Y>;h9B"-NĂ6=>LR6j5A@.Bä0 ELDYW }+`vprR8׸abe0a}@Hr Dl%s)RJVOW`ե'$dD#-a\4N7*$4̬2m#2 E|sf5ݺ@f;Axɜ9]^e{)o7<3"춓 k8[%CR$Pp 5@6rR - iUKg a^my aʢ8ekmʳk$A;zChZ+6V&+"Z"T$*fa;;kٌV`[~ak{.]ABWHiIoZ˦-6ZPmU]s0+aׁ:G8sY6&T5,yS2MZc9{]L}ܙYvi q2dz)t"[ItwMech|#[H Hy\3YlQFƄf{qL0arg@qDz,"3g*۰#ڴ#vx3d0`#HEN8o@%*׶6gL8'5fo2%0"lAi^k";{z魘mHitTsLn9E"*K(qWOVb akFU(@2R҂@=E?n)@"#Y`S1-0F(I3!vyܢ*uc2XQufD]7]m ī# wpb۩ UK҄Qz'LQk/JAQIx B^Jo%Yة:lz9CǾLFj:F|+XѻhFO: HKÚuBxWfb3Rzwbnil!tQ7Mzg!' bho_WrkUUNeMIYL-`vShXSH +z 4xG2rK4uF!4p R8`$%!6 uK*D&v)8ܵ,'C\Ύ}L.8(@)~UFk<{H>dFInp@M#v=jg*<3TMú\$$Qyf#8ǀJ٠jD\R4q1_JFϱ *@H}I՛fptC- 34vFT4֜g:343v@@ardY:pPKS]ƥ5Trª4%$ńhD M3&}W@8[2&Iq(a8%v9*&DM:|0ϔst @o |Svw{` !QqRV{3eSRHwx>hX(#nȂoݪ; px7 #f#DK>$ + p.dWj80qnIG7m :OS'|R$F Nįkヽ>-Q+-dJX-^ %UL*Z8 AD=h!z (@* MYhDqp[-$ɵ|Yl8wrV \CgRӥjϓe|(Ϋ3%u:GJIMU2 Mw@yq ©P^6JWÈ櫚@&%xh>5ȷY}ӵ;wl_"͓ )ó䂎K[X2"9FHD#knF_E;7TpOD/d+Θpʓ{y~/r+E|/Hj" Fɀgʢslݜ#D}=c~mI@&>X7>uJ)PE*4 vg0iA1NQ0>`qp=] !27l/`֒bD[ƙɻLw8L@$o!U˒1͎\i-Lg"Йd#9rNpN@`0` BI;l߾BrOg$ռsb/w妝o~koc;*I$Ċ7w'}4Ca;ԛ@#}| Mh#˘/TE6bɰA((Ɇxh`12D<3@n%FO=64KH;I;휀(|C a rr"@dB;.Xwxyr{4;usԬSU\UL(J6HG EZZY$_$# ivl`N;գ`ے=' 0o(0qM0dAj$%PT`0W N׺vrhVD`EeгMbX!Ya@ #LOGA܇' G98GorQTq7d3keFwҚHP4Ԫ-Ң=;=٣uԤ+uB,U$M$M,:w8X~Z{ ʊ60.yL_c. g@O 蒂BN1p9tib; (&vAD2lV!"!Eo// .鵸3DDP[˝LrP%q@iմ H ۍet @HUU+C`@&;AFlOz( &^*$/"|c &cA.I߷JXg.:(qe_FNaG[Z5] XzULh+%zb([w}u !UY04@4pwK-a|xzyaFzϕ "q2OlU$òpP'7&tǫAŝ9Dh1HG`G!h` w6sRu@ Ux,jΞIcsת^ 5K2k/ CwW~Q h3iXӹ_aY :%*s]{yL饣i]\2G/,ї=S5Z&ӌfifsABmu Hf-JR+sOK2" T9\D yvt͟$$-0qbͼ6{e>VN!N DF43̡fpsŅ6/r+Ya yl)v۬`pK|y9u94ë[^RfP٘`N$ipx29*\H7ܬ_7cUB m5:[dTisy ;Y7phJ(O) c\3UPCiĶ`Y+8hflcQ^= ӣ&?ĖKޒE;,eGv, Pq]=3HQ}shmصݞz '-䩯}n1lļ>Z,'5}4x_%Z!NeESVA<՟DhO8݈Q(Vʢ6= 0@T[0"YBnAz0M`Py;2Z/&V~ז\b.6 t'\*tS #j9eZgiv "5::F-x٠O!4Er_8mnZ&lk%Xp.Y A;4fM"A- zc;I!GHdܞdÕ<C5Odi&w>B.|iܶeZP[v1 u"27 9i1ˀ#FX2,E|?vb](3I /kАH˶@$HTߧݦjEjȹsiȻl Vzipw p@J,W{nn-TylN%Dsͬ_I/TjѬpC%.:t(T@akN4UKn-3Mr@ 9-{8ȹCk{o9H=%vMSfK5O1rlQ+$k+Mcpn u/6@3a; אO2%{-^Epܖ[Y:,G Ba˲n3ftJݎ/撙Ű".j Q;bp[.4'3a#=fH R 緍 McRU-aΆn65oLJךƜfP:Bٴsϲԙh;6 Y;)3]'@8kWzh+9z1~WeiF C=n3st۞w˳=I}WP#.Kwf.v^|ZvNC^; 7Hqۊn)F|NbRC}&5 }:]L ʉW|eqzq΃R6.7c4zÄκ+Hb;`e!Blrh>v 3sRә8'KND ܰgb. KsZr2EHN\/ʀ/#Pȁ3nZiԜZaN2QkSEFE<Κ2JҸ;1ӹiN&&.d*"Gŋׯjv%N VW[,oZ,pfь?@wTТ6ȼL⪡4Ude4JvYH['rRH;f|L4 rF6j'f'LJrtd^ZS&c@5%ť= tdMrE,{awhs[8kv66C5߇ӵ3Bs[ɜ3 ,}0h>6Ѣ3ZZ,Qh[5RU;qLDi#袎B ,ͽf,t#) VY) NFdGIQU/,{}qMcrOv51f H -]+ di0`r0<i$tR|-,gyHp2L)٪g^ +g4Iq}|Fhpcn)۲*/ A&fGs@s;򔉘8< 4faKk4ɕ{[k *[HEдI<获w6M5zVZ/3hӒ"m,F[" >9Iztd[,vnmIm ^u!P1eg2k6nB:Qk^FjT !Xw!ɫ uZgqWBj^ /nO(cE.eQAwrY&Jj|5ZEs>᪇t:l:= Glw['Y~ݝ2¨ O;1ki-p[5=v5f[_)fkdRժte=-D/InD溼vY1ÑӲ[J 8Y-ӎ&NWfNt>4O{s K~}Y-Z\2^6gq1}RmaaB: zw[fgi҂G #R,k-i bya {QWIdtN.:RԱXuL%憽*1F9LԢ+idAck;˘IC-c&tOX?]D"6EF$ӯrqCNxouF;7Zni}2)2|+9Rh; t?Fǧ~NuԤ\ʲ"5xvr;@ %pJEl#3QN[5pTgj;kdW)@P5,SN5`׵m2jj h8os6l2-/z!Y[CF% K5L~@2 UV"D &cd~[yy Hcm|v6 : Q{լaY 9`q]diP{;:!6{miCk%2ee(&DvN];zjaڵCvY6P5mEg l]tA@zvV/{`\ds5Mn@ "AS4< 4%"t H:6\Qw;qS7. *6hȩq0a^Ɏ ҢG҂M+ @X݊6qCoϦM)MfT%\ȅ DjVΆl EQ`荀/5`3\ ACg'bhf`UnK<$R*B ۣLVV X߁0 d"ʅ\ ŘL=BYh `+`!K )z$!?b5ؽ!RtXPk٪[޼rXJΈ9_By_,˃\uvl-6E4@Ǯ ]YI`>t }tZM= uB1կڙfY$HIB)CpAS :b!l"V(xʊ?@b@_ҩh/RDD#_&bUR{TE}dUUqS( #PPH*(!DD=ARNFS?Jݛs@HaWa1ܯX~Ta/ϟ6U{6 {}4%o폹1E۽M -~"<8Ea& aokEL9s$?K:g:rQ0 o )&$š{Vqn\iLGeQ<h?%r4kFiM36pThϿUyٺF49Ӱc!TFY-nWX//ٟw?_Ye|N~q>>"`^O tzJ] 7?!|C]2԰(t|=P}O Lyldw'ycE^x3K̓ MX^a^;.~yœ^,ڡ#|GBʢ!*u?x~f? yW'M9ze?M EZ4UWe>_ӧ&Ӗ[^P'zDUٙ@dy9w0S,{a^ƴe2UZ]/C]W6 _Kwϑh{k܄հ=?'K7†J''ywc["Y Q`?*39͢3: JQ>> Xtl0X8y;nٌt _^5WX(DqD{B[HYvvz| w]=,QCkW0yv\sL'(`H#aLAaBTNI:FjGl|xޝuنnynI`*]N]u2E)t%C1t9"|)x\8obATUH=q8v6hEM~^^b9>ŠQ0DKP yΤЈl\IDd&8=򗴖K/GrNvx=s~(!]TO2k7@B4kTN X2rhu"RݗP̜]t!YrŬ rp=TWkBF(b# <6vn. &9Hbf|sL[Csvc)$Π^(<N߳C~dr= tzr,m87RQD迡aWJ*uy)60{rG;ʏOExNrf `=o>!&w,I{r7ebo a<Rv]?)yAU;&GWs BH>HUGKxޢ|4Vr vLstg^n+Rp{S@D^2H/CGemUoŒx}`~ s5ŐG aHg7jVhB3V96$(ÚIЀ-(""lM.1r<‡ lo6(4(׊\+.hVG$weѠ۳n@k" ~3ˌof|`Gp 2^*0!lGv2KmжdͅBWYh*1@'VwYM3?fLry9 [d;Dm*3gݮanXP8eOr~58g"X(Z|S2g%I34N*=|fY^|MnE_|K7Sꗹ %6nOJdB  +լ7E]#WExy-FB"."/j\j9vd%$pArI.Pja2eTR$bu]u9fxn 5 P)]Br} sD@P>p ,kv|+|;]Acյê92* 7;c0[JhG7NkNLUb 4i<ފ߿Y!=1Mrz,gyf%+II,ЉkPg5Î՚li3w'$g N!)#ჲIQlI[ 쑂fTld,#eJr>p?l8ƟYzXcp>jd8<ɽ'Q):㾡ܠm:h6+| lܩӠze"O` d[3Mݼvz'N 6YsAf^@!retg2Kh'~c4ߡ&ꅁUAETXRNz6;ʰbnMW<ƛ@)DN 9pcɗ7J75*o#:f9L0~"XS 7@ ADrY!?떖eՋKܖ^[_K=^]n[h P롢(%PQ ^1p 2Jy2Ldg(Ks;~$1/fL0OUSE9o`1p6/C۩Oǖ8z>=nB=j]yXO,U^?zS@ $Ы֜N=[z^!_'w0r+Ja UYee5f(XR,.=WlW>!ly.FWl|ۺ{3^s5na6vvT${3@vMtQ2nr0l҈l)ȓk-ּy |&9iT@e=o´:‘gwfYcn@|/-B>riRPv(nkәڀaIuw xz@D<#KBWz+S w.?㒸ܼnQ+pmvxS40'"9(5vy99WWCn_@HW(A}Qh~U<6`7f㧧nͮQm>V(&S0bovO Q*~ꞻ;d5\7QUOwMS"n4v]yy!ǚ2%@7`MG,b"K~5Ubi@;2"hf?ӻNOqQ5-CǬ뷰½TskKA J ='lUw@D ?,<<(|;1x>͙l@2)@GsZ&"(ѓy^ P!%w~/Ku4Mg(?'(~]vϊBʠO)ԋE_?#z tLaܱXC2vlĪ&B.|_?^o$e?5ǍFj,(k^K:܎UZZk%%O2;s,krzj^2krEM sc]B5h߼|?FzܓP;HHM{QO;K$U?BU#'Ϋv>Oyy| Um|!j^'h9dжo 5K;^ũvF];\th{q{*Ğ1?>)5NAR$ˎIL>)ct)ZSuZ̉ ,(+r DYNfl0d 3Ǘsu)SG,W,Y QPRH} De.&﯏ nC(?}_fW6$(`j% nic׻M1"eQh5v+r5XѬkFԔsmඃVlZnjFd]M\ɱj*/nbɭW$վg}4>VΐE}S,kn;s&os5Q*y&_.f5ݾn4pt$?V m Y!_ݽTCyEq9D?Gͧ0! to?*C|r̦;~"`$X{oQ&4/,cwpNTGDpqt'(x"HKM؂&Da&аESb9|sB;(Q5a1#qx-'1F 廲 9i P`2 ͅ~ rىLJ͓FEML;O\O3^{?cj#a-xOO&!+4CؕGG .Re3^UxuŮ'sO+FvjyUlNK-ZH d`"}( &D(#jv)ý?L: NvsߋE֬_ܶa<)!waLkw`VM19UJL\Úu`9J^ߒC´ A FxK["\ate2QwI^7ʋLA13T4ULtY@Ol= [_Bˌ(}|Db:_=‰Uo#.ZT,#}MG<$hML(K (ҡꡈBPm"P@Ҡ0rrwU۽5F$+֥ٔ Th}*to+< C-Qє3Jg 1X>*<2EFleCm0UJUC L na~SP`{äcJs۝sD1iF-)i*y nt;- 8ʉrBRCȰ|m#L:vjwS:_?Cܳ& p s#x\ ,o fjA%4v y1SpTC N}Vf*\~R? dS܁x8q|(ewPN7n$>SEmyLC3d }FBND>]rzm݄^\(?c&~\|~~\zKѶ^sL_NyRUC=;` Tr i#iQ(AoW,yXj4Tf"ΊlP+&Tjʍh:٧g;NtsU9 $ 6ct 'c_f\|̍:6CUbX[\YOksʨtLz_/#h) r( '߹ƺ Ւ@|r/=YI ̩p*F TEàNxy\_6ZLIBıI̓$dg ;} ГD5Adkέ u"J(H;5/_*T̂Qa5) Sˣ߯n=曘m N n|I2Th:өFI*i)dviM$T5RwLV5ST,X_؀i#}q7!C%mofRUVR5ѭ1цٕտd^DYO$6MNP3 ) ˖x橚p? ʍhd$19%CM |>cB IcX"(#PW~/'O/ >kE٣L2Oot+P7 .I  7DAPB@$x)5&5yj|}C4-b rIm.ó{we`|/)^A¢=DTxJp=Ki=Vޟy}/JmF] 2t@ M_yXHnF֭*HaXQ"c@(ށ >܂̇jt˕@˟Nxiz{L>_SG}1f"|*=YvAZ0>zZSɤ s<<; vI^υb{2wӿt/t|X+-l'=Jyv|~k7_{OSOB|^WNϋ|[{M`%gV`&@;?h +-J~y; p4K.ItRPewt2Ձ{إ]4swvj6P[<|0U_6j˸>hVT1k`HlfvC;/ob%Tw8Q'٦'>qń9WcJ+ in }@eR:Z`(v4fiW֔@Sr{tB9~x-zUB]*@yu-@l:(&l X>]C FBwDOM'MjX,jQrfP0$خ#lJk$D˭KF(O mɲZC/GW :61젊ʨw}6̙(af'`\ә+" %qp% ;1Yڸ O䇉jdO=/W!vݰQp.CMw6=epq5P26xa~.z$rf'7 sD/g}аZ|߿#b X\^07=%2\_#))be7h=PB"1t֓qd@,8Ϻ>43VTѯꪜ>ƾoU "㔣~NmCǽxȢN8"C.2%nUVl"Kou$P2% 䘪-k+_BaD՘S/rǞ\6:'1*<)<uV7KbqNUC=HxH}t~&)o|vqX@PdS#iT{TVm]*û5U|ncT%GJ<22[g{C+)df,W֓_D]456c@a /]iL2\JX6m6z;~m;zky_z|;g@%ݟt\]Y@ qTWftGf^OZEh_Lϭ?ne)}3FϤ-t%ǯrs$!՞@[7v.!p(D85yn(_<~4{38}-k篥hꐵE_q B%R^\5q̶_,yM2͹8χLİ%mtN߫q3hMZP'lpB2EdFR؄%nԆNer:x@eAfzmKֈr9 Dξ\J`&4ACjv!4ۙiGN. uMrsE >aтY٨QoHjΞvm*iΫXiԶRm~-q If4!n(U-"mm1BfsIxV1Ao]Jfx4bwEgIݶsIX,C@v6`9K)6 @ҁSW'3r Jּ|z8QK9}H+s<-QfV^pC xq$BpR™S`*ʃ=0|і>_s. -s|( +Ap|Um+ˆS6 _l?ĩDL9@SlՒ-\u03({41X<&I^AθSsJ%%F+8 =>3U~; up6Qiw'}tW$L6)!S>hpA+~莧?c;~#wj|ߔٺ;A3|w\_C@Ġcg8ݛۿ>A% dz:p95=HvV͹i!״)!㺀2҃sUEJG/2y+'׵"OyZt'>g;:СʹoL;1YfM@fRfF2R~9NFb֍.<ިD,LO"3lk3Ɓy}W&/#^/)$lIt0QzL=Lo݊2 ʮMP{JDFo`Oƛh V F*鿩uq ?za 'va 0l}(n~_GSh|O>Ky>Nq| &i_>իGwl?|`+ A >\EdT^~R> g:1>Oׯ:8w龡r.?Z̏ݮi]['.kȊ>O<EG8 u67N 'JotAr-I4i tH}ViEQX7$$:Q8&MQj]SJ_gg،Av~F&TT|oYSt@Dy`6:yWo̹[цɇ}~d!իUShU|x;Ê"aEݪGz'TUCd}6e}eu4E%#$_cϦz7`d4N v^Xwsf2"<[Iuu9X8j+"3+.v%&mY뺍^/3nU`C2Bj[ $f@bj~/fV )uv[R(mk|)N'а۳gnD .<:\׺xԊ-2$Ԅ8$6t,P rL7q3& c: WSM3?v&T9Xd|ZP@fys83`lAjyQ2aH0I.GP<:lt8d]K+N9Ww\֡|9>(;H߻j>侉ݶQ X ':z٤oK:)拺fr0ow5@@^="x5 z'W {yvǭYD2R9Vd/%ssH#" ssk3O>M($7!ՠМb.R9>zDy#=856{B" ||"2:?S:*cE4pk%]mձIJ MDxNKr=f'2`x)%[%l$ ct(rڟC0E_Lʱ4qsю瞦lm">z`*y7roa/Ss Y:q 䭰8Yx{!n:HLSYhnZ9 v(0HPP1yU铧`9cZnh,EED%{qh) DSIi!Kq\ a`uˁCCds 0\Ł*˂d&9!2@ٟe&5MA( OPwE+-`X:@L0/5ӄq4JC\G/EzK2/Xg9ƤhddQYXTUyTeLbX-:p rPJ"m&6u}6M"*ωـDB&Qh@69xB Kp_3sgcソyzAU@Gi||p-c8j/鑨v߃M^PA-RjV>c5S|m5/HT~4в~__ ;)`{[I4EZi+mʊCTա.7p Ml!]vb:yf*ԇ-~m63svY;TPCǏZ%:W_GGk>3YgV|vI%O#G2#p39f***Fp awfPQ D@!&:G甒,E7}޹=Su:re[+E.%ryTW{:*3?d"(! I!zQ}=ކO>QC3~cy|O{6it 92R ! 9 /%l萅v_ `:= $e'8mn>5-1!eUPr(Ҋ< }<s |; {O =PvAB!QGj(/qnrR@((̺o9xSmϖ]?o~)֋8xIil7\ 1Zڤ>:Ѯwƪ+5~TROLD1(|@ZWY `鷫qhiöT m;36#_V_g>؏}//ǰ@{`EMTzL x|YB Cm)+(iS1œp?&n:1p :y Vw#HO)U"(/:dZ;1V?-RݫNW܃/w[d8O s'uF;Do3Hw~nIc'mb:VbOZCcXz[g8{WjuCGr4Spv;3 Vΰkt..N:|yÜi)plT0"f 0,#<׿u2i6I|~Fi_1Ue8Hc&뽽ᓎh9͓ް͸ny}]_Ǵr3yGCE=o= ج 43DM 3ϞY|8tŽ7G-Ԧ^)'d$8)՛@òT8$%\d7|JAQ@ PD^ 9k,;͐6Mw^We!m!+#=jwܒ)x" 4!"cdL`Qx75M*eFgQX+lLQ[F;~ 2Y궦s0߽7"Ċt[mdŭFbTRM ߈,Cw@b(X&lO?v=PGĤ,kPX-|1d >/¹4M0Vՙ{ޟ *WqS͕g}|LX uq/'G߲V HQT,;~BaCFў'Xa ""Q;w7ѾS iI+ƶ`oJ<_P T_pdD5^o՜߅ Zo`]pdah贠;oW|9>L*?{]$J c0ʓ~&w>Vj`g_{(PawC|26MڨZJ( NC3lZ!q bs" u?w5RjޛRIm((Fj5kEAQhU&%hJUbUF-lS,m2Ѷ6sB11G5.;NREٙqϯ~wZYu#l oKBf"QP']CZS.!T@"|fv9h=ċd>,GGME(ɰ*7 2 2<|E+ >tmơ: t)ښEo܈.d7 ˅vk8RiMwc?EkÒ-)(-z5sWQA/Ry`nItmy7z'(`06Hƺu[ri-t@х(A:S2Th(!ͮɴZru-UE઺NGyeŎX{ɻJipeHi|6/Px(?F^qTTZR"pE_ r(D?GO3ܿ||\/`W\.$#kW[Vn2L~7gcXh9'ӪCuY|)-Ç^'߯ DU+*4vPc"\BvĬ>䷏,p+d:5 RWsj4Y)IK6xLk?P;w5sJOyKN˙˃mN. ߭:K֪_8@}={Z^ .scy1{ĵc,zDy(8OhC *z{L /3*zLTP%ysK#A3as#S&8tHts sdsZ.D33R$7 \ W*Њ4s7_]@>LAC@R'7,i7g!f(fM2 b 9ue3](*.4{~7>ܔMu9[$ dGN5v">t7zgÎxtŶKcm͊ZquCI*~O/L\5G/φڷKQm`iTk&.ww^ 4lXZ%1LlT7W;sDOku5w$T6U$73}jOٹ,VP^zV †Z\},C׼xxT@f𨜦>MpZQ6XtXfU3w.x(4kE7EY زhzH TIklxyEP\,#\ D8"3Qt^.T cQ:>X:]2R@P&y@%1'TaDnLDi^gj 9A)\>(x5irf?,xa$I$ֶ@ocX*E"%fbFJbެ~ĵ+x{ܱGȪ3*1AEE=~oz^x*2wv g*h`&;`էUu_Όe 1EhtX $cU8Pzʥ7\Wf:']K+k,YtW_<',. ;O;H΀$uj ף|d!VȠ*'OkK{}XoS,.)`12I˞/3øPBa\! uv$Y`Jx_ȧ,r3&C10i)Qe 8(mp+ү-|+(c]䗏&Ye7cާO3fQfێxxq5d <1h"C@}QhE/iWsQn7$D>fLy~go0Z{pܞ "aaJ.:LW|# "):; .iB'(̘J##GNyi%踄 gxcaD/=.0%$LAYB?'lC*AUdV2ux: MP#$(@neÄ:oc@PR,D<{g~> ÜnM؝uqx؀oWMLU~[DGdiU/Î=vVݖ0qfŀdpp/sM3-)}zxzngl%]+4S-xÂ1͚ Oԙo߯ ;MQG}krR*jO{,vsp*9"ޱ3 u-x0I"}yQ.}?ƂaJ 3 `37>B^DfHpädNy4bta^,T$sqd(VN<ٴ}|;XHO*Z6cY=GR_6u rX:cW5U rϢc-et5jv ^:T"XAؙ";+^T9$!Q̝$0B9| tLТ.7\]q *+zz>?Y\zw`Pkv+PX' 4nO{}{) +ЅmXeW6ȔQQ߇_lQC mR1fJͭmz=;4]ŖD-$5BPkPS dBǻ2j*B8QTQ+SD1E@ rP "_jTЫMe=/!ǘ:;^QQPEBztx=Um3R!"sGcBje]~6O FI@̻TFrL:M󭐡yYvzQI/:gZTZx!xk/lu19-Zȳ $QR*6"EJd̩0.ޏ^X`ޠJD:<^G$6>ΎGkVbmlD1@RY4dx'̳@)'dhK+QHcgןϤhR;E1x|PÕSCc56F߁f+׊r*7zuamdHI:x#pЈ@گ&\agdυߌj+'EJH/=b:Ӿ@Ɠ2܄DD r Utt fw'$mGg_6C1,V2 -zip3/}<>7ɌЮa.*Au.3=_V™1{YrGIhql麡:(c6ܓ^1 t,3V=i]nNGf{d3. O( "pAE%Amu|r:Rn!Ȫ'7bD;YX=Vϕcz% :Ljv4sjKJ ~u)!ϥ]{v8UŔ#=aҜn:OpoO!`I=;q01ʙL  ќfłF g0t*}\;Jvx;R[mny?*:9y/Bd[~`S*wgESE8!%Xύ`YHCOOLoP9d> Z-]b,!.0hqS)ʆn<}:WF!hYxيfҵH+iPãVh`4dp[rߛ2~Z~S;,VݸsB hFM2\[P@us[x}l^أYi' L>;HrJL YBrPTū)^AP9_xW" sc`pGu f1xZͳq2˟AviJ1(7[T#y􁸛]ɭ~?3kr'SLDYiT% YNw{iv "D/ⅻWF'fAW}!l1o3s͞kӢ񈐛Rjp#̙-bs=ybi.UPY9I"zf줍Jԁ UaA+*ɎJ!vg9a{zdpLEżÓmbyqgbpEYb[LylR. ~,"f~kwvxq"L{~GFB}Ŕםw S-4~Κ/ -VdYf%Ueu+2ij*M;f$ R)2eEG2^7?B|Yܫ!}Z͝:/f K3jC=CR)Rg'*\ˣcB1TpU",yR{%uѹ'\%&gauUXUC /R DA< C`juf5 - Dr'v/S"$AR̘(B>}Iy\ʂ"+'hTXGڕI ܸL\*EI! Zx|^{ҏW>xD3f[nkjzZ`l鯶((A,v\<ij0%,˕v-Zq)?2eGF~4p.3ߧluFeXP,?QPu\hZf4$Uki{rN%pπuuXApz@3>,V!E"p*T@!0r=Xӹ8{:p $ DaMJ8$RG:Gѣ^4,啂".\Kk4ގ~tzeضv㐃MiݷG hqtN).Ұzׇ^-˨{p[iQ- i"&Xσ~b@rH6OSp 3W`k&BK"a\.Mص L\ÃW՚N8ˊnW7Qrs3AyTЛ*_O8nVp=4}6V7AضglSp;ɋSK>lKq`b<(NsMڅDF)$S({q8Fﳺޒ^w W A%-( xV7{l=4Q*%W_OWhuU׏$'>.4u&=oAsq99^4 R(Dq|L^Y؃" ;곌Kt>;v=fp~ $I82'@hohL=RV20/sr5y3EV 3ma617ݑ( ϚW#qc,c·veaErd>0B0CDK<JC;uddP^ƋANĦarO"DzxC#ܣ|<#dX9|~rNqB"qjwG œK M۶Euk)}}9ܕ=$(/;&/K%},^L=vfHdj,袀H J@4L:{lИsN:sz/E'ZU(*̶$Is.zxݸsr㤛Cqsy o5 $DqbX06um@HdZ}mK(?b ڂnnb0S\7IOCB6e[-p02 c1(i<*_4N"K&IxǓpM!!\/oWTA( I04dS0:2")$U) Y4Ch AY۞dXxL$H! , FckSCvZitH.sμ* HtVpmRJ[@“Chv_HzLc)}|:ȃfC1䁘i,P8_p?,Yw_-LP'q`hڲ`0~XK8SB5j*#\kep:>?(of*<[rFb-fM{~؎ b42Sœ2Ɔt"c[ё:'l",УubLl#l1a ad9f.3P==&U<NJpB| =&87-2c'?!B"Y"ty2@DD,Tƚv袔&3bwffԨ1D8P-QQ@(lpJ 7:O\ؾsdɓ*qaqHa$:i=hnd2@PWo.~ϟg{ B H  E!E "QfkFiPPpCg oB^_cbB;8f|&8ik˹\߱ݏkȐ|:{1vC h}zlfDeB$"vWPtbeV`Ԝ#"+dy:w`1H]/4d_'n*01IHr2][&-ۑxP@JڄBh"ȈRD*fH ɟ?TmD," U38;~봦C3}:)aY'f [yWXklFD0qDZUX͝j'݀jb"9i( "sQ}㿿Lgz˽9^H@sD5Gr`E6R]i4M8{8P *E]K T_?-2Z yee #Mm@ٵ}>kak SPDBp~}vNe7\_u$&rV䶘';g22גAf7i8~bۮ~ `rڇD,@09HӾenIW$gU`4a r;+`=w~]L?G0ȖLu㺈M'pr T7Ex:xb^{sFdQ2AKi?i9*,weTb"'\@©gW;dDC1Fڈ|'ֵ銇Q6τ䅴Gܘ_"h9l\)A!PM*P`_q\@XQQQ/׷TBi#:$,9 &QsgrݧvGw]agi&]1kZ+=UE]"A ,Th.SV^e.n6$B\ % d|-z.T4&k6)xX3!䊧;容ĩ&,b$^ffzfM֥gXW }}y5u kc.ѱ^ . *Ds|ǿO80rMA2SF'{s=Mvm劕 7u:7n_OvdDt6`")EM:NOy4R(cgX胱Q/ikʠB H3ԯ q(U⍃L@R,Jg9S٩e ՐUU4FZR$#hkQCH3SR#& 5&PIQ&:6+eĸx hܨ%Dz`m)~֡,(GMZuWL,pq2Ȫ*fK'&m3kq֝IuB4r͝3Lˋ Y*n56I݈Ҏ Dl(/bQ{HiJ n6@K-y|s9O;)uo>ٛvJuU=p1j[rPcM7{<1ܺs㯎z%@-*+7.<5P)Ol'Ty Qh0iCƌ8߯6wo%٭R@e d(:*h嗌 Z y@ L*r ԣ] 6PcdѐKyv{LqT:rtk Ոp:%vr֚crD&;rW!hތϊD W2,6B\wan uQ=N~7 zX saNmn{7sBwj`4aw"\2`xI<䇨U  xNj,slF(R,OOW5^3'2 Ys( lXD6TICvi!Ci %UR%OkV|x̷L @5<"ӷMn QA lyPǍ5()%! `*Zz:^_e0!!{DjlUV#yI#@[QdY'N;wE{m_Atش*ឰhShpGLU8~-5̌$sI.[Tرbm/tm!Xܻ9všdވ3z+(Yw.! .q❥(WGo%aj.) 69-q%+LM +xzi & ZX[=8c7 w8?"_\=L D pJ1ʯ(#+V{,_֡*CIRGd^Ȣiz_u9C%9]f= 9%n2Syz]AڠN=?$9aT^ep, ;Zq>)@ y%TP-9NEO "-Zs(uGHqO̭4J:nBN/]ȋz[FvxxQ܍W'0-;C5]'֬l_" 3#v(c{>Mb$pdbV&@S PR{ QlN33lX_'2 pYNtR⠂ X%d/:NBrg`L jFVwzg`dStᝡ 6t8: u'r4}ц(SQvQMVwq ԢCH|w+BB !A 0];_QgBCЖCjqMC%gw { 9e3Pi:ss˾I>2IHWf2ҡL9Px[ 93&;|A`d ^q[nӰ6*'m@l5aMB @cr GdG+.N0ϭ ]T4LlC=5a(t2)JLBD̢e#6۳95׾5MXqb.t̪Nq 3vfRwhe _Fm(ZFb*UߝY-0tJuiD~#[ zUuUSSsM0"|/8c|!#Ja=KG{xÃݻOdukn;XQ8D(\[z)tݥ_"{OoqAj-L-EMjBeWEjKu9tirR]j<~V{+aQT(Т R*Up W\U|:nDTk^&0kQ_taLؒhPەE=>k"8b\lF(dXIjjc"eY xD|{65mxPU1=[ήx,ŢIlL{$2 i|\(}W^$QeDDԖd%(];k>#lV8vmWmѩTd>$:'*![o7.i}jڟe2PS܀ ,)~-yUC56gU1ai :~Ύmppj)>8QnVçڿŃ՘9 Ǖ¨׍UK| yoMf{6:CXPHpo+D^@|vPZO^#g ֳB#Z*;S 92* eкG>;Lj$= 'Pqb59W3Fr$)IJ0/&{l<[ ČKuyW냫X{L0o=$.oXQD""ɕD3]7&kiQrA旌yU`+}|}o*+K;m0< epSIV}kKsOjjZ ٣|h=wgHUUk6N<igk|$)d;y'IXh>M_[b} {W5[ZڡB~Vz|a_G|Moy,.G Oa\>:bopU<8.Kqegӓ PKad]pCBwl3SmWwpd 2Cۂ'V9\H̨V)CGP5Šeհ.ƙx]M%9ae21 0(}^w-U(`g`1 jF~,E{JܽUvYLzsJ1Fٚ@X, aCG㸎UܖE/-:;5Fx$r.(P' ƴC F~ޏ[^CCL9Ԩu \bGu8+/*0@ p9CG2lDqUG>"jI U>nJ!G1qqL+>LNal86 3 pSDT +ss:9RL$(dQI4 CsNq\UłKK3F2MZF0xFrаpGDo[\WI\90*qu 溩$R'D=!UN`zVژ㏽ -HE9 fL }(9B0PGȋn CD;O=368&Ll+Q D"BC#Tc Ar__*(ڦg'iq0W|'pWe½*Z#x`]Pu:'[:vt' \vfuzUkN͌*L,Τ]pN3ۦiץ;yQ(MM( GIώ->;m'}̠*h Mw&&g3P D@Ak;#?V~_ʒ"{o̳s7M"A. B!oky'I׃$m;b2k5\ R)X3aHTD wC˒dmAx@ϖ9JASb_'Vwo^پhhx,Ӛnuf|KӄNnƏ*D+穜q/ c Scl񒯀 AR6׍|{Hې)!yH;.YHoF~%}7T ` dvDXCkPQ#G H dEcd;p gϳ5U}BmlrǍykxm=/ff=@2&]:%aHTPXo:Kz6t.h9;vu1|E8 5xzeu}d0Ӗ -Hdbų\#/!5"IC0 vC 7ΐr1 Rfc17ڜpcչ)KeB/LbIfyy՟VqhS|P5|r_ڽ٤,;jv|zЎJZBU}smv:gFV @ PbP>o>^,9۝Bճ4@D1g*L oOC\by?;/|D-D"Gs{g2`ТUG I:wyô/'>܎rK-" X#ՊlVhe!r[m+52/, ۈH |mK5=;i MB\ r37/ԉ! 2.|ۭwdoH~o? {Fa{J3/X4fS&͒i`S'E6b#!:|>;soHt&EÜC/;%9n =, KĽd(zo ~̻˙1PD6"dFRJ ~2 fR ~{ aiY6ٺ]Y=5 %2VUh{\ŗ.ꃣoS(^<6@̡ Y\q&}\ t!q@F_Z9zBMnRJl00d%3Ň,isᲓ'4 /oXPM!g!n؄05KXL@AWɮv:PP 4y@)6b=xg➡5ώ_'Q^5hv,X gfVRSZI#^3ha bH"*2>§7!b8ܲQKE_m-?e=d >}c']<0I$ɒflpV\GJX UG7jysŖ̈́"v+=3c⢐,Bv ,ؑ+5ђ6e ,kyΠ\(+4Թq#%(3da̽pϡmދqnK NuZyݹ`gYRFAbLIpD2CzIwLq3;2C۶2KzD{cTn$^w u׎Q=ŐiP]7Mj[#Nk4Y1LZ*Bd',نHL2$8 !H!}!s$m<m<+z#ϮmlLe8KfNJ4" &2eCYaYBĚRȋ*&mf ;Т< ʧ-o=jKur3t== s盬i;Qp P㺆Fu'뭛*<35ehע5kVngs.S 6Ò$O.G "hmsHMv2RÚ.; 6 Oj}xkq@oΜrqQ֗HзјRxXKd4*ȒÈ*kunߩaiNg͕ͬ &:MHjts&M(&RLQ$ hRJ2FRNقX&<&H L9uoʱ3~cLfL#mLbl(*$)1+F#U~N TqA('FDA~ĈnHR8umt(,#n" ,Y&p9x8sK(F ѫM_|ڋmR[lkQmb4k汮nZ4GV8~n;an}8`ZůjUmof6\^MS(B@K;x)"j[[smZp(Հa (,Bqp h@U\og^%維hb޽&Ur EYeՉj;g"2uAB`X 1BP6p[r!UPSKqG2ku߽sdP`.l#qNLj6^#*+%DXPԻqkV>1 -nq{p 6_{NɚA{d%/|qA~w ΢3G_cVkPbd<ۆ#֕.E} o{b@#/Xn n)BSym"8BI!Negl{3ݞT͒W1JN0p˦;&۩P>pTòUJ$`^.a5ioz9u /e"Q5ca3ݺYRϳCJKf]$z vmTƳMx#.jdS U̔q]T}ޘ۷p U{rX=hc~VXGnTo'h$Γ4;NlOv㞒&чTN34Ph?$Qji2Ċl-$@>4I^8=kT/_.#O},7wi:Nt8Q'ٗԯNBZ4xf ) ~Nuf͌XlPG5pܣnF" łN>`uĊxZ$j͉ϙ" ۑEuQeήNJwU|8Q@E>zIcFuͦ+xlWy j"dzefɹ+sWZSE@ĈJAHζJ:9];AQW tP)8$̆oreߑ' <"~Kg"{ #Io JQQgi1djCQa:,ޑ4-r)D$h2.IpȂh/wXP}-!bNM^+nq Cܓvu2.s$2/ w]\HIh|OZ>r[,6#Q&'$L!Zc %x;w(y6e`/qńi-bƴmFj* QA&`FhlʍF$Qhϛkk|>_nˑIg7^/NGU3tXZX^:CTP ܷvD^Yin.>VC7%* pCNCKj*G /헴K$ b\QLٻwx7[p1UU %A`*64FMޞTZZ5!z8v)qgyOawlA ޯTHQSwQ"`&Rvĉ{ÿ ʞ[}r9!bPr fCa#H(G28x?^)hW9>E~O" h80~%"x1~2M,ؖW(Qf= 斧)"ibs`m4%?L,gfhxUC$ CFCp"e^4@4E٫4ʙ-Sc*S Kٗe{c;pь7G 3ȿ W3T_z6&\;F6X,) TMgiL@q OB=hY> vK蹂z(hb 6 S D& ^i ߲C٧ki/ wYC9A9Dx{ɡ 6=S#vg~\Yޝ3D2xzrC8?P;Z﨨/Sr|pE(>!@Ur?ŠRcZXܒ@FAOrtfu}lDtH*PPJO9&\?pCxPFk"bsmK(-qA>5Cw@ytCr`цQ%3T&?R?nt=.FT?UFv/M-%1;5b( 2yȣx.w?zb}K٥>5?Ho~_,y>)HAT'pw|I5:I}qRjcXFG֎؇{DOz!ө9A*ʔAH2q2B?p=<͐`[/< eA,cc`RxrhIvYCn,~/EB9krL ]!ή]^DX0$2҂ $+@tuՇ()􎟱+ 9 ;d9<Ըl6, E?xpGkزYRZ{^!Pf ЯIbE}+8[!0 ?B:b;{K* 0K ~GqtMYO˸'Cӽ  ҈\/\է<&ʏ}ن W PLfk#ڐsTs?]}D )@gzE{h:J1P@H!AA!)AO y BR+L ?׵aSްsnN z =go9}Ƃx'dS 7;33cuvalWA?o!|qӆBH$zp1d|zP(ͶZ(`nߓհo" ^h2l 6~oq`Cnp"*V#FڐEhZL&T1U0 dF(cX-QbMh$TfbL߅s\(EţcdX5#tNqI@1QYDϡJ!y7o`?j :Xz†Q~^6"HۤY[P5ToVոlN 4p7B-'+L,㟽CxaJW!$]czX_ˣ2T @CLHd 4*RRagfLlW暀ǒ,o-c(TRA&~N Ǽdn-1{ ~?

 \<۵@'L"_ZP~BCSzDl |L3nQn};1?m1Xb Hb,T>Fy~MwAy?pf:qB𳃫Y2ttJ;_䈧ROa@7_3咏8+oC5fa1]zN`8AH(=X(/>Wd@#λi[kzQȡP!4H B`PI8,xQmr;o]lښ-qwh HܜҀ ߢ\^>È#r_{9OeXRPvqI [c tE4ƈBϑHuVCݭ,=\N%SPQd~^jX&X[#5-ȸH~XR,DNBitٰ 7] CfFlcܚ.I#1c*ЬGl"so9 = (z§F_VzaL^ps8U4]݇sVgݹwCyj# w7OLMP!rl=&";OΫkeH 9Z4lүKbYKR/QါT̓L`\6U Uu˪mjy"ϼKwߐ!#g0zE`)k`TٌVWnmji7#E{M\]&5L*|#&T253?)-ddW~DžŧfDct4mmHa ;iH9MNYnp8t^"d!${&x𥉉PiQȝVI88/:pPyb9Yo;.WtEq:2 &1~abT碐:8_z^hݝzRc}_AW53jKh(5'CQmP{KHb˷&M h'LfE ߟJ^ ʾQr;=g=<,3ߞxlRESv δl O֔MN*@%zB{:,/ ` jXw &*My_FEA `𹡃 Oł q}T9SkC4^W~7~*lQ`"" fh]}DпyWV Y‚s[>E<x-Uȃfx/:_kƌe7ȷ4>c!yF{ux\n>;E,UJJ'}M8b^|-x\14r֨uq7(4JE-M7V?w!4Ho6&O~D r 7W^hϵ 0)J2}9. UL$)?vp+ҥ+d5(*'UQ,O}I!ۊ_EبwB [%O̐Ek h/RPn=/9,| dײZ,b, mc;q9dQN84n{A]mfLZ\pd !mˮ~ofʪwG|&{Pj=:K%!tsA&3X]B,8nov"ϲؼ~gt{{n%G!>Ϙ|A4PڸlhX6̬ܔltriqVdf38>jAe(&rbT0"x:gc}ls}oyhAd ˩zMkv]Uqd]4y ^ e:q_/ r'K^vWyT ס9wßıbmQ$"i0`ȢBZȉu˜]ۺ""86 $ms".%qٌfE9$$F&IdpqP?D&I$c"ܓ]tKE$ZpcEQq`b*^=_ҔY Bn "ÿ*{r}>_{B@/?ߋK{+(*/-(x΃xؗ$&y?$ I%*œrf~_co-D$"5ݗp^ ȏ|})ࢀɑ {ow|%NB] ұLC3Z O:rFM>d>ҿʟ/~De"wdѵ6kI!A!litK0hI cuB7[It9@HBB9$|ʹM6`ɺ,z9,i?ÞuʙQ]6tҿ?iFa\2(Hu$oG}oDyཥbÚgZ !Y*C0`ʨ0#v~s1!MJr<éPpYY5=-{\>~3{nP ]g?P/‑o[v:fl„\/_z#I-<ҿ%OxS'tűP`xX.W8A]g(#imY[r(|=ѠBaD0S? ^^G~;s1} J[;m GqryZE~^;Qb)kgʿ +JQi2mr̟e/NHQG$ر(؍D5FDZB%a6fQ6$ƒQUş:ƿ.y&,`̔IG1FXDTFFQ1d"FAݫ"`$̱(X)v}ƢiT޻7N ӳz2<*VږW$}Iڻ4ZmM;5d^>uaCHY^%!+ IPʿdNo**|2 )~d 1GS~[&@d 5\ ?^ڱHra}0C&]`,ƕ."TxP奇cSa1qUL",2ϼ,쳒!`bU"V<ϓ}qx4lgHmQ}q\$L??+\?q8O?}>|r΄}(0 EK`'``N88ggZqg\/-yx'Ѭ+Y[J@)^g%7>d,EJ ƷI(ITA&8ڄ{kHipg۽E_3P5' qX̆u5MTʞvaK/}070:x_aK0K_t ;x2T~5DN?<ڔDx 3LrHGFoV!$#3񱭩=vz?yآEb"Dc]W@5EP2^~օǸ(x$ #n,!aw \`b "la76+"1OT!;+0 g UKڲ#L]_VU^Oˉ ?I(Aυ\?u4>O<};! y1Ts^/sas~gƃy%7^[D(hRYng$DtGV @0 ff&z""!!TU2*DR`?k56FGu\)֌ [Q׳{1&z7 Pz2d,Rw޽8"W"iqoo]u W^yYn) GuN]PΆ8e?4T7e02$dS,,Y.FQ*)@=i1x#Egqyj]dE\;tLU]kjq|+b2D+ Q W?[P"FR 6R՘Tv C?®^co{,$F (.* l.;f!G%*f("]IԆBa.sj\]5ӂwDq29fuѷM5nK284BT!5Pvݙs:A HET$%lrq׭IͧkIfud t]NXW8FI9A,=ݒ[c嘚+v܂fA# "3Qv\K̙PptgRq8RK YHc2q˭":YJRwCHd!ˁU8HQ4C%.kRwٹApr@ nh.kۑˡwi2`nrʹHy "䤶وesr͵5Ӓӹs;bjS%k3ndDTGBJE*j,Mf!- "TnX@f`Im`: jn(|&tukIIӧb뮊g8!st FM{l5뎐K@R̤)\vo.݉3r\6..w˜9H'VS#D97B0$o[6VƵ皮弛npq7 0B"gZL500A-2˅vEWb!ķZDM% bNGBB%aJ)Q5 8I9TfXŲ9Aʗ+eYjA%FLp&dIԲW2$5mIZnM(ԊZLI7웰5qNP\b9pDW#lJe^:Q-w"Ɂ޹UhvJ'S UX$f I8t$9)*r, .m꘺HFDI/$x3+eUÔ+fQ I+`nf1 sB6Wwe];qNTtIӚBHF %d#a&X$cTy.6XmݫMG I[!ʳ'I1irBd9HuHxZRQ쨼F, uZql%#*ɷRȫ2H UƱ[k "A65QU-c84ơrF1TA5*PR` bM"ԙ&HArۻQªqD& @f=$Bf ܸq vظ/;#jfY& p>qc& o.rʪ%LAWr`LT3eM)y ۈ#0QL}nguk1gWKrp&"aEQY-2LF+Ȩg0G;Q$7WR.2Bmo:dO;YM[6GX 5(q)!U܇)mI8I%PVmvU6C&b"K y(.w#MZ:w̺͈FlkNēM+nI#մ%,m*2 ulk [g[3 B,rd1 Q 4ϛ +`VcFBLW:$l+A i㩬E""*;$vnN4ruQɛԠi2l1:,JBd!Jb`Kj@阏Fk';.9h:H=GQЯS WwéqNI)L!HsHfmhqsLAi P5fÍiPrDkMAs+ə\`@s$0R$Yr628G$a}%.G')JY.BR;0R bG. 0#lLȼnnfQĢ1drƄG';ɾ^Pp6 fEpMZBPٲp]9K2.6{js\ f#J1 w;rQw:WvH2^/I뫄yLDnB($$1l L@+ B^ss#R5.BǎY Aޮָ\w̓fPFY\L2 T [rT%$57w4&ejBڳ.j:02c `,ҡ0bF##"̄M!LLrGD|461+V9li4*,er*3dQdYlAZ'-/%ʔu(w#ǹr',r+gW>O{e'65t?ԁ}FFX>p'-a:VoIB?/Q}ٿr9'?s\D|;nJ%<@AO 'O΂cpH.0}W`ruOXy*:xU7mƉs27D+֋D4@~mȀoL Q# TWQ  bes~^}.<CR |f{1_=M&ҥKM4knF|}wO t^E`22Ƌ vD}G1e;rX, In)Np\ɚliQ$&osYy0ws'0n˻u 3먎FWv'HeHDJª]Qf\J6-n#0ӎdJ-TEWE;ّ".:cFNN;;WqL͋dDc&Z.NublHK1SS }OM&41 PKf#,b̬6Swe3@UF#ME}v "))$5ۀex*owkQHFc} h#Ef8{2%dԙ&(1Ysvە]ӥ;Nj9̮VȺn܌4urɔ=O* GH&u'Oݣ]b1DlifF ,FK],I)}^(tIn}j"بVX,[EHɉ,eK,eb-5) LIZ%,5P4RADn;1wF5x+Sr"npDG+DZ9LC %lB\䉤w\ڹljQbIk[޼/Q\`䀷$tgW$H].4+fW&(h4dlmb,FuvمκwKl̼vtwљnt㳩.Bt݋nWB'N"y\Z$R4PD2#C@M kt]ۗ414y0ŎklN DF i2&/dC#9}6=u׍Wh%f ۫*U$݄ҵwAsܒTØA7⤰Z)lُ/BAĐCz3Uq佌6[b\'TGJ H-r9eFix5geiTqSuI)c4Z7ho A uߋ+ٻ~0ky3z&Y $PcI_Eщ&z2yS!2.|}S8-Rkȭ䣟kґ\_VU1#XM#G䗛Ԍͽ|ك>H z:e쟂MrF:ҵaM_ĪҚ` (+#"FTjEFZ5Z5mW*[F؍PloUl*|xh)`zk,,I9g8p\2^$ x<7؋tu2LeN5)t(7u :~a= ڙ1ʱ;糗^YDD{PǧVPo͉ e aG/cٳQ+d ,_?'9mso_ٜ`Nû˸F[V^Au*B@ā:N?kZ`Is6& )].^oq {tEߥmy#/B%XC6R_h$#x(5$<7|/ᾋ#7 Tx{ e"blA4%-,@l3KnQPpUT"z5?d{mGA!JôkBaS:D`|J#ejTSq9Lăo㿨t{syVM+.#!A vB횊El,' fV_ռ:Pod~,ȬVټ6r]o%3NG (@ar9Ch.BA$PE-J$9. h-.c𴽿ih}N{5TarHG54[vukZvbRgF_oNCv\& (5%}Wz/u(2<ű6+;]/#GD\)S=>wtQfU>h D$={1ovlYmyW5),ƀEw_k0s(q$8uo\;qߺ̵}tLDH()s0D(!(kjD4H2sY`ioiVo]^+|$;t0Ub,Ѡ&b(1M nQN'𿂫 %P, uKѾ@fPOjԚ-@;42\?QpB T æ.G^uCXPN=jXŋ3?VʨIs=A(:~9g'qYO|oYţDߌw8Z$~vz ^p?3,ߕeS1f@iEF+~J *D%VE&~{Uub WtM9Κ2b0bwv )Dc)2bute0-ʹ4661ee"K 04*LdEl9d?\6 ?zg&,$v C@fQ%7o_lM] Ӂ! odN:ݵl}=,G6 SW|Mvi^· >ߨߨ? ȑa`w' bmWAK/er `<S$,6 2,(diA$Je$ҙ%!AHD)0# !Q4i(2bƛ Xb2L@f!)#F,"Db(e$Q0L)!LFe1JIƛJiRe$H fdĈhPDƀRi2FId30P2$̙@63I "$EFY% XF$ (F6#L041& Z (P51B10hF&c,idb* JJf̘IҖ@6&DbaLe"k,&Œ2;[231ɦL$bd*%bHhb&)J36$JjIi6ɈE6J,p~*?@/U~[^4i~22CĻ~ߜ $ͻtEAXKMlxv'k]IJ>  TB/}$Mneȗ- =Դ 4=<IǬǛMi3k'3IJ"<n8>T[s_C->fXPwqN֩;e/<9Q]~^7 5CGú_m,v3Qp3;Åԉ?]Gœ ]À:YT4(@ʲd/y?'' G>{36wYo6mcQ-?_4|ƾ'jFRn×7wl؈@Q( 1) $Hڌ%1"! {+"C!ܢM_SO'cu H0m YHd"$D&RK f0H#4LRdİM)3LRddR !"!L""A4HI$X$I 4L&u!mJ_VV'إ,7Oi:Rn} 1U%2{[ֽRk?b4 sq_CWqda?S0B~}*1U_[3zvv;`,QZ/r?8}1bak)KEWUeDEb(XC0$HGX9;r3FO(jOamqο9$R#9LxHT&C?}\6CgTWl_v(,$1ܟE~MT|ӠTC4lRI_Ơ/uSJTij fi"if IlmCQaCƿHvyJ6AP[:*!Bȿ(9@ xio|'tQwuPfAmFDU|"?οU7:OQXڃ7֡_#^aat}rlپQ#jȑ($ 4hBLHA6)$JXQa%43," " FCAb! - K2Ii“(D)2I&1%F@@4Y1JJh h́(e$ L҃$EP!1aScL1D4,Q"0L#5"6`hBDU( ń0 M4aM(!FA hJYH2%"FIHDBF"M,JLe*Q iI,Q42HM Df)(" H DSX͠I$ldj,RE$eMI"j4cDbQʖH DȒ"BCD&DXTHD4Fhfjl"I1YJ)j B,1I 6RS"I(,6IJfMԱ(c 4 `,$B$fLLiE@"E,&iHHDBfIXJ&% #1)DJ41!i34i" `LJQ M&@@#DXQE (DIJA  eBd 0ĐQR )QA)!%2  &FYL*_7I[qC(0JZXhMH}1Rƒf`)_漊@ ($C_룋> @1@+=XKWT'"DX$2sHL@)/`g@iQ.O ЄUHOCΧ?LsA#ʏpbZZ~ 8 .cwy?d X,vdJe-Kif4 +3`d$cf(Җ M]ХBKe J)ǂ,|Gw!R|"c&:(s6RZ#Z4ܯi))):4Y`܊2 RYq} bF>;,c#4%fF,3fh0$b 0$LJ fFDHcRB! R 4dPd a(&3J!CFR1@#Hf&2n!n.>k^X8F1&aNp<xVUteZx v|Ć@\w*~1b4Cض_>,6?;8coSYd\8Z,vg@|'?]i_Be1'cHb#oiB_dđ9/؆qTXƌ@"JY)k ;L !;z*4@!$Eȩ($b$P5I R,(H#"JLL LfƈbH,&ИBYHVf{vZEh4VbmbتbO=zPвYD D*)Yji4Aɍov`ehF", "i paS(SLĚ)JViQiLj4%2IRlʍPQB3E(;C{ +߲WV!4%b4m<)/1ߡrf8Q>\OMePLء0c RXFBJ!fI)D&B2Ҕ`&3"ELH 2Y,@H4ʼn`Lۡ3W}5}^ dRJlwrN)+'~[WdܑS3m%N:hSzN6N= 9%2OURHvmOV/QQfI&:;s>7:fZYS7u{!~ ]@&DC׫w20aFhdJfƂFd$j(lDhR(2l͢șԘ RM4!3%Q2E 0hH((T%$P)PS0IFh!V@ӝl( d tmZ"VŋQ-j6Ɠ[%dfUal(l"ʹR1#JY ͘2 sFW:I X^>w)$$a0a-Ut UK 7n^;A鸚6)ջIkm;M 4MoJ2/ $@}ldq) #YNxxWs (F5&6zWx )bC]NpHAA`,RaYS9$1Gン܊.m^}ϫO])wt掻\opAۅp %-[i ό! \|D<)Ug$IlX!+} 4 eę2ExI1PX.E2$dwtҿ 4}}y4&PSGVd 'RA* -m".0l ;zlͺ+qT}7]uƅJYJ1buҩ~,{[7TRLg~5aٕ+R(]ZF |_ce>k+oT{F+V_ቪ(1Ȣ?3Q)D.C4CDh44d%hFbXf+Ow˻#(E(̳IČFF} Og\DH"^q qE_O1cX:>mj(qZ%";:^QDn,aM꘯v+N<ȌH^p$TީSOeGRL )f2731e~ ;;LWI2Sע-)1_Lg^,c&M#(iA <&Ƃ,V**EkQ䔚%%!( WM|DJ] =G\`/zɡSe4D_>!|$Xϗvs]&J#L T<AQ t_{s˚O䥷S( xof_eֶ^bD\8O`!U(b&2{O5B*(kRaU(X=*GGCو?&ݼc1U~m"C"kܘ0Sv[~twF,b1EEcg睆"mW#1R2ay2 3A=hVçOh3CYG |\ ا!~_qXdz%²HZ$掗O #Ce 9hg{:#;rEW`^O.414_R$z A '>?g\~x_ݼ绗ŗ)F2"g2_רH~uT"+|$' |zUԄw7gg%M 2~z:ssz3TEDvۿuV3PPmcV{Wq9l%SԜTaCԈ.-;&Qs+Ze,R )U*/6bjRZ,5zfU>%+\=D%QD`꧝2 ?ƓѿM7d )$"`7Q$I`4LS&2 v" a)bi4Kp 4Ih}{:kږj+6U! (ѭشUL@܂?CicdzM$hj!=LY/+ʋ?}ONkMWZ䩁dDKy /gm`|>RJ!J2 ̚d,5A`ab1TIg" ⸮3UqW?aw[f?`5 :pBuB߹?}yfAA2`$ˈ8 E:{/sE$QDX)tQM'i_ϧfYLDO6rM x&BbԎ?ԏx\v/Y $j 틬9^BF IjH 6 I$LFE0aI"ū BXYlđ`MI) H20)(d`4i6#3R )*L)DX2a)4B4&iV&fDYD(+!F$I$S36H,#`PaFabMf"L$%i1I&i2aAIDhbJ $1 5a2"b)i6D5 R4i 4%1$"$DH%&DLPh$)&@Ȉ@̄aM% BFLlɥQE& h$ "X#!6DED0HfL!C0 &P %6M,&٦bbQe"BJRcb&&FdiIA &dBD# JEEdIB*0ɤ`4 04A"@DH$J$ĤI) $c3QS#&6Q&0 ia%"iKƛIVA)a$P)bКIXb[%-4i6RLZɶ$Ė%,Ih؁2ъ3)&hDQh4cXAah*C%`L)1dRb**1Qd#h$LXA1Ʊ,DcDjưX,Q`6MEcb)#FH i&"Q))*01SiK6+FQPF$$$EI`"LX$ Z`H#B2@D&J$L0befh6"ƙɨ6Xi(,lġLF,j$bLCEBAō$4CZFL؀"&c &&b PQTDi(DbXa&dhQ2RHA(eHRSi0&$L4 X LYD(љc RFłMMhd2d&I(Ѧj(h!YlTbdH6!F+ 2)20*#cEFE-21Fl0T42$IFP)ad2F$4cR2‹)"%Ah"Ĥh4%&f$J2$)HS1$mQcTF4(,Fm 2j6)#4BMi 6#F!,) "2"Y "FFɔRj*(,Q 2M6QLL4`1d@Z6ThbRHALBI@LT$KIXM%Y`kBA"ECi2 T@l!24R "Il))DȒbfL#m!,L%4FI2`F#%%5ďd"(eQ(`Z5X(cF 0@Taj PhbJdV*X)2PFJe f#ɃD(Il&VLY54ci2 Ia6LII35MmlYF%!lLf2JL”JHI2E&Y2 (fkLII,AR3"ɘ XM"ҘH@IȔĈB I$$2eda%FdCdh3,Rb$X PBP2DPRd"1Ri% %K(c#R$L(Ma,HdH1Qaf a 0dJ F!%d$ HMd(э4TR#b2a"SHbA B6,D@L&LDQi0#,b(D$a0B3DHj _3*#&6HPH#Y,4DĊ,Q#ib4icS53Y2bi&I 6јQH5$MK22 BPR`5&BMIE&H)4JLD! dLj MLъ@ƆfJF)+4ccHe2A E&QBBcd*#a0($3Il$A$R[1Me1JHj"PѱF ʄ ؉ZL̰02E &`LEMF !E"C!DL0@ɅdFҦflMEb*QC&Q#E2H$2SH‚I Q#BSM XhHFS %0QXɅ6QLъX"1 S)#2hEbS&Y(ŃA,RXd "2,E$j5)2HZ $b H*"Bc0Q" fML3Q$  !Q BIY (b fP0RF`"%,h I !0̆ #"D D4J"EhЖ4 DhHdfh"1ĩDcQI&X2fE$)(̖0aIBKF$R)PQQPa3(т,0`FS#$!0jI5 "b&&&ILQDDJH "  DF%`Ic FL4m" hı1$(h)I(53d`4JDa1M$d$$$A$%"4HIJId-Ō@&HFM$d ))dM(B1#S(#b#1 da"4T 4dEFe(f) b!#Xd2& cL,ɡb$%1@D$)ƢF4QД%BXmF@h&)ŋ%%$XXd!#F(bLJP#)6bDB)HЄ1AH40HFFJRbLdH"T4ؘј"0!(K&),%2j1R)"&Ie4bIL+FĔA"(ɐ)*D*- A QD#DDd``d1эFH0Zfib")43E(؂(e#% I$ m0bI(`10 !)̘DJ@ iF($c1A $b66H(c&S0@&MIMŲ,Ec!20a&2M0D&H Bƀ22L$Ɖ,U"Q@F%3( 2QE 2h؉KF`HI& 2Y43@f%*K0ɄCa%$M ,Xa$IbبD2U$cQ4Lb0B0!J0S)4ILB "R2 #1!EHaDe̚Bf$ 4h%e&EEĐI#LddiF @XIEcccA&Hj)*ad4SP`iX*d2i6K($dSKXjER i(Ѳ4D"#FJ(DK`"$)6(QFbdZZB*&(P1"! K02K (fC4c1F2(Ѵb#FĘbDH#I130QbH$ɢd&4&$ $ 0"TQ6LDDe% %Xc̄1F,bJ)d$lI!em&$eda"E0Q2dK)H)Hƌ,3Dd)H%" 44HM!1$dLĽ4Ʌ4&(ʐM Hɰ4hYLb61b3 &Q2IM` A@B)"E ,#)B!&m#SBYBb2H "lВ4`ȃbd,FEIH&F AH5X)Ld FX2i1!ȥD4LɈE@(Y$ de1Pd$he K-DBTZe"-)*2KL@ PD̄؆LJLiRhJ$f*`E%-cD &RfJ,4QS&c2HM4c$@&l22$Y"S(J D6HM6Pc$E4$3(%a3D*1EJ&,PD@B(SIFP&LQB4J%I& dTٖ6J ̍F4Fc2E Ydm" āB@S%!1h$A!D H @ L4 d 0SI `ČY,RLP -2ƑFF(1 $&Dh(&LV# ZL FH)Y1X)0Qld)&LjM L M4(h! 4dhђHf$eF4 FJBRLXR!fddDld(Q` b012b%)"X0d*"LB,͊Q&S1IAЖ0E0 eF0 )4"5ff10e3 @`A"!4ZA"$a,fRYDM@RF600IQf(1 ҒS"*e( ",#$1lF -3"%J`LBBi"R`5Q(P!60TIB@4H̛R؈Ɉ3ZA2c C&đSI J!L12ѣD HhM2K$d̢4Rɑdc SI bXрщL"Lb$*,ɘB1 "XAdhfJɢRL4Y-"A",Zf4XLDġD`(C$1EDHhXT iQJPI4)!,cdjDl(0h bI$)AɰhL4HJ%DE0BBP`1&@fE PL!1Q` L4HJLBDR2FafEF)ؑbI AFHBB cjB14I$̬!4)K(#hIɰE`!c"B,ThJ і605f#& Ѥm%&,Hh &iQFVHPIM1Q,Ā!2c"H!T!0L@2R@R($X0C#)1J#fYa(BEIS1R2M ,DA0Hʑ1bB1DbF $RFM5 DbB3LRR$c(&Ɍ,BB1)%M"dLb6FE 226FDA(`Qe Bl4)щA06VbF *JC#(0PYCH"(XFi" H`H"1Q0bL,lj#A4A%655dƂcE( (Ƌ$ &l@`bc ШHƙ$e34)dC"XH$Y*6HdK,@ɔh-4RcADi5 L 2FPF0F(*JSP[%&2hlID61b*Hhf"!Eȅ34)"hIMD(iaf1(Y DlRl(`1f,!%&1H( j4l0B&MB2!LΉh &e!"L$ (l@dЌ &L)4j"HL*D  dhQfbSD(l1I"L$l*"BQ!(Ibш4B"H)61c`"$єYd$4Dʢ $P`D%(ٙFfa3-% #HBIa$$)LlM* hIň31"RLФ&DEIM%$#-@dC3&K)dc HZ,E-$2F3"CdB,FKDBEQ4Ԓ!cX$"*4H&QK@Lb% c3I&LL$6,+#i"ddJJ(jhHDQfF 14bQ B`" e&$LdHTH` d`"6B3%&B$jHHhbaD $1PH4f$(RH%FɣDJPIAE#HM %$$h̴QF QL` BB4i6!#(J%!#)ٓ2,) 10 1Lf5dCF0&Ldf11%&L36QQ&!F$3JZ)6 E$-h-(%1hQ-QQX))LFb2ƴFhA!C4ilb,Hf  ٔEL(ƒU#"iL1R#Phb(bVAIFfQ́6,#$4BZW^I~kf",K8 m0)l$"JXn_&4:Ӓ> =b~W:rSI ,a?N9ur;_D8򼼐!ݻi1$3B238ADg5ĠD+j*&|%jl*iiH$G 2"V`)x nn^;'{+T5QTrraBɊE*CCo`1ɤd{61`ɅA[f[U$UaܢY)oAsMΰOz/9 Gp!#2ḗdb wI!  ~_ٝo!!2QpMsai=^{r4LA }2`ß朤2߶^x=|]=cLW_sd'y Z0bL&u2n\ln%+#B 鴩=ǔ9e̬ڣ3E Sz=YS?ksP.&ǪiCH͘i6fo3w."=Z$]qZo~ 1#F Xk$':[4L<$f. R&P'KU]Q-UEQG-}RE6,SNw~u7dsj0f(#$mN2P:mSKUjS8aFbJU:f7k{}n1y{yF#.} ~1TgU`bߓ^SL㒌` 4Fi60}uyW8-gINpJi,D4!o@4c]Pߗ9RIvU˯w*MTK ?qm<4;Aet݋~]h;q묻h6@G~ H4 :yA~"fFw?H}?=f MA[NVq|0C-7:XQ;6*;bs ~uWƓ]ԳƣE&e$ك(͓* gKE(,C/+D>QĈ\㺺Q7NAsNΎ* XX`p::QǝLʎ5[T·z1kijX?%D}ZX*xw8fJq!9W`j~"\(8ۖJQl ܚD+OL%"z|YXp&T;pQzaOon_USE)6S.H1&ZWFƂ,yk\sq,;G!և~b1R֯v u7 B $$%#H#($b(:03) 33GnYlP(+úc1,#S7S8lBhin,ёWv~FvIE-u]yv3;kIgՖ?\yy {RE:ΤS90o~aOعH"{$ZK~! &NI??z~/=PLɝHkr9qJ3c,~w`Ҏcߧސ?o_sG}^oߚw28[էZ?|ߺ[?.͗2VgC(LKـ6f#ӸpTkY&(R7>HWgfLs;͍ i ^?"T6_~Mg._LGtJޑ[GO4vɟ?ճmV c,8M?7CC$pApH(:$jQ'9r =X^>EQWoZ1_* }D_}WlBսͯ)VJ6=]tz6 ZITUdځdL H^p5z!9>oFN6eˢn7 \Ⱏ\I$!s;{$4!b D"Q`d1;yiJ Aq.LX &>ιJ ,U.up4)$)%SMfVƈI PQBͪ %TBM(f԰Ɇi@Xz\e(n]Hw&O{resblɚMSE_k{;)(;pysSN.qA )(ZeFЍ1Mn]ݕ!L^wm&ч]jcC?K ªz %EDʇDvG=r2~[yt|c¡+ȰyOdQɿ~mr/^G>7}Gj_IS?˫5_ũry{1Dž|S;7gWPDcRAO>ngݳqRPMA"(nMFyZmWmBQHȴV!m%iY7:O͎Kj:Ƹ{-ԝ;S'UGHdG2U5e(Wr14W'@aN`o=#غigt}󂀊Ej( a<_Z"x{X7˂75%>r}EuFR၊Fuy\:SA'g4+MˉjM^m*iz;L9`d^?b* tB RKPab1g$EjDt21 nZn\>ѐ<ƭ)9F:/ZHD[|ƈy򓙴}Ա_bъ3È4rK{ΒÂ=}3==Pg>Q<."17`y-lgCmT@c&*'#aC9&:'/M}m屐KBd7'&yIxӡ%]/1NiYKc \XT"'PH i*+v|3)eyrM2W7'5%YfnӋsFkYՄ{c6#F#dJP}m9s`p6 ~g-wdz`4C,OcUaP l%4cnAHbu 1p.Fʙ7ɕP=»lHaX܊$JWji}g71^Ȗ^˦|Ø+9}} u&rWepY|>*wCwI!C{+^7QPp{y-el;{_)F{oAkM?$o'|T>:f'4;kQ_6"%:> C[VYr!|YN˦ܹ!6 ur60?)+3#% 7/"[A rɟrYEYW%EQo|Y YMGr"|l-e*64>mK7\H=w;dRx]<#|6}݊ r4!p}G&K-BBKPEt-V%ƬWu`))YiִD@*ߪ~5j{}*"|L:_"x~WR!-U7=P-pl,%{a-M<]RS{O9~' k2vSHTc./ l= qv]}_SXly~;lRp08 wZ7ƭ1%,!By"gua^ Ķ\E$+9hA;gǞOLzI|y^x8+F}~IA1rٚx | ++FUmRnW/t9߬m{a#!–pG7{4,4Ɇ9ΗMΆKnھBZ[=e5Vj 4ݷ#){P3VnNXyh#F9poLvk) qo'qչEKhrа˲J]ghA&-/&~~V .skۖE>?䅂B@-ZW% SS% u ϯjPw1hoc+`$?>[q(EP천8-+1wfu FA`HN,a+.uHIjҲihQ:XcBxQfpQI}+Sbldz.X ]ʨYk`c+^s*_)FOml2d.*fݮMk'R1$%>#^m@=h#"#ڟgld@Vҹ0%Ծl)ıVK\ 8g}u Õ->*qaWC{MB(6_%K FF M W)j)b{rە]ZVG[6\Qg!n4+݃9 C fDpvDb q௹H{},p:V/'E,Q'B(L{V6*7?Vyx>􀜛O3su6g"x3>ωK/2tٸ%7/ qT B0E9N_3"q27iΤx0vg?Ih2)GqS=k?@;K7M?ͷn#Z?fPz,pߺ2" WszI|8_nW-|Qg1%%LTJu´>u/HOG! ۄy<]LF "eBz~I䘸.e@21 &к!$@{}_R1@ qw/G5I߃j3秥ljcL2s yph̔IiI?KyűvAnl#͜r<Y@EJy/|_d_qe^vg*6YںS({u辺)+ [1bHT0㋃0D UbqC7`[ Ho)H}hĴzWk,,-/36]4>uҗw Ujrk?PԶ!dePvŷ=82Z0/E|^ϻ n)f5a+Ii_5C| J/VqCͺ/)lƘ]~dfxUx)c[yF^!ڨ!*OkxG h9_$,,Ph/b2p֒eK--z@LJնxP=IyzꍠcYSPMcT`SC퐮1ypM1knb!ɪoq~U^xxAѯ"vcSY9 TrZȺHCD[3wzޡVdH}{:5@ wג..,)كv@Ab 9VnhǛ4EJOrA&mi~3E?cPZt74 &:/ ir=܄R`uZ+OVvLLqHUyQ3_`ێ(ʆUo S(ģ[䫜B φas VkZcRe@(]rg7>,z/9XT.Uqa(yô!tx=ahѾZM(#-/#U6N2 %T5E$2\6ݽf?w+W@U\$q޴ =@3v_ƹ3CD}Ag÷4-ǰ0 //^in&t1Lz9v8:!$r?*0A QtrI6hTL\b+ +V&J*4V`}^L֜Ρ4!R=D _-7&?}8pSɲ9*DFO(G@Ń 6Nl请zuJxktc:IՊ{](|Q[ Q(,[yƊω<ӂ⩢< <Z!0rʳ:;} &>^Yw<<ʆN>ЕQMT5W$y:nZ&7?5cCQuO+K(NҪCNPuZF/wmzK\;Evz#G]8*8k >-uQ:4~yb4N;-Dey#X' |)ϔzc$M&秡t 䇏oc(=o}*FؾVm.6h\Kϕ@ R'W[;0K6f"d*9͔QİiDDY40gŊ){ؓNie5R bpNݫ>)$>TY_Ezب%rOP~e 4H#`iG%m/'BUUw3|w=~%sBv8O,DcW\Jaz&5 V|Jꁊntc, $_1Z#K k>t%;d~ϚG!ږJ;hCr}|M4^18(j5C[tAvn,0,O+(;n2yD& ӽSZJ">$~}ru;Q:JY4;r̪5y*o[sw qyHf%8YWh*APnͽ 3namp572^l( T"4_C=Ut)0On9pyw2k[ܴJZg(:F?dB;nA]RmM%P@gZ$GtSvi>@*gaqF䃼ͤaChT \,#k2,ьL'ciȟ @1CdD~ߨHTI/]'%DP.LdMf哆;K۽ kM78ͥet?1q >E^һ[#/X= " * ?+޵2໮6;Uǟ@V-ݾ[vHkz)zl.. sU=;*ft`tATƤ[YI4[g{zKYFg)y852Uin sc,Tagܩ4VkVeE#ᇃD4'a2 o (ᑋ);vQ7=i=L)NlPeSwo=)]uMUkv[:=g fũ뉗e|1l4dbE~TŇe1dE`V.ccZ^'l5hū]Jy)]% D^iԟt5_ڏnr4z'ƥ.hT ,r$^EqF#lMec 8`78'K_9&00W> KuP߶z?Ԯ"q <ȁ M U?XdDFFd)qn?&QYmhבOJ*ԴPľ&#` R]̺ǸX]Zyfi!LJ׾ΘU%Gre tu ֤C᮹}RlL]RkcH+ٹڗVG1 @] dԣNC#̖u #D.cP-ZX>N0U ".> ޥ*%4] *o ƠDu/Fl}K)M̔a8ɦ]N"4Fp)x-D[2T #]Ot?BQ`?RjM$^]=*Tx^EwH 4#mMT! FCN?Dr?P%$s2'10-YC~uFRxʕ{<@T@apŒ)ϓLymsr'ʘ2fh?I/@Ͷk*`J;aK11v+ G01@f [ۏia蹆|cʢ:\UhhI#̝w,)j;Jx/LORF6/< '52)^C`TMvW,uCuf *3cYbCwmt?ޥ;u[ZɘӾnz$5 J_C4;C. !ƇPa,{cE),ˌAf#Hȷz6@gx V׆FEPCHo W*r=oSYJxk(;46qcS1y8=e-,ղN,̷wkd333'DuG݄zi;l^=wdg;(U0v{HMU:b;Q8aeKZ&RO}r'QL/JՇYb=ey!}W y4=lEDxkPQ%+B PӚpc.ͱܣZ='<`@K;@<k݁wKOaevLwH!BiԷPc?HiGy rs8Ke(J!ۤB'GXlªg=,C;./'LO_:{ VN1<&N" lֹ&ID=xi( T[ ssr9cH3xe2dvX,wAOI!Nj@͒b8^TE8T$=pw0{}Sm`588bK (?yW/+dҳ FhJw7y†Z(M҆oRwY'n$Q00?[ZDsWw9 ;un9}ٱi]g2?s1)CM jiz/*d+;=Y\"2-j))H1<Բ]`6 07QlSb ~Vqc>ax- l|Ojtsu[!.(APlPJ"A̜Imr+ bw:Mb'&g`e_CO ^ߵ֑_BMJHUW C` {-8:y Ti9 7r!AAǷz 0LAQ]ƣ ,<4@,;9z #'Wi`_̭VĐ!A^V:m10!(EKΆ*r:;&n{0N9|jOPHm"6oLĎ^iJ%:: Y<knL-6 D*NU%6DRSS(\﬇J\i=DB{%?Pw [[ªKMw<+9aa%gj?&B@o ^ǯz|tdz1mX.Wش-Zh=k+AXg,##zꉽMsXAX- 5g4;Z#f H{:CTۜp_îUaq 󕥤m|Iwz1q{si%|O|b1SOO*=Љa=3rLIwg+ d?{7=~Rӊ @xw-y8H(3tYGN3@? =$F\g+W/RcU庼ÀSZ^2 Qݒ520enɒ*'ˋ#Uz[⯬fͤ 0> !e:B-Hi r❺<t wzԽKUÛd9NfbKeh̵Y G> TG-MF;paFOz0lsh%+zX=ҺY9Dzqp:fkmV=jq&EL+T2@i)|W'@it).Z}U|(Ro͇BdC2y1t'~E3Y 'k$Et^_&iԼ:|˜LOJʫc^=OS\A\!I(aQ.#WE?/|!B6{q8(V  J8m0l6~*cDSIɒ  m=|.c0/'c<0on/ 132pfl6G1CNG140 t\;`B*3/g.tUUrj% Z 9l/`ȏ)S.:9i#'S)(:xlOU1X㪔QU{)am@c]JooyC_lqM*e+#H¯KErCoՃ7=ٹ^22qI%X,|'?~W#N\V wи t B" 1PGnf4)k`ƅ|BY> "S++#Z7xlZ_ۯI< YQZ\~X$<1X>nJӁy;u W^!"ӛ]ekMjKg[3y}~E4!ZͽMi3B_-=AKDQ7@_ Dd6c'a(sKltgY$X9?Oa)Cc"QBR5%jD1@py*ʉ{#! 3Яv?dOQK'7VcWSg|hOΏo(y&@bYC^Tk>0 e EΕc"y*參{] U8{:%F sI'Gǭbv>k2b6rN2D}b!ua# |?W&`-ɖx.M2"p<9Jv@,OX.q!!L~,`% ;U7#>־m.obn00D-ڠ矙p_jwC8FU;R[ۅbir@Db.b?ET[)ԣڶ J4GZ*%YF9S3`@-t.{Q:`UgL4%W$@D,[S0o/ixPMuJƻɗ9|z)O9$s$QJw. PTV:SRm4[dBk0}~8Qa!N5 q[1Ï_t70WjR9tG-_i(qd#C,/ bTSH?^ * Y@"W`!VTxQQj?_Dnqi謿VDVA@)'r Sbu̬ jO®Y'7Uo1 X(#EhtxЭk< %Pp1P X6v"=ǚ?36v" $gSHi'j =P[3r;P]:JV fĝQzɸ#zڲ) 2(g7zN8aH?9iŮ ?َ5"dǑ6c0$Nw\b1g*Z蓭BNդ;yk1"6E{{|{_2k)<7y+cY?Y2T>e6 >U 51y$y U/ꌇg{AS\ĈEEϷ9]]!!tD"rh.tIL{Dn\@}9 bf%wTadG/[YEy|$%..O-sM4HMݫn)wߟv;i Q8b{h42nR$NR|^ЭeD̎@#7WYʫ+t] xjS| ݨ1Ղ;;aD e;L߱2"i窭3)pDTas~'xdL]%kβ<҅[+WYfuj)5.$߇|ַ)^ýs2Ѧ`o (P+OTJSϥG]iwP7Ior2zOӢXί ? &Wʎ@xľxwÖ劗}MAyit5`ڙMG#NW) = ?oe||1.]?Ӽ3 TK<f6mwk=/v}ǵm(81/LEyiE)ynĐsӁH[ N~؅=E0 /quOFWXv3%FA T(+[u O,jUhڙsz->: slvU)z'et Qm o\524X_ <'0z0'].ܺV݉^@'\ńiBO8."Bw hCT败j`(:ˣ*׼ߏi[Q8q3TC5v઴4V9˱L"gA:J+CR?8$Ɯ/^^)Gf _Y[MՉ "~&  2ari>P4eVRtb熁7g(G_> =OXLV g;zpx&שXpݗ4խLԻ.A .wd 0( &;LV\8>Pk#[2|,} UoI Ej-s4ڝ툛5lª)|34b>zRBecT)i YkhS"CN̲BI  ۑ{x{zYͰ _iZtiBjP#L:m0$nK&UVRyo7߃3Xw^g0݅W;\֎t{ u.\z0=waH(Bm?^y FK2/C8?'lZVbj*R8CPZG(Y??Xi4N]C6dm nxe5lܨU 3**4P LW|ao.͉_t5}b"/:j:ֆ^)x(<(|Mw̧TT0߳R Y˯i>l G1"U`%`1wi?狷 ^b=\.!M]_zX\CG!y8۝,b~n(a[%FdP|| eϔ ~ol6$/.O\xek'icĞ͂{n^Qlb[Hc'hwf-O2;Z.)n7k.YT!CA9d~(~,漐7,=%\"z$[+'gSt(p<iЅH@!ߋբhBVU!fFX >kK9it\ȈkÙ8I3hL{ {h^7)м+eq`¿F$5Da'#_'s6VΫ_?1 mI4:dlRtY\SQJ*<a| Jac4~wIUňH_K;KWeclj*kzg-{  ˓[80&/?kan(T`1=C|LZ!T[dɆgu# XGPųP,OEgsq/P:ع-O鲚Po[0BI&%;P'LgU =ſ3c3lV+ X]j|\8Eĝ3eu3gQ""#3wcb"$tk Ԁbt|zHò>Rr'J*Agۥ;Æ<4qNb>&0;515o~ՋrҭMk>| [lFd35P 2:]nyYLxduV7;0X]9"8);/)2aTH23S9 [ nSfR+v=bXu13$$}8LLJ=?s򹄮{[a5~kQ(݄(B VFy*q )gozUń;뇴ѩy޿U <Ȧ؎ zY./ּVȱ[a=ZSK\{&xpV.̱0o:giU݆]9\wQg ̱y5Ѽ $7I[n8./yq֖Sl6łj!=}lm]t/PH1ED@u:*Lr2M/ͫ ZG M)}{ Wbc0IcD&d ;gp{2t6S}'9IZ5AWK'}4{K[@4mLMZ^jjO~4PGČ/{Ksi*쎢{=Aņ$h/yq%cߠ[U.%Fm"%_÷H)c]x82LpxyaXt ))i 6B؞w*Wm2q,#εj0ҺAlsˎ~?|dY0<P^>>R*X7N â*5Q`5AµIE8s׻lM.ei*iQP9Jdub≣+YfLx@g!dv:w>~BjbC;/X;^ 8he5t|Dr=zcuT0h4sdqEwO{lrȩƀJ?YWȃh|N톧262Q3U"iP(qJX%e)vl0ĢUdc$[/ZO6]69'S;]nz\=)űbV"n̅U$EbU25P1:#P/7UR؜0%R@ BjbB Q)-5[ ()J_G$y:~k$,>yVxbq8X;6f,b@*jZe7t z~{rǫ}%pS/ 9.M1"dɯk ;q&yv 2yY]>W= X{s'Oc{Rָp>}+2&iu0S!Jt]GWɸ?>Okyr}@*&.bLⴵ3St5G5Y҆ Ofk?} |Q=ad2NqPVp%ϳ:zc[XƗjd"IPR)u_#}v bdE'Ã.$ـJT ɝsYef0=wz?j׽,dP(MYX,fakLiqJqNw] E؋w:ERB!?;]4T9c۷^tU6gc]{: n$aky|*i_sٚҔi_Z6@ϤLa)kN/X3b%1#W#AQ74\ n wvh vԋ3"z62W?7JἯz$U ɣmZEvTw0Nl2m32ʡ6MD \T>>qͦ_\D5$Gh\Fe>hS< qEaqMr_j.`a#a2; 4-G3R=Q`/)5Nh5 ,n!@ZCrͅ{I2"rW=]AIZR ׋ |1Wߢ"_0(1Kgt cr_A{>KZ!O>9&êFW茈(P#Sq6~*iuFh>D6?e@,CF#C㑿t%)@ +XY槜47qU {'s!new JKj'bp' MBnn $cNMt/SG6"a/ *=7 )Uߥ⹇'v\ȒD' 1alt,\"{xŴPBǰVXVMvJA2#*AďKܭgLa](EmV ,  X Z(J&=`}0>+M'jlWbD=JND%uWFo"IԠJUhFŢ8'Y1u8`!CK-ۃ3eqh,w-gܟc1Cqj.(P;Av׎++Y4b8UXQ ՚EV55r/mi, |2[n~ɠ[UI߷/'d*"thH@ρhxJ@[2[nwMN̦fJ֠TU;, 1ЏS!$z=Ǔ&6ViuK kF1T>߈ݮm#vi>ċ)CWMS}:`sceWV۴Ώ?]OݔԅsnBd`h~HK b" D`.!ؽcB)cP9Q:'&4p3R| ]d/P|GMJyqG \ţqg#R0wpZ& 8 fVnVf ./DL!N;w,M5aB"]pz SV'2:8YԘ& 4z'Zk;ƃKڲWCӼ赴Z /(G0 QOOTaQwʮ" Qs#r2;r2^e>LG_Ohn7qr2lU2s3vS\ddeW$SENj@,G{TpMp5m񚳷^uS^A?TKw$9'L@(b,#m,Pj-VϘUIlajt^VV ߋEr֠dٳOIV5 k/C2΍eTT6@`An'6P{J#e ۢ|عR:<%晧VcB9(YSUdZ*\U\ +c@8B1+=Zsntm-eWժgl#=~Xõ KyH gu @]l>OP7,U||̗q] ~řL̚;gq Ǻ)rCt2D SNJJ€_&A_3d HGӟ7fji0п܄O>z"omR 6԰y/ :_mvq^I"*d;3YiOeǔʳ $Ө)l]cxtwĚ.7бcs"71c*W+hq.wC@ HtsB~-5bio͟DnM|EJ7:E[ڨi -ﮈ0y#NTWkq4rT4`LDCKRH8lg+!*tSM֯s[AHxMw b}ktUsH~3\DA^\)TO7Ä ED v4*LAR(.aOG>px{NM6*_\zˣ+Qx7 gg704 _9Yt#F#sz O!'WfY2H T;0PnP4k[Y˶Q9ϳ39^M}qډ4 iS6՝H~X֞==-ɋ͚ίC{SWeԼԌ<(|sW%Pʙ35Nz{)Y$tmqn/~F=ݙr!ߴ{uπIl6(ߎw8C($beWi1bIR{(@'00W'+,6Dl^ ޶P'G09e ch9TO~b^K7c"DCg4e:{F0>Y鞤9xD\Jf#=c&̇V1q3>Q>mtlugjH1/g!܌E-/ t:$\`JQ^&` zkUcrOu~m I՛X-a" 3bCg%YE25.^NqQ!1;5ĽrAדI\DŽgB rvmO'ϔE%6dz׸xR?LDaTK E=Wj>&v6ה8pG8]ᴞ ,y홊> z%׵ٷ-- 8ldX>lk'&E\5L?>0Aϖ/f+5,'UmG: {zmÒRH̜JЃPO4n>|Dž}}!J[{@~,L-^ 8{q'n{_V&4KtĨLAx>PK^%Jh7 :P|~Ta7ۖ3W)94-yM5L/~Pp9 3{1{T6OkՏj[3ݔ΀㶺Na9B⿰^0rpn} _iRe8]`nvd$s\۽'}Wh=7r2 ")sƸC>|9qkM3oϐC\{0OFjPFLHu ['Ԁ,&qvÞ䧲)}D@3Xru\i`)QĤ-V7l1{C٨W#[d֭|\Sf(AWHb]zت  +f_C{|bs6mL~|Z&i Rx Oܓ !!;0PGNl"",j7QN<ΛzixK/ t~ra.mG@5[LöSgKOqBqOzv-f[}\f2s`C2vXFmR;\/4/بɉh$G8:08]1քr̼ HwjoNCG/Lu#Z \ !ljIَ{v7!Β[4 \n3_3J&ǖPNw<#, r-d&Osd ssko`wvvq$8+ q8:blH:$#Dž z8) umR0L0\lm}YϤr@]O8[ uQ=>w:> v(HNȆ9w3Z2F{[zV.hnɘS0Aϥ=gh)dq 4%]*긻k,f㮗5CaIN`%qf„0UVj-t7qP}QN)ԓ;lEgXa}gN:-s1n=VD|x~V drMHsokFuʟZLj<y%}Tq#We4o@iǀe)CKaKcBd Icdh^3!%(r47LT2\\a:JxȫY 8\ 4 GDwFbCjC2W0=<;smU9:[[.dy;>W`#*TJa~@w:l@~ eNe ,=J9GbXlA1byp_p 7N91`Ӵ8 DV:]zvҁ?d~/\b]kV1ng|k/s ~`̐z˝*zʪS@U/=5Q6\)s@rHZtŜaU8VH]3PfF-61DDbrl4$8*7gr#FC{*!ͽ 3 OSj95GKYwE$2 $gݗ huD'C"3|c?vN@6D@ +iSeJ4́7BK)ø Q4F;2 $fQP\6EZ= sG< jWtedq;Aڶ;se,X٤2ĮfS%ڢZ}S  m;`HBks(͆OH_MHfT5@8Y=\oGE#TZ+=}VTIj0 1F`Q¾$AޕRiG8;%Z=Nе܏Bfje|ܖjU0:JN4Bz @A~;C>0o7Y@HqE8C(V|e[xxq 0?"-r֊k.J5ϝ#/ ; t] ažR׭W"V P-Vhh]EtP+J[l3V#ںѾ!LsB?nW ZܥnE0֠,\=5ݭ"Φ3+\ ]9eGu[bfV{L%q" gc5mǓ=_J wo?N2M c^]=wpgDG W>^v:3X3X\hJ9.F3| ٜ@X=ti1jJ>@5E ʄ%q#6jG. '|&Y)0NM,dO] mb2 F/̖R 72`z1)4VT߀2Nis# hi(3@ MdJK򨽇=dRzWi 3wq=xB)H3rl[йk  Z@:(Ɍ3S=^kmi1ڊŨQo;V:P'ٺ\Jq샬4ٻ/KMkJ$3#R-d hBPmͷYʡBnWؕ>^hdp$]5X/ 3&S Gpj*<14Mi]BxIm:𠅲Μ@13^ʊ,PT/Tr)83mHIaeeKk z"yj1gl'eϛS,#dOs,oB'A‡!\+9 G|0x܉0TúJ%/,0 Y +,6MM:'o'w烔jLW0-a&&+ZYc-+z a1]BOA&_›HSE!dC. ysf6OSPf;b._ XiCm"c:zX٭^I5CԄD{=}%[3BF%g枲\+ 4{&VX\%5UęIRYt\ e1AjluWI˯j\ʘ H%MGOTUZ†dĞHy#u9f![+ɽHQpH"(pԘ1s?:&! t'Lm8D幔c]gap}o^eg/V_Qmdo=EDtBduZiusf찞M;NwTQf=7$Fu"h,qKtHe,i9u{VfWO9ؕ@Kob]`"_(XY6-/wY?`Ɖa `{yշ־lg5K-=EJ!bN&D3s2e(z/.{"YkvJ#m㖖)Y zoUTe2Fc-xK;[nmPelk%]I tMk+WQRYSj9̝FMt̖Dr{vLCQz bֺwKDg@;EOhs#KheXohq^'?}_=Jl5—^`P\~ Gπ>yNL%棼Dv 5<hTz٦To$rI*ɐJZF_.o`̝R,&-VUfb|di-z|FF9$+(lHl4 nyW?%X3s K#4faY˜%(?.>5JS bW [OI`vl(GK֯| G]hTl£$ʼn]LJw= & r 9c\>$9%]Ȏ1毀$*A%1bx.P)pdC2Uc`?w %vKw? -nK^ Cj[a7E(fR8~/s9 pFUZQ^Ӣ2l)=3_$\m_Aus6J4MF!J S.rǧkZ$#_b Sx=a•;W'_cwM4=<IXK}qm 菱"U']^Bq!=<Ѵ$恵E9\g?=?u&Á1S-;(_,qB5Lϳڂ=7:ør ~kg+Q:tLe;Ձ\B,O^s/f&bKP/>N+kFywF!J vi$95EE~Z| rvhb`&G}`Q0uC 4ˆk"~La!c4)C`vVH~bI{dU@選fUIDUI704ίU vC{K tV6 wDcSɣ WK.^ݠni4YX36gWAwV$l{-L%t07zH۝\KC=֙,dMq| I3;Oh%7)n4'hmu)a pl-x#Eֱ@1])%Mؐs\LL]edWXf,kSD-n}$kcs&><߹}<"uu-vYLsWEW- xLOҠի/\f*>K<Gy}H(>RX6|ehj=?p;Zq8}g2|6 Ae B4NO/ TSOdOxFy 8kqPoB= Nrd yHKRсK3D0hT>jٕh)?|KQtt8%:H!ղո4aPJjlEyl'5t)"XG0>Kcp$ M֌+ L^<:[R Qh.y~q:ֱ'" U/;bwP':1 U#e's\.W*lg0F4-Y$fqHJܫx~6\E5f ':AQ]W-êleK,QD[{ 70XH(('b4pEljRBWxFx0!D>xlnn hb5j-zrKÙX"ubES05,߶~`B|a#Q`<^qwuo%IHv:wAG|GJx`/HaaCpv#.{wVl?2jg-hm٠FP͵9&#OϪa}(_7jh(LVR`a>[]G<xXvOɰdOTۘJelu70[EN2>(\›,N#w8wnKMY%D+L/<`j6JtVRl@)1xmAX;# }oT$-S#"Q[)}<0v_@zn}ӆnH|^ +t& xWx”{E II "ϩo/'뇳+wzL>mui2*(a4 MHj BA`3B-B$kE>*f[YZ\r-kqUx gj| v.s>烏~QlFtPqeN/ }Q觑MU&v C4fюP=]yI3<5B[D 1~>/ Jɣ"T` W"p~OFv0J[if);s-UذHH!pR)5ϲL98>OEWT7' s,F{8"Ed yI1 ȿ$t?B\^e:mtphdw(.ٟ=(Aы?3blQ=t_ِ+w9v.pu*t| uw{_%TI# QʒCYvILLrP'\xv>Q 8:ISMk#vB͡6YSh:ͲnJz"LTTk$"PXkaʉd=|Șs2cS-i )T5,Bl馀w .9ZIՠH_pőn?]WdE *Ǒyevm2a%%p={=-El/DbvR:嶥m)ml?ͳ$!j\}]3J3G7 ^9?,ՠTΠ@}=4Ѵu:*T#\gey\!$[ƇG N1la}[ڕa.`4I?k5 ;ms M;X7hs,@Sg 鹙->TT]J$E9$O9.59f6<$#Z?9҄@pN[W}3f++yӭ\|yT`jO rʞk :|//QxZ*E=05Z6ksck% "8! ]3zUҚ@N誕TEC|Vw!:/4/o;>m]N%݀lZI=^"\od.F#;Vhٰ7u06$hX>1x,Mnl顊SeNf\4rmV7ڤZ}?lq*{hyī0z1wş]xmYN:dz?`0B2֙WfqntzbHnMdc X^t( 9YٽtՋˍ-,R[ng*(QV%EĽH eR@țb)o 0H5G_i؎*jZ6TN.j`$'# %A3x? 28{ZAol랝.' k0O@2WFo YqD-3`3L+;)KӐxkR*dE?0Tz &}`^ZN-,oZ{pҷ '•I,L΋m@#=[{RWb5lx2ubքkPDkG^H¨Fj- jՉA-!b-A/yZ=`ȍ)+SN1S l:Ĺ9IN|_mYlDBWVB \Bv޹)|ܕOA{V|=^kTWZL,_Bua8$yV2H7 'aA2&'<9'`{ ׵JC7} v4MV˼%0h{ Oyci&EFjB6IX5Dz5yM52΃~h건F!u(pgɔHwz}Ы\(ւ{[RZg]ȓ-؜|^gz9n -17E7p>u}"̷[Zol> eQ_ %){si_Jk5o!"3r<T82d*6HQ^S^T Y$c{Nxv YfJ_x_\x@Lq+Uyz(2 65ʉ2bb]թ`CNBTx ,~W`Z7 Ö4Jf,w'f0A}-vw_  |O)Eu)R.nC:  O8*`l{X? aSiZFåZT5[!]J\myOSwdOůӋ^TO"/P<|¨+"U1g. Ki.0U|WmkL5XE`e^okf E9&G"/kyܔR,k'_GWbKyь50sS̻4o$\+1>Q=3Y`Rv.X8sv(;yo32Ha ( CMLo/Tp̀4ܔp K"ܚ ZCSP΍a~݅K]F t0re#]Xy& !1¤Yz9u?i>Ԉ)HH Q׿pѦ4s8::O CVFG84(=׮Gi8I57_4&1J6Vp.y:e k9nmW:R"4,dA#֢ gGy^xCYm|f{=要v3V:s$F`~"Síظ5|ΰe@Z93:t[9KhN0rϓuؙ7SwTÖ̢rµSV@r(1},CedP4n63']ڡj nةJfLM(N=$Q,!8ywldĦ9 iQV0yOfXimL%E'Zˬ?H{sy#_WG(|khf 5i_\Շbgtb(2%ۥb<iTcQ$%𬻗{Cg=_`niİF`t_Cp[UZ>5RXO6߲Eigeb' 25VN8"U%Ge"a8 P8$&㏠ $:ak- [xLݮ\! h2urJs7Vd+-gvoӎ"*'MxNd _ D-D{|(y|s"J:$3V \kTsa3T(ý>;߸D(-صxcDpq:-Frh\絛t=@"sd˷נTa݁c׻ ={V[?9#H& '淅-6ʅGmZ?K$=wa-Ը O/U2=j%SkpE%rEyanE+Fx ݻǺQgSOItY&׭܃a@['oOOx(t惌Z$B_I]К uUkL$~h+P,ҖJ+:r%Ǝgݤy9=u!m W%-D;[umU]j)M]jɅPXS7 HlB2[洤M*0Iӛ܇g.Ŝ`ÆְQO6M_A R!ip2'VPRX8iϘN[} z#?#bhiED8)v25V&di;Ujl,5t/C_P^e60 /Swru{hE`n=v>)l==⫾BJ/-q^_dԙbUvI&m.ҺϜF??iXf~gLM#C'hu<Xsjd07-< ˅@ܜ`4T/r?PtpHTar7A& YrPdV[)Z-!oe)r.ws2U>jzȑ*Y9ŕ+eeOd-3!aj4k`2’L Z@6;˵Px\AO播jEmq LhP%5eD31[3;uzzՅK2m]k+bB r6S@wF3&Pq-WU%QEOPfS%7Q`q@&D L Uja?.>2AZ6`]kY~Vr?xǎ6=moṌcǫ0@9j~RIӽ5&ΔJ~:\VY%MNZ&f‚8{qM2NhXIx{Ѣ4CR3;n(Hbh^Iݔ1' KFfhme\Std 7r}1׵4!H">BSSwr>H1},K[K Zk~ o#Y.|\ B'4s( @"OO|XhRtdlL^ # 1#pL_%* ìcfGc @D~_ÕZmRq%V5_[-=Dz:w4uvc7 BjBAV6j鹤̅^U1ZQ7Fŷ{^8ޒ,e%?^fݩ IRK0n&prDMz%;AK%?l"pWG,EW?%ytrn T 9gO8.8pMɈLGe MDB= "+[0Zx:zA_ֽ~|?;}-2LO>6!S&KiIo*Fa,{kʺ^2zDg+i. oh+0p.t+noدhI\ D9aޞK6F҉'a9wg^ LYddCffɖ2wZ0C͈$/=YED+gL7.bfGxR?Vb~WxY~{2 VބhOPstN砆{mhVsOz ٪F;ջ0 c H0tt?#"KqhDS(TtM\ZN6+F9ދmhuKl4RcR-u,ɽD66PĒٟBB0t<&~:廍h3f؟95RNjiȪyOl%:]:16:8F;df=cn8gڄWvj85jy:kOj5e]c8$ő( B;≲"*x4?njs.$X\/@CvW؇8q;}Y)h.-#UI]E``2gfC ;^eDf {| !~&Ruy_|e^'(6ýjk+#&90{s;̉DpuP9Mhlzw,JlW[:5w-U,U3'I(QYWgչG j/.%l[S);Azdt_s:/ GN_ ~Z(3Lo餆2'iU/Be)x 辦ɓV?>3(-)W A#hѓPz*E\ C %} }?#:1I6DhYത x`m7!97o꾭ɳ7E>&X~G!w5pe*}j~*٧8wUCT$kΠ0}\%F̞C3Pjz4- ֺz0i81NB>L}^:/]9u!ip+zY>'|׊81AJFآ zmi}IfفнܘMŪ1x{?Cf)<2 W+YtV؛bē@EE/nA>2b!]5K[X y~ԣT.c2*{Zp;!9 vQjhFp_u]Bɼӫ$\SgY0)b C:˰f٭|3$8|! F^{9Ǚ]2!4"/"CGÃz<2]%`f1SARjA:hnrJ\eQT[ 6[ :5DIYk8ƻ U-dA2;CԓK`~ʼnJ< -tYnȋȘ=h!EÉNq32%%Nzj)^+t*bLD5!(Fz3 mlvZe`G{X?h;3QߕH-4ADTڃ2t_B8ye-Ddht"  n"b&ƕ]#85I@hMkIpL\@Y.X?ЎV؍-dv@#r*&zIZ(mz֋њ~c)uPyfĶ\|㔛O’' 6T,kZ} {#?ςAI1:YYd~#l)R.=0|唆׼o֧Ьd9.G+iML>~ΉuAD]봟VUDA9]Rl#4' T% S|Vn 7Ha/Yx9ݿR߆SΡD7a>$YC-QsJGmBU@4{ @B"͠ xr|%=ҘmyhUhɑb^D=`:!ͭԲ@vfD򂳔Lςfr쌸3 7blJI3]~})(;LMU@u]b~lI~tB!: SYomyΐ[6 /8ѡ({WN[]vRW8aNm/(~BA=3bPڎ֘ĖvVT]Vpxx;bY{4OxNlȥ=W7vӥ{QGMSqTN[r NI2vfJ-kSsOД)+-k_gVE,r.n(Ƀ? hmue(%+hV,=OE۷9[`7j!Rg5=γ;~V*yH*15,UnҭPJwtIW"HW s\9i"/z} a` h=me}J0J0k3d%3TZ Izl9d;X޼0]A҈O?0'Q^QԪ4ݥVO&}J0a$KEG1<//S%G lROƙ:U"iɗT&<$fٱsY~WBuȾ042őۉK%!溂fٰ  j* yTNC*[$F'|d'[]l:rK4LProD !,p'5<֖Ï'yEt.M.|/2O-8+m-{[=~$ԋ`7@X$ד/6-XAJtR34zu#hgNu)})O)XfAG]u غOL g+"o>GU%[NҞ^**g#3StCz{ݢs0o 2-Wzr[AтPݶFJ3~ Q (☝>/whE*_%;?% ~eV[KP qLf"DsvF..4WդKY'5OnU i<1Hq\_k jSzU\e]ÑV u>uLH#i@JFq;IPIΩ2unEyTף/hZQϕA;y. 7/d)֐r>twIXK;_ - 7qP~S}6f?]5B][ \0Ok4O& ֝ ה3He$9r=, LĘo`}_TPC-o@ l.n@2ͫ{JO7lK6֛j?T\$j6zud`BH_ʛECWB,}׎vL^ K~~UD*C+GCjjCFc:Vm~f#{QGcO(6Q71b=17V!G@*tp|&4S#ylSdPX"{` :/OY8?*d0XV-D.ː6~okt{C5d  +5w88rE!Oi*PP%i %\WJ kŔԩP=P.81 +G<(iր<Q#&c ,Ӎk\>9 )R&wY!I~k[z u}|3{b;yFo^B<pOкgJ"܉S0-a@58,lGnCi*[I&ѿ\z'o_?`H7\b7/YUu`wF/`_gMWt7O`'z LSҞDhpkI /< G>xf&JըN,%y'◴l94aJ1ŝ(T{Ovدq6#$ (y52N ˵v':<*7*ƥ ׬^=O/eet?=؝o9clQ 9}"tbI3}iMPzׂSxUGI&k*@;ۥ*#ZX&6ppv, 2/E:?L 72_EZq[8R^camuCo_9tӉ}O<744\mJ3wÔ/-̇RwA׵dU'6RmP ]Χz a\ЅR0{ p>2'ֲaߍ:=@75+j}~=~{6ҟ]TUf/l֬#~LueM jR|8XqtVjncfkiqOGVuĜ4Mʑ>#&a2#g\+hAnpI#.y5?wiGHIBHHlUq!4X(Li(XԟrNo)#™F't} 0UGŜb5-娊s Qk2=xBp2KK²sIP./{8qd~w?):[mٱvG2Nbztm6@zc+O ]"}[}p9hz滋Ez8J)g4oxDD|S)g.m_ucN#:GkхDeGkEid# b~X6f<A|C}Ӷ2Ix]aj Pp R_QzԘ҆cOI_ǁ7'^6gǿȂf|a0ݽ_ЌVKwD9Li;mduN\H?LO`:>G^tB ?qo炜̼#Z{`i&li.'k8;G[ oWM@mF<ߛP=M܂AܔdSPc 446iDp26>*E"8cm/+u, Vt,3Flg4-Į.-I}6Sg:ܧȏT<*಼ڂq8QEHQafڭ zd$5A|zh' ʜZxgY,xREГ.;@6ʹ@Ǵ{2O3u>`QU+`f_ݱ?ic(*`8f@@ěH}C<2d8)>:84(QWG_|*@l;v0ct&?6ܒCdoY7nm}Mf@bcq.-zO >٭o'GҲG, aO<51N^v'֣cd@R >͟q:ZҚPVY^ BAub+؆6.R?f|\bs(ZmNo^h>4^MZ݂1X΢/Gvqt7l| &/6M k] +O^c| Xh4L[064~2XWa>9HBzpUkª$lTLpÞӻu'D䩇9MC(#`-ErK@XteE:\P5]d{9Y yyZ('6 vtQсaJ\H |bxH` *fט;,׫9l ;Fˌz1^g"\#L@}SggHa#Gl>mu7Ua7:nB$8QE~l5enÉ,+,jV+D7I)\ɕ鐏)(ΔVۦ'V2CnZ?yJk'6]A2=Eg.fD\[q۞uVESKl3YMmb_lQ}NSfaWyǎ%ZJr^7 `s0w}K\+ZF~hݼSS8^oS^8KC  SiɘDްETHtaBiԿ|B1cZD4nM['B7@i}">oz!r[5g@b01uO}RM8 ; 91ᖥ#*zL Z.4 >hҀQho֨<-_ٻycs+g'c$ 6$O&a}_'`Mo`4q_Ha|U<̳ вtRQ_tvh3Vu:Xg77Zj[}^MߢWCT-Z U-Ơ~&߸C ɹ%ze(}S6 p?- PRjzȰ 1üXaUD4V* h]E0Oז_K&́&r[_ZX#O^X"*Tdb qw/''rJENU}*Kc.(6HWH%L,UܛNm5p6'S_\ 9<'@Ue@w&hъ&ʆgu J w]J-)@@P,\Z4Xx:J{j33C6㫻K0#7mz}#გݢ)4k#O,JkJ&]Pe5Df6oi,4`5C1en{#`s<^-1f/ATX!]|P]|Q>?7cMq$UdEd`n|:$9+W${hJ=뫍>=evn%3!Xju?ØtO33N|lա9Wh*()@E9I>rh ՝cYo(rJw? *{,)V/L Ѫ7QM, BDݧEJ›kH5h>hɂsg" 5~X -eMۿ;K4z!aq$=+h ZU |RXaﻹ$,)`>6&+tvy@3jJ\7@Zm6 Q7 5J'8˳u~VrwR3cCh`eFFT%r|&!3`'JW&3Jy &,[*+<:[?6z{I7l)ŅZ0Nwv$IqS ~)  Q+HacA48ApnXwaa5;rӏ)/t>;D7-9jqFhD2~<#+Ҋqg~DZ6,z{@)/eV",t_6|”TqbGj|Z2\,P¿TDd#G +_<9SOGTҢ, WD+WA`p^x0[<&ma&0,gaװ覫ZA*5^rsK{{#2Jቦ-<(tÚ' 'sZί.kyn -.?kՖ|t >29MHGsi[SY|BFofNB y(yj:tLpF{z  F ]nUOPcIhYM7-iD!"9$FWdP&DzRy Sc_Z-4BSJ ] v؏SP($! N9f6Mѱ@wZ~#w!Y6g.<+%i)^=]a[A}̅TGC&66Yfj+R C@= Ibt91/lY;0],H,yURjPO(8_$+5ԫ>$ek=R?UX\&ʞ9T?S-~ݵS)px֘?99P3<1! vBdYr;wDZ1}g˲)<|]h)TRl>c=$x9ػTw}4l`WGU\C^}q=͠p}micAe|w`,?]LNH>C&a>dJN_ 4_L{@\EzN+#A5cJnˠr0&.kн.pЈaX ng~g y]Zz -l•K"h9YMhH& KqWSYQ,OC| -ӹZn@ww IJGoHuzY_ td pg5C"PeKI"k]jdn>|͟6U=Pс+pڞWNyz[m&y|(􎥖y9fIJ&!Dez7-6c}?5Sӥ B.kcIimsӢYLi(fh 'ʑw\R 6|Mx{)HFJ=@6P]??.*JɖT{.CL#+jH:1.(H2OFW \ 䴮ƕk^ &̀Ce7h=$Yo+O_Cx$C P-׾ ,{j%Y]65Vȝp:K͹p1L[EyJ>njUʄ- _|jᆃKnL¬Vcʻp!ٙ^>7+(ZDMIt@ֶ3HP7#81w> bҺ rR5x; (u."NFN_w&rteῶ/\Lj*s{hMaI'r*ybњh#͝\|)^7F0WB 6; #"x^>$xHˍQb~KMTHs90q BzCamjOR7 YeHӥD\i$ ":-EI„)WUւ[c5|® C$bފ!%2n>Bg>9.mDD=U2f)g(xQ{0E*۸ie4sCt?^Zmu8Gd_i z3!!5֡ |u k|SMҭ i_"~`c,hJLO!0ou &4\sDuQOeD8RxF/<.Ԏw#qӹcWlYR+iL oSH:끤jxdmY3Xkq͒wHúe ~(W5f@hIl 0_& _:-8X" Qs~ U;ho`FcM̾;8TBTZyUV`u?dhۊLnzÅrO.'|UEfHrjԓ) igWOov] 0t^S򾬠 A>W-O!h)>/j' ;}䄉yջ_{xݸUwM/wʷfԃ3yXԥ5 d VA5Mh4;1XsLfODwτw!UMH@-YfQk(*^)rDA3PےN!*ƕK7}DtCT͇wQpoDδv.:?:w(,q܌A@+Z7(N g3vׄ/lRav!Й2YmL ;oᴞӾbt/E7IP#<׿[32w`6GUpmz-R,lsk .ʳ~ ư4&H0 :ۜfd|T݄ c( q$A0}k=-d$<]\!"9. ){c3P[vBc`+Q*N*f;dDéL'[Hl`8䏕=/@'fW$yj=t{0m4Ȇe~61x\_7GOK̍Wdb$@AGܴ eL{'UډƐQ\ 3BKDqF:Eݎq10 'b km`2$>,7N_1bT>mGT=#+MDĉ$Y_#cx1Btdj@*΅9/HnVm3:W4y!DBika~K]lJDNF+:/9Dn"Q0pj+8e{4/$gNT\-ۀkKڡxzkj.xQT Aj=1ޖ18(9aô^i{`g`JmHʼ~t+"+ȿ+hԉ܋ԁD埽ߓsγR#ɃCjNFc#BT ]aN%@Ro e޶rpi;Km8XЪ'DZ= 3Ts@}ǔn0ʎ//NJ1'3|/--`S2/Q M LREZEWF8{mbf #EwhF=5 |S-C=Rqͣ"*PgK?Ϝ@p*qVzXxPOd=̿05bJ14J u@_ڼ*ߎi8bqi ݓONkD!M^o>Z~8 h#M(:.AZ 2% q˘N ޱ8L{Px%р6 Vp&#(&n xKr@5m 6xު/|ʯS_y^ 80 tyq 5 ӸHItNޫ8-r.f\ϱBG7_r- C!k,+lGtrK2]+JbsMr}0z$FqeFȉdƩot[oXBş|(jڇK#nĨzDF#OM8a:DVN=i-\  ,w[@A,J@uMEH;)p\M_}٣yP@G{HACX vg>`}S~{jlYUnUqpuzmSOZ}Wk$cIak8¸ΰA7 JT2?,li֌uEWIe2ޟeFހ9lOwAO^U);~uRVw<+&p z?t9vd@@JH[EZ>jvfp:A%f!; 1.B]Y"&~KͫҸBGprH |ڱeaY1FEnu/ZI50?j8=&xmqȭKYym{-gI#TȢMih+ӼPm^`c#bB䀵 7E!0HY DaD\`xPS0 <# t j~:Րt^ˣ*nQHIfaA4Y1w0ײHK7DKNՍ:ae#+Ϡi.Gpl%"ZCfQ+jd X~qhGpF~lu2D5> ji^HRj.I=eԥy5  ">_Y'" 4^5`A^8{1)T-0XБsѕS.(wwM&ACW93B]i? jt̐𻅔fR1N9H ֮ű{dde'VH -^.H$V {'BK=Ts|OET QDy+~Ǡ-reqi$b2'CFuM"1 ~C5K4پ}{$t,W6VIܕU_3\(4."ߚpJRk>Ҽ!0%,g# DG?NfI䞀)4 ۗcS^vzŞEFH|w[!,^}Up'lFSdYfn 8z$&3~ȼc'C4LMLx9ʓiGi+-\jpkM 0%.~Hqor?uhaft⩢0R uT|1v;I^g _P3SCm@LggB$E]"qnh٫L6EU ]Ecx~sBLdtMOvw,qr~At Ua&O1Gx裃}Ռ(g d.{EW #^=S2wEG`ߐSy1rkypHT$hE}%yz=}~1BO z Ë¿MPC1+@0U-d,hYUe;i7Џhδ+IahRd,#UE/QѲэnS>'Uz[+GvPgqr=HCҮi!q`y4X+_n#*41/`'X~UwPtLS2|MiQLqn)Llr-'Fh*{ ;[_08vλh4y券xo>H]޽/ĺ3~Sk#1Kr_:}ZP}|!F&$tG~͞6h9RSm(h .kx۫9;7Cㆣ QIQLiL/pdI|zGR \QJ6p=;jǚSA1 dY<]q7`y%8B}sķJDt):8Uˋ %eK[~Р}=ӆBءTK2t2E&kUsE[ V>}61oKC& q)hnR~n1XOsk*]2eًh%Nu6-Ĉhݛu%@JwOW0d-"q\:W`$y2(o&X[? q(k&۪/jY?]NӍ߈j[ʚN9|/oh AЦFDMbhTΨ{=`#5~jϡDY/:T$!SSex $RU1nn~[g24)ڎ+xxK,ec%3w4CN!zsT_lUbV@g؁Awh} +aX?ߊM)ޭȫ\l?yNGoi֯fuǖfҘFm?;벾ט2@#,g棙'NS=f`*"x7u ŁIBC䣖WOz=W{hHqXoN v"cLj[,c XC"R\dނ]v\9u3&ys,^dֵGQ3zqrqͅsnA2g}FH,l&R9ZHK{5u]c|nS?={0 ̊I /;M9g(&ަ-Fv//M_LHG'޺ڄum ]+rBqʼn׌vK~,s٪If|o7n^a襀@c\RӿѸř٥~UݸThŌIDl@sڈp+zՙU˯bFƇ}!^֚nf =[I=,rrľ,6b#lJ(9H1oA T_;!:6nxfʀs~p!0n ػ:ҪR %@wՈJ\wTO!j1ϫ{${iܺ,<{do:qs Z*9.Hj.ȹ^:JgȼA"Ҍa;lX YҖG8g{яr'syRkNBh'_]*w!cOǬb`;_P8>T]P!ۈ->N_$]P =;({mѣ((ǒ:9e>3TCmr>*:Vz$X ܑ4ۤ>np6Пx qCзoM0W\$-/:ݚYwc*1WOYC5nɻVpA?bDN\('HScXIM=6p5Ƌ~ jA#>S("=&y ? @dc~AfqL*~/+1k2RQ܊'+ FiZaG9*IWXq@P`C.ޙ6uo E5:gLw.j;T}}="f=e|) ڰSa"OACO$>o6L.kVKW'}Ӊ%j멥}Ѝާ{Ac2/2(wo>:v"LpЖ|D˕m!B̏ ;{%#rkZn?Nhi8v=#s'/*pqi yfMA )۶fXۍ]Y7r2^FW:;p)w^aS.<"@|+sHu3 !BN/xD$S6,_,WC5243;³,=e!D16s=Ȣ˼r:!?B7w.׼,Gc.^ʾB^e1oyV'+۟,8 ᰐT{`QT$AFyCD)X*P MUֵ.6X(ɦhzI!=Jl6m(5 lk,C7a̎$3]E]͓2?蘓 8F1ne%R4ɱR6f[2N y~`f\֖u I{]e] Ŀ]$Ss5TUV,ޤDԅɃW1:2ָ(78p :vȫӘN+˭zd L7¿W| loCN5.+ Hf,)n?{Fej)cX3[;Z)OT뢃j7RkmM{kqZ^ɮoEs=mcWڭG]WX]MDgz+JTLqƒ?OE+Y9BE]jtXZt*5_L֫h{{Tbǁwa:Z g!3('uy*f=Vg} G[MJlIGJ #*+-hχG-&+Y2Q6=H&=dlg%ulGi7c/^6//4_z/6 J\dSD6NJBQn^))~[BRM@QS >fB3/@\_I;ߏ阓kr'޶3ňw4W )A~UR{]wW%iqDQfP'LP, {K p%LƯ[7H vg-|6.E)$Q9T p饕L+W͌޲ f8I8^%Xpy1 'ZZJiNAW=+VMEьΞ]vjʾ#faK)2Wlv6SmpnPwTw&\d+sqP2ZqήrNvx֐\-BZ%d-^Z(e USsYPXΉf (O %ońVS&!M$1tW]yy&_Pc-e:{_ȵ"K`q>;N1o:&R iFNURcenF2P#7w|1=bJCb>QqBXN2:u0kGPx+rXrDCaH;(Hw2?4ƫ&R=T6YEjgwn7Vg}a_$c1;dXF)tNB>Gtt8R}!@(6ͱ!ٌ^qI^chkx4'e? gq(8ǃ1V7cvKqIސ*d-kl @ \A/?m´k8-! *{`qIiQs&*p/ 5C 0Ky}brCwϓsGVg`ކJ}YfQ E{U߻G.'$UyʷBÀ%|z:P{KΘ^;Su IpnңT3ђ^Ć2vMv|0׻ gӭm߬?>Só{8T`t&G5/lsʝG!hުS"hJJ~/ړaQ~$~􇬿n;bƏœ#:=P '74N'C8;HQ^9K(;Uھ=rPyaBG;?~8C"6_ {(1&.S$sK0p-]p+%enUmR@Rrl=FX@g%ey>|b deʓ @PYӟ˝o#9<~8/n ѴNtb~ZֽYdNх CnChS[ehP+_n7 UU <$m'dl:`ATϾ{Kz6&Q#c.kd4vEP!sҭ7$BDSr2G8[׏Ê=S nPS`L቟|Fy&yv8o~El)0 Z_MYnn_{aݤ6SM-׼t J'Ϙzq?x;QoCenP=8}2@j3 _w}[4A2LvoM*йpJWĈH*D,>c*|G?j߻'lVW)/ EĊ/ڱgʀrT`ڀ:qѧ<嘞A1,C&N/rfPt]7G:<Htm,n+Y2 V`n mN@^gi?:1dewLNm#d'%z҇zlT>/[tr(, e;Qm zPG0 xJ7F횒߳bL~;OiǠX*`kv㏱nkEpꢗs,zS@pݮ2?CoH5Gs0- q#hRԡDZP+6/ƣDjAk^DeAIW\SUu˖KYTi 1{}$^ߪ+J" f{~:i~"%z-]b>TȮR׍f_TNl?YpM)[" u{lb"\}3ºN+bD&ჍF~" m0vUσ v7$`P}r~})whZYVUvv(T"ʲE{{?vX6.Q_^/kn,rݍlgB2{ Fb8* ,bX>v4??Ysq= g'^N9_3/x-^Mz06VIaMzC -Wj?y[k8ȥxzf :S @4 jgdKqlM_Uq>t^vl57b'QZן̳0yr[˄ 8^ȸ?hW:<U 7=:|~EBloWﺒ@E`Bֈ;\mЫa\ pj35l:WEמԻ?2n}Jkao{y\sj^;r"]sE[)(rD5G :w9*p5d 'G$GX ӳM(rF8<.#gkp2Umw_]8pc L$bx1\i4 "5$miڳPGR3P1;z\m9q_(V WV& UͿ,KqDlz{Y":6!Ds6‰ߙt>:ḕ;__~XUZׂW&ܮơZI^XZ/l;R[풒7֦U5nv'/Z g 0JYBC7e[HM37O'u?1U|L=*Cj<cj8=iK0#xA3f`aBS5/tizTI)*ӧ` f<}Oٽ v.jLEr6N!u& iн7,ʫ'qn¹T -LKp^ò6aE(M-Ծϼ̔}[-Ghf1n'zuTy~Ѧ[^H>:ijOCMΞLЊkѽ}g~8 =H_ 䑻Q+W%h t2ԼuH/#;?iȶH-({g ,c;@APjʷpOx6x.-A^V-iF2”;Jo^ `tBc/kw_6W Qd 1DFC"簠vB,?9-.aU{nQl-r"f7AZ^M\ԫNa_mxm%e%ۅ+#,(qvdd?|h ҙ1`|xC2)y4\KbdFMV 3j[#Vb3*'¸` *C!͒ =z1[[\P:L~](% 9=zl⍐IsT|QQgxի ١HH;X쬜 >p6RIOr'x^;<zT>nF\pSP>2Z&ZFx},H RwOvArh/CG2@HM9 =nO0(iz4{\‹[ŮiRgsFD nT2ҁ(>9-/j rCuZDe< PTK,g7ռk [Bú<.?̐͌'5= E76[Ymiz0G4(+&Eu+e('Om*9HxAfsk<{#f7>jqp=N']E6'PnꡰM&^! b ! vr$2!8P {:#IXL`@#zYH%SN>@=MjN+ "#%Q@@0N]QD8e3w [WɣrҲD[bDm?#uFE(|>cD F1[d(}s76˵Ů Lb[4@AY'ȼ{_H k.Wdϑ +Ne) AJ #&qȤ\|.\ˈE;-%6?^$L)Fy'HQ|F$51$\APqxڮTDҽ87DܣtI{í Y1á jj:K}r`j7m!B6kd<@v"@v B4N ȕۂ\\`_tE .I7A'*]{{yZҹF]GmV*g%P L0jwԗq'n^22˔g'YE[F":렅@;#I5[Nl._6H:oQ]];ar-j\?}^p3!sKx է.A'Q#7g!Nn,E3]wܒDD~3S[b>2e[S@8@fɟ=&a:(k|.dنC v_>hdYWa1ft] }:ieRݨ#$u.|#S?͏}mpo*.BIU%7WSS^4B|$V9Ã@C_LEk#SQv؊ǵ;pˇ5ͣY[o/ҏSV=7cq\D4 ea ɗ5כ{ NR5&r42Ĺ ѵWza=an.S׷ʫ8 ø1 hܬKV * 3a]q,޼B{)-3'w ݂+(bA._YA(`D>GB񽶢#F>Tk8z{,&OPLC?Aױpa#)a>R} ,d@י ᒗ`N3SPj0`+Wrb=xηf(&: k9̳,? Me-0=q,ym~=֢h96pƘg,ޞ*vr4X~׳]!@BΨ)tj=rO>V7A 0g/WҢ0nIiQwI#yNh}y3,5r5G. 8c+yplpYz-dJ:CWK&Ƃ={*ц4q"<Ew O9cVO/4e#QQێ: Gױj3q\v&$gH<7]Z/LE}s9V38 i4rk Ƽ |F1MZCF v3v=# ܣIyP6eG%#(8){0ZP&8ǃkx3 d sB븢oӛqH7)B C~nZT.$u{/s[hRo0/yr;o0 f8ONvHRd,m]%;"rSaga@X!UڤѝtJ+hᛠ-}MIvnJ"|ڌm Գxm|bs*'B(gp,% %PzgI*#܍!rIh&K HL)pfsh3pDa*hM9l;jyvX%|RtIpY ~NW¡zXR'9Q$@:,v}$(ۤN?ęo͟pK <;hR&?|,K[xc-lB};ϒ qլSJg@ pJx1XSPFxKF3~!kD7Бm=S}tC||W>I_J_drzN|QVUaf *݇>-![,EtTRUC3|kذ-LZ)1bbYՉp|Jup1EzP%?Ķ!o٢F#8,ܼJ޻b|k؃y;8c7C  s.*0&|QlRs̬o|qdd4ܣ}`PZ*JUu2 } ?;\>>)Q8zR0:~%Gak"jL]q -{\v^|sIF Ku+ka v#FՙR cH}JF*G$/j)N2oϿzNbQEnxWLyJal{{lflfwfOQ}ųS~E*}Т-*AE*Ә]rpՑMlj͹ LNx/k˺ū6$$&X |f8(junH !k b2h3.ݶQGTonFGF'ήAxzK{:61m:t!n! {uu J{|q%/C]ۛ, Y^7-Aٗ㻭ū\-zR.ր Q)ȋV+8"I)f$hĺt% 5ӭ+.0GALb7_-!GO3Gt"`U8w!;Hۯs@if3c/ઽRlsΞ[b7 z$/ h}2pm DIbGԦ:OjxCjcK0#:X lm]LGP|IZ(1hﳠpeA Y#YFU4SC}pB9U~hcϺo%#kB - 92SQZ8nDwJ2|06z}=Q:Xæ O=폨)jhc=}"K:’yqI"sV9 ]g5(yBprpdԔ4(ttP %D̍)ӍU(FIx8V>Ͳ d:5>Q͛|!Y-u{ʼi.A!{d+vF_Vr(&ɋ.>PARtwJ4z 6}: YՍy [: &EPD{.| ^RY1K5ްԟT0' Hjٙ(vGjTX\/Bc_Ykt{_x{RkO] KwsE\YGc+vW/XP˥Ab))Nzё2#; ]f;ChځCW'm{潷au$8p{sRB-pp;GݣX 1 Dxv0(5xIH5XtMNO?Q]ΧTPcpjo$x4,oE=IׯWvClld\͉47Eea NMz&r߫~N?g K| C^hrRZ0X\|>]4 jvQhR-O>*F-,SS{?hǨ),VZⷣp%%06H %ɸ{@u<8yR;.ܱ)9!ñVﱞX*yƆiS~^<$h>^p52P;: yz2^\cu|HP\rp.jC9К hٔ8Gkf>&$(gI| E-8,xm '6~$|KBtSoR '\ÆbcA7DI}> Qw9h{=S~c Аdj#JC SqJt9)C)1j4o”we|s f] xY)}ý pNzKDw`wgƍxLs܍%|oXiR󠂤{]>\ߪ'KF콟 C?vI}\ws1BM ٳ[4ɕOU 3IUH@BE[Vxi!*ω&eegr(F^1WyFؠ{&q7r_V˼8ƍ8 DTȽnv3/yw̩6?uKm SO1k'{#yx v\|Ny!\ 劒ŷ˔C>.ek1i^sHD{NFz7Ovx1s;ÜT+?*BA0+ɻ\.舄{ڱ&H] ,:yI0F{xD|3=TCC 5]C_BK+a'QuS_x0=aP08Vbu|X_Nӱ͛ 2 #+XhgIDA9/W$@wf0hN.p,sX꤭;ϡXH7{I"5ON !ѩ(y|?"5:`"EQkH8?+I "4%{sc{ۂ%&|,RckZJ~7V~R >}뽻JNIo'GDeV5a,X٥||PO7!Υ "Ùfr%z)ņ]?Xw]RK hcG>$ kήڿUO5"vˇ!t_>P#qi3%ɤ/%kN4zБ2z0_ͻکM}qt'qWҽ(XwW\C8o9cw ݨl8ADI_R`Ӻaxdx7C-Hʉ}dW,/P{dmسϘ@L"+* ±.Ƚϡ/D1%4[hk͇~~ ,y $`o (qoa:o6PzC+Sw]VA6%.Qg40ŐK@gO[pBKN9nb Q(Tn/V{ a, sȝX;L(qh2Gj|g k|tԁA~ޢˋ~י9"!,Sa.>*q@19oY%}?V ^lg򐭞Fn *M` P}3ѩ-f,ZXO,'}yb%QI%R@?s՝cyy ?b}1n .;tB,(!b$; 9 f[~$Mk~XA#ؗ+hĤk]_n4}oH2Zh#V  aسE/}* U+wqRh(X>ؓ| ?N`OۥUqD CVoۨ*N&!<1w]}hyGK'T4>Za˳#(S+Ez/L7!"tp*B~}J ųW9V${IɊ:4 fja#Z{kユn.Ws37}}?ab@ X)Q쫡t5<,vx P?GE(?|3"n'u)&(?QXq'G_Gl[ueyJ0Mp0kÇS2K:\ AeMZNVA⪖J-tߊ'X`$yAtPOC&r^P/@WGFBG{܅L?RČъ N3xgHΎm4{3|H^m"\X8ՙUjgn %a(:F1R17=[#0*%F1O.G@H$#Ng7'@ΖӚn [. 0nΕ۪ )ʃ{yd>U'7 (@F2WSH7xLD mgO { Z;TDҔ l3FZa[/3>*+3`10r> y6:p>{B&$\P3iQ@]dS g~3{@u8:]P6? >74yGsҞ-3% 1NIO$2EJQI>(Ԭf:1츩<865 ܋FS.?P0ۄ~6_HIKvmext1w*1@JWЦBHYEO4ZrvRn QR]mП.dDb{ϣ ͬ6w8T"2:]33nENdTaAh@f9GIWp?v_!1{~Ab;q.{LԴíu{ݡx Y1'-&j gPW?,[(詙Ba@ q <}8VGZs%::zح R=@a&z7~!A BdtLAvYf giB=XKyv '"W*K R")B|+ ߄qQ'in5'D`ǿ;0+_ƹn7^s %:cOaE: !Ia'lv;.O  kgϧ__nl(ف37j#4>nY)eg[EŨLH # ]tmXGrD-dC$v>- +{$3qR&S"gM ::ddž нɧP$fvH!O*Ct`R U{XPྚ+7F}%]np*I9/`WEB*z[:\?xPMCp͏l(7 y; Gѷ\zl1t$s qZRO㨜|_X8FUvl L&؊n}'7K[mϭ3;& (j~X=sTt<@3/S[zia}qCTD&mSiMmdNHKQJnvvG|RWMr'U<+eDܮ5 EVpJ2-H%*P nAsb~TW/R@b^ڷF3依Άlz CJe;פ< ש9Ԓ `.s/0iBAa]0(Ks%4%Fo؄[*Vlm_-!! Vm;\'"ZPŏڽ?T{scSKs|~H.LAHya йb.5jf}sCܟӝ3G0`z& 7Vz?.#~=HDQ!مoN9I8%BXyΎIBn!s~Y3`#/ru3`,?{&"(Ky/xS pS$oo1Wj*E-ƖdCL6ߋy##de9v`˻YR&6 piB-`g-N[XMFj&@I?1/E!`ajg@܃8:i_rc%3r~!,WVΕb+6&O>H(Srˣqⷰ7`_dx>}V\)\.M#Bbⵚ7LB(ڬz0s'랒wLl-|^&^L6[O)Vڌ6%\k㥑.Lo'ZJ%ⅼ:<\*þ*NIbN%x8 G0yD0''mE?|&)=q/'ri)e eĥHF6k1X㕴JAF1HPIcOG?`hiJ:4aOָ؎>LAK\خ2~Eh-?Mw-|l-_z,UQwK'jȜƷr`%#-OyԝJ-5<:t7n>hа7]~QDx[ps7+%K{?kOlz-@_ '׀uCB%w/=|[ J.;R;cjg/~&1I[lK .fkah5b:R“-- t,}3pW$ ^N[I+nDQ..#eW$aR܅'$qD\0Y\µ#,'х=3d 5,t'Vq9-{v3q#{윋$=c=}=]艝xz gj85Pªgi&Ke/fB=mY>!.Gudj: *@ˠm"R_/ޅ<0CR {ŅeMUB A="jG {HQ U 8KJFB.F+Ѹ4k.,]sAܡ?Q{9*IQ`gcL]7`MK(J:opy|[O|;Jk)|ccWv߄iHS-`gα+;w4l/!f` }6զeLP5*n-߅oe T Vbo D Ǎhܪ]).._/xȻ$Rh=AN~FBv֮i.ng0f9l-3*_yG+/?DJN Gu(Bodg9HZ}6X0M_.VFnP'̧x" zer: 2%p(QĊ?Ϲ&X$(㝲ѓ<7®TK` yw\ܹ,/_iBU]7(Ir-4}rh%}Y B7!a8IqPad<^iۋuobߊV[SfK"LdռUhf90!C]ur`bSuD1D/ iQ rG9#~X,x*B~))(}-oԢ ϊ^ dx)lۄ``qܽ Q {R٪ྥ>heʒF|gŴ.o!|.^f8/SI>B[M@kۗ8D=g ̔؞;\ .v<5"}O4( fF&yQf{]|zU\7*XtV_c,sTl,N`ϋ4@u^KWH=**GS醿'#:o\+/]%nY%yzH;5) Nc=`"e X&Ct M6lzN%89n K