samba-client-4.6.16+git.166.8fb11cda200-30.1<>,] ͎/=„zysPJ!ҭ8쀦[)0241E,Uy^ROsGNjaaE Xe1n}%TEuWR-trx8K~S~h 3bס2((|fvu8w*[J/[Ad FDl?\d* / F  &D[ah M  ii i Ti i Ai iPi!]i#j#i%<%(HI(I38I<9T :=k>s?{@ڃBڋFڱGiHliIiX|YޔZ[\8i]i^bNcdefluivD&wix(iy`zLCsamba-client4.6.16+git.166.8fb11cda20030.1Samba Client UtilitiesSamba is a suite of programs that allows SMB/CIFS clients to use the Unix file space, printers, and authentication subsystem. The package named samba-client contains all programs that are needed to act as a Samba client. The binaries expect the configuration file to be found in /etc/samba/smb.conf For a more detailed description of Samba, check the samba-doc package or the Samba.org Web page at https://www.Samba.org/ Please check https://en.openSUSE.org/Samba for general information on Samba as part of SUSE Linux Enterprise or openSUSE products, links to binary packages of the most current Samba version, and a bug reporting how to.] ͎cloud1036d`openSUSE Leap 42.3openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgProductivity/Networking/Sambahttps://www.samba.org/linuxx86_64/sbin/ldconfig if [ ${1:-0} -eq 1 ]; then # Only insserv cifs if we're not in update mode. ln -fs /etc/sysconfig/network/scripts/dhcpcd-hook-samba /etc/sysconfig/network/if-down.d/21-dhcpcd-hook-samba ln -fs /etc/sysconfig/network/scripts/dhcpcd-hook-samba /etc/sysconfig/network/if-up.d/21-dhcpcd-hook-samba else for if_case in if-down.d if-up.d; do test -h /etc/sysconfig/network/${if_case}/dhcpcd-hook-samba || \ continue rm -f /etc/sysconfig/network/${if_case}/dhcpcd-hook-samba ln -fs /etc/sysconfig/network/scripts/dhcpcd-hook-samba /etc/sysconfig/network/${if_case}/21-dhcpcd-hook-samba done fi for fn in MACHINE.SID idmap2.tdb idmap_test.tdb netlogon_creds_cli.tdb passdb.tdb secrets.tdb smbpasswd; do test ! -e /var/lib/samba/private/$fn && test -e /etc/samba/$fn && \ mv /etc/samba/$fn /var/lib/samba/private/ done for fn in brlock.tdb connections.tdb dbwrap_watchers.tdb gencache_notrans.tdb g_lock.tdb leases.tdb locking.tdb mutex.tdb names.tdb printer_list.tdb serverid.tdb smbXsrv_client_global.tdb smbXsrv_open_global.tdb smbXsrv_session_global.tdb smbXsrv_tcon_global.tdb smbXsrv_version_global.tdb srv_fss.tdb; do test ! -e /var/lib/samba/lock/$fn && test -e /var/lib/samba/$fn && \ mv /var/lib/samba/$fn /var/lib/samba/lock/ done if ! test -e /usr/bin/get_printing_ticket; then ln -fs /usr/bin/smbspool /usr/lib/cups/backend/smb fi PNAME=dhcp SUBPNAME=-samba-client TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME SD_NAME="" SD_NAME=network/ if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi test -n "$FIRST_ARG" || FIRST_ARG=$1 if test "$FIRST_ARG" = "0" ; then test -f /etc/sysconfig/services && . /etc/sysconfig/services if test "$YAST_IS_RUNNING" != "instsys" -a "$DISABLE_STOP_ON_REMOVAL" != yes ; then for service in cifs ; do test -x /bin/systemctl && /bin/systemctl stop $service >/dev/null 2>&1 || : done fi fi/sbin/ldconfigYtdSQ`IHh(`(0m0`^^@nx x:H@Xhhx`H` 8hx` (i@ a v 2  -  }@ M*=AA$A큤AAA큤A큤AAA큤AA큤A큤AAAAA] O] S] S] R] R] R] S] S] S] S] S] O] T] T] T] /] T] T] U] S] U] U] U] U] U] U] U] U] U] U] U] U] U] U] U] U\㹼] V\㹼] V] V] S] S] S] S\㹼] Y] b] O] b] S] S] ] ] ] ] ] S] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] ] S] S\㹼] S] R] R] R] S] S] R] R\㹼] S] S] O] O] O] O] O7303d05507c158aab72b890a23a8bf50851c373aace809f07b8d729eddb786af523ab01d741b41f3dbee0abf3d9d44ff25bd570ccb3aad8dbcb2c3fa5cb1fd72d41d8cd98f00b204e9800998ecf8427ed41d8cd98f00b204e9800998ecf8427ebe1c1591dc49f8ca1e122e295f46a3a1a108366dc42a8456581ddd290e8f92b6da88f50a5167dd3b0ff0755d69c5f3293cf2a83f6165314c7d936ad53d5b5c2be170191642416d2bb72ac4965688b33feb453c6420eb9d5e412dd83e08f8e991b09740d9c486fd353235457f8b9410116d5cb540591b33b31ccb80bf09efb8a510ac3d235b2048a1577e6c0449fc99abc63c9d54dd3e17f0571cc75f2d8c3f2073fb57e0a2b9b212238c3415a123f0266186340bdbeaf5513095cbb9c0789d021fee41e093c0844b506d2fe2c0e9ebdacc39960119168f24bb5de23b3d827f2991a9f5687b70bda4d9149b995a9859a36898a8bdf0157b1225d3d945b3c4e56e0375f45c37ed0010740e0c631febfeb550698da081b9fa3f4a4011117f59b4b0293baefade88a946bc9f12d3caf6a7e4cf90ba5f74c08139b0fb20ceb9032af55eec13d11a3cfb4b3c7f360e8cd6d265574aabf4e6250a4b07122bce288ffdf3c90cbe4aa4ab8002468e9d3519951bb203a0a9312587ef57e08087e3cd278d484e577ea95188f615ed68a1efdcf9545e045f705eb4497c7cd3bdb1018051873809e20501eefcd19163ce8f60b8be1ca29fd23d3241eba29da271d2e407c24d85c030651d97e1c897941f2b0c12a285bfdb97785107ad2cf33edbacfd3ce93264e33c379b09ef49a94056f816c222c43fd41d8cd98f00b204e9800998ecf8427e27d586f60b2dd96c22dbd50cb31b5312ac5dfa061f3aa0744b96dad63d25c4d6760ccaf7473997f5b5fd3709ff3d3f78015dcf0534debff8d1282559a814c89d153be65e51947314bc11c2d6b3b9460860686a79dc43e33c8c500097faf89ffa2d0396d292b249a8b7ef4f8153ecc9d373e73a7e656ea138f129cebbb702e2a71ce3ee0d86bd9a12f0155569ff6997d3f3864a327569c508a0ac4d94752f23019c30e43bd2b8bf157f0ac6307fde41e4a0981e7b7a7ea639166cf50dd71643eb2ed18d7236c26668c4e7c8a6ada4ebcdeedbdf0b3759ae37d0d0603649c8423de7e4e6f1e0fb7421febbc113d3a7745b9e7de842bd879d91981e89f566e9f856beafdd7ffd32b8d144249499d7ea8c2f17fe6f9ec934e0b7623fd47abd48e1dbc464e67dc77eb79eed974a8adf4ef347418b473b04ac4289f46cde28bf3a083c4f8b2703a2bb4ad3095d88aa0b53e510decbd0ea439258acf72f5c4429e33eda727ebd583feb49dac8805bdfc53d714d53dec642542df3115a7689684443430138b423c6437e39ca93eeb0b38e977f8448e35581ec4aeabb5fba1a4f24afee3f125f92d3d50a32920985e721d3e0f48211fdd9104e5cdea9f07e76da1fe05027e0deab72ecffaf900c1519c49015ae93f98eb4af16e6f0b5536d4d9bb4181ff0eaa15aa817a60ecb7cb3e6f2d8cc07a577c0e75c07cb464615ab82c9ca278fa669c1549766f002e9942b752ec449109baee001ddb505855ff97fd66d93b6be8a148744fa8173df43a47957ebe55fb17fe43066ce046773b8a59b39c8a35f8e0885113b409be1b463f4f53cf953723010f6fb3afc0eab7f6d0ae90d07327f12c98f2f348ec8e905d58657eefd1105c662d41d8cd98f00b204e9800998ecf8427ed41d8cd98f00b204e9800998ecf8427ed41d8cd98f00b204e9800998ecf8427ed41d8cd98f00b204e9800998ecf8427ed41d8cd98f00b204e9800998ecf8427ed41d8cd98f00b204e9800998ecf8427ed41d8cd98f00b204e9800998ecf8427eaedc38126f4d086262af54cd3b9fd49ac04f18c7dc8bd25f242eddb55a1618a8e977eb00696d7e1c7a2e9be119754ff6@@@@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.6.16+git.166.8fb11cda200-30.1.src.rpmconfig(samba-client)libnss_wins.so.2()(64bit)libnss_wins.so.2(NSS_WINS_2)(64bit)samba-clientsamba-client(x86-64)smbfs@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   /bin/bash/bin/sh/bin/sh/bin/sh/bin/sh/bin/sh/sbin/ldconfig/usr/bin/env/usr/bin/perlcifs-utilsconfig(samba-client)coreutilslibCHARSET3-samba4.so()(64bit)libCHARSET3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libaddns-samba4.so()(64bit)libaddns-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libads-samba4.so()(64bit)libads-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libarchive.so.13()(64bit)libattr.so.1()(64bit)libattr.so.1(ATTR_1.0)(64bit)libauth-samba4.so()(64bit)libauth-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcli-cldap-samba4.so()(64bit)libcli-cldap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libcli-ldap-samba4.so()(64bit)libcli-ldap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libcli-smb-common-samba4.so()(64bit)libcli-smb-common-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libcli-spoolss-samba4.so()(64bit)libcli-spoolss-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libcliauth-samba4.so()(64bit)libcliauth-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libcmdline-credentials-samba4.so()(64bit)libcmdline-credentials-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libcom_err.so.2()(64bit)libdbwrap-samba4.so()(64bit)libdbwrap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libdcerpc-binding.so.0()(64bit)libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)(64bit)libdcerpc-samba-samba4.so()(64bit)libdcerpc-samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libevents-samba4.so()(64bit)libevents-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libflag-mapping-samba4.so()(64bit)libflag-mapping-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libform.so.6()(64bit)libgenrand-samba4.so()(64bit)libgenrand-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libgensec-samba4.so()(64bit)libgensec-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libgpo-samba4.so()(64bit)libgpo-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libgse-samba4.so()(64bit)libgse-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5samba-samba4.so()(64bit)libkrb5samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libldbsamba-samba4.so()(64bit)libldbsamba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)liblibcli-lsa3-samba4.so()(64bit)liblibcli-lsa3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)liblibcli-netlogon3-samba4.so()(64bit)liblibcli-netlogon3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)liblibsmb-samba4.so()(64bit)liblibsmb-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libmsrpc3-samba4.so()(64bit)libmsrpc3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libncurses.so.6()(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-samba-samba4.so()(64bit)libndr-samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libndr-samba4.so()(64bit)libndr-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libndr-standard.so.0()(64bit)libndr-standard.so.0(NDR_STANDARD_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnet-keytab-samba4.so()(64bit)libnet-keytab-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libnetapi.so.0()(64bit)libnetapi.so.0(NETAPI_0)(64bit)libpanel.so.6()(64bit)libpopt-samba3-samba4.so()(64bit)libpopt-samba3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libprinting-migrate-samba4.so()(64bit)libprinting-migrate-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libreadline.so.6()(64bit)libregistry-samba4.so()(64bit)libregistry-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libreplace-samba4.so()(64bit)libreplace-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsamba-credentials.so.0()(64bit)libsamba-credentials.so.0(SAMBA_CREDENTIALS_0.0.1)(64bit)libsamba-debug-samba4.so()(64bit)libsamba-debug-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsamba-errors.so.1()(64bit)libsamba-errors.so.1(SAMBA_ERRORS_1)(64bit)libsamba-hostconfig.so.0()(64bit)libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.24.2)(64bit)libsamba-security-samba4.so()(64bit)libsamba-security-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsamba-sockets-samba4.so()(64bit)libsamba-sockets-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsamba3-util-samba4.so()(64bit)libsamba3-util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsamdb-common-samba4.so()(64bit)libsamdb-common-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsamdb.so.0()(64bit)libsamdb.so.0(SAMDB_0.0.1)(64bit)libsecrets3-samba4.so()(64bit)libsecrets3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libserver-id-db-samba4.so()(64bit)libserver-id-db-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libserver-role-samba4.so()(64bit)libserver-role-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsmbclient-raw-samba4.so()(64bit)libsmbclient-raw-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0)(64bit)libsmbd-base-samba4.so()(64bit)libsmbd-base-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsmbd-shim-samba4.so()(64bit)libsmbd-shim-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libsmbldap.so.0()(64bit)libsmbldap.so.0(SMBLDAP_0)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtdb.so.1(TDB_1.2.2)(64bit)libtevent-util.so.0()(64bit)libtevent-util.so.0(TEVENT_UTIL_0.0.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.12)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libtime-basic-samba4.so()(64bit)libtime-basic-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libtinfo.so.6()(64bit)libtrusts-util-samba4.so()(64bit)libtrusts-util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libutil-cmdline-samba4.so()(64bit)libutil-cmdline-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libutil-reg-samba4.so()(64bit)libutil-reg-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libutil-tdb-samba4.so()(64bit)libutil-tdb-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_X86_64)(64bit)libwbclient.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)rpmlib(CompressedFileNames)rpmlib(PayloadFilesHavePrefix)systemdsystemdsystemdsystemdrpmlib(PayloadIsLzma)4.6.16+git.166.8fb11cda200-30.13.0.4-14.0-14.4.6-14.11.2\ڭ\\ \N\}@\\\X)@\@[%@[F[z@[a[WZ@ZZZYY@Yo@Yo@Yo@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USaT5'@T5'@T3T12T->@T->@T%U@T$T!`T!`T@T@TSS<@SS@S@Sہ@Sہ@Sہ@S@S;@S.S@SSSS@S@SS8@S}SxSg}@ScSZN@SXSO@SM@SM@SG@SG@SG@SG@S:@S:@S5d@S2@S,)S L@SSSS@S@S(S @S S 4@S?S?S?SK@R@Rb@R@RRR@R@RRRRRURURURRR&R@RR=R=RʚRʚRʚRʚRʚRʚRSRR@RjRjRv@RG@RG@RRRRR RiRu@RpRW@RUE@RUE@REs@R:@R6R4OR2@R(r@R%@R!R7R@R@QQQ@QQQQޞ@Qޞ@Qޞ@Qֵ@QQo@QzQQɆ@Q@Q(@Q@Qzl@QdQAQ,Q+R@Q@QQQ@Q@QEQ@Q \Q \PP-P-P9@PPDP[P@PѬ@P @P @PPP}@P+P@PP@PBPBPPP@P@P*P6@Pd@PoPoPoPoP{@Pb@Pb@PWPWPQP,PPP H@P H@PP@OjOjOORORO Ọ@OȮOȮO]@O]@O OE@O!O@OOO@O OoOc+@OaO`@OKp@OB5O>A@ODavid Disseldorp David Disseldorp npower David Disseldorp ddiss@suse.comSamuel Cabrero David Mulder Samuel Cabrero Samuel Cabrero ddiss@suse.comscabrero@suse.deddiss@suse.comjmcdonough@suse.comddiss@suse.comscabrero@suse.comscabrero@suse.descabrero@suse.descabrero@suse.deaaptel@suse.comnopower@suse.comnopower@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comnopower@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comnopower@suse.delmuelle@suse.comddiss@suse.comlmuelle@suse.comjmcdonough@suse.comjmcdonough@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comddiss@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comadrian@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comjengelh@inai.delmuelle@suse.comjengelh@inai.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comjengelh@inai.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comsjayaraman@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comshargagan@novell.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.delmuelle@suse.comlmuelle@suse.delmuelle@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.defcrozat@suse.comlmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.decoolo@suse.comcoolo@suse.comlmuelle@suse.deshargagan@novell.comddiss@suse.delmuelle@suse.deddiss@suse.deddiss@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dehhetter@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deshargagan@novell.comddiss@suse.delmuelle@suse.dejmcdonough@suse.deddiss@suse.deddiss@suse.delmuelle@suse.dejmcdonough@suse.demrsb@novell.comlpechacek@suse.czjmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.deshargagan@novell.comddiss@suse.delmuelle@suse.deshargagan@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.dejmcdonough@suse.deddiss@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.dejengelh@medozas.delmuelle@suse.delmuelle@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.deddiss@suse.dero@suse.delmuelle@suse.delmuelle@suse.delars@samba.orglmuelle@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.dehhetter@suse.deddiss@suse.dejmcdonough@suse.decoolo@novell.comlmuelle@suse.dejmcdonough@suse.degber@opensuse.orgjmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.desjayaraman@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dehhetter@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delars@samba.orglars@samba.orgjmcdonough@suse.dejsmeix@suse.delmuelle@suse.dehhetter@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.derhafer@novell.comhhetter@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.deboyang@suse.dejmcdonough@suse.delmuelle@suse.deboyang@suse.deboyang@suse.delmuelle@suse.derhafer@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delars@samba.orgjmcdonough@suse.desjayaraman@suse.dejengelh@medozas.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.deboyang@suse.dechris@computersalat.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.deboyang@suse.deboyang@suse.dehhetter@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.desbrabec@suse.czlmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.deboyang@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.desjayaraman@suse.desjayaraman@suse.desjayaraman@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dero@suse.de- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- s3:winbindd: let normalize_name_map() call find_domain_from_name_noinit(); (bso#13173); (bsc#1123755); - s3:winbind: Fix regression introduced with bso #12851; (bso#12851); (bsc#1123755);- s3:passdb: Do not return OK if we don't have pinfo set up; (bsc#1099590); (bso#13376);- s3: winbind: Remove fstring from wb_acct_info struct; (bsc#1114459); - Use foreground execution mode for systemd samba daemons; (bsc#1112223);- Update to 4.6.16; (bsc#1110943); + CVE-2018-10919: Fix unauthorized attribute access via searches; (bso#13434);- Update to 4.6.15 + Fix ctdb_mutex_ceph_rados_helper deadlock; (bso#13540); (bsc#1102230); + Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bso#13453); (bsc#1103411); - s3: winbind: Fix 'winbind normalize names' in wb_getpwsid(); (bso#12851); - winbind: avoid using fstrcpy in _dual_init_connection; (bso#13294); (bsc#1087303); - Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1068059); - net: fix net ads keytab handling; (bso#13166); (bsc#1067700); - fix vfs_ceph flock stub; (bso#13506).- Fix vfs_ceph with "aio read size" or "aio write size" > 0; (bsc#1093664). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425). + Fix memory leak in vfs_ceph; (bso#13424). - Update to 4.6.14 + winbind: avoid using fstrcpy(dcname,...) in _dual_init_connection; (bso#13294). + s3:smb2_server: correctly maintain request counters for compound requests; (bso#13215). + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375). + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338). + vfs_glusterfs: Fix the wrong pointer being sent in glfs_fsync_async; (bso#13297). + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270). + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244). + s3:libsmb: allow -U"\\administrator" to work; (bso#13206). + CVE-2018-1057: s4:dsdb: fix unprivileged password changes; (bso#13272); (bsc#1081024). + s3:smbd: Do not crash if we fail to init the session table; (bso#13315). + libsmb: Use smb2 tcon if conn_protocol >= SMB2_02; (bso#13310). + smbXcli: Add "force_channel_sequence"; (bso#13215). + smbd: Fix channel sequence number checks for long-running requests; (bso#13215). + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197). + s3:smbd: return the correct error for cancelled SMB2 notifies on expired sessions; (bso#13197). + samba: Only use async signal-safe functions in signal handler; (bso#13240). + subnet: Avoid a segfault when renaming subnet objects; (bso#13031).- CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741);- Update to 4.6.13; (bsc#1084191) + ceph_statx configure time check doesn't work with a non-default - -with-libcephfs path; (bso#13250). - follow up fix for libceph-common detection; (bso#13277). + Fail to copy file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181). + vfs_ceph uses a local statvfs() call to determine FS capabilities; (bso#13208). + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193). + smbd panic when chdir returns error during exit; (bso#13189). + ctdb_recovery_helper crashes if recovery process times out; (bso#13188). + POSIX ACL support is broken on hpux and possibly other big-endian OSs; (bso#13176). + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986). + g_lock conflict detection broken when processing stale entries.; (bso#13195). + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132).- Update to 4.6.11; (bsc#1084191) + vfs_glusterfs: Fix exporting subdirs with shadow_copy2; (bso#13091); + s3: smbclient: Ensure we call client_clean_name() before all operations on remote pathnames; (bso#13093); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + smbd: Move check for SMB2 compound request to new function; (bso#13047); + s3:vfs_glusterfs: Fix a double free in vfs_gluster_getwd(); (bso#13100); + s4:pyparam: Fix resource leaks on error; (bso#13101); + s3:smbd: Fix delete-on-close after smb2_find; (bso#13118);- CVE-2017-14746: Use-after-free vulnerability; (bso#13041); (bsc#1060427); - CVE-2017-15275: Server heap memory information leak; (bso#13077); (bsc#1063008);- Update to 4.6.9; (bsc#1065066); + Reverse sense of 'clear all attributes', ignore attribute change in SMB2 to match SMB1; (bso#12899); + SMBC_setatr() initially uses an SMB1 call before falling back; (bso#12913); + Fix segfault on MacOS 10.12.3 clients caused by SMB_VFS_GET_COMPRESSION; (bso#13003); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically; (bso#7909); + Honor SEC_STD_WRITE_OWNER bit; (bso#7933); + Kernel oplocks still have issues with named streams; (bso#12791); + Handle EACCES when fetching DOS attributes; (bso#12944); + Missing assignment in sl_pack_float; (bso#12991); + Fix wrong Samba access checks when changing DOS attributes; (bso#12995); + Groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + Fix GUID string format on GetPrinter info; (bso#12993); + Match WS2016 ReFS set compression behaviour; (bso#12144); + Fix implementation of process_exists control; (bso#13012); + GET_DB_SEQNUM control can cause ctdb to deadlock when databases are frozen; (bso#13021); + Free up record data if a call request is deferred; (bso#13029); + Initialize ctdb_ltdb_header completely for empty record; (bso#13036); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + Ignore event scripts with multiple '.'s; (bso#13070); + Sort the GPOs in the correct order; (bso#13046); + 'smbd' uses a lot of CPU on startup of a connection; (bso#12973); + Fix str[n]casecmp_m() by comparing lower case values; (bso#13018); + Can't change password in Samba from a windows client if Samba runs on IPv6 only interface; (bso#13079); + Fix file change notification for renames; (bso#12903); + Avoid a socket leak after fork; (bso#13006); + Fix a potential memleak; (bso#13090); + Fix passing of errno from async calls; (bso#12983); + Fix segfault when running with log level 10; (bso#13032); + Do not report an invalid range for AD DC role; (bso#12629); + Print the kinit failed message with DBGLVL_NOTICE; (bso#12704); + Fix changing passwords with Kerberos; (bso#12956); + Fix changing the password with 'smbpasswd' as a local user on a domain member; (bso#12975); + Fix a read after free if a chained SMB1 call goes async; (bso#12836); + CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); + Let non_widelink_open() chdir() to directories directly; (bso#12885); + CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); + CVE-2017-12150: Some code path don't enforce smb signing when they should; (bso#12997);- Fix GUID string format on GetPrinter info request; (bso#12993); (bsc#1050707).- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.- Rebase File Server Remote VSS Protocol (FSRVP) server against 4.2.0rc1; (fate#313346).- Backport upstream master fixes for samba-regedit; (bnc#896536).- BuildRequire python-xml on SUSE systems only.- BuildRequire python-xml. - Exclude unwanted texpect binary and libhttp, libsamba-cluster-support, libsamba-debug, and libsocket-blocking shared libs. - Add vfs_fruit and vfs_worm man pages and ndr_dcerpc, smb2_lease_struct, tstream_smbXcli_np, idtree, and idtree_random header files. - Remove nmblookup and smbclient4 binary and nmblookup4 man page.- Update to 4.2.0rc1.- Fix small memory-leak in the background print process; (bnc#899558).- Modify samba-regedit so it displays correctly (related to ncurses). Changed code to use menu sub windows, seems to fix problems with display not refreshing; explicitly BuildRequire ncurses-devel; (bnc#896536).- Exclude unwanted libdnsserver_common and libdfs_server_ad shared libs and the man page of the unused findsmb script.- Skip groups that aren't mapped by idmap_ad; (bso#10824); (bnc#897969).- Update to 4.1.12. + s3: winbindd: On new client connect, prune idle or hung connections older than "winbind request timeout". Add new parameter "winbind request timeout". Please see smb.conf man page for details; (bso#3204); (bnc#872912). + Fix smbd crashes when filename contains non-ascii character; (bso#10716). + s4-rpc: dnsserver: Handle updates of tombstoned dnsNode objects; (bso#10749). + passdb: Fix NT_STATUS_NO_SUCH_GROUP; (bso#9570). + s4:setup/dns_update_list: make use of the new substitution variables; (bso#9831). + build: Fix configure to honour '--without-dmapi'; (bso#10369). + provision: Correctly provision the SOA record minimum TTL; (bso#10466). + s3: Enforce a positive allocation_file_size for non-empty files; (bso#10543). + lib: tevent: make TEVENT_SIG_INCREMENT atomic; (bso#10640). + Make "case sensitive = True" option working with "max protocol = SMB2" or higher in large directories; (bso#10650). + Samba 4 consuming a lot of CPU when re-reading printcap info; (bso#10652). + lib: strings: Simplify strcasecmp; (bso#10716). + Allow netr_ServerReqChallenge() and netr_ServerAuthenticate3() on different connections; (bso#10723). + 'net time': Fix usage and core dump; (bso#10728). + sys_poll_intr: Fix timeout arithmetic; (bso#10731). + s3:idmap: Don't log missing range config if range checking not requested; (bso#10737). + Fix flapping VFS gpfs offline bit; (bso#10741). + s4-rpc: dnsserver: Allow . to be specified for @ record; (bso#10742). + s4-rpc: dnsserver: return DNS_RANK_NS_GLUE recors when explicitly asked for; (bso#10751). + samba: Retain case sensitivity of cifs client; (bso#10755). + lib: Remove unused nstrcpy; (bso#10758). + Fix a memory leak in cli_set_mntpoint(); (bso#10759). + docs: Fix typos in smb.conf (inherit acls); (bso#10761). + libcli/security: Add better detection of SECINFO_[UN]PROTECTED_[D|S]ACL in get_sec_info(); (bso#10773). + s3: smbd: POSIX ACLs. Remove incorrect check for SECINFO_PROTECTED_DACL in incoming security_information flags in posix_get_nt_acl_common(); (bso#10773). + Don't discard result of checking grouptype; (bso#10777). + s3:libsmb: Set a max charge for SMB2 connections; (bso#10778). + smbd: Properly initialize mangle_hash; (bso#10782). + dosmode: Fix FSCTL_SET_SPARSE request validation; (bso#10787). + vfs_dirsort: Fix an off-by-one error that can cause uninitialized memory read; (bso#10794).- Wait for network-online.target to prevent caching of pre-network failures; (bnc#889175).- Use domain name if search by domain SID fails to send SIDHistory lookups to correct idmap backend; (bnc#773464).- Prune idle or hung connections older than "winbind request timeout"; (bso#3204); (bnc#872912).- fix FSCTL_SET_SPARSE request validation; (bso#10787); (bnc#893774).- Remove pre-11.2 patch which by default uses the smbpasswd passdb backend.- build: disable mmap on s390 systems; (bso#10765); (bnc#886193); (bnc#882356).- Create the cups smb backend as sym link pointing to smbspool; (bnc#891220).- Fix winbind service parameter usage; (bnc#890005).- lib/param: change the default for "winbind expand groups" to "0"; (bnc#890008).- Update to 4.1.11. + A malicious browser can send packets that may overwrite the heap of the target nmbd NetBIOS name services daemon; CVE-2014-3560; (bnc#889429).- Fix "net time" segfault; (bso#10728); (bnc#889539).- Update to 4.1.10. + net/doc: Make clear that net vampire is for NT4 domains only; (bso#3263). + dbcheck: Add check and test for various invalid userParameters values; (bso#8077). + s4:dsdb/samldb: Don't allow 'userParameters' to be modified over LDAP for now; (bso#8077). + Simple use case results in "no talloc stackframe around, leaking memory" error; (bso#8449). + s4:dsdb/repl_meta_data: Make sure objectGUID can't be deleted; (bso#9763). + dsdb: Always store and return the userParameters as a array of LE 16-bit values; (bso#10130). + s4:repl_meta_data: fix array assignment in replmd_process_linked_attribute(); (bso#10294). + ldb-samba: fix a memory leak in ldif_canonicalise_objectCategory(); (bso#10469). + dbchecker: Verify and fix broken dn values; (bso#10536). + dsdb: Rename private_data to rootdse_private_data in rootdse; (bso#10582). + s3: libsmbclient: Work around bugs in SLES cifsd and Apple smbx SMB1 servers; (bso#10587). + Fix "PANIC: assert failed at ../source3/smbd/open.c(1582): ret"; (bso#10593). + rid_array used before status checked - segmentation fault due to null pointer dereference; (bso#10627). + Samba won't start on a machine configured with only IPv4; (bso#10653). + msg_channel: Fix a 100% CPU loop; (bso#10663). + s3: smbd: Prevent file truncation on an open that fails with share mode violation; (bso#10671); (bnc#884056). + s3: SMB2: Fix leak of blocking lock records in the database; (bso#10673). + samba-tool: Add --site parameter to provision command; (bso#10674). + smbstatus: Fix an uninitialized variable; (bso#10680). + SMB1 blocking locks can fail notification on unlock, causing client timeout; (bso#10684). + s3: smbd: Locking, fix off-by one calculation in brl_pending_overlap(); (bso#10685). + 'RW2' smbtorture test fails when -N is set to 2 due to the invalid status check in the second client; (bso#10687). + wbcCredentialCache fails if challenge_blob is not first; (bso#10692). + Backport ldb-1.1.17 + changes from master; (bso#10693). + Fix SEGV from improperly formed SUBSTRING/PRESENCE filter; (bso#10693). + ldb: Add a env variable to disable RTLD_DEEPBIND; (bso#10693). + ldb: Do not build libldb-cmdline when using system ldb; (bso#10693). + ldb: Fix 1138330 Dereference null return value, fix CIDs 241329, 240798, 1034791, 1034792 1034910, 1034910); (bso#10693). + ldb: make the successful ldb_transaction_start() message clearer; (bso#10693). + ldb:pyldb: Add some more helper functions for LdbDn; (bso#10693). + ldb: Use of NULL pointer bugfix; (bso#10693). + lib/ldb: Fix compiler warnings; (bso#10693). + pyldb: Decrement ref counters on py_results and quiet warnings; (bso#10693). + s4-openldap: Remove use of talloc_reference in ldb_map_outbound.c; (bso#10693). + dsdb: Return NO_SUCH_OBJECT if a basedn is a deleted object; (bso#10694). + s4:dsdb/extended_dn_in: Don't force DSDB_SEARCH_SHOW_RECYCLED; (bso#10694). + Backport autobuild/selftest fixes from master; (bso#10696). + Backport drs-crackname fixes from master; (bso#10698). + smbd: Avoid double-free in get_print_db_byname; (bso#10699). + Backport access check related fixes from master; (bso#10700). + Backport provision fixes from master; (bso#10703). + s3:smb2_read: let smb2_sendfile_send_data() behave like send_file_readX(); (bso#10706). + s3: Fix missing braces in nfs4_acls.c.- Reduce printer_list.tdb lock contention during printcap update; (bso#10652); (bnc#883870). + Only update the printer share inventory when needed.- Add missing newline to debug message in daemon_ready(); (bnc#865627).- BuildRequire systemd-devel, configure --with-systemd, and modify the service files accordingly on post-12.2 systems; (bso#10517); (bnc#865627).- Prevent file truncation on an open that fails with share mode violation; (bso#10671); (bnc#884056).- Update to 4.1.9. + Fix nmbd denial of service; CVE-2014-0244; (bnc#880962). + Fix segmentation fault in smbd_marshall_dir_entry()'s SMB_FIND_FILE_UNIX handler; CVE-2014-3493; (bnc#883758).- BuildRequire krb5-devel, libiniparser-devel, and python-devel in any case.- BuildRequire libxslt and perl-ExtUtils-MakeMaker and BuildIgnore libtevent on CentOS, Fedora, and RHEL systems.- Update to 4.1.8. + dns: Don't reply to replies; CVE-2014-0239; (bso#10609). + Malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response; CVE-2014-0178; (bso#10549). + s3: smb2: Fix 'xcopy /d' with samba shares; (bso#3124). + Extra ':' in msg for Waf Cross Compile Build System with Cross-answers command; (bso#10151). + s3: nmbd: Reset debug settings after reading config file; (bso#10239). + Fix empty body in if-statement in continue_domain_open_lookup; (bso#10348). + script/autobuild: Make use of '--with-perl-{arch,lib}-install-dir'; (bso#10472). + wafsamba: Fix the installation on FreeBSD; (bso#10472). + Use exit_daemon() to communicate status of startup to systemd; (bso#10517). + Fix adding NetApps; (bso#10524). + s3: lib/util: Fix logic inside set_namearray loops; (bso#10544). + s3: lib/util: set_namearray reads across end of namelist; (bso#10544). + idmap_autorid: Fix failure in reverse lookup if ID is from domain range index #0; (bso#10547). + build: Fix ordering problems with lib-provided and internal RPATHs; (bso#10548). + Fix read of deleted memory in reply_writeclose()'; (bso#10554). + lib-util: Rename memdup to smb_memdup and fix all callers; (bso#10556). + Fix lock order violation and file lost; (bso#10564). + dsdb: Do checks for invalid renames in samldb, before repl_meta_data; (bso#10569). + Fix wildcard unlink to fail if we get an error rather than trying to continue; (bso#10577). + byteorder: Do not assume PowerPC is big-endian; (bso#10590). + printing: Fix purge of all print jobs; (bso#10612).- examples/libsmbclient: avoid some compiler warnings; (bso#10624).- Fix printer job purging; (bso#10612); (bnc#879390).- Update samba-pubkey_6568B7EA.asc which will expire 2016-01-17.- Fix byte-order macros on little endian Power8; (bso#10590); (bnc#871701).- Pass through vfs_btrfs snapshot manipulation requests when "btrfs: manipulate snapshots = no" is configured; (bnc#874180).- Clone the base share security descriptor when exposing a snapshot share; (bnc#874656).- Use appropriate HRESULT return codes; (bnc#875046).- Update to 4.1.7. + Make "force user" work as expected; (bso#9878). + Fix build on AIX with IBM XL C/C++ (gettext detection issues); (bso#9911). + Fix problem with server taking too long to respond to a MSG_PRINTER_DRVUPGRADE message; (bso#9942). + s3-printing: Fix obvious memory leak in printer_list_get_printer(); (bso#9993). + doc: Add "spoolss: architecture" parameter usage; (bso#10188). + Make 'smbclient' support DFS shares with SMB2/3; (bso#10200). + Make (lib)smbclient work with NetApp; (bso#10230). + SessionLogoff on a signed connection with an outstanding notify request crashes smbd; (bso#10344). + dfs: Always call create_conn_struct with root privileges; (bso#10378). + 'net ads search' on high latency networks can return a partial list with no error indication; (bso#10387). + max xmit > 64kb leads to segmentation fault; (bso#10422). + Fix STATUS_NO_MEMORY response from Query File Posix Lock request; (bso#10431). + Increase max netbios name components; (bso#10439). + smbd_server_connection_terminate("CTDB_SRVID_RELEASE_IP") panics from within ctdbd_migrate() with invalid lock_order; (bso#10444). + Fix 'wbinfo -i' with one-way trust; (bso#10458). + samba4 services not binding on IPv6 addresses causing connection delays; (bso#10464). + s3-vfs: Fix stream_depot vfs module on btrfs; (bso#10467). + Don't respond with NXDOMAIN to records that exist with another type; (bso#10471). + pidl: waf should have an option for the dir to install perl files and do not glob; (bso#10472). + s3-spoolssd: Don't register spoolssd if epmd is not running; (bso#10474). + s3-rpc_server: Fix handling of fragmented rpc requests; (bso#10481). + Initial FSRVP rpcclient requests fail with NT_STATUS_PIPE_NOT_AVAILABLE; (bso#10484). + lsa.idl: Define lsa.ForestTrustCollisionInfo and ForestTrustCollisionRecord as public structs; (bso#10504). + Make 'smbreadline' build with readline 6.3; (bso#10506). + smbd: Correctly add remote users into local groups; (bso#10508). + rpcclient FSRVP request UNCs should include a trailing backslash; (bso#10521). + Cleanup messages.tdb record after unclean smbd shutdown; (bso#10534). + s3:rpc_server: Minor refactoring of process_request_pdu().- Create a new DBus connection for every vfs_snapper request, to ensure correct snapper UID detection; (bnc#866354).- Fix "Invalid read" in method reply_writeclose; (bso#10554); (bnc#873658).- Fix minor compiler warnings in snapshot code-path; (bnc#873177).- Remove references to the obsolete samba-krb-printing package and get_printing_ticket binary.- Fix malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response; CVE-2014-0178; (bso#10549); (bnc#872396).- User error strings instead of hex codes where possible for FSRVP errors; (bnc#866927).- Fix remote share shadow copy request UNCs; (bso#10521); (bnc#870957).- Add krb5rcache directory to the winbind package; (bnc#870607). - Cleanup and consolidate the sysconfig and systemd service files.- Extend vfs_snapper man page to cover permissions; (bnc#870570).- Fix RPC server handling of fragmented requests; (bso#10481); (bnc#869707).- Default with the cache and lock directory to the same path to have both non-persistent and persistent data at one location; (bnc#846586).- Depend only on %version with all manual Provides and Requires; (bnc#844307).- Update to 4.1.6. + Password lockout not enforced for SAMR password changes; CVE-2013-4496; (bnc#849224). + smbcacls can remove a file or directory ACL by mistake; CVE-2013-6442; (bnc#855866).- Password lockout not enforced for SAMR password changes; CVE-2013-4496; (bnc#849224).- Call update-apparmor-samba-profile via ExecStartPre too; (bnc#867665).- samba4 smbcalcs --chown | --chgrp dacl regression; CVE-2013-6442; (bnc#855866).- Retry named pipe open requests on STATUS_PIPE_NOT_AVAILABLE; (bso#10484); (bnc#865095).- Propagate snapshot enumeration permissions errors to SMB clients; (bnc#865641).- Properly handle empty 'requires_membership_of' entries in /etc/security/pam_winbind.conf; (bnc#865771).- Fix problem with server taking too long to respond to a MSG_PRINTER_DRVUPGRADE message; (bso#9942); (bnc#863748). - Fix memory leak in printer_list_get_printer(); (bso#9993); (bnc#865561).- Fix stream_depot VFS module on Btrfs; (bso#10467); (bnc#865397).- Use libarchive to provide improved smbclient tarmode functionality; (bso#9667); (bnc#861135).- Depend on %version-%release with all manual Provides and Requires; (bnc#844307).- Update to 4.1.5. + Fix 100% CPU utilization in winbindd when trying to free memory in winbindd_reinit_after_fork; (bso#10358); (bnc#786677). + smbd: Fix memory overwrites; (bso#10415). + s3-winbind: Improve performance of wb_fill_pwent_sid2uid_done(); (bso#2191). + ntlm_auth sometimes returns the wrong username to mod_ntlm_auth_winbind; (bso#10087). + s3: smbpasswd: Fix crashes on invalid input; (bso#10320). + s3: vfs_dirsort module: Allow dirsort to work when multiple simultaneous directories are open; (bso#10406). + Add support for Heimdal's unified krb5 and hdb plugin system, cope with first element in hdb_method having a different name in different heimdal versions and fix INTERNAL ERROR: Signal 11 in the kdc pid; (bso#10418). + vfs_btrfs: Fix incorrect zero length server-side copy request handling; (bso#10424). + s3: modules: streaminfo: As we have no VFS function SMB_VFS_LLISTXATTR we can't cope with a symlink when lp_posix_pathnames() is true; (bso#10429). + smbd: Fix an ancient oplock bug; (bso#10436). + Fix crash bug in smb2_notify code; (bso#10442).- Remove superfluous obsoletes *-64bit in the ifarch ppc64 case; (bnc#437293).- Migrate @GMT token parsing functionality into vfs_snapper; (bnc#863079). + Improve vfs_snapper documentation.- Fix Winbind 100% CPU utilization caused by domain list corruption; (bso#10358); (bnc#786677).- Fix memory overwrite in FSCTL_VALIDATE_NEGOTIATE_INFO handler; (bso#10415); (bnc#862370).- Streamline the vendor suffix handling and add support for SLE 12.- Fix zero length server-side copy request handling; (bso#10424); (bnc#862558).- Set the PID directory to /run/samba on post-12.2 systems.- Make use of the tmpfilesdir macro while calling systemd-tmpfiles.- Make winbindd print the interface version when it gets an INTERFACE_VERSION request; (bnc#726937).- Fix vfs_btrfs build on older platforms with duplicate WRITE_FLUSH definitions; (bnc#860832).- Check for NULL gensec_security in gensec_security_by_auth_type(); (bnc#860809).- Ensure ndr table initialization; (bnc#860648).- Add File Server Remote VSS Protocol (FSRVP) server for SMB share shadow-copies; (fate#313346).- s3-dir: Fix the DOS clients against 64-bit smbd's; (bso#2662). - shadow_copy2: module "Previous Version" not working in Windows 7; (bso#10259). - s3-passdb: Fix string duplication to pointers; (bso#10367). - vfs/glusterfs: in case atime is not passed, set it to the current atime; (bso#10384)- s3: winbindd: Move calling setup_domain_child() into add_trusted_domain(); (bso#10358); (bnc#786677).- Default sysconfig daemon options to -D; (bso#10388); (bnc#857454).- Add /var/cache/samba to the client file list; (bnc#846586).- Really add the WINBINDDOPTIONS sysconfig variable on install; (bnc#857454).- Correct sysconfig variable names by adding the missing D char; (bnc#857454).- Update to 4.1.4. + Fix segfault in smbd; (bso#10284). + Fix SMB2 server panic when a smb2 brlock times out; (bso#10311).- Call stop_on_removal from preun and restart_on_update and insserv_cleanup from postun on pre-12.3 systems only; (bnc#857454).- BuildRequire gamin-devel instead of unmaintained fam-devel package on post-12.1 systems.- smbd: allow updates on directory write times on open handles; (bso#9870). - lib/util: use proper include for struct stat; (bso#10276). - s3:winbindd fix use of uninitialized variables; (bso#10280). - s3-winbindd: Fix DEBUG statement in winbind_msg_offline(); (bso#10285). - s3-lib: Fix %G substitution for domain users in smbd; (bso#10286). - smbd: Always use UCF_PREP_CREATEFILE for filename_convert calls to resolve a path for open; (bso#10297). - smb2_server processing overhead; (bso#10298). - ldb: bad if test in ldb_comparison_fold(); (bso#10305). - Fix AIO with SMB2 and locks; (bso#10310). - smbd: Fix a panic when a smb2 brlock times out; (bso#10311). - vfs_glusterfs: Enable per client log file; (bso#10337).- Add /etc/sysconfig/samba to the main and winbind package; (bnc#857454).- Create /var/run/samba with systemd-tmpfiles on post-12.2 systems; (bnc#856759).- Fix broken rc{nmb,smb,winbind} sym links which should point to the service binary on post-12.2 systems; (bnc#856759).- Add Snapper VFS module for snapshot manipulation; (fate#313347). + dbus-1-devel required at build time.- Add File Server Remote VSS Protocol (FSRVP) client for SMB share shadow-copies; (fate#313345).- Do not BuildRequire perl ExtUtils::MakeMaker and Parse::Yapp as they're part of the minimum build environment.- Update to 4.1.3. + DCE-RPC fragment length field is incorrectly checked; CVE-2013-4408; (bnc#844720). + pam_winbind login without require_membership_of restrictions; CVE-2012-6150; (bnc#853347).- Make use of the full gpg pub key file name including the key ID.- Add transparent file compression support; (fate#316266). + Implement FSCTL_GET_COMPRESSION and FSCTL_SET_COMPRESSION handlers. + Add FILE_ATTRIBUTE_COMPRESSED and FILE_NO_COMPRESSION support. + Extend vfs_btrfs VFS module to utilize get/set compression hooks.- Add support for FSCTL_SRV_COPYCHUNK_WRITE; (fate#314770).- Remove bogus libsmbclient0 package description and cleanup the libsmbclient line from baselibs.conf; (bnc#853021).- BuildRequire systemd on post-12.2 systems.- Update to 4.1.2. + s4-dns: dlz_bind9: Create dns-HOSTNAME account disabled; (bso#9091). + dfs_server: Use dsdb_search_one to catch 0 results as well as NO_SUCH_OBJECT errors; (bso#10052). + Missing talloc_free can leak stackframe in error path; (bso#10187). + Fix memset used with constant zero length parameter; (bso#10190). + s4:dsdb/rootdse: report 'dnsHostName' instead of 'dNSHostName'; (bso#10193). + Make offline logon cache updating for cross child domain group membership; (bso#10194). + nsswitch: Fix short writes in winbind_write_sock; (bso#10195). + RW Deny for a specific user is not overriding RW Allow for a group; (bso#10196). + vfs_glusterfs: Fix excessive debug output from vfs_gluster_open(); (bso#10224). + vfs_glusterfs: Implement proper mashalling/unmarshalling of ACLs; (bso#10224). + VFS plugin was sending the actual size of the volume instead of the total number of block units because of which windows was getting the wrong volume capacity; (bso#10224). + libcli/smb: Fix smb2cli_ioctl*() against Windows 2008; (bso#10232). + xattr: Fix listing EAs on *BSD for non-root users; (bso#10247). + Fix the build of vfs_glusterfs; (bso#10253). + s3-winbindd: Fix cache_traverse_validate_fn failure for NDR cache entries; (bso#10264). + util: Remove 32bit macros breaking strict aliasing; (bso#10269).- Let gpg verify execution condition not fail on non SUSE systems.- Add systemd support for post-12.2 systems.- Allow smbcacls to take a '--propagate-inheritance' flag to indicate that the add, delete, modify and set operations now support automatic propagation of inheritable ACE(s); (FATE#316474).- Unconditionally create the CUPS smb backend sym link pointing to smbspool; (bnc#850656).- Update to 4.1.1. + ACLs are not checked on opening an alternate data stream on a file or directory; CVE-2013-4475; (bso#10229); (bnc#848101). + Private key in key.pem world readable; CVE-2013-4476; (bnc#848103).- Private key in key.pem world readable; CVE-2013-4476; (bnc#848103).- ACLs are not checked on opening an alternate data stream on a file or directory; CVE-2013-4475; (bso#10229); (bnc#848101).- Update to 4.1.0. + pam_winbindd: Support the KEYRING ccache type; (bso#10132). + Fix PAC parsing failure; (bso#10178).- Unify the defattr lines in the pidl, python, test and test-devel files section by removing the optional directory mode.- Verify source tar ball gpg signature.- Update to 4.1.0rc4. + dsdb: Convert the full string from UTF16 to UTF8, including embedded NULLs; (bso#8077). + python-samba-tool fsmo: Do not give an error on a successful role transfer; (bso#9461). + dbwrap_ctdb: Treat empty records as non-existing; (bso#10008). + Raise the level of a debug when unable to open a printer; (bso#10118). + Add "acl allow execute always" parameter; (bso#10134). + vfs_shadow_copy2: Display previous versions correctly over SMB2; (bso#10137). + smbd: Always clean up share modes after hard crash; (bso#10138). + Valid utf8 filenames cause "invalid conversion error" messages; (bso#10139). + libcli/smb: Use SMB1 MID=0 for the initial Negprot; (bso#10144). + Samba SMB2 client code reads the wrong short name length in a directory listing reply; (bso#10145). + libcli/smb: Only check the SMB2 session setup signature if required and valid; (bso#10146). + Better document potential implications of a globally used "valid users"; (bso#10147). + cli_smb2_get_ea_list_path() failed to close file on exit; (bso#10149). + Not all OEM servers support the ALTNAME info level; (bso#10150). + Regression causes replication failure with Windows 2008R2 and deletes Deleted Objects; (bso#10157). + Netbios related samba process consumes 100% CPU; (bso#10158). + Fix POSIX ACL mapping when setting DENY ACE's from Windows; (bso#10162).- Require libndr-standard-devel due to gen_ndr/lsa.h from libpdb-devel.- Add libdcerpc0, libdcerpc-atsvc0, libdcerpc-binding0, libdcerpc-samr0, libgensec0, libndr0, libndr-krb5pac0, libndr-nbt0, libndr-standard0, libpdb0, libregistry0, libsamba-credentials0, libsamba-hostconfig0, libsamba-policy0, libsamba-util0, libsamdb0, libsmbclient-raw0, libsmbconf0, libsmbldap0, and libtevent-util0 to baselibs.conf.- Add or polish the shared library package summaries and descriptions.- Update to 4.1.0rc3. + Fix working on site with Read Only Domain Controller; (bso#5917). + Add man page for vfs_syncops; (bso#7364). + Add man page for vfs_linux_xfs_sgid; (bso#7490). + When replicating DNS for bind9_dlz we need to create the server-DNS account remotely; (bso#9091). + Winbind unable to retrieve user information from AD; (bso#9615). + winbind_lookup_names() fails because of NT_STATUS_CANT_ACCESS_DOMAIN_INFO; (bso#9899). + Build Samba 4.0.x on AIX with IBM XL C/C++; (bso#9911). + Add SMB2 and SMB3 support for smbclient; (bso#9974). + Add man pages for ntdb tools; (bso#10000). + Add man page for samba-regedit tool; (bso#10001). + ::1 added to nameserver on join; (bso#10030). + Fix memory leak in source3/lib/util.c:1493; (bso#10063). + Fix segmentation fault in 'net ads join'; (bso#10073). + Fix variable list in vfs_crossrename man page; (bso#10076). + s3-winbind: Fix a segfault passing NULL to a fstring argument; (bso#10082). + smbd: Fix async echo handler forking; (bso#10086). + MacOSX 10.9 will not follow path-based DFS referrals handed out by Samba; (bso#10097). + Honour output buffer length set by the client for SMB2 GetInfo requests; (bso#10106). + Fix Winbind crashes on DC with trusted AD domains; (bso#10107). + Handle Dropbox (write-only-directory) case correctly in pathname lookup; (bso#10114). + Masks incorrectly applied to UNIX extension permission changes; (bso#10121).- Implement shared library packaging guidelines. - Correct interpackage dependencies; (bso#10129).- Define the source URL differently in the case of a release candidate.- Update to 4.1.0rc2. + Add vfs_btrfs module. + Add support for server-side copy operations via the SMB2 FSCTL_SRV_COPYCHUNK request. + Fix replication with --domain-crictical-only to fill in backlinks; (bso#9029). + Windows 8 Roaming profiles fail; (bso#9678). + Fix crash of winbind after "ls -l /usr/local/samba/var/locks/sysvol"; (bso#9820). + Windows error 0x800700FE when copying files with xattr names containing ":"; (bso#9992). + Do not delete an existing valid credential cache (s3-winbind); (bso#9994). + Fix segfault while reading incomplete session info; (bso#10003). + Missing integer wrap protection in EA list reading can cause server to loop with DOS (CVE-2013-4124); (bso#10010). + Fix a 100% loop at shutdown time (smbd); (bso#10013). + Fix/improve debug options; (bso#10015). + Rename regedit to samba-regedit; (bso#10040). + Remove obsolete swat manpage and references; (bso#10041). + Fix crashes in socket_get_local_addr(); (bso#10042). + Allow to change the default location for Kerberos credential caches; (bso#10043). + Remove a redundant inlined substitution of ACLs; (bso#10045). + nsswitch: Add OPT_KRB5CCNAME to avoid an error message; (bso#10048). + dsdb improvements; (bso#10056). + Linux kernel oplock breaks can miss signals; (bso#10064).- BuildRequire pyldb-devel.- Add libnetapi0 and samba-libs to baselibs.conf.- Update to 4.0.9. + Fix crash of Winbind after "ls -l /usr/local/samba/var/locks/sysvol"; (bso#9820). + s3-lib: Fix segmentation fault while reading incomplete session info; (bso#10003). + smbd: Fix a 100% loop at shutdown time; (bso#10013). + Windows 8 Roaming profiles fail; (bso#9678). + Add UPN enumeration to passdb internal API; (bso#9779). + smbd: Cleanup disonnected durable handles; (bso#9930). + vfs_streams_xattr: Do not attempt to write empty attribute twice; (bso#9970). + Fix Windows error 0x800700FE when copying files with xattr names containing ":"; (bso#9992). + s3-winbind: Do not delete an existing valid credential cache; (bso#9994). + Fix excessive RID allocation; (bso#10014). + Add debugclass for DNS server; (bso#10015). + Fix/improve debug options; (bso#10015). + Allow to change the default location for Kerberos credential caches; (bso#10043). + Linux kernel oplock breaks can miss signals; (bso#10064). + net ads join: Fix segmentation fault in create_local_private_krb5_conf_for_domain; (bso#10073).- Update to 4.0.8. + Samba 3.0.x to 4.0.7 are affected by a denial of service attack on authenticated or guest connections; CVE-2013-4124; (bnc#829969).- Require krb5 and not the non existing krb5-libs package.- Update to 4.1.0rc1. + Directory database replication (AD DC mode) + Server-Side Copy Support + Btrfs Filesystem Integration- BuildRequire perl ExtUtils::MakeMaker and Parse::Yapp. - BuildRequire libxslt, libxslt1, or libxslt-tools depending on SUSE version. - Require perl-base on SUSE systems only.- Adjust group setting of the test-devel subpackage. - Require perl-base from the pidl subpackage.- Remove libdir/samba/ldb after install if we're building Samba without Active Directory Domain Controller support.- Remove unused ccache switch from the spec file.- BuildRequire docbook-xsl-stylesheets and libxslt-tools to build the man pages and add them to the package again.- Build from the package from the top level directory; (bnc#794744). - BuildRequire pytalloc-devel, python-tdb, and python-tevent. - Also use out of tree builds of talloc, tdb, tevent, and ldb for pre-12.1 SUSE systems.- Remove the empty data dir from the doc package filelist. - Explicitly use samba instead of the name macro to define the docbook dir.- Update to 4.0.7. + Fix a core dump with invalid lock order while opening/editing or copying MS files; (bso#9794). + Fix crash bug from search of mail=; (bso#9967). + s3-rpc_server: Ensure we are root when starting and using gensec; (bso#9465). + Add support for MX queries; (bso#9485). + dns: Delete dnsNode objects when they are empty; (bso#9559). + dns: Support larger queries when asking forwarder; (bso#9632). + s3:lib/server_mutex: Open mutex.tdb with CLEAR_IF_FIRST; (bso#9805). + Use of wrong RFC2307 primary group field; (bso#9880). + Check for system libtevent; (bso#9881). + is_printer_published GUID retrieval; (bso#9900). + Doc fixes for 4.0; (bso#9906). + Build fixes for 4.0 found during autoconf or debian packaging work; (bso#9907). + build: Add missing new line to replaced python shebang line; (bso#9909). + PIE builds not supported; (bso#9910). + s4:winbind: Don't leak libnet_context into the main event context; (bso#9929). + Fix a bug of drvupgrade of smbcontrol; (bso#9941). + Check for netbios aliases in ad_get_referrals; (bso#9947). + Fix tevent_poll on 32-bit machines (Coverity ID 989236); (bso#9953). + docs: Avoid mentioning a possibly misleading option; (bso#9964). + Fix build with system Heimdal of samba4kgetcred; (bso#9968).- Use SLE as product prefix for SUSE Linux Enterprise, oS for openSUSE, and OBS for any other operating system to define the vendor string while build.- Remove ldapsmb from the main spec file.- Adjust ldapsmb and nmbstatus man page syntax required by a newer pod2man.- Don't bzip2 the main tar ball, use the upstream gziped one instead.- Explicitly BuildRequire cyrus-sasl-devel, libattr-devel, and libopenssl-devel.- Fix libreplace license ambiguity; (bso#8997); (bnc#765270).- Update to 4.0.6. + Fix crash during Win8 sync; (bso#9822). + Fix segfault when loging in with wrong password from w2k8r2; (bso#9834). + Fix the username map optimization; (bso#9139). + Add support for PFC_FLAG_OBJECT_UUID when parsing packets; (bso#9382). + SMB2 server doesn't support recvfile; (bso#9412). + Fix the build of vfs_notify_fam; (bso#9545). + Fix adding case sensitive spn; (bso#9699). + Properly handle oplock breaks in compound requests; (bso#9722). + Properly handle oplock breaks in compound requests; (bso#9722). + Cache name_to_sid/sid_to_name correctly; (bso#9766). + Fix 'net ads join' when called via stdin; (bso#9767). + Fix segfault for "artificial" conn_structs in vfs_fake_perms; (bso#9775). + vfs_dirsort uses non-stackable calls, dirfd(), malloc instead of talloc and doesn't cope with directories being modified whilst reading; (bso#9777). + Fix panic when running 'smbtorture smb.base'; (bso#9782). + Use specified python for runtime installation of Samba; (bso#9785). + Change '--with-dmapi' to 'default=auto' to match the autoconf build; (bso#9803). + wafsamba: Display the default value in help for SAMBA3_ADD_OPTION; (bso#9804). + wbinfo: Fix segfault in wbinfo_pam_logon; (bso#9807). + Package new dbwrap_tool man page; (bso#9809). + Old DOS SMB CTEMP request uses a non-VFS function to access the filesystem; (bso#9811). + Fix 'map untrusted to domain' with NTLMv2; (bso#9817). + SMB signing and the async echo responder don't work together; (bso#9824). + Fix panic in nt_printer_publish_ads; (bso#9830). + talloc use after free in winbind4; (bso#9832). + Function called in unix_convert() path can overwrite errno; (bso#9833). + Fix NULL pointer dereference in Winbind; (bso#9854). + Fix making LIBNDR_PREG_OBJ; (bso#9868).- Remove disabled and anyhow obsoleted net-report and net_rpc_migrate patches.- Update to 4.0.5. + Fix large reads/writes from some Linux clients; (bso#9706). + Add 'samba-tool dbcheck --reset-well-known-acls'; (bso#9740). + Can't delegate adding computers to domain; (bso#9267). + Fix GNU ld version detection with old gcc releases; (bso#7825). + Never try to map global SAM name; (bso#9039). + Certain xattrs cause Windows error 0x800700FF; (bso#9130). + Samba returns unexpected error on SMB posix open; (bso#9519). + Fix build on AIX; (bso#9557). + libnss-winbindd does not provide pass struct for groups mapped with ID_TYPE_BOTH and vice versa; (bso#9617). + Reauth-capable client fails to access shares on Windows member; (bso#9625). + PIDL: Fix parsing linemarkers in preprocessor output; (bso#9636). + Rename internal subsystem pdb_ldap to pdb_ldapsam; (bso#9639). + Fix the build of vfs_afsacl; (bso#9642). + Fix the build with --fake-kaserver; (bso#9643). + Fix compile of source3/lib/afs.c; (bso#9644). + Make SMB2_GETINFO multi-volume aware; (bso#9646). + idmap_autorid: Fix freeing of non-talloced memory; (bso#9653). + Work around FreeBSD's getaddrinfo() underscore issue; (bso#9656). + 'make test' hangs; (bso#9663). + Fix correct linking of libreplace with cmdline-credentials; (bso#9664). + Fix filtering of link-local addresses; (bso#9666). + Fix crash in 'net rpc join' against a Samba 3.0.33 PDC; (bso#9669). + Samba denies owner Read Control when there is a DENY entry while W2K08 does not; (bso#9674). + Fix several resource (fd) leaks; (bso#9683). + Fix a memory leak in spoolss rpc server; (bso#9685). + Fix a possible buffer overrun in pdb_smbpasswd; (bso#9686). + Fix several possible null pointer dereferences; (bso#9687). + Make sure that domain joins work correctly when the DC disallows NTLM auth; (bso#9689). + Backport tevent changes to bring library to version 0.9.18; (bso#9695). + Remove incomplete samba_dnsupdate IPv6 link-local address check; (bso#9696). + DsReplicaGetInfo fails due to sendto() EMSGSIZE error on UNIX domain socket; (bso#9697). + Fix vfs_catia and update documentation; (bso#9701); (bnc#824833). + Fix build on solaris8: Do not force a specific perl on pod2man; (bso#9703). + Fix nss_winbind name on FreeBSD; (bso#9704). + s4:winbindd: Do not drop the workgroup name in the getgrnam, getgrent and getgrgid calls; (bso#9711). + Set LD_LIBRARY_PATH in install_with_python.sh; (bso#9717). + s4-idmap: Remove requirement that posixAccount or posixGroup be set for rfc2307; (bso#9718). + Allow forcing an override of an old @MODULES record; (bso#9719). + Do not print the admin password during 'samba-tool classicupgrade'; (bso#9720). + Make samba_upgradedns more robust (do not guess addresses when just changing roles); (bso#9721). + Add a tool to migrate latin1 printing tdbs to registry; (bso#9723). + is_encrypted_packet() function incorrectly used inside server; (bso#9724). + upgradeprovision and 'samba-tool dbcheck' patches for 4.0.NEXT; (bso#9725). + Fix NULL pointer dereference; (bso#9727). + DO NOT install samba_upgradeprovision in 4.0.x; (bso#9728). + Fix 'smbcontrol close-share'; (bso#9733). + Fix Winbind separator in upn to username conversion; (bso#9735). + Change to smbd/dir.c code gives significant performance increases on large directory listings; (bso#9736). + PIDL: Build fixes for hosts without CPP (Solaris 11); (bso#9739). + Make sure that we only propogate the INHERITED flag when we are allowed to; (bso#9747). + Remove unneeded fstat system call from hot read path; (bso#9748). + Don't leak the epm_Map policy handle; (bso#9758). + Fix incorrect parsing of SMB2 command codes; (bso#9760). - Update to 4.0.4. + Remove forced set of 'create mask' to 0777; CVE-2013-1863; (bnc#809624).- Fix periodic printcap cache reloads; (bso#9650); (bnc#807334).- No longer use the cifs- or smbfstab named configuration file on post-12.2 systems; (bnc#804822); (bnc#821889).- Shift the smbfs init script nfs dependency from Required to Should.- Fix SMB1 Session Setup AndX handling with a large krb PAC; (bso#9658); (bnc#802031).- Point LD_LIBRARY_PATH to the just-built libraries while calling testparm to generate the default share snippets on pre-12.2 systems.- Explicitly configure --with-ads.- Fix smbclient recursive mget EPERM handling; (bso#9633); (bnc#786350).- Remove superfluous quotation marks while setting the SAMBA_VERSION_VENDOR_SUFFIX string.- Do not restart the smbfs service on pre-11.3 systems during dhcp lease renewal when the IP address remains the same; (bnc#800782).- Update to 4.0.3. + Fix ACL problem with delegation of privileges and deletion of accounts over LDAP interface; add documentation; (bso##8909). + check_password_quality: Handle non-ASCII characters properly; (bso##9105). + Fix 'smbd' panic triggered by unlink after open; (bso##9571). + smbd: Fix memleak in the async echo handler; (bso##9549). + defer_open is triggered multiple times on the same request; (bso#9196). + Add extra attributes for AD printer publishing; (bso#9378). + FSMO seize of naming role fails: NT_STATUS_IO_TIMEOUT; (bso#9461). + Downgrade v4 printer driver requests to v3; (bso#9474). + samba_upgradeprovision: fix the nTSecurityDescriptor on more containers; (bso#9481). + s3:smb2_negprot: set the 'remote_proto' value; (bso#9499). + waf assumes that pythonX.Y-config is a Python script; (bso#9503). + s4:drsuapi: Make sure we report the meta data from the cycle start; (bso#9508). + wafsamba: Use additional xml catalog file; (bso#9512). + samba_dnsupdate: Set KRB5_CONFIG for nsupdate command; (bso#9517). + conn->share_access appears not be be reset between users; (bso#9518). + Remove superfluous bracket in samba.8.xml; (bso#9528). + Fix typo in vfs_tsmsm.8.xml; (bso#9530). + terminate the irpc_servers_byname() result with server_id_set_disconnected(); (bso#9540). + Make use of posix_openpt; (bso#9541). + Fix build of vfs_commit and plug in async pwrite support; (bso#9544). + Fix aio_suspend detection on FreeBSD; (bso#9546). + Correctly detect O_DIRECT; (bso#9548). + sigprocmask does not work on FreeBSD to stop further signals in a signal handler; (bso#9550). + smb.conf(5): Update list of available protocols; (bso#9552). + s4-resolve: Fix parsing of IPv6/AAAA in dns_lookup; (bso#9555). + Fix compilation of Solaris ACL module; (bso#9564). + Adding additional Samba 4.0 DC to W2k8 srv AD domain (in win200 functional level) produces dbcheck errors; (bso#9565). + Add dbwrap_tool.1 manual page; (bso#9568). + Document the command line options in dbwrap_tool(1); (bso#9568). + ntlm_auth(1): Fix format and make examples visible; (bso#9569). + Fix file corruption during SMB1 read by Mac OSX 10.8.2 clients; (bso#9572). + Fix a possible null pointer dereference in spoolss; (bso#9574). + Duplicate flags defined in the winbindd protocol; (bso#9575). + gensec: Allow login without a PAC by default; (bso#9581). + smbd: disk_free: sys_popen() failed" message logged in /var/log/message many times; (bso#9586). + Archive flag is always set on directories; (bso#9587). + ACLs are not inherited to directories for DFS shares; (bso#9588). + Correct meta data in ldb manpages; (bso#9591). + s3-winbind: Fix the build of idmap_ldap; (bso#9595). + Linked attribute handling should be by GUID; (bso#9596). + Fix timeouts of some IRPC calls; (bso#9598). + Use pid,task_id as cluster_id in process_single just like process_prefork; (bso#9598). + Add 'ldbdump' tool; general code and documentation cleanup; (bso#9609). + dsdb: Make secrets_tdb_sync cope with -H secrets.ldb; (bso#9610).- Update to 4.0.2. + Address SWAT security issues CVE-2013-0213 and CVE-2013-0214 which both don't apply to any SUSE Samba post-3.6.10 as it isn't longer built. + Don't build and package static libraries.- Drop separate build-source-timestamp file as it led to a second, incorrect Source Timestamp line.- Add server-side copy support; (fate#314770). + Implement FSCTL_SRV_COPYCHUNK and FSCTL_SRV_REQUEST_RESUME_KEY handlers. + Add vfs_btrfs VFS module for optimized Btrfs clone-range ioctl usage.- Add filter against shlib-policy-name-error for /lib*/libnss_wins.so.2.- Disable SWAT during configure and don't package it any longer.- Remove dangling references to Heimdal from the spec file.- Remove /lib/samba prefix from the localstatedir configure option.- Update to 4.0.1. + Samba 4.0.0 as an AD DC may provide authenticated users with write access to LDAP directory objects; CVE-2013-0172; (bnc#798364).- Add the missing get_printing_ticket binary path while calling the set_permissions macro; (bnc#783375).- Use the version macro while definition of the branch macro.- Remove references to no longer used devel macros.- Update to 4.0.0. + Honor password complexity settings; (bso#9414). + Install SWAT *.msg files with waf; (bso#9415). + Fix netr_ServerPasswordSet2, netr_LogonSamLogon with netlogon AES; (bso#9438). + developer-build: Fix panic when acl_xattr fails with access denied; (bso#9456). + Fix "map username script" with "security=ads" and Winbind; (bso#9457). + Install manpages only if we install the target; (bso#9459). + Respond correctly to FILE_STREAM_INFO requests; (bso#9460). + Users can not be given write permissions any more by default; (bso#9462). + Fix MMC crashes; (bso#9470). + Fix SEGV when using second vfs module; (bso#9471). + Support FIPS mode when building Samba; (bso#9479). + Fix ACL on "cn=partitions,cn=configuration"; (bso#9481).- netr_ServerPasswordSet2, netr_LogonSamLogon with netlogon AES broken; (bso#9438). - s3:auth: fix create_token_from_sid() to not fail in the winbindd case; (bso#9457). - s4:dsdb/acl_read: return the nTSecurityDescriptor attr if the sd_flags control is given; (bso#9470). - Support FIPS mode when building Samba; (bso#9479). - s4:provision: set the correct nTSecurityDescriptor; (bso#9481).- SEGV when using second vfs module; (bso#9471).- Update to 3.6.10. + Respond correctly to FILE_STREAM_INFO requests; (bso#9460). + Fix segfault when "default devmode" is disabled; (bso#9433). + Fix segfaults in "log level = 10" on Solaris; (bso#9390).- s3:smbd:vfs_acl: fix a PANIC when setting an ACL fails with ACCESS_DENIED; (bso#9456). - Install manpages only if we install the target; (bso#9459). - Users can not be given write permissions any more by default; (bso#9462).- Fix MD5 detection in the autoconf build; (bso#9037); (bso#9086); (bso#9094); (bso#9418). - Use work around for 'winbind use default domain' only if it is set; (bso#9367). - Allow smb2.acls torture test to pass against smbd with a POSIX ACLs backend; (bso#9374). - large read requests cause server to issue malformed reply; (bso#9422). - s3-rpc_client: lookup nametype 0x20 in rpc_pipe_open_tcp_port(); (bso#9426). - Fix ncacn_ip_tcp reconnection code for lsa lookups; (bso#9439). - Allow to force DNS updates using net; (bso#9451). - Respond correctly to FILE_STREAM_INFO requests; (bso#9460).- Update to 4.0.0rc6. See WHATSNEW.txt from the samba-doc package.- On uninstall remove winbind from the pam configuration, invalidate the nscd passwd and group cache and only recommend the install of nscd; (bnc#792340).- BuildRequire libnscd-devel once.- Remove obsoleted references to pre-9.4 SUSE systems; (bnc#792294). - Add SUSE version depending pkg-config requires macro; (bnc#792294).- Define library names and use it instead of libldb1, libnetapi0, libsmbclient0, libsmbsharemodes0, libtalloc2, libtdb1, libtevent0, and libwbclient0; (bnc#792294). - Provide and obsolete libsmbsharemodes for post-10.3 SUSE systems.- Don't clutter the spec file diff view; (bnc#783384).- Fix fd leak causing 100% CPU in winbind on certain dc connection failures; (bso#9436); (bnc#786677).- Fix spoolss segfault when default devmode is disabled; (bso#9433); (bnc#791183).- Update to 4.0.0rc5. See WHATSNEW.txt from the samba-doc package.- ACL masks incorrectly applied when setting ACLs; (bso#9236). - s3-kerberos: also try with AES keys, when decrypting tickets; (bso#9272). - lib/replace: replace all *printf function if we replace snprintf; (bso#9390). - lib/addns: don't depend on the order in resp->answers[]; (bso#9402).- s4:torture/smb2: improve the smb2.create.blob tes; (bso#9209). - lib/krb5_wrap: request enc_types in the correct order; (bso#9272). - Fix net ads join message for the dns domain; (bso#9326). - docs-xml: fix use of tag; (bso#9345). - s3-aio_pthread: Optimize aio_pthread_handle_completion; (bso#9359). - s3:winbind: Failover if netlogon pipe is not available; (bso#9386).- Execute the run_permissions macro on pre-11.4 systems and else the set_permission one if available.- Ensure adding the winbind group never can fail.- Create ntadmin group only if it doesn't yet exist.- Update to 3.6.9. + When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). + Winbind can't fetch user or group info from AD via LDAP; (bso#9147). + Fix segfault in smbd if user specified ports out for range; (bso#9218).- quota: Don't force the block size to 512; (bso#3272). - Fix poll replacement to become a msleep replacement; (bso#8107). - Fix wrong test == syntax in configure; (bso#8146). - Fix --with(out)-sendfile-support option handling in autoconf; (bso#8344). - Fix builtin forms order to match Windows again; (bso#8632). - Fix RAW printing for normal users; (bso#8769); (bnc#790741). - Initialise ticket to ensure we do not invalid memory; (bso#8788). - Fix 'net rpc share allowedusers' to work with 2008r2; (bso#8966). - Fix crash on null pam change pw response; (bso#9013). - Connection to outbound trusted domain goes offline; (bso#9016). - Increase debug level for info that the db is empty; (bso#9112). - 'smbclient' can't connect to a Windows 7 server using NTLMv2; (bso#9117). - Winbind can't fetch user or group info from AD via LDAP; (bso#9147). - Open printers with the right access mask; (bso#9154). - Fix makerpms.sh on RHEL; (bso#9165). - Remove non-existent option '-Y' from winbindd manpage; (bso#9171). - Add quota support for gfs2; (bso#9172). - Make SMB2 compound request create/delete_on_close/close work as Windows; (bso#9173). - Empty SPNEGO packet can cause smbd to crash; (bso#9174). - pam_winbind: Match more return codes when wbcGetPwnam has failed; (bso#9177). - Fix crash bug in idmap_hash; (bso#9188); (bnc#788159). - SMB2 Create doesn't return correct MAX ACCESS access mask in blob; (bso#9189). - Fix service control for non-internal services; (bso#9192). - Don't take 'state->te' as indication for "was_deferred"; (bso#9196). - Parse of invalid SMB2 create blob can cause smbd crash; (bso#9209). - Bad ASN.1 NegTokenInit packet can cause invalid free; (bso#9213). - Fix segfault in smbd if user specified ports out for range; (bso#9218). - Signing cannot be disabled for SMB2 by design, so fix the documentation instead; (bso#9222). - Fix NT_STATUS_IO_TIMEOUT during slow import of printers into registry; (bso#9231). - When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). - lib-addns: ensure that allocated buffer are pre set to 0; (bso#9259). - Make tdb robust against shrinking tdbs and improper CLEAR_IF_FIRST restart; (bso#9268). - Add support for reloading systemd services; (bso#9280).- Warn via the smbd log if AppArmor and "wide links" are in use; (bnc#783719).- Do not write the build date into the header of the default smb.conf as this causses superfluous rebuilds of packages depending on samba; (bnc#781601).- Do not prerequire SuSEconfig.permissions as it's already enough and more generic to depend on the permissions package; (bnc#782293).- Update to 3.6.8. + Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). + Fix Winbind panic if we couldn't find the domain; (bso#9135).- Backport FSCTL codes and fix segfault in smbstatus from master; (bso#9058). - Fix bad call to memcpy source3/registry/regfio.c; (bso#9065). - "Domain Users" incorrectly added as additional group on domain members; (bso#9066). - Use correct RID for "Domain Guests" primary group; (bso#9067). - Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). - Fix smbclient/tarmode panic when connecting to Windows 2000 clients; (bso#9088). - Fix refreshing of Kerberos tickets in Winbind; (bso#9098). - Fix identification of idle clients in Winbind to avoid crashes and NDR parsing errors; (bso#9104). - Fix compilation with newer MIT Kerberos which hides internal symbols; (bso#9111). - Fix flooding the logs with records we don't find in pcap; (bso#9112). - Initialize the print backend after we setup winreg; (bso#9122). - Fix lprng job tracking errors; (bso#9123). - Fix setting of "inherited" bit on inherited ACE's; (bso#9124). - Fix Winbind panic if we couldn't find the domain; (bso#9135). - Make 'smbclient allinfo' show the snapshot list; (bso#9137). - Fix nfs quota support with Linux nfs4 mounts; (bso#9144). - Valid open requests can cause smbd assert due to incorrect oplock handling on delete requests; (bso#9150).- NMB registration for a duplicate workstation fails with registration refuse; (bso#9085); (bnc#770056).- Remove backup files caused by running configure in examples/VFS.- Update to 3.6.7. + Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). + Fix migrating printers while upgrading from 3.5.x; (bso#9026).- Correct documentation of "case sensitive"; (bso#8552). - Printing fails in function cups_job_submit; (bso#8719). - Fix kernel oplocks when uid(file) != uid(process); (bso#8974). - Send correct responses to NT Transact Secondary when no data and no params for the Trans2 calls are set; (bso#8989). - Fix build without ads support; (bso#8996). - Don't turn negative cache entries into valid idmappings; (bso#9002). - Fix posix acl on gpfs; (bso#9003). - Make vfs_gpfs less verbose in get/set_xattr functions; (bso#9022). - Fix migrating printers while upgrading from 3.5.x; (bso#9026). - Fix typo in set_re_uid() call when USE_SETRESUID selected in configure; (bso#9034). - Using asynchronous IO with SMB2 can return NT_STATUS_FILE_CLOSED in error instead ofNT_STATUS_FILE_LOCK_CONFLICT; (bso#9040). - Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). - Fix build against CUPS 1.6; (bso#9055). - Fix bugs in SMB2 credit handling code; (bso#9057). - rpcclient: Fix bad call to data_blob_const; (bso#9062).- Create missing doc directories while install. - Remove no longer existing Manifest file from install. - Don't creat a link to non existend html man pages for swat. - Don't call the no longer existing libsmbclient testsuit while build.- Configure with option --mandir instead --with-mandir. - Remove obsoleted --with-rootsbindir, --with-nmbdsocketdir, and - -with-swatdir configure options.- Update to 4.0.0beta4. See WHATSNEW.txt from the samba-doc package.- BuildRequire gcc, make, and patch; (bnc#771516).- ndr: fix push/pull DATA_BLOB with NDR_NOALIGN; (bso#9026); (bnc#770262).- Fix shell syntax in dhcpcd hook script; (bnc#769957).- Add missing int declaration to the net kdc lookup patch.- Update to 4.0.0beta2. See WHATSNEW.txt from the samba-doc package.- Update to 3.6.6. + Fix possible memory leaks in the Samba master process; (bso#8970). + Fix uninitialized memory read in talloc_free(); (bnc#764577). + Fix joining of XP Pro workstations to 3.6 DCs; (bso#8373); (bnc#787983).- resolve_ads() code can return zero addresses and miss valid DC IP addresses; (bso#8910). - Can't join XP Pro workstations to 3.6.1 DC; (bso#8373); (bnc#787983). - winbind can hang as nbt_getdc() has no timeout; (bso#8953). - Fix crash bug in dns_create_probe when dns_create_update fails; (bso#8627) - s3-pid: Catch with pid filename's change when config file is not smb.conf; (bso#8714). - Possible memory leaks in the main Samba process; (bso#8970). - s3: Fix uninitialized memory read in talloc_free(); (bnc#764577). - Treat exit_server_cleanly() as a "clean" shutdown; (bso#8971). - Avoid crash with MIT krb5 1.10.0 in gss_get_name_attribute(); (bso#8988). - Winzip occasionally can not read files out of an open winzip dialog; (bso#8311). - s3-winbindd: call dump_core_setup after command line option has been parsed; (bso#8975). - Directory group write permission bit is set if unix extensions are enabled; (bso#8972). - s3: remove dependency on automake for "make everything"; (bso#8978). - sd_has_inheritable_components segfaults on an SD that se_access_check accepts; (bso#8811). - smbclient's tarmode insists on listing excluded directories; (bso#8922). - Notify code can miss a ChDir; (bso#8998). - s3:smbd: add a fsp_persistent_id() function; (bso#8995).- Call autogen.sh even on post-12.1 SUSE systems.- Don't call autogen.sh on post-12.1 SUSE and post-14 Fedora systems. - Recompile all IDL in any case.- BuildIgnore libtalloc and libtdb to prevent a package conflict on Fedora systems.- Install talloc.pc only on pre-12.2 and non SUSE systems.- BuildRequire libldb-devel, libtalloc-devel, libtdb-devel, and libtevent-devel on post-12.1 systems.- s3: Fix a segfault with debug level 3 on Solaris; (bso#8861). - s3: wbinfo --lookup-sids "" crashes winbind; (bso#8904). - smbd crashes when deleting directory and veto files are enabled; (bso#8837). - winbind_krb5_locator only returns one IP address; (bso#8897). - Wrong assertion/comparison: Compare value not pointer; (bso#8859). - Inconsistent (with manpage) command-line switch for "help" in smbtree; (bso#8831). - Fix incorrect debug statement. - Setting traverse rights fails to enable directory traversal when acl_xattr in use; (bso#8857). - Syslog broken owing to mistyping of debug_settings.syslog; (bso#8877). - s3/ldap: remove outdated netscape ds 5 schema file; (bso#8869). - s3-docs: fixes several typos; (bso#7938). - s3-VFS: Fix building out-of-tree modules; (bso#8822). - s3-docs: Add hint that setting "profile acls = yes" on normal shares can cause trouble; (bso#7930). - s3-pam_winbind: Fix the build with a newer iniparser library; (bso#8915). - Avoid null dereference in initialize_password_db(); (bso#8920). - s3:registry: implement values_need_update and subkeys_need_update in the smbconf backend. - s3:registry:reg_api: fix reg_queryvalue to not fail when values are modified while it runs. - s4:torture:rpc:spoolss: also initialize driverName before checking it in test_PrinterData_DsSpooler(). - s3:registry: multiple cleanups, fixes, and optimisations. - s3:auth/server_info: the primary rid should be in the groups rid array; (bso#8798). - s3-printing: Add new printers to registry; (bso#8554); (bso#8612); (bso#8748). - Fix the overwriting of errno before use in a DEBUG statement and use the return value from store_acl_blob_fsp rather than ignoring it; (bso#8945). - s3-auth: Don't lookup the system user in pdb; (bso#8944). - s3-passdb: Fix negative SID->uid/gid cache handling; (bso#8952). - Fix typo in pam_winbindd code; (bso#8957). - Fix remove_duplicate_addrs2 previously it could leave zero addresses in the list; (bso#8910). - Slow but responsive DC can lock up winbindd; (bso#8943). - Broken processing of %U with vfs_full_audit when force user is set; (bso#8882).- Disable included build of ldb, talloc, tdb, and tevent on post-12.1 systems. - BuildRequire libldb1-devel, libtalloc2-devel, libtdb1-devel, and libtevent0-devel on post-12.1 systems.- Add PreReq /etc/init.d/nscd to the winbind package; (bnc#759731).- docs-xml: fix default name resolve order; (bso#7564). - s3-aio-fork: Fix a segfault in vfs_aio_fork; (bso#8836). - docs: remove whitespace in example samba.ldif; (bso#8789). - s3-smbd: move print_backend_init() behind init_system_info(); (bso#8845); (bnc#730769). - s3-docs: Prepend '/' to filename argument; (bso#8826).- Update to 3.6.5. - Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; (bnc#757576).- Remove all precompiled idl output to ensure any pidl changes take effect; (bnc#757080).- Update to 3.6.4. - Samba pre-3.6.4 are affected by a vulnerability that allows remote code exe- cution as the "root" user; PIDL based autogenerated code allows overwriting beyond of allocated array; CVE-2012-1182; (bso#8815); (bnc#752797).- s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; (bso#8599). - Correctly handle DENY ACEs when privileges apply; (bso#8797).- s3:smb2_server: fix a logic error, we should sign non guest sessions; (bso8749). - Allow vfs_aio_pthread to build as a static module; (bso#8723). - s3:dbwrap_ctdb: return the number of records in db_ctdb_traverse() for persistent dbs; (#bso8527). - s3: segfault in dom_sid_compare(bso#8567). - Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER; (bso#8768). - s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path; (bso#8771). - s3-winbindd: set the can_do_validation6 also for trusted domain; (bso#8599). - Fix problem when calculating the share security mask, take priviliges into account for the connecting user; (bso#8784).- Fix crash in dcerpc_lsa_lookup_sids_noalloc() with over 1000 groups; (bso#8807); (bnc#751454).- Remove obsoleted Authors lines from spec file for post-11.2 systems.- Make ldapsmb build with Fedora 15 and 16; (bso#8783). - BuildRequire libuuid-devel for post-11.0 and other systems. - Define missing python macros for non SUSE systems. - PreReq to fillup_prereq and insserv_prereq only on SUSE systems. - Always use cifstab instead of smbfstab on non SUSE systems.- Ensure AndX offsets are increasing strictly monotonically in pre-3.4 versions; CVE-2012-0870; (bnc#747934).- Add SERVERID_UNIQUE_ID_NOT_TO_VERIFY; (bso#8760); (bnc#741854).- s3-printing: fix crash in printer_list_set_printer(); (bso#8762); (bnc#746825).- s3:winbindd fix a return code check; (bso#8406).- s3: Add rmdir operation to streams_depot; (bso#8733).- s3:smbd:smb2: fix an assignment-instead-of-check bug conn_snum_used(); (bso#8738); CVE-2013-0454; (bnc#811975).- s3:auth: fill the sids array of the info3 in wbcAuthUserInfo_to_netr_SamInfo3(); (bso#8739).- s3:client: ignore SMBecho errors (the server may not support it); (bso#8139).- Be more strict when using PAM_AUTH API from winbind if Kerberos auth is enabled and don't unintentionally use a bogus domain name; (bso#8734).- smbclient fails with posix large reads; (bso#8727).- Use the smbfs init script on versions pre-11.3, or cifs in later versions; (bnc#744614).- s3: Compile IDL files in autogen, some configure tests need this.- Fixes various deadlocks in if-up.d / if-down.d when running under systemd; (bnc#732395).- Update to 3.6.3. + Fix memory leak in parent smbd on connection; CVE-2012-0817; (bso#8724); (bnc#743986).- Use spdx.org compliant license names for all packages.- Update to 3.6.2. + Make Winbind receive user/group information (bug #8371). + Several SMB2 fixes. + Fix a crash bug in the spoolss code. + Add new contributing FAQ announcing acceptance of corporate (C). + DeletePrinterDriverEx deletes files in use; (bso#4942); (bnc#742504). + Fix cli_write_and_x() against OS/2 print shares; (bso#5326). + Fix 'smbclient tar' for files greater than 8GB on BE machines; (bso#563); (bnc#726145). + Remove pointless use_memory_krb5_ccache; (bso#7465). + Fix perl path; (bso#8176). + Grant credits in async interim responses (SMB2); (bso#8357). + Make Winbind receive user/group information; (bso#8371). + Fix Windows XP clients crashing smbd process every once in a while; (bso#8384); (bnc#731571). + Make VFS op "streaminfo" stackable; (bso#8419). + Add an allocation pool to idmap_autorid; (bso#8444). + Fix SEGFAULT from net registry export on not zero terminated REG_SZ values; (bso#8528). + Make DSO_EXPORTS_CMD more portable; (bso#8531). + readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). + smbclient posix_open command fails to return correct info on open file; (bso#8542). + winbind_samlogon_retry_loop ignores logon_parameters flags; (bso#8548). + Fix setting the machine account password; (bso#8550). + Make SMB2 handle compound request headers in the same way as Windows; (bso#8560). + Password change settings not fully observed; (bso#8561). + Fix double free error in talloc; (bso#8562). + Fix alignment in the non-extended-security negprot; (bso#8573). + Add systemd service files; (bso#8575). + Add systemd service files; (bso#8575). + smb2_flush: Don't send uninitialized memory; (bso#8579). + Enable inotify if sys or kernel inotify is available; (bso#8580). + Increase a debug level; (bso#8585). + libsmb: Only align unicode pipe_name; (bso#8586). + Fix marshalling of samr_ChangePasswordUser3; (bso#8591). + Don't limit the number of open dptrs for SMB2; (bso#8592). + Fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). + Make cldap work over IPv6; (bso#8600). + Fix intermittent print job failures caused by character conversion errors; (bso#8606). + Improve configure.in so it can be used outside the Samba source tree; (bso#8607). + Winbind: Don't fail on users without a uid; (bso#8608). + Ensure we correctly calculate reply credits over all returned SMB2 replies; (bso#8614). + Fix migrate printer code; (bso#8618). + Fix crash bug when trying to browse Samba printers; (bso#8623). + libsmb: Don't duplicate Kerberos service tickets; (bso#8628). + POSIX ACE x permission becomes rx following mapping to and from a DACL; (bso#8631). + When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636). + Fix the vfs_commit module; (bso#8639). + Add an update function for Winbind cache; (bso#8643). + vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). + Document the "ignore system acls" option of vfs_acl_xattr and vfs_acl_tdb vfs modules; (bso#8652). + Fix deleting a symlink if the symlink target is outside of the share; (bso#8663). + Fix renaming a symlink if the symlink target is outside of the share; (bso#8664). + Fix NT ACL issue; (bso#8673). + Fix buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). + Fix Winbind segfault if we can't map the last user; (bso#8678). + recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). + Try ctdbd_init_connection() as root; (bso#8684). + Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686). + Fix typo in 'net memberships' usage; (bso#8687). + libads: Fix malloc/talloc mismatch in ads_keytab_verify_ticket(); (bso#8692). + Make DeletePrinterDriverEx remove printer driver files; (bso#8697) (bnc#740810). + Fix major leak with SMB2 in connections.tdb; (bso#8710).- s3-spoolss: Pass the right pointer type; (bso#4942); (bnc#742504).- Use correct license, LGPLv3+ for libwbclient packages.- When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636).- Fix incorrect types in the full_audit VFS module. Add null terminators to audit log enums; (bnc#742885).- Prefix print$ path on driver file deletion; (bso#8697); (bnc#740810). - Fix printer_driver_files_in_use() call ordering; (bso#4942); (bnc#742504).- Buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). - NT ACL issue; (bso#8673). - Deleting a symlink fails if the symlink target is outside of the share; (bso#8663). - connections.tdb - major leak with SMB2; (bso#8710).- Renaming a symlink fails if the symlink target is outside of the share; (bso#8664).- Intermittent print job failures caused by character conversion errors; (bso#8606). - ads_keytab_verify_ticket mixes talloc allocation with malloc free; (bso#8692). - libcli/cldap: fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). - s3:lib/ctdbd_conn: try ctdbd_init_connection() as root; (bso#8684). - s3-printing: fix migrate printer code; (bso#8618). - Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686).- net memberships usage info was wrong; (bso#8687). - s3-libsmb: Don't duplicate kerberos service tickets; (bso#8628). - Recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). - s3-winbind: Fix segfault if we can't map the last user; (bso#8678). - vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). - s3/doc: document the ignore system acls option of vfs_acl_xattr and vfs_acl_tdb; (bso#8652). - Winbind can't receive any user/group information; (bso#8371). - s3-winbind: Add an update function for winbind cache; (bso#8643). - s3: Attempt to fix the vfs_commit module. - POSIX ACE x permission becomes rx following mapping to and from a DACL; (#bso#8631). - s3:libsmb: only align unicode pipe_name; (bso#8586). - s3-winbind: Don't fail on users without a uid; (bso#8608). - Crash when trying to browse samba printers; (bso#8623). - talloc: double free error; (bso#8562). - cldap doesn't work over ipv6; (bso#8600). - s3:libsmb: fix cli_write_and_x() against OS/2 print shares; (bso#5326). - SMB2: not granting credits for all requests in a compound request; (bso#8614). - smb2_flush sends uninitialized memory; (bso#8579). - Password change settings not fully observed; (bso#8561). - s3:smb2_server: grant credits in async interim responses; (bso#8357). - s3:smbd: don't limit the number of open dptrs for smb2; (bso#8592). - samr_ChangePasswordUser3 IDL incorrect; (bso#8591). - idmap_autorid does not have allocation pool; (bso#8444). - Add systemd service files. - s3:libsmb: the workgroup in the non-extended-security negprot is not aligned; (bso#8573). - s3-build: Fix inotify detection; (bso#8580). - SMB2 doesn't handle compound request headers in the same way as Windows; (#bso8560). - Disconnecting clients swamp the logs; (bso#8585). - s3-netlogon: Fix setting the machinge account password; (bso#8550). - winbind_samlogon_retry_loop ignores logon_parameters flags; (#bso8548). - smbclient posix_open command fails to return correct info on open file; (bso#8542). - readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). - s3-netapi: remove pointless use_memory_krb5_ccache; (bso#7465). - s3:Makefile: make DSO_EXPORTS_CMD more portable; (bso#8531). - s3:registry: fix the test for a REG_SZ blob possibly being a zero terminated ucs2 string; (bso#8528). - Make VFS op "streaminfo" stackable; (bso#8419).- Fix incorrect perfcount array length calculations; (bnc#739258).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems.- Remove call to suse_update_config macro for post-11.4 systems.- Use samba.org for the ldapsmb source location.- Fixing libsmbsharemode dependency on ldap and krb5 libs in Makefile; (bnc #729516).- Do not map POSIX execute permission to Windows FILE_READ_ATTRIBUTES; (bso#8631); (bnc#732572).- Add ldap to Should-Start and Stop of the smb init script; (bnc#730046).- Fix smbd srv_spoolss_replycloseprinter() segfault; (bso#8384); (bnc#731571).- Fix pam_winbind.so segfault in pam_sm_authenticate(); (bso#8564).- Fix smbclient >8GB tars on big endian machines; (bso#563); (bnc#726145).- Fix typo in net ads join output; (bnc#713135).- Ignore a potentially missing AppArmor snippet helper script; (bnc#725256).- Update to 3.6.1. + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Several SMB2 fixes. + The VFS ACL modules are no longer experimental but production-ready. + Fix 'net ads join -k' when KRB5CCNAME is not set; (bso#7465). + smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509). + Return error of cli_push when 'put - /some/file' is used; (bso#7551). + Fix usage of cli_errstr(); (bso#7864). + Fix 'widelinks' regression; (bso#8229). + Empty notify servername; (bso#8236). + Add man vfs_aio_fork; (bso#8256). + smb2: smbd logs "Invalid SMB packet: first request: 0x0008" and crashes; (bso#8334). + Add a fallback for missing open&x support in MAC OS/X Lion; (bso#8338). + While migrating forms, don't fail if the form already exists; (bso#8351). + OS/2 sends an unexpected write&x/read&x chain; (bso#8360). + Fix build of vfs_prealloc on SLES8; (bso#8363). + Fix the build of gpfs.c on RHEL 6.0 with gpfs 3.4.0-4; (bso#8364). + Fix the fallback to the deprecated spelling idmap:script; (bso#8368). + Fix vfs_chown_fsp; (bso#8370). + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix smbclient access to NT4 shares; (bso#8385). + Optimize serverid_exists() for Solaris; (bso#8395). + registry/reg_format.c must include includes.h; (bso#8401). + SMB2 server can return requests out-of-order when processing a compound request; (bso#8407). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Fix "saving as" of MS Office 2007 (Word) documents on Samba shares with SMB2; (bso#8412). + Fix 'getent group' if trusted domains are not reachable; (bso#8420). + Fix infinite loop in ACL module code; (bso#8422). + Fix wrong reply to DHnC (durable handle reconnect); (bso#8428). + Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429). + Fix segfault in iconv.c; (bso#8433). + NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442). + Be smarter about setting default permissions when a ACL_USER_OBJ isn't given; (bso#8443). + Check the wct of the incoming SMBnegprot responses; (bso#8452). + Fix smbclient segfaults when dialect option -m is used for legacy dialects; (bso#8453). + Fix uninitialized memory problem in group_sids_to_info3; (bso#8455). + Samba PDC is looking up only primary user group; (bso#8455). + IE9 on Windows 7 cannot download files to samba 3.5.11 share; (bso#8458). + smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473). + SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474). + Don't call smbd_terminate_connection in smb2_validate_message_id(); (bso#8476). + Samba asserts when SMB2 client breaks the crediting rules; (bso#8476). + Map to guest can return uninitialized blob of data; (bso#8477). + acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480). + DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493). + Remove "experimental" label on VFS ACL modules; (bso#8494). + SMB2_OP_CANCEL requests don't have to be signed; (bso#8503). + smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507). + Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509). + Disallow "." in can_set_delete_on_close(); (bso#8515). + SMB2 create call returns incorrect file allocation size; (bso#8518). + Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520). + Winbind cache timeout expiry test was reversed; (bso#8521).- s3/doc: add man page for aio_fork vfs module.- Fix uninitialized memory problem in group_sids_to_info3; (bso#8455).- s3: Samba PDC is looking up only primary user group; (bso#8455).- Add script to create or update an AppArmor sniplet with permissions for all Samba shares; (bnc#688040).- Add "ldapsam:login cache" parameter to allow explicit disabling of the login cache; (bnc#723261).- Retain the smbd startproc return value for correct startup status reporting. unset was incorrectly being called prior to rc_status; (bnc#723724).- Prevent deadlock in systemd triggered by if-down.d handler on shutdown; (bnc#721598).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; changed defaults and documentation (bso8473).- Empty CIFS share can be blocked for other clients by deleting it via empty path (DELETE_PENDING until the last client); (bso#8515).- winbindd cache timeout expiry test was reversed; (bso#8521).- Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520).- s3:smb2_create: fix allocation size return value when opening existing files; (bso#8518).- SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474).- NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442).- s3-docs: Fix bug (bso#7908) and typo.- Return error of cli_push when 'put - /some/file' is used; (bso#7551).- Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509).- smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507).- Default user entry is set to minimal permissions on incoming ACL change with no user specified; (bso#8443).- smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509).- Handle the SECINFO_LABEL flag in the same was as Win2k3; enable Microsoft Internet Explorer 9 on Windows 7 to download files; (bso#8458).- DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493).- s3-docs: Fix typos.- s3:smb2_server: SMB2_OP_CANCEL requests don't have to be signed; (bso#8503).- Remove "experimental" label on VFS ACL modules; (bso#8494).- acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480).- s3-smbd: asserts when SMB2 client breaks the crediting rules; (bso#8476).- s3-libnet: allow to use default krb5 ccache in libnet_Join/libnet_Unjoin; (bso#7465).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473).- s3-netapi: allow to use default krb5 credential cache for libnetapi users.- s3-docs: document -k switch in net manpage.- Map to guest can return uninitialized blob of data; (bso#8477).- s3-registry: registry/reg_format.c must include includes.h; (bso#8401).- smbclient segfaults when option -m is used for legacy dialects; (bso#8453).- Fix 'widelinks' regression intro'd in 3.2; (bso#8229).- Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429).- s3-spoolss: Fix bug forms migration; (bso#8351).- s3:libsmb: check the wct of the incoming SMBnegprot responses; (bso#8452).- s3: Do not fork the echo handler for smb2; (bso#8334).- s3-spoolss: Fix bug empty notify servername; (bso#8236).- SMB2 server can return requests out-of-order when processing a compound request; (bso#8407).- Remove smb child crash fix. The issue had been fixed upstream differently.- BuildRequire ctdb-devel version greater than 1.0.105 for post-10.0 systems.- Fix samba duplicates file content on appending. Move posix case semantics out from under the VFS; (bso#6898); (bnc#681208).- Make winbind child reconnect when remote end has closed, fix failing sudo; (bso#7295); (bnc#569721).- Spec file cleanup as suggested by the spec-cleaner tool. + Make all BuildRequires, PreReq, and Provides a separate line. + Use %{buildroot} instead of ${RPM_BUILD_ROOT}. + Use straight commands instead of macros (make, install). + Use -p in post and postun if we only call one command. + Use %{_localstatedir} instead of %{_var} in the filelist. + Remove superfluous AutoReqProv on lines.- Remove %release from all Provides.- Fix segfault in iconv.c which caused a null pointer dereference; (bso#8433).- Use /var/run for the cifs state file in the init script too; (bnc#710304).- Microsoft Word from Microsoft Office 2007 fails to save as on a share with SMB2; (bso#8412).- Use sys_write and sys_read in fork_domain_child to fix a winbind race leading to 100% CPU usage; (bso#8409).- Fix wrong reply to smb2 durable handle reconnect (DHnC) request; (bso#8428).- Fix infinite loop in ACL module code; (bso#8422).- Fix getent group if trusted domains are not reachable; (bso#8420).- smbclient can't access a NT4 share since 3.6.0; (bso#8385).- Optimize serverid_exists() for Solaris; (bso#8395).- talloc: + check block count after references test. + added test suite for talloc_free_children(). + license info erratum in the manpage. + fix typos and better differentiation between versions 1 and 2. + preserve context name on talloc_free_children(). + ensure the sibling linked list remains valid during a free.- vfs_chown_fsp returned in the wrong directory; (bso#8370).- Remove irritating "." targets when recent system libs exist; (bso#8369).- Correctly initialize "idmap config * : script" with NULL; (bso#8368).- Add missing include to suppress compiler warnings; (bso#8365).- Point the chain offset beyond the current request; (bso#8360).- Fix gpfs vfs module build; (bso#8364).- Make vfs_prealloc even build on older systems; (bso#8363).- Do central cli_set_error and return the actual NTSTATUS; (bso#7864).- Add a fallback for missing open&x support in OS/X Lion; (bso#8338).- Update to 3.6.0. + BUG 7462: Make SA_RESETHAND conditional on its existance. + BUG 8303: db_ctdb_send_schedule_for_deletion() is not defined. + BUG 8324: smbclient cannot list directories from a big-endian machine. + BUG 8326: WinXP cannot join a Samba3 domain with a 'even' hostname. + BUG 8327: Fix the reload of the configuration, also reload activated registry shares. + BUG 8328: Cleanup of idmap_tdb2 code. + BUG 8330: Fix NFSv4 ACL merging logic. + BUG 8335: File copy aborts with smb2_validate_message_id: bad message_id. + BUG 8341: Fix segfault in libsmbclient. + BUG 8343: Fix SMB2 crash reading with aio_fork beyond the end of file. + BUG 8347: Fix regression for HP-UX, AIX and OSF. + BUG 8357: Make sure we grant credits on async read/write operations. + BUG 8358: Fix a bug in run_poll_events(). + BUG 8362: Fix build issue on old glibc systems.- Remove references to disabled vscan build.- Add missing define, includes, and initialization to get_printing_ticket.- Use /var/run for the cifs state file; (bnc#710304).- Fix #ifdef CTDB_CONTROL_SCHEDULE_FOR_DELETION issue; (bso#8303).- File copy aborts with smb2_validate_message_id: bad message_id; (bso#8335).- Fix reload of the configuration and also reload activated registry shares; (bso#8327).- WinXP cannot join a Samba3 domain with a 'even' hostname; (bso#8326).- smbclient cannot list directories from a big-endian machine; (bso#8324).- Update to 3.6.0rc3. + BUG 7841: Explicitly pass domain_sid to wbint_LookupRids(). + BUG 7888: Deal with buggy 3.0 based PDCs. + BUG 8083: Fix "inherit owner = yes" with vfs_acl_xattr or vfs_acl_tdb module. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8193: Add new command 'enumerate_recursive'. + BUG 8195: Make rpc client code working against NT4 servers. + BUG 8211: Fix "inherit owner = yes" when "inherit permissions = yes" is set. + BUG 8213: Fixes in idmap_autorid. + BUG 8214: Fix smbd crash on printer driver upgrade. + BUG 8215: Fix Winbind unix username lookup. + BUG 8216: Make Winbind returning correct results with 'sids2xids'. + BUG 8217: Do not stat-check the share path in 'net conf addshare'. + BUG 8219: Fix SMB Panic from Windows 7 client. + BUG 8224: Fix the build on FreeBSD. + BUG 8226: Use c99 initializers which are supported by old gcc 2.95 compilers. + BUG 8230: Move .nmbd socket directory to non-hidden name PREFIX/var/nmbd. + BUG 8231: Fix crash bug in 'net cache get'. + BUG 8235: Fix smbd crash on startup caused by migrate_printer(). + BUG 8240: Fix Valgrind warnings in winreg/spoolss code. + BUG 8244: Fix copying files larger than 2 GB to a Samba share. + BUG 8247: Fix Coverity ID 2582: FORWARD_NULL. + BUG 8253: Fix Winbind panic if verify_idpool() fails. + BUG 8254: Fix "acl check permissions = no". + BUG 8260: Fix DCERPC responses with fragments larger than 1024 bytes. + BUG 8262: Fix build of vfs_commit. + BUG 8263: Fix build with --with-fake-kaserver or --with-vfs-afsacl. + BUG 8264: Fix Valgrind bugs in svcctl. + BUG 8276: Close all sockets attached to a subnet in close_subnet(). + BUG 8278: Fix smbd panic when CTDB is unhealthy. + BUG 8281: Fix build of examples/VFS/*. + BUG 8286: Fix smbd crash on premature end of smb2 conn. + BUG 8292: Fix a major architectural flaw in the SMB2 server code. + BUG 8293: Fix log file rotating in SMB2. + BUG 8304: Fix uninitialized variable in error path. + BUG 8305: Fix segfault in nmbd when using 'smbtree ...'.. + BUG 8307: brl_close_fnum does not call SMB_VFS_BRL_UNLOCK_WINDOWS on all locks. + BUG 8310: toupper_ascii() is broken on big-endian systems. + BUG 8314: Fix smbd crash with unknown user. + Mark 'time offset' parameter as deprecated.- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site scripting vulnerability; CVE-2011-2694; (bso#8289); (bnc#708503).- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site request forgery; CVE-2011-2522; (bso#8290); (bnc#705241).- Fixed the DFS referral response for msdfs root; (bnc#703655).- Fix CUPS print job IDs; (bso#7288); (bnc#701257).- Make use of the actual library version as part of the package name on post-11.3 systems only.- Fix winbind internal error; (bso#7636); (bnc#659424).- Improve ctdb vacuuming performance with use of SCHEDULE_FOR_DELETION; (bnc#705170).- Specify nmbdsocketdir at configure time; (bnc#700953).- Build the tdb, talloc, and tevent libraries ahead of anything else.- Update to 3.6.0rc2. + BUG 6911: Fix Kerberos authentication from Vista to Samba. + BUG 8166: Don't lockout users when offline. + BUG 8200: Add support for multiple writeable ldap idmap domains. + BUG 8148: Default to protocol version 2 for SMB Traffic Analyzer. + BUG 7054: Fix X account flag when "pwdlastset" is "0". + BUG 8144: Fix setting timestamp when touching files with CIFS clients. + BUG 8153: Fix setting up getaddrinfo on IPv6-only machines. + BUG 8156: Fix 'net ads join' using the user's Kerberos ticket. + BUG 8157: Fix parsing a cups printcap file. + BUG 8175: Fix smbd deadlock. + BUG 8189: Support shadow copy display over SMB2. + BUG 8197: Winbind does not properly detect when a DC connection is dead. + BUG 8203: Winbind needs to reset the DC connection if an RPC times out.- Make cupsaddsmb fill printers location; (bso#8132); (bnc#698209).- Add "winbind max clients" parameter to remove 200-client limit; (bnc#697461).- Disable logon cache for password lockout consistency when running in a cluster; (bnc#694836).- Fix logon of AD users with many group memberships; (bso#6911); (bnc#657026).- Don't lockout users while offline; (bso#8166); (bnc#692607).- Update to 3.6.0rc1. + BUG 8111: CIFS VFS: Fix unexpected error on SMB posix open. + BUG 8112: POSIX extension opens of a directory are denied with EISDIR. + BUG 8132: Fix filling printers location field when using cups. + Remove fstrings from client struct. + BUGFIX when converting from safe_strcpy to strlcpy. + Fix off-by-one calculations with strlcpy. + Ensure we always write the correct incoming mid into the share mode table entries. + Fix the SMB2 oplock showstopper. + Convert user-specified domain to uppercase in libsmb. + Fix Coverity CID #2302: FORWARD_NULL. + Fix cups_pull_comment_location(). + Fix double free of cups request. + Make cups_pull_comment_location() work again. + Fix potential crash bug in display_print_driver3(). + Properly clean up in pthreadpool_init in case of failure. + Make plaintext session setup async. + Reduce fd load in Winbind children. + Avoid a potential 100% CPU loop in Winbind. + Tune broadcast namequeries for unique names. + Properly deal with exited winbind children. + Fix dup_smb2_vec3. + Fix return check in nss_wins.- Fix to renew the kerberos ticket in samba after expiry; (bnc#669949).- Fix a 100% CPU loop when ctdbd dies during a traverse; (bnc#693945).- Make dhcpcd hook BOOTPROTO check cover dhcp6 too; (bnc#691969).- Handling of large (> 256 bytes) ntlmv2 blobs in winbind; (bnc#529946).- Package static libraries with 0644 permissions.- Add Requires libtalloc-devel to libldb-devel and libtevent-devel.- Rename libldb0 to libldb1 as 1 is the current major version of the library. - Add libldb1 and libtevent0 to baselibs.conf.- Don't call the suse_update_config macro before building lib ldb and tevent.- Update to 3.6.0pre3. + Listen on IPv6 addresses with IPV6_ONLY; (bso#7383). + Fix wrong output in 'smbget'; (bso#8066). + "inherit owner = yes" doesn't interact correctly with vfs_acl_xattr or vfs_acl_tdb module; (bso#8083). + rpccli_samr_chng_pswd_auth_crap segfaults if any input blobs are null; (bso#8088). + setpwent() actually does endpwent() and vice versa on FreeBSD; (bso#8099). + Fix the build of 'smbget' on HP NonStop; (bso#8106). + Fix build of tdb2. + Correctly detect and deny symlinks anywhere in a path (not just the last component) if "follow symlinks = no". + Fix timeout in rpc_pipe_open_tcp_port(). + Fix the build of "--with-profiling-data". + Fix Coverity IDs 986, 1340, 2047, 2299, 2307, 2325, 2335, 2336, 2470, 2471, 2478. + nsswitch: Add 'wbinfo --lookup-sids'. + nsswitch: Add 'wbinfo --sids-to-unix-ids'. + Fix smbd with the async echo responder. + Fix the build of vfs_gpfs.c. + Add a 10-second timeout for the 445 or netbios connection to a DC. + Many pthreadpool fixes. + Fix transaction recovery area for converted tdbs.- Add PreReq permissions to the krb-printing package.- Remove _libdir ldb and tevent from file list. - Explicitly state not to bundle talloc or tdb while ldb and tevent build.- Always use the actual library version as part of the package name. - Exclude shared python modules.- Fix printing from Windows 7 clients; (bso#7567); (bnc#687535).- Update pidl and always compile IDL at build time; (bnc#688810).- Update to 3.6.0pre2. + ID Mapping changes. + Implement SMB2 support. + Add an Endpoint Mapper daemon. + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Quota only shown when logged as root; (bso#7080). + Fix printing from Windows 7; (bso#7567). + Retry DNS updates when connection to one nameserver has failed; (bso#7690). + Unlink may unlink wrong file when hardlinks are involved; (bso#7863). + Fix 'nmbd --port'; (bso#7875). + cmd_spoolss_deletedriver() returned without checking all architectures; (bso#7880). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix cups pcap reload with no printers; (bso#7915). + Fix bug in chain_reply; (bso#7917). + Fix problems with "kernel oplocks" option set to "no"; (bso#7928). + Fall back for utimes calls; (bso#7940). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let winbind try to use samlogon validation level 6; (bso#7945). + Sgid bit lost on folder rename; (bso#7996). + Fix getting username in 'net rap session'; (bso#8009). + Fix inode generation so nautilus can count total dir size correctly; (bso#8010). + Use jenkins hash for str_checksum; (bso#8010). + Add explicit configure option whether or not to enable dmapi support; (bso#8033). + Fix smbclient segfault with Cyrillic netbios names; (bso#8040). + Fix file creation on OS/X; (bso#8042). + Add "--option" to 'testparm'. + Fix crash bug on smbd shutdown when using FOPENDIR(). + Ensure we don't return an incorrect access mask. + Fix bug against the new Mac client. + Fix leak in error path. + Fix error where Windows client spoolss returns WERR_INVALID_DATA. + Fix a segfault in the krb5 locator plugin. + Enable sharesec for registry shares. + Fix memory leak in "security=share" and "force user". + Add "net idmap check", a check and repair tool for the id mapping database. + Add new 'net idmap delete' command. + Fix segfault on missing input file in 'net idmap restore'. + Fix 'net usersidlist' not to skip every other user. + Fix potential crash bug in spoolss_PrinterEnumValues push path. + Internal restructuring. + Don't wipe out all printer drivers when only one should be deleted. + Fix winbindd_dual_pam_auth_samlogon() for NT4 domains. + Fix memory leak in print_cups.c. + Remove duplicate cups response processing code. + Follow force user/group for driver IO. + Initiate pcap reload from parent smbd. + Reload shares after pcap cache fill. + Fix numerous Coverity IDs (2041 and others). + Fix a memory leak in check_sam_security_info3. + Fix a segfault in the nss wrapper when libnss_winbind.so is not loadable. + Make "net sam list [users|workstations]" list only the right things. + Fix a potential memleak in secrets_fetch_trusted_domain_password. + Use the right credentials in check_netlogond_security. + Add support for AF_NETLINK addr notifications. + Fork multiple Winbind children per domain. + Fix a deadlock between smbd and ctdbd. + Add 'wbinfo --dc-info'. + Make "nmbd socket dir" configurable. + Fixed valgrind errors. + Fix a memleak in receive_getdc_response. + Don't grant SEC_STD_DELETE always to the owner of a file. + Fix segfaults on addrchange errors in Winbind. + Allow machine accounts as members in groupdb. + Add IPv6 support for the endpoint mapper. + Free unused memory in the rpc server. + Fix possible segfaults in svcctl server. + Fix possible segfault with client_id in rpc server. + Add a 'svcctl shutdown' function to rpc server. + Fix a resource leak in net_afs. + Fix a resource leak in smbta-util. + Fix possible resource leak in net_usershare. + Fix possible resource leak in 'smbget'. + Fix possible resource leak in 'smbfilter'. + Fix a possible null pointer dereference in smbd. + Ensure we send the direct levelII oplock break to the correct fid. + Fix private libdir and codepages paths. - Add RFC 3454 to the vendor files.- Fix idmap_tdb for big-endian systems such as ppc and s390; (bso#6901); (bnc#675978).- Fix smbclient -M NT_STATUS_PIPE_BROKEN failure; (bso#7635); (bnc#681913).- Replace jobs by _smp_mflags macro while calling make on post-11.4 systems.- Don't crash when publishing a single printer; (bnc#643119).- Carry error status in printer list IPC message, do not refresh printers if cups is unavailable; (bso#7994); (bnc#675478).- Define the libwbclient packages ahead of packages with a different version.- Use %_smp_mflags for parallel building.- Update to 3.5.8. + Fix Winbind crash bug when no DC is available; (bso#7730). + Fix finding users on domain members; (bso#7743). + Fix memory leaks in Winbind; (bso#7879). + Fix printing with Windows 7 clients; (bso#7567). + Fix 'testparm' return code when EOF in encountered in param name; (bso#3185). + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Fix "Your Password expires today" message for users of trusted domains; (bso#7066). + Fix maintaining of users' groups via UsrMgr; (bso#7262). + Fix 'net ads dns register' in Windows 2008 R2 domains; (bso#7356). + Raise debug level for "reduce_name: couldn't get realpath" messages; (bso#7409). + Fix updating the time on close in vfs_gpfs; (bso#7498). + Fix "log=>ndr_pull_error" in 'wbinfo -u' and 'wbinfo -g'; (bso#7594). + Handle Windows 9x adddriver calls without config file; (bso#7641). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix memory leak in the netapi routines; (bso#7665). + Store unmodified copies of security descriptors in acl_xattr and acl_tdb modules; (bso#7716). + Fix incorrect unix mode_t caused by invalid client DOS attributes on create; (bso#7733). + Apply appropriate create masks when creating files with "inherit ACLs" set to true; (bso#7734). + Fix "dfree cache time" parameter; (bso#7744). + Fix a getgrent crash with many groups; (bso#7774). + Fix requesting lookups for BUILTIN sids; (bso#7777). + Fix smbd crash caused by expand_msdfs; (bso#7779). + Fix atime limit; (bso#7785). + vfs_scannedonly: Switch from mtime to ctime which is more reliable; (bso#7789). + Fix copying files from a SMB share using Gnome vfs and SMB signing; (bso#7791). + Make Winbind recover from a signing error; (bso#7800). + ACL inheritance cannot be disabled in vfs_acl_xattr/vfs_acl_tdb; (bso#7812). + Fix "force group" with ntlmssp guest session setup; (bso#7817). + vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835). + Make WINBINDD_LOOKUPRIDS asking the right domain; (bso#7841). + Make WINBINDD_LOOKUPRIDS returning the domain name; (bso#7842). + Expand the local SAMs aliases; (bso#7843). + ntlm_auth: Support clients which offer a spnego mechs we don't support; (bso#7855). + Fix 'net ads dns register' in cluster setups; (bso#7871). + Fix 'nmbd --port'; (bso#7875). + Make 'rpcclient deldriver' delete drivers for all architectures; (bso#7880). + Fix flaky Winbind against Windows 2008; (bso#7881). + Fix SMB session setups with Kerberos against some closed source SMB servers; (bso#7883). + Fix stale lock in open_file_fchmod(); (bso#7892). + Fix sporadic Winbind panic in rpc query_user_list; (bso#7894). + Don't set SAMR_FIELD_FULL_NAME if we just want to set the account name; (bso#7896). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix connections from WinCE; (bso#7917). + Fix opening MS Powerpoint files; (bso#7940). + Fix endless loops caused by inotify; (bso#7942). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let Winbind try to use samlogon validation level 6; (bso#7945). + Revalidate the pathname once re-constructed from a root fsp; (bso#7950).- Require a particular library version even if the major version is part of the package name. Using the same major version does not guarantee forward compatibility.- Fix a fd-leak in libwbclient at dlclose-time; (bso#7684); (bnc#668773).- Update to 3.5.7 + Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Disable separate build of samba-doc for post-11.1 systems.- Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Increase the log level for missing PIDs on SIGCHLD, printcap child processes are not added to the children PID list; (bnc#666460).- Do not require a particular library version if the major version is part of the package name.- Use the actual version numbers of the ldb, talloc, tdb, and tevent libraries on post-11.3 systems.- Abide by print$ share 'force user' & 'force group' settings when handling AddprinterDriver and DeletePrinterDriver requests; (bso#7921); (bnc#653353).- Remove pcap_cache_loaded asserts from (re)load_printers. pcap_cache_loaded() returns false if the pcap cache contains no printer entries. correct call ordering is already enforced. (bso#7836); (bnc#625936).- No longer force activation of the cifs service on post-11.3 systems. - Add X-UnitedLinux-Default-Enabled to the cifs init script on pre-11.4 systems. - Move the cifs init script nfs dependencies from Required to Should.- Recommend to install samba-krb-printing from samba-winbind on post-10.3 systems; (bnc#661845).- Fix error paths in cups_async_callback(), an empty cups printer list should not be treated as an error; (bnc#661842).- Abide by printcap cache time, reload parent smbd pcap cache on expiry; (bso#7836); (bnc#625936).- Fix race in cups async printer services reload; (bso#7836); (bnc#625936).- Don't tweak with baselibs.conf during %post if not present; (bnc#652620).- Don't make use of baselibs.conf on SUSE Linux Enterprise 10; (bnc#652620).- Don't use --tmpdir as this option isn't known by mktemp of SUSE Linux Enterprise 10; (bnc#652620).- vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835).- Replace Requires samba-client by samba-gplv3-client in the gplv3 packages; (bnc#652620).- Fix Dolphin SMB share IO with SMB signing enabled; (bso#7791); (bnc#656112).- Add Conflicts to the samba-gplv3 main, client, doc, krb-printing, winbind, client-gplv2, and doc-gplv2 packages; (bnc#652620).- Add Provides samba-client-gplv2 and samba-doc-gplv2 to pre-3.2 versions; (bnc#652620).- Obsolete samba-client-gplv2 and samba-doc-gplv2; (bnc#652620).- Remove Provides samba-client:/usr/sbin/winbindd from the samba-gplv3-winbind package to avoide an accidental install trigger; (bnc#652620).- Add Provides samba-client to the samba-gplv3-client package; (bnc#652620).- Remove all Obsoletes from the samba-gplv3 packages and only keep the Provides samba; (bnc#652620).- Add fitting Conflicts to all samba-gplv3 packages; (bnc#652620).- Reduce unnecessary ldap round trips and eliminate invalid DN messages; (bnc#654719).- Exclude cifs-mount and ldapsmb from the samba-gplv3 build of SUSE Linux Enterprise 10 SP 3 and 4.- Add the _build_arch at the end of the vendor version suffix.- Provide and Obsolete samba-gplv3 to replace potentially installed packages.- Change package base name to samba-gplv3 for SUSE Linux Enterprise 10 SP 4. - Do not package libsmbclient and libsmbsharemodes.- Update to 3.5.6 + Fix auto printers with registry config; (bso#7280); (bnc#617153). + Fix SPNEGO auth when contacting Win7 system using Microsoft Live Sign-in Assistant; (bso#7577). + Fix 'net idmap restore' setting HWM to avoid duplicates; (bso#7578). + Fix "admin users" when using vfs_acl_xattr; (bso#7581). + Fix using cached credentials in ntlm_auth; (bso#7589). + Fix Winbind offline login; (bso#7590). + Fix Winbind internal error; (bso#7636). + Fix mknod/mkfifo failing with "No such file or directory"; (bso#7651). + Fix smbd changing mode of files on rename; (bso#7693). + Fix crash bug with invalid SPNEGO token; (bso#7694). + Fix smbd panic on invalid NetBIOS session request; (bso#7698). + Fix smbd crash caused by "%D" in "printer admin"; (bso#7541). + Fix 'smbclient -M'; (bso#7635). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix crash bug in rpcclient; (bso#7688). + Fix file corruption when setting Samba "write wache wize"; (bso#7715).- Let startproc wait for nmb, smb and winbind pid files getting created on post-11.1 systems; (bnc#520036).- Include the reviewed french translation for pam_winbind; (bnc#499233).- Fix smbd crash with CUPS printers and no [printers] share defined; (bso#7297); (bnc#637755).- Fix printing from 64-bit windows clients; (bso#6888); (bnc#640870).- Fix baselibs.conf for libtalloc.- Fix buffer overflow in sid_parse() to correctly check the input lengths when reading a binary representation of a Windows Security ID (SID); CVE-2010-3069; (bso#7669); (bnc#637218).- Use cached ntlm password in libsmbclient. Prevent lockouts when kerberos tickets are lost; (bnc#602418); (bnc#606304).- Add a dependency on nfs to the smbfs/ cifs init scripts as they require the en_US locale and /usr might be on NFS.- Complete fix for trusts with Windows 2008R2 DCs.- Fix authentication dialogs when connecting to older systems; (bnc#632055).- Adjust position of conditional ldapsmb %package and %files definition.- Create the /var/run/samba directory on the fly and package it as %ghost.- Fix preexec scripts; (bso#7104); (bnc#632852).- Add missing netapi, smbclient, smbsharemodes, talloc, tevent, and wbclient pkgconfig files and BuildRequire pkgconfig; (bnc#632770).- BuildRequire python-devel for post-9.3 systems.- Only create precompiled headers for post-10.2 systems. - Remove mkinitrd scriptlets.- Add vfs_crossrename man page. - Call make basic and remove conditional proto target. - Increase libtevent version to 0.9.9. - Remove wbc_async header from the file list. - Remove remaining cifs-mount pieces from the spec file.- Fix printers not auto loading with registry config; (bso#7280); (bnc#617153).- Update to 3.6.0pre1. + SMB2 support is fully functional despite managing quota using the Microsoft management tools. + Internal Winbind passdb changes to use samr and lsa rpc pipe to get local user and group information. + The spoolss and the old RAP printing code have been completely overhauled and refactored. + The SMB Traffic Analyzer (SMBTA) VFS module got added.- Intilize workgroup of nmblookup as empty string.- Fix net ads join when using parent domain users; (bso#6364); (bnc#630812).- cifs: do not restart during dhcp lease renewal when IPaddress remains the same; (bnc#573246).- Fix "Too many open files" when trying to access large number of files; (bso#6837); (bnc#619787).- Update to 3.5.4. + Fix smbd crash when sambaLMPassword and sambaNTPassword entries missing from ldap (bug #7448). + Fix init_sam_from_ldap storing group in sid2uid cache (bug #7507). + Allow previous password to be stored and use it to check tickets; (bso#7099). + Make ea data checks identical for trans2open and trans2mkdir; (bso#7188). + Fix editing users' groups via UsrMgr; (bso#7262). + Fix Winbind over IPv6; (bso#7341). + Samba sends "raw" inode number as uniqueid with unix extensions; (bso#7410). + Fix printing large formats; (bso#7423). + Fix spnego returning incorrect mechListMIC string; (bso#7449). + Fix some crash bugs and missing error codes in AddDriver paths; (bso#7459). + Fix crash bug in _samr_QueryUserInfo{2} level 18; (bso#7479). + Fix 'not a string literal' warning in netdomjoin-gui; (bso#7500). + Fix calculation of st_blocks in vfs_streams_xattr; (bso#7503). + Fix numerous build issues; (bso#7504). + Fix session setup from linux kernel cifs clients with "sec=ntlmv2"; (bso#7517).- Remove all provides and obsoletes samba3 from the spec file. Packages with this base name have not been offered as part of a product.- Fix a NULL pointer dereference in smbd of the 3.4 code base; CVE-2010-1635; (bso#7229); (bnc#605935).- Address possible buffer overrun in chain_reply code of pre-3.4 versions; CVE-2010-2063; (bso#7494); (bnc#611927).- Update of the SMB Traffic Analyzer v2 VFS module- Fix trusts with Windows 2008R2 DCs; (bnc#613459); (bnc#599873); (bnc#592198); (bso#6697).- Update to 3.5.3. + Fix MS-DFS functionality; (bso#7339). + Fix a Winbind crash when scanning trusts; (bso#7389). + Fix problems with SIGCHLD handling in Winbind; (bso#7317). + Add replacement for IPV6_V6ONLY on linux systems with broken headers; (bso#7196). + Fix cups encryption setting; (bso#7263). + Fix exporting printers via 'cupsaddsmb' command; (bso#7277). + Fix SMB job IDs in CUPS job names; (bso#7288). + Fix segfault in mount.cifs; (bso#7315). + Make TIME_T_MAX defines consistent; (bso#7352). + Re-fix a bug with smbd serving a windows terminal server; (bso#7357). + Display an error on 'net conf import' failures; (bso#7378). + Fix bitmap leak in dptr_Close; (bso#7384). + Fix rename problems with full_audit VFS module; (bso#7398). + Fix setting of passwords via 'net rpc user password' command; (bso#7417). + Fix 'net rpc printer list' command; (bso#7418). + Rename mod_name to module_name; (bso#7421). - Fix unnecessary traversing winbindd_cache.tdb in SIGHUP handler. - Added EN ISO 216, A0 and A1 to builtin forms; (bso#7423). - Winbind not working over IPv6; (bso#7341).- Honor "interfaces" list in net ad dns register; (bnc#606947).- Exclude the RPM release from the vendor tag for openSUSE Factory; (bnc#604049).- Enable the build of the idmap tdb2 module; (bnc#600822).- BuildRequire keyutils-libs-devel for Fedora and post-RHEL4.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- Add "net conf import" error messages; (bso#7378, bnc#598189).- Define cups_lib_dir %{_prefix}/lib/cups for post-11.2 systems; (bnc#575544).- Update to 3.5.2. + Fix smbd segfaults in _netr_SamLogon for clients sending null domain; (bso#7237). + Fix smbd segfaults in "waiting for connections" message; (bso#7251). + Fix an uninitialized variable read in smbd; (bso#7254); (bnc#605935); CVE-2010-1642. + Fix a memleak in Winbind; (bso#7278). + Fix Winbind reconnection to it's own domain; (bso#7295). + Fix segfault if hide files or veto files has no ".AppleDouble"; (bso#1206). + Fix parsing of the gecos field; (bso#5198). + Fix several printing issues; (bso#6727). + Fix valgrind warning; (bso#6814). + Fix race condition in mount.cifs that allows user to replace mountpoint with a symlink; (bso#6853). + Fix bug in vfs_scannedonly rmdir implementation; (bso#7075). + Fix handling of bad server data returns in client rpc_transport; (bso#7159). + Never mark external domains as internal in Winbind; (bso#7170). + Fix access by multi-threaded applications; (bso#7202). + Fix 'net share' command; (bso#7203). + Fix DN parsing name was always null; (bso#7204). + Signals are processed twice in child; (bso#7206). + Fix returning of group members with 'getent group'; (bso#7212). + Fix the build of net_afs.c with --fake-kaserver=yes; (bso#7216). + Make Winbind logs more verbose for troubleshooting; (bso#7225). + Fix a NULL pointer dereference in smbd; CVE-2010-1635; (bso#7229); (bnc#605935). + Fix automatic building of vfs_tsmsm if gpfs and dmapi are present; (bso#7231). + Fix race conditions in CTDB persistent transactions; (bso#7232). + Symlink delete fails but incorrectly reports success to client; (bso#7234). + Fix "printer admin" functionality; (bso#7255). + Fix value-needed calculation in_spoolss_EnumPrinterData(); (bso#7256). + Fix _winreg_QueryValue crash bugs and implement Windows behavior; (bso#7258). + Fix job management commands for CUPS queues; (bso#7269). + Fix smbd segfault if using vfs_acl_tdb; (bso#7283). + Fix core dump in 'ntlm_auth' with "gss-spnego" helper; (bso#7290). + Fix smbd crashes with CUPS printers and no [printers] share defined; (bso#7297). + Fix DOS attribute inconsistency with MS Office; (bso#7310). + Many disconnecting clients render clustered Samba unusuable for some time; (bso#7312). + Make 'net conf addshare' atomic; (bso#7313). + Eliminate race condition in creating/scanning sorted subkeys in the registry backend; (bso#7314). + Winbind possibly segfaults when trying a trusted domain without inbound trust; (bso#7316).- Add SMB Traffic Analyzer v2 VFS module.- Document "wide links" defaults to "no" in the smb.conf man page for versions pre-3.4.6; (bnc#577868).- Fix workgroup enumeration, for client printer and file share selection; (bso#6880); (bnc#586215).- Fix tdb validation for offline auth; (bnc#587014).- Fix "printer admin" functionality; (bso#7255).- An uninitialized variable read could cause an smbd crash; (bso#7254); (bnc#605935); CVE-2010-1642.- Ensure to have a valid talloc stackframe; (bso#7251).- _netr_SamLogon segfaults for clients sending NULL domain; (bso#7237).- Merge missing pam_winbind message translations; (bnc#499233).- Remove cifs-mount subpackage for post-11.2 systems as the tools are now part of the independent cifs-utils package.- Fix join of Windows 2008 domains; (bnc#567013).- Update to 3.5.1 and 3.4.7. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222); (bnc#586683).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; CVE-2010-0926; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7; (bnc#619787). + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7; (bnc#619787). + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7; (bnc#619787). + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build./bin/sh/bin/sh/bin/sh/bin/shsamba-client-gplv2samba-gplv3-clientcloud103 1561120142  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi4.6.16+git.166.8fb11cda200-30.14.6.16+git.166.8fb11cda200-30.14.6.16+git.166.8fb11cda200-30.14.6.16+git.166.8fb11cda2004.6.16+git.166.8fb11cda200 openldapschemasamba3.schemasambalmhostssmb.confsamba-client21-dhcpcd-hook-samba21-dhcpcd-hook-sambadhcpcd-hook-sambadhcpcd-hook-samba-functionssambacifsdddbwrap_tooleventlogadmfindsmbmvxattrnetnmblookupnmbstatusoLschema2ldifpdbeditprofilesregdiffregpatchregshellregtreerpcclientsamba-regeditsharesecsmbcaclssmbclientsmbcontrolsmbcquotassmbgetsmbpasswdsmbprngenpdfsmbspoolsmbtarsmbtreetestparmcupsbackendsmbtmpfiles.dsamba.conflibnss_wins.so.2sambacharsetsmbspool_krb5_wrappersambaREADME.SUSEdbwrap_tool.1.gzfindsmb.1.gzlog2pcap.1.gzmvxattr.1.gznmblookup.1.gznmbstatus.1.gzoLschema2ldif.1.gzprofiles.1.gzregdiff.1.gzregpatch.1.gzregshell.1.gzregtree.1.gzrpcclient.1.gzsharesec.1.gzsmbcacls.1.gzsmbclient.1.gzsmbcontrol.1.gzsmbcquotas.1.gzsmbget.1.gzsmbtar.1.gzsmbtree.1.gztestparm.1.gzlmhosts.5.gzsmb.conf.5.gzsmbgetrc.5.gzsamba.7.gzcifsdd.8.gzeventlogadm.8.gznet.8.gzpdbedit.8.gzsamba-regedit.8.gzsmbpasswd.8.gzsmbspool.8.gzsmbspool_krb5_wrapper.8.gzsambaLDAPsamba-nds.schematemplatesdefault-globaldefault-groupsdefault-homesdefault-print$default-printersdefault-profilesdefault-usersglobal-winbind-offlinesamba-client-dhcp.confsysconfig.dhcp-samba-clientsambalockprivatemsg.socksamba/etc//etc/openldap//etc/openldap/schema//etc/samba//etc/sysconfig/SuSEfirewall2.d/services//etc/sysconfig/network/if-down.d//etc/sysconfig/network/if-up.d//etc/sysconfig/network/scripts//run//usr/bin//usr/lib//usr/lib/cups//usr/lib/cups/backend//usr/lib/tmpfiles.d//usr/lib64//usr/lib64/samba//usr/share/doc/packages//usr/share/doc/packages/samba//usr/share/man/man1//usr/share/man/man5//usr/share/man/man7//usr/share/man/man8//usr/share//usr/share/samba//usr/share/samba/LDAP//usr/share/samba/templates//var/adm/fillup-templates//var/lib//var/lib/samba//var/lib/samba/private//var/log/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:10483/openSUSE_Leap_42.3_Update/3be556ce4b1735da54b485ec0dc8850c-samba.openSUSE_Leap_42.3_Updatedrpmlzma5x86_64-suse-linux  !"##$$#$$#$$$$#######$##$#$#$$####$#%directoryASCII textemptyBourne-Again shell script, ASCII text executable, with very long linesPOSIX shell script, ASCII text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=82e1e01af177a25b33905f4a1040aa56eb207543, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=a7323329c46414aab1915ea5e62dd97be9ad34c2, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=8aef8a72c177d1196cd2e3eacf766d02cfd0f8e5, strippedPerl script, ASCII text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=70dd1e028f4e9c2abc44c42e33f4b48ca91d68d9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=91c965634fc9b90086c5cca87ed0ccc7d76bfb95, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=5541ba3c90f6a42bfed920c80cd7436daaf49bba, strippeda /usr/bin/perl -w script, ISO-8859 text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=1ece729c1cd499cdcf8a39607a5e194e899179c7, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=bb02ec94e01aa8281c15e8c84ebc82f6343bbf6e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=b2c8f3416e20a801d0c39e4e28587cc27a5687fc, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=a50e9ab65da161df58fd402712de45a2293ca87f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=436a18eacd5cb69787cadd71bf757be5fcd05f45, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=18b836613eeb7b715434d02400d94ca3b2bd5d2c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=5fc56d10f6348c46c0babc9251271702439d8e6a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=9bc2a277a23977c8d692f73064ea1d12cb4afa93, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=863d5073bc983aee921a551fbeed4438b9772de9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=a3a211206dd0ee5dc0c66f51c2df277329792eea, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=66caaff30ceff05823cad708a6644525b4163224, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=cadf8cb44b70b17e769131f7003c1191375b2365, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=a102b48b5c3388d5e41e08852e3cd0e1de087eed, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=7df6608eea4b9346da403efcdb51beef7dff1071, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=9c3e3f80ebe9f11a7d6dc64c3544c66441c2efa4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=d6106bdf4fc92b0c7e50839364ff52f4fd9642cc, strippedBourne-Again shell script, ASCII text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=9b1de99a905f6d60f18fe0b7cbdabfdef7dd3345, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=2e6b0f2b16d623c3c5a41b46d9ee5d9fb7925018, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=c855808bf455ab06819a89cbffcfebb11507b6b9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ecf8d1da4cf046307fe1e848cdd678e391431f09, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.0.0, BuildID[sha1]=eb037a09a1d099d3998a7128ae8e3e4753a608fd, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)ASCII text, with very long lines3Ijkx'BXo@g  8NZ1! u%H!'," # RRR(RR:RvR}R*RgRR^RrR3R"RtRR$RRVRRxRRkR RRRRRjR)RRRRqRuRwR~RR|R#RUR]R'R2R9RsR!RRfRRRtRRRvRRgReR-RRRRRdRRsRRR,RuRRfRR R}RpRR\R^RRvRRRRRtRRRRRRR|R]RoRRuR RRRRsR[RRRRRkRRRRRgRRjRRRRfRR RDRrReR@RR8RpRTRRRRgRBR5R:RQRRiRtR/RRkR`RRvRRRR>R$R\RRRXRR&RRR}RRbR(RRRRRRRRKRRRRRRReR\RORdRRPR0RNRRuR=R[RsRRfRRRtReRgRRRRRRRkRRjRdRRR~RsRRRfRPPRRpRRRRkRjRRoRRkRRRRjR|Tq/'b)?]"k%J-2_e#ZWx' 2 wr0NV0JcEh]>ATYe2yX6(P(j P`fItՃf=AB奅e]|\v)6F@HW_bх1S7ɛ>JqGS}_ӹ>K|DnH3]Ӹڋ3[nwjv *Y}bǰ?|J7ѣ D*G@`%B20J P0,*fB3u7"4~\IM]_90|F׺WD) O5{!(j|hśvVWuW(nWIw_E XfX=yf@2On3gĆ !{ZрȜ=&\r?GV+fˍ#Qypf\EEH$J,Ie{/$pObNk lփOa=甀5~&9^( ~cY[d7XȽKXѻs83zoPҿ5If@f{).,iVf2Mh?&XضT?V@g)` ܄PW*o#e`fXxGRV:=:PI{|~`mkϤBFP7HZ-p2uyь`KGFG( _mZ C.O%~{Uz?PZ5~r,uZ[l=o\*[D &w s:J*lCm<\D["d@W[ƃ:6>i$y4U`JT㙌"6`&dz g b$9k=)`j,3FR,>%C&Cw TI@_eb9KZlBYͽv;Bs w;E$fd[?<`-7掉nLúެ [S}] g,ˬR@/GQ_B>d&> h[1rˊB8`Ί[ganS< mafgnBNƹ=̕.Z}4Z(Rtȵ c;#{ 5d0s;jl{;^VkJF"F [Pf=[]F|OeHFPJy 2+Νps+Oe # vy{$>@ʾ@iEqstߋ_kt|KS`޼l>I0,#лfF3X;=z B%\\S+kŴgB~Sf΀XWbUuK `^ o-T64ۖ@ &bR(amJA ŵ`aAH|_\{`/ḍQm.ʻ VgkSFQÍ; c4M̠k>fɭ<|R}HRE\,{QG頛z *'Ǭ`#ީ4}] Ֆ]>LɐVXkw+]_0ʃFnΛA5*V@*&dVjF! Z^u/s :^ga\Jp=2*(>d|n "x\ ;X6Y8+hY2}e*EϘ@ۀ y`mA 5~Xj^  "9vV C'p) 4?.qjYs#,k&Q#bBX0%$Јg0)hNrf_^uuV2Z/lqxkQ>Tꋚ~9x)en.^9F@*a,Ȕ |ȴ&xZu,OVu$y Lblz|3H-`lYr=@hL^UE\=XI"1*|ePBf+'KX`L!~Wnq{cRRoF6z1!J< |؀@S/@X:X%.mt*GU-S P#X|Z.LuK'&N O_r*H3Td8z6\5whH4o]dKZcWG q{rT ՐĆl, @ D&O^$e`Crc"RUZŶ%U0*ǚ@ê܎5"qXaŮװ.|$sĴhq$rFe'#_ .D\i>?j ~joCEvs`_u4˿}hy* &Q&@/~LBu%-- N&]y˾*MO4FTSc1.s1ϢYMJUH0 ѯTR"e2r!AA%bMyM"qFSjiPAc4+nJS2d] AZW5Aй }oM*s-s1>K~.ɡ¾h HAO}Ce^_y`b)A՟G4gÊ6"ŻT NO4? =',voK2I43V`r3^mK/e] ?'c{%^M\,|{l@dc' fQ\I6R<_oa)§_5o+:[ գT~U,6ZdѠofl$qe%w? ٜk .]=$AS|o@2A-:c;GJ#5;K6wךλMy3ڱSW=l2w_>g#zŪå{r1hܷ&YG>l 0 Q3*-PƆ-E!||DO::&dv62)ڨ)br-R%s9D CfE'ù1d9GA0j&40V?On0~GoYVj*aE 7< qgtt=Dn^!IPH'bTNAn7yCJs,ZdЙj f}Qkv{(4wۀRх_oe7=p8I ZSp3/xf>7#0pJQ`RXF ! $䯎@ȸ;G`y~a?EtÝHjp' 9+ R%x>=L=,CD%U:Ry[;kRAwCCv 2.v`rJϾ-\+znwSqīGHoGm0[i9ٵ)D7!lܸ4enp83j_ڪ hYc[+I2X. y0G[49>2ي}3b_"#-η.c}C=8PF K[ 0] x(ߐqzV(ҬE@/4CRj|EkF9D> p3ӧSZ0 9w.ǽ~ ]eW;#P: +JpˀUQ|`# L&<kJXZ r;#;ۊ3rvm^`9dC,}/dתh}8]2u3DG6-Z~9ռu\eWU'(ʳݑzQ9Ɋ Nm6s6z~,jo5?!K,<ΰwOEFL);NmSA4h9xNVGYVfO}vRXkvwmN#i&1]V~ EfB9X>"ĂF6]Y\Ss”]1(ζ/s -)9:PPt6!U`]yKlh@͹. ={7n/_$_X.BCQ5uϖQDL{J&@ailv \ۄqTOZ@V²UȲ8Wx[u3BkJun/{EM1⿾y="%:fyT~ Bcf PNG0ꍄ. q6A JP;B!f3&TLB$һ0Ue/8NΔ+x(݁!GYœ'PZrCׂ(_5VԂHRƃeoY$i)ٝeOܒF# !\z=^5Cb5s=R9}i&ݰ{H K?O٧i2m\tܖ2.]L c%S_̏(D^jD/q9E< PxxcY8Humc*?С}|q8~(Qbec\чkrKc'/{7\VC^XI~!xU3Y?fuuLv/\¬ܾt kƾNKEK{1]`i,#Px ~nT: ]4zpX]CoE{5aR+R794"Ϫ:z?ӵaHZBҘt<t ٨?;lfN.=\P A{Y'RS-Fw Ɨ6VPKw&|cPL Z{߆'oUyվkUߍ1/_&yeK 6 %&3 ڞj֜dI VgKD" ZZ.k>?юP{\mQ7\? Lz:0*v0 mf{mi_s;H$ab63-7(/+H˙9u>+dV_F"FNxUڐqC}T^ L7J {46u)! Jv@ǂHf6lbuNI4 5b!1$'^9dE$G*Kv^D{mRXےT6"rgi>Cvoc'9-otgں}Jru$ݦj/[ OeXSnw*7ŅӶ"V#mT91/VQ|+d}-0^_DѾmh1ְi.oh-^ 7g T5◠P-@>S^Acdv)Oҵ V1f-L= 8X9eډxN\R-8m. ##x~Pi!'jp0S6n86i܅A.A|$ XfSu#(X.e5:(8P/ZUB}~MCw|]s7KQn*+v:ХotݸQYUh Y3tsMw?uei<6^Ai3z-#rfY-c=znQ+OvVAE֤Az`o|xS%N-:.%\iO? ,-vY~W:K *ޢ:.,(:w&B㲬ϱ"XA xÝn:4p;wjV6@ZI:79't..jWhjr_Vw3ؠsc_#WC7`pjfk+uRYwJI#&S4;>伶l{(.l'un[xlefk]8Ꞃ]n= TvM~4< *B@ 4/ZiTQ\W"*^]nj?,1G=.)%{<9ƈ;3f٢GIy]m j W~yNE,5ɂzYာwMh'kO!b!Ӗ JVPJǷd\{j?n R_ы࠺s{nGBd]v*jG4zސ A~fe(&3ȭsw8V\y!,"-܉ >0<wtvbry`űA6(L%KG<^d0[/gfwY5[6j..6zZ.1Y||Uyč󯊄.Lg/%M?)T,vSIN [h 2 5%#Gl]m&H0@A)k?tyZ}CȬd#epxܴN'H{h9&N/ U{̯jlj# S@.Ȇ S~*Y0t#J%L4_tjⳈQ8UɕG|æSLLSeYVR1&W5Y0 [:Sx=7y `$\F?Y+~g ~WMF?j m+]$N${ w~P"4f,(01J:QbtٵlfI$8so$ }']޸F`#+*U:jd;>^ Nd{+L$MoF2o'=PFS~jM!V<<93;Pem~YQxWyRbz6q^'դa|"̦$1PW3 +engzu0+8GSly2HeDP?0A:F `6!" pU0P|sDSݣC? H $yyh@3~¨?#5|2A("韆9x.䃬bwfZ:Y&81LJJ>xm™uG󇃠o:J2p'^2%ӡ1Ry bF1M3,˃,*Lړg۰ `꧃sB7VP˯B"*DSOuȞjXYiC5 MaQߤ} +H'o -+N oK̅zS19rm1I'{dxBwh-@0:;dWe-t$twQރٕgR n"G),P< A1\8'J*܉=lHQd;e{N Kk%BrP2ifM?V'b`@3CdXa75ٖY6\Mߺux W:ytQ1~v nvpׂ^BK^{cЌoI!i.MS]hjFݶj1QX5| A)PrL; w &`IB!!k+nTm@+D֮爢?.JM?AZ yqVN㻣Z'N\ @lkv:^W9&{d:>4a7(JAH4MzU=pS#HB[hJRKErbr n+S/C5tMqk3 5S9r( 4*_)ؿ[U<-m.mZ I|{,;į<}<镶CiqL|UN1P--[b|R&'%0ibh0jp{>j$*5* =C H&vKю*7)Xհ-4Y>O;XӖ&U a}J-..R~<2@0/eD>/Ѧ 1/ur˕֡;86حP]> VxEjd(pu/Ƕ\ZDzz~oc4Y)nTd)4DВQꠔ#]pB3Wos2-n Mr˒#\GC(/X+pkt@e*P!}i>-V D:&t=X)dyYQ&Z(sF嬺??4ɦΈ.E?.@{9Hyˈ?ܠ2h-{es-|;un ||?7:ǪwrS?~ EI}L6koDO&bW={x znnq(f_DFD|Uz+![OEBhvz|Z `ۅgj#]P`宿V!}]D[UXup"56>LVrT0m6kg}jCw[lBm0ǫp̓De&{n̖$bF8&+Sͬbra>_g{j+T.9Q@ ^:ݹbg#)E6EKAD;_8CIJ±'3&5s/އc$MWs΋Gr>tͥ?wZ09Ky/"A; ~A Ns8E1Z$5,(02B+=y]ᑘs .Nl"^'j H&zZ t @ y^@3#@+]!AYQ@Xɺ#Al,[n_ak[kFVTdwh5JbڏwP'DD"T&> cSw ۧ4,_UKƜzc{"xW\mΤ߷<2-\\[!q" bS//ZAҲ"<(}j!*-}> @G +OY$}*k0>21SA@y]33ސ"`p/ R$(1 nf"(0H= /s]mz gM3mk-\B,[pAC#Y'Vb)u ]u,Jpth*g+ 4HOcXwFp&tj:z*  US Mc,(Vk8v+ĞMr}ԻCY޷bkg0lGݎXI7nL5?IB|x8$q$NsHCJp/)hr6+i.21I,ԍ?ΓunH3YGSo2u @u^E= #b7502Lm< u$YסSTkP ~۱^T˥\)c81OfTIww!g12n"\*!ڊǀiA`57@-9mR$8_;:l*+r-.4td>ZRA6 W oD~5)TM)I- Hc4.߈TircOK Y>r^DГUmfkԔϰԯa;`t!ҴA([{.a+B%`X2&H٢qoR!4Żڧ54A%MbQ`a%6Q%|߳C:~xl4a'謘y9i)N` ZIӑi\.Kn@Y>nT,{-fCV][x\Rp#q@Dkj"kp$ةO@_V@P`+Z^̚E`P-@o`)ռ^~beRd6O!zZ״:~o1 ΄?̊1WjنL1#!; )i|U ՛ yN+7 AIq).j Wۥ'V)F`i/es.=L\q55\?] 8Qt:+dϙةu7aFLge5n8_D=Z%(kN {r;g#‰ٟSb@޸:%2;&f+DH)Ǜ8hxp%BoT[ (emF+6]R? g%nn4j‡:-m?:k;4OG!^x<[`i]sVwJ䢳΄e5j_ QQr5N@ bD3w.ˉXEb mrTDc^G?rB%(Ǡ[e22%zQzYqb>gɋԪX&ҁf@3-W) uE4w(Y-BBfχ't:iQm5x67EMA|۲˂MIx6I Sװ?@ȹ-.c )7#quv‹ۊNWL10V"WgG`*ԣ.ë"*]H 9^j4NZwj`oҕlOB {dCQWd@+YՍL))}3¼X>j=%eiҪeRs;"Ac3[\x`k* NNӫ1!#*VQ8%;_du"A.dZAs6IX @'ķEZ8tmvEX ~.Pz,B%+ Ǣ"YRr¾-חi?n \_7S qe uI;BS]ǀUȀŕ MwuTTkzIFӤcRĈV:Z*>Є)7eAH!떙d}W2s)"QUvbGCatVh#jQ]z :o5S}3^[UҀn+u 7^&rx$xV&Ajɖ? 4tdKZ4"5~aOEJd @PEĵ)E^Am|}cy3g}Ͼ&ҧo-)t,8}5tu͌.q؈הrZSS4 g3gFxd e.}j:~ͬ{<yΚc2Ŀ"qYá70Q?[H0ݶd˿=3kn` m4U*o)˄PuB"]Al#K vs(܇uv.fRxq{z6&N6Z5V"GY93$)nTjJR8Nɾ@B계!/)*WDvSbFѲw=l.%STIװl\6?I#shx&`5wEbK唙lkǿp+Dh@_ZDyi㜖DV|Oк@di OwyBϬjGMO(K5+.gAd&)fߖvp`:/p$FSDZO5 No 0>ikH>M؋/K?R{\F tr]}̈́Bul7WeYu֝j:L%~s KRͰaʩv#tE~_ xT ӝ( n:]ԪiW] /`+FzLIBiz^3>@$ܼbYO:Eh_ԷW}L \2KPsŧxH&ȩcm[#dr&dDtyH;u3N>M/*YiIԘȅR{GkP ԅ'na84"R?9a9!?Wo𼽉S?K,ipEd!ݏG?MKʆUy GO>'+u$=|NNH-訊0Ċ,q3Ea_Ih\P>BsB.@ uʧnnk`kng&O=‡lтSũTH!aI;K߳h B ΰ}2^͑.r!=q-oeWe&P6n>䁁Ax[וA 5g]h )} hŎ3q?^`[^]p-G̅x5Œz *3W=AAg8=.PqK/3. fywFK R$IRqyHQ3 Az5=&d1QPSi񨰄tslɲIxyg#H"qW'u6ލx@/03 Fi'&})Q@|wHop٭^9! ^&n#E6 KRG\;bͿ{gIupvE(`O+jA59d"mBDoVC,5f֙TqQeG͋Vf&}X,la);ñ:YUԺR'.uK~@0;he 2;e4+ijjH Sv@Ax5!D$tH-G_/I_4/0|x,!8#.]cHx :(!7՞,VڭqnmWw0УQVcq)r".z6Ӷ{_sD\ |Er2Rֱ?n($'J:Ӫlh]jQgmw,zevƥ? TDR̤@ePt¡C&ÇzWl)N  ύ~ePm[y5<qŠj'if+] z] J*+.邺+Q*hNE%^9$>[[Hf % tK@I@73젢 |J74 6We?PI#W#yoWZvzkRK5T$ySzljYG#o~壎1NB@kL8?4.o%ҁ)5 ˕Ci>GT Z d,q tuR0܏!p* w{WrC1 *aclp[] `^i`a6s]GZUG}B)@D+cvt)FGՠfE^IH 𽬹Bŕ68iǺYB(R@=]tTĻR&6!H[*+X&(p<95:)'L-EgK OUE@uM3V7zC- vrY_#=VepQ1&6GY/DϦM h$_*.kDgz&[̞Y-( ^1.ᤕfV.\;}Q%Bi.R&D~3VCZT2*0˂/tq)[C1,?7;3Eə A+K>5R?Aԃ$~|BkPЕf{'@~uӞ>=:btbeR ձ-:e6hUCcp; ID$N6Ƀ45˭^/a`xxZzbޛ* t/aCYVB'G׈nkSD?qF$(jvE_x߹^ܘ =p2HF&lQ4KVJ)"AsnxWbբ^U-8"\4VF̐:'|dP&S *d&puV Jx~o44U5I16N?Nb gtk$BG UMM=K\u~xՊt-Zp9:y[Җk.@GX@*\ Jcm6n霓Ynsp-dDB+apjT R[ByIޛ{~XԢXW3$\ [{?~|" `8idf,vL;HWdF]!`-bT4V΃A|5A\,ͯֆx'ZRhWQ$ `F#i Ū*gA{DuҁCtf$v" &$g7LIBP#Ҿ ` 9QS[f)k7+EToD1~{N(w&L+Ϥ‹pзI;בp%N^稠eZ[EGGSL-&>;8Y(M7a= *6C[m tW~L5IID#,^v~i֐k'e,u?.7mDZgE'@Љn5_&(+eW.{ |2P,e8V7B#iVVqb^{,_),6'M-eFӳ Bf{p$>MlQL flyPӥ<ԈO+& U ˀpHD2GFebVgA6x8&7vzL<<Ar5S@D&~'DTFe5~֋t]$[ <ׂCޮ:R \u[R!Q0LMhro#2\ܔ.̟O4NqRa\ ! 븖=iD_JhWLX~fGdR:T AD=|0 ){Y/!ιhKjwY<ޏ"2H;J$9WQƟ̴wr1!%M63q>+j5#2jnٜLDx1u.P4u9VS6&҆Vk:CC&Pxy?EJċei˒GoOsӪ˪Ze%:&6N6FTĮHܪqi@_%Vզ[Q)ÉG|2}F`0]T#'rSc/Hq]b'diЍ6<0p2l'+xʲ0w9T\!ChIC=^#+vyz9k,Z9j[@e*h yuyER!iQ.}el.%C2[b=bjEkoa~cփ4 m &Ky#^n xVօJUҞ(Ѷ?TAڝ\ E%@YZ H Kց4c ˨RnV]߇s>S`u{*VRL-sK9&0DR/ם5Xfa7\BƚՅHU뙠۱%[x?B?AkPo"vБ&'@8iE[T3 =)y[O+Oz6ȫv| x 23XԶ[+`ʠV0T.Kx4",B97W;uD~ U)ӖMu2R1:eLK<X>/M3CFLMx0cx97E5BUM6U%P74n@{ n wPxr 俋n.Uj0-zaΝ4A. ݕ678k` TF @9J8̔4H 3C@ʒ\Wòa0vٛc}+Z?S63$,x}ż&nU`Bf^瑨RRĢS[.ZpwGQ첗#4iff^xI@\UN$W(aYx=6%]joͳd.8S/N;= vlF:r2BpI,eώ5hk>SA< 9MS\-US*$AO8k#,ʪOȃ;u}13˼d(@M0Q g c@&n{: sfU Ĭ,ؓ% 0āF>*ϋaș6Zͨ4$}PPԧlԻv`\YKɝ Wm BҲ=--C*&1pъ?kߏ;}M*9R{༙A 1Lr=D`C <?{@pZXׅPqB%⽠hvSe$V<@<4 8XÄGYR:2 pO):~+0t9az6x>8i94RE6i%*vϩsRAekϥ8c `l%PL'H#Vm_Jwms\sS/d>[ׅ勻.GG)kCo*,쌩JYەTƑX76{r'45QgXp#X7qdؽURӋ&?_QM=eyagۗihoYfV16%S}ՌbqZnf?'{}-oў~vؖrx/dŷoN=|6[ (6#:lf+ϼخ[B%Nۓf0䌖/,g6ŷ$8>{HFxeWw䈂GD^QXIH}#S|7a?$ $ QUޛfN_c:mJX++z Nlh{{Ս`O0Ҹ!ޞi(:X/~?f'hۑFˡU)t]l{y*n6&%']̍(ۚvqZ_Z@AVD$}̅u5I}?-,+9L 9|y }m[7A=E+z|L]=XWt?0z权=҉|>cX]_qjoMnčE 4h |ٜL߮R UV{^b7!3ڬLjߵPJz9l(k$ cCSѢ % (Urh&_v$,acCtD)↖$ |d!l({Ra[I Dcw#m vЧ7n:q l3\jT9Uk˓&U`b SB_BGjۂfi FyDWhdu ve;fiI.d! 4`*!ovF1FmpLQUI g?e{6 ߃mxR-BpnCz&ɒu!REȭ'`N=4q\Ki^ y?fExc7ujH'bBR>B?tG D_{H/_ه3C1m\d$tQ3OqYX]9ZsK)K3<֪90:)fBt5`ki-NtWA}XgXF e)AũpV2ZڭTf #A0CwZMju'j%~.~yG4fW=Fƅ ֕f%7Yd_y2whmB\f:܈dh34%[Ư.:0:@ 2k,>6/,lnKQBkUk+yE/` 'xgKGb6~LziGBB 䀓mÝNgKE0 rAzᦘ0ǖͫZ&gG2tMi>On}J4(-˺<.(M7~t LwcQ4=9ؖ͒ok0p/u6/@לrEjV79?jmAL%UQg4앭{szn Yw`A$Hb ņzJnL%Ǧ E*$+f4uqUm3EXr`Զ~^kOjk&*]u(V4F{2fw&o&j g4st<`ɯEk>LyF8i/4!4u@xg>D aM#TģH+ݡ[஥-(S11yƍwW~!_ԉf!my~g6"eRl[Ә"P{$23S$xQ%9p\,XfWR )d~#yʓr-H+zejtBM bopP8y)w- ~;_w1cZ^ RAZ<ңdSD@qʱ@ۄh *ܒ}m\h|)Ϲ'pGÔq C"o!)~nK\ .q[- ~1'~]F]趢p{C"i?4]b+ߎ+?G`Z#VW%+e2k_zD7`Qs1uf7R( 'Z>wP1(BiiU)(7 2r RFf i^D>1EDG66RDzT% NCn^^݊cA%a'KlA@|%%hq7fB -Itl8l޳~ B`r]_(W5fr)_5F|=Ʉn2IEAP}ɂi"۶ܺbn.':[{J0o(,--$|/Dv\a|0ѢJ_l϶U$m6۹a+ɔ"*٨X[*eUJ)dAJwX{gx^`zeK%H I\_+Ӑ zu ^ީۙx*uNwgU({[,:n7idc3 tu5xV+YqLIl5m>9_$[~?+ d`? ~ q"Vq> BRc pH{?`+'0{ॢ`Kh@2Śa+7j)QS>#vQz@J/Ӏzi&\kBHL3C bMwLQ=0\ZR7غQC3BFXySibԐPxt~"#.lBoRrSĹ>&R-T6#S>mՐRVX;Xsa@zf@d9.-?Ȕ <äI 392<%C3bQwł1dl9I5]*ķ܅JEjm.&COҕ"r+Y"c@Apiv`~O g+=p"0.| !C@i* d>OJHc'^Þ7W+\ӕpI#x3_.t׈='zQ/#[DUb /@9TX81UBEB>Gi#{t:>%J5jů}I?LvA$hoY&!g ;ArnB+~͞@#:g;탗%Yص! |<2YھIj<)C!{2:+EKNfLjɲD7X:Z*z5ƨq׺(/T=\- 1ėׇЂH,TB <,I~q:L+Y#hѷX~+p+[ep)=dZm$_@2GN߲4gD[ܲet.[Cn+ǜxVk \$)ߛ*!v6i޶9\\B yrmi`/)8r%hq6_^Qzijh-m"Z9iVAu`ne A 2֛od\|p~6g0<`~ )EZW\ NوXRYRIݿ-IBm<1_ jj#&Y%J`>8){h˸pM Q<Ỵ0^3-l(]1N6O+>S7 F`<Z}E,kUW[2NMkV !ٟJ{Y%c%!Uؕu`t<_Xs]3lly&#ܥGnDGߵ)x<^*#8|}r* .*lfnlM߯OScDq|H`j:C-dǩBLy>ց v#s&1W)j W ` t+AgG^>/Bi;ʤ4jIjO]\AC;%JރYЬb# ʌb76$UZKB'8t4?NzyPS+Gg@BMmZBy&!r) rS(?z<073-#,mǘE𖆚 o6:~IrFZ&K mn/$ ;\K6 ?( xW5 Ɓ*{~$znNΉK ~ݣ?ng{+j,~49v#bqM;A2\\.0SR)/v`2rr"-h$e|Q}h5iҋvf c[|_P<Ί`1Ne?O4Wjdp_0[]8lAU+se_Sor韻6vC% B!Yk&gH'RrmCa)r̫8X++ql(y 7}dh$ZYf6w5ƸB2mR/0}zܠ|OQ1:tyNoSfT6Sҟ$\a/Z*j;B>^]↨ P|ϹYf$ 4aG&tCUf[ɃtA^Rx>7Bp)Rz\m5p6$d춍Q FICtE[RlV|e+i%~ij;bd/JfKdzwU""̹I AZ'8$47m>y-agPXDDV9o(Clr:kcp+Wܼ.C[Slz _-. 9_5Ҫur#߿Q}I1׹PڞHCCRVH[ybPg6.N,,WTɤg*܆J D f!q`^]t2l=4JU* iϳLTgI_[q`,C%c*P;lf!ꤰ3f`]buy,X\ʃ?t 05Q>6cP(5zyc: Sn+|/XێfS[tj mM~< 2$wEiMx[PwǦȢ"e"׍ph&Oh̉*E2˟n.EI(YS&1Σj<-AqȘ3ZH- MXhnX 7@FŎ@~<au໴ӎm[uw4 1ZgXf-*[v}>8qPDRگH QrW],TzҺbVLȧrE7La͛l>.ahPt uUJF9q` +J?_;#Sv"& x]LkXxTېF*Ԝ88:[" :"W8-+~ \4D,lP5WƲƺa-HVe;BAsyJ〉d$mfH9{ UH>ȥޡLtqT k]ĕ`{U|&xHCG"+":}dgq{\c:9#C6p>uF:^}6ۿ;q00O<\ 8sxEk>{UBd~m˒_"8mAGB^-FVP:rMbA-gfPStX\?x37Kw`irIGJ9r0&A1!"i u,3ܷ@1Fg>MZL,lu[s#4<]j wC\òf;:lJ^/ϑhŃX^D/`1[ _TD5DLȢ99o;`դe&Q&^Q?:R `RУ 2QM+ewsϏ=RnB\q ؟+i<6һn0Xf;Ϝ@X)6ƎsVJ@UUVG-oؤR , $&g"X/2AϿʔ{YErv|qGvkPk{ΌG9#d5H\wfa뢫7][ 8ATeluUP}[{}ԛB@h,Mߪ^ LbQݲ PHVЛФ -E`&qnt4}'R `|('B \rPt78eV ,[ft.#_\4A hfaxlTܚ^}K#w:5לwy Zn&0UG\*2sWIԧ'm2 e?SƧsch_mFX鵉]]ͨ٦Ӫ|jX$Ȇ "Y82Ta>>h0y#8;ʤmYWKs_(o0s-ΊG4 -T =حoo?i|5>"Cz'"MUR8>*=XH-nE r_|JSL4F檮")Աe.Qo-d/!ZdPg*ܓ5\]$9G6'[9>E|Gbl/Y~~3`n%iaTgri͗i˩J^׃`9Gӄo[Nt;ɽ>2oGdifsQ[fpo–:Z@RbA4KΚs:9tPPK}'w:ˉu"\,k*^#~͢'2m4Om@Q(_)[y͚*pё#OxJҽ2Z-yDb*ѨMELG)nE1z_¹ֆwo#G̘uc`"ovؗ4@Df"x1 SX.J^GȢ bRP29aPnDp.ҘsL_v\Ff4P~S(rѻ~<ָMc-hUZިNE {L>-͞UK:d!E,~t wJ=nT^ TFЏؙZEu jbX;'Rc!:|PZ11X.f*5UF!+HoH+E 6WYwT [ymEe,QH_lW՟/~M%ǣ >Ih~yR5 &6Ϩi_xk%䜷:a"C_:7< ղ8*T4qRĦ\{PAz/;а.FZNSNdyr-g|4f)a!.]s6laulK? :uE J2* pV)~Vtͭ=48P1`t.'?Eù6/M縂:pB73wd'2t))Fdӿ?Uz+d,d|j>bkneC0;^?RtiiQ磌&#aU̻HE.h /Hu+.IYX/s,Y圱(Jsq9ɺ!A26?ѺLwl?kH<\M3HBt9 >eQA6X*@wʑjU:l~Ղ^J^ݑrRS{J^hR | DjaXjJ,L 8^H\9'JJ2uMyo70p땐tDȱ&ڜw$uZ\BT KZfzkLjpr'<(Hɑ$Ƨv%0 2V1u5tMPP 9-I5;(4"{43<)jd#&ܛ&̿PG/RP` |0n(4&!XN$>,`w-׭=!h]1Y0ui+jhv,A\S Jpȷ)7'דW/Yq/%οWP&B#B=0D=B_7@1y|{Me~~.#Obl"El1B7k2-ܡ~l)Iuo>H=陨0isl#UUVLENppq>* 2-ӗ=g`='&sM־m}R+h" ;c!-)La3ӽOO)9~gsɥZAS+獊W2!IP 0OgN4vy\<oh_ Ciqs@b<`*QD!g"K/AXQ'|[;Ŗ{LO0}T}t0潓jEdT/|yȨ6}=Tfr]G; _$1*#c(k u ?P? ٜAsg+Ʃ!o(*0`~ǒbh=_ʕV:;R0e }e)ru#@7֬,"KlTE/5e] ]vO-8wx(MhX_[р)4 wc,d b|J:"i/"1w.g.$M9!?j:QvdyCYj pcPV5ĜKI<(+q1! ?P-O#u_AgBE)g*f~q2#nCz8&,ϜM)).7АR9aiЪM@[<kK{22SK[ҹ&+Gz'!/"/^% A-B߽֕SkuG+^%j%5dWP PWmX_TKnڝ@g~;Qo:ϠO##bb{‚X4o>;Y;/eQt{Bu=~>3w<6bNV1nrEF**$ mvKd݀ę:ұ6BFq.43z⺆t.&f aB`eQ^S-jx( g#Wb-/scy\՝'k2̧l9:L,VEc9aO1=-'}^jZmB"e,OD`&w'BEnfbZw"0m`K/0u6V3#2ҽʷ@9jcFsG ^OnG;ŇYmG68>R4d:#jL•*Om I4:93>]/X ҃3<֭31;կiduBjjEwHIInSZM~ceN~q꤭DGamߪ۸HLKUn) ^ sY$C1ban0 ae0Zk 5)a|!^*Z:.Nnަxp}@V IrY57ڂwDuц^bݻ_!l~\~nZFf1ɼFÓBR/0KoT~;O͗p؎ J3h1RsLvcGV0eS砷5NX(Aw"swwig]XU1xx[p6  J1rb.v8s5pz6YLe娴+Sg>|}Y X,$(Yɭo߳Vw i3`߉CѡhH<_RJ;SZ` feNa.ٴ7Y^KEV̭cTs*WBX.g")ADbȍ8r1MxRu#yTqʛu6qW_: RI(iVrV{dI_{J*_$4[N)SQ0fuˀ V@K@0L0oON(M¦vpv \ @KF2"+ekm v 9eoR!TXпRyedTiAq ;I?^?Yx %[qI*!RC'C 4M <CjƲ狑LYױ+RIAr9N N֧kV.Y*ia,y a+- pWRFE 9oT=,prI AےP-U@Y1IڽCL]"֓nplSI cw™Kt0X%o[jf01s糑Nk|Yw }eYh]dRnd=n5WON[}zIP .꡻i׍<~xL XuWFS_T%|ld( &,j @G{r?TT:9{Π ܢ|t48G?+NJ?;qleLدYYۜH\R% Ϝ: d@Z4 i銱Bp#-S #/"OcNd谻۝:8_MxAؔKL"g%TE(GJ:7Qm^NgG?NF[,FӍJJ3izȾ&JFq8 ) "( 5ΔZRm[+H%b)Ŀzp9L^@HR2_f\Jl;EmG6Qw5MMSW̒g_Bѓ#^`[ݓ?? (,iHKU?H~{r߄z<9s"4"xTM$q?G3`#pV<ҳK="WGE_ܢvb1Bޮ@7ğ8A; 3=ZlD(# oa9 QfQ~f{Ab<ю*κ >alyXS7ju^Mt&"YG-,u ҕ/ V'~C(R"k z{FULA[[cςtwQHC'2|ˇ.e;|z Cܿ )Bk-ie`݅I[Ѽ)A7;OneBSH)JvPA~pkJ#hVH_f 䨶~ m1fg΅smSP`nrGxOX/9bQA|f9KKͪ컋h꿬P Gu '~˲˽T)Cls KKe%zS,0E=8چ*pϯĢ^=FYt IR1C{X1EILfvT5ն]ƣi/w%ˢL;à?Dr2f/-wЯQ'%,=>o`6TCUz <Œ$;D%F7Qi.ܿq#.&?o+TWODOO@P5MnFLyܗY(cZ,hhBL%ஹEJr9h;~hעFytPm&hYKKi4cQ)y>֭{68W؁J8XCY4~ cH$aCȈ2iUAe"1KiP?+FehjoTDk\ܯ[]V,.y/ HͦWCe|a\pD•βBN-cW3):gh4wߦ64}No-]y=wۤFM۸ L7 {y{y8+oa Zӑ; MdD#8T(&7`VCPԭ Ʒ{1 a8~ek'O3H*{VX~K";7>a^8gB+x|uӜ}f2bݑʆâv5_|7$-RrCEMj;?7JH ˵ آ9:|ZΦ=ϿaJ>;_ ~gE$L3fq^ԟN<7a=_2`}J$$3w!yxh [hj:;DnJP[,Zb_SR. >i 8UcD<}2rjs_]Y9? :>BKFav%u :rÛdVko^&| L;|B 0$SY*} z;4z2LJ/:$^#C6VD9-a1' Zgxt"#u/GT3 7uu<&S񈼊yB8*ЉVN*йoq)׵Uu||fD%3pJcL !E^@!/B '.GJ}@̎AQcD-aNZ؞2.=L7ז+`c\UGzrnZJU y9f"w'MeE ;"'wк _BRǣaGz`.Q=[!z0Yu9cNĂIpS)D8\2:/"21NV2]Fcx|Nľ!i{BKj+]i#7YX_I)/Oӡ<WϏXzV2hD@D-QޅmB/k\BYc@TФJCɦ+eM"SGJs"i⮳v*;`X=,o @y`<ID>#N,׫DrUsG"oL]T\+|ђtmKyLmZO҆(dBobvҊ#& 2TrČ.%~_}9BIO2U0:JVaVUGEvL{ DKJ n:؊tsb͖E=-2pB Dh&yb$^žarlraZjShdI4.IZ︲b:g9U Ggm=M3(cb"tl!eF{;zq; *=+-!YNHj)VoB$^{ `=*F2uT xz!a0MfYP=mm@npn! Ro~M43/ \`j֋R(B@.~)`m$D̛@Hyu6cK:+>cb}T~ɆʏŬ.k<Qb.]g,P k#llX -!ݲjfdpR%%Ǹ8(a8pv bGV!1N?om j_m?ߔ;g쉮DS!hgǩNط=3? *xBr:!SRVqʱ稲4HbUzLyfHpjNwT tIth}#/duK50j(75`:Uda> ~M;c ޖg+%/wj`6:CM%)uv %S#H{rѷwq5Z{=IXyiZ+1b ĔcU.3QFRFhN fӠ͑G+=1(;zo4k14KO}d"n8?$^u?Jt1UYT7w"^D&0Ľ2Yj@ u R:"$:12BKlH(XMPeޓ)M Nw C>cj}k1Γyë3Jz|VD~H )w 8*BwLN߱ !į5c뚅zo H>ج8=-׏/$` h'=哝v;I&:e޽Oya"3:6I'ԯDnNx%y^l JY$UB5"X D0a2ZG8!&^^]Cv Oq8*L{],X[OWBB|q.ϧHXsk(T*"iV0Iumm+@ X1-?dƇtdUZ掇v"ӧSpoW 2e13nu=;A=56ܬb@96[e 덊-9{4*=][%Q\d~@OJk?o:&+Kv ̝ݘ!𱘀"%J}h4dekzgn:z> i]etQh( 5eUd:y YΓ5kS?)lC{Y]eV,} Nÿhum^= ౟\ve Zd8Vm6:^} h\T*GC`aDUFK)`(D;QGyT  Y@Դ p~jPCrO+8jM,yJHp}/Y[ƅH.FʌS!; /wv^9Ǎ)[$Z,+wkFfKpKCkaV.AijxY形llHIZe7>Ƞگ4 |ϚSKa(vaɳUMaԳA!vx J՟ ŌS*+\cG~je%e:W-TVOk|p.;yC7x?jQC8!hUMc+yku+tdAP$$V}B7: A`¿gw՗5 S>RN)}9`emf 79s͑☛F)= #zlHB*)FR03 8,n@ƞ738N@d8yu\F AcÞMҧc=]\uqf݂%BtE`gñg";D/j'b8Xr̀}iՈ_~鳅2]uc?Cﴫ:6 $Ohb HYd! Be8 <` K7|VftLQ$8؂%RB}OܔT$eqq{RrD?#zQ;HE"t n8_Wf<yFVJkgy9QC .v+큕|B۠,e6N/Pcۺ5paGvrs>(1ٳ3;c;&Ũ617Te s^-k:3/(Iz}; ,A?pr.#9nR𱑧pgw6h5[eBpvϸ-G<ņ Lԟ֛F|k}?m|= 5llN&.,ӝv,8W(sw@ GewY*x" xuSqG?I'|FI=aICcyeyk~pT(NR R"/Gq&!ڣ'EnrPmDK?XƾU> Uc oz Rl]i8pHWV~8d dV' v@i,(?Bj:%%?tAznvA-Qˋ8_nrd ƥhzn#T~46%w5wVFwolEv5ܨ2OB|.^lEJ^Dj6cOӻI>M:{ΛT> ]j5 pl8{^.qv~[@h?)IG|ue +*̀FsJ1&!da}H+X _NJK8 Җ+觘@L- - (K,EbTm*A:j1(BzFWҝ\ ,C`:>kXc̒ 4Kf+$m@}sXr4;vA"_o{Ca(L%pYvP!ŵao6TGD Bmt{8[] kgyE )2 je7^gzi#ʪ@,zU5"EƵdjfi.b{)g.-8=>-Y⻦qYjDI8u~$L.Zά! Ll,!V8Y4+"`ӄ8OTAAgưUoI ‹ B1/[[f_7Tvݞ;]~sk,{+GU2wō ; tӸy] xYlyK(a.vD#q8(8\ЬBn S=.?g֔cb"OIMX0nYES(h2:ޅgwjGc_%Al&cuh~"XK&4j5dR[B=:Gv+{I8|wȥ GZ#&>ZJd%hCG<5q!_mQ3QK7X!H2vN{x, 1 wV80T_hi*۰IӤ $P7nIgsJԮ;UnW̵\#H`0m,5K`#;Zn?oJPH᧛rP-y29& /ƌF9«6oK|@QPb5rtd{@ >U Rtivzx)j? :f0J,)l!]/2LNI|!֨™]7.tedu+dWd ZZ BIGt  F+҆/RpB,f}9Jd^_n7%MXީNLY i]^&'WT1.ig/,xQD>>3T}Ip6Tq;D%@ܹ˳ .hƵdvϊ;tNDVUZL[wbN ՀMcXdΝm~~S v G*e*NrW29>5<䘰vHقidzL?R'*Á"I+Fn_#a}MLzgpOCh(At9>O׭4%,9O)7sJh'TUTa&Ѭ+ʟv| /m z4CLS{2S۠_NE#JIJH?Ul4hfggY,\eN)QB oOpڱHce7g!22< 溟Qœk+Ā/ƒ$xK1Y˳Ej o2j=4BG}$% @"O2h<$Y#BaׁF+c ~aEGM|["|ꡁFJnȆ[eSfhU łLBDBs׽E@<::Z,\{N[oJ&0E?p X .IBۮ·{ ٟ>it&f$QZfK0qk f#qtJ>]'?}yeg7T2yl1 q[}(E7$?0%$:bV!S<@zޥЍ۳@LaPqWRX\DgjHQe.,,9AKKis`l _pSJ3iucoK8l=@$˻Y.+ڥ[YRiĎ= wkK_E.J~Jb~~c'iՈhp>û1ҌlV/S6,S ~F*4«&Īy!*J]Z@QK7|1svAͰ*-~i|ZI/]%v$`>38rPS%Z6Ĉ:m ۿ~$ڒ.2|MTD .k*nȣW?cJ=h<12oH`37@F;i%_m}43 w"kGIWց^M ="w#_z)SY #GN|U~qf7Q\9 'Цߎ~rU:eʅ[d Z~% Xoaޚ=(-«G\}).sr~)_]0nt}%*a"F%N.3z Rg*G3YߡON%IJkM7&^֯?PǼzb0a{+WM6&^Z㶁$ģX5?jc2nGqfuh…n'&3I"um!F:jP7$EѰƾʇ R`g9 jLhW' U.|Ma2䋗 ]&xlY+![N-Z"-S_ ǎPߴ-չ6 ;ʞp'K<(ZNQ]lP*}i.ƅ$2re}nV;Z=z #r*ςp>#o'i4Bίٛ$Ӏv$(UZv?s؝J|#vFl |Uy.s"8ָfJ#U2ܠ.ݍzB^ۜT s\*I4ʴ.K=Bמ^{l w{wC2OHlEJ=xVĦ鈜lRx/1R҂&s8ꍰXkkbX +z6R 9t7 H஫>GX?!G^-ɹv--/c#1YKKҍQ2`g4AL#5D[B!!ҔD\2٤[u0'k_l۲g>]$qE7DFEg+>q -O0 tR,.ŏGDZE3ɽ*BJp(cLKRڣYt+WgdU+)j> +!a8H03º8㢇:܊OF2E8?Wε̨;0v0RsnwRo(yKk0:52;$+*ig4.>5-rfm@sF jn M6x!*w7Iph,FHA(9GS٘'w2xK5!%05.L1/]wœ|P'ÀEuiGEOrDTܺ?'~. kbte~7Z/[=8Ә?b4D 7/c_ǻ$(tYC$sSY R>n"N 7fih\$kj $j w'k|F;0I=b9/ : cKHovҭ-b[0Y,y{X.eGg@o4i%LY2S8Ջ6aن(C`GVfJ@yR5]j0hݰmJ2bرK$<䪅v~#]C?J ur}˶6tH3fq< _DT 3뢵䘎 gC&?fGLrP6 v[Vb+cFi78̺vFp~8996QG%Z|v4ӧ]!)=H"e1}[0, ] (-sJ6A(-T1y>JQ !ζ StəHc8W Cx-h^G|Sy?C.g ODB H{#L/8JI#m>?g!:.gw擳tS'S5.⟛hD9l!P#^a3=53a~mQ|/::Vl@,^˶;RVjcU,u'3'P s~k"ɸ->oLB 6$')vI`4k`pTc>Ir/0Eh >*9^ӄͣ gJRy-D [BE{UxT++^)?U4PˋepV#֍cOC*&ߟ 1H2@Y\b,v_|źۇ˭If^|Jt9LnڿkXD.nVSngt䢷Hr|/;DQW>s3HS5k72Rdwt6h*}w`tY@ymèH 7Rjlgb̟nbr]q,{$C9&7\釪l[+:SXpY+Lr`3>=^X539\ P;mmMmRhqߒ;ڶl Wg\v%>#[FfhnPQl!SbsO՛!d)}q>װR"'U #vo Cs"B=-`>qAͼ&\szV˖5phOwy`WGP4t8̥&WoAbf,*Z1PQ%:_'I5:PW2~'iiYs=o4,?(԰ޢ|RjZ1Jr?8҉Tg!GBpE^{ދXǹiWcPze)Y]ʘx 9'th-5lt7ru9m" f]^"VUHtˊJ-C *PWK{mI%w!Ĉ{pZ-ϖD n/>#Bf84n㎁ +!'6jtfpG !"y%sRL>߇%dN+m)h(UתѶ\/Df6#@D 8Mv8CXoU.ÒՒA4&Ih LQǐnˀkF=%[.//Va "YxKnE=.yE*<{-"FJf Zf;":@FGᣣ7zZ`:9 @h6P.A~|k ~q' )pqȿ]w+ G 4juS((NMۭQ_ qǬ:wAm]YG|* ׹ m p@O(\ףv >?2N!V;&LEõAgT~D fdwLDŃ?dWK5%6!tm|5΀%fY2I:;iy¯`M^EG!{ޙEy*cX L|1r5L]T޹ yIŒkLXU؀HT. {sZpN@}(3 6y;`ro{~H/: N'eZ&Tmo{>FnbGdj_[iSk$9{ZH]c3yx;mV{OD !7vߕMϼe;_w. oD|]R wY9pwВ!2д6:ߝ6%LkTgT~iSgiƱ:ކvA[[Ľă(Ӓa*PX㾠G?s!rMHcY"gB( tϬ( `|kEbIT:qR;OƮpz|2.%G9T6MJ裳37=˵_Qsr+̻ g냔'>.ԓFj.G߉Xևx.OT Z4AFp},r<"t:oЭV‰~cu+Im)VQh0g%k{M5(|9)= X.YvOOem<9}z1+MI6b]CCۆ3J b "q>HG[ڍ`,Oͧ[H !/W-ҙHk:u.f7ڃDCn=zoߜLm.ɹ ung}4j5on9xBdY`X2Y9HȀ uw[[یK@poVp3|Oߍ`_ ЂA 0OJ41[d_"'8aF0~&૶lW%0YhaZ>ITn9udI 遰<]`]p T8]Æ 1HʭrZ䩚k ٽ՚Ad!LWn&WydLm!KHF.I2ܘ^X!\L`׀p웷0xύOu=4Os?9w\9(M `jWH=R&aiNbi[D^J~l!\;7@jRl0Կ=zD{97~FwQ<줯2˲=WhIm\){hq"# 3yqH5LgdC^ EʡMH;7b<ñp+{AQ8sQ(7}bu꺾FNFѴhɖw\lgh7*iệCfزK좻e1.=΄E-!:%Z:¤68+֣k74s14.A.OB1n祣6,:){`X;)^.r1Q\]]m`+ .. ϸ2`%"6V.*F* &Ku "(- }~o+3pQY_AfcOyAD:F79/2g{V`N3K"âwUÎ/nPކ+n5MOF8dkCv]t65ϕHOjQ_T{*m6cg G>]ةFx4* (ehv}༝y6RZ*Nk<<5FZ%QoZ7:jEZ8!D j$d>b_~:W30]~2 o c}P+ڍ-UCC#.eͦMb Vy@< ڠuP]V0#*= +\PV#E l)nN _4fXn&M9q2Ai|)7y̙\,CZaSD8Zyx  _.Xjmǥ: o >)tXl2@R޶7 wl tsH cK;K힯m0Qsil\@~R|{n=0rP5Rd)K\5\ݔ_4ظ[ 6d3LkIsD̽Qݯ;Eϯ M0#Gw&.V_7 GO;lxUy"mFNc*03.?v,k څ꿖'ddsMȵrlbp(lnՉ]9Aoمz7~^ A/T}Ih6Ŧmb9䱦F []ݺ 1x)(\6mg8RN~",,]x̒C~ 5`؊+lso<.^>}\m:ܱ_.vqJTGYР RY&:z{ [rW T<\F1h&t9gn/ jOeV xfkhEC/5O3.p]03')4j2Տyˆ^R du&[dD|E>4w̌Aۆt&dzo[{F8˝^nHvk5aN Üsf|Syp )?:pptZDo@&Fv9oxƨ~@GwRvm 9bg@>IJ1Ud.Or̉æ#QZ 4@|<ABw|EQ_}O`,C8v% pc xԐJi?F ^ P'J*?P d,;$6^iu-]<_l:AlJE&?5aAEL$`؛yU`ٯ)BzeQmg|͒Ue ]bs!a`$aXo#e3Ly`F75B r/M~pKF1? Bu)3׻3 =Vӹqin h y/yi)䌇C`Kg{[R&4jpڒhʗb@QȎTRƌY&" _g`8Ր#sy!tv@&~A3g*lX\7np!ԮL\2#ڄP#=3tE EBmLj'N\iJҦbdAw´U4{DZ\1:S=K/![*:lTO Yj]9A5Yš$#Po-9u#o]syh w⌻Z_;xG58u2N2Y]Exȡ,QbF,0I$>5WM-,i64IٞneT8\9 5"kOM}GA@ 6%XB)度.5m[B3-;â%Nܡ}NEуj5sSӱ* kTuDBTBѤ\$F[">$S;F-!W~F~e;}]sXhc#I֊ql#Pκſיrf=E, VJ9QJY::S¬.igM^73 |ўHaX,(H&:Lz|Q}'kjWPobEOa #˴ks35@xW7V63cdTeRy.E mhO ̀n7ƙA߫G'l|%T95'`UZC~I"4'\_ֳ62Z8TRt"urX6?=s0y.&dǦW@̏2QNai%"5/t W+eYB wP߷Zᙴ'iʥva. Uacy>  I(nd`g₟{uVrOdh~6(VYSVx̓ }|^{] ӳggQqIP؀Mn5-L?? )6 dw=5ՒSE`&N'3d %4 WuHf@c]%^$lj?;:zUPM& {ν_J8.5EIc,{ZJ \Y iዪoK /@NthޤM;iB}5{+9 {O4.x_5!ez8t8W5XnHK${c0wNm!Ͻ{{dp} 𚠚8˵_f?M "ـ q&cHs*7q eFUȜ.B( #*B^?:Sy\[6W`,u8O>K Ɛr҆*I*fNMU^ , bA/G3ƭ[J&o>3W1/s~5$ Vqu-igrDz^rq;PE{Pip wf k`Hze:5ۏ8OB一 <)P| l@.ګ(s&݂fvCl)۷1oIjaYn>ryxDTȎǭ W=>: I b ¨wΜJE)/wv%<`a_-cv\93n"vF!I2/6;tYueȁT 3= <KUs@58W ),^yk"ޛ(gLJ?`IjNR71{z=y~6EH9>Pe|B>֮^Pw TegZ9WDb"|Py]L4KDo0,c^3`@FH4~mj(ƤM٩z''@/+nd s\ti_i(];?vI}oTµL%U"wiIᝲF _ ҠLћ5K,Y/J}9I0Gg ܏uq=uflX=i5bp(K86EG=.o8 ] -QHy+ڗK"T/]A~:Id }ƌnv^0sd;gRIU7[f ׸@$!%8躯@/A˽*w~.I>uf&J$+c'39st+[ojg[ # M(z!c#>xX^=k/.*[m f|1uǖT ֝D+0IuN0nA#V[ҩ2GL rDb)F"ϙE ,p)gi`UېzGq'dxCxAjMɮZz!~: }@TD g0%Ts`1'trqwB"UNz3dmw K-l`)$jeQ%wE@nRbݶRYƻp̾w Jf^!uȾu㻈,t>l4Ugxj) 0GLF$i?up)thE?QNe 7hm@C(87#C,! 1=it>Ɩ*$3T0]bZdNM j߭,g'qlΝqbWaT vH4/-)mGXjg=8C%RBb".Hwڴߩϧ2ax꾯_t@gJK7U4*W"Qoat܍#hMBPXW@+/+SSRxU֙aQ#6\꤄wp 4!m`.|᭷Hۏ@]O7W\]"}={C9f p.ב/Z*'Kj&S JhgLO mC@(v 3aV[ Ql^:^B1Rգcok4Yo2G~;3"<ק ;N.pŞI^P*oT ґ`?~-hT\G;vOX3J=cPKu{JVj 7 ߀OJoǴbF/[Lw3&Y0[kǙK)P>;WUjBvL:%r%[MOA$n݆֓‰Sڅ"?=4䯱}\0N-/eHWDbN=xuRV˴|wИ"َq1U&WBzbI8U#,]Cg>Ÿͬ:BЎHlX]8(ޫs h'SfP,;st%erAVjk2><ȻQ:ID' e \ApL yuhO,FX5gr?=Hm fsѝ܎y\qc˭yNԟQZ7Y],|&/#~s ~Ίbܘ q_ץ h!s@HSIA پUܥ/tvqXH-'OxgrC~?0yž>+ uqw Tra׊+%Y(2ە09{*6Z{嶘ן9_4%=a'֙,nz#cD_o)E`^bf8gyx R-TNq`AC dhOnk >ZBf/7NS\ ĸ`cg#%$QnO1lOSD)H1P.p饕0z9ՉcWVA\)~>I@@Y/5]zweDo5a EJCW ^q Ħ׬^bc^]"Rメ#8 Fy쳐iՏ2;:_5M&DV5ϑb21S^8soZGԔ7Os='&&)?=B'Po@:Wn_0t^|}ʚlWPnVzHkJN/J*|M_2谮3ׄK$蟮Kc3]VjqS5wL{2 OqAIoS0OJ3-wwwk79nw <\q&cZ)׾zmf<҅Gh$Eȼ zK]KP/ʨk5oNNMOV{*Sm/e֨"^ݲzvQYc!a5/o8/7&Ժj%}.H}|={fJ&qVOK_6(]J0@DohgKgPFiMaGĬAj+ <+:EG_gD1_D‘GCYH5Jn`tUFTbt VaӇnf0K"=Xw@Nha{.H{J P54A8VٸY Kg$ߎ`E0jVxzh8M|{/9GZy(h7`a[{FGZ#3\*/ɬLgy'te]3=7OqF?abѿOHTMby۴p|N黡WYo6ǞźVaoJ2Z4+{zԴɈ#0)"2 e>WF$/XȔ쀍M~݄@r,j'iy_S.ۿ38jEA$(,'챦N@PEdҹP/[@w8 bsd1ES Oή(/D-s91Mc X2 j d-rgVW2ED]f T&b0HM"jo΃ śQX*Fx˗{sFmOU~p=fdU .<@V>ٝ·;"7Us+s\MH+#v6#[J ]$˜?$lC]v3К/S6vVZky-jFcGKyu`]J>oE9mPY.h9Mx Df/O-TnxPee wETIXkA](ds1HG0IHep-+vP1 NڸsEؘzTcMpՏn56 !?rb^b*e˹%(5eDK(x2so[z--&D'wm} ,dMTD侩FbrjmToqɍA;s_ȞoֽtUFT˩L9I-fև 9J] VQY&,&!fDq\3x}q͟BZs_}3sOZGi$:mif7\R7CG5f,4T.iO.6xjy|FS[*8BWGcy@m3i>6Ơ^a>@ u+huf3y J[D7q6Y=n~E &8zLKS\!_!٘-QuF`u|,s|Iw(O١gMˎ d$ru 6Tƒs͛ޓ+:qD̫E{ ِF^vhu 5#\[79lKPmR|UamdR` Z4;HJRpg⧕+*ӘflYD4x Ă >)%;?| E2\-mWWrD{C5Sxqm1bpsNCvձU|TfQ _$uR!i#XS ߓvePk\7x2h-$R t7,̚2g%O±{3 *m g'C0gdow}s&pF+4}0d `ys:"7q b!ԖYu?"IWλ)BV Y(̑bdc+A.zc,G jDM#LU K ^ɥ VG >J(vm1Ad"v,ォ-yK(pKV707E˥w͊ e!u8 Bͽ 8vN8C狼&MfUFGmuTj!I+*^]G&{0)Ay*'u4-Dvj^,/0OgSl> 6W EF.:YqVZZ)g;k{0EK$^w6 igއg!ZkK](KyS:< ]C!]nBx}tum*T/Eq{HNP * BMHP #-d9.7ȴZ}`+u/8f4XؤV bjF eR^7˯mZUO;9os έBb&Ĵrg|AnדT`r9rmYWC8zPX(@~79'숈Bv*'&wT׍C7_#L[O6GÞ[_K 5";~&`Ix@IUUQXHȵڸ<-y?B$l2Ofn`W2!!!sУsMqBU\/), &Sahm&6roKPy9σ43 ^e$z.h'4.u y)ܖ]$ra,أQh9;> A@GФ2djJ':%9J^sLKwW_/b12R5,G~؉vĊK? Fa2ZTtY XtzSUǙOP0tgJEU*K q7=C_kl{JcLg} p(AM~*~LJ]lI.)'<-0'*4-olwZrɴH|\HS~zke6Ҧj3jm|ɐ*Yȝp&s/޿<_h -)縭kK"uB^-"2~QȻ.%(9MU*Qzf{ *cבnISlЧ" Y(W1" s q1GRg*Y;M@>~>DHgRph7q+ ^ 2ӱm!!6'^y(w>oe/QHF|ŭBuڻHR߼uSLn+L-O\l$ݯr:+8xM?9IaCaa<4ڣ 87NZ TdZe n:C'R}AM`w@C! #:Y <:mu=i굗Wcy@:$nhD˔Trx&eȋ͵y A\[ HhGe:sl1ֆm,$jݙ~E{9>i`hgGrj_$ѣp/$8*ۙ&4&OťYv9W'Fds3s-|yů2~MpҺ~l$ǘTh eV}Z{Ԕ6j:̬q1VUeIK&ǴI7 ~cmQ!*4yp0/^/?/zx1[{[|+F0:"vɖe(gm[Qb>hwW%r Ik. 3iOmոd2?B&>*Ap).1m?^S{`qa epii\b턔:7_?nٶ_^չ;OӵΆiҮ'TQ|dZjf z;k9C J j!)'?bfKfKfϖw.Pbg$f?y @>=IWKYqyY-Xi(P;i3'@l}LX<KE( PsS݄Z1SSJQ+}oE."b3Zqd0=1 :wkqȉN x{gXR<:z]RHK<t_T(0[M~k;ap3Ckz5w8<&5@3行sSr(Ur[UѺ]E D0CVBش"/Z[:k`OB9qe/v?fMB. /2OnwM`X OE9&G47;f28bHX(AU9L BS -cxjf jmJ]1|ZE2/4&)k+UbYI+6bC"i:M#d B N~sh7ξڮW{_e &k:|#,\MFҋUbe8eꦣ*gr6){Q0-d^'՞5bGfcYo*Um=?WNY(ϡ@@Ӛ}<5ab*eB+uuG@Paj֚AǙ=\6žhറ,EWad YW\VO-x":)VZ`W+vir[{q?q#K|V>|4!q4UBW2O6q+ȸPSް] 1x^ݖ p%aNichk8( B%J_;ڥd]ZiM9uM{[8hZa %pCL(-9 X]: 6|,[]h5w2[L^OZ igkIs3p)ȣjx+S0KtH!(~ee9zG5F31獶2)sjub߾`ۖzv]8"@g^b`V}a˙~Ғ|.fkO"HvX]Z[&_(i PnZ}Hf" f}*'d̸9$ӭ8×z,Z{*uc.XnɕK ξhTl>1TFVYqmb鈗kvkX0Pme.ޡ ˅BdԾӚQ8I \ u2Dgnxc1H% %)KX{"jvbc|.5(胤doNI#dFK}KEbQ(jȚא9Mx`TECB.dU:VQ@تt8i@܇8:h 2CP(.%gQJ>N[s(M^`Jz$JBn~jQX%!TD(L,cߓ\u0"%`mM`@l Ltȯ iݜSNu]!!W+ΤJEn{p U:F+ Kr?⋷,YTJP_af;SO&>0r+I2v,^.v 9|ohrko,Cב ݷ,=Cbd,}zQ@ɰ.73Xp-JKZ- Kb[ +YeU;uonKO`肱:\O5{V'F5%$8af$i8X&-XL"VRG`& ƿς)vQ1y0/I#]`z,ko.UT]\Cا(! 5t-HR[j8Mf:oy]=HMlVR{kzC1XɯCȥz;*XZ5=A20 \6S%NHޞ 6d%grLi.XߦGy5k )wm}N2BbQ9LҠ}Ѽd{N"p\BnRbn?pe.kv9իhFe#pgOv;anGa=@t[b}8fKcMS +V;?NG{mQ7fu|܈;W*L^+&` e萏&Ra\o ` ^7& :g5sst-*^l7va%w~x !FChZ!KÍ8I('O4\J20{K:Z5wu "ߙ_INI&/X.5 fq'nG[ fU1\_QKv hzi8nw%,Q'JWň._V't.Idj$)E]֩z*$/k>BKͲ~T#9u;n:M[Uh̕rȯq]&mE WݜԚlot'TH\4X! rΒBoo>EN@a PZ6,U 12;jU_n\,u>ekCUbG!ht$Pd^r"Qk֓^Ѽ1G|F?JtBMZRQ~N8ojΔ/|#&?x<4pL&3+aBޖ{%ìYpk3"#3K-^/զo ATo|# rߊ7bOٚSx2ѡ~X "~=!kҒ@LkҎfZw/2Eu|XB,#ނ 4L_Z<駊zP ߪ$} xL1̍ڄv 0p 2.!D6- H򳹾[gd\-zFj1X*3hʢ/x -ȃK:F5`΁ܨWuQr ;u@˦+71uzGw2ൣh%D-Vr臅~cFnN60oVaE AdQG鵓-U?S,̺ؔXTC9>~b7[ե=ʫuEnuAo!9n:+ùlc-Lk$˲ӾX@Vl*Cudƙ*,KdFNm]om%DFv`_l2ښ} Ttˬ|*~lLhaml)q'2!(ۮ Q3 8b{l=B|z&<==| 52Jv, }KKsGXσ{7 AhSߔ!pT.,7gˑT6pMָk= 0X{}NDv,26-bˆ)0vOQMF/\5cOCRa zlz_88&K*w0s@Nf31ɢ03= $`q苗Կ^#w9 4IƍpSdK{ dK4D}G4O7qJJ"X[RJ [=%N=ff(vYpzR]{FwYZ8`ns*MLoG4e]|09'q Rzt4#}?;bE ܞ^Z{ xJPu:]}j9? SwrGi9GO"JzSkEY[yTإKb57&z1]4AA.1%6(74Jwl;aLcxFnM@FTuUc#ּf  # Oa4`*6 O;$V*#(Strv"NJYm )eb~@)KŎn"R N'ga%/r'"[n"gzX"=oP&tBc:r3%#3%С6,Xe zȥa(z1_;yڜ ͕`WX`p %{spg,RnMcɬ=2H d^mt2vӷD§Rf<؀O/b4Ņnu-fCP:BҸey2I:Ay|sh01a?;XhM95[K:k?ƽAgypȌ-ۙ~w^W%8ޢi0ƂE~oԡ8Sfs2m 3w bۚ~w(K}E"nN*;?Q_LJTBh4!:a>sWu+aBiM²/Ur5{ؤ(o[s ݄ fɦNH+͞|;+Mm 5*@0:U9R};ܳ-qh;Oo~zA QZw**ѿ>B=l 㟹K}GSc0Lz4maT@ID[ ԁ,6忲0C[!Ƶ"EvGE 9VWHQM4("R8Vy_s(GSW_37w 7O͹‹ DPGɂؠ1ܠH=ZTlFߵnY􍤫x1$d6q 1J'iSuuv$VB2d^]2's5#wf~?0eX Ab[|[>)U6h8Ct$>iJl;mWǚ<8~+)G0] n(~^+o?}?teLf;{E9[%ދ:3Se_PWI?,YhAV@aBK~L2'$K'wI# 9?!YQ+DX\uLh 48 :D][-Xx 2'oxAd yD;ge+?"̄g]??3_\ZшH`fV &蛨r02~5QƂÜ%gmQ kF1K3tY[=3Zju"(0eCP6,c"#kZu+g0UC+'GfV3Li*z #O;Vʽ[1tB9-QK";ְ!@ͽW]ہNt ڮazʞ/NoU\{ِr /BI07)SC9quJ!R4`J Y;?MDvLlpb oal?W0+ޝ#?RXܰbROtnm `! 'Vi7]mÎs Lw*pkTF= ']I*RJgno*@#@s|p,+ np&XK~/vV銾)A]BHt%oF>4j€k-\>=Vv Lv)&jUw ] "i9䏟_62,99 30?V}*P ۡ8 X~eh8.P[ 9>bY 9Ѽ15-`MՌ,/ &#m"z7nrESϝ55"q:[,uDk3w$e݃s%7OB N ;yp[x\"G>vg὿9O Ey O:f`ũ Zf~Wn 5B6B!_KT^TYV]Mn#J1R*&?/a?ض6B+L[CB02qlڏ%Ӕj~:]Qq&zgViR@.+-O9fN0mXW??dID5ku<.0/Fs9j1\0Q)*Fo>3j ˴Dnڒ ~`QwXPA]@;vC~NSIA#^e׍ď~z\";p((E;GʲZic R ]z4y•و+.&&OG Hn=N|%6q-j-{ HcyC{anf!Yr|&gt# q, K=IASv[搨l" +}{oЩ茣cQ0%UҚ0[7^el-3'wSO{F'b`]VRN"^0N o1%Imm䤵S.яy3߱jln|tR !&*B9~bcm* s̞@ kH/b}9"HN5NW̕ ElK0[m6(V2tdԴ"Nz:r`ADOtp W߆.[{ro+P{/6P'5u²8Z!pgcǺnCmBYH{YޯG*@ݴ" qΝW^í,ʼ3qK2SWIhdc 1oϜyQW-6 ^-f***|c5xt[ڹ(ˬAl_)0m'Brj7o6˵[˛ DQ࿠@Z56‰LnS!S:ZR,^xI ߀B)>2kfmQh h/0B]ZWF6? @#` rˍ#z gR{'aQXEw˭Nb} 41kU@<w"hq}uޤA:=Ifr8R0$kH2hg@TE&E䄜~rk' (pR8+]l-SE 2zu7,( R'dPaknjjqGs^ݚJV`8hr䙻cgNپəޥKVc*5ӺZv8$ϙTZ:F+'{f=~1[xі8Ics9 pJd&!/.f %[31uLuG)DhG?fʕ̞TOңMZ +ۈqaq}U'W՗ĝg,bM<`k",xǝ'2F HLJtұ,d/v0ƃ7cX@FL봷ʦMe!|ׇa;6 Ǵl)ک|լX^[T4>.~]tXOZ.6M~B(%20J]`@{#VC/ǀ(S.Hx/Ax`<k5CeS6-CI6D1smB^rgQ48r.4?Q9>(Xti=qx_X/[{=Z> R/t$Z[T’%U^`ےhc"ڦ<<HZ7JC |RKPnai%.,P-ocN RbTFZDZ٬ zq\.3vNE(ᄒ!WQBi$2b>iRr v ڹ:˶\ p|@-( zԄ$sSdx@QtseMW2k<1"$)2yG1 ۟8t+"dX Z)-}ߝ@e ,m|Sits4MEHGV#$vGۚhR yBH8:[дaԣ 8r&}EaIj@p#؝CNZ:H_f6a  nE_LMSKPчv/b0M:tѸ")xf}G[1M\Ou3Fl'$>!!WnLNl|GT8D.-]-rrrr qFƶ=@*4_oAM;ڐJ}~LH'+KOӐz+>$mWq$vq|&_qYEq(D(_(|ȭ5 BKJt2#N(gehphYKʞG~9ݩu5ۆ C<i7*KLa琛ԨD-KY1KB1)Ox,Z} 몤ۼ#ׅX-ndHپv}ĚaȣK@$جSշ: [=Ydge5;ʃ\3޾ge5LJ?7 G3y=Ƴv+TOT gO]|cjө'tpBoA[nyw=;T;!B ,FYy+D^{E4g:3c)]@B2?k|42(B <εi2:M}C| 9["Ébx},juyI .) ڹSJʼne8OV#n%4} H`klq+"[ZåKMQ({|2SxӘ#-I1>u DtY9bCET ;%Bl1(3C/%N+ֺ}f}a*O>g 1Hc@:}=]oO_+`6F/+*xrrQ !(v*0k r@Y~s)~̾&m1a[Z.]L>fx:bIU5>DE;1h~YCOxF"_aA.{ Q\GJr緘yZLoG k,K(m ~@!lbSnHj]CCJ˦7In+x֕JRDݴ|]ym<eʜl$.YٟGQeK!qqŞ{Jٌ 1ZZUBķQ{\-Ccms݋V.8#1!ZUNw$E)Quli*%ao'} JP(g3-N;#6?ϱ%8"/{p+ Pc- KmfOgqK-`]^OM@p xMX##Uw;?vr皗8CsUŶ]w=b/_ wR<(8t'k~HXOIJ/YBkU2=7!"m"~I)VrFZ :߭*ڬl-U*$i9m{>Sq; Mט{JȔp*Y){F\z>y;1Qڹ{KUYDxY"~qtdiߌѡn.)Pr.QŊ~s o7\>(Ĩ/8q4#3oz#vs~KXF! )Ohl($@T$j .Mi+\0WU?›VV{ẓv {o|}h꡽'Hj+0V9ď* -=dg`6sWP˜r"tRoJmӰIW ?Oner*x7 V߲xt #<5NjG7djmGxdv4b:atR7?1w .ka!ksZ־9&X1. lTwitraDVv*R4Pqekp6Lجj4{\kJ3rR um,s:0qSlT7GNl_Kb%5k|syW-\ɿ8 WKfں~9L:tzp:q;S♨2tD=*Sa6Լ(gثB}^،F3_t'e0zRZ,P(m\u96-w2@oТ=.V ! -رωk,\ NTdkٔqrX.*ݯ5s)#PI4hSȚb!N>LɌTBeԆZsGՠ;9|fY~S؀tYY"Р0>w] "5=F/ɀ ]LЙEhat:q9TIYi6L459 ԐY&ЕK[ ``ACf@wb(kɰ`D3!=,L5a"\H .Q@m,0['h&Sj+1Mers?.^oܱ }ׂ u21^ !pǻ "ӓȨwdІZ@3/^4n@G4Fv;~U%fkR dvPU%U8 ޵DU=)>u^9,-5= V};A @)sZRziL ʌe Bq¼Iw/s_ԷʦǝKeヱ/|wKzGCP2XߊXlD-9Զ`!(; ܓ|O? GFp!h_eCX-%VzIKE7@EUhp>Er.vC [C%jf[gv` 3D=iիeN$mlXI,Rsln*VMs2:d^"\U\Z5.w4NvEmWbDH԰ߪ 4dB5ͽ50sϣccc0T.\/ Θ`1ة=MgZd`2Z \1yS' *c  _wkt .tu!Rʿ`/B+[FZMgzRy/47~2*(BYѕ|!W+9 OkS*ӕ~\@(7l;]$AD T#w=Oc? $J~Gw(s!^/cTx:[lH;)bG8XIOlЀR_Hб jƅV٠L8mUdQ0.DkCs{%V/nk{i uwGfM7e:P086ݱ+Ip dˌ_U"{QT '@J=`~InJL.j0 e6kv֨${In9YzBQM!WǤPP 6Eq>og9 0 &=w/EbNJ4Iܑ"LSִi=lq}?zelb_'?A(UWjfPfo G|@o<{%Su\lӻec;^$OlD"pd?}1׼kXT?Ū0~P%t u 2N!L혮ewV'elm+{CbXKcC9 ͔W3$O+^ʷ`k2A-X2ڸIzfn7Ykwmx QWm.n,D)|+vσ͜0w"艟,;MAҖ"HY<Ss~("=m3 1SP?N"ɽRs)㹿xjiW6oV`z܃ C<)r]@ ny8pM\NN~AGbt3,M: 0E+32I8LF˿ ^Ćsj~)Kxdh^/U.KY8 oiN¦e 6|BQ7iPlEnRX]TI- B{H-Tn F('om[0DɡN.?p2H9Z滈BO8o,kLC&֪e(x rH1h=|zUE,SjF Z 69}=j<ܒ`j}r<%?.hD'C;| ׀)3t]˝q GcH$g'o] 2 ٠ /M Diz(<<σ-,x;MoNKS4X=qޔvW7- ˇEs~ ɹGU&t ?de4Lh _ ]V2$ZMxCm tsockF.>"6=12t5dE֦Rm$i{É"Pʬ;hjo^SFc /8N$Ql.`r qZ< @+Lcҟŕ cɌG/;v^KT)u9׬%~0[tõKp i*4c(|LL`y6RDwT}|1P"^m穑N+Լҧڶ, OSŐ*OFySf>:"5yo_MѓEeS|hDJ[[ v%Zh7o(%W:c렀(Ϭ=x~C]ˡ =tէ8hD )$Rq<`}"^ÈjjT!N#vN&l~DU[[\]!-wۈv`fLG~Z}[,@*慄s.r/ǜ]6;O]2.f-&Wjk}R|ǽ\ (} *LLCUv_:bU|'qaZ@ U$+@pX`F%")@ȇsNbS`F5'CTaPRvkLgg;NAsFE8À,3guh?Pj@\XfC޵x.? t c-+s۪wms-tzƧ|'$?#RRہS=[YJ3}[sʄaXJVI&lѻ")FLZ΄8QȺנ۵RvSHN:ʼ-.u T|vʹI^-pN#v heڲC&M.;ѕj$OҥSqn򴲳v'Nv28 !xE/tڦ$:!:0eyAj?RD2&=x&1b&.L'+/ Ÿp}˷rßm{SqBJ z +u#1Eod2&Ff*+J'w EpyXmRNn_(>2w2 .a vV!;[R:`kT7RIm)GI*D?܉G '"9ZHkN㶴C,4y8bgTP JP=äҵ6UnXuo d4/,'nqF3hKe~rU& ZW;"s(A&=וWN)N υO\f\{3#(8b E]\IDDZF ]:dܔ^4R7 ݕYbhlD4Fh*ph ž{E*޲W5=[6t S +˰hS8IH3u݈"9NsՆN\_5^3FQ6޻c9`AdAˇAsIhE)@!)2!=ɐھ'n)0.#hI F2[х 9e٢gYfW $tmad.GĎb⢄S;; 18)Z?B*/E4"Y/S ۸7cA?N>/jN' X9Y lNL5EHP77Ώe"ɎzGV/(=D4 Łj+M a]5~clP>В Z7kV SN"\}&_p@"G9 uEVO@uI8:((_b\Xk+HWն>:\7mZ3Ir?S'?YR[ֹk;s+)}Q#xg*EG7"^N@W勭_ŧɭO;Q/PV4 (p @u8Z9p:V !BYh {B $5>. zmXT^c_z#]}"= tp%5*&ӻhL/Wj0Oap@t`3:_t0Cf8]r؉A+KODŽ.tjasڳ̏Zh95|̝+ kd(BȎhE95wIq^_=^\Qa EhcD|8nWڕAr2ץ[=]cbҴkZs #O)Ӷg%q@\pb /%:ʣiN_YDwy1(e1ǕCWRsyKusA h)tK2}L*Ƒ1AFPDfQ:ɯf{'۸4 Fk̈vXV{ ƹq;;a$3/ه}(L322"(UFurdM.S)<,, JrDD)A9 F)}'f:!1wh!fĭ Nx;R4O;Re5yo*SWĥC%<"֡+Is7RIqݭ F{~l3x93x)>#*9"gFZ*^'"6Evk!FqpfZ֡ChK@}BPY{7N5!)etS).kM5Q6 >ל;x:!nuUsk2S/8qޥuFfi"ױY`m-ZV$-s0W7Xwb}VK?9K aU7EQ#4|fπ Zb:,l@9N4 E_r .U0 v/E#|0dqUjMq^͆I+4ςK{%,0Miu\0sOA28ZdC>BA>mzF/ Έ05YBN Wc6f6?ڄ޽ =$ieF]xjK"7ʄx `9F斚Ԯ F!\ϭ+C͛}-pj즂ҨK8>gĿ|۫wOio]]M]!C~@M6$q>"ˎ,(3 U1gV%r?CNh2iʄ ëp<%/Ͻ]\Q :R}^Bqd[̇LLΐ2DD"zЀ0j]^w3NBW#܊.?pÁ.j:[J&^\c:{lиU J 4e?59۱>FP3 YW>XQWM܆Y~:<ֱc-4B:o,vS8XjC`67GXoL3;wvL^b#ǀ:kK%ρMNvXPMͥ+AmXDFWCN6:2CX2y-8 ˀ^@qCC@`>!"*ϳNqm̤2P6*V>o[@A9Q&5. 燘B,InE5"-[)pwFjVe䴑K] ײַ(hgƷ856}fãWg5vx |gw8H3//4tBv= TylrpYv{fzRc{MxbC?׉X>W҄c7chwÐ_\fNAs[yH̔ń¯r)W #80B1Cy}~v -"9eRǶnLM%AN8_%W.~FοVd6\Џնxݥ鞉B^XI~TWsd(6EeAͤv 抒t*өGɱ_WZOjʾB_nB/U1\{9%ͮx_U]^R>r̭E3 ۬ȱ-)$IkV# |a~uC @ѐixİT3dTL*/m9VDй &q3pv:Ύ/]a ._Psi1+f+OMvnPb)ApUeXlXt`̈́RI:MNJN' ~.Ս]x`>)}Q h6`ȗC) ȈFzRvVhnKw0V} F9,uu= *h;VT*vܨ3a7Rl8lx€+Y薞0" u7vv oXE`{Ӹ&^cY+[(P_9 -X ;'s I" v1j{4q+y u}o1*rkN (ONkH. Zn'm}Z l4UUjOq*2pװEgƤq.WQLRH|Y߰%&4s5`s$mqv9H/噗 ߒtD47D[Vi3̫jN6)I8at>8؋i!hc`lbL9R* p'.lGmt;^tFQըth(t_pf|0À@HYS=[9aK'k3s,;ID ! gzx́ SE:t4lh:eeRNڹx{xĜ$ba^Ҵg] kKm,=-FIA91j&~m;h_ G9}d[s}A^V}MlKG_wDRTNNC-c >][~cXxr\Vlۺ 16%j3 hH8)9\ͺG8=ጼ`'ĥ6B0G[I#~iXD^-T ' rFfVƆ^.qAc c&Gn#f܀]Fj ks%.N :7E|^(l>:UFw:u\g]j|V#ZDvϐx 8 \f ne*_Q߱; uKWk\TD ݳ$ = d Y ne<8VCG8a[*:j!]ozL_TZBۛ߰F.;PmkVǨ}NoIfbp^/ z*cK.K} ~6Q6[Z>VaLwƵm-rWuh=p)eKʎ1i(Z5A#A k>o窾󌀣[oFLvïfFIn@Ĝ"62-fR4F^q*~Ov= B0d?d9Ñ*ȦB뱍;Ư{[oJiIe&"y=j"dFW3J]חKFWNxFn]+)b cEz0 AvA͘`gC6Ϡv7-"B<ijy3>R(J_FTKdrk%<a.UYI Mr^ 5 @Sa_S"Xt\),;45^R%'ظI d~)"ny7`(>gFfT}3%(F^`;$F5jv1##l<,4Tٸ,`Vq[3=%4if)c.K+` 'hH'jmk#/DaN/-*7QE!'a}D߳B0)λN"SEF2mNhS9&h8׆sRD #_9,XЧZ[Ѹb4{?% W8QR@姰~@Rm4U¼ ] og'.VRDncVSqu|c~V)' P3 XJ'WUn/} l mXJKCpGTr]+ @)!) 8k/|25QآQKOHħb XBPFN_NwA/|z}1JBY"pM`15t+ #͑ŔwD˯ƬthjӾ;rwӓI-{-6ޕ?l+=Z5 HyO @rF".iT2I E=RQ[|DԷ̨WI%OY%eT'{wտgU#J?X1ץh< }S1вTcF2|3 >gnhS 'S55u[jha(!w7ςber=DlZ}[¨(l-̩ʻ=C:%r)ٜ~q? MS^@msѦaOXPM^#4ZyuntrgO?\i/jF= s ?IՀb؂ü,IAV/,t~E>KzCkW@'JwjZ-~lm) Z9lx2("G 1يN$`_%%C[4͂$Љ 4(n$v@$I3?43U7ߢ2>18 oA jqL^sI*_'I'BG ,/S7ֳK$}=1h ӝcv()sR Bʾ+;m糆O)>?n>ц|hU@?Ѻ0<+'+<%{$Z,H[;9/_e}uMn{MP6Jd0+U x_ԬN[#:8DnqC4SXdX KIC 5H5szeٚ_ݾŎ*KMTZrSQHhtjUu\W ȃO }cN?JQ}o rA_`ll0L射8ȥ@zKi>[;3)a 9|7&9Bؙ=u#IO) :&K߿ڤ+1u!l8˟闘UMևbc6f{D+zrHn;sĠw ˘O"w7j[? h7Ś-_wK@{ЦHy#yu`c7sAi/$O Sknʎ?"{9,Tըq-SKVaz6?_[ba(LкU`T: MHz(f2j? $&6\U(A͏A&%U^$T6mԕAp6M;#Gr"zƬDҒ@G7-vQNƉ≆/\Lsz*QR1`gQ+hAi/A\D mIA>7`q NNrر4OhJ(S$&g 2qq9,򥢋dؿ @:=o}Yu;)|ɳǥC]q qm(Q0^ ɞ-3vqZ'RK-Y7d,w` \c¿F\(ֺm9\#Y?a}{{ۦۼw:^# Y`V<5laO`cjtB?Ģ&0,h&9^f"%rq@s5̨9&X,P-4(ZϬJa9ą$H}9Bj6lrR%z9E% }߯kc\Ţx/FH\#Ӄ[!S8;|oDt䫳yo(0Au|zhmɕŁZgP$1|Po U/69=l9 o8X h2"56benܯ^9Wr,*@ح7mLk]Z̬Ntr3QIEQ!݉ ale9ȞU^XHzӉś$3*L\c3^s[p֮.痴Gڞ(a*OV+)OZ 嬽-k;_gr{BD ͂١KLĭpTom> tu$v1ԵJ֔ij{$@[ aBD)7f(++0;2CheHt`HK~P`i+; O@?3>i tD7ﲂDP11Zw6ƹeEqʀ^=$m-Ԩĵϙ౐Vk*{ $]^X$ dsv:cMJ!3_S#mҏ7iy!dgZ–A^G*AR8ت @iydDh%jfKﺏh0*Y՛p|95%z\ @Y!'Ʋ]_|%'|A~ET!usɛj^JAŷ/q>YQM@fX9y$x2cBw_N~Bm#rPy>ec=\lA Y+S,碖D<`zhÉz˺XWtڲ.:gnMݐۥ 4U]8T7FvrRy %KAc:n|?4fe,@lLC%Vɲ+ŅhbaZE)khsՃCL SSm`ï'B/8O=ʿO!"w5ZO3Mpn6vh#ҷ.7<q/ Ol/ X[OzLL3ZyE]k19(gNND7Q b9ƛt >{_M4%oJ{C`h]G{ 4ÎIU kT?7&# 3Ρ*! NS׿O؛'س辧47g-ߊ[(G<9&83õg4w!%i2$5wNX6+l?4@r6LR .wE_B}Tއaӱ #GRʽ[cD\녿\.s9ro@@33vSd}ATPT\:e"WIzEphƤuǔk,j.O?o;C0 nV>GYu3]U$g ~9I> X I9ޕ𫙸f PVFL #ctVO>0 6µN$(% #'=w(M97RzH{j~qS%D#[‘UPhgfx@|13^rr_ߦO 0$7pW&iy&ILTZ2bV*Nlt(ap0ZtLtGh871Apx-:DA 3YFh譅!8+)7 _9~ROLH1SQڇ,ȩY;?qڹVN5\8efwdYի.i'f$vtB* ܇'+@(&y *A] I$̃:Sp6EӟcMǜ5&shj-9ݡ{$?L#￯5v%fNj>f'g wSOxk zqxk,>#@L^]cA2NǏX9"pyWÃ+I %FJd i0<|޻1L?8Ee.I=JjĉQ tvB4q,?Ch@scfm;t Wֿ]8vawsҟu'SIP}dE!cQ$}!=ܩ=$.DɆ6H>8EZF77%5f0VG9mTy*ўJN3)ٔc|YjhJ&yrXɤZz ܏{&KTbHh %xȀvx Xxc3eyX;ŗGl~VynSLdvO>qô0jr!J`sW8dfGKu1Ǫx7iDns #&|29lC؀ ޒvJV G4=?t37{Ry@S5-9jD=^`tFe^嘃P* ˌ MFZ( puA&ŧnB_+9*t5a[ K4 Z\A|N"RֱK[wԯ5_-xy4XQ=heI( $J+x̻UA@DB (mLB]~kFX2Ql#tEG}~ #-ˬ=Mvhlh#hY6l #S0$qn?DSC1l4ꋪNp EOv=NVʞl%*ۼ;"C65yÎaӦ{{zVU\ _[<8;S'Mb3r;kt9Vƺ TfO#$R+rNܲw3f>=t\k ~&ꢬn{ ^PizIQ.ZҀ"lCcSI:j>!`-wztAA_~x4IJbYlgAaV>6z~; ]*iE 2JU)IDG1w}&8ߌ,[@^lj&5SB˄F(b|` 큿I$ԿLƆ2IU$ɖ$ Vi]Zb(Id`vh`rΆ{~ci9e>&* }$L̸D՘C<^W{{ҏ:'SrMAް+`?Nz0V+U84b@FRĠ5}RouO@S Ѱe*~Wi4`zIZ>4V!p8:.ि#3lFrIѤ0&bǝF%`JqZ7X_oۡkwMÛG5:aM86mx*GO8tn\Bw [5EӭGۅ5/ 'SDo*:Ubh26s{Iրaҳ.[ Vr1yj35W0F2 y=-D=x\̚ΒP!`ޠ >k;DyمfZ@rߏ. U]\-)lԼR~b ڔZP 4Y`q)+PV@=@M<^vd߅һGFV.hJu2!ڵO#JTqٕb8aXp*өbfxǢXsaI@bܾ4%<\=mfRiB;5 /DI 3HϋE}jP\,̜3~TI Bh^}݋t p⡆v6;*ƲIt@k_p`̹K8W]g$U1IⲠ@bݞ?f᜾; ADAFyc_@~b:MBUI1覻#ٹSU5c(@ohۊ<*? /22|؄L=PR]~W];Fs%)(NBHDfcᚐg' |&"9_f'O^!B'}@Ւ%DqA''FT%,p7E?%$ܪh*􀸔VkRWby q7&c/G HjЂeAXZ! ̈́&; .sj\r)B2k8-B]db(qϔʊ0'tǩ$  {y'm?g"T)WQ5WZ$)  WB蜑3*mv7o;,5~$ӛߨ2϶9טkoGZB͓ ;M3=zⰕz_=*OC]eH<6t!ft_ygzv,dKEO!n]e*!vɈ/@٠b4Y!U iOei!ajQA7${y{4] nm7/.e"z B!4Ծ\&Oᮊ5xӰ7ڦ8e:N&BThS\Z7ߛ`tP/Yo9;ØBEFyiE>|̦*Xv+Hq3\э=S;TsҊʚꨠEoVHߋ PBEbGXsKkj˺7įK;+1`֚g ivt/+C%v(dCݟ l%JHj?آ"S)2[)"Ֆ}hm( nUAk~z1)1!,i SKo%> 6<pqvϐ(gcHE\;HQhʂэ|wM{R5$0Đq_8 |=VPk/-Z85)*}\Mɜ3ŕ\DA`al$ڻ䦡4t֋HSVgT{L~k!w & pG> p)m77ƀLFEB Oκ_!:0rZ&UOsѬ-+[9#t3#jdX- $bnI%zYH%|E uwL XOSn}H-9AAjP]hkl]a3::b^F.U=@O;25'x2@8TYpѾ voЀ$UqnѰ'Bur_k 8bh&G8I4?*Kуc+w"$EAnD~QƯnxwg<߫l!mzqUƹ D:f`%(D IӜVc~ 0G1VWHSU1Wl疀]O MԖ!ł9;ٜY(Y/Lθk@&lP6 1Ȳ ՝o&:b9wq<\Vߪ̓MgjfG@%Hǻ.K*y5laOw DLn}J vqʟ8&JAe9)T p}G:{ ]+^opFJrx":#FCC"dl!**0z*ײYD}qGTӿpЃ͗zdT&4KpVٹB\ /EtLB=/PדSdt [ yb WĴi؟ƢEDi0;`j")i>4χC4*RQ_QqɃuJ|*DfW31tl5\IkM<m{$BGۣQY!x?OYX˻CUI юr]&sA?<7l!ϒ p[+*9L>DwQtDg~,򚚽&!v^.YkyÖVZUX ƤC)̐q |,]MLJ HC&洭+s6OX{cx(2@vOBwOBFrX迭keb$6#׼I{ yxv(ڸ)ݣU`TxI[ؔ[~ǎ 'X-wANQ͸oKLI(}BFn.Qi+p5fvM =e$НfZO_` n2ׂX̡U$eXœ,V 4x"(LUA:ԇpKs|V?9c* VuC oi옌-h8__e=d@Le\|(xgxלʜCȋ+lѥV.E?ʬJP  qrđ*.NԖH+i+\UhYnbCo *YA/*>mu`;`u ]"24 mDЬ[m}&escx8S3֮ nv6y fX~贈$5#=! l^Dȅ ;OE9lYʚQ@j,FĴ,(=/ Dg%LuU35B60u?.‘Colv ﺔίC E ]bʂ؃g[RYc)=^Y6;ψ픘Ee\= h^:R}=H'Է6XhBb=-vD;݋ PCZ߫=M-`1T%{oJ"gb|Gz;YNo!?K'ٺP ctV77"⿈I]qI`.`+?YKz+9w >$̙ 7F~o?k4VB^L5oE@0}1}H)Gi\2iNx'&S8ǝw0MT?Pl险,ά7MW~Y4]l$%qR}3(&'/Ќ#:!''m3y'MjCA#J]ƒ9ǙwRS{ۺvQ\ J4֕SlXO5zwbpG97(c|2}\\l ݂4mHDNǙ! Wus5uN0nXshlաF{ C&O 5ш;ԺUh*ҎEXPhhqw^>gZcɅ ^1b=ȒqqHV@~3MN"Ӂ"}\a{T^B*5vǯ\Zs|s%fXkTyC!72ql9sًi 2%b!s@kZA$l0;ȴ_3WI!MHj6T'ӲDv5$.@7}Ǟ9mObw3\(T p`[g:=R`ĈoYx` sbJd, ޯy¦^un}ֈ\zsS0ľG],3 J#D`7GN9XHL.^ e*@ g4܄]az~y(H]B"DnI ) ]-`$?V£j-?}oCǶ >I>cB/ D> xPPV| H~l+BB}!ȽQi;E K-#/D`Xf35% Ru;iCCvQ@pA$(-|}코m= ,`ŀƧ͈~ <}1C8𜊂GZPK ڒ.Uev!a_uLr>K=&fK{&͔~lV7&NQ~?zSy!}c!78!Eg2V|iBq̇ d:*~Sr7`i{xSc8LTŦ9Sw}]$➵LFi{8 bSYڼv۾@⚫WIVy!*_#̅ U[fAGtM YʽwP\w|FS`,(l141 \xgB61ό̦CǒU6R_= h9x k{VL>s+[;sxM44mzJdGь\gv(9CebM粈B"1y.fKr2=g3z`Y7\A,t3<jVIɒw&k-d%ahk/Bv=, s& $xl HVXX/R\MūKhmi ]YFۧ6.^R7UߦA#i3Ο~DBw-(0֒x^1R3~_ѧ&oک{|9uČp]]".fzy>dP }׭=@Tup;cPhwPvY:O$ f,T"6teG(1djS箐y7 ]CY|? "=- 孮P$ 8kOec74o"~0)]##C;jT@"O$\؀smS{&BmvVUP(d54kԵh- /W d=5p̲~t?{jGɥmC: >eʋKt ?->:| (1`"`L`=.\fe,6\xf&-%Pά&NٖpDT;{Y=:  %kpئY*S{{ O.ƍ51`z4ir&_ ^ t4U>dG}yr)&mgwH\b#*ύ9uN@i lq-P4?Y֯]xU.(0Pډg5EAЇ;T\2/b|7g1&j\U4´eǘP8Ya )FzMA58BX,{w0Nh0*pw(pّVѧԗd.A*%CPEu /V0 -\ D3qd.Axn8wʮSMmQι^ PI CPR()͊msnG4z#. U',2\Br,r}[!xu_<&Gc,vNxxE$>J \c/=|̎I 7 ePBsܚ)JN\26R^ˆXW3 coT"v\^(0-@;́"/J-?vh6>x$ǫ y܄PK{̎}j_-9<Թ\>=MT=<eC䵲bt=w1՘9ev:%Fm/ |wg{#~Vo~bJÃ<`)\,zy4+<:Tp RfR: Q1PҟZf i\VP2 ŵ*x6$\G*RԵ1:>|s : TR{xA ]EہE2Wk<jz};:FʿuTpt7rwσ\! |?8Y1ܴsTe2dZn+=mr" S^^1@K^8D󧇯iQ/bZKT_%I LQ$V$'+ZCHZ7BIN@ j[ ȁB~,Ӄ{<{@ <̱PDBw -UY'<6)dYl`M㎖KOM#ݦ4ƽF?r屓}o3c[! ,49&2)qk::yr?ڳPJ$.On*WhѴvtH_(P.JM- N&ion$uצI+V #i+q7@D,`vkjKcc4?.bJ 2!!5Hz!Y oEj&XP.s% Ǝv 2qBl.F5i HQ/mov-s6|'TiL近u-yf@ Xwq9$HD8H)F9.G6կ_#egї`OI5ڍitA %31*3M]WŨJ!hlY 5mq3tV;zH/Ǽ-lga)XR2\Ȋ[|llEy0KG.QE}_4Q3헋/%Zr!UW=Y"|uՔ6d?KZ-菆EFᆾQXaijs^FBBenPt^ =9t _Zl$ۂHTwP5c1{b-l7t&gNo2^V'/tdZKhyDr\BdKAI %('uBG}:5`HF=zف)x߮q `@U3 w?;Q OrX?`sp, )C8Eͮ{ri,ߛ|s[3QC4Ѐ@t |06Dª! rd-h2="Zd4.goqA^)AH;2.VsԺi11%z7(;ۍPelQ7<ڧ7ÁxM;F9R#@eꈡc19zb7 yqOPb?.]ND ݂\U.u> pSc;-;vW= ?%N]stb3ioG\0q/$YY]In+xl>_MU"ϩ;>PPXz@KR# \xhM nA!MV_F/kf@ e0dm$>lqH҃Hy@`mq F@%,p#].*KOM%ucӲ7䓄 u'TJ+r:@H;#R=aM @/H@2Sl/V'Wyu6^2HɆ`7p6&ԥoy39;'XΫ(d/WGWU)`Y?2/1X̰s l`f_5:"8&,/ǭ  %2Ug!cctѐ)k]f" w\[;hzї -nZH-fm .Kh k يÉ?K(?CGjj"@B8*]PG:̱;$CE%m>#%9͑v]j`_Ɛ#le >g ADEy5u>D* Y˯'pvK Gfj,A)ܶJߗ1HOwYvs[ICй hއEZ?U_BٵH#WE1]lE*`_ZV1;TuLr)Y\^C"?.^[-CF4:*KS{VJ;ĂEtOw jןuД;[+g̶ͳ‚1/$fxӣm-v ~MT$ hk3(K7Ra%3BE] |@)0RSsݦWEȓ"<q%?j»ըtAV'T>p8u8X99=u;H.&m[8@m8V]hҪK^_+#ҽB/q=:#_+.fq3xԥ؞κ(kW.³4ȴ' үd0z'#}#R1}ھ7Aiw(JczQ´;/[i9/^O(]1cL:U$Qf]♂/Krs=ݖksx+r=}0\8aԟ~6(CPO=qX>BPVr ('Sm UόDmb!H3\i]BSVou h->-!AƏ9=1&<7km]I.2X)M]BU߶2ֈBW1:CPcHp_5mi,#:0G"ezcM·l9n% Qtt@H)trS(T螜Zf_)?>002 =f8ìDÇ_ʣ*"̎ TBuU]m(-önԢPF/^2hs3j^ɄC˄•&M.y?AYVNA;G[fw>aG^.ley(&]%+4L)7(g" RʈiO$-M`+|^fxw(n݃`;qvPіGVC2_ĤA%lTV+bė궀uC'MyB1LRnG?> EEꬅ LK;RntpݑH/'{usfak*$]#aj2՟vo[Zmٻ20Ba/\S#:tlSQt=p)*Myl*@:0y1#H15*C&\ SOI`9k~;֍(Rb=b_EK' * ?*5]nd2d`9)qq ` gAd蜋m&1,Lc}m!-Z4d_MS5 FaIiG@b 9T?͢p-'4K3$(O{c .i7e]oZ V ITnY̙5 zoind[̢]Hөp*ھߵ# |#BT,Z&m̡UQ8ߙ⽪mih$E-O&v\Cn70pG($6rXONܾJ/R`B睾RDsׄ1kr `P$:F?x*Xv_.e LZ^5uTjD5Ls,M a$p p`jBHDS;sb73y{(W }R 3aCv*, &B(E2RihI-~f Abgrnp({$KX;NLr-˕^HP!oPk n)>a?gj[rE-}{)LAg`frP ҈؜,y!(#AAJNF3&CJ,A7z̽V@S$|K,I:j!ZbFẄ́eک_R0rקj;e0>ruޱ0J~+-  PV4pRJ߈= `[ oOY1ٔSЎ"Z":竪y)ưB_}L缃Lʾ˱.lr:|fKNųwo'ˆ0 cun4i%9tIzg:RU9AފE][uH&VñSZb]N#f0g5$SP NDLdm'5q V` \NyZզq)D=t;/%a>n=#ۭQn 17Rx?BZȹZc{& Ζ%zݢf-!cH[v _cEt#IdvlG<5j6Tohg׏S>6]\EeQYN6AqsAv!mS0BeGZ\y2}<`܊[VWa'|?yî@u6d  }Y*b10]("Ueku,N;.qE1t됋7ie>|wUG; :2eJ"Z\:ݮsԿ.B8t\svp0zdJe+8Z] ?TwIH_"51бT@tNqa7? 2+%c- , 7GJ\ k8-rʀ@C=fE dJ7=q VGFm#~zf3Luo7 )C_pgA憝>$Qh*x^ /oSG!^KgIž@\TASof-ssx3+t5)ky4Gv]?1w)ls#P_7Y)NH ΢g R|'D[y&SwnF^:M[WHD¬On&~\ޠi4OW-?S =zU8gF*Q5I x暂%m n ǘ&ҝF^ID( zI@kHʏ`#%&WX[͸4Tl=CU~&'HQbq$ NY1k1)4fq qjiYs>&1c*Ǧ~W> ׾a5Y2rH3(_et2Uy|iڡ#jqt):X],yF>pA:?P gR/IC;w6\:L `7V&㔉Bȵu@ز[O+,B#z'ׁDʮN 5 <@Qɶ!_7C7I!E>"8\;acllfq*A48Jun5>*&Gmk7.TMg=b'Fu@Y6ћOC0'+Qw9~q!c|K2݁Q EIi!ٙw+/h-ok}9IY J`sXY%4ՉӼ_䘡) E'f*B,QDXL;+Ўeޝf+z^ \Ʃk1a$`mZaK`L!he) qtIs'L[v~P10֠()pPýߪ -$G\O FơntB 3ş& v5ď݉KV@(N˭!K+ah<Iv~)А1W^"- "2E@?smbRUE`7RRqJb[h SP'_ >UMJz@:<[N B7K8ŮӸ߶~sXzFG9rcE(Q p޴gtQTMCRa|,shKB[v =;"4I#N FPr(lkUw0qCHCZ{(źn֍+F}OL}.S4xB0͖[KOykq^-~ZNbbtm &nЊ]ax1t\;z4DN*Щ aB}[U35(|y7w`͋FC0 )Z\rf{09 /*ޣ %:w=wIU /a|߲;&缵H+J!Bc1p@ ?6 9ze_[C #PpGÍdw @^g9 /OE:vBMécQzxok̽S8X|i{vܦFDdqNH7A_qՑђ%hh_ǔ[XQhUS;fI)ʍ7efe&\S/ CcSh}>ي֥Qc5NV_WV./_GLtW߮^cm79m*$/⤺Uu%JxRy@4Zi0ou4uBc^1$zN*b\ЛB༦2-˓2;֍o}Hӈk0IvսfO֐Ѽ.`RiG13K|^&~49!;O-y"0' qV2[z )ľ43l4=iiԧ>PffB@Z::6czjY?,JZkw&n/PF X J~GX2)?WfQ5Xp DDj |إ/iK#]dY87hZ(P؃xt^O5?Ԟ* Q _!?'o9 oGWYzde6EYyumx^]=v1K, Pkk%!ŁDef$(H=ssy'`T8;&Q[\6ӫ:y1婶0Y[.C | ԾO2L)mRNztT1c ,"Cv%1od=(/wB%o}ʨ+m3kDyvvuDfAb ' z8S?ц"̛hu #AV2葝Vu(I$j,bm^>'"M,+W-1AaIY78gWf=܁x|_x)dU{J5+뿼?)nhǿt2)NL@] YI@mZCA`szkvz"#Q_+b7oc1 ;M06q CBSKȲ-~|CB=C^PsxvL- Zר0Ίcd .4Db/R<^ Wd6hDuhp iiI$uA V'/b$1o=|G=݃й,.wEѝs@0txʔIl?nysQz&PAZ&iׯT<̰C 慐$6u 4bb ɡ{B\:hLIW8'{5[ON; @7_r:qwIduȵ|=gu \V| ;N\N%OW5!):vn8 &8q1JBUՖ`DXՁx%A  ?-^/%dР Ư3`t4olGa7nŊsμvuHHX4窭- FX gx$^rFCxj`%CeGaQѭZJG, Kq/=lKvh#F#7.[5H_ Rus+ő4\ VJe{ 7s2(p7eQAP4 > REt̽Js^S*&z` ㆾRNLO+PO\ƺd!#mb/aGtk6Z8cwYLULj>8$HqyY(9$;} I!ʹ/Ȏs KFK]`oh0Negj\$Ӵc4te7XDo{]omF/覔+@Z<&r{@HtBȐJWJ!J b^ R>IF]+~'+Zgy-w2p7c_TWCk|\WcD3 rBhsD [qJьM xSs+Ty@|:,/,K<7OAew]U7.bͩ=Xj"7̨~\&FyH& SDmJY3bqN EccQ k06kyVKwM;sT'<myЬo-_ z:kҲ_cS Z=Je[Vu\旽v7Yݴ g ]р{MG|E\.AlT[Vf(l4;& I<~;Ψf D+̊zF`&&j?T˳='`21.l+0lL][ʍLǢ-ŲՊ 22=Q!qr*|"{lx(WD1a/4vf8Q9vCC ] RŽJp( _M1b.VFć{TJ;B1w3qYUlCs!=24pJ r5l0i -]if5DOQQmA5̑:v&jm?@v"ےU,p:l BP2I7db{`n,oU҃4\ Vjr}c*ߺGj#JFV :Mrv$Dns2Ra!zTtYrgi[YbHB܂[J9 wwM >4oTŀ$vG{T"23P'|OdU麾!VU24W! rvqWƚͽG" X"rH.4 1@27Tw 붘9i|ΐ:19_y UQ0 QWP½bgi7p)B.+"(w\ilEc=kS<9ZXC?q-?$ɒPӁ߈ՇgPF dL*@Ȼ70xlTКJkM^8'Μ}SZh%Zd:f23 W̅KȖA۫sX=җx79!uG!7wDdل!~?:I)gZ[u"gTTEKCe(&jeC}=R#- \[ed;Q?DyI '+S$?"2` WJ6S^wZhaԄ"^p]aL?LXޒtIz.{K򌈗qC8cձZ㲜q%]ڴ\ H2δ>geB)K*d @fxq݃ G&&/fۄh1G!RwU $v/iOO@ Frr~`lгPj!ds7(gG.~,(Ut5`ݖWG VyGJԬL5yg(9XK\O;t·B{+}> }M -on`1]USeaէF(=}5髥a3,]c?]K\a"^5fJKbjmլKt`ZpD] ؕ?zẸX^VЄFIn-/: lQȠЈ 5 2lB@d&֫"^{rW7>y/e{ȁ)P0Q>i"x羾{eH=Ɛſ m .2IC+jZ UKn6E j YNV^!<x$O0Xp^黩yk$/id0n[?U>Ap;j!.>.q'cf:=>xy{QƼP eՊRHz냵B2t]xtkvIy !r%xjh'&D{t;1'6aVG W/º)*9. pLWa:g8c @#A97qjoP6ԖqB&.g;Kk!A qA@+qAK%{C xvпxY{x9O*DŽ-ru6ےHPDN6j#dl̇ e4E]FI w )UOE _ UB|7z8@`0҇J,f#'yޝ^sĎJjXY:RoJ=Ii1{1X2}$C 頬jgM':u{:Č%h#i{O^\xa?!=Q*Ț{Np$mv]w`Oc%Ήκ:NYS.Ca/Ϫwym!k1|'AݡߝfR^^ 0 d?:M ̖L/(,˓ƚf)=YAf`"FGLLJ<n7&o8i C*Tm 0dЈ]_^"`:hE0Fh)_LJJv7Jˏa!HG#r S \,\F|qmv:*CHDά;C>K!O"q~UkF(ׂ`Q)*8Qs_6hRM+?ppZ.sY`$;9yoVٗ^[Hu܍h01FX]tsnM8~q^Q_h1K{mlY*f?)p3npƶ9 ygnTm߿NgfÐKlH{N\ @|^Fr LpDQWӕ"cH BWSOpB:S"sw!Q~ 38;,};]d3zgcA|%_(2<8M&xZR} -ȴB2~ 0 bNRGSFdL>@,2=^`9{H #u;EGRPQHo${sZh)g%B[k%+:!ލ 81$0ORؔO=_a^.n٦5v@XĄYˈvR;7Ðg˘G1J`W*|(ㅏTT3Fg4% JZSp+C5*"^wjX <.{(Om='eǂ3, %:_DE_Un$uq ux,Zf}:*[J@I 4O`;!הhyݔbiԡ.hߥ H.V~66Ǽ(Vw8A*w{NϦ+g@^8…ХNbc,6kzU%m]l}MҾ|Uߎ'u<|QDԎvgST yܤm {sD7njJ9]%؂S}%$Ӄ}$ XJD+NwG?hŘ?F )m(JP t}.q= Tkީ#6>4NأnKlb%RBS?Mq,$ja/%rpދ^pɨoCvBa`aU.XZʛt3SKm&p_3ÔHmi & j{ Ae@/'khFs*9#Y3ܽq_nڪ2K1K/*t j8B7lØJhu٨4EY㿔,6o!4h r)q .8Eno*zzpˠ:Xjܜp ìKpEEh0Zë 3SOMR\% oIvMH})F2R =1p+9ٓ4͖I^5P^v]|mW-<<͖n(2VCo̿L] U-224%ֻV7Ko\_m Z^0A`,>6+%sz ؞nñVk~4ĦV㏾!oTwhYF%)gE>8: R>ʿ &Wo1"L]yi# IHŠt 6 3,ӧ3>>M -J:L!`y0Z$V\;}* 6;{E)+\J#?Av G/#*$ø'Ȏj>DGU bKs}E =' 'F^Ó|qT)QqL)f7 Ї4pFwvӃA&moudI$8iPH\g?`1rB(8ZQ! j(50',750p]LK2>VwGsnLW?Jnӈo[¨Sa>9|}rCy,AΧD(rO4];E !BTJ˽m p$_̰3G~tkye)CDDx4%Uae;tqL4S";<ΊN W|ˆ ٛĐ=Eq |Rw)qO^ _v3 [8y̺H75Z\* -}ž,> ?cjJ銫ԐO=Gv 'V3z:k;+@17d:w> S2p*S&QPsc7;pA ˡb}Η hB| iM-+U }0KG~m{b tdj ҁkۣqo8FwW:ق}Pa5k<m~䊧Sͭ3šͭoúrօLЫ)X]oTUo ]fD>w?m/[TP4h^~ԎND,b͓RKnÔE|g\MBX|K:qCy(@x=2vYot:,?*` EYꘗowʮQغ , h3ie T4:~S.*]E7 ٽ>Vpp.bGV7-g}On±&~_ͼd ^KLUTR n;cLf'#iy>$> wSG A~RKENǬib̡%|dTb2r0"-9Z˅iX&.MR²>*%5)%; |%oguG~s c8>k棋#hhh4>6 2PtZ]aY;y&ZܦsjX-\~Nf҂X!^K-Z^p(+P7' 0/z(r}_%~.~R0%ͨjT㥜f:B>ywО/&| w[w%YbA}y画ƟfvcE?se+TM-As4aa<< M#xPY:8 Ÿ~/u- `oGAczdGSuA@3?Ug{+) v:uf!Ki@ьd^*qu1F_N{N@ƌPTyϓYmuAv51d+~zUG:Am*PKEe8wL{]WTB# LXǪ7K,1dzf@a 4V٭ԂT6e$ \,)ΐ 2F!ļ:pvLfhVLz:Z*ˎ|WFRuZTBL~(?]]~C&/^mN,u?_TKC5m~چq8MANU;v0{%cY|M̒oVp : 4E9n|@a00{mF`=ޟBc(Z~! P2_DIeZ ʧd.d\Ź1h¹}KoEЏyg1V^++_357CIgM|CV^ϑD12;דf-whO8|]VP\3,Em'SpZt[.3{`)Z3Β 3dzn n6 މe(pB SRVA`8$);5H{P]l].d!Q&glŠ+))7_;]I `.\Ke$gu>N1Di;]-pA‹7*z^6]CrZi@&U%1!%Ȥ[bIwnwZ󠳚+.'Q'I5޹pSᳲҲNjf{(l8O+\pi=eH#ܝQ4=і" XV`t\Qz@DU⵭Tu}j#̥·zOʷc<6 'rwyJC( je nZ5n#𜏲KbXw 5*\T_P>+=! 1ˍs׺OE̿fؑ$a0LsN>F&|гHnj1 M1t={(Yہ_A{"\z:1uР=!4N#/\|L":.NROW)wFXg^Şnqc ԤaAxN]0j;쑣w,3.-ZV0Im_@ҝqZ&F|{ho0)H5#jdShaD`&]K%_t=H|@Rb>_QX8_w,vK6(S}R% ;,1еLI#Uj=Lu1xHIzXr?O *G^ .U*.q6>KIQ1:.%,Si{YMǶ{$5ޱSÅpћ Ģ>TaA9iyvFСFZ˦%{PiA߳koEACPDV1Hqލ[n*dr(іq\e"wCh w g~(p5o1\Nw.Q\(D7^0jKJ&-=U90m;gz̑ 4j;M%V+e!}W[dE )d_8 Ҫ׌Zzvf UQ 7Vr+&\ ΛNp!x Hpe>!sj TVfˑ" r o3:lO}(b1 %-9YnnZE A =3&R@fnSYP@n-gLY%^2eo)e3x~ M9!.X(;SǢ\ch70 Tk?c]bIe⮂68ӏ?dbJ hhWvrAHJ2Zvس#"5f眹`:ȃkH,j$X#nb:;<2{F݅bν[GÃa_4U^~=/;m3ί]>v[]^ӂġ_(ɻ<7;4lҢ6M_nAH-|8t{j ~{q:o|8]$s)Db $[#>2H4"ڪ4y~uv~zN fBpEǛ/MY떸f6A4$ZZ+H!^ۏ4aC/A=Io [Lr};2Dཿ9{Z]:qHɎVl&0ik5_U {ŋ' %SI4 '1wyθXKPnqgw𒴣^~ՊrkR(/SS}gO4XdcdQ2*9Ύk>;a:tRk:@ÍE^1n \Uh. ̶woV]|1{LI*Z.dw`̵͹[] P{䩽⮈b5TIɉmr gZu 0ÜiwP^t)\!ES^y*~3Os<3hPԄg#%2;_K K-q!'|yW $7gW`@PC|QwɅQGԄ`L~]@@| 8 `f)1ͥ\:RLd=J l+Z+ uo!Z1 8<EOw?0@lCpq1zQBo0f,1P4ݱ_Jp*۹޾uk:)E0/.t2xSK@+avЇ[Xa&DZlS(mdE?Ź{V*!7ߠfáyqbb\hD}haa \0cV v̐? D17מm) )RXj~aü1f0݁$; 'Ў3NG΄ ztJSF{ D3*bgTu‚>' erz*fzSeBEUh9i/=P] i T&2\[7gH%HPkBwlaz"r}7؅ (t{ (]=2sPNa4F7UA?v8@8X550#3D7cL 02*(؜,ƫFhlok{yІhpiTsq ~uC"7}A^}whRǤF`0;"+軧y8UTek\0'H1ؾK_Ʒm{rJ!}Q-z8l^wͩ1WRa*BNGRYɃP,Me}5cg33QNv,mHҔ@f(F{}Hu-g;oV:;v&b͡ѨM%rbcL3yVu6*!̐Aϝ}4C[mMMDY' Ҳ[EB>ϗX[y:DrFAF`{c[iǙu, .͘?A }˵gP@a/ USr5,ޥ +LH5"3{HQV>2k(1!燐 kMPY߶\p i 2%  ea;6ojGai3y.0DUsJD$ zAT7;D-()"ݮKRIXESF5zGHd. ??e &ބ!]3sa d #ҁ'sAV"o݂R2olB#gso#^"VwctB zxΠH~T8mh! 1:[,YbkMn("k />N!ˊtyP4\]L?fmVpSZ}h/uKYj[I8w'Xg\JjFɦkoۙKpxngvBUot]!?8Q_ܑUguL 𶬽 n32_7#BU:H'ofY%夾(qoH?c@) ɵ L^L~Fٞ>3čQ[W?-Q>:V*NpBn *~}# n5ԘH =:b;|u7? =F45ǝCurˏƒcόT RsBIp/4ֽc lg)2"VC%\T.W&~ xrB,D )Qr7B7aTk^8SG8v+M·dYK!MΞO ؑ~Σd#Å\ETfbxBNsIRD@f뀴+\`Śtd-f@oDu+gofٍᶑ Tɇ52ZBU,ZgiCR1^_Y,z]-vtqFHIV.-bP|'oF57ƣ9.CcmY a=-#vǰp9DXi '\PRЬ!Ņ[/ E3ٮ鷈a'Ky*ܧ|9{Wx#z"d J";"5F~WJzpa4oϡ R;N+V3 hnj`-7&gݧK7;=ƵՄi)4HoV7zӿcw.x_isuc"/)5B هmwˠKVG9%o k\3`lҤFSqąDmIPڋnb5E_/4̈HHfP_:zOTa#q)0$.Efڵ둨ph*AK|OW^hVlR,ux!Аd!Z@X]?+(qv[K/F<7W 78r@.&,p*^#V694+^ X,sum4)߱t[;t(R.=: boeՅ@'(6kRG9C큢s+G+ \bS.Ե/S[\f\Q{Zx^AIOozd#|sa>Х}x(eX@ 9"CE7O\I/? Mϰ(9;ꠎ@?0M6+)|UNX.J… Wv6zmFG+ޜٯH|2V_s0vP@Ue=\Aփ7"K;; :<\/LIp}+P]j1$oK|Ui 9ky`mX8T EVMtt#H7eQ[+\U59]Κ-,κ'uwwBAaרJe ~&q0 GP2DqQ 5Ln̝1r+cc~GBuJj/s G&IzjA^`]y05}l-bs1:n o;cVR8;ETŬZrb(ʴԭ5${G.?d̀ź~S=ەWȯ AXjl{O[d ;6'{ਬhQNR^v&n!iyg|Sce@=sIQ{<Gu3jwWE;PQX9 `3W. ӢoA׆#,&ef+L90g%w]ƈ\It`?r}v$P&*3oyp~Ye,I}EϢ7mʝz${hV ?򀂌-\"gQn酛{y2C1$^F'0hؼ%׵ZAHC[3Tm#U̬qxEcٲ_ɁHs`l="%Ƀ\Yz7WwEI# Å/׶ gGF5 :͛ ۀ^\L5N!J_OYZc_hy!@/e{ȶ Lt˹sm7\.A>2ס\(eJ?, Pv_R[JjoIn2zix{Ea@On@!Ft7H<i|P-a=|2Q_.Bt?xm. :5]Ug'PmB _vwQ'+Jgr1<~CSh}|3:aUt<ɚlM~ Ȣ.g,PdPxX b O@Y'{6aeJV7j mF YUys2 ww'`K?N2}Dܤ*s&wiQU]v߁5\ f::4%%)S]Z{50¹6*7gugEJ?滨|z6MMxghegS>j/9 Nc3d}dZn`1Þry`+7@7?迆( `pBMl׳>AO&ZUS.7_ݿbwWC`t*9&Yl^!92(EAY.UR&f*94s۫m>Šo FxfqZJYߤh(lO[O !uk[p-|T7BYeJqh:΄)PzrJhF(p3Ie֮R $ZCs%;1&O/`WCB6Mce"IdOT~5<:In;o ݆-TrslKb7k r8ixbIC?Z,W"/4?UVl{}^{bN2ՇM~uL~Aym:YFgb>y(Z{9=㉨d@7c)+/kvfjY!O 2XkܹpI%4l &)<=.\WD.?VNzDLvOդLZ_ݯ~=g5z0ݜlאA˯)l5M^ju4o\\coqӻgyk/|s}6An$:͢XC-Ge!VH7k -,˕'˲v7 Éo BN߷3F\h٩d'-U?AZ Q cDH]#&'!w" ZoXqg\zð=}ߗ5Tme087],hnm5f6HO8\ ŏ8Kk3^v"#P@KtQwˠ eX 4$@717(qhc`*xͅBT2BUi PZdLzW (Lֵ`Z%HM%1AC%mSƱ/&eMuK]9򓁭=?pXh'2>e|_uQԼ坧xC~m5$nWd$R"_ V% eqvƌ:~D@˺i)ӉnYu?WHmS`0n`.m3 8#"yH֡HC*,0=x׳Te_?礥w"?7OS(kPt;Hetd~^1eXZY,V-Xj4L̑Q<:mQ%ٻkM{VDq6V^.aЭۧ2T{+ nv7Nlr]95Fu8Ȩm+)3Eo(yG%,c0j+1!Q3A8|WĆ!?!lr#sq_vks5<>egogqhh]epdY`+D5*') 3@a؈Lj{[A@S%Is<%x77Ssgǧ7te|q IDiM2H2[ ]N0ͣPhOX%%۸~畲#qixGXiNG^CCwSx~vnQf D`FYqZbq LuTW],.:!vStϹ'Q ŜtL`)lLEy0#6Yxil[nh6⸤~Y$Nlu3aZ^ކA8^^+NX9]<-t,,wd0"O,ߛ,İ/_)gX;V YTM&LF+~%Z|._]VqXIAoaES5tӘ{1(%y V &.nk{ȹ݆*O; DSaa{>Biǂg #ʅ1^g?OҬ\luH}]]Vqaޗ>lc`gk5je+`'@gt:Z,;~*6 %*`iO a8Xnp\78?<1a|P\T,kWXYF1첢+I\c  ACsߞhzD:Zכoh{gR%c4)3K:QX(rIVmDk%X|k&M ~$!A.dXڴDxbI[k{ZfyHPvU,%kiY2'lLNC{8Ϳ,l y-w{4!|1_c=~4`2иj<H3NWሞhSzUL=8vZQRog:XW>2*ds&33hI7/0_&EYȼAV-+.rjAIJ֫@ă_naI { lS'tŦ63*@! QC]J&0Y+7,E>{p1 nE~}vm[dhIׯ/[?UL+lL=F/ȅ R(_ۯ|_.X}'IQo;L:2#1y(.=I=T 83TE6ǁ{Dx}JṲ1GA/q{e _ "Q8^IҡK Xhf܃bM}:\];r| ~r^Lln4fiaCq y,+68b~a ۍ08 a(C93!RN6q>Ƕ+B҉ ӡekENy{^OKIKKHG$ՖE[;+>-$ߞj.We4 GJ02DXxjo04߰jVåD*+oǚd2M_Mm҇{Z=DߞM9j,捃vJB~^T%܄Js_5b?f;d'Kě f Q_Α|w?CU_)3y*C]lEy”L!x[vQ9ayyLKy?1fG{#PGӈg>ĉ0ٵvA2K~T_ruhNxx)mPIӎ==5ߤ [XӋm&g@5qԭ{tTR#]e?B`# UƃbqMC`Y. ki C:k c%+^k ]soѬ }Bu٢&֥7r`1]GEMWa>_.@t+ם MQ߷+Z0~x;L9HҖ_G)6S82N+Ѧ7.%w38-#>K9_:ӢAOya%8YsTJMB@@OI_f+ 3&X2䮊,?7c]YkY9rm x#FmA%Aⅹ€zq嵌lP]όbO9HuoJ&:T]uL jS8_{ӧ,!( Mn\ ]ӮDm!зC?r)=Tn&&Z w<2_FR%;%Ԍy@Ѽ/Z۴AWPB]{=ǁI|0UD!m]S|ͫt6LjfZΕ')4n}HoE+?FŚg|ltn_ړ$^?}}PO{ @bQX0urq&wTe._c5FZ<,vyc+f9 +-GB)M~w4PJjiY\୯g M}'R%-w.w˸ީQeգusRUٴɐBbqu9GeT6!5G[pFT sƠdIApQ{3UGx o־H֢c":elؼ9l1m@8w0V5"NZlbXw]rbSU?Zz%Ͽ$3!v +@ w⿞ ά/Oc'c## 29 ;mAbZWpZ YOf!>-?Ȱ*gp5NQW  jdCd {&}/V7 }$3;74/ST3i;! 4-M?94y6:7 f(H]2DT|ɝaQED>Gɀ msuo頂 ŰrzQd>*t%{F^2 'VSb]'Be8͵\BHsV~$-Mߝ rE6ꇅH -Y])y YR4E i* l`ZqlKCk8F3)˾[_?.B{:5vy Jay2xWν\, QK0HZu)PX ^ޚ F(Y,>ǸI;͠q ni+K+ft^Iˁsİh\S25ZU%ݺ$iLW샿8iήxU?X5g-ED|s8u'EiEo9ڲ^@}2/͏WeyeYhFQ_ S`F'NŹKސM(>UԌq5V |]N.oaܦ-5F{jq3'3eX >7(<h;6+>!̇×!<B-~6KtKiBvykܚ{Fo b_C"H{#ȴ2xop1LO~`0a>wXY m27Ǽt>i_=NqaZ0Sd-Fv2#X vsuUCfbDU <\dQLؿjS~;XFm=ZF3;Q ?+-͆ϖ!r' "wxX%R\?v˫Gn"1r?N=X:!`8΋6$XK!kYQFqBDYx_/,N*~)qpс\(2)-(5 "uUy5&x r8er\  v5#.BP'TDܳܕl>@xa"2޸dkv.DҸj-V|dB!t84$"yeZz-k&4 [pмaE)f/?UӡbyQp8I_.*S"z^y! >;@@G%[QBx#`ZI7wn-bl\{7*Fi\݄V(*\c #%V*<ΕfLy bgit; p ֭X0[ż mYLN絔\);"U퀃LBr*@~h+XǺK?mmB-aE֣b(h~1M+̎ լmS Ms(^MZWE?oY|m؎jr4nS;HaHNv:wk{1nY O5RC3s ǺW ֋YH ofWP`~WQ XI0 ciEWI ~}&&kI% m;ɖ  XЌnhѿ%||X}}eq%Fn`mç_5:)¹Bi;y pAe=Up6svu^XPcyUr86`9njGA'cZHhRI%㣰CPByQjP-G*ysq]^*pNB\_b99 h59 P=1>#As#}rFi{N 0jW2C<ʐ:#JG99袐hQF?Ry?%447)VJET81KXxLP*UK.ЈRav6v@k\YNi2*?͌˟6[e3ٻx [K$L j[\I*?K$)}+a"z6¡#))iFD咆.iIl% K_DpKT? ȓ٧khkJOмL VYa|L#څ#@1^"4r9a=W0!wxJSw9ꌈY]י`Bc+l}v'TDΐ,R:Adϐ 3f<7vA#^+>69L?֮/N!" èB?ph!œvJwwԾ ࠈ8*eԡ P08O`o\~'ň爻OG#Ěyh0Ъ$@W#*اYp0nl-6Гu6dCm,ud+K2eTٟs2A\$(gkȫdHT_Vd?|~mQmef7R~X!I8OY׌pAF8veWPA~C1kruYGa`sbșOEapY3zv:<x̔AF ר.'&= ch*]yN+q Rۂ&2\֬ ݉p]:6"U'؋ϱ:)b色5Uh1Z<=wKCP6ރ%;5qLMDȹi2,tYaUgͤDe'4͔b̾!/A! @p@(!Xsl;U=h:I/uڇg٣Mv\i6I1I[%wϢ)FI0  w߻"vI^eʐRӋ5ēYi<#OVgHF >ބT9t5yX~⦷NDj݉^<|k(xR2am UC~W -VW| 0>\#=PyJ:2ŞzS6W' P!%leywj] "n*sKռ`5o`sxKSH*IC8 辂fMZW(wLsٲǙ2ZboVQ9Y砂$ˀ,ncڛ^™T} Ie%Z)dBXD`|10ҚsVz JʢQЛ]5^\ƒ2H sțj/[/gdE߮ZˬKJ˓j@D3 \A5|suX(QOcu~$TѾ\"od8=7;.s} k4*6(Ϳvͽ{#F 9^g B>yeZ.:iz¨Fe\$(GAG\.ԑȄTRC=e h!e1idrlh~O o{Y;%ٽg؈\V~$U *\pZDmf\"VjmSEԠ=7 \|m;]Jޯ/f!'>7zc6OwobKڹ2O]qv<FA$2TWoQc[wusT~Ta=oq+me_2w8 `ywH@Wf%V|lpWv~JU #n2o1qgzE}S&v7?A\ jÉxM5v62[G5^ݫc:aE`-\cn~$w)!\S!(\/+i}c^UP}$/|W?dzOӠW,e&邋t*p ,4"޼߼]k ; iWN]d!W/{ID"Z2-˓*U R7ʻtg]4VV**I@e抋"hNv(%mOv2MLռXs~( $z%U4%YZ7-wԚ}뇆oN/LBLً/0HЁ𜤅dBNhҟvua,墹&UthT΁{LP] جE΅"yZ;<솖"Z:B~vӆ,p*fxB"N!a qs+Gr1}%\cpjXcl?KnEA+5f(v :g+l' @僷z w 'VOtبҁs!rg)\4hfѥbb.@gj1+0ʲ_|8tW{z`ybȄ"Et B/EN( BGn`49 w]{VpߏLgtʋLhRȟ jΜ} cQ$2Ljڇg;YxKgݨjg ?kTg@$xՊd>% O_ɬnk$lJYؕEqȲ6 $/}џrO@uхpHYUmR5PvVHw(zA!Qr(Q3S;v4-W- TLoCh}8PBjH>y@Ʀ jVՁ;%6\uqVM籚 <\=)XARoW1{4[UN*Kh}[?Y+n77/CqHWicM2S k,ډՙ!\E=R1]~_j qv2qR.-e~2=y}z>|5u"m DObVQ[0}ޖ3}8-`@3[ca+o,ݸim[Q"{ѷ:-u0۬5%lg[J %  =,CEzў;!X>mTE `p\sk%2BkU] tLazmd99dޤЪ{a@?l9 8t~ "e cwOu/șQ[l6V tX/`H"x**)tÐ&~Z4/qIf73EJm}}x :Z7vLɺ=Jx9S&5`ipN[X?3$nE'n8H\+ =dϠqu,s202|q8p>TW J:2\/&:|X BT^SƺNVVm]oV0[Zc.XWI:#ynԇ+]N@*qXAhzEl;xLWm d u',|~gLIo+eVTCfIadgue%-HU]A]i.o֗_wgӅAZ?xXzeihg%1jIG* :l5X x80\oFiUFJXi"KP #TeR6$`o獫"F0Z]~oi{Rq ^m"(n,Č+aнSIS } !VF΍bp Pz-t~}pM!s䜥JMr̙z! 9ձKLQQe+($c`_^6JXCl9}õ8N~iЁi)rTrw#Og]F `b" y G47_}K=mV9绳jwbѝ\+P" E_~?L2 AaS|zv})GA(}*SLzTS$Z;A0s@٭R$ <[>^/ .vV.ۣF+hm/Ǚ{tfɝ`J*CrY<)%Q{㗖ݼֶH:)g8t= 4'I5ۤ3̦,r1@0٧FEw&(+JUeMЖrh}#Z?&3XftvKf:e4H*X{O"Hq+c[VNF]1`Ц?DR T{ uP.3Z2|QgCa&AruY[1!aR0͉fntQl8זfw ` Msa4]əvҠ%[j҅,c."翌)x~9k{P,ʰ8wd*g(b8NuF!e+h"CpD5ow7'xt@;Js tь\GL"G /(kU;!Vg.K 4 LN.y9^D: {\q>U?8#oFݲ[0{L6G<'ݿ!.SԱRj ͽHԃ8׏U 0tYl[ĵِMbZ;շmfaճ8ZY+7h7`%YhMhW4\#@jz9"XXAUrƁu}$FQlwUx=A1IK1U-܄KIH!d 8!p~t Bdaɕ _lf5W[Q{EH}Vc*Ua֭#,H!r@J˛ 0I"Qh_1UK{ C-LrdKDߩ_ٮ(&in~﹠iw!"z20k㫩)D A'Bd[$\u=kԵܺ&"A{:^? zfI?A3S8H+3g] Tldr' Hg8?=p&Or,Y;ؕX>O`5VM7)5 jye\,ZYUϺ꼝]cO{̫ T/dOy{cR~AqʻnU/(T= n^@⑦ t2YzD+JP3Tu)~*_`{":3/h>Ow!h™{ǖpWǫVp- }!3SU/e"I'\K.p~m^.D.*8C 7j[dgHJl2%w`؈=mOyhre s$2XBR۹+6SY^iHQTNR,[%:Svz瘈qAT:IrȅL4"4x9iV9#)`L_#%WKz/ʘy(Rh|.C(/c_XlqdkR;T0\< uGc<؞qOQڠaGi>SD1-Mׁ?c-3^) 2x=4g?&GZySYbj^K`X]f7-bJv~cOi 30LvJ?ўWEY,cjI7:}LU =Q}Щ+^]{*Yw)ZEZ0`\ж0(A6鄶&RK6kd^_`N [jľzȾb՞4e;F.TUzƇF 0~VBԃC3])v'Kكи"+gCH*S(8͹& Cw 8|T(`s7L.˱ Wb -곦%rQkΙҹNaNϟ,Y*p0*\%Nu)µ57@oPJFJg,!nnKk1xFa dzD -(GL FÞYPJ=i1/i6x~>`5G+r-E]XREw' |yI*Ju^sb f N @= -RR<7~l۳z59Am2Tv̐m9äJw֗C*J(xs!F0?d@)x' UT &1v7ֈ@?ƛNjA 9g(HGfƘL<Ȼ3wJc#~21[^ r;Sӱ}X 9/^ņu0$IMp9W!G9ӼiL; P>uoo}q&}!&2-="IGVI74|?6/ ~d=ֱVƷUmA[ o(eZgE(':@$VcbgɷzzZ̍N|b ؚbFq{4pWH9.qQv p1.?I_zhJI'-T ,BT2Ѓ&Ag_,_I x ޸tX/NVW'l%᝴q~J)^SB8 LmԬ.ǥe#ۭ~lm, X u !$Um  ³sC:Ŝɰ3M[m(} Cl<Ţ_0Pϥ1gVgf'.IQ#d/--BwJ1~Tpz._lx+R Ial(yZ0>NcRfrPʛ2 m#edlF@z'\v Mmvad7SVQHy~e*͟{j/&d%n/euSiRh @{'|s{KW&I\ٷrbcVuop }'YjΔV7q '|T*4]3}Ʉ" :OEh&I>W"Ya%S Rn94ua?ɘbaG&p>i@i]-v(w8thhmJsc$ 3 y RM/MbJpNt))>Rz z [9!'QV]$[ȥ3n%ϔ_G Z4y%A_ o 38>wA`@f Ĥ.EvAab&nDSSXKd|_p̐2 ׯ): O>㮌}X#ch5_|lA=ucʬRy4;b4-qx9vd+_, C符8#&ֈ-rpp.'+"fAWBF->B?Z; *e$mZiNdGQڃ+-}97s!9pGΈT9Giik6kF mX~ )݄CZ^ d4z^]lpNhK-/l5 @*kg U9 tAGb> PfoVo # giVg~| !38kzyrL5Bm, ˙ۜ%B_2wΉ0y#,@MQ  5U(XV -*FE4 YFc 2C WˀܴVԿY yuc|JM^E)8oZ0hϻۥLf>%(8iLՕ-oHlc}`Bhlz՛?OxLխ}2's3WŎA Y+&oyޚ);\32;HrAq#S2~EÓR,Qݏ9b\osxb>J‡H!mae[#t>Bk _0"m}r;f*q`TeV)?Rl~"J o_M k_cͩ ivaD9{|MqK$XHH>ʼfJ];OKihg< FO\Ι5Z4u~]|xwʙ^I)0Rfߣq8`!|+@~CIӀKGƘ_ha@WS`U(tz2-&ɀ]\6 np0~H0BD-qxJs<^'ALpmn4g9*r|= Pl>ey`g*bnMIAڨuǻ,2VֿÏu.%pVjXwCo72&y+{y jM=^/p eCSS2\Up a۷ڂOf0vSYWtqU>v>"дp, l(,oƟx.;m{ۢI8PO,!wbL*ho>Ȋ[XkvAԀF|yϊljH{4HW$ 2-D >i. G*) j1A$Uu9te5vխ`9ꭱ4Y 0SZMhvc? Bo66`j}ŌզuX7Vj@YϢG!^fzu#fo7zFX*@2Fz$^9gY |0ɻfn5҈H9k-]K~A:&?CFssꙋbUt``J 8nSm`Ug . :\&n9 ;Q֒>d#0;(<!8E7X`YKLyEwȅogss b$sJ,wFSķֹX0/bbqGhk2 2*? gA:7\BkA;]\ʩMG0 êu_QSa5[rB AJXcl ?FK~Ryz~z,(MvتN*k\dZJxn, ؐ|Z5˱a >ᒗ PƟf?g@Ӹ(ET\f }gą6F{k+p\PW[qzڈu&j.1頲TxիLp:9$0S  pަUW"烿گ_|U~cC&Wᮓ-\AB_,;FD3 u\A$F0 >0#( CjQU`MDKP"ԅNgiX*@4W;A% ڏ ]'%S`?OMuU!~!+KӜrT=Qf&NG~Wh{S]l$O ߦּ{&e@џ`o@z5/V-j]kRAVn =ewu/6썎=ȱ"pl6eZɵ"EWY>Lnj(ryu@:N'Gqu˔0Qĕǧ#>Rj.++.Ta(r1z OB`u]j$ _4&gu#Sм$d_/JbP\zJ]F'V$JM.J0Nt-jH>z~k%([jNP#) %d@= a붓CN_둄h1iuPXqR(\qB~l!|2M8ٝS)2Zm\gM3Jes,JR{X#FYΝ‰M0P-$Lo2碘;ْ;~EoQD0uE&Ό8 xLյf݂2:l[aЀBqXpi@,pʻ'^P'93p ] e@ݢ6Q:U'B ,ZL0P9H ,zqԡS@d@#xIxLtzU!sպn>7>t?Z# Tkk`mVAs>3^U3^gҨ ?Hg%,@F :e9k랈!7'|lYy fƚSs+_K-7ց}@u*Ihݓ~p HlyWӘlPUdm 3e>ӕa;YQ6*Hzh ^,mCTyع֔vpZh}D@j b֘$CTp\Gη:ӀF+)‚)Zt@_󴾁xΆnfE1 .>b%W_]O`g PR"xdo9ʸYf~*\cs)YTEfJCuߖ64k[A!-e;V ?}$X3'Ҟt)bxVGYy4G.Hœ£\/WF&YH9<?a:~xJ$vk~%)8(:Bx03[r `11l{i{yI =[KM%Ю9Sevfu "3AUa0.|,rbށލ}%hg֍H!A|>z_e.g},\!5}aY>j_+5Yg6):}d@b#tW85WBQZZRfS9`x;b.B!'!vՙp B(۴ĪkC1N|捌o:3ty ku>i+J-”3aNhz쩬 سxQ,eK-c !kٞ: I~;A咟8ZtdOkśTA\·$TۥL|Z3P Xs'ϴ'yi_ .h7|ʨl)Qt$I{`e~/lҝ}-Z:9ݕ;//:D7ӝ$Hb X:6p#b !^}ce֩7Jo {wP^d6c4`]xVѼ#$GdjPum T`8)W'o9c{|zlи9zρDZƘ&>jx( ,#!^eo`ew$GHLj#W,ۦ,~<8!l0cFfE*{;]Ƴ1ˤo\Mak~!Ov~3n%9wv5@qGnk}gh#}RP:S Ukj7/q؀MQ-e4|h;1ۨAQK^аl rSX^P#-MG/YO,L"f +U9[$Uel;X BԖ܀J?Y'3ձ%#hL ){MZ3USwħG'n⪢aN EbPi%Wet胭18Y75mGhscƄ{mEaYN]UH> ։þฎHkWr`w72Iv㶵M!:N_Ʊmz]Z+ɀHyl'\1T{}.;/xoF WXy`\$U6 *ղ K],` Yup 7sk.wi/PkIघQo߭љO)ѣ r ?u#pO O"lo#iYR$HGJPfitYW})D&j@T[v͟3n_/~))Ps !gfBQMw#MNüINrz&H]pTHXc%۞llq苊Pk~KXCMr`Ɵ8t!4p9 yV9@Sj\J=&@-@(]:ݕc ;g2`n/L) -ƣ;L})Nϲj~$kPsCWɁ%Y7wx֤ ٭97noqL뷃+!޾<1,%XU!h@!!6Ldj(;jN.S!v]1@gDg&{4}d~Aeg=W,Vh*1apӖqbrDW$9 zC,<ȟFٖ\?XYjIܛ,U 3k"T:1t].ʁr XiD{Y!YW & Rc]Yߧ:uHIҊ\$>ϻ+,1Ha.Սƅk"{^Eì76PV 5s}і&v{$Z"rC:LS`[3HP|w~i:>`O, H SR^peL~ gvԄ W/d Bko#,O4. aT9(O`^Ny ~#:8?2tΧi pRg#y*f2E- N"_ܨ}fqKTѡ~Q@| XM=kvhV<$~[THr :jF.n  ?c|'j E 3s%>9S6ݷ#7x(Ffp~9WBTo6ZO f'`fh sHx !:3 a@ϨAf ҢA=K2gt͘! #{;Y$vR$xC{S:V?xJ뤯i Wuļi3$X$/@H:]||AӦV.ixd5=&(cl괽OhēYb^{\̢¬*^$,:9֜@|Pd![&F^-^ 0 `KlpPhNgV~=w"$:v"& &G~WsW"*{,94G*aHPFX@7XHP xVOJNocxVAW:(wk^ UD/-쉂W>D?b)u%x1'gu K NA°fm1}lX={z[A]#%%wF~ S6J'9;ܚ#"Qs[s^O*|3qkD^9AflХPA4K-{h2Z\[NK.9׳|@!coL}h_d /D rPi;^rSV1${"s98gKW}iڒ4ӄPȻ;.Oص>1OHԿZ73!žTS$'ФVp*k隙!mHkcͪVb 1OS9J%0c bDߐ7D ?'dq3E>3ȁ16'Wr[w_sRO}U}DqhHWU|4)<~Y}䋆|&hPƐprcc%Vew Ϸe'蜜aLCL> wo*p")v8~kSyy 6z9};j<Ȑ&N{[kI",'+6 o7B2B,?S>]* ŽI.d!^':]tOxGG+0Wڌ=;]?AD0v\;c7YCLP 钌 v!)hӬ+=A=KWlU*llAw?i1OYD5b-Jm)= H'6Ü*1`~K}ibE+KʐiA.ke m^ps:lsLAZ J+}o1 4xVRv̠~4V0PC|ELK2O?V/06j21%;7yuS2$uhr.ya=Bӿ5 CL@ivuғ i mrA;!QӰ??U.ᒜ<;:KmmzEF ^Oz~MߢZ5$4G %EXW3 6u gUDbY\Xې5}YFJp FD6] ' nI[t8l b104.B&f -#^(gR: !fͻ[#WO+5sNׅh+E+ Si:ȥ0p>1-U[ͦR'˟bGG~,YK&<XrSIjOgMIMbRVU`9,#ࠦ Yr"?SzZadKvQr$T*^Bp,Fp d#ʨ4 r3t@Pv&Klw[+gv lsJU͊"O/h&,ɭaNmUՠ~iӘYAVSi]+zKO=Kϗ lmޚ VI6>Z1zfMnG mAX Ba,a7]EQt:NMҴjH5P#">rk-,IMgepi_0#Kn:|Vӿ$CkVZ  No|P^@dKze qQèušMgu}^K`Bm̀4Ipi7ALgujg=5;>`YgrMLk4 y[򯾲!I)LĔ7YB~m!NP60o-2u<ܤ@.SV uoy=ðVW]+9absZ`n$:o$-p{ư _բtnv1R΍哖1{Ņ%ba,ګrw8Mf=Re ;9U&{*+a`ʺ$Nx5"-+|kn4ԁ8.J An#v88.4Iڐ1781 L},~m`LcACqBmGB\J,y7 ,8Kz4K^}5p,fUfc7Y-zn+jp  4Yɋ[*.&c-ٳA6Au.\Viӥ`#dDF 榞y36sc.Go3N\_oZī" (xy`#4fc3^27J9Mj7Iy!+&RTaɢ61wlk$)ULFo΢YG6y4g ,M fŝª7P؁(s@V1i[˾qԓh]O;! tPZ Nc984.}OW~2ՖP9?|I%dLGRHY4Q뗥}SKn`Q65HݑvG\i}w\~i|'uzQz rn? ;bW9IC T/v+9) Z ơSc^#vSivV2RR~a0}Ex6ǚkخ՜_n=`ى_w{&5l+(ia{F!Ի5k3~Gޏ814 W; e JR2ɌE|ٛEI-cER`gM? 0Wg'6P,d9]O9 $<ŝVP; 9,1,r#Yp9#>aN.^ͩKZS K H= urg`4DpQGr(^sq9eZe 悟2 P )z*ѭgZ>ɂis\LkU iTza(]A~De "Ȅ8Lpl(N^ |}#$ x{6kf,`xz˳}bY!TsQ@{0 dZу|nMY+&z?^ P]|x80xTpޚaɲ¥?Luش,LrJAvpKwdL{`Pd"V#V$-ipQrb"Q:~wHKI. *cD͟]XCXce|vL8v`8J\xv" QHD;LR&ec-V]oEAd@M:! 2:V{~QВxq=#^+8t?͇>gFfЇL^8*հ˃a),K9s<'LZ#v) ?5ZL.EC: &{Ğϙ Z)_B/!Bl>% KvCVadDp}j!VT~f {z]Ṓox@9KKU4ʇD&?L0>:&W}˄Tp`s.| kӔSn$| g֤>(d|*)X ]Q`%Xl[,+#xo8AɪR tK$_{b'D־opNytws֤baہ *'>oI6Ag:4Kb$?4dԛK_5Ii< 1kRTg" ]gsz)WOsYSUf8AU걁"a("-ɎMD_W)3$tp9vG)P%w9| .f3ƛ`͖z#nzv/Vh*X(du ..c<>Iy 'F\+feZ`.eu2Z9$7CY" Wòa@`yxUg(jEU" E?nj]Ut#?,#B} neMe^{L}񥏮ׂugFPNպ>m)B%t>`RE)ϚFWƶgF$+4EalK)E_6ua-\5}J鬣&]rR8>NEÜsS%& ^[d?H *)^w# Jt<EE''r[11hWg\0NUFp3 bv[NH!=87z1BWˡ( >Ы)sp@d[%d#u}!ͅ K00Tk~? a娤@7J"&a>c,^p̾P9G$ʛI=9SFRn$Ш[ 0pn/ I玦F*sǚޕhi?{νXReNP~fϰ3WGRhr!q. E xCXE6ML~i"tX\w f[*zN_ަǦ<:ҕF]삓T5kިv/™ O#~ Ud뎌7Qs;Slc^8Vg5 m~2[8^%B,7zs (:v.:k?~IYQmwCԌ4::DJ~7oĶCAot]"e%'s%7DqwYuM6k*01=U.fv7*duʇ t5"?vSu-ߎ8mu۝9?Ƽ\-H~ZDڶnIߊ73BXlSGW,wNj`ZTk OV]¯s>kՀ \:dhrBx?3<0  *7USg_]41R?}l"'~$7%ePg9\nrӿB5_#hl1kT¨K>$ = @<"RQL3^F!yi nr vlݫl;V+5(!*MaK-לȪad]+2V/hvqU7/e)>B \g]/sWɓ*`woW-N K,RG!M51Y0VfD"Jwem !Q6j4^pPJ ,+&sJ'(ҕ6cT:MHiOMkMW2ќmJ7 ʤbש!h6׎Y~zVlXfdJݧ?2Z> \'VF6Lbpm _Cn6*IK`mCl. ʓ2צ65V#="X0K:y#/}֢.YH;ͻJvԬT~j^䲵vAî rSv<Bp)@2H9G#7xw_<,J 0ٕ_*b rNRSDl(>ܬ&_fBgHI2ѻFр 웓Sep-YbGɃ}su?f| nG}ŃWZ|洱$8lb?j } |<HhCG>D/o~T#k)ȟ29Cv|/gsD4˞ cx"uo :c適(dF-#i]KRx , w^csy9j\xx1'vW"4M-hÙeefLǪ8bYs{1]Ʌ5EC%Ҟ584٤yWB`$7,U+>[2LZ'|4MDYg@?[t 7kRyn.q!u=qk'?ĉ<+~I#PX7uYJdi]4UJyMҥOv;^@0lu / p(Q̅rU ra33Й@藷A} Ls9X[(>G!odq3ϯFtK0\oL`V YDc ui{<"Gchr3/D PG}\~śkStn(10!Rć{gV]Q \΋ 0VBDPzBe!ztzdo*JPEǤ_t{iu6YbgtPk ckK[;{e oF‰/iaxǠt9&|}mmB8^Pm53(=KZu\5Y?M1]ƣV@ "5;͓ 2;`&/Θ;w­)zEJ 2z8ivM" n]99Y:g+tb?ߐ@Ps^l dxu sqk_?qn˟m蕰>pϫ_3jI|0E~7sޒ$׆V.<7LHv*fu[m`^_CQ0jF$Y5/9O^& ΑOa `'ِ8{w}EXZ~ݎ7e"fM@S;LR-wԎ_5!T?gߎ8odgSEtIҥ A~sޚ pzIAm F 54)?ZLcNG폱B6c&7Y? Eӊ8@FFVxWq%mtȇ41K͒H,r#{[4M:|'ݏu0 NPO7>rck]xP4dt\}:LyJXf9բsgv](49{&?RU #0 *Ok\fمkpߕ`:Ţ\%YɿgVe+eQ|oϞ`9 [t5<M*9ut:$'B{Of(l(l$lrMUtI q$HYwlAY0s.P:DB/7 y/ݨ}{,]6$zKV1kyW ]65N!c~Z݋Ok e.!)/Cҙx;@d &P̬.(+2F=kbG?Lmo? P8_7gȓ<3Cuw nYuɤ ijBף6CyXcHgx+:L_ZSE")+7+Z{8>WƃF7991p~ηNv^ JSS8Ɔټ]_?؈nsOI*)5DEiFm=1|>XFbtP$(1@*&Ahv8&N+lx I$Յ1#q-B;"wX4!}sRf~F=IamD10>gs4}IH>'Q sQG(XXpȣ彣Q)`j:oH+P>NjZ6O&Ƭa鎲C6LN|2HWmq|ţ_yxyBA@sz6hrƙ^NH!i On{!>[uZ-W7<;U$]3 - SG̱'{mM0f^և{ud=2d1=aؑ#8ej!S~;+^UB&Lj%@)]mA]O"¥V{p;TTDC;l1jTUAZ@6_ =WyC,?yZ?4얽x #e@ҙAͅف z$Kk9z mlX.BkPNj.o |$G5{&y@\.i=ˁV MCԸf{a~ЕiACeQJI4i0 ]f5?c7뇞vB.i 鰖rxX̅Y!/ut({|^y/|ddzPAr{vId\|_ k{Ͻ5K|qc+wU߼ !Ԭ+#_SAffP7mFR];.Wz:?8*2%4 "f@*O6JFry<\}?ξі YmV5str'bb!xgNqmHf\&{V7FsJ}j([ >{Vi~1fVoH@XJ}̮^0ods/)"2 oHwk-2?a93!^x=ϔs#`!pe+n\kYhfѝGC{VFN idoxD #?E_B<&$ɢ] ckLm-!><]L"n\ ~^n)$iUop@#,ޭFێJX9V@{,o0y<Ե p680j&98×1m@r[爂%)u/3b*TɯWeuj E' @!lp90MUŝLB -jLsFwx䢫bchyjF>iM4W. hYuc*ӁĂn[z;|̮Ud }0+\9ESMkBşV뼏USmMo[m] G'iK>MSg)Ws;_"^bzDکJ(V8}P'e3@o"*-xߗ 8|o)gi\kI8C{tCJҦX~i'0f|.T)^ 6xgLL⪙t)68:"%n5B:R` u -B5yWWv[X7mWT.!4\zwKDg NTI=raM7 6ti ;ыGY^/,UF*u?90e_eWMY7Oyp[mBOV(]kق~JvF\/ P9̆řfeVKbF UuxH9`,βU-,9{)Ҁˏ<5 $HSܼB(RF'ͫR[>ٕe@L珔<6.t))ݮɷ;^9аvP.vn-K7(}u_eͫl,D>*$bd*LJaXv*`GKdO@:`C"MÊÊNL3;^Yyv:P.j@L= TL~./*sx=2jUWz6元k[a!(aK3F͢-!S|Xd`[a{_mG~ױ8D隃TDztcNEáΤ&F$(5h2A&͒=N,-PH yζ,>$%!ͪVCᡎM03J_@}PA T#X9,,pf#QxϹ2cIև6zjoLc&|Z',Zc8LgC|U_!;l,@؉OIUuˇ_4䳼:i΋8jo~S@f\mCA|vhZMK(6 7RXj@Ӈ+;jor#d`tyr/v_e #A{~/&3%,ώº|(`« 8c8PYo Tz%}p3C[0ѕJF1z+c_Eހ?v4<ئ7W3]- ~ͬٳE,R8]*+2_v:+/n3Bsl~:^5IYSܪ_dNnZ]֠ܲL~,5n^W$!S*Kt st{,V7|E->WIwe90gO{);҅L -/ꖮ'SUHf gs׹Mc?~qͥ~5 )[2'd> ͣ$Guܷ=w8/Ij.X!  עT]4HǶ{5CIyէ-qqI&tjS)lWlι^aXEQqDݬ)IIyD6RtAjZQh Q>+ Pnj=},&0a{KЗfFLķejDWS53Ӯ z"wAJK#]g6h PpRPc1&:g+[׵ @42b;faՄDP)AÄZ%'jvVhdCRui&M\Pď gįr?p1Z;J3&J1='R<'H Rf\Hb[`Z1B^=tֶ:`E<ېM>wmЕ g )=<2垔AN,VE{&M42IJhߍ|:ZQJ-%3Ĥ.e=G? O09:n 6CVO*T^,ud̈\i,[P AfEܪE"X H 2 'pbeíWIY >eINPPp rkR"P=-_(ȉQF=}k!l4_xtVSXGK*L\{4L'x^DEWd):kVk 9!PYaF i~LI͸bVIAhZR/CvdW{iQυۻ#ÄO|. j^]1nՃ t'SGCQӲ!7@Uzr| +JCz5eb&\t0ӹ9yv oϏȽN`А XYJ"޸U{FC`Ap3|YPj= ˋ9>f4$^_с&+f]"E_PJA_>.FIӀm:0&0v eؑ .,UM&r88l T2Hs}*tlQӟv1zͯu^ O6 4?@@ЫXE9޴(3{ofL<*do'zu(6FՇ";`Om<8sOM>˄ FоzE=E15~oლRhzYXر;2{'wc)EsxҥZ/ IMl} s/p7}YVUbBar^|er8Q~S a:?ΤI3¾|낯o0k+.3V H.^XNgL`dֹa=_`Jg[s~Ou# EnfJ 1nlNLzgxkFI+^e R9XUz4Nm\&&BrΡ#JiOAUq)U֛P݇k Ρ:ڦVXF8BD4"cc1R5`f4 Tg{]cɦ5xIqkLУ\&Š k0Y=Q}UMZk5RHe m>ĉ~k񍚾1p?CP7K屎U{&+?7ul*m?&56ykr^{(e}bKF+خkrbp(^N_`x6<ִhRi/u\\fu?F_7~Rw%5mԲ]̹D@ct Ȍ:isGXfqoDNg4ܺ@CS$AbTB]k_ff=eTy5o'R Ҹ _4Fjf[Ƈpi !\MRg(Rg3on>lLp!cۍЎ9A{L = h(=''O&@r񏽽r-Wɡ+羣?.9>w0s\K4H"[Pڠf-ffD { <] \"@tIg26}fCWlW.UDOEOع[{}*I]D⍎tN׊DȰ+D Jf6-% :1T )-zNÉzw-T Jm h$fE*׏EЮ(mǃǂ4*ýps}kpMW@PjF7 s?O#gEuY/';|)ʸ^B͸o'vЄ0 |XGr8>o#t7~"eР0pN㢤 /ڈdmMA 8eqF"$G|_y)b*S~,eJ+՝X􌪄D+̐NI$]Bs\a_4>ܜN]`hxe{ d슍U٧ޮWSu(w;.Ksew|uK9{5xEl x(U1 E}}-3LH9aoB4k^ NFSYr{c'%@6yyad#>26faST bT3 ]pyX6uw۠p1= MDoݩtyH5q% k\EG N@^'uR??8Ufv"F5ViC]ݤNU:4&?}>]5B|\K2$Ԅ؀H=\..!Aw?TQ ^CR*]-Ү$sm4XSGCaDX,F9aM^>*XK#J3tM+ϸ[250Ý10.x3slYZF1†]V|۾czRq8OKA4¥ӭ@* .u!=Rw07?|N@ [ڰFmt5&7&h'1B9u[jINO58mp0V+x HK|z$8X4FP#Zx>06Z,Zн^4gx9cۋarQ纑ڕGfWPÏ։\0=8ђV8*$#,s31xLJw;sCgx;܅5g*1Ia', 9B.S:` CMwx_%-7wۄMێ) -.uaNHLqfes&52j<"EWZ#*љijLU+[t[ԮZþYj 2P3_^3%Ɋ26gk[13MqA_/OIC9@@ <1b1W~ʟ[3΂RϒM'*LK vb j[27f^Ա76'oI{uD~m}B ~E!*F1hb)_"՞Q\6n("g3iCmGr#PیЉP#IaARA9Ze-*kT8ܹbɯk؛@=|o8E!V &=?CT { Vs·SٵTm; :CUa I kPCįR8Xi Z^T3eR]H݉(× ӂrTsY +p#J6(cX) xW>@bͣU&U#ןF'Rvwf^Li @/NHmiBu %Q2dQf1@նSxd 0b7>"TW5p줽pDf tw/n& k ͭKơ?,6 , 5$ziA#0_i I&bQו``$  98oD5?`o͑ 0)d^o[d FY&J߻}%q%MwI4A]/#O EsS_Vj$EweC>~Ɠ|H'+fȠ - j2e-+Ɉr}K"T;!w]_T]V^ڭD'Vn-~S憙BI503ڕ$/֘Y?=ٿOg:&99?"{HSGF)JmZ T\0Xŭicш 1GwrYzM%S|sL2OT W<2l 8ҐuS6rlr7gd/n6UTv*ͧ>0ioz Ժ"GnNT[g;K;Y x`s@+>î[ONiT2o|Lrh šjG6ZD+lYuc\.f W,OۈNqг\5ȐH!Tc" 0NR);6 :%;HZ#Kj}W~PD_̗%.e`ahSF;Aã8X}Z4]p-y^ѱV!Y՘"X_MaQ(܏V `/&!r[z/Qb0>uP=2u2J0}'3qHIm;x "}.Oq &&sr(M@M1d1orR,)1͈" 7fh탔[=dzjGY@ՉsqQ~>3YD"GYK ["z4*Kg56W:W,wjco [:9"T0Z$"`X|SDA3;himloNU^8˕1'EʐaX1,]B}[@4>lg&6G޶ሏDݖ i!tsh[4HI'[M=4Bk`:0BPl بʁ9)9#WRs|jHJW|Umf^mPMJ&_pOk6Ь`0l35:JETحXٟ)V?۲= ęZjk=W|$=NRٔShzs4 yKߜ-O1*#l Л=lu7TDNr5JYbF~Gdܸ" D˷y"-ހmv`u(r=x|ATWX/DN:(̓)ێ'2J$JLtсNnl5Fu\QY`(fY>~)vV% uph" ,Ylwyǹ<8 g3ȡL~ث<דġ]s-3H#f,yT aq{j/GdS:[L?'cFJ!6Ltn+IiX ZC0lIe`0}J H~&' tД*s9>^X4ŬZX-$itXI CBhe1v$ H6Qhl]BC^c;@9iZDίׇU6&tM)3}:joj<ߤO_ݺ5v"ׁܹ$O'K:3\*.+zdb =*aǓϡMvk+aPc.E$,ULmo! Z^Qi ->(Ӳr(O|5C%x/ƌ.9kyu˃ٕ@Sۃ=dp$ #|ݡ*%o-'kSw8EOM ZX0~GYJ5WJ/p:\XJ714d`$bPR Dwy|V5Ktz!x4awUgsM%P.i8$EݒMI'õp6T,1 `JGiDAN@gy7&0{Q'\ZPHGAI-8Fv=$Ajl;E"] a#F;!ucBJl2ǣ{ =+2Ɓ|[pi96j-5OPv0Ho#utbBpJI}W+Xm"VaddtIqWa֪k\3X77@,8sVVEG9N-8㆐ϩu{ .S7Mc1DJ~M~<0u曗)qs +*<'4QV__1f^GF:5]bZG+/G>ȫ@@p}a1#Ԙ>G?PUh?~7_KkƝj6L%6yLk&ޮޤVj'.+)!B\el nj@.MSq[oHR_wTsen~x\Lskuf3Y~:K2cL֓w+0~`2J0DܬZfZȭ=:ŒhWQ5ͼ|wmVQU:5^+/OHDpO|zwA;J(pu0Zkwʲ; Id j;6qk.F;w5іͩ}jU$ ~Ђ4Nq R!.&zA!BVzd@@X>6 RMbˠxV%"n8 oGB0cpφqFPh6띢1";[ v&$K-e4nh3!?U-䠵LBtYpXsZD(P 12x4鍶^Qr Sp+2M+F>,ȶrԇ+.TR0{ rs:8 ,F$9? 6"aRy6=e--򤠘snlu>s`ݒW M:< v7;7t̓%:J@>3q(;KG]<VCrf[mJ5vHZi+h^ {g<֤! ›%{XSVF.Q\$ɑպ>;ƨO4iHDG!KɁ.1=Ⱃ"fRkOk,S%4qZ l_9:&ʊ)kF#0__/.(ǥranαzԿ*;e'/ PMϭ:x f`jZ "A&2\1v΄h ԔD)RfiapxHM,.+~l<<Qɿ?HuxIPS+G%^쳎ŧ*dZ~CX? ~\*;[F ,%<׽P)s'cw0e@xAt%ek K?$ ҩ8XZ` :k 66fcgw"@ ~(%H4Q/@kɦ=iufz Cp~ק Sn;_)p}-+f "i~vx[ qEߨ ǸPXE.q#([Z )%+Y `Yd/;WS_/q2];}% PO?t|*ְ|7bgVѕ2ctrǡD3r&X$մQ鰋΂S9H`,b!H-*ZrwU!@MnofGi8dO 2&Hk>S 'ƐFлP޴# sn(ĎM]J;ܻ_ _@&;Lbts"!{:SIIq' Щr brZ~ɡv_BHBQM jG]w=K?o1#$bޠ=lZPsOȝHL wIfc21yNV\Ep,u}>\|3 -Fl:JWXFvȁPxj/ܽΓI uWu @#6 "VG}~RϨ̵`,)%O:s4ᕏ TÇ4͈]T>2db@sOu7,kh?cƹ(wP"ȪKyT##o.h|, J cE]v6 ^K+L~O>h2HG{N^1c rX$v$I0^eWi-Rh҂^S}TS9ˮlҍ¥wt#(HXrթ}dXG-pa1,Ex=b]D t4vM/Mv4c.)iAhpDWlT[~f)mh67c1M cty%86rl+6 phFɭW6txu\݆SU+[ޘ>/Az%q}h'uH\ Gbzo.|hevr$ ݲT'`+{HF8XaW֓8(&;H K͂tjw&-h8MBݐ%-`?֓wF6Yդį]&jȚdEć[,I~ScRY'O|/7b5VPҽKx ^b¼ubBc9ٔ37 {֬V2DbW8s)xb YQE\#J3.Z ɊhYvӬʘyÕNPÑzԕ%(k!:V8a|vگvGՃ`΁z#a \;o0wޚNvb־ *XԜs@n/[0Ekɝd`(SVe:ȝnb.hʕ69rK탹eqQ`}㣪/C AL(J`]~_(?]pj 5Nބ@զ-Wă`i%yX]c'6Mq_EPffcla򽮫Fш2-q"ΰ ip1< ٢5߸@[éF\'2䘗^-#xvT`+X@N﶑%J8_h- HvrJn$QNl_ԥp9rII:O^ #G6Bc vqhb K0 bihWXѳ«e q)/ZUO',}δMX½2<^q N2V= ~EI;øyx;_%Bcu5!=⼎:xuM=dbf̻&@đ⚢6OR 1Jl0g"@#p\  FyݪɐHFIζq9bh:{lT ;5 jgL8 da⻓tQf1:iZ&7GI_w誩j:3D{W1c!E܁Sc͛4г,9'U-6NwvOC 6@xv:_wF?g߃2DF $^. <&L3?F4]^<`N$TW%e$C/`bpҢGjy!=6 y>(\t~)%xg>zaYW`:'&bIa> 'K*IA% ٞ?8@RBoqƀSG8G3 3ڎXod FOs-+cKK+*4K ]&+"7# L^fF6x8pTNx,! mOzp~]!ȋF ",*"H=1q im~ D#shZf~ԁ?e H z|biQ2}_jэ{p(d[>4kU,\z\!W&IW(Kp@v x<㛎2"<=!\̔X3, A"1ǔl'j-#h5TזI ~J䐓 N Gcd7th;ۣIo:Ry&KI%O:]l\e`U*MhMh;b#(f6Fr\^P2'2_YF%j]dʢ(RE6 'P+ɵ&aqh/Yp_pa>$!gěM'Ƶ0)E~͔*a> ꢧT<~}<:!ZUBM륻 |(FY` $@$?/s\>.CuH\(o}:>P1zHҸKmfJ,!Z+T4c9<͇zןXf^I@}xErqWa8j3׏_ʃ|sӯp=vM+Gn G6(y1oZ2-#[7f:&oyW\Kܾ/rG@3fR g^7oJe/?T ij87>BɖP2{JmKQ2VӠ-rust-Qmk>80+( Lo5"xA +0A%iy33U)ƍͶ\_n{2#D lW%=l7.| 6`7nz's1xuI< 9QY>ȳ@|99 Nv"2 ,['0SiPq'>;-MII,<-2@ xdYeKVH>b2>14i^j Z]19Dt}5,m!Uʼ]vRq={&5"drݑ \:}V"`| < ew+] b(XCP:ѮAQnj c\?eu':'=h@mq,ptA^q)^C\JDm﹪-Q6y#C#=&=dYkbt+NC6}/I*6(IR?ʰ> Pɩ;łtԌ7{ ٚd?1"d"gjáb%f&F-]:i[ੋR2ac~1c=!q`,Xt^;'6^6Kq 7/w c҄_JU4eZ@q z r$w/Ƴrvl|6 f,Mβ):R}l~T4$4X Yg7%\oM kQ'gH>1 DE$d^ZAe~>he1g_ ZH/xB!aCB>#p`g,jG&GÕ^8@O 7eİh 5, @q j~׌YVHTm'w)eU:=HBF)MBUQ6F [_?0/A# %.?0<u[G_}%z[H*M7"Qt1KRE߲@! ז)Yj+JđL-. cDIFJ=pd}Ps3ֈ3C5c[V;KݢdO3)XFH %W F-Ý= DS ނs5m{pԿzD@]@ 8.ASҬ]~,`#d2g}ҵny7f͛[fi8gA&*rL&; l/FH4p0G䦦$|6n sz7ބ# lKSz?m5v5TOܟrWcvC&Ÿ|Ɵܜ5F6m٥>.MΚSnlȍJ~lnghOA`X3{_!!zq/T^퇙~ңӭÇSj^%6]! ;!tqxc?Ϧ 7G3*#pWgi|ŏ`|Et~P1 Tc#)u?nW"ĺԐ᷃xV} ξae#:so~:+]{E6lP8K)&^g9sӑߍ]Eppk6{[!9mI{s1/@ڭ9.2-;ɟ0%B_X$p{A1d)eXAPy`Y5t0~FB8@l6X9(Xxקn`kgaP{묣Z,m@*=r~Õ?0vLk~uTc胶3DP~#-DVGT_ǽ,(l}BcN.e֩ؤ0R/}n_ ՘YvH[dKAp)pvbB050 u߿^ X Ȋ@gE`_,Pq72z/:kF,EsN >b riTC$7*` ^vexV!G)܉VDSX& ջI;TӒB!A,/Uq,ɽƋJ*&K "[( >no|z(,)IHh|{80L4|.S*Peg՚^Ov"\EůIL8 Y 7 5gZޖ_0l)8c7Ab vv-dFu_]*cXZUjE)k& _0vuI^0t u0eJ[8msdL[S=}Q'l~jS%&u1ںP{(;{/zzr@kkᨇk5Ǝy]PI`^]Xy%} @ՈhpIeYaCLASBHZ;_<*4Td`ȳ( >,mnhOkzn~7:C/ )cwwcqر3_VhJWYD>AyuF gX8XVOf~?JB6sv;6˚w9-Q4\`$\(񏮜1pI!eNߐ>c&YNJ-RUQy'=:1M!YUơ`>j[9> W'C=hLB?Ξ u#vZ_LX8otAa{@ `IbIL%a ``.Rv -;L l8i5' }&.Q~>2ҲZ{)uᕜ0"rŊ9ipf)0=nj&y5J?SYy]Q]yBgɔ@zcCrT=,a gN o Ʉ>JQҩ .ħxF5[n C>r~fCcIt93zN;XɕZ`旛ʤ-IƠuH jEz 4Hf_,Kp\EGFT˰Jp,Ƣ+uld➴?9qP(3:,{O/O^Bm=,c;+!>A=59u,&t)%^c ܳ`lAuYfk H_rmfOa٢p\*gXz`DsϟY*iYA3B[s%dP;aPӏ6p6@y+Ӭ7j1Bke_z3PMmKG~J`p"K%Dңv`~Xcy?s ,U "5Ģ >{fjIJ(;{Vɡ?iHPA8zP\^Y&ۭѨ'bYXr4,0NӤ"bfۦ[rY/)ǿbcsnAUak%p j PO8jgpefCkHƂ䎓8Lkd"ݬuT/i`U`tmr:qεKӼ]?mP j*;TPgSYx$: ¢nli]* ?({}x (HXzNW):4C=v;L!$6.²#.lSad$2i=q;¼0=0 ؖ~"`u>Y e ٮJjL$+W6_u:zΜ[,Hyk@]c)|׊j\ZXKN/Č>*\*a^g0]m|F+5URt<{Ƒ7ɩ,W DD"lTj_J7D`~wy#V\كZ b&7,D)0XZ"hab5&Adma] :*5 Cz &0^řɱt*!2Pq mr-axu3zC̱!j#iBfk'\{SD6[ZYCjҳ,/&&΢Lho IF;pyoyRIm0pRa$X__un cXɗV+l!`}]C)yAWww&S Aᅲg@)1!$L(>IB42m~pzPj(y>[:8O,zۓ_ΜS>G Ud smAA8rHu^&ν&;nԧRum'+=<Ȃ2Y0.%.֩A c٪~_ %xp3!_SoZ.;$$?LslyhbW>hӗ;I%82*I93 uTK TrDZGB%0qeTQSrI]ѸTX" -)ekjAKO3]ߖ)7RhgGvDegᕄc 6jr  >>ee*cED6m!>ihJXV><,doˇ;-TJ8)?`72E#Xhǘeq\.L^O~i{` `ا7{YgYER4E|bhoW}0@+](`h؊"&`P׋|G8[DGL[So_ [ #*h-g[Q{"&d[&}~Lj2SU C"Juk@g-͢`'պVv݉Հ,Ymky+(RVut> #˷rhwQa WI2tx^2zr; ͤL:4r be Dxn m hmkjg1\x ?臁^ P`XcAf]kgx<jBmbE$:4MLI^EaO2WS`CRWTsh}xd[ ֛]H1}\uȼdniD>‡ !GI}gxYzG0P@;_ AEb ]aY7՗Imc~(r[bcw2$&Spjj ~P/_.WQO&1XԠC{z\\34at @*4{OU;)Rਫ਼/# %^@fwoTہyW./ёfjn%ך6JAUW_Bsr ]tũ~y$S⻰XNByw;e~Iv[2TX*(^B(oʴWTީ)EVOdUltAtr!۱ɠ?^ovi)B S+5f8Pד;/F:m4._/(,%f8+ uj96фCRzdpNLO02[~7C谚xzO2mŚr4/7m<_-V6IBR4ؾCTSm68v/~I%#njFÄ+SN>ih_Ke+eJʎTP+t (JY<~>_q@5VkΜ=.u0Z?Tn"ipo.<( M> D53bD]n4eHf:T;6q2zS\y%i"^xyW="u8Ts,g}?h&՚D}j~*}w=LynC߼lDx-qtw\ڇsy^ځWB>TSdӭ2Բ?6#r < `͎RH drѾ6{?V @P΋}P!DS C)Uz}&K:@VNNx{;bpٍRpUWEQ~^6VDʯz9K=/{_:@ Jnˀ#prr3Y=]a~ԺG PgԄ3%Nr"@k6S.sʷfP#ñS]HQ?{xvY?̢NK1k=2밊s ' ߣI~ PK Ј]g$sb T: 7wƈRnS[Axri;f4z:} ̄uaac% X[=-rV sŃhT-b]~ECd8ʺk5-fzV(~"@5%xxgyzNLZL~8%ǖl=s MmPL/`p Y_݃+b+\Җ 5WtV\)#ЎSaw$ASpJ56WZNMYt?kĚ{ "y@/Z4;ymj D#G^3xeB ~c5RF8|8"ü61ngExgkfݔ?qLƢʖ9L2+5:eGMUA9Ȏ-E?P&\]hV-Bh2V{÷ tHKnCOeX VUS-ZZ'}Fڠ)[)$bR@N╢Y!]Q鴇* _X@FA7CE,ޥ%Xoa0{EcbCuCA^WGY^۵O+ᯁd5r~*t D@KpN^'$9O?&&d}B5MKUĥ~eBSmi@^Gv>?>bC;AFhu[Q7HtD^uX60_ک,|%C(Zg!Ƹ8 4/ӏLwsÅC!*DqCyp$fVs>H!4[|=h9Pe,Re2?S/H' {/˝ ]-p ')K6Chbx6q0+%jɁB5h#xLW ߇{>? c7ُ)$w-fzsEU_ٟM愕 k{΢dT H5T%5ˬYM&?;c@a4$ ^;&M |;&u(HpsLBhO}2tx~7UtAgH u;jq}X5|_{5`tBqxmj*Lµ2uLU<;I`],8N#wE=٬=R%K s"hNZⴍ@->1Jaמ\|I9tQh0P7;܉P6܆< 'Qb1@;˜p?dMˁ|W+uv: [N^G&ndZfb̰MI`QxzէZڧ/sf' BeV1exk78r"Pؑs^=R\ VϪR낼ݶ(< uz Uw_Xah{S4Һ4@@.5ZJ_^(G%Vi-E+75L~$ʹC<g|ZVzO7.?m3yk`T[Q1f<u2&" ^ pB|+?L=E*_om5$¶ZSHQڛ`R59({Ģ/L.RD|8J[5nKBcu7XX-cp Fp7ؕ#F̏"۪pڨ JsZN!IK V 9?2ߎZTP)Z/ʥwQ5k Ko4RS/O/>ȍx՚Uy};oԲĚn*!e祕p`ZiK X95w+4K87gG &!F{AĀ&&qno(Cn1 dؤLӤO}^4T ΂V +-9%Ǡzu s?72c KoO.Wl )M-[0۽I#(?`J%~diZgwf9j >0-zL'[&x祧@JROr,Cf寴jQfZM7?i[oː= +paf;?QP#0k*-Oq3lxDX~ ܳLSk.bq:ZY"h.Zd5k HC,M;0< Ǿqb*$BnbYM;([;S Le$!@rG⧝ +S|Ozay{r}nH%}supS3zC )vڴIaUDBֱ7!>a+B:](N5]a@]d_(R+JؓSV}2!%hha(vg<~jׅ:_9f$' l$8Z`멇lb]gf>|4Xހg~ҏɡS5@$fTS,躁B !lHK4*xU-jȸ pr"Ҝ@"G+|534V̴5&gL{z^=߳:Φ!mNb}'0kԚYu-P"- km~C`Jq{߫ )rnr" %UR5Z %KѭuQ_XȾw4p8&I{:!Q3ԂjPỴMQ~,H%r9R&Vb<{eF ;#}L+kƐ!(J$c H"du& [̻s{/aR4ߪֶyZQg&"nekX;[O6e؈?2NJqO͜H}k Cz4tVJs' hDG@6h8$wU;rqVMA\(^.ki;I>kKZ~sݛJAlJ^|uih㹲I,Z\\#֚TuhroMqVYsv5]Q4 81:DPOOeѪi oh ^cCÅDr;]dAnn[$Hͩ85%lА1)+cM5O{#@9W1]iybVpNds&{ق `4͔!3k^5]j*$41Kc})pZٯAP}b?p%CSEtI#0KAi+J-}1%[n}|}w[Wp1%"xVP E]B̬8gK`@1+:oIKծ3)PゾVunBTӬ"ӘݕyAmêXp3uiڙq$P Ժ uM>.0qS/Oj1G Y;~]3 ]39y?Ros-2( w GϹ4{`][ř p9L40ᄭr<7EόOr2RM.X? 譼XX\'$HޮIl-6}v7\P>墭SLZP8h% |*OogzeAA( _s F=<cc<]2q3$/ +%zeR/cTd+-7u8?D~` Qƫ 1ڨ5# GcAS'{@#٠/^q}Fȧp]v;ONDR Vhi4 ;݅i {Mj'#U\xEŖ{1̀ȣugO{1Y9@y 1c,?ӎxX__suexڗ@%Cб~? W;s4NwKGNC|wC@cf}mT 6y"MQ ȍ9#bJ.ݗRg tǩc^ө*PhFbxC:Z :݌1N.q\yyB= ܍8(sAɣ%h.ӯV8:R ~2ųO uSR:AۆGfeai$^]trpV赤OctB<:2FɰCܶ08H/S̰lϛ#$kNplFH@MOfn}vy!اk!yԪ. v/]XQ,}2 N8mՐlJݚOi%&COE ay+__/8ĖD]cH"wCB/]2LYOwqO}jX9Ia8eoʃsMK)&}lUœr?DS?!c5dѵ6-G^ֆEPzp:\)sRIV*^a4N% Ƶ/ ")RDd(3,- Oc;E&}A3~g`~5y, 9;;5]n"\ HiL$Zߏy:79/F϶8CԾl:=rbp-,$upOpZ#m+Kzȏ\eNT:Һ9Yge04E-?οYXLO6(yO!sw b 6DH*3#2=sH&2 Yb? 5oqx z?&g8ǚ Wyd`7TGc}y|~\*'Go|1C#Th"X,54WڠJ"ZwY#MVat568+25 i:" 6 ރzSJ6%,}{;WT&FD32 B{W4vb"hD*Qs8XU[fOVag~;L1I} ӗ܊ʵh//7ef.δh~.1opWrZ XaHW|ҵ^ _9~}٢*ANtʵ}Xئ2nU6^PͿΝV@h1e ~'dW s}>-~(:=BG-tgܨY]=˕@o@z(IOKru\i:5vtp0;NQ|8(Dէ蜥7$XUt9f#I剾\܄}]hdb+pH%- "ԅY>Zy+nԇ<;_(O@i2i:=AOsFwqrfEj2,du-@9y?:(g,1؍,GP WKIGF*[)rDv/DznI0}ch{~<^^)x߿XSo6}j-Ay E<4~NX8#\_[ _ XjqoO$4:Jgvbhl{ p@!èap}pmKIDה(i +0WSĘRi9D|32\h9:anO! |u@YDš8@| ]V)$l^tVUQhêK9-[9MSd2fYi"uguڄ}Ky[k?<{ oq(52,UVQ&P]¢Xc{ʀ)xllB$q A*('-T* ;h k]xz}<<8%˞[NOJ8Bt'z߀#|tȞJw½UfU#)ڱjt!(w4-5[A0 Q[ 3Əcv =-0zix#YyrۨBUy]lqq 3?RTTIO5:à˭`U! HS+͊x͉9'Xm8TQ.^lG7q&yưzZ.St+S2;Y! .]=)M1@Ea+ǦzYZ+RMAA3*Xl$2YlC;8W9Juι|,e, 7ⰛB' c[`0X썝/B8')G*q DZs:YusaD2qzw% jGp쭙*%|bEտ#O}Q5JxCn}!{=pa4SI<w(&A/(Nf%]Ve+NQw Qj&>l0z7֕9`1/gd-ep@ Mbxg{Zs[X6%OTRPfJ YrHR@̷C5fEvmTseb14|À_)Y1wb fQ̈޹ ȦasRׂ텬va]%wM%_4. IrE*ȗK~ l0dIJ2j# V*3@כ"_lڍcexy{,~M$ D)wVI ɾ`sK~ca`йY^ W{N@om3Tp f|rήixy#DX3d*EJ M:bwJjV"o@rxӬU7MN%vX:zy BUkRoQ n\I!4*者yƑm4t&s ؕ=SpuGP`\ǡOLA"?$ȷO9L49aX֗u=iF8{QzZG] >^N0q^(B&ThOfu2o_8(~y)_9CA:AB5=\wol),)yȃdOdۨ홻>Z&DQ?сa.h>΃V LlLNlGy郩0K]t]\P)=^*?kTЀr7Wіm^ӽ)xȄ{?HF_%x) 0pʖ615ײ{ !G;֓:+Q),_4^uHSļIKĎO(PPɅwQ9qTBt5A QEDD"8FЄn^ {n?;2QPql_;nm3gy5 ';jF*'c9\1{$1L ÀjLC`pGOԸ9meMŚL wgE<^BAH֨\qtE"іW\DOUӂћ/EPxhĘyf}rQ8q'~q'] }斕vfȉbc Cc]WS'N5r.lQ4x,rǣ[@1 b#ICdoB6cW+ )zؽs.)hcb'uNĥϹ+P (C o2ɣqL,/U2B fJ;PxEn2} MWt|JR JZ/WO++rArDgbY'/ ԣ- ]dKl$ t FL]TS8Я +ӳE 86Tu7ɝU㰭zl%L"~2]a-ջ漂 |!E, 8{Oai<UW }Cq&oB - ayz6%nƲŨ˜9Y K9`|N[N߀*[C"117B?X\8&Vi= #<&a gZ`ge5ֻʷ&7֔rL_â7S߸)ʦFhW+6Gdx?$f~*< sC9j_Oܘv_U%w\/XǀHAwVy 8(8;s)զ]p3%>|n᮰&TQuֆI}&@ ҩ*]a\N2 A 9,뒬Υ3v_0]FKI6n_~3dٱ39WBsi7wۻoB f7p|j R\%1@:"Ya~ë956`Y)C %t<TFCO%M܉;5~Q|=3x(5}0<@Ƞ鼥m8q:þ1f|XbV0oTb/{|ęǎp/4Ӑ Xs+DJ$^ctl585N Y:?? [LN *+qKO49%;?}FgS}caXEͮ**B'V.j7t>!kp*׮<[X;I1k8 EztbSFWEkc}iNQ`7'Ʋ>3ΗS +̈6b5 =(YBKf6Z7O幼ևo#t6h&KD/g`'tu"V&f&1G=spl `Ѫ8N`g$XlF#H*UJ3\_OoY8OʢSc"a*lO(dȀC]}Vq?#.晨eoŵ[o>( F"3B5LHhg W}p#uppX 9^ZMfk8!&;V痛DCV(Rm*SIɿmۗ[OvL] ]sʕU11]cVe޽hO6BlL*$u-{}j=AW'e9m|HSu.FR<%(/Cq[m%|KH,V|PwV]-{EGI:#oh_3Sp˰up`ʷLPR\P2+T"676ƛS4!pl|caRTxBb[⥂WWe$B5ቚQeʡF||~Qm=|/gW2ҰO|.zyE'!{'D4e4S2I- Գa=pG"e;W5 "mV8{K-xMʼn܁PřaZZ|6TH4ea/&aaU|W- ՗7j~^xmX]MnHRFnێر`|JLl'\Tq+iH3)4Q45LL>Q/^oHגb<.pc\: n2GO7HgtT$!E %`+]ԭzm̩%gT, |~.HSq{lGKϦ>{G sfGeT+2]3J(`lݛ2%+T ԇ4#9cn;h]&8 b4"4-oj<d1_k@$MPzu:+ $+isd\MM[*Ljqٗ|-v<5@KBobyH[X_l%I7^Y$Xf5+$QWK2nC?Ҙ5)ެt''%@'j.Gg9 0:j.$tQlfů-ȫyw:I#HtW+ RBYJDGՖ)`+; W/ -xM:b1h6! 'w'( B! 2h_@lHUÜٶX5 J<;rkqp5U!;"CUGUbl %Wk-B?/< x`0n{ϛB%L.Zc~ h=zU*7e6=_TetPi wuc)ߤ(flJG[  '(`!Bi2!%\mD}[ ޜԄ|h u=T;R7:T,LMp+8 Xӣk@\TOip1ԊuS;9f>ޭ^v;m@|S39[eܩ;VjWJ!P3iޫg6G%gl?x)d@Wwrt`<3`2#wAV~]ߺX| /P\( }: $ U%=Y%*),gSkO-+~96$JP4rc:__-HCb@(  jh6ha7|D?&SIʫpzQf"%Voy}NJdDx`yIG/wqQQT9(XVC& __}3Eca\I~͹:䈵FQ.&q1L-ȿDE '$T6h-}Hs󚛧\ X450 s45Djm| 6vR Ʉβ}uÕ]?^ e c=0U9,+Qa=A J-i[j+,ˡf."n:k]f_/!A2̨k1`] u=LJ’?$NUt0#6~) C?-bׄw vW SWjCCAaq|tN,?rjb`'pyU|[/0X!TU15'Z!0UYګ`v6!`(+O?K n;D*r&LAђH#TOSJQL Za$+[y>J uG"=8+(4_~{A2&?{%y ,f2+S~a`kE,k sz+!G-dp@tu`GC?` :YEoՖPj8 {ފplfq%TR㿗y Ona. gEO+mX\3#GgEȰG3˂Z#gk)$ \YOHXysn@7pJj|R4:Foi#.C?Jq9ؕ5$M$9/R<_Ǜ:SmQY0xӎGȋiԔ1KP"7k?DLnŇ9(GU%/!B쀠s#yL6ybmM܃SN!K:`Չ AV>,4>U6-9if U=c5v0e6W,;lN60kXsjGfaa-Yv\=稆v>c]9><"6TeaOΏN4 {NV0n߰}DKrl4RN1 G2rS50Dhovhz:VrSapO,@>85VnLHWUHƦ ?H5ڠT|=\ ҾkNS9Hs)pmÝnm8Tn=Mg $syF76"\[m<@+ps 1/,tYWߓ8m_:v8s{%ywp HdXk Aq=0%fd]<;-%,d29̾Q)y)4BDU{t3!ƺ!ݡ1MqAsէDADdZjZ֖i?N>̎\gٝ5tn"2OEX=3y3its}/=%5-h7zeІOR}讶-TFS.ckd|h۪$@'~,)2q ѷޕsbuP8e¹yiu~|^CNoBxUQw1({[Kכ)XRB"vx2iΔRs[.Hl$vEւp(Y@zuWr8GoqX>_Ub:q_՝RnO,nbx2YOD:]sYckGdxR*X8"{tE0۪_ {7s2zw"bk;[LU 7 _YUsՒ녁!-}DX%YSem~beP &^"_ y4En*zf~st)y}u"|Kl9]M6Zmm"Q@Q62[` Ugp<$zMK&իUoh2Ls2ZQ\2 9ǐKCn]j35%Yrhrc'Bhf$╾6΋Zd\N DI#ᵃ1%qSiЧ> 5v/ ­Et9!+s(|+Py,X(1i" f~ֳVN~Tpv}"Ol(Ad+kڿSitFfea499!$yw;"&=dp9| $^9i1Üb ? 팓"K/UA2Z&SG=8dYa}/_ǗfZ!;,'C@\!n#1Ĉ3wK'OJ#X@WE~p}ZKaLGO !g4RTmICauw!F︽ݞ2o3}No(RB2f8(ȍLf<& -m%FKgсĨ-bpmρ~M'XAl)us j0OA7y E6{VoLHGz :{h@fbL$};nx FpͰ #A W fFtY 4oP mG+/9c@(\'>O&*U_et o몕T;Hɷ!*?XTEy+(OfVN:,w-\ `sy6 ¯*7 y!﮻v5*qm**¾-Fm+ ӑ%|lqrz\v3)72NMG<[6٧4}=W}$37[uܘK@EyVOXL|Uy௑~v4#w> `ACc@?۰ߡQ _,[H%{W)CWFGQt dC  +%+ˎ;TgVmE16rb`xCuz JʪG/Q0wl/3P"QxÅGߔ|';:!f4_%" 3#8e0?M~vB,'*B.%F]A086^@?+"b^ac!7mVtV’%/DXpèT{i{d[j5̐b2hֶhnI. ;mL,+j%Ю p?H81 tD,<+%R]4ѱI˶3!+- 8XBq*χOBi+sJEi0evthVoAVX5gB-mhvT0|,\2`Jh\6Rw\U@}Pù눏PU)>S-n2SUn}/ }<5P|kw6%T|JZOtS3c:asIN=,O٧D TY:iPG[#)do0x[0Zڒ4QYucEBǾS 9% wPƣ~՝X~6;5prAuL[f#x6[nRMV!ŒI>PE1HfyJ bc]\Ҡz闰\@ƣ7GZ:*rDGuߎ9xxxyxUa[)`*@+ތN\%| ;^86J0_<~wUB`"CzdSfv\iuYB($.(s'ػkPcnKQ%Kr$EM?# 'y$+l㔵]FƹCԙ3OV_05)ww?ǝ =*#~}?O`YgΈb9pp^˸/~ѐjb*WC4 mu3OТi*. S.ZS,iř_{⮀eъj2 Rߞ9&m3ú-Ns{?3V'< dÈ#, :m;Ս4rqEfZL8X!a= Dx(^zZ["[${' !gw+ϦP]."vM'F7)nW{ PET*X\trh?}\Is#*9;¦SXNT04ȯi~S d"J_miW AVNGyZ׈keK0X+W]!grgu1ݢۜ1Cw YWf ( Rԃ:Ck$À;/~6pTS k7Y֑$j91 ~ 'C:.=2pqiƥ1.NUh"b<ů>2q:C3^];HF`$P+Vcl?ɪpмôa ߋw6vf#4Q(jZkߥvq(1ۙS&yQS:84(% ^uwNvUO5e#AE"}u{j MYf:f1P|gpSG>5vbH< vo;{l JDǞgKA(w1gYs}x7dHboN2 VOi1W~twπlyШSwˏ{+31@lukH\4NՍU<gN&w0ZLkr 0s'pCyWf`9)e!Uo.ؖ(hb.Js '%lʎKz8cF89Tr4e-sǾ&;s"'gw$XD$;J8v{ߙFWGዦn8Oҷ0,0r-~iDRؒN@.0$\XM~ɖ!vo d[&.].G y`4ҥ^j;s⒍Yp@Rbμo'ʡz#Bԋkve㮵jA[a6HK0 ߸%(4\'ۓᇥul׎"#ELQpktQtz0,C3 l`H\a%2/+1Ц{CڑDe߂50:ڝU%ο5* ꬰd1i|`&u(P9ܟgA{ OVVOp!l)NNaYܵ p6W.&Y ׳c1kTf3N|ʘ[ohˀqeU4i. 5WąiUꔊdWԩhAlsQkڂvUH{X8; -V68VM?~ ;5&H}I<ӝ-Cf$ _tq~m1+A=Ь6<Ʉi!#mc7}DOSV>`dq8zrbW^HcuFVjʉ 8z9S_+,u`#ٙ;(Х`;v[[ƛ$I5uD"0)><ꉇȁQ:m7>G<bb` ]Ygݕ L9U}Ffx~6h˕x※~\ ݝ?80Q8^L:X-`=U /{ WVl\@L%E} L)YQ@ +sXŒPa"H 3ϲ&VN( g-/DZ@N:r&>A-_j^'³ tb\Ɍj"6p&ߎ6GִF O7rFu\Go'L`'G:f*ZI]Iw)Pm2 pz7橑/`)L/rպVR\!rHA&љTCX "r6-FiKybT-{܍lLϪ&CZ,[=sxQ$+UfmK*."{"cZh u}:gC mlcglkc 7bF};ԛ8߯Rmń M@9ȴ!tRE|rio2D'l B2 4ZR&Rb 8cSc;jzo#@0m`YBB$L^T;0qVɺ.JA՘͇ܥOow7;5|p(r\x>"?=i~Q3EHu}mƁ>_€YE(H_R' cv[œ(C@s~Gkk X< XKef| $n7 -"&yi^Ϥ$2^ei)?*iLhjUE^g3izfgIJ̄3$ j>j\ Pt"gz2wuD}Q^Z). r7LgB0Uvl*4ͬOy1L46;ݘ'{*wÖ5Xee)H\zwWki U O`NU+a&ӌ!m,u.y6!;m>O!_{XAAڵD>KqaM;]\f}]Ůwj^Go*!XXEFZE:Kyn ,9{X|fAo"!rX,)#t(ܷpY`̎kX g<~8t $[?}*a끋GrG&d~Ƞ60L(NQ2nkS8\nj+{ pm*W{ɒf7Dvyw7#_Kgq9Zǹ aWx >T0vڒ?YRr*ӚY*,T7[[L{?UP'զkYT/HPRwE ')U!+ǗEyC; ّ_Q >Sm\ݲZYs:| if[bmhFLNhad[≗q5$5VXW F٦9~bQX\9/3>9r4fYIv" "&@ְf<z3jF0qig7 O4&RJ7 1Au6&ung2q| Ya>M gӊDc* 뉴r)$; ]ԌH+33/A?8y)'Hb5ʰqҊKcډKMh: ^f$KƦ*U(~RIjk暬#@ mRAo]`2yJ jEykG 1yƤ UBPA17\T+lYT>=[>Oh0##[֒]ra,|3ւgͣv}N'Q,߭A+ 5'<[UO.d@ȩ׈J_V_X ̏1na8 YYqHf۶e/\R c^[E+hT5 uekd,yJbY=SlD"%eɢW7%0yH|x;{\HX2aԾ(RO@G,R{Hj+6uw;As7ofXa '%x k#Fƾ a(s(,*vfbJv_.PeU8|H6G]M_:%С1 $^@?ӡҌ*WD?+h#T c矶_DSyzNyݜ5Hψ"_f.W b-uCeh)ƛtCT5`Lf2}* ]#JK68'Sjn 6`б%SwUArm:@ziON>I qiK..eՙ.;R-w_? ᩗoR[Ʈ7,w ]0dy ?c( ׁl+84|G{G ?fXR|mX4)~r麞)^78e}v'b fqW`[8WKS&>2z@A6B1LFFDb)Gel귕( !ba9"/.2 (@VL|;qC|aFUymLP3Xk.J~Evl-4phn`Q xZu)>>6A`@SjGc,抋ƙ~6f=GObk bw)Ks-tWĉJX{K}9F ")%踗$߫`¼Ĵr oaaIbn>FPdX1|"[?AN{˜N Y:hn44WgLVCUy>[j^\U>Ǥdf;GSW&p\,%ϰWj.%På"09RJtP*1z@ %{[P<6Oh0=+VN?`CTo.Ѥ`FJ'ALOQʖLBM {HǟG{5%d FGh$!A&Qz D$6%@Eڡ6u?oQGTRv }0zazWPUIp(%-wR"G/aj" ˏHƣWWOr"/Z<]a"2Ы"A 91O rW8WWy<!x^O:D J(AVf};~mqA2Pp\b\ 8X#H,3Uo_Q2)E!BۈUp+_ƱN1AϷ1pW>>[ ڒwu%ڝB(?5{]\ԵJnA܅”!wx^\+ό5n-H6RqeBۏF__:D]3Њ5S6r(mxH.K0;fikeT|̛@ReW z,N B9<k&tns/'|; !l voI#(?j:uc&kqs4| ߰MAK]cr6sQ#_W! AXנ,H_1YCa,a;fS],'%H^;Lc=sv>B.#fGvKw=V~I^ʤ!VEVo+eQL4GyYn.tqWG桚;OxYC8vaA0|f'a= {7(ޢNX]q3H $l3WҀoa8S2 qwHf>I(beum|q¯ i8',[lM107u nנr]p5Af5_0ץ6&<6h߆q_wLN_4ΏkҜMոH~ҳlFBdduzP 7ݠIQ MNHvTDC"oZтr1{ykW'T+LC3fۑqo %e\)_}{r 6Lc?ryfuMGp=ÖzqgXKʵ EH;zgo ˌg2#(`-c{. "&yYӮhW?uxUt*^'9&Ș_0rq5~lSKQDz_Ô7H'򄠫d qVŐe*̧uG80kZvH%&ktXH͂YB`9pIxgVHjd45' -Tfk,V!4'W'`Mq=CÚh\(sh p%5p\pn[A)vőEdϨޫs#QIuqMqDCAaƩ[lE٠*ƒ-hKI",οҮT@YMeB+c_5I?Nq'1nX~Aj,y= KMlq(ioKWfEmN@>Vl=bpE] sL1Dhz:.nqa=^xyN qL|no-ll~_f h)fvj78* 120-I(}' $09 ĊY3ڤIhvn~/e!Ցvk&wȾvCbne O|SgwE3~EFcu{ q8* ʈ@pBM vkPPnkJ# =#NYIIͶ*^Mi$a LO]:H E͓*.m KRp2T^`I?Jb.1lMe ࢎZ߅ԇ;/P߿Aȶ=NֺX ª[]lb|WcÏaRoMXҁo5oمp&u4Od-jɸ,?#sX?6Fl\,zf?zO Di|Pt"]' i<ܟ1G yG|*)RaPKʹJ$Eq1H>iPW(nZ(1E[/TNx*$1, Idr*$˷G2a:ڳ3|4K+ Ni1]N P]/B9.45kX޹C=Cf^uoQj x%nl*ʰ1S0XC=l/ D~Y~2 {֢$ˡMaUkێy! M?FzXkD~(ܖKШ 7/M۠j-\²*T*:#2%& ЖcԆ &@\rb>*XOH ߖsSm{?sײmҦ49J@dg<%E`\.+O6C tNE~] ޼U‘7W* ّvoF3UMߘLT:Ww-FcmpRm34!Ԡe}SҲW]̀XަK1_D Uz`$ lQ/Uz w2_5ǞUT>AE#H1t"Ad# |TuuD9c@$S-}[eKʢ@Cz&cL:Q;@uAc081)| VןLv;+.0e3M^^ ˭ mgb/ a1 Iv2_MMO:J倘l8Vپ7U$J/'QoOm=A8 4} " כR'z0r\}4{U s wZ5@6KFt HL_A4z4aߣF!8068՘R&zMxpx_'2/P@f6SWK=bJL.odOI`A7U.},<2"ڬDw"E=C0L{ԑX~[k5';$^ᦒ& 0v7D/Ej%#)]_'j~G߷u3HfngY-m- Kvb솭Cb8$Վ޹5o B4;_> w*zsS-"- 4;W]M .=q0~v;MZ1xpLkKi&S?OY|F~L7F84Bh-IZ*8`!tit'2` `wU֌|/@,/W ,kHə;u2!jLya߫Ȋh,W>coe2lZjWCHmT${_.mޚvBËm ~_#`ְʑC'r(Ls`z%gc@?uwnw,SB y(Uǃ`{lai+t0ގwͦ;! {~hW쪀˅]poT2'n)*2yy-u n5skNk8\`q0@ <bq5ÿr#ߎG5e o3YO ۳͘\$ڝ.l~onۛ 0i} ${:zH EJګ!rax"RΔ)P5K:9墱4ïPKQٌpBq=K8i$Jy#KuC$OF^G~@3;H"]h1阧Eڛ_2)jp߳F]EWrNR$rm!{S(|jDz (lؑ;L</<өVJwB"n|8o2 E\y>/b<#`C,FBDȽ[U%q5<쑓B2`|Bl5'6g&怃OuۮKxl'~U"?kFz)qf! m7-[?{ÞXAјd|bc>7;kG2*~rjp`CC<2P^ [7fէ-Dd`#F( l@d2˞=Si볣|G?]0IOI$K*Ovj/B;/@+Y#J=Y b2R 0)mr8u4RB:P_@VA@r%.QIPe\'ȫYFk6l=՗$W .f}]4FCPx*nx$ׯLnjrxeSe+ke5[dHoXK6ygY V !,<uGjx3@bB2ozIlnhR*&x)Ee?(n\Fx ^eA8ۄEf>9w2J낟xvJ8 { n]:Ќ_hŒCV)]bgw FcL=q؃MWPbTJ aŝt'o=!fq!+_ m.65~a%nI𹌞>X~{%IR?/۟J$|6@@6tjD7 @8sI;-*.TJ&3)*{!W֓R&(?1{\l.h 9۵e}m(ujs"B3kVd BuO*xCr(k<J'3zV0 <)t%GS6 ΩJMhgRl`xSr1 Ng)aCW1!|j۪{orTHAү'>!95zшV$߄&/oMo(+2PS<5,Pp( ˪mw6ehʧ/=pBS>C< ;C*1rw #EQ=8gے cW޳o2kG u!PHVsU"O|V9-TH)iG}McTٰ@/~t@u'5U8ZYwѯW o)7^~*ߒYON).6L|9i|1%LFV(R7 Xn2rBCg>T0h:b d~S*RJ*-?zό}[Ϥ5m=3*%.z*_Nh].ur&T&@ , :׆ uhZFb%$q3/u#|EpeRss׵!wBus䋒bEc,=?o\P?ՅR =3GpAGZ+/ET!>q~ѨD|%sg^L9ed@Ns[&%FDd/=lk%kyܡھ6p#z60 ^.*&'(NhUsbgQ]Z Ak/G\$~#gTh0" ;]L;#G0LiK֦ŷ sjb09)~VpW#B߬4ok\n&8[U+Μ"]G/(o*y'zO;Ogޮ&]>n ½S3 Ceǯ4 saq:8m:(]{q dى[-} B& C'&;=UcoFVIDk;h6GZT6][@/uٖNkW]б?63=х')((HK#/w"-"G8 Ѡ}i1 ?$Wj{ڳzN˾/ѳRfbRl/aFԲ. DS ѐbe,S:G}iK#.y rKj>%y6f&pA+ib{=0 Asq?gb\W3g7 ?c'U?#`ɹr堹@Bml͂΋}ulrOopWw i$ M ;O͖3>4H€!Y,Jxri3a @}uPR[ݢE$exwoR?VJ7xx #kEPEP+ = ٫О ?'7L{*gi$jsCLڜڐa AÎ8.i3x8SRCA ZQlx9/᭬W4ާMq` < ܺ"rM{5rb֨-;L( r_& sڸ;xb:F¬1Y$Ia{[Zkc2p= sjߥo;gwA# A1S%˩LܬV9W:&*ȹQPomT ~iW#e;,@aJB%Z&vwƄ`[Ms-8:+ń v%뇟vpKt VF{ pnV.hz-Q쪛A׬,Q!JE >o nTtjs"ĝh zK9~q&"hÃl`h\ĵHPV"phK趺\ѹe@0/ o6:>O-/lПn(yB 5_VΧiv*yfBXٛu~ Uс,"ޚ 'Qq3|zvߗq# F97VWy7J4+n&8tj ݞ0iO2v*z K!"~76dYD*0;22[zl(w` UՈC{%Gs.yCshPJ__q%(g z k!6Xh;? +nrJ)Glc?8 [/@,~3T9[Y?,aEpS=l[:M MP9z@zS#M];jN{*#1.2ZxH:I[ҟ<욼kOwu(f6nEk)Z %vors4&CF+>Z=4n{oF:Y.0WzD+ ݩڄň9k"YaYۅ03M qt04 +(/97sU^O`jK+A `r )v"7/\WD__% on̴@#ADA"62ڃ5f`H_( {&#6̟߬ u cQIS rp=mƚyGfjFkvRE}mm=bQoj6 2=L;]`ef/īPMuE! !v?:7+xT qn:>BIK/=׈uh >kpo$&+VRHeQ{_<-aI뻈*U \@s5K*c? FެGD8յ\`F+y՛[)љ 檛+y_*wzyuAxZHD])7buqڦ/qm6fsmIa#UG?\;v9y#ߠ1X.#$7/z^]TEi+aC=LR782y0L#6,Dfv}m]Wf)ȥE=#$Ţ [oLZb 8[jr>nr1b']) vqN_5׌b!y`|Odž̷V+yü8,U @rAɻDSٵ; ztKdM ͓('\E~wUٸY(H(`c<wV 3VR2pSǝn Wi8Dak竹7e\cLU+ Ec(Yƽ@1J쀒~Q5'B6)OA$re3}53l5 MhbK >Re> mF}7~\.Lj溶;1(@1L"Ygq>Wx^4뜵f8Z7(¾j|NukVG…5Hs1(I5|^i|sI_io,)\RQ i 3=96#|흛K'/)N~P%s{ރDiOTUc6IE_a΅Iyޡ!:/!|=ɴ`!R;Vhg Q~'P|[$dlb o"q1Q_u!a~Idf*T>/=H5Mi ބX#ՈIr9xoj]8<Ka1M]*'}1xV?=Z}Ԫ"1G$x¿$E 26s#5cEiԨ/5}ϣC!f"3:{_p7 , 8cKYPfИo ա#RnGV3/J YA[=vHQHYEAvm `Rڐfȕyy‚RgD2} rZ%fLju$ N^E u"Jf-#t5_`kjv I {U״#spe[WI꽕_AXǰ"a>\n[@fz%0BTX~>Y6i0ݣ8axv'*g sLS[sx IxSǔvZ{L9b@J܏uoZ[4Z@"}u@۞|(5蛟gn`%6{B$ 58X *Vꔸe 2 |.`T'ۭѿC@$;9plYKyH)\ r`7\v=(厠Ur%F=/ >5Fp\ʦkiw=zj.p~2܊!kE.U2"AkeabAneKc_;^' Fc,Ľ(aK%8KǗ+U\gw|޻,.J=E 5 l!-Z&LWq{k61ѷ'`Wۄnݓ(Ѕ><xUKWHe0$cB/X}YP|e?#1PB1 kC̿FlI~Tܱէ ]@/}`X*@0[Rdl'at,m?b7ӞȒ7a7-:f6:t=bNG* B: ʊXӚ\OČh&r5S:5WְΡM< *aG 'BtBmXFu8*V1lٕhsxQԥXbn.azp!Bs%"KR׳UZ^|a֑o&ɛB R"h%lcTY0ͿkiJN\&Gݲ_!K3_?ՏP3_:):(o"Cc(O^ZP2 tyzבvtxUݦvcf{`dm!r\ Z^8W5'| hMp|퉶cp# dBKc;.sF8 ΟqB, X-! o˒ocGBtW!O# (q{!W$nP/j]j/3dIj=Z&Qipk[ۇq1xG'BB̥i껛bCiÆ8 EutBS@> l0 9{˚>E}WzU:N-*"'HF.(>ua,':Aߦz [?t NvKm2lǭB9/<> #ܨr 83(s&Z[j^N;H /`y2U&ĉ~ 7K-G[`cGCKy.<0И?'t?.3Q$ш7#z99v1~&r u'/n%u!Ge(O4SS ӪP$7m71cAZ(ۤgZh11 ˎsQ4)CRH|gFl3 J {M2i ƣr\GfYKn^r`'pˢ3X o8Dj\]LcmA>MeV7>) 'Rӊ,m$i* *8y=?=ORz|lD$j{T[igUF+#ymlFH~vrM)/0Ĭ@)9MYĀ^Ex{('@X{>҃ebXe3RȰDX=DaizI-c\=o ^ar\rF U/~q*%K>1#j3-ĺy\okS5%J;;6_]e8?,0J B+ۧnXJ[wB*>7S(8u!*?Ꮓ~74|a(/eH[-:j {,=,S/ࠐ[oV"x*5|DR20D'/z4uBNIl&ֿ!{uz[Z4N52xpḙ(0#XPw~FnwmumfB9\~Ԣ<:m:T=ELqʯ=*܌qnNx·pfe,p:% Ȼ.rYeujF9,yyg5'Sˊ}3P A*pӳUΉa`VK"U*3fX ?͵mi VZ /|?ȴj3m45ofNՓ:9^jLw -zTy`[+쑇.0LIDhs佬5~Q2L& dm =macP\t{,( Zc h2:ā\؇2ٺ%0Y ^WH1偺M ̃dE9$}#qe)T[5}᫨l|*w/E悗\^؞ Dc 0 ve7Kc. Dϡ%WD(& vBsh@YGkUlRE:IL6dICK@q;ej_H[?j&NFSmhxVA%7%CaS(j"NtODwei_)ղX L-!W&is}#yG$#udṂ tZ86ޏ+]ԝԕKٮVEv AuNcFnXi3%vU$_ AJGCXPVV& hAKӅ4uX")U>dOV֥G嶵D c\˅E7\ct8޵4kEo M&ۖ2}m|3₡/+<*g1D廱0ݙcʩ4 P?aÜ:tqRBp < e$}wPqʝuGcC1\#Q1PUxiq,A>n>o.?Njo.wXA \vJA]iS#<#X BF. FMC|γ'iܔ7{rBt-} k`)d?dhˋ+P;aG9[3HtV*ȝI 4VsH'¥rGV-ŌhZ4@$f4e"X5~<Ϊ4uUO/"#a$*x^Fwav~9]w@e9^{`H%0O$Fq Wʋ\ T {aPVSwʉwC R<դf1׃*[{r^42Iief!SAjV6M.t ODMky#G% f1}S$1h˿¼S%U6PkHvEb44Џ9&pu\fV,+ZolcB<L3g4>bAJ~M-ݦzz\(,:Tw؄g.GAhDɿմ<=CRD =aEY_] }tAC Xe>"_`),\3X.:/K .@I uФD|]=iE3a=~J8E|eh~M\vCrpf,q @=ث E`&q3{^}dTgj5(3(%Z-n }+ 6!Й?chHƄ\橖0N6nACFwAnH1:WӜ-JP`!B(,pO)N+σA[].A[IFni/,p];`Q8J'Z;bϗN%ҽT\',bwvf(3nc1P[F^u;8zP/fKѫ4 m;>ÀT*4{]"!ߣ %~1"o~xBsyJ&8 j㗊 κnOJǭ]ɇ@4Gd9ϮMt}01[=c".&KG.y]~n0Q "M? #=AC9ր:>Ok}uB] =wO[LL^w Gqn{~1E4[ۥ'tt^`wF{bfxJC͔y +?,e=g?--H CqCcoH?zpt?"IцzI&QƊb:嫵j\ _Od*^2 lW%s4uJ3aS M-3/giZ|iT|B춉 Jd0h=:6Y̅n%R˗[yJut՟E #j>n_j[Z\Nh,} {K쳼*KK7ƾ(x"Lvfm) YNQձ<:n)(v "f ~iEpU¥ )1G:l`*IcbmQЇz %=U._C1$_55*)<j`gS"X,A".:'[J3Us7 9{ː2E2@&F0P]3u JZ9N>h{%biCFVgʳk5zUi$;ZBELC`2Z>H{T9nVOmyz`f5D6s[qĈ0f]^-t,$`~^7ڽa$&R3͋ 0*զF !UybJ?)J 0O ͳ'crbJV%u /+Â};  JLc b&{{vV=Mv=[.?drBVsx|mc+tsYE˙g OPL h  uvΆqWVהs#/)w_UR^(hZkȕ~[ 8]כiCN<'6%%xC>NWpʕSG!̦+lܔW;K VgusTQ(+CN$96Vv>&iĆ{߭Ux`u0g٧ ɆȂ۴rԘ1N i9ͅ=r{ @Ƿ0xMYj4YډR[ee _ Ystp^% c* _oG3׽T⤐$kEa" h;Te1غ3b3]@m"DP^% uۊź%Wu@R)FЦ J).U_jgcX)с?Cvq*ngy8`-__# '){cfy#JPPdI+ WŎ8u}R©:uֲ[Qoɞ.lrX}7$3=dCn`߃ ^ \f?mBL]Au AarU-߹D=9_)=)Ur(<Kգd'<)Єu̓*w~QVjZ(pS;<[w>[-o-(J\A{ү93F{U@6o/o:^Ni:D:nKqFtNo+ ?,QT. epsT5v32UQ;m 4Oe€sM[:]<1k^!cU `"%%S}d]+Q\ɦ{Mvͷv%am*k秛 b[(&Sh6xFUAAGzF_)r[AFf)ï|]jUqi+yyyHd؂#=VhSZ`"ө3OK}ŝ 3]^4̀iֈ~ܨjp,tZ-5'oIJS&lʮ/ЕM݇<8ur K)U=Z )v_V>f)=Fj20{r?_Pzn62)% "'&I% nХ(<aLkP+??8X#5A` E}Jاe* kE7W)UՁ6nq\E7uR愩Frkڏwe֔{-ehԏlޥLIk;S"R +Vo\NG˜H(EgP$3ǕtB|bEmZ1UniF){|1caBrA3 !*O /HnM  Tn]ҐQM-Op&s0m ) ?%2c/s*W8`/cR'0R #wIϚ@-y!:RrF\ӫq8.$A?S+A ߦX aG77|miPy ƕ4"pf-@y-Id`p}{a ΩZ>I#DatQH烓)s_/‚$=] &^f*5_Kzg3BgLC[ʣYv1du0?4v5FDA/ArAŕcN=9== 6GPgo~ݓI~pƒr1rJVJ)l0`&l69Lo9a3X떣9'FtO,#ZI=ןg-YN(Ūρ,SހI@X7 SM֚(?ͥ1>]@6T)Z7 Dq7&mh|\/3}$غei3:/   _nV=Vg9`E[QۺM[R-h F{=T-J2yWX{h 3٬O4Aos2 uK{RgºQA`vDYD%S1AEtnan%MD?T{u 9*[@^0Y/Za]Īg5U*0` >!'1D %5Ê( .y )H T3OFLy뱊.[&H`<9UO=A-uҸL`n>a n{ЅX/E+3S9o{ 0! 8I QAS;'x-,H`KAww <7ײP2l8E}o7G 兰5k"og-5J#;OPyЊ X}cɐcoB˦s*K$ѭV j_-~W)bK}du~X̴\4ڪ]Tſǭݕ?1ax*A*Q.y+,;"@Q@qY2YfZLKF2LiߏQYfZN·|*dԟ%L\6Ve;ܐE37%M&šYp>ieAkrv jv xPPG?y]5'|L-11.8 G<Ax)[߿uk`(ptv(""%m%T3)I~cVuY42{KU|xO;;&c-]p~p$bA\ L\2Rw 䐡Ѿ0GA=|ǵ1oxy9KNokfAWِDr gF`=.NV=Ol]Hcn.(CO/;JBčuy\0,9I{-'*OYB-LEk68K#Z/cI{uo6`* ǩtMGq%9s}7Phk<NJ׸I2H/][WX^2:pe7 ;ǎcIVI)uE P >7 H6! um*c^&ɓ ;1z1/}3pLI@mjg{-$Ec&i De+*g#^=;Eo[}X=+:Jr,U5K?"55GI#g̉7zҷ˷fɰ򮱉g˹ tU.0B#RDvn'b7U vr 77/7YrU8/iWs]؀YKT̉ ” 庪JsMBЈI#`[0Hu%M&bV_-ҡ`ˉ@ X1fBՏ ('>BmNk YBOWhFɹssU51{;V"HS@ bיg'S_k$nQYHO3AT(Ku MSrN~_14LӚ=7(0^s:rxnEwQ9X-T:ŘlmkJ8)e b9QIaz<\5V2vC/CsrCɈYY9ˀBgJ.2A$D"A?-qCSkTy Dg)ѪkZE& Ӱᦐ& %05Bp0en+~طauc89cwc8|]lKt[zU" SS4s|5exԾ=Ӹ5IPcG z!WNr Fְ7L,62x9pX" +I#DSlp%l"+ v<5>(Wtp 7<ܫ%Qq˻cis0fHIF-lYx?;o|QH&CqmucŁ0?rWm; *4iK&w@W:U屵8tm#ELV%\X_J } AG0f0!3B ݘ0>4JR82n'mQ>&- Y]ǒ:-w;V `cGуSHfe󿼌\!'or*7_OMYo6R9]z>itސ2TQe˘M}BlPr( =s+(gv bq3Aa- ڳa 6[aiƓ횶 56bfV) }J]Q|MϸvNg$:ɷ()>˸ڑn']8,L޼o>N}C HC fL$orF"3̨PX4M?jߛKЕ{%˙Ae]5rPYouXy͙rFuu'ӻyT^ eX TBMI'Xw,9 %r?NwnE uٯ;kkFӅDž:}(}d{cܧxb}h%FƴNڮEnyA76dKa]y%س'p-͒(Sp 'F$qޥ0stvm]8kςR l'2k`vD-rpxwzII՞(!HUg:T ?N4TjLf~P*iU Vdb buo5uwus^>H>_ymdKYv5Q( 7-ބyJ\H6*qhb8qE"Sd`fzPƈ!Q;1w  `H]']{:j&'_{",=*簣C m^4ң&=mqoѥr W,c-$EU[Dž=mk5ۤv]ENY#2e+tP(9,BkRE5+!BbOve3EQ'#>!( 6ehsb.r-/Lu)LUC0lMQ aFzos#9 R8q#H<qV!^d^uO.ǺE5s"l;eAsVVj* 4' ;A4ՙٛuK TBD/A*{d*84l$+8RLN;T1?3q{45O v(;GWO67GOlޤW &)ji#дuyWd!A4o"TѺps Nt0g` da MG靶x,_cgQjmC> *ОIa%OghKzYSCF7(4n87vhEʻH (m񎒚H丅kTF5- %&2^xNPbu<$"1.poK9/)1-2$oړCwaLt֑TEs;BJ%tFy$,."=ORVXxFMb;76FcS|X\"$EpKSpٜ*&ҏAX ,C,wʷqݐ&iC 3fd/Nll\O^Gq#P`w\@ l~3+"ݴr?x9?+Z)DqoV:l{}*@/ 1Pԗ/k=:&O﹩'Y.d7ϝs2 |?c?@/jV=N3P Q8׺ P4]Rf'3m鑾wgjY@CQB|UkvAyO#v_dbE5ޚzkV^h(FEdKĺ zQwqxܻ} \' /LՕnz.ް*`z+P \CclI9LwXƱ^ dwٍmE3S79aRHxԘ$XWOWx,s7m juJdy&L=6T{y%}Z)ZAI"qN>oO>I!-+11Ή*)~E^!@12фE@AܺNQ 'x0#%dLDǍR@B+ULZԆo p]PEDdV`<@(<ֻ0Sn *m75p0#jh113%4 UiFuKt_XׇYiWqB#i:>md ipz702萚)bK)ekXA@(M_([]ob܂Z pa:/ݨS0]S 0=TwR'Bc٤Dl'Qj@ֻ8{F*h a:!O8&~6 N8 n\S4,_b}! v|U*Lj,E;-lF@+;Ok"NZS Xp80r97ٛ 59kt&F{`⟫٪Ы ;)ulN P#4dԌpDTތ&'+_"nulvluvVjcurQ͆@ '馐|0W+ .;36$软KTIUio:g)E v A/Yk/6L( NKj6ggؠ3M=c=۷%A0Dݑ!J-n?Gn 09Ae a*7ҭ(9WΟG^[1"|^WC\.Z{:u8-> 7Gl p ̓ {R: Ffkhn}N3`"W_.+wz#_czM*%'{P\muOM$*cKq}ΉF^VΝޅ>q!߶Y6k S`#ꭓ@d [N?yijTEAr&^8u~U#!ZGW<}!^}wtdR*-. _fh+J|`i 1p*(:d#'X#~=^J7U5ƕD JfCSUd1#է7hQ)zHpD"$Bt`Ee3fs{lQnnR'՛ ʅG'?AEv# ]qVV?_ ׉eNOD6B'*;vx& ^OD,{UKsYm[DI|A.E8}:=pŴDo}EZM(W̶yz.11  ><7h4[K8(ٷ.0Ȭ&kݧē"kE׋8됄I`/H"ѡ\?xo؇q&[|,o vQ Qg7|(!Zl@iph3r& 1UEЃ迋5{V->KKFja̟}gmDQOPb+ؐ&Qg%cmjٔYԜ.QM' d }LV;oEc#w_2pLPS3rt7xpDL]Lx٦К7 SwcLg<ܚoįĀdDFZlٷ4ev2̔Zqbދ{@r{l\ρl/j(WE٩k"cMMs,D DrDo+qTLED}Boe̙r``M훱1\Mo𚿎P팳9n@B) 8C NAEBZ )s!Y"Ŗ| Cv`I3v o0$!p4>G"woGo#wjU *#^S fXtZWX@4.PhO ~.u` R9?["է3fٵ'"/\Χ%F^bnwry×I7z[(p+q4g6%uT~}&'ÿNmrϐäxo#0#7 QK:u%B#i U Ĥk8d=GgXA>I-7O4sy5Y6vkeGӀ}Z"zvp3>]V.BfX0@\'lk]J:K"ӳkrpC l7#cB.»vlwb|YR5_n'/@wꁺj ƃsm:v5KUũ;˖ӹ)gk:km,MݳT*8zXЯu},*|l: RȤ0'S/9?ڠD78Q.g;HB s}g‰i2,2 WNfrb>F)θ rN#Ճ$NAˣFE(qX>iݴnP絚OcG@4E WQ-9HRBOeMkAO k6X4@[[ c »K048Uw{Z Q?ţ?bJ|-~y} [W10614dH7Ԋi~aE%Z4ͳ ԃfL C7IIlWU Ld͊: yTC,\I4Mǰ|ꈸ`>6sr 4\RDx_%$ۇBTuK7Gm@6*'QjILP,4/zi ?昢;ZMeo)6>s)SkH񜠼0ޅa#35:4*0:w ?a,N^%DMQ$NE${ (L q:CY[W~U]nQw1HB(]9v 1|0vCA:S!@rXszytf$ώP(`*mHpw5ۭeT!tӛu=#?ٳ?"`o pnn{/N&g wpn~0YV9iĩ%C ݒ B 1/lF`nW^,$ (*{wJwJC_x_JA}oN3^E[EN`Q: ܏ЍaZ˿nD^4c^FWu D\pvBJVj ל  ϊ鼥ԋYUtNw]eA.| K?.r籈UGIei܏E%m߲vިwi=%rGڻPյud ],k5_nC#c\Q38 "|VsI%'5<-#tC0n3S][ߨbm@. a<h^#:7ܶ1m~Tp} F.66biY/;eUO|1X0uQ hB-}S&0T3XcqJPomrh.Jy nqqb50 m4VIwTrIIu)Rdؘ<<7GB^W5yY)F+eBs5lu>{ě墜Ēn]AA[Nr=F/Bl}pG zQ?V/ NXa=U~̡ҁWi4A/\$Shb3jL DI`԰&Qt%O}=\|qq]饳t)N3.J]`U׍ݎ*zݦ<. SD>S]_61U$||Ȣ}8+IyE&3%={6eNGop=P6#JmD^Z[JgG] Q~r+ځYb.Į,6^cwXH.Cy˛]PS.y2X!*0yh+bTڨ#w;D ?K搀~l!BUϹ bo]ts/!_ FK 2 A=0{~Ĕ~$¹cx)ʉ)lPq:`|orf@סt\g0Z=Rw&նCqޭeDr!idBL ~/GK*f̼7Gcb_6k u' [Q} N>[D&4rJzJ֣)15`U_lBOr!knln]dɡr$I]D5} (S C|҆nmm0mjA{OD=EM 6;w70e;vC.#\&`1w) k%BP-9Dm2w Iݗ4)4hmZS L4G;uwY)T%FjGb)gŘ6MяȒN# &,L} -e:cytK+3 JoC矖X5s_ؠkǔgQ$ 'E68s@b8k-yP(i%b7j{&f$uMۢBxBY6\cbGx[o!ë Zg>9ۏP\FMm 7rJ&۱kgo '@n{+mB|kv^|Oi„kTQɌ }\DXoNGN|A<,Us$,|>=!+oIdC6"`) z\7*Y4GE,+0aE¨oAp{Zg:d"x_u tCO #SpL{Ҧ^~z< Y}Q]Nzz)^}~L. f 8@j׿i^ѳ޿/udUFz"q] LbW7"\2*9ZvDZ=P=FVePD!!EO)t{#Jtohvs [Td2CK/oq`ôx>=-~|2 ";UP>kD̦m4̼S0[( :~٦%qpjU!`&eX"}[1Za֕.O)Bm$'J#)POpn%Wo)0"TEsįizyYU lt 7wJ˂ *i46~N„w"p8o߼S'F2/KtoqNy87" ϔ4Lؤ\~D SzNw?^hqL#_ΦZD5H=Mn/9zpNrصǧl$9i #ak0F2 j:=,k#4u [b>td>~F/L,JDmʥew7/)"SZYE6[|3*Y^G-K^CO:^ʝF{GC.nɨUcՀm %"G'j}G+ ϘK =zop.~&;KGLdq} Mz5eyED$?{4q7L_ ,ӨҊѻT +֏HPIUV`\ыP[^(ԵNx^HZ;^ oeODhҤl5.Ξz^9s0 66] D4ݎdK;u#ο\"@EK$ͳW 5[#V/q ꆂ&_ѿ=UCߏ-k 3BDJ. \:H)eƘ-͘W 4&&}_cS ^tUٜ*L]jZTEgu[O14fOtLRv \NYq8rgQLdN_4}ûN]9 Q,yMqޛBhi`hYWCa6 NOw i./Ry4 RT}#xaI'C/WsB_%1;LS'2Xt=V?廤F \oF03~~_WwV{eNC7Cc+t!rKISH^~^L;*j_+Ev4 E^!tVӱMcNoq聞N.f.4>~Fo;,Z4xh2!fQS 4ݟ}!cN1* ft͵^LXO,*eG,@ɱ&P/!^keO9s*ܥun/,$r6N!$n0slX`~۟ͤ9 _r fe_t(V!?,v^(t)@00$? {ݧOLR"X;C"z0F<3N#juUx7z4Q3THԼ|%y?+z]?9+‚.d(ۅ;J^+9]a0.H$73Ton5uk7Bb eJܗp,Њ~;(ʀ.3#+>b1!CTUlj~( ȫd}y". B17SUd"᨞V)Q! G]&X@j;,D?Z:,!brXǡ8 <{mXmx]feY&N#\'X-_kn;(6>pԒe _2?FaZ 4(_ p&vJ5vlh p}r= `ev{`5˅Tu u[<9ehi6`u`%ц&>pֆpɬnƒxNf.ʿ1AsW4hдfʀfǷ"r1=A睒 <)AY2-iU@"(E:_aeo-Tr9>ج1;.dFO5lP,֝mp>EXT{7/[#|ga f5 *q]WR-\ yiE>&`S\Qdi(YOO@kQC`ei><} o;xqISy>[n_习,TG1l>~LX6V5^C[+PMy⢚S˯*+[=WF22"Ț+[:2_57h˿$ joCk{TO`1w@S &"=Gl|t~"R^P1k٩`B۽NXfIuaWS p{&K(ٮ4~v U']>!/@egÌ%!(HV !ffw`Q4rqE#c#Wk(/ڂF:ڷK!IŠdmKC!xq sMW8D4jЀz@Υ D]eG@B& = B4ܳ|I[TQ?iZV# n^1|2="b˜ A ׉ѫԽU<} 9VPLz\ROQwDH!哮9#2Jfv_뽟R7Nq3+$VaE‡M~eu >Xtc>Xdy2wSuCyg%UWOآfթvzӕO')yu n(myh̦(|gpM6 fV7vd#n /~*x0Zx%8rBad'\pCoSL\g.\p&b2J uEvY&؜Vzhְo{.Y.ߢbY^*n\Md7c[94kga