samba-libs-32bit-4.6.16+git.166.8fb11cda200-30.1<>,U] Y/=„tGMaS\ +ڪG^RhFEس 6y E!G[o BY{-:b?o«SDp11JI5:n?nd. 3 C *Jagn__ _ x_ _ _ T____0=L Ax i8 (jV8j`9uD:>G_H_I_XY\_]D_^ b c dAeFfKlMu`_v^wD_xFl_yG Csamba-libs-32bit4.6.16+git.166.8fb11cda20030.1Samba librariesThe samba-libs package contains the libraries needed by programs that link against the SMB, RPC and other protocols provided by the Samba suite.] Ylamb28ȫlopenSUSE Leap 42.3openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgDevelopment/Libraries/C and C++https://www.samba.org/linuxx86_64/sbin/ldconfig%tE|eXUtE|ep%|żuu|tUxEt%textU%txx'<uep%xDx5xE|txLDeEx5t%|59%xeF%tVh%|tExxt5xuU|7/%xHH|L%D%|%txUUxExH5t55x884%8AA] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X] X61d1b12bd8738fff5e90ca89f24670ce607e7c1ec24d7a5488d67ee84dfed125e2a37051daf2a221af5eb5f3689559d310269e3ead29e4e0a797429075d88270fa06fe692d2979d98cc84863e710ab976e9edb532399dd66f0ae1c659b0499a2b35894941eb2cd8f166f8a8a5acba2cb955556f0c23cd0a607b613cd574ec5fd949363aaff9d551e830721bcb4eff8ffaa8003b670bb4a2ab00e664d49993a77490b7e3c4ca209edc6ed11c046d82a3afa0ceed90f0e959e1d2804fbf607475bc68951742643897c07e7cee3285c38a2078f03ffef6ea4eca115dce00fdfcacec9f875c5cc4ee904f88ac9a976b149edbe655fd6968659c7450838ef6490a48a4140f794ab6c278869786f6eaf6cdb0159aa5d2976661f0f41f2ed2296b78a91aea6df18d650b357b89234f3586ef733cdf0b43c7e6be8e63508d8ba2ff063a51c8cd13a0bcaf33797ac539181b4cd7a9633dc55f020df41da48bc58bd1eab10d493793bce642ca48504c6322fdf482827130d89ee8e6453fe4be6b57464f74707eee792509e4ee15171eae154bb276f00a6e912f7897ede52ae8a9a1856f124d2fc1bb9d04c94b6ecedc5712d4599e27cab6a3c9723e63fb88062667db8d6ea928c6d299d2df08556e10b7715cd96ba31e723e2ef536ed1c3e9d1fb704b784f8974baef9a69b96fe163a9fca8317194ae806869dbd7ec9eda144b3cb1aa4636679ab1811e82c91bd2349cf8d6c3936e197f5b899778dc39ae44ef3dbe64e28f51c52054ad11e15665686c6e3a23009b06ec7a2cdaaef1973757f7bbdba0a0eaf7c52cc00d9200f0ede97a089086309c19ed8c8425ac7b4b25db27f9afeb58a8d673cc84c41cd29b057356fd75cbb432f5cf3656b7ea0b8c2cbb30396be23eb7351fbc327085059e32b4a9ecc3727771695ee0d1d4268e7e3e638677e1bcd416a3f5a3e8ae9cf57eb55162f51464dd6953422b4fa110149059bb14eed49abc3863cddc08fdd7f353fcd8bc5e162aca0a43563b58029d13a8e12e361e8207ad3e37e6a76f5f8b5515561a84dafb787b8d582050c234b2cf5a2073285ed79178e0f8818e26fc1a39f214c76343dab63e33dd146481f0f4a818db99a320bbe03d8292d49a4030741fc63e964788f634f6b90477fb056f4fde3357eb1f3a8fadff204556a34d7b0f1a7f5824d2c451b07c621d7ba19ba0aeaec39757bc3c77297a223be65ff25195d4ccbad825f319452c5e003f02216ae4ef735b8914ab6e4fe0aa7748699f90c02c31967dbe8bdd00a652f2d1ef7e46c0a0de8e25ba97e245ed3702012174b3c24f0974ec3fe9354cb9bc2948c19ab790889f87af104f4c07389746387120c83f7a726ecc3dd83b2cd668e9b1e10b6de640b3f5a4ab62ecc5a71fe8a63cac1032793d5df4e2f83d2f8167daa10b073fc668db40dbaa39d69b48c162da9a461c900f345b7d2399cd423f54f2ba520de82402ec23dc121ab45c7cc93cae010ee960631b64f8364f21446debf96bf66471dd6549f4095f5fefc70b38272e7210613cb36d1e44de4e70f2c18fa4e8e281c967788ec9763c41bc88ffec4957c18a2f8951d8b24d952a771aabed0dcc40a105fc3e9f08b7c53c6804935223dfad12fd0c917dff39cd6fb02df7e0338d0ee64b45f4711f185116873717560c3c99b580cee4406202d4ff91d99a9f58f4f497d2f7b7ba963cc9f254aed2a15d42afdf05237bf4556b74f3dd1a03e175bd545757a2b70b232f012330cd574af13d9267f230e152bd4e30bcac0dd5cc62c7ea673e99a83462e2bfd4a3528ea45e32f175b9ea8d7a120cb726be0545bc623471f343dd4230252c3f0b365b86a4255d26c4085170c750eb1c8ceb8e401965351da57ce87906e8190c374f85d758352c72abd74c01f42a0975573ad11acdb4d9749444a9684d82187f806f1aaed67922d07eb39cf4f91589f7a9b64b8101125cff934a04034223baa75b46f2a8b672f59ef39b091e996e8a027acd4432940b3d6940c075a359dbdeb96677683e03c32819a3e6be9b93b6971b347c3c469b4edbd79d8c09202958204bd77675078d5d0f99468e3890a0a123a5cfb1957aaarootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsamba-4.6.16+git.166.8fb11cda200-30.1.src.rpmldapsam.solibCHARSET3-samba4.solibCHARSET3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libLIBWBCLIENT-OLD-samba4.solibLIBWBCLIENT-OLD-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libMESSAGING-samba4.solibMESSAGING-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libaddns-samba4.solibaddns-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libads-samba4.solibads-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libasn1util-samba4.solibasn1util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libauth-sam-reply-samba4.solibauth-sam-reply-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libauth-samba4.solibauth-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libauth-unix-token-samba4.solibauth-unix-token-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libauth4-samba4.solibauth4-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libauthkrb5-samba4.solibauthkrb5-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-cldap-samba4.solibcli-cldap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-ldap-common-samba4.solibcli-ldap-common-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-ldap-samba4.solibcli-ldap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-nbt-samba4.solibcli-nbt-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-smb-common-samba4.solibcli-smb-common-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-spoolss-samba4.solibcli-spoolss-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcliauth-samba4.solibcliauth-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcluster-samba4.solibcluster-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcmdline-credentials-samba4.solibcmdline-credentials-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libdbwrap-samba4.solibdbwrap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libdcerpc-samba-samba4.solibdcerpc-samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libdcerpc-samba4.solibdcerpc-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libdsdb-garbage-collect-tombstones-samba4.solibdsdb-garbage-collect-tombstones-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libdsdb-module-samba4.solibdsdb-module-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libevents-samba4.solibevents-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libflag-mapping-samba4.solibflag-mapping-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libgenrand-samba4.solibgenrand-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libgensec-samba4.solibgensec-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libgpo-samba4.solibgpo-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libgse-samba4.solibgse-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libhttp-samba4.solibhttp-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libidmap-samba4.solibidmap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libinterfaces-samba4.solibinterfaces-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libiov-buf-samba4.solibiov-buf-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libkrb5samba-samba4.solibkrb5samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libldbsamba-samba4.solibldbsamba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)liblibcli-lsa3-samba4.soliblibcli-lsa3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)liblibcli-netlogon3-samba4.soliblibcli-netlogon3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)liblibsmb-samba4.soliblibsmb-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libmessages-dgm-samba4.solibmessages-dgm-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libmessages-util-samba4.solibmessages-util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libmsghdr-samba4.solibmsghdr-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libmsrpc3-samba4.solibmsrpc3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libndr-samba-samba4.solibndr-samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libndr-samba4.solibndr-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libnet-keytab-samba4.solibnet-keytab-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libnetif-samba4.solibnetif-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libnon-posix-acls-samba4.solibnon-posix-acls-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libnpa-tstream-samba4.solibnpa-tstream-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libnss-info-samba4.solibnss-info-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libpopt-samba3-samba4.solibpopt-samba3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libposix-eadb-samba4.solibposix-eadb-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libprinting-migrate-samba4.solibprinting-migrate-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libregistry-samba4.solibregistry-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libreplace-samba4.solibreplace-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-cluster-support-samba4.solibsamba-cluster-support-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-debug-samba4.solibsamba-debug-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-modules-samba4.solibsamba-modules-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-net-samba4.solibsamba-net-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-python-samba4.solibsamba-python-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-security-samba4.solibsamba-security-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-sockets-samba4.solibsamba-sockets-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba3-util-samba4.solibsamba3-util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamdb-common-samba4.solibsamdb-common-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsecrets3-samba4.solibsecrets3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libserver-id-db-samba4.solibserver-id-db-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libserver-role-samba4.solibserver-role-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libshares-samba4.solibshares-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmb-transport-samba4.solibsmb-transport-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbclient-raw-samba4.solibsmbclient-raw-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbd-base-samba4.solibsmbd-base-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbd-conn-samba4.solibsmbd-conn-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbd-shim-samba4.solibsmbd-shim-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbldaphelper-samba4.solibsmbldaphelper-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbpasswdparser-samba4.solibsmbpasswdparser-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsocket-blocking-samba4.solibsocket-blocking-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsys-rw-samba4.solibsys-rw-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libtalloc-report-samba4.solibtalloc-report-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libtdb-wrap-samba4.solibtdb-wrap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libtime-basic-samba4.solibtime-basic-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libtorture-samba4.solibtorture-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libtrusts-util-samba4.solibtrusts-util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libutil-cmdline-samba4.solibutil-cmdline-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libutil-reg-samba4.solibutil-reg-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libutil-setid-samba4.solibutil-setid-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libutil-tdb-samba4.solibutil-tdb-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libwinbind-client-samba4.solibwinbind-client-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libxattr-tdb-samba4.solibxattr-tdb-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)samba-libs-32bitsamba-libs-32bit(x86-32)smbpasswd.sotdbsam.sowbc_sam.so@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   /bin/shlibCHARSET3-samba4.solibCHARSET3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libLIBWBCLIENT-OLD-samba4.solibLIBWBCLIENT-OLD-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libMESSAGING-samba4.solibMESSAGING-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libacl.so.1libacl.so.1(ACL_1.0)libaddns-samba4.solibaddns-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libads-samba4.solibads-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libasn1util-samba4.solibasn1util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libattr.so.1libattr.so.1(ATTR_1.0)libauth-sam-reply-samba4.solibauth-sam-reply-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libauth-samba4.solibauth-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libauth-unix-token-samba4.solibauth-unix-token-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libauthkrb5-samba4.solibauthkrb5-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libavahi-client.so.3libavahi-common.so.3libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.2.1)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.2)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libc.so.6(GLIBC_2.8)libcli-cldap-samba4.solibcli-cldap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-ldap-common-samba4.solibcli-ldap-common-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-ldap-samba4.solibcli-ldap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-nbt-samba4.solibcli-nbt-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-smb-common-samba4.solibcli-smb-common-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcli-spoolss-samba4.solibcli-spoolss-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcliauth-samba4.solibcliauth-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libcom_err.so.2libcups.so.2libdbwrap-samba4.solibdbwrap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libdcerpc-binding.so.0libdcerpc-binding.so.0(DCERPC_BINDING_0.0.1)libdcerpc-samba-samba4.solibdcerpc-samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libdcerpc-samba4.solibdcerpc-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libdcerpc.so.0libdcerpc.so.0(DCERPC_0.0.1)libdl.so.2libdl.so.2(GLIBC_2.0)libdl.so.2(GLIBC_2.1)libevents-samba4.solibevents-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libfam.so.0libflag-mapping-samba4.solibflag-mapping-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libgenrand-samba4.solibgenrand-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libgensec-samba4.solibgensec-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libgse-samba4.solibgse-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libgssapi_krb5.so.2libgssapi_krb5.so.2(gssapi_krb5_2_MIT)libinterfaces-samba4.solibinterfaces-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libiov-buf-samba4.solibiov-buf-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libk5crypto.so.3libk5crypto.so.3(k5crypto_3_MIT)libkrb5.so.3libkrb5.so.3(krb5_3_MIT)libkrb5samba-samba4.solibkrb5samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libldb.so.1(LDB_0.9.12)libldb.so.1(LDB_0.9.15)libldb.so.1(LDB_0.9.19)libldb.so.1(LDB_0.9.23)libldb.so.1(LDB_0.9.24)libldb.so.1(LDB_1.1.1)libldb.so.1(LDB_1.1.19)libldbsamba-samba4.solibldbsamba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)liblibcli-lsa3-samba4.soliblibcli-lsa3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)liblibcli-netlogon3-samba4.soliblibcli-netlogon3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)liblibsmb-samba4.soliblibsmb-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libmessages-dgm-samba4.solibmessages-dgm-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libmessages-util-samba4.solibmessages-util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libmsghdr-samba4.solibmsghdr-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libmsrpc3-samba4.solibmsrpc3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libndr-krb5pac.so.0libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)libndr-nbt.so.0libndr-nbt.so.0(NDR_NBT_0.0.1)libndr-samba-samba4.solibndr-samba-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libndr-samba4.solibndr-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libndr-standard.so.0libndr-standard.so.0(NDR_STANDARD_0.0.1)libndr.so.0libndr.so.0(NDR_0.0.1)libndr.so.0(NDR_0.0.4)libndr.so.0(NDR_0.0.5)libndr.so.0(NDR_0.0.6)libndr.so.0(NDR_0.0.7)libndr.so.0(NDR_0.0.8)libnetapi.so.0libnetapi.so.0(NETAPI_0)libnetif-samba4.solibnetif-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libnpa-tstream-samba4.solibnpa-tstream-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libnsl.so.1libnsl.so.1(GLIBC_2.0)libpam.so.0libpam.so.0(LIBPAM_1.0)libpopt.so.0libpopt.so.0(LIBPOPT_0)libprinting-migrate-samba4.solibprinting-migrate-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.1)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libpthread.so.0(GLIBC_2.3.2)libpytalloc-util.so.2libpytalloc-util.so.2(PYTALLOC_UTIL_2.0.6)libpytalloc-util.so.2(PYTALLOC_UTIL_2.1.6)libpytalloc-util.so.2(PYTALLOC_UTIL_2.1.9)libpython2.7.so.1.0libreplace-samba4.solibreplace-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libresolv.so.2libresolv.so.2(GLIBC_2.2)librt.so.1librt.so.1(GLIBC_2.2)libsamba-cluster-support-samba4.solibsamba-cluster-support-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-credentials.so.0libsamba-credentials.so.0(SAMBA_CREDENTIALS_0.0.1)libsamba-debug-samba4.solibsamba-debug-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-errors.so.1libsamba-errors.so.1(SAMBA_ERRORS_1)libsamba-hostconfig.so.0libsamba-hostconfig.so.0(SAMBA_HOSTCONFIG_0.0.1)libsamba-modules-samba4.solibsamba-modules-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-passdb.so.0libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)libsamba-python-samba4.solibsamba-python-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-security-samba4.solibsamba-security-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-sockets-samba4.solibsamba-sockets-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamba-util.so.0libsamba-util.so.0(SAMBA_UTIL_0.0.1)libsamba3-util-samba4.solibsamba3-util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamdb-common-samba4.solibsamdb-common-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsamdb.so.0libsamdb.so.0(SAMDB_0.0.1)libsecrets3-samba4.solibsecrets3-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libserver-id-db-samba4.solibserver-id-db-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libserver-role-samba4.solibserver-role-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmb-transport-samba4.solibsmb-transport-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbconf.so.0libsmbconf.so.0(SMBCONF_0)libsmbd-base-samba4.solibsmbd-base-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbd-conn-samba4.solibsmbd-conn-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbd-shim-samba4.solibsmbd-shim-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbldap.so.0libsmbldap.so.0(SMBLDAP_0)libsmbldaphelper-samba4.solibsmbldaphelper-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsmbpasswdparser-samba4.solibsmbpasswdparser-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsocket-blocking-samba4.solibsocket-blocking-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsys-rw-samba4.solibsys-rw-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libsystemd-journal.so.0libsystemd-journal.so.0(LIBSYSTEMD_JOURNAL_183)libtalloc-report-samba4.solibtalloc-report-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtalloc.so.2(TALLOC_2.1.0)libtdb-wrap-samba4.solibtdb-wrap-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libtdb.so.1libtdb.so.1(TDB_1.2.1)libtdb.so.1(TDB_1.2.2)libtdb.so.1(TDB_1.2.5)libtdb.so.1(TDB_1.3.0)libtdb.so.1(TDB_1.3.11)libtevent-util.so.0libtevent-util.so.0(TEVENT_UTIL_0.0.1)libtevent.so.0libtevent.so.0(TEVENT_0.9.12)libtevent.so.0(TEVENT_0.9.13)libtevent.so.0(TEVENT_0.9.14)libtevent.so.0(TEVENT_0.9.16)libtevent.so.0(TEVENT_0.9.20)libtevent.so.0(TEVENT_0.9.21)libtevent.so.0(TEVENT_0.9.30)libtevent.so.0(TEVENT_0.9.31)libtevent.so.0(TEVENT_0.9.9)libtime-basic-samba4.solibtime-basic-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libtrusts-util-samba4.solibtrusts-util-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libutil-cmdline-samba4.solibutil-cmdline-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libutil-reg-samba4.solibutil-reg-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libutil-setid-samba4.solibutil-setid-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libutil-tdb-samba4.solibutil-tdb-samba4.so(SAMBA_4.6.16_GIT.166.8FB11CDA20030.1_SUSE_SLE_12_I386)libwbclient.so.0libwbclient.so.0(WBCLIENT_0.13)libwbclient.so.0(WBCLIENT_0.9)libz.so.1rpmlib(CompressedFileNames)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsLzma)3.0.4-14.0-14.4.6-14.11.2\ڭ\\ \N\}@\\\X)@\@[%@[F[z@[a[WZ@ZZZYY@Yo@Yo@Yo@Y3YYu@Yg`Yf@Y7Y7Y, @Y"X:@X:@XXsX@X9@X@X@Xg@X,XƉX@XYXe@XX@X@X@XWXAb@X-W Wv@W$W;Wu@W#WW W@W~D@Wj}W_WYZ@WYZ@W=W(W!@WW@V3V3VV'@VՄ@VՄ@VVIV@V`Vl@V@V@V<@V<@V@VjV]VI@VG"@VG"@VG"@VG"@V(V'~@V V7@VBUYU@U@UUAUĝU@UU@Uy@UUrUq@UhTU_@USaT5'@T5'@T3T12T->@T->@T%U@T$T!`T!`T@T@TSS<@SS@S@Sہ@Sہ@Sہ@S@S;@S.S@SSSS@S@SS8@S}SxSg}@ScSZN@SXSO@SM@SM@SG@SG@SG@SG@S:@S:@S5d@S2@S,)S L@SSSS@S@S(S @S S 4@S?S?S?SK@R@Rb@R@RRR@R@RRRRRURURURRR&R@RR=R=RʚRʚRʚRʚRʚRʚRSRR@RjRjRv@RG@RG@RRRRR RiRu@RpRW@RUE@RUE@REs@R:@R6R4OR2@R(r@R%@R!R7R@R@QQQ@QQQQޞ@Qޞ@Qޞ@Qֵ@QQo@QzQQɆ@Q@Q(@Q@Qzl@QdQAQ,Q+R@Q@QQQ@Q@QEQ@Q \Q \PP-P-P9@PPDP[P@PѬ@P @P @PPP}@P+P@PP@PBPBPPP@P@P*P6@Pd@PoPoPoPoP{@Pb@Pb@PWPWPQP,PPP H@P H@PP@OjOjOORORO Ọ@OȮOȮO]@O]@O OE@O!O@OOO@O OoOc+@OaO`@OKp@OB5O>A@ODavid Disseldorp David Disseldorp npower David Disseldorp ddiss@suse.comSamuel Cabrero David Mulder Samuel Cabrero Samuel Cabrero ddiss@suse.comscabrero@suse.deddiss@suse.comjmcdonough@suse.comddiss@suse.comscabrero@suse.comscabrero@suse.descabrero@suse.descabrero@suse.deaaptel@suse.comnopower@suse.comnopower@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comddiss@suse.comnopower@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comdmulder@suse.comnopower@suse.comjmcdonough@suse.comaaptel@suse.comkukuk@suse.comkukuk@suse.denopower@suse.comaaptel@suse.comdmulder@suse.comddiss@suse.comdmulder@suse.comddiss@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comnopower@suse.comnopower@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comnopower@suse.comddiss@suse.comjmcdonough@suse.comddiss@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comtchvatal@suse.comlmuelle@suse.comnopower@suse.comcrrodriguez@opensuse.orglmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnoel.power@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.commpluskal@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.denopower@suse.delmuelle@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comnopower@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comnopower@suse.delmuelle@suse.comddiss@suse.comlmuelle@suse.comjmcdonough@suse.comjmcdonough@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comddiss@suse.comnopower@suse.deddiss@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.comddiss@suse.comddiss@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.deddiss@suse.comddiss@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comadrian@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comnopower@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comjengelh@inai.delmuelle@suse.comjengelh@inai.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comjengelh@inai.deddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comddiss@suse.comddiss@suse.comlmuelle@suse.comsjayaraman@suse.delmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comjmcdonough@suse.comddiss@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comshargagan@novell.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comlmuelle@suse.comddiss@suse.delmuelle@suse.comlmuelle@suse.delmuelle@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.defcrozat@suse.comlmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.decoolo@suse.comcoolo@suse.comlmuelle@suse.deshargagan@novell.comddiss@suse.delmuelle@suse.deddiss@suse.deddiss@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dehhetter@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deshargagan@novell.comddiss@suse.delmuelle@suse.dejmcdonough@suse.deddiss@suse.deddiss@suse.delmuelle@suse.dejmcdonough@suse.demrsb@novell.comlpechacek@suse.czjmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.deshargagan@novell.comddiss@suse.delmuelle@suse.deshargagan@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.dejmcdonough@suse.deddiss@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.dejengelh@medozas.delmuelle@suse.delmuelle@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.deddiss@suse.deddiss@suse.deddiss@suse.dero@suse.delmuelle@suse.delmuelle@suse.delars@samba.orglmuelle@suse.deddiss@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.dehhetter@suse.deddiss@suse.dejmcdonough@suse.decoolo@novell.comlmuelle@suse.dejmcdonough@suse.degber@opensuse.orgjmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.desjayaraman@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dehhetter@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delars@samba.orglars@samba.orgjmcdonough@suse.dejsmeix@suse.delmuelle@suse.dehhetter@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.derhafer@novell.comhhetter@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.deboyang@suse.dejmcdonough@suse.delmuelle@suse.deboyang@suse.deboyang@suse.delmuelle@suse.derhafer@novell.comlmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delars@samba.orgjmcdonough@suse.desjayaraman@suse.dejengelh@medozas.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.deboyang@suse.dechris@computersalat.delmuelle@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.deboyang@suse.deboyang@suse.dehhetter@suse.delmuelle@suse.delmuelle@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.desbrabec@suse.czlmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.deboyang@suse.deboyang@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.desjayaraman@suse.desjayaraman@suse.desjayaraman@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dejmcdonough@suse.delmuelle@suse.dejmcdonough@suse.dejmcdonough@suse.dejmcdonough@suse.delmuelle@suse.delmuelle@suse.delmuelle@suse.dero@suse.de- Fix cephwrap_flistxattr() debug message; (bso#13940); (bsc#1134697).- Fix vfs_ceph realpath; (bso#13918); (bsc#1134452).- Explicitly enable libcephfs POSIX ACL support; (bso#13896); (bsc#1130245).- CVE-2019-3880: Save registry file outside share as unprivileged user; (bso#13851); (bsc#1131060 ).- Fix vfs_ceph ftruncate and fallocate handling; (bso#13807); (bsc#1127153).- Abide by load_printers smb.conf parameter; (bso#13766); (bsc#1124223);- s3:winbindd: let normalize_name_map() call find_domain_from_name_noinit(); (bso#13173); (bsc#1123755); - s3:winbind: Fix regression introduced with bso #12851; (bso#12851); (bsc#1123755);- s3:passdb: Do not return OK if we don't have pinfo set up; (bsc#1099590); (bso#13376);- s3: winbind: Remove fstring from wb_acct_info struct; (bsc#1114459); - Use foreground execution mode for systemd samba daemons; (bsc#1112223);- Update to 4.6.16; (bsc#1110943); + CVE-2018-10919: Fix unauthorized attribute access via searches; (bso#13434);- Update to 4.6.15 + Fix ctdb_mutex_ceph_rados_helper deadlock; (bso#13540); (bsc#1102230); + Allow idmap_rid to have primary group other than "Domain Users"; (bsc#1087931).- CVE-2018-10858: Insufficient input validation on client directory listing in libsmbclient; (bso#13453); (bsc#1103411); - s3: winbind: Fix 'winbind normalize names' in wb_getpwsid(); (bso#12851); - winbind: avoid using fstrcpy in _dual_init_connection; (bso#13294); (bsc#1087303); - Fix ntlm authentications with "winbind use default domain = yes"; (bso#13126); (bsc#1068059); - net: fix net ads keytab handling; (bso#13166); (bsc#1067700); - fix vfs_ceph flock stub; (bso#13506).- Fix vfs_ceph with "aio read size" or "aio write size" > 0; (bsc#1093664). + vfs_ceph: add fake async pwrite/pread send/recv hooks; (bso#13425). + Fix memory leak in vfs_ceph; (bso#13424). - Update to 4.6.14 + winbind: avoid using fstrcpy(dcname,...) in _dual_init_connection; (bso#13294). + s3:smb2_server: correctly maintain request counters for compound requests; (bso#13215). + s3: smbd: Unix extensions attempts to change wrong field in fchown call; (bso#13375). + s3:smbd: map nterror on smb2_flush errorpath; (bso#13338). + vfs_glusterfs: Fix the wrong pointer being sent in glfs_fsync_async; (bso#13297). + s3: smbd: Fix possible directory fd leak if the underlying OS doesn't support fdopendir(); (bso#13270). + s3: ldap: Ensure the ADS_STRUCT pointer doesn't get freed on error, we don't own it here; (bso#13244). + s3:libsmb: allow -U"\\administrator" to work; (bso#13206). + CVE-2018-1057: s4:dsdb: fix unprivileged password changes; (bso#13272); (bsc#1081024). + s3:smbd: Do not crash if we fail to init the session table; (bso#13315). + libsmb: Use smb2 tcon if conn_protocol >= SMB2_02; (bso#13310). + smbXcli: Add "force_channel_sequence"; (bso#13215). + smbd: Fix channel sequence number checks for long-running requests; (bso#13215). + s3:smb2_server: allow logoff, close, unlock, cancel and echo on expired sessions; (bso#13197). + s3:smbd: return the correct error for cancelled SMB2 notifies on expired sessions; (bso#13197). + samba: Only use async signal-safe functions in signal handler; (bso#13240). + subnet: Avoid a segfault when renaming subnet objects; (bso#13031).- CVE-2018-1050: DOS vulnerability when SPOOLSS is run externally; (bso#11343); (bsc#1081741);- Update to 4.6.13; (bsc#1084191) + ceph_statx configure time check doesn't work with a non-default - -with-libcephfs path; (bso#13250). - follow up fix for libceph-common detection; (bso#13277). + Fail to copy file with empty FinderInfo from Windows client to Samba share with fruit; (bso#13181). + vfs_ceph uses a local statvfs() call to determine FS capabilities; (bso#13208). + smbd tries to release not leased oplock during oplock II downgrade; (bso#13193). + smbd panic when chdir returns error during exit; (bso#13189). + ctdb_recovery_helper crashes if recovery process times out; (bso#13188). + POSIX ACL support is broken on hpux and possibly other big-endian OSs; (bso#13176). + Kerberos: PKINIT: Can't decode algorithm parameters in clientPublicValue; (bso#12986). + g_lock conflict detection broken when processing stale entries.; (bso#13195). + The KDC on an RWDC doesn't send error replies in some situations; (bso#13132).- Update to 4.6.11; (bsc#1084191) + vfs_glusterfs: Fix exporting subdirs with shadow_copy2; (bso#13091); + s3: smbclient: Ensure we call client_clean_name() before all operations on remote pathnames; (bso#13093); + Non-smbd processes using kernel oplocks can hang smbd; (bso#13121); + python: use communicate to fix Popen deadlock; (bso#13127); + smbd on disk file corruption bug under heavy threaded load; (bso#13130); + tevent: version 0.9.34; (bso#13130); + vfs_fruit: Replace closedir() by SMB_VFS_CLOSEDIR; (bso#13086); + smbd: Move check for SMB2 compound request to new function; (bso#13047); + s3:vfs_glusterfs: Fix a double free in vfs_gluster_getwd(); (bso#13100); + s4:pyparam: Fix resource leaks on error; (bso#13101); + s3:smbd: Fix delete-on-close after smb2_find; (bso#13118);- CVE-2017-14746: Use-after-free vulnerability; (bso#13041); (bsc#1060427); - CVE-2017-15275: Server heap memory information leak; (bso#13077); (bsc#1063008);- Update to 4.6.9; (bsc#1065066); + Reverse sense of 'clear all attributes', ignore attribute change in SMB2 to match SMB1; (bso#12899); + SMBC_setatr() initially uses an SMB1 call before falling back; (bso#12913); + Fix segfault on MacOS 10.12.3 clients caused by SMB_VFS_GET_COMPRESSION; (bso#13003); + sys_getwd() can leak memory or possibly return the wrong errno on older systems; (bso#13069); + Cannot delete non-ACL files on Solaris/ZFS/NFSv4 ACL filesystem; (bso#6133); + Map SYNCHRONIZE acl permission statically; (bso#7909); + Honor SEC_STD_WRITE_OWNER bit; (bso#7933); + Kernel oplocks still have issues with named streams; (bso#12791); + Handle EACCES when fetching DOS attributes; (bso#12944); + Missing assignment in sl_pack_float; (bso#12991); + Fix wrong Samba access checks when changing DOS attributes; (bso#12995); + Groupmap cleanup should not delete BUILTIN mappings; (bso#13065); + Enabling vfs_fruit results in loss of Finder tags and other xattrs; (bso#13076); + Fix GUID string format on GetPrinter info; (bso#12993); + Match WS2016 ReFS set compression behaviour; (bso#12144); + Fix implementation of process_exists control; (bso#13012); + GET_DB_SEQNUM control can cause ctdb to deadlock when databases are frozen; (bso#13021); + Free up record data if a call request is deferred; (bso#13029); + Initialize ctdb_ltdb_header completely for empty record; (bso#13036); + CTDB starts consuming memory if there are dead nodes in the cluster; (bso#13056); + Ignore event scripts with multiple '.'s; (bso#13070); + Sort the GPOs in the correct order; (bso#13046); + 'smbd' uses a lot of CPU on startup of a connection; (bso#12973); + Fix str[n]casecmp_m() by comparing lower case values; (bso#13018); + Can't change password in Samba from a windows client if Samba runs on IPv6 only interface; (bso#13079); + Fix file change notification for renames; (bso#12903); + Avoid a socket leak after fork; (bso#13006); + Fix a potential memleak; (bso#13090); + Fix passing of errno from async calls; (bso#12983); + Fix segfault when running with log level 10; (bso#13032); + Do not report an invalid range for AD DC role; (bso#12629); + Print the kinit failed message with DBGLVL_NOTICE; (bso#12704); + Fix changing passwords with Kerberos; (bso#12956); + Fix changing the password with 'smbpasswd' as a local user on a domain member; (bso#12975); + Fix a read after free if a chained SMB1 call goes async; (bso#12836); + CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); + Let non_widelink_open() chdir() to directories directly; (bso#12885); + CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); + CVE-2017-12150: Some code path don't enforce smb signing when they should; (bso#12997);- Fix GUID string format on GetPrinter info request; (bso#12993); (bsc#1050707).- CVE-2017-12163: Prevent client short SMB1 write from writing server memory to file; (bso#13020); (bsc#1058624).- CVE-2017-12150: Some code path don't enforce smb signing, when they should; (bso#12997); (bsc#1058622).- CVE-2017-12151: Keep required encryption across SMB3 dfs redirects; (bso#12996); (bsc#1058565).- Update to 4.6.7; (bsc#1054017) + Joining a Huawai storage fails: empty CLDAP ping answer; (bso#11392). + smbcacls can fail against a directory on Windows using SMB2.; (bso#12937). + vfs_ceph provides inconsistent directory listings; (bso#12911). + Misused talloc context can cause a user to crash their smbd by chaining SMB1 commands.; (bso#12836). + Use-after free can crash libsmbclient code.; (bso#12927). + Server exit with active AIO can crash.; (bso#12925). + Ensure notifyd doesn't return from smbd_notifyd_init; (bso#12910). + fd leak to ctdb sub-processes leads to SELinux AVC denial in audit logs; (bso#12898). + vfs_fruit shouldn't send MS NFS ACEs to Windows clients; (bso#12897). + smbspool_krb5_wrapper does not tell CUPS that it requires negotiate for authentication; (bso#12886). + finder sidebar showing question mark instead of icon when using ip to connect with vfs_fruit; (bso#12840). + Winbind stops obtaining the 'unixHomeDirectory' & 'loginShell' attributes from AD.; (bso#12720). + KCC run at selftest startup can fail spuriously due to a race; (bso#12869). + winbindd changes the local password and gets NT_STATUS_WRONG_PASSWORD for the remote change; (bso#12782). + rpc_pipe_client memory leaks due to long term memory context passed to rpc_pipe_open_interface(); (bso#12890). + CVE-2017-2619 breaks accessing previous versions of directories with snapshots in subdirectories of the share; (bso#12885). + dns_name_equal doing OOB read; (bso#12813). + replica_sync tests flap; (bso#12753). + Selftest should not call 'net cache flush' and wipe important winbind entries; (bso#12868). + Old Samba versions don't support using recent ldb versions (>=1.1.30); (bso#12859). + pam_winbind fails with kerberos method = secrets and keytab; (bso#10490). + race starting winbindd against posixacl test; (bso#12843). + Crash in the reentrant smbd_smb2_create_send() if the something fails in the subsequent try; (bso#12832). + spnego.c passes the wrong argument order to gensec_update_ev() for the FALLBACK case; (bso#12788). + Clients with SMB3 support can't connect with "server max protocol = SMB2_02"; (bso#12772). + A log message of samb-tool user syncpasswords reverses string arguments in a debug message "Call Popen[...".; (bso#12768). + The smb tarmode tests kills the share dir contents; (bso#12867). + Fix for a bug in MacOS X Sierra NTLMv2 processing; (bso#12862). + CVE-2017-2619 regression with non-wide symlinks to directories; (bso#12860). + manpage/index.html lists links not in alphabetical order; (bso#12854). + smbcacls got error NT_STATUS_NETWORK_NAME_DELETED; (bso#12831). + If a record is locked in a database, then recovery does not complete; (bso#12857). + debug_locks.sh script does not log any information; (bso#12856). + SIGSEGV in cm_connect_lsa_tcp dereferencing conn->lsa_tcp_pipe->transport after error; (bso#12852). + smbclient can't parse DOMAIN+username if a different winbind separator is used; (bso#12849). + Related requests with SessionSetup fail with INTERNAL_ERROR; (bso#12845). + Related requests with TreeConnect fail with NETWORK_NAME_DELETED; (bso#12844). + cli->server_os not filled correctly; (bso#12779). + REGRESSION: smbclient doesn't print the session setup anymore; (bso#12824). + smblcient doesn't handle STATUS_NOT_SUPPORTED gracefully for FSCTL_VALIDATE_NEGOTIATE_INFO; (bso#12808). + CTDB NFS call-out failures do not cause event failures; (bso#12837). + net command fails due to incorrectly return code; (bso#12828). + Fix building Samba with GCC 7.1; (bso#12827).- Fix duplicate CTDB_LOGGING params when downgraded and upgraded again; (bsc#1048339).- fix cephwrap_chdir(); (bsc#1048790). - Update to 4.6.6 + CVE-2017-11103: Orpheus' Lyre KDC-REP service name validation; (bsc#1048278).- Fix ctdb logs to /var/log/log.ctdb instead of /var/log/ctdb; (bsc#1048339).- Fix inconsistent ctdb socket path; (bsc#1048352). - Fix non-admin cephx authentication; (bsc#1048387).- Update to 4.6.5; (bsc#1040157) + Specifying CTDB_LOGGING=syslog:nonblocking causes ctdbd to crash at startup; (bso#12814). + vfs_expand_msdfs tries to open the remote address as a file path; (bso#12687). + PANIC (pid 1096): assert failed: lease_type_is_exclusive(e_lease_type); (bso#12798). + With clustering get update_num_read_oplocks failed and PANIC: num_share_modes == 1 assertion failure; (bso#11844). + contend_level2_oplocks_begin_default oplock optimisation doesn't carry over to leases; (bso#12766). + `ctdb nodestatus` incorrectly displays status for all nodes with wrong exit code; (bso#12802). + CTDB can spin hard on revoking readonly delegations if a node becomes disconnected; (bso#12697). + Printing a share mode entry with leases can crash in the ndr code; (bso#12793). + Fix flakey unit tests for eventd; (bso#12792). + CTDB daemon crashes if built with clang; (bso#12770). + smbcacls fails if no password is specified; (bso#12765). + idmap_rfc2307: Lookup of more than two SIDs fails; (bso#12757). + samba-tool user syncpasswords doesn't trigger the script when a user gets removed; (bso#12767). + systemd: fix detection of libsystemd; (bso#12764). + Notify subsystem only maps first inotify mask to Windows notify filter; (bso#12760). + Allow passing trusted domain password as plain-text to PASSDB layer; (bso#12751). + Can't case-rename files with vfs_fruit; (bso#12749). + wrong sid->uid mapping for SIDs residing in sIDHistory; (bso#12702). + vfs_acl_common should force "create mask = 0777", not 0666; (bso#12562). + Ordering of notify responses broken; (bso#12756).- s3: libsmb: Fix error where short name length was read as 2 bytes, should be 1; (bso#11822); (bsc#1042419).- Revert explicit winbind %{version}-%{release} dependency. + The ABI has stabilized since (bsc#936909), so remove to fix cross-media dependencies; (bsc#1037899).- Fix CVE-2017-7494 remote code execution from a writable share; (bso#12780); (bsc#1038231).- Update to 4.6.3; (bsc#1036011) + s3:vfs:shadow_copy2: vfs_shadow_copy2 fails to list snapshots from shares with GlusterFS backend; (bso#12743). + Fix for Solaris C compiler; (bso#12559). + s3: locking: Update oplock optimization for the leases era; (bso#12628). + Make the Solaris C compiler happy; (bso#12693). + s3: libgpo: Allow skipping GPO objects that don't have the expected LDAP attributes; (bso#12695). + Fix buffer overflow caused by wrong use of getgroups; (bso#12747). + lib: debug: Avoid negative array access; (bso#12746). + cleanupdb: Fix a memory read error; (bso#12748). + streams_xattr and kernel oplocks results in NT_STATUS_NETWORK_BUSY; (bso#7537). + winbindd: idmap_autorid allocates ids for unknown SIDs from other backends; (bso#11961). + vfs_fruit: Resource fork open request with flags=O_CREAT|O_RDONLY; (bso#12565). + manpages/vfs_fruit: Document global options; (bso#12615). + lib/pthreadpool: Fix a memory leak; (bso#12624). + Lookup-domain for well-known SIDs on a DC; (bso#12727). + winbindd: Fix error handling in rpc_lookup_sids(); (bso#12728). + winbindd: Trigger possible passdb_dsdb initialisation; (bso#12729). + credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case; (bso#12611). + lib/crypto: Implement samba.crypto Python module for RC4; (bso#12690). + ctdb-readonly: Avoid a tight loop waiting for revoke to complete; (bso#12697). + ctdb_event monitor command crashes if event is not specified; (bso#12723). + ctdb-docs: Fix documentation of "-n" option to 'ctdb tool'; (bso#12733). + smbd: Fix smb1 findfirst with DFS; (bso#12558). + smbd: Do an early exit on negprot failure; (bso#12610). + winbindd: Fix substitution for 'template homedir'; (bso#12699). + s4:kdc: Disable principal based autodetected referral detection; (bso#12554). + idmap_autorid: Allocate new domain range if the callers knows the sid is valid; (bso#12613). + LINKFLAGS_PYEMBED should not contain -L/some/path; (bso#12724). + PAM auth with WBFLAG_PAM_GET_PWD_POLICY returns wrong policy for trusted domain; (bso#12725). + rpcclient: Allow -U'OTHERDOMAIN\user' again; (bso#12731). + winbindd: Fix password policy for pam authentication; (bso#12725). + s3:gse: Correctly handle external trusts with MIT; (bso#12554). + auth/credentials: Always set the realm if we set the principal from the ccache; (bso#12611). + replace: Include sysmacros.h; (bso#12686). + s3:vfs_expand_msdfs: Do not open the remote address as a file; (bso#12687). + s3:libsmb: Only print error message if kerberos use is forced; (bso#12704). + winbindd: Child process crashes when kerberos-authenticating a user with wrong password; (bso#12708). + vfs_fruit: Office document opens as read-only on macOS due to CNID semantics; (bso#12715). + vfs_acl_xattr: Fix failure to get ACL on Linux if memory is fragmented; (bso#12737).- Generate and update vendor-files tarball from Git + SuSEfirewall2 service samba-client only setup IPv4 rule; (bsc#1034416).- Generate source tarball directly from Git using OBS tar_scm + use version string derived from parent Git tag and commit hash - remove obsolete vendor-files/tools/package-data version ID + explicitly generate ctdb manpages, needed without "make dist"- Update to 4.6.2 + remove bso#12721 patches now upstream- Enable samba-ceph build for openSUSE and SLE12SP3+; (fate#321622). + x86-64 and aarch64- Enable librados CTDB lock helper for samba-ceph package; (fate#321622).- Build and install the html man pages (bsc#1021907).- Fix CVE-2017-2619 regression with "follow symlinks = no"; (bso#12721).- Update to 4.6.1 + symlink race permits opening files outside share directory; CVE-2017-2619; (bso#12496); (bsc#1027147) + testparm checks for valid idmap parameters + add new krb client encryption types + support for printer driver upload from windows 10 + inherit owner = 'unix only' for improved quota support + improved CTDB event support + new primary group support for idmap_ad + idmap_hash deprecated + mvxattr added to recursively rename extended attributes- Remove chkconfig requirements for systemd systems- Don't call insserv if systemd is used- Fix check if we need to require insserv- async_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416).- Force usage of ncurses6-config thru NCURSES_CONFIG env var; (bsc#1023847).- add missing patch for libnss_wins segfault; (bsc#995730).- Fix vfs_ceph builds against recent Ceph versions; (bsc#1021933).- Document "winbind: ignore domains" parameter; (bsc#1019416).- Add base Samba dependency to samba-ceph package.- Update to 4.5.3 + Heap-based Buffer Overflow Remote Code Execution Vulnerability; CVE-2016-2123; (bso#12409); (bsc#1014437). + Don't send delegated credentials to all servers; CVE-2016-2125; (bso#12445); (bsc#1014441). + denial of service due to a client triggered crash in the winbindd parent process; CVE-2016-2126; (bso#12446); (bsc#1014442). - 4.5.1 and 4.5.2 updates + various streams vfs fixes + various printing fixes + ntlm_auth: do not map explicitly empty domain + various stability fixes in smbd + match file compression ReFS behavior- Add missing ldb module directory; (bnc#1012092).- s3/client: obey 'disable netbios' smb.conf param, don't connect via NBT port; (bsc#1009085); (bso#12418).- Include vfstest in samba-test; (bsc#1001203).- s3/winbindd: using default domain with user@domain.com format fails; (bsc#997833).- Fix segfault in libnss_wins; (bso#12277); (bso#12269); (bsc#995730).- Update to 4.5.0 + NTLM1 Authentication disabled by default + SMB2.1 leases enabled by default + Support for OFD locks + ctdb tool rewritten + Added shadow copy snapshot prefix parameter- Fix illegal memory access after memory has been deleted; (bso#11836); (bsc#975299).- Prevent core, make sure response->extra_data.data is always cleared out; (bsc#993692).- Don't package man pages for VFS modules that aren't built; (boo#993707).- Fix population of ctdb sysconfig after source merge; (bsc#981566).- Enable vfs_ceph builds for Factory (x86-64) + Package as samba-ceph to avoid Ceph dependency in base package.- Update to 4.4.5 + Prevent client-side SMB2 signing downgrade; CVE-2016-2119; (bso#11860); (bsc#986869).- Remove obsolete syslog.target; (bsc#983938).- Honor smb.conf socket options in winbind; (bsc#975131).- Don't use htons() with IP_PROTO_RAW; (bso#11705); (bsc#969522).- Update to 4.4.4 + SMB3 multichannel: Add implementation of missing channel sequence number verification; (bso#11809). + smbd:close: Only remove kernel share modes if they had been taken at open; (bso#11919). + notifyd: Prevent NULL deref segfault in notifyd_peer_destructor; (bso#11930). + s3:rpcclient: Make '--pw-nt-hash' option work; (bso#10796). + Fix case sensitivity issues over SMB2 or above; (bso#11438). + s3:smbd: Fix anonymous authentication if signing is mandatory. (bso#11910) + Fix NTLM Authentication issue with squid; (bso#11914). + pdb: Fix segfault in pdb_ldap for missing gecos; (bso#11530). + Fix memory leak in share mode locking; (bso#11934).- Update to 4.4.3 + Various post-badlock regressions; (bso#11841); (bso#11850); (bso#11858); (bso#11870); (bso#11872). + Only allow idmap_hash for default idmap config (bso#11786). + smbd: Avoid large reads beyond EOF; (bso#11878). + vfs_acl_common: Avoid setting POSIX ACLs if "ignore system acls" is set; (bso#11806). + libads: Record session expiry for spnego sasl binds; (bso#11852).- Fix NTLMSSP regressions caused by previous CVE fixes; (bso#11849); (bsc#975962); (bsc#979268), (bsc#977669).- Revert shared library packaging to comply with SLPP- Update to 4.4.2 + A man-in-the-middle can downgrade NTLMSSP authentication; CVE-2016-2110; (bso#11688); (bsc#973031). + Domain controller netlogon member computer can be spoofed; CVE-2016-2111; (bso#11749); (bsc#973032). + LDAP conenctions vulnerable to downgrade and MITM attack; CVE-2016-2112; (bso#11644); (bsc#973033). + TLS certificate validation missing; CVE-2016-2113; (bso#11752); (bsc#973034). + Named pipe IPC vulnerable to MITM attacks; CVE-2016-2115; (bso#11756); (bsc#973036). + "Badlock" DCERPC impersonation of authenticated account possible; CVE-2016-2118; (bso#11804); (bsc#971965). + DCERPC server and client vulnerable to DOS and MITM attacks; CVE-2015-5370; (bso#11344); (bsc#936862).- Fix samba.tests.messaging test and prevent potential tdb corruption by removing obsolete now invalid tdb_close call; (bsc#974629).- Obsolete libsmbclient from libsmbclient0 while not providing it; (bsc#972197).- Update to 4.4.0. + Read of uninitialized memory DNS TXT handling; (bso#11128); (bso#11686); CVE-2016-0771. + Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); CVE-2015-7560. + Sockets with htons(IPPROTO_RAW); (bso#11705); CVE-2015-8543. + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystem with no ACL support; (bso#10489). + docs: Add example for domain logins to smbspool man page; (bso#11643). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + docs: Add smbspool_krb5_wrapper manpage; (bso#11690). + winbindd: Return trust parameters when listing trusts; (bso#11691). + ctdb: Do not provide a useless pkgconfig file for ctdb; (bso#11696). + Crypto.Cipher.ARC4 is not available on some platforms, fallback to M2Crypto.RC4.RC4 then; (bso#11699). + s3:utils/smbget: Set default blocksize; (bso#11700). + Streamline 'smbget' options with the rest of the Samba utils; (bso#11700). + s3:clispnego: Fix confusing warning in spnego_gen_krb5_wrap(); (bso#11702). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + s3:vfs:glusterfs: Fix build after quota changes; (bso#11715). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + lib:socket: Fix CID 1350010: Integer OVERFLOW_BEFORE_WIDEN; (bso#11723). + smbd: Fix CID 1351215 Improper use of negative value; (bso#11724). + smbd: Fix CID 1351216 Dereference null return value; (bso#11725). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + docs: Add manpage for cifsdd; (bso#11730). + param: Fix str_list_v3 to accept ; again; (bso#11732). + lib/socket: Fix improper use of default interface speed; (bso#11734). + lib:socket: Fix CID 1350009: Fix illegal memory accesses (BUFFER_SIZE_WARNING); (bso#11735). + libcli: Fix debug message, print sid string for new_ace trustee; (bso#11738). + Fix installation path of Samba helper binaries; (bso#11739). + Fix memory leak in loadparm; (bso#11740). + tevent: version 0.9.28: Fix memory leak when old signal action restored; (bso#11742). + smbd: Ignore SVHDX create context; (bso#11753). + Fix net join; (bso#11755). + s3:libads: setup the msDS-SupportedEncryptionTypes attribute on ldap_add; (bso#11755). + passdb: Add linefeed to debug message; (bso#11763). + s3:utils/smbget: Fix option parsing; (bso#11767). + libnet: Make Kerberos domain join site-aware; (bso#11769). + Reset TCP Connections during IP failover; (bso#11770). + ldb: Version 1.1.26; (bso#11772). + s3:smbd: Add negprot remote arch detection for OSX; (bso#11773). + vfs_glusterfs: Fix use after free in AIO callback; (bso#11774). + mkdir can return ACCESS_DENIED incorrectly on create race; (bso#11780). + "trustdom_list_done: Got invalid trustdom response" message should be avoided; (bso#11782). + Mismatch between local and remote attribute ids lets replication fail with custom schema; (bso#11783). + Quota is not supported on Solaris 10; (bso#11788). + Talloc: Version 2.1.6; (bso#11789). + smbd: Enable multi-channel if 'server multi channel support = yes' in the config; (bso#11796). + build: Fix build when '--without-quota' specified; (bso#11798). + lib/socket/interfaces: Fix some uninitialied bytes; (bso#11802). + Access based share enum: handle permission set in configuration files; (bso#8093). + See also WHATSNEW.txt from the samba-doc package.- Update to 4.3.6. + Getting and setting Windows ACLs on symlinks can change permissions on link target; CVE-2015-7560; (bso#11648); (bsc#968222). + Fix Out-of-bounds read in internal DNS server; CVE-2016-0771; (bso#11128); (bso#11686); (bsc#968223).- Upgrade on-disk FSRVP server state to new version; (bsc#924519).- Only obsolete but do not provide gplv2/3 package names; (bsc#968973).- Relocate existing lock files to /var/lib/samba/lock; (bsc#968963).- Obsolete no longer existing samba-32bit package; (bsc#967625).- Update to 4.3.5. + s3:utils/smbget: Fix recursive download; (bso#6482). + s3: smbd: posix_acls: Fix check for setting u:g:o entry on a filesystemi with no ACL support; (bso#10489). + s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks; (bso#11400). + vfs_shadow_copy2: Fix case where snapshots are outside the share; (bso#11580). + smbclient: Query disk usage relative to current directory; (bso#11662). + winbindd: Handle expired sessions correctly; (bso#11670). + smbd: Show correct disk size for different quota and dfree block sizes; (bso#11681). + smbcacls: Fix uninitialized variable; (bso#11682). + s3:smbd: Ignore initial allocation size for directory creation; (bso#11684). + s3-client: Add a KRB5 wrapper for smbspool; (bso#11690). + s3-parm: Clean up defaults when removing global parameters; (bso#11693). + Use M2Crypto.RC4.RC4 on platforms without Crypto.Cipher.ARC4; (bso#11699). + s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703). + ctdb: Remove error messages after kernel security update; CVE-2015-8543; (bso#11705). + loadparm: Fix memory leak issue; (bso#11708). + lib/tsocket: Work around sockets not supporting FIONREAD; (bso#11714). + ctdb-scripts: Drop use of "smbcontrol winbindd ip-dropped ..."; (bso#11719). + s3:smbd:open: Skip redundant call to file_set_dosmode when creating a new file; (bso#11727). + param: Fix str_list_v3 to accept ";" again; (bso#11732).- Shift samba-client sysconfig data into samba and samba-winbind; (bsc#947361).- Simplify shared library packaging; (bsc#966956).- Enable clustering (CTDB) support; (bsc#966271).- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703); (bsc#964023).- Add quotes around path of update-apparmor-samba-profile; (bnc#962177).- Remove autoconf build-time requirement.- Update to 4.3.4. + vfs_fruit: Enable POSIX directory rename semantics; (bso#11065). + Crash: Bad talloc magic value - access after free; (bso#11394). + Copying files with vfs_fruit fails when using vfs_streams_xattr without stream prefix and type suffix; (bso#11466). + samba-tool: Fix uncaught exception if no fSMORoleOwner attribute is given; (bso#11613). + Fix a typo in the smb.conf manpage, explanation of idmap config; (bso#11619). + Correctly initialize the list head when keeping a list of primary followed by DFS connections; (bso#11624). + Reduce the memory footprint of empty string options; (bso#11625). + lib/async_req: Do not install async_connect_send_test; (bso#11639). + Fix typos in man vfs_gpfs; (bso#11641). + Make "hide dot files" option work with "store dos attributes = yes"; (bso#11645). + Fix a corner case of the symlink verification; (bso#11647); (bnc#960249). + Do not disable "store dos attributes" on-the-fly; (bso#11649). + Update lastLogon and lastLogonTimestamp; (bso#11659).- Prevent access denied if the share path is "/"; (bso#11647); (bnc#960249).- Update to 4.3.3. + Malicious request can cause Samba LDAP server to hang, spinning using CPU; CVE-2015-3223; (bso#11325); (bnc#958581). + Remote read memory exploit in LDB; CVE-2015-5330; (bso#11599); (bnc#958586). + Insufficient symlink verification (file access outside the share); CVE-2015-5252; (bso#11395); (bnc#958582). + No man in the middle protection when forcing smb encryption on the client side; CVE-2015-5296; (bso#11536); (bnc#958584). + Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2); CVE-2015-5299; (bso#11529); (bnc#958583). + Fix Microsoft MS15-096 to prevent machine accounts from being changed into user accounts; CVE-2015-8467; (bso#11552); (bnc#958585).- Update to 4.3.2. + vfs_gpfs: Re-enable share modes; (bso#11243). + dcerpc.idl: Accept invalid dcerpc_bind_nak pdus; (bso#11327). + s3-smbd: Fix old DOS client doing wildcard delete - gives an attribute type of zero; (bso#11452). + Add libreplace dependency to texpect, fixes a linking error on Solaris; (bso#11511). + s4: Fix linking of 'smbtorture' on Solaris; (bso#11512). + s4:lib/messaging: Use correct path for names.tdb; (bso#11562). + Fix segfault of 'net ads (join|leave) -S INVALID' with nss_wins; (bso#11563). + async_req: Fix non-blocking connect(); (bso#11564). + auth: gensec: Fix a memory leak; (bso#11565). + lib: util: Make non-critical message a warning; (bso#11566). + Fix winbindd crashes with samlogon for trusted domain user; (bso#11569); (bnc#949022). + smbd: Send SMB2 oplock breaks unencrypted; (bso#11570). + ctdb: Open the RO tracking db with perms 0600 instead of 0000; (bso#11577). + s3:smb2_server: Make the logic of SMB2_CANCEL DLIST_REMOVE() clearer; (bso#11581). + s3-smbd: Fix use after issue in smbd_smb2_request_dispatch(); (bso#11581). + manpage: Correct small typo error; (bso#11584). + s3: smbd: If EAs are turned off on a share don't allow an SMB2 create containing them; (bso#11589). + Backport some valgrind fixes from upstream master; (bso#11597). + auth: Consistent handling of well-known alias as primary gid; (bso#11608). + winbind: Fix crash on invalid idmap configs; (bso#11612). + s3: smbd: have_file_open_below() fails to enumerate open files below an open directory handle; (bso#11615). + Changing log level of two entries to DBG_NOTICE; (bso#9912).- Ensure samlogon fallback requests are rerouted after kerberos failure; (bnc#953382); (bnc#953972).- Ensure to link with --as-needed flag by removing SUSE_ASNEEDED=0. - Always use the default optimization even on pre-9.2 systems.- Remove redundant configure options while adding with-relro.- Relocate the lockdir to the /var/lib/samba/lock directory.- Cleanup and enhance the pidl sub package.- Require renamed python-ldb-devel and python-talloc-devel at build-time. - Requires python-ldb and python-talloc from the python subpackage.- Update to 4.3.1. + s3: smbd: Fix our access-based enumeration on "hide unreadable" to match Windows; (bso#10252). + nss_winbind: Fix hang on Solaris on big groups; (bso#10365). + smbd: Fix file name buflen and padding in notify repsonse; (bso#10634). + kerberos: Make sure we only use prompter type when available; winbind: Fix 100% loop; (bso#11038). + source3/lib/msghdr.c: Fix compiling error on Solaris; (bso#11053). + s3:ctdbd_conn: make sure we destroy tevent_fd before closing the socket; (bso#11316). + s3: smbd: Fix mkdir race condition; (bso#11486). + pam_winbind: Fix a segfault if initialization fails; (bso#11502). + s3: dfs: Fix a crash when the dfs targets are disabled; (bso#11509). + s4:lib/messaging: Use 'msg.lock' and 'msg.sock' for messaging related subdirs; (bso#11515). + s3: smbd: Fix opening/creating :stream files on the root share directory; (bso#11522). + lib/param: Fix hiding of FLAG_SYNONYM values; (bso#11526). + net: Fix a crash with 'net ads keytab create'; (bso#11528). + s3: smbd: Fix a crash in unix_convert(); (bso#11535). + s3: smbd: Fix NULL pointer bug introduced by previous 'raw' stream fix (bso#11522); (bso#11535). + vfs_fruit: Return value of ad_pack in vfs_fruit.c; (bso#11543). + vfs_commit: set the fd on open before calling SMB_VFS_FSTAT; (bso#11547). + s3:locking: Initialize lease pointer in share_mode_traverse_fn(); (bso#11549). + s3:smbstatus: Add stream name to share_entry_forall(); (bso#11550). + s3:lib: Validate domain name in lookup_wellknown_name(); (bso#11555). + s3: lsa: lookup_name() logic for unqualified (no DOMAIN component) names is incorrect; (bso#11555).- Fix 100% CPU in winbindd when logging in with "user must change password on next logon"; (bso#11038).- Relocate the tmpfiles.d directory to the client package; (bnc#947552).- Do not provide libpdb0 from libsamba-passdb0 but add it to baselibs.conf instead; (bnc#942716).- Package /var/lib/samba/private/sock with 0700 permissions; (bnc#946051).- Package /var/lib/samba/msg with 0755 permissions; (bso#11515); (bnc#945502).- Require to install libfam0-gamin from samba-libs on post-12.1 and pre-13.15 systems; (bnc#945013).- Update to 4.3.0. + Samba "map to guest = Bad uid" doesn't work; (bso#9862). + revert LDAP extended rule 1.2.840.113556.1.4.1941 LDAP_MATCHING_RULE_IN_CHAIN changes; (bso#10493). + No objectClass found in replPropertyMetaData on ordinary objects (non-deleted); (bso#10973). + Stream names with colon don't work with fruit:encoding = native; (bso#11278). + NetApp joined to a Samba/ADDC cannot resolve SIDs; (bso#11291). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + "force group" with local group not working; (bso#11320). + strsep is not available on Solaris; (bso#11359). + smbtorture does not build when configured --with-system-mitkrb5; (bso#11411). + Build with GPFS support is broken; (bso#11421). + Build broken with --disable-python; (bso#11424). + net share allowedusers crashes; (bso#11426). + nmbd incorrectly matches netbios names as own name; (bso#11427). + Python bindings don't check integer types; (bso#11429). + Python bindings don't check array sizes; (bso#11430). + CTDB's eventscript error handling is broken; (bso#11431). + Fix crash in nested ctdb banning; (bso#11432). + Cannot build ctdbpmda; (bso#11434). + samba-tool uncaught exception error; (bso#11436). + Crash in notify_remove caused by change notify = no; (bso#11444). + Poor SMB3 encryption performance with AES-GCM; (bso#11451). + Poor SMB3 encryption performance with AES-GCM (part1); (bso#11451). + fix recursion problem in rep_strtoll in lib/replace/replace.c; (bso#11455). + --bundled-libraries=!ldb,!pyldb,!pyldb-util doesn't disable ldb build and install; (bso#11458). + xid2sid gives inconsistent results; (bso#11464). + ctdb: Fix the build on FreeBSD 10.1; (bso#11465). + Handling of 0 byte resource fork stream; (bso#11467). + AD samr GetGroupsForUser fails for users with "()" in their name; (bso#11488).- Configure with --bundled-libraries=NONE; (bso#11458).- Adapt net-kdc-lookup patch for post-3.3 Samba versions; (bnc#295284).- Remove libiniparser-devel build-time requirement.- Update to 4.2.3. + s4:lib/tls: Fix build with gnutls 3.4; (bso#8780). + s4.2/fsmo.py: Fixed fsmo transfer exception; (bso#10924). + winbindd: Sync secrets.ldb into secrets.tdb on startup; (bso#10991). + Logon via MS Remote Desktop hangs; (bso#11061). + s3: lib: util: Ensure we read a hex number as %x, not %u; (bso#11068). + tevent: Add a note to tevent_add_fd(); (bso#11141). + s3:param/loadparm: Fix 'testparm --show-all-parameters'; (bso#11170). + s3-unix_msg: Remove socket file after closing socket fd; (bso#11217). + smbd: Fix a use-after-free; (bso#11218); (bnc#919309). + s3-rpc_server: Fix rpc_create_tcpip_sockets() processing of interfaces; (bso#11245). + s3:smb2: Add padding to last command in compound requests; (bso#11277). + Add IPv6 support to ADS client side LDAP connects; (bso#11281). + Add IPv6 support for determining FQDN during ADS join; (bso#11282). + s3: IPv6 enabled DNS connections for ADS client; (bso#11283). + Fix invalid write in ctdb_lock_context_destructor; (bso#11293). + Excessive cli_resolve_path() usage can slow down transmission; (bso#11295). + vfs_fruit: Add option "veto_appledouble"; (bso#11305). + tstream: Make socketpair nonblocking; (bso#11312). + idmap_rfc2307: Fix wbinfo '--gid-to-sid' query; (bso#11313). + Group creation: Add msSFU30Name only when --nis-domain was given; (bso#11315). + tevent_fd needs to be destroyed before closing the fd; (bso#11316). + Build fails on Solaris 11 with "‘PTHREAD_MUTEX_ROBUST’ undeclared"; (bso#11319). + smbd/trans2: Add a useful diagnostic for files with bad encoding; (bso#11323). + Change sharesec output back to previous format; (bso#11324). + Robust mutex support broken in 1.3.5; (bso#11326). + Kerberos auth info3 should contain resource group ids available from pac_logon; winbindd: winbindd_raw_kerberos_login - ensure logon_info exists in PAC; (bso#11328); (bnc#912457). + s3:smb2_setinfo: Fix memory leak in the defer_rename case; (bso#11329). + tevent: Fix CID 1035381 Unchecked return value; (bso#11330). + tdb: Fix CID 1034842 and 1034841 Resource leaks; (bso#11331). + s3: smbd: Use separate flag to track become_root()/unbecome_root() state; (bso#11339). + s3: smbd: Codenomicon crash in do_smb_load_module(); (bso#11342). + pidl: Make the compilation of PIDL producing the same results if the content hasn't change; (bso#11356). + winbindd: Disconnect child process if request is cancelled at main process; (bso#11358). + vfs_fruit: Check offset and length for AFP_AfpInfo read requests; (bso#11363). + docs: Overhaul the description of "smb encrypt" to include SMB3 encryption; (bso#11366). + s3:auth_domain: Fix talloc problem in connect_to_domain_password_server(); (bso#11367). + ncacn_http: Fix GNUism; (bso#11371).- Disable rpath usage; (bnc#902421).- Make the winbind package depend on the matching libwbclient version and vice versa; (bnc#936909).- Backport changes to use resource group sids obtained from pac logon_info; (bso#11328); (bnc#912457).- Order winbind.service Before and Want nss-user-lookup target.- Remove fam-devel build-time dependency for post-6 RHEL systems.- Update to 4.2.2. + s3:smbXsrv: refactor duplicate code into smbXsrv_session_clear_and_logoff(); (bso#11182). + gencache: don't fail gencache_stabilize if there were records to delete; (bso#11260). + s3: libsmbclient: After getting attribute server, ensure main srv pointer is still valid; (bso#11186). + s4: rpc: Refactor dcesrv_alter() function into setup and send steps; (bso#11236). + s3: smbd: Incorrect file size returned in the response of "FILE_SUPERSEDE Create"; (bso#11240). + Mangled names do not work with acl_xattr; (bso#11249). + nmbd rewrites browse.dat when not required; (bso#11254). + vfs_fruit: add option "nfs_aces" that controls the NFS ACEs stuff; (bso#11213). + s3:smbd: Add missing tevent_req_nterror; (bso#11224). + vfs: kernel_flock and named streams; (bso#11243). + vfs_gpfs: Error code path doesn't call END_PROFILE; (bso#11244). + s4: libcli/finddcs_cldap: continue processing CLDAP until all addresses are used; (bso#11284). + ctdb: check for talloc_asprintf() failure; (bso#11201). + spoolss: purge the printer name cache on name change; (bso#11210); (bnc#901813). + CTDB statd-callout does not scale; (bso#11204). + vfs_fruit: also map characters below 0x20; (bso#11221). + ctdb: Coverity fix for CID 1291643; (bso#11201). + Multiplexed RPC connections are not handled by DCERPC server; (bso#11225). + Fix terminate connection behavior for asynchronous endpoint with PUSH notification flavors; (bso#11226). + ctdb-scripts: Fix bashism in ctdbd_wrapper script; (bso#11007). + ctdb: Fix CIDs 1125615, 1125634, 1125613, 1288201 and 1125553; (bso#11201). + SMB2 should cancel pending NOTIFY calls with DELETE_PENDING if the directory is deleted; (bso#11257). + s3:winbindd: make sure we remove pending io requests before closing client sockets; (bso#11141); (bnc#931854). + Fix panic triggered by smbd_smb2_request_notify_done() -> smbXsrv_session_find_channel() in smbd; (bso#11182). + 'sharesec' output no longer matches input format; (bso#11237). + waf: Fix systemd detection; (bso#11200). + CTDB: Fix portability issues; (bso#11202). + CTDB: Fix some IPv6-related issues; (bso#11203). + CTDB statd-callout does not scale; (bso#11204). + 'net ads dns gethostbyname' crashes with an error in TALLOC_FREE if you enter invalid values; (bso#11234). + libads: record service ticket endtime for sealed ldap connections; (bso#11267). + lib/util: Include DEBUG macro in internal header files before samba_util.h; (bso#11033).- Avoid a crash inside the tevent epoll backend; (bso#11141); (bnc#931854).- Remove the independently built libraries ldb, talloc, tdn, and tevent and the post-10.3 renamed libsmbclient from baselibs.conf.- Drop redundant doc attribute from man pages.- Update to 4.2.1. + s3:winbind:grent: Don't stop group enumeration when a group has no gid; (bso#8905). + Initialize dwFlags field of DNS_RPC_NODE structure; (bso#9791). + s3: lib: ntlmssp: If NTLMSSP_NEGOTIATE_TARGET_INFO isn't set, cope with servers that don't send the 2 unused fields; (bso#10016). + build:wafadmin: Fix use of spaces instead of tabs; (bso#10476). + waf: Fix the build on openbsd; (bso#10476). + s3: client: "client use spnego principal = yes" code checks wrong name; (bso#10888). + spoolss: Retrieve published printer GUID if not in registry; (bso#11018). + s3: lib: libsmbclient: If reusing a server struct, check every cli->timout miliseconds if it's still valid before use; (bso#11079). + vfs_fruit: Enhance handling of malformed AppleDouble files; (bso#11125). + backupkey: Explicitly link to gnutls and gcrypt; (bso#11135). + replace: Remove superfluous check for gcrypt header; (bso#11135). + Backport subunit changes; (bso#11137). + libcli/auth: Match Declaration of netlogon_creds_cli_context_tmp with implementation; (bso#11140). + s3-winbind: Fix cached user group lookup of trusted domains; (bso#11143). + talloc: Version 2.1.2; (bso#11144). + Update libwbclient version to 0.12; (bso#11149). + brlock: Use 0 instead of empty initializer list; (bso#11153). + s4:auth/gensec_gssapi: Let gensec_gssapi_update() return NT_STATUS_LOGON_FAILURE for unknown errors; (bso#11164). + docs/idmap_rid: Remove deprecated base_rid from example; (bso#11169); (bnc#913304). + s3: libcli: smb1: Ensure we correctly finish a tevent req if the writev fails in the SMB1 case; (bso#11173). + backupkey: Use ndr_pull_struct_blob_all(); (bso#11174). + Fix lots of winbindd zombie processes on Solaris platform; (bso#11175). + s3: libsmbclient: Add missing talloc stackframe; (bso#11177). + s4-process_model: Do not close random fds while forking; (bso#11180). + s3-passdb: Fix 'force user' with winbind default domain; (bso#11185).- Prevent samba package updates from disabling samba kerberos printing.- Add sparse file support for samba; (fate#318424).- Purge printer name cache on spoolss SetPrinter change; (bso#11210); (bnc#901813).- Correctly retain errno from Btrfs snapshot ioctls; (bnc#923374).- Simplify libxslt build requirement and README.SUSE install. - Remove no longer required cleanup steps while populating the build root.- Remove deprecated base_rid example from idmap_rid manpage; (bso#11169); (bnc#913304).- Update to 4.2.0. + smbd: Stop using vfs_Chdir after SMB_VFS_DISCONNECT; (bso#1115). + pam_winbind: fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Make 'profiles' work again; (bso#9629). + s3:smb2_server: protect against integer wrap with "smb2 max credits = 65535"; (bso#9702). + Make validate_ldb of String(Generalized-Time) accept millisecond format ".000Z"; (bso#9810). + Use -R linker flag on Solaris, not -rpath; (bso#10112). + vfs: Add glusterfs manpage; (bso#10240). + Make 'smbclient' use cached creds; (bso#10279). + pdb: Fix build issues with shared modules; (bso#10355). + s4-dns: Add support for BIND 9.10; (bso#10620). + idmap: Return the correct id type to *id_to_sid methods; (bso#10720). + printing/cups: Pack requested-attributes with IPP_TAG_KEYWORD; (bso#10808). + Don't build vfs_snapper on FreeBSD; (bso#10834). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3: smb2cli: query info return length check was reversed; (bso#10848). + s3: lib, s3: modules: Fix compilation on Solaris; (bso#10849). + lib: uid_wrapper: Fix setgroups and syscall detection on a system without native uid_wrapper library; (bso#10851). + winbind3: Fix pwent variable substitution; (bso#10852). + Improve samba-regedit; (bso#10859). + registry: Don't leave dangling transactions; (bso#10860). + Fix build of socket_wrapper on systems without SO_PROTOCOL; (bso#10861). + build: Do not install 'texpect' binary anymore; (bso#10862). + Fix testparm to show hidden share defaults; (bso#10864). + libcli/smb: Fix smb2cli_validate_negotiate_info with min=PROTOCOL_NT1 max=PROTOCOL_SMB2_02; (bso#10866). + Integrate CTDB into top-level Samba build; (bso#10892). + samba-tool group add: Add option '--nis-domain' and '--gid'; (bso#10895). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + Fix smbclient loops doing a directory listing against Mac OS X 10 server with a non-wildcard path; (bso#10904). + Fix print job enumeration; (bso#10905); (bnc#898031). + samba-tool: Create NIS enabled users and unixHomeDirectory attribute; (bso#10909). + Add support for SMB2 leases; (bso#10911). + btrfs: Don't leak opened directory handle; (bso#10918). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: fix keytab array NULL termination; (bso#10933). + s3:passdb: fix logic in pdb_set_pw_history(); (bso#10940). + Cleanup add_string_to_array and usage; (bso#10942). + dbwrap_ctdb: Pass on mutex flags to tdb_open; (bso#10942). + Fix RootDSE search with extended dn control; (bso#10949). + Fix 'samba-tool dns serverinfo ' for IPv6; (bso#10952). + libcli/smb: only force signing of smb2 session setups when binding a new session; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + socket_wrapper: Add missing prototype check for eventfd; (bso#10965). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + vfs_streams_xattr: Check stream type; (bso#10971). + s3: smbd: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + vfs_fruit: Add support for AAPL; (bso#10983). + Fix spoolss IDL response marshalling when returning error without clearing info; (bso#10984). + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279). + Fix IPv6 support in CTDB; (bso#10996). + ctdb-daemon: Use correct tdb flags when enabling robust mutex support; (bso#11000). + vfs_streams_xattr: Add missing call to SMB_VFS_NEXT_CONNECT; (bso#11005). + s3-util: Fix authentication with long hostnames; (bso#11008). + ctdb-build: Fix build without xsltproc; (bso#11014). + packaging: Include CTDB man pages in the tarball; (bso#11014). + pdb_get_trusteddom_pw() fails with non valid UTF16 random passwords; (bso#11016). + Make Sharepoint search show user documents; (bso#11022). + nss_wrapper: check for nss.h; (bso#11026). + Enable mutexes in gencache_notrans.tdb; (bso#11032). + tdb_wrap: Make mutexes easier to use; (bso#11032). + lib/util: Avoid collision which alread defined consumer DEBUG macro; (bso#11033). + winbind: Retry after SESSION_EXPIRED error in ping-dc; (bso#11034). + s3-libads: Fix a possible segfault in kerberos_fetch_pac(); (bso#11037). + vfs_fruit: Fix base_fsp name conversion; (bso#11039). + vfs_fruit: mmap under FreeBSD needs PROT_READ; (bso#11040). + Fix authentication using Kerberos (not AD); (bso#11044). + net: Fix sam addgroupmem; (bso#11051). + vfs_snapper: Correctly handles multi-byte DBus strings; (bso#11055); (bnc#913238). + cli_connect_nb_send: Don't segfault on host == NULL; (bso#11058). + utils: Fix 'net time' segfault; (bso#11058). + libsmb: Provide authinfo domain for encrypted session referrals; (bso#11059). + s3-pam_smbpass: Fix memory leak in pam_sm_authenticate(); (bso#11066). + vfs_glusterfs: Add comments to the pipe(2) code; (bso#11069). + vfs/glusterfs: Change xattr key to match gluster key; (bso#11069). + vfs_glusterfs: Implement AIO support; (bso#11069). + s3-vfs: Fix developer build of vfs_ceph module; (bso#11070). + s3: netlogon: Ensure we don't call talloc_free on an uninitialized pointer; (bso#11077); CVE-2015-0240; (bnc#917376). + vfs: Add a brief vfs_ceph manpage; (bso#11088). + s3: smbclient: Allinfo leaves the file handle open; (bso#11094). + Fix Win8.1 Credentials Manager issue after KB2992611 on Samba domain; (bso#11097). + debug: Set close-on-exec for the main log file FD; (bso#11100). + s3: smbd: leases - losen paranoia check. Stat opens can grant leases; (bso#11102). + s3: smbd: SMB2 close. If a file has delete on close, store the return info before deleting; (bso#11104). + doc:man:vfs_glusterfs: improve the configuration section; (bso#11117). + snprintf: Try to support %j; (bso#11119). + ctdb-io: Do not use sys_write to write to client sockets; (bso#11124). + doc-xml: Add 'sharesec' reference to 'access based share enum'; (bso#11127).- Update to 4.2.0rc5. + Ensure we don't call talloc_free on an uninitialized pointer; CVE-2015-0240; (bso#11077); (bnc#917376).- Fix usage of freed memory on server exit; (bso#11218); (bnc#919309).- Fix tdb_store_flag_to_ntdb() gcc5 build failure.- Fix vfs_snapper DBus string handling; (bso#11055); (bnc#913238).- Update to 4.1.16. + dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl; (bso#10993); CVE-2014-8143; (boo#914279).- Adjust baselibs.conf due to libpdb0 package rename to libsamba-passdb0.- Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals; (bso#10123); (fate#316512). + Set domain/workgroup based on authentication callback value; (bso#11059).- Update to 4.2.0rc4. - Add libsamba-debug, libsocket-blocking, libsamba-cluster-support, and libhttp to the libs package; (boo#913547). - Rename libpdb packages to libsamba-passdb. - Drop libsmbsharemodes packages.- Enable avahi support on post-12.2 systems.- Update to 4.1.15. + pam_winbind: Fix warn_pwd_expire implementation; (bso#9056). + nsswitch: Fix soname of linux nss_*.so.2 modules; (bso#9299). + Fix profiles tool; (bso#9629). + s3-lib: Do not require a password with --use-ccache; (bso#10279). + s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control; (bso#10949). + s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses; (bso#10952). + s3:smb2_server: Allow reauthentication without signing; (bso#10958). + s3-smbclient: Return success if we listed the shares; (bso#10960). + s3-smbstatus: Fix exit code of profile output; (bso#10961). + libcli: SMB2: Pure SMB2-only negprot fix to make us behave as a Windows client does; (bso#10966). + s3: smbd/modules: Fix *allocate* calls to follow POSIX error return convention; (bso#10982). + Fix 'domain join' by adding 'drsuapi.DsBindInfoFallBack' attribute 'supported_extensions'; (bso#11006). + idl:drsuapi: Manage all possible lengths of drsuapi_DsBindInfo; (bso#11006). + winbind: Retry LogonControl RPC in ping-dc after session expiration; (bso#11034).- yast2-samba-client should be able to specify osName and osVer on AD domain join; (bnc#873922).- Lookup FSRVP share snums at runtime rather than storing them persistently; (bnc#908627).- Specify soft dependency for network-online.target in Winbind systemd service file; (bnc#889175).- Fix spoolss error response marshalling; (bso#10984).- Update to 4.1.14. + pidl/wscript: Remove --with-perl-* options; revert buildtools/wafadmin/ Tools/perl.py back to upstream state; (bso#10472). + s4-dns: Add support for BIND 9.10; (bso#10620). + nmbd fails to accept "--piddir" option; (bso#10711). + nss_winbind: Add getgroupmembership for FreeBSD; (bso#10835). + S3: source3/smbd/process.c::srv_send_smb() returns true on the error path; (bso#10880). + vfs_glusterfs: Remove "integer fd" code and store the glfs pointers; (bso#10889). + s3-nmbd: Fix netbios name truncation; (bso#10896). + spoolss: Fix handling of bad EnumJobs levels; (bso#10898). + s3: libsmbclient-smb2. MacOSX 10 SMB2 server doesn't set STATUS_NO_MORE_FILES when handed a non-wildcard path; (bso#10904). + spoolss: Fix jobid in level 3 EnumJobs response; (bso#10905). + s3: nmbd: Ensure NetBIOS names are only 15 characters stored; (bso#10920). + s3:smbd: Fix file corruption using "write cache size != 0"; (bso#10921). + pdb_tdb: Fix a TALLOC/SAFE_FREE mixup; (bso#10932). + s3-keytab: Fix keytab array NULL termination; (bso#10933). + Cleanup add_string_to_array and usage; (bso#10942).- Remove and cleanup shares and registry state associated with externally deleted snaphots exposed as shadow copies; (bnc#876312).- Use the upstream tar ball, as signature verification is now able to handle compressed archives.- Fix leak when closing file descriptor returned from dirfd; (bso#10918).- Fix spoolss EnumJobs and GetJob responses; (bso#10905); (bnc#898031). + Fix handling of bad EnumJobs levels; (bso#10898).- Remove dependency on gpg-offline as signature checking is implemented in the source validator.- Update to 4.1.13. + s3-libnet: Add libnet_join_get_machine_spns(); (bso#9984). + s3-libnet: Make sure we do not overwrite precreated SPNs; (bso#9984). + s3-libads: Add all machine account principals to the keytab; (bso#9985). + s3: winbindd: Old NT Domain code sets struct winbind_domain->alt_name to be NULL. Ensure this is safe with modern AD-DCs; (bso#10717). + Fix unstrcpy; (bso#10735). + pthreadpool: Slightly serialize jobs; (bso#10779). + s3: smbd: streams - Ensure share mode validation ignores internal opens (op_mid == 0); (bso#10797). + s3: smbd:open_file: Open logic fix; Use a more natural check; (bso#10809). + vfs_media_harmony: Fix a crash bug; (bso#10813). + docs: Mention incompatibility between kernel oplocks and streams_xattr; (bso#10814). + nmbd: Send waiting status to systemd; (bso#10816). + libcli: Fix a segfault calling smbXcli_req_set_pending() on NULL; (bso#10817). + nsswitch: Skip groups we were not able to map; (bso#10824). + s3-winbindd: Use correct realm for trusted domains in idmap child; (bso#10826). + s3: nmbd: Ensure the main nmbd process doesn't create zombies; (bso#10830). + s3: lib: Signal handling - ensure smbrun and change password code save and restore existing SIGCHLD handlers; (bso#10831). + idmap_rfc2307: Fix a crash after connection problem to DC; (bso#10837). + s3-winbindd: Do not use domain SID from LookupSids for Sids2UnixIDs call; (bso#10838). + s3: smb2cli: Query info return length check was reversed; (bso#10848). + registry: Don't leave dangling transactions; (bso#10860).- Update to 4.2.0rc2.- Rebase File Server Remote VSS Protocol (FSRVP) server against 4.2.0rc1; (fate#313346).- Backport upstream master fixes for samba-regedit; (bnc#896536).- BuildRequire python-xml on SUSE systems only.- BuildRequire python-xml. - Exclude unwanted texpect binary and libhttp, libsamba-cluster-support, libsamba-debug, and libsocket-blocking shared libs. - Add vfs_fruit and vfs_worm man pages and ndr_dcerpc, smb2_lease_struct, tstream_smbXcli_np, idtree, and idtree_random header files. - Remove nmblookup and smbclient4 binary and nmblookup4 man page.- Update to 4.2.0rc1.- Fix small memory-leak in the background print process; (bnc#899558).- Modify samba-regedit so it displays correctly (related to ncurses). Changed code to use menu sub windows, seems to fix problems with display not refreshing; explicitly BuildRequire ncurses-devel; (bnc#896536).- Exclude unwanted libdnsserver_common and libdfs_server_ad shared libs and the man page of the unused findsmb script.- Skip groups that aren't mapped by idmap_ad; (bso#10824); (bnc#897969).- Update to 4.1.12. + s3: winbindd: On new client connect, prune idle or hung connections older than "winbind request timeout". Add new parameter "winbind request timeout". Please see smb.conf man page for details; (bso#3204); (bnc#872912). + Fix smbd crashes when filename contains non-ascii character; (bso#10716). + s4-rpc: dnsserver: Handle updates of tombstoned dnsNode objects; (bso#10749). + passdb: Fix NT_STATUS_NO_SUCH_GROUP; (bso#9570). + s4:setup/dns_update_list: make use of the new substitution variables; (bso#9831). + build: Fix configure to honour '--without-dmapi'; (bso#10369). + provision: Correctly provision the SOA record minimum TTL; (bso#10466). + s3: Enforce a positive allocation_file_size for non-empty files; (bso#10543). + lib: tevent: make TEVENT_SIG_INCREMENT atomic; (bso#10640). + Make "case sensitive = True" option working with "max protocol = SMB2" or higher in large directories; (bso#10650). + Samba 4 consuming a lot of CPU when re-reading printcap info; (bso#10652). + lib: strings: Simplify strcasecmp; (bso#10716). + Allow netr_ServerReqChallenge() and netr_ServerAuthenticate3() on different connections; (bso#10723). + 'net time': Fix usage and core dump; (bso#10728). + sys_poll_intr: Fix timeout arithmetic; (bso#10731). + s3:idmap: Don't log missing range config if range checking not requested; (bso#10737). + Fix flapping VFS gpfs offline bit; (bso#10741). + s4-rpc: dnsserver: Allow . to be specified for @ record; (bso#10742). + s4-rpc: dnsserver: return DNS_RANK_NS_GLUE recors when explicitly asked for; (bso#10751). + samba: Retain case sensitivity of cifs client; (bso#10755). + lib: Remove unused nstrcpy; (bso#10758). + Fix a memory leak in cli_set_mntpoint(); (bso#10759). + docs: Fix typos in smb.conf (inherit acls); (bso#10761). + libcli/security: Add better detection of SECINFO_[UN]PROTECTED_[D|S]ACL in get_sec_info(); (bso#10773). + s3: smbd: POSIX ACLs. Remove incorrect check for SECINFO_PROTECTED_DACL in incoming security_information flags in posix_get_nt_acl_common(); (bso#10773). + Don't discard result of checking grouptype; (bso#10777). + s3:libsmb: Set a max charge for SMB2 connections; (bso#10778). + smbd: Properly initialize mangle_hash; (bso#10782). + dosmode: Fix FSCTL_SET_SPARSE request validation; (bso#10787). + vfs_dirsort: Fix an off-by-one error that can cause uninitialized memory read; (bso#10794).- Wait for network-online.target to prevent caching of pre-network failures; (bnc#889175).- Use domain name if search by domain SID fails to send SIDHistory lookups to correct idmap backend; (bnc#773464).- Prune idle or hung connections older than "winbind request timeout"; (bso#3204); (bnc#872912).- fix FSCTL_SET_SPARSE request validation; (bso#10787); (bnc#893774).- Remove pre-11.2 patch which by default uses the smbpasswd passdb backend.- build: disable mmap on s390 systems; (bso#10765); (bnc#886193); (bnc#882356).- Create the cups smb backend as sym link pointing to smbspool; (bnc#891220).- Fix winbind service parameter usage; (bnc#890005).- lib/param: change the default for "winbind expand groups" to "0"; (bnc#890008).- Update to 4.1.11. + A malicious browser can send packets that may overwrite the heap of the target nmbd NetBIOS name services daemon; CVE-2014-3560; (bnc#889429).- Fix "net time" segfault; (bso#10728); (bnc#889539).- Update to 4.1.10. + net/doc: Make clear that net vampire is for NT4 domains only; (bso#3263). + dbcheck: Add check and test for various invalid userParameters values; (bso#8077). + s4:dsdb/samldb: Don't allow 'userParameters' to be modified over LDAP for now; (bso#8077). + Simple use case results in "no talloc stackframe around, leaking memory" error; (bso#8449). + s4:dsdb/repl_meta_data: Make sure objectGUID can't be deleted; (bso#9763). + dsdb: Always store and return the userParameters as a array of LE 16-bit values; (bso#10130). + s4:repl_meta_data: fix array assignment in replmd_process_linked_attribute(); (bso#10294). + ldb-samba: fix a memory leak in ldif_canonicalise_objectCategory(); (bso#10469). + dbchecker: Verify and fix broken dn values; (bso#10536). + dsdb: Rename private_data to rootdse_private_data in rootdse; (bso#10582). + s3: libsmbclient: Work around bugs in SLES cifsd and Apple smbx SMB1 servers; (bso#10587). + Fix "PANIC: assert failed at ../source3/smbd/open.c(1582): ret"; (bso#10593). + rid_array used before status checked - segmentation fault due to null pointer dereference; (bso#10627). + Samba won't start on a machine configured with only IPv4; (bso#10653). + msg_channel: Fix a 100% CPU loop; (bso#10663). + s3: smbd: Prevent file truncation on an open that fails with share mode violation; (bso#10671); (bnc#884056). + s3: SMB2: Fix leak of blocking lock records in the database; (bso#10673). + samba-tool: Add --site parameter to provision command; (bso#10674). + smbstatus: Fix an uninitialized variable; (bso#10680). + SMB1 blocking locks can fail notification on unlock, causing client timeout; (bso#10684). + s3: smbd: Locking, fix off-by one calculation in brl_pending_overlap(); (bso#10685). + 'RW2' smbtorture test fails when -N is set to 2 due to the invalid status check in the second client; (bso#10687). + wbcCredentialCache fails if challenge_blob is not first; (bso#10692). + Backport ldb-1.1.17 + changes from master; (bso#10693). + Fix SEGV from improperly formed SUBSTRING/PRESENCE filter; (bso#10693). + ldb: Add a env variable to disable RTLD_DEEPBIND; (bso#10693). + ldb: Do not build libldb-cmdline when using system ldb; (bso#10693). + ldb: Fix 1138330 Dereference null return value, fix CIDs 241329, 240798, 1034791, 1034792 1034910, 1034910); (bso#10693). + ldb: make the successful ldb_transaction_start() message clearer; (bso#10693). + ldb:pyldb: Add some more helper functions for LdbDn; (bso#10693). + ldb: Use of NULL pointer bugfix; (bso#10693). + lib/ldb: Fix compiler warnings; (bso#10693). + pyldb: Decrement ref counters on py_results and quiet warnings; (bso#10693). + s4-openldap: Remove use of talloc_reference in ldb_map_outbound.c; (bso#10693). + dsdb: Return NO_SUCH_OBJECT if a basedn is a deleted object; (bso#10694). + s4:dsdb/extended_dn_in: Don't force DSDB_SEARCH_SHOW_RECYCLED; (bso#10694). + Backport autobuild/selftest fixes from master; (bso#10696). + Backport drs-crackname fixes from master; (bso#10698). + smbd: Avoid double-free in get_print_db_byname; (bso#10699). + Backport access check related fixes from master; (bso#10700). + Backport provision fixes from master; (bso#10703). + s3:smb2_read: let smb2_sendfile_send_data() behave like send_file_readX(); (bso#10706). + s3: Fix missing braces in nfs4_acls.c.- Reduce printer_list.tdb lock contention during printcap update; (bso#10652); (bnc#883870). + Only update the printer share inventory when needed.- Add missing newline to debug message in daemon_ready(); (bnc#865627).- BuildRequire systemd-devel, configure --with-systemd, and modify the service files accordingly on post-12.2 systems; (bso#10517); (bnc#865627).- Prevent file truncation on an open that fails with share mode violation; (bso#10671); (bnc#884056).- Update to 4.1.9. + Fix nmbd denial of service; CVE-2014-0244; (bnc#880962). + Fix segmentation fault in smbd_marshall_dir_entry()'s SMB_FIND_FILE_UNIX handler; CVE-2014-3493; (bnc#883758).- BuildRequire krb5-devel, libiniparser-devel, and python-devel in any case.- BuildRequire libxslt and perl-ExtUtils-MakeMaker and BuildIgnore libtevent on CentOS, Fedora, and RHEL systems.- Update to 4.1.8. + dns: Don't reply to replies; CVE-2014-0239; (bso#10609). + Malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response; CVE-2014-0178; (bso#10549). + s3: smb2: Fix 'xcopy /d' with samba shares; (bso#3124). + Extra ':' in msg for Waf Cross Compile Build System with Cross-answers command; (bso#10151). + s3: nmbd: Reset debug settings after reading config file; (bso#10239). + Fix empty body in if-statement in continue_domain_open_lookup; (bso#10348). + script/autobuild: Make use of '--with-perl-{arch,lib}-install-dir'; (bso#10472). + wafsamba: Fix the installation on FreeBSD; (bso#10472). + Use exit_daemon() to communicate status of startup to systemd; (bso#10517). + Fix adding NetApps; (bso#10524). + s3: lib/util: Fix logic inside set_namearray loops; (bso#10544). + s3: lib/util: set_namearray reads across end of namelist; (bso#10544). + idmap_autorid: Fix failure in reverse lookup if ID is from domain range index #0; (bso#10547). + build: Fix ordering problems with lib-provided and internal RPATHs; (bso#10548). + Fix read of deleted memory in reply_writeclose()'; (bso#10554). + lib-util: Rename memdup to smb_memdup and fix all callers; (bso#10556). + Fix lock order violation and file lost; (bso#10564). + dsdb: Do checks for invalid renames in samldb, before repl_meta_data; (bso#10569). + Fix wildcard unlink to fail if we get an error rather than trying to continue; (bso#10577). + byteorder: Do not assume PowerPC is big-endian; (bso#10590). + printing: Fix purge of all print jobs; (bso#10612).- examples/libsmbclient: avoid some compiler warnings; (bso#10624).- Fix printer job purging; (bso#10612); (bnc#879390).- Update samba-pubkey_6568B7EA.asc which will expire 2016-01-17.- Fix byte-order macros on little endian Power8; (bso#10590); (bnc#871701).- Pass through vfs_btrfs snapshot manipulation requests when "btrfs: manipulate snapshots = no" is configured; (bnc#874180).- Clone the base share security descriptor when exposing a snapshot share; (bnc#874656).- Use appropriate HRESULT return codes; (bnc#875046).- Update to 4.1.7. + Make "force user" work as expected; (bso#9878). + Fix build on AIX with IBM XL C/C++ (gettext detection issues); (bso#9911). + Fix problem with server taking too long to respond to a MSG_PRINTER_DRVUPGRADE message; (bso#9942). + s3-printing: Fix obvious memory leak in printer_list_get_printer(); (bso#9993). + doc: Add "spoolss: architecture" parameter usage; (bso#10188). + Make 'smbclient' support DFS shares with SMB2/3; (bso#10200). + Make (lib)smbclient work with NetApp; (bso#10230). + SessionLogoff on a signed connection with an outstanding notify request crashes smbd; (bso#10344). + dfs: Always call create_conn_struct with root privileges; (bso#10378). + 'net ads search' on high latency networks can return a partial list with no error indication; (bso#10387). + max xmit > 64kb leads to segmentation fault; (bso#10422). + Fix STATUS_NO_MEMORY response from Query File Posix Lock request; (bso#10431). + Increase max netbios name components; (bso#10439). + smbd_server_connection_terminate("CTDB_SRVID_RELEASE_IP") panics from within ctdbd_migrate() with invalid lock_order; (bso#10444). + Fix 'wbinfo -i' with one-way trust; (bso#10458). + samba4 services not binding on IPv6 addresses causing connection delays; (bso#10464). + s3-vfs: Fix stream_depot vfs module on btrfs; (bso#10467). + Don't respond with NXDOMAIN to records that exist with another type; (bso#10471). + pidl: waf should have an option for the dir to install perl files and do not glob; (bso#10472). + s3-spoolssd: Don't register spoolssd if epmd is not running; (bso#10474). + s3-rpc_server: Fix handling of fragmented rpc requests; (bso#10481). + Initial FSRVP rpcclient requests fail with NT_STATUS_PIPE_NOT_AVAILABLE; (bso#10484). + lsa.idl: Define lsa.ForestTrustCollisionInfo and ForestTrustCollisionRecord as public structs; (bso#10504). + Make 'smbreadline' build with readline 6.3; (bso#10506). + smbd: Correctly add remote users into local groups; (bso#10508). + rpcclient FSRVP request UNCs should include a trailing backslash; (bso#10521). + Cleanup messages.tdb record after unclean smbd shutdown; (bso#10534). + s3:rpc_server: Minor refactoring of process_request_pdu().- Create a new DBus connection for every vfs_snapper request, to ensure correct snapper UID detection; (bnc#866354).- Fix "Invalid read" in method reply_writeclose; (bso#10554); (bnc#873658).- Fix minor compiler warnings in snapshot code-path; (bnc#873177).- Remove references to the obsolete samba-krb-printing package and get_printing_ticket binary.- Fix malformed FSCTL_SRV_ENUMERATE_SNAPSHOTS response; CVE-2014-0178; (bso#10549); (bnc#872396).- User error strings instead of hex codes where possible for FSRVP errors; (bnc#866927).- Fix remote share shadow copy request UNCs; (bso#10521); (bnc#870957).- Add krb5rcache directory to the winbind package; (bnc#870607). - Cleanup and consolidate the sysconfig and systemd service files.- Extend vfs_snapper man page to cover permissions; (bnc#870570).- Fix RPC server handling of fragmented requests; (bso#10481); (bnc#869707).- Default with the cache and lock directory to the same path to have both non-persistent and persistent data at one location; (bnc#846586).- Depend only on %version with all manual Provides and Requires; (bnc#844307).- Update to 4.1.6. + Password lockout not enforced for SAMR password changes; CVE-2013-4496; (bnc#849224). + smbcacls can remove a file or directory ACL by mistake; CVE-2013-6442; (bnc#855866).- Password lockout not enforced for SAMR password changes; CVE-2013-4496; (bnc#849224).- Call update-apparmor-samba-profile via ExecStartPre too; (bnc#867665).- samba4 smbcalcs --chown | --chgrp dacl regression; CVE-2013-6442; (bnc#855866).- Retry named pipe open requests on STATUS_PIPE_NOT_AVAILABLE; (bso#10484); (bnc#865095).- Propagate snapshot enumeration permissions errors to SMB clients; (bnc#865641).- Properly handle empty 'requires_membership_of' entries in /etc/security/pam_winbind.conf; (bnc#865771).- Fix problem with server taking too long to respond to a MSG_PRINTER_DRVUPGRADE message; (bso#9942); (bnc#863748). - Fix memory leak in printer_list_get_printer(); (bso#9993); (bnc#865561).- Fix stream_depot VFS module on Btrfs; (bso#10467); (bnc#865397).- Use libarchive to provide improved smbclient tarmode functionality; (bso#9667); (bnc#861135).- Depend on %version-%release with all manual Provides and Requires; (bnc#844307).- Update to 4.1.5. + Fix 100% CPU utilization in winbindd when trying to free memory in winbindd_reinit_after_fork; (bso#10358); (bnc#786677). + smbd: Fix memory overwrites; (bso#10415). + s3-winbind: Improve performance of wb_fill_pwent_sid2uid_done(); (bso#2191). + ntlm_auth sometimes returns the wrong username to mod_ntlm_auth_winbind; (bso#10087). + s3: smbpasswd: Fix crashes on invalid input; (bso#10320). + s3: vfs_dirsort module: Allow dirsort to work when multiple simultaneous directories are open; (bso#10406). + Add support for Heimdal's unified krb5 and hdb plugin system, cope with first element in hdb_method having a different name in different heimdal versions and fix INTERNAL ERROR: Signal 11 in the kdc pid; (bso#10418). + vfs_btrfs: Fix incorrect zero length server-side copy request handling; (bso#10424). + s3: modules: streaminfo: As we have no VFS function SMB_VFS_LLISTXATTR we can't cope with a symlink when lp_posix_pathnames() is true; (bso#10429). + smbd: Fix an ancient oplock bug; (bso#10436). + Fix crash bug in smb2_notify code; (bso#10442).- Remove superfluous obsoletes *-64bit in the ifarch ppc64 case; (bnc#437293).- Migrate @GMT token parsing functionality into vfs_snapper; (bnc#863079). + Improve vfs_snapper documentation.- Fix Winbind 100% CPU utilization caused by domain list corruption; (bso#10358); (bnc#786677).- Fix memory overwrite in FSCTL_VALIDATE_NEGOTIATE_INFO handler; (bso#10415); (bnc#862370).- Streamline the vendor suffix handling and add support for SLE 12.- Fix zero length server-side copy request handling; (bso#10424); (bnc#862558).- Set the PID directory to /run/samba on post-12.2 systems.- Make use of the tmpfilesdir macro while calling systemd-tmpfiles.- Make winbindd print the interface version when it gets an INTERFACE_VERSION request; (bnc#726937).- Fix vfs_btrfs build on older platforms with duplicate WRITE_FLUSH definitions; (bnc#860832).- Check for NULL gensec_security in gensec_security_by_auth_type(); (bnc#860809).- Ensure ndr table initialization; (bnc#860648).- Add File Server Remote VSS Protocol (FSRVP) server for SMB share shadow-copies; (fate#313346).- s3-dir: Fix the DOS clients against 64-bit smbd's; (bso#2662). - shadow_copy2: module "Previous Version" not working in Windows 7; (bso#10259). - s3-passdb: Fix string duplication to pointers; (bso#10367). - vfs/glusterfs: in case atime is not passed, set it to the current atime; (bso#10384)- s3: winbindd: Move calling setup_domain_child() into add_trusted_domain(); (bso#10358); (bnc#786677).- Default sysconfig daemon options to -D; (bso#10388); (bnc#857454).- Add /var/cache/samba to the client file list; (bnc#846586).- Really add the WINBINDDOPTIONS sysconfig variable on install; (bnc#857454).- Correct sysconfig variable names by adding the missing D char; (bnc#857454).- Update to 4.1.4. + Fix segfault in smbd; (bso#10284). + Fix SMB2 server panic when a smb2 brlock times out; (bso#10311).- Call stop_on_removal from preun and restart_on_update and insserv_cleanup from postun on pre-12.3 systems only; (bnc#857454).- BuildRequire gamin-devel instead of unmaintained fam-devel package on post-12.1 systems.- smbd: allow updates on directory write times on open handles; (bso#9870). - lib/util: use proper include for struct stat; (bso#10276). - s3:winbindd fix use of uninitialized variables; (bso#10280). - s3-winbindd: Fix DEBUG statement in winbind_msg_offline(); (bso#10285). - s3-lib: Fix %G substitution for domain users in smbd; (bso#10286). - smbd: Always use UCF_PREP_CREATEFILE for filename_convert calls to resolve a path for open; (bso#10297). - smb2_server processing overhead; (bso#10298). - ldb: bad if test in ldb_comparison_fold(); (bso#10305). - Fix AIO with SMB2 and locks; (bso#10310). - smbd: Fix a panic when a smb2 brlock times out; (bso#10311). - vfs_glusterfs: Enable per client log file; (bso#10337).- Add /etc/sysconfig/samba to the main and winbind package; (bnc#857454).- Create /var/run/samba with systemd-tmpfiles on post-12.2 systems; (bnc#856759).- Fix broken rc{nmb,smb,winbind} sym links which should point to the service binary on post-12.2 systems; (bnc#856759).- Add Snapper VFS module for snapshot manipulation; (fate#313347). + dbus-1-devel required at build time.- Add File Server Remote VSS Protocol (FSRVP) client for SMB share shadow-copies; (fate#313345).- Do not BuildRequire perl ExtUtils::MakeMaker and Parse::Yapp as they're part of the minimum build environment.- Update to 4.1.3. + DCE-RPC fragment length field is incorrectly checked; CVE-2013-4408; (bnc#844720). + pam_winbind login without require_membership_of restrictions; CVE-2012-6150; (bnc#853347).- Make use of the full gpg pub key file name including the key ID.- Add transparent file compression support; (fate#316266). + Implement FSCTL_GET_COMPRESSION and FSCTL_SET_COMPRESSION handlers. + Add FILE_ATTRIBUTE_COMPRESSED and FILE_NO_COMPRESSION support. + Extend vfs_btrfs VFS module to utilize get/set compression hooks.- Add support for FSCTL_SRV_COPYCHUNK_WRITE; (fate#314770).- Remove bogus libsmbclient0 package description and cleanup the libsmbclient line from baselibs.conf; (bnc#853021).- BuildRequire systemd on post-12.2 systems.- Update to 4.1.2. + s4-dns: dlz_bind9: Create dns-HOSTNAME account disabled; (bso#9091). + dfs_server: Use dsdb_search_one to catch 0 results as well as NO_SUCH_OBJECT errors; (bso#10052). + Missing talloc_free can leak stackframe in error path; (bso#10187). + Fix memset used with constant zero length parameter; (bso#10190). + s4:dsdb/rootdse: report 'dnsHostName' instead of 'dNSHostName'; (bso#10193). + Make offline logon cache updating for cross child domain group membership; (bso#10194). + nsswitch: Fix short writes in winbind_write_sock; (bso#10195). + RW Deny for a specific user is not overriding RW Allow for a group; (bso#10196). + vfs_glusterfs: Fix excessive debug output from vfs_gluster_open(); (bso#10224). + vfs_glusterfs: Implement proper mashalling/unmarshalling of ACLs; (bso#10224). + VFS plugin was sending the actual size of the volume instead of the total number of block units because of which windows was getting the wrong volume capacity; (bso#10224). + libcli/smb: Fix smb2cli_ioctl*() against Windows 2008; (bso#10232). + xattr: Fix listing EAs on *BSD for non-root users; (bso#10247). + Fix the build of vfs_glusterfs; (bso#10253). + s3-winbindd: Fix cache_traverse_validate_fn failure for NDR cache entries; (bso#10264). + util: Remove 32bit macros breaking strict aliasing; (bso#10269).- Let gpg verify execution condition not fail on non SUSE systems.- Add systemd support for post-12.2 systems.- Allow smbcacls to take a '--propagate-inheritance' flag to indicate that the add, delete, modify and set operations now support automatic propagation of inheritable ACE(s); (FATE#316474).- Unconditionally create the CUPS smb backend sym link pointing to smbspool; (bnc#850656).- Update to 4.1.1. + ACLs are not checked on opening an alternate data stream on a file or directory; CVE-2013-4475; (bso#10229); (bnc#848101). + Private key in key.pem world readable; CVE-2013-4476; (bnc#848103).- Private key in key.pem world readable; CVE-2013-4476; (bnc#848103).- ACLs are not checked on opening an alternate data stream on a file or directory; CVE-2013-4475; (bso#10229); (bnc#848101).- Update to 4.1.0. + pam_winbindd: Support the KEYRING ccache type; (bso#10132). + Fix PAC parsing failure; (bso#10178).- Unify the defattr lines in the pidl, python, test and test-devel files section by removing the optional directory mode.- Verify source tar ball gpg signature.- Update to 4.1.0rc4. + dsdb: Convert the full string from UTF16 to UTF8, including embedded NULLs; (bso#8077). + python-samba-tool fsmo: Do not give an error on a successful role transfer; (bso#9461). + dbwrap_ctdb: Treat empty records as non-existing; (bso#10008). + Raise the level of a debug when unable to open a printer; (bso#10118). + Add "acl allow execute always" parameter; (bso#10134). + vfs_shadow_copy2: Display previous versions correctly over SMB2; (bso#10137). + smbd: Always clean up share modes after hard crash; (bso#10138). + Valid utf8 filenames cause "invalid conversion error" messages; (bso#10139). + libcli/smb: Use SMB1 MID=0 for the initial Negprot; (bso#10144). + Samba SMB2 client code reads the wrong short name length in a directory listing reply; (bso#10145). + libcli/smb: Only check the SMB2 session setup signature if required and valid; (bso#10146). + Better document potential implications of a globally used "valid users"; (bso#10147). + cli_smb2_get_ea_list_path() failed to close file on exit; (bso#10149). + Not all OEM servers support the ALTNAME info level; (bso#10150). + Regression causes replication failure with Windows 2008R2 and deletes Deleted Objects; (bso#10157). + Netbios related samba process consumes 100% CPU; (bso#10158). + Fix POSIX ACL mapping when setting DENY ACE's from Windows; (bso#10162).- Require libndr-standard-devel due to gen_ndr/lsa.h from libpdb-devel.- Add libdcerpc0, libdcerpc-atsvc0, libdcerpc-binding0, libdcerpc-samr0, libgensec0, libndr0, libndr-krb5pac0, libndr-nbt0, libndr-standard0, libpdb0, libregistry0, libsamba-credentials0, libsamba-hostconfig0, libsamba-policy0, libsamba-util0, libsamdb0, libsmbclient-raw0, libsmbconf0, libsmbldap0, and libtevent-util0 to baselibs.conf.- Add or polish the shared library package summaries and descriptions.- Update to 4.1.0rc3. + Fix working on site with Read Only Domain Controller; (bso#5917). + Add man page for vfs_syncops; (bso#7364). + Add man page for vfs_linux_xfs_sgid; (bso#7490). + When replicating DNS for bind9_dlz we need to create the server-DNS account remotely; (bso#9091). + Winbind unable to retrieve user information from AD; (bso#9615). + winbind_lookup_names() fails because of NT_STATUS_CANT_ACCESS_DOMAIN_INFO; (bso#9899). + Build Samba 4.0.x on AIX with IBM XL C/C++; (bso#9911). + Add SMB2 and SMB3 support for smbclient; (bso#9974). + Add man pages for ntdb tools; (bso#10000). + Add man page for samba-regedit tool; (bso#10001). + ::1 added to nameserver on join; (bso#10030). + Fix memory leak in source3/lib/util.c:1493; (bso#10063). + Fix segmentation fault in 'net ads join'; (bso#10073). + Fix variable list in vfs_crossrename man page; (bso#10076). + s3-winbind: Fix a segfault passing NULL to a fstring argument; (bso#10082). + smbd: Fix async echo handler forking; (bso#10086). + MacOSX 10.9 will not follow path-based DFS referrals handed out by Samba; (bso#10097). + Honour output buffer length set by the client for SMB2 GetInfo requests; (bso#10106). + Fix Winbind crashes on DC with trusted AD domains; (bso#10107). + Handle Dropbox (write-only-directory) case correctly in pathname lookup; (bso#10114). + Masks incorrectly applied to UNIX extension permission changes; (bso#10121).- Implement shared library packaging guidelines. - Correct interpackage dependencies; (bso#10129).- Define the source URL differently in the case of a release candidate.- Update to 4.1.0rc2. + Add vfs_btrfs module. + Add support for server-side copy operations via the SMB2 FSCTL_SRV_COPYCHUNK request. + Fix replication with --domain-crictical-only to fill in backlinks; (bso#9029). + Windows 8 Roaming profiles fail; (bso#9678). + Fix crash of winbind after "ls -l /usr/local/samba/var/locks/sysvol"; (bso#9820). + Windows error 0x800700FE when copying files with xattr names containing ":"; (bso#9992). + Do not delete an existing valid credential cache (s3-winbind); (bso#9994). + Fix segfault while reading incomplete session info; (bso#10003). + Missing integer wrap protection in EA list reading can cause server to loop with DOS (CVE-2013-4124); (bso#10010). + Fix a 100% loop at shutdown time (smbd); (bso#10013). + Fix/improve debug options; (bso#10015). + Rename regedit to samba-regedit; (bso#10040). + Remove obsolete swat manpage and references; (bso#10041). + Fix crashes in socket_get_local_addr(); (bso#10042). + Allow to change the default location for Kerberos credential caches; (bso#10043). + Remove a redundant inlined substitution of ACLs; (bso#10045). + nsswitch: Add OPT_KRB5CCNAME to avoid an error message; (bso#10048). + dsdb improvements; (bso#10056). + Linux kernel oplock breaks can miss signals; (bso#10064).- BuildRequire pyldb-devel.- Add libnetapi0 and samba-libs to baselibs.conf.- Update to 4.0.9. + Fix crash of Winbind after "ls -l /usr/local/samba/var/locks/sysvol"; (bso#9820). + s3-lib: Fix segmentation fault while reading incomplete session info; (bso#10003). + smbd: Fix a 100% loop at shutdown time; (bso#10013). + Windows 8 Roaming profiles fail; (bso#9678). + Add UPN enumeration to passdb internal API; (bso#9779). + smbd: Cleanup disonnected durable handles; (bso#9930). + vfs_streams_xattr: Do not attempt to write empty attribute twice; (bso#9970). + Fix Windows error 0x800700FE when copying files with xattr names containing ":"; (bso#9992). + s3-winbind: Do not delete an existing valid credential cache; (bso#9994). + Fix excessive RID allocation; (bso#10014). + Add debugclass for DNS server; (bso#10015). + Fix/improve debug options; (bso#10015). + Allow to change the default location for Kerberos credential caches; (bso#10043). + Linux kernel oplock breaks can miss signals; (bso#10064). + net ads join: Fix segmentation fault in create_local_private_krb5_conf_for_domain; (bso#10073).- Update to 4.0.8. + Samba 3.0.x to 4.0.7 are affected by a denial of service attack on authenticated or guest connections; CVE-2013-4124; (bnc#829969).- Require krb5 and not the non existing krb5-libs package.- Update to 4.1.0rc1. + Directory database replication (AD DC mode) + Server-Side Copy Support + Btrfs Filesystem Integration- BuildRequire perl ExtUtils::MakeMaker and Parse::Yapp. - BuildRequire libxslt, libxslt1, or libxslt-tools depending on SUSE version. - Require perl-base on SUSE systems only.- Adjust group setting of the test-devel subpackage. - Require perl-base from the pidl subpackage.- Remove libdir/samba/ldb after install if we're building Samba without Active Directory Domain Controller support.- Remove unused ccache switch from the spec file.- BuildRequire docbook-xsl-stylesheets and libxslt-tools to build the man pages and add them to the package again.- Build from the package from the top level directory; (bnc#794744). - BuildRequire pytalloc-devel, python-tdb, and python-tevent. - Also use out of tree builds of talloc, tdb, tevent, and ldb for pre-12.1 SUSE systems.- Remove the empty data dir from the doc package filelist. - Explicitly use samba instead of the name macro to define the docbook dir.- Update to 4.0.7. + Fix a core dump with invalid lock order while opening/editing or copying MS files; (bso#9794). + Fix crash bug from search of mail=; (bso#9967). + s3-rpc_server: Ensure we are root when starting and using gensec; (bso#9465). + Add support for MX queries; (bso#9485). + dns: Delete dnsNode objects when they are empty; (bso#9559). + dns: Support larger queries when asking forwarder; (bso#9632). + s3:lib/server_mutex: Open mutex.tdb with CLEAR_IF_FIRST; (bso#9805). + Use of wrong RFC2307 primary group field; (bso#9880). + Check for system libtevent; (bso#9881). + is_printer_published GUID retrieval; (bso#9900). + Doc fixes for 4.0; (bso#9906). + Build fixes for 4.0 found during autoconf or debian packaging work; (bso#9907). + build: Add missing new line to replaced python shebang line; (bso#9909). + PIE builds not supported; (bso#9910). + s4:winbind: Don't leak libnet_context into the main event context; (bso#9929). + Fix a bug of drvupgrade of smbcontrol; (bso#9941). + Check for netbios aliases in ad_get_referrals; (bso#9947). + Fix tevent_poll on 32-bit machines (Coverity ID 989236); (bso#9953). + docs: Avoid mentioning a possibly misleading option; (bso#9964). + Fix build with system Heimdal of samba4kgetcred; (bso#9968).- Use SLE as product prefix for SUSE Linux Enterprise, oS for openSUSE, and OBS for any other operating system to define the vendor string while build.- Remove ldapsmb from the main spec file.- Adjust ldapsmb and nmbstatus man page syntax required by a newer pod2man.- Don't bzip2 the main tar ball, use the upstream gziped one instead.- Explicitly BuildRequire cyrus-sasl-devel, libattr-devel, and libopenssl-devel.- Fix libreplace license ambiguity; (bso#8997); (bnc#765270).- Update to 4.0.6. + Fix crash during Win8 sync; (bso#9822). + Fix segfault when loging in with wrong password from w2k8r2; (bso#9834). + Fix the username map optimization; (bso#9139). + Add support for PFC_FLAG_OBJECT_UUID when parsing packets; (bso#9382). + SMB2 server doesn't support recvfile; (bso#9412). + Fix the build of vfs_notify_fam; (bso#9545). + Fix adding case sensitive spn; (bso#9699). + Properly handle oplock breaks in compound requests; (bso#9722). + Properly handle oplock breaks in compound requests; (bso#9722). + Cache name_to_sid/sid_to_name correctly; (bso#9766). + Fix 'net ads join' when called via stdin; (bso#9767). + Fix segfault for "artificial" conn_structs in vfs_fake_perms; (bso#9775). + vfs_dirsort uses non-stackable calls, dirfd(), malloc instead of talloc and doesn't cope with directories being modified whilst reading; (bso#9777). + Fix panic when running 'smbtorture smb.base'; (bso#9782). + Use specified python for runtime installation of Samba; (bso#9785). + Change '--with-dmapi' to 'default=auto' to match the autoconf build; (bso#9803). + wafsamba: Display the default value in help for SAMBA3_ADD_OPTION; (bso#9804). + wbinfo: Fix segfault in wbinfo_pam_logon; (bso#9807). + Package new dbwrap_tool man page; (bso#9809). + Old DOS SMB CTEMP request uses a non-VFS function to access the filesystem; (bso#9811). + Fix 'map untrusted to domain' with NTLMv2; (bso#9817). + SMB signing and the async echo responder don't work together; (bso#9824). + Fix panic in nt_printer_publish_ads; (bso#9830). + talloc use after free in winbind4; (bso#9832). + Function called in unix_convert() path can overwrite errno; (bso#9833). + Fix NULL pointer dereference in Winbind; (bso#9854). + Fix making LIBNDR_PREG_OBJ; (bso#9868).- Remove disabled and anyhow obsoleted net-report and net_rpc_migrate patches.- Update to 4.0.5. + Fix large reads/writes from some Linux clients; (bso#9706). + Add 'samba-tool dbcheck --reset-well-known-acls'; (bso#9740). + Can't delegate adding computers to domain; (bso#9267). + Fix GNU ld version detection with old gcc releases; (bso#7825). + Never try to map global SAM name; (bso#9039). + Certain xattrs cause Windows error 0x800700FF; (bso#9130). + Samba returns unexpected error on SMB posix open; (bso#9519). + Fix build on AIX; (bso#9557). + libnss-winbindd does not provide pass struct for groups mapped with ID_TYPE_BOTH and vice versa; (bso#9617). + Reauth-capable client fails to access shares on Windows member; (bso#9625). + PIDL: Fix parsing linemarkers in preprocessor output; (bso#9636). + Rename internal subsystem pdb_ldap to pdb_ldapsam; (bso#9639). + Fix the build of vfs_afsacl; (bso#9642). + Fix the build with --fake-kaserver; (bso#9643). + Fix compile of source3/lib/afs.c; (bso#9644). + Make SMB2_GETINFO multi-volume aware; (bso#9646). + idmap_autorid: Fix freeing of non-talloced memory; (bso#9653). + Work around FreeBSD's getaddrinfo() underscore issue; (bso#9656). + 'make test' hangs; (bso#9663). + Fix correct linking of libreplace with cmdline-credentials; (bso#9664). + Fix filtering of link-local addresses; (bso#9666). + Fix crash in 'net rpc join' against a Samba 3.0.33 PDC; (bso#9669). + Samba denies owner Read Control when there is a DENY entry while W2K08 does not; (bso#9674). + Fix several resource (fd) leaks; (bso#9683). + Fix a memory leak in spoolss rpc server; (bso#9685). + Fix a possible buffer overrun in pdb_smbpasswd; (bso#9686). + Fix several possible null pointer dereferences; (bso#9687). + Make sure that domain joins work correctly when the DC disallows NTLM auth; (bso#9689). + Backport tevent changes to bring library to version 0.9.18; (bso#9695). + Remove incomplete samba_dnsupdate IPv6 link-local address check; (bso#9696). + DsReplicaGetInfo fails due to sendto() EMSGSIZE error on UNIX domain socket; (bso#9697). + Fix vfs_catia and update documentation; (bso#9701); (bnc#824833). + Fix build on solaris8: Do not force a specific perl on pod2man; (bso#9703). + Fix nss_winbind name on FreeBSD; (bso#9704). + s4:winbindd: Do not drop the workgroup name in the getgrnam, getgrent and getgrgid calls; (bso#9711). + Set LD_LIBRARY_PATH in install_with_python.sh; (bso#9717). + s4-idmap: Remove requirement that posixAccount or posixGroup be set for rfc2307; (bso#9718). + Allow forcing an override of an old @MODULES record; (bso#9719). + Do not print the admin password during 'samba-tool classicupgrade'; (bso#9720). + Make samba_upgradedns more robust (do not guess addresses when just changing roles); (bso#9721). + Add a tool to migrate latin1 printing tdbs to registry; (bso#9723). + is_encrypted_packet() function incorrectly used inside server; (bso#9724). + upgradeprovision and 'samba-tool dbcheck' patches for 4.0.NEXT; (bso#9725). + Fix NULL pointer dereference; (bso#9727). + DO NOT install samba_upgradeprovision in 4.0.x; (bso#9728). + Fix 'smbcontrol close-share'; (bso#9733). + Fix Winbind separator in upn to username conversion; (bso#9735). + Change to smbd/dir.c code gives significant performance increases on large directory listings; (bso#9736). + PIDL: Build fixes for hosts without CPP (Solaris 11); (bso#9739). + Make sure that we only propogate the INHERITED flag when we are allowed to; (bso#9747). + Remove unneeded fstat system call from hot read path; (bso#9748). + Don't leak the epm_Map policy handle; (bso#9758). + Fix incorrect parsing of SMB2 command codes; (bso#9760). - Update to 4.0.4. + Remove forced set of 'create mask' to 0777; CVE-2013-1863; (bnc#809624).- Fix periodic printcap cache reloads; (bso#9650); (bnc#807334).- No longer use the cifs- or smbfstab named configuration file on post-12.2 systems; (bnc#804822); (bnc#821889).- Shift the smbfs init script nfs dependency from Required to Should.- Fix SMB1 Session Setup AndX handling with a large krb PAC; (bso#9658); (bnc#802031).- Point LD_LIBRARY_PATH to the just-built libraries while calling testparm to generate the default share snippets on pre-12.2 systems.- Explicitly configure --with-ads.- Fix smbclient recursive mget EPERM handling; (bso#9633); (bnc#786350).- Remove superfluous quotation marks while setting the SAMBA_VERSION_VENDOR_SUFFIX string.- Do not restart the smbfs service on pre-11.3 systems during dhcp lease renewal when the IP address remains the same; (bnc#800782).- Update to 4.0.3. + Fix ACL problem with delegation of privileges and deletion of accounts over LDAP interface; add documentation; (bso##8909). + check_password_quality: Handle non-ASCII characters properly; (bso##9105). + Fix 'smbd' panic triggered by unlink after open; (bso##9571). + smbd: Fix memleak in the async echo handler; (bso##9549). + defer_open is triggered multiple times on the same request; (bso#9196). + Add extra attributes for AD printer publishing; (bso#9378). + FSMO seize of naming role fails: NT_STATUS_IO_TIMEOUT; (bso#9461). + Downgrade v4 printer driver requests to v3; (bso#9474). + samba_upgradeprovision: fix the nTSecurityDescriptor on more containers; (bso#9481). + s3:smb2_negprot: set the 'remote_proto' value; (bso#9499). + waf assumes that pythonX.Y-config is a Python script; (bso#9503). + s4:drsuapi: Make sure we report the meta data from the cycle start; (bso#9508). + wafsamba: Use additional xml catalog file; (bso#9512). + samba_dnsupdate: Set KRB5_CONFIG for nsupdate command; (bso#9517). + conn->share_access appears not be be reset between users; (bso#9518). + Remove superfluous bracket in samba.8.xml; (bso#9528). + Fix typo in vfs_tsmsm.8.xml; (bso#9530). + terminate the irpc_servers_byname() result with server_id_set_disconnected(); (bso#9540). + Make use of posix_openpt; (bso#9541). + Fix build of vfs_commit and plug in async pwrite support; (bso#9544). + Fix aio_suspend detection on FreeBSD; (bso#9546). + Correctly detect O_DIRECT; (bso#9548). + sigprocmask does not work on FreeBSD to stop further signals in a signal handler; (bso#9550). + smb.conf(5): Update list of available protocols; (bso#9552). + s4-resolve: Fix parsing of IPv6/AAAA in dns_lookup; (bso#9555). + Fix compilation of Solaris ACL module; (bso#9564). + Adding additional Samba 4.0 DC to W2k8 srv AD domain (in win200 functional level) produces dbcheck errors; (bso#9565). + Add dbwrap_tool.1 manual page; (bso#9568). + Document the command line options in dbwrap_tool(1); (bso#9568). + ntlm_auth(1): Fix format and make examples visible; (bso#9569). + Fix file corruption during SMB1 read by Mac OSX 10.8.2 clients; (bso#9572). + Fix a possible null pointer dereference in spoolss; (bso#9574). + Duplicate flags defined in the winbindd protocol; (bso#9575). + gensec: Allow login without a PAC by default; (bso#9581). + smbd: disk_free: sys_popen() failed" message logged in /var/log/message many times; (bso#9586). + Archive flag is always set on directories; (bso#9587). + ACLs are not inherited to directories for DFS shares; (bso#9588). + Correct meta data in ldb manpages; (bso#9591). + s3-winbind: Fix the build of idmap_ldap; (bso#9595). + Linked attribute handling should be by GUID; (bso#9596). + Fix timeouts of some IRPC calls; (bso#9598). + Use pid,task_id as cluster_id in process_single just like process_prefork; (bso#9598). + Add 'ldbdump' tool; general code and documentation cleanup; (bso#9609). + dsdb: Make secrets_tdb_sync cope with -H secrets.ldb; (bso#9610).- Update to 4.0.2. + Address SWAT security issues CVE-2013-0213 and CVE-2013-0214 which both don't apply to any SUSE Samba post-3.6.10 as it isn't longer built. + Don't build and package static libraries.- Drop separate build-source-timestamp file as it led to a second, incorrect Source Timestamp line.- Add server-side copy support; (fate#314770). + Implement FSCTL_SRV_COPYCHUNK and FSCTL_SRV_REQUEST_RESUME_KEY handlers. + Add vfs_btrfs VFS module for optimized Btrfs clone-range ioctl usage.- Add filter against shlib-policy-name-error for /lib*/libnss_wins.so.2.- Disable SWAT during configure and don't package it any longer.- Remove dangling references to Heimdal from the spec file.- Remove /lib/samba prefix from the localstatedir configure option.- Update to 4.0.1. + Samba 4.0.0 as an AD DC may provide authenticated users with write access to LDAP directory objects; CVE-2013-0172; (bnc#798364).- Add the missing get_printing_ticket binary path while calling the set_permissions macro; (bnc#783375).- Use the version macro while definition of the branch macro.- Remove references to no longer used devel macros.- Update to 4.0.0. + Honor password complexity settings; (bso#9414). + Install SWAT *.msg files with waf; (bso#9415). + Fix netr_ServerPasswordSet2, netr_LogonSamLogon with netlogon AES; (bso#9438). + developer-build: Fix panic when acl_xattr fails with access denied; (bso#9456). + Fix "map username script" with "security=ads" and Winbind; (bso#9457). + Install manpages only if we install the target; (bso#9459). + Respond correctly to FILE_STREAM_INFO requests; (bso#9460). + Users can not be given write permissions any more by default; (bso#9462). + Fix MMC crashes; (bso#9470). + Fix SEGV when using second vfs module; (bso#9471). + Support FIPS mode when building Samba; (bso#9479). + Fix ACL on "cn=partitions,cn=configuration"; (bso#9481).- netr_ServerPasswordSet2, netr_LogonSamLogon with netlogon AES broken; (bso#9438). - s3:auth: fix create_token_from_sid() to not fail in the winbindd case; (bso#9457). - s4:dsdb/acl_read: return the nTSecurityDescriptor attr if the sd_flags control is given; (bso#9470). - Support FIPS mode when building Samba; (bso#9479). - s4:provision: set the correct nTSecurityDescriptor; (bso#9481).- SEGV when using second vfs module; (bso#9471).- Update to 3.6.10. + Respond correctly to FILE_STREAM_INFO requests; (bso#9460). + Fix segfault when "default devmode" is disabled; (bso#9433). + Fix segfaults in "log level = 10" on Solaris; (bso#9390).- s3:smbd:vfs_acl: fix a PANIC when setting an ACL fails with ACCESS_DENIED; (bso#9456). - Install manpages only if we install the target; (bso#9459). - Users can not be given write permissions any more by default; (bso#9462).- Fix MD5 detection in the autoconf build; (bso#9037); (bso#9086); (bso#9094); (bso#9418). - Use work around for 'winbind use default domain' only if it is set; (bso#9367). - Allow smb2.acls torture test to pass against smbd with a POSIX ACLs backend; (bso#9374). - large read requests cause server to issue malformed reply; (bso#9422). - s3-rpc_client: lookup nametype 0x20 in rpc_pipe_open_tcp_port(); (bso#9426). - Fix ncacn_ip_tcp reconnection code for lsa lookups; (bso#9439). - Allow to force DNS updates using net; (bso#9451). - Respond correctly to FILE_STREAM_INFO requests; (bso#9460).- Update to 4.0.0rc6. See WHATSNEW.txt from the samba-doc package.- On uninstall remove winbind from the pam configuration, invalidate the nscd passwd and group cache and only recommend the install of nscd; (bnc#792340).- BuildRequire libnscd-devel once.- Remove obsoleted references to pre-9.4 SUSE systems; (bnc#792294). - Add SUSE version depending pkg-config requires macro; (bnc#792294).- Define library names and use it instead of libldb1, libnetapi0, libsmbclient0, libsmbsharemodes0, libtalloc2, libtdb1, libtevent0, and libwbclient0; (bnc#792294). - Provide and obsolete libsmbsharemodes for post-10.3 SUSE systems.- Don't clutter the spec file diff view; (bnc#783384).- Fix fd leak causing 100% CPU in winbind on certain dc connection failures; (bso#9436); (bnc#786677).- Fix spoolss segfault when default devmode is disabled; (bso#9433); (bnc#791183).- Update to 4.0.0rc5. See WHATSNEW.txt from the samba-doc package.- ACL masks incorrectly applied when setting ACLs; (bso#9236). - s3-kerberos: also try with AES keys, when decrypting tickets; (bso#9272). - lib/replace: replace all *printf function if we replace snprintf; (bso#9390). - lib/addns: don't depend on the order in resp->answers[]; (bso#9402).- s4:torture/smb2: improve the smb2.create.blob tes; (bso#9209). - lib/krb5_wrap: request enc_types in the correct order; (bso#9272). - Fix net ads join message for the dns domain; (bso#9326). - docs-xml: fix use of tag; (bso#9345). - s3-aio_pthread: Optimize aio_pthread_handle_completion; (bso#9359). - s3:winbind: Failover if netlogon pipe is not available; (bso#9386).- Execute the run_permissions macro on pre-11.4 systems and else the set_permission one if available.- Ensure adding the winbind group never can fail.- Create ntadmin group only if it doesn't yet exist.- Update to 3.6.9. + When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). + Winbind can't fetch user or group info from AD via LDAP; (bso#9147). + Fix segfault in smbd if user specified ports out for range; (bso#9218).- quota: Don't force the block size to 512; (bso#3272). - Fix poll replacement to become a msleep replacement; (bso#8107). - Fix wrong test == syntax in configure; (bso#8146). - Fix --with(out)-sendfile-support option handling in autoconf; (bso#8344). - Fix builtin forms order to match Windows again; (bso#8632). - Fix RAW printing for normal users; (bso#8769); (bnc#790741). - Initialise ticket to ensure we do not invalid memory; (bso#8788). - Fix 'net rpc share allowedusers' to work with 2008r2; (bso#8966). - Fix crash on null pam change pw response; (bso#9013). - Connection to outbound trusted domain goes offline; (bso#9016). - Increase debug level for info that the db is empty; (bso#9112). - 'smbclient' can't connect to a Windows 7 server using NTLMv2; (bso#9117). - Winbind can't fetch user or group info from AD via LDAP; (bso#9147). - Open printers with the right access mask; (bso#9154). - Fix makerpms.sh on RHEL; (bso#9165). - Remove non-existent option '-Y' from winbindd manpage; (bso#9171). - Add quota support for gfs2; (bso#9172). - Make SMB2 compound request create/delete_on_close/close work as Windows; (bso#9173). - Empty SPNEGO packet can cause smbd to crash; (bso#9174). - pam_winbind: Match more return codes when wbcGetPwnam has failed; (bso#9177). - Fix crash bug in idmap_hash; (bso#9188); (bnc#788159). - SMB2 Create doesn't return correct MAX ACCESS access mask in blob; (bso#9189). - Fix service control for non-internal services; (bso#9192). - Don't take 'state->te' as indication for "was_deferred"; (bso#9196). - Parse of invalid SMB2 create blob can cause smbd crash; (bso#9209). - Bad ASN.1 NegTokenInit packet can cause invalid free; (bso#9213). - Fix segfault in smbd if user specified ports out for range; (bso#9218). - Signing cannot be disabled for SMB2 by design, so fix the documentation instead; (bso#9222). - Fix NT_STATUS_IO_TIMEOUT during slow import of printers into registry; (bso#9231). - When setting a non-default ACL, don't forget to apply masks to SMB_ACL_USER and SMB_ACL_GROUP entries; (bso#9236). - lib-addns: ensure that allocated buffer are pre set to 0; (bso#9259). - Make tdb robust against shrinking tdbs and improper CLEAR_IF_FIRST restart; (bso#9268). - Add support for reloading systemd services; (bso#9280).- Warn via the smbd log if AppArmor and "wide links" are in use; (bnc#783719).- Do not write the build date into the header of the default smb.conf as this causses superfluous rebuilds of packages depending on samba; (bnc#781601).- Do not prerequire SuSEconfig.permissions as it's already enough and more generic to depend on the permissions package; (bnc#782293).- Update to 3.6.8. + Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). + Fix Winbind panic if we couldn't find the domain; (bso#9135).- Backport FSCTL codes and fix segfault in smbstatus from master; (bso#9058). - Fix bad call to memcpy source3/registry/regfio.c; (bso#9065). - "Domain Users" incorrectly added as additional group on domain members; (bso#9066). - Use correct RID for "Domain Guests" primary group; (bso#9067). - Fix crash bug in smbd caused by a blocking lock followed by close; (bso#9084). - Fix smbclient/tarmode panic when connecting to Windows 2000 clients; (bso#9088). - Fix refreshing of Kerberos tickets in Winbind; (bso#9098). - Fix identification of idle clients in Winbind to avoid crashes and NDR parsing errors; (bso#9104). - Fix compilation with newer MIT Kerberos which hides internal symbols; (bso#9111). - Fix flooding the logs with records we don't find in pcap; (bso#9112). - Initialize the print backend after we setup winreg; (bso#9122). - Fix lprng job tracking errors; (bso#9123). - Fix setting of "inherited" bit on inherited ACE's; (bso#9124). - Fix Winbind panic if we couldn't find the domain; (bso#9135). - Make 'smbclient allinfo' show the snapshot list; (bso#9137). - Fix nfs quota support with Linux nfs4 mounts; (bso#9144). - Valid open requests can cause smbd assert due to incorrect oplock handling on delete requests; (bso#9150).- NMB registration for a duplicate workstation fails with registration refuse; (bso#9085); (bnc#770056).- Remove backup files caused by running configure in examples/VFS.- Update to 3.6.7. + Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). + Fix migrating printers while upgrading from 3.5.x; (bso#9026).- Correct documentation of "case sensitive"; (bso#8552). - Printing fails in function cups_job_submit; (bso#8719). - Fix kernel oplocks when uid(file) != uid(process); (bso#8974). - Send correct responses to NT Transact Secondary when no data and no params for the Trans2 calls are set; (bso#8989). - Fix build without ads support; (bso#8996). - Don't turn negative cache entries into valid idmappings; (bso#9002). - Fix posix acl on gpfs; (bso#9003). - Make vfs_gpfs less verbose in get/set_xattr functions; (bso#9022). - Fix migrating printers while upgrading from 3.5.x; (bso#9026). - Fix typo in set_re_uid() call when USE_SETRESUID selected in configure; (bso#9034). - Using asynchronous IO with SMB2 can return NT_STATUS_FILE_CLOSED in error instead ofNT_STATUS_FILE_LOCK_CONFLICT; (bso#9040). - Fix resolving our own "Domain Local" groups; (bso#9052); (bnc#779269). - Fix build against CUPS 1.6; (bso#9055). - Fix bugs in SMB2 credit handling code; (bso#9057). - rpcclient: Fix bad call to data_blob_const; (bso#9062).- Create missing doc directories while install. - Remove no longer existing Manifest file from install. - Don't creat a link to non existend html man pages for swat. - Don't call the no longer existing libsmbclient testsuit while build.- Configure with option --mandir instead --with-mandir. - Remove obsoleted --with-rootsbindir, --with-nmbdsocketdir, and - -with-swatdir configure options.- Update to 4.0.0beta4. See WHATSNEW.txt from the samba-doc package.- BuildRequire gcc, make, and patch; (bnc#771516).- ndr: fix push/pull DATA_BLOB with NDR_NOALIGN; (bso#9026); (bnc#770262).- Fix shell syntax in dhcpcd hook script; (bnc#769957).- Add missing int declaration to the net kdc lookup patch.- Update to 4.0.0beta2. See WHATSNEW.txt from the samba-doc package.- Update to 3.6.6. + Fix possible memory leaks in the Samba master process; (bso#8970). + Fix uninitialized memory read in talloc_free(); (bnc#764577). + Fix joining of XP Pro workstations to 3.6 DCs; (bso#8373); (bnc#787983).- resolve_ads() code can return zero addresses and miss valid DC IP addresses; (bso#8910). - Can't join XP Pro workstations to 3.6.1 DC; (bso#8373); (bnc#787983). - winbind can hang as nbt_getdc() has no timeout; (bso#8953). - Fix crash bug in dns_create_probe when dns_create_update fails; (bso#8627) - s3-pid: Catch with pid filename's change when config file is not smb.conf; (bso#8714). - Possible memory leaks in the main Samba process; (bso#8970). - s3: Fix uninitialized memory read in talloc_free(); (bnc#764577). - Treat exit_server_cleanly() as a "clean" shutdown; (bso#8971). - Avoid crash with MIT krb5 1.10.0 in gss_get_name_attribute(); (bso#8988). - Winzip occasionally can not read files out of an open winzip dialog; (bso#8311). - s3-winbindd: call dump_core_setup after command line option has been parsed; (bso#8975). - Directory group write permission bit is set if unix extensions are enabled; (bso#8972). - s3: remove dependency on automake for "make everything"; (bso#8978). - sd_has_inheritable_components segfaults on an SD that se_access_check accepts; (bso#8811). - smbclient's tarmode insists on listing excluded directories; (bso#8922). - Notify code can miss a ChDir; (bso#8998). - s3:smbd: add a fsp_persistent_id() function; (bso#8995).- Call autogen.sh even on post-12.1 SUSE systems.- Don't call autogen.sh on post-12.1 SUSE and post-14 Fedora systems. - Recompile all IDL in any case.- BuildIgnore libtalloc and libtdb to prevent a package conflict on Fedora systems.- Install talloc.pc only on pre-12.2 and non SUSE systems.- BuildRequire libldb-devel, libtalloc-devel, libtdb-devel, and libtevent-devel on post-12.1 systems.- s3: Fix a segfault with debug level 3 on Solaris; (bso#8861). - s3: wbinfo --lookup-sids "" crashes winbind; (bso#8904). - smbd crashes when deleting directory and veto files are enabled; (bso#8837). - winbind_krb5_locator only returns one IP address; (bso#8897). - Wrong assertion/comparison: Compare value not pointer; (bso#8859). - Inconsistent (with manpage) command-line switch for "help" in smbtree; (bso#8831). - Fix incorrect debug statement. - Setting traverse rights fails to enable directory traversal when acl_xattr in use; (bso#8857). - Syslog broken owing to mistyping of debug_settings.syslog; (bso#8877). - s3/ldap: remove outdated netscape ds 5 schema file; (bso#8869). - s3-docs: fixes several typos; (bso#7938). - s3-VFS: Fix building out-of-tree modules; (bso#8822). - s3-docs: Add hint that setting "profile acls = yes" on normal shares can cause trouble; (bso#7930). - s3-pam_winbind: Fix the build with a newer iniparser library; (bso#8915). - Avoid null dereference in initialize_password_db(); (bso#8920). - s3:registry: implement values_need_update and subkeys_need_update in the smbconf backend. - s3:registry:reg_api: fix reg_queryvalue to not fail when values are modified while it runs. - s4:torture:rpc:spoolss: also initialize driverName before checking it in test_PrinterData_DsSpooler(). - s3:registry: multiple cleanups, fixes, and optimisations. - s3:auth/server_info: the primary rid should be in the groups rid array; (bso#8798). - s3-printing: Add new printers to registry; (bso#8554); (bso#8612); (bso#8748). - Fix the overwriting of errno before use in a DEBUG statement and use the return value from store_acl_blob_fsp rather than ignoring it; (bso#8945). - s3-auth: Don't lookup the system user in pdb; (bso#8944). - s3-passdb: Fix negative SID->uid/gid cache handling; (bso#8952). - Fix typo in pam_winbindd code; (bso#8957). - Fix remove_duplicate_addrs2 previously it could leave zero addresses in the list; (bso#8910). - Slow but responsive DC can lock up winbindd; (bso#8943). - Broken processing of %U with vfs_full_audit when force user is set; (bso#8882).- Disable included build of ldb, talloc, tdb, and tevent on post-12.1 systems. - BuildRequire libldb1-devel, libtalloc2-devel, libtdb1-devel, and libtevent0-devel on post-12.1 systems.- Add PreReq /etc/init.d/nscd to the winbind package; (bnc#759731).- docs-xml: fix default name resolve order; (bso#7564). - s3-aio-fork: Fix a segfault in vfs_aio_fork; (bso#8836). - docs: remove whitespace in example samba.ldif; (bso#8789). - s3-smbd: move print_backend_init() behind init_system_info(); (bso#8845); (bnc#730769). - s3-docs: Prepend '/' to filename argument; (bso#8826).- Update to 3.6.5. - Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; (bnc#757576).- Remove all precompiled idl output to ensure any pidl changes take effect; (bnc#757080).- Update to 3.6.4. - Samba pre-3.6.4 are affected by a vulnerability that allows remote code exe- cution as the "root" user; PIDL based autogenerated code allows overwriting beyond of allocated array; CVE-2012-1182; (bso#8815); (bnc#752797).- s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; (bso#8599). - Correctly handle DENY ACEs when privileges apply; (bso#8797).- s3:smb2_server: fix a logic error, we should sign non guest sessions; (bso8749). - Allow vfs_aio_pthread to build as a static module; (bso#8723). - s3:dbwrap_ctdb: return the number of records in db_ctdb_traverse() for persistent dbs; (#bso8527). - s3: segfault in dom_sid_compare(bso#8567). - Honor SeTakeOwnershiPrivilege when client asks for SEC_STD_WRITE_OWNER; (bso#8768). - s3-winbindd: Close netlogon connection if the status returned by the NetrSamLogonEx call is timeout in the pam_auth_crap path; (bso#8771). - s3-winbindd: set the can_do_validation6 also for trusted domain; (bso#8599). - Fix problem when calculating the share security mask, take priviliges into account for the connecting user; (bso#8784).- Fix crash in dcerpc_lsa_lookup_sids_noalloc() with over 1000 groups; (bso#8807); (bnc#751454).- Remove obsoleted Authors lines from spec file for post-11.2 systems.- Make ldapsmb build with Fedora 15 and 16; (bso#8783). - BuildRequire libuuid-devel for post-11.0 and other systems. - Define missing python macros for non SUSE systems. - PreReq to fillup_prereq and insserv_prereq only on SUSE systems. - Always use cifstab instead of smbfstab on non SUSE systems.- Ensure AndX offsets are increasing strictly monotonically in pre-3.4 versions; CVE-2012-0870; (bnc#747934).- Add SERVERID_UNIQUE_ID_NOT_TO_VERIFY; (bso#8760); (bnc#741854).- s3-printing: fix crash in printer_list_set_printer(); (bso#8762); (bnc#746825).- s3:winbindd fix a return code check; (bso#8406).- s3: Add rmdir operation to streams_depot; (bso#8733).- s3:smbd:smb2: fix an assignment-instead-of-check bug conn_snum_used(); (bso#8738); CVE-2013-0454; (bnc#811975).- s3:auth: fill the sids array of the info3 in wbcAuthUserInfo_to_netr_SamInfo3(); (bso#8739).- s3:client: ignore SMBecho errors (the server may not support it); (bso#8139).- Be more strict when using PAM_AUTH API from winbind if Kerberos auth is enabled and don't unintentionally use a bogus domain name; (bso#8734).- smbclient fails with posix large reads; (bso#8727).- Use the smbfs init script on versions pre-11.3, or cifs in later versions; (bnc#744614).- s3: Compile IDL files in autogen, some configure tests need this.- Fixes various deadlocks in if-up.d / if-down.d when running under systemd; (bnc#732395).- Update to 3.6.3. + Fix memory leak in parent smbd on connection; CVE-2012-0817; (bso#8724); (bnc#743986).- Use spdx.org compliant license names for all packages.- Update to 3.6.2. + Make Winbind receive user/group information (bug #8371). + Several SMB2 fixes. + Fix a crash bug in the spoolss code. + Add new contributing FAQ announcing acceptance of corporate (C). + DeletePrinterDriverEx deletes files in use; (bso#4942); (bnc#742504). + Fix cli_write_and_x() against OS/2 print shares; (bso#5326). + Fix 'smbclient tar' for files greater than 8GB on BE machines; (bso#563); (bnc#726145). + Remove pointless use_memory_krb5_ccache; (bso#7465). + Fix perl path; (bso#8176). + Grant credits in async interim responses (SMB2); (bso#8357). + Make Winbind receive user/group information; (bso#8371). + Fix Windows XP clients crashing smbd process every once in a while; (bso#8384); (bnc#731571). + Make VFS op "streaminfo" stackable; (bso#8419). + Add an allocation pool to idmap_autorid; (bso#8444). + Fix SEGFAULT from net registry export on not zero terminated REG_SZ values; (bso#8528). + Make DSO_EXPORTS_CMD more portable; (bso#8531). + readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). + smbclient posix_open command fails to return correct info on open file; (bso#8542). + winbind_samlogon_retry_loop ignores logon_parameters flags; (bso#8548). + Fix setting the machine account password; (bso#8550). + Make SMB2 handle compound request headers in the same way as Windows; (bso#8560). + Password change settings not fully observed; (bso#8561). + Fix double free error in talloc; (bso#8562). + Fix alignment in the non-extended-security negprot; (bso#8573). + Add systemd service files; (bso#8575). + Add systemd service files; (bso#8575). + smb2_flush: Don't send uninitialized memory; (bso#8579). + Enable inotify if sys or kernel inotify is available; (bso#8580). + Increase a debug level; (bso#8585). + libsmb: Only align unicode pipe_name; (bso#8586). + Fix marshalling of samr_ChangePasswordUser3; (bso#8591). + Don't limit the number of open dptrs for SMB2; (bso#8592). + Fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). + Make cldap work over IPv6; (bso#8600). + Fix intermittent print job failures caused by character conversion errors; (bso#8606). + Improve configure.in so it can be used outside the Samba source tree; (bso#8607). + Winbind: Don't fail on users without a uid; (bso#8608). + Ensure we correctly calculate reply credits over all returned SMB2 replies; (bso#8614). + Fix migrate printer code; (bso#8618). + Fix crash bug when trying to browse Samba printers; (bso#8623). + libsmb: Don't duplicate Kerberos service tickets; (bso#8628). + POSIX ACE x permission becomes rx following mapping to and from a DACL; (bso#8631). + When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636). + Fix the vfs_commit module; (bso#8639). + Add an update function for Winbind cache; (bso#8643). + vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). + Document the "ignore system acls" option of vfs_acl_xattr and vfs_acl_tdb vfs modules; (bso#8652). + Fix deleting a symlink if the symlink target is outside of the share; (bso#8663). + Fix renaming a symlink if the symlink target is outside of the share; (bso#8664). + Fix NT ACL issue; (bso#8673). + Fix buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). + Fix Winbind segfault if we can't map the last user; (bso#8678). + recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). + Try ctdbd_init_connection() as root; (bso#8684). + Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686). + Fix typo in 'net memberships' usage; (bso#8687). + libads: Fix malloc/talloc mismatch in ads_keytab_verify_ticket(); (bso#8692). + Make DeletePrinterDriverEx remove printer driver files; (bso#8697) (bnc#740810). + Fix major leak with SMB2 in connections.tdb; (bso#8710).- s3-spoolss: Pass the right pointer type; (bso#4942); (bnc#742504).- Use correct license, LGPLv3+ for libwbclient packages.- When returning an ACL without SECINFO_DACL requested, we still set SEC_DESC_DACL_PRESENT in the type field; (bso#8636).- Fix incorrect types in the full_audit VFS module. Add null terminators to audit log enums; (bnc#742885).- Prefix print$ path on driver file deletion; (bso#8697); (bnc#740810). - Fix printer_driver_files_in_use() call ordering; (bso#4942); (bnc#742504).- Buffer overflow issue with AES encryption in samba traffic analyzer; (bso#8674). - NT ACL issue; (bso#8673). - Deleting a symlink fails if the symlink target is outside of the share; (bso#8663). - connections.tdb - major leak with SMB2; (bso#8710).- Renaming a symlink fails if the symlink target is outside of the share; (bso#8664).- Intermittent print job failures caused by character conversion errors; (bso#8606). - ads_keytab_verify_ticket mixes talloc allocation with malloc free; (bso#8692). - libcli/cldap: fix a crash bug in cldap_socket_recv_dgram(); (bso#8593). - s3:lib/ctdbd_conn: try ctdbd_init_connection() as root; (bso#8684). - s3-printing: fix migrate printer code; (bso#8618). - Packet validation checks can be done before length validation causing uninitialized memory read; (bso#8686).- net memberships usage info was wrong; (bso#8687). - s3-libsmb: Don't duplicate kerberos service tickets; (bso#8628). - Recvfile code path using splice() on Linux leaves data in the pipe on short write; (bso#8679). - s3-winbind: Fix segfault if we can't map the last user; (bso#8678). - vfs_acl_xattr and vfs_acl_tdb modules can fail to add inheritable entries on a directory with no stored ACL; (bso#8644). - s3/doc: document the ignore system acls option of vfs_acl_xattr and vfs_acl_tdb; (bso#8652). - Winbind can't receive any user/group information; (bso#8371). - s3-winbind: Add an update function for winbind cache; (bso#8643). - s3: Attempt to fix the vfs_commit module. - POSIX ACE x permission becomes rx following mapping to and from a DACL; (#bso#8631). - s3:libsmb: only align unicode pipe_name; (bso#8586). - s3-winbind: Don't fail on users without a uid; (bso#8608). - Crash when trying to browse samba printers; (bso#8623). - talloc: double free error; (bso#8562). - cldap doesn't work over ipv6; (bso#8600). - s3:libsmb: fix cli_write_and_x() against OS/2 print shares; (bso#5326). - SMB2: not granting credits for all requests in a compound request; (bso#8614). - smb2_flush sends uninitialized memory; (bso#8579). - Password change settings not fully observed; (bso#8561). - s3:smb2_server: grant credits in async interim responses; (bso#8357). - s3:smbd: don't limit the number of open dptrs for smb2; (bso#8592). - samr_ChangePasswordUser3 IDL incorrect; (bso#8591). - idmap_autorid does not have allocation pool; (bso#8444). - Add systemd service files. - s3:libsmb: the workgroup in the non-extended-security negprot is not aligned; (bso#8573). - s3-build: Fix inotify detection; (bso#8580). - SMB2 doesn't handle compound request headers in the same way as Windows; (#bso8560). - Disconnecting clients swamp the logs; (bso#8585). - s3-netlogon: Fix setting the machinge account password; (bso#8550). - winbind_samlogon_retry_loop ignores logon_parameters flags; (#bso8548). - smbclient posix_open command fails to return correct info on open file; (bso#8542). - readlink() on Linux clients fails if the symlink target is outside of the share; (bso#8541). - s3-netapi: remove pointless use_memory_krb5_ccache; (bso#7465). - s3:Makefile: make DSO_EXPORTS_CMD more portable; (bso#8531). - s3:registry: fix the test for a REG_SZ blob possibly being a zero terminated ucs2 string; (bso#8528). - Make VFS op "streaminfo" stackable; (bso#8419).- Fix incorrect perfcount array length calculations; (bnc#739258).- BuildRequire autoconf to avoid implicit dependency for post-11.4 systems.- Remove call to suse_update_config macro for post-11.4 systems.- Use samba.org for the ldapsmb source location.- Fixing libsmbsharemode dependency on ldap and krb5 libs in Makefile; (bnc #729516).- Do not map POSIX execute permission to Windows FILE_READ_ATTRIBUTES; (bso#8631); (bnc#732572).- Add ldap to Should-Start and Stop of the smb init script; (bnc#730046).- Fix smbd srv_spoolss_replycloseprinter() segfault; (bso#8384); (bnc#731571).- Fix pam_winbind.so segfault in pam_sm_authenticate(); (bso#8564).- Fix smbclient >8GB tars on big endian machines; (bso#563); (bnc#726145).- Fix typo in net ads join output; (bnc#713135).- Ignore a potentially missing AppArmor snippet helper script; (bnc#725256).- Update to 3.6.1. + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Several SMB2 fixes. + The VFS ACL modules are no longer experimental but production-ready. + Fix 'net ads join -k' when KRB5CCNAME is not set; (bso#7465). + smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509). + Return error of cli_push when 'put - /some/file' is used; (bso#7551). + Fix usage of cli_errstr(); (bso#7864). + Fix 'widelinks' regression; (bso#8229). + Empty notify servername; (bso#8236). + Add man vfs_aio_fork; (bso#8256). + smb2: smbd logs "Invalid SMB packet: first request: 0x0008" and crashes; (bso#8334). + Add a fallback for missing open&x support in MAC OS/X Lion; (bso#8338). + While migrating forms, don't fail if the form already exists; (bso#8351). + OS/2 sends an unexpected write&x/read&x chain; (bso#8360). + Fix build of vfs_prealloc on SLES8; (bso#8363). + Fix the build of gpfs.c on RHEL 6.0 with gpfs 3.4.0-4; (bso#8364). + Fix the fallback to the deprecated spelling idmap:script; (bso#8368). + Fix vfs_chown_fsp; (bso#8370). + Fix smbd crashes triggered by Windows XP clients; (bso#8384). + Fix smbclient access to NT4 shares; (bso#8385). + Optimize serverid_exists() for Solaris; (bso#8395). + registry/reg_format.c must include includes.h; (bso#8401). + SMB2 server can return requests out-of-order when processing a compound request; (bso#8407). + Fix a Winbind race leading to 100% CPU load; (bso#8409). + Fix "saving as" of MS Office 2007 (Word) documents on Samba shares with SMB2; (bso#8412). + Fix 'getent group' if trusted domains are not reachable; (bso#8420). + Fix infinite loop in ACL module code; (bso#8422). + Fix wrong reply to DHnC (durable handle reconnect); (bso#8428). + Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429). + Fix segfault in iconv.c; (bso#8433). + NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442). + Be smarter about setting default permissions when a ACL_USER_OBJ isn't given; (bso#8443). + Check the wct of the incoming SMBnegprot responses; (bso#8452). + Fix smbclient segfaults when dialect option -m is used for legacy dialects; (bso#8453). + Fix uninitialized memory problem in group_sids_to_info3; (bso#8455). + Samba PDC is looking up only primary user group; (bso#8455). + IE9 on Windows 7 cannot download files to samba 3.5.11 share; (bso#8458). + smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473). + SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474). + Don't call smbd_terminate_connection in smb2_validate_message_id(); (bso#8476). + Samba asserts when SMB2 client breaks the crediting rules; (bso#8476). + Map to guest can return uninitialized blob of data; (bso#8477). + acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480). + DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493). + Remove "experimental" label on VFS ACL modules; (bso#8494). + SMB2_OP_CANCEL requests don't have to be signed; (bso#8503). + smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507). + Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509). + Disallow "." in can_set_delete_on_close(); (bso#8515). + SMB2 create call returns incorrect file allocation size; (bso#8518). + Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520). + Winbind cache timeout expiry test was reversed; (bso#8521).- s3/doc: add man page for aio_fork vfs module.- Fix uninitialized memory problem in group_sids_to_info3; (bso#8455).- s3: Samba PDC is looking up only primary user group; (bso#8455).- Add script to create or update an AppArmor sniplet with permissions for all Samba shares; (bnc#688040).- Add "ldapsam:login cache" parameter to allow explicit disabling of the login cache; (bnc#723261).- Retain the smbd startproc return value for correct startup status reporting. unset was incorrectly being called prior to rc_status; (bnc#723724).- Prevent deadlock in systemd triggered by if-down.d handler on shutdown; (bnc#721598).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; changed defaults and documentation (bso8473).- Empty CIFS share can be blocked for other clients by deleting it via empty path (DELETE_PENDING until the last client); (bso#8515).- winbindd cache timeout expiry test was reversed; (bso#8521).- Fix SMB2 SMB2_OP_GETINFO and SMB2_OP_IOCTL parsing requirements; (bso#8520).- s3:smb2_create: fix allocation size return value when opening existing files; (bso#8518).- SMB2 create doesn't cope with an Apple client using NULL blob in create; (bso#8474).- NFSv4 DENY ACLs always include SYNCHRONIZE flag - blocking renames; (bso#8442).- s3-docs: Fix bug (bso#7908) and typo.- Return error of cli_push when 'put - /some/file' is used; (bso#7551).- Read-only handles on SAMR allow SAMR_DOMAIN_ACCESS_CREATE_USER; (bso#8509).- smbd doesn't correctly honor the "force create mode" bits from a cifsfs create; (bso#8507).- Default user entry is set to minimal permissions on incoming ACL change with no user specified; (bso#8443).- smb_acl_to_posix: ACL is invalid for set (Invalid argument); (bso#7509).- Handle the SECINFO_LABEL flag in the same was as Win2k3; enable Microsoft Internet Explorer 9 on Windows 7 to download files; (bso#8458).- DFS breaks zip file extracting unless "follow symlinks = no" set; (bso#8493).- s3-docs: Fix typos.- s3:smb2_server: SMB2_OP_CANCEL requests don't have to be signed; (bso#8503).- Remove "experimental" label on VFS ACL modules; (bso#8494).- acl_xattr can free an invalid pointer if no blob is loaded; (bso#8480).- s3-smbd: asserts when SMB2 client breaks the crediting rules; (bso#8476).- s3-libnet: allow to use default krb5 ccache in libnet_Join/libnet_Unjoin; (bso#7465).- smb2_find uses a hard coded max reply size of 0x10000 instead of smb2_max_trans; (bso#8473).- s3-netapi: allow to use default krb5 credential cache for libnetapi users.- s3-docs: document -k switch in net manpage.- Map to guest can return uninitialized blob of data; (bso#8477).- s3-registry: registry/reg_format.c must include includes.h; (bso#8401).- smbclient segfaults when option -m is used for legacy dialects; (bso#8453).- Fix 'widelinks' regression intro'd in 3.2; (bso#8229).- Compound SMB2 requests on an IPC connection can corrupt the reply stream; (bso#8429).- s3-spoolss: Fix bug forms migration; (bso#8351).- s3:libsmb: check the wct of the incoming SMBnegprot responses; (bso#8452).- s3: Do not fork the echo handler for smb2; (bso#8334).- s3-spoolss: Fix bug empty notify servername; (bso#8236).- SMB2 server can return requests out-of-order when processing a compound request; (bso#8407).- Remove smb child crash fix. The issue had been fixed upstream differently.- BuildRequire ctdb-devel version greater than 1.0.105 for post-10.0 systems.- Fix samba duplicates file content on appending. Move posix case semantics out from under the VFS; (bso#6898); (bnc#681208).- Make winbind child reconnect when remote end has closed, fix failing sudo; (bso#7295); (bnc#569721).- Spec file cleanup as suggested by the spec-cleaner tool. + Make all BuildRequires, PreReq, and Provides a separate line. + Use %{buildroot} instead of ${RPM_BUILD_ROOT}. + Use straight commands instead of macros (make, install). + Use -p in post and postun if we only call one command. + Use %{_localstatedir} instead of %{_var} in the filelist. + Remove superfluous AutoReqProv on lines.- Remove %release from all Provides.- Fix segfault in iconv.c which caused a null pointer dereference; (bso#8433).- Use /var/run for the cifs state file in the init script too; (bnc#710304).- Microsoft Word from Microsoft Office 2007 fails to save as on a share with SMB2; (bso#8412).- Use sys_write and sys_read in fork_domain_child to fix a winbind race leading to 100% CPU usage; (bso#8409).- Fix wrong reply to smb2 durable handle reconnect (DHnC) request; (bso#8428).- Fix infinite loop in ACL module code; (bso#8422).- Fix getent group if trusted domains are not reachable; (bso#8420).- smbclient can't access a NT4 share since 3.6.0; (bso#8385).- Optimize serverid_exists() for Solaris; (bso#8395).- talloc: + check block count after references test. + added test suite for talloc_free_children(). + license info erratum in the manpage. + fix typos and better differentiation between versions 1 and 2. + preserve context name on talloc_free_children(). + ensure the sibling linked list remains valid during a free.- vfs_chown_fsp returned in the wrong directory; (bso#8370).- Remove irritating "." targets when recent system libs exist; (bso#8369).- Correctly initialize "idmap config * : script" with NULL; (bso#8368).- Add missing include to suppress compiler warnings; (bso#8365).- Point the chain offset beyond the current request; (bso#8360).- Fix gpfs vfs module build; (bso#8364).- Make vfs_prealloc even build on older systems; (bso#8363).- Do central cli_set_error and return the actual NTSTATUS; (bso#7864).- Add a fallback for missing open&x support in OS/X Lion; (bso#8338).- Update to 3.6.0. + BUG 7462: Make SA_RESETHAND conditional on its existance. + BUG 8303: db_ctdb_send_schedule_for_deletion() is not defined. + BUG 8324: smbclient cannot list directories from a big-endian machine. + BUG 8326: WinXP cannot join a Samba3 domain with a 'even' hostname. + BUG 8327: Fix the reload of the configuration, also reload activated registry shares. + BUG 8328: Cleanup of idmap_tdb2 code. + BUG 8330: Fix NFSv4 ACL merging logic. + BUG 8335: File copy aborts with smb2_validate_message_id: bad message_id. + BUG 8341: Fix segfault in libsmbclient. + BUG 8343: Fix SMB2 crash reading with aio_fork beyond the end of file. + BUG 8347: Fix regression for HP-UX, AIX and OSF. + BUG 8357: Make sure we grant credits on async read/write operations. + BUG 8358: Fix a bug in run_poll_events(). + BUG 8362: Fix build issue on old glibc systems.- Remove references to disabled vscan build.- Add missing define, includes, and initialization to get_printing_ticket.- Use /var/run for the cifs state file; (bnc#710304).- Fix #ifdef CTDB_CONTROL_SCHEDULE_FOR_DELETION issue; (bso#8303).- File copy aborts with smb2_validate_message_id: bad message_id; (bso#8335).- Fix reload of the configuration and also reload activated registry shares; (bso#8327).- WinXP cannot join a Samba3 domain with a 'even' hostname; (bso#8326).- smbclient cannot list directories from a big-endian machine; (bso#8324).- Update to 3.6.0rc3. + BUG 7841: Explicitly pass domain_sid to wbint_LookupRids(). + BUG 7888: Deal with buggy 3.0 based PDCs. + BUG 8083: Fix "inherit owner = yes" with vfs_acl_xattr or vfs_acl_tdb module. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8102: Do not allow to change file ACLs from normal domusers. + BUG 8193: Add new command 'enumerate_recursive'. + BUG 8195: Make rpc client code working against NT4 servers. + BUG 8211: Fix "inherit owner = yes" when "inherit permissions = yes" is set. + BUG 8213: Fixes in idmap_autorid. + BUG 8214: Fix smbd crash on printer driver upgrade. + BUG 8215: Fix Winbind unix username lookup. + BUG 8216: Make Winbind returning correct results with 'sids2xids'. + BUG 8217: Do not stat-check the share path in 'net conf addshare'. + BUG 8219: Fix SMB Panic from Windows 7 client. + BUG 8224: Fix the build on FreeBSD. + BUG 8226: Use c99 initializers which are supported by old gcc 2.95 compilers. + BUG 8230: Move .nmbd socket directory to non-hidden name PREFIX/var/nmbd. + BUG 8231: Fix crash bug in 'net cache get'. + BUG 8235: Fix smbd crash on startup caused by migrate_printer(). + BUG 8240: Fix Valgrind warnings in winreg/spoolss code. + BUG 8244: Fix copying files larger than 2 GB to a Samba share. + BUG 8247: Fix Coverity ID 2582: FORWARD_NULL. + BUG 8253: Fix Winbind panic if verify_idpool() fails. + BUG 8254: Fix "acl check permissions = no". + BUG 8260: Fix DCERPC responses with fragments larger than 1024 bytes. + BUG 8262: Fix build of vfs_commit. + BUG 8263: Fix build with --with-fake-kaserver or --with-vfs-afsacl. + BUG 8264: Fix Valgrind bugs in svcctl. + BUG 8276: Close all sockets attached to a subnet in close_subnet(). + BUG 8278: Fix smbd panic when CTDB is unhealthy. + BUG 8281: Fix build of examples/VFS/*. + BUG 8286: Fix smbd crash on premature end of smb2 conn. + BUG 8292: Fix a major architectural flaw in the SMB2 server code. + BUG 8293: Fix log file rotating in SMB2. + BUG 8304: Fix uninitialized variable in error path. + BUG 8305: Fix segfault in nmbd when using 'smbtree ...'.. + BUG 8307: brl_close_fnum does not call SMB_VFS_BRL_UNLOCK_WINDOWS on all locks. + BUG 8310: toupper_ascii() is broken on big-endian systems. + BUG 8314: Fix smbd crash with unknown user. + Mark 'time offset' parameter as deprecated.- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site scripting vulnerability; CVE-2011-2694; (bso#8289); (bnc#708503).- The Samba Web Administration Tool (SWAT) versions 3.0.x to 3.5.9 are affected by a cross-site request forgery; CVE-2011-2522; (bso#8290); (bnc#705241).- Fixed the DFS referral response for msdfs root; (bnc#703655).- Fix CUPS print job IDs; (bso#7288); (bnc#701257).- Make use of the actual library version as part of the package name on post-11.3 systems only.- Fix winbind internal error; (bso#7636); (bnc#659424).- Improve ctdb vacuuming performance with use of SCHEDULE_FOR_DELETION; (bnc#705170).- Specify nmbdsocketdir at configure time; (bnc#700953).- Build the tdb, talloc, and tevent libraries ahead of anything else.- Update to 3.6.0rc2. + BUG 6911: Fix Kerberos authentication from Vista to Samba. + BUG 8166: Don't lockout users when offline. + BUG 8200: Add support for multiple writeable ldap idmap domains. + BUG 8148: Default to protocol version 2 for SMB Traffic Analyzer. + BUG 7054: Fix X account flag when "pwdlastset" is "0". + BUG 8144: Fix setting timestamp when touching files with CIFS clients. + BUG 8153: Fix setting up getaddrinfo on IPv6-only machines. + BUG 8156: Fix 'net ads join' using the user's Kerberos ticket. + BUG 8157: Fix parsing a cups printcap file. + BUG 8175: Fix smbd deadlock. + BUG 8189: Support shadow copy display over SMB2. + BUG 8197: Winbind does not properly detect when a DC connection is dead. + BUG 8203: Winbind needs to reset the DC connection if an RPC times out.- Make cupsaddsmb fill printers location; (bso#8132); (bnc#698209).- Add "winbind max clients" parameter to remove 200-client limit; (bnc#697461).- Disable logon cache for password lockout consistency when running in a cluster; (bnc#694836).- Fix logon of AD users with many group memberships; (bso#6911); (bnc#657026).- Don't lockout users while offline; (bso#8166); (bnc#692607).- Update to 3.6.0rc1. + BUG 8111: CIFS VFS: Fix unexpected error on SMB posix open. + BUG 8112: POSIX extension opens of a directory are denied with EISDIR. + BUG 8132: Fix filling printers location field when using cups. + Remove fstrings from client struct. + BUGFIX when converting from safe_strcpy to strlcpy. + Fix off-by-one calculations with strlcpy. + Ensure we always write the correct incoming mid into the share mode table entries. + Fix the SMB2 oplock showstopper. + Convert user-specified domain to uppercase in libsmb. + Fix Coverity CID #2302: FORWARD_NULL. + Fix cups_pull_comment_location(). + Fix double free of cups request. + Make cups_pull_comment_location() work again. + Fix potential crash bug in display_print_driver3(). + Properly clean up in pthreadpool_init in case of failure. + Make plaintext session setup async. + Reduce fd load in Winbind children. + Avoid a potential 100% CPU loop in Winbind. + Tune broadcast namequeries for unique names. + Properly deal with exited winbind children. + Fix dup_smb2_vec3. + Fix return check in nss_wins.- Fix to renew the kerberos ticket in samba after expiry; (bnc#669949).- Fix a 100% CPU loop when ctdbd dies during a traverse; (bnc#693945).- Make dhcpcd hook BOOTPROTO check cover dhcp6 too; (bnc#691969).- Handling of large (> 256 bytes) ntlmv2 blobs in winbind; (bnc#529946).- Package static libraries with 0644 permissions.- Add Requires libtalloc-devel to libldb-devel and libtevent-devel.- Rename libldb0 to libldb1 as 1 is the current major version of the library. - Add libldb1 and libtevent0 to baselibs.conf.- Don't call the suse_update_config macro before building lib ldb and tevent.- Update to 3.6.0pre3. + Listen on IPv6 addresses with IPV6_ONLY; (bso#7383). + Fix wrong output in 'smbget'; (bso#8066). + "inherit owner = yes" doesn't interact correctly with vfs_acl_xattr or vfs_acl_tdb module; (bso#8083). + rpccli_samr_chng_pswd_auth_crap segfaults if any input blobs are null; (bso#8088). + setpwent() actually does endpwent() and vice versa on FreeBSD; (bso#8099). + Fix the build of 'smbget' on HP NonStop; (bso#8106). + Fix build of tdb2. + Correctly detect and deny symlinks anywhere in a path (not just the last component) if "follow symlinks = no". + Fix timeout in rpc_pipe_open_tcp_port(). + Fix the build of "--with-profiling-data". + Fix Coverity IDs 986, 1340, 2047, 2299, 2307, 2325, 2335, 2336, 2470, 2471, 2478. + nsswitch: Add 'wbinfo --lookup-sids'. + nsswitch: Add 'wbinfo --sids-to-unix-ids'. + Fix smbd with the async echo responder. + Fix the build of vfs_gpfs.c. + Add a 10-second timeout for the 445 or netbios connection to a DC. + Many pthreadpool fixes. + Fix transaction recovery area for converted tdbs.- Add PreReq permissions to the krb-printing package.- Remove _libdir ldb and tevent from file list. - Explicitly state not to bundle talloc or tdb while ldb and tevent build.- Always use the actual library version as part of the package name. - Exclude shared python modules.- Fix printing from Windows 7 clients; (bso#7567); (bnc#687535).- Update pidl and always compile IDL at build time; (bnc#688810).- Update to 3.6.0pre2. + ID Mapping changes. + Implement SMB2 support. + Add an Endpoint Mapper daemon. + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Quota only shown when logged as root; (bso#7080). + Fix printing from Windows 7; (bso#7567). + Retry DNS updates when connection to one nameserver has failed; (bso#7690). + Unlink may unlink wrong file when hardlinks are involved; (bso#7863). + Fix 'nmbd --port'; (bso#7875). + cmd_spoolss_deletedriver() returned without checking all architectures; (bso#7880). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix cups pcap reload with no printers; (bso#7915). + Fix bug in chain_reply; (bso#7917). + Fix problems with "kernel oplocks" option set to "no"; (bso#7928). + Fall back for utimes calls; (bso#7940). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let winbind try to use samlogon validation level 6; (bso#7945). + Sgid bit lost on folder rename; (bso#7996). + Fix getting username in 'net rap session'; (bso#8009). + Fix inode generation so nautilus can count total dir size correctly; (bso#8010). + Use jenkins hash for str_checksum; (bso#8010). + Add explicit configure option whether or not to enable dmapi support; (bso#8033). + Fix smbclient segfault with Cyrillic netbios names; (bso#8040). + Fix file creation on OS/X; (bso#8042). + Add "--option" to 'testparm'. + Fix crash bug on smbd shutdown when using FOPENDIR(). + Ensure we don't return an incorrect access mask. + Fix bug against the new Mac client. + Fix leak in error path. + Fix error where Windows client spoolss returns WERR_INVALID_DATA. + Fix a segfault in the krb5 locator plugin. + Enable sharesec for registry shares. + Fix memory leak in "security=share" and "force user". + Add "net idmap check", a check and repair tool for the id mapping database. + Add new 'net idmap delete' command. + Fix segfault on missing input file in 'net idmap restore'. + Fix 'net usersidlist' not to skip every other user. + Fix potential crash bug in spoolss_PrinterEnumValues push path. + Internal restructuring. + Don't wipe out all printer drivers when only one should be deleted. + Fix winbindd_dual_pam_auth_samlogon() for NT4 domains. + Fix memory leak in print_cups.c. + Remove duplicate cups response processing code. + Follow force user/group for driver IO. + Initiate pcap reload from parent smbd. + Reload shares after pcap cache fill. + Fix numerous Coverity IDs (2041 and others). + Fix a memory leak in check_sam_security_info3. + Fix a segfault in the nss wrapper when libnss_winbind.so is not loadable. + Make "net sam list [users|workstations]" list only the right things. + Fix a potential memleak in secrets_fetch_trusted_domain_password. + Use the right credentials in check_netlogond_security. + Add support for AF_NETLINK addr notifications. + Fork multiple Winbind children per domain. + Fix a deadlock between smbd and ctdbd. + Add 'wbinfo --dc-info'. + Make "nmbd socket dir" configurable. + Fixed valgrind errors. + Fix a memleak in receive_getdc_response. + Don't grant SEC_STD_DELETE always to the owner of a file. + Fix segfaults on addrchange errors in Winbind. + Allow machine accounts as members in groupdb. + Add IPv6 support for the endpoint mapper. + Free unused memory in the rpc server. + Fix possible segfaults in svcctl server. + Fix possible segfault with client_id in rpc server. + Add a 'svcctl shutdown' function to rpc server. + Fix a resource leak in net_afs. + Fix a resource leak in smbta-util. + Fix possible resource leak in net_usershare. + Fix possible resource leak in 'smbget'. + Fix possible resource leak in 'smbfilter'. + Fix a possible null pointer dereference in smbd. + Ensure we send the direct levelII oplock break to the correct fid. + Fix private libdir and codepages paths. - Add RFC 3454 to the vendor files.- Fix idmap_tdb for big-endian systems such as ppc and s390; (bso#6901); (bnc#675978).- Fix smbclient -M NT_STATUS_PIPE_BROKEN failure; (bso#7635); (bnc#681913).- Replace jobs by _smp_mflags macro while calling make on post-11.4 systems.- Don't crash when publishing a single printer; (bnc#643119).- Carry error status in printer list IPC message, do not refresh printers if cups is unavailable; (bso#7994); (bnc#675478).- Define the libwbclient packages ahead of packages with a different version.- Use %_smp_mflags for parallel building.- Update to 3.5.8. + Fix Winbind crash bug when no DC is available; (bso#7730). + Fix finding users on domain members; (bso#7743). + Fix memory leaks in Winbind; (bso#7879). + Fix printing with Windows 7 clients; (bso#7567). + Fix 'testparm' return code when EOF in encountered in param name; (bso#3185). + Make "rlimit_max below minimum Windows limit" notification less scary; (bso#6837). + Fix "Your Password expires today" message for users of trusted domains; (bso#7066). + Fix maintaining of users' groups via UsrMgr; (bso#7262). + Fix 'net ads dns register' in Windows 2008 R2 domains; (bso#7356). + Raise debug level for "reduce_name: couldn't get realpath" messages; (bso#7409). + Fix updating the time on close in vfs_gpfs; (bso#7498). + Fix "log=>ndr_pull_error" in 'wbinfo -u' and 'wbinfo -g'; (bso#7594). + Handle Windows 9x adddriver calls without config file; (bso#7641). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix memory leak in the netapi routines; (bso#7665). + Store unmodified copies of security descriptors in acl_xattr and acl_tdb modules; (bso#7716). + Fix incorrect unix mode_t caused by invalid client DOS attributes on create; (bso#7733). + Apply appropriate create masks when creating files with "inherit ACLs" set to true; (bso#7734). + Fix "dfree cache time" parameter; (bso#7744). + Fix a getgrent crash with many groups; (bso#7774). + Fix requesting lookups for BUILTIN sids; (bso#7777). + Fix smbd crash caused by expand_msdfs; (bso#7779). + Fix atime limit; (bso#7785). + vfs_scannedonly: Switch from mtime to ctime which is more reliable; (bso#7789). + Fix copying files from a SMB share using Gnome vfs and SMB signing; (bso#7791). + Make Winbind recover from a signing error; (bso#7800). + ACL inheritance cannot be disabled in vfs_acl_xattr/vfs_acl_tdb; (bso#7812). + Fix "force group" with ntlmssp guest session setup; (bso#7817). + vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835). + Make WINBINDD_LOOKUPRIDS asking the right domain; (bso#7841). + Make WINBINDD_LOOKUPRIDS returning the domain name; (bso#7842). + Expand the local SAMs aliases; (bso#7843). + ntlm_auth: Support clients which offer a spnego mechs we don't support; (bso#7855). + Fix 'net ads dns register' in cluster setups; (bso#7871). + Fix 'nmbd --port'; (bso#7875). + Make 'rpcclient deldriver' delete drivers for all architectures; (bso#7880). + Fix flaky Winbind against Windows 2008; (bso#7881). + Fix SMB session setups with Kerberos against some closed source SMB servers; (bso#7883). + Fix stale lock in open_file_fchmod(); (bso#7892). + Fix sporadic Winbind panic in rpc query_user_list; (bso#7894). + Don't set SAMR_FIELD_FULL_NAME if we just want to set the account name; (bso#7896). + Don't return "-1" on success in 'net rpc vampire keytab'; (bso#7899). + Fix connections from WinCE; (bso#7917). + Fix opening MS Powerpoint files; (bso#7940). + Fix endless loops caused by inotify; (bso#7942). + Catch lookup_names/sids schannel errors over ncacn_ip_tcp; (bso#7944). + Let Winbind try to use samlogon validation level 6; (bso#7945). + Revalidate the pathname once re-constructed from a root fsp; (bso#7950).- Require a particular library version even if the major version is part of the package name. Using the same major version does not guarantee forward compatibility.- Fix a fd-leak in libwbclient at dlclose-time; (bso#7684); (bnc#668773).- Update to 3.5.7 + Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Disable separate build of samba-doc for post-11.1 systems.- Protect against possible denial of service caused by memory corruption; CVE-2011-0719; (bso#7949); (bnc#670431).- Increase the log level for missing PIDs on SIGCHLD, printcap child processes are not added to the children PID list; (bnc#666460).- Do not require a particular library version if the major version is part of the package name.- Use the actual version numbers of the ldb, talloc, tdb, and tevent libraries on post-11.3 systems.- Abide by print$ share 'force user' & 'force group' settings when handling AddprinterDriver and DeletePrinterDriver requests; (bso#7921); (bnc#653353).- Remove pcap_cache_loaded asserts from (re)load_printers. pcap_cache_loaded() returns false if the pcap cache contains no printer entries. correct call ordering is already enforced. (bso#7836); (bnc#625936).- No longer force activation of the cifs service on post-11.3 systems. - Add X-UnitedLinux-Default-Enabled to the cifs init script on pre-11.4 systems. - Move the cifs init script nfs dependencies from Required to Should.- Recommend to install samba-krb-printing from samba-winbind on post-10.3 systems; (bnc#661845).- Fix error paths in cups_async_callback(), an empty cups printer list should not be treated as an error; (bnc#661842).- Abide by printcap cache time, reload parent smbd pcap cache on expiry; (bso#7836); (bnc#625936).- Fix race in cups async printer services reload; (bso#7836); (bnc#625936).- Don't tweak with baselibs.conf during %post if not present; (bnc#652620).- Don't make use of baselibs.conf on SUSE Linux Enterprise 10; (bnc#652620).- Don't use --tmpdir as this option isn't known by mktemp of SUSE Linux Enterprise 10; (bnc#652620).- vfs_fill_sparse() doesn't use posix_fallocate when strict allocate is on; (bso#7835).- Replace Requires samba-client by samba-gplv3-client in the gplv3 packages; (bnc#652620).- Fix Dolphin SMB share IO with SMB signing enabled; (bso#7791); (bnc#656112).- Add Conflicts to the samba-gplv3 main, client, doc, krb-printing, winbind, client-gplv2, and doc-gplv2 packages; (bnc#652620).- Add Provides samba-client-gplv2 and samba-doc-gplv2 to pre-3.2 versions; (bnc#652620).- Obsolete samba-client-gplv2 and samba-doc-gplv2; (bnc#652620).- Remove Provides samba-client:/usr/sbin/winbindd from the samba-gplv3-winbind package to avoide an accidental install trigger; (bnc#652620).- Add Provides samba-client to the samba-gplv3-client package; (bnc#652620).- Remove all Obsoletes from the samba-gplv3 packages and only keep the Provides samba; (bnc#652620).- Add fitting Conflicts to all samba-gplv3 packages; (bnc#652620).- Reduce unnecessary ldap round trips and eliminate invalid DN messages; (bnc#654719).- Exclude cifs-mount and ldapsmb from the samba-gplv3 build of SUSE Linux Enterprise 10 SP 3 and 4.- Add the _build_arch at the end of the vendor version suffix.- Provide and Obsolete samba-gplv3 to replace potentially installed packages.- Change package base name to samba-gplv3 for SUSE Linux Enterprise 10 SP 4. - Do not package libsmbclient and libsmbsharemodes.- Update to 3.5.6 + Fix auto printers with registry config; (bso#7280); (bnc#617153). + Fix SPNEGO auth when contacting Win7 system using Microsoft Live Sign-in Assistant; (bso#7577). + Fix 'net idmap restore' setting HWM to avoid duplicates; (bso#7578). + Fix "admin users" when using vfs_acl_xattr; (bso#7581). + Fix using cached credentials in ntlm_auth; (bso#7589). + Fix Winbind offline login; (bso#7590). + Fix Winbind internal error; (bso#7636). + Fix mknod/mkfifo failing with "No such file or directory"; (bso#7651). + Fix smbd changing mode of files on rename; (bso#7693). + Fix crash bug with invalid SPNEGO token; (bso#7694). + Fix smbd panic on invalid NetBIOS session request; (bso#7698). + Fix smbd crash caused by "%D" in "printer admin"; (bso#7541). + Fix 'smbclient -M'; (bso#7635). + Fix scalability problem with hundreds of printers; (bso#7656). + Fix crash bug in rpcclient; (bso#7688). + Fix file corruption when setting Samba "write wache wize"; (bso#7715).- Let startproc wait for nmb, smb and winbind pid files getting created on post-11.1 systems; (bnc#520036).- Include the reviewed french translation for pam_winbind; (bnc#499233).- Fix smbd crash with CUPS printers and no [printers] share defined; (bso#7297); (bnc#637755).- Fix printing from 64-bit windows clients; (bso#6888); (bnc#640870).- Fix baselibs.conf for libtalloc.- Fix buffer overflow in sid_parse() to correctly check the input lengths when reading a binary representation of a Windows Security ID (SID); CVE-2010-3069; (bso#7669); (bnc#637218).- Use cached ntlm password in libsmbclient. Prevent lockouts when kerberos tickets are lost; (bnc#602418); (bnc#606304).- Add a dependency on nfs to the smbfs/ cifs init scripts as they require the en_US locale and /usr might be on NFS.- Complete fix for trusts with Windows 2008R2 DCs.- Fix authentication dialogs when connecting to older systems; (bnc#632055).- Adjust position of conditional ldapsmb %package and %files definition.- Create the /var/run/samba directory on the fly and package it as %ghost.- Fix preexec scripts; (bso#7104); (bnc#632852).- Add missing netapi, smbclient, smbsharemodes, talloc, tevent, and wbclient pkgconfig files and BuildRequire pkgconfig; (bnc#632770).- BuildRequire python-devel for post-9.3 systems.- Only create precompiled headers for post-10.2 systems. - Remove mkinitrd scriptlets.- Add vfs_crossrename man page. - Call make basic and remove conditional proto target. - Increase libtevent version to 0.9.9. - Remove wbc_async header from the file list. - Remove remaining cifs-mount pieces from the spec file.- Fix printers not auto loading with registry config; (bso#7280); (bnc#617153).- Update to 3.6.0pre1. + SMB2 support is fully functional despite managing quota using the Microsoft management tools. + Internal Winbind passdb changes to use samr and lsa rpc pipe to get local user and group information. + The spoolss and the old RAP printing code have been completely overhauled and refactored. + The SMB Traffic Analyzer (SMBTA) VFS module got added.- Intilize workgroup of nmblookup as empty string.- Fix net ads join when using parent domain users; (bso#6364); (bnc#630812).- cifs: do not restart during dhcp lease renewal when IPaddress remains the same; (bnc#573246).- Fix "Too many open files" when trying to access large number of files; (bso#6837); (bnc#619787).- Update to 3.5.4. + Fix smbd crash when sambaLMPassword and sambaNTPassword entries missing from ldap (bug #7448). + Fix init_sam_from_ldap storing group in sid2uid cache (bug #7507). + Allow previous password to be stored and use it to check tickets; (bso#7099). + Make ea data checks identical for trans2open and trans2mkdir; (bso#7188). + Fix editing users' groups via UsrMgr; (bso#7262). + Fix Winbind over IPv6; (bso#7341). + Samba sends "raw" inode number as uniqueid with unix extensions; (bso#7410). + Fix printing large formats; (bso#7423). + Fix spnego returning incorrect mechListMIC string; (bso#7449). + Fix some crash bugs and missing error codes in AddDriver paths; (bso#7459). + Fix crash bug in _samr_QueryUserInfo{2} level 18; (bso#7479). + Fix 'not a string literal' warning in netdomjoin-gui; (bso#7500). + Fix calculation of st_blocks in vfs_streams_xattr; (bso#7503). + Fix numerous build issues; (bso#7504). + Fix session setup from linux kernel cifs clients with "sec=ntlmv2"; (bso#7517).- Remove all provides and obsoletes samba3 from the spec file. Packages with this base name have not been offered as part of a product.- Fix a NULL pointer dereference in smbd of the 3.4 code base; CVE-2010-1635; (bso#7229); (bnc#605935).- Address possible buffer overrun in chain_reply code of pre-3.4 versions; CVE-2010-2063; (bso#7494); (bnc#611927).- Update of the SMB Traffic Analyzer v2 VFS module- Fix trusts with Windows 2008R2 DCs; (bnc#613459); (bnc#599873); (bnc#592198); (bso#6697).- Update to 3.5.3. + Fix MS-DFS functionality; (bso#7339). + Fix a Winbind crash when scanning trusts; (bso#7389). + Fix problems with SIGCHLD handling in Winbind; (bso#7317). + Add replacement for IPV6_V6ONLY on linux systems with broken headers; (bso#7196). + Fix cups encryption setting; (bso#7263). + Fix exporting printers via 'cupsaddsmb' command; (bso#7277). + Fix SMB job IDs in CUPS job names; (bso#7288). + Fix segfault in mount.cifs; (bso#7315). + Make TIME_T_MAX defines consistent; (bso#7352). + Re-fix a bug with smbd serving a windows terminal server; (bso#7357). + Display an error on 'net conf import' failures; (bso#7378). + Fix bitmap leak in dptr_Close; (bso#7384). + Fix rename problems with full_audit VFS module; (bso#7398). + Fix setting of passwords via 'net rpc user password' command; (bso#7417). + Fix 'net rpc printer list' command; (bso#7418). + Rename mod_name to module_name; (bso#7421). - Fix unnecessary traversing winbindd_cache.tdb in SIGHUP handler. - Added EN ISO 216, A0 and A1 to builtin forms; (bso#7423). - Winbind not working over IPv6; (bso#7341).- Honor "interfaces" list in net ad dns register; (bnc#606947).- Exclude the RPM release from the vendor tag for openSUSE Factory; (bnc#604049).- Enable the build of the idmap tdb2 module; (bnc#600822).- BuildRequire keyutils-libs-devel for Fedora and post-RHEL4.- BuildRequire pkg-config for post-10.2 systems and else pkgconfig.- Add "net conf import" error messages; (bso#7378, bnc#598189).- Define cups_lib_dir %{_prefix}/lib/cups for post-11.2 systems; (bnc#575544).- Update to 3.5.2. + Fix smbd segfaults in _netr_SamLogon for clients sending null domain; (bso#7237). + Fix smbd segfaults in "waiting for connections" message; (bso#7251). + Fix an uninitialized variable read in smbd; (bso#7254); (bnc#605935); CVE-2010-1642. + Fix a memleak in Winbind; (bso#7278). + Fix Winbind reconnection to it's own domain; (bso#7295). + Fix segfault if hide files or veto files has no ".AppleDouble"; (bso#1206). + Fix parsing of the gecos field; (bso#5198). + Fix several printing issues; (bso#6727). + Fix valgrind warning; (bso#6814). + Fix race condition in mount.cifs that allows user to replace mountpoint with a symlink; (bso#6853). + Fix bug in vfs_scannedonly rmdir implementation; (bso#7075). + Fix handling of bad server data returns in client rpc_transport; (bso#7159). + Never mark external domains as internal in Winbind; (bso#7170). + Fix access by multi-threaded applications; (bso#7202). + Fix 'net share' command; (bso#7203). + Fix DN parsing name was always null; (bso#7204). + Signals are processed twice in child; (bso#7206). + Fix returning of group members with 'getent group'; (bso#7212). + Fix the build of net_afs.c with --fake-kaserver=yes; (bso#7216). + Make Winbind logs more verbose for troubleshooting; (bso#7225). + Fix a NULL pointer dereference in smbd; CVE-2010-1635; (bso#7229); (bnc#605935). + Fix automatic building of vfs_tsmsm if gpfs and dmapi are present; (bso#7231). + Fix race conditions in CTDB persistent transactions; (bso#7232). + Symlink delete fails but incorrectly reports success to client; (bso#7234). + Fix "printer admin" functionality; (bso#7255). + Fix value-needed calculation in_spoolss_EnumPrinterData(); (bso#7256). + Fix _winreg_QueryValue crash bugs and implement Windows behavior; (bso#7258). + Fix job management commands for CUPS queues; (bso#7269). + Fix smbd segfault if using vfs_acl_tdb; (bso#7283). + Fix core dump in 'ntlm_auth' with "gss-spnego" helper; (bso#7290). + Fix smbd crashes with CUPS printers and no [printers] share defined; (bso#7297). + Fix DOS attribute inconsistency with MS Office; (bso#7310). + Many disconnecting clients render clustered Samba unusuable for some time; (bso#7312). + Make 'net conf addshare' atomic; (bso#7313). + Eliminate race condition in creating/scanning sorted subkeys in the registry backend; (bso#7314). + Winbind possibly segfaults when trying a trusted domain without inbound trust; (bso#7316).- Add SMB Traffic Analyzer v2 VFS module.- Document "wide links" defaults to "no" in the smb.conf man page for versions pre-3.4.6; (bnc#577868).- Fix workgroup enumeration, for client printer and file share selection; (bso#6880); (bnc#586215).- Fix tdb validation for offline auth; (bnc#587014).- Fix "printer admin" functionality; (bso#7255).- An uninitialized variable read could cause an smbd crash; (bso#7254); (bnc#605935); CVE-2010-1642.- Ensure to have a valid talloc stackframe; (bso#7251).- _netr_SamLogon segfaults for clients sending NULL domain; (bso#7237).- Merge missing pam_winbind message translations; (bnc#499233).- Remove cifs-mount subpackage for post-11.2 systems as the tools are now part of the independent cifs-utils package.- Fix join of Windows 2008 domains; (bnc#567013).- Update to 3.5.1 and 3.4.7. + Fix security flaw on Linux platforms if built with libcap support allowing file system access even when permissions should have denied it; CVE-2010-0728; (bso#7222); (bnc#586683).- Fixed libldb.so link in libldb-devel.- Fix argc handling in net_share, making the command "net share" work again; (bso#7203); (bnc#584253).- Update to 3.5.0. + Fix duplicate sam and unix accounts; (bso#7145). + Keep the the correct negotiate_flags on the cli->dc structure; (bso#7160). + Avoid calling cli_alloc_mid twice in cli_smb_req_iov_send; (bso#7166). + Fix 'net ads dns' usage calls; (bso#7181). + Fix uninitialized variable in wkssvc_enumerateusers; (bso#7182).- Update to 3.4.6. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix printing with 64 bit clients (bso#6888). + Fix core dump on 64 bit Linux (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio) (bso#7067). + Fix string buffer overflow causing heap corruption in smbd (bso#7096). + Fix bogus ip address in SWAT; (bso#5885). + Fix vfs_full_audit; (bso#6557). + Use the first "uid" value; (bso#6157). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix DFS on AIX (maybe others); (bso#7052). + Fix pdb_search crash as non-root user; (bso#7068). + Fix unlocking of accounts from ldap; (bso#7072). + Fix vfs_expand_msdfs; (bso#7081). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Fix reading of large browselist; (bso#7122). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix listing of printjobs in Windows 7; (bso#7130). + Spoolss getprinterdriver2 level 101 marshalling is bad; (bso#7136). + Make idmap cache persistent for "ldapsam:trusted". + Also fill the memcache with sid<->id mappings in ldapsam_sid_to_id() not only the persistent idmap cache. + Shortcut uid_to_sid when "ldapsam:trusted = yes". + Make pdb_copy_sam_account also copy the group sid. + Shortcut gid_to_sid when "ldapsam:trusted = yes". + Speed up pdb_get_group_sid(). + Try to build the full unix_pw structure with ldapsam:trusted support. + Optimize ldapsam_alias_memberships() and cache ldap searches.- Update to 3.5.0rc3. + Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; (bso#7104); (bnc#577868). + Fix vfs_full_audit; (bso#6557). + Fix crash bug in 'cifs.upcall'; (bso#6868). + Fix duplicate initializer in the rmdir module; (bso#6876). + Fix printing with 64 bit clients; (bso#6888). + Add cross option to samba_cv_linux_getgrouplist_ok; (bso#7047). + Fix core dump on Ubuntu 8.04 64 bit; (bso#7063). + Fix failing of smbd to respond to a read or a write caused by Linux asynchronous IO (aio); (bso#7067). + Fix 'smbget' error status; (bso#7069). + Fix build of 'smbfilter'; (bso#7071). + Fix unlocking of accounts from ldap; (bso#7072). + Cliconnect gets realm wrong with trusted domains; (bso#7079). + Fix vfs_expand_msdfs; (bso#7081). + Fix storing of create time on directories in an EA in new create time code; (bso#7084). + Fix an early release of the global lock that can cause data corruption in libtdb; (bso#7085). + Fix string buffer overflow causing heap corruption in smbd; (bso#7096). + Fix results of 'smbclient -L' with a large browse list; (bso#7098). + Normalize "Changing password for" msg IDs and STRs; (bso#7102). + Fix malformed require_membership_of_sid; (bso#7106). + Add pdb_ldap performance fixes; (bso#7116). + Change ldap filter to what really was intended; (bso#7116). + Add new "nmbd bind explicit broadcast" parameter; (bso#7118). + Fix nmbd problems with socket address; (bso#7118). + Support large browselist; (bso#7119). + Fix reading of large browselist; (bso#7122). + Fix listing of printjobs in Windows 7; (bso#7130). + Owner of file not available with Kerberos; (bso#7139). + Fix IPv4/IPv6 problems; (bso#7140). + Fix get_acl_blob in the acl_tdb VFS module; (bso#7148). + "mangling method = hash" can crash storing a name containing a '.'; (bso#7154). + Valgrind Conditional jump or move depends on uninitialised value(s) error when "mangling method = hash"; (bso#7155). + Fix some wrong newlines in de translation strings.- Take extra care that a mount point of mount.cifs isn't changed during mount and don't allow it to be run as setuid root program; CVE-2010-0787; (bso#6853); (bnc#550002).- Check in mount.cifs for invalid characters in device name and mountpoint; CVE-2010-0547; (brc#562156); (bnc#577925).- Don't invalidate cache for uninitialized domains; (bnc#538923).- Signals are processed twice in child; (bnc#538923).- Allow forced pw change even with min pw age; (bnc#561894).- Change parameter "wide links" to default to "no"; it's also incompatible with "unix extensions"; CVE-2010-0926; (bso#7104); (bnc#577868).- Fix enumerate domain local groups for primary domain; (bnc#573813).- Fix malformed require_membership_of_sid; (bnc#525123); (bso#7106).- Normalize "Changing password for" msg IDs and STRs; (bnc#499233).- Build libtevent and libldb and put them into separate subpackages.- Update to 3.5.0rc2. + The Using Samba HTML book has been removed. + 'net', 'smbclient' and libsmbclient can use logon credentials cached by Winbind; (bso#7062). + New vfs_scannedonly module has been added; (bso#7028). + Check password history before increasing "badPasswordCount"; (bso#4347). + Fix changing of ACLs on writable file with "dos filemode=yes"; (bso#5202). + Restore Samba 3.0.x behavior and use the first "uid" value in pdb_ldap; (bso#6157). + Fix deletion of an object whose parent folder does not have delete rights fails even if the delete right is set on the object in vfs_acl_xattr and vfs_acl_tdb; (bso#6876). + Fix large paged search with DirX LDAP servers; (bso#6981). + Fix a segfault in winbindd_dual_ccache_ntlm_auth(); (bso#7027). + Disable sanity check in NetShareEnum for better compatibility with Windows; (bso#7029). + Fix SMBrmdir error message when deleting a directory fails; (bso#7033). + Fix segfault in vfs_cap; (bso#7034). + Fix 'net rpc getsid' in hardened Windows environments; (bso#7036). + Fix a Winbind segfault in "trusted_domains"; (bso#7037). + Complete and improve some German translation of 'net'; (bso#7039). + Fix compile error with WITH_DNS_UPDATE. Update .po files; (bso#7039). + Fix crash bug in libsmbclient; (bso#7043). + Fix bad (non memory copying) interfaces in smbc_setXXXX calls; (bso#7045). + Fix libsmbclient crash against OpenSolaris CIFS server; (bso#7046). + Lock down some srvsvc calls according to what w2k3 seems to do.- Update to 3.4.5. + Fix memory leak in smbd (bug #7020). + Fix changing of ACLs on writable files with "dos filemode=yes" (bug #5202). + BUG 6642: Fix opening the quota magic file. + BUG 6919: Fix remote quota management. + BUG 7034: Fix internal error caused by vfs_cap. + BUG 7036: Fix 'net rpc getsid' in hardened Windows environments. + BUG 7043: Fix crash bug in "SMBC_parse_path". + BUG 7045: Fix bad (non memory copying) interfaces in smbc_setXXXX calls. + BUG 7046: Fix a crash in libsmbclient used against the OpenSolaris CIFS server.- Free unused memory after a packet got processed; (bso#7020).- Add timeout to rpc call to prevent infinite loop when network is down; (bnc#538923).- Update to 3.5.0rc1. + BUG 6837: Fix "Too many open files" when trying to access large number of files with Windows 7; (bnc#619787). + BUG 6939: Fix long filenames when "mangling method" is set to "hash". + BUG 6991: Create symbol links to shared libraries. + BUG 6992: make test for getgrouplist cacheable. + BUG 7014: Fix Winbind crash when retrieving empty group members. + BUG 7020: Fix smbd using 2G memory. + Ensure dos_mode can return FILE_ATTRIBUTE_NORMAL, then filter the returned attributes by protocol level. + Vector correctly through reply_openerror() (which uses the same logic). + Fix bugs with the full Windows ACL support. + Add a few missing gettext calls to the 'net' command. + Fix up a share type translation and translate some more strings in 'net'. + Allow to call "pdbedit -N description -u user" without specifiyng "-r". + Add spoolss_DriverInfo7. + Fix rpcclient after setprinter IDL fixes. + Use generated krb5.conf in 'net ads testjoin'. + Add some German translations for the 'net' command. + Update mount.cifs man page with nounix option. + Fix _samr_GetAliasMembership for results with 0 rids. + Fix an error case in cli_negprot. + Add a lower-cost alternative to wbinfo -t: wbinfo --ping-dc. + Restore correct timeouts for SMB requests. + Fix a 64-bit error in libsmb. + Replace IS_DOMAIN_OFFLINE by a function in Winbind. + Simplify/cleanup Winbind code. + Fix write behind memory block in libtalloc. + Fix result check for getaddrinfo(). + Add tsocket_address_bsd_sockaddr() and tsocket_address_bsd_from_sockaddr() to tsocket. + Always set tdb->tracefd to -1 to be safe on goto fail in libtdb. + Add TDB_DISALLOW_NESTING and make TDB_ALLOW_NESTING the default behavior. + Fix standalone 'make installdocs'. + Output %p as unsigned in snprintf replacement. + New attempt at TDB transaction nesting allow/disallow. + Remove swig stuff from libtdb. + Reset tdb->fd to -1 in tdb_close() in libtdb. + Change the way mksysms work in libtalloc. + Also build and install tdb manpages from standalone tdb. + Fix infinite loop in NCACN_IP_TCP as there is no timeout. + Make winbindd_cache.c aware of domain offline to avoid unnecessary backend query. + List trusted domains from wcache when domain is offline.- Update to 3.4.4. + Fix interdomain trust relationships with Win2008R2 (bug #6697). + Fix Winbind crashes when queried from nss (bug #6889). + Fix Winbind crash when retrieving empty group members (bug #7014). + Fix "UID range full" error in Winbind (bug #6901). + Fix multiple LDAP servers in "idmap backend" and "idmap alloc backend" (bug #6910). + BUG 4832: Fix iconv checks. + BUG 6338: Do not always display "none" in 'net rpc trustdom list'. + BUG 6851: Add pdbedit --kickoff-time/-K to set the user's kickoff time. + BUG 6828: Fix infinite timeout when byte lock held outside of samba. + BUG 6837: Fix "Too many open files" message when trying to access a large number of files with Windows 7; (bnc#619787). + BUG 6841: Fix "map acl inherit = yes". + BUG 6850: Fix shadow copy display on Windows 7. + BUG 6867: Fix listing of directories with a lot of files. + BUG 6868: Support building with Heimdal we well as with MIT. + BUG 6875: Fix DOS attributes on OS/2 clients. + BUG 6880: Fix listing of workgroup servers in libsmbclient. + BUG 6898: Samba duplicates file content on appending. + BUG 6918: Fix krb5 build problem on Ubuntu karmic. + BUG 6929: Fix build with recent heimdal. + BUG 6939: Fix long filenames with "mangling method = hash". + BUG 6967: Fix 'net ads join' with OU. + BUG 6981: Fix paged search with DirX LDAP server. + BUG 6982: Remove erroneous out of memory error path in lookup_sid. + BUG 6997: Fix _samr_GetAliasMembership for results with 0 rids. + BUG 7005: Fix "mangle method = hash" truncates files with dot "." character. + Fix the build of the winbind krb5 locator plugin. + Fix enumprinter key client and server.- Readjust the _libdir/cups/backend/smb sym link only on uninstall of the samba-krb-printing package; (bnc#568603).- Add BuildRequires to fam-devel; (bnc#564260).- Prevent winbind crash; (bso#7014); (bnc#566119).- Fix processing of open modes in POSIX open; (bnc#530683).- Add baselibs.conf as a source.- Update to 3.5.0pre2. + BUG 2350: Add LDAP Alias Dereferencing support. + BUG 6288: SWAT adds a second share when changing parameters of an existing share. + BUG 6435: Fix minor memory corruption. + BUG 6710: Only install the cifs.upcall man page if CIFSUPCALL_PROGS was set while configure. + BUG 6802: A created folder does not properly inherit permissions from parent in vfs_acl_xattr. + BUG 6837: "Too many open files" when trying to access large number of files from Windows 7; (bnc#619787). + BUG 6860: Fix shared library build on QNX. + BUG 6879: Fix crash in Winbind. + BUG 6929: Fix build with recent heimdal. + BUG 6938 : No hook exists to check creation rights when using acl_xattr module. + BUG 6967: Prevent glibc error on 'net ads join'. + Fix vfs_acl_xattr which was failing to call the NEXT connect function. + Restructure the ACL code. + Refactor reply_rmdir to use handle based code. + Fix the build when no external talloc and tdb are installed. + Fix detection of CTDB headers on systems without system-libtalloc. + Fix several printing issues. + Fix the build on Mac OS X 10.6.2. + Fix net and rpcclient after setprinterdataex changes. + Add full support for level 8 printer drivers. + Add more spoolss architectures to IDL. + Fix enumprinter key client and server. + Fix crash in EnumPrinterDataEx. + Prefer posix_fallocate for doing "strict allocate". + Restore "fake directory create times" as a share parameter. + Fix explicit stat64 support. + Add support for NetWkstaGetInfo 101 and 102. + Add rpcclient wkssvc_enumerateusers. + De-deprecate "write cache size" to prevent its removal without a proper alternative. + Allow more than 1000 users in BUILTIN\Users. + Complete support for NetWkstaGetInfo/NetWkstaEnumUsers. + Fix the build of the example VFS modules. + Fix crash in free_file_list(). + Give the user a chance to change password when password will expire soon.- Store the smbfs service state if enabled and restore it for cifs while upgrade on post-11.2 systems.- Prevent cifstab from being overwritten while upgrade on post-11.2 systems.- Give the user a chance to change password when password will expire soon; (FATE#302414).- Rename smbfs init script to cifs for post-11.2 systems.- Allow Windows 7 to connection to samba domain controllers and member servers; (bnc#551811); (bso#6099); (bso#6100); (bso#6680).- Error on joining windows domain (invalid pointer); (bso#6967); (bnc#553622).- Add PreReq /usr/sbin/groupadd to the winbind package; (bnc#559165). - Simplify the winbind package %pre script and suppress stdout only.- Update to 3.5.0pre1 + Add support for full Windows timestamp resolution. + Experimental implementation of SMB2. + Add encryption support for connections to a CUPS server. + Major windbind asynchronous refactoring. - Remove using_samba from the doc package. - Increase major version of libtalloc to 2.- Fix kerberos refresh chain; (bnc#546162); (bso#6872).- Hardlink duplicate files on post-11.1 systems.- Add BuildArch noarch to samba-doc on post-11.1 systems.- Use full 16byte session key in make_user_info_netlogon_interactive(); (bnc#551811).- Update to 3.4.3. + Fix trust relationships to windows 2008 (2008 r2) (bug #6711). + Fix file corruption using smbclient with NT4 server (bug #6606). + Fix Windows 7 share access (which defaults to NTLMv2) (bug #6680). + BUG 4675: mount.cifs: Do not attempt to update /etc/mtab if it is a symbolic link. + BUG 6529: Offline files conflict with Vista and Office 2003. + BUG 6532: Fix domain enumeration if master browser has space in name. + BUG 6606: Fix file corruption using smbclient with NT4 server. + BUG 6690: Fix wrong error check in profile. + BUG 6703: Allow smbstatus as non-root. + BUG 6704: Fix syntax error in avahi configure test. + BUG 6707: Fix an occasional segfault in config file parsing. + BUG 6710: Adjust regex to match variable names including underscores. + BUG 6711: Fix trust relationships to windows 2008 (2008 r2). + BUG 6726: SIVAL should have been an SVAL. + BUG 6728: BSD needs sys/sysctl.h included to build properly. + BUG 6731: Fix reading beyond the end of a named stream in xattr_streams. + BUG 6735: Don't overwrite password in pam_winbind, subsequent pam modules might use the old password and new password. + BUG 6764: Fix timeval calculation. + BUG 6765: Add a "hidden" parameter "share:fake_fscaps". + BUG 6769: Fix symlink unlink. + BUG 6772: Allow outstanding_aio_calls to be decremented. + BUG 6774: smbd crashes if "aio write behind" is set. + BUG 6776: Fix core dump caused by running overlapping Byte Lock test. + BUG 6781: Fix renaming subfolders in Explorer view. + BUG 6791: Fix linking order in cifs.upcall. + BUG 6793: Fix Winbind crash with "INTERNAL ERROR: Signal 6". + BUG 6793: Fix segfault in winbindd_pam_auth. + BUG 6796: Deleting an event context on shutdown can cause smbd to crash. + BUG 6797: Fix a memleak in libwbclient. + BUG 6804: Fix hpux compiler issue. + BUG 6805: Correctly handle aio_error() and errno. + BUG 6807: Fix a segfault in "net rpc trustdom list" for long domain names. + BUG 6810: Add support for finding alternate credcaches to cifs.upcall. + BUG 6811: Fix reference to freed memory in pam_winbind. + BUG 6815: Fix Windows 2008 R2 SPNEGO negTokenTarg parsing failure. + BUG 6824: Fix avahi activation. + BUG 6826: Don't fail authentication when one or some group of require-membership-of is invalid. + BUG 6828: Fix infinite timeout when byte lock held outside of Samba. + BUG 6829: Fix displaying of multibyte characters in smbclient. + BUG 6840: Fix crash in pam_winbind. + Fix an uninitialized variable. + Only ever handle one event after a select call. + Conditional install of the cifs.upcall man page. + Fix warning occuring when building the manpages.- Let smbclient show special characters properly; (bso#6829); (bnc#544204).- Don't fail authentication when one or some group of require-membership-of is invalid; (bnc#525123); (bso#6826).- Allow winbind to ignore certain domains; (bnc#539506).- Update to 3.4.2. + Fix unresolved home path; CVE-2009-2813; (bso#6763); (bnc#539517). + Fix potential denial of service; CVE-2009-2906; (bso#6768); (bnc#543115). + Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix potential denial of service; CVE-2009-2906; (bnc#543115).- Fix potential mount.cifs password leaks; CVE-2009-2948; (bnc#542150).- Fix unresolved home path; CVE-2009-2813; (bnc#539517).- Don't overwrite password in pam_winbind; (bnc#515444).- mods for winbind (when used with squid - ntlm_auth) o winbind adds group 'winbind' o permission 0750,root,winbind LOCKDIR/winbindd_privileged- Merge two fixes from 3.2.8 and 3.3.1. + Adjust regex to match variable names including underscores. + Conditional install of the cifs.upcall man page.- Remove supplements from baselibs.conf while %clean for pre-11.1 systems; (bnc#520579).- Update to 3.4.1. + Fix authentication on member servers without Winbind (bug #6650). + Nautilus fails to copy files from an SMB share (bug #6649). + Fix connections of Win98 clients (bug #6551). + Fix interdomain trusts with Windows 2008 R2 DCs (bug #6697). + Fix Winbind authentication issue (bug #6646). + BUG 5879: Update LDAP schema for Netscape DS 5. + BUG 5886: Fix password change propagation with ldapsam. + BUG 6105: Make linking of cifs.upcall and rpcclient --as-needed safe. + BUG 6222: Default to DRSUAPI replication for net rpc vampire keytab. + BUG 6437: Make open_udp_socket() IPv6 clean. + BUG 6496: MS-DFS cannot follow multibyte char link name in libsmbclient. + BUG 6506: Smbd server doesn't set EAs when a file is overwritten in NT_TRANSACT_CREATE. + BUG 6532: Fix the build with external talloc. + BUG 6538: Cancel all locks that are made before the first failure. + BUG 6560: Fix lookupname. + BUG 6564: SetPrinter fails (panics) as non root. + BUG 6568: Fix _spoolss_GetPrintProcessorDirectory() implementation. + BUG 6585: Fix unqualified "net join". + BUG 6593: Correctly implement SMB_INFO_STANDARD setfileinfo. + BUG 6601: Avoid global fd limits. + BUG 6607: Fix crash bug in spoolss_addprinterex_level_2. + BUG 6611: Fix a valgrind error in chain_reply. + BUG 6615: Fix browsing of DFS when using kerberos in libsmbclient. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 6650: Fix authentication on member servers without Winbind. + BUG 6651: Fix smbd SIGSEGV when breaking oplocks. + BUG 6655: Fix 'smbcontrol smbd ping'. + BUG 6620: Fix a bug in renames of directories. + BUG 6664: Fix truncation of the session key. + BUG 6673: Fix 'smbpasswd' with "unix password sync = yes". + BUG 6680: Fix authentication failure from Windows 7 when domain joined. + BUG 6688: Fix crash in 'net usershare list'. + BUG 6693: Check we read off the complete event from inotify. + BUG 6700: Use dns domain name when needing to guess server principal.- Update to 3.2.14. + Fix SAMR access checks (e.g. bugs #6089 and #6112). + Fix 'force user' (bug #6291). + Improve Win7 support (bug #6099). + Fix posix ACLs when setting an ACL without explicit ACE for the owner (bug #2346). + BUG 6387: Fix Winbind crash when multiple IDmappings exist in the LDAP directory. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6089: Fix SAMR access checks. + BUG 6112: Fix SAMR access checks. + BUG 6279: Fix Winbind crash. + BUG 6291: Fix 'force user'. + BUG 6099: Try to fix domain join of Win7 Beta. + BUG 6386: Groupdb mapping fix. + BUG 6421: Fix POSIX read-only open on read-only shares. + BUG 6476: Fix more smbd-zombies in memory. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + BUG 6504: Fix SAMR server for Winbind access. + BUG 6520: Fix time stamps. + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6465: Fix enum_aliasmem in ldb branch. + BUG 6484: Fix searching for users while adding them to groups via Windows usermanager. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 6526: Let parent_dirname() correctly return toplevel filenames. + BUG 6627: Raise the timeout for lsa_Lookup*() calls from 10 to 35 seconds. + BUG 5798: Preserve CFLAGS info in configure. + BUG 6382: Case insensitive access to DFS links broken. + BUG 6481: Don't require "Modify property" perms to unjoin. + BUG 6628: 'smbpasswd -a' uses algorithmic rid base with 'passdb backend = tdbsam'. + BUG 6560: Lookupname failed, cannot find domain when attempt to change password. + Prevent creation of keys containing the '/' character. + Fix join of Windows 7 RC to a Samba3 DC. + Fix bug in processing of open modes in POSIX open. + Fix the negotiate flags. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to 'net'. + Fix a race condition in Winbind leading to a panic. + Add workaround for MS KB932762. + 5945: Fix out of memory error with Winbind idmap. + Avoid duplicate ACEs. + Fix profile ACLs in some corner cases. + Zero an uninitialized array.- Unable to browse DFS when using kerberos in libsmbclient; (bnc#528271); (bso#6615).- check in .po files for pam_winbind; (bnc#499233); (bso#6602).- Add ntp and network-remotefs as Should-Start dependency to the winbind init script; (bnc#515629).- Update to 3.0.36. + Fix Winbind crash on 'getent group' (bug #5906). + Excel save operation corrupts file ACLs (bug #4308). + Prevent segmentation fault on joining a very long domain name. + BUG 4308: Excel save operation corrupts file ACLs. + BUG 4370: Clean-up entries in /etc/mtab after unmount. + BUG 4640: Fix guest mounts in mount-cifs. + BUG 5906: Fix Winbind crash on 'getent group'. + BUG 6066: netinet/ip.h present but cannot be compiled on Solaris. + BUG 6099: In order to allow Win7 to connect to a Samba NT style. + BUG 6279: Fix Winbind crash. PDC we set the flags before we know if it's an error or not. + BUG 6085: Fix build of vfs_default. + BUG 6098: When the DNS server is invalid, the ads_find_dc() does not work correctly. + Fix logic error in try_chown. + Correctly use chroot(). + Fix bug in processing of open modes in POSIX open. + Don't install the cifs.upcall binary twice. + Fix mount.cifs handling of -V option. + Prevent segmentation fault on joining a very long domain name. + Don't try and delete a default ACL from a file. + Add workaround for MS KB932762. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Fix a crash during name resolution when log level >= 10 and libc segfaults if printf is passed NULL for a "%s" arg.- Use a conditional suse_version macro in front of the SUSE_ASNEEDED export.- lookupname failed, cannot find domain when attempt to change password; (bnc#520645); (bso#6560).- Don't link with --as-needed flag on post-11.1 systems.- Stop the smbfs service if an interface goes down; (bnc#517768).- Disable build of static libraries on post-11.1 systems; (bnc#509945).- Fix missing zlibs for cifs.upcall and test_shlibs.- Update to 3.4.0. + BUG 6431: Local groups from 3.0 setups no longer found. + BUG 6459: Fix build of pam_smbpass on some distributions. + BUG 6481: 'net ads leave' needs to try account deletion, NetUnjoinDomain not. + BUG 6497: Fix calling of 'test' in configure. + BUG 6498: Add workaround for MS KB932762. + BUG 6499: Fix building of pam_smbpass. + BUG 6509: Use gid (not uid) cache in fetch_gid_from_cache(). + BUG 6512: Fix support for enumerating user forms. + BUG 6514: Improve error message in 'net' when smb.conf is not available. + BUG 6520: Fix time stamps when "unix extensions = yes". + BUG 6521: Fix building tevent_ntstatus without config.h. + BUG 6526: Fix notifies in the share root directory. + BUG 6531: Fix pid file name.- Package /etc/samba/smbpasswd as %ghost on post-11.1 systems.- Fix net ads leave; (bnc#511695).- Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164). - Supplement glibc-32bit/glibc-64bit in baselibs.conf (bnc#354164).- Update to 3.2.13, 3.3.6. + In Samba 3.2.0 to 3.2.12 (inclusive), the smbclient commands dealing with file names treat user input as a format string to asprintf. With a maliciously crafted file name smbclient can be made to execute code triggered by the server; CVE-2009-1886; (bnc#513360); (bso#6478).- Update to 3.0.35. + In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a data value can potentially affect access control when "dos filemode" is set to "yes"; CVE-2009-1888; (bnc#515479).- Uninitialized read of a data value; CVE-2009-1888 (bnc#515479).- Update to 3.4.0rc1. + BUG 4699: Remove pidfile on clean shutdown. + BUG 5456: Fix "net ads testjoin". + BUG 6081: Make it possible to change machine account sids. + BUG 6253: Use correct value for password expiry calculation in pam_winbind. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6305: Correctly prompt for a password when a username was given. + BUG 6328: Add support for multiple rights to "net sam rights grant/revoke". + BUG 6333: Consolidate create/delete account paths in pdbedit. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6451: net/libnetapi user rename using wrong access bits. + BUG 6458: Fix uninitialized variable in local_password_change(). + BUG 6465: Fix enumeration of empty aliases. + BUG 6476: Fix smbd-zombies in memory when using [x]inetd. + BUG 6487: Add missing DFS call in trans2 mkdir call. + BUG 6488: acl_group_override() call in posix acls references an uninitialized variable. + Improve pam_winbind documentation. - Install a vendor copy of samba-common.dhcp as dhcpcd-hook-samba-functions.- Samba 3.2.0 - 3.2.12 smbclient commands dealing with file names treat user input as a format string to asprintf; CVE-2009-1886; (bnc#513360).- Fix a bad memleak in vfs_full_audit; (bnc#510035).- Update to 3.3.5. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix joining of Win7 into Samba domain (bug #6099). + Fix joining of Win2000 SP4 clients (bug #6301). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5853: Add keyutils-devel to build requires to fix build on RHEL. + BUG 5897: Fix shutdown script example in the smb.conf manpage. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6297: Owner of sticky directory cannot delete files created by others. + BUG 6301: Fix joining of Win2000 SP4 clients. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6315: smbd crashes doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix 'net groupmap set' segfault. + BUG 6361: Make --rcfile work in smbget. + BUG 6365: Re-Add the "dropbox" functionality with -wx rights on a directory. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6415: Filter out of range mappings in default idmap config in idmap_tdb. + BUG 6416: Filter out of range mappings in default idmap config in idmap_tdb2. + BUG 6417: Filter out of range mappings in default idmap config in idmap_ldap. + BUG 6441: Fix the compile with --enable-dnssd. + BUG 6449: 'net rap user add' crashes without -C option. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent infinite include nesting. + Mark registry shares without path unavailable. + Also handle DirX return codes. + Fix Coverity ID 897. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix a race condition in winbind leading to a panic. + Some man pam_winbind improvements. + Zero an uninitialized array.- Update to 3.2.12. + Fix SAMR and LSA checks (bug #6089, #6289) + Fix posix acls when setting an ACL without explicit ACE for the owner (bug #2346). + Fix "force user" (bug #6291). + Fix Winbind crash (bug #6279). + Fix joining of Win7 into Samba domain (bug #6099). + BUG 2346: Fix posix acls when setting an ACL without explicit ACE for the owner. + BUG 5798: CFLAGS info lost in configure. + BUG 5832: Fix build on RHEL when ccache is not available. + BUG 5835: Add keyutils-devel to build requires. + BUG 5945: Fix out of memory error with Winbind idmap. + BUG 6089: Revert the extra SAMR and LSA checks. + BUG 6099: Fix joining of Win7 into Samba domain. + BUG 6279: Fix Winbind crash. + BUG 6289: Revert the extra SAMR and LSA checks. + BUG 6291: Fix "force user". + BUG 6301: Fix samr_ConnectVersion enum which is 32bit not 16bit. + BUG 6372: Fix usermanager only displaying 1024 groups and aliases. + BUG 6386: Groupdb mapping fix. + BUG 6382: Fix case insensitive access to DFS links. + BUG 6465: Fix enumeration of empty aliases (ldb backend). + Prevent creation of keys containing the '/' character. + Fix bug in processing of open modes in POSIX open. + Protect netlogon_creds_server_step() against NULL creds. + Also handle DirX return codes. + Fix a race condition in winbind leading to a panic. + Fix a crash bug if we timeout in net rpc trustdom list. + Fix profile acls in some corner cases.- Default with passdb backend to smbpasswd for SUSE products older than 11.2.- Explicitly use 'tdbsam' as passdb backend in the default smb.conf file.- Update to 3.4.0pre2. + The default passdb backend has been changed to 'tdbsam'! + Samba4 and Samba3 sources are included in the tarball. + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Made parameter syntax of the net command more consistent. + BUG 2346: Fix posix ACLs when setting an ACL without explicit ACE for the owner. + BUG 4271: testparm should not print includes. + BUG 4831: Don't call openlog() or closelog() from pam_smbpass. + BUG 5681: Do not limit the number of network interfaces. + BUG 5859: Fix renaming of samr objects failed due to samr setuserinfo access checks. + BUG 6099: Fix NETLOGON credential chain. + BUG 6136: New AFS syscall conventions. + BUG 6157: Fix handling of multi-value attribute "uid". + BUG 6253: Use correct value for password expiry calculation. + BUG 6291: Fix 'force user'. + BUG 6292: Update config.guess from gnu.org. + BUG 6302: Give the VFS a chance to read from 0-byte files. + BUG 6309: Support remote unjoining of Windows 2003 or greater. + BUG 6313: ldapsam_update_sam_account() crashes while doing talloc_free on malloced memory. + BUG 6315: Fix smbd crashes when doing vfs_full_audit on IPC$ close event. + BUG 6320: Handle registry config source in file_list. + BUG 6330: Fix DFS on AIX. + BUG 6336: Fix segfault in 'net groupmap set'. + BUG 6340: Don't segfault when cleartext trustdom pwd could not be retrieved. + BUG 6357: Use Samba default command line arguments in 'net'. + BUG 6359: smbclient -L does not list workgroup for hosts with both IPv4 and IPv6 addresses + BUG 6361: Make --rcfile work in smbget. + BUG 6371: Unsuccessful 'net conf setparm' leaves empty share. + BUG 6372: usermanager only displaying 1024 groups and aliases. + BUG 6387: Fix a crash bug in idmap_ldap_unixids_to_sids. + BUG 6415: Filter out of range mappings in default idmap config (idmap_tdb). + BUG 6416: Filter out of range mappings in default idmap config (idmap_tdb2). + BUG 6417: Filter out of range mappings in default idmap config (idmap_ldap). + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Fix the core of the SAMR access functions. + Fix SAMR server for winbindd access. + Add dbwrap_tool - a tdb tool that is CTDB-aware. + Hide "config backend" from swat. + Fix linking with --disable-shared-libs. + Fix issue with missing entries when enumerating directories. + Map NULL domains to our global sam name. + Fix driver upload for Xerox 4110 PS printer driver. + Add "net dom renamecomputer" to rename machines in a domain. + Inspect the correct computername string before enabling/disabling the change button in netdomjoin-gui. + Fix join prompt dialog test in netdomjoin-gui. + Only gray out labels when not root and not connecting to remote machines (netdomjoin-gui). + Allow to switch between workgroups/domains with the same name (netdomjoin-gui). + Add NetShutdownInit and NetShutdownAbort. + Fix samr access checks. + Add a security model to LSA. + Also handle DirX return codes. + Do not crash in ctdbd_traverse if ctdbd is not around. + Fix Coverity ID 897. + Fix a race condition in vfs_aio_fork with gpfs share modes. + Fix bug disclosed by lock8 torture test. + Fix a race condition in winbind leading to a panic. + Detect tight loop in tdb_find(). + Fix chained sesssetupAndX/tconn messages. + Fix strict locking with chained reads. + Fix two bugs in sendfile. + Fix memory leak. + Fix file descriptor leak. + Fallback to the legacy sid_to_(uid|gid) instead of returning NULL. + Always allocate memory in dptr_ReadDirName. + Fix 'net' crash during domain join. + Zero an uninitialized array. + Allow child processes to exit gracefully if we are out of fds.- Enable cifs.upcall on versions newer than SUSE 10.0.- Add BuildRequires to keyutils-devel.- Remove redundant Requires to keyutils-libs for cifs-mount.- Detect tight loop in tdb_find(); (bnc#450974).- Fix lp printing with kerberos; (bnc#476913).- Add BuildRequires to ctdb-devel for systems newer than SUSE 10.0 and all other build targets.- Update to 3.4.0pre1. + Samba4 and Samba3 sources are included in the tarball + Changed the way smbd handles untrusted domain names given during user authentication. + Various fixes including printer change notificiation for Samba spoolss print servers. + The remaining hand-marshalled DCE/RPC services (ntsvcs, svcctl, eventlog and spoolss) were replaced by autogenerated code based on PIDL. + Samba3 and Samba4 do now share a common tevent library. + The code has been cleaned up and the major basic interfaces are shared with Samba4 now. + An asynchronous API has been added. + Change the way smbd handles untrusted domain names given during user authentication. + Replace the hand-marshalled DCE/RPC services ntsvcs, svcctl, eventlog and spoolss by autogenerated code based on PIDL. + Fix several printing issues and improve support for printer change notificiations. + Add 'net eventlog'. + Add asynchronous API. + Make Samba3 and Samba4 share a tevent library. + Add two new parameters to control how we verify kerberos tickets. + Add 'net rpc service' subcommands 'create' and 'delete'. + Make merged build possible. + Move common libraries to the shared lib/ directory.- Update to 3.3.4. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix usrmgr.exe creating a user (bug #6243). + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6279: Fix Winbind crash. + BUG 5329: Add "net rpc service delete/create". + BUG 6238: Make sure wbcLogoffUserParams are properly initialized before freed. + BUG 6263: Fix domain logins for WinXP clients pre SP3. + BUG 6286: Call init function for builtin idmap modules before probing for them as shared modules. + BUG 6243: Fix usrmgr.exe creating a user. + net conf: Save share name as given, not as lower case only. + Prevent creation of registry keys containing the '/' character. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Don't access a freed structure when logging off and re-using a vuid. + Try to to fix password_expired flag handling. + Make sure to grey out change fields in the netdomjoin-gui when not running as root. + Don't look up local user for remote changes, even when root. + Use procid_str in debug messages for better cluster-debuggability. + Use cluster-aware procid_is_me instead of comparing pids. + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Do not use the file system GET_REAL_FILENAME for mangled names. + Fix a crash bug if we timeout in net rpc trustdom list. + Add '--request-timeout' option to net. + In net_conf_import, start a transaction when importing a single share. + Fix writing of roaming profiles with "profile acls" set to "yes".- Update to 3.2.11. + Fix domain logins for WinXP clients pre SP3 (bug #6263). + Fix samr_OpenDomain access checks (bug #6089). + Fix smbd crash for close_on_completion. + BUG 6089: Fix samr_OpenDomain access checks. + BUG 6205: Correct sample smb.conf share configuration. + BUG 6254: Fix IPv6 PUT/GET errors to an SMB server (3.3) with "msdfs root" set to "yes". + BUG 6263: Fix domain logins for WinXP clients pre SP3. + Allow pdbedit to change a user rid/sid. + When doing a cli_ulogoff don't invalidate the cnum, invalidate the vuid. + Fix resume command typo for "printing = vlp". + Fix smbd crash for close_on_completion. + Fix a memleak in an unlikely error path in change_notify_create(). + Don't look up local user for remote changes, even when root.- Don't lookup local user for remote password changes; (bnc#493507).- Update to 3.3.3. + Migrating from 3.0.x to 3.3.x can fail to update passdb.tdb correctly (bug #6195). + Fix serving of files with colons to CIFS/VFS client (bug #6196). + Fix "map readonly" (bug #6186). + BUG 6195: Don't let smbd child processes panic. + Add backend_requires_messaging() method to libsmbconf. + Add methods is_writeable() and wrapper smbconf_is_writeable() to libsmbconf. + Fall back to file backend when no valid backend was found. + Fix a memleak in dbwrap_rbt. + Provide transaction_start|commit|cancel fns for the registry tdb. + Speed up "net conf drop". + Speed up "net conf import". + Add transactions to the libsmbconf API. + Reduce memory usage of "net conf import". + Registry cleanup. + Fix handling of SAMBA_VERSION_VENDOR_PATCH. + Fix build of pam_winbind.so with static linking. + Tidy up some convert_string_internal error cases. + BUG 6224: nmbd waits 5 minutes at startup before checking if it needs to run elections. + Allow DFS client paths to work when POSIX pathnames have been selected. + Try and fix the build farm RAW-STREAMS errors. + Ensure files starting with multiple dots are hidden. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6193: Avoid messing with sync_context in libnet_samsync_delta(). + Fix notify_printer_status_byname. + Fix Coverity IDs 722, 762, 774, 775, 776. + Fix build on old Heimdal based systems. + Fix compile warning. + Use parentheses in if condition to make negation clear. + Add dirsort module. + BUG 6147: Fix detection of the GNU ld version. + BUG 6097: Fix smbd segfault. + BUG 6130: Don't crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6139: Add missing whitespace in mount.cifs error message. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix a valgrind error. + Speed up "net conf list". + Add sorted subkey cache. + Use StrCaseCmp in the dirsort module. + Document the dirsort module. + Disable dns_sd by default. + Add avahi detection to configure. + Add event avahi binding. + Use avahi to register _smb._tcp in smbd. + Fix two memleaks in the encryption code. + Fix a scary "fill_share_mode_lock failed" message. + BUG 6228: Fix SMBC_open_ctx failure due to path resolve failure doesn't set errno. + Don't use reserved words in smbconftort. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Parse_packet can return NULL which is then dereferenced in match_mailslot_name. + Format the header check for netinet/ip.h more nicely. + Missing break in conversion function prevents tdb password database update.- Update to 3.2.10. + BUG #6195: Don't let smbd child processes panic.- BUG 6195: Fix crash on passdb conversion.- Update to 3.2.9. + BUG 5920: The length of the memcpy was calculated wrong. + BUG 6097: Fix smbd segfault. + BUG 6098: Fix ads_find_dc() with "security = domain" when the DNS server is invalid. + BUG 6099: Samba returns incurrate capabilities list. + BUG 6100: Implement _netr_LogonGetCapabilities() with NT_STATUS_NOT_IMPLEMENTED. + BUG 6102: NetQueryDisplayInformation could return wrong information. + BUG 6130: Fix crash in winbindd_rpc lookup_groupmem() on unmapped members. + BUG 6133: Cannot delete non-ACL files on NFSv4 ACL filesystem. + BUG 6161: smbclient corrupts source path in tar mode. + BUG 6193: Avoid messing with sync_context in fetch_database_to_ldif(). + BUG 6196: Unable to serve files with colons to Linux CIFS/VFS client. + BUG 6224: nmbd waits 5 minutes before checking to run elections. + BUG 6228: Fix SMBC_open_ctx failure when path failure doesn't set errno. + Numerous Coverity fixes + Fix double free caused by incorrect talloc_steal usage. + Backport delete semantics of alternate data streams on a file truncate. + Allow set attributes on a stream fnum to redirect to the base filename. + Fix use of streams modules with CIFSFS client. + Fix more POSIX path lstat calls. + Allow DFS client paths to work with POSIX pathnames. + Ensure files starting with multiple dots are hidden. + Fix guest auth when Winbind is running. + Fix memleak in get_remote_printer_publishing_data(). + cifs mount fix for handling -V parameter. + Fix guest mounts. + Clean-up entries in /etc/mtab after unmount. + Add fakemount (-f) and nomtab (-n) flags to mount.cifs. + Enable total anonymization in vfs_smb_traffic_analyzer. + Don't try and delete a default ACL from a file. + Fix remotely adding a share via MMC. + Fix resume handle for _samr_EnumDomainGroups. + Fix a buffer handling bug when adding lots of registry keys. + Fix a O(n^2) algorithm in regdb_fetch_keys(). + Fix a valgrind error / segfault in dns_register_smbd(). + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a malloc/talloc mismatch when cli_initialise() fails. + Fix two memleaks in the encryption code. + Fix "fill_share_mode_lock failed" message. + Add S-1-22-X-Y sids to the local token. + Fix smb signing for fragmented trans/trans2/nttrans requests. + Don't miss an absolute pathname as a kerberos keytab path. + Have nmbd check all available interfaces for WINS before failing. + Initialize the id_map status in idmap_ldap to avoid surprise.- Obsolete change from 2008-03-05 by removing the needless examples cleanup.- Update to 3.3.2. + Fix "force group" (bug #6155). + Fix saving of files on Samba share using MS Office 2007 (bug #6160). + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + Fix corruptions of source path in tar mode of smbclient (bug #6161). + BUG 6082: Fix renaming and deleting of directories using Windows clients. + BUG 6154: Make ZFS honor admin users. + BUG 6155: Fix "force group". + BUG 6160: Fix saving of files on Samba share using MS Office 2007. + BUG 6161: Fix corruptions of source path in tar mode of smbclient. + Fix some NetBSD warnings. + Fix bug in processing of open modes in POSIX open. + Fix use of streams modules with CIFSFS client. + Ensure ACL modules work with POSIX paths. + Use fsp->posix_open in preference if we have it. + Fix more POSIX path lstat calls. + Fix a bug in message handling for the change notify code. + Fix guest authentication in setups with "security = share" and "guest ok = yes" when Winbind is running. + BUG 4640: Fix guest mounts in mount.cifs. + Fix displaying the version string properly when no other parameters passed in in mount.cifs. + Prefer gssapi header files from subdirectory. + BUG 6176: winbindd -n should disable the winbind idmap cache. + Add a vfs_preopen module to hide fs latencies. + Don't log NDR_PRINT_DEBUG at level 0, this always ends up in syslog. + Fix a valgrind error / segfault in dns_register_smbd(). + Fix build on SLES8. + Decremented by 1 for ntcancel requests. + Fix creation of core files. + Fix first mapping of uids/gids in Winbind. + Initialize the id_map status in idmap_ldap to avoid surprise. + Fix initialization of idmap status.- Only call '%find_lang pam_winbind' in the samba spec file, not samba-doc.- Ignore return value from subshell to fix build./bin/sh  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_4.6.16+git.166.8fb11cda200-30.14.6.16+git.166.8fb11cda200-30.1sambalibCHARSET3-samba4.solibLIBWBCLIENT-OLD-samba4.solibMESSAGING-samba4.solibaddns-samba4.solibads-samba4.solibasn1util-samba4.solibauth-sam-reply-samba4.solibauth-samba4.solibauth-unix-token-samba4.solibauth4-samba4.solibauthkrb5-samba4.solibcli-cldap-samba4.solibcli-ldap-common-samba4.solibcli-ldap-samba4.solibcli-nbt-samba4.solibcli-smb-common-samba4.solibcli-spoolss-samba4.solibcliauth-samba4.solibcluster-samba4.solibcmdline-credentials-samba4.solibdbwrap-samba4.solibdcerpc-samba-samba4.solibdcerpc-samba4.solibdsdb-garbage-collect-tombstones-samba4.solibdsdb-module-samba4.solibevents-samba4.solibflag-mapping-samba4.solibgenrand-samba4.solibgensec-samba4.solibgpo-samba4.solibgse-samba4.solibhttp-samba4.solibidmap-samba4.solibinterfaces-samba4.solibiov-buf-samba4.solibkrb5samba-samba4.solibldbsamba-samba4.soliblibcli-lsa3-samba4.soliblibcli-netlogon3-samba4.soliblibsmb-samba4.solibmessages-dgm-samba4.solibmessages-util-samba4.solibmsghdr-samba4.solibmsrpc3-samba4.solibndr-samba-samba4.solibndr-samba4.solibnet-keytab-samba4.solibnetif-samba4.solibnon-posix-acls-samba4.solibnpa-tstream-samba4.solibnss-info-samba4.solibpopt-samba3-samba4.solibposix-eadb-samba4.solibprinting-migrate-samba4.solibregistry-samba4.solibreplace-samba4.solibsamba-cluster-support-samba4.solibsamba-debug-samba4.solibsamba-modules-samba4.solibsamba-net-samba4.solibsamba-python-samba4.solibsamba-security-samba4.solibsamba-sockets-samba4.solibsamba3-util-samba4.solibsamdb-common-samba4.solibsecrets3-samba4.solibserver-id-db-samba4.solibserver-role-samba4.solibshares-samba4.solibsmb-transport-samba4.solibsmbclient-raw-samba4.solibsmbd-base-samba4.solibsmbd-conn-samba4.solibsmbd-shim-samba4.solibsmbldaphelper-samba4.solibsmbpasswdparser-samba4.solibsocket-blocking-samba4.solibsys-rw-samba4.solibtalloc-report-samba4.solibtdb-wrap-samba4.solibtime-basic-samba4.solibtorture-samba4.solibtrusts-util-samba4.solibutil-cmdline-samba4.solibutil-reg-samba4.solibutil-setid-samba4.solibutil-tdb-samba4.solibwinbind-client-samba4.solibxattr-tdb-samba4.sopdbldapsam.sosmbpasswd.sotdbsam.sowbc_sam.so/usr/lib//usr/lib/samba//usr/lib/samba/pdb/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:10483/openSUSE_Leap_42.3_Update/3be556ce4b1735da54b485ec0dc8850c-samba.openSUSE_Leap_42.3_Updatedrpmlzma5x86_64-suse-linux  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]directoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=36846241db22bbf632c8d6b4fd7ee5bf5e0d9cbb, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3e5b5c6c18d64fe51ec1667908ef6331e505bbe1, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2f646bf53b567a30797917637b4ddbdc5a33d84f, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=6269db9bf1b10ab322185567883c53d2209b3b3f, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=5828ce3a543cf8136d773fc1650821fb02538c49, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=7d90f742ea3f2008c7e5566a50308750603528fb, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=0d05afecb63e3ea79bb33fe95f554ec60d7731c8, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2e62f2fc081894c4d9acd66ce85c8923da924bd2, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=dfd5156696c638279f0e2cf138ce4aae5703769b, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=4bac4cd0260639b973dec66c7d3f8acb3fa2f763, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=5574b03a7ca2d157eb66f68871c573535094b40b, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=20ae1db240d3c5a91f251dedcfa30f2003e7818a, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1f0b4645bc9bd442732f5f3583a834f68522d495, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3e41bd00ee6c81ecb69ece84b95106e19fe950b9, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=a072b8f746008c0511f5df6d15486ac04f88c222, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=289340743ff5fac26a2c022f380858585f06f939, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3a2ef5d2f6e288c1dbd89988c06a31ff82c6f09c, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=78e4cc851457a3659239999ba3bef0199b3c8230, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=711c8f4fe49fb9e0778cc0e8b776d19b30f72bcb, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=63e8e4d9ddc8c5b44724a8ddd92db0fd81569897, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=b76ca0960847e79dabcbc8dcd7f23aa0598fe4ba, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3ebf17860571d6c7d0a88bf31aa77bd7fb627cdf, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=bdb3f3391700ded8ca3c9bccfdc27f92ba16975d, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=bb3c32a957f30c11213e401aad0ed469bceedb78, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=0a1df19ba3c5084adaec6c24fa22b662f8d99c6d, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=c2c1ce1bab6fb7070367000f55f5b1036acc69d0, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=a97ec60fb6272e4bae59bfc9ed871ca2db9741e1, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2aa5e550e4d6c2fb7dc9896b8cb48bfdcfd9fbad, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=5f005ced165cf05d24a95de5d180cb0d3df63eab, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=e3680ee8cb438bdea450ad60ef0da5f1d46615d6, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=9cce6fa3540976ccf477e490afd2165df59d8e00, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=a5c3fd894a7eca7731827892e7446abe9a34a58c, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=eb264f638d075c37e5a9a12f4476df0240d245f0, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=0f761cef82a6da81891129c551e7c23da904f861, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=b128e7eeea315717f641d52648e7801cfdefeddc, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=80796d6d9ba1f1ee40f76b276dce3ae58748ae3e, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=d7f15a7ded2977999a3f1d4f6dc3f739743a2123, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=931ac974f21a344ffde8e27a25f5b434ac2abc82, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=ab704730bea38aa84abe533b7dbd9c66174ec0d5, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1791678d1105e2c8db92a6db7ba6ddbbec6f521d, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=aa1d1b2ed097f1419778a8f61feb9c8ded7ccc63, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=37d8b3e751023cb453f660eca882d527e1a77c59, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=14050ac490ea553fc9f88d93079fd5d386ee749f, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=abdfd3c6455a3f832cad4be987e73ed8cc30b679, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=9c178dff73547cb253c5290a97a8257a47f1cdcb, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=00ee4db9926747272b7d3b6479119cef8af193e4, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=06a58ee62bd68ee0894c2eb159ca0528bdf77eb7, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=467ccb4c0c3a24ffa5abd33a8aa2eecc941e02e9, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=0e43854ccf6f2a933aa3e7cdcbf873d6bf33a4f8, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=8722993f984bfe0728460fabff9ad09df729e15d, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=cece7a233a7e77cbb461e1fb7fb60a830861138e, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=59305061ac338ebf2aaa0d648f7ffdeb3029543b, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=e0cf15eed3d43d9fad6db7ef5aca8d0bb0635aeb, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=125fb24518802d7bf7089ee55f64929863642872, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ad6a6f581e18dadc893d2d4c25c08ca8756f0a2, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=a7769e30a89731facf1e0f19abb5898305034d46, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2c9fd4f769c4ac8b20988080301bf14677005f17, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=cf6f3dedac72422f9a1f0f6a0a4bdd4cd6edc3d1, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=ca001b508d93ffc48d92eeaab861151ae86c6d86, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=c140ad3c1d11c4acc652163452611d5d55a7a7ed, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=5359a40b30b5de77f60b9adfc2664b5234099c64, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2a7cda87ae873534609d2f95507b51bea50cf288, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=f44d182638dc350066d8771dd07392b8ddc80fb6, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=613b71e7507b5bdc66778b16cd15d874ebe77c88, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=14115365e702fb0857df35dd20e80353b77fc317, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=244cc8061cae486b5977a5e3044a327f7b26da80, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=527a01601ba9d10b9ac404c3625414aa253e659e, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=136d7f37fe5f71693c1985004a8d29f168b1da41, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=37414492bd4c2352079ebfd602fe7d0c6cb67226, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=af05764e318aeb7caae92ba001cb83ac63515f45, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=48502742ad9cfd96a06e99ccd3af962a549ff3bc, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=542d0a127c4547a5e4fc4a724a4e774b3c3f0311, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3828d62e884d83857486feaadda8a9d67ea9c921, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=968d908565602be28bf9fb12c51fa8f17e75f9b0, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1ddeb569333387d554de677980ddaa391517f749, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=0b8cf7608fafc31f8992f4e3325d558e19d28b10, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=8f446352725ae3e92d0c0f85a6b74b7c98ea73ac, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=57e602e9c7f164487fc7824550b2a19f58161bd7, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=72787d7df668e86751656378cf970d02918eba76, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=ddecfe02c3ba05535a510809d6d6d79598260c76, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=cc93c3ad6f9ccf4e56bf0b8f9a4620dda4cc5c5e, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=023ac41ddbf6d231b27b0b5eb349b9b828c83c07, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=889ffb210d0c6194fe4542f51c99953790263810, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=65c1617806c74c1eb48bd32833269ebbb43ab609, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=a42a49946e8ceff5a122a5cdc77366a68603a4bf, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1833cd66ca458e6b0361fdbbf9eba85fcbec1789, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=83f17b37e54a83faa4b99d868084367885057ad5, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=8da7295e77be87a77acae1903b4458ae4dbe0d04, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=88aefcc1b04e664c239f63a0154c2309219caba7, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3aa9166a15947564d77ac2f7fb2880fa60bb131b, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=50657e470f6aa6e6348afc8a0bde249054038254, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3dfe04bd15fe29231f0d404f7802ff8e14f47094, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=fdcc7ea9088dc31d6219863bd69ac1a7924dd55a, stripped D_ Vz#@eozFq:Ji1Kas$7N_ 6csycpu   " . L u 'F R6$#2$% & 5+;!*<& = ")H +-(    )" PPRRRRRRRRRPPRRRRRRRRRRRRRRRRPPRpRRR~RRRRrR;RRRRRRRR%RRRRRR}RqRRRRRRRRR:RoRRRPPRRRRRRKRRRQRRR%RR$R"RRRRRJRRRPRRP P RvRjRKR=RR+RRRRRRR RQRRR)RzRRRYR[RMRORRRRRRnR'R%RRR$RR RRRmRR*RuRiRR(RRRZRRRJRNRLRRRyRRRRRRRR}RRR4RRJRRR:RR^RRRRPPRWRRRRR[RxRRRRRRRQRRYRRRRwRRRZRRRRRXRVR6RRPRRPPR_RRRRRRRRRRRzRR+RRRRRRRRRyRRR*RRR R^RRRPPRR_RRRRRRRRRRR RRRR^RRPPRR_RzRRRRR+R RRRRRMRR/RRRRR%RRRRRR R.RR*RRRRRLRRyR RRRRRR^RRRRPPRRRRRR%RRRRRRzRRRRRRyRRRRRRRP PRRURRRRKRRRRRR$RR%RRMRRRRRRRTRRRRLRRJRRRRRP"P!RMRRRRRRRRRR=RRRRP=RR RRRMRRRRRRRKRQRRRR%R RR'R$RR/R)RR[RRRRRYRR RRR(RRRZRRRLRRJRRRRRR.R]RXR6RRPRRP@P?RRRRRMRRRRRRRRRRRRRLRRRPBPARRRRRRRRRRR%R'RRRR9RRRRRRRRRR8RRRRRPDPCRRRRR"RRR%RRRRRRPFPERRRPHPGRRRWRRQRR$RR R%RRYRRRRXRVR6RRPRPJPIRRRRRRR|RR'RR%R"R$RRRRfReRaR_RRRRRRRRR{RRRRRRR R^RRRPLPKRRRRRRR=RRfܯ:$*1ChZ:jo#vX\uM1d} Kj7X `}ڕƳTUڞm07_ZL")R '-Ԑ20%>_6̍_GuncFco0g7FCs%Ujqk0:\Ӣ9yK͡g!œ@DAI'P5쏦N țJ¬H1t KwNZ1['2nuɞf T.ɴ R7t/[qZe_O[$b⪠dn*)䃈c,P=9СtJiIrɮ|E\ M5 VWرC>ZQh쌗vD@:^73Y:Tx5 (W̖qq<]偌ȃ6/:{)|Ц1]$ݼg6BD~Lj>7wɆyR %m(CNv/xoo.hK\=Fώkk&Q?o.ӓOȨ1&Ao]D6m(2Ӵv &^/f`G}D(|kǕrXYgGc廼`^q[RB*o J݂#|a& JRnxYlf[o\Z̜ٖcb.Ʉc"t.A~pS3HK4]S2eH8~b7_ÕfeyUsB+Lᰇ> ;~BwKv:R2ݶxB[dHrobG`6[Rm^B8F0X ceJw}АpgleR;+^Pwy IB?%XpTQ,Qh工[2IQrWXZ_c#iscI\2.9ӯ6)n9fݍeԝv4{ʉe[4#%0|1qmk/%x4#{"3ⱛZU>)+k\9vA08¿z:~✫|L(+#>Dzu9@2;F6o >V~PTyUƟJ-b+3Z YW~9mYpEfo&dLJ9dy a "͂|A39PpDD!bxuEVqbf|i<d3Nl]E+֤;b{'0`pVޠ>4N'h̾ cJ댒 ''8cRtU<q4g8Ϥ*ހ=^=w`vz6t^;yP_k?Cb2-K( GYng|R1p@0n8:p:+|r@h])>^\ç]}g<}f#;=.0k3R!iKK1d1D_pkԵV&ˍ6[uxG`UM6=Dպ*zSN9z% d+?OӑAO|ɿ>+EǭBnnw'_Ƭγ3`M8U)d?fOuE 3sr eә$7T!~CGkz$ ê@ 3au~h%TX;yp>An쫔)ZR6t~~ Sub[)f<A8SIބ q ~ٵ@TK;2%yG+K gZǯ`KsE*tɰ7WMؔ9GD[l!`>Q}ILD=S[:{d/)K=ۨ/I3~6esz,7r{ iE3s>1Y..Q$c+w#Zޢft7wp2y1m bd<7R@>ޓAQ Л|xt`o/~m3_U&{MO TF JqYKZ~( M1J57gʇ}SlAh̅OTJ ]yX&`kSةSIMW`ՇfL`gzꈗxaӨlwu40i*ͫ4ۼzzhh ,N"EYBZWLNJ5Cк{=kqF7ߏh_,ȃ 6Z.Jz>Z0y]Mp ΀()5-ƪުpϲ+q oդ`HHkJ*Vatҷa\|"34v^mh׷/$ro32 p=@<"c C3<)0iQkfMjQ_)kP*t(l eF4/c:> H_##-?*VO К+.;Df%eBF,'[4y~BUs|5߶p(tNGhc^ qtQ #* 9c 9_ji>geXAutG$d9xp\ KkmJ.|;|ߖ1!87<Vgpp^H?I  &.zU&n|>E0YU'vHÐ\zގЭSH7b ?Cx333!uZ7nlq{78i"N9!d? D8+vQLB;|nkT”^^p!k˸R#󮯡7l!րM" tj6dJno;`nsjK NEP|Ld G5xոnTZaߜaNWldH*-CDЕϰ X(\.w Ɗg7BZ$ZQ6zӇfJ8_%ˮ~n`q bh(v5{iV^"c/o Ͷ-jtjWO_3b}] ù]ԢP4o-C l2`1ctğeѫS2c t{*s NMFuqE UV*H | .I 0Lno iL֓C#H|zf[;-]1yY` :^>OvLQQdrlQӛK:m)ƊOQy<4-Kp0(! M>ˡ8Ҍ͘GUH?\\ @ Q9rԪBe G(}k<"D=OF,#)Ϫy0 z`&}sx.Ѐtl|<DFnml ~i[ x;[VmE4{<9LZxY*Ɗ6°e1再3ru|ƲDghIK0DVa,|o%?6Ӽ=dP~r-n'%Yi+0ڿ&-?û^lHO YB;%ы9y.`y] 9LX=[~,ba{flD$$Gk0Iph箻 ձ=Zt6`:7I"{pS<ȍTy&H#zt{ V!@$ BҠ^_n4ٴhX_[; l#bԴ%3 w=? ?{g#"apȎZ+WՐq/`Uu€w;`U_<_;TG<Ƿ:<|%JXچ&)0 >ǜ ORǯyu{Ajpu%[m))p3 n' ",1{<\^JƩv*}c@OwZ u1{}lbn\-̒X{z10::-_XSpep=+Z@?̜rBh "X ;j'g̋qA`udE>F yDRy6G"׾)vpdtHpzP+;Xf#$W3يB]7p5uKr3pF%Q[ s+3Jۑ*UܔghA=>6>n-4;qLON֠#[MkT^pV  FjqPA&~vƛ{2Rmz?m+|Il6FجB*Vԑ-Ju쯮CNoOժ޸ET|N,~t _wB3Uu%َP?`r_S%S $¡+#vPu2PHsYp!o,/[hW@0HEw O09_l/Δaj>]G{ϴuՄ~HmI~ 0TW!XE/KeZeN$xA5.y~C`3.nI%{RqTn=mf*L pDRa SCnzղTP 싚JpBn0Vn:L( WȸXKpKcS6+Vs vH } @y2y4Tr1Ԗ5(YZz)̝( ٮEb#<[XZOItUL$\ >$m1׏zdm۱'4ARkV\t.Qu1Uȍ'|PCqʁ7̋_/]sU,$P[,Î\k)RǞn|J#o2vyMDZ!M6E5N-vPYZ/ 9Ej_o3sqhR$#Sw(!-]dqmQAB ǚ1QY^+{ A D$\S,pVlDvlMhi:.|k"c _!ie_).htx$aaB*j" JG8A>:G`濫nwKJziƆs Zʄ3`qteiҍ߲`IZU9vIqBuF Dbw@׭}clsM!زDEMܘY-u|`x^F͆lb4p\ئD5RI}l+ޥa&X̵Z. 5!BIlg#0#fs Ml Rt N&d4 øF3J)5a5#iw0mܼ )MٓK/Y ZzM{pq!5B˨C_ &Q(x\U0^$kAVO=zd02Lo $!b#9kk ^QC ^O:О"HW3xl0b?J&aS3-M' ƵF9#ɤP%ބVYgF TU&Hk#* ӷ :;՗WaԽ d<‘I' 1\)Q@^uF'*`w}KY")=XRQ4lWd' ^QltP[Vŀ‰\^q!q^Q_4٘ti'ҏ X ,r 27V)6S(kȟ8|S2-ΙLŞfT_{^]d(3OwOa|j!#+V6]4!PXƍq,l{t8[7>B98$)C>Fd"vﴺ eLWÚmRbf0ODը}&h9켔$HWC$=Wjߣx* ;H'0Ԩi)c, r.Ivͪ7u@3(_D'\sfQ1Df/qוM+[-H6&YN\ INݜI8<q麆9>kzw$z3\j c69c[/j] t6n{Pog@\‰POg#<ZFi=$PkᲤMyteHDIPs K;qpkT $ 1 ;JjqmS@ZZڗfēY%gԝ3\y.UER%z(͛}L!jK1\|ds)-Ay,xNԽʼ7ijC\vyϖxIdPK@GOŐ"}^"tlD7^ԔF\:dV-u,- c+p\-φKfGܐsޕptTPQMz4 tNdUq@?k=b~?s@s c\g cd7ʀ&G?A~w4 O4ϙڀvN$qO&5 e"2S RrnTWͫކ.itGis ǘ6~j6 eڏi->_Ax_ax@!9{[dvkSIXAMɏt ΨuKLOJ8\dH»`m_&708\X]O:qJ#i wQu%ڰvW@loH}& >:3Ɩ 64vޝ•me2EreרSK)vWd}?TM $b[=m-gm[G`t}cKm '= XCJD_( ΉfXaȑ_{AşHW?p9{Ȭ-;W@_sp(0Y _9觫b"3_"Ng GrQc"}mrmnvf8_]WDo8Bt U-PI1uC{l)9&Q,)(,@,jܢ$/9T9²w3> {[zif|5e!Y#')sVUK,Sr r `-Zh <녋]N4g_ۂV 1LIU{ZΊX1A |!oUq7/0|f<dž]mCqsqU@IoۇHgw_ Gʢԡc1X̩qp "d[CWddvM=mi[ ?(;(A*kkQ5c\t633T7_TBǤq\uÝ-l[;lU64w1а: fj @^Wp3WWnbNjc4DLAvBeTg)鞭&$wB/n`aJ/ &T.οo{5 .XY:YV}JB]RJdP}nt)-OXRlx;ROq޹NP$`p^o$j\K0J(WFJ($u}Hr@*4,X$ =LiqOڲ:=/i$I(PZ nIBѢbR߭'AP,Tݬ9ӗc7"̈́)?.2]_YTS 7=?CO@sQ?3K9 @z_~7Ȗ T-B60Z NA8&3[~^Icfp=i"(~ръ0P[bәܚnd`"P&v.hx(c}#(^WB:xnO.Q-ͭU3̇E.Y~v^}UL% LM @mXͣkSq>YqUZ7SK#db s2k]XZ*Xqt҄a`0[6@ 'M4R}[iR$oJ2)ɻ%7fzߕqNژ+APrIdc]'>tpP\,L-`==O࣪}cqeT AF?$iYXs:?psh 6j g vR&˭Y 3X nL[_|%2={c^m)zom 4>J7o)Jt*4J ٯ?Ncf"b%tNLbh>;:t^m~=p#栊O n {Ph?Wpd-F/Ym:xu9&Gᡐmr7fS|i30~5~2cRǭ=c] AU8-1ë<|J `d߶'g4a B42bxм:d,YWU CH3"'5M 6&:/H ےTȪ2qWNp!W?/yn=yR#yT3<=}~m1绬 ] YA9aw`WJ LJ~Ǹ Q=}^3\WS?j@0E"hUTi(ެQ 5a5j$/N.Uz_}8 m$9khsP$mx9s2L711rsdփ>Ts;WUFmԯ 6 z&sfp:]Ϝ G$.Pm},7>s{Y` E͍oE|]F+lW`>H'!Haxl* SqiR(0 \ 1N Op!x]3 2KbKh1n BPw|vu|piyAwI"{ 2Q7o+w&x卓,£h =aws*#{H{+V6h'&s~EK\VB.Ʊ({^k0 Cvt]rN `7pEFތP0 ZhVOVb&eVRRW.̼M]"ijOItfl^ew5"p/ !kTeÓ]s{bx_ N_a6Q=z]hݳsAp*>d t--E)&[mYؑtGW9??( f8舊I/{uZMRTz1ͺQcܦkYj҈`ϼDɃ!s%sZ/1DM`֒nm4ϧ.l:u$ld3֖Q`X鉌F;Vyȓb`ML*Ux腷8'o+W~(4 C }@al]H1"Cx%i 5`SO['_^aB&qxB -4A3N$G&zF QYW.C(.~|%>=4l*Laιg1McB=}yu2LTA_ULv+u*}C$ZxsG=;ŭb1SԵnak+-AN Z&yP7|k&`87[ lB-H^'(S-:v=I'-^,q"-/[R<]d"UJ9sER?}|q( 0VNZRQ)wC?Y/]͢e Ь[aNho@TWs·b"ZZPڧ爕{[:NxaHRX,\LFR[D旟)5kwIT^+Ѽ=9ӟX,nΥGLsQۉ41(k%woOiK=:S̱_fI洋?4sW$/\;YEdm.7TnX:0QT΁L^=5*dB17/}vty~o1UP}5uI/a=^ us8> ǥql| nz+j{9rQtlsWBj(ӿ"r;SXt%z2 =n0kMm 寸EF{yFo67/eHGˍ^92qw8Ad'}@AY7;Y@KgSMM3raPx\w**vt]GD+}W`$/mt$< E9V^7e8/\3Tׯ)Z07he (^;?9Ъ ͊^YrJwȵ?Oy*pYL09()+#;5VDB{"2:m8dVrkz!7g[Pl ,xwf":P<-2(d`19,w̨5J Z,6j׼^d`7/ů(P] :];bŶ^;I -lL(d Yc$L0F#6pRV۷c4ZjuU\~힘aLj|5HCe'rٯ٠1$J$'Sp%a}Vdh6kY gkl  ΗxS$X LYvM&뚘1ip©m C XC2l~u"_ ƈc(MS=#`MW;Hub )P$cLb>Hח62$L5)ME)19XW_%ΪNG288`ҝ?jrS~}vc+gu#QrM|! -6I<_P9I"1rOHPFwE'~"·ڏbآ3{ѵ}'[/LﯽD8dW)-"ldNRs_\ҟX[-}uu<XESK`b3Izd] 3K) gO>+6[Uvl"*fETxVC+nm$ʴ#Sw@/ u[^Tm5ѬUvhi)j 3 '^jq(NEAE/wp߃4@E)LxC]mX=mUΈXULqރʯJcA>#VMx`bo,5,r{Ѱ1-,{tU\z2n10LRm*"ȵo?I-ű;=CqppZ1l3ح)Gt[]_ 7_r@~mckC ?@+Ue% p`G)x#0%p0$o?(R+2ٸ*3@jqJOhEdq[I| J@8K* C Gs: ? yV@LAhqqI:>NN&5Utdc N?f,TÇjq`ryX9]&eW-;h-ΥFTuB/WB8){ݵlJWL:%ZX7"]Yd?3"Ƶ+;' R"4 |,IcP粝/_z²9 #'(wbZSR9t#+z6-ju *\/$@* Rjͬ3_slԙJ QtǑm ph$4^yHD MOyg4k'1`B>bEs7×ov8l4RXx=%[]!U˧._\ȶ9mTGBK'!vI0(&F'$ P9[(t,S>ۧ6o`wkC,@rL)H$q$H@|gmX!pPqx Y2sZC@H]fUc 9}W%ol:Y@mnbd9^]p3)٩][!"b`gYtcM]69";7/$u\:7qIi8 5:J 7d) fcۭ@{ (mo&ank#ۆϒ$K%T4c!܀8XW&QwZ+ϵ}:%*6Oy3,Q*4WtC<$ɲITWD,fZ{44wFgEzt=nbCtt(hcsT3t|Yqgܮi  0ͤk$RlLi4E# U򉍃{BÜ@4!h\LGtƏVc,) ($3R`{Ķt@ -[@JO]c;J]#N3p5d\b-l4SQָR@2yW7 ]!`FOZɅէ9 ` 0%G6%rŤݳq;~ɡ35d}f:!0/^ݧ7ӯ.V+C|{ 1:nFZQ6BxpXھ9Ss*)@Isz%bF:UG x&Bo(0lpG8 ; P2z*:4d]X10aƔBnn}K%I'/Hj=QFs߱%#Si}{qAĶl?kx~Mwi֌ $Dt7nMɾb8:T|ZKe*yY~w vaӂb"CQiZLf4ww.4)ޑꓵJ ԙ,M ē}~LGq>M6j|NQ5E=|Kx0ewD$ q %`jEȇEaâF1-oi@H3>yE BW3:6nM 1<ߢZh@Ll2qiI 6,[ FM 6 ٳPTihEF -B)]naNUB)/`]:= ig /Eri=4bLI:W(cr̰ŧ b3"Aw O#ǸH >gT0 ÂcCyk؜[c@keR#ڴ Kkʼ$[:ӳqϞpRTE(^ǾsG "LVuxҕ # t)4M!0nj7ķ# XU?5> dAr 7֬ɛCReeʪmۻ\V:ިB?Yi1s6u,C MH'ΉmܗKz:QFجao\ÈQ]f^^R Tć=H! ݀@37:6WO{JWR"5ݢ >1a\,i P=\KǺfP[D'֪D5\hfr @z2j!ЌN;m- ER_&$O*]oZdv ( e )DbOaB{-aqZeA"꠻ c\̸R<'=rs8.a` N٢u B媅!^:ve82F (Zi^lc|&߈ \S-T1be>m^G?30,r4z}.5ޫP|_E8LͼXi+ {%ǧE)puVz0l |nG17>m;|HRw|g,k3pMazhQ m}LjTף=lk fqVXuP` ߚ\4"=;F .+HZx"x߰订D00=89p߸K`?$6+⛮ڃJ)5*R1 c<1 XJS݂}q/ΤDEllHdh siA烽F|' r63{-1 }%!H)qT:hdhmþ<(C,J]76{\л^L??NkO'0ճy2n)GF{H雜u-Pf/&=ѹhtP5.{蹨ZdpҘK3'1+/;TCVfR mg ͻSw>/| t=I .!dVaybLGsn,'?'H{RV(+J*y⤒ _? >NhU-|0ޝPQJ96w/9̀|̬˄M>Ng=7-P*GxL'[IVU@Dݢ}]؁zimc&v ~0\S+mKiVJ\hcOOC$۩X]c*Ro9GyaQ RO35TG?^j+;`Y/C6=S~PFܰi4M#-y!yCt sWfBVt6N s'[^[ En5XkѰf)j^!gB'MJLӬ׿Ls] "CLʽK ns/P6>h1n-9ܓZݏXiRG g2`V0qem+7KFБ6u۬xkҍFZ3Ǟj>1Vf$wAm=3 󝼗d 3F WTw:P8``5]JʪcٝTw5S-264\wc&> ˡ^8%)؇͘qTO] z/Ȟ8g.ax q35&e:W.'Ǧ8l47#Ʋ-%CfkWCB=2 Nv}*t=ޑ{ӡS8hqk#b4jmX3+]yӢX]p"AtzX.S>{O'rB9( ۈ ѭ3F{so`x}{"X)uAJC3{cSP'+@-""S\?w47}#O Z =!'wm0GfRIG5Dm2%KC$c KWlo#=~-R,Ӻ 蓝CݦA[LbpiN[•uѵNZǒ"h…(/sՍ94ǰuh'FlWBՆ^e4M>N&H #PYG%]ظ MUgiʟq#F9BSk{^?2n$CLva& fǥ"c>8H&\o.dpv:)J[jf`]]VD;KF,Au}]EiNt_* wn{HyB;Yr)ap&%ψ6yrۭ:LT*VE >DIW>.U>7F& + 7* 1Oxf@[y"yQKU8p8?f }&ݳV8;R#l4_lxuP}y~0mlߝ$kS@2hRT5p̩" ;c %y{^/AYCq)/#;u5%Nr4irt^ 6Dimғ!RLnn) 9 pl0|\HeB[|Ks٫KpݎUbo94:ƹxKfTۢv#54r$6'O$ (};EKGB|xk񃿐t zs{tROOʾ7{ÀuA$]klhlg1%B'k!qX&jD~{l!Vi4뒤Z35Wclqr7 [t|iR"xwN-~ձDBfC57%T+*rZJpd#݉91IEη4jЗJgb[9 #La v !Nv;n; RW*߆¦Ʋ_&x%JTgz +~zJXX!-!j2щ05{ǙL:Lcc1;3<\}xď) `lJ/(OL٧DSMM)yFg۷-a/*!Gl쀲mH&mnc*b& #_j *[J ]Aih)tפ1ނewr)Tkσ @Em -:-Rl7rb `"0ĠXXnGu-9cP|v #|p6x NuQcne-Zzw\  4;EBHn;G1ξ^\[{(BGvJLoI5 kBH7:[VZ}BȕMSJ 3&^,Lm ϗ+yiՁ0dw' XAtkͻR l3MÄ=Et4§+IxL JZy$.¤nvo\N&7`LM +Jpp٫N7m72c$;">0jƏ@;"DN&"2PE,uL+JX}"\9Pc󘶓-W`̍%֍lvj[q {x#nJH;2pQdIv]!K x9NVä^yu(.\fT|PeQJ*/D^G G/JǗݔiTk(rgY r~UEly1UC53 2Ҩl*}RE, &ev>L[r 彖."*ln|Q:Sld AA"SXl\_|RM9McKOV;]4LwtK;ǹ;xzT |g,AFhOnbaZME8Plbn:OSnA _w# w QXoQ>5+\ K6>GyO7 N Tiۂƞf3lyC"ih&/yidm0y KT5Pp} #< Mލ{bGKFQڅk{ =5-ҽ޺ |2i`tGw;xXg٠Opd#lJj-DyАXkΟIqJ3פF& ,k~\9_'Mi$kuMZbW!5YY֋I;m\Z:tsyv~n"?hI[ S6{-"H(yߞa/Ǒ'`UØ ;!;bHkj]6|,v4:dvl)v<2-\ H=dezcY䌊%Sܱi|S(asIEpDy"2-:#~8zR? 3:V6*> 8@4ziy&AbA(;LC ˪M[5b߰&)'i5FEѡh-HS!~>d з|4{@&V P/[n@|O,bjH6H}CUSh'y#$#ʌ`dd1i-##0*fxjyyrDt`p-{2"F]SMeMj5A8GiPvq!t\IF5rb~N00hޝW̻%u[ABPi<í)'g !5ğ!u>rο[y1@wbYsϋ(HnwPO5~"n)ou󠲻hS:U?!M%F-@"phQz -zh hw(BBXV:BCӹ}= yyw[:L#;X|)ɃHm':&'$敶[K//cĎ![ ]UA `5[uOQg @hvIL3mpBw,eL+xZU@Nz׹>{4)4_T9Q͆\7hrvK epU} -'n%d`+xd6ԷHbùP10ʀ= =˸TOW|t\Ǐd)%ĥKWS$BnY%pI(`nsNSn,u,Lv~3xVAWaD )@$/b K>ՕLۚL43"h~}*`k㝕0'nUc gh0H0w5k\ kVN-:9V|:4MسcM3q[:Kn4A7Ȥ5s!N)%i{l)z6NМufs8Fi`Hh$y]VAZE+BbEz fr :yI8OKUu!]@mW1KSL5Y8jw^= i%;~cU3'R>DgR1P=(W05-~9.>?*{̸>IHlmn> W`E9zu p{2!ѻ+/|t=o|R#c~pm]s~8mj PhvRo:"us|ٶKY[}:X_VR`}.p\,܃1\H2 k!m|c #jrG D g^5g5Ie⤲EdV yۥ`j7}ĮvP(yl;,w o(.\ M gBT EFAĩi$b$%Kov= _9ؑޖ8sMdz N=tDks ;eu9yW_ ĝkBY "!6S!ZfG XC趫>$e`G۵8)(! WL4<N``a3K}dҚ8]ۭMk &#@+OL*δ+v%|{x1 'ZٮQ*upT PaPuWG{}0CodW0$p Tm"684xe+gM(QC"{eƨUq偬 +>l+g{ 41c|/$ZG0 O}$QBdnec?꠸9qWH/(xtư/r<+6g`ƼE[`աd. {hYlalt,pD 6* ,ε 7~IhS?5 Fzߞc 'POӎ˼>`ܫ$DN6RqW$*’/(:[]鋪* s=K2V|GI~ͭšo-BGNJ5b9\,JIc|έhR̹[o xK%A.K}Df%OYޫC嚤LRxiLw{wDn#~uT0sL@ߺOljAQJL5A)J2KSiQ]#."}𙕽B B6_uK(:i`ɫ862u8ƷЛ7$R(ްLA["e@J]FyzISƤFXٻE:W|n!-`W!8 oVEEu (Xas<zEtǯҲ*:Ԝ})>Ky:F=g3,%}t|%p]4+A0ʍ:f `g[X<*=cCsH@@0lrv 2>,-}Rwk6Y<1)BφLZ ^N*G9{0W3[::dM!nd~Mo<>#zW@}53klg}^>mw,ϐ lr"rS\= .6%PgPJojXil0r Ln{MIŐ-cv8p l<{GEht{iQh'PpxKuk'yu,d†JAxrDmQ|E_H|r'm@`[,#U0 ܑ@]  fHXsIijWDl1[AleWiRR'Po7FRvOAr FXƚ̡W2)P@qYe"2P41u꿵ͅ72I$Oۅ:BEUYhe6VQUe;7ZKiTmŰ MVx'ĩ%i=7QQO_Y'eKZK,@P}2QJ'Ů\/b,Sg 7>I?Ɋ5=@45;0\ޒYV ~fii25ÞiG4:jA_M ݿ_vБ,+%klVGT^oIy_[X!iOKO!Gh_O{Y`X8r)|e$qlM~PT#"W$5xrbnqe4$A&dV+47'ؐӰ¾,*nBRTzhJ$x*~%q-|q`#VE$;<&:Ŏ[d `Mpg+W~)IwTCey흉Y3++?~b|v91VZyw^[/#ba PrxL(@xTfpMS Z欆 UnjB(9Mi*7[HE9N bƝJA8W{DAf֤ q`<@#B+ٷzw>zwona^e!cH+[%:XoSO]CHτaZb{ܨ7g 'KZT{!S&3iqsSdF'ZS.N?MpPa8"vX)B͡ *c,nGMdc*9sujQK]y$oNƤY߄ j2=UjFk9J]UmW7!R+m~K.҂"ƹ@uD "l-KJd $:=gȻC;]=n؛m޴r_e=9Q Wiayh+ENEޖw'8vk3Юϼvzlea6F>He?YN߭Mi^Sv`a8'W169 ģAFg_;|<_13q6`b KwS驐V}{o96 rCִA`!rPXȱzlLQ4ɾ%O] l۫ʍɹ=vy9y!qq^b~Ϫ}|k|. eR6lc!W3 &y暅C88䡴{z@-JcuG_Qnˁkؿ$,4\MW_na\9|KbC9T =“=;'m;RA7'H.TI` !4=. `*?,%M@U#l 'D8<}J#K;{/9ô'=ĴyZ~+ixpI P顺ҞS.gke^2%Hn& EK|r0 u{sxO\mQ/ZՎ͠.R332h*pnJSyy{"$t9aA쓷P 2d8zU I!(2*"[EoyN|cL-6Tnɧ)%{TиOpF{[64̻(% EAwJX,AG$MSGhNڗ vodUC΢(* 88*W.tQnF5BgƂ,lE$ȅts['k;=09 vOWb"YUS⁘"ih kI+V*d~Q=ʹ/Y(Fsզ(1$<}.4Ԯtv`8wƯ7j=h+BԖP¨-6OƉ6(7PDs_14$ZY[n2cꊟBcc)]EL"_6x6ɫal!^Lɀqarw-G…GNz<apt҉Xv(62g؜_Xԫ*k~@l)^oEV=)(h~{"FN4?guG@؍Vm~;dkWA«'˗B겲_dylU'Wo|kwu68rbY uh< 6fFr19_?EG4`7g{&Oh,e)zٿ>E&Ƽ3U@,얉U1NSC,Y h/V4_unUE/ W!~D Bg]оǧ 4-g8[>;ƅׅ盤,ڗj^KE+"9GrZh\hC5yg93ͬ槉DzQαC`԰)B`DRcN؇@([D6T[J"O,MH g8v/*nP-oPNOr[6 B8lmg# 6`D6]^\.>vЯ&D &Yx } %V΁:T+e}2 iSnoMI0ZlE83< G;ES#s愲 ˇFy)`R02ȃ6PBnl{j|_?fm}v1Y9ide"}JT^ M?|[qŀ}(ͧ+ \,2!Ũx闕fdR- D, ÷f_Q^GZ!GJtݳPmiR |g*e|r0ي&dS8CxؑL ~]Ʃ>'1ʺ=ꃣ/N$u$o HiwN@CKkh"]%Y|1O,9؉k;/A_NԯAYR5K6[kj?G "ra#}4T.esGn#@ ooA\f#)~k`P)u*] 2IUћ)Kq@]k#( yӠp%%*.VVZՠ)Ƀjzޯb/0tēRAJg195 WLF>dBdTf ndt5-^`AhGQX~`Q^ T(S+_Pu> ne7l>vza5^G`Z<ԙc;F ZYȌT:1vD>6IäW-#ϧKf ʞӝ[& ۟}0rETfa${ ab_7YftlMl/yxӘ cɂcP*\`$ƂWxZ[Q%K66^[d(tu"X,!]+\1P G)aD7xjQz#$dpR!vڧ/VTF, 5}ׅJE^qK7['`zY(֛H< AsBϝ(x :LtNӭ"+5B <6dp/HRe|Dг{)A,=$x|x:*ѧMqLsf5 ̡wYv% bLc$s=';ݰPM5(5ø8 P<"7C[O%pwVT̮67FHkŸkIҁ2;8H+@ۚ ]bC)ԧýl ?8e?ƥO`Ry鯶_q]yI'݂$\w\ .C"Ly8Glc΂Mw FBVЂ8u*غattgJޚm9L]hK]FƯ-yp>دjϬB84WL#? BIo S=?vv-q!ES1hsH BFe|n 7VAǀ+]ɇ_6>W ҏ.^u3D-ɽoW`lŻOĘ7*np18%2){ R%;M%*_rYIt=Nz4fC<+߲좊AV9?fJ`@r*Gz03jbPEשfiS`z/İܔǖ(oG'޵;.O b!?}[v(wcQ:38"I3vfF :q"<ߜl41kbDBmob*ffgPJZ'ȕ!^/@hӬRF}6e7p2|H.|!5ZW3 _0-nJY4NaXK l%`졇[/]ROh$+;aKኸM ĥ2281P/wׯluM"**yM^,}"$׽H?я|VlnB&!ΉI/=.T ͯ;YGpK}hHe:Ļɛ{qDGx+Cp=`6RM|-Ym[,ҕpE9PoSdHQw  ק*Lˁ,r9_( %Oh_nͳ.XV|T&0sI-QS~)vyƗꕹpjD=in\w,no5uZJRF<\f ܞh2H/fK©"J [Q%ΉwBхP5.tYhDXK8l`4Cy=:~Ivҋ5E+4hLKau+x)K&5w]uޤNωLƂe=Ɓ}IdPO~0zxLp$dm\nYQ~#jAmgقlAm!'i%kfZuJ$L+8wBlH~3l?@2IT{:a2.Hٟ Č߄pPpeR_\,ϓ|('pWh)#aҷvOoYipHR0`K[V|"UyP7N~x/[v eJj<_#kD 7(:NБ%]E2!s_6?y0u|\ U<5=h}^' x&.<Ƒ%v}F;六4!v,=<*4 (_f2N}xcqq] ?†p-* 셂/!tL'І#-#A+Y=ozǃa`m=O3 yr}˅+2Yt ppp#;Gn8K~Ľ^C;NЩTjM(6EZ_43灪+v(\X0'E2>cO3}߸:;+‹EN|5n\5ihγYMҲA&Πo K#"|т8[Zz0#Bıt.w1ʺAkIJ+bVzH8#榸~1ŝ"Of~7o;/u OoݹVri7abqfs1Zf 7vЖ`U|YZISLR&9){`4M26k}//@tN}}mEaڋf(5 )höZ.(8g0$e,׎_FʫmǬ0v^&7QG.C{$b&z S#f_zVմ'u+{tPzFK 8+ ?C G^u!k4̺jdW_7{价r;>m-vyZ/ή𙜢(>ZvX[ >h y]7ɦ@r9Nk3CNǵLD0qVtQwdr@6CaȨ0Fw[;3 ]n=8igYn:E/y[C@[Յzy#:.iӄAް/'TݥaDkͷ aչ(= 0N{|iLrht(ҝEOdpKtw_@ $rw| 'ՀSKUĝQ('1?!rcqɜ^}ǀ<.TPDN/ 4 aKn1]޶a"."@U>~!"@x4?ux$ <P%/xḺp̼=I"}H 8C7kp*\4+]Qm-zzlnj5o)m*6>Z/^$wDT+ ]E# G { UB:QW1O=^Yޘ))7ɞጳG|E'l|3jdGx*#ˠDr 6ROPb.;uoO,8~3\ Hdj&GS=ZZ MH*Wj_qt0D)qt3Figĥ4 Q2N,h\=niGr 7n}R ӧ6@ZY Hd0Px@/ny`7ȢJ xfOshSo'׋b\bwl;Zq[AѤ3#놴1fRJ ,S&/Hc8naiX`4μZ+jcQ =Mk m)f](N6.xH ݦ cU6uU||fvK/J@U72q+jʹ93g2鎺]IXGZ;.`~_ e(r>cLD[^vJ"p. MUiZbȰ}hE>L b9rnGcoWoT]`L"PܷQsN'[B11o˪GhK%[1|B 7Tm&'|Eh0ߺaL: ]Tע9ALYad$SR=8'[$iY+lQZS=> I^[8f}Z5UOjdOwmPcC;N8"O._ʾŏ!l+rk8Et^|2 tlc* yb[Ќk0Y-HIT2$U"IĆkk̤Sʱb&X^DecԬ?ۧH<:*\B^YʲE_2:|CODD)Ww82'DF' 174LZ PFns_?}ƽ۵+DNhncc5 I rFgGB.2wxjjf\Wwү>cǮCp̬G9YW)V:uM(Z\~\vbmAqNl܆T4]_}jgx#e Ѹ:ZZ<4,0lմfz:?B~ukhm.D+_Ev9_9;j5aCVQ*{+dF;2vam =:T=^tܲm6g zΓ*pqR7\_+YY:gL:poq=򙗹UKFm V;ke=!G~]GX}'Z ~֮\~ D]R;;i-gx̙FfjH$foc]<.BO~ 23[ms&I(UxhVq1BᛄY#JwVOo>E/yF@ :E'Q xz א\l,5Zy"`DPBlH@a+/'A z]AAf0yƷ|6='kK+-WK١nzF*:xY3휶'vHY0p ϓtޚ '849PiGB *z"4:#&f9oARfvh/Sǘmp k]>T怂c) CSOh֊1:G*l':br=CgJmr1]^ :F3U ]5kt\gn'=_!0|Q/Y-b9[6o족QԢuMB]ֵͦ?[pENMW8T6#)EO9¼Hi2HXeI+kO7}Q|q2cGЛ4'1D/z<JvڼKD~NQͬ=g=g1I0/9` k+Ľl7}x|٥ U\,g-7!0H$E*qj۸r9Dn)o䨎L8sUţ64Qek"f?Z$1eOSYFĦ (;qC lpnԇ}d驥-&> <+V䐿IyD U tJ⛢ 5"`hM$=PbEE>mwE1*XVmw +wnLJvQhouЁ7A9ʡ԰3u,S(夒@A$LD -)ַ)!n3Zh)Li̮,k/U8TbډJ]B&p0JAx*5PGWqGwD+֐ źy`;*a}zi/lV}/4bs(*Nkʞb9Wi@ ߿OZDx ڠ8 חjrٽRbʨ'],gi*3?u dVs ļm$~a}.@~.ϲh{GN-bW; R1$ZOOp#iTSmb!.RFo璬sW?2`4~Sd7f07՜LN&!\w[zd&y7Ru g`yG7C i? 7DqW[M4q8խ@J;p1IbO% lQC!#PaR-S{bt|ZTjĠOeD;o}Q.cuXh5/lk֬sbc/y=ZUAM|҃)h|4K ]cŭMԄJϺ"m?Ub`"Mÿht$/~0ԕӟ/]g "=d9=͓!کԯ7#,O>O?%KAےzՋY:@ݒgҽ Mǟc“>)Uo}؇(BeLyn+{qcWHCSJn%!Lpw(\;H߲$bЗrx9.맓_=+o y@.T gJϜFUDBJ&k΂mݘ0 /(sA_VKoz$)#$q=B`fF Y,MZt\>(]咧 hVyZ5Ɖӯ"6S*n9GECQ\ >2v71,ZfĢ "U^ٷKN(/+$2C׆n摚˪2j1&. \Ld}͵&WEDM.QHb_70W8z/m 7#> fmwz#֘Ntk 7W2V[/{0ᒡCBM1C,gmy I- 9S.u]H準!~aEYhx!؇iQJсJO EQ] x>i9Z@er 1,EЪS@LAUrvTOݻUğX9Hunz媤iTXJ͋( T$ pF.]—_YV~QGߐzR[9bR[g33YGcՁl(M"kq FE qMS}Qz;V/Tc0Ee퐟Fk]J,_)KC^E>S\?(esYX=N+K aKA4*p["vCM9$-üe^9ʈ< (Q^qʑ_ⵔ'Q(4O *c~6? Q)(luɭ-zloG7R=e{z8uk;i.qG$QإR\VK { ^%zfj(zbe7m<*w8:ڑ +ac4q52BWSٱ!c# |R[DV K̻&RWȎA96 ؘs\qە*)+ʀM'Y* 믮w%:oNŐjFG.o1qfa5!bھRgE:LwNuaQ0_XMjǝE|vEcd<Ւ)J.`ݚWKHCcYU'!6ipC& ĜzRH8v6Cu#<ـ l>^8U玽ŷ^nFK36!֗ʓY ޑ裞 >IYpC~b9=oUlH0& ɐ^rxmVӽC/KȄ4<_ZbWdcg~/BO. 0SI0rEec|M0J)_d%gּk auPF2J+iNd˔d "yvcs4&IXʊaPNVE9`6R ׻iUc(KÇa(]@<1Df_EbϾj%RMc89/ tӯn@j^ /M{s(u؃3R1tQm5$Wתx1uN}gbЉ\5r8@gTA |ڬQ!cήv]:X`4yAJ.Oyd<\s䐭um݉ ƟMLAtdGv=%}¿;8q#\oNC% Xb_\|I[1?H3hnOp5G`J}{DQ' @S{c;,Sr5c"ίZ [=#>MTWH=r^D$.ed;iJn7hn=fh/`4h~]D)PS>7l×gL mx+mĿsiei񷩺lhu# έN'|]H]gn BaNn7`ET'+dWbfTgz 76)՘hU~jp֮[W]Ⱥ܁Mw,DArXJ VE":.hp%<?j oXc0H L 9<#<OsC #AcŬ kdo=ct}S. Hs)Dր5̹>JͅwNٍdHXoQJC⢜e`8$G^oI$LpWRHW&jNA-븘Q_ ;(sO:@eqA{ѫ柄(\9xn|ƧL擮ƫaD${+ȷE: `Qn/ȰgU®]T%eT!ߕ9IJFixЈ8kZAYWu |GW)F1UX4:k/OU1MD:2FV*QwBRJgPGr~IB ]Wm%?ۤmwL`W[Wk bu仈 ,+>n?R:NR%"s<[^av%Ts>}0t0] PU%O{g 6zCKdxK @TGs# @=`g J)D6YrLjl5f[hp@lӔc&kq.0lJrɐ.˺|g6mI#H~'[q@uF-‎ge֜E?vU@mt}Mcmk [}wȘOޗk $EfJ!Gk&uB<]ѳ3o~6阴pB0е暶{ C?QCĀe5GE(-Wa>$1l?m}lD{yfEHx ph-F=O2eMoo@a7ceۥt{*"CWMb]~tT-'M#ÿG0dTϵdIC{D7!C+CK-3qq`LjPDG:'5C_SR8Ěmִ*yϥq:@lBH"'f&޴$m0:)NT}w n4cvB&f- RYcÚ .a-[.QEoAco 7Q~)t5u0a>EFg.<9x4:Jøg)o" $_'j<}rsCbK̫ h1Lα"4|/<: ΛZplwQִ9nS%;a˟OQUdE1f~V^םު|zb%]:g?LyPm2z>YIU`ww2maaLdcr}p\AX|+h8&r*zRkD,lVE Cug HQ.RQJWݶGFl'Hwbɸ}'ˏ~ 5Χ T<_ʕP[DT4& GQ\?mm.B@paξ]qz^c עN0z0]yKtJ"UYnZ<oo)~~+o'd !Z C-@J58TRD!QM-2,lGnioڊʩLhFIEVJUR d(Ÿ,\Zic[:T$>~K!I̞K_HY }zB(^ŔjěO4qRϋbDTI+PэzwU)':M{&R<3Vnd+;F=44IN?W͎_A9[bkM4@ජF j]fc)PnzYO Oy{lWHkHSb ٰN.Фg99 raG$uxVXM~Fh?'.?=0y_) ZDL}!-8UX6[vC$>?i*}NrB(_c2>jJTeqȼ"ֱٓY- |x([+V:# 1ɏ|ÈK=;v) 0J)7yb7zЧŶ+~xH `9$enîC070fSC1{ +:?)RCC)>W=2k|ݟ1~S`bm}À-x3 \ƾ 5ׂA@^A'F-6LpƿѨe:Bާy`x @)67 /~ HSAN=0,NfN1-_|ᗰ%Y̬™HyX ܙ}m':tV rxe ڸ/uo#l?z=B2O%Z B?=Oh|9}y![d8@%5mb{/brg)3)^&RC8ZlW- G #(0;FC]?O8: | DGOGs!{8޼Aԑ8}4vA-,ͧoղt`or߁|·Ie6 0Pn#3Ď%]=~P{DYcm͜.\o  mOԐ 9˜vu^ ks 㮢p4>C**}168ڿRO\ƁЍswdK`>jBSt7 +JlC l=7LlvP; H2[ɼ~e,+퐤*&Zo m/1^d WȡM2^)K8i`_ \q]K8 &Sϣ=Js^b%ӤƔ "kS |CX֜G%~TJB8VMa\%h⅙gYsazchskCzUghvQ%83ͺ}eu|JOYVicӜ6Py=Iye"gMϰql >zf&q RW`Ԩ1w%4ÑFMm I0º~Tcͩ+2Doި]+v&T_騍/- 4l /3>= fni8O(,u7gA|Ίa|)yVwc3K`0@;B8FD1쀋b̀QӴVYȗK)3LG Ƚ$3zf;v_oLW?먪r!'ypNXɼ`X`4&#jmc%cAp"MJ`т.Lu2!Qu 2Ƨݦd!'fodrbG(Camcr+bTե'|`*t|QY]kȭ>Aj_Dw ޫ" QmZaRYҋ[.'<.Be%BDI8$dxboE:0gg͗o"sV7E;K3?d0gϬڢ?;Hqcot٦ݒRڼ q '/l/$r7 g-!]GhzPu¸C`yph, EMa늬B~6_xR}}N`ZtNYkd!l_J9/$EJ{o_< ڨ [@|Wb$Y1O4І˩#ƮP \ՠoeP |UxXᛑlz:kP H9ه`s5 _Xc<"iwuK0ӊ[ruwڳRla*FA)l$_&ũnJ_ǽ!7~ZbԭA߈##"yEY05}d ,c%Jw۸WViTl)˫/Ɣ# D5QxBʹl|8}k&Y8eLH)R'EMqQ, 0נ@5e` h _"Ei>YGnh\m<)loRl7r1ݩx^_ӣH.*"n>z!/-=0~e-=9kz-fi2>j \r9ncfL5B&ʑ4ZH1)T /~UQa(CAbaS˓45{H1=jӍݮP |ˊp aO18v@>(GIjŋwFa½(,SiJj.]D^{e$@[MRX .QDK..E]Lܷߞ󽓂{T5,#1;&ܚdVe&tqK{ՄEFr5Pbۧ1^⣛ń$hr17)_U\SÎ;E/Qϔ7 [mMͲ40x`Ѩ&Wv۲sP*c؜5PD.(>Q\2?'7#eݽ82 ։Qc Padܽ"2Mv< gk0a9+δ@ UӔn(x0uW&Z8qNꑵh#$?[.ޓA#^'ZoR4c&7o_a%Di_[^7LPW؂a‰.EǎK>VD}RvA[ed7=0n*V Jʴ2GY?mwiy ;ѸGq} x9w.Mc_7Z_z:-f޳y='XqFXҵ3$ sԖINFt'U_@1$U6u߯[O+!L] 2$_C[%F/AEF}ƠMI?nSvy#0`睲Ж'k!^xч|Z_zd Iw U"esy4 7ew;aHhFޑ:k otyVN>xD\;R CpP Bi%Ѿٟk$oJ g}'T-=!R_5UIODuFB˩}_7W{T[-]Ľmx0z$N4a.KG"+gx`p1nx3F/(frç([ L/0%s̏^88VBh'%2УuK, ꤋ ~]#Ħѹk1bՓsԀ)>ZA-Xѡ{`og0P8|}O+\DR|FX \Xis/ ^&Dhz(Ȏ4Þ0RkE`Ɇ%csb9hPEƇqLSi(K'jۘ5bGW*F7n܁]D /OrΒ!;SB .z+&rmGH{LX 5Me镃(ppk7y^5Z;IM_]V;(̣,Y1^3I] L(TE#+2+tP95(ɇFa1Ni߯FJ?eڕ^<=ON߻&d&:֘[E[0NP[Oc E17n·IE·lYZTkY{;,F^@Y$9Q#qdPm8}P2_}s2N|G\XqHv:=#BtSx^RB{ ;cn䗚_-T-\ iu9BmM<\LhldI`vg~k*VhobO$/hf(uM y(سqK8`EQ2td u5q-U*?2@&k%f1̦ Q<0G޽ƥcbܗ6DQIyyHQ۸ GHgg3cn+u*0A]E+";-Hqyy҈Ʊ,[x0:iW3u)!bQ)7,t7Td9 DfV(+xiڀm1"'QB0a{:Qm~aeu8lHk+Ј%rjWl,D[iT_5_@3;*7R-4Aф"\q v=-d 9gb'{9UTzY\P$Q5D=AǁW|gԙ'f YzZ<qpqj.DH?쇮5 ƣv%w~=vsri׊4~CG˷B~[u*( 8e|M΃LmXt Ĺ*HY]=63rF'p DŅ*ɠ.&^K>fwHne*O2D꾔j4i.3; {]WZg?~QWeIgnt<1Εftx\g 6Jiʌ1]( Kxm{3=P$.!X8??nPWd>)Ob$R/qq_/%%lC_8Nk֭R:0i8G kkW;CS_a6YSXrlu4h $9WY~e"/uFklЈ_g۸~]([Ubdg7kI7Bus5^bty[&G7U@ LgJ%C ALOsGc-;-K /  L 54ھhZ ɻP EBHQI֕n.oyspBʉ`O+[FĞpxLt`Kx^:䶏\7q0D51* ㊬*}BJsYj4%z&P/O7(a= [GQ~0Rލ/߂ 4CK Z"wk>=c"a=#d(k(1rQ\`Pner5(D*4\B"ۍ* cBUpd%"&H5[w\le-tz-g:F9C{җuVݘgk 3ڥ]%Mߛ(G݌/3B VXN>b? j}OC'L/&pt68>)H\Uw~yIox3a-r5^gpiѻԲp%c9JI`wF< >!fֺ2W@q3k9rD۲H&~ޘ]u(+ ,e+?YeO2MmQ١h:0-ZΡW:~\i_AQu*'eS>&B2.J4Sb9( ~#ܣP}Gh!omaxJMaLa޷A`@9:yhefbI5fZw~mtFAX Ԟn/ƒx׷{g I“A+nh@Pl;I:k˱ ƥ^ű+F )Ys%kcI )LEC|:0E HKX$=a/>zq5uk'_3X_B$bĭI579~=+ >mh tW۶rQDx2$S'p-|Z VuFRT,4x@[SiSK9 F6"lS:#o(Zp+ރ2tHB5 e)2}xVd pZMōI m2W@gB,rEd2;єg -sAp3;B72&[E*DV q{-s/d~@\AO}iS|oY> ̬UM.*IT),M`Q׸ 9Y0龜L? 'p籦X#Ikb}7Q Ϊn_rt:Nˆ8sfS~fDtSɽJHuתxLкLA@_#5һ^d!n;:h077^ux7}9'AgnT0,XtaGxOg-eϠ;Yeq@9&:'q(Fr'ĥrPQJ ]^#`M`E2*<ЋCSvh p4!A;~R DZ$Qw|i5ty:2>A: ԱFV(L:=t}Yhբ||Yp 6\g%Yklokbӟ3(z B>+p)v[FoԈ;2TJd?5U =' їk~Dkh1Ax( ƃ>!R0I4hՉX* mf"wM=ǔǡ1vf86 |1ۖ1 JYw@ w<~nE~_atbHdĮkԚ@D҈ вM6,WP{˛'U4MN% 42w.[QpC_`ގd69,vW.Lʲߩ\b`/Pgy"%y7ݴA3ݪc]ɗ*NkiEwG>Mb:HmаP#$0!L"pԺ&"89`D9%vX#z]@t׾kD_zduFO|:u(Z|[Tn!7DWkz y Yc<BW^Ѱ?_|,?;: ,z߫L}joA_}8W**jYs$++1Tkڸ}Ґq#EAhg P:Ka8Lkr OI4Yu'dA)@_i$ٗijP 9 vRCDSɗ?|GV3LޱS1Xí S҃X+ !6p^Sel{cPN7\K?H0Iiz{A" G l Ǹ֚2 >U7 #WZ*V5A.]-EOV5N?$["~ 2 Tŋ2֚&a\JCསXwH.L?h\A'bk_`p_~%r2% x$c#~!lU'W<=+a'Xlá< {WKJnӝG‰^YBKó?1ÎSѾx eM[#DO,-y  P 6n,!J}%VYX-/])hq ʡu\ 05}9E31lp j^;vZ&ʉ<ɼA? 1H`*טU!㕴 wGW-AhYyr)(s6e3@3 .hb'-|ZC 월Og8p2AugLzHM85¦i6 m旑('ӛ}*|&#~ 9'fv|t.*X[΁ jZ/z8uct`&lX3K\sEؠ1nF]U2xݺo[ ;)Iz k_8_~ƱںL)J+}q)mJvU;izJ@RZ@ eІj|N-)eC㜨8+uȪ<w/1ј2rӑ9Л 8._kL{t{sesx:,eb'ucq; )qvu7 剠Zylśn0ܾĥRiN5kV-vkGnpH´Y q FL4[y*Wczu#,%!hN%}LROR!˾GU- `?~8F} dsT ;vF`# +Ta3YT\?B mA Ѩ?J#yJuH_+ۋ+O*L5~Ww8}kv%k8kpfJ[rwqhUEӮ &a>zkdwtzQ1t#PB9&w,A p.>C`4{Ql`R\WIn\C9:J GJa;c[: iEd.Way7(&˜TԉHdc=Y)ELh֖}3~1Ou >Z 9'E\x>'ݝ AVj"ŝ3L( AՒF2_5.cWgk /з4y8M&~b)G,>Qܩ>mMM5r(X*qb(pUzg(u@wN23hL8 l@ vE tJ.Z dJLȳy>Ik-}uV]fqȭʜ$;&#$c7 +2~Rj#z(uOW3,L̄=[aQ#jfeɤa^̒ʴ &Ip N˧~X!9|+fĻ%S ?NɩU?HíZ,𲏂i wV݁6}ňC(xOՉOnk%]=է R66,A{sVG_[Dw7lTsY.]] =K}W_h/,Uq=t\0L޼y@>0B`hL (}|u;? !K%Gd0eDZ*^'̾tA}ZH~W$c-a.n'c^÷ƈ~/ V戓&z"{z8=?@ .n#%KGE4W|yPH {{HsYC d~ЪwwuTƝe^ʊ;}Ghkkڅ]E&q"`.gED+~MkҴU͟(~9N6)HH|O(>`5'3aJaa2Pnae +M΅`, QZ}{Nr\Dxʃ q[=٣:lyJ)yWF[Ⱥsi0.ǔ6aQ%Dzxʢt>+[~༬`vP΀PS3Zw&%@mcy,dVkĉq2RE񕻽gQ)V#fnu{Iu?10 ځFqieS֍NWXWc;sR-q T_ʞ>fU`W19vNP-?[*rs80?OCzOaZxf6D輑lBD핍:ZkEoRqluYp(/ő#GH+q r~5blSg!iۂ& . _ 5jTID6QrmR++-GGT7UbC?D~!L i"l8h\JWf~Wm9L~ůp^-|yM͢:֬Rr9`aB Z]9c[ԦҊay-&T$>+ c!Qf!U̹%CqȿƗO8n"^y|VqդVC%rvtq\B9М{Msv6n&ڌ̻%B3hyϙzTHx`\[NԷpAqk,_{}#1!:c0PpKob/ğP^q.# Dm).F{C,NkuDA!#gz E!#Fgfu1:Meהqb}Q6 ւT6a9657vjt(iv`@kGTX(M(J@F<,NW ;V.unTZ}\I_M1 z8.*ii>!7 n;+DB9[(sL SEfzڇFxTn@u罶#'Kmn4L"7ݶ/?Y~qbt}md}ވ+zwOZg LL,WdZl֫@%_,ҭ'r63@YV[!$>]Q皡"'.(]p׊ W{ݔy]lfZ|uZ_R Zm}hʐtf"*ƙ˛u_)mPsQoAQIM˫4vwW\,*(!-h᪝Le%íZR`E f% e!&P$+:.:¸%(.he]V PTrYQU7 `J88=P4JsB $>\ >Mi͝p ~)m+)J0-{Rz{4#nTvS;/2\FBfY 3(oThg*VR)&n$!DJ%K§_-Z<}(o5=Xv۠~&f%o>8FmNThAqD i})!BTmA.urq3H LH U0&OE.\ '7կ͹t+!oMjcQ C tThOYSNڌAKkYJ&}`@&M`_ql B/˩X7̶6ư nbR" iMFDs37 2ZL݂RqNO_4L[eחf27Gi2jx,h7OO #|o^0'~COLFBe`SFuƸЂ6zgtnDo4u’y/K*y>oTǔ_5aZd?l!cTK;מ=%ND BƝl&syʚaw ?XƊ\mrUP.LhVB n Ǚ1m'70]|^Pz$S/}#)XTfaE0R xʾP\ܢ#eE`-zHN5R^WTz]+E/QHދt;;~zY{28?Q ܁:Ѡ3m'R֫)ڳsV:C.3^?b}Mο5=qDdIH,6)(GL%: MuE?AXPsBLLfJF*Lս{Lyհ1W7xbTĻFynH ZV߮;LmpxsOxftO1D9Kl--%_@gAi bv2W4OIZ])#vFɦ$[]R`;_wngyIƖS"ׂ*PD,/t8m s,>cW4˒fB 4;Qzb75 z0&W#wC09^g.fM rb1"eSr;;D_`5,[ηmO]@i[FžI#[t=#|So~Sj,끒5Dl^d. }e~c@e)$) b#(mwIamusZܸ7DTҶ;mT%\6>J# YN@`5}5y40zs~Wi}Bg(3M_wRVM[, 7%b p<ХH ׹SlʢRA}wy WcH]׾_U.,Pq}] zr) A<<%kQ, ư .O%o9Xl.i |@ǑwnM8kEUpe'bSE@7Qsse%wܢ0{Ee= Ǒ1seN&pt%mQNA:"|ڢ⧑렟=N,H-0Obe{Y~3#-rajK§7t7^\h1 OܘǙiVyd7^V~`"mk4ΎikpݏNUk5wf5mΌNtCzC3iws26wTrdw?9{Ct|#vg', 4(\d\*9ja FҘா}_VǏhtC\(8n0 t}[c} OG&>)LJ5IV6>a2tv@m>O9d*-9 !"GPҥ3e[!o[ ZSkR]=?n*4bmDUtQȔu^Z x Ne,E<;O˕r [rPik0X|ٻ{̿%w%9v~wM&[I1Td_3W~#ZDMضj>A (ľXE&(08VgdU0\Zt2$Av\?h&Hu/cQ5t%8(NDo۩^0P|}_0IJE/~ۘ +"BVOv񻜋޿jhe[~G4TE.uqDI LL;#o"r׀Jx'x 0Y33ao1KF.6JoISc!5@#Ṇ2{}HwAB8gd{ ˰i޻HPռEgpldxc9CI~S/!M~Ptd9~X@G% ѧ`rFbjδ~bf$rZd4X[fբ_fW[A41/DRm"2̛4oc$CMya?a5"B&Au-L,r T=X8"]ZAqЎo٘ ֥qo4#u>}*ikB]{KװD' vkK-NNEm"߾@*Oin$,L^ӯY](Hju+ƅé+$zKQVV".|dX_%B'`M 6_W@{° JY˃ßό֋hj =6zJhH cX"_c9R }YNJftZ3}CV-}L)mـճN̰%=g8 (Ȉ 4U_nٻrsDmr̘n/N L?oP 9)**60H&RژM.]RqF!֣k`ZgYjb.1J)^):KU ~$VdPE'&1YZ$?"8huOg5r/fA3AA:4'plXkyby~]1P<5?4^H wFXB3w"P0;(l){l[HdVW{?9yf.YSY35f t&:ʰ?|2߻#-!Toz( Rh.T~+LK핵1&Ln:HĖf֦M֤kG8`;is`؜.f?P+5A3vIz6kй*7kqڬ~Կ ]n7Tձ&ѫ].514oU//ih,p<ӕ ˛} *| qWw A.tȊdv᪩|"くŕ^ [mbkYGv }=[&dCHIA^|QKHzi#G8`tnem˳$%#1]F̓SYSQ!$0BQ7T\y`Jv1 Ճ5 JݹHr(>m׈?b"te2k/XaPy5Fl4r1!W/EeUri!%s]һX|raKߙZ+ٯO-Up\}_z~va)Tڰa`NܜYa&KA [D--ϨĠכ;5QGPz[rNbdxk=T|k;{ ň=Kov+ᓜ}M1oEjQ~S6kw{s9@Q\6vLPKF\5[i  y+:8k-ȤP$ʸހVOOW^CČ} Zt^W)nw6{Q\ alt sX2< GHN[V}柫:֏ǦQ)Ayt61|UУ-ǒͤ ?M9`WF$Ifm{{|w"\/૟z>L_1 L}#kH#/nM$s{#~SӈhvZȌy&uA=Sz ʸ?oNfɻfp']|h*>X/6G46j=PJ9 p d` /RFrYòeVs;)IFC)e!k00?D'"UHm9#@W~u[1t98L; 1Gf?zC㧏 QxF$G/v`xH6d'ZP}j`#Nr3; {OK\@zȟֵ><=l,6h-'vZ󰽆+"z%*VLɵ_X.Še( ^+9 _A۸ +lw;ĄmGD [n5듗7|%vqfKbt#+h'=.jqHB{EW\K|],AAF+\ x|]o4DEA2h.rc[;GlTUP}"&XrZBܰHآ%uj>+U(@+Q9SRሀ}g/|.ˡ$Zm5 Kuj'UVAUbRgW,Fh5=}LX&JH>g XK$7xT/sP2W\lj[#\<1-zԥT)SxGfFM-aXzUkL!!)I;M8 SְrK֌jWZ_%~Gb%:A^%m%VA d(brv5> ƶhkG$6pyh +u%$kInaFYܻ{WҦ@w:F`s\݆k'?ћBA D$)av=sZ̤(SӐ1PP,*3mAiQf u$s( 2*UcT[j7:W4C4BJ+:u)Qċ5'D!,^FXZC A (Yi.s= 6;#؞>Pz\C~1oex9ILl"+5Da!wbC@blr1cEV(Xuiߓ{ qG1MkˤߕO.*+Z: jk ^#QM'-2^XiNU7?%Fqz爣4h%)n-t 3c;dI~t×Țf%I3EqwDCua֦Ma.lpXz!k*A DfhԖbbKZOHX n׏T+Tf?BvZ*Lh*eÎUbp}1|ԜnZ9Ip2\@Dp_`C|A˂|s4W)%Zꃇu"ADwI >c$Hrx&{kmHjð(O6{°~r@?*&BCYS(Y!m:e-hsŎ{4$z CLHy+>uX$Onn?Gn W+35:P]@ᐤ !%M`^.X-j*"od ݏ2C,Zw9Dơ\Gofy"bO+κP UANTp%­cW}.PM-x-~kqW9y9|V#KXWUBN Z=3D]'6ks/СZp%Ow"&?n9N$8ZJ5%TLܱG4Nw ve/5מx#H3Cp6+Ф0Jj7&,]່pZfi ԕ)~FwoM95VwWC*<7+ AXTN:IQ?0N|OR'%̔Xb$ܡWD^H]<&kiJm(Lg䟀z7b 2(*Y^ٜ\%zC3wg?a'v6Q %bE?f3 sߙ]}RXTcSG4C anSCaUci k mR4cG?12**>ȯs@Gj OLj#M#e ]ۖryB +d\X~t2p 0=UvOɊwuɚ&ʛC4 v a7ܺ~ @w{>N,䠓]f'j&:{RHq=T4T a͍aگm܅p֫DFwXQ1bh ϧs1&2TD29T&཈ htexK8b-x8zU̹涫İ$oq<9eHB9Ogkf.ՇLŝZͣ8BԒq8[:hԐ=eБLb@MfTi^&<K5JDu5ES4#&80Znw=EoOX0Spw c tۺ0b3 hm0\dvwnEozmFn\ [v<~J̺,qZklIqkZ}qooJNnqqo%QZ:bgCW|K<WMFߔDE34祥zչ -\$29D]0硅6d17asMaAͽ8_Sh<&exx>jR )zme@Βp\^ FI*0~9OMU~Ě1/Cdׯ#hHC)P}zpkK!i'E} ::"\ Y|Tp\/\htɼ2 uzR; t8ĭ{T8#  #ھ:3%k8/>G2ytb r(̪r!ɛ{'s~Jq:;HAy8@T L|i/ G8Ac8prK9y?DPs OC7caKP +]d w,)e *웯ER~X&+%b.dE/Ic‡uBpkSyn0,vx2ټ N]^Ĝ'Zkc լZAt^ /wPÙj9,Ȱiq"5>TGJ&@6 K+,hR26ql wU^|^z^7\Y߃{R.9&œ3ET^_ZCJ=E8(~!>/azE9E7`D/W3z^D'pO:dz5tmgV^O)p-z~e]YWYo_zUx;=GިpdO|]w/43CABbrFsG5me넠l|쌣Rf}KM<>X_>4թrXy~)\*ȼ,}%X0-UŇXDhνBK}K^L;:ϭ ]^m}2Cߣ:ABZQ:s;4m)?sR:?kR8]cnx-bCh.tLu6ܜjtu YΘcɗjSGF-r.^UQ)*).n4E͈rē*=m"}b%z'x2%Đ?13/Wg=|.̪QmHp:y fq^zU` +笞汙*{yCFdG%r()1%_-QhD8 GnR @oorHghU'TI׭ՁqС`gWD^?I{Ts~#v098#Oq^0%[ q}yOe m; X>5IRVW 9A[. :x iL#|)mgTa( Όa'50zzZ>@:` Mg([O^a:o!QD%Rm/~6NN3Y|i5ndJ}AŢ дP5 W|KVǍbx\2)p4eDV=tMGOG${DJ3_eVQB^vq%N]~k@LqL< %Jᨥ5Un7n0nИf8T: !V5lR?jr6 }T9ez8>x/nT_$r  ӡ=n`b5ױ_T(2A3Ax2Ns7%CZ#` r5=O>`&%My=a>ksaF":q7vhJGPDfq̠^Z=$& q|^b}JsT*u<=񡉧fq"݆y>VPFs橕:XL2]ȷ8G`#"p>7jZ̗Axf-ˡ+0qw'Lkުn¯zHx?"D7}? nf] je@BYQC_XW{'+_[Y`ʮRi¢n $KM/&ac٫Г8(UFB"د0Yۍcl彻9IҳU>D<.lw)Yk%4]^\K][\fZ&TuԺYnG.eC^+DLlR9kt%Z#l7mJv ,Ơrra͠}G3.UE|x]hK(,JjXkRm[ix!7$Iߑ>u>5qQ 0rVUOI3ymAR;z>mVXؿPp*%~Cغ+i.vD[i5'gz6f܈AoI=]u+^DIH3ژ?dKWh4CuHGLϫ@>x'[ drZ|D^UA5(4PsJHV`__uOlN4u<´&Ʌy'̓}BU+sP)m36s4ZCno[^x?\ڈѥxa+SBfB. <^FEIFO5D}M ^oꄲ k34^4CM8lmQ/݂kTa3<_MhqT@AZ /9 )F.D{0?ܐNoۅ޳FʫOZ dAw.*#Yg6 5 =ϗ^?iPCpII=aZ>0A2[^bd-5oJa3,t)Z`>t tnixECwQ,I=p̶3U'm PTN̾g{UO.5klƥ{VEjoI6u $c]$q!Ñ~Kc2DVgɻh!}Jٲk]V@%葜cB8T?d{s<7ΓMفP6?VQk74#'+,fߌ>n,Vd/J:衊AEO}Cy3o!{@,XAgZzfATTS;|w{ܰae uf]V6 5-Xo$EeU "x4H|װ~Kߺ)י J,Tmhȉ 40YDʟ2r~'02dlFn( dSU%n͟}X_[D^Θ9E~3G[;[GNXh _٬Mq(X3] E%eZ(3p9WlbR @)1~j "*lnU8Fr"Uطrǧj¶wlҮ&dNJR~c /9<*oNe~&’Cja,-bgAxb(? EK;;IJz}%}zX80~|i=yN(;V2⡳nK[}%;r5xo2Mxl]i S~4EZ!g*N4٫;ҙu(1v#Y3MBD6!2u'c86Mgp vNa)"hm͘Lǡsyo6?bos_]Q$(a!eGcڹa73".qלp \426oRxf΋C"%-ZݙJ CGa9qp }lhz"U qtX[~)|"\{S]{mff5wFq >LYgw7j\XtO)() NB}(!Xӵ%ZVQ&N( &.Ņt 3vӲ%O}e,Fd8M<3%  :"@i>PC\k\ռIW7q;e*s9_Bx D- FMj:Q$VM;ĀTWG 09 "@N;+޻heESF!Q`YS @P`?@}׻]66߷,(&˹V/*L;9N 26m׼BCiwm˜J.('"t  e7OD(|m%cUw|x&aI2`zq# p4GLcVp/YR~F050k*IX2^de#X$!LA%LS,uh`t#*Bt6j|,YmH[ƅaݳ]Qk:Xߠ1KHPe=]pP "Nwۛ?$)PJ2QeF:LiPj|^|0k@)SNMkJk`O6 )3T5 V+俛Uc6>H*C|SS(o=!b3|<NnU]N ;ں^ c%8)h.{¢]ߐ0 //?rS5ayĀ2tz>d8:&&Iz EA"cJȞC(!|IxT9T3zNu]iI ed <8eSQh5fUh>tˡGd35)6SugUnCZhy#z{/}MB&'s_3n.e~~ [EzehSNPD0`Um0}iBPuVfD2RD.]'r^{x)ی J5'B1H!('g2OHci; ѐݑ.&61^91@v.dzB_tE#JE* OfCw#Q?g2[̻זd` 2 =HQNBt闗c=yf%A>8#|"i 6뗉H&4: zY "H;SJ!;.qim_,b`uUfuarwU4cGFo춉h[8H2 ]?L0u>}D!_1|L}0#ū 4H#pqQ(t VwEI=q.y#Mي9e(2q6GIJ̑IGt#L< Z擘0L§_: ӕ:` >grjCex /EFtƼ躓F-A)su%ՊG U) zhF9\;L͹tӻ-%TVɕѷNKX+Cß3 0'[*`,h]Nmk#J̚E %NKk% l0K[-Daatө{ =!~Ȗ)6o/%̘p/tS<& {-Pi'7 UXk-n ov;tce8nkf egѮ-X8 Cvb嗬m bDQ( /,ԯ60E"KXwc(”eLj!d:5b` X,$ "ee(B7<6p}q"ckj5O*0k~!ZGc@]zt |6t#N1߆Dr+?o9f\IjfR|VINҧA/oEI0d ړm(ǟ֧PSO7OWF!;LZeDl?ۄsr}ZrJZi|w;q8)Qh ݾg xAH㐊M1HJ-.|RT9)Sv!\oCB9#|gf滌i筺/H~ ÷gJ5J4}r/ ?uOp5tHjVy'~`Y!9ݬo\x>#u69tvj퐟ASBWj\̬U t3Ge!w.T/tC%F5#mGɺhbwv,KxY"cP|HSe(<7ƽbtB#X7Fo`ReEEt[`!SOɧ!~@j_Fva$}11#ٿMɤǦqKS)u!b3F$(rɷ=R%l+Rf6)MZ/D*E Es'=cyƫ^gƒ=fm"dCy ˸ +Ùf:ܼЫ%@62cELfVGq@ӭ!$!;Cx<^?ZN i8&ܫr u7`]9EtCĤZ_۬^n;Б!d-3QRGĊ^a\]ڃgJo7Z܉"Fl$r*^6*s!;۠|lp\~EiԜ-*es: =ѥ{]E ,y  N|Rօ6+@!ݴL9[z[ &xέO߻>nng's2p#n>0eIqԷ]KvhZX㵑wNBbRT{'!? Tp;Gl gZ]zL_hzÆ "ӳkN1%助:zi^y?}-V9yS PH*qaFyU5gE}Bʧf t\r[S.;-yf:Z6TʬCHF(6 tMfPgil1#=J%i^bPi#*W$Q+S4sCiͅDPk,ɖ/ft7+ލ^;<J ,+7_(4.Wxǀⲭ8gҠp$87<6L7~zGth xȜbpN j*ϭl4s ( 0-NVE8c/@XFB4h1/>)hLWw|*%s 4]h52So㎘\1$%Ȋ{t A#8O~w3v%!չwuY%<!Yt'EтR6 E)D*uC@nqm93w,oy%:Q+tާ`!,yUf1y5 <UT_7e~H$EJ="Q橉-OCn*TH͕Oߣ!.ȏ<5F,? ʮ{ƇUղ%3X $ PMfB4L لbU gWD2w"ۚ`sEr_/H"] cO{<<Хւ ҌXՃDt6Ӛ;Შ!>M`tRO ᦏXlx)~}U6Y?@Z(ʱR:%j@Dx6QIm-k?a`\j١Rlt 7הּ#X)Ej 3Fݣ_e_BR<}E.?9й;hY)Bui3s$-/"e.a+r"krCg%V0dL3A4)KtJ# rA (.)qIy 'd#zf c?uQO_/Y_aFJ_Ғ\OS8ߓ`C})n9P>E3|-i4K1l')Ո' G[Urک QfP:rrf瀸a z%׋D+Z{]F caDt@KpzRMIڎETGȌ#z|崻Qlo$s^k[#m #g  VQI̺F+s S_'{Α$w^UN)7/&ĤvS~'acsXOԏyN7y/(> u^ ZjbnMRA@wq;[ Nq~x͊p|HCN|w 4pUҪ.ٯ2D"s- RXdJ_.w8{m3XG DJsX`fB}XsTC.9gaE@+F9SmIx|W*w2ٟdָA'#e3V| 󌮃9#W{8707Pՙ$="ھvv鲫vشQ`}CO'=rX'r3(5SyPmIsr9?6[xa($&v(ZS3+w#5T ` k${h br|2Vj VI& qzLmAOy Q[~5k3 n^+㧥_X*v?%Juk`Սr~c5'd1vê?ACQxsڞOYvW-@=ZGհrSԖ"QQ4k#cc|/=Q3[w K|,m2UMCz(^uq$3jac5K|*y̭V<|O;qe} 1@P{]!3Me]+o\8b+2" (K)}f(n۞$.64O>L%L6v]it.mME` }rWnIq ͉?1H e|FlG}`\7)ul^EJbqag5If?m>o9(7l@B_5lF3w;q2D 1QGߎW1ll߳shYHE]. sݖKO[)݀ $krGuEE-zf~)ALʀa_󸠃-ƫN9TnEH*o|/-gq^m-Ej]rymC<] JGeբX6ц0 KsųEcDqA-xbl6GM.֯<`NE\cZxq븆)Hl\f0Xe8B4{b͛2LJh\fpGΪ%gd*o!#k])?D(hN|MmDh/(-B:_6#R-R(nI,ZoHz3̉wN "N(󔌕P7wjң(vr R0 5B=?nX^Ad@g&Rpx]<8 ȧ.YmcjXNN_W+wXH(kKȟ W%澁7=~CX\z*0%jfJ~Qbۣ14ljG ݇%<-:e ?︔[Wǥ6LCj6a=0*{]h0 /6 nF_nx,=,,@)9bm7Ylr<& r\Q!ߣ0s3=dŰ3zHf Cf-J!@(" x˛ s_4H/]>|zoYeΦIJK9Y Dt3&('eF9Ou4E T=([8؝0h¦y `^ Ԝyb(T/XTꖓ60\;/}T%X@y3xӉGuˊ?M(N]N2C@ $%8 =)ye:QkV=TZqgSYz@5)ujܓU~ lw&P`*%p͹CӪ}iFp9Ey%KdZr' ąt<ӂ0\Ym6ڀȯk7<8c&ZnD\_i3` GxdSwh|z7 MEj;0%U bA#p&Tb\we/ y|!8vS|Q~"c@o/9ht~  Ȼ5'j4%-iJeZJ 3:@@#hp\hEը!ei H 듑u0S YYaƄ|(넱2yr`eOºsOJ#:NMIGp2\ST$ ;KBd$^ܯBN q&Mb(AB ^ 5A/iUzdBB 7pa]--eD׉t&:xozJ@p# %@6[j^Gz0̙'PInUΓP%bEVaJ7.*ڼ{F]B_Y)D|?5_OCs6΀ Ydnre0O T@ 2I=6ji\sWŮЛ`-AgXsyx~1$ OB1uxh: P;oΔtxB->]Ό a/f,'Q@~Xdf E[5_Gjˤ"z w-I "j̈e7z1tFVf)Ms9X Bm  ]z?bH؞iMY_>q0sVː/K,[T` !ڳX}: ȭ~3Ha!AIcu)cWM-r$xk>qJVcӳlt]<ڠZ~ Af1Jo"tRv̥qJ96 !Rv *:!v ֎qj٭?Htؾ~=AX&v1h:8}-BTh]:t?]L*\`2@b$f{567t2]rMk\;Q.E- aUR֪˷` W oa- S5m:?cRy`iʎ}GX|]F0HOlk%6~sXL 4ꊿ0f { LHNkebUWOQ|ߪo43PYb^~hK]#lw~Nȑ /RH0)%9E*.2{Hp%0*gpB(DpE1s}"on,QH9(%Z1.E`6!N5#PHr=㇯@. y!k 3ׯwOFkU>XICkH7-1 h"P"vH)w4G}1n&wN ocHLdlk:S<ՈA EäR(fn$P !rNRǖn.}ZŴK:S'Kh!N }kH4fv<𴋜E#oU i$fқ;,CQM_;% 9߻Lɠ&GE19deodU4P.ISЉҀnHL/R=H耶;-WB҇`l+/$Kuzh }[XsnVb6 zGs#RJmjS9Z2 _E2P u]Ȫ0E-vL=;K55ӰoVYn&f*tJmͬ=D >#`m5S |096<1]tXxpbB(GL+`V"_|!YDZQ樈DuFb09n9`'~uZEҕ$*x&.Gjw9S ~Fk9l7S#I}vuҴ@W wO8EIX…jQ}b;',s3'4hW_vԩ<Ʒ+],  Rhv.C( LգrUҘ(d];۳xZ긘N.%V^/~u24o}/" iPhJDC~iq³ Bu~ -lD0n hv0-+2Ju *(}_D9?[jdiwk2K.*]}-6Sx|j7lrA.VW+{)=8a&5gA/0YL ?Ў0y؉I m;˥4 =yp>,9#FK%`ke|Bepߨ양P\ C_cl:eSұh6+2ɢơ&ܾ(Zzаt$y<YIGG?^jlZfp6{q} r_*_LɌ@;m7]ڔJZܴ&M0RNMZKkjmo׏An;?W0S@)bAsqtKscEh>P:AXx#bS%`:TpB,VsǛupC^2ٌ؛]SF+^GnHәwUC87TG Lqðۊz@R0z֋4>{Oo;ԫ.PIO\h;E0!ݳew/6&;n-_+WP(]ƛ PcSko ~-T݀Tm: K̞ =3+qP`6q櫑ս3 Ҿc  ͍$zoN?tTx 8o?sf,Y]11 FCP 2,υs۹J뎨q5"/6E:0㞈Ѝ؜7G]R!,#7 b OԳ>@ѰhF;e}|#C{}'ͺ&Hm!¤!bFDZ-r.GS552l+qd1eDR&Fٕo٥T[N11\ LwLb,A֯x]3E6|J#ڨ˚J/K3MCj ca9:S;c|u#!*%]AEK}@GU|u|Fl"o>My*R(=%;߰Ȓ BsC!v;sf`.33d1-I5^n1nFb6vTCP[}.s"%3aUң$z5a8e)Ɏ<_PDLqEZ7LZdUJ@d|Qycf>n8sHJ qyZhǟuV#:O\rfC1-u*CMId-l腛m=%5zXn,p]1%tXNA Eg9l'!.Ydm: ;JYc爮!rN~kp@%1@ ꦧg KC*Qw a Dʼn"H"Kd <[uT9un*c/_*pL]h\lVg1-:vtt07~e&ZR_EHs+bBe4u9`*Y CIٺ5#X2+{Y?1E)ɅF$ۈ(6x)T.XG۬f/Rpբ18kAJk/*C\tFPmhw4z͖w!,y ]ZOaN _!C%fHjV|kL?2ޛ2 3Bh6PԵJ+sU?'qgJ˝C|pךO 8G`Z̉$:yx*Ӣ0va@G=5\= c=NaD"4w6ˏw_^Zz|P`&1[܈'3 Nև~MהhܳfFci߹ߧlQ[oG_ * G:KKe=kqg(<⍎8Kp҈ubkBx*JjN)h:~5xbAs1|vJVt;fjU< ne1<,ƩXyViP ޻bi:ӯjXU]YQzRd}S!G?#$m!ga2$yrYVobl[*OXy&zŽ)pGSE=UM]c~.-m @B}=A;ULwQMeEr{CCc4TsƎv7tLR{gL/Wzr%Q8,7T|Ey:V;Ot`kl00@:ؿذ3C^ݽ+c+f"u+`}wHy%zOVAzʝc5mq9O#B2pۤ绦5E?)A0I>Z}niÍՙ`4x,n-@]Pps! ,Edɕ[~v8? :dADB6@ZMYͫ^ n4:S*eԥ58]t,+r:wkZzmX]FvRQڙ 4o"لJٷhw#lپp0a #H9kFNgx,%ɳ߭8 ~[ej s3V'W m%7Wbov+(oE#|0fEV %w?>͐dobX8f<b^}G\&&k{bь.;} mh6܃@C=ѱ!IBe31bvLr+qu\ɘ\ɇŮP9z!-5VRBBګG3v{JM1,*jnPTa@3L:g٣ƒD$8N|jF"|^V \V9WJ_W'=dLK)b} UYGïr~w+pS3 k`({=29rm0ԃw*q_gT2zMZ+67u4!{/MaN?DzGjA!χ5W{j!˩ }u,B1,@V\eb=f((A4X~[|2϶mB"A03BC7Ii lG sX,3̨%kNBy~748Bp`-B8Aa ?['$;%I~/M9)o ?BX_PsqqQ5IqFjE# O 73!cy*Bf Mw .]W6?{.(^#vcF"Pj` M퉺ymV*#tdTi|qecVda3lE_N0^؄]FD'HA\9iz% liMN@+I3h:%!O Y&yt')+NXFRM7nlܶc_34wQˣt880Ə^tKePpʌ I$͑Mk<9!WlsJ^0Eڑ'Tf]'%R4oLzK.Njpǔv(k*@~#&+Dbp$s%E'k,~GW~џ&HOD'^3Q ¼W5σg /GV7ErW XvQ[#OEޛ+kkX+Dg:|+%_E:j|"MgG4/ky⎊%x I#qwnNhq' omK ORkl2AX)R3}‚\xWѬ w( ].عr^0krHN=OPYŽLRr>SMc,s m'n'.x g͑R`[JՖ+Ly򍛾S8xT.OoV iqtC0E=_ΒGNv_ a.F~j_ke}X~Ri;wL5{fmKmE odHlwam΀/I|8biR㩭 Ds#:UÌ"R-fAY_H/CV eW%ǻkiQ^[` ƹKu4g_: yg*̕U$CTYoԌ$ۊn>|f6~XsŧNW'cw\iWp2;ޡ@In%6Uctp{! }f3 wؒۄ.֝İ3UJucQA3dx4ٶjꛌ%c`xDdJ&Qb]xlC܇eW#?APvZn`<9 ߎ`U0gqI"+IfPkSV@3%7V(+IӀj|KoyQˡ f=L$ꋉ2IAꕪ@MpIŒlyalyEO00pMʼ`:&_Δ僽@yJjlqP(-f׬ed kd$7E.n?ܳC{b/^h @Gʛ{Tf@‡vq55'  Rgׅ*:fD| gSFCJ)JMɀ6Gq-Dcn{J;;?!9Ep, 7J.F0 $iTd$UQ]p)^|;;;4:OsnF&hC/}4ǡԓPJe*!ݶ^IR <|1lK![AFq{`5=Gz Z#|პ(*JHA)l2rZG5k47'(=Q^;oE.qKkI;I|Z.1/VXWY}@yX<,eZC?W}!5c*s"v!j8u96} 9T#]vSl;iFV&F;|]8EjͥgS2 ]n]#CkLNwhi%q (%è6b$#4_atqL25&FN+$ov/760:{(VwߥTA80G~E ;y̝}/gb¢F&]%^k'rA)5˅3඙3#< k@kҍR*@ 2zkܸs= ?_VT6Osrq,M|NʂTj m8<LL֟YFOb\'pI=JT1W#^AZjaA]Q5N<%$ M6YKS\W:}f0Ϋ>;D ̏%0QDf]q,6KL $k9i(KȮ *VC4|žIjN~OijM&!@X#卝,Ty Fn.T:ܥ*p)N>解rۇ禥s}& Q[*)EeTs= Mi @ٶZ}ZK6R ~d'HjC_B}Im+M5(ؖY\C@Nf3 CB[~+Kv(kh/VK͆+C)@hYEy5Ïj!aP̄wknZK⡥NGso6znpN6v ɦd Jۻ]Ot==}GxjZtJi\&E}f6lI]B4a_)U1GoȢA4Lj$ZpelT}!!p3ETQ #..cEA1^UQg P iGn=iFbVﺜy$(`dfvE :Hn*W:/MDu9O2fvF tP)VHx^Dˎ]nne=3 !\NJ)T \x}#BRRd33 6#[d !<‹8'=][#DVҺЈb3!HC#ra˧>(gCy2%AB8s{uؕLmI?]@"j :Q6ѷNDzHd<j DpgaSPfJ}ѬH1ƳA}GQ2琦f-A%窅R! &hj+3?ʍKtXyаۖTZTFۘ2*X3M ]T7*c`c=y 0bEtPƐ910̓(QuyDJi75kr$lGjnz!Eg =YrE]D$n ^[FiP;hqe曲v=ZEڠ[?A+E"ap+ X9suB)z7ﳉgpu,/ؿiTjÀ8ah 66 :$IYu/ݺ;s>Nz2r͹7 ">$ M%y@!{*oa#DûXܟ"3[O̤;W9y626ZChv10/WJsf&J;\58eEO6üNƬ 'lmq w 2ώ`DMS/A8j}Fdv<1`jsy +] HaW8XW"Lex)>Pߦie Av AHGQA鞁l?mf"vpHL?&f*I+̫fFmvK.?yѰ䁵{n;OC?kL>h-0mjj`H q#d9L!Z᧚3"D2wFX0hkXcN7XC&[]@\] U]ǃB+ FT7!M%"ate3%vh@8Vٙr͓aiDٜ9vmL ?/H̐|7koݡhY49[œkYxWzd5*e3Ż^lQʹ.w6t-I`Io (Ns` ӭ^%:prjH89O4ku%P32-]GJYhi@A*SZهVsxi܀:)- >nHFkD_c{={\Tϔnq. xAm5J/:j3MnU@E @_OB.}a=e`72bҘٱ}ӖQ>a pBr8k:2ɍ| qq~Ju/2c_i58ꦞ)^|JQyW&d5ݩpy` m5P NSwdIlcp#P%]kHnU6 9Je͂TzOߊG'q7a9zC+-"{nLE+;E'VNA]ǬAV_'[V>o=+Mn4InFLSŘ%K;pFʙY_#_8Y`些7@ #2Ԕa) r}`DUqrWn5H [$j(|us^bU\r @i dʃ0Ư޹B *>P;#=oO,wM\ӈqOc^Y%ھC##7I1tɵlEkL'X\J"l~(SM* [ c~iNS hK28 O]s 鹴nn3-ϚF,K-`xh0w+3PDFwiCҗЊF=c &6Z<.pзUV%K#kۥ+ YUh((#RkU7q)qpK Y2 XWIB L39XLߡ  ,434P+xZgEiy6X?TB`Otnu%ɋEbsC)zdFSCLFRqyYjM-PW#EwhY !bsSk\9hĄCyPl L%4wB́pq M ꔞl ^eĮ+R,4axoIP(M%3ъXdq;jyNWzs} V't'ոAz^(``.u9EI[ZVS-++>`5&@u]'khtJZ3KfA!U4yf "]E_-!2+>t+I^v*o] ~H%X3/)qJA*5GX-s\9sE[(+5:#Mm"9T[e @q_ivI I\?mW'@)^DWbCĎ u@/؝{N(UlO; !ۨVc(r[] V~xصQJsbO8Z EV^bh`X$NqJ^. G ݒ~ХW7ILVXͤf1Y/څM<a/RFPZnH]iH 'LGMXXcb7b]Չ̠Bg> .5?"쮠}5=@<[[ASOoP&YJY=)$]_t"@dG?pt:@\{v~謋ӫs"Hzs#W čt?7#A)vVP"LF xC`,pjyY.7ys6z- ψmؚ³D8]RG Yy/,G6v=6QeLb;~7e/,˱ Q~l;^8x2.c;%vb`ߜ[D #OLNF^?yInmxHrx؛^"3/]O$ž>s0t˜A#Ƿ"0ne] p҇ZK3Ũ%;}?˦(xԒl=*2h<óVQ K cMP{b34m6† FW8RV-\ikYs^;=HRBUFk)S  . \ɜ+Be5Qao;<A,c`<7O12 n MWW?v !BBzFvO⎮w\ZZ6EM bGjj7~T^΅ QcR]pB!/Qx)>%DK+fons).o 2jqlR.0 sKM[8`ÙQRT(Tuo`)v!Uo-N[#d FXqT j<šhtE"X _^PEڤFFP-KsV.0~n x\8vw9p0mZ7=@]߳=+Ql4;5S6qI/j$hJ GT*Uű'N4yߨID+VEϽKHI^ 'Qv &eSoC*}rQ38u}Uu,jDlQN3IC5[uF8z)=hwO~I+hĪt-2u(`t}qv79ReaM@,@<oiqND("8|g:?ijIЏ rx٦TдRk(Lv(M֬Sb]/ p2 R`#y.b/85k>xx 5-ٳH:F>'>yՄǁo#DZ,K8&7Ia:2kDIIŜ@~x`R}%vLcKtr=G<%wX׋.T4/1lDXu4ՕTCReSod3+#R|-6cul ivWѸ~+]e'+'x)T6Աr `lbx1N)4f+^FτBLySm3G@MŇEd7ɲC+ayC^f\Le-$%ƤZZ``*r cTw 롥l)Jtb MXvP{9a^.vXx ,"78!߾)Gn0HlʔG |G÷ 2jiZgVڸ(iXrmsvp#r*_y3F:w̓^gYJ0M.LIE˩T5,uɹW![xkόg2LO"9`̈́m/&YYd2<$AZXN'H.MWMBL aClTJySԏoo#^+=;&Sbjs@b3sZ*Z''d 6*HF9] "`W@;2>΂EBƱbתZ,#RuK'7,$D2),1iDբPN;sϱ<ۚ%AG].!ȱNHINK ?E\ b܈UPo^|&)QY]CUە Cs& jn/9L{/٠Ug{|V0L4Nj'K [Ăp] eSzLm^IfZU]h,tFdvJ'TԞHtЏWKN A5ZN/Ȣ5PO lb9(9)^P *@$YXt ֈ_F kPD#TMCJ^'Йw__oeQ}t$.ܤyRg װ*֙AEНlPGF,ks Εa,w}gxgu5< H+m(j@KuN:]fY@MmчeQ'A蔎XHvʘw8ykmW*5 E1~ WKT<5嵦'j{Ƃbg`FC ı(/LVF,c:00®ΉMzcHef;87$}흫nepAwdIaBXkhzT)OSTh'cV|sUx'Jo.+l3L('aӧoDI0ْL/3JG}*d^Ib ITWLع&"nM~>PSj6FJGHўY=EY;{?.w?bD9i +t\ਖ਼7?$u*ۣy<rzS =׶#3p@-'d'/>FVeVD^RL'<#"=!!De`!7 bҪ ieFqZǧmf"z|2p5lDž(]@Rck2^$WH Cl3-s{~k|Z%?|Jr:7쇳^V?ah\؍DӗbB)b] OF?oߜ|6LĴkgF(ofd@6bwES,w"x:XvkLM+aBWl&<\[1NgȲ!vc;knn_p1j {yN<+ Ɏ:s`Q1$^E}>|GZϽ3;x̰+P7M )\B=Wli*,?i1i[{s >!O],FfSSCTAȌV.QAa6f9i9ϝq79ŋQ.|Y#q0[,P̳7=R>"=e:n b\iV tshɆ ٲHxh$#6},)d3΃5VZ4xϵ7\EN@M./x]ⵊqJ @DMULXQ4@HL$uK{={AKc)C2(0f@̍&YP#XɮFIŔ/'#|ad|w fdJxq8yq + 6yV%"u8ȗ&YyeKUlg.sVw/H3exaB?օL.tV`=s4#&|rʒ١rTf ::$_ z~{ߔ)wۃea fi싇^ HhA]iLGn7Z?ðp r[Pu=@E >W5rhzˮˊp2A|T>S$(.AtR X# ')V.|c>Jx(c; 1 B|Y~uYols嘥vcbk(: 1CzB6vf1Hp&ͧfp~T1[BI٫V9%;$ƿ=lXyJ&g$YghF`IEE]{HB;j"&WCIfJܓsa[QJͤMZ̩;n:}[4kƓ:̾YMj]l&߅,Q0a;!2pӔ-.!'G$uO#u^jYtD2Pnfrl)`"Ǯxz`omYeO]h t^ˌ$MfFY޹#Yݵx2 ݕ >\0P_RV\cs&dRY#xnй. *='ag3UR+NJbPLC:Yc(ƄUD 1QyB~љk- )A}' m,Hʤl_Ki6e-?b&ש>ZLb rZ9W?A23Ә͂?V>$ 1VDGnH aX")qxYy>w(Vg.TTi(gd*]";l,gġWn☭D wIӋ#BޖS؏o?zzz's݊9tua1/G؅hҗ3:T7Y$ab[>@-0C as!Ld'.W*#THڜ9mnnRsq#'Vm ~h1]ѫhк 8n~0zQ.$$4SbzS:NlD>sTNyU `T7lTNa 5 tJ*KUNfD)d1(2#Ahv˰bDN۱Aꁞ; k.KR9]n2lj/xP=G0_ݙUHY/Bօ(,?(R̅'y -diG =}%b$Q6^ L|Z$:z޶$"c%f0KX q0r?(/ھ|e#dcO=(,z/ί`[5ZXtf8qz3qST믢v/P1҇>Q(@g'1ٜL6`5?yZ& (V`uVgTE\- =KI7މ ~!Ua4>CCrz{ͯc)}xU/.oMyUBciT }@A`/؞Sp^}%C:vgNag&Tᬠ"ҨYc+Aڏ%a^{uɖ#Z'@0>/ Eo?vEr?@TLizi(P~?Y;X@ѓxAC̬2m_™gl,X1^A 𙈓fxp(hS읟pjBW->-& Eժ8JGO`ahZF8L05p%R9D{-gY|;?Zr5}#SbZxKJ]v8yf'#(˗ɚҗ;⚿;*/(.G\jbjwKLZt=+<-PsLI$}O`>|'EiЩ=G<]$!CCGḨ"NPOnN{4P:2 Xl :' ق+L!T.C%Γa`{;xKs)_䢏`F*5^,NYW #o!ˈ:nGĝRN-΍@Y k[Z6gIޚR?z_YMGOi^(cV"6%RIwY{T– ri' eڔdlimk|$PvaXn)e<<+@J Y-R/7'D/Bɥ" }F~ JD=K#rٶF]*BH5PMG6z6[6x핤)vbFV[Z()sA\hsd8Ȏb0\]_H͑-rk'`z-4y$?9n[Z) g9 6R+<,j*KC?Xl`m[\Ѕ;k-z ^1'kHCn*~o`*~m2$m'gBCn4mY[i·\ٺ43ap WG)mcM$R#Yo#}mN-Lh?0"%UМ|p~$DIDdp5yކ9Zi[YܬŴX4 Ac ؃:n)(Z'b}V SI-2Ds6ұtݵ#p3vJ{oCvfw b)'-׀|%'\d5%N o H6~Bi z,hw[`y6_e ,U(un_t+!%|".r vize<;:o㋩M4U]R~7r$O|:Xٵa2W#yS-ѧ'^GbBÚYה*ݘdl׸[; R̨0H̃W|FҜo8q$xPlsCk'3Vc'2BG]mK擊*B(dYJ f/oۿN4im9EK'RF?;<ئ F;~sҰ&o[+ku?8am\%9ǴIKrF=^n0weX-(:Yy8̔qᑈd1oz&hLX.Ȇ1P[@m(,:[O'ТB:mhrk 0-pEG#2[6&4thCjEfU G&4p!,dS2 E\FKn$e0in[f#nb[V ԏvznBO}VYQ/w\\M( *2;tG .+O$_se6( ̸FXT)Okt qif":E;aVõo˄ʨٳÌ϶(pu+/HUߦu ݉iaa REFNc} U6GnE#Aǂ$ˇxb$my<0d-s]ݪa)],?fSo&I|CklCpgVcʬ{v:R?#-HpEE>*#s l.*˛ kYK%1f1͂l/o|fMqEXЦ83 >6n.0R=c*oG'<ӄS 2ݐ0uoR6e+[I&ƆyF*oJݖ0+Ҽ!PKS0}J`K7')؞ͮ^?s+FSc뿯{>+m°W˪?v{R569yx4*j̱a><~i .z [!<ԎVrpTX ^xccӘ { WӗƇ>97miGhݦ`>VE{{7㬱+VnU~SY91mR ok\0F3& Q]:ox,c/ݬȥ_pIueGAD^ |% H|NBr_VC銣]ޞݙGdAốCmu1t̠ހJu>}NSzFUQд ]`[\>xkYJ_͋|K:S{O}C*80}x1l JcÊQ\YuHAO1q7u1ZҚݎL=}}v!7oWކU\ h2 ;yaA.muLT6q3D*#up)˺vq(Ln r(΍w%0[CF)|$tYsz;vo357.y$5)Ew A,Q `([7D(îTW)v?aJ^Hd? Ӎ1sRu8D@HsŷJ>&#|m4ߵY!4\?*p~GVfFRx@~zst5_F!]]LtQ)+([ 9r:et^Kf 5 UzɢCtxYF5ie“='IH/s"/rtݪp%A|f[GAG&-eCE,_ʕڿ"3n *uMAMݾFϛr6]s7zB9F +@RȑZل@1/KCBpԥRvOȼ6C/q8N4.} |al2>BQfxG:hݔEɞ7[0sϿm8lθT@ 2%PrƈQ{dYxe${#M#LnN N"x=|k^_zm>l4:/ڲmp|-0-3T),9U': H"Fťƃ SȏANzQ-WoHM3ކPpZ[6x'̚ٷol©W`mcM%x4aivLߖO h:҈' [0ݧִl0!=T{QojWh)(b}*$r/x|MH*O3 AB8.Dh}p6DW *\*iٖS~{(~Wi萠bjLiQD~lkHqROI JҘv6eV4jʩ]TdWUbtZ[5Rt'XYEti~5[ -܅BTv;uaà1{r$MicqSyO eWKK1ŋ{@}痭 U^я=# ƍ%< |xo7A]b#z^86Ωny!5#%t&:03mE]*bZؼmso='W-uZdJAiGH{&6_U2JFυּ )9Fp2jyÝF φlK-$~@)b6se^mOS:$ jY4!Xi=OJgaԲ-\S -M %3;N0Lâ@<|As2aK#??_gl9lUz<8ǿ^љ-pB ۵ LqZPWϦ7ؘd 6.$L)9u!7$p5ձ˂3}x>y5ޑ;!,MGkEȂhkNqjSe);ĭ /].#[YYuDgkLU 6a!7W]ȕ}VE"ܜ߄Х`VEo82]rT' 8[?l+0 ^..pR))3͈'ĹeyumN |V$6OemePAɜeq -mÞm[sI#eo eÞ%#b}>dva0J-Na/لTZ@[pwj\)Nan2]"704dQz3;`wM4Hq<Q8n \;r cwamH>EC'4E)j]ՖqZp<2zދ d>K=5ruYp6|ll)E-5 ]5LA:j;X1wqg:$Ғ2ܔD@Z_F^ (g3ѨSܶ dv$&h c JY :z֦vqؾv3MTۘP ͱdrB[LU1W\ufjp񍇟2ĴSgR9<<::1w]#;ŒGY8YeU^["֡["@~!`MT?E\帿-.[OS5 (_ ? mn~b /|a$%Zx\ +tĦ^+f7&d,)y/S)$ЁxZTt["#%޳i#0pO`JoyOX ak1#V'#JlQF;)bAb&{iJ7 GzG>]FPBN!~-4ѷ 1m gL“3jJn'?' y7ceVaw<1WO}Ѐ{ISޤʎ+we@G7'(>|YXl ϛ=ە}Q`w &[6(S(,XFUr"nU%P~xUTޙ64շ1~Lgo&蝦88tDUzlf#s;T0fSƑ4:5r .(CߜGv}Ad;Fߺ! dQwiLKG6<:!I@ ,c : 0XqF-MRGa!V TSa41==3̢A'VtScb5qJ͎XPP&${W]qZ+fI埃Id7E2-0/KjzƽJ3ٝsQRpr?&Q2'?t*Q@`UsSj!`?`jjqm׌ХSi ҺZgkU񗿦}&b{= Yi?)!^S(Beͧ%)0oQ96 eDu‘(X]2Ԉ ՎyqH2^b<}(F pIq_4+F,b5h}RppE|nHc5zt#\t|»$hua0`uT2*{$%0]˗ {iiPgdꭣ 5'6܀IE.ݴ&m?!!1ȉ' PĖڕVX4([s t%fȰeDB|@?}ϳ[9TI$d5CJxCTmX&Q),Y"1ҧ̚;s&#F-e_l~-_5caspoʞTu>pƪPd:~CyWđ!`fl0cQ&.-QQ; m\̏;*(*c.ߠT@3`pݸ ~=cqRU63/eb~Y1= @*]h¾>6.b2dϜ{$ٷ^~[]g@Z;游`mW(BtFwAJrpX`{>̡XȰ ʖbojo۩%FKw c i5Ɨb rt.MB W娭O"y_Fy;'I6m\(7^w;Q(7zF-9RJ::HX,*%G`hyKd-`PfsدJFx%B'+z^Np*O[Q9e_&8:=S(NIgFTbdcw5,/D=sp)`[ylF>6+!n_rf62I"[vp.[zgߐ(uiU JJCpFs ]B7)+tdܡ`BاxXUC6219Wr^t)9IRp/rd6Qz)rѶ"/w (/ʿ^@~DC(]F؟;P@GԘ-Z$&,U8HT\?-$KP|}:ldoS\]nR8~ed㵕<׭U(vh`dVc~szyPY7?[ܣT'|O5$H_N `d>*?di |4sX34EIK~M1HQL(NLiZ$lN⁇D]4<=#QM!k!A؛;Za\v(y_{,APDIQOtDstfaMx'Eچ^&d_.&S=k:XAon֞q\ɺ1f VG1!/d>f}!Bt@qQ\8ƥp-.;N!R7*̅(gʎ 6xpg%&:ѫnZWFG;A £z'ə?hJDezFG|˨!k ,|/՛2.u4t4D>[P͇a@2￰*х,e ~ݞFa2-?7.N7QJe *+!n8(ըMrj%H..zzXOIWߒ1+:K˱4A>P1NGdAyTSF qD>Z_[B9Ul-x>GoL.>V6 /gޛC[Mڍ(f\Eyc` -6f,<^{^Ooh@Cc ;nuB.r1pۡ3t@s Q}BNDab& `zkSN h8 X|vP؆'a,2Q  <J-!h/(yxet%s7r&H evuWMP?npMŖƥ߈H:T7RQ*Q찹dAnI&單|PSsaRk` whڱ'{ k3-.6\kث5I)A3n[RCrH9EN4I b]5,um) sWM@_}ot?2jΉV}01qhϏ`ciWwO2ކQUDQ-~eWW#dPK˹>X+W:Vwj$V>F Aġl8cF$OBgʦ+Y?@f]~ŏGpeH K4;`afk t?4[d|]:;Z.ե$ os4PM':@EjIi/bq8h7? 譍M`4e/;G;̢{)\8b)_x1BH&3;;s2Bꝕ^71~kOIu"jeW(lDk/|U!Οӕ. 9CTU0IC n~Rq0L֣y\7 tYS+('{9R3l v8zW&w]}ial٭:0}J @rEѠgbe8wހhٛ%ȺC͑-DF_X*AV\!_)!~>W3Gg Gpvh)I≱Ire:hd m1fp7]oH|E՝>~A+xɧZ0l@WgUP/̪# i"Χ^b*őOy]lA4M"- .lT}Ůbq|&i.Mu9Bt2^b"†0]1E|л{;y_~8UF^Mb ?$Bu7XoCgHQerlH%t3׭]]p'E)G}$c]nE1nx]L–Raa~ @d}<9}asM rQde<{: {Y>wWpkgXdxc}*Pgu!Lc2FHa\Ks#D ^!)1LB[,91U>dirG>H C$ɢ^zG ^`c&:",P"KAa})-cS*4`U_xMDQ$_6.75+PwKr(ydj[g-z/d\A Oa@"ʋ؉DCa}DWIİP XkLW$Z_Ȼn_f8%!mO.5"k+n/\p"3>L_mXJ1;XźqKu(ΝVQgqEg2z?+zms36iz"dTٍC@=\o*G7W#>(V#1B ׼)D] .$,('h%lݖǙxc;eγ<nמdx2vbMnqmXz@lԽ(ٔBͬ=1JgbHȬ1^@ٯ -p=QuB^x^zc6Z3H<'8Gs|x,X # Ri (8I*x)ߦ+@Vຳ5K|KRo6ݚLh;, lWe+G?#zq[xPHet*Y5 oU:)Zx I|^~ +f3c)p-nLsQNTԌ)n&A#2t8Oipi]/g+d`Cn0At!Z0jm#Oh*SfhTzQaϛ(qz3vS .yt :hH 3+| )v%f^r9-`R5W.fy(X+Twp0?(1զ}h>/~/o#z QMpy utdod"NQԒt;Tn̴5C`rPj§W͕%ٟ:ŽF}fOag"fAe~ Mb@KPwSUz{ &Hy:>)xq)!k[I Eb>y9?W?5 4^ ZbߑlfA\H_J*¥?}!ࣂD)InL\;9`5N@MIT"Dkw#Uf>/="BJJC -*[gֹ^({*׏yc4MT)]6Z49dL/ϥ$KQ;Gy)-7JNQAk.*q5"Z "]r aZšM.HifLYڳP1ʝ<c7Dfhy,pzli{Y l@􊵬*Y&5Ozk>cfIF@XtLSc}\ƅ@uҊBfT5T]k0JhbʳMM1LJ$;8"NL~O Gܴ3Aj4q0+iG& H[ϜԚdP5y^jJIs۲MkHeM.yJr}wI1^_Ֆm^Ӂw{ƵDp>߷̄"l!-VA^Cbz,joE^럍<7W CxWsmFT7 G}; ׇ4E!cNtu"b&d迶vq:E^GEM+ؓEt" Ńʸ9O* ;ݚZn4a耪\jef'D05=j'^2?:!LG$auΠpF@l+@H6pѦ.#?g3w;~dyL.1u lFdx\PYr1ۃ Σ>_i7.ϽBáPnn[vPL{LJ,{QQg]0)r:Dlk LK㿤k;j@-z.ͦ$ߧ$/8ȰLo9yá,IC: R"S g&bbf", &%O 0}3”2]s]AK->}p3pڤ!瞖&yQyސ2ǸfBI5xJ FE "5w{Ƚ s gA7v}*= WCmFX'fTjV׀߹ BۆxUGa,/5N:@-(,OxʈPT`/8ߧ?ĐN|aװ7T"У1]3Jd nqf0 ɻB%?J)mQTOo8';P"v20́!Ʋ 'E474;!7'= />Kr_c,Pxinw YKP eX_:` JI &I2Du:>W68*k? {Q6ت]C2v Cu1+ B&dT-X!M~հAloBH߀U/S,ĚEʈxbVZZl1!潄P\IC~wܣV[g*Dqe1GK$$oFF,娐[*:.W@YgFz$ Pd- 6@Z'{'c7d ]3 dY:ur 7ܧ:$Gz 2vR%qy'Er07IO/cBSðk]&@PI쓟Am ڭO Xq~87S*#zrjq$)3o026GlɽB#=9WI)]3Sok/hL7 Td)n(e/8h+coܦK-Xjnk6Hmا3u,fڶQ޺[oS\-4w= ^*@d;k)TH=>@u"W91501zȶ{5m:`͵^_3ãN4{=p'._Mb"NA$%;&z^s;b禵^Pc'@jޣ6 >- '?kEnXGe䢦UX=#OP<<c C0:mn+3Tջ!ST ,|q_q1Y- oږ*BKz0u 29tF*YFхҁ7)m<ژĒ ֙}pIwD HrW+}^/Ҫ\%/#`d&-81>uShly ~!` 6Tj'(M nxķ6FM S a2V"BϺ/}2lD`\\S5VEDYݶptY_u3lή='_n4_9mKD҆-W350`nƚ1i (d섴C ԬQG96,M#^K>pJSl@mTA[O.֘o&Mez7ڋ33>B: 1ĶZ>cHо!!(olL|k :=;yt/*Q yRBk^c6S]̼81 }ۘQ# R.\) Ow+S)+pЧQ׿Z_K9}J (7?{d Fu*b~1Yl"kq==SэN5 6Ҹb-!nSaƦCFXU-f£c4h:  y8|ǸLBUMt~k,Os} --gp՚.EK_-dХq1$1u xUBA$BprFDЦ-6qTc%D+RR"a ?LwqDt ݋:gl^»Q/ lF[ 'M\$Â~A  'uFKY- aSsigd.rFGʋM[ g?p;E˞7$xxah):"5#e7 ͷa &$Fyr9*r%;f39yoIXn5?I`lcۛY FgXsGJij,؊ Ypέ fTL=0EtlVe*+.–haàFkieoJFԹYLiAK';ԮC2 +ޱ#Ye-?ACV|.٫e:۠?X+ə4ЙM2vSX~|E}cpDU |sn m#Y{`޽ aQbpG,yO\B">sz|mا渶%dKC;U4FA~2x2gON%w3ݭ^HFKA} 4ߎp09J}w|OKn[](l~#lhZꇨgnhh-">'WH![w);ضpŤ6䏇 kQsHjA^뛮[0үrK6"E܁l ퟭFcuAs,R?[~S%w:bwԾ!Er~ sR&m%Kz7:8gw ͬiQȂmpCJhxXuR<5g8fʥ 42=Nsś2~BǢ*%dӼhKkCc>%[t1B7X G Hoa\"ޟlfn {_OL6O 6^QxY)eJfvga;ͭ 5F.C-j]"vhvnDoa=>jV>.Lh7ISg^? W$p䉜"sFh%$m)0;6:_W'P (I] FvϵyNm\Fo1)'ok%#3 l:N3YڼMm$>Fn_se+3R}J,Jj41b zT^@5/6y=8^ųP>$;P(X@@as1eq?r3 (xB稨J7jc{"du4&WEh{Mb*2s|)ҵy5yn_D."~{vW y|.`ÚÁ[TF񝵯1i'Mނ{ !KxE/$W1dOo/`ZF [Zc?EU^ gI+ YMk0Li$oeBf,fiK·ZkzU(·928c?Ώb{-i6 }ad'A<0S`5@@~?5~>Z*ɗ/ZY/)wd? f+F?I=ﲷKKTQߖF1jY|M`Of<M3%n׭+gJ/=mFq&4~.i/)7\Zc?ޟf"/}Fq3LC}O<æ!W&-\, UuPbmgQ}5O=gP!BwmRLixK[-sxfc8(E(ruxÉ[NY͏&>V^aΕ7W<1naYެ] 5y$-7g;4yΆEavɭ 啲'oc| n < GZWUujYq?ٌѥ0F$MLE ε jc|Xg%K$*n ,o/f[vo S6 u%[ӎ,Xg-!ꠍŔY%a j;ћ*5,̌7]U9J8I=ۊ;OD @,R3&@1EÑі掏)ư`54ރ^im ? *еD@{;}2o;ҿB+3ȣ~<@ 1>L-qV 47kҼ|E˟hCe_ 0,hJ(ȩdN:FƝOX_n[|Pq\]|XtOR UcdHЧgxWx j .Ki-7?.",T@u몎[C-}@Y7YE +dtr'd,l,- kbp0&6o2딁Pf4M]ű;n}-%LL23WX#o9)6"EvkNl#BhYn:0 uDTysfUy/Yrpnv "ήG%`~YuhaĘb6;59V,0_}]9+3hgE6y狦XEhɖx[ OkDq1E.rMs5rIuC﫷iR5FЀ>K6]uI, = ptp, `d&̸ZT-Eq* B59N}%QҖ\:5wXQȹfәEX5 ÷ʼn/^ [KWYg/#^,^l"˄t0 Tiwũe#'UAu<(c9Šm4﷓_ܰ5d/Kq"L"Zj"(i)H.%޵mL7) ]WQwmЩcL'G##C]ed;F>|K6}D CQ#}KUB0(` D뜒׋xei(8zF~vNvД}T&uvw%@Y^b^;ś8/ڭ7)d  کtM'd<P !%DEU cuw/`­ltSSU xVB~"U}jPDu S#s|О?8=?!vuKj (ݨd 5FE+@PdɨE$B'LqOmۂ'[ I~ rƨBs^apeSgĪk'Q K^Q/.N>eɥZ4  Jܓ;9@tJHqL) /qhrIًmXvvۍ8 ;:*T4{'eoCGn@M뵗( jn&ew9U3g]B yUDFo?]A"PnG;)/A<=%?d\~Ff؄c6U6(pb)]"8]5׼yY# uP;߷@'X&2<+lm9>䄦 7 T SLsUKk܅hHCu; qHWzɵTr5,qj\^@ &S.@/*.A\re:h^RXr<#V-b}&SI:̊s0?_ *',>ޖW•GYEfLl'd?'mqG} &'uN}TސR?M9ʸ<ih%M&$'aȡo*RAKrJZB-+U0$SCnI(qn:KgVJwjL;Vo5g0o5„ eG v Ы6JƖ,NL^{AÔNVd&ց>ҽY4(=kI KXj>l;tXUY8(NG}\%qo1ߤ[i3#j!AܜP,:udqS uMwٶ!tz+= t 5 fekγFx љԊB3ȒIݳ`y2eDŽ%0ݖ' rIlטwR3o SܑQtI6 gOCoR{E?6 -GʂJq$RjJY{T{ת-0j=徑Ԯ{P %ӚD?:Xs"5UcS0&n-XS}i UH4P}Lԗ s}LіtzNlN-xSsi|< l_4,*hc8<(M]Kg҂SP }Oaȷ9 =F12 E,ɼnl^vG )R̵O!gwtݦ4n9)jLjp_v:Ԇ*ŝ^Sis _tËJ@$(8 :?e.-o8f{_:P@ T~2NmDG&&:t:oIyF*DY&^%peU[f֕C*|P?4?jRv/6hI/*e7,d4ʓ) yNSA2#{Pʼ,ۢ^;%CCƔsb|Q: ,v1b/hPia0['{SՕQ.5'A ru5vbm`ྂI<4;P4q%v&tӱk4>}|\j%ra/;)q\Vj4y1*:҇{ -H-_Nn;pL0Zwʴb=l8_|3ٍ!xֻiį"/}po<$n}_O~4? 0\r Y ek^W l/[z=tu5͚9K.8C*_Fd/XCg+NAiϺZi&+]'#*ݘ0Qyas܍WչxdH6`j=@Ȓ{+~>@ <ԔskGZ 9)Q7L(ÆrfUtHֆ+5Puԥeb"֎3> w uƂ9R^h߉b<#I~sK>ͼц^p, [?HCHgT&D ]CpPDBdt,V@O"r5>DvI?,j!;; $M3# J/L>D8  ..1[w.SN-CaaZ92Jc?7*gno@k\RfO Z#aez=o٥r2ǩz7g<"|Z-@}D* s;F; }Yɓ6.{JؓЩ>7,^k=JM(m֡~WQOk&%IqCLgVZDƆ@}8Oʿ #84E_MOYŘ|dQou>Fe#t̝ \4{=[\022}|ĝ Ub͔0Q^GP,Rxͩg`ꌝJ0FKpý=}$TlLԓ%daX1"-2XFcWgļ08cClubuld8ɃQ [JXN` ;j[,E_!Xu&Ff>hs6lXdA~%$C!6IHԞqMWY'1C-45A_axFfh>Jsp$vcF?\ɣí2oq >+ .z,<F Z/߱\fvxL-79WuEc4R(rqji[9" gv֗ #LKYYXuv 0UILӎ^e)BѨ澩Th$`|{ެK㸶v Ojt*Ͼ@.D„)1@T83H0:VgO/~%;g~5<\ v'[4Z2 $CeH8ýXa Z'+ipPx<  6^g07|^Z{k=ZiUL>JZDB141v-er9phD(S1c׺3+e~H_(oU#6*p|p͌L_=66R>O_=8gA#s1-o{6<±$ ԸoˬBH۔7 ^s/1җ!*l#I&jHf* aⲤ,md.'?+w :e M2W}ױݗiR#:gQȳLdesc7KžOxneVQOˇL3]O*x1W%>;/0 -.F%iV >HEGΩT )eAhkqwXx*3Iw#'dHei85,-=4AlgtV]Ybh2<a6 W8<Up3cӴX*}ӒNhQeCpge0Ka u@1OEbfiQv8 @ Db|B5(e:3:@58d /P8ΙivSD4>?DT]3n\b~ }; CYF80] -\2@{Mgx&=1m;l$5t7sJt&hG#>r¹IV'n㴤'd3!_h$!K-|k졩JO|2֧ZHQwM"796:fF/(hͮ fl'A{kA/zyӯ>$$S"1 sBE~Xpj)Z);aYaZj7%+Eb!7~ ~IAԌ*ܜV*M1{9b' i 7>rLj&qaZ)oB ,Pnnb7=LeEAq!ӒMVi`$rHlNj sv9T}KƯ WaRHն.J?('4LH zϐ[B)R鲖{JF/ M^}K< naNx~2Ʉ }e5[L*a_^D~rפǯi^¶Txpըaqpn } v#|1۔URv QZ9_?3 m񁴤?grș/jVih7;(MUb6~E[Ùu\" TB"RWw\. VfºJ*C v77z pžs*O}3:XZhTY.Q6kwJ#WjB|(,)l{G2g9C CS7*qZ[.$r=/hjKyS~[6s0sRLמO^J'qko_ϲL܏b08hq.D+ЍV).k(/v@5Xt(15 + Ox8UȋLN=gJOKb0%a Ӄzuq8G>I&*cg!MuTN0tV|ȸeT.?T;&μôvӸG`&+r]@F$[\8s\|D$) 3 h#4oT+m1ךh N_S 8u1Wj)+T~&_H_s,|YvS?.!3Lgz=zw;Ckm x}‮2<1ihs"5kUbX?Ϛ/&=q *b4hzT8^g]Os0S#{zʸTyzvP-!gLF*JE4krS(0ԓZa(a0۳E|'׿HEwĦdv ERy9b7VutS9AF!PlKmasK%z䐚z6 zb5ȗjִ C7ʽs(zl&8͌UH?;#MSA}`>?q~NmY+ Q'o<^p#Y&iAaUN PʃMۻ\T.i5>n)p[|;s?QW500 ^ &}UGd-* COቯI ͏4&\S7ph򗞅r2sx$4U g.?f' qdR#[!"n*'S+'9zT0/1>-1*6NAG ܓb%P5s4It%j)}+k!:eH$GcHÝ@J |Zv/zʪ ] uU9Ɯ[-wyGs ℿ3< $P%˅i8^ *}Kd7 'WlR=YebHt{2HY"ꬃ dp1k {gz6,acD7J|X ذ/FcȿIm'n]&B295$FfO]!Qgp@#? lȧ2wa/E%bB_̋fSc$?@#s=5䡟c ]h w]$r,,R.4`χzbe3 pK yzdX痈*)e.!=@B` ^ 2r"up7 QC}jP>lp1ƟpOZ?k)afp#GWLr.^RLBRP7<̔n*) H{B֔}5QZtOA?F%D$uKGy(C ,/Z5 )WmF$7zu4Pq's.|Hz?۾Hn`>$&[.v\Na6fW2^Is ~HȝHW{;ǧq,~١ ln;F3u15Mm |;Ŀ\TRю*[(d p]ehgIt(9)뻁%G&fMXH8V*VХtyi L]#' E4:_+|5v!D5|U;r;Mv#$,ۑHa2MIkeM}O nAo*J}r7-ݿt܀dEm@jsq ̗u0s4t^ đD'˥^8C_3ep 90O\o=57ok1˨/!jt&)n|AL=l6:.zcq] ";]2XA3D`>EZm nY)+?3"pa7Ҝp-eQ)gVF5W"o&lighiyEU>.@5Zܠk+ G'/9 Zz?"SYju۹a1`T<¢Qi Y4P- v[0چ2ڨa/՛>; #ܐ@>K{0U^ں>Voɕ:a^#$U[5Wt 6CwUAm^^n `wHTk!ϑbo:i-dc_˛ctuKںp 3+10ꎸ@2jR_9£P"BW("⒢W`{R {:Hw+鈂|JrK=e [n} Qo?-:OڀFR?U6@ ב*w+.aڜahF7/fA9ZuR)N8 _`+5 TXΫKwYʇ nx?14=#%Qӻ*O}[3Ca(uF˷:vm<,C?EP䈠6 f (.p츯OXZUjCSMwaX[Vx}L&?0}^MCK˻Xuu1W-hc> geh\_CfŞZsHJ^{k|ӁQVv sbʓAB#TxcXyUD}ԩ;󜣄x@7Q vƤ6\#9IRsjl 69>':yQwϊZ 0 ^#2|T{s4P3{BƤDU>Z ➅+N[0X )OO:x6,!04r&7*Hۈ 柠q?A"P}p0;A%&w M{B%\:h8anB5K҅t'P[n-H*`kQeZ@7k߱DYþ5dc9^fS8UOmCD !}P3=^jhCΖ֜>W#X=E~$GlژF4V1܊nI~b5̂\٤#B,&$l7&EYEE6[+A(λOv&>zdDL 0|.$@hD kRtACn:ma` 4%*чyz遰a0:.!80رϿ^%-ZHſ"w#;\ԧ@~ˉ0]O_5kvs3 /$20)Ag%dA*c\^6%w%6Y#^8_څt\iC\ RҀ 6XUL ߩSڿxP|)&fop]f@ef9?vov-g1xz,8EQ_{_7l$씬at|UE>z`v|*jŌuf9FmP)q*LnlQ.7|?ǚ1eQ@;^3 ML /+Ep:(ԧq6ܘybYYDfPbZjj؊mULF";gYOVExSo}'7 Uv>hpixj:Z5M֪٭g]23جj쮅ϑ=e_>yTFn*ኣ{ڸq*w㡥%RU'n*} de<>x sU*=Hd |[~@~% A]Ϫ]Sʚ}?p'j1[N?(n(CǬZ(9QAsLfAܩPP5}[Z.g:z\^m)\y']Kp̴Qfy[wu\PAxl<P'aA/+^,=ióODcʟ8秸 xaSs҅Ut*64ʺv#'j+̵)XB \a=QQtI#6ǿf@RxuE=LPR%p24O':za(FQT3S՟Q2]u3"JZ<ެ̩'.|=G^diBS b8.HSӆ? Uh8J4v.84RJbv`q#eZ. घfՉ\P$_Pk;!>UNƷU,ze쁱AnZڠt9Dv;2!`df* h" IsBBcvлb3^wni!1N;]GBktLm?. unk >I\G)K!Ȱs.:-(*ٯw'$Vxk}Nݪt)=/,z ywM( 7RtCهԕjNJ.9 %I7Hl!cҶ !l:$d*4wvjiupki }VӔEMiA@\G{Ꭸ^ \G ¤) AxyV!ʝv%ߕ펇f(j%{Ut%1]U.7^k$3Le]b\כlHCH)3:lRlB|m*el}*D2WqF8SVlV=qnB\ڃѣQ$_- Hnzƶ LHn9IȠ#AAg''Y8o6x4B^IT?FLvر86:fKoIp>GLMB>w&Q34|Ei:kFMAćqɂ?oDʑNZ+Hå  R(b[<)4aB#d}JyT(Zay. qO%Wˡ>e__Y~ a's|sWdp L\+:G{X+\^HEL)4CcaX1H4*YQ%aFMCtM~a̪Ik0}rX{Qyc[h o٢0uSuAOu=~|fVKU:TLF+¡ӢC}ڣ(ayc=W N1Ȧ[\+^eH'^#WMWO߀Ԓ+r\׊%?LBIͫyb-8BX؟`-˩/ W,f֛wYcG6%.^q5)̵qr~itUCV_lK˙#H{kifK:3hAU%z3nZR%ϵ0L[&1ZxbN't=:s70r(|^mUQPkOgAK*h4ve.@ji@q葬P7'Dx޿ʍw+a.` Yg(f t\P\K;9', z5㒞g&9#l0UJ}gqw},LtT#|H! Zխ&Q ZMqxF ?/jDeǚ;M~_ј9t&ob{ o٠R H  Kͤ|3*cj>̛ iKEyv1r+T[*1 w/"4-B$PN^D}J-C6\Ef׽?cbgxED Kw7lQ4-I&@ _P)xSrϦ]VP3Re\)M, ׿JAa0:t)u4θ·Ć:ϰ$do'}xq}a kg*Sͪ5䋺ٛ81~IaE#4u'w%9^EQB5ro.9Y%F챗sCZ/0:? /XS1OTB f%x/\Cw .JD8Î.*|9Sks.3 t282흪jo1.gRq(mR.zi)R\}Q-*)hK3YY$6{ĝɞ0_0#\Ђ4,wåNd8٦&n1Gʉfȱ* 2W{P(F^WHЮ%r#M$ĤcEfmY. 88zDFйvFzGS+?A Ȑ&=k|#N\{-jX3SjU!`ޏbLR:H9̞ɣrGY:j,Iۂi1 Qɿpj6)=z wxKiN,..^sd*:,uЖ˽k~;cw7 ؃p9:=H?8 aWWBR-3vi@b6)7mLq᭛cW"ߍ 3F8]ޤ4`/qt?ݦ9N+OQU>ٻ/=rꆡ>dk\a`\?(5MX3Р n$z$g+_fgL^`# _wH>Ժy3 o{ ܿF% A Y6ӡYQ%ez2NjbJiH]ܨ#Kl#j ɭ%{IDX*)&SggܠBqW֌E<+kPRgRcswx(|ƗRDԗ@\`eV1:XvȱplDap0dϏXx pRH$f#YIEmCl] Fp^LXr@cIWR-e/~!hK)YzV[>]FMV Y{vr&[  3C kb-.ʛ*/=w^rS 5z;Bn.y<$<4Uc+ 4_S iV-ѴĦw,K+_zDpe!d"͢=S}Õ׳ Ԅ/rce w&t~)plVgUUߥtn-9Na+]_Ie=:OP.n)>EvĊoW`0]+G <qtK\Z*5R>#c!$THB*2uu>@,Wuq*{,T)}l7q֊Z"fQ0?XFϳT3*vwhL"#<@,UĪ2Z@P>ʧ>sZAQ|񾾸=~䋨+b8J i]nVuξ{%^娃tC"ܾg˰ % S,JuKhpUre QuYeesH'Zc$ M*mÓ-{VL|Oo$|l%=>aN͝|Ռqγ~EG&X"ߗbbuWx94-8jl[[y.3f ~Zj>BՎxA?Rd:`QdEGb\Z RՏRE c?BRrv= ,T!>-m+y0HVɑşVXJRjέklbֿxSY;S\MiBsZ Qߋ-qqczd4lF16UrNI yI L<Շ@`KBe(4hQ?afJ:^=f~-8 u0/<+n AjˆUqw}ҝcǖ-Kc/#<5jLdJZJJNtHN˲FZ1I*P|3*)^T[e& $N{*,1v 2|I[HkٌɅM*eT zN<}Vm07][)o JÒ,VxʨbMUEj0ëR|xO8hmu̫GzhwM,*,UPZe!9>K؆&7pá(zΠ}.@׽S?\UcSQ8aw|oBcD+'%3ohh@@"˳ +Jn6v,3~8^!S)MG{"q[^6wR E_^Hvɘg.%^G6ן^M݋sux 78"*.BgsDoƬ,Xw-9tݎuݶ'8PD n7xgT|.4:^j瀀ܲX,.'4:l9=m!D3!Gx-&1o`zw q;F3ٍb/W8;9 8́WG)ԚQf?+ڼe5@l;oM9;{Ziрx@ |i6h}61EBBf>1ʐ u[|>.`k1w 0~Z]'JmF #bcϝ?Z{#q=[, '4J>;70+:a' lc —`rRW*h4(]ອ[mnxPmqGSj^."t\-+e.%ˍ,cWKO䯏ODB}mGV S֞:)">%Es>#Pkm'_^`Gۜbkw5w,%ϵJN#>1뉂F̟Ya쏷ك.-!ᅆը 8XQ̋P=<+s-_/Lq3rBm*#.o\s l*__pÀYѦVx`Ã~+s#Ȩqt4A^Uܡt?Lϧ)DCQE.dYŷ62ʔAg"HLUg`c%&h26- B2Ȝgz=[ƯD%"T s;+ף"`?i0.OEbB8{[4jQxl(zϼ!§ űn0/ǽF6uXV幇ѤdVn4A!z˩"̪<[ii31tJ/lޣ+qD7/Nu-h-8Lk٣шZy2&X:gep#5O|g'J [ P_\3XFGE.@Eѯ>)xFm`T, Jb:rwa`Ѐp] =(+CG!{M{;Ɓ} RnA-d:lQt!Yr9}mnQcI8s!;1wڐ*yB (cPL'R%=*I]}|iL7iZYNf !K{Bx XMdԚƺ.QOwz%(51R J¨y(PR1~f$fo*1; &+W}t5(A^?S 3Ғ=^Lbuph]Vv23F<`Ra!^ݾS}/q;U޿RrfEt_[hBuK}R%|bxKbu_)­9yZZejF&\@vл *% |:Ui: ⁺+(~Nlt\{A=n K tutiW1"4M:-'ӍO Yj蓔 q6yn}}-n듅bUvH/&3Q/F 1^2pE™(FC.b|Rh)\eS8$L p W*={G^vꦨ@EU4Xk OU}ʍ2r_q=r\l6QټbB5ew5MZlF Le FAͩ^؁#}-m0xs#R"TaEoL63߷hʟwLu$os k$޴;D2/MDh[];_$E,f!DI% ֦⍛ZuÛwis[Ywp66G@]s,asi0e)PI# @XU*sj5:;ʻE'B"n$qaYG W1dHy{7 .C%\ -xoXn?[7=. 9ɣq-λxi8X{'[[ e.τg H0_A6\I#}ԵOgIJ{늆`6Nj8X\iۙ*9 qH$쒒,m!U+6)Ba{zWal'\*gRyps ػ0\p PǼ@;FoUwm1(gGe:h*:rnVS._zH{2ڂc_h1|!c TsV9מ!Tv ^7V`o見Jti^)}љΜa[mq>sud eC뫯bB$*| |>5-UL p7^pO> m#_u2ץS UzޣVq{N`(6T=7waz~Ḩ!ݩBGN4㞳ŵ2(+k:w:AO"w; w "VTߠLd6k1uk+,l G.mg||xNeg6*d ف09_Q-(X4hͦF"&||4+ Y&1pٺ=I:,$D+MT90w΄ta4 3\0Ŋ%I`2Hf0)˗:E:4Z[v{@.--l8\dId(~0yފ gj"Ox}թd=|[qB)^V/u`г 1DD/U68/ƒ`db~F>= U =y"g]L M-~@~DyC RZ gH)=Ie* w80xPH iU4L'&䠼`!0v}:? &GJ ]* 9 D0i;LTɧfTy,1ɀ0g[G̜A{5$-}{rL?S{H~Y Osb̆!nY\L4ACMD֮ڽ ꣫xԔٰ9Ȅ eEA'WXyA hԉ<"}lii<) N-U*hK:*OhnisiWfKA=o_;ɢlz߯`)3=pŜ ț ҏg(-}m_Gh*P)J@ֆ'T _nGջ8$ }3eڇhnꎶFQ1$#PcCVrD^rΘd-*"3!cZme TXv_]yE]N Sf^hr`Ye< J5%!XDX|v? ԟkÞ u% 1j{#c3: e[EH6 Ek'߶_}fztP\$#GzϦ눹zHW J158Qo"b"ݟN 5Ec] 9&yTii4ŗAժϱO6|%kcLi)c(b-eZia+HsYA5(c*ezRW{P=x7֤x sԠOkZP;ʮG+#VeKWe (əӋ')8JD$Mp:1ްi]6i*D6.ZK`JՖnD^6 *;񘴨~p5FWń. M5oW`Ҩ9VLYqŵ Q^T؊$Jf;gϖKV1)u,. zٓVu cuqPs f:{eݜc-9N\Ϣl]⭎]LJoo#Z (ZClU$;HYlVA7;}uz)4R=֦ȶ?nPv)y^pt9p49uکN>k0 ӊAy9 w]E0K=gH6yZIJ:xB[-n9Y3Ij[1W&T{*w^JԽ.Ҷaa*qY(zF F(@Z:[{STt;gFFwLOl?t (c`I rg-{mf>"E0SaVxܿje~ԮItkeln6D]x-O^쁼fY]Ӯ:(ie[e};fTBCUU\xft|"bSm]v/gYz۝\,u-xZanǻG}B-tq(DfxLia# %A<ܥݣd?EeW%ZhGgX$"hً&3?IL WkCULz=+dSV)B\ԎLŖ{@Q@oLC@~U>Dvx `1|P!QjH~VqfgW,K{-!Y4z@a߯:vD\*_'?֘/u02"3E"6B7v.p >ϱ)SHW81H#3+Gm߮f~OP/uXmiL (F4kRdJ-DzSQ3oc]=7O4t,ZR;ge؀b.869vV'=Z`M > / bR`:/K槸IOկ+5i b٣xsѬne*>*pb̽ Pxy+߹'$ĩ?qiGß  i5HeDS{=JN%zZ3v~\ncӯ&֜$Azo m @3ejx\DD_?=9NU!voI@$^ؑM,6b2^ֆn n٩>d ^O Jp'>H}ě]ƬGG{W?yZ,3ەh$Μ qf6í zԋ o P%TnDyQB(aGyQAV UFAK(Dcdӧ[yc(8sB/283ſT'rۆ^ްCsMC[| 9*UM'Avbd3#Zb ѽ W~T6|/zQRKփjr!u/]+m@k˩bU]Z[*"R* f uwC{⦿W.=Uo.kxP-ZExm=k4gT9G1T|y%E,\N[4Jt]K_hƱ-EGw%eA7]aiGd-.˔[KОo> 8)nP"+zXànzy/>X15uK2+p&Ӻs$u՛Z<&Um%8g<gSKI<vM4546 lgcHC,*TjiaE^dMLʃnoUIRM3L xaLۅ}.uYƴjl@ }USç fA/ !vzV/9C)KyZCTihsl(MY-%!'g\o4̊Zvkm8 S|1EQ$Vt9}n u>u&eP d/>`WRn4=b g9N)VrVFCb$8+^ XCW"BmʔAP}l5FOߢmʱi3aڵ$A$K'D3[A5* 3kU6ސ-F>6{QtnɏG&~и]g{!XM cuarm>Y,7'.E?58YbPATgXL&:Z,T\B\/GtrgvﮛN$TtR y~5ir"7wV9t66SqgEw(Ktbd@GrV7 (ז >@ §@]1վ-j ^2!U,*}5uN>-Wc[D߄FGo"uv*=>vupNhKAϹm_yu/]/\&Zr 8:ײ9^U _Ex4ټ t 觙ܭV8HFUPfkwSGP R0,Әhs8uF [Bk1d/R w_k9~ôN 0R{u 'o`flh=,zZ"d,W,,.(#'.nWC^oKfnTZV0w YS{pݺ=(hi*MyCjp@r?D92w Ǜ)]BC$|}˜5AE]bb`sCaahH!Kjֲ,vD$y+XZE{:QJA6KIP1YGJ\@eE=^i禶dq J6MQ_^|Qo!Af?x_tcR-)2 *,(*Ρ|!(՗De%$D9wlT%o5L ht§?'2An8zZX &aZTM…}Z@]Jzm#1cӎzd阛͚,hN!WCrrQħ[يZǹ(.Rhd$!zs|asA.vb݉ ;h~/O`woFA1[ 8$Q k`+.*Qnk3A]"8jAήxJtl;79h"r, z/o왻nr[xx*n( W鯤b>]1+|mxa8xNMphE}ٝ:CϣrR7A$x ȓ.6'Jrٶ oNA̦ro3Rr4X6l|:wspJv"~P8WyL"b*Z &j~͙>:[KjH}L+h]FK,16*$*کzR!jg3q|y!oloB$LJt*:Oߌ@O#|i6(q1 0[tTUYg޼⣲%y8󮔾H Z>=` #[2 FNh`r.E^F*6&mQf5BF:l lI{662rl,ҏC s3.6-k!vDW*fb阣/:,{c Ho9ȠY.OM4lCN*nUL%ks|0(˕ N:=~ް#<C>)*~/׀a^ЛIKq Tf-Q"$=vyaL#@UBy;^^|-/?Nw~}!퉋 APN58_͕*/~供WZviD$H+wRt]YRan_@ƼJ Nfyo.Ѻ{2آjs&?<#׿/ /v ^0eqsDފB:jIͳ B׮JBųv :=8B6ꊬpOߏ^ GXkPWP );*lDQcO` D>޺ P(2M@/4Mˑۂ3v ^tv(+F^;desQm|W|lKo 3ylwyWC J $w1?*j쁜NnHIRj#'RPX\5}p}܀A1lbJ ֦eiזɢtׄZ'> I^658"Tn؁"tg )й t' uʨɁx=`L+tdo,]2Fd fMṿNDt0BJsa/%3nc›\4)7W@((aM@2, En :4 T2*k&5Dd1.%KD:%D(v#[hH=/t-m "FVy.)Rn0>KoƊF{((Ro|R*>K$UG}r5@f eVh A@"IʔHKmBO9F 9/Vy(me`cH[&S(v97x @3Ҭ;tb֊KQ;T%"jD؃xN/5BxAתC^ -HSNu[^8'6&B9#ץݛx/a+Q暸nj`EԸsƙ@`V#sB(e5C8tۏc+ ʌ X,^R6Bz1J;랠a/ IPg@C$9(GV(5ښT^KP} RAl71(2g 7IhnH#d :`7gi!r=^uA< y7/@fԜb'#ŝ+:$oslٻQٔ4jUoTBY%RXyd,|}4$3 S)G}ӕ Lݛt%Lsj ZuڭJڜ] n32_o;s%&1;[v&yc :ܒĖLoAPtgg 0DYxIO4-ɷa/YL`}B %T DHܵQOE)KE7^ ܃U\GY.*, m$iL[5r<90qVɞ 6~ |ѤS] ~d[h~cHXjj7 2˲5?aC/vp|eֿIeyW}? bl"i=-yg;6ݴѦRFY#Xp4] x'B)bLnUl.s)StO1\b-e(#A-! >emw:w`ȌuTV60 ûW%NnɁޒ$ofg^TU~2x;1s'X*LՠUw1a _VqEq'{i \_1|wnguO)K(4ڿ@hi+ɷiR^`dBSV!K}>Cvdy!፧LjsJW#bZBIqn'/VOo~ś1||P%!uN- LCKFɚbV )oVNz<ʛMVsc-@9#U"v@r%z! {EarÜwJr7J ;$o4TS'MAg3 N.fiȔ<ͪ!ʸhSDHjaU"\C]Ecuo@IAaHmK^=!+4Μ)9f.E\xr`ONL"mmƛD _K+MMYD`L&iUEQ߼x;CʺJrS R?E>"1ɁӠoϒ>e/B+ sb)jԳvᏛ> d'F7`'$qiBDLЩiU,M4 ̿ve;fukJ G$ZןC~JV,,Eyi{)EB[75W{t'g{,&OhNJu-h=L? $$DBR\, qTi@]ޘSFlKTU&.ا<1<.",M̱uՑ/ĚRWQ(!5~~/H>䐬7BU" 6/@/;+R T|>Uf(~w`Ma4^@ͫ~=%j[m~Bp#m8E!zB8j/tC\:C2qq+IeT wyؓa g"em xXܲ3M̚34*vncUH<pt>L,$"ќJ ןvb ic\i%Gy5bmE8Q\\B$&<'hBiH/{ӡlj!4 TX42]>dO_k&QU;I1SmK]JΦ>~LRl^I-gZ]LhljAy`AE)%])AVđ"^l}ɶ^8e=A#\/9Oz>,2aDu#U 2 8tW^e5z]OR*dwΩ:B b!mSv­|1xt lH{lQ%|A4|Y4 <%M=BBnP H47;#@ät6Ua=vʰ_e]!.u%Tϋj :~㵞N }izAbYD8jRn#A֝]_ᦢ 1$y:U6ش}/}:f;/HuBkR}RI-ygqq hw^6x9z#U!/@Ȯ0^&TF y@n#ЃTbS2i<&]$5,M_=W~5Tt&wSj'i\Ffܥ3x'VL6~A:%YEo`5h66FX۶ILv ZNDk<̒~RiJ<fjm2c7xׄ١`b@y ~Ti/+!siBA/Q7 [xϩ}F5ӪpȚ.E'~նޯUսLo^l 8WD÷ƻi>l\>JC~'}aXBt_dH\wMܻ+&u7.A!{bZqM]a~-Mϳ@G'?ʪnNfT=bFu>o?S~}y(xB $\V_}G+{0М֣GeS U!Y^1g=.lɛWƃ7]LHy?{tm|~Yi00@t'aP`3vUJIwqnHh^iM/ÑEƇ7I/۔"VklI&U^XJЀJZt^.I`,Gv V!$OR-!$Y}N۽%f4b+e**k^t9amz1x8'eb{;q0$Sjw!w8PIFrrᴈ3mPi:'jb"ktV>ʛ0:`N=,xE xwVKP\K>I< l.LZ ,ı;+6(9/:xhx5NőVo9fOՁB)iT;t9ThB5W)rK> (W;ST)]x$o*}h,aΦ74/~(>:tOŒtJ+XxݠhЏ6t!/'t%Q3z~^nSͩ"fW}Ni2r@h%1" k2]Ļ,z@owL[h:,U&8^\ƪ*yU@{6)Y a.I4_KTZ`P=dREtt:CR`jah0.+yضù1ccC8IaT3 hL l+5&brxwy*,O ܱl0Q7o7~ϓHN 7Y`Ni?ZBmZ̓Ƈ=jyP "#ڃh}lhSSFrҹ[cpNg2Ε4 419,kQߣsy_<͸C)?vSs N4+)LKj|En%=x{^Uv?\y2î]z;[l{dc ĸ,eV7ɪUe' u=B5i;ű[C&~?:.0oz|AWW,疆/gZ ܹtU zV{,yu<2MB_ ,,W@,zPWv>>tcNkoG"芊' 8˃bY gCj"nV$/W0v ҥGcהNLb)^tujT@PDkHJV~4Dn7 $sY~ 6D oaw!Ŋ|2~qHX%Y]N8]Vj dk>HG)r _R.ur[=]׍.@MgEo/"gNV$zr.!M3wUPQDha^NDic)VOKǢk 9ھ-NVqR')-6j ܦ͘Xn5 Qꂣ΢Q?vjԇ/It䋉lw9eI)H]t`/@VVݟ @B._x͹=or 旪\7ehb>/sw~S㬔ZIHf-(dy^Yn̯hmMBkPCJQY^;zFKWlfu) 0O\JS[[}2p魭)4>cVӭEeO@3%S̒m7ܟ<8@D 6T7ez6q֡'#z/䫃&ZIƯ$뻼0y/dCM2b{(sW캫M2n]@s_;xnD y]T;'e-Y쩳TliW{If veߩB…_ʃ"p, ,]5iaԡt;J푦›* >0|^eT8Ҵ1¢Z! 2T׏/`&af(D3T`سeos7);Wel) mɈ_˝ȁ!mn'rR^68O# "N9=#"_JVW2GNhmX#*4{޸P`EObH:1PNVPԚQ iԅEN;K6x:&[WYt,1D!NSdKxl5-7<†=0g)a7k|o z ǻ ?c^ImKi-(Yǃc{3Ȅ-u i;eFڊS5j6y^{z՝qM$ X엺Tx!>E$;JZ*2p6 O JU(),4`80LDe=ԳoY(3wGkh*"k39[8> J=EL(eYXoy\ *NB(`гklq Yߚ nzrWPrsNXϾ^?/ZztCdC; 'Nj* IIcxd ~mIʇ[S]M/s üI ,)1 Lhnr(AP<:Z D5dE'VJ~r+ub)kTQ~/ \ tmU ;Lk:eB/+>iaO){ic9PPapBe$L\Ӵ̸'cbB70T懰|kW3{$'&QlBUe-x٥s׆rH}`BT슾rqw+2d4!f?*v۽hN<]UX9R5`ܛN7SLÓ}NhF5![uܹs"~IC85cy#ΠP* u.,F$Ĺ?am𬙯F`ɛ8aeY/bR{iqC$9Pn滥4K|^jk z+j_O+io!+ ;[7v{7{zǭ˼l^X9F㱍$BLzar9jG>MB"E#U-;xg>2l.Ge5P2j94di \ZSq>c"*DyD6('p\p "i8""2L5T o;cUivPG"Bv\ ADq;/57j/1^Hn;7Kqm; 0B'd(?ThqDKʒ%v[c:gy}}]J{ѣ%>+CZhp)X䖷tx%ߓqRՑcZ8 bJ&etl3>F߃Xe_.1ꇂdTQiǤ/pǜ#-1 ˫#ٺT>x6]M6!/:eBYAK+[E1ay/%y T'5fjX骪[1~|sRptcvA.l64nbⷑ U :j@^H q/ NW\Li{ C׼*bӊHh")Mem̹U {.o18_7,E9j(7𾚲/URnxKÐpcQF-V6Vz2LP'Tb9%18(^1z AgsZdͲV3)D9)PB':_ylK1_0/7 * BM$/\%9f*ʱsMO;o=G=<5$3ɋ\D^\F\g=9LΆ0x;m^DE,˿kb2uC}^b= @h/[ b zzj_♂<\.6΋4 4<0+זR[o`4T6A+*Yz@s'$Hens A.GvUNtT+Qڝ@V5Ő1yUo6zUl3G&.J5:'Jlu ]n5#iQʹ ]o=CTo뎞j’3!џkAZ$gey6|Q0'Y1%}q`k(09: +Na_rr[u8]U?c% zdZlrQӜl՗Y=XL[BsL^ڕOp~ -wQ?C_ [CP6߾}BւE rV+ h~HȜ^KϹ}nBXc vEϙ`syxH<&/~HAH;g #2u aRS\ojn`L,T?o͓=S`CMz1jCcMfI\):BnsqW]8)4}ɟ+TNRp΢We9lZ XBFߤ.vHRi}ҹ/RIWZHC"(Ɍy"#UIo;UXWqn+>Qn0g F# G AeEM͋ڊ2cnQ~ kp@8s`VEk/]h{\ԍBe#X_ȃUYU Ak&9-|[X,+h :%14N~ 6jsF^IF˱[GM{:bACՇuݻbDx6r1FRνoϝlJ_U4"Uy-{q!TbJUV _"R7d0YNv"3yH']'agV&*b#Og 'dY~:ڵpolhĚ.3vɮ%%\J_ElDʉ#B?>#!T= E}M/lkcs!fX\9O p7h[Gp۫EI z1t:tvYk8^!8]G]3OP~!p/}.s(T^G;3u1IK :DC}c2C (f=?/%=2ɹ5f $r0*g&1]pU;i?j{;8wl'g@6QN"3ׯwUSǦ3ē} -X˝jYy\/.Rw97\b1+#P]x0`Ai\nlryq8f ^oRHW1hCZ"% ':6俉S)ΡՆ7N5CU$nۻasqǃC;%hXssӯ]Ab󕣧g Sf' Wc , a_*K 94-)} S)S#'uowcw n'f)ޒK~x 6!2jG'+oIԘ0VXlZ~Aa^>/Mǻ;olH#пRpr_ :(@V0XC_M"4)$ҹb-Z1'utT♿u= -u d\Y!h酑_G 2d_K'3[w8ᑚHOqY􆁑'2ˢHL +h^xޅ7yᓀ8E,!?0eXR[TvTXbzjb~6.6N%#Η䓶6OV{5Z?̣@nggZfyn3Ty7_D9 _ D.ЊJTT[+7<9r40Ѕ(ܓT!+T!LQ7wN_oL2xCZjcdMH%FSKL Ɇ,-Ĝ}&oQ( UQ.-,/j^ד8 jAyf%+1 㽟5_qoN{D"i9o}s&%2S@3xU~]ISsG"dH{5bSP/RlU!eC4I@:ё45Ⱥ&U>|8 anr()hQ< Z`šg9u)/ƽ[k`1qyO!MsϹ4P8BύVP . 9'T':W󾘯DAp:3CE3&U9r {l)K1HX0~Uܨ4/ѡh:$]a*EЌ 5N# n{*~N3KtnLoLrxݳm9@u_mgUxˉSm҆e;qΖ/fD {{F@eԂ9&6˪:x]m狟']e|8rAp49BYE>R# pD]ܫP)CG>:]T38DsM؍+$.4j,ıbc ~{=39awMd 9E7Xht1 $!E%> нcϑZrJƋh_iY$àqjGÿ{'-}7$4aFO*z5:t56a#Tn)XNJt)O1=iwTO^RD2f%? iWѦ pj}D_Ƌ>;#xDh!([~X>g\D?cHVv2Cդe~8F7'xCʤ ІEcvf[@Չq%ߍtˬ3q1RP߆)+I/$ #Nķ|LΖ"CXV}Vς6BWvxP@e[_vyǓd>0 d|(mHd?p"kOpB8 Qt$2!0^#UnXz7ŹsJ} 7#4-aZyj6,:8" NݲR"2Ɯr(7spl%ľ]Fw]agv"팂EsӢ[e: <;d*Ri.֓T:<6KԪ_cy5/“tSspb*goPp.ڔAJrj26]WA3]WCD4~]I1L FМnLxTU*u;kZ#ڮELfA64?pU K&Ѫx׀ᘴT,wbZJm]zD:Nh*^-͞JTO>wJR`MF@ ΍I2a"IՉy%YQϤuo&$:^Gb߇MeF#+'~BUegCbISŎ8>ÔHY*8|J+[ Gax0歘qBo}swͶVv_3<(+O!U:m.*898l;874q:Pxa4beNFD%/ITXLXS +zhHҠ5>1eCQ o1^61 ~ba:Do‹ce% G$7hVv +S)o^Cpl)m}/:Ab/r\Z?v#xZ6)P.1gG9_۟8P*|gKxD/OT^\cB^'ZfF/hD\)~J^wķy\TgK, "ߺ(ֽ[-.ی |7NC[p{w*w-<(%хdvLWӣcrm)I/QiQiqd{Lg]/ +zͼٟO.O5,"ڣ%l.Re'i:ӎܽo-?: }Z f =￉[5nڒu"V}D-,7'jMBwfܸCZov:@z}54m^wՈ׌Oj驒I^ji0 PIe=7 OdUƵm*̈́A=Jf֣,"1Goek{}fPl [ 'u &c}܏Q7 OU nK)iRuNLKEL)R׷y1biV^if`r&x)vS)۪ Yt%ISdBAk@aL.u*&YLy)tbW_0YBAYJ*,+#VòzX;Cu` #%rwȞ)OЧ䔯K1!x(fGVUW7\"V[ jvCD~]Wk|1˖{]0)Y:gpׂxM)R+B0n?1dׄ :0zgpޮDKG"ڴ /l'm""\`2u$`ąXlㅐϖ^,yB#/\ě1 Š[UCW3&0T-d >r0"Aپc23}{$B W][K3V@):6|F;?N5kwd"=2e/?5k"Ϯ2seE$L:\%}P6.'IW*~k[sb- @W#|1zq-$WyD{M,h>,5 9rE<\K~ pT\qt ytGV?BΊȴ?_.mk8LȵܟDvҸ&9Xf@Kg ܂ {ҼVF%b 7M>ma`*f{R0s?15ryZ`X++DоL~n,xx"z,ķdCI +H6WD ;Uؚ%;,Tn.V*U唁q]-LzGs潎gzZ lQx%B%:~O]jZl-z>Ztȵn.V^RdA̭ul瀦I,U^22u؈ CYVҨ+a\3 K ~ q:3v МBz5Vr[0+X-?*Pw}%I ͼ:GU+:of56u8*h#k%}qw?Q fe|˭p'H"j{:,YB СmC'խt#`rw<+1e\Er 8-P|@T{Ei$B3~OMxYdci՞dE\!5\\4<Ӊ:zi,ɹeI|xusu,!>5Z\ۆ}[CGF)dQ|n̬^ߎ)}:}zXE>X͵{YƑ^`Օ̀HfOٙ@cɶ~m@#m,'H~8P&ce_xp!>\ `89lI=DޗT}|/\Я ʂ+k3ő&lOY#K{ϋjWO\NP/Ұvjz1+9C<Կ/7eOبyS┘Xzzܲz'zb~23r8scCnMF; 4kf5*\,U)O+>\ܹI,XT4Pil;+0[Rbo2TU}ڔЕuE2b@-bPή9w5; "=;|iRO'!Qiχ 'w˂B=`T|oXQ>|`Gt0>ުTVHh,`[%HUt D-`qٵ1騥!LJY=yGVIG%XgCn0p?B?R Jn,Yvm]Z!PȆl)&wiJ;#ͪ 6[߰O:?KQu#)汣nH5xTGl9Y+i fƨUn ]ې]3`j1%ᰃP9\KOY?㻸Ӆ䁻pna;jG2{u"r3cֽY>L⇊a# ;Sv`2ͯ@%\ .WWWS&?˕Ŀ4qTJN`}d_if 1JA$i&vy쒸$=ӈΔ7/"5+r kM :7#5K*;8ŃǏY ݾBMipa`w4'On蜢l9c$6ML5$s*e $K6nاm7`J*J g/]2J&v lfbFŵOj4^*fgJ#2黇e`Dq&SY9u}g{It_̑Tz+F"=,>ѵETRJEg*+ fޚ *Nz;EҲԊ%Ts> .ZwqtXIw7m. .иAgD=w\ClP)H[y +R+;4rQ) a.4cJiר%4'1I&,d=5\~5XڋNFs-#ל#eWek./(G|g 9P0fފL-,# vZI}m#m'Fy!S.* D4wTk/fnF$WME׼o]#=ܖ <4bHOG>f~ \9"W!iRy6.6nцݤY6]㠤o4xLzhͱb(G"t.Q΍\l 7ڰMjo=?0U MiBNk؁Xr»FNrcTU$z A7|ʲ/TN'g|6Nr߅^<#5n):f]=;Z6Sc˨@ԙd.v+.S)\ڼH}/=Bp61eKSsUuT]!5~us( n+[W/pwb `II!W ̴[<=4y"g[񷁚mn*گ3ldږSUδM,V[DS˜wP%л3w!-w9DJb(c던nI*qvROL4.( &f$ڣ=@蒨\V#AUZ^+h[;vhkަL8vTBl_dWNůAv ֊sk6-.c6r#Y'˵OIt֗zWri1R9)|%K-yɲ{N玝W4r[H;d%HzC®fo(N'C'Ӓ%^ phQ(~#6v:'GѝE\d'awت~X;$|+6B,Bo=]iՉ#M<r_0 5th8pS>nTRS`6@02D0!FkTEo+GZX~HA ~<0# LI0y_:X~ɛXxN,_LJ^aП\诗;rկz_R|VmBjwwK}mdz>`94G<6e{[qWr\^ ƜȪHs^7k u8 eI-/t@G&@N멇F ;Ҭ T7G_>+'vmr!ZiY!RdiƊ0 >tu(:EV'xrK{7U<^=`囔 ?8f ӎօ, S`9ֶ ^w9yA"JaEpO"Q9U<07]JS`Tqo'5\}n/@%#jjwԬz*~]D Ee{!?kzRp50HJk>e K򮈌νUG7Ϫ-;3c/.hKM1_mgSGvo;FM\? AQj_iH)ʅF~՗;N|]C/& [ hn\]E$y.gĶN@("2 $d"˾U 6۬oVNڇTZeٟ1'ID[člH܏ucQmR!ks]&x$ْf;p,'߄T`Rݾa HO^pG޳4_5Μm+  p$!0sAמsq%[8ܣ *F:fv(w5l0=7 ;i㐉h|ⳕ!eŐUT.:vsToI[vkfN2Yk,^EyT3ҚD*^T`J )4adV݁ʰwnT6UFkOaa86Q;rSR|n+l XA gh711 *&{B)2$1-tM۸z /;+eQjQ:t4~8dWi" /rRVpmT̘x>_K*f]J,8aB.Ϛm[ԪDKIbq?xf:HxhFEޔ6u"JdI}p`DCuRӌq2g8Rl@)J9(YR"5=8XxwHWdXzY,m s)w G+td2я}.%<h&X߼:Ԗ/C:wU3r,,>"Qe>.@[5P,t%A5<2ǻВC*U,3J^E`9y'G]Fo.*V(5P|)ٝT[I‚;rnP9,AmUDNcl#%gmpF6t *Io7pdǂ {$ lG# ġCOӍ:C\B%Ve&s.iDکaH$ʻ\"_*Kѩ̏ dau{%BO=T\[8d0NT'd2{S7Eہ]}$Wk}yCVBLr@-ط Մ O72#a4WE/7Vwߞj,;NUCfU!/kxNAqjqVwWxCY(|CQ4㝷ClVn7쳀m VbcOqg0HP܍7$+&VSsxY!$UA{=У6t k4 B>;G5>P(`?_\n7&o>}hL<jdEo.{ m$=H2o-Ϳm;,gxkjCxBzP@/vSR"S^l,RjVLi*o:@ $JC-~!6oh0AF9fOI[.nSS^vsi'8I$ +a >ڮ Pv>ޜ`|caUlwX]IiPh#eW@4mIDZzƪL5SlL9O9Hh}pZ"ivәb_2 8M޾lm UA ,Lo(x抲>.%bדi|ў(&9/:~܁r2;b#YZLADBFard넲T"r5mzT]z敊xôe=A扐_r-?N[Mo~aa+I6ix5VZ, c"R--˽)k id GZNr/Or!+m|vf7psIK'WV!I8OV&/jE <Fg]z=mYP-;)TY˽TB%H3JY L-QOY`vpLL[aSfˆjn;~=4˹<!o= C25lI384q[x**Q p=+yqgMO\צ2i;Q (T8?ݟMFWu`T`ӍWk^v{ Ϩk]ĀWXt?H(Ɯ69uNےf=={[8*œ,K$ئL?^ovt9쮾aؙ1㢧"-胷@cçhmIIR>b ]x!X\Q%^rNqꎴSĠ#ic#ueP~&AM"h岸pܷp3g>X.,mdtG@I _Y<ÜsBܞ8*ņ cg6( >,7rMv9VvsH*kmtLqyMZ-p, .r 0d:y}ȣJoAe*P :\׷sB%]$pa~W4!:QZn@cQsﮠQ4ujM3Yaqh c-SN u=swG+2 4yg3O12 OphdIe0r&$WA`,eL42 =C3ٰx<= iHzD J]Њ )˽uf;=J/w]MY]ǻMs:QCx{T39t Ec 9kDn6Tvc HS d}>o+Kpodգ$J ^! fW{ƠzqA05OY"jdKO!WڻclfL2k@arơY*\ٹiR/\*I _mF=q2V <@͎C')ZTmMfŘXDjQqsl앍0M c>WϏzPv'Q9} $aҤi4k!0?K&'UkUFH:+ƒI8Nl$3qcr,{^#;1~ٜDV[ 6'6mft &{Dz߈pe$dHQ&b[+^@9-ߜyU"lM9cS2j OB=kh[_/cxiIs*q\MϗF}3ON .>r牠/Rg9!*;WI]ni5eǟNG>4vaYWZ]-Feպx֔ ,` :@X1ݦVnKu[n=:OlB\Ƕk%-dWSj<ʯ BXe(R zflܿ fA/b[t3#~w7 {A~aOZSbfӒdȹUXl@j%]c%,yߞulC $Y] YF{=@-C]koZhx|%q_HNEl ze3iwWn}U 0>8:ER_R$ܨO)tۗPFZĖFv}03plz_a qz|j+}8rKL 9殳ݠ.M3AhIY|/S3* F{&emžBʃ2tvpb&8ֵ؎6vu%B旱=L0p9 o1m{z#J`:վ%A?t?Rh7f;uM!DP8;3'$ 3T߷^~Cڶ .Wd%=mlvn ;LZѧSbc4X ,3jR&N D5R~Ɉ*؝.@J%<!˲ {92ϖc m!Mf'3e[*YbEV= ɋǭ俶})mJ:)?$K<.3SEQ`*b=4a5O8 ry}CWC.G菘>pX6<ylṘG^FHt1zNҗ2g^rC]",d:W2٪lThjq5yt~=K1Oib??}ag="1" ˴:HYPl*cZE=m~|so!!@w̕1:Kp f\QGdQV|9ۘS׹WBEt$)7m* eLQ|LB/Qlcڟ kJ7]BiPڲK'N,mxV)c+ uųURD~;V #["ߛ_ emsNxfe(bKISF$Q= N=v n3ޮGoYY P-Nڡu^id v"{(&5Ԇ$ %w\w 21.I2Bvr )GWí&QqxkP&e8㘘]Xb.쨇㝃e 봶NP\ )(FDχ9w R |. \J 8n vyȚx4g N9gܜEiCuf0KI Z1퍜h! ( N6*$,G k{N-ЉI.x"KaL:.q=4|9I5P.F yQ C8 WY sz/Csyܵ|:5HUItyrFޤ x<;|Cee$=P=,#~n#`Y !T" ?+B]^S͓ yxb1.dV-6g{ -` w{T? X~4/CĴM /2nY@QJ./6uc8pe v,w]b -sB9RsgUu8>oR!؍ }T.H 1ԪDiN+P 63T5]#:YFKǔdfkT[_2PŽ2gA# BJjibz V[$ vtjTH&3q"qƩSd Яeqt3:gv,2Kmd=UD 9w' ~C溷-A7؂:å?t@ Aikth+ &r(yAlt e\_I@оqC#臀Tdc)@$ #Mןvif φNQ'HLۄfAg%i}ā6bTbd~~R? dI,ŬƷN|${FJ h6e мpѷ͵H8-)Og'nF(]jJע~A=_-~gNgʧ8_C}Gg<џ?*'T%l?vfa`$w|*AoB;sPKLj- nV Vg,wZ}9`߂NUJ6 Pص~{Po4 ].sYve' va+u98@cAήPs뭪fAu7I\}l E}T !0~aDfpmt "hƎt_[lī]+K^78^jtꐝ tQ[]+VQdރE~Qv;Jh{-43`nRV\1T${ $ٳU2Rnb ?є8pJs ⰓYnOڮ߳h(K4 UM}xA2Zoӕ'"E `uDo8`yjx{奒/[Rl>m.V33^͘J5/ܨ Sљo%#QewF5~S$Ua\eMcNVB]zGKqfxXyNd5-ͯx ڼr^?RäB( hH(ReϩVDvWGX)N3_D4]2VHeтݡ [%@#,8'je΢/1zG}*N)b!gW}?4@ 6̇+}M uQDl$F wWK2r>:6m_3\)C QJ ʔ'j"+3γDUT/65+O2$!KҺȱyQ¯@kȳ%JfT}T0aM\4Q|EFl6.*6c AS!(>tXЫ/U;cƊn;=`鸫JV~|Yˏ-P߽aeBd!%:}Sˣ?_?*vUWd^m~ cG.1 CͺS WBJ^wO9,)f2rq΢]U:'=^$,UU{sv-Se=vC䛤╽}]N;d \^1s!: 8gqʃ7^[ O}97>GaHl#W/³3*-Z X%hO-Zv4'6*( K1*x#}~!qK`A½F'v')k"3=C;"I D.v[s[:kHB5ip+G>  s{e2Ϥa4d t+{o10К^nݫW YX5%k4;΢7U8!TsHD >BGX5X )" -MZDȪz@_ \"`^4lirU zj `ܦ%b_ҁĂ^{hsdL_ގF>K9IЧ.\.OZG&u{Ny?lw҈LTFjK I:}*=( l˒ ힶW` .T"t:Md:!!; uSf 11[pYr9؂puBcY?XPɲj5!67O2hmt|6I8J FXOemm'w&2L0ЎH*k{bc =@Cen״2m,[xD+gSg@&@F>^XU $]RPMnh`UoP{($\uGVa֖'TyJO &wY>b TbbN,m+$r]U5xpbPe5i|"ByRȃR7kdYu6 luĿ%g8Lޱb{s1QIf+ i*@N=uUA8m/8m/X|H'G \s1^7q^^ ^'A"PjV&R ]{4 )\/$g;.\C z6t+.nrz:УKx"5Ԑ`j]l>f$pq"H^$HN$ky#'R 6ePLXvlNSޤwGN=5}[,Zv6oU"euѶ٨.E, %N j R5POߠHH|9! BfDJИv̝64B2pU_V^!w-:L0<c?^FA" 6M>M2)ĸ]_0u˸B,aKE܃j_KRx,:-g~D@ωG|;x,@lTx&x%+|]3b,uס 7 e͊T)S95h}(eeӤns!vbMB,b7! zE눲oVGΎ A(x3%hSZwӨ.Հ*%HDߚJN,f2|efң[Zoa+r3![&βEIuaVa&ڣZ\'um\bg ݲ3JpHkU; fnyM; |3%.~/e]Uk8"u/锐OcwcFw=08P,sb S_KZN; ߇x&|'s2 J;_Ih=T+Qz>x-i(y92~.! WJ4'Mu]S3i$iD# z4BF rN F aҷ<+/<*CWeO$~>Kb N,-j#H&Btv u]! How}zId30P r\NUg\|ooW@L!sa} i.!R-6fh rM*N=.{v֟0'249Q;t.9Kח)n ߁lˌ"/u<&ܲsM>p0v[v.@CЩ{f|*}1hUf+0&=;0.=^;^YTcQ~_CX G4q䚺7ޮIW=QXc07Timc.'$7~Ҥ ,2,8!J<|ե_CyiWlvw1x}aeJCrmkD'd;z )U,:X>+㳀vg{(ʻE+B67峛Z6T8đ+3ر n'N|hj[s3Ik8 906f8d }*F?b2 Eٱxkɧ x:0DuL۾g%AOJƮtw# WyaJOiEAf p\"O_ud򀑬6h7 '#n(g!本1B~wt4ld?~~4]}<'ջ E68a#܃}-:2Z*Ƙ %4eg<|4v`lw-'{v U`Lz0b31.z6¡с^Uu6,̼j&tbyЁv%z/) c )C1A $6sl|GN gO'TH}9(O6-Tuu1fa0-IQTa?haYAOCe3"9{zYX4u6_ kV (NҜ =cjG1Ҫ_4@؊ 7#Ӷ2r)^3#_y\!´vڞc/nRٙ *l7\v򋊹ڱ$#rj q.,kΜH*|ʀdAW7}dɱ *?1Ă=35t)۝4hа9A>"W%i- ]@F%_ x5mg|n?HKiX2a '4'ygZ_ 0w߶z3{}t-k V! jQw93A+\Mӛb]!5do=/9x,8bE V|` 2JKn9{鄩{ZZSг Pn$'*)&˲V:\(~NN4|eJ:=lXFۮU>||UPNࢵW+oz*|9PvL]E`{Pvjg\ @ AT.DO{ܭf%ua+]O BHެstov!qj y}|?{)zv!}%ӆ\o_O4^|Å'A$~NJ\y61G=eR^ d4}v_fI DDp-&f6|Vc-/D5+}d2ᦗdfo-A1ZFl_{~mzLZ_ '[_xX~9YqMq?Ɨ&MWOF6=t4^ ."WLecaჰI}٣"616} K%,(֊U<,m(/v\,L <ۊǒxLW\d26k5ץ;(͘^V0rqI`e }SV% 8鳰=~| kd4!'(6ڪ_#COsSh cn.hNxwX%@K!#ZJKT$*+z#R~ tu'(aMtb[RfT{j>-yFvo9%"C_F-m9FR,#~Ij,)ؠMy<60i:.%=$W2#p-NvJHD`&_iq#^#>,}1;H**-Zy(#|pD=Q{"LGi!abGGOE}{3߅flaxcJ龗D[P҈e5ʌ4u \?ehU/fo&V8oFiWt>;ZL7r0N6+,Iەp7<] :,NSj]7~A&upzFFmQ{}װ!tE$-Eim)wvvc>,̔ _?$@}C.9Y2 LJ0lAgiL7~mnce8k@oꘁm $9z꟪ҙ\̈́S2A5( S2B É 56$܃rbROߴ;۰o _0s|g f ZV ljנز϶0ѿV0.C9OƼ L:8EA_"vqV;$LtF1Tsy-#l*^Yk~q>ӧj\7Aw (h͖.|*\+plӭ -<%#p;5FYFX0Jcs[S6q[STho J\>~ruX&WASX&N<_|j˥ d2ܖ85[-ڝmL _ Ok'ql\wqy" G;:2GM40ќu A5}hh7;S-+ϔS2$1m[׽4Ɉ yI_\O*8 Aԏ`rS *ϤLu5KEXHYN)ThJRR UDY[Η;Y1쳏(8%9:l;nNƜ4q_Pך{ZZ׆Tr> U'l=Bxմ _qEF׎J϶xT}qSa~|?9 an=z Eɂ .qC+5Q ۼn F kD ߷lN7m¿M7x߭]kvY`b| XbO؍u_)AQXbgFbnRvEW .rRMP"dfKc`P鹙d$)f)TmF%Lq_& QXQ~ȴ̹b?Up:B"=^ {u+璑-5ⱥ3n][u&aӂ^ Q^D`\#9Sc攔*N}tv&HՑbO Ztǣ| @>GP&mjܒ/M_u Y)sNԋ)}`CT^_E(3ZZ)P]_Q ܹ6_em7$@ts@,"bElnO䳚4p4'+#:\ƟvUpb-eXZS73oY!v`a hL5OeE9_5\$|Fdױ b'KC;̝=.r\dKD,V~>fk^H g8))wս-]~q6KLY#h%|:prF;j鵕W ;4&T';=g\ nׯJ ,o,_h旄ɨż xk_a1m^a}!b=L^@z Y+uJoKPn#n0X_YOyF+G_jWs HuW0fi(W<7ˬ 6po]zSeՌt{gA{ 9@AA*hlqm2/Zhc=(Eυ-ձ[W[*.A(2I_EJMR&Nϫ,V=Y82>,mvsT/ᠦj>ֈ7l3or3LU? \< d=7}) j%nt.qsd+M\ItoxgÓ"<Qʳ`"o4CBдGƆr~*$r9[kufoNVZ4 /?~vG۬-G{O$|qZ<CZg0LR(ZZ#Ǯ`2p ; w|[ͪ⋥<Tmg5j-=^3++p[Cs۫q@?إyqA+cV"JC`"`S 6*'YY@@rT,!\j5K=|t#"oZ6Ŕf4KvΏPB|(}ăZYM'`%A:hYB`66 LG`|B_Ո*ݴd0AbmKD}_I-:k18o&*Yڶ>+2J޵<S%@xQ֌MWh\@ J"jzE (6K&{p{@$H8ܜB2ޯ/Uk9A[Zۘ nJRegB1c9$rvYiC9XXajO[^&f͘H\-@mVma.aGpM)%R`hǿrڶ撌̘>G`&YEIaRPJ\l>?(F$1N ^⳦ 'cq8N#-O]6"w:oс:p<&O稾6}IE9Bп*J)nѰ|cR./$fstKlXic aro U@gn[vBgeCޅ3j+] y" H9޿kT\+m969` xjJj,ggkz,*=I xd 4[H?'Ngdi= /F\ EѬo6#'"׳Q?G. T꼁lepZ8J5)KdE0ɺ*HE^}ҔU(rNRhxDԱ ySbX %PPu^%qvTvN(;$132[5`=)!F3+`8:ruO _ŷd] YBYX#!"0)7Bpa;uL-Ph;3pMcI|A{vM% ,߻In,a{]}Ú߼'F t_Xeڀt(}gtj04q)^J̴PjB"t_n"`yf&SNnMo Hϧwۥ\GەeXkx -]& 9#owc0kؽJhqZy[$0Ƕ]S%%oi"$(w-fӚTISސB4y(])vݶO8Ql%M4ݝo'CL#;{S5D%nu>ulzIkb)Bpq#jGFLZx:7nS f6uƦjHp^LO[0#"Ǣtېv 6EGuȆ(`BrʺHAʚ]xx 7\6+j@A0C%wՋpE8Dd(jL[jH[4I{_r'/|xO|bSo̶"6}bÈ%٢:֫P1m-FѴ6׺ݝMʊG94Z}Gl+&u=eoF mWZ:dK\s$Y4 6dD5DBs ];Uu1i@Sٚ*m'H['HksnWh׆.MxɡbuW, Za< aͻ|Jּr1lΥ]9-ӵKOlw|~Rjm:IU(edS-` bUWrı ||rGL\a2D1jyt+'=J ȏD3>FI=&je\YU`,FUO(ezo7-\"н#ōGu1Ǵ"ao(>A,l EO /ru.*vc22< 1AR @IBY fkx¢(]V7OKϧ?,IhPDYUb?g2Sڣw1J$&;m]^5M\o;Q,a^ g.q8\ODLj<6\( ;7U MG;d36u6Oִ~xz=dC24 TDzOzM^ GWuIh-kЛbkEH 0rJE-I)PR*8zDU˃N.4eVp1'{0:KU29:vHSSw&;Lu~HA%4F;acO᳨X2]"v mSz#˭8˕I[' _/+rJWIW BLI.>&VewEҲMK1q()Y򮼨RpB}T;Z:gzO"Ow:X¦:JS(uӆMp]Z4K;6ܱEĔLag3|o3'ڰw7iO؂o=TߊMwQ6Z.&ʠB\{EyH궴/ 'P9QH ZCv$םQ SRŏ)CQt{wp1@ӨcYϑމی@~r![D^^ӗVdbc@<7o"pX A\A WϝynX|]4Snň7(ۗ;fIelta]AwmsCi "1љ9UZvJc p EQ˖nA˪ču.,@7Bku\@=&:&R#1@:pbkr&wq$@OP_H ¹X 'k͔rFc#&` }/ .l4~R.d\7l^NФ4[[ھn̓o2mhg*NȥA }?7B&}x' 5z'c4yE Z#Ⱆy4xb;Jޜ(nzͧ='`E6x mD"zo]4ˢs eI,op+y7hwDE-5w68IfQV=j VzC?l\(R{e/ V=TqGAKG8ԚX$:P_们EOm/8БpE5Ƈ!/>=VT X$D>gŝ͉G)&n7}lr3s"/8C5b΄_D#OyMߘd1[LEezM|1Bл LWGƀ;}]ły<:͉=ޅwϠ0u†ggO [U}˅0 YIp?<ɋ<}%\.0G,:xV& / O N'S:u~ |uz#U{,:ڄM=!>rq'O0^pA@<>s@U9&4tI=>0soY/ě~{\j<< VυG—ZFOmW$M&GպpW߹rXhpu}bɂ/n Ɠhjt'xzl5)jOx@/ֽF+0]ojuuQFjh]XR Fa D VR.k&w0"a7x}ہ|6N$P;th'h'gcA%NB~BxRgM*6%o T7\3pi`uDB,ǪvR2J`yR y~w9kiRn_@Om&[XZ-n`l"5k փcVc=ڿ ikv11= P-Iqx,hߚ,;)Biq-(0mW^GV"Y/AhvӗL{ܟ~Αgr⥠.VJض',]vzo(g /sS֯0Y<$|Kڲ(/K:xLۆ]k0T1& a/u=|+ i@ >&&]G`T ɢsPAq,G/X&\ǚ CgiRT"mB@mA4i}:[HH%7wh/_7szmBO)O#y'U,u=HOr;bחڢ4UiE{C3R;Ħ]E,0JSZR-K_oY'X ;UP<7.Ofb zR%ͨ:ˮ?tl:fU,3!S>l,\ ƶ^ h$&X0t;dxt0hxMWOw^,iȊ6K+AKb_d^*/dr=-^3u{fbz* ZJ.C$ }f_AM/#}TuD/hE1 5}dL0F3!QGV9 Ca+,v۠1M9eҊv#4%[yC?R b1>!; NqX(DϷ՚ܷ& E]@lGAX=YN4;7\(QnTr+O n:}$B;;(-o򤕯f@W+JؽF&Ua4<'`_pW̴4Eqח(,zkW/1sΠ X?u >U@%vJX?CcE`GAt޲ e, \ +ƕ\G,/J/AťfX?&DǷ2&à(q6' 0WjAe .M#'6H4M+tI;8xh(6{>s*ܕbq8NJflg<)8Jaؔh-I^͔Eo؄kFhzɳ!X5IUn!:W$ }>2DPy-hɳ%:צRsOW8tst2!<"P=KKȑ>eHFvh`'gFlԫc*Ě[B4=v0ku !2^<0HX7$d!Oz.'3-R;SPd"i=[ͣJ+TOJNJ8(L/5+3?Taza*(o}kǢNR]/=ť$ ӝ䙟εiO|h{>~HRWM+-DAG2$l3 TV˧ )<ֳhRlU&'@bj/ mf*lN~?^!ٶK:dX8 ]4EvMo*[`B1G6/@1\$LG>Ib$$֦>9;,fW~Ř7(x7ui(8QuO[>f KZa#/Gz#qd?GO%#JXZ|LD S,,ʋu#|a6e]h+tsbo\bs:_}?iZ7|r7–Th5oP|y^$t_u|n4r74Ѣ2c[XMzan:Ғa:U4r82!*l~[l*!P ;%YA4kx% |C_pEt(H AB*:t7SuEպKŜRpYo+-Z''akK#6ϝMv/դT{ƼY,#vVMZ0&6-(.H 9KMވn{40n#.G 3J@onJĽ|*5h_S/N8;+]8EĭwYb-vm~߮E?i c*=Č@7rIDPjYq:F[KfmԓNId\A-<* I '2h fR$.$ 254b;99=2i7ksA(Xf ixc0PҦ/1QJH+ftʘ |xW{أ|Ӥ]64EGѴ61zzɧ 4Z!?Em=hpcffE֞a{Suk>ߕIL' DҌ8] KqI9@ ѿ8($쌯6s׀%5tc]LgM| ``K~EM=I:{TitQMmErUuu!G3rvYkiZHeB:_I-YyhN뺬":x&եZH:_Jڅpb|W`I~iU]@M!6M>:H~&e߼cٟ? Rs o ÆZixM J%ANgg>Qێ0KNUIąH%d˲ iWӒ:†r+68!RK▣au*q/M_8m B@s- @g@Gc g 1Rӝ}3|Ҏ2”>%:;0VK!Ddyo(I'v95Iĵy\7n3142lFpP!{ءO*35 ؃-)FD36_⻎v8ĄM_>]#e~*%5eK7ŨkߑA+^Ξ@٪Vrܝ.q.T^(O> ͠;,.ABꯅ^pSمLtkH~eXԼ7[OZ-+p4nlD[ypiFYuMbB}hHS ǃK(j4YJcJ Bwj[Qq3j8øx3evV7[ЇPRg!|,pNyX@=Z^pDޞg ~^XVRg4GŤްy)eq4dzfAYFCktRyNb\B+X6&-Ɖ4wv>\ڧQ%47" h&&I5U#]/4khN.ab0PǚS]TGs΄xٕS7w={M^z? Mז%m mia*d>WZ>Gj@ m.CZ8yOX̺9† `RV*A{}X>YPmD!UosIϰ%2ή #oȻr~ǗVJp2ce6Dn4I?o`eD9 xJpϸfͪ4P =oR>ƞ\X/ >!¥Lˍ&~.r_@!M - ȜUL!#JT1:1w{8}x7iM6jZ8pu,Q=J$N@ጛKxxBu}*0p2%1=hIl/mF{*U";"NEjR| =/}vjiG^l .%FNfJs~]^>prJ nQ`b 23n Uy0tf˘pEW^IC'l4|?rb:}Elq՟=Ħc`&uU c 1妃Z}ҋoVV8Obx_e5$ShOЮ4 x0ߦ{ct ohIb(N;$ ]׆zR͖eS Z8<=9/Ъ:K-\mPZH>UB4o(afA-#(wY1md I/HFOގsA|ST en{]Sl'xK8ta?ɋ r#+ x&>QuRcGt7Kޔt&jTsfj6SBJ™گkWkr[ t_W;aI52 "v*^s zńYaL_&AJ wFeš<-EC˵CAhʐ;Qb2 RkRc>4؎ DT4.!~L!TaQxlx v[qח_h[Qe]Yݺt&g ;GlKo)|*1/Lm}bzTPIPfc}"1/;!zxS\-O[qJi|N_y.XgԞJ5(q*ByiyՖ柺C:`^p ?m ~G4S8e2M_ lYOsQp6,>Y$>F{U (Ǘ3ڼ#[g(c4|\/Drz' ՘tWN,~' M oYrwV* [/= FѮV8V1'9naBpC)]ȢGc!S{sDMne%0=e~1=3F^eJg-ڞؾ^eԔt`[8N9Im?xW:/0 ܮB};5)^u{꓂`S#Z3 QXɖ#2 SP+XA2&.i"l`iƃB fW"K=^̏ /'k^4[``5Zuނk4f,k O76|'OBtaGA2nc!kQ >,XU"!^w@V-x\yqiy;-ɣx*kW=S#Cg;h&I{RusFu7(+<E09e,顆JFe *99ouTzMqT}M'?p JiCaVq[\\>iQg-Rg4:-K |39,(U1!y`NP]KQ::Qfϵ;>YH-(cc]l.vcS_O#t0[MO{CS^L LrWWnxP| p}ep~Ģ _B8OYKÔޔ: 8O2Ta9UD=#LSCW]JIwjrȜ#`# ٮ-p-؋δp$IOeGN26m_q*hmUqkhFZgI/'χàX_/$W=fUf$UjskA1RbOk>Fb;C=%v,n(Û1s28Dnf||IPWF FkɈSv*"p׺c#H1h^֓$Uj|Qw!gp Jt4=029+{F]t_'f9rx/MLi 3P7#7vR91oA9P?fޑV&xY'1ef ԪӻJcs;v{ޅ;Uz@2oZpS \}FQiUiCpg ZC_}h6TK'ng׈JP,\̩ɇ6RiMݦAḤb>&%TԦDŽ &UNMg7ڒ:Kw@/_>}Z _|kG@^/bG~KP$b=3Ѥ0RRtwy,Y[%lJtsdiLf$EG`)I^[h>d[N 8"3gIk*2 ("⴮j2p69sX72v'L&7]ni;?TOi] Wg3loˡB2QP3쇈HUt@feBǙl_au׌w.h!! ]ZCd={@̟^ j fg oj5iY>!\ew%jX1 TM~MjLڗ`آ_ 2`<\(e2@336 08S;6CEx(t6 $:m[T0CZ8&eRՉpK&0 3=B;aKC;QEof9sAIb0ge#pP|3lgއ}FgQ$J||6̡ܶqV*S8|=ہ'ڱMh%K 6ճ.$gXhO\@B?O)5%=.>Y38]H:|QtLŤVG銔4=n/q/AoAz) 'RefDk5 ?\u⸥.KdB7!c6w4Cg%;qZ0Z\zz[ Ȉn5܂Ly$hAǜ͕Jz:mc e"0O\rWj!W$ǁ4 3ЪESzq%' 7_v *0ٟxNULLaf^T$8z%(eYs0}֫ kaD'7r$@T[E^umҧؼm Bg!S&0;Yˆ(K x d:}~ 6ʦ2'uΎySTT1.ECwy%1# {:Wy+ yŷE zF }T+nICnYmT_:iK,k|G^&? ^\F|VhVDuckTwQcxC.Ԥp^+P5 խ4цͣ^7%kG[[<g8}ʼ _DCZ%|IJ@xе؈YB4DbQA;h09j@CڸV˦$WM7lYuVaDlh1&WHIHÍrk4?~띲+: Hcf4qit1f+8d˾*аOώ%- x1Ml*n":/ӜzbP~uxEހkaߨ'1ne,[JȻ,͑k|wVƣԏoo,e^cF>jz&@usP{x ўA_f{ϘJ'$§*iĢ/U'aqT^z*2FހZ~ Y!~!UeJ9L\mE.҂_g7WbMPE=kOl%gV\x'ΰTyך,@^@9'jPOyL9D&fmZfkqF U<"A 8X_A1P39 ؾArb* 1m]8:Qz`q|s] =h&.t}H95xQ2FϧUvSX{05]olid9\Nq*9(\>Ѝ5Eə 4iKp .#3*DH_mmZ3v?^ׁT(Tw2?km ֗2 1/UmD1QfN.4xN;V%Xȏ_JqaVAT]So |TCf3W{ݺ:.'fT Yt,RbZH =jc"MNY ?SzxS5Zݲ:Fᜪ*C]d??q*gwk\t+g< еT44Z7#7+}FaWd3"@x;gz{T+:^r 9הAna4Ҋ&@Ko~FiT^CN^ \USO"k|޵jpZZoC0k/9bh)=d=V-uWHٙ)H_NN)G$nI gP5]A襽٪u>'{M1XK gP]["/m’34)10>i.c Qeaa+uc _zKFu}3Bz+ ۳jY@ՠ֦SEO!Ē$_rD+Ofٵ%Ym/at3ꆩße%NgWϯ9Z9 K2gԕ51G<|8 նU/WM]Ya]fk[uB]]wFltи-2_],*$f G;H$n T::R-\ Ks#Z;z&ۧQ#Aq|uS1Fa;g{(D ٨"";kݣU4HɅU<[SqF [^C+F7ȳg%X?Μ*?"G +{rكWXX,U83tk rjڨJ$<ȑBGd' Lf /Y.%ؼ5Q⹦8Oo[rg$uwm7 pUGlD1LO.g d](d$h{kG jIIfEr:&|?~!^\v% Q\o<`%-$m%"(Vl19*oHVw*b E|">A-t,>g~EGomM/9aIWq󼱛>tny~j)Urn, |Ju&9$q  8ٺ:^ f#(|U<'<ӫQ8$Dld3D4j#_=UStd%6Q472NG1T @̳q[Zd5ݽwG7gsMP+zХ)N"͌Ba#jXAt'APGto%7h;KFU=4n`|peü$q' vBt(o1 ;;3|2=Sv+iF)ܷxty늘P A^A.lqӕת~5i(I`J|ſ̀=`>jv#Y1ȨeOigA2WEZiZݳ=ưM[jEDƏ/n@^y"ù d%It=zV68V6}a>$}Z#leh֨5 K%L1c#Es+7k qL8I{<cfqwe`:?w4|EO(8E\ ؇ b [`d@"[D=ŖNƳ":9.'*3{!'v2"3'f2qrVn(~r)RH-KرY*emi)]j:r~(}3НKS39J%N*1 C-;. Urڶkl?zKW^&=ˊtѥ[^%_9,O^*]w\\oyWJ+FhpF$F,R*QʗGvu,&|" Al2GU34(f2]Bo,5PqeBM?y>_*ŔTVZXG_ ټxcDbp0W4SYYw0tU) )!ڮavܞIݼ8c "ƭcĉct?xR5Jq~qcc6[o/KLO*<6>!D'Vp X*kҵ25d'LXZ?(Ss_ h۝ydIDۯS##u#*9z*gK@_ZB*eБ_s ڕUdHVH //v?ZھYXpg1MvNzXV} w'c.U^E\jMۖwmMMa:yRh&8^ g} mjy_k@d~Vc[9q2IrㄽgQa[/PP] 4r6r8%ك=<׃( !םFhP E;l\>I._}Ǚ]+weY7<[!߈kD!}yt_? 'YG #)#!$|IAK9;rIyi/~MϜ|)&"%ri-p@>άMmILl{4Q.QRe ~2I4F5V6G#x%>gغ>ۊ6bO ˰N+jYf%嶬>i}VnH*gjV}npW2A_;%%="*F QM,Ԛss~v2~CN y$+ :3/ +<'54TwNOk[bAa;d:݄<X]`zJy;וfJ|ΥEԬ5,O@?Fƿa{Q"^#T:֘&Ax0IU~+v"f=TNX|`էk?c>/UZTK! F߄deRP#E! cnBYJ|f$KzɪסTp,Q ZLCu+Q0bg,l R̺<?30F({']w6J;wsgّ/IXgfx*:_!c3EFGϮ3>CQ^ sX,PRW JJ=u'ƥjhL,Xwtx4Xr)]hbktK ZN'jAdШ 4 #Մ9~К!2 -0\S)qYAܖ ?לq{Wc vTDh.s&77l/e}7HɸvQS۴ۋݦ׹#Ğ l`E@=TwEa=eԅ0D#i<$?|ğ6(.<sIьC)G9"$Qn9]V2\I\x̸ك園]Xu3?׆r^ț׿hxIbOC pmH:l[vHR9@o0#tY3i[IDf%ʍ2H#v9ՆrB+58dͷc[Ph/-jaAjرeK/!Y ] UL.O*`A2rQ5 .O*c[ycWd˙K Ѓ;tTݽZln$}; (X0;=y,ꂞf &.aCܐ._5lk.wk?ƀvh ;;~2. ##wF'ʵH )ҋ mȘ9C7BgxP7{ {YE$ƉA 0R{:NQu0h,O[y{ ︁ϳ -rT_OSTP.D?͠;GL#F="iFLX/:b0O;-0yw\cփG#ゖ4nU6D%a]zQ?[Z$^;x;}p;t0*ih<,7mT&A|ⱹAgnA`k#GDږ6OG]|d;dHE<NX5}IYyB:O2\u2C#{+fjtwj\_~@u zjF.m {xL:{lo.Iͬ򠧻ހZgR t:kП@cj67C|n-A V+p9P=Di;1^ٖ'Kdl3gNCjyͥعdLo_Rx"i9XVJ \`GbU_9ūA&m#"Wok$>HSaD@n^a[0\(Eµ_‹c P$vx6-a)ay}23=lIm)Ks]P#>SDHNo2 ;kO 7gkl+Z 9g "zI$<#`{勖g^"tZ;9S,_Xz#No2Cб݇*ڵIA yŝ &;ՍGdgYY&߅&blxLt |˰G:ܼ9^rBEՀu &em" SHbXH͞A#ۋDqޱ +D$ۗ_dFLc3gHӊfԢ\idդТFCϽYrfEUOƒp*f(E2lʘuZ1>Yͤ?t1m`VB\֎K=:v  ?vd|Dcy`"#wb `^E7Xw5/P7 Gdȉu\J.qAl*ϲB}[[cv3$^FTE$Aσk•Lpޘb9s:u%58+;sJpj]AxΒ1DQV]4Bl!}Qi(C}/}K+x&̻ZV ;3cW9/R6;I{ L C,W{˃-xS۷xa{m 7%1-ƃHm+wpŶLm6cz?hs(IF_^[4̀דt-zigpidT#Z5f9 הAÞ:@?_eW&F0X2{$9Ltf<'hmB?7rGsvJRt|wɘX1ӨE`/vȜ}E(gf-D/w?O!,lp N 2WZ}V>#fEMy>nL dA LM|k i>z/L?%RJc҃*  7>f;3C-5`i􋠖k>5|ASAJC1#KUܱ5ҀDu A|YYԮNiĻȊ˃2.Sgޙu>/(>?@uJ D@sau`TФF|]raKW{`rdS;<Λ*3 Y(2ZBIj|>j[,[h"_ZY i[dژ+b: 1 QxYFZ'N.CK )Z{l*%) CMY.j66bG9(Bx:*ˉKlgikdJ- %?:"Ϡ2EFergjFo"Js¸h`f97,&|c:9 4en\Hj ,jDd[ӁƘ )iAG+ig9) sge!M]]Gmf/SL6)1+ͤpj).[wWJ:nIGsH&lm;@?{oV}?늾;IZ R8G Ѱ9Y!2zyYەF_yGij2PP^9[1$UL*簏Ny;ް _tK;.Z.f/<%6=H)41޵hxfG_t|)Y_T_'%h(bulCTWd|5z4ե^YJwV"P!#%#hq2T'y<:}C@a$`2z2"2@[ŶշAs%Fw=|7Dh:Ӂ $}1ۭ)tA/kyg߮,Q~kEV]TSL(qLcsX9JݦyBfQF;F3[O-( b(m֙AqPJ̓lp l i+q`JAYzF\pdn g3aRO?,WpbiF;ӊRS/icpkmM)Z-oZ}YE8 F/9JEݡ}wO\蠦7opc^kԜՑJ!,j uRٍkZhm1 I, ݄yg ƙLPjj"R.ނL Ekz̃}1±lqpo<ܡ 4.IyUUz)QdKѢ%a1;)eqx7VzhU Ccf_;H!K=VɟL.8wD (z%Wz}h X }9K1D2~ |^1r;窶P> Ë<$mP~t@ad09 sBhgu` ڪBl'׺ύ$-3>nDH5DǼ?Y4j3#:=tDJJFQT]TDSH$NVB 2[(+Ɲ[YVFXO`ZJRSu &SPt#!+(= ;N]N"!|IKPi~̤5_:$S&4=MV,jT';)~W ByAAo1 RzK_tCg36#b>I⑩wz $*p5̅;*ihZw=!KOxblg>7UJ7"K~L-Cbz/Х>< '5%0PƋӸ9k (n82hhT$JcVi4CO5P߄Np%s]_^v1sQ7zκQb/+"E\$ Mr7q"8HdH+sI?LXӧR4H Y%ZbO|dc igs瓟Wtƪs۝|%n=JDeI/勗  reHJ-xy7;󈻢[PQE#>9E 'CMSs!p?MįBՄs(HdN1Kcv c~lVήIYδZ&7O+U!pT ZO4u^&`tX ۹зalvSgpz8ϥdt8yRFQk,Rü^?]+u"=QiI-~4Z,A.BMMʡ U+n=\W`Q_[DGR&NJRg^RgGK77فwەY)|׮E1y*Tp(PddՀo?-( 8O@v)\ }fCOo7 `gw̯edlN{8 =yXc ˾_ѿ2?tF xfh| ,Rm:p+u)5Vjx|,^f{0U=HW- & 65] WrE4g`e*%G°_bK&%fZqΨW?AKڝKt{̗wL(_ʒz$*ؗ$ʙ/HCQAu*YY1GwYz i\+:mJ 1BD/JDj]۵O;׀^2=1&F#B_ܵxy1$')rJA i+5PǀJ3 8ITW~C 1LVu[Ns~WT/O:Cpa(w@i9`Xt)R0a@[]0s` +lsKʛVCv$+|r xs[YavF'%?"o?BE4 -Xlpdu(۩Qxh͹\xZ*gd{ = 4o(y埴jMVYL1J-تE QM88v'vƠ dk~j-Y+7iZ6.ǟ;j'MY|\bHxzʙX) 'T ?.Ԣ:HzSqH[3')-']"MC>1FK+d,^[U,M;&u^Hۄ:Pz~viT ɱӜ BV7ճF͞(qpiNCR}aozaްU?]3y ]LQ61jޏxuN2Ps 9h' S2D)V]PC[(gnl0[I޳**l@bi:ေ{-X!8|t;7s ?-LC#X86,_(d̀UdL\Ǧ:A4^+" <:]On[Mه 0j i&!A$dsf[]$O>m8&|s3e>/66Wע  R(hGe9ısN򫠦*̍-/ =s}5691}e B}"ISw"t9VaҊ%sqU @@ K  NS9~9q6yβ{Ns-cK듩x v3{o3տP1`;N>oeQ be)C(G,Ex©qok{In!Xm趲)@FSLJ}`bccIpo1?8D &cE8)x?;$l"p,Ԥ 7<`c\#ŭ|!XڙcԾU R'8Xj:F'XzjF# ͉>pٷSPVѕYYu0e29<0^adsaL('WV]ׂ_>e^ 9(^1cc&|SFiMgDֺj9-D=qDV:邱z[ZZ|1oP5' B=jD߹Ah], n^gJaNNwҚvN%V@-N1w 1~Tg~6&27]J4]l_^F(י(. A>W>5-q30?\08Wi!J $?9]M¿a+x㩣3,Mn^M*e;1N(l >-@ @@pg-O+2-_D.j_,Πy<6:SRIdA*?lqaZ@Ӭ3_"3xe ˼69N>fjEAGŜ4SB6b/ ލp87h7E64[b.5a^&%䒆W3L#=9]i=Mh"AJl 0 *2&ĄlnP j&k6\'bVPTq$(jM6,n%pmXN(JfИKH#ʜ>^4lUa?z43cC3dN (m߳ 7~Bb~C=g\I';bmV+Ve勈F/HÙǶ{DU!5˛M_<1Yȝܦ?2[x/@*+hT^>C b$ȫ S:\6m6T0' CM! Za*Dr M(+4CqWn O]=*Zxw$-w+!0= pCטKt6\s :/UpozNg  |R)aE+Q(8VrA@mb՘Dݮ(Gt9՛%'KYv us2C^$jڜM KؙW8@Q0K:0X'kC; \fC5_TJv { E/)Pl+1֯dX@uYD@K7ߚ?qmx]W`rU"_uo}f},,-g.@LN+˂`Ỳ@R>YnЦ3_/pG:,V8zisO)m@]n+aLFb-]|oL2`爜I1;e5pSeYl2 ~[7vD_1$+ԙdͯFSR'IX|%r@J C/ F7b> +|j@gsl4W wx]$ˠxoض)94,~{OQ%h-%$:CQ/:gBZ~_ RCЙV/zxrc-U*%izsa݀cLǥ/+.Z@;.V4yf1{Wz{7 5^p-gy'qēU{^VPZ#q_@\3Zu0{2ƺ3!ͳe:rJG f)r%E|TF($=*|6t5#ȕm,~zf4o.SBOcDg }buc(Ɋ%,@.U\.}uK_Re> zt0p'\$bb\{҆S!jP?̀0aPBh$9J1~ @ }P俴Zpt^êuՐT^ FtUohQFYk+X:^HȯY҆EaY&kX?OCO1:ۓwfPt-2 ?hqↃzdܰ}+G373)L{QxlViDq>|]e:z=.` $ǎ,. !KBH~=FI)hq֤%;ƣNao; )O`"5 /$~C?j!ˠp'ttB=2>z#mh"_FyzNCգ~chCV005w~korh聨j輕 c?uy*ƪhF$v+:-#Hc= yWv :)|* /۷lE_Wӥ.걡z_iz2.0A{/T25v]ix7l.:9%`~ԝ2P_RZu 7UhTqzTc\u OK^WZ6c}|]'a"NM߃w(C0903zi rkuԦPhп wLA.ump G8t}[ꌶIb̛;S?& ߋrzjh҄^vUӤ+p{؇x u˙$'*sƇs!u wHmb-ebFl|ocPǏOMRgbzPMt0#R%_Wג n㘱.Q io&D?.um`E4cWLٍIV$V~&c$v+ b#6௫j ?)*N %ikCJMS#XݞnZٜse~6@W^r>v3Jsos4?K,l ٯp &䔀H)R m]/H%`JDbo#v=)WL3qK{q@:fc,b6_wwG!>gWMj⮓R/G%j Mfsx#IA|ண5IqevuZ‹_'.U}jщ]E擡]+ K:L`YhId{^$Έ`0|:YW0PsG$dNlhbW iFB9g,} yX94ʰheLd fފ$>TF*anju5!%苗;&g=r)U<q2'w>*%`T=9PxE ~ђ&AFNL 7czAu0r*P//>|hF+ljƜQ̩V/T\E 7(fnnfFr}Mm,/+دLl@Ci6~xgm!\0EnDZ1Fa:(IU|_kz$ϟj>9QMhBKma˽SrH+6ɦS3K۸XKq0Oϧ#HnAbwX8$ՖYF#& ?Y/Q4,!&>Q[]<(RU/~c{2VT~"oL;*Q9k+=_XM͑k2ْe6@|&wzRHe`MQ8HlZ/p$ZFm' NPmI5YHNuv'!*dБfFY7,a/(ݵFZ @@#&.b1*5Kj.f[v.$x3/t]:~8e1QkL*jvu;Is3ƂU[V́ (CGMPA.ƻ3 Q,9PCHrKYwc& D7oxɧpi0Qĉ;8ٙ'{d#SkjWmGoP3hNҜzK |!'FP_Lu=I,f@ n=ʺrz4e LѶ 7?1FGAHl !N5cG{>bEkJ k\8`Do*x] UF89N:EğkA^0󥙧I0GյIejjrXwCq&y?$m voBo[4WH·+l ͱiHKG\iQqI F<pi_.4K&~o#TC·<~CrN$Kf鐹`1(ڏ&Wϔ;]!sʒnԴO!2z )O|\^V<=_oыp,4D6YY9<.|+}ڏdܝŨHzL6_i(-OxɊ;Z(  sHqf*aA`!k5WI7lKnBFrti؀IH2x٧trpdAd.",%H=j|CyxEp|mNܵZ_0OaGJ^\|j5!:VK#[ 蹳 0w} Oľ5G&ct įy {45 s_|V9k1HA9& ^~%j- hςUoF6Nd K g^%k;f!Q8 {-LƔ| )LdOcs0b+{lΌw5ܯ>@nݎ<+ VA&UF9+_|l8g~OYy+w 0Z6C<7(.Jk$4"} ECpr8rkh+Nͣ==;Y`1dXLb1Tv oު֡AzdSC$Їr2m]u8Dv9}afi Z Q9W,a<pKViWPgTf6/9VNaG-kp-lOQg߀BMc #WjRS6iߏSoSQu۪B#4beL$xHP /kbk9K2> ޭi۲:by6~sH.I޵=ň>t8'!p1~gv[E,]|WJT7X`+P뀱5yJG{Y`n_q_ A.gqj}w\,ۿYv"I:€s^VwF<梜uw=:<>{ ִMT4n.iéyL_2({P]Y;;` Xvb꟎L0Z>r؎^oJͼ䉎Dz$V!Vuf/ҋ )ĶF-渶fmpX}cߘɵ O?ăݱDÑ/maBTZa7-쵤|h{Eى΋H\<6ih6 ozWYU7OEg`ߓ,S*̯YM)pBjH[X`|J; 0 ԸdkzXv!ӽTn܌*trkỘ"1Yrca4Jb) JJx[6w9E~1GϤ((Ð%~2_wC[bӶ{ 5Q{=|Jߨ6-5CUcLc3Ձ< DN5x87E`x?*b5!\W:U"TM%=xy^S#ŋVU8`ܵl|gEg /Qh`#btLwInMW%3h؍G:6?8zkޫQĕ0&<5ª 0VηaaO#&r!8xَDG(۽b4:"ޛe6~՚ |2!øCSz(4 cpi,3gSx)$[y$Žǯ)o6WTq vD!/<U0FѱroF84Sަ2{ @SrAsco]ރԂv3xALuiUc"#Ftօ y2t~S*+ci r/:ٹA"LTAjO+m~+}U*H112 eUi.ܲQw͚,0n #au3}|`Ր2ᩈ"/X,l'a ̫fсHI>`<:@  2cxqQ<_eeY2uu̓4b>?ZHDyڷg?ƴ}g1elՇ& rm%N9MB\'lm<4F%=Y7Q<#a }x'T5ֵ-ٌE%UcE+{F- e/Nu,b3x%iE^|J8XFg"4HK~.4i`wO X_>"[Eq$xSD>9y0~X>akg漞ѸV4z&:Zχ'Yk%M*(fM$q{hG)[rWQ%>'e Hw8F`H-Mt#Res~Jۭ#Ҋ Q3YOxx\yzU <<{tt܃?, @Շ" ZE|giB@V**k|ijDNZFgXSNJmϺo#eWslYoX4#<]O6Q$:hVa0Zޢj?ju%!c|z P.Cs„ #M,8>/4ň`(E=#*x EZb0PIc8?Xҳy{59?#V ~e|` )F+xgwO :7^q,rQ) 9uI8l%!SE[ު1%\{V kXR@T!|UqX}9TPȢs*Qm#N4#VRȖ>l &b%I@4A'V36geLL!Ƀ2ZiI{ .WKF))G-u.ocpD8/{\ÁN'7}2Cњ97 c5qWD]Yz))UziձޅT{)GrY g wrRu@}cZԟyRYE/ moe˪qכMBt+H Tٻb L$dgan3|A:BcװA~T>527Upw6NAJ/%7lsGv9BD!27r|VǪ@eV|leL삆t6ڽ waG.r- d\rƴjOj.N]"lHC XU)sm5-}/+'?- |׼ 7m+WK]²HBXHtߝpܣͱ 4ƺs R QbmvqtbRl̵:&qlЬW(!m'P5fG!l^3sSNz.\ފ G'74u:W#}lW Af~y֝E6HA QdlutqSѭgȿA`Siɑyby)b´#g $v82xPM2 ġR?dֶ2U-T(tH29[$}O9P׺-Ih̑~ZEM7=k5ԮEc.A(fL~:j3O.Dڶǭ24~G~ުegQ;ZC: K,RnvEn?Ġ>,֫x:[b{Yo\TL/Ȥy4t쩢n$H&-__е1#W{ױ$eqG#1L鯣ܽUVv/@R`ں2P tO }MJ!r9jM"3#$_#BrkL++\{6=k(b__&]wEqȇr G! 1 z.d]`rqu29s<~` s{?ݩ8^f_4ekMF~0sN$/:M*0/Yܻ5Pn d08^qYΈgVZK:(BdfD?nYѣV}CG:*ĭLSx+2U3ފ2VْrH6د1U;_@-yd|҅Y4,$9{tg+?[{34  ,rF#>+2 IOo{-az8YZz!Pc5[!||ȭ xsF<0.6:vjᆛ[Oy+bBt V|)NnVIyJET|3/d˂J p>ޱҖu @"pI"v+U^S^)ߕ9ׂa+t\3UIĔ[25[Z "_ r H]R]&O& \^)b_dH (Wf,vW/䤗CgVI|Q$TwJeѣJ(yl)DPYF922b207bǏLUTCς*~PN▬oۥ=1p+ԝC+`枘 Zt%r#T;W_ӁU7?o(;>t.K*%ItXM3@ۋKƐyJKCqKz& g+[_KxXvЄdKk)d#s RVM5 7ɎSPWK1SB; m;R8߽箲=JțʰSW HXd01iO2ƫq}*],!8 Peo,~s C$5W[rkB4 p+Hc>,+\}dIa myD?:X7Ot%'-6D<Ԡ+З"2ܒ,[6e V !W˙u>%|vBxM[wJ ֣=KMxf$_7pG+ZeFl_Q,Piٴ4*^m;Ͳiܡ~a= Y-{cb>͉xgi{D G6|k oQsxfpw﵊ξ{6KFP*ٝc41!CI:d'2ۧw)~ a)~渶?R7AtAʍѮEg/{ $G;~Qb$meØi m_O԰Vya;W&/8k㾅˻G>zqT,xЈ~,Mn(0 Qc%p l_|)|D` l_e+FR<ڮ_aӻO]85)6HU_v96:lhoh_12<_#IWJY!ǥK@֐96u MPbݶA{(?y{n|y͠aRq gKޯSMuR |N5i2x#֌^Nb f}j&eA!{28#8bK7W>**^f H^ 41UT04/,"2DSi^6z3Po,7qq"J S{Bc@LJC,tgW0!-lٻ8%ԱvfffLrkK&:ht婃K:m?O#J{%~'×=}9_V !e9cT*s;>jhT) =HNbU8^ w7'*)H=_2]ΛImt(TdЇHQ\!߭Q5 vmYJ{FB6LsBf0(JLg|E2F\$:Rwy-6>p}Gdg'oz_cm^ѬԶ<Q[W_}$t)= }^fb,ULHd);k ,KɧpȤ(5*ͺ:9XvU1Њ^ӿzvC*R_65&&nE?xqUSD߮%bAyUg~lQJhSpfp+j-n_-VuEb YZZ_v L޺z;uC9}Θ/@+Hw?qt[1Y/| p3 slG%'\; & BRYɰxdӇmשo4'EƃFy4\`KM;]8G]7T /dg A8@5|yxkOvnU{lRiw29YՂpi8fc+s(lt[gEu`LO eğ SV_jL@,sWiQP]Ce'ʊeKPAdPv2bGVsyA2b%/ꛗ`ǭ$Ͻ"eU_~ۆ5ދqh5nY4h"eU满iW_27sSӟD|-`q)sCwa.~1 IǞ)b^ nrIFT|_KG^}䁗d,qʾ"Etx[i6H&DUf"<*~âR 퀦D3gBݍ{82rl;X3%lGg'#&b<[7ČX*\ck'; /\qROV"(LɷI/r2 !++Ze\Sb녅JYGKsNg/41"@wkW#0'7N5C+%l*“CUZZbsy^7?1em X,4kն3 &FRc?*[Pl>%`3^RJ6 rf] !ϝNxn5.m]nXpƮy١>()ylfDb$<]ӂ:~t402zza^(Uh'C7xaXAZԸ[h,ǀc'&QH8.)%2kK9lNYD V 0m>U9FsZm"2ƂEQ n=ſiʽ|ϴ.M(wX09c:$7:ik7ĵJB GZ'#L VBXh_"f Yrlj+ QR)aصB)| bF0N!◱)9]=ۅhw-RSE:1;?Z{LkSRVtiLc`G|ǹ _O_"+id'F'~QFWTlZ<K+)==Xb"_WW,c%ÀoRtufʁh<+G o /WXRGhP7qЃbgM0OxZѻFFZ2lNQ}UfQC?^K{}e}zā,W0gT4ꣾ%sJ:/}QPXr4rɚY2Wa.=Ǿ:O1ro":6 56|mbbĵl狛@$6mzmPݶx4@y/DzXCKя}avhhM[P呾Ք:B\8'_7W~]/m srgv5m@ǛvQ`%fŢGL0-n ֟ٸ)(_hb1B_ŖPFÍ2)٭J)K``ƏrmCuUeʸD֑|u3i72ac<4\Nǽ{Нt:@CqB}lB[b8VCqYWp]@{{T ]i#Δ>bR%~ (ys(ff ur_$TК*҈Ze!̨lTzUĪkwΝ1}v.#lud3R;|:K~ ~ɏfM ?+q`4XZ $Ϻ_^fˡn`)ch>1Ą--:?_EǴ}x/uDxk biLBuFKYe[>9rS,^Ѽ_^ʆ34v)P.#(0;QDLQRpg/(i^`c(8uٜǨb3+ &o֫9=3i?K‡. 2jeVʴ9LSf0‘Eh@l^߅B𳪄Jwy{m4d[,n>mkeg*6.@&"Rx  Cs0RCh)Grq3o ,*!/`Y\Z_ N7OZ'N~77Hj5ޅ.z<_j_kzw V` <⟘%AD䳌,EJar1sclnFo~kQ+%w~|.4@оIzbv}=lSwdž/|a5MbPzW309b| ^o Uz8HGQ<8N@Ȳ+Snu&ơz !s X ytuG|w`KQl[η;FX2A@MG;~om ۾?˳Sג!4&HmO5quJK dRל@Ւ-Wv0x$/L]c\̉7]{GZ '{KțIk-2 ZyHw@E~X7{Ӽf8)nJGUND(̓iU{4Oto QC9?BWAhN+p3( ^` T/Ls-l[ ]>;j'#,[,۩$NWtjYӴLpJzd?/~?i1xJ_Nv%̹+1b=`d,$%WFzg&f?~XJ33vF6z31Y+`xAeG]{*BLvt컝չP J,%/{"tnw_1&b&mӊ Gv 4{$ŕ+mZ*/h9 of5"Bu:@=z;Z4U$01ĎlLSJ A`e# he@RL.ȇRwڰR:k:w? B7^q{a)B@]p91_^qL2trP4jx\Ŧ0j %i XQ'S?:>D\+ sۥ6qHhu06kz e&b/]E.b|b|&1;MwP 4)"?,!!ж߰zUnƿg,^^CGb~)8[t۩v%69qæLX/11%x_4cH_-iI =+y<ɣdkȯhRAFķjLMJMБH KK^>yKtA;~% ܲpjF+EHx<:=f0ѺӛHt9)L)Qp3dZ\\XnOȏ/JҌCּ;=x! T&#=mn#ˬy ;Bg5apj[0ƂmWC#Bvɝ݄?NEqNՙV]3 ?܆m@ im R&(nUy zx~u]8oGυڝCAI7+pZ -Ĺ 1-O&M-`?9Ar//8tg_7!^u ew!P!+/{kQnLc*Eפ.WNISC=7o;ŵ~ 7ǩPb_`Dؤgi.9g5&A:1ʜXCCws%X7ǐDyoz~8 \ԮML<"r{hzN]j {BRN' G>(ԙX/_,WaRD<`[-X`ܷZn}?G*1FdGhϛ{Lx;;Gg׉fIQ>HNi'b błRޭKNȬ.z;``q(ti[)\  $4CDx2CjzRYaw^B"L=zjM]`0wh!!߽*sv%8nafn}A:E쀞N-K"/"԰OoyXinwM`x$}Ekř m,)GY!^ KnMk˵a;. oIOوb20kA<Ӥսc`|I>9"n0yQ;v'u{(#Wmx H[ ad =WڣL}H/b/~> }۝ߤ'%c;VTC.y[|h؂ޗ<] {щP{# Ѱw %3*OG'jD1;'cMt nGh)$#&9lBt'Y 5ST:ZZ/(wN?'}xd¾-57zqL7qh%] /N=|6rڪg&ʹplK΍5@:Q79&~! :W"D j̴ְ,y^bnd,Or0Zv/Lgyf%0ABH)Q&bM3Z&› a#ZI#\#,WPrŠ0nQq-`v[1ʎ=gBRZ;x1_ٰ׹s8CuB}g>?=3J\mnFk(,ԗ1XD: O|LFW1`qGIB*?j |W/7o`.69)whSȸtpz,4k /.~Haïpgj/ zi/v>7g0NY e--%\%`1/y1@!T0VUs,Ek{$|R8l|rYHqWro=^Me#}yF2ǣR\XcxT|9ҽf޼UPՁ 'a+GYR[##sVRkxR.ǰONڵ/#ApRX\f };^@mMv+i5yK +0K.;l0#@Oxzwۿ Clj'#80JkS*ɳ@$SM>Q>ƖG.JW.`dVrدpN0!zޫ$V+YM+'Tꃗ/iI22 ,u6ǐO^0 Z )z)3$XPmNƲem~a[Ar$cimO5,G5aRsnPOY0榉j_*ߑ@H7cU+,w!Ab;~tNxVjjS8ugw)VX".MZ7h]3Bq__hz853m.o_/A.'/ 6gra+xM/)TRΘQQqW0gBCPw՜jFRԦmU-0?q$̟}u;[`Uč(4H w筁P,] 7+Y/jY\M H]iAMW3r8zqN! Yb!'iİ=":^";TG3?u'xꂰºo /WO+WN3H "{_, pVȷs en txKy >Oy`sdAF Bh ?+5.A>4xާ*Ey,&Ц勠+Z|GL> ӟVFZb75΀6d1 rEd맦jEQHAD֘ oH\͑T[isSw+1UE|Uq4U-[;i%y>(nJk:MY2\T2rmDL@.\$p 3=BxJŀcB坄k}TnkTTln.xne$Ug4#Q@gf3yG$#5^;uI%=\lfNxd 8gCY쌵{ii5ئa ;<ͮaix3#bSX  G(C s6cI}{̑T -# $LȢίuE׍\M.~z~J'"l2>ט}Ó;_ Y{*|#Yp š[&Y^y.6jRN@\ I9 X4gjk*?]r CE_+9Muٚ]*: W\$/Q4nI0 )ӏ*ٿ*m`:xZ'#x.%Lkn .xdᗦuEk% ZvŎxaY=%Tõ4rHn80`{" \?R!-*ʓa8WKkP=҈g ,=ŀCP_>ђ?S@А;#Jnɪ\{=]ユB' bDgL|52lM>kֽI=|M*M~iV (t_w*#"BC#/$\ IO/xo*cvL1%eHEq1ޛC՘65/N[dnV14}KI!0rS<s99T7I0† ¦:4]/•H~ۗS՞= %šAfo3 ?1ݑgyʡ+Dz]0vDXt~.?Rwx ^ e̮Z20`P_u9֖ ̐1vn&"zy=xBqby`4^ymX=;=4؃e8`-*`=Vi)9^2\!O#;\ Pi4\֮y R|KJiNdA(DS| ղb8h^1?AnF NhNb2r$\ #IWlG7=b'=)v[#gj N AtR%RLWw՟1x:"}I~=m_ QC̚=:^Ofz2#6c'kIG8O;Or\$)h. :؋)TBu9!29U@=0$vl.[-fć"aػLD±mMQ9RB po>'a$w%rfN%{0|O4 ,0* .-]:}B f>(j4*p Ox=9پF]X!clv ]۫!uί0dwQ`싁PyoJV\Ǽg!X7^K*9` \8+ԤaPc|iC()I1AZ )HM(4ȍ` }+{ǭ[Li_$đ{"bLˊδwK6xl?Eb#Wu`rfma.!EwLXh9ÚO }S(xhlHMwܚR|\W:gLKZcn;{I=im37h 2l05LA"K?j8}#:H wz6HӱֻU7`Ge <g5Aqjyi-ɢnSD5v/ʉ1CWT tt ;k߆`URnieҌh._LE65Ow]2'_G.5yzfH~ v?!ƁqbA;܌jJZַ #YZ<<~ku΋.OM<ɵ!ƝvjbR S ]45ي`PM'=z#6n?Ȝ͒N!(s|]rjq&/Ŋ*=z*DYb!@9S?LZmS/cmx,{,~Q7%V TIC;jCȗ~Ճ*3C *+ރ&B2wBZXC ;}A-o剶*'Wu@\xh>Rx ͡<.¨jKĄ/.v⫻/XY~&u QmUh NOvwRA[JfV`TI950|t)Ӊ[-;2Z d&nuϢ9:x&TcnGw"dٞ5Ė{cOΦ1qd.h~ښIVLvc֪ {A?a9 aDHJ# R. 2N`i&Y%'"WL|Rikm1ݼBYڄyd﯆YTK"󭭻k/s&`, >.$z 8yT+Ezm82l' z͐N`rp1PZ_yQC ⹵b)~?)z5fEF2mD#lcb?TɆP)V/b f0,]ۅ£:sz{~٤;s.]qdO 5/IVKC5׺@Dކl:5""'frf>2~g  AY T(XVF%s:f1qL!G2g\]c$;m5)hAeta+ {g̫?m]/*ϊH 0&C7f6gv[ob295@ &ɋa3pA4`%Ϲilڅ/~}1!Tr=1K TI{k2NSS1Ӑ)h} *C|zApԚ߇A rqe[`Vpɉܯy@ CR7CsfsI^.?Aik :ЅEҤ9pN܏F$cr&VUxl%Q& U69:wr:5 ؈66a켈O{\_4M"th̠ھtoz[wp8we>bI'VMe'%Π{Tj\!oҭmpu HŘIi87USǩ#7>۱D^ 6$!皦@nY#á)b!{NwOZOy ;t7ĝ(y hY{s{}\&}_t45B9a,&\yRŠc$SRV;_ue.xjFp7ӑL1s+AL DmDS`~Oc7yeK"VV8n< Xv.ɬ{lBm8 ><_yQ fBm&PPTD[ gh8|./3FwYGݪFY ,f:0j*KBpB8-H\)z/_NpQf/ l.^'a<_BQzCT'